From Clay Seals to Six-Digit Codes: A Short History of Proving Who You Are

Every time a website sends a code to a phone and asks for it back, it is solving a problem that is far older than writing. The problem is simple to state and hard to solve: how does someone who cannot see you confirm that a message, an order or a claim really comes from you?

The archaeological record is full of answers to that question. Looking at them side by side shows that the modern verification code is not a new invention so much as the latest version of a very old idea.

The seal: identity pressed into clay

The earliest widespread solution was the seal. In Mesopotamia, cylinder seals appear in the fourth millennium BCE: small carved stone cylinders that left a continuous impression when rolled across wet clay. Each design was distinctive, and the impression it left worked as a signature that could not easily be copied without the object itself.

Seals were used less for letters than for control. A jar, a basket or a storeroom door would be closed with a lump of clay, and the clay would be impressed with a seal. If the sealing was intact, the contents had not been touched since the person responsible closed it. If it was broken, everyone could see that access had taken place.

Excavations have recovered these sealings in large numbers. At Arslantepe in eastern Anatolia, archaeologists found thousands of discarded clay sealings in the public buildings of the late fourth millennium BCE, many of them impressed by different seals. Read together, they document an administration keeping track of who opened what, and when. It is, in effect, an access log.

The seal established two principles that still hold. Identity can be proved by possession of a unique object, and a record of that proof is as important as the proof itself.

Tokens, envelopes and tamper evidence

Around the same period, administrators in the Near East used small clay tokens to represent quantities of goods. For transactions that had to be verified later, tokens could be sealed inside hollow clay balls, often called envelopes or bullae, whose outer surface carried seal impressions and sometimes marks showing what was inside.

The design is clever. The outside tells the recipient what the sender claims; the inside proves it. To check the claim, you break the envelope, which also makes it obvious that it has been checked. Many scholars have argued that these marked envelopes sit close to the origins of writing itself, a reminder of how closely record-keeping and verification have always been bound together.

The watchword: identity as shared knowledge

A second family of solutions relied not on objects but on knowledge. The Greek historian Polybius, describing the Roman army of the second century BCE, explains how the nightly watchword was distributed. It was written on a wooden tablet, the tessera, which was passed from unit to unit and returned to the tribune. If a tablet failed to come back, the officers could trace exactly where the chain had broken.

The watchword solved a different problem from the seal. A seal proves that a particular person handled something. A watchword proves that someone belongs to a group entitled to pass. Its weakness is also familiar: once the word leaks, anyone can use it. The Roman procedure dealt with this by changing the word every night, which is precisely the logic behind modern codes that expire after a few minutes.

The split stick and the matching half

Medieval Europe added an elegant object-based method: the split tally. A stick was notched to record a sum, then split lengthways so that each party kept one half. Because the notches ran across both halves and the grain of the wood was unique, the two pieces fitted only each other. Anyone presenting a forged half would be caught when it failed to match.

The English Exchequer relied on tallies for centuries, until they were formally abolished in the early nineteenth century. Their end was dramatic. In October 1834, officials burned a large accumulation of old tallies in a furnace beneath the House of Lords; the fire spread, and much of the old Palace of Westminster was destroyed.

The same idea appears in parchment. A chirograph was a document written out two or more times on a single sheet, with a word or pattern written across the gap between the copies. The sheet was then cut through that word, often along a wavy line, and each party took a copy. Authenticity was proved by fitting the edges back together. The indented cut survives in the legal word “indenture”.

The telegraph and the secret test

Long-distance communication sharpened the problem again. A telegram carried no seal, no handwriting and no physical token; it was simply text, transmitted by strangers. Banks that began moving money by telegraph in the nineteenth century needed a way to confirm that an instruction to pay really came from a correspondent bank.

Their answer was the test key: a private system, agreed in advance between two banks, for calculating a check number from details of the message such as the amount and the date. The receiving bank repeated the calculation. If the numbers matched, the instruction was accepted. The principle, a shared secret combined with the particulars of a single transaction, anticipates the way many modern authentication codes are generated.

The code on your phone

Set against this history, the text-message code looks less like a novelty and more like a synthesis. It combines three older ideas.

Like a seal or a tally half, it depends on possession: the code goes to a device or number that the account holder is expected to control. Like a Roman watchword, it is valid for only a short period and is then discarded. Like a telegraphic test, it is tied to a single transaction, one login or one sign-up, rather than being reused.

It also inherits the weaknesses of its ancestors. Seals could be stolen, watchwords overheard and tallies forged by a skilled hand. Phone numbers can be reassigned by carriers, intercepted or transferred to another SIM by fraud, which is why standards bodies such as the US National Institute of Standards and Technology have long treated text-message codes as a weaker form of authentication than dedicated hardware keys or authenticator apps.

There is one more parallel. Just as merchants in antiquity must sometimes have hesitated before pressing their personal seal onto a stranger’s jar, people today are often reluctant to hand their personal number to every service that asks for it. Some choose a temporary number for verification when signing up to something they only need once, keeping their main number for the accounts that matter. The instinct is an old one: separate the token that proves who you are from the places where it might be misused.

What the long view shows

Read across five thousand years, the history of proving identity at a distance is a history of trade-offs rather than solutions. Objects are strong but can be stolen. Shared knowledge is convenient but leaks. Every method that succeeds becomes worth attacking, and every attack produces a new method.

The clay sealings from Arslantepe and the six-digit code arriving on a phone belong to the same story. Both are attempts to leave a trace that only the right person could have left. Archaeologists read the first kind of trace to reconstruct how ancient administrations worked. Future historians will almost certainly do the same with ours.

Cover Image, Top Left: Credit: Cylinder Seal with a Seated Deity,, Walters Art Museum, CC BY-SA 3.0, Wikimedia Commons

____________________________

Advertisement

Subscribe to Popular Archaeology Premium. Still the industry's best value at only $9.00 annually.