Oluwadi About · New Org. · Analysis · Reports · Trends · Blog ·
Oluwadi

Investigating the Overlooked

Region What Who For Analysis
In 1943, an Oscilloscope Spiked Every Time an Army Cipher Machine Encrypted a Letter. By 1951, the CIA Could Read the Plaintext From a Quarter Mile Away.
TEMPEST -- the NSA program addressing "compromising emanations," the electromagnetic leakage that lets a listener reconstruct what a device is processing without tapping a wire -- traces to a 1943 Bell Labs discovery and became a formal government concern once the CIA read plaintext from a quarter mile down a signal line in 1951. It's the operational-trust counterpart to the fabrication-trust question this site already covered in Trusted Foundry: not who built the chip, but whether the finished device leaks what it processes.

In 1943, a Bell Labs engineer noticed something odd on an oscilloscope sitting near a piece of Army cipher equipment: a spike every time the machine encrypted a letter. The device being tested was the 131-B2 teletypewriter tape mixer, part of SIGTOT, a one-time-tape cipher machine just entering Army service. On closer inspection, those spikes could be translated back into the plaintext message the machine was actually processing -- proof that an encryption machine's own electrical signature could leak the secret it was built to protect, without anyone tapping a wire or breaking a code.[1]

The scale of the problem became a government fact in 1951

The discovery sat mostly unexplored for years. Then, in 1951, the CIA told the newly formed NSA that its own engineers had been experimenting with the same class of Bell teletype equipment -- and found they could read the plaintext message from a quarter mile down the signal line, with no physical connection to the machine itself.[1] That single fact turned an oscilloscope curiosity into a standing national-security problem: any electronic device processing classified information was, by default, broadcasting some version of it into the surrounding electromagnetic environment. The NSA's own classified name for the resulting countermeasure program is TEMPEST -- a real acronym, not just an evocative word, most commonly expanded as Telecommunications Electronics Materials Protected from Emanating Spurious Transmissions.[2]

1943Bell Labs discovers cipher-machine emanations are readable
1/4 mileDistance the CIA read plaintext from an unmodified signal line, 1951
$350-$1,000+Cost per square foot for TEMPEST-shielded facility construction today

The standard scales to the threat, not to a single fixed bar

Modern TEMPEST requirements aren't one universal shielding standard -- they're tiered to how close an adversary is assumed to be able to get. US and NATO zoning runs from Zone 0 (an attacker essentially in the next room, roughly one meter away) through Zone 1 (about 20 meters, or equivalent attenuation from the building's own materials) to the more relaxed Zone 2 (roughly 100 meters of effective distance).[3] A facility processing the most sensitive material at Zone 0 needs shielding an order of magnitude more rigorous than one that can assume real physical distance from a plausible listener. Most of the actual technical specifications -- what NACSIM 5100A, the controlling document since 1981, requires in decibels of attenuation for a given zone -- remain classified even today.[1]

That rigor shows up directly in what it costs to build. A Sensitive Compartmented Information Facility (SCIF) with TEMPEST requirements commonly runs $350 to $1,000-plus per square foot, with accreditation timelines of 12 to 36 months -- meaning a single closet-sized 200-square-foot secure room can carry a price tag around $200,000, driven specifically by whether the space needs to meet a 60-decibel or a 100-decibel attenuation requirement.[4] Retrofitting an existing building that wasn't designed with TEMPEST in mind is routinely more expensive than building shielded from the start.[4]

Most popular accounts of TEMPEST reduce it to a single machine leaking its own signal, but the discipline the NSA actually built -- it calls the broader field Emission Security, or EMSEC -- evaluates a system, not a component. NSTISSAM Level III, one of the governing test standards, is formally titled a laboratory test standard for tactical mobile "Equipment/Systems"; the distinction is in the standard's own name.[3] A device that passes an isolated bench test can still fail once it's actually installed -- its own cabling, the power line feeding it, and the other equipment sharing the room can couple its signal onto paths nobody tested in isolation. That's also why TEMPEST evaluation is fundamentally observational rather than calculated: an installed system gets physically measured under real operating conditions, not certified from a spec sheet, which is a large part of why accreditation runs 12 to 36 months rather than being a paperwork exercise.

Why does this matter? TEMPEST and the Trusted Foundry program already documented on this site address the identical underlying question -- can this system be trusted -- at two different points in a device's life. Trusted Foundry asks it before the device exists: who fabricated the chip, and can that fab and its ownership be trusted. TEMPEST asks it after: once the device is built, powered on, and doing its job, does it leak what it's processing to anyone close enough to listen. A chip can pass every fabrication-trust requirement in the country and still fail the second test if the finished equipment around it wasn't built to contain its own signal. Both are real, both are expensive, and neither one substitutes for the other -- which is exactly why the government runs them as two separate, parallel disciplines rather than one.

There's a third variant of the same question, at a different scale entirely: what does an entire facility's aggregate power draw reveal from a single point outside its walls, no access to any individual device required. Fabrication trust, emission trust, and aggregate trust are three separate tests -- none of them stands in for the other two.

The takeaway THE SAME QUESTION -- CAN THIS SYSTEM BE TRUSTED -- ASKED AT TWO DIFFERENT POINTS IN ITS LIFE. 1943: A Bell Labs engineer notices an oscilloscope spiking every time an Army cipher machine (the 131-B2, part of SIGTOT) encrypts a letter -- the spikes decode back into the plaintext. 1951: The CIA tells the newly formed NSA it can read plaintext from a quarter mile down an unmodified signal line. TEMPEST becomes a standing government program. TEMPEST zoning scales to assumed adversary distance: Zone 0 (~1 meter) requires far more rigorous shielding than Zone 2 (~100 meters). Most of the actual technical specification (NACSIM 5100A, controlling since 1981) remains classified today. $350-$1,000+/sq ft: cost of TEMPEST-shielded facility construction -- a 200 sq ft SCIF can run ~$200,000, driven by decibel-attenuation requirements. The comparison: Trusted Foundry asks who built the chip and can the fab be trusted. TEMPEST asks whether the finished, running device leaks what it processes. Same underlying question, ingest vs. operation.
Sources
  1. National Security Agency, TEMPEST: A Signal Problem (declassified 1972 Cryptologic Spectrum article)
  2. GIAC / SANS Institute, An Introduction to TEMPEST
  3. Test and Measurement Tips, What are the three levels of TEMPEST testing?
  4. Salian Defense, How Much Does a SCIF Cost? Budgetary Ranges & Cost Drivers