Chapter 2 of Trappe & Washington: the shift, affine, Vigenère, substitution, Playfair, ADFGX and Enigma ciphers, each with its own worked encryption and its own break. Builds the frequency-analysis and coincidence-counting toolkit, and argues the chapter's thesis — that ciphers fall to structure, not to the size of their key space.
Subject: Cryptography · 64 slides · diagram-first lesson
Open the interactive version of this deck
Title
Cryptography · Chapter 2
Seven ciphers that were each state of the art, and the reasoning that broke every one
Objectives
Chapter 1 named the players. This chapter hands you their tools — and the arguments that took the tools apart. Every cipher here is symmetric: one shared key encrypts and decrypts.
gcd(α, 26) = 1 is not a technicality but the whole reason an affine cipher can be decryptedFigure (svg): A timeline of the classical ciphers in this chapter, from Caesar in 50 BC to the Enigma machine in the 1940s.
Warm-up
Kerckhoffs's principle, which Chapter 1 stated, says the adversary knows the system. Only the key is secret.
Discussion prompt
If Eve already knows you are using a shift cipher, what work is left for her to do — and how long should that work take before you would call the cipher secure?
Hint: Count the possible keys, then imagine Eve trying each one and reading the result.
Answer:
All that is left is to find the key, and for a shift cipher there are only 26 of them — including the useless key 0.
Eve tries all 26 and reads the 26 candidate plaintexts. Twenty-five of them are gibberish. That is not an attack that needs a computer; it is an attack that needs a lunch break.
So the honest measure of a cipher is not can it be broken but how much work does breaking it cost, relative to the value of the message.
Figure (svg): Alice encrypts a plaintext with a key, sends the ciphertext over a channel, and Bob decrypts with the same key; Eve watches the channel.
Section
Section 2.1 · pp. 11-12
Concept
Label the letters as integers, a = 0 through z = 25. The key is a single integer κ with 0 ≤ κ ≤ 25.
\[ \text{encrypt: } x \mapsto x + \kappa \pmod{26} \qquad \text{decrypt: } y \mapsto y - \kappa \pmod{26} \]
That is the entire system. Caesar used κ = 23, which is the same as shifting backwards by 3, because −3 ≡ 23 (mod 26).
Monoalphabetic — One fixed letter-to-letter substitution used for the whole message. Every shift cipher is monoalphabetic, which is exactly why a frequency count works on it.
Figure (svg): A cipher disc: the outer ring carries the plaintext alphabet, the inner ring the same alphabet rotated by three places.
Worked example
Encrypt gaul is divided into three parts with κ = 23. Spaces are dropped — they leak word lengths, and the recipient can put them back.
Strip the spaces: gaulisdividedintothreeparts
Why: 27 letters. Punctuation and spacing are not part of the cipher.
g = 6, and 6 + 23 = 29 ≡ 3 (mod 26), which is D
Why: The wrap-around is what makes this modular arithmetic rather than plain addition.
a = 0, and 0 + 23 = 23, which is X
Why: The beginning of the alphabet wraps to the end — this is the step people get wrong by hand.
\[ \texttt{gaulisdividedintothreeparts} \;\longmapsto\; \texttt{DXRIFPAFSFABAFKQLQEOBBMXOQP} \]
Verify: shift D back by 23: 3 − 23 = −20 ≡ 6 (mod 26) = g
Why: Decryption is the same operation with the key negated, so one routine does both jobs.
Figure (svg): Two aligned alphabets showing a shift of 23: plaintext g sits above ciphertext D, and a sits above X.
Notation
Every cipher in this course arrives as a formula like this one. Learn to read the parts before you memorise the whole.
Annotate
On: \( x \mapsto x + \kappa \pmod{26} \)
Four symbols, and only one of them is secret.
Sorting
Chapter 1 defined four attack models. They are not degrees of difficulty — they are descriptions of what Eve happens to have.
Sort into buckets
Sort each situation into the attack model it describes.
a makes the ciphertext letter be the key, because 0 + κ = κ.A makes the plaintext the negative of the key.Notice the shift cipher falls to all four, and to the weakest of them in under an hour.
Prediction
Eve learns that the plaintext letter t was encrypted to D. She knows nothing else.
Predict first
What can Eve now compute?
Correct: The key, exactly
\[ \kappa \equiv 3 - 19 \equiv -16 \equiv 10 \pmod{26} \]
And a single letter of crib is a very low bar. Military traffic in both world wars opened with predictable words.
Why: t = 19 and D = 3, so κ ≡ 3 − 19 ≡ −16 ≡ 10 (mod 26). One matched letter determines the key completely, because the key is the difference. This is why the known-plaintext model is so damaging to a monoalphabetic cipher: stereotyped openings and signatures hand Eve those pairs for free.
Edge cases
The shift cipher's key runs from 0 to 25. Two of those values deserve a second look.
Discussion prompt
What happens when κ = 0? And is κ = 13 special in any way that matters?
Hint: Write down what each one does to the letter a, and then to the whole message.
Answer:
κ = 0 is the identity. The ciphertext is the plaintext. It is a legal key that provides no encryption at all, and it is why an honest key count for the shift cipher is 25 useful keys, not 26.
κ = 13 is ROT13, and it is its own inverse: shifting by 13 twice returns you to the start, since 13 + 13 = 26 ≡ 0. That self-inverse property is why ROT13 became the Usenet convention for hiding punchlines — one routine both hides and reveals.
Neither is a security property. But both are worth noticing, because 'the key that does nothing' and 'the key that is its own inverse' are genuine failure modes in real systems: weak keys in DES (Chapter 7) are exactly the second case, and all-zero keys have shipped in production more than once.
Section
Section 2.2 · pp. 12-14
Concept
Generalise the shift by scaling first. Choose α and β and encrypt with an affine function:
\[ x \mapsto \alpha x + \beta \pmod{26}, \qquad \text{with } \gcd(\alpha, 26) = 1 \]
The shift cipher is the special case α = 1. The condition on α is not decoration — Section 3.3 shows it is exactly the condition for α to have a multiplicative inverse mod 26, and without an inverse there is no decryption.
There are 12 admissible values of α (the numbers coprime to 26) and 26 values of β, so the key space is 12 × 26 = 312.
Figure (svg): A black box labelled with the affine map, taking a plaintext letter in and producing a ciphertext letter out, with the key pair on top.
Worked example
Take α = 9, β = 2. First check the key is legal: gcd(9, 26) = 1, so 9 is invertible mod 26.
a = 0 → 9·0 + 2 = 2 = C
Why: Because a is 0, the ciphertext letter is β itself. That is the chosen-plaintext attack in one line.
f = 5 → 9·5 + 2 = 47 ≡ 21 = V
Why: 47 − 26 = 21. Both f's give V, since the map is a function.
i = 8 → 9·8 + 2 = 74 ≡ 22 = W, n = 13 → 119 ≡ 15 = P, e = 4 → 38 ≡ 12 = M
Why: Reduce mod 26 after every multiplication to keep the numbers small.
\[ \texttt{affine} \;\longmapsto\; \texttt{CVVWPM} \]
To decrypt, invert: 9·3 = 27 ≡ 1, so 9* = 3, and x ≡ 3(y − 2) ≡ 3y + 20
Why: 3 plays the role of 1/9. Finding it is the extended Euclidean algorithm of Section 3.2.
Verify: V = 21 → 3·21 + 20 = 83 ≡ 5 = f
Why: The second letter comes back as f, as it must. Decrypting the whole string returns affine.
Figure (svg): Aligned alphabets for the affine cipher 9x+2, with the letters of the word affine highlighted.
Anomaly
Someone chooses α = 13, β = 4 and encrypts two completely different words.
\[ \texttt{input} \mapsto \texttt{ERRER} \qquad \texttt{alter} \mapsto \texttt{ERRER} \]
Predict first
What has gone wrong?
Correct: 13x + 4 is not one-to-one mod 26, so decryption is impossible
13 · x mod 26 is 0 for even x and 13 for odd x. The multiplication throws away everything except the parity of the letter.
This is worth holding on to: an encryption function must be a bijection. A cipher that loses information is not a strong cipher, it is not a cipher at all.
Why: gcd(13, 26) = 13 ≠ 1, so 13 has no inverse mod 26 and the map 13x + 4 is not injective. Multiplying by 13 collapses all 26 residues onto just two values, so many plaintexts share a ciphertext and no receiver could tell which was sent. Encryption must be one-to-one, and for an affine map that is exactly the gcd condition.
Figure (svg): Two different plaintexts, input and alter, both arriving at the same ciphertext ERRER through the broken map 13x+4.
Fill the middle
You have the encryption rule and the inverse α* of α. Complete the decryption rule.
Fill in the blanks
x \equiv α* \, y - *αβ** \pmod___
Why: Start from y ≡ αx + β, subtract β to get y − β ≡ αx, then multiply both sides by α* to get αy − αβ ≡ x. Decryption is itself an affine map, with key (α, −αβ) — which is why the affine ciphers form a group under composition.
Worked example
Eve learns the plaintext starts if and the ciphertext starts PQ. In numbers: 8 ↦ 15 and 5 ↦ 16.
Write the two equations: 8α + β ≡ 15 and 5α + β ≡ 16 (mod 26)
Why: Two unknowns, two equations. This is ordinary linear algebra done in a ring instead of a field.
Subtract to eliminate β: 3α ≡ −1 ≡ 25 (mod 26)
Why: Subtracting is the whole trick — β is the same in both equations, so it vanishes.
Solve 3α ≡ 25: since 3 · 9 = 27 ≡ 1, the inverse of 3 is 9, so α ≡ 9 · 25 ≡ 225 ≡ 17
Why: 225 − 208 = 17. Check: 3 · 17 = 51 ≡ 25 ✓.
Back-substitute: β ≡ 15 − 8 · 17 = 15 − 136 = −121 ≡ 9 (mod 26)
Why: −121 + 130 = 9.
Verify: check the second pair: 5 · 17 + 9 = 94 ≡ 94 − 78 = 16 = Q
Why: Both pairs are satisfied, so the key is (α, β) = (17, 9) and the whole message is now readable.
Figure (svg): The two simultaneous congruences from the known-plaintext attack, subtracted to eliminate beta and solved for alpha.
Estimation
There are 26 choices of β, and α must be coprime to 26.
Predict first
How many keys does an affine cipher over the English alphabet have?
Correct: 12 × 26 = 312
\[ \varphi(26) = 26\left(1 - \tfrac{1}{2}\right)\left(1 - \tfrac{1}{13}\right) = 12 \]
You will meet φ again in Chapter 3 and then constantly in Chapter 9 — it is the size of the RSA exponent group.
Why: 26 = 2 · 13, so the numbers coprime to 26 are the odd numbers other than 13: that is φ(26) = 12 of them. With 26 choices of β the key space is 12 · 26 = 312. Trying all 312 by machine is instantaneous, and about 20 characters of ciphertext is enough to leave only one meaningful plaintext.
Explain it to yourself
Textbooks state gcd(α, 26) = 1 as a condition. Conditions are easy to memorise and hard to use.
Discussion prompt
Explain, without using the word gcd, why α must share no factor with 26 — and say what would go wrong in a language with a 27-letter alphabet.
Hint: Think about what multiplying by α does to the 26 letters as a set, not to one letter at a time.
Answer:
Multiplying by α maps the 26 residues onto the multiples of α. If α and 26 share a factor d > 1, those multiples all land in the d·(something) pattern, so the image has only 26/d values — the map squashes the alphabet and cannot be undone.
Sharing no factor means the multiples of α run through all 26 residues before repeating, so the map is a shuffle rather than a squash, and a shuffle can be reversed.
With 27 letters the modulus is 27 = 3³, so the bad α are the multiples of 3 and there are φ(27) = 18 good ones. With a prime alphabet size — 29, say — every non-zero α works, because a prime shares a factor with nothing below it.
This is the first appearance of a fact the rest of the course leans on hard: arithmetic mod n is much better behaved when n is prime. Chapter 3 makes it a theorem and Chapters 9 and 10 build cryptosystems on it.
Section
Section 2.3 · pp. 14-20
Concept
The weakness of every cipher so far is that one plaintext letter always produces the same ciphertext letter. Vigenère's answer, from the sixteenth century, is to use a vector of shifts and cycle through it.
\[ k = (k_1, k_2, \ldots, k_n), \qquad c_i \equiv m_i + k_{\,(i \bmod n)} \pmod{26} \]
The key is usually a word, so it is easy to remember: vector gives k = (21, 4, 2, 19, 14, 17). The security rests on Eve knowing neither the keyword nor its length.
Polyalphabetic — A cipher that uses several substitution alphabets in rotation. Vigenère uses n of them, where n is the key length — which is why breaking it starts by finding n.
Figure (svg): The Vigenère key vector 21, 4, 2, 19, 14, 17 written under a plaintext, repeating once the key runs out.
Worked example
Encrypt hereishowitworks with k = (21, 4, 2, 19, 14, 17).
h = 7, shift by k₁ = 21: 7 + 21 = 28 ≡ 2 = C
Why: The first letter uses the first entry of the key.
e = 4, shift by k₂ = 4: 4 + 4 = 8 = I
Why: A different shift, so the same letter will not always give the same output.
...continue to the sixth letter s = 18, shift by k₆ = 17: 18 + 17 = 35 ≡ 9 = J
Why: The key is now exhausted.
The seventh letter h wraps back to k₁ = 21 again: 7 + 21 ≡ 2 = C
Why: This wrap is the periodicity that Kasiski's attack detects.
\[ \texttt{hereishowitworks} \;\longmapsto\; \texttt{CITXWJCSYBHNJVML} \]
Verify: the two h's gave C and C, but the two e's gave I and — later — a different letter
Why: Repeats survive only when they are the same distance apart as a multiple of the key length. That is the leak.
Figure (svg): The plaintext letter e appearing as several different ciphertext letters depending on its position under the repeating key.
Picture it
A monoalphabetic cipher preserves the shape of English. Vigenère flattens it, which is why frequency analysis alone stops working.
Figure (svg): Two histograms side by side: English plaintext letter frequencies with a tall spike at e, and the Vigenère ciphertext frequencies, which are almost level.
But flat is not random. The next three slides turn the flatness itself into the attack.
Hypothesis
The ciphertext frequency counts above are nearly level, and no letter dominates.
Predict first
What does the flat histogram tell you about the cipher?
Correct: Several shifts are in use, and their number is what we should look for first
Splitting the message into every n-th letter gives n separate shift ciphers, each of which has an unmistakable English profile.
So the problem reduces to a single number: the key length.
Why: Flatness is the signature of several shifts superimposed, not of security. Each ciphertext letter is a blend of contributions from n different plaintext letters, and averaging n copies of English flattens the profile. The flatness therefore tells us n is greater than 1 — and the whole attack is to find n and then split the ciphertext into n monoalphabetic pieces.
Translation
Vigenère keys are written as words because words are memorable, but the cipher only ever sees numbers.
Match the pairs
Why: Each letter is its own index: a = 0, b = 1, ..., z = 25. So cab = (2, 0, 1) and key = (10, 4, 24). The last pair is the one worth dwelling on: the keyword aaa is the all-zero vector, which is the identity — a perfectly memorable key that does not encrypt. Any keyword whose letters are all a has this problem, and more subtly, a keyword with a repeated pattern such as abab has effective length 2, not 4.
Pattern
Write the ciphertext on two strips of paper, offset the second one by d places, and count the positions where the two strips show the same letter. Those are coincidences.
Step through it
Why should the count jump when d equals the key length?
Because at that displacement each letter is compared with a letter shifted by the same key entry — so you are comparing English with English, not English with a rotation of it.
Prediction
Counting coincidences at displacements 1 through 6 on the book's ciphertext gives: 14, 14, 16, 14, 24, 12.
Predict first
What is the key length?
Correct: 5
\[ \sum_{i=0}^{25} p_i^2 \approx 0.066 \quad \text{(English)} \qquad \sum_{i=0}^{25} \tfrac{1}{26}\cdot\tfrac{1}{26} \approx 0.038 \quad \text{(uniform)} \]
Multiples of the key length also spike, so 10 and 15 would show up too. Take the smallest displacement that stands out.
Why: Displacement 5 gives 24 coincidences against a background of 12-16. When d is the key length, like-shifted letters line up and the coincidence rate is the English rate of about 0.066; otherwise it is about 0.038, the rate for two independent uniform letters. With 326 comparisons, 0.066 × 326 ≈ 21.5, which is close to the 24 observed — while 0.038 × 326 ≈ 12.4 matches the other displacements.
Figure (svg): A bar chart of coincidence counts for displacements one through six, with displacement five standing out at twenty-four.
Cost model
The coincidence method is one probability calculation, and it is worth seeing it rather than trusting it.
Annotate
On: \( \Pr[\text{two letters agree}] = \sum_{i=0}^{25} p_i \, q_i \)
Friedman's index of coincidence in the 1920s is this same sum, and Chapter 20 derives it again from entropy.
Worked example
The key length is 5, so split the ciphertext into five columns: letters 1, 6, 11, ... form column 1, and so on. Each column is a plain shift cipher.
Count letters in column 1. G is most frequent, with J, K and C close behind.
Why: A short column makes the top letter unreliable, so test each candidate rather than taking the winner.
Test J = e: that forces a shift of 5, hence C = x — but x is rare in English, so reject.
Why: The test is not 'is e frequent' but 'does the whole implied profile look like English'.
Test K = e and C = e in the same way; both force implausibly common rare letters. Accept G = e.
Why: G = 6, e = 4, so k₁ = 6 − 4 = 2 = c.
Column 2: S occurs 12 times, G 10 times. G = e would make S = q, which cannot occur 12 times. So S = e and k₂ = 18 − 4 = 14 = o.
Why: Same argument, one column across.
Repeating for columns 3, 4 and 5 gives k = (2, 14, 3, 4, 18)
Why: As a word, that is codes.
Verify: decrypt with (2, 14, 3, 4, 18)
Why: The plaintext begins themethodusedforthepreparationandreadingofcodemessagesissimpleintheextreme — readable English, so the key is right. A wrong key produces nothing that reads.
Figure (svg): The five recovered key entries shown as numbers and as the letters of the word codes.
Error analysis
A student writes up the Kasiski attack on a ciphertext whose coincidence counts spike at 4, 8 and 12.
Annotate
The rule in one line: take the smallest displacement that spikes, then check that its multiples spike too.
Two truths and a lie
Three claims about the cipher you just broke. Eliminate the false one.
Eliminate the wrong options
Which statement is true?
Survives elimination: a
Why: A Vigenère key as long as the message, chosen at random and used once, is exactly the one-time pad of Chapter 4, and it is provably unbreakable. Everything that goes wrong with Vigenère comes from the key repeating: repetition is what creates the columns, and the columns are what get counted. Note that (c) is not merely false, it is the wrong kind of explanation — the cipher does not fall to exhaustion.
Section
Section 2.4 · pp. 20-23
Concept
Drop the arithmetic. Let the key be an arbitrary permutation of the 26 letters — a lookup table with no structure to it.
\[ 26! = 403\,291\,461\,126\,605\,635\,584\,000\,000 \approx 4 \times 10^{26} \]
That is a key space far larger than DES's, which Chapter 7 will show took a dedicated machine to search. And yet a substitution cipher is a newspaper puzzle.
The reason is that the cipher is still monoalphabetic. Eve never searches the key space at all — she reads the statistics straight off the ciphertext and reconstructs the table letter by letter.
Figure (svg): A bar chart comparing the key spaces of the chapter's ciphers on a logarithmic scale, from 26 for the shift cipher up to 26 factorial for substitution.
Worked example
Suppose a long ciphertext has these top counts: Q 13%, M 9%, Z 8%, and the digram QB is the commonest pair.
Match the frequency profile: e is 12.7% of English, so Q = e is the first hypothesis
Why: You are matching a shape, not a single letter, so a few hundred characters is plenty.
t, a, o, i, n, s, h, r fill the next band — assign the next most frequent ciphertext letters to that set, without committing to the order
Why: Individual assignments inside a band are unreliable; the band itself is not.
Use digrams: th, he, an, in, re, es are the common English pairs. If QB is commonest and Q = e, try B = s (es) or read QB as he with Q = h
Why: Digram statistics resolve exactly the ambiguity that single-letter counts leave open.
Look for one-letter words (a, I), doubled letters (ll, ee, ss) and the pattern of a three-letter word ending in e (the)
Why: Structure in the language does the rest of the work.
Verify: read the partly-filled plaintext aloud
Why: Once about eight letters are right the remaining text becomes guessable by eye, and each new letter confirms or kills the earlier guesses. That self-checking is why the attack is so fast.
Figure (svg): English letter frequencies as a histogram, with e, t, a, o, i, n, s, h, r marked as the band that carries most of the text.
Trap
The trap. A substitution cipher has 26! ≈ 4 × 10²⁶ keys — more than an 88-bit cipher. DES has 2⁵⁶ ≈ 7 × 10¹⁶ keys, ten orders of magnitude fewer. So the substitution cipher must be the stronger of the two.
The reasoning is that security equals the cost of trying every key, so more keys means more security.
Why it fails. Exhaustive search is an upper bound on Eve's work, never a lower bound. Eve is under no obligation to use it, and against a substitution cipher she does not: she reads the frequency profile and rebuilds the key one letter at a time, never enumerating anything.
A large key space is necessary but not sufficient. It rules out one attack — brute force — and says nothing about any other.
The honest statement is: a cipher is as strong as the best attack against it, and finding that attack is the hard part. This is why Chapter 8 spends its length on AES's design rationale rather than on its key size.
Keep the counterexample handy: substitution beats DES on key count and loses to a newspaper solver.
Discrimination
The frequency attack works exactly when one plaintext letter always produces one ciphertext letter.
Sort into buckets
Sort each cipher by whether a single-letter frequency count breaks it directly.
Faded example
A monoalphabetic ciphertext of about 400 letters. Fill in the reasoning.
Fill in the blanks
The commonest ciphertext letter is almost certainly e. The next band — t, a, o, i, n, s, h, r — carries about 70% of English, so the next eight ciphertext letters by count map into that set, though not reliably in order. To settle the order, switch from single letters to digrams, because th, he, an, in, re and es have distinctive rates. A ciphertext letter that never neighbours the assumed vowels is probably a consonant.
Why: The attack is a cascade of increasingly specific statistics: single letters give you e and a band of eight; digrams break the band's ties; word patterns and one-letter words finish it. Each stage checks the previous one, which is why the whole procedure is self-correcting and why a wrong early guess does not sink it.
Section
Section 2.5 · pp. 23-26
Concept
Conan Doyle's The Adventure of the Dancing Men has Holmes break a substitution cipher whose symbols are stick figures. The reasoning he uses is the reasoning of the previous section, done aloud.
_ e _ e _ is a strong leadDoyle's cipher is not a new system. It is a substitution cipher in fancy dress, and the story is a demonstration that a cipher's appearance of strangeness contributes nothing to its strength.
Figure (svg): A short cipher of stick figures with the commonest symbol marked as e and a word pattern picked out.
Real world
The dancing-men attack is pattern-matching against a known distribution, and it did not stay in fiction.
Discussion prompt
Name a modern system that is broken by exactly this reasoning — statistics of the plaintext leaking through a transformation that hides the values but not their pattern.
Hint: Think about what an encrypted database column looks like when the same value is encrypted the same way every time.
Answer:
Deterministic encryption of a database column. If salary is encrypted with the same key and no randomisation, equal salaries produce equal ciphertexts. Counting repeats recovers the histogram, and a public salary table finishes the job.
ECB mode, which Chapter 6 covers, is the same failure at block granularity: identical plaintext blocks produce identical ciphertext blocks, so the famous ECB-encrypted image still shows its picture.
Traffic analysis generally. The lesson is that a cipher protects the values and not the pattern of the values, and the pattern is often most of the message.
Section
Section 2.6 · pp. 26-28
Concept
Invented by Wheatstone around 1854, named for the Baron Playfair who lobbied for its adoption, and used by the British in the Boer War and in World War I.
The key is a word. Strip its repeated letters — playfair becomes playfir — then write it into a 5 × 5 matrix and fill the rest of the grid with the unused letters in order, treating i and j as one letter.
The point of the design is that Playfair is a digram cipher: it encrypts pairs, so a single-letter frequency count tells you nothing directly. Each plaintext letter also has only five possible ciphertext letters, which is the weakness that eventually undoes it.
Figure (svg): The five by five Playfair matrix built from the keyword playfair, with the letters m and e highlighted in the third row.
Ranking
Given a pair of plaintext letters, exactly one of three rules fires. Put the procedure in order.
Put in order
Why: Pairing comes first and is not optional — a doubled letter inside a pair would break the rectangle rule, which is why an x is inserted. Then the row and column cases are checked before the general rectangle case, because the rectangle rule is degenerate when the two letters are collinear: it would map each letter to itself.
Worked example
Use the playfair matrix. First pair up the letters, inserting x to split any doubled pair.
meetattheschoolhouse → me et at th es ch ox ol ho us ex
Why: The doubled oo becomes ox, everything after it regroups, and a final x pads the last pair.
me: both m and e are in row 3 (e g h k m), so use the row rule — m wraps to e, and e moves to g → EG
Why: m is the last cell of its row, so 'to the right' wraps to the first cell.
et: e is row 3 column 1, t is row 4 column 5. A rectangle, so e takes its own row and t's column → m, and t takes its row and e's column → n → MN
Why: Each letter keeps its row and swaps its column. That is the rule in one sentence.
ol: o is row 4 column 2, l is row 1 column 2 — same column, so each moves down one, wrapping → VR
Why: o → v (row 5), l → r (row 2, wrapping past the bottom).
\[ \texttt{me et at th es ch ox ol ho us ex} \;\longmapsto\; \texttt{EG MN FQ QM KN BK SV VR GQ XN KU} \]
Verify: decrypt EG by the same row rule run backwards: E moves left to m, G moves left to e
Why: Decryption reverses each rule's direction — left instead of right, up instead of down — and the rectangle rule is its own inverse.
Figure (svg): The Playfair matrix with the rectangle for the pair e t drawn on it, showing e mapping to m and t mapping to n.
Socratic
Playfair defeats a single-letter frequency count, and it still succumbed to ciphertext-only attacks in the field.
Discussion prompt
Two weaknesses in the design are enough to break it. What are they?
Hint: Think about what statistics still exist, and about which cells of the matrix Eve can guess before she starts.
Answer:
Digram frequencies still exist and are tabulated. The common English pairs th, he, an, in, re, es appear in the ciphertext at their usual rates, just relabelled.
Reversible pairs leak the geometry. If IG and GI are both common, then e, i, r, g probably form the corners of a rectangle in the matrix, because the rectangle rule is exactly what makes a pair and its reverse both encrypt to a reversed pair.
And the tail of the matrix is predictable. Unless the keyword is long, the last rows are just the leftover alphabet in order — u v w x z here — so Eve starts with several cells already filled.
Add the fact that each plaintext letter has only five possible ciphertext letters, and the search collapses.
Elimination
Using the playfair matrix, encrypt the pair hd. h is row 3 column 3; d is row 2 column 5.
Eliminate the wrong options
Which rule applies, and what is the result?
Survives elimination: c
Why: Neither letter shares a row or a column with the other, so the general rectangle rule applies: h stays in row 3 and moves to d's column 5, giving m; d stays in row 2 and moves to h's column 3, giving b. So hd → MB. Working through the three rules in order — pair up, row, column, rectangle — makes this mechanical, and the rectangle case is the one that fires most often.
Section
Section 2.6 · pp. 28-29
Concept
Used by the German army in 1918. Its name comes from the five letters used as labels, chosen because they are maximally distinct in Morse code — a design decision about the channel, not the maths.
Step one puts the alphabet in a 5 × 5 matrix, labels the rows and columns A D F G X, and replaces each plaintext letter by its row label followed by its column label. This is fractionation: one letter becomes two symbols.
On its own, step one is only a disguised substitution cipher. Step two is what matters: write the result under a keyword and read it out by columns in alphabetical order — a transposition that separates the two halves of every letter and scatters them across the message.
Figure (svg): The five by five ADFGX matrix with rows and columns labelled A, D, F, G, X, showing which pair of labels encodes each letter.
Worked example
Take the matrix above and the keyword Rhein.
Fractionate: k is row X column A → XA, a is row F column F → FF, i is row G column G → GG, ...
Why: Thirteen letters become twenty-six label letters.
\[ \texttt{kaiserwilhelm} \;\longmapsto\; \texttt{XA\,FF\,GG\,FA\,AG\,DX\,GX\,GG\,FD\,XX\,AG\,FD\,GA} \]
Write the 26 symbols in rows under the keyword R H E I N
Why: Five columns, so five full rows of five plus one leftover symbol in the first column.
Reorder the columns so the keyword letters are alphabetical: E H I N R
Why: This is the transposition. Nothing is substituted here — the symbols only move.
Read down the columns in the new order: E gives FAGDF, H gives AFXFG, I gives FAXXD, N gives GGGXG, R gives XGDGAA
Why: The leftover symbol makes column R one longer, which is a detail the decrypter must reconstruct from the lengths.
\[ \texttt{FAGDFAFXFGFAXXDGGGXGXGDGAA} \]
Verify: count: 26 symbols out for 26 symbols in, and the two halves of the letter k now sit 15 places apart
Why: Fractionation plus transposition is the point: the row label and column label of a single plaintext letter end up in different columns, so no local statistic recovers either.
Figure (svg): The transposition step: the fractionated symbols written under the keyword Rhein, then the columns reordered alphabetically and read downwards.
Analogy
ADFGX is the first cipher in this chapter built out of two different kinds of operation. That combination is the shape of every modern block cipher.
Match the pairs
Why: Shannon named these two ingredients confusion and diffusion in 1949, and every block cipher from DES to AES alternates them for many rounds. ADFGX does one round of each. That is why it took real effort to break and why one round is nowhere near enough — Chapter 7 will show what happens when you iterate the same idea sixteen times.
Section
Section 2.7 · pp. 29-33
Concept
A rotor machine, designed by Arthur Scherbius in the 1920s and used by Germany through World War II. Its parts, in the order the current meets them:
Because N advances before each keystroke, the substitution alphabet is different for every letter of the message. Enigma is polyalphabetic with a period of 26 × 25 × 26 = 16 900 — far beyond Vigenère's handful.
Figure (svg): The Enigma signal path: keyboard, plugboard, three rotors, reflecting drum, then back out through the rotors and plugboard to a lamp.
Worked example
Sender and receiver set identical machines to the same starting positions. The sender types plaintext and writes down the lamps; the receiver types that ciphertext and the lamps spell the plaintext. No 'decrypt' switch exists.
Lamp a and key a hang off one wire out of the plugboard; lamp h and key h off another
Why: The lamps and the keys share the machine's contacts — this is a wiring fact, not a mathematical one.
If pressing a lights h, the electrical path connects the a wire to the h wire through the rotors and reflector
Why: A path through a network of wires is undirected: it connects two contacts.
So with the rotors in that same position, pressing h must light a
Why: The path is the same path, walked the other way.
Therefore the permutation the machine applies at each step is its own inverse — an involution
Why: This is exactly the property the reflector was installed to create, and it is what makes the machine usable in the field by one operator with no mode switch.
Verify: an involution that pairs 26 contacts can never fix one
Why: Pairing up all 26 contacts leaves none over, so no letter can map to itself. Convenient — and, as the next slide shows, fatal.
Figure (svg): A panel contrasting a substitution cipher, where a letter may map to itself, with Enigma, where the reflector makes that impossible.
Counterexample
No letter is ever encrypted as itself. The designers considered this a strength: it removes the 'obvious' weak outputs.
Discussion prompt
You are Rejewski, or later a codebreaker at Bletchley, and you suspect a message contains the word wetterbericht (weather report). How does the no-self-map property help you find where?
Hint: Slide the guessed word along the ciphertext and look for a reason to reject a position.
Answer:
Slide the crib along the ciphertext. At any alignment where a crib letter sits above the same ciphertext letter, that alignment is impossible — and you reject it without doing any cryptanalysis at all.
For a 13-letter crib, most alignments die immediately. The survivors are few, and each one becomes a testable hypothesis for the Bombe to grind through.
So the design decision that was meant to remove weak outputs instead handed the attacker a free, zero-cost filter. Chapter 14 revisits this as an example of a security 'feature' that leaks.
The general lesson: any structure you guarantee about the output is a structure the adversary can test for. A modern cipher aims to guarantee nothing at all.
Comparison
Fill the blanks. Each row is a cipher from this chapter; each column is the property that decides its fate.
Comparison matrix
| Cipher | Key | Key space | Broken by |
|---|---|---|---|
| Shift | one integer κ | 26 | exhaustive search |
| Affine | (α, β), gcd(α,26)=1 | 312 | search, or 2 known letters |
| Vigenère | a vector of n shifts | 26ⁿ | coincidence counting, then per-column frequency |
| Substitution | a permutation | 26! ≈ 4×10²⁶ | letter and digram frequency |
| Playfair | a keyed 5×5 matrix | 25! | digram frequency and reversed pairs |
| ADFGX | matrix plus a keyword | 25! × keyword | transposition analysis with much traffic |
| Enigma | rotor order, settings, plugboard | ≈ 10²³ | cribs, the no-self-map rule, operator error |
Read the last column downwards: not one of these ciphers was broken by trying all the keys.
Trade off
Fill in the blanks. Every row is a real choice the designers made, and every one bought something and paid for it.
Comparison matrix
| Decision | What it bought | What it cost |
|---|---|---|
| A reflector, so the machine is its own inverse | One machine, one procedure, no decrypt switch | no letter can encrypt to itself — a free filter for the attacker |
| Rotor N steps before every letter | a new substitution alphabet for each letter, period 16 900 | predictable stepping, which the Bombe modelled directly |
| A plugboard with about six pairs | By far the largest share of the key space | swaps are involutions, so a crib constrains them in pairs |
| Daily key sheets | Limits the traffic available under any one key | operators under pressure reused and shortcut settings |
| Message keys sent twice at the start | Protection against garbled reception | gave Rejewski a known relation between positions 1-4, 2-5, 3-6 |
Read the last column: not one entry is a mathematical weakness. Every one is a consequence of a usability decision — which is the oldest lesson in the subject.
Explain it
A friend asks why anyone bothered with Vigenère for four hundred years if counting coincidences breaks it.
Discussion prompt
Answer in a way that is both fair to the sixteenth century and honest about the mathematics.
Hint: Separate 'nobody had found the attack' from 'the attack is hard'.
Answer:
It was genuinely hard by hand, and nobody had published the idea. Kasiski's method needs you to write the ciphertext out twice and count agreements across hundreds of positions — days of clerical work, and only worth attempting if you already suspect the answer is there.
The attack needs volume. With fifty letters of ciphertext the coincidence counts are noise. The method became practical when message traffic became heavy, which is a nineteenth-century condition, not a sixteenth-century one.
And the conceptual step is not small. Treating the ciphertext as a statistical object rather than a puzzle to be solved is the move that makes cryptanalysis a science, and Friedman's index of coincidence in the 1920s is where it gets fully formalised.
So: it was not a bad cipher for its era. It was a cipher whose security rested on nobody thinking of a particular idea — which is exactly the kind of security Kerckhoffs told us not to rely on.
Missing information
You are handed 40 characters of ciphertext and told only that it came from a system in this chapter.
Discussion prompt
What is the minimum extra information that would let you make real progress, and what would still not be enough?
Hint: Ask what 40 characters can and cannot support statistically.
Answer:
Enough on its own: if you learn it is a shift cipher, 40 characters is plenty — try all 26 keys and read. If you learn it is affine, try all 312. Exhaustion works precisely because the key space is small.
Not enough: for a substitution cipher, 40 characters gives frequency counts too noisy to trust — you would be relying on word patterns and luck. For Vigenère, 40 characters cannot support coincidence counting at all: there are too few overlapping positions for the 0.066-versus-0.038 gap to show.
The general shape of the answer: statistical attacks have a data requirement, and it is a real constraint, not a formality. Changing keys often — as Enigma's daily sheets did, and as ADFGX's changing matrix did — is a defence precisely because it starves the statistics.
That is why Chapter 4's one-time pad works: a key as long as the message means there is never more than one message per key, so no statistic ever accumulates.
Pattern
Seven ciphers, seven breaks, and a single recipe underneath all of them.
None of the five steps is exhaustive search. That is the chapter in one line: ciphers do not fall to the count of their keys, they fall to their structure.
Figure (svg): The five-step cryptanalysis recipe drawn as a pipeline: find the period, split, apply statistics, exploit guarantees, confirm.
Check
Work it out before you click.
Check your understanding
Which of these is a legal affine encryption key (α, β) over the 26-letter alphabet?
Answer: C
Why: α must satisfy gcd(α, 26) = 1, and 26 = 2 · 13, so α must be odd and not 13. gcd(15, 26) = 1 ✓, so (15, 7) is legal. The legal α values are exactly 1, 3, 5, 7, 9, 11, 15, 17, 19, 21, 23, 25 — twelve of them, which is φ(26).
input and alter to ERRER.Check
A ciphertext is suspected to be Vigenère. Counting coincidences at displacements 1 through 12 gives: 11, 13, 26, 12, 14, 25, 11, 13, 27, 12, 14, 24.
Check your understanding
What is the most likely key length?
Answer: A
Why: The spikes are at displacements 3, 6, 9 and 12 — and 6, 9 and 12 are all multiples of 3. A displacement that is any multiple of the key length lines up like-shifted letters, so multiples always spike too. The key length is the smallest displacement that spikes, which is 3.
Check
Consider the whole system, not just the rotors.
Check your understanding
Enigma's key space is around 10²³, far beyond exhaustive search in the 1940s. What made it breakable?
Answer: B
Why: Cribs — predictable plaintext such as weather reports and stereotyped openings — combined with the no-self-map property let codebreakers reject the overwhelming majority of rotor positions with no computation, leaving a residue small enough for the Bombe. Operator errors, such as repeated message keys and lazy rotor settings, cut it further. The key space was never searched.
Connect it up
Before the recap, put the chapter together in your own hand. Nothing here is looked up — it is all on the previous slides.
Draw it
Draw a table with one row per cipher: shift, affine, Vigenère, substitution, Playfair, ADFGX, Enigma. Give each row three columns — (1) what the key is, (2) whether one plaintext letter always gives one ciphertext letter, (3) the single fact an attacker exploits. Then draw an arrow from each cipher to the one that fixes its weakness, and mark the one weakness in the chapter that nothing here fixes.
That last arrow has no target: every cipher in this chapter reuses a short key, and the fix is Chapter 4's one-time pad.
Exit ticket
One question, and it is the one this chapter exists to answer.
Predict first
A colleague proposes a cipher with a 500-bit key and says it must be secure because 2⁵⁰⁰ keys cannot be searched. What is the single strongest objection?
Correct: Key size bounds only brute force, and no cipher in this chapter fell to brute force
Why: Every cipher in this chapter has a key space that is large by the standards of hand computation, and every one of them fell to structure rather than to exhaustion — the substitution cipher most dramatically, with 4 × 10²⁶ keys and a newspaper-puzzle break. Key size rules out exactly one attack. The colleague has said nothing about any of the others, and the burden of proof is on the design, not on the attacker.
Recap
Seven ciphers, and one argument repeated seven times.
Chapter 3 next. Every argument above leaned on modular arithmetic — inverses mod 26, gcd, φ(26). Chapter 3 makes that machinery precise, and from Chapter 9 onwards it stops being a convenience and becomes the security itself.
Figure (svg): A clock face for arithmetic modulo 26 with the shift and affine maps marked on it.
Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.