The Drawbridge Model of Cryptographic Communication
Open-access preprint.
Abstract
This article introduces a theory and model of cryptographic communication that treats conditions of communication failure as the basis for different types of information security. Building on the metaphor that communication is a bridge when it succeeds and a chasm when it fails, cryptography serves as a kind of drawbridge to limit the audience of a message through selective communication failure. Different forms of cryptographic mediation are thus framed as arts of privation that selectively limit and divide an audience. This theoretical framework is illustrated using a model with a series of drawbridges representing distinct sources of communication failure, each of which induces distinct limits or privations depending on the manner and conditions of failure. The model’s descriptive, explanatory, and diagnostic power are illustrated through various examples in which distinct forms of communication failure are used to facilitate conditions of privileged discourse and dialogue by narrowing the dissemination of communication.
Keywords: communication theory, cryptography, information security, privacy, secrecy, surveillance, communication failure.
1. Introduction
Although cryptography is often defined as the art and science of secret communication (Kahn 1996, Singh 2000), much of the research conducted on cryptography today is very distant from communication studies. Modern cryptography is typically treated as a matter of algorithms and their implementation by the mathematicians, computer scientists, and software engineers who have guided the research agenda in cryptography and information security for decades, while theorists of communication, culture, and society have made fairly narrow and limited forays into the many challenging complexities of cryptographic media (DuPont 2020). This article is an effort to open cryptography to new forms of inquiry in communication studies by rethinking the subject from first principles.
Consider an apparent paradox at the core of how cryptography works. Every type of cryptography is a kind of communication in which communication failure serves an essential role, dividing the audience between those who receive the message and those who do not. Just as distortion may cause transmission failure and camouflage may conceal an object, the fundamental purpose of cryptography is to cause selective communication failure, not only through technical means but using the full range of ingenuity and artifice in the means of communication available to us. Whether it’s invisible ink, a whisper, or the digital encryption that secures much of the internet today, secret communication leverages communication failure by rendering a message indistinguishable from noise, silence, or nonsense for everyone but the intended audience. This basic principle leads to a novel definition rooted in communication and culture: cryptography is any form of communication designed to limit the audience of a message by generating a reversible state of communication failure, just as a drawbridge selectively allows some but not others to pass. Every historical means of information security has thus taken the form of communication’s shadow, rendering the readable as unreadable, the visible as invisible, the clear as obscure, the open as inaccessible—but only to those who have not been granted entry. The true inventiveness of cryptographic mediation lies in the assurance that a message has not actually been destroyed once rendered unreadable, but is instead recoverable by those who either know the system or manage to crack it.
The work below develops a new model of cryptography and information security as the artful use of communication failure to divide an audience. The following section introduces background material to root this subject in communication studies and adjacent fields while placing the present state of cryptography and information security in context. Next, a description of the model delineates five varieties of communication failure and the ways each variety can be used for cryptography and information security, both in everyday practice and in technical applications. A discussion of implications follows with analysis and practical considerations that emerge from this theory and model.
2. Background: Bridges and Chasms
I view the selective reversibility of communication failure by analogy to a drawbridge, building on John Durham Peters’s (1999) memorable account of communication as both bridge and chasm, a duality of promise and impossibility. On the one hand, communication offers the means of bridging divides that separate us, channeling the basic desire underlying friendships, relationships, families, even cultures and societies. On the other hand, all communication is imperfect, minds never fully meet, and often communication simply fails even in everyday interactions. This line of reasoning offers a compelling challenge to the position of privilege we often grant to dialogue and discourse in communication studies. What common sense leads us to view as direct transmission or exchange is really secondary to the basic act of dissemination, the expansive propagation of a message to anyone who may hear it. From this perspective, even the most intimate acts of interpersonal communication share many qualities with mass communication, behaving as broadcasts unless the audience is actively limited to a privileged state of dialogue.
Indeed, the primacy of dissemination argued by Peters is evident in the basic reality of information security: anything communicated may also be received by eavesdroppers. Assurance of privileged transmission requires actively devised security measures, and this task is increasingly fraught today as electronic transmissions must traverse an expansive tangle of infrastructure controlled by parties interested in covertly joining the conversation (Schneier 1996, Lyon 2015, Zuboff 2019). While security models going back to Shannon (1949) have treated surveillance as the disruption of one-to-one dialogue between two parties, often named Alice and Bob following a later convention (Rivest, et al. 1978), these frameworks mistakenly treat dialogue as the default, primary form of communication. Attempts to exclude eavesdroppers—whether by lowering your voice or encrypting a datastream—really amount to interventions upon an initial state of broad dissemination, in which any broadcast must be effectively narrowed to create a state of discourse or dialogue, let alone secure transmission.
So, even when critiquing the lofty notion of communication as the meeting of two minds, approaching this subject by way of information security addresses another, equally troubling problem: acts of communication may both fail to reach their intended audience in the ideal sense of meeting minds, and at the same time leak into a space where unintended parties may receive these messages in a manner that feels intrusive. While this concern is raised even in Plato’s Phaedrus, where he laments that the invention of writing renders what is intended for a select audience as readable by the many, this incidental feature of the written word is magnified today through digital communication technologies that multiply the volume, paths of transit, and points of interchange for electronic information.
The everyday handling of personal information has been examined and modeled in communication studies through a large body of work on motivations and practices of selective revelation and concealment (Goffman 1963, Altman & Taylor 1973, Petronio 2002). More recent work in interpersonal communication has examined how various forms of power affect why people may choose to selectively reveal invisible, non-normative, and stigmatized information (Moore 2017, McDonald, et al. 2020). Beyond the willful disclosure of personal information, the rise of mass surveillance has introduced many technical systems that both extract personal data and persistently fail to see or understand people, whereas some information obfuscation methods promise effective means of resistance against alienating and objectifying uses of data (Brunton and Nissenbaum 2016, Gaboury 2018, Constanza-Chock 2020). This literature on concealment, disclosure, and exposure offers valuable context to consider why information security matters in everyday life, not just highly charged domains like hacking and espionage.
While cryptography activists of the 1990s first articulated the need for digital security tools in everyday life online (Levy 2001), there has been a considerable rise in the availability of user-friendly encryption tools over the last decade, notably in the wake of the Snowden disclosures of global mass surveillance and widespread public backlash that followed (Bell & Owen 2017). The growing use of encryption for digital privacy amounts to a large-scale conversion of electronic communications from plaintext data, clearly readable in transit over the internet, to a shrouded assemblage of ciphertext more easily monitored through alternative means of surveillance, such as metadata and network analysis. Today, encryption is a readymade component of many information and communication technologies, where even mundane exchanges over the web are often protected by the HTTPS protocol and an increasing range of chat apps encrypted by default. Yet despite cryptography’s growing status as a basic component of digital media, communication software, and web infrastructure, the technical complexity of cryptography makes it a formidable subject for critical analysis as anything but an infrastructural black box, albeit a crucial one in studies of privacy and surveillance (Lauer 2011, Tufekci 2014) internet policy and governance (Gillespie 2007, Owen 2015), online activism (Tufekci 2017), and hacking (Coleman 2013, Kubitschko 2015, Coleman 2019).
While communication and media scholars studying digital signatures, cryptocurrency, and the blockchain offer valuable accounts of the cultural techniques underlying digital encryption (Blanchette 2012, Brunton 2019, Dupont 2019), the broader history and means of cryptography before the computer is equally important for communication theory because the means of secret communication are just as ancient and varied as communication itself (Goody 1968, Ong 1982, Drucker 1995, Kahn 1996). Even leading security experts find it apt to describe encryption software like PGP and Signal as the digital equivalent of walking into an open field to have a conversation free from eavesdroppers (Schneier 1996, Diffie and Landau 1999), and these nostalgic comparisons rest on the recognition that digital security mirrors the affordances of past techniques for dividing the audience of a conversation, such as whispers, locks, and other techniques that already serve as commonplace analogies. A theory of cryptographic mediation that is grounded in the general category of communication failure promises one means of connecting these disparate cases.
The following model outlines a novel framework that connects current forms of computational cryptography to non-digital techniques, viewing information security in terms of many enduring complications in the fundamental nature of symbolic communication. For simplicity, the term ‘information security’ also encompasses privacy and secrecy concerns throughout this paper, passing as shorthand for any measure taken to ensure audience selection through cryptographic mediation. By treating communication as both a bridge and a chasm, cryptographic mediation works like a drawbridge making inventive use of knowledge we gather through a lifetime of encounters with different kinds of communication failure. This model situates distinct types of failure in an ordered series of passage points, illustrating how different sources of communication failure can be used for different forms of information security. Framing cryptographic mediation in terms of communication failure allows us to delineate formal features of cryptography based in a broad range of communication practice, offering everyday parallels to even the most complicated forms of information security.
3. The Drawbridge Model
The Drawbridge Model of cryptographic communication depicts a chain of islands linked by a series of drawbridges, each representing a specific source of success or failure in communication. Starting from the initial island, passage over each drawbridge takes you closer to the point where it may be ultimately possible to understand a given message. Likewise, failure at any stage renders further stages inaccessible because the effective implementation of information security at one stage will also guard further stages.
Each stage of the model yields its own arts of privation, in which different types of cryptographic mediation share in common the stage of communication failure they mobilize as a form of selective privation. This is ‘privation’ in the philosophical sense once used by Aquinas, Locke, Kant, and others to denote the general absence of a quality, capacity, or other phenomenon. Darkness is privation of light. Ignorance is privation of knowledge. And specifically for Locke, communication makes common the private thoughts that originate in the isolated confines of the mind itself. In this way, communication was once a much broader term that referred to the transmission of either thoughts or objects (Carey 1992, Peters 1999). Because the Drawbridge Model views communication and its failure in a broad historical sense rooted in cultural techniques, the scope and implications for studying different arts of privation is correspondingly broad. As the following sections illustrate, communication failure can take many different forms, while arts of privation can use these sources of failure in many inventive ways.
3.1 Recognition
The first drawbridge to pass is recognition, in which the most basic source of communication failure is to be unaware that a message is even present. This can take many forms. You might wave to get my attention, but I don’t notice. A shipwreck survivor might construct a signal to be visible from above, but no rescue planes pass by. Our planet might be receiving transmissions from another galaxy, but our antennas could be looking for the wrong kind of signal. In each of these cases, communication fails even if the message is perfectly viable otherwise. Communication that goes unrecognized thus stops outside the first drawbridge without encountering any further conditions of success or failure. The recognition stage of this model centers on qualities of awareness, attention, sensibility, and the basic capacity to realize that someone is attempting to convey a message. Forms of information security that operate on the recognition level induce such privations by design. Arts of private recognition thus operate a drawbridge by mediating the capacity, readiness, or inclination to receive a message in the first place.
Information security is often implemented at the recognition stage through practices known as steganography, or communication hidden in plain sight. One well-known form of steganography is invisible ink, which must be heated or exposed to another chemical to be rendered visible. Other forms of steganography may be endlessly idiosyncratic, as camouflage tends to reward the unexpected. Yet because steganography relies on security through obscurity, knowing the system is typically enough to break it. A message might be concealed beneath a postage stamp, placed within apparently innocuous documents such as invoices, or even signaled by the seemingly random blinking of a light. These are textbook cases of steganography because security rests on the difficulty of recognizing a message is even present. But if you happen to know that some lights in a window are meant to signal “one if by land, two if by sea,” then you have already broken the recognition-based security of this steganographic system.
A more recent technique for recognition-based information security is the digital watermark, a form of computational steganography used to identify and trace copyrighted, classified, and otherwise restricted files. A digital watermark is designed to be undetectable within the encoding of the file, thus passing unnoticed. For example, a PDF could contain a digital watermark to verify the file’s author, recipient, or its original contents. If someone alters the file, we can check the digital watermark to verify this information. Likewise, if someone leaks that file to the press, publishing the file might expose the leaker by revealing who downloaded the file. Most digital watermarks are fully hidden, unlike many physical watermarks that readily reveal themselves in the right angle of light. Due to their invisibility, we are unlikely to notice this additional information layer when we simply open the document for conventional reading, while even examining the file’s source code can pose a challenge for digital forensics. Even documents printed with a digital watermark may contain a concealed pattern of microdots that tie the document to the user. Overall, the multiplicity of possible ways to read and display this information leads to a corresponding multiplicity of techniques for encoding messages with information we cannot easily detect. As with traditional forms of steganography like invisible ink, the point is to design a system that makes use of the ways communication may fail by escaping recognition.
3.2 Access
The next drawbridge is access, in which a barrier or lack of authorization may keep someone from reaching a message even if they are aware of its presence. For instance, if I go to the post office to retrieve a letter from my box, I would not be able to access it without the key, just as failure to login to a computer account can prohibit access to information held within. Communication fails, if only temporarily, because I am blocked from accessing a message. As with the case of recognition above, no further stages of this model come into play if the access drawbridge is impassable. For this same reason, the basic functionality of a communication medium is also a matter of access. Cutting a data cable or sabotaging a radio antenna causes access failure because it renders the information fundamentally inaccessible even if the audience recognizes that transmission efforts are underway. Arts of private access thus operate a drawbridge by mediating the functionality, capability, permission, legality, and even morality of accessing a message.
Navigating this drawbridge involves passing through, or else circumventing, any barriers that would limit the audience of a message by stopping others from reaching it. In physical terms, the access stage includes any kind of lock-and-key mechanism, but also a wider array of systems intended to block access. In the case of a traditional lock, modes of circumvention include copying the key, picking the lock, or simply breaking the mechanism. A telephone wire tap is also a form of access mediation, as it facilitates a direct line for eavesdropping. The same goes for software written with backdoors and other forms of ‘tailored access’ designed to permit eavesdropping. Side-channel attacks are similarly insidious forms of digital intrusion at the access stage. By training an infrared camera on a computer or recording the subtle sounds its CPU generates while processing information, security researchers have shown that data and encryption keys can be lifted directly from a computer without circumventing its software-based security. You might think of these side-channel attacks as the digital equivalent of lip-reading through a pair of binoculars. Meanwhile, for everyday computer users, software-based security such as login screens, file permissions, and passwords are the principal means of access mediation. If you can’t login, you don’t get access. If your user account has not been granted “read” permission for a file, you can’t see its contents. Likewise, if a file is protected by a password, the system only grants access if the correct answer is given. The same goes for compound access protection schemes like two-factor authorization, in which an additional token must be given with the key or password. You may recognize the existence of a certain file, database, or other information, but without sophisticated means of circumventing these measures you will find yourself locked out of systems designed to grant access only to authorized users.
Beyond strictly technical systems, access may also be mediated by laws, norms, morals, and other structures of power governing permission and consent. Consider the case of the envelope, which is simple to open by design, but still provides some security because it signals a desire for privacy, discouraging unauthorized access on both legal and moral grounds. While the envelope figures prominently as a digital metaphor, especially in the case of secure email and chat messages, the analogy is flawed because envelopes are not especially effective for stopping intrusion efforts, but rather discouraging intrusion and leaving identifiable traces of tampering. Likewise, to signal that we are having a private conversation, we may simply close the door, speak quietly, or walk to a secluded area. The point is not to sequester our conversation from a dedicated eavesdropper, but rather to signal a desire for privacy that rests on our tacit trust in the general civility of others. Personal privacy laws serve the same purpose, working as a kind of behavioral drawbridge to discourage intrusions upon personal information. In the case of doctors, lawyers, and other professionals whose confidentiality is generally protected by law, access is mediated by legal restrictions, even if no further means of security are in place. The dark side of this phenomenon lies in access limitations that amount to unjust and discriminatory structures of power, often in tandem with technological systems of exclusion (Constanza-Chock 2020). While purely behavioral forms of access privation offer nothing close to airtight information security, these efforts nevertheless operate at the level of access by promoting behaviors that limit intrusions upon private information. Thus, these examples illustrate that soft arts of privation are just as relevant as technical solutions for cryptographic mediation of access.
The same is true of private property, in which laws and conventions operate a drawbridge by mediating access to objects and spaces claimed as the dominion of a specific person or group. Private property is barred from communication, in the now-antiquated sense of materials literally moved from place to place as all communications once were (Carey 1992, Peters 1999). Here, the social and legal institution of private property produces a kind of selective communication failure by barring the transfer of one person’s possessions into another one’s hands. Given this affinity between the disparate framings of communication as physical movement and conveyance of information, it is apt that cryptography is now used in a similar manner to protect private property in the otherwise fluid realm of digital information. Cryptocurrency and other non-fungible tokens (NFTs) promise a kind of algorithmic claim to solidity. This digital solidity is an atavistic design that mimics the unique materiality of rivalrous, privately owned objects through cryptographic assurance of their unique identity. Cryptocurrency leverages privacy in a double sense, both in the cryptographic privation of its unique identifier and the status of private property as its basic design principle. Blockchain encryption thus mediates ownership by manufacturing a privation of access, transforming a string of digits into something that cannot be endlessly proliferated as digital copies with the same claim to the original’s identity, value, or other seemingly intrinsic status.
3.3 Legibility
For the sake of this model, legibility means the ability to apprehend individual symbols. A message sent to me in characters I understand, which is rendered so that I can reliably identify those characters, is legible for our purposes. The text may be a meaningless jumble, but as long as I can recognize those characters, this satisfies the legibility criterion. The same goes for a string of digits. They could be random, they could be some sort of code, they could even be lottery numbers, but what matters at this stage of the model is for the symbols to be recognizable. If I have not learned these symbols, or they are scribbled in a messy hand, communication fails at this stage. Any form of information security that operates at the legibility stage creates a deliberate and selective privation with regard to the cognitive or technical processing of symbols on an individual basis. Arts of private legibility thus operate a drawbridge by mediating the clarity, familiarity, and apprehension of distinct symbols.
Several historical examples should help illustrate how the artful use of the legibility drawbridge has been used for information security in the past. Many legibility privations take the form of a secret alphabet or other glyphic system, in which an invented symbol stands in for one from the original system. For instance, a code known as the pigpen cipher is one of the least guarded secrets belonging to the society of Freemasons, as some members have even inscribed their gravestones with messages in this system of simple geometric lines and dots that represent the letters of the Latin alphabet (Kahn 1996). Likewise, the subculture of traveling American workers known as hobos developed a system of symbols to assist one another in basic survival as they traveled through unfamiliar locales (Wanderer 2001). One symbol inscribed on a wall would indicate a good camping spot, another would warn of a vicious dog or a source of potable water. Whatever the case, you must know the meaning of these symbols to pass the legibility drawbridge. Whether the message is intended for a select audience of hobos or freemasons, the point is for everyone else to see these abstract lines as illegible glyphs.
Another historical example of legibility-based information security is shorthand, in which obscure, often idiosyncratic and invented forms of handwriting may conceal the contents of a letter, note, or diary, typically with the added bonus of increased writing speed. The writer Samuel Pepys is known today for his personal diary recording the events of the English Restoration period, but his illegible shorthand script made this diary incomprehensible for centuries until it was deciphered. Likewise, the journalistic shorthand used by many news reporters can pose legibility troubles. Some reporters follow a standard shorthand convention designed for general use, while other reporters invent their own shorthand script. And while a particular reporter’s shorthand could be as undecipherable as the one used by Pepys, even the conventional shorthand will be mostly illegible to outside readers.
A familiar contemporary example of information security deployed at the legibility stage is CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart). CAPTCHA systems are widely used for web and mobile apps today to verify that a user is a human being and not a bot, hence serving the basic role of a Turing Test in delineating humans from computers with a task that is difficult to perform by automation alone (Turing 1950). Some CAPTCHAs present a string of mangled text, whether in visual or audible form, and ask the user to enter that text in a box. Others present a series of images and ask the user to identify which ones have stoplights, bicycles, and other objects of special interest for training computer vision algorithms. Whatever the form of the CAPTCHA, the level of security it provides will depend on the relative legibility of these symbols, images, and recordings to human beings versus automated systems designed to act like human beings.
For the sake of assessing the role of legibility in communication failure, it is worth noting that literacy is not binary, but often falls on a spectrum. Many of us can recognize just two letters in Morse Code, but only because “SOS” was once a popular trope of radio, television, and cinema (short-short-short, long-long-long, short-short-short). The point is that legibility of different symbols does not necessarily come in complete groups. Before the rise of mass literacy, this was the case even for many without a formal education, who could identify a bit of written language in the marketplace or church through repeated exposure to these symbols. The fact that literacy falls on a spectrum is even more pronounced at the next stage of the model, because even a full grasp of a given character set that is inscribed legibly may not be enough to ensure successful communication.
3.4 Readability
Closely related to legibility is readability, the comprehension of patterns, words, and syntax in a string of known symbols. Successful communication of written words in any language requires not only knowing the symbolic components, but also gleaning how they fit together. The legibility/readability distinction is drawn directly from the field of typography, where graphic designers differentiate between the legibility of individual characters in a typeface and the readability of words, sentences, and larger blocks of text (Bringhurst 2012, Brideau 2022). Arts of private readability thus operate a drawbridge by mediating the structure, pattern, sequence, and comprehension of symbols in a collected form. If the entire message is one symbol, this case bypasses the readability stage by default.
A traditional form of cryptography that operates at the readability stage is the acrostic puzzle, in which a sequence of letters in an otherwise innocuous text (for instance, the initial letters in a series of words, lines, paragraphs, or pages) spell out a hidden message. The novelist Vladimir Nabokov was particularly fond of acrostics, using this device to place secret messages in several stories as rewards for his most attentive readers. A formally similar device is the anagram, in which a message is concealed in the reconfiguration of its letters. Acrostics, anagrams, and other word puzzles call attention to the fact that a configuration of symbols can be multiply encoded, and different reading techniques can make other encodings intelligible.
Many of the traditional ciphers that preceded modern cryptography also operate at the readability phase. The classic example that opens many textbooks and historical accounts of cryptography is the Caesar Cipher, purportedly used by Julius Caesar during his Gallic campaign (Kahn 1996). The Caesar Cipher shifts each letter by a set number in alphabetic sequence. According to the chronicler Suetonius, a shift of three letters was always used in Caesar’s army, which would transform “JULIUS CAESAR” into “MXOLXV FDHVDU” using our modern alphabet. Advancements on this system may match each letter to another letter randomly, making it slightly more difficult to guess, but still easily deduced by counting the frequency of each enciphered letter (the most common letter in any English text, for instance, is likely to be an “E”). More complicated cryptographic cipher systems developed over the centuries have led codebreakers to develop increasingly sophisticated statistical analysis methods to locate patterns in encrypted text, but the fundamental premise still hinges on the readability principle: the letters themselves are known, but comprehension breaks down when the structure of letters is unreadable.
Even today, the most common forms of digital cryptography mediate exclusively through the reconfiguration of legible symbols in unreadable form. Modern digital encryption scrambles a given string of plaintext characters into new strings of ciphertext using algorithms too complicated to perform by hand, often reaching staggering levels of complexity. Like earlier cipher systems, the individual characters in an encrypted message remain legible (insofar as any digital encoding is legible), but the message itself is beyond readability until decoded. The process may be reversed if you have the corresponding decryption key or otherwise manage to attain it, whether through statistical analysis, brute-force guessing, or by stealing the key. Whatever the method, performing digital decryption drops the drawbridge of readability and renders a ciphertext message intelligible in its original plaintext form. This form of information security is so widespread today as to be conventionally treated as though it comprises the totality of cryptography, despite the wide range of communication techniques that may serve the same purpose through different means of privation.
Like legibility, readability also falls on a spectrum. Few speakers of any language could claim mastery over its entire lexicon. If a sentence contains an unfamiliar word, sometimes context is enough to carry on reading, but it may also mark the point of communication failure. Understanding these lexical limits in others can yield a humble, everyday form of private readability: the deliberate use of rare, technical, and otherwise obscure language to deliberately evade someone else’s comprehension. Parents may use elevated vocabulary to keep children out of the loop. A government functionary may use highly technical jargon in a display of bureaucratic obstruction. These are readability failures that can be useful even when the other party has partial grasp of the lexicon. Certainly these uses of exclusionary vocabulary are not suitable for high-stakes security, but as communication practices they are nevertheless consequential and revealing.
3.5 Meaning
Before even beginning to address the fraught topic of meaning, it is worth noting that the Drawbridge Model is largely ambivalent regarding different theories of knowledge. Given the many ways to define, delimit, frame, and critique the meaning of meaning, what functionally matters for this model is how efforts to convey meaning can fail. Whatever you consider the nature and limits of knowledge or meaning, what matters for our purpose is to identify different ways that meaning breaks down in communication. This section only addresses a limited number of concerns related to communication and meaning, but future work could productively address types and implications of failure for different theories of knowledge.
As an initial outline of distinct varieties of communication failure, it is useful for the moment to treat basic passage of the meaning drawbridge as everyday apprehension of the conventional, plainspoken content the speaker intends share with someone else. In this case, success amounts to shared intersubjective accord on the meaning of what is expressed. Failure to clearly communicate with your interlocutor leads to breakdown. Such pragmatic definitions evade the most pressing challenges posed by Peters, but call attention to everyday successes and failures. Supposing for the moment that the meaning of a message is the literal, overt, surface sense conveyed by its author, who intends for this message to be understood by anyone else who wishes to receive it, we must momentarily bracket the question of whether the speaker and listener ever truly share an identical interpretation of a given message. Instead, the mark of successful communication is mutual agreement that both parties understand one another. Arts of private meaning thus mediate who is capable of apprehending the sense, substance, significance, and implicature a speaker wishes to communicate. We also require a distinction hinging on whether this communication is accessible to a few, select people (weak private meaning) or nobody else at all (strong private meaning).
What does it look like when communication fails at the weak level of meaning? Even if each element of a sentence is legible and readable, the sentence itself may be meaningless in terms of basic semantics. Chomsky’s (1956) classic example of such a sentence is “colorless green ideas sleep furiously.” Likewise, many works of conceptual art, poetry, and experimental literature contain grammatical messages with coherent syntax that nevertheless resist direct comprehension. Indeed, linguistic barriers were a hallmark of modernist art and literature, which often focused on noise and breakdown as emblematic features of modernity. These cryptic works of art and literature are especially compelling in the context of the Drawbridge Model because they engage with the nature and effects of communication breakdown for aesthetic effect rather than information security. While a difficult poem invites the reader’s decipherment, a deliberate act of total communication failure expresses a politics of refusal.
In contrast, arts of private meaning may subvert the literal, surface sense of a message for the sake of dividing an audience. These everyday techniques involve the coordinated assignment of a new meaning to an existing message, such as a secret code known by one or more people. Examples include insinuation, slang, innuendo, and other covert meanings that filter those who ‘get it’ from those who do not. In everyday acts of resistance, James C. Scott (1990) describes the same tactics as a matter of infrapolitics, or political action in which subjects of dominant power operate most effectively by remaining unnoticed. Throughout history, the value of whispering, winking, and saying one thing while meaning another has been the bedrock of information security in everyday life, from gossip and seduction to palace intrigue and peasant resistance movements.
Marwick and boyd (2014) underline the everyday use of weak private meaning in their study of teenagers practicing social steganography, covertly communicating on social media platforms where their digital lives unfold under the intrusive gaze of peers, parents, and teachers. Recalling cases discussed at the stage of recognition, steganography techniques like invisible ink involve hiding messages in plain sight, relying on security through obscurity. While some methods of steganography were already discussed under the recognition stage of this model, the cases described by Marwick and boyd largely operate upon the drawbridge of private meaning, where teenagers rely on coded language to control who knows what they are really talking about online. By using a code only understood by friends and confidantes, these teens raise and lower the weak drawbridge of private meaning for different audiences, mediating conditions of privacy even in public speech.
Strong private meaning is a more difficult and troubling subject than its weaker counterpart, pointing to the inviolability of the mind and ultimate impossibility of fully understanding others through communication. Under the strong version of the private meaning drawbridge, we may keep our thoughts to ourselves if we wish, and perhaps never fully share them with others even if we want to. This conundrum is the subject of Wittgenstein’s (1953) private language argument, which explores counterintuitive implications of the idea that we personally ascribe meaning to the words we use. If that were true, Wittgenstein argues that language itself would be fundamentally meaningless to others, and equally meaningless for ourselves. Despite considerable differences between this later work of Wittgenstein and his earlier work in the Tractatus Logico-Philosophicus (2001 [1921]), one theme that endures between these two phases of Wittgenstein’s career is his concern with what cannot be communicated. This concern is illustrated in the iconic ending of the Tractatus, where an otherwise dense and highly systematic argument loosens into a poetic appeal to the ineffable: “what we cannot speak about, we must pass over in silence” (p. 89). The shift in Wittgenstein’s later work, especially evident in the private language argument, is to both broaden the scope of statements that evince this fatal privation of meaning and to examine how such statements nevertheless prove useful in common practice.
Recalling Peters, the strong case of private meaning is not so much a guarded redoubt of information security, but rather an impassable barrier for any communication at all. Peters describes communication as the endeavor to reach across gaps that separate us, but also a reminder that we may never fully close these gaps. Although this animating concern is agile enough to traverse each stage of this model, as it draws upon our general awareness of limits and failures of communication we encounter throughout our lives, Peters’s central concern resides here at the level of strong private meaning, where we confront a chasm that may never be within our power to cross. A message may move past every previous drawbridge without reaching the private meaning that constitutes what each of us directly knows and feels inside.
This formulation of strong private meaning suggests a form of communication failure that simply cannot be leveraged or broken by technological means. Even if a polygraph proved effective in detecting deception, this would only identify the state of the drawbridge, but not lower it. Someone can always conceal their beliefs or withhold information, whether through common discretion or deceit. This is why the meaning stage of this model deserves considerable respect as a common site for the everyday practice of information security. Each of us has private thoughts that simply cannot be pulled from our minds. If indeed this gulf cannot be bridged, it also cannot be used for information security, at least not in the reversible manner that arts of privation require. A drawbridge that cannot be lowered cannot be used to selectively control the audience of communication. Thus we cannot artfully reverse the sort of communication failure that troubles Peters when he laments, alongside Plato, Augustine, and others, the gaps that ultimately separate minds from one another.
4. Implications of the Drawbridge Model
The initial motivation for developing this model had been to delineate how different types of cryptography and information security work in terms of communication processes, but the resulting work has broader descriptive power and unexpected implications. The Drawbridge Model generalizes across various forms of symbolic communication, from gestures and facial expressions to speech, text, and digital code. It covers historical practices of information security, such as acrostic puzzles and invisible ink, but also applies to a wider range of cryptic communication practices such as poetry and innuendo. The model reveals connections between historical cases and modern computational ones. At the level of access, the model even offers a theoretical framework to describe private information and private property from a common basis in the means of selective communication failure. Hence, even though the primary purpose of this model is still to describe and categorize different forms of cryptography and information security in terms of communication processes, the model has broader efficacy as a means of illustrating how everyday confrontations with communication failure may lead to productive sources of invention, placing boundaries and limits on communication in its broadest sense. Faced with the many bridges of communication and the many chasms of its failure, this model locates means of building drawbridges with a wide range of social, cultural, and political uses.
The Drawbridge Model thus delineates a theory of communication that treats cryptographic mediation as a fundamental concern, suggesting that the experience of communication failure and resulting means of selective concealment reveal fundamental features of communication itself. By revisiting certain paradoxes of communication raised by Peters, this model develops a more expansive understanding of information security as a subject in the philosophy of communication. This model also highlights how the logocentrism of cryptography—a word that literally means secret writing—also diminishes attention to analogous forms of communication that operate without written symbols and yet mobilize the same general principles of communication failure through arts of privation.
In this way, the Drawbridge Model also suggests interdisciplinary opportunities to develop and evaluate various means of cryptographic mediation, offering the initial sketch of a schema for the design, engineering, and assessment of information security systems and practices in terms of the kinds of communication failure they rely upon. Some readers may have been struck by the fact that digital cryptography, despite its growing ubiquity, only operates at the readability stage of this model. Access is the other stage used for most of today’s everyday digital security systems, such as logins and passwords. Social steganography also works at the level of meaning in relatively low-stakes scenarios, while digital watermarks perform computational steganography primarily at the level of recognition. This should provoke some curiosity about why certain stages of this model are underrepresented in digital security schemes, while also priming our attention to whether technical advancement in fields like AI could lead to new ways of leveraging communication failure for novel security schemes. In this way, the Drawbridge Model may act as a framework to locate dimensions of cryptographic mediation that are currently unexplored in computational security applications. Indeed, scholars of communication are well positioned to examine how a range of cultural techniques for symbolic communication may point to unexplored domains in which the artful use of communication failure can inspire novel means of information security through interdisciplinary approaches to engineering and design.
Still, the scope of this work is also limited by the particular forms of communication it directly describes, which center on the transmission of messages and meanings as the basic criteria for success and failure. Standing beyond the apparent remit of this model, Habermas (1984) treats the failure to influence your audience as a form of communication failure. While I acknowledge the general importance of this framing of communication as a matter of rhetoric and persuasion, the failure to influence others would appear to be an outlier in terms of the information security and audience selection techniques outlined above. The case of persuasion might even require an inverted lens, where bolstering defense against misinformation is a sort of information security in which the ideal outcome is to raise the drawbridge rather than lower it. Is there a situation where one would wish to communicate a message that selectively influences some people and fails to influence others? Perhaps, in some highly contrived game of deception, one could conceal or misdirect others by deliberately failing to convince them. Yet even this headache of a hypothetical is already covered reasonably well by the discussion of deception in the meaning stage. Thus, a lack of attention to influence and persuasion is a fairly minor limitation in terms of this model’s core purpose of surfacing previously unrecognized structures and patterns in the nature and uses of communication failure.
The simple linearity of the Drawbridge Model raises more interesting challenges for describing forms of cryptographic mediation that appear to operate at two or more different levels. These multistage ambiguities are often compounded at the level of recognition because communication failures of legibility, readability, and meaning may also camouflage the very presence of a message. Multistage complications are especially common in the case of digital encodings, where the computer and its user are often reading in very different ways, simultaneously and in parallel through an interface. Consider the case of digital steganography given above. The presence of a digital signature is hidden at the recognition stage, using an encryption algorithm to hide data in the encoded form of a file and make this signature undetectable. On the other hand, detecting this signature would occur at the readability level because it involves analysis of the code itself. So, digital steganography appears to be working with two different kinds of communication failure: a readability failure actually seems to raise the recognition drawbridge, and this lack of readability may even hinder recognition if someone tries and fails to find a hidden signature when they suspect one is present.
Similarly, a decoding effort may deal with different stages of communication failure simultaneously. Consider a paleolinguist attempting to decipher an ancient alphabet. They are already confronted with a considerable level of access failure due to the scarcity of artifacts available to use as a corpus of samples. If new samples are discovered, there will be questions of attribution to legitimize the text for inclusion in their corpus. Moreover, these paleolinguists are likely to work on problems of legibility and readability in parallel, perhaps with some work at the level of meaning if they reach the point where an apparently comprehensible fragment emerges. Above all, the tricky task of the paleolinguist can be modeled as a matter of navigating different stages of communication failure in parallel.
Loops and recursion also suggest additional layers of complexity to enrich the explanatory value of the Drawbridge Model in future work. Returning to the case of acrostic puzzles discussed above, imagine reading a text without realizing that a message is concealed in the initial letter of each word. You could still reach the meaning stage in the surface text, and perhaps even glean deeper contextual details placed by the author. But if you happen to notice the presence of the acrostic, one way to model this process is by looping back to the recognition stage and proceeding through each drawbridge once more to decipher the newly recognized message. Further work is needed to fully model tricky cases like this one, which may be better understood through more complex non-linear models, perhaps with forking paths for different messages encoded within a single source.
5. Conclusion: The Uses of Communication Failure
Whereas cryptography is typically defined as the art or science of secret communication, this definition neither describes the communication process nor captures the wide range of ways that cryptographic media operate in terms of the people and messages involved. A more useful definition of cryptographic mediation is this: any form of symbolic communication using known sources of communication failure to create a reversible encoding that selectively limits the audience of a message. By centering failure as a productive aspect of the communication process, a more detailed, functional, and revealing theory of cryptographic communication treats secrecy, privacy, and security as matters of selecting an audience through the arts of privation depicted in the five stages of this model. The resulting framework renders cryptography newly amenable to communication theory and even suggests unexplored technical possibilities for the engineering, design, and evaluation of secure communication systems.
Full references and figures are in the linked PDF.