Cryptography Worldcryptographyworld.com

Section 2 — Polyalphabetic

The table that held for three centuries

A grid of shifted alphabets with a repeating keyword defeated frequency analysis and was called indecipherable for three hundred years — until someone noticed that the keyword repeats, and that the repetition shows.

SectionPolyalphabetic
RegisterEntry 5 of 22
LengthLong read
Hands feeding paper into a vintage teal typewriter beside a stack of typed pages
Many alphabets under one keyword — the defence that held longest, and the one that fell to arithmetic.Photo: Ron Lach / Pexels

A cipher that wore its invulnerability on its sleeve

For most of the sixteenth century, frequency analysis was the cryptanalyst's reliable instrument. Arab scholars had understood it as early as the ninth century, and by the Renaissance any patient reader with a pencil could pull apart a simple substitution cipher — counting letters, comparing tallies, guessing the commonest. The defence against that attack was obvious in principle: use more than one alphabet, so that the same plaintext letter lands on a different ciphertext letter each time it appears. What took until the mid-1500s was a workable system for doing so with a short, memorable key.

The construction usually credited to Blaise de Vigenère, though he owed enormous debts to Giovanni Battista Bellaso and earlier work by Johannes Trithemius, is a square table: twenty-six rows of the Latin alphabet, each shifted one position to the left of the row above. To encipher, the sender picks a keyword and writes it repeatedly over the plaintext. Each keyword letter selects a row of the table; the plaintext letter selects the column. The intersection is the ciphertext. The receiver, who knows the keyword, simply reverses the lookup. Nothing about the system is mathematically deep, but the effect is striking: the letter E, the most common in English, might emerge as H, P, Z, or any other letter depending on which keyword letter sits above it at each position. Count the ciphertext letters and the fingerprint frequency analysis was supposed to detect is smeared flat.

Open book with columns of coded letter groups beside a typewriter and pen
A sheet is used once and destroyed. Everything the system promises rests on that being done every time.Photograph — collection credit

For roughly three centuries the system held. Diplomats used it, armies used it, conspirators used it. The French called it le chiffre indéchiffrable — the indecipherable cipher — and the name stuck because, within the limits of what anyone tried, it was accurate. A monoalphabetic substitution will usually yield to a determined analyst inside an afternoon. The polyalphabetic table was a different proposition entirely, and that difference sustained a reputation few technologies of any kind maintain for so long.

What holds it up, and what wears it down

The source of the system's strength is also the source of its eventual undoing. The keyword repeats. If the keyword is five letters long, then position 1, position 6, position 11, position 16, and every fifth position after that are all enciphered by the same alphabet. The ciphertext is not a single substitution, but it is a set of interlocking single substitutions, each applied periodically. An analyst who knows — or can determine — the keyword length can slice the ciphertext into that many independent strips and attack each strip as an ordinary monoalphabetic cipher.

The question is how to find the keyword length. The answer, worked out independently in the nineteenth century, comes from the way coincidences cluster in the ciphertext. When two identical sequences of plaintext happen to fall at positions that are multiples of the keyword length apart, they are enciphered by exactly the same sequence of keyword letters, and so they produce identical sequences of ciphertext. These repeated sequences are not accidents; they are the keyword's shadow cast across the message. Measure the distances between them, find their greatest common factors, and the keyword length declares itself.

Charles Babbage, better remembered for mechanical computation, cracked this open in the 1840s. Friedrich Kasiski, a Prussian infantry officer, arrived at the same method independently and published it in 1863. The technique that carries Kasiski's name reduced the indecipherable cipher to a series of manageable subproblems: find the period, divide the text, apply frequency analysis to each slice. A cipher that had worn its invulnerability like armour turned out to be a monoalphabetic cipher in disguise — several of them, stacked together, but each strip long enough to betray itself.

A printed cipher table with hand-ruled columns
The keyword selects the row, the plaintext letter selects the column, and the intersection is sent.Photo: Lucas Andrade / Pexels

There is something almost archaeological about the Kasiski test. The analyst does not need to guess the keyword. The keyword announces its own length through the pattern of repetitions it leaves in the ciphertext, because every time two matching plaintext fragments align with matching keyword phases, the ciphertext obliges by repeating too. The more text available, the more repetitions appear, and the more confidently the period emerges from the noise.

Three centuries, then a morning's work

What took so long? Partly the problem of data: short messages produce few repetitions, making the attack unreliable. Partly the absence of the right framing — frequency analysis of ciphertext strips requires someone to think about stripping first, and that conceptual step was not inevitable. Partly, perhaps, the authority of a reputation. Le chiffre indéchiffrable was a phrase that closed enquiry rather than opening it. When a system is universally called unbreakable, the incentive to try breaking it diminishes, and the practical cryptanalyst turns attention to targets that seem less forbidding.

There is also something worth noting about what the system was not. It was not mathematically secure in any modern sense. It had no proof, no formal bound on the work required to break it. Its strength was entirely practical — a function of the effort required and the tools available. Once Kasiski published, the effort dropped dramatically. The same cipher that had served European diplomacy for three centuries became, within a generation, an elementary exercise in any book on the subject.

The lesson was not lost on later practitioners. One response was to make the key as long as the message, removing the periodicity that the Kasiski test exploits. A key that does not repeat cannot produce the repeated ciphertext sequences that betray it. That reasoning, pressed to its logical conclusion, produces the running key — a key drawn from a long text rather than a short word — and eventually the one-time pad, where the key is random, as long as the message, and never reused. But those solutions import their own problems, chiefly of key distribution, and none of them enjoyed anything like three centuries of practical service before collapsing.

A thick codebook open at a page of word groups
A codebook replaces whole phrases with groups. Its security lasts exactly as long as the last copy stays in the room.Photograph — collection credit

The Vigenère table endures in the history of the subject as a demonstration that a strong reputation is not the same as a strong cipher. The keyword-repeats flaw was structural, present from the first message ever sent under the system. No one found it for three centuries not because the cipher hid it well but because no one looked in quite the right way. The moment Kasiski framed the right question, the answer was straightforward. That is usually how it goes.