Cryptography Worldcryptographyworld.com

Section 2 — Polyalphabetic

Running key

Using a book instead of a word, and why that is better but still not enough.

SectionPolyalphabetic
RegisterEntry 7 of 22
LengthShort entry
Close-up of a vintage black Mercedes typewriter with round keys on a wooden desk
Many alphabets under one keyword — the defence that held longest, and the one that fell to arithmetic.Photo: Sebastian Luna / Pexels

A book instead of a keyword, and why it still falls short

The weakness of the Vigenère table is repetition: a short keyword cycles, and that cycle is findable. The obvious fix is to make the key as long as the message. Use a page from a shared book, start at an agreed line, and the key never repeats within any single message. This is the running-key cipher, and it was a serious refinement.

The mechanics are identical to Vigenère — each plaintext letter is shifted by the corresponding key letter — but the key material is a stretch of natural prose rather than a recycled word. Two correspondents with the same edition of, say, a legal dictionary or a Bible verse agree on a starting point; one enciphers, the other deciphers. No short cycle, no Kasiski examination to exploit.

A thick codebook open at a page of word groups
A codebook replaces whole phrases with groups. Its security lasts exactly as long as the last copy stays in the room.Photograph — collection credit

The trouble is that both the plaintext and the key are natural language, and natural language is not random. Both streams carry the statistical fingerprint described by frequency analysis. A skilled analyst attacking a running-key ciphertext can work simultaneously on what the key might be and what the plaintext might be, using each hypothesis to constrain the other. Where a common English digraph appears in the ciphertext, it is most likely produced by two common sequences — and there are not many candidates. The mutual constraint collapses the search space far faster than brute force.

This attack, developed in detail by cryptanalysts in the nineteenth century, means the running key is not remotely comparable to the one-time pad. The pad's key is genuinely random; a book page is not. Predictable letter distributions in the key are the lever that breaks the system.

A sealed envelope with a signature across the flap
A signature across the flap proves the envelope was not opened. It says nothing about whether the contents were read.Photo: Melike B / Pexels

The running-key cipher nonetheless had practical appeal: it required nothing but two copies of a commonly owned text, left no special cipher apparatus to be found, and was far stronger than anything with a short repeating keyword. It was used. It was also read, by analysts who understood that natural language, wherever it appears — plaintext or key — always leaves a fingerprint.

A printed cipher table with hand-ruled columns
The keyword selects the row, the plaintext letter selects the column, and the intersection is sent.Photo: Lucas Andrade / Pexels