History
History

Secret Tallies and Fragmented Letters

History

Secret Tallies and Fragmented Letters

A runner reaches the ruler's tent and lays down a wooden tally one foot long.
stable·concept·1 source··Jun 12, 2026

Secret Tallies and Fragmented Letters

A message you can measure with a ruler

A runner reaches the ruler's tent and lays down a wooden tally one foot long. No words pass. The ruler already knows: a great victory over the enemy.1 A different runner, a different day, lays down a tally three inches long — the army has surrendered, all advantages lost.1 The message is the length. You read it not by reading anything but by measuring the stick. Eight lengths, eight grades of news, from the foot-long triumph down to the three-inch catastrophe.1

That is a cipher with no letters in it. Long before anyone in China is encrypting words, the Six Secret Teachings is encoding the most important battlefield reports into the physical dimensions of an object — because if the runner is caught, an enemy holding a plain stick has no idea that a foot of wood means the war just turned. This is the ancestor: secrecy achieved not by scrambling language but by refusing to put the message into language at all.

What this actually is

These are the pre-alphabetic Chinese answers to the problem of secret writing — three of them, escalating in sophistication. The first is the length-coded tally: eight grades of news, each assigned a tally of a fixed length from one foot down to three inches.1 The second is the fragmented letter: a written message split into three parts and sent by three separate couriers, so no single carrier holds the whole thing.2 The third, centuries later, is the one-time pad of the Wu-ching Tsung-yao: a forty-character poem keyed to forty pre-scripted battlefield reports, so that marking one character in an ordinary-looking letter silently transmits a coded message.3

All three share one premise that Sawyer, following David Kahn, makes explicit: the Chinese writing system largely precluded letter-ciphers. Until numeric codes were assigned to individual characters in the nineteenth century, you could not easily build a substitution cipher the way an alphabet allows.4 There is no "shift every letter by three" when your "letters" are thousands of distinct characters. So Chinese cryptography went sideways — into coded objects, split keys, and steganography — precisely because the front door of letter-substitution was closed by the nature of the script.

How the three systems work

The length-coded tally. The ruler and his generals hold a shared system of eight tallies.1 One foot: great victory. Nine inches: enemy army destroyed, their general killed. Eight inches: enemy walls forced, town captured. Seven inches: enemy driven back, deep penetration reported. Six inches: alert the masses for stalwart defense. Five inches: request supplies and reinforcements. Four inches: our army defeated, our general dead. Three inches: total loss, surrender.1 The security rule attached to it is ruthless. The T'ai Kung instructs: detain everyone who brings in and presents a tally, and if the information from a tally leaks out, execute everyone who heard and told about it.5 Only the ruler and general are to know the system's meaning, so that "even though the enemy have the wisdom of a sage, no one will comprehend their significance."5 The capacity is tiny — eight messages — but the security is near-total: an intercepted stick is just a stick.

The fragmented letter. When eight grades aren't enough — when there are "secret affairs and major considerations" — the T'ai Kung turns to letters rather than tallies.2 The letter is composed as one unit, then divided into three parts, sent by three messengers, each carrying one part, "with only one person knowing the contents" — meaning the message reveals itself only when all three parts are compared together.6 Even an enemy "with the wisdom of a Sage" cannot recover the message from one part.6 Sawyer flags the assumption baked in: the design presumes only one messenger is captured, which renders the other two parts useless even to the intended receiver — and presumes every concealment measure is also applied to hide each fragment.7 It is a split-key system. The whole exists nowhere except at the point of reassembly.

The one-time pad. The Wu-ching Tsung-yao's "Tzu Yen" — "Verification Through Characters" — expands the T'ai Kung's eight grades into forty.3 Forty distinct battlefield items, from requesting bows and armor to reporting the enemy seen or unseen, numerous or few, a siege laid or lifted, a victory or a rout — each secretly designated by a single character.8 The forty items are correlated, in sequence, with the forty characters of an old poem chosen because it has no duplicate characters.3 The general and his subordinates each hold a copy. To send a report, you find the relevant character in an ordinary letter and mark it — solid circle for granted, open circle for denied — and this "kept the masses from understanding."9 Recite the poem silently, count to the right character, and you have your message hidden inside innocuous text. Sawyer notes the refinements available: scramble the forty items before assigning them to the poem so that knowing the poem isn't enough; bury the marked character at a predetermined position so no mark draws attention; embed phrases at fixed count positions in a scenic scroll covered with poems.10

What this gives the rest of the vault

The cryptographic floor under the whole intelligence corpus. Where Secure Military Communications gives the courier and the channel, this page gives the thing the courier carries and why it survives capture. The two are a matched pair: the communications page hides that a message exists (invisible ink, unformed words); this page makes the message useless even when found (split it, code it by length, key it to a poem the finder doesn't know).

It also hands Tiger Tally Command Authentication its informational cousin. The tiger tally authenticates who may command by matching two physical halves; the length-coded tally encodes what news arrived by physical dimension. Same material instinct — meaning carried in an object's form rather than in words — pointed at two different problems, authority and intelligence. And the split-letter logic is the direct ancestor of the compartmentalization that runs through Camp Security and Movement Control: no single node holds the whole.

Case study: the three-part letter and its hidden assumption

Take the fragmented letter and press on the seam Sawyer himself exposes. The design is elegant: one message, divided in three, three couriers, the meaning emerging only when all three parts meet.6 Against a single interception it is perfect — one captured fragment yields nothing, and an enemy with a sage's wisdom is helpless.6

Now read Sawyer's caveat, which is where the system's real character lives. The T'ai Kung "assumed that only one of the messengers might be captured — which would of course render the other two parts useless even to the intended receiver."7 Sit with that. The very property that makes the system secure against the enemy — that any missing part destroys the message — makes it fragile for the sender. Capture one courier and you have not merely failed to leak; you have failed to communicate at all. The message dies with the missing third. The split that protects you also strands you, the same way total compartmentalization strands a sealed camp.

And there is a second buried assumption: that the same nefarious concealment measures are applied to hide each fragment, "as mentioned in the introductory section."7 The split-key security is not self-sufficient. It still leans on steganography — each fragment must itself be hidden, or three captured-but-innocent-looking strips might be reassembled by a clever enemy who realizes they go together. So the "hard" cryptographic method secretly depends on the "soft" steganographic one to keep the enemy from even knowing to collect all three parts. The systems on this page and the communications page are not alternatives; the strong one needs the weak one underneath it.

Marking the character at the desk

You are a subordinate general. The enemy is massing; you need reinforcements, and you cannot risk a plain message that, intercepted, tells them you are weak. You have your copy of the poem — forty characters, no duplicates, each one silently mapped to a battlefield report.3 You recite it under your breath, the way you have a hundred times, counting until you reach the character that means "requesting supplies and additional soldiers."11

You write an ordinary letter. Something a captured courier could carry without alarm — a routine note, a few lines of nothing. Inside it, at the spot where your character naturally falls, you place a small solid circle.9 If you wanted to be safer you would bury it at a count position you and the commander agreed on in advance, so the mark draws no eye, but tonight the circle will do.10 To anyone who takes this letter, it is a soldier's idle note. To the commander, who holds the same poem and recites the same forty characters, the marked one says exactly: send men, send supplies. You have transmitted a critical operational request through a letter that confesses nothing — and if they granted it, the reply comes back with the same character marked, the circle solid for yes, open for no.9 The whole exchange happens in a code that lives only in two men's memorized poem.

How the system fails

Each method fails at its own ceiling. The length-coded tally fails by capacity — eight messages cannot cover a real campaign, and a tally that must say something outside its eight grades simply cannot say it.1 It also fails the moment the system leaks: which is exactly why the T'ai Kung attaches execution to a leak, detaining every tally-bearer and killing everyone who heard a leaked meaning.5 A code with eight entries is trivially broken if even one runner talks; the only defense is terror.

The fragmented letter fails by fragility, as the case study shows — lose one of three couriers and the message dies even for its intended reader.7 It also fails if the enemy realizes three innocuous strips belong together, which is why it secretly depends on each fragment being separately concealed.7

The one-time pad fails when its key is compromised. If the enemy learns the poem and the items are not scrambled, the code is open — which is precisely why Sawyer notes the refinement of scrambling the forty items before assigning them, so that knowing the poem is not enough.10 A pad reused, a poem shared too widely, a marked character too conspicuous to escape notice — any of these unravels it. And the deepest failure is structural, the one Kahn names: because the writing system blocked easy letter-ciphers, every Chinese method here is a workaround, and each workaround buys security by sacrificing either capacity (the tally), robustness (the split letter), or simplicity (the pad).4 There was no method that was secure, capacious, and robust at once.

Evidence, tensions, open questions

Sawyer is careful with his own evidence. He writes that "something like the array described in the Six Secret Teachings may have been employed in the Warring States and thereafter" — the may is load-bearing.12 We have the prescription; direct evidence of operational use is thin. The same hedging applies to the more exotic refinements of the pad (buried characters, scenic scrolls), which Sawyer offers as possibilities the texts imply rather than documented practice.10

The Kahn argument is the spine of the page and deserves to be held as an argument, not a settled fact. Kahn's claim — that the nature of the script precluded ciphers until numeric codes arrived in the nineteenth century — explains why Chinese cryptography took the tally/split/steganographic route.4 Sawyer endorses it, and notes that character substitution charts and book codes "would equally have been possible" but shows little to no evidence of their use.13 The open question: is the absence of letter-ciphers genuinely a constraint of the script, or partly an accident of what survives in the record? Sawyer treats it as constraint; a skeptic could read it as gap.

The continuity tension: the Six Secret Teachings (early) and the Wu-ching Tsung-yao (Sung) are separated by many centuries, and Sawyer presents the pad as an expansion of the T'ai Kung's tallies.3 The conceptual lineage — encode predetermined reports — is plausible, but "expansion of" is Sawyer's framing; whether the Sung compilers consciously built on the Six Secret Teachings, or independently solved the same problem, the source does not establish.

Author Tensions & Convergences

Sawyer narrates these three systems as a single developmental arc — tally to fragmented letter to one-time pad, capacity growing from eight to forty, security techniques accumulating. That arc is his synthesis, and it pulls against the centuries between the texts. The Six Secret Teachings and the Sung Wu-ching Tsung-yao may share a logic without sharing a lineage; the page reads cleanest if you treat the "arc" as a conceptual ordering rather than a documented historical descent.

Where Sawyer and Kahn genuinely converge is the negative explanation: Chinese cryptography looks the way it does because of what the script wouldn't allow.4 That is a strong, clarifying thesis, and it reframes every method on the page as a creative response to a structural constraint rather than a free choice. But it also has the shape of an argument from absence — "they didn't use letter-ciphers because they couldn't" is hard to distinguish from "we have no surviving evidence they did." Sawyer leans toward the constraint reading; the honest position holds the alternative open, because the same evidence supports both.

The internal tension worth preserving: the fragmented-letter and the steganographic refinements embody opposite bets about the enemy. Splitting the key assumes the enemy will find the message and makes finding it useless. Hiding the marked character assumes the enemy won't notice the message at all. Sawyer presents both as available technique without ranking them — faithful to sources that offer a toolkit, not a doctrine.

Cross-Domain Handshakes

Handshake with Secure Military Communications. These pages are the two halves of Chinese communications security, and laid side by side they reveal a dependency that neither states cleanly. The communications page hides that a message exists — invisible ink, unformed words, a blinded carrier. This page makes a found message useless — split across three couriers, coded into a stick's length, keyed to a poem the finder lacks. The structural relationship is that the hard methods here secretly lean on the soft methods there: Sawyer notes the three-part letter still requires each fragment to be concealed, or the enemy reassembles them.7 So the split-key system, which is supposed to be secure even when found, depends on steganography to keep the enemy from finding all three parts in the first place. The insight neither page generates alone: there is no purely cryptographic security in this corpus — every "found message is useless" method rests on a "don't find the message" method underneath. The strong defense is load-bearing only when the weak defense holds. A general who trusts the split letter while neglecting to hide the fragments has built a vault with the door propped open.

Handshake with Tiger Tally Command Authentication. Both pages encode meaning in the physical form of an object rather than in words, but they point that instinct at different problems and the contrast is the insight. The tiger tally answers authority — does this person have the right to command? — by matching two halves of a split object; possession of the matching half is the credential. The length-coded tally answers intelligence — what news has arrived? — by the dimension of the object; the foot of wood is the message. One authenticates a person, the other transmits information, and both refuse to put their content into language that an interceptor could read. Held together they show a single Chinese design principle: meaning carried in matter, not in script — a principle that makes deep sense in a writing system that, per Kahn, resisted ciphers.4 The insight is that the script's limitation didn't just shape cryptography; it pushed a whole class of Chinese security solutions toward the physical object as the bearer of secret meaning, whether that meaning is "you may command" or "we have won." The same constraint that produced the tiger tally produced the length-coded report.

The Live Edge

Sharpest implication. The cleverest secret-writing on this page is writing with no letters in it — a measured stick, a split key, a marked character in a poem nobody else holds. Because the script blocked letter-ciphers, Chinese cryptography put the secret into the form of things rather than the content, and that turns out to be a remarkably durable strategy: you cannot decrypt a stick, you can only know or not know what its length means.

Generative questions.

  • Kahn says the script precluded ciphers, forcing the tally/split/pad solutions. Is that a real structural constraint, or does the absence of letter-ciphers in the record reflect what survived rather than what was tried?
  • The three-part letter is secure against the enemy and fragile for the sender — one lost courier kills the message. At what point does a security method become so robust against interception that it is more likely to fail your own side than to protect it?
  • The length-coded tally carries eight messages and defends them with execution. Is terror an adequate substitute for cryptographic strength when the code itself is trivially small and breakable?

Connected Concepts

Footnotes

domainHistory
stable
sources1
complexity
createdJun 12, 2026
inbound links4