Cryptography Intermediate

Affine Cipher

Multiply and then shift: E(x) = ax + b mod 26. The multiplier a must be coprime to 26 or the cipher is not reversible — this tool shows you why, computes a−1, and can break the cipher by trying every one of the 312 valid keys.

Key validity check
Modular inverse working
All 312 keys ranked
Live
Message and Key (a, b)
Valid multipliers (click one)
Result
Ciphertext
EncryptionE(x) = 5x + 8 mod 26
Inverse of a21
DecryptionD(y) = 21(y − 8) mod 26
Key space12 × 26 = 312 keys
The 12 valid multipliers are exactly the numbers below 26 sharing no factor with 26 = 2 × 13 — that is, the odd numbers except 13.
Working
Break It: All 312 Keys Ranked

Every valid (a, b) pair, scored against English letter frequencies. Lower is better; the winner is highlighted. Click a row to load that key. Only the top 40 are listed.

KeyDecryptionScore
Multiply, Then Shift
E(x) = (ax + b) mod 26 D(y) = a^-1 (y - b) mod 26

The affine cipher generalises the shift cipher by multiplying before adding. With a = 1 it is the shift cipher, so everything Caesar can do, affine can do too.

Decryption needs to undo the multiplication, which means dividing by a — and modular arithmetic has no division. Instead you multiply by the modular inverse a−1, the number with a · a−1 ≡ 1 (mod 26).

That inverse exists only when gcd(a, 26) = 1. Since 26 = 2 × 13, the valid multipliers are the twelve values 1, 3, 5, 7, 9, 11, 15, 17, 19, 21, 23, 25.

Try a = 13 above. Thirteen shares the factor 13 with 26, so the map collapses: many plaintext letters land on the same ciphertext letter and the message can never be recovered.
Bigger Key Space, Same Weakness

Twelve choices of a times 26 choices of b gives 312 keys — twelve times more than the shift cipher, and still nothing.

  • Brute force still wins. 312 is a rounding error for a computer, as the panel above demonstrates instantly.
  • Frequency analysis still wins. The cipher is still a one-to-one letter substitution, so E stays the most common letter, it just lands somewhere else.
  • Two known letters are enough. Each known pair gives a linear equation in a and b, and two equations solve the system outright — no searching at all.
The real lesson: enlarging a key space from 26 to 312 changes nothing when the underlying structure is unchanged. Security comes from destroying plaintext statistics, not from counting keys.
Put It Into Practice

The tool shows the mechanism — the slides show why it is built that way.

Modular inverses not clicking?

The affine cipher is the first place gcd and modular inverses stop being abstract. One-on-one tutoring makes that machinery concrete — and it is the same machinery RSA runs on.

Book a Free Consultation →