The Vigenère cipher is a polyalphabetic substitution cipher that uses a repeating keyword to encrypt a message. Unlike the Caesar cipher — where every letter shifts by the same fixed amount — each letter shifts by a different amount determined by the corresponding letter of the keyword, making simple frequency analysis much harder to apply.
How does the Vigenère cipher differ from the Caesar cipher?
A Caesar cipher uses a single shift value applied to every letter. If you know the shift is 3, you know immediately that every A becomes D, every B becomes E, and so on. A frequency analysis attack — counting how often each cipher letter appears and matching the most frequent to the most common plaintext letter (E in English) — can crack a Caesar cipher in seconds.
The Vigenère cipher uses a keyword of arbitrary length. Each letter of the keyword determines a different shift value (A = 0, B = 1, C = 2, … Z = 25). Because different letters of the plaintext are shifted by different amounts, the same plaintext letter can produce different cipher letters depending on its position. This breaks the direct frequency link that makes the Caesar cipher vulnerable.
How do you encrypt a message with the Vigenère cipher?
The encryption formula for each letter is:
Cipher letter = (Plaintext letter + Key letter) mod 26
where A = 0, B = 1, …, Z = 25. If the keyword is shorter than the message, it repeats.
Worked example: Encrypt HELLO with the key KEY
| Position | Plaintext | Plaintext value | Key letter | Key value | Sum | Sum mod 26 | Cipher letter |
|---|---|---|---|---|---|---|---|
| 1 | H | 7 | K | 10 | 17 | 17 | R |
| 2 | E | 4 | E | 4 | 8 | 8 | I |
| 3 | L | 11 | Y | 24 | 35 | 9 | J |
| 4 | L | 11 | K | 10 | 21 | 21 | V |
| 5 | O | 14 | E | 4 | 18 | 18 | S |
HELLO encrypted with key KEY becomes RIJVS. Notice that the two Ls in HELLO produce different cipher letters (J and V), illustrating why frequency analysis fails.
How do you decrypt a Vigenère cipher?
Decryption reverses the process using the same key:
Plaintext letter = (Cipher letter − Key letter + 26) mod 26
The +26 ensures the result stays positive. Using the example above, decrypting R with key letter K: (17 − 10 + 26) mod 26 = 33 mod 26 = 7 = H. The +26 only matters when the subtraction would give a negative result.
Both parties must know the keyword — the sender uses it to encrypt, the receiver uses it to decrypt. This is an example of symmetric key cryptography: the same key is used in both directions.
Why is the Vigenère cipher harder to crack than the Caesar cipher?
| Property | Caesar cipher | Vigenère cipher |
|---|---|---|
| Type | Monoalphabetic | Polyalphabetic |
| Shift | Fixed single value | Varies by position (determined by keyword) |
| Frequency analysis | Easy — one shift to guess | Harder — each position uses a different shift |
| Key space | 25 possible keys | Very large (depends on keyword length and vocabulary) |
| Known weakness | All 25 keys can be tried in seconds | Kasiski examination or index of coincidence needed |
The Vigenère cipher was once called "le chiffre indéchiffrable" (the unbreakable cipher). However, in the 19th century Charles Babbage and Friedrich Kasiski independently discovered that repeated patterns in the ciphertext reveal the key length, after which frequency analysis can be applied to each Caesar-shifted group separately.
What is the Kasiski examination?
If the keyword repeats, identical plaintext sequences that happen to align with the same part of the key will produce identical ciphertext sequences. By finding repeated trigrams (three-letter sequences) in the ciphertext and measuring the distances between them, an analyst can determine likely multiples of the key length. Once the key length is known, the ciphertext can be split into groups, each of which is a simple Caesar cipher — crackable by frequency analysis.
This attack does not work if the key is as long as the message and used only once — that arrangement is called a one-time pad, which is theoretically unbreakable. In practice, managing a fresh key as long as every message is impractical, which is why modern cryptography uses mathematical algorithms (AES, RSA) rather than letter substitution.
Frequently asked questions
Why do GCSE exams include the Vigenère cipher if it has been broken?
The Vigenère cipher is a stepping stone from simple substitution ciphers to modern cryptography. Understanding it shows why key length matters, why polyalphabetic ciphers resist basic frequency analysis, and why the security of any cipher depends on how hard it is to deduce the key. These concepts transfer directly to AES and public-key cryptography.
What is a Tabula Recta and how is it used?
A Tabula Recta (also called the Vigenère square) is a 26 × 26 table where row i shows the alphabet shifted by i positions. To encrypt, find the row for the key letter and the column for the plaintext letter; the cell gives the cipher letter. It is a manual lookup table that avoids computing (P + K) mod 26 by hand. Modern students typically use the formula instead.
What is the difference between monoalphabetic and polyalphabetic ciphers?
A monoalphabetic cipher maps each plaintext letter to exactly one cipher letter throughout the entire message (e.g., Caesar, Atbash). A polyalphabetic cipher uses multiple mappings — the same plaintext letter can be encrypted to different cipher letters depending on its position. The Vigenère cipher is polyalphabetic because the key letter changes with each position.
Can the Vigenère cipher ever be made secure?
If the keyword is chosen randomly, is at least as long as the message, and is never reused — a regime known as the one-time pad — then the cipher is information-theoretically secure and cannot be broken even with unlimited computing power. However, generating, distributing, and managing one-time-pad keys securely is so difficult that modern cryptography instead uses computationally secure algorithms like AES.
Want to work through cipher examples step by step with immediate feedback? Professor Turing at aitutors.me will guide you through every encryption.