CipherLayer
Home / Tools / Vigenère Cipher

Vigenère Cipher + Kasiski Attack

Encrypt and decrypt with a repeating-key polyalphabetic cipher, then paste ciphertext and let the full cryptanalytic pipeline — Kasiski examination, Index of Coincidence, Friedman test, chi-squared per column — recover the key. The attack that took 300 years to discover.

Classical Educational Kasiski IC / Friedman Auto-crack
Called "le chiffre indéchiffrable" for 300 years. Vigenère was published in 1553 and remained unbroken until Friedrich Kasiski published his attack in 1863. Today, a 200-character Vigenère ciphertext with a 10-character key falls in milliseconds.

Inputs

Vigenère was historically called "polyalphabetic" — each letter of the key chooses a different shift.

Output

// Output will appear here
Status
—
Key used / found
—
Length
—

Why this tool, and why this version

The Vigenère cipher was misnamed for Blaise de Vigenère, who described it in 1553. It uses a repeating key to apply a different Caesar shift to each letter of the plaintext. For 300 years it was considered unbreakable — "le chiffre indéchiffrable" — and cryptanalysts spent their careers trying.

The attack was published in 1863 by Friedrich Kasiski, a Prussian army officer who noticed that if the same trigram appears twice in the ciphertext, the distance between the two occurrences is usually a multiple of the key length. Computing GCDs of those distances reveals the key length. William Friedman later refined this into the Index of Coincidence test, which estimates key length from a single statistical measurement.

This tool implements the full attack. Paste any Vigenère ciphertext of ~200 characters or more and click Crack. You'll see the Kasiski trigram table, the IC curve for key lengths 1 through 20, the Friedman's κ_estimate, and finally the recovered key character-by-character with chi-squared scoring per column.

Why the cipher fails: the key repeats. As soon as you identify the key length K, you split the ciphertext into K Caesar-shift sub-ciphers and crack each one with frequency analysis. The polyalphabetic defense collapses under any ciphertext long enough to expose the periodicity.

Who this is for

Students studying cryptanalysis

Vigenère is the textbook example of a polyalphabetic cipher and the textbook example of why polyalphabetic ciphers fail. Running Kasiski by hand takes a day. Running it here takes a second, and you can see exactly what the attack does at each step.

History of cryptography enthusiasts

Three hundred years of confidence, broken by one Prussian major. The story of Kasiski's attack is one of the most famous pivots in the history of secret communication. This tool lets you reproduce his reasoning on your own ciphertext.

Curious minds exploring statistical attacks

The Index of Coincidence is a beautiful piece of math. It distinguishes English text from random text with a single number. Watching IC peak at the true key length is the moment "polyalphabetic cipher" stops being intimidating and starts being mechanical.

Frequently asked questions

How does the Index of Coincidence find the key length? ▶
Suppose the key length is K. Then every K-th character of the ciphertext was encrypted with the same alphabet — a Caesar shift. If we split the ciphertext into K columns, each column is a Caesar-shift ciphertext over the original English text. Plain English has IC ≈ 0.066. Random text has IC ≈ 0.038. We try K = 1, 2, 3, … and compute the average IC of the K columns. The K that pushes IC closest to 0.066 is the answer.
What's the Kasiski test and why does it work? ▶
If the same three-letter sequence ("trigram") appears twice in the plaintext and the two positions line up with the same key offset, both encrypt to the same ciphertext trigram. The distance between the two ciphertext positions is a multiple of K. By collecting many repeated trigrams and computing GCDs of their distances, we find a small set of likely K values. Kasiski published this in 1863 and cryptanalysis of polyalphabetic ciphers became routine.
Why is the cracked key sometimes wrong? ▶
The chi-squared scoring picks the best Caesar shift per column. If a column has very few characters (say, fewer than 30), the noise dominates and several shifts may score close. The tool reports its confidence and the chi² values; if any column is below ~80 characters, double-check the result. A short ciphertext simply doesn't carry enough statistics.
What ciphertext length do I need for a reliable crack? ▶
A rule of thumb: at least 20× the key length. For a 10-character key, ~200 characters of ciphertext is enough. For a 20-character key, you need ~400. Below those thresholds the IC curve and chi-squared scores get noisy and the tool will report its uncertainty in the output.
Does this work on non-English text? ▶
No. The IC test and chi-squared scoring both rely on English letter frequencies. For other languages you'd substitute the appropriate frequency table. Spanish has its own distribution; French another; German a third. Adapting the cracker is straightforward — change the frequency table in the code.
Is there a Vigenère variant this can't break? ▶
Yes — the autokey variant, where the key is the plaintext itself extended by a short priming key, defeats periodicity-based attacks. The one-time pad, where the key is as long as the message and truly random, is provably unbreakable. But for any repeating-key Vigenère, this attack works.

Limitations you should know