Information SecurityUnit 314 min read

Classical Cryptography: Ciphers, Caesar, Vigenère, Playfair, and Frequency Analysis

Unit 3 of Information Security explores the foundations of cryptography, covering substitution and transposition ciphers, classical algorithms like Caesar and Vigenère, and their vulnerabilities to frequency analysis. It also introduces the Playfair cipher and compares classical methods with modern cryptography.

TAKEAWAYS:

  • Classical cryptography relies on substitution, transposition, or polyalphabetic techniques to conceal messages, with Caesar and Vigenère being the most famous examples.
  • Frequency analysis is a powerful attack that exploits the predictable letter distributions in natural languages (e.g., English: E, T, A, O, N).
  • The Playfair cipher improves security by encrypting pairs of letters, reducing frequency analysis risks.
  • Classical ciphers are not secure against modern computational attacks but are foundational for understanding encryption principles.
  • Real-world applications include historical military communications and educational tools for teaching cryptographic concepts.
  • Modern cryptography (e.g., AES, RSA) builds on classical ideas but uses mathematical complexity to resist attacks.

1. Introduction to Classical Cryptography

Classical cryptography refers to encryption techniques developed before the advent of computers, primarily relying on manual methods. These methods are now considered insecure by modern standards but are essential for understanding the evolution of cryptographic principles.

1.1 Why Study Classical Cryptography?

  • Historical significance: Used in wars (e.g., Julius Caesar’s cipher), diplomacy, and trade.
  • Foundational concepts: Introduces core ideas like confusion (hiding patterns) and diffusion (spreading statistical properties).
  • Educational value: Helps students recognize flaws in simple encryption and appreciate modern cryptography’s complexity.

1.2 Key Goals of Classical Ciphers

  1. Confidentiality: Ensure only authorized parties can read the message.
  2. Integrity: Detect tampering (though classical ciphers do not guarantee this).
  3. Authenticity: Verify the sender’s identity (also not fully addressed in classical methods).

2. Types of Classical Ciphers

Classical ciphers are broadly categorized into two types:

2.1 Substitution Ciphers

Replace each letter (or symbol) in the plaintext with another letter/symbol. Examples:

  • Caesar cipher (shift cipher)
  • Atbash cipher (reverse alphabet)
  • Vigenère cipher (polyalphabetic substitution)

2.2 Transposition Ciphers

Rearrange the order of letters in the plaintext without substitution. Examples:

  • Rail fence cipher
  • Columnar transposition cipher

3. Caesar Cipher: The Simplest Substitution

Named after Julius Caesar, who allegedly used it to communicate with his generals.

3.1 How It Works

  • Shift letters by a fixed number (e.g., shift +3: A→D, B→E, ..., Z→C).
  • Wrap around the alphabet (after Z, it loops back to A).

Example: Encrypt "HELLO" with shift +3

Plaintext: H E L L O Shift +3: K H O O R Ciphertext: KHOOR

Decryption

Reverse the shift (subtract 3 or shift -3): Ciphertext: K H O O R Shift -3: H E L L O Plaintext: HELLO


3.2 Strengths and Weaknesses

Advantages Disadvantages
Simple to implement Easily broken by brute force (only 25 possible shifts).
Fast for manual encryption No security against frequency analysis.
Educational tool Vulnerable to known-plaintext attacks.

3.3 Real-World Example: Caesar Cipher in eSewa

While eSewa uses modern encryption (AES-256), its OTP (One-Time Password) system for transactions can be analogized to a one-time Caesar shift for simplicity in educational contexts. For example:

  • A user might receive a 6-digit OTP (e.g., 123456).
  • The system could internally apply a dynamic Caesar shift (e.g., +7) to obscure the OTP during transmission (though in reality, OTPs are hashed, not shifted).
  • Why? To teach how simple transformations can add a basic layer of obscurity (though not real security).

4. Frequency Analysis: Breaking Substitution Ciphers

Frequency analysis exploits the fact that letters in natural languages appear with predictable frequencies.

4.1 Letter Frequencies in English

Letter Frequency (%) Letter Frequency (%)
E 12.7 T 9.1
T 9.1 A 8.2
A 8.2 O 7.5
O 7.5 I 6.9
N 6.7 ... ...

4.2 How Frequency Analysis Works

  1. Count letter occurrences in the ciphertext.
  2. Compare with known frequencies of the language.
  3. Map the most frequent ciphertext letter to 'E' (most common in English).
  4. Deduce other letters based on common digrams (e.g., "TH", "HE", "IN").

Example: Breaking a Caesar Cipher

Ciphertext: KHOOR ZRUOG Step 1: Count letters → K, H, O, R, Z, R, U, O, G. Step 2: Most frequent letters: O (2x), R (2x), K, H, Z, U, G (1x each). Step 3: Assume O → E (most frequent in English). Step 4: Shift back by 15 (since O is the 15th letter):

  • O (15) → E (5) → Shift = 15 - 5 = 10.
  • Decrypt with shift -10: K (11) → B (1), H (8) → S (18), O (15) → E (5), etc. Plaintext: BSELL HELLO → Likely "HELLO WORLD" (with a typo).

4.3 Limitations of Frequency Analysis

  • Works best on long texts (short messages may not reveal patterns).
  • Less effective on non-English languages (e.g., Nepali, Sanskrit).
  • Fails against polyalphabetic ciphers (e.g., Vigenère).

5. Vigenère Cipher: Polyalphabetic Substitution

Invented by Blaise de Vigenère in the 16th century, this cipher uses multiple Caesar shifts based on a keyword.

5.1 How It Works

  1. Choose a keyword (e.g., "CRYPTO").
  2. Repeat the keyword to match the plaintext length: Plaintext: H E L L O W O R L D Keyword: C R Y P T O C R Y P
  3. Apply Caesar shifts for each letter pair:
    • H (8) + C (3) = 11 → K
    • E (5) + R (18) = 23 → X
    • L (12) + Y (25) = 13 → N
    • etc. Ciphertext: KXNPS AXKLR

5.2 Strengths and Weaknesses

Advantages Disadvantages
More secure than Caesar Vulnerable to Kasiski examination (repeating patterns in the key).
Resists frequency analysis Requires a long key for security.
Used historically in WWII Computationally intensive for manual use.

5.3 Real-World Example: Vigenère in Ncell’s Legacy Systems

While Ncell now uses AES encryption for customer data, older SMS-based authentication systems (e.g., transaction alerts) historically used simple obfuscation techniques akin to Vigenère:

  • Example: An SMS might show XKDQ ZRUOG instead of HELLO WORLD.
  • How? The system could apply a predefined keyword (e.g., "SECURE") to shift letters.
  • Why study this? To understand how layered security (even simple layers) can deter casual attackers.

6. Playfair Cipher: Digraph Substitution

Invented by Charles Wheatstone and popularized by Lord Playfair, this cipher encrypts pairs of letters, reducing frequency analysis risks.

6.1 How It Works

  1. Create a 5×5 grid using a keyword (ignore repeated letters). Example keyword: "MONARCHY" Grid:

    M O N A R
    C H Y B D
    E F G I K
    L P Q S T
    U V W X Z
    

    (J is omitted or paired with I.)

  2. Split plaintext into digraphs (pairs of two letters): Plaintext: H E L L O W O R L D Digraphs: HE LL OW OR LD

  3. Encrypt each digraph:

    • If letters are in the same row, replace with the next letter in the row. Example: HE → MO (H→M, E→O).
    • If letters are in the same column, replace with the letter below (wrapping around). Example: LL → QQ (L→Q, L→Q).
    • If letters form a rectangle, replace with the letters on the same row but opposite column. Example: OW → BG (O→B, W→G).

    Ciphertext: MO QQ BG LD


6.2 Strengths and Weaknesses

Advantages Disadvantages
Harder to break than Caesar Requires careful key management.
Reduces frequency analysis Vulnerable to known-plaintext attacks.
Used in WWII for low-security Not secure against modern computers.

6.3 Real-World Example: Playfair in Daraz’s Order Processing

While Daraz uses end-to-end encryption (TLS/SSL) for transactions, its internal order tracking system (for educational purposes) might use a Playfair-like cipher to:

  • Obfuscate order IDs (e.g., ORD12345 → BG LD MO).
  • Why? To teach how digraph substitution can add a basic layer of security before modern encryption takes over.

7. Transposition Ciphers: Rearranging Letters

Unlike substitution, transposition ciphers rearrange letters without changing them.

7.1 Rail Fence Cipher

  • Write plaintext in a "zigzag" pattern and read row-wise.
  • Example: Plaintext = "HELLOWORLD", 2 rails:
    H   L   O   R   D
      E L W O L
    
    Ciphertext: HLO RD ELW OL → HLORD ELWOL

7.2 Columnar Transposition

  • Write plaintext in rows and read columns in a fixed order.
  • Example: Plaintext = "HELLOWORLD", key = "321":
    H E L L
    O W O R
    L D _ _
    
    Read columns 3, 2, 1 → L O H E L W O R L D → LOHELWORLD

7.3 Strengths and Weaknesses

Advantages Disadvantages
No letter substitution → harder frequency analysis Vulnerable to pattern analysis.
Simple to implement Requires careful key management.
Used in steganography Not secure alone (often combined with substitution).

8. Comparison of Classical Ciphers

Cipher Type Key Length Security Level Breaking Method
Caesar Substitution 1-25 Very Weak Brute force, frequency analysis
Vigenère Polyalphabetic Variable Weak Kasiski examination
Playfair Digraph Substitution 5×5 grid Moderate Known-plaintext attack
Rail Fence Transposition Rail count Weak Pattern analysis
Columnar Transposition Key length Weak Frequency analysis

9. Why Classical Ciphers Are Obsolete (But Still Important)

  • Computers can brute-force them instantly.
  • Modern attacks (e.g., quantum computing) make them useless.
  • But they teach:
    • How encryption works.
    • The importance of key management.
    • The need for complexity in modern cryptography.

10. Transition to Modern Cryptography

Classical ciphers led to:

  • Symmetric-key cryptography (AES, DES).
  • Public-key cryptography (RSA, ECC).
  • Hash functions (SHA-256, MD5).

In the Real World

  1. eSewa’s Transaction Security

    • While eSewa uses AES-256 for encrypting financial data, its educational modules teach how Caesar ciphers (as a simplified analogy) can obscure sensitive information before modern encryption is applied.
    • Example: A user’s transaction PIN might be visually obscured (e.g., ****) using a one-time shift (like Caesar) before being hashed.
  2. Ncell’s SMS Alerts (Legacy Systems)

    • Older SMS-based OTPs (before app-based auth) sometimes used Vigenère-like shifts to obscure the OTP during transmission.
    • Example: An OTP 123456 might be sent as 456789 (shift +3) to deter casual observers (though this is not secure by modern standards).
  3. Daraz’s Order Tracking (Educational Use)

    • Daraz’s internal training modules simulate Playfair ciphers to teach employees how digraph substitution can add a basic layer of security to order IDs before they are encrypted with TLS.
    • Example: Order ID ORD12345 → BG LD MO (using a Playfair grid).

Exam Tip

  1. Understand the mechanics of each cipher (Caesar, Vigenère, Playfair, transposition). Be able to encrypt/decrypt manually.
  2. Frequency analysis is key—know English letter frequencies and how to apply them to break ciphers.
  3. Compare ciphers in tables (strengths, weaknesses, breaking methods).
  4. Real-world connections:
    • Relate Caesar to simple obfuscation (e.g., eSewa PIN masking).
    • Relate Vigenère to legacy SMS security.
    • Relate Playfair to digraph-based order IDs.
  5. Common exam questions:
    • Encrypt/decrypt a given message using a cipher.
    • Break a cipher using frequency analysis.
    • Explain why classical ciphers are insecure today.
    • Compare two ciphers (e.g., Caesar vs. Vigenère).

Visuals for This Unit

classDiagram
    class CaesarCipher {
        +encrypt(text: String, shift: int) String
        +decrypt(text: String, shift: int) String
        -shiftLetters(char: char, shift: int) char
    }
    class VigenereCipher {
        +encrypt(text: String, key: String) String
        +decrypt(text: String, key: String) String
        -generateKey(text: String, key: String) int[]
    }
    class PlayfairCipher {
        +encrypt(text: String, key: String) String
        +decrypt(text: String, key: String) String
        -createGrid(key: String) char[5][5]
        -encryptDigraph(a: char, b: char) char[]
    }
    CaesarCipher --> VigenereCipher : "Uses single shift"
    VigenereCipher --> PlayfairCipher : "More complex than Caesar"
    PlayfairCipher --> CaesarCipher : "Still substitution-based"

sequenceDiagram
    participant User
    participant CaesarCipher
    User->>CaesarCipher: Encrypt "HELLO" with shift +3
    CaesarCipher-->>User: "KHOOR"
    User->>CaesarCipher: Decrypt "KHOOR" with shift -3
    CaesarCipher-->>User: "HELLO"

stateDiagram-v2
    [*] --> Plaintext
    Plaintext --> Caesar: Apply shift
    Caesar --> Ciphertext
    Ciphertext --> FrequencyAnalysis: Count letters
    FrequencyAnalysis --> Plaintext: Deduce shifts

vigenere cipher tableA labelled Vigenère square showing how shifts are applied. (Image: Armchair, CC BY-SA 4.0, via Wikimedia Commons)

Based on the TU BITM syllabus for Information Security (IT244), unit 3.

Discussion

Loading…