Cryptography Worldcryptographyworld.com

Section 2 — Polyalphabetic

The keyword repeats

The Vigenère cipher survived three centuries not because the flaw was hidden, but because nobody looked in the right place.

SectionPolyalphabetic
RegisterEntry 6 of 22
LengthShort entry
Typewriter paper reads "turn the page" above the black and red ink ribbon
Many alphabets under one keyword — the defence that held longest, and the one that fell to arithmetic.Photo: https://kaboompics.com/ / Pexels

The crack in the foundation

The polyalphabetic table promised to defeat frequency analysis by cycling through multiple alphabets: each letter in the plaintext was shifted by the corresponding letter of a keyword, and the keyword repeated from the beginning whenever it ran out. ATTACK enciphered with the key CAT becomes CTMCCD — the two Ts land in different alphabets and emerge as different ciphertext letters. The fingerprint, it seemed, was erased.

The repetition that made the system work was also the thing that broke it. Once the key resets, an identical stretch of plaintext will produce an identical stretch of ciphertext. A phrase like "the general" appearing twice in a document, if it happens to fall at the same position relative to the repeating keyword, will encrypt identically both times. That repeated block in the ciphertext is a signpost: the distance between the two occurrences is a multiple of the keyword length.

A rotor machine with its cover off and wiring visible
The wiring inside each wheel is the machine’s only real secret, and it is identical in every machine of the series.Photo: Lech Pierchała / Pexels

Charles Babbage worked this out in the early 1850s. Friedrich Kasiski published the same method independently in 1863, and his name stuck to it. The Kasiski examination is straightforward: hunt for repeated sequences of three or more ciphertext letters, measure the gaps between them, and take the greatest common divisor. The keyword length falls out of the arithmetic. Once an analyst knows the keyword length — say, six — the ciphertext breaks into six independent streams, each enciphered with a single fixed shift. Each stream is then a simple Caesar cipher, defeatable in an afternoon by frequency analysis.

What is striking is how long this took. The cipher had been in circulation since the sixteenth century, and the table's reputation as le chiffre indéchiffrable — the indecipherable cipher — persisted because the flaw required a new question: not "what alphabet was used here?" but "where does the key restart?" That is a question about structure, not about letter counts, and it needed a structural answer.

A telegram form filled in groups of five letters
Traffic handed to a commercial telegraph office was copied as routine, and the copies were kept.Photo: Bastian Riccardi / Pexels

The lesson generalises. Every cipher that uses a short repeating key inherits this vulnerability, regardless of how complex the substitution within one key period becomes. Complexity inside the period is not the same as randomness across the full message. Length of key matters enormously; a keyword of two letters is almost immediately transparent, while a keyword as long as the message would be unbreakable — which is exactly the logic that leads, eventually, to the one-time pad.

The keyword repeats, and repetition is always an opening. Kasiski's insight required no algebra, no machinery, and no insider knowledge — only the thought that identical outputs imply identical inputs, and the patience to measure the gaps.

A reel of punched paper tape on a bench
Teleprinter traffic is enciphered character by character as the tape runs, with no operator between the two.Photo: Nikita Korchagin / Pexels