StringMash.com

Vigenère cipher

A Caesar shift that changes with every letter, following a keyword.

Conversion
26 characters
Updates as you type
Key: Manchester Bluff

Using the Vigenère tool

Type a message and a key. Each letter of the message is shifted by the matching letter of the key, A for no shift and Z for 25, and the key repeats as often as it needs to. Swap to decrypt, with the same key.

Only letters use up the key. Spaces, digits and punctuation go through untouched and the key waits for the next letter, which is the traditional way and how cryptii does it too. Anything in the key that isn't a letter is ignored, so "Manchester Bluff" and MANCHESTERBLUFF are the same key.

Key runs switches to the autokey cipher. The keyword is used once and then the message carries on as its own key.

How the shifts line up

Write the key under the message, letter for letter. With the key IOZQGH, attack at dawn becomes ihsqir ih cqcu. A shifted by I is I, T shifted by O is H, and the key starts again after its sixth letter.

That's the whole cipher. It's a stack of Caesar ciphers, and the key says which one to use for each letter. A one-letter key is a plain Caesar shift, and the key A leaves the text unchanged.

The strength comes from the same letter encrypting differently. The four As in attackatdawn come out as I, Q, I and Q, so a frequency count, which breaks a Caesar cipher in seconds, sees a flatter spread. The weakness is in the same example. Those As repeat every six letters because the key does.

Named after the wrong man

Giovan Battista Bellaso published the cipher in 1553, in La cifra del Sig. Giovan Battista Bellaso. He took Johannes Trithemius's square of shifted alphabets and added a repeating key he called a countersign.

Blaise de Vigenère published something stronger in 1586, the autokey cipher, where the message itself carries the key onward. In the 19th century the simpler repeating cipher was credited to him anyway, and his name stuck to the one he didn't invent. The Key runs setting here gives you both.

It earned the name le chiffre indéchiffrable, the indecipherable cipher. Charles Babbage broke a version of it by 1854 but never published. Friedrich Kasiski did, in 1863, by looking for repeated chunks of ciphertext and measuring the gaps between them, which gives away the length of the key.

The Confederacy's three keys

The Confederacy used the Vigenère cipher in the American Civil War, set on a brass cipher disk. It had three main key phrases in turn, according to David Kahn's The Codebreakers. They were MANCHESTER BLUFF, then COMPLETE VICTORY, and late in the war COME RETRIBUTION.

Three keys over four years is the weakness Kasiski's 1863 method feeds on. The longer one key stays in use, the more ciphertext there is to find repeats in. This page opens on the first of the three.

Related conversions

The Caesar cipher is Vigenère with a one-letter key, and the page there breaks it by trying every shift. Playfair was the next step, encrypting letters in pairs so that single-letter frequencies disappear. The cipher identifier can tell you whether a mystery message looks like either.

Questions

How do I decrypt a Vigenère cipher?

Paste it on the left, press swap and type the key. Each letter is shifted back by its key letter. Without the key you need Kasiski's method or a frequency count per key position, which this tool doesn't do.

What happens to spaces and punctuation?

They pass through unchanged and don't use up the key. Some tools remove them first, or advance the key over them, and those give different ciphertext for the same message and key.

What's the difference between Vigenère and autokey?

Vigenère repeats the keyword. Autokey uses it once and then continues with the message, so the key never repeats. That defeats Kasiski's method, which looks for the repetition.

Is the Vigenère cipher secure?

No. It's been breakable by hand since 1863 and a computer does it instantly. Use it for puzzles and teaching, never for anything that matters.