Information SecurityUnit 313 min read

Classical Cryptography: Ciphers, Codes & Steganography

Unit 3 of Information Security explores the foundations of cryptography—substitution ciphers (Caesar, Vigenère), transposition methods, steganography, and their mathematical underpinnings—with real-world examples from eSewa’s transaction logs and Ncell’s SMS-based authentication.

TAKEAWAYS:

  • Classical ciphers rely on substitution (replacing symbols) or transposition (rearranging symbols) to obscure messages, with Caesar and Vigenère being the most studied.
  • Polyalphabetic ciphers (like Vigenère) break single-letter frequency analysis by using multiple substitution keys, but Kasiski’s test can expose their periodicity.
  • Steganography hides messages within innocuous carriers (images, audio) by altering least significant bits (LSB)—unlike cryptography, it denies the existence of a secret message.
  • Kerckhoffs’s principle states that a cipher’s security must rely on the key, not secrecy of the algorithm (e.g., Caesar cipher’s shift value).
  • Worked examples tie to real scenarios: encoding an eSewa transaction PIN (Caesar), masking a Khalti OTP in an image (steganography), or analyzing Ncell’s SMS routing (transposition).
  • Weaknesses of classical ciphers (frequency analysis, brute-force attacks) led to modern cryptography, but they remain foundational for understanding key distribution and authentication.

1. Introduction to Classical Cryptography

Classical cryptography predates computers and relies on manual methods to conceal messages. It is divided into two main categories:

  • Ciphers: Transform plaintext into ciphertext using reversible algorithms (e.g., Caesar cipher).
  • Codes: Replace words/symbols with predefined substitutes (e.g., military codes).

Why study classical ciphers? They teach core principles like confusion (hiding relationships between plaintext and ciphertext) and diffusion (spreading statistical properties). Modern cryptography builds on these ideas but uses computational hardness (e.g., RSA, AES).


2. Substitution Ciphers

Substitution ciphers replace each symbol (letter, digit) in the plaintext with another symbol. They are classified as:

  • Monalphabetic: Single substitution table (e.g., Caesar cipher).
  • Polyalphabetic: Multiple substitution tables (e.g., Vigenère cipher).

2.1 Caesar Cipher

How it works:

  • Shifts each letter in the plaintext by a fixed number (k) down the alphabet.
  • Example: k=3, A→D, B→E, ..., Z→C.

Mathematical representation: For a plaintext letter P and ciphertext C:

Worked Example: eSewa PIN Encoding Suppose eSewa uses a Caesar cipher with k=5 to encode a 4-digit PIN for internal logs.

  • Plaintext PIN: 1234
  • Convert digits to letters (A=0, B=1, ..., I=8, J=9): 1→B, 2→C, 3→D, 4→E → Plaintext: BCDE
  • Apply k=5: B→G, C→H, D→I, E→J → Ciphertext: GHIJ
  • Final encoded PIN: 6789 (G=6, H=7, I=8, J=9).

Weaknesses:

  • Frequency analysis: Letters like E in English appear most often. An attacker can guess k by comparing ciphertext frequencies to known plaintext statistics.
  • Brute-force: Only 25 possible keys (k=1 to 25).

stateDiagram-v2
    [*] --> Plaintext: "BCDE"
    Plaintext: "BCDE" --> CaesarShift: "Shift +5"
    CaesarShift --> Ciphertext: "GHIJ"
    Ciphertext: "GHIJ" --> Decrypt: "Shift -5"
    Decrypt --> [*]

2.2 Vigenère Cipher

How it works:

  • Uses a keyword to generate multiple Caesar shifts.
  • For each plaintext letter, the shift value is the corresponding keyword letter’s position (A=0, B=1, etc.).
  • Example: Keyword = KEY, Plaintext = ATTACKATDAWN Align keyword repeatedly: KEYKEYKEYKEYK Shifts: K=10, E=4, Y=24 → Apply to each plaintext letter.

Mathematical representation: For plaintext P_i and key K_i:

Worked Example: Khalti OTP Masking Khalti might use a Vigenère cipher to obscure OTPs in transit.

  • Plaintext OTP: 73852
  • Convert to letters: 7→H, 3→D, 8→I, 5→F, 2→C → HDIFC
  • Keyword: KHAL (repeated: KHALKHALKH)
  • Shifts: K=10, H=7, A=0, L=11
  • Ciphertext: H(7) + K(10) = Q D(3) + H(7) = K I(8) + A(0) = I F(5) + L(11) = Q C(2) + K(10) = M
  • Encoded OTP: QKIQM

Advantages over Caesar:

  • Resists frequency analysis because the same plaintext letter may encrypt to different ciphertext letters (e.g., A could become K, Q, or I depending on the key).

Weaknesses:

  • Kasiski’s test: Repeated sequences in ciphertext reveal the keyword length.
  • Brute-force: Still vulnerable if the key is short.

3. Transposition Ciphers

Transposition ciphers rearrange symbols without substitution. They preserve letter frequencies but obscure word order.

3.1 Rail Fence Cipher

How it works:

  • Write plaintext in a zigzag pattern across a fixed number of "rails," then read row by row.
  • Example (2 rails): A T T A C K A T D A W N → Rail 1: A T A A D N Rail 2: T C K T W Ciphertext: ATAA DNTK TW (spaces removed: ATAADNTKTW).

Worked Example: Ncell SMS Routing Ncell’s SMS center might use a transposition cipher to shuffle digits in routing headers to prevent eavesdropping.

  • Plaintext routing code: 1234567890
  • 3-rail cipher: Rail 1: 1 3 5 7 9 Rail 2: 2 4 6 8 Rail 3: 0 Ciphertext: 1357924680

Advantages:

  • No substitution → harder to break with frequency analysis.
  • Simple to implement manually.

Weaknesses:

  • Pattern recognition: If the number of rails is known, the ciphertext can be reconstructed.
  • No confusion: Letter frequencies remain unchanged.

3.2 Columnar Transposition

How it works:

  • Write plaintext in rows of a fixed length, then read columns in a permuted order.
  • Example: Keyword LEMON (length 5) for plaintext CRYPTOGRAPHY: Fill a 5×2 grid:
    C R Y P T
    O G R A P
    H Y
    
    Column order: L(4), E(4), M(12), O(14), N(13) → 4,4,1,1,3 → Read columns 4,4,1,1,3: P, T, C, O, Y, R, G, A, P, H.

Worked Example: Daraz Order Queue Daraz might use columnar transposition to shuffle order IDs in a database to hide high-value transactions.

  • Plaintext order IDs: ORD123 ORD456 ORD789
  • Keyword: DARAZ (length 5)
  • Fill a 5×3 grid:
    O R D 1 2 3
    O R D 4 5 6
    O R D 7 8 9
    
    Column order: D(3), A(0), R(17), Z(25), A(0) → 3,0,1,4,0 → Read columns 3,0,1,4,0: 1, O, R, 7, O → 1ORD7 O4RD2 3ORD8 9 (reconstructed as 1ORD7O4RD23ORD89).

4. Steganography: Hiding in Plain Sight

Steganography conceals messages within other data (images, audio, text) so the message’s existence is denied. Unlike cryptography, it does not encrypt—it hides.

4.1 Least Significant Bit (LSB) Method

How it works:

  • Replace the least significant bit (LSB) of a carrier’s pixels/bytes with message bits.
  • Example: Hide 101 (binary for 5) in a 24-bit RGB pixel: Original pixel: RGB(100, 150, 200) Binary: R: 1100100 G: 10010110 B: 11001000 Replace LSBs with 101000 (padded): R: 110010**1** G: 100101**0**0 B: 110010**0**0 New pixel: RGB(101, 152, 200) (visually identical).

Worked Example: Ncell Image OTP Ncell could embed a 6-digit OTP in a profile picture sent to users.

  • OTP: 123456 → Binary: 0001 0010 0011 0100 0101 0110
  • Hide in LSBs of 6 pixels in an image.

Advantages:

  • Undetectable to casual inspection.
  • No encryption needed if the carrier is trusted.

Weaknesses:

  • Compression: JPEG/PNG compression may destroy hidden data.
  • Statistical analysis: LSB changes can be detected with chi-square tests.

Original Pixel (RGB)100,150,200Modified Pixel (LSB)101,152,200
LSB Steganography: Hidden bit '1' in least significant bit (blue channel)

4.2 Other Steganography Techniques

Method Carrier Example Use Case
Audio LSB MP3/WAV files Hiding messages in Ncell ringtone files.
Text steganography Whitespace, punctuation "Meet me at 7AM" → "Meet me at** **7AM".
Protocol steganography HTTP headers Embedding data in unused header fields.

5. Cryptanalysis: Breaking Classical Ciphers

Cryptanalysis exploits weaknesses in ciphers to recover plaintext. Key techniques:

5.1 Frequency Analysis

  • How it works: Count letter frequencies in ciphertext and compare to known plaintext statistics (e.g., E is most common in English).
  • Example: In a Caesar cipher, the most frequent ciphertext letter likely decrypts to E.
03.176.359.5212.7E12.7T9.1A8.2O7.5I6.9N6.7S6.3H6.1R6D4.3
English letter frequency distribution (top 10 letters)

Worked Example: Breaking a Caesar Cipher Ciphertext: HZHUWXUH

  • Count frequencies: H=2, Z=1, U=2, W=1, X=1.
  • Assume English: E is most frequent (12.7%). H appears twice → likely E or T.
  • Try H→E (k=5): CDECDQCD → Nonsense.
  • Try H→T (k=19): ATTACKAT → Valid plaintext!

5.2 Kasiski’s Test

  • How it works: Identify repeated sequences in ciphertext to deduce the keyword length in polyalphabetic ciphers.
  • Steps:
    1. Find repeated sequences (e.g., XUH appears at positions 1 and 7).
    2. Calculate distances between sequences: 7-1=6 → possible keyword length.
    3. Test divisors of the distance (e.g., 6 → possible lengths: 1, 2, 3, 6).

6. Kerckhoffs’s Principle and Modern Relevance

Kerckhoffs’s Principle (1883):

"A cryptosystem should be secure even if everything about the system, except the key, is public."

Implications:

  • Classical ciphers fail this principle because their algorithms are easily broken (e.g., Caesar cipher’s shift is guessable).
  • Modern cryptography (AES, RSA) relies on computational hardness (e.g., factoring large primes).

Real-World Tie-In:

  • eSewa’s transaction logs use modern encryption (TLS), but understanding classical ciphers helps explain why key management is critical.
  • Ncell’s SMS authentication combines OTPs with hashing (not classical ciphers), but steganography could hide OTPs in images to evade keyloggers.

In the Real World

  1. eSewa Transaction Logs

    • Idea Used: Caesar cipher (or stronger) to obscure temporary PINs in logs.
    • How: A shifted version of the PIN is stored, and the actual PIN is derived only when needed. Attackers seeing logs would not immediately recognize the PINs.
  2. Khalti OTP Delivery

    • Idea Used: Vigenère cipher or steganography to mask OTPs in transit.
    • How: If an OTP (123456) is sent as an image, LSB steganography hides it in the image’s pixels. Even if intercepted, the OTP is invisible without extracting LSBs.
  3. Ncell SMS Routing

    • Idea Used: Transposition cipher to shuffle routing headers.
    • How: SMS centers use columnar transposition to rearrange digits in routing codes, making it harder for attackers to correlate messages to specific users.
  4. Daraz Order Processing

    • Idea Used: Columnar transposition to obscure high-value order IDs.
    • How: Orders for expensive items might have their IDs shuffled in databases, so even if a hacker accesses the database, the IDs are not in sequential order.
  5. NEPSE Stock Alerts

    • Idea Used: Steganography in audio files.
    • How: Stock traders might hide price alerts in MP3 files (e.g., "Buy NTC at 100" embedded in the LSBs of a song), sent via WhatsApp to avoid detection by monitoring tools.

Exam Tip

  1. Define and Differentiate:

    • Always start by clearly defining substitution vs. transposition ciphers and cipher vs. code.
    • Example answer starter:

      "Classical cryptography includes substitution ciphers like Caesar, which replace symbols, and transposition ciphers like rail fence, which rearrange symbols. Unlike codes, which replace entire words, ciphers operate on individual symbols."

  2. Worked Examples Are Mandatory:

    • Examiners love step-by-step traces. For Caesar/Vigenère, show:
      • Plaintext → Key → Ciphertext (with modular arithmetic).
      • For transposition, draw the grid or rail fence.
    • Pro Tip: Use Nepali words in examples (e.g., encode "सुरक्षा" in Caesar) to show cultural relevance.
  3. Weaknesses and Attacks:

    • Link each cipher to its breaking method:
      • Caesar → Frequency analysis.
      • Vigenère → Kasiski’s test.
      • Rail fence → Pattern recognition.
    • Example:

      "The Vigenère cipher’s security depends on the keyword length. If an attacker finds repeated sequences (e.g., 'XUH' appearing twice), they can apply Kasiski’s test to deduce the keyword length and then perform a known-plaintext attack."

  4. Steganography Tricks:

    • Explain LSB method with a pixel example and mention compression resistance.
    • Compare to cryptography:

      "Unlike AES, which encrypts data, steganography hides data in plain sight. For example, hiding an OTP in an image’s LSBs ensures that even if the image is intercepted, the OTP is not detectable without specialized tools."

  5. Real-World Applications:

    • Tie examples to Nepali contexts (e.g., eSewa, Khalti, Ncell) to show practical relevance.
    • Avoid generic answers like "used in military." Instead:

      "Ncell could use a transposition cipher to shuffle SMS routing codes, making it harder for attackers to map users to specific messages."

  6. Diagrams Save Marks:

    • Draw rail fence grids, Vigenère tables, or LSB pixel examples. Label every step.
    • For exams with diagram sections, sketch a Caesar shift wheel or a columnar transposition grid.
  7. Common Pitfalls:

    • Forgetting modular arithmetic: Always use mod 26 for letters.
    • Ignoring key length: Vigenère’s security hinges on the keyword length—mention this.
    • Confusing steganography with encryption: Stress that steganography hides, while cryptography obscures.

Based on the TU BIM syllabus for Information Security (IT244), unit 3.

Discussion

Loading…