Multiply and then shift: E(x) = ax + b mod 26. The multiplier a must be coprime to 26 or the cipher is not reversible — this tool shows you why, computes a−1, and can break the cipher by trying every one of the 312 valid keys.
Every valid (a, b) pair, scored against English letter frequencies. Lower is better; the winner is highlighted. Click a row to load that key. Only the top 40 are listed.
| Key | Decryption | Score |
|---|
E(x) = (ax + b) mod 26 D(y) = a^-1 (y - b) mod 26
The affine cipher generalises the shift cipher by multiplying before adding. With a = 1 it is the shift cipher, so everything Caesar can do, affine can do too.
Decryption needs to undo the multiplication, which means dividing by a — and modular arithmetic has no division. Instead you multiply by the modular inverse a−1, the number with a · a−1 ≡ 1 (mod 26).
That inverse exists only when gcd(a, 26) = 1. Since 26 = 2 × 13, the valid multipliers are the twelve values 1, 3, 5, 7, 9, 11, 15, 17, 19, 21, 23, 25.
Twelve choices of a times 26 choices of b gives 312 keys — twelve times more than the shift cipher, and still nothing.
The tool shows the mechanism — the slides show why it is built that way.
The affine cipher is the first place gcd and modular inverses stop being abstract. One-on-one tutoring makes that machinery concrete — and it is the same machinery RSA runs on.