FIT1093 Chap.2 Classical Ciphers and the One-Time Pad
Classical Ciphers and the One-Time Pad
Week 2 begins the unit's study of encryption with a simple premise: you cannot stop an attacker intercepting what you send, so you must make the intercepted message useless. Encryption scrambles plaintext into ciphertext that only a holder of the key can reverse.
The lecture contrasts keeping the algorithm secret, known as security by obscurity, with Kerckhoffs' principle, under which the algorithm is public and only the key is secret. A key is small and replaceable, which is why modern cryptography follows Kerckhoffs.
The classical ciphers show how much can go wrong.
The Caesar cipher shifts every letter by the same amount and can be written as adding the key modulo 26, but with only 26 possible keys it falls to exhaustive search in minutes. A monoalphabetic substitution uses a whole secret alphabet table, which defeats brute force but not frequency analysis, because each plaintext letter always becomes the same ciphertext letter and English letter frequencies shine through.
Transposition ciphers such as the rail fence reorder letters instead of replacing them, so the letters, and their frequencies, survive intact.
Modern ciphers answer these failures with product designs that combine substitution and transposition to achieve confusion, diffusion and the avalanche effect.
The chapter ends with the one-time pad, which gives each letter an independent random shift and is unconditionally secure: every plaintext of the right length is an equally likely decryption. Its price is a key as long as the message, and its one unbreakable rule is never to reuse that key, because a single known plaintext then exposes every other message encrypted with it.
What this chapter covers
- 01
Security by obscurity versus Kerckhoffs' principle
- 02
The Caesar cipher as addition modulo 26 and its brute-force attack
- 03
Monoalphabetic substitution and frequency analysis
- 04
Transposition and the rail fence cipher
- 05
Confusion, diffusion and the avalanche effect
- 06
Unconditional and computational security
- 07
The one-time pad and the danger of key reuse
Worked example · free
Decrypt a one-time pad message letter by letter
- 2Convert both strings to numbers: Y, X, R, J, F are 24, 23, 17, 9, 5 and H, J, X, Q, B are 7, 9, 23, 16, 1.
- 2Subtract key from ciphertext modulo 26: 24 − 7 = 17, 23 − 9 = 14, 17 − 23 = −6 → 20, 9 − 16 = −7 → 19, 5 − 1 = 4.
- 1Convert 17, 14, 20, 19, 4 back to letters to read the message.
Key terms
- Kerckhoffs' Principle
- The rule that a cipher should stay secure even when everything about it except the key is public knowledge.
- Substitution Cipher
- A cipher that replaces each letter or group of letters with another according to a key, like a lookup table.
- Transposition Cipher
- A cipher that rearranges the positions of letters according to a rule without changing the letters themselves.
- Frequency Analysis
- A cryptanalysis method that matches ciphertext letter frequencies against known language frequencies to recover a substitution key.
- Diffusion
- The cipher property that each plaintext symbol influences many ciphertext symbols, hiding plaintext patterns.
- One-Time Pad
- An encryption scheme that combines each plaintext symbol with an independent random key symbol, using the key only once.
Classical Ciphers and the One-Time Pad FAQ
Why is the Caesar cipher insecure?
Its key is only a shift between 0 and 25, so an attacker can try all 26 possibilities and spot the one that produces readable text. The sample in-class test treated the short key as the reason for its insecurity.
How does frequency analysis break a substitution cipher?
Each plaintext letter always encrypts to the same ciphertext letter, so the most common ciphertext symbol probably stands for E. Short repeated words such as THE then confirm guesses and reveal the rest of the table step by step.
Why is the one-time pad unbreakable but rarely used?
Every possible plaintext of the right length corresponds to some key, so the ciphertext reveals nothing. The cost is a truly random key as long as the message that must be delivered securely in advance and never reused.
What goes wrong if a one-time pad key is reused?
If an attacker ever learns one plaintext, subtracting it from its ciphertext reveals the key, and every other message encrypted with that key can then be read directly. The lecture's lesson is to never reuse the pad.
Assessment move
Practise every cipher in this chapter by hand on a short word of your own, both encrypting and decrypting, until the modulo 26 wrap-around feels automatic. For the Caesar cipher, write out a brute-force table for one ciphertext and notice how quickly the readable line stands out.
For substitution, take a paragraph you encrypt yourself and try to break a friend's using letter counts and short words, because doing frequency analysis once makes its logic obvious. Then connect each classical weakness to the modern property that fixes it: frequency leakage to confusion, preserved patterns to diffusion, and small edits to the avalanche effect.
Finish by working the pad-reuse attack in both directions, recovering the key from one known message and using it to read another.
Working through Classical Ciphers and the One-Time Pad in FIT1093? Sia is AskSia’s AI Cybersecurity tutor — ask any FIT1093 Classical Ciphers and the One-Time Pad question and get a clear, step-by-step explanation grounded in how FIT1093 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.