Information SecurityUnit 314 min read
Classical Cryptography: Ciphers, Caesar, Vigenère, Playfair, and Frequency Analysis
Unit 3 of Information Security explores the foundations of cryptography, covering substitution and transposition ciphers, classical algorithms like Caesar and Vigenère, and their vulnerabilities to frequency analysis. It also introduces the Playfair cipher and compares classical methods with modern cryptography.
TAKEAWAYS:
- Classical cryptography relies on substitution, transposition, or polyalphabetic techniques to conceal messages, with Caesar and Vigenère being the most famous examples.
- Frequency analysis is a powerful attack that exploits the predictable letter distributions in natural languages (e.g., English: E, T, A, O, N).
- The Playfair cipher improves security by encrypting pairs of letters, reducing frequency analysis risks.
- Classical ciphers are not secure against modern computational attacks but are foundational for understanding encryption principles.
- Real-world applications include historical military communications and educational tools for teaching cryptographic concepts.
- Modern cryptography (e.g., AES, RSA) builds on classical ideas but uses mathematical complexity to resist attacks.
1. Introduction to Classical Cryptography
Classical cryptography refers to encryption techniques developed before the advent of computers, primarily relying on manual methods. These methods are now considered insecure by modern standards but are essential for understanding the evolution of cryptographic principles.
1.1 Why Study Classical Cryptography?
- Historical significance: Used in wars (e.g., Julius Caesar’s cipher), diplomacy, and trade.
- Foundational concepts: Introduces core ideas like confusion (hiding patterns) and diffusion (spreading statistical properties).
- Educational value: Helps students recognize flaws in simple encryption and appreciate modern cryptography’s complexity.
1.2 Key Goals of Classical Ciphers
- Confidentiality: Ensure only authorized parties can read the message.
- Integrity: Detect tampering (though classical ciphers do not guarantee this).
- Authenticity: Verify the sender’s identity (also not fully addressed in classical methods).
2. Types of Classical Ciphers
Classical ciphers are broadly categorized into two types:
2.1 Substitution Ciphers
Replace each letter (or symbol) in the plaintext with another letter/symbol. Examples:
- Caesar cipher (shift cipher)
- Atbash cipher (reverse alphabet)
- Vigenère cipher (polyalphabetic substitution)
2.2 Transposition Ciphers
Rearrange the order of letters in the plaintext without substitution. Examples:
- Rail fence cipher
- Columnar transposition cipher
3. Caesar Cipher: The Simplest Substitution
Named after Julius Caesar, who allegedly used it to communicate with his generals.
3.1 How It Works
- Shift letters by a fixed number (e.g., shift +3: A→D, B→E, ..., Z→C).
- Wrap around the alphabet (after Z, it loops back to A).
Example: Encrypt "HELLO" with shift +3
Plaintext: H E L L O Shift +3: K H O O R Ciphertext: KHOOR
Decryption
Reverse the shift (subtract 3 or shift -3): Ciphertext: K H O O R Shift -3: H E L L O Plaintext: HELLO
3.2 Strengths and Weaknesses
| Advantages | Disadvantages |
|---|---|
| Simple to implement | Easily broken by brute force (only 25 possible shifts). |
| Fast for manual encryption | No security against frequency analysis. |
| Educational tool | Vulnerable to known-plaintext attacks. |
3.3 Real-World Example: Caesar Cipher in eSewa
While eSewa uses modern encryption (AES-256), its OTP (One-Time Password) system for transactions can be analogized to a one-time Caesar shift for simplicity in educational contexts. For example:
- A user might receive a 6-digit OTP (e.g.,
123456). - The system could internally apply a dynamic Caesar shift (e.g., +7) to obscure the OTP during transmission (though in reality, OTPs are hashed, not shifted).
- Why? To teach how simple transformations can add a basic layer of obscurity (though not real security).
4. Frequency Analysis: Breaking Substitution Ciphers
Frequency analysis exploits the fact that letters in natural languages appear with predictable frequencies.
4.1 Letter Frequencies in English
| Letter | Frequency (%) | Letter | Frequency (%) |
|---|---|---|---|
| E | 12.7 | T | 9.1 |
| T | 9.1 | A | 8.2 |
| A | 8.2 | O | 7.5 |
| O | 7.5 | I | 6.9 |
| N | 6.7 | ... | ... |
4.2 How Frequency Analysis Works
- Count letter occurrences in the ciphertext.
- Compare with known frequencies of the language.
- Map the most frequent ciphertext letter to 'E' (most common in English).
- Deduce other letters based on common digrams (e.g., "TH", "HE", "IN").
Example: Breaking a Caesar Cipher
Ciphertext: KHOOR ZRUOG Step 1: Count letters → K, H, O, R, Z, R, U, O, G. Step 2: Most frequent letters: O (2x), R (2x), K, H, Z, U, G (1x each). Step 3: Assume O → E (most frequent in English). Step 4: Shift back by 15 (since O is the 15th letter):
- O (15) → E (5) → Shift = 15 - 5 = 10.
- Decrypt with shift -10: K (11) → B (1), H (8) → S (18), O (15) → E (5), etc. Plaintext: BSELL HELLO → Likely "HELLO WORLD" (with a typo).
4.3 Limitations of Frequency Analysis
- Works best on long texts (short messages may not reveal patterns).
- Less effective on non-English languages (e.g., Nepali, Sanskrit).
- Fails against polyalphabetic ciphers (e.g., Vigenère).
5. Vigenère Cipher: Polyalphabetic Substitution
Invented by Blaise de Vigenère in the 16th century, this cipher uses multiple Caesar shifts based on a keyword.
5.1 How It Works
- Choose a keyword (e.g., "CRYPTO").
- Repeat the keyword to match the plaintext length: Plaintext: H E L L O W O R L D Keyword: C R Y P T O C R Y P
- Apply Caesar shifts for each letter pair:
- H (8) + C (3) = 11 → K
- E (5) + R (18) = 23 → X
- L (12) + Y (25) = 13 → N
- etc. Ciphertext: KXNPS AXKLR
5.2 Strengths and Weaknesses
| Advantages | Disadvantages |
|---|---|
| More secure than Caesar | Vulnerable to Kasiski examination (repeating patterns in the key). |
| Resists frequency analysis | Requires a long key for security. |
| Used historically in WWII | Computationally intensive for manual use. |
5.3 Real-World Example: Vigenère in Ncell’s Legacy Systems
While Ncell now uses AES encryption for customer data, older SMS-based authentication systems (e.g., transaction alerts) historically used simple obfuscation techniques akin to Vigenère:
- Example: An SMS might show
XKDQ ZRUOGinstead ofHELLO WORLD. - How? The system could apply a predefined keyword (e.g., "SECURE") to shift letters.
- Why study this? To understand how layered security (even simple layers) can deter casual attackers.
6. Playfair Cipher: Digraph Substitution
Invented by Charles Wheatstone and popularized by Lord Playfair, this cipher encrypts pairs of letters, reducing frequency analysis risks.
6.1 How It Works
Create a 5×5 grid using a keyword (ignore repeated letters). Example keyword: "MONARCHY" Grid:
M O N A R C H Y B D E F G I K L P Q S T U V W X Z(J is omitted or paired with I.)
Split plaintext into digraphs (pairs of two letters): Plaintext: H E L L O W O R L D Digraphs: HE LL OW OR LD
Encrypt each digraph:
- If letters are in the same row, replace with the next letter in the row. Example: HE → MO (H→M, E→O).
- If letters are in the same column, replace with the letter below (wrapping around). Example: LL → QQ (L→Q, L→Q).
- If letters form a rectangle, replace with the letters on the same row but opposite column. Example: OW → BG (O→B, W→G).
Ciphertext: MO QQ BG LD
6.2 Strengths and Weaknesses
| Advantages | Disadvantages |
|---|---|
| Harder to break than Caesar | Requires careful key management. |
| Reduces frequency analysis | Vulnerable to known-plaintext attacks. |
| Used in WWII for low-security | Not secure against modern computers. |
6.3 Real-World Example: Playfair in Daraz’s Order Processing
While Daraz uses end-to-end encryption (TLS/SSL) for transactions, its internal order tracking system (for educational purposes) might use a Playfair-like cipher to:
- Obfuscate order IDs (e.g.,
ORD12345→BG LD MO). - Why? To teach how digraph substitution can add a basic layer of security before modern encryption takes over.
7. Transposition Ciphers: Rearranging Letters
Unlike substitution, transposition ciphers rearrange letters without changing them.
7.1 Rail Fence Cipher
- Write plaintext in a "zigzag" pattern and read row-wise.
- Example: Plaintext = "HELLOWORLD", 2 rails:
Ciphertext: HLO RD ELW OL → HLORD ELWOLH L O R D E L W O L
7.2 Columnar Transposition
- Write plaintext in rows and read columns in a fixed order.
- Example: Plaintext = "HELLOWORLD", key = "321":
Read columns 3, 2, 1 → L O H E L W O R L D → LOHELWORLDH E L L O W O R L D _ _
7.3 Strengths and Weaknesses
| Advantages | Disadvantages |
|---|---|
| No letter substitution → harder frequency analysis | Vulnerable to pattern analysis. |
| Simple to implement | Requires careful key management. |
| Used in steganography | Not secure alone (often combined with substitution). |
8. Comparison of Classical Ciphers
| Cipher | Type | Key Length | Security Level | Breaking Method |
|---|---|---|---|---|
| Caesar | Substitution | 1-25 | Very Weak | Brute force, frequency analysis |
| Vigenère | Polyalphabetic | Variable | Weak | Kasiski examination |
| Playfair | Digraph Substitution | 5×5 grid | Moderate | Known-plaintext attack |
| Rail Fence | Transposition | Rail count | Weak | Pattern analysis |
| Columnar | Transposition | Key length | Weak | Frequency analysis |
9. Why Classical Ciphers Are Obsolete (But Still Important)
- Computers can brute-force them instantly.
- Modern attacks (e.g., quantum computing) make them useless.
- But they teach:
- How encryption works.
- The importance of key management.
- The need for complexity in modern cryptography.
10. Transition to Modern Cryptography
Classical ciphers led to:
- Symmetric-key cryptography (AES, DES).
- Public-key cryptography (RSA, ECC).
- Hash functions (SHA-256, MD5).
In the Real World
eSewa’s Transaction Security
- While eSewa uses AES-256 for encrypting financial data, its educational modules teach how Caesar ciphers (as a simplified analogy) can obscure sensitive information before modern encryption is applied.
- Example: A user’s transaction PIN might be visually obscured (e.g.,
****) using a one-time shift (like Caesar) before being hashed.
Ncell’s SMS Alerts (Legacy Systems)
- Older SMS-based OTPs (before app-based auth) sometimes used Vigenère-like shifts to obscure the OTP during transmission.
- Example: An OTP
123456might be sent as456789(shift +3) to deter casual observers (though this is not secure by modern standards).
Daraz’s Order Tracking (Educational Use)
- Daraz’s internal training modules simulate Playfair ciphers to teach employees how digraph substitution can add a basic layer of security to order IDs before they are encrypted with TLS.
- Example: Order ID
ORD12345→BG LD MO(using a Playfair grid).
Exam Tip
- Understand the mechanics of each cipher (Caesar, Vigenère, Playfair, transposition). Be able to encrypt/decrypt manually.
- Frequency analysis is key—know English letter frequencies and how to apply them to break ciphers.
- Compare ciphers in tables (strengths, weaknesses, breaking methods).
- Real-world connections:
- Relate Caesar to simple obfuscation (e.g., eSewa PIN masking).
- Relate Vigenère to legacy SMS security.
- Relate Playfair to digraph-based order IDs.
- Common exam questions:
- Encrypt/decrypt a given message using a cipher.
- Break a cipher using frequency analysis.
- Explain why classical ciphers are insecure today.
- Compare two ciphers (e.g., Caesar vs. Vigenère).
Visuals for This Unit
classDiagram
class CaesarCipher {
+encrypt(text: String, shift: int) String
+decrypt(text: String, shift: int) String
-shiftLetters(char: char, shift: int) char
}
class VigenereCipher {
+encrypt(text: String, key: String) String
+decrypt(text: String, key: String) String
-generateKey(text: String, key: String) int[]
}
class PlayfairCipher {
+encrypt(text: String, key: String) String
+decrypt(text: String, key: String) String
-createGrid(key: String) char[5][5]
-encryptDigraph(a: char, b: char) char[]
}
CaesarCipher --> VigenereCipher : "Uses single shift"
VigenereCipher --> PlayfairCipher : "More complex than Caesar"
PlayfairCipher --> CaesarCipher : "Still substitution-based"sequenceDiagram
participant User
participant CaesarCipher
User->>CaesarCipher: Encrypt "HELLO" with shift +3
CaesarCipher-->>User: "KHOOR"
User->>CaesarCipher: Decrypt "KHOOR" with shift -3
CaesarCipher-->>User: "HELLO"stateDiagram-v2
[*] --> Plaintext
Plaintext --> Caesar: Apply shift
Caesar --> Ciphertext
Ciphertext --> FrequencyAnalysis: Count letters
FrequencyAnalysis --> Plaintext: Deduce shifts
A labelled Vigenère square showing how shifts are applied. (Image: Armchair, CC BY-SA 4.0, via Wikimedia Commons)
Based on the TU BITM syllabus for Information Security (IT244), unit 3.
Discussion
Loading…