Glossary

Autokey Cipher

Autokey cipher is a polyalphabetic substitution cipher in which the key stream is a short starting keyword followed by the plaintext itself. Because the key does not repeat inside one message, it avoids the repeating-key weakness of the Vigenere cipher, but it is still a classical cipher and is not secure by modern standards.

How it works

Choose a primer keyword such as KILT. Write it, then append the plaintext letters to build a key as long as the message. Each plaintext letter is shifted by the matching key letter, exactly as in Vigenere: ciphertext = (plain + key) mod 26 with A=0 to Z=25.

  • Encrypting: for MEETATTHEFOUNTAIN with primer KILT, the key stream is KILTMEETATTHEFOUN. The first four letters come from the primer, and the rest is the message shifted along.
  • Decrypting: the receiver knows only the primer. After decrypting the first four letters, those plaintext letters become the next four key letters, and so on. Decryption reveals the key as it goes.
  • Key space: the primer is the only secret. A primer of n letters has 26 to the power n possibilities.
  • Variant: a ciphertext-autokey uses previous ciphertext letters as the key instead. The text-autokey described here is the form most puzzle sites use.

The run below encrypts and decrypts the KILT example, and shows a second key and message.

import string
A = string.ascii_uppercase
def auto(p, key, d=1):
    out = []; ks = key
    for i, c in enumerate(p):
        o = A[(A.index(c) + d * A.index(ks[i])) % 26]
        out.append(o)
        ks += c if d == 1 else o
    return ''.join(out)

e = auto("MEETATTHEFOUNTAIN", "KILT")
print(e)
print(auto(e, "KILT", -1))
print(auto("ATTACKATDAWN", "LEMON"))
WMPMMXXAEYHBRYOCA
MEETATTHEFOUNTAIN
LXFOPKTMDCGN

Notice that LEMON with ATTACKATDAWN starts like the Vigenere result (LXFOP) and then diverges at the sixth letter, where Vigenere repeats the key and Autokey uses the message.

Is the Autokey cipher more secure than Vigenere?

Autokey is slightly stronger than Vigenere because the key does not repeat, so the Kasiski examination and key-length tests no longer apply directly. It can still be broken. An attacker guesses a likely word in the plaintext, and every correct guess reveals more key letters, which in turn reveal more plaintext. The primer is also short and can be found by trying common words.

Common pitfalls

  • One wrong letter spoils the rest: because decryption feeds each decrypted letter into the key, a single transcription error corrupts every later character.
  • Assuming a repeating key: if you decrypt with Vigenere logic, only the first primer-length letters come out right.
  • Different alphabets: tools differ in how they treat spaces and punctuation. Strip them from the plaintext before building the key, or both sides will disagree.
  • Using it for secrets: it has no integrity check and falls to known-plaintext guesses. Use AES for real data.

Related terms

  • Vigenere Cipher — the repeating-key cipher that Autokey modifies.
  • Caesar Cipher — each position is still one Caesar shift.
  • Playfair Cipher — another classical cipher, working on letter pairs.
  • ASCII — letter codes used when implementing the shifts.

See also