← CS Unplugged

CS Unplugged activity

Vigenère Cipher: one keyword, many shifts

About 30 minutesSolo, or pair up to trade coded messagesPencil

Why one shift is not enough

If you have done the Caesar cipher activity, you know its weakness: one shift for the whole message means the most common letter in the ciphertext is always the same real letter, so counting letters cracks it fast. The Vigenère cipher fixes this with a keyword: each letter of the keyword picks its own shift, so the same real letter can turn into a different cipher letter almost every time it appears.

How a keyword picks a shift

Turn each keyword letter into a shift the same way you number the alphabet: A shifts 0, B shifts 1, C shifts 2, and so on up to Z, which shifts 25. Repeat the keyword under your message for as long as the message runs, and shift each letter by the keyword letter under it. Spaces do not shift and do not use up a keyword letter.

Here is the keyword KEY used on HELLO:

PlainHELLO
KeyKEYKE
Shift+10+4+24+10+4
CipherRIJVS

HELLO becomes RIJVS. The two Ls turn into two different letters (J and V), because each one lines up with a different keyword letter, something one Caesar shift could never do.

Decode these

Use the Vigenère square on the last page.

Every message below was encoded with the same keyword.

Keyword: OCEAN

  1. O DCTR WU IITVV FIGG

  2. HJI FVFUX PECIVAZAGV WNG CHA YCXILNQG

  3. O ISOQ DCWSJCTH IF ZQRG EOPHOZ OPH NRJGV RRIUID

Encode one of your own

Pick a keyword (3 to 6 letters), write a short message in capital letters, and use the square to encode it. Copy just the finished message below and swap with a partner.

Keyword: Message to swap:

Check with a partner: decode each other’s message using the square. You are both right if you each land back on real words.

Why doesn’t counting letters crack this? A Caesar cipher always turns the same real letter into the same cipher letter, which gives away the shift. A Vigenère keyword breaks that: the shift changes letter by letter, so counting letters here will not point at a single answer the way it does for a Caesar cipher. Learn more.

Your lookup tool: the Vigenère square

Find your keyword letter down the left side, run your finger along that row to your plain letter along the top, and read off the cipher letter (to decode, find your cipher letter in that row instead, and read the plain letter off the top of its column).

key ↓
plain →
ABCDEFGHIJKLMNOPQRSTUVWXYZ
AABCDEFGHIJKLMNOPQRSTUVWXYZ
BBCDEFGHIJKLMNOPQRSTUVWXYZA
CCDEFGHIJKLMNOPQRSTUVWXYZAB
DDEFGHIJKLMNOPQRSTUVWXYZABC
EEFGHIJKLMNOPQRSTUVWXYZABCD
FFGHIJKLMNOPQRSTUVWXYZABCDE
GGHIJKLMNOPQRSTUVWXYZABCDEF
HHIJKLMNOPQRSTUVWXYZABCDEFG
IIJKLMNOPQRSTUVWXYZABCDEFGH
JJKLMNOPQRSTUVWXYZABCDEFGHI
KKLMNOPQRSTUVWXYZABCDEFGHIJ
LLMNOPQRSTUVWXYZABCDEFGHIJK
MMNOPQRSTUVWXYZABCDEFGHIJKL
NNOPQRSTUVWXYZABCDEFGHIJKLM
OOPQRSTUVWXYZABCDEFGHIJKLMN
PPQRSTUVWXYZABCDEFGHIJKLMNO
QQRSTUVWXYZABCDEFGHIJKLMNOP
RRSTUVWXYZABCDEFGHIJKLMNOPQ
SSTUVWXYZABCDEFGHIJKLMNOPQR
TTUVWXYZABCDEFGHIJKLMNOPQRS
UUVWXYZABCDEFGHIJKLMNOPQRST
VVWXYZABCDEFGHIJKLMNOPQRSTU
WWXYZABCDEFGHIJKLMNOPQRSTUV
XXYZABCDEFGHIJKLMNOPQRSTUVW
YYZABCDEFGHIJKLMNOPQRSTUVWX
ZZABCDEFGHIJKLMNOPQRSTUVWXY

Check your answers

Decode these (keyword OCEAN).

  1. A byte is eight bits
  2. The first programmer was ada lovelace
  3. A good password is long random and never reused

CC BY-NC-SA 4.0.