Cryptography Worldcryptographyworld.com

Section 2 — Polyalphabetic

Autokey

Letting the message extend its own key.

SectionPolyalphabetic
RegisterEntry 8 of 22
LengthShort entry
Handwritten song list resting on an open piano above the keys
Many alphabets under one keyword — the defence that held longest, and the one that fell to arithmetic.Photo: Alina Rossoshanska / Pexels

The message that carries its own key

The polyalphabetic cipher's chronic weakness is the keyword repeats. Use a short key, and the pattern cycles. Use a long one, and distribution becomes painful. The autokey idea, developed in its clearest form by Blaise de Vigenère in the sixteenth century (though Girolamo Cardano had sketched something similar earlier), attacks that problem directly: after the priming key runs out, the plaintext itself continues as the key.

The mechanics are straightforward. Suppose the primer is a single word — say, GOLD. The encipherer keys the first four letters against those four characters, then shifts each subsequent plaintext letter by the value of the plaintext letter that preceded it. Because natural language is effectively unlimited, the key never cycles. The repetition that frequency analysis exploits in short-keyword Vigenère simply does not arise.

A reel of punched paper tape on a bench
Teleprinter traffic is enciphered character by character as the tape runs, with no operator between the two.Photo: Nikita Korchagin / Pexels

That is the promise. The failure is subtler. Natural language is not random. English plaintext drifts toward certain letters — E, T, A — and that bias propagates directly into the key stream, because the key is the plaintext. An analyst who guesses the primer length can, with enough ciphertext, apply statistical methods to the key stream itself and recover the underlying text. The autokey cipher is harder to crack than a short repeating keyword, but it is not a different class of security. Its vulnerability is the non-randomness of the message it conscripts as a key.

A variant attributed more precisely to Vigenère runs the ciphertext back as the key rather than the plaintext. This ciphertext autokey has the advantage that errors do not propagate in the same way, but it offers no stronger statistical resistance: the ciphertext, derived from biased plaintext through a structured transformation, retains exploitable patterns.

A single rotor wheel showing its contacts, macro
Twenty-six pins on one face, twenty-six plates on the other, and a single fixed permutation between them.

Autokey schemes appear in various diplomatic and military contexts into the early twentieth century, generally in combination with other measures. They represent a genuine insight — the key and the message should not be independent — but fall short of the conclusion that insight demands: the key must be as long as the message, truly random, and used once only.

A telegram form filled in groups of five letters
Traffic handed to a commercial telegraph office was copied as routine, and the copies were kept.Photo: Bastian Riccardi / Pexels