Sunday, September 13, 2026

Places of Memory · Konzentrationslager Auschwitz I · The Watchtower

Watchtower · Auschwitz I
© 2026 Bryan R. Hinton

She arrived under a tower like this one, three kilometres away at Birkenau. She left as Reg. A 105, folio 9.

Auschwitz I was surrounded by a double barbed-wire fence on concrete posts 3.3 metres high, curved inward at the top, with guard towers at regular intervals, the kleine Postenkette, the small guard chain, manned whenever the prisoners were inside the camp. The towers stood on the outer side of the fence. The wires carried three-phase current at 400 volts. Along the fence, on the camp side, ran a gravelled strip three metres wide. The "neutral zone". Camp regulations, corroborated by survivor testimony, held that guards in the towers could shoot any prisoner who entered that strip without warning. The towers' function was custody: to ensure that the people inside could not leave until the state had decided how they would.

The Franks had been at Westerbork since 8 August. They were Jews arrested in hiding, so they were strafgevallen, punishment cases. They were held in the punishment barracks, Barrack 67, a closed-off section of the camp behind its own barbed wire, guarded by the camp's own Ordedienst. Edith, Margot and Anne were put to work in the batteries, splitting them open to separate the tar, the carbon rods and the casings. Scrapping batteries was dirty and unhealthy work. Tar and acid smell. The smell stayed on the hands. Margot Rosenthal, nineteen, arrested for underground work and held in the same barrack, was asked to look after Anne. They brought Anne to her, she later stated, because both kept diaries. Anne told her she had written before. Whether she went on writing in the camp, Rosenthal could not say. Punishment cases were generally placed on the next transport.

On 3 September 1944, the last transport from the Westerbork transit camp to Auschwitz departed the Netherlands. It arrived at the new ramp inside Auschwitz II-Birkenau on the night of 5–6 September. Two and a half days in locked cattle wagons. Of the 1,019 Jews on the manifest, four were Franks. They appeared in sequence: Margot at 306, Otto at 307, Edith at 308, Annelies Marie at 309. A family, in order, on a typed page. By the Anne Frank House's reconstruction from the transport list and the camp number series, 648 people from the transport were registered into the camp administration after selection. 371 were sent directly to the gas chambers, 231 women and 140 men. The women remained at Auschwitz II-Birkenau. The men who had passed selection went on foot to Auschwitz I, about three kilometres away, after being registered, so the Anne Frank House states. On 30 October, Margot and Anne were selected for transfer to Bergen-Belsen. The transport departed the night of 1 November and arrived on 3 November. The dates are reconstructed from survivors' letters and interviews. No transport list naming the sisters survives. Edith was left behind at Auschwitz II-Birkenau. According to the account of Rosa de Winter-Levy, she died there in the infirmary on 6 January 1945. Neither the place nor the date is confirmed by any camp record. Her daughters had been gone from her two months.

That transport left its own paper trail. The Jewish Council's Centrale Kartotheek typed a card carrying the transport date, 3.9.44, Blatt 7, the sheet that runs from 301 to 350 and carries all four Franks. After the war the Ministry of Justice copied the same data onto a working card, a further number, 232, struck in beside her surname. It is not her place on the manifest, which is 309. The ink additions on the first card are postwar too, and one of them is not administrative: † te Bergen Belsen vlg. Vader, died at Bergen-Belsen, according to the father. It is probably the earliest trace of it in her file.

Centrale Kartotheek · Joodse Raad · Frank, Anneliese · 3-9-44, Blatt 7
Nationaal Archief, Den Haag · 2.09.34.02, inv.nr. 539B · public domain
Werkkaartje Justitie · Frank, Anneliese · transport 3-9-44, Blatt 7
Nationaal Archief, Den Haag · 2.09.34.02, inv.nr. 539B · public domain

The Westerbork camp kept its own register. Her entry is on page 40. The pink card below is an extract citing it, preserved in her death file. The Committee's own oldest documents in that file date from April 1951, so the card was most likely made in the course of postwar processing rather than at the camp. Transport: 3-9-44. Naam: FRANK. Voornamen: Annelies, M. Geboren: 12-6-29. Adres: Merwedeplein 37, Asd.

Westerborkregister · Frank, Annelies M. · transport 3-9-44
Nationaal Archief, Den Haag · 2.09.34.02, inv.nr. 539B · public domain

Bergen-Belsen kept a prisoner registration system. Margot and Anne would therefore have been registered on arrival and given new numbers, as was standard practice. Shortly before British forces liberated the camp on 15 April 1945, however, the SS burned the prisoner registration records. As a result, the numbers Anne and Margot received at Bergen-Belsen are unknown, as are their Auschwitz numbers. Apart from the transport's small Schutzhäftlinge contingent, the women registered from that transport were tattooed in an A-series assigned roughly alphabetically by surname. The Dutch Red Cross's 1953 reconstruction gives the series as A-25069 to A-25260, with a second, shorter run from A-25262 to A-25290. Alphabetically, the three Frank women's numbers would have been close together, under F. No surviving record ties any of the three to a number within that series. Three women, one letter, somewhere in a run of numbers nobody matched to them. Their father's number is the only one of the four that survives: B 9174, within the men's series B 9109 to B 9364. It is preserved, among other places, on a Raucherkarte in his estate. A smokers' card. It records that prisoner B.9174, Block 5a, held coupons to spend in the prisoners' canteen at Auschwitz I. In November 1944 he collapsed. Samuel Meijer Kropveld, an Amsterdam surgeon from the same transport who had found a place in the sick barracks, arranged his admission there in consultation with the Prague physician Bruno Fischer, as Kropveld stated in 1948. He was still there when the Red Army arrived on 27 January 1945. The paper survived with him.

After the Westerbork transport list of 3 September 1944, no surviving wartime document names Anne or Margot at all. They died at Bergen-Belsen of typhus, probably in February 1945. The dating rests on witness statements; on the 7 February 1945 transport list to Raguhn, which fixes the departure of witnesses who had seen them ill; on a Red Cross letter of 23 January 1945 naming Hanneli Goslar's grandmother among 51 intended parcel recipients (whether the parcels arrived is not confirmed), which anchors Goslar's last meetings with Anne at the camp fence; and on the ordinary course of the disease. Goslar's account has several constant elements: contact through Auguste van Pels, February, Margot too ill to get out of bed, Anne thin with a shaved head, two packages thrown over the fence. Willy Lindwer's 1988 interviews add other details: the blanket, Anne more worried about Margot than about herself. One sister at a wire fence in February, wrapped in a blanket, her head shaved against the lice, too thin to keep her clothes on, taking what came over the wire.

Margot Rosenthal reached Bergen-Belsen from Birkenau in January 1945, on a later transport out of the scarlet-fever ward. In October 1945 Nanette Blitz wrote to Otto Frank that Rosenthal had spoken with Edith in Birkenau after the selection, and told the sisters their mother was alive. The news, Blitz wrote, cheered them. Edith had died on 6 January. None of them knew. Rosenthal's own statement, given years later and undated, carries a scene of Margot's last day found in no other testimony: Anne called to her that Margot was failing. The barrack was to be turned out for the Appell. She asked an SS man to let Margot lie, and he agreed. That same day, she said, Margot died. She still saw Anne daily in the days that followed, in a raised barrack reached by steps. The received account runs otherwise. Otto Frank learned his daughters' deaths from the Brilleslijper sisters, who had been with them in the camp. In the account descended from their telling, the sisters lay side by side in the sick barracks, Margot died first, Anne a few days after. The two versions agree on the order of the deaths and roughly on the interval, and on nothing else. Neither carries a date. The Anne Frank House's reconstruction uses neither scene. Its documented trail ends before 7 February.

For six years, the paperwork caught up slowly. The oldest of the Committee's own documents in the death file are forms dated 6 April 1951, in which the Commissie tot het doen van aangifte van overlijden van vermisten, the Committee for the Reporting of the Decease of Missing Persons (created under the law of 2 June 1949), wrote to the Dutch Red Cross and to the Amsterdam civil registrar to ask what was known. The Red Cross filed the Committee's request against its own record: "dossier N.R.K. 117266. Cf. concl. RK † 31 Maart 1945 te Bergen Belsen / Dld." Conclusion: died no later than 31 March 1945 at Bergen-Belsen. The Red Cross's dossier numbers keep the family adjacent, as the transport list had: Edith at 117265, Anne at 117266, Margot at 117267. Otto, who survived, is filed apart at 118834. The Amsterdam civil registrar confirmed that no death certificate had been issued. Six years after Anne Frank's death, the municipal record said only that she had vanished and had never been declared dead.

On 7 May 1954, Johannes Kleiman, Otto Frank's colleague and one of the helpers who had hidden the Franks, wrote to the Committee as Otto's authorized representative, asking that the declarations for Margot and Anne be processed. Otto needed them to have a certificate of inheritance drawn up. The Committee acknowledged receipt on 4 June. The declaration itself was issued on 29 July 1954, in The Hague. It is the document reproduced below.

Aangifte van overlijden · No. 107658 · 's-Gravenhage, 29 Juli 1954
Commissie tot het doen van aangifte van overlijden van vermisten · Nationaal Archief 2.09.34.02, inv.nr. 539B

The declaration is a typed form on light paper, numbered No. 107,658. Stamped at the top: AFSCHRIFT, copy. The printed Dutch is dense with legal procedure: Krachtens art. 2 van de Wet van 2 Juni 1949 (Stbl. No. J 227) doe ik U hierbij aangifte van het overlijden van de hieronder vermelde vermiste. By virtue of article 2 of the Law of 2 June 1949, I hereby declare to you the death of the missing person named below. The filled-in carbon strikes are faint: Op een en dertig Maart negentienhonderd vijf en veertig is in Bergen-Belsen in Duitsland overleden: Frank, Annelies Marie. The date is written in longhand Dutch, een en dertig Maart, the certainty the facts didn't support, spelled out word by word.

The form was sent to the Amsterdam civil registrar. Three months later, on 29 October 1954, the registrar entered the death in the municipal register in faint purple hand at the lower right: Reg. A/105. Fol. 9v. Initialled and filed.

Registratiekaart overlijden · Frank, Annelies Marie · Reg. A 105, Fol. 9 · d.d. 29-10-1954
Commissie tot het doen van aangifte van overlijden van vermisten · Nationaal Archief 2.09.34.01, inv.nr. 95B

The registratiekaart is the Commissie's own card for the case, filed under its archive in The Hague rather than Amsterdam's. Printed fields in Dutch: Naam, Voornamen, Geboren op, Overleden op, Overlijdensakte opgemaakt, Bijzonderheden. The handwriting fills them in. Born 12 June 1929. Died 31 March 1945. Overlijdensakte drawn up at Amsterdam on 29-10-54. Bijzonderheden (particulars): blank.

The working card that produced the date survives in the Dutch Red Cross Information Bureau's persoonsdossier on Anne Frank. It is pencil and ink, dated 22 January 1952 in the same pencil hand, and records the statement of Lien (Lientje) Rebling-Brilleslijper, who had been imprisoned with Anne and Margot at Bergen-Belsen. In the clerk's hand at the bottom, ruled off from the rest, is the conclusion: Overleden te Bergen-Belsen niet eerder dan op 1.3.45 en uiterlijk 31.3.45. No earlier than 1 March, no later than 31 March.

Cartotheekkaartje · Frank, Annelies Marie · d.d. 22-1-1952
Nederlandse Rode Kruis, Informatiebureau · Nationaal Archief 2.19.288, inv.nr. 101677 · vervroegd openbaar gemaakt oktober 2023

The date 31 March 1945 is a bureaucratic default. It was the Committee's standard practice to date unknown deaths at the last day of the assumed month when a witness statement could establish the month. The witness statement was Brilleslijper's, given to the Dutch Red Cross. The Anne Frank House's Knowledge Base dates it, by the card, to 1952. The House's 2015 source review had given 22 January 1951. She said Anne and Margot died "around March 1945." She had put it differently elsewhere: to Otto Frank in November 1945 (the end of February or the beginning of March), and in a memoir written at his request in April 1951, where the end comes in February. The Committee picked March 31, and the date was published in the Government Gazette. The Anne Frank House Knowledge Base now brackets the sisters' deaths between 7 and 28 February 1945. The Amsterdam register still reads 31 March. No one then knew, and no one now knows, the day Anne Frank actually died.

Her name also appears on a typed list. Lijst No. 1908. Every entry on the page is a Frank. She is fifth down: Annelies Marie, Frankfurt am Main, 12-6-1929, Bergen-Belsen, 31-3-1945. Six rows below her: Aron Moses Edward, Rotterdam, 7-8-1910, Polen, 31-3-1944. Place of death: Poland. The last day of March. Almost certainly the same administrative default, one year earlier. Near the top: Andries, Tiel, 4-3-1914, Omgeving van Auschwitz, 30-4-1943 (surroundings of Auschwitz, the last day of April). The list is one of many. This sheet was typed on 29 April 1959. It covers the letter A through the start of B.

Concentratiekamp · Lijst No. 1908 · Frank (A–Ba), page 14
Arolsen Archives, Bad Arolsen · 1.1.46.1 · DocID 121247320 · d.d. 29-4-1959

Sources

Transport list: numbers 306, 307, 308, 309 (Margot, Otto, Edith, Anne Frank). Nederlandse Rode Kruis, Den Haag (war archive now held by the Nationaal Archief): Transportlijst Westerbork–Auschwitz, 3 september 1944 (inv. nr. 1066, Blatt 7). Otto Frank is listed at number 307 as "Frank Otto 12.5.89 Kaufmann." Cited via the scholarly apparatus of the Anne Frank House Knowledge Base: Deportation to Auschwitz-Birkenau. This was the last transport from Westerbork to Auschwitz, not the last from the camp: transport XXIV/7 to Theresienstadt left the next day, 4 September 1944, with over 2,000 people (counts in the sources run from 2,074 to 2,087; it was the largest transport from the Netherlands to Theresienstadt), and the final train, 279 people to Bergen-Belsen, departed on 13 September 1944.

Transport of 3 September 1944: recent scholarly treatment. Digitaal Joods Monument, More about the transport of 3 September 1944 Westerbork – Auschwitz, from Auschwitz part V: Deportation transports in 1944, addition of 23 March 2025; and Anne Frank House, The final transport from Westerbork to Auschwitz (3 September 2019).

Auschwitz prisoner numbers of the 3 September transport. The Dutch Red Cross's Publication Auschwitz part V (December 1953; paragraphs 8–9, pp. 33–37, reproduced at the Digitaal Joods Monument page above) reconstructs the number series: men of the ordinary transport and the Häftlinge in B 9109 to B 9364; the corresponding women in A-25069 to A-25260, with a second, shorter run from A-25262 to A-25290; the Schutzhäftlinge in separate series (men 195286–195429; women only partially reconstructed, 88397–88427). The numbers ran alphabetically by surname, though not strictly. Otto Frank's number, B 9174, is the only exact number known among the eight from the Secret Annex; a Raucherkarte found in his estate records that B.9174, Block 5a, held coupons for the prisoners' canteen. Anne Frank House Knowledge Base: Registration in Auschwitz-Birkenau: the men; Otto Frank in Auschwitz I. The bracket A-25060 to A-25271 long repeated in secondary literature spans 212 numbers, matching Czech's count of registered women, and derives from the Kalendarium's tattoo-number records, on which the Anne Frank House also bases its own calculation; the 1953 Red Cross reconstruction differs from it at both ends of the series. Of those registered from the transport, 127 survived the war: 45 men and 82 women.

Auschwitz-Birkenau: selection at the ramp, separation of men and women; arrival confirmed on the night of Tuesday 5 to Wednesday 6 September 1944. By the Anne Frank House's reconstruction from the transport list and camp number series, 648 of the 1,019 persons (399 men, 249 women) entered the camp administration and 371 were killed on arrival: 231 women and 140 men. Danuta Czech's Kalendarium der Ereignisse im Konzentrationslager Auschwitz-Birkenau gives the older standard figures for this transport: 470 registered (258 men, 212 women) and 549 killed. Anne Frank House Knowledge Base: Selections upon arrival at Auschwitz-Birkenau; Auschwitz I: the men in the Stammlager.

The new internal Birkenau ramp (Neue Rampe), operational from May 1944. Muzeum Auschwitz-Birkenau (Oświęcim): The unloading ramps and selections.

Auschwitz I: double barbed-wire fence, watchtowers, high-voltage electrification, and the "neutral zone" where prisoners could be shot. WacÅ‚aw DÅ‚ugoborski, Franciszek Piper (eds.), Auschwitz 1940–1945. Central issues in the history of the camp, OÅ›wiÄ™cim: Auschwitz-Birkenau State Museum, 2000, vol. I, and survivor testimonies. The double fence stood on 3.3 m-high concrete posts, curved inward at the top, carrying three-phase current at 400 volts, with a gravelled neutral zone three metres wide on the camp side, within the small guard chain (kleine Postenkette) security system: Muzeum Auschwitz-Birkenau, The small guard chain (Kleine Postenkette). Photographs of the preserved fence system: Muzeum Auschwitz-Birkenau: Watchtowers and fence system (Former Auschwitz I site).

Otto Frank's transfer to Auschwitz I. The Anne Frank House states that all the men from the 3 September transport who survived selection went on foot to Auschwitz I, about three kilometres away, after the registration procedure, ending up in quarantine block 8. Anne Frank House Knowledge Base: Auschwitz I: the men in the Stammlager.

Otto Frank in the Auschwitz I sick barracks. Otto Frank collapsed in November 1944 and was admitted to the prisoners' sick barracks; Samuel Meijer Kropveld, an Amsterdam surgeon deported on the same 3 September transport who had obtained a position there, stated in 1948 that he arranged the admission in consultation with the Prague physician Bruno Fischer. Verklaring S.M. Kropveld, 4 maart 1948, NIOD, Kampen en gevangenissen (toegang 250d), inv. nr. 646, as cited in Anne Frank House Knowledge Base: Samuel Meijer Kropveld. The single statement is the source for the intervention; sources differ on Fischer's specialty.

Transfer of Margot and Anne to Bergen-Belsen (selected 30 October 1944; transport departed 1 November; arrived 3 November). Dates reconstructed from survivor correspondence and interviews (letters of Margot Rosenthal and Nanette Blitz to Otto Frank; Willy Lindwer, De laatste zeven maanden, 1988; synthesis in Bas von Benda-Beckmann, Na het Achterhuis, 2020); no transport list naming Anne or Margot survives. Anne Frank House Knowledge Base: Journey to Bergen-Belsen; Arrival at Bergen-Belsen.

Margot Rosenthal (later Drach-Rosenthal) at Westerbork and Bergen-Belsen. Her statement: Ghetto Fighters' House Museum archive, collection Holland 195, file 90 (cat. nr. 195, inv. nr. 11723rm), an undated questionnaire of the Committee for the Collection of Documentation on the Pioneer Underground in Holland. The diary conversation in Barrack 67, her January 1945 transfer out of the Birkenau scarlet-fever ward, the account of Margot Frank's last day, and her seeing Anne in the days after are from this statement: a late, single-witness account with a visible dating slip (it gives her liberation at Bergen-Belsen as 11 April 1945; the camp fell on the 15th). That she told the sisters their mother was alive: Nanette Blitz to Otto Frank, 31 October 1945 (Anne Frank House Getuigenarchief; original at the Anne Frank Fonds, Basel), as cited in Anne Frank House Knowledge Base: Margot Margalit Rosenthal - Drach. That none of them knew: the same Knowledge Base page states Rosenthal was unaware of Edith's death; the sisters' belief is evidenced by their reaction in Blitz's letter, and no account records the news ever being corrected. Her scene of Margot's last day diverges from the account descended from the Brilleslijper sisters, from whom Otto Frank learned of the deaths: side by side in the sick barracks, Margot first, Anne a few days after (Anne Frank Fonds, statement of 5 March 2020). The Knowledge Base page Death of Anne and Margot Frank records that Lientje Brilleslijper's own statements contradict one another on the date, ranging from late February to shortly before the liberation, and builds its dating on neither scene: the documented reconstruction ends with the observations of witnesses who left on the 7 February 1945 Raguhn transport.

Registration at Bergen-Belsen. Bergen-Belsen maintained a prisoner registration system; arriving prisoners were routinely registered and assigned numbers. The SS burned these records before liberation, so the specific registration of Anne and Margot is an inference from standard camp procedure, not a documented fact. Gedenkstätte Bergen-Belsen (Lower Saxony): Register of Names; The Dead of the Bergen-Belsen Concentration Camp.

Death of Anne and Margot Frank at Bergen-Belsen. No camp record documents their deaths. The place and approximate date rest on eyewitness accounts (Brilleslijper, Blitz, Van Amerongen, and others) and subsequent historical analysis. The 31 March 1945 administrative default and the February 1945 revision are discussed in Anne Frank House: Sources for the date of death of Anne and Margot Frank in Bergen-Belsen (2015): eyewitness statements, the Bergen-Belsen–Raguhn transport list of 7 February 1945 (ITS, Bad Arolsen), the letter of the Commission Mixte de Secours de la Croix-Rouge Internationale to the German Red Cross, 23 January 1945, naming 51 intended parcel recipients, Goslar's grandmother Therese Klee among them (ITS/Arolsen Archives, doc. 3396827#1, collection 1.1.3.1, as cited in the Anne Frank House Knowledge Base; whether the parcels arrived is not confirmed; the letter anchors Goslar's meetings with Anne at the camp fence), and the clinical course of typhus. The blanket is from Willy Lindwer, De laatste zeven maanden (1988). Anne Frank House Knowledge Base: Death of Anne and Margot Frank. Official date based on Brilleslijper's statement to the Nederlandse Rode Kruis (file 117266, cartotheekkaartje of the NRK Informatiebureau, dated 22-1-1952 in pencil; the Anne Frank House's 2015 source review dates the statement 22 January 1951, its Knowledge Base now, by the card, to 1952); the same 2015 document records her earlier statements of 11 November 1945 and 5 April 1951, and notes that Otto Frank needed the declarations for a certificate of inheritance. Official date set by the Commissie tot het doen van aangifte van overlijden van vermisten, Dutch Ministry of Justice, and published in the Government Gazette. Underlying archival research: Raymund Schütz, Vermoedelijk op transport (Master's thesis, Archival Science, Universiteit Leiden Instituut Geschiedenis, 2010).

Anne Frank House 2015 research and current position. News item Anne Frank's last months (31 March 2015), announcing the revision to February 1945, and the Knowledge Base event page dating the deaths 7–28 February 1945: Death of Anne and Margot Frank.

Edith Frank-Holländer: death at Auschwitz II-Birkenau, 6 January 1945. The components of this statement rest on different evidence. That she died rests on the silence of the tracing record: no repatriation list, registration, sighting, or claim of survival has surfaced in eighty years of search by her husband, the Red Cross, and the International Tracing Service. That she died in Birkenau that winter rests on two 1945 witnesses: Rosa de Winter-Levy, who was in the infirmary hut (Aan de gaskamer ontsnapt!, Doetinchem: Misset, August 1945, pp. 27–29, which describes the dying but gives no date), and Betje Jakobs, who deposed to the Dutch Red Cross on 2 August 1945 that she had witnessed the death (NRK, toegang 2050, inv. nr. 1267). The infirmary setting and the manner, exhaustion, rest on de Winter's account alone. The day rests on a single line: Otto Frank's notebook entry of 22 March 1945, recording what de Winter told him in Katowice, that Edith had died on 6 January 1945 in the hospital, of weakness, and had not suffered; one witness's recall, eleven weeks after the fact, and the closing phrase shaped for the widower hearing it. The 1953 death certificate and Staatscourant publication adopted the date from this chain. No camp record could confirm it: the surviving Auschwitz death registers end in December 1943. Anne Frank House Knowledge Base: Death of Edith Frank; Rosa de Winter - Levy.

Westerbork transit camp: site memorial and documentation. Herinneringscentrum Kamp Westerbork (Hooghalen): kampwesterbork.nl.

Westerbork records as archived in the International Tracing Service. Arolsen Archives (Bad Arolsen, UNESCO Memory of the World): Westerbork Assembly and Transit Camp records (DE ITS 1.1.46).

Westerbork: punishment barrack and battery work. As Jews arrested in hiding, the eight from the Secret Annex were strafgevallen (punishment cases) and were held from 8 August 1944 in Punishment Barrack 67, a closed-off section of the camp guarded by the Ordedienst; Edith, Margot and Anne worked dismantling batteries; punishment cases were generally placed on the next transport. Anne Frank House Knowledge Base: In the Westerbork punishment barracks; Punishment Barrack 67, Westerbork Camp; Daily life in camp Westerbork. The Punishment Barrack 67 page's apparatus lists the family's Joodsche Raad card dossier numbers at the Nederlandse Rode Kruis: Otto 118834, Edith 117265, Anne 117266, Margot 117267.

Anne Frank's Jewish Council index card (Amsterdam). Arolsen Archives: Index card from the Jewish Council card file in Amsterdam, Annelies Maria Frank.

Westerborkregister: extract card for Annelies Marie Frank, transport of 3 September 1944. Pink preprinted card citing the Westerbork register (Blz. 40) and recording surname (Frank), given names (Annelies, M.), date of birth (12-6-29), home address (Merwedeplein 37, Amsterdam), and transport date (3-9-44). Preserved in Anne Frank's overlijdensdossier at the Committee; the card's own production date is not established. The oldest of the Committee's own documents in the dossier are its forms of 6 April 1951; the Joodse Raad card reproduced above, typed with the 3 September 1944 transport, predates them, so the card was most likely made in the course of postwar processing rather than at the camp. Nationaal Archief, Den Haag: Ministerie van Justitie / Commissie tot het doen van aangifte van overlijden van vermisten, toegangsnummer 2.09.34.02, inv.nr. 539B. Publicly accessible; no copyright restrictions ("Volledig openbaar. Er zijn geen beperkingen krachtens het auteursrecht").

Aangifte van overlijden van vermiste (declaration of death of a missing person): Annelies Marie Frank, No. 107,658. Issued in 's-Gravenhage (The Hague) on 29 July 1954 by the Commissie tot het doen van aangifte van overlijden van vermisten (Ministry of Justice), a body established under the Wet van 2 Juni 1949 (Stbl. No. J 227) to produce paper closure for Dutch residents missing from the war. Entered by the Amsterdam civil registrar on 29 October 1954 in the Register van Overlijden, Register A 105, Folio 9v, so the afschrift's annotation; the Commissie's registratiekaart gives Fol. 9. Nationaal Archief, Den Haag: toegangsnummer 2.09.34.02, inv.nr. 539B. Publicly accessible; no copyright restrictions. The same document is catalogued at Yad Vashem, Record Group O.41, item 5222601. The full chronology of the Committee's handling of Anne Frank's case (6 April 1951 inquiries to the Dutch Red Cross and Amsterdam civil registrar; Kleiman's 7 May 1954 letter on behalf of Otto Frank; the Committee's 4 June 1954 acknowledgment; the 29 July 1954 declaration; the 29 October 1954 Amsterdam registration) is set out in the Nationaal Archief's public exhibition page, Het overlijden van Anne Frank wordt vastgesteld.

Cartotheekkaartje: NRK Information Bureau conclusion card, dated 22 January 1952. Handwritten index card summarising Brilleslijper's statement and establishing the administrative bracket for the date of death: Overleden te Bergen-Belsen niet eerder dan op 1.3.45 en uiterlijk 31.3.45. References NRK Information Bureau Report 6/XIV No. 102, Opsporing Joodse Personen (Search for Jewish Persons). Preserved in Anne Frank's persoonsdossier at the Dutch Red Cross Information Bureau. Nationaal Archief, Den Haag: Het Nederlandse Rode Kruis, Informatiebureau: Persoonsdossiers, toegangsnummer 2.19.288, inv.nr. 101677 (persoonsdossier Anne Frank, vervroegd openbaar gemaakt / released ahead of schedule, October 2023).

Registratiekaart overlijden Anne Frank. Index card of the Commissie tot het doen van Aangifte van Overlijden van Vermisten, recording the overlijdensakte drawn up at Amsterdam, Register A 105, Folio 9, d.d. 29-10-1954, with the Bijzonderheden field blank. Nationaal Archief, Den Haag, 2.09.34.01, inv.nr. 95B (handle 10648/f154f363); a second copy of the same card is held at 2.09.34.02, inv.nr. 647B. Public domain. It is not a Stadsarchief Amsterdam archiefkaart: that is a separate, typed card in toegang 30238, which records the same death but was made by the municipality.

Typed concentration-camp victim list reproduced above. Header: CONCENTRATIEKAMP, Lijst No. 1908. Column headers: Naam / Voornaam / Plaats en datum van geboorte / Plaats en datum van overlijden. Page 14 of a larger series; typed footer dated 29 April 1959, with bilingual Dutch-French labels par typ and par contr. The format is consistent with Nederlandse Rode Kruis compilations from the postwar Afwikkelingsbureau Concentratiekampen. The scan reproduced is held by the Arolsen Archives, Bad Arolsen, collection 1.1.46.1 (Documentation about the fate of the Jewish people during the Nazi regime: list of names of Jewish victims of the Nazi regime in the Netherlands, 1941–1945, A–Z), DocID 121247320.

Where the ABC/NRK victim lists live today. The Afwikkelingsbureau Concentratiekampen (ABC) was founded on 26 November 1944, immediately after the liberation of the south, at a meeting in Huize Bergen, initially as the Afwikkelingsbureau Kamp Vught, renamed when its work widened to all camps after May 1945. It built the card systems behind the postwar victim lists; dissolved in December 1946, its task and archive passed to the Information Bureau of the Dutch Red Cross, which extended the ABC cartotheek after 1947 (to some 80,000 cards) and continued the typed victim compilations. This is the archival family to which the format of Lijst No. 1908, typed in 1959, belongs. The cartotheek is held at Nationaal Archief toegangsnummer 2.19.313 (donated by the Red Cross in 2018), the ABC forms at 2.19.305, the related Kampen en Gevangenissen dossiers at 2.19.321, and a further part of the ABC archive at NIOD (toegang 250m), largely opened to the public on 1 January 2025 (inv. nrs. 176–198 remain restricted).

The alphabetized ledger of Dutch camp victims. Lists of this format were among the International Tracing Service holdings that came into public view with the 2006 decision to open the Bad Arolsen archives; contemporaneous reporting describes Anne Frank's entry among dozens of Franks in an alphabetized ledger: Anne Frank found among names in ledger of Holocaust deportees (Associated Press, 25 November 2006).

Provenance · Integrity Record
Hashes of the byte‑identical processed JPEG (raw → JPEG). Verify with sha512sum -c SHA512SUMS.
SHA512SUMS (processed image) · SHA512SUMS-scans (archival scans)
SHA3‑512 · BLAKE3 (processed image): MULTIHASH.txt · asc · rsa · mldsa · slhdsa · ots
SHA3‑512 · BLAKE3 (archival scans): MULTIHASH-scans.txt · asc · rsa · mldsa · slhdsa · ots
Processed image · 2969AEB80A42E0215E664D93BD9BC85E02138166415C917120743657B386AF51
Archival scans · CA4247E89A5EFEAB36DC6A42C5479171B69A3CFB887DB92C3FB1480A299357A3
Processed image · SHA512SUMS.ots → Bitcoin block 951191, 2026‑05‑27 00:49 UTC
Archival scans · SHA512SUMS-scans.ots → Bitcoin block 966592, 2026‑09‑12 01:40 UTC

Saturday, September 12, 2026

Majdanek

Mausoleum, State Museum at Majdanek. This is a primary record of my visit.
© 2026 Bryan R. Hinton
Provenance · Integrity Record
Hash of the byte‑identical processed JPEG (raw → JPEG). Verify with sha512sum -c SHA512SUMS.
SHA3‑512 · BLAKE3: MULTIHASH.txt · asc · rsa · mldsa · slhdsa · ots
CA4247E89A5EFEAB36DC6A42C5479171B69A3CFB887DB92C3FB1480A299357A3
SHA512SUMS.ots → Bitcoin block 962233, 2026‑08‑13 03:55 UTC
MULTIHASH.txt.ots → Bitcoin block 966690, 2026‑09‑12 16:00 UTC

Friday, May 29, 2026

A thousand years on Polish soil

I took this from the train back from Majdanek. Fields outside Cienin, in western Poland, fifty kilometres from Chełmno nad Nerem.

The train was carrying me away from a place where people were murdered. The window was cold. The fields were ordinary.

Cienin, near Chełmno nad Nerem. Still in the shadow of Majdanek.
© 2026 Bryan R. Hinton

Between five and six million Polish citizens were murdered, three million of them Jews. Much of the killing was carried out on Polish soil: at Auschwitz-Birkenau, Treblinka, Sobibór, Bełżec, Majdanek, and Chełmno, all of them German Nazi camps and killing centers built in occupied Poland.

Whole towns where no one came home.

A civilization of a thousand years, destroyed in five.

The fields look ordinary now. The forests have grown back. The track is still there.

What remains is the duty to remember precisely. The names. The places. The dates. The silence in those places now is not empty. It is the shape of what was taken.

This is a shared history, and it cannot be told without Poland. For nearly a thousand years, Polish citizens (Jews and Catholics, scholars and merchants) built one of the great civilizations of Europe. From the Statute of Kalisz in 1264, through the academies of Kraków and Lublin, to the printing houses of Warsaw and the streets of Wilno, they wrote in Polish, Yiddish, and Hebrew. They fought together in Polish uprisings. They rest together in Polish soil.

And then they were murdered, the Jews to the last one they could find. And the world let it happen. And the fields kept growing.

To study this history through the objects, documents, and testimonies that preserve it, I recommend:

POLIN Museum of the History of Polish Jews
Warsaw

OÅ›rodek „Brama Grodzka – Teatr NN”
Lublin

Emanuel Ringelblum Jewish Historical Institute
Żydowski Instytut Historyczny, Warsaw

Images are now fabricated as easily as they are taken. So the claim this page makes is narrow. Light hit a sensor and the sensor wrote a file. The file is the one you are looking at. The hash, the signatures and the Bitcoin block at the foot of this page say it has not been touched since.

Provenance · Integrity Record
Hash of the byte‑identical processed JPEG (raw → JPEG). Verify with sha512sum -c SHA512SUMS.
SHA3‑512 · BLAKE3: MULTIHASH.txt · asc · rsa · mldsa · slhdsa · ots
SHA512SUMS · 2969AEB80A42E0215E664D93BD9BC85E02138166415C917120743657B386AF51
MULTIHASH.txt · CA4247E89A5EFEAB36DC6A42C5479171B69A3CFB887DB92C3FB1480A299357A3
SHA512SUMS.ots → Bitcoin block 951189, 2026‑05‑27 00:28 UTC
MULTIHASH.txt.ots → Bitcoin block 966616, 2026‑09‑12 05:01 UTC

Wednesday, January 12, 2022

Concurrency, Parallelism, and Barrier Synchronization - Multiprocess and Multithreaded Programming

On preemptive, timed-sliced UNIX or Linux operating systems such as Solaris, AIX, Linux, BSD, and OS X, program code from one process executes on the processor for a time slice or quantum. After this time has elapsed, program code from another process executes for a time quantum. Linux divides CPU time into epochs, and each process has a specified time quantum within an epoch. The execution quantum is so small that the interleaved execution of independent, schedulable entities – often performing unrelated tasks – gives the appearance of multiple software applications running in parallel.

When the currently executing process relinquishes the processor, either voluntarily or involuntarily, another process can execute its program code. This event is known as a context switch, which facilitates interleaved execution. Time-sliced, interleaved execution of program code within an address space is known as concurrency.

The Linux kernel is fully preemptive, which means that it can force a context switch for a higher priority process. When a context switch occurs, the state of a process is saved to its process control block, and another process resumes execution on the processor.

A UNIX process is considered heavyweight because it has its own address space, file descriptors, register state, and program counter. In Linux, this information is stored in the task_struct. However, when a process context switch occurs, this information must be saved, which is a computationally expensive operation.

Concurrency applies to both threads and processes. A thread is an independent sequence of execution within a UNIX process, and it is also considered a schedulable entity. Both threads and processes are scheduled for execution on a processor core, but thread context switching is lighter in weight than process context switching.

In UNIX, processes often have multiple threads of execution that share the process's memory space. When multiple threads of execution are running inside a process, they typically perform related tasks. The Linux user-space APIs for process and thread management abstract many details. However, the concurrency level can be adjusted to influence the time quantum so that the system throughput is affected by shorter and longer durations of schedulable entity execution time.

While threads are typically lighter weight than processes, there have been different implementations across UNIX and Linux operating systems over the years. The three models that typically define the implementations across preemptive, time-sliced, multi-user UNIX and Linux operating systems are defined as follows - 1:1, 1:N, and M:N where 1:1 refers to the mapping of one user-space thread to one kernel thread, 1:N refers to the mapping of multiple user-space threads to a single kernel thread. M:N refers to the mapping of N user-space threads to M kernel threads.

In the 1:1 model, one user-space thread is mapped to one kernel thread. This allows for true parallelism, as each thread can run on a separate processor core. However, creating and managing a large number of kernel threads can be expensive.

In the 1:N model, multiple user-space threads are mapped to a single kernel thread. This is more lightweight, as there are fewer kernel threads to create and manage. However, it does not allow for true parallelism, as only one thread can execute on a processor core at a time.

In the M:N model, N user-space threads are mapped to M kernel threads. This provides a balance between the 1:1 and 1:N models, as it allows for both true parallelism and lightweight thread creation and management. However, it can be complex to implement and can lead to issues with load balancing and resource allocation.

Parallelism on a time-sliced, preemptive operating system means the simultaneous execution of multiple schedulable entities over a time quantum. Both processes and threads can execute in parallel across multiple cores or processors. Concurrency and parallelism are at play on a multi-user system with preemptive time-slicing and multiple processor cores. Affinity scheduling refers to scheduling processes and threads across multiple cores so that their concurrent and parallel execution is close to optimal.

It's worth noting that affinity scheduling refers to the practice of assigning processes or threads to specific processors or cores to optimize their execution and minimize unnecessary context switching. This can improve overall system performance by reducing cache misses and increasing cache hits, among other benefits. In contrast, non-affinity scheduling allows processes and threads to be executed on any available processor or core, which can result in more frequent context switching and lower performance.

Software applications are often designed to solve computationally complex problems. If the algorithm to solve a computationally complex problem can be parallelized, then multiple threads or processes can all run at the same time across multiple cores. Each process or thread executes by itself and does not contend for resources with other threads or processes working on the other parts of the problem to be solved. When each thread or process reaches the point where it can no longer contribute any more work to the solution of the problem, it waits at the barrier if a barrier has been implemented in software. When all threads or processes reach the barrier, their work output is synchronized and often aggregated by the primary process. Complex test frameworks often implement the barrier synchronization problem when certain types of tests can be run in parallel. Most individual software applications running on preemptive, time-sliced, multi-user Linux and UNIX operating systems are not designed with heavy, parallel thread or parallel, multiprocess execution in mind.

Minimizing lock granularity increases concurrency, throughput, and execution efficiency when designing multithreaded and multiprocess software programs. Multithreaded and multiprocess programs that do not correctly utilize synchronization primitives often require countless hours of debugging. The use of semaphores, mutex locks, and other synchronization primitives should be minimized to the maximum extent possible in computer programs that share resources between multiple threads or processes. Proper program design allows schedulable entities to run parallel or concurrently with high throughput and minimum resource contention. This is optimal for solving computationally complex problems on preemptive, time-sliced, multi-user operating systems without requiring hard, real-time scheduling.

Wednesday, February 24, 2021

A hardware design for variable output frequency using an n-bit counter

The DE1-SoC from Terasic is an excellent board for hardware design and prototyping. The following VHDL process is from a hardware design created for the Terasic DE1-SoC FPGA. The ten switches and four buttons on the FPGA are used as an n-bit counter with an adjustable multiplier to increase the output frequency of one or more output pins at a 50% duty cycle.

As the switches are moved or the buttons are pressed, the seven-segment display is updated to reflect the numeric output frequency, and the output pin(s) are driven at the desired frequency. The onboard clock runs at 50MHz, and the signal on the output pins is set on the rising edge of the clock input signal (positive edge-triggered). At 50MHz, the output pins can be toggled at a maximum rate of 50 million cycles per second or 25 million rising edges of the clock per second. An LED attached to one of the output pins would blink 25 million times per second, not recognizable to the human eye. The persistence of vision, which is the time the human eye retains an image after it disappears from view, is approximately 1/16th of a second. Therefore, an LED blinking at 25 million times per second would appear as a continuous light to the human eye.

scaler <= compute_prescaler((to_integer(unsigned( SW )))*scaler_mlt);
gpiopulse_process : process(CLOCK_50, KEY(0))
begin
if (KEY(0) = '0') then -- async reset
count <= 0;
elsif rising_edge(CLOCK_50) then
if (count = scaler - 1) then
state <= not state;
count <= 0;
elsif (count = clk50divider) then -- auto reset
count <= 0;
else
count <= count + 1;
end if;
end if;
end process gpiopulse_process;
The scaler signal is calculated using the compute_prescaler function, which takes the value of a switch (SW) as an input, multiplies it with a multiplier (scaler_mlt), and then converts it to an integer using to_integer. This scaler signal is used to control the frequency of the pulse signal generated on the output pin.

The gpiopulse_process process is triggered by a rising edge of the CLOCK_50 signal and a push-button (KEY(0)) press. It includes an asynchronous reset when KEY(0) is pressed.

The count signal is incremented on each rising edge of the CLOCK_50 signal until it reaches the value of scaler - 1. When this happens, the state signal is inverted and count is reset to 0. If count reaches the value of clk50divider, it is also reset to 0.

Overall, this code generates a pulse signal with a frequency controlled by the value of a switch and a multiplier, which is generated on a specific output pin of the FPGA board. The pulse signal is toggled between two states at a frequency determined by the scaler signal.

It is important to note that concurrent statements within an architecture are executed concurrently, meaning that they are evaluated concurrently and in no particular order. However, the sequential statements within a process are executed sequentially, meaning that they are evaluated in order, one at a time. Processes themselves are executed concurrently with other processes, and each process has its own execution context.

Tuesday, August 25, 2020

Creating stronger keys for OpenSSH and GPG

Create Ed25519 SSH keypair (supported in OpenSSH 6.5+). Parameters are as follows:

-o save in new format
-a 128 for 128 kdf (key derivation function) rounds
-t ed25519 for type of key
ssh-keygen -o -a 128 -t ed25519 -f .ssh/ed25519-$(date '+%m-%d-%Y') -C ed25519-$(date '+%m-%d-%Y')
Create Ed448-Goldilocks GPG master key and sub keys.
# gpg --quick-generate-key ed448-master-key-$(date '+%m-%d-%Y') ed448 sign 0
# gpg --list-keys --with-colons "ed448-master-key-08-03-2021" | grep fpr
# gpg --quick-add-key "$fpr" cv448 encr 2y
# gpg --quick-add-key "$fpr" ed448 auth 2y
# gpg --quick-add-key "$fpr" ed448 sign 2y

Sunday, September 2, 2018

96Boards - JTAG and serial UART configuration for ARM powered, single-board computers

The 96boards CE specification calls for an optional JTAG connection. The specification also indicates that the optional JTAG connection shall use a 10 pin through hole, .05" (1.27mm) pitch JTAG connector. The part is readily available on most electronics sites. Breaking out the pins with long wires and shrink wrapping them is ideal for making sure that each connection is labeled and separate when connecting to a JTAG debugger. While a JTAG connection is not required for flashing or loading the bootloaders onto the board, the JTAG connection is useful for advanced chip-level debugging. The serial UART connection is sufficient for loading release or debug versions of bl0, bl1, bl2, bl31, bl32, the kernel, and userspace. Last but not least, ARM-powered boards, with 12V power input, often require external fans to keep the board cool. As seen in the below photos, two 5V fans were powered from an external power supply. Any work on microcontroller boards should be performed on a grounded surface. Proper grounding procedures should always be followed as most microcontroller boards contain ESD sensitive components.

In the below photos, a 96Boards SBC is mounted on an IP65, ABS plastic junction box for durability. The pins are extended and mounted with screws underneath the junction box. The electrical conduit holes on the side of the junction box are ideal for holding small, project fans. The remaining electrical conduit holes provide a clean place to place the remaining wires from the board - micro USB, USB-C, and 12V power.

© 2018 Bryan R. Hinton
© 2018 Bryan R. Hinton

Thursday, June 7, 2018

HiKey 960 Linux Bridged Firewall

The Kirin 960 SoC and on-board USB 3.0 make the HiKey 960 SBC an ideal platform for running a Linux Bridged firewall. The number of single-board computers with an SoC as powerful as the HiSilicon Kirin 960 is limited.

When compared with the Raspberry Pi series of single board computers (SBC), the HiKey 960 SBC is significantly more powerful. The Kirin 960 also stands above the ARM powered SoCs which reside in most commercial routers.

USB 3.0 makes the HiKey 960 board an attractive option for bridging or routing, filtering network traffic, or connecting to an external gateway via IPSec. Both network traffic filtering and IPSec tunneling can be computationally expensive operations. However, the multicore Kirin 960 is well suited for these types of tasks.

In order to be able to run an IPSec client tunnel and a Linux Bridged firewall connected over 1G ethernet links, certain kernel configuration modifications are needed. Furthermore, the Android Linux kernel for the HiKey 960 board does not boot on a standard Linux root filesystem because it is designed to boot an Android customized rootfs.

The latest googlesource Linux kernel (hikey-linaro-4.9) for Android (designed to boot Android on the HiKey 960 board) has been customized to remove the Android specific components so that the kernel boots on a standard Linux root filesystem, with the proper drivers enabled for network connectivity via attached 1000Mb/s USB 3.0 to ethernet adapters. The standard UART interface on the board should be used for serial connectivity and shell access. WiFi and Bluetooth have been removed from the kernel configuration. The kernel should be booted off of a microSDHC UHS-I card. The 96boards instructions should be followed for configuring the HiKey 960 board, setting the jumpers on the board, building and flashing the l-loader, firmware package, partition tables, UEFI loader, ARM Trusted Firmware, and optional Op-TEE. Links for the normal Linux kernel configuration, multi-interface bridge configuration, and single interface IPSec configuration are below. Additional kernel config modifications may be needed for certain types of applications.

kernel build instructions

mkdir /usr/local/toolchains
cd /usr/local/toolchains/
TC=gcc-linaro-7.2.1-2017.11-x86_64_aarch64-linux-gnu
wget https://releases.linaro.org/components/toolchain/binaries/latest/aarch64-linux-gnu/$TC.tar.xz
tar -xJf $TC.tar.xz
export ARCH=arm64
export CROSS_COMPILE=/usr/local/toolchains/$TC/bin/aarch64-linux-gnu-
export PATH=/usr/local/toolchains/$TC/gcc-aarch64-linux-gnu/bin:$PATH
cd /usr/local/src
git clone https://android.googlesource.com/kernel/hikey-linaro
cd hikey-linaro
git checkout -b android-hikey-linaro-4.9
make hikey960_defconfig
make -j8

multi-interface bridge configuration

Bridged configuration, no ip addresses on dual nic interfaces. (crossover cable is useful for testing). Bridge interface obtains dhcp address (/11) from wlan router. Aliased interface added to br0 and assigned private subnet ip on different subnet (/8). Spanning tree set on bridge interface. Basic ebtables and iptables ruleset below.

brctl addbr <br>
brctl addif <br> <eth1> <eth2>
ifconfig <br> up
ifconfig <eth1> up
ifconfig <eth2> up
brctl stp <br> yes
dhclient <br>
ifconfig <br>:0 <a.b.c.d/sn> up

iptables --table nat --append POSTROUTING --out-interface <br> -j MASQUERADE
iptables -P INPUT DROP
iptables --append FORWARD --in-interface <br>:0 -j ACCEPT
ebtables -P FORWARD DROP
ebtables -P INPUT DROP
ebtables -P OUTPUT DROP
ebtables -t filter -A FORWARD -p IPv4 -j ACCEPT
ebtables -t filter -A INPUT -p IPv4 -j ACCEPT
ebtables -t filter -A OUTPUT -p IPv4 -j ACCEPT
ebtables -t filter -A INPUT -p ARP -j ACCEPT
ebtables -t filter -A OUTPUT -p ARP -j ACCEPT
ebtables -t filter -A FORWARD -p ARP -j REJECT
ebtables -t filter -A FORWARD -p IPv6 -j DROP
ebtables -t filter -A FORWARD -d Multicast -j DROP
ebtables -t filter -A FORWARD -p X25 -j DROP
ebtables -t filter -A FORWARD -p FR_ARP -j DROP
ebtables -t filter -A FORWARD -p BPQ -j DROP
ebtables -t filter -A FORWARD -p DEC -j DROP
ebtables -t filter -A FORWARD -p DNA_DL -j DROP
ebtables -t filter -A FORWARD -p DNA_RC -j DROP
ebtables -t filter -A FORWARD -p LAT -j DROP
ebtables -t filter -A FORWARD -p DIAG -j DROP
ebtables -t filter -A FORWARD -p CUST -j DROP
ebtables -t filter -A FORWARD -p SCA -j DROP
ebtables -t filter -A FORWARD -p TEB -j DROP
ebtables -t filter -A FORWARD -p RAW_FR -j DROP
ebtables -t filter -A FORWARD -p AARP -j DROP
ebtables -t filter -A FORWARD -p ATALK -j DROP
ebtables -t filter -A FORWARD -p 802_1Q -j DROP
ebtables -t filter -A FORWARD -p IPX -j DROP
ebtables -t filter -A FORWARD -p NetBEUI -j DROP
ebtables -t filter -A FORWARD -p PPP -j DROP
ebtables -t filter -A FORWARD -p ATMMPOA -j DROP
ebtables -t filter -A FORWARD -p PPP_DISC -j DROP
ebtables -t filter -A FORWARD -p PPP_SES -j DROP
ebtables -t filter -A FORWARD -p ATMFATE -j DROP
ebtables -t filter -A FORWARD -p LOOP -j DROP
ebtables -t filter -A FORWARD --log-level info --log-ip --log-prefix FFWLOG
ebtables -t filter -A OUTPUT --log-level info --log-ip --log-arp --log-prefix OFWLOG -j DROP
ebtables -t filter -A INPUT --log-level info --log-ip --log-prefix IFWLOG

single-interface ipsec gateway configuration

iptables -t nat -A POSTROUTING -s <clientip>/32 -o <eth> -j SNAT --to-source <virtualip>
iptables -t nat -A POSTROUTING -s <clientip>/32 -o <eth> -m policy --dir out --pol ipsec -j ACCEPT

Thursday, February 1, 2018

a Hardware Design for XOR gates using sequential logic in VHDL

ModelSim full window view with waveform output of the XOR simulation.
ModelSim-Intel FPGA Starter Edition © Intel

XOR logic gates are a fundamental component in cryptography, and many of the typical stream and block ciphers use XOR gates. A few of these ciphers are ChaCha (stream cipher), AES (block cipher), and RSA (block cipher).

While many compiled and interpreted languages support bitwise operations such as XOR, the software implementation of both block and stream ciphers is computationally inefficient compared to FPGA and ASIC implementations.

Hybrid FPGA boards integrate FPGAs with multicore ARM and Intel application processors over high-speed buses. The ARM and Intel processors are general-purpose processors. On a hybrid board, the ARM or Intel processor is termed the hard processor system or HPS. Writing to the FPGA from the HPS is typically performed via C from an embedded Linux build (yocto or buildroot) running on the ARM or Intel core. A simple bitstream can also be loaded into the FPGA fabric without using any ARM design blocks or functionality in the ARM core for a hybrid ARM configuration.

The following is a simple hardware design written in VHDL and simulated in ModelSim. The image contains the waveform output of a simulation in ModelSim. The HPS is not used. On boot, the bitstream is loaded into the FPGA fabric. VHDL components are utilized, and a testbench is defined for testing the design. The entity and architecture VHDL design units are below.

--three input xnor gate entity declaration - external interface to design entity
entity xnorgate is
port (
    a,b,c : in std_logic;
    q : out std_logic);
end xnorgate;

architecture xng of xnorgate is
begin
    q <= a xnor b xnor c;
end xng;

--chain of xor / xnor gates using components and sequential logic
entity xorchain is
port (
    A,B,C,D,E,F : in std_logic;
    Av,Bv       : in std_logic_vector(31 downto 0);
    CLOCK_50    : in std_logic;
    Q           : out std_logic;
    Qv          : out std_logic_vector(31 downto 0));
end xorchain;

architecture rtl of xorchain is
component xorgate is
port (
    a,b  : in std_logic;
    q    : out std_logic);
end component;

component xnorgate is
port (
    a,b,c  : in std_logic;
    q      : out std_logic);
end component;

component xorsgate is
port (
    av : in std_logic_vector(31 downto 0);
    bv : in std_logic_vector(31 downto 0);
    qv : out std_logic_vector(31 downto 0));
end component;

signal a_in, b_in, c_in, d_in, e_in, f_in : std_logic;
signal av_in, bv_in : std_logic_vector(31 downto 0);

signal conn1, conn2, conn3 : std_logic;

begin
    xorgt1  : xorgate port map(a => a_in, b => b_in, q => conn1);
    xorgt2  : xorgate port map(a => c_in, b => d_in, q => conn2);
    xorgt3  : xorgate port map(a => e_in, b => f_in, q => conn3);
    xnorgt1 : xnorgate port map(conn1, conn2, conn3, Q);
    xorsgt1 : xorsgate port map(av => av_in, bv => bv_in, qv => Qv);

   process(CLOCK_50)
   begin
       if rising_edge(CLOCK_50) then --assign inputs on rising clock edge
           a_in <= A;
           b_in <= B;
           c_in <= C;
           d_in <= D;
           e_in <= E;
           f_in <= F;
           av_in(31 downto 0) <= Av(31 downto 0);
           bv_in(31 downto 0) <= Bv(31 downto 0);
       end if;
    end process;
end rtl;

entity xorchain_tb is
end xorchain_tb;

architecture xorchain_tb_arch of xorchain_tb is
    signal A_in,B_in,C_in,D_in,E_in,F_in : std_logic := '0';
    signal Av_in                         : std_logic_vector(31 downto 0);
    signal Bv_in                         : std_logic_vector(31 downto 0);
    signal CLOCK_50_in                   : std_logic;
    signal BRK                           : boolean := FALSE;
    signal Q_out                         : std_logic;
    signal Qv_out                        : std_logic_vector(31 downto 0);

component xorchain
port (
    A,B,C,D,E,F      : in std_logic;
    Av               : in std_logic_vector(31 downto 0);
    Bv               : in std_logic_vector(31 downto 0);
    CLOCK_50         : in std_logic;
    Q                : out std_logic;
    Qv               : out std_logic_vector(31 downto 0));
end component;

begin
    xorchain_instance: xorchain port map (A => A_in,B => B_in, C => C_in,
                                          D => D_in, E => E_in, F => F_in, Av => Av_in,
                                          Bv => Bv_in, CLOCK_50 => CLOCK_50_in, Q => Q_out,
                                          Qv => Qv_out);
clockprocess: process
    begin
        while not BRK loop
            CLOCK_50_in <= '0';
                wait for 20 ns;
                CLOCK_50_in <= '1';
                wait for 20 ns;
        end loop;
    wait;
end process clockprocess;

testprocess : process
    begin
        A_in <= '1';
        B_in <= '0';
        C_in <= '1';
        D_in <= '0';
        E_in <= '1';
        F_in <= '1';
        wait for 40 ns;
        A_in <= '1';
        B_in <= '0';
        C_in <= '1';
        D_in <= '0';
        E_in <= '1';
        F_in <= '0';
        wait for 20 ns;
        A_in <= '0';
        B_in <= '0';
        C_in <= '1';
        D_in <= '0';
        E_in <= '1';
        F_in <= '0';
        wait for 40 ns;
        BRK <= TRUE;
        wait;
    end process testprocess;
end xorchain_tb_arch;

entity xorgate is
port (
    a,b : in std_logic;
    q   : out std_logic);
end xorgate;

architecture xg of xorgate is
begin
    q <= a xor b;
end xg;

entity xorsgate is
port (
    av : in std_logic_vector(31 downto 0);
    bv : in std_logic_vector(31 downto 0);
    qv : out std_logic_vector(31 downto 0));
end xorsgate;

architecture xsg of xorsgate is
begin
    qv <= av xor bv;
end xsg;

Saturday, September 17, 2016

Implementing Software-defined radio and Infrared Time-lapse Imaging with Tensorflow on a custom Linux distribution for the Raspberry Pi 3

The Raspberry Pi 3 is powered by the ARM Cortex-A53 processor. This 1.2GHz 64-bit quad-core processor fully supports the ARMv8-A architecture. For this project, a custom Linux distribution was created for the Raspberry Pi 3.

GNURadio Companion Qt Gui Frequency Sync - multiple FIR filter taps sample running on Raspberry Pi 3 custom Linux distribution
© 2018 Bryan R. Hinton

The custom Linux distribution includes support for GNURadio, several FPGA and ARM Powered SDR devices, D-STAR (hotspot, repeater, and dongle support), hsuart, libusb, hardware real-time clock support, Sony 14 megapixel NoIR image sensor, HDMI and 3.5mm audio, USB Microphone input, X-windows with Xfce, Lighttpd and PHP, Bluetooth, WiFi, SSH, TCPDump, Docker, Docker registry, MySQL, Perl, Python, QT, GTK, IPTables, x11vnc, SELinux, and full native-toolchain development support.

The Sony 14 megapixel image sensor with the infrared filter removed can be connected to the Raspberry Pi 3's MIPI camera serial interface. Image capture and recognition can then be performed over contiguous periods of time, and time-lapsed video can be created from the images. With support for Tensorflow and OpenCV, object recognition within images can be performed.

D-STAR hotspot with time-lapsed infrared imaging.
© 2018 Bryan R. Hinton

For the initial run, an infrared Time-lapse Video was created from an initial image capture run of one 3280x2460 infrared jpeg image captured every 15 seconds for three hours. 40, 5mm, 940nm LEDs, powered by 500ma over 12v DC, provided infrared illumination in the 940nm wavelength.

Tensorflow ran in the background (on v4l2 kmod) and provided continuous object recognition and scoring within each image via a sample model. Finally, OpenCV was also installed in the root file system.

The time-lapse infrared video was captured of the living room using the above setup. Below this image are images of Tensorflow running in a terminal in the background on the Raspberry Pi 3 and recognizing/scoring objects in the living room.

Tensorflow running on the Raspberry Pi 3 and continuously capturing frames from the image sensor and scoring objects
© 2018 Bryan R. Hinton
GNURadio Companion running on xfce on the Raspberry Pi 3
© 2018 Bryan R. Hinton

Tuesday, August 16, 2016

Profiling Multiprocess C programs with ARM DS-5 Streamline

The ARM DS-5 Streamline Performance Analyzer is a powerful tool for debugging, profiling, and analyzing multithreaded and multiprocess C programs. Instructions can easily be traced between load and store operations. Per process and per thread function call paths can be broken down by system utilization percentage. Branch mispredictions and multi-level CPU caches can be analyzed. Furthermore, disk I/O usage, stack and heap usage, and a number of other useful metrics can quickly be referenced within the debugger. These are just a few of its capabilities.

In order to capture meaningful information from the DS-5 Streamline Performance Analyzer tool, a Linux, multiprocess, C program was modified to insert 1000 packets into a packet processing simulation buffer. A code excerpt from the program is below. The child processes were modified to sleep and then wake 1000 times in order to simulate process activity. The program was analyzed using the DS-5 Streamline Performance Analyzer tool. There are two screenshots below the code excerpt where the program is loaded into the DS-5 Streamline Performance Analyzer.

void *insertpackets(void *arg) {

   struct pktbuf *pkbuf;
   struct packet *pkt;
   int idx;

   if(arg != NULL) {

      pkbuf = (struct pktbuf *)arg;

      /* seed random number generator */
      ...

      /* insert 1000 packets into the packet buffer */
      for(idx = 0; idx < 1000; ++idx) {

         pkt = (struct packet *)malloc(sizeof(struct packet));

         if(pkt != NULL) {

            /* set the packet processing simulation multiplier to 3 */
            pkt->mlt=...()%3;

            /* insert packet in the packet buffer */
            if(pkt_queue(pkbuf,pkt) != 0) {

               ...
            ...
         ...
      ...
   ...
...

int fcnb(time_t secs, long nsecs) {

   struct timespec rqtp;
   struct timespec rmtp;
   int ret;
   int idx;

   rqtp.tv_sec = secs;
   rqtp.tv_nsec = nsecs;

   for(idx = 0; idx < 1000; idx++) {

      ret = nanosleep(&rqtp, &rmtp);

      ...
   ...
...
ARM DS-5 Streamline - Profiling the process creation application
© 2018 Bryan R. Hinton
ARM DS-5 Streamline - Code View with C code in the top window and ARM assembly instructions in the bottom window
© 2018 Bryan R. Hinton

Source: run.c