Cryptography Worldcryptographyworld.com

Section 1 — Substitution

Homophones

Several symbols for one common letter, to flatten the fingerprint.

SectionSubstitution
RegisterEntry 4 of 22
LengthShort entry
A man examines coded symbol charts with a magnifying glass while writing in a notebook at a desk
Everything in this section replaces one symbol with another and leaves the language underneath intact.Photo: cottonbro studio / Pexels

One letter, many faces

When a cryptanalyst attacks a simple substitution cipher, the work is almost mechanical. Count the symbols, rank them by frequency, and map the most common symbol onto the most common letter in the language. The fingerprint of English — or French, or Italian — survives the substitution intact, and the cipher collapses in an afternoon.

The obvious counter-move is to give a common letter more than one symbol. Encrypt the letter E sometimes as 7, sometimes as 23, sometimes as &, and spread its frequency across several bins. The statistical peak flattens. The analyst's ranked list becomes noise. These multiple stand-ins are called homophones — a term borrowed from linguistics, where it means two words that sound alike; here, it means two or more ciphertext symbols that mean the same plaintext letter.

A single rotor wheel showing its contacts, macro
Twenty-six pins on one face, twenty-six plates on the other, and a single fixed permutation between them.

The idea is old. A Mantuan document from 1401, sometimes cited as one of the earliest European cipher manuscripts, already shows a rudimentary homophonic alphabet. By the sixteenth century, the technique was a standard tool in the diplomatic ciphers of Italian city-states and the Spanish and French courts. Secretaries assigned two, three, or four cipher symbols to E, T, A, and other high-frequency letters, leaving rarer letters a single symbol each. The assignment was written into a cipher key distributed to both ends of the correspondence — a key that, if captured, collapsed the whole system at once.

Used carefully, homophones do genuine damage to a frequency attack. A cryptanalyst who expects E to dominate now finds several symbols tied for the lead, none of them clearly identifying themselves. The more symbols assigned to common letters, and the more evenly an encipherer distributes them, the flatter the frequency histogram becomes. If the distribution were perfectly uniform — every symbol appearing equally often across a long message — frequency analysis in its basic form would yield nothing.

A reel of punched paper tape on a bench
Teleprinter traffic is enciphered character by character as the tape runs, with no operator between the two.Photo: Nikita Korchagin / Pexels

The catch is that perfectly uniform distribution requires the encipherer to track every choice consciously, rotating through alternatives with discipline. In practice, operators fell into habits. One symbol for E drifted into heavy use; the others sat idle. The histogram recovered its peaks, and the protection evaporated. The cipher had also grown more complex to use without becoming proportionally harder to break. That imbalance — usability cost against security gain — is the persistent tension in every homophonic scheme.

Homophones never disappeared entirely. Later nomenclators often incorporated them for their most common letters. And the underlying intuition — that a cipher should hide statistical structure, not just replace symbols — points directly toward the more systematic solutions that followed: polyalphabetic schemes, running keys, and eventually the machinery of the twentieth century. Homophones were an intelligent patch. The flaw they addressed was real; the patch was just never quite large enough.

A rotor machine with its cover off and wiring visible
The wiring inside each wheel is the machine’s only real secret, and it is identical in every machine of the series.Photo: Lech Pierchała / Pexels