Vigenere cipher is a polyalphabetic substitution cipher that encrypts text with a repeating keyword, shifting each letter by the alphabet position of the matching key letter. With key LEMON, the plaintext ATTACKATDAWN becomes LXFOPVEFRNHR. It is a sequence of Caesar shifts, and the key length decides how hard it is to attack.
How it works
Write the key under the plaintext and repeat it until it is as long as the message. Convert letters to numbers with A=0 to Z=25. The ciphertext letter is (plain + key) mod 26. To decrypt, subtract the key letter instead.
- Key: a word or phrase of any length. A key of length n splits the message into n interleaved Caesar ciphers, one per key position.
- Key space: a key of n letters gives 26 to the power n choices. A 5-letter key has 11,881,376, which looks large but does not protect against the attacks below.
- Tabula recta: the traditional way to do this by hand is a 26 by 26 table of shifted alphabets. Row is the key letter, column is the plaintext letter.
- Flattened letters: the same plaintext letter encrypts to different ciphertext letters, so a simple count of letter frequency no longer reveals the text directly.
This Python run encrypts and decrypts the standard LEMON example, then shows what happens when the key is only two letters long.
import string
A = string.ascii_uppercase
def vig(p, key, d=1):
return ''.join(A[(A.index(c) + d * A.index(key[i % len(key)])) % 26]
for i, c in enumerate(p))
print(vig("ATTACKATDAWN", "LEMON"))
print(vig("LXFOPVEFRNHR", "LEMON", -1))
print(vig("ATTACKATDAWN", "LE"))
LXFOPVEFRNHR
ATTACKATDAWN
LXEENOLXOEHR
How is the Vigenere cipher broken?
The Vigenere cipher is broken by first finding the key length and then solving each position as a Caesar cipher. Friedrich Kasiski published a general method in 1863 that looks for repeated ciphertext fragments and uses the gaps between them to infer the key length. Once the length is known, frequency analysis on every n-th letter recovers each key letter. The index of coincidence gives the same length estimate statistically.
Common pitfalls
- Short or repeated keys: the shorter the key, the more often it repeats. In the run above, a 2-letter key leaves visible repetition in the output. A key as long as the message and never reused is a one-time pad, which is a different system.
- Dictionary-word keys: a keyword from a word list can be tried directly against the ciphertext. Treat the key as guessable.
- Spaces and punctuation: implementations disagree on whether the key advances over skipped characters. Two tools can give different ciphertext for the same message and key.
- Confusing it with a modern cipher: it gives no integrity and no protection against known plaintext. Use AES for real data.
- Mixing up Vigenere and Autokey: they share the table but differ in how the key is extended, so the same inputs give different output.
Related terms
- Caesar Cipher — the single-shift cipher that Vigenere repeats with a different shift per position.
- Autokey Cipher — extends the key with the message itself instead of repeating it.
- Playfair Cipher — a digraph cipher from a different family of classical ciphers.
- ROT13 — a fixed shift of 13 and the simplest relative.
See also