Chapter 2: Classical Cryptosystems

Chapter 2 of Trappe & Washington: the shift, affine, Vigenère, substitution, Playfair, ADFGX and Enigma ciphers, each with its own worked encryption and its own break. Builds the frequency-analysis and coincidence-counting toolkit, and argues the chapter's thesis — that ciphers fall to structure, not to the size of their key space.

Subject: Cryptography · 64 slides · diagram-first lesson

Open the interactive version of this deck

What this lesson covers

The lesson, slide by slide

1. Classical Cryptosystems

Title

Cryptography · Chapter 2

Seven ciphers that were each state of the art, and the reasoning that broke every one

2. What you will be able to do

Objectives

Chapter 1 named the players. This chapter hands you their tools — and the arguments that took the tools apart. Every cipher here is symmetric: one shared key encrypts and decrypts.

Figure (svg): A timeline of the classical ciphers in this chapter, from Caesar in 50 BC to the Enigma machine in the 1940s.

Four hundred years separate the invention of the Vigenère cipher from the publication of its break.

3. Before we start: what is a key actually for?

Warm-up

Kerckhoffs's principle, which Chapter 1 stated, says the adversary knows the system. Only the key is secret.

Discussion prompt

If Eve already knows you are using a shift cipher, what work is left for her to do — and how long should that work take before you would call the cipher secure?

Hint: Count the possible keys, then imagine Eve trying each one and reading the result.

Answer:

All that is left is to find the key, and for a shift cipher there are only 26 of them — including the useless key 0.

Eve tries all 26 and reads the 26 candidate plaintexts. Twenty-five of them are gibberish. That is not an attack that needs a computer; it is an attack that needs a lunch break.

So the honest measure of a cipher is not can it be broken but how much work does breaking it cost, relative to the value of the message.

Figure (svg): Alice encrypts a plaintext with a key, sends the ciphertext over a channel, and Bob decrypts with the same key; Eve watches the channel.

Every cipher in this chapter is symmetric: Alice and Bob share one key.

4. The Shift Cipher

Section

Section 2.1 · pp. 11-12

5. The Shift Cipher: add a constant, mod 26

Concept

Label the letters as integers, a = 0 through z = 25. The key is a single integer κ with 0 ≤ κ ≤ 25.

\[ \text{encrypt: } x \mapsto x + \kappa \pmod{26} \qquad \text{decrypt: } y \mapsto y - \kappa \pmod{26} \]

That is the entire system. Caesar used κ = 23, which is the same as shifting backwards by 3, because −3 ≡ 23 (mod 26).

Monoalphabetic — One fixed letter-to-letter substitution used for the whole message. Every shift cipher is monoalphabetic, which is exactly why a frequency count works on it.

Figure (svg): A cipher disc: the outer ring carries the plaintext alphabet, the inner ring the same alphabet rotated by three places.

The shift cipher is a disc with 26 settings. That is the whole key space.

6. Caesar's own message

Worked example

Encrypt gaul is divided into three parts with κ = 23. Spaces are dropped — they leak word lengths, and the recipient can put them back.

Strip the spaces: gaulisdividedintothreeparts

Why: 27 letters. Punctuation and spacing are not part of the cipher.

g = 6, and 6 + 23 = 29 ≡ 3 (mod 26), which is D

Why: The wrap-around is what makes this modular arithmetic rather than plain addition.

a = 0, and 0 + 23 = 23, which is X

Why: The beginning of the alphabet wraps to the end — this is the step people get wrong by hand.

\[ \texttt{gaulisdividedintothreeparts} \;\longmapsto\; \texttt{DXRIFPAFSFABAFKQLQEOBBMXOQP} \]

Verify: shift D back by 23: 3 − 23 = −20 ≡ 6 (mod 26) = g

Why: Decryption is the same operation with the key negated, so one routine does both jobs.

Figure (svg): Two aligned alphabets showing a shift of 23: plaintext g sits above ciphertext D, and a sits above X.

Caesar's key was 23, which is the same as shifting backwards by 3.

7. Reading the encryption rule

Notation

Every cipher in this course arrives as a formula like this one. Learn to read the parts before you memorise the whole.

Annotate

On: \( x \mapsto x + \kappa \pmod{26} \)

  • The plaintext letter, already turned into a number 0-25. Letters are not the objects the maths acts on; their indices are.
  • "is sent to". It names a function, so the same x always produces the same output — which is precisely the weakness.
  • The key. One number, kept secret. Everything else on this line is public.
  • The alphabet is a circle, not a line. Without this the cipher would run off the end at z.

Four symbols, and only one of them is secret.

8. Which attack model is Eve working in?

Sorting

Chapter 1 defined four attack models. They are not degrees of difficulty — they are descriptions of what Eve happens to have.

Sort into buckets

Sort each situation into the attack model it describes.

Ciphertext only
Eve intercepts a radio transmission and has nothing else; Eve has a stack of intercepts and a table of English letter frequencies
Known plaintext
Eve knows the message begins with the word "general"
Chosen plaintext
Eve slips the letter a into the outgoing queue and watches what is sent
Chosen ciphertext
Eve feeds A to the decryption box and reads what comes out
co
Eve has only ciphertext and public knowledge such as letter statistics. For a shift cipher this is still enough: 26 keys is an afternoon.
kp
Eve holds a plaintext-ciphertext pair she did not choose. One matched letter already gives κ = y − x, so the shift cipher dies instantly here.
cp
Eve gets to pick the plaintext. Choosing a makes the ciphertext letter be the key, because 0 + κ = κ.
cc
Eve gets to pick the ciphertext. Choosing A makes the plaintext the negative of the key.

Notice the shift cipher falls to all four, and to the weakest of them in under an hour.

9. How much does one known letter cost you?

Prediction

Eve learns that the plaintext letter t was encrypted to D. She knows nothing else.

Predict first

What can Eve now compute?

  • Nothing useful — one letter is not enough
  • The key, exactly
  • The key, narrowed to about six candidates
  • The message length

Correct: The key, exactly

\[ \kappa \equiv 3 - 19 \equiv -16 \equiv 10 \pmod{26} \]

And a single letter of crib is a very low bar. Military traffic in both world wars opened with predictable words.

Why: t = 19 and D = 3, so κ ≡ 3 − 19 ≡ −16 ≡ 10 (mod 26). One matched letter determines the key completely, because the key is the difference. This is why the known-plaintext model is so damaging to a monoalphabetic cipher: stereotyped openings and signatures hand Eve those pairs for free.

10. Push the key to its edges

Edge cases

The shift cipher's key runs from 0 to 25. Two of those values deserve a second look.

Discussion prompt

What happens when κ = 0? And is κ = 13 special in any way that matters?

Hint: Write down what each one does to the letter a, and then to the whole message.

Answer:

κ = 0 is the identity. The ciphertext is the plaintext. It is a legal key that provides no encryption at all, and it is why an honest key count for the shift cipher is 25 useful keys, not 26.

κ = 13 is ROT13, and it is its own inverse: shifting by 13 twice returns you to the start, since 13 + 13 = 26 ≡ 0. That self-inverse property is why ROT13 became the Usenet convention for hiding punchlines — one routine both hides and reveals.

Neither is a security property. But both are worth noticing, because 'the key that does nothing' and 'the key that is its own inverse' are genuine failure modes in real systems: weak keys in DES (Chapter 7) are exactly the second case, and all-zero keys have shipped in production more than once.

11. The Affine Cipher

Section

Section 2.2 · pp. 12-14

12. The Affine Cipher: multiply, then add

Concept

Generalise the shift by scaling first. Choose α and β and encrypt with an affine function:

\[ x \mapsto \alpha x + \beta \pmod{26}, \qquad \text{with } \gcd(\alpha, 26) = 1 \]

The shift cipher is the special case α = 1. The condition on α is not decoration — Section 3.3 shows it is exactly the condition for α to have a multiplicative inverse mod 26, and without an inverse there is no decryption.

There are 12 admissible values of α (the numbers coprime to 26) and 26 values of β, so the key space is 12 × 26 = 312.

Figure (svg): A black box labelled with the affine map, taking a plaintext letter in and producing a ciphertext letter out, with the key pair on top.

An affine cipher is a shift with a multiplication in front of it.

13. Encrypting the word *affine* with 9x + 2

Worked example

Take α = 9, β = 2. First check the key is legal: gcd(9, 26) = 1, so 9 is invertible mod 26.

a = 0 → 9·0 + 2 = 2 = C

Why: Because a is 0, the ciphertext letter is β itself. That is the chosen-plaintext attack in one line.

f = 5 → 9·5 + 2 = 47 ≡ 21 = V

Why: 47 − 26 = 21. Both f's give V, since the map is a function.

i = 8 → 9·8 + 2 = 74 ≡ 22 = W, n = 13 → 119 ≡ 15 = P, e = 4 → 38 ≡ 12 = M

Why: Reduce mod 26 after every multiplication to keep the numbers small.

\[ \texttt{affine} \;\longmapsto\; \texttt{CVVWPM} \]

To decrypt, invert: 9·3 = 27 ≡ 1, so 9* = 3, and x ≡ 3(y − 2) ≡ 3y + 20

Why: 3 plays the role of 1/9. Finding it is the extended Euclidean algorithm of Section 3.2.

Verify: V = 21 → 3·21 + 20 = 83 ≡ 5 = f

Why: The second letter comes back as f, as it must. Decrypting the whole string returns affine.

Figure (svg): Aligned alphabets for the affine cipher 9x+2, with the letters of the word affine highlighted.

a → C, f → V, i → W, n → P, e → M: the word affine becomes CVVWPM.

14. A cipher that cannot be decrypted

Anomaly

Someone chooses α = 13, β = 4 and encrypts two completely different words.

\[ \texttt{input} \mapsto \texttt{ERRER} \qquad \texttt{alter} \mapsto \texttt{ERRER} \]

Predict first

What has gone wrong?

  • The arithmetic was done wrong somewhere
  • 13x + 4 is not one-to-one mod 26, so decryption is impossible
  • The words happen to be anagrams
  • β = 4 is an illegal choice

Correct: 13x + 4 is not one-to-one mod 26, so decryption is impossible

13 · x mod 26 is 0 for even x and 13 for odd x. The multiplication throws away everything except the parity of the letter.

This is worth holding on to: an encryption function must be a bijection. A cipher that loses information is not a strong cipher, it is not a cipher at all.

Why: gcd(13, 26) = 13 ≠ 1, so 13 has no inverse mod 26 and the map 13x + 4 is not injective. Multiplying by 13 collapses all 26 residues onto just two values, so many plaintexts share a ciphertext and no receiver could tell which was sent. Encryption must be one-to-one, and for an affine map that is exactly the gcd condition.

Figure (svg): Two different plaintexts, input and alter, both arriving at the same ciphertext ERRER through the broken map 13x+4.

When gcd(α, 26) ≠ 1 the cipher stops being invertible — and stops being a cipher.

15. Write down the decryption formula

Fill the middle

You have the encryption rule and the inverse α* of α. Complete the decryption rule.

Fill in the blanks

x \equiv α* \, y - *αβ** \pmod___

Why: Start from y ≡ αx + β, subtract β to get y − β ≡ αx, then multiply both sides by α* to get αy − αβ ≡ x. Decryption is itself an affine map, with key (α, −αβ) — which is why the affine ciphers form a group under composition.

16. Two known letters are enough

Worked example

Eve learns the plaintext starts if and the ciphertext starts PQ. In numbers: 8 ↦ 15 and 5 ↦ 16.

Write the two equations: 8α + β ≡ 15 and 5α + β ≡ 16 (mod 26)

Why: Two unknowns, two equations. This is ordinary linear algebra done in a ring instead of a field.

Subtract to eliminate β: 3α ≡ −1 ≡ 25 (mod 26)

Why: Subtracting is the whole trick — β is the same in both equations, so it vanishes.

Solve 3α ≡ 25: since 3 · 9 = 27 ≡ 1, the inverse of 3 is 9, so α ≡ 9 · 25 ≡ 225 ≡ 17

Why: 225 − 208 = 17. Check: 3 · 17 = 51 ≡ 25 ✓.

Back-substitute: β ≡ 15 − 8 · 17 = 15 − 136 = −121 ≡ 9 (mod 26)

Why: −121 + 130 = 9.

Verify: check the second pair: 5 · 17 + 9 = 94 ≡ 94 − 78 = 16 = Q

Why: Both pairs are satisfied, so the key is (α, β) = (17, 9) and the whole message is now readable.

Figure (svg): The two simultaneous congruences from the known-plaintext attack, subtracted to eliminate beta and solved for alpha.

Two matched letters collapse a 312-key space to a single key.

17. How big is the affine key space, really?

Estimation

There are 26 choices of β, and α must be coprime to 26.

Predict first

How many keys does an affine cipher over the English alphabet have?

  • 26 × 26 = 676
  • 12 × 26 = 312
  • 25 × 26 = 650
  • 26! ≈ 4 × 10²⁶

Correct: 12 × 26 = 312

\[ \varphi(26) = 26\left(1 - \tfrac{1}{2}\right)\left(1 - \tfrac{1}{13}\right) = 12 \]

You will meet φ again in Chapter 3 and then constantly in Chapter 9 — it is the size of the RSA exponent group.

Why: 26 = 2 · 13, so the numbers coprime to 26 are the odd numbers other than 13: that is φ(26) = 12 of them. With 26 choices of β the key space is 12 · 26 = 312. Trying all 312 by machine is instantaneous, and about 20 characters of ciphertext is enough to leave only one meaningful plaintext.

18. Say the gcd condition out loud

Explain it to yourself

Textbooks state gcd(α, 26) = 1 as a condition. Conditions are easy to memorise and hard to use.

Discussion prompt

Explain, without using the word gcd, why α must share no factor with 26 — and say what would go wrong in a language with a 27-letter alphabet.

Hint: Think about what multiplying by α does to the 26 letters as a set, not to one letter at a time.

Answer:

Multiplying by α maps the 26 residues onto the multiples of α. If α and 26 share a factor d > 1, those multiples all land in the d·(something) pattern, so the image has only 26/d values — the map squashes the alphabet and cannot be undone.

Sharing no factor means the multiples of α run through all 26 residues before repeating, so the map is a shuffle rather than a squash, and a shuffle can be reversed.

With 27 letters the modulus is 27 = 3³, so the bad α are the multiples of 3 and there are φ(27) = 18 good ones. With a prime alphabet size — 29, say — every non-zero α works, because a prime shares a factor with nothing below it.

This is the first appearance of a fact the rest of the course leans on hard: arithmetic mod n is much better behaved when n is prime. Chapter 3 makes it a theorem and Chapters 9 and 10 build cryptosystems on it.

19. The Vigenère Cipher

Section

Section 2.3 · pp. 14-20

20. The Vigenère Cipher: a different shift for every position

Concept

The weakness of every cipher so far is that one plaintext letter always produces the same ciphertext letter. Vigenère's answer, from the sixteenth century, is to use a vector of shifts and cycle through it.

\[ k = (k_1, k_2, \ldots, k_n), \qquad c_i \equiv m_i + k_{\,(i \bmod n)} \pmod{26} \]

The key is usually a word, so it is easy to remember: vector gives k = (21, 4, 2, 19, 14, 17). The security rests on Eve knowing neither the keyword nor its length.

Polyalphabetic — A cipher that uses several substitution alphabets in rotation. Vigenère uses n of them, where n is the key length — which is why breaking it starts by finding n.

Figure (svg): The Vigenère key vector 21, 4, 2, 19, 14, 17 written under a plaintext, repeating once the key runs out.

Six shifts in rotation: the seventh letter is shifted by 21 again.

21. Encrypting with the keyword *vector*

Worked example

Encrypt hereishowitworks with k = (21, 4, 2, 19, 14, 17).

h = 7, shift by k₁ = 21: 7 + 21 = 28 ≡ 2 = C

Why: The first letter uses the first entry of the key.

e = 4, shift by k₂ = 4: 4 + 4 = 8 = I

Why: A different shift, so the same letter will not always give the same output.

...continue to the sixth letter s = 18, shift by k₆ = 17: 18 + 17 = 35 ≡ 9 = J

Why: The key is now exhausted.

The seventh letter h wraps back to k₁ = 21 again: 7 + 21 ≡ 2 = C

Why: This wrap is the periodicity that Kasiski's attack detects.

\[ \texttt{hereishowitworks} \;\longmapsto\; \texttt{CITXWJCSYBHNJVML} \]

Verify: the two h's gave C and C, but the two e's gave I and — later — a different letter

Why: Repeats survive only when they are the same distance apart as a multiple of the key length. That is the leak.

Figure (svg): The plaintext letter e appearing as several different ciphertext letters depending on its position under the repeating key.

With a six-letter key, e is spread over six ciphertext letters — and each of those letters also receives five other plaintext letters.

22. What the spreading does to a frequency count

Picture it

A monoalphabetic cipher preserves the shape of English. Vigenère flattens it, which is why frequency analysis alone stops working.

Figure (svg): Two histograms side by side: English plaintext letter frequencies with a tall spike at e, and the Vigenère ciphertext frequencies, which are almost level.

The letter e is spread across six different ciphertext letters, so no single letter stands out.

But flat is not random. The next three slides turn the flatness itself into the attack.

23. Where did the information go?

Hypothesis

The ciphertext frequency counts above are nearly level, and no letter dominates.

Predict first

What does the flat histogram tell you about the cipher?

  • The cipher is secure — the ciphertext is indistinguishable from random
  • The key is long, probably as long as the message
  • Several shifts are in use, and their number is what we should look for first
  • The plaintext was not English

Correct: Several shifts are in use, and their number is what we should look for first

Splitting the message into every n-th letter gives n separate shift ciphers, each of which has an unmistakable English profile.

So the problem reduces to a single number: the key length.

Why: Flatness is the signature of several shifts superimposed, not of security. Each ciphertext letter is a blend of contributions from n different plaintext letters, and averaging n copies of English flattens the profile. The flatness therefore tells us n is greater than 1 — and the whole attack is to find n and then split the ciphertext into n monoalphabetic pieces.

24. Keyword and key vector are the same object

Translation

Vigenère keys are written as words because words are memorable, but the cipher only ever sees numbers.

Match the pairs

  • k1. cab
  • k2. key
  • k3. zoo
  • k4. aaa
  • v1. (2, 0, 1)
  • v2. (10, 4, 24)
  • v3. (25, 14, 14)
  • v4. (0, 0, 0)

Why: Each letter is its own index: a = 0, b = 1, ..., z = 25. So cab = (2, 0, 1) and key = (10, 4, 24). The last pair is the one worth dwelling on: the keyword aaa is the all-zero vector, which is the identity — a perfectly memorable key that does not encrypt. Any keyword whose letters are all a has this problem, and more subtly, a keyword with a repeated pattern such as abab has effective length 2, not 4.

25. Kasiski's trick: slide the text over itself

Pattern

Write the ciphertext on two strips of paper, offset the second one by d places, and count the positions where the two strips show the same letter. Those are coincidences.

Step through it

Why should the count jump when d equals the key length?

  1. The ciphertext, first few letters.
  2. The same text, displaced by d = 2. Compare column by column.
  3. Mark every column where the two rows agree. At d = 2 there are 14 in the whole text.
  4. Repeat for every displacement. d = 5 gives 24 — far more than its neighbours.

Because at that displacement each letter is compared with a letter shifted by the same key entry — so you are comparing English with English, not English with a rotation of it.

26. Read the coincidence counts

Prediction

Counting coincidences at displacements 1 through 6 on the book's ciphertext gives: 14, 14, 16, 14, 24, 12.

Predict first

What is the key length?

  • 3
  • 5
  • 6
  • There is not enough evidence

Correct: 5

\[ \sum_{i=0}^{25} p_i^2 \approx 0.066 \quad \text{(English)} \qquad \sum_{i=0}^{25} \tfrac{1}{26}\cdot\tfrac{1}{26} \approx 0.038 \quad \text{(uniform)} \]

Multiples of the key length also spike, so 10 and 15 would show up too. Take the smallest displacement that stands out.

Why: Displacement 5 gives 24 coincidences against a background of 12-16. When d is the key length, like-shifted letters line up and the coincidence rate is the English rate of about 0.066; otherwise it is about 0.038, the rate for two independent uniform letters. With 326 comparisons, 0.066 × 326 ≈ 21.5, which is close to the 24 observed — while 0.038 × 326 ≈ 12.4 matches the other displacements.

Figure (svg): A bar chart of coincidence counts for displacements one through six, with displacement five standing out at twenty-four.

A displacement equal to the key length lines like-shifted letters up, so coincidences jump.

27. Why 0.066 and 0.038 are the only two numbers that matter

Cost model

The coincidence method is one probability calculation, and it is worth seeing it rather than trusting it.

Annotate

On: \( \Pr[\text{two letters agree}] = \sum_{i=0}^{25} p_i \, q_i \)

  • The frequencies of letter i in the two strips being compared.
  • If the two positions used the same key entry, both strips are English shifted equally, so the sum is Σpᵢ² ≈ 0.066.
  • If the shifts differ, the sum smears out to roughly 1/26 ≈ 0.038 — nearly half as large.
  • 0.066 against 0.038 is a factor of 1.7. Over a few hundred comparisons that is a gap no eye can miss, which is why the method works on a strip of paper.

Friedman's index of coincidence in the 1920s is this same sum, and Chapter 20 derives it again from entropy.

28. Recovering the key, one column at a time

Worked example

The key length is 5, so split the ciphertext into five columns: letters 1, 6, 11, ... form column 1, and so on. Each column is a plain shift cipher.

Count letters in column 1. G is most frequent, with J, K and C close behind.

Why: A short column makes the top letter unreliable, so test each candidate rather than taking the winner.

Test J = e: that forces a shift of 5, hence C = x — but x is rare in English, so reject.

Why: The test is not 'is e frequent' but 'does the whole implied profile look like English'.

Test K = e and C = e in the same way; both force implausibly common rare letters. Accept G = e.

Why: G = 6, e = 4, so k₁ = 6 − 4 = 2 = c.

Column 2: S occurs 12 times, G 10 times. G = e would make S = q, which cannot occur 12 times. So S = e and k₂ = 18 − 4 = 14 = o.

Why: Same argument, one column across.

Repeating for columns 3, 4 and 5 gives k = (2, 14, 3, 4, 18)

Why: As a word, that is codes.

Verify: decrypt with (2, 14, 3, 4, 18)

Why: The plaintext begins themethodusedforthepreparationandreadingofcodemessagesissimpleintheextreme — readable English, so the key is right. A wrong key produces nothing that reads.

Figure (svg): The five recovered key entries shown as numbers and as the letters of the word codes.

Four centuries of reputation, undone by counting.

29. Find the mistake in this key-length argument

Error analysis

A student writes up the Kasiski attack on a ciphertext whose coincidence counts spike at 4, 8 and 12.

Annotate

  • This is the finding that matters and the student has walked past it. The smallest displacement that spikes is the key length; 8 and 12 spike because they are multiples of it.
  • Size of spike is not the criterion, and the largest is often at a multiple because longer alignments accumulate. Position is the criterion, not height.
  • The conclusion is an artefact of where the student stopped counting. Had they tested to 16, they would have found a spike there too and concluded 16.
  • The practical cost of the error: splitting into 12 columns rather than 4 leaves each column a third as long, so the frequency counts become too noisy to read and the attack appears to fail.

The rule in one line: take the smallest displacement that spikes, then check that its multiples spike too.

30. Two of these are true of Vigenère

Two truths and a lie

Three claims about the cipher you just broke. Eliminate the false one.

Eliminate the wrong options

Which statement is true?

  • a. A Vigenère key as long as the message and never reused is unbreakable
  • b. Vigenère resists frequency analysis because the ciphertext is genuinely random
  • c. The Vigenère key space is too small to search exhaustively

Survives elimination: a

Why: A Vigenère key as long as the message, chosen at random and used once, is exactly the one-time pad of Chapter 4, and it is provably unbreakable. Everything that goes wrong with Vigenère comes from the key repeating: repetition is what creates the columns, and the columns are what get counted. Note that (c) is not merely false, it is the wrong kind of explanation — the cipher does not fall to exhaustion.

31. Substitution Ciphers

Section

Section 2.4 · pp. 20-23

32. The Substitution Cipher: any permutation at all

Concept

Drop the arithmetic. Let the key be an arbitrary permutation of the 26 letters — a lookup table with no structure to it.

\[ 26! = 403\,291\,461\,126\,605\,635\,584\,000\,000 \approx 4 \times 10^{26} \]

That is a key space far larger than DES's, which Chapter 7 will show took a dedicated machine to search. And yet a substitution cipher is a newspaper puzzle.

The reason is that the cipher is still monoalphabetic. Eve never searches the key space at all — she reads the statistics straight off the ciphertext and reconstructs the table letter by letter.

Figure (svg): A bar chart comparing the key spaces of the chapter's ciphers on a logarithmic scale, from 26 for the shift cipher up to 26 factorial for substitution.

Key-space size is not security: substitution has the largest space here and falls to a frequency count.

33. Breaking a substitution cipher without guessing a key

Worked example

Suppose a long ciphertext has these top counts: Q 13%, M 9%, Z 8%, and the digram QB is the commonest pair.

Match the frequency profile: e is 12.7% of English, so Q = e is the first hypothesis

Why: You are matching a shape, not a single letter, so a few hundred characters is plenty.

t, a, o, i, n, s, h, r fill the next band — assign the next most frequent ciphertext letters to that set, without committing to the order

Why: Individual assignments inside a band are unreliable; the band itself is not.

Use digrams: th, he, an, in, re, es are the common English pairs. If QB is commonest and Q = e, try B = s (es) or read QB as he with Q = h

Why: Digram statistics resolve exactly the ambiguity that single-letter counts leave open.

Look for one-letter words (a, I), doubled letters (ll, ee, ss) and the pattern of a three-letter word ending in e (the)

Why: Structure in the language does the rest of the work.

Verify: read the partly-filled plaintext aloud

Why: Once about eight letters are right the remaining text becomes guessable by eye, and each new letter confirms or kills the earlier guesses. That self-checking is why the attack is so fast.

Figure (svg): English letter frequencies as a histogram, with e, t, a, o, i, n, s, h, r marked as the band that carries most of the text.

A substitution cipher hides the letters but not the shape they make.

34. A big key space means a strong cipher

Trap

The trap

The trap. A substitution cipher has 26! ≈ 4 × 10²⁶ keys — more than an 88-bit cipher. DES has 2⁵⁶ ≈ 7 × 10¹⁶ keys, ten orders of magnitude fewer. So the substitution cipher must be the stronger of the two.

The reasoning is that security equals the cost of trying every key, so more keys means more security.

The fix

Why it fails. Exhaustive search is an upper bound on Eve's work, never a lower bound. Eve is under no obligation to use it, and against a substitution cipher she does not: she reads the frequency profile and rebuilds the key one letter at a time, never enumerating anything.

A large key space is necessary but not sufficient. It rules out one attack — brute force — and says nothing about any other.

The honest statement is: a cipher is as strong as the best attack against it, and finding that attack is the hard part. This is why Chapter 8 spends its length on AES's design rationale rather than on its key size.

Keep the counterexample handy: substitution beats DES on key count and loses to a newspaper solver.

35. Which ciphers fall to a plain frequency count?

Discrimination

The frequency attack works exactly when one plaintext letter always produces one ciphertext letter.

Sort into buckets

Sort each cipher by whether a single-letter frequency count breaks it directly.

Yes — monoalphabetic
Shift cipher; Affine cipher; General substitution cipher
No — needs more work first
Vigenère, key length 7; Vigenère, key as long as the message; Playfair
yes
Shift, affine and substitution are all one fixed letter-to-letter map, so the ciphertext frequency profile is the English profile with the labels permuted. Count and match.
no
Vigenère spreads each letter over several outputs, so you must find the key length first and then count within each column. Playfair encrypts pairs, so the right statistics are digram frequencies, not letter frequencies. And a key as long as the message leaves no statistics at all — that is Chapter 4.

36. Complete the frequency attack

Faded example

A monoalphabetic ciphertext of about 400 letters. Fill in the reasoning.

Fill in the blanks

The commonest ciphertext letter is almost certainly e. The next band — t, a, o, i, n, s, h, r — carries about 70% of English, so the next eight ciphertext letters by count map into that set, though not reliably in order. To settle the order, switch from single letters to digrams, because th, he, an, in, re and es have distinctive rates. A ciphertext letter that never neighbours the assumed vowels is probably a consonant.

Why: The attack is a cascade of increasingly specific statistics: single letters give you e and a band of eight; digrams break the band's ties; word patterns and one-letter words finish it. Each stage checks the previous one, which is why the whole procedure is self-correcting and why a wrong early guess does not sink it.

37. Sherlock Holmes and the Dancing Men

Section

Section 2.5 · pp. 23-26

38. Cryptanalysis as detective work

Concept

Conan Doyle's The Adventure of the Dancing Men has Holmes break a substitution cipher whose symbols are stick figures. The reasoning he uses is the reasoning of the previous section, done aloud.

  1. Count the symbols and assume the commonest is e
  2. Use the flags on the figures to mark word boundaries, which single-letter and short words then constrain hard
  3. Guess a word from its pattern — a five-letter word with the shape _ e _ e _ is a strong lead
  4. Exploit context: the sender's name and the recipient's name are likely to appear
  5. Confirm by prediction — write a message of your own in the cipher and see if it provokes the expected reply

Doyle's cipher is not a new system. It is a substitution cipher in fancy dress, and the story is a demonstration that a cipher's appearance of strangeness contributes nothing to its strength.

Figure (svg): A short cipher of stick figures with the commonest symbol marked as e and a word pattern picked out.

Holmes counts symbols before he interprets any of them — the same first move as the previous slide.

39. Where you have already met this reasoning

Real world

The dancing-men attack is pattern-matching against a known distribution, and it did not stay in fiction.

Discussion prompt

Name a modern system that is broken by exactly this reasoning — statistics of the plaintext leaking through a transformation that hides the values but not their pattern.

Hint: Think about what an encrypted database column looks like when the same value is encrypted the same way every time.

Answer:

Deterministic encryption of a database column. If salary is encrypted with the same key and no randomisation, equal salaries produce equal ciphertexts. Counting repeats recovers the histogram, and a public salary table finishes the job.

ECB mode, which Chapter 6 covers, is the same failure at block granularity: identical plaintext blocks produce identical ciphertext blocks, so the famous ECB-encrypted image still shows its picture.

Traffic analysis generally. The lesson is that a cipher protects the values and not the pattern of the values, and the pattern is often most of the message.

40. The Playfair Cipher

Section

Section 2.6 · pp. 26-28

41. Playfair: encrypt letters two at a time

Concept

Invented by Wheatstone around 1854, named for the Baron Playfair who lobbied for its adoption, and used by the British in the Boer War and in World War I.

The key is a word. Strip its repeated letters — playfair becomes playfir — then write it into a 5 × 5 matrix and fill the rest of the grid with the unused letters in order, treating i and j as one letter.

The point of the design is that Playfair is a digram cipher: it encrypts pairs, so a single-letter frequency count tells you nothing directly. Each plaintext letter also has only five possible ciphertext letters, which is the weakness that eventually undoes it.

Figure (svg): The five by five Playfair matrix built from the keyword playfair, with the letters m and e highlighted in the third row.

Both m and e sit in row three, so the pair me is encrypted by the same-row rule.

42. The three Playfair rules, in the order you apply them

Ranking

Given a pair of plaintext letters, exactly one of three rules fires. Put the procedure in order.

Put in order

  1. Split the text into pairs, inserting x between a doubled pair and padding the end if needed
  2. If the two letters share a row, replace each by the letter to its right, wrapping around
  3. If the two letters share a column, replace each by the letter below it, wrapping around
  4. Otherwise the pair forms a rectangle: replace each letter by the one in its own row and the other's column

Why: Pairing comes first and is not optional — a doubled letter inside a pair would break the rectangle rule, which is why an x is inserted. Then the row and column cases are checked before the general rectangle case, because the rectangle rule is degenerate when the two letters are collinear: it would map each letter to itself.

43. Encrypting *meet at the schoolhouse*

Worked example

Use the playfair matrix. First pair up the letters, inserting x to split any doubled pair.

meetattheschoolhouse → me et at th es ch ox ol ho us ex

Why: The doubled oo becomes ox, everything after it regroups, and a final x pads the last pair.

me: both m and e are in row 3 (e g h k m), so use the row rule — m wraps to e, and e moves to g → EG

Why: m is the last cell of its row, so 'to the right' wraps to the first cell.

et: e is row 3 column 1, t is row 4 column 5. A rectangle, so e takes its own row and t's column → m, and t takes its row and e's column → n → MN

Why: Each letter keeps its row and swaps its column. That is the rule in one sentence.

ol: o is row 4 column 2, l is row 1 column 2 — same column, so each moves down one, wrapping → VR

Why: o → v (row 5), l → r (row 2, wrapping past the bottom).

\[ \texttt{me et at th es ch ox ol ho us ex} \;\longmapsto\; \texttt{EG MN FQ QM KN BK SV VR GQ XN KU} \]

Verify: decrypt EG by the same row rule run backwards: E moves left to m, G moves left to e

Why: Decryption reverses each rule's direction — left instead of right, up instead of down — and the rectangle rule is its own inverse.

Figure (svg): The Playfair matrix with the rectangle for the pair e t drawn on it, showing e mapping to m and t mapping to n.

The rectangle rule: swap the columns, keep the rows.

44. Why does Playfair fall anyway?

Socratic

Playfair defeats a single-letter frequency count, and it still succumbed to ciphertext-only attacks in the field.

Discussion prompt

Two weaknesses in the design are enough to break it. What are they?

Hint: Think about what statistics still exist, and about which cells of the matrix Eve can guess before she starts.

Answer:

Digram frequencies still exist and are tabulated. The common English pairs th, he, an, in, re, es appear in the ciphertext at their usual rates, just relabelled.

Reversible pairs leak the geometry. If IG and GI are both common, then e, i, r, g probably form the corners of a rectangle in the matrix, because the rectangle rule is exactly what makes a pair and its reverse both encrypt to a reversed pair.

And the tail of the matrix is predictable. Unless the keyword is long, the last rows are just the leftover alphabet in order — u v w x z here — so Eve starts with several cells already filled.

Add the fact that each plaintext letter has only five possible ciphertext letters, and the search collapses.

45. Which rule fires for this Playfair pair?

Elimination

Using the playfair matrix, encrypt the pair hd. h is row 3 column 3; d is row 2 column 5.

Eliminate the wrong options

Which rule applies, and what is the result?

  • a. Same row — shift each right: h → k, d → i
  • b. Same column — shift each down: h → q, d → f
  • c. Rectangle — each keeps its row and takes the other's column: hd → MB
  • d. The pair is illegal and needs an x inserted

Survives elimination: c

Why: Neither letter shares a row or a column with the other, so the general rectangle rule applies: h stays in row 3 and moves to d's column 5, giving m; d stays in row 2 and moves to h's column 3, giving b. So hd → MB. Working through the three rules in order — pair up, row, column, rectangle — makes this mechanical, and the rectangle case is the one that fires most often.

46. The ADFGX Cipher

Section

Section 2.6 · pp. 28-29

47. ADFGX: fractionate, then transpose

Concept

Used by the German army in 1918. Its name comes from the five letters used as labels, chosen because they are maximally distinct in Morse code — a design decision about the channel, not the maths.

Step one puts the alphabet in a 5 × 5 matrix, labels the rows and columns A D F G X, and replaces each plaintext letter by its row label followed by its column label. This is fractionation: one letter becomes two symbols.

On its own, step one is only a disguised substitution cipher. Step two is what matters: write the result under a keyword and read it out by columns in alphabetical order — a transposition that separates the two halves of every letter and scatters them across the message.

Figure (svg): The five by five ADFGX matrix with rows and columns labelled A, D, F, G, X, showing which pair of labels encodes each letter.

Each letter becomes two label letters: its row label followed by its column label.

48. Encrypting *Kaiser Wilhelm*

Worked example

Take the matrix above and the keyword Rhein.

Fractionate: k is row X column A → XA, a is row F column F → FF, i is row G column G → GG, ...

Why: Thirteen letters become twenty-six label letters.

\[ \texttt{kaiserwilhelm} \;\longmapsto\; \texttt{XA\,FF\,GG\,FA\,AG\,DX\,GX\,GG\,FD\,XX\,AG\,FD\,GA} \]

Write the 26 symbols in rows under the keyword R H E I N

Why: Five columns, so five full rows of five plus one leftover symbol in the first column.

Reorder the columns so the keyword letters are alphabetical: E H I N R

Why: This is the transposition. Nothing is substituted here — the symbols only move.

Read down the columns in the new order: E gives FAGDF, H gives AFXFG, I gives FAXXD, N gives GGGXG, R gives XGDGAA

Why: The leftover symbol makes column R one longer, which is a detail the decrypter must reconstruct from the lengths.

\[ \texttt{FAGDFAFXFGFAXXDGGGXGXGDGAA} \]

Verify: count: 26 symbols out for 26 symbols in, and the two halves of the letter k now sit 15 places apart

Why: Fractionation plus transposition is the point: the row label and column label of a single plaintext letter end up in different columns, so no local statistic recovers either.

Figure (svg): The transposition step: the fractionated symbols written under the keyword Rhein, then the columns reordered alphabetically and read downwards.

The column that held F A G D F moves from position three to position one; reading down the sorted columns gives the ciphertext.

49. Two ideas, combined

Analogy

ADFGX is the first cipher in this chapter built out of two different kinds of operation. That combination is the shape of every modern block cipher.

Match the pairs

  • l1. Fractionation (letter → two labels)
  • l2. Columnar transposition
  • l3. The two applied together
  • l4. Changing the matrix and keyword daily
  • r1. Confusion: obscure the relation between key and ciphertext
  • r2. Diffusion: spread each plaintext symbol's influence out
  • r3. A round: substitution followed by permutation, as in DES and AES
  • r4. Key scheduling and rekeying, to limit material per key

Why: Shannon named these two ingredients confusion and diffusion in 1949, and every block cipher from DES to AES alternates them for many rounds. ADFGX does one round of each. That is why it took real effort to break and why one round is nowhere near enough — Chapter 7 will show what happens when you iterate the same idea sixteen times.

50. The Enigma Machine

Section

Section 2.7 · pp. 29-33

51. Enigma: a substitution cipher that changes every letter

Concept

A rotor machine, designed by Arthur Scherbius in the 1920s and used by Germany through World War II. Its parts, in the order the current meets them:

K — keyboard
A typewriter keyboard. Pressing a key sends current into the machine and lights a lamp for the ciphertext letter.
S — plugboard
About six pairs of plugs swap six pairs of letters, before and after the rotors. This is where most of the key space lives.
L, M, N — rotors
Three discs, 26 contacts on each face, wired across in a scrambled way. Rotor N steps one position before every letter; M and L step like an odometer.
R — reflector
A drum whose 26 contacts are wired in pairs, sending the current back through the rotors along a different path.

Because N advances before each keystroke, the substitution alphabet is different for every letter of the message. Enigma is polyalphabetic with a period of 26 × 25 × 26 = 16 900 — far beyond Vigenère's handful.

Figure (svg): The Enigma signal path: keyboard, plugboard, three rotors, reflecting drum, then back out through the rotors and plugboard to a lamp.

The current goes through the rotors, bounces off the reflector, and comes back by a different path.

52. Why the same machine both encrypts and decrypts

Worked example

Sender and receiver set identical machines to the same starting positions. The sender types plaintext and writes down the lamps; the receiver types that ciphertext and the lamps spell the plaintext. No 'decrypt' switch exists.

Lamp a and key a hang off one wire out of the plugboard; lamp h and key h off another

Why: The lamps and the keys share the machine's contacts — this is a wiring fact, not a mathematical one.

If pressing a lights h, the electrical path connects the a wire to the h wire through the rotors and reflector

Why: A path through a network of wires is undirected: it connects two contacts.

So with the rotors in that same position, pressing h must light a

Why: The path is the same path, walked the other way.

Therefore the permutation the machine applies at each step is its own inverse — an involution

Why: This is exactly the property the reflector was installed to create, and it is what makes the machine usable in the field by one operator with no mode switch.

Verify: an involution that pairs 26 contacts can never fix one

Why: Pairing up all 26 contacts leaves none over, so no letter can map to itself. Convenient — and, as the next slide shows, fatal.

Figure (svg): A panel contrasting a substitution cipher, where a letter may map to itself, with Enigma, where the reflector makes that impossible.

A design feature that looks like a strength — no letter ever encrypts to itself — is the crack the Bombe walked through.

53. The feature that broke it

Counterexample

No letter is ever encrypted as itself. The designers considered this a strength: it removes the 'obvious' weak outputs.

Discussion prompt

You are Rejewski, or later a codebreaker at Bletchley, and you suspect a message contains the word wetterbericht (weather report). How does the no-self-map property help you find where?

Hint: Slide the guessed word along the ciphertext and look for a reason to reject a position.

Answer:

Slide the crib along the ciphertext. At any alignment where a crib letter sits above the same ciphertext letter, that alignment is impossible — and you reject it without doing any cryptanalysis at all.

For a 13-letter crib, most alignments die immediately. The survivors are few, and each one becomes a testable hypothesis for the Bombe to grind through.

So the design decision that was meant to remove weak outputs instead handed the attacker a free, zero-cost filter. Chapter 14 revisits this as an example of a security 'feature' that leaks.

The general lesson: any structure you guarantee about the output is a structure the adversary can test for. A modern cipher aims to guarantee nothing at all.

54. The seven techniques side by side

Comparison

Fill the blanks. Each row is a cipher from this chapter; each column is the property that decides its fate.

Comparison matrix

CipherKeyKey spaceBroken by
Shiftone integer κ26exhaustive search
Affine(α, β), gcd(α,26)=1312search, or 2 known letters
Vigenèrea vector of n shifts26ⁿcoincidence counting, then per-column frequency
Substitutiona permutation26! ≈ 4×10²⁶letter and digram frequency
Playfaira keyed 5×5 matrix25!digram frequency and reversed pairs
ADFGXmatrix plus a keyword25! × keywordtransposition analysis with much traffic
Enigmarotor order, settings, plugboard≈ 10²³cribs, the no-self-map rule, operator error

Read the last column downwards: not one of these ciphers was broken by trying all the keys.

55. Enigma's design decisions, and what each one cost

Trade off

Fill in the blanks. Every row is a real choice the designers made, and every one bought something and paid for it.

Comparison matrix

DecisionWhat it boughtWhat it cost
A reflector, so the machine is its own inverseOne machine, one procedure, no decrypt switchno letter can encrypt to itself — a free filter for the attacker
Rotor N steps before every lettera new substitution alphabet for each letter, period 16 900predictable stepping, which the Bombe modelled directly
A plugboard with about six pairsBy far the largest share of the key spaceswaps are involutions, so a crib constrains them in pairs
Daily key sheetsLimits the traffic available under any one keyoperators under pressure reused and shortcut settings
Message keys sent twice at the startProtection against garbled receptiongave Rejewski a known relation between positions 1-4, 2-5, 3-6

Read the last column: not one entry is a mathematical weakness. Every one is a consequence of a usability decision — which is the oldest lesson in the subject.

56. Explain it to someone who has not taken the course

Explain it

A friend asks why anyone bothered with Vigenère for four hundred years if counting coincidences breaks it.

Discussion prompt

Answer in a way that is both fair to the sixteenth century and honest about the mathematics.

Hint: Separate 'nobody had found the attack' from 'the attack is hard'.

Answer:

It was genuinely hard by hand, and nobody had published the idea. Kasiski's method needs you to write the ciphertext out twice and count agreements across hundreds of positions — days of clerical work, and only worth attempting if you already suspect the answer is there.

The attack needs volume. With fifty letters of ciphertext the coincidence counts are noise. The method became practical when message traffic became heavy, which is a nineteenth-century condition, not a sixteenth-century one.

And the conceptual step is not small. Treating the ciphertext as a statistical object rather than a puzzle to be solved is the move that makes cryptanalysis a science, and Friedman's index of coincidence in the 1920s is where it gets fully formalised.

So: it was not a bad cipher for its era. It was a cipher whose security rested on nobody thinking of a particular idea — which is exactly the kind of security Kerckhoffs told us not to rely on.

57. What would you need to break this?

Missing information

You are handed 40 characters of ciphertext and told only that it came from a system in this chapter.

Discussion prompt

What is the minimum extra information that would let you make real progress, and what would still not be enough?

Hint: Ask what 40 characters can and cannot support statistically.

Answer:

Enough on its own: if you learn it is a shift cipher, 40 characters is plenty — try all 26 keys and read. If you learn it is affine, try all 312. Exhaustion works precisely because the key space is small.

Not enough: for a substitution cipher, 40 characters gives frequency counts too noisy to trust — you would be relying on word patterns and luck. For Vigenère, 40 characters cannot support coincidence counting at all: there are too few overlapping positions for the 0.066-versus-0.038 gap to show.

The general shape of the answer: statistical attacks have a data requirement, and it is a real constraint, not a formality. Changing keys often — as Enigma's daily sheets did, and as ADFGX's changing matrix did — is a defence precisely because it starves the statistics.

That is why Chapter 4's one-time pad works: a key as long as the message means there is never more than one message per key, so no statistic ever accumulates.

58. The pattern behind every break in this chapter

Pattern

Seven ciphers, seven breaks, and a single recipe underneath all of them.

  1. Find the period. How many independent alphabets are in play? One for shift, affine and substitution; n for Vigenère; 16 900 for Enigma. Kasiski's count answers this question for Vigenère; rotor stepping answers it for Enigma.
  2. Split into monoalphabetic pieces. Once the period is known, the message decomposes into that many simple ciphers.
  3. Attack each piece with statistics, not with the key space. Letter frequencies for single letters, digram frequencies for Playfair, cribs for Enigma.
  4. Use structure the designer promised you. Every guarantee — a is never A, the matrix tail is alphabetical, the key is a pronounceable word — is a filter Eve applies for free.
  5. Confirm by decrypting. English is its own checksum; a wrong key produces nothing readable.

None of the five steps is exhaustive search. That is the chapter in one line: ciphers do not fall to the count of their keys, they fall to their structure.

Figure (svg): The five-step cryptanalysis recipe drawn as a pipeline: find the period, split, apply statistics, exploit guarantees, confirm.

One recipe, applied seven times with different statistics.

59. Check: the affine key condition

Check

Work it out before you click.

Check your understanding

Which of these is a legal affine encryption key (α, β) over the 26-letter alphabet?

  • A. (13, 4)
  • B. (2, 11)
  • C. (15, 7) (correct)
  • D. (26, 3)

Answer: C

Why: α must satisfy gcd(α, 26) = 1, and 26 = 2 · 13, so α must be odd and not 13. gcd(15, 26) = 1 ✓, so (15, 7) is legal. The legal α values are exactly 1, 3, 5, 7, 9, 11, 15, 17, 19, 21, 23, 25 — twelve of them, which is φ(26).

Why A tempts people
gcd(13, 26) = 13, so 13 has no inverse mod 26. This is the exact key that sent both input and alter to ERRER.
Why B tempts people
gcd(2, 26) = 2. Any even α collapses the alphabet onto 13 values, so the map is two-to-one and cannot be decrypted.
Why D tempts people
26 ≡ 0 (mod 26), so this map sends every letter to β. It is the extreme case of the same failure.

60. Check: reading a coincidence table

Check

A ciphertext is suspected to be Vigenère. Counting coincidences at displacements 1 through 12 gives: 11, 13, 26, 12, 14, 25, 11, 13, 27, 12, 14, 24.

Check your understanding

What is the most likely key length?

  • A. 3 (correct)
  • B. 6
  • C. 9
  • D. 12

Answer: A

Why: The spikes are at displacements 3, 6, 9 and 12 — and 6, 9 and 12 are all multiples of 3. A displacement that is any multiple of the key length lines up like-shifted letters, so multiples always spike too. The key length is the smallest displacement that spikes, which is 3.

Why B tempts people
6 does spike, but only because it is a multiple of 3. Taking the first spike you notice rather than the smallest is the standard way to get a key length that is twice or three times too long.
Why C tempts people
Same reason: 9 is a multiple of 3. A key of length 9 would have shown no reason for 3 and 6 to spike.
Why D tempts people
12 is the largest multiple in the table, not the period. Reading the table right-to-left is a common slip.

61. Check: what actually broke Enigma

Check

Consider the whole system, not just the rotors.

Check your understanding

Enigma's key space is around 10²³, far beyond exhaustive search in the 1940s. What made it breakable?

  • A. The rotor wiring was mathematically weak
  • B. Predictable message content, plus the guarantee that no letter maps to itself (correct)
  • C. The key space was actually much smaller than 10²³
  • D. The plugboard added no security

Answer: B

Why: Cribs — predictable plaintext such as weather reports and stereotyped openings — combined with the no-self-map property let codebreakers reject the overwhelming majority of rotor positions with no computation, leaving a residue small enough for the Bombe. Operator errors, such as repeated message keys and lazy rotor settings, cut it further. The key space was never searched.

Why A tempts people
The rotor wirings were adequate as permutations; the machine's problem was the structure imposed around them, not the scrambling inside them.
Why C tempts people
The key space really was of that order once rotor order, ring settings and plugboard are counted. Its size simply was not the binding constraint.
Why D tempts people
The plugboard contributed the bulk of the key space and made the attack much harder — it was a genuine strengthening, just not a sufficient one.

62. Build the chapter's map

Connect it up

Before the recap, put the chapter together in your own hand. Nothing here is looked up — it is all on the previous slides.

Draw it

Draw a table with one row per cipher: shift, affine, Vigenère, substitution, Playfair, ADFGX, Enigma. Give each row three columns — (1) what the key is, (2) whether one plaintext letter always gives one ciphertext letter, (3) the single fact an attacker exploits. Then draw an arrow from each cipher to the one that fixes its weakness, and mark the one weakness in the chapter that nothing here fixes.

That last arrow has no target: every cipher in this chapter reuses a short key, and the fix is Chapter 4's one-time pad.

63. Exit ticket

Exit ticket

One question, and it is the one this chapter exists to answer.

Predict first

A colleague proposes a cipher with a 500-bit key and says it must be secure because 2⁵⁰⁰ keys cannot be searched. What is the single strongest objection?

  • 500 bits is not enough — modern systems need more
  • Key size bounds only brute force, and no cipher in this chapter fell to brute force
  • The key would be too hard to distribute
  • There is no objection; 2⁵⁰⁰ really is unsearchable

Correct: Key size bounds only brute force, and no cipher in this chapter fell to brute force

Why: Every cipher in this chapter has a key space that is large by the standards of hand computation, and every one of them fell to structure rather than to exhaustion — the substitution cipher most dramatically, with 4 × 10²⁶ keys and a newspaper-puzzle break. Key size rules out exactly one attack. The colleague has said nothing about any of the others, and the burden of proof is on the design, not on the attacker.

64. What to carry into Chapter 3

Recap

Seven ciphers, and one argument repeated seven times.

Chapter 3 next. Every argument above leaned on modular arithmetic — inverses mod 26, gcd, φ(26). Chapter 3 makes that machinery precise, and from Chapter 9 onwards it stops being a convenience and becomes the security itself.

Figure (svg): A clock face for arithmetic modulo 26 with the shift and affine maps marked on it.

Modular arithmetic is the one tool every cipher in this chapter shares.

Sources

  1. Introduction to Cryptography with Coding Theory, 3rd edition — Wade Trappe and Lawrence C. Washington — Pearson, 2020 (ISBN 978-0-13-485906-4)
  2. Chapter 2 — Classical Cryptosystems (sections 2.1-2.7) — Trappe & Washington, 3rd edition, pp. 10-39

Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108