Ciphers

Chaocipher

Byrne's 1918 cipher. Two alphabets that shuffle themselves after every letter. Secret for 92 years. Now it fits on one page.
IDchaocipher18 / 69classical · polyalphabetic
Cipher / Polyalphabetic

Chaocipher

Two disks that reshuffle after every letter.

Keyspace
26! × 25!
Decode
same options back
Works on
A-Z, the rest passes
Family
14 in polyalphabetic
required 2 / 2

Options

keystring
required
The left (ciphertext) alphabet: 26 letters, or a keyword the rest of A-Z follows
secondKeystring
required
The right (plaintext) alphabet: 26 letters, or a keyword the rest of A-Z follows

Access

Createcreate("chaocipher")
CLIciphers encode chaocipher 'WELL DONE IS BETTER THAN WELL SAID' --key HXUCZVAMDSLKPEFJRIGTWOBNYQ --second-key PTLNBQDEOYSFAVZKGJRIHWXUMC
Tryplayground with the sample above
Kinvigenere, gronsfeld, beaufort, porta +9

John F. Byrne invented it in 1918 and tried to sell it to the Signal Corps and the Navy. Nobody bought it. Nobody broke it either. He printed challenge messages in his autobiography, Silent Years, and kept the method to himself. It came out only in 2010, when his family gave the papers to the National Cryptologic Museum and Moshe Rubin wrote it all down.

The reveal is almost funny. Two disks of 26 letters and a small shuffle after every letter. That's it.

ts
const chaocipher = create("chaocipher");
const disks = { key: "HXUCZVAMDSLKPEFJRIGTWOBNYQ", secondKey: "PTLNBQDEOYSFAVZKGJRIHWXUMC" };
chaocipher.encode("Well done is better than well said", disks).text; // "Oahq hcny nx tszjrr hjby hqks oujy"
chaocipher.decode("OAHQHCNYNXTSZJRRHJBYHQKSOUJY", disks).text; // "WELLDONEISBETTERTHANWELLSAID"

That's the exercise from Rubin's Chaocipher Revealed: The Algorithm, with the alphabets from his figure 2. Want to check it by hand? He prints every alphabet the 28 letters go through. Bring coffee.

Which alphabet is which?

key is the left disk, the ciphertext one. secondKey is the right disk, the plaintext one. Each takes 26 letters as they stand, or a keyword the rest of A-Z follows, so CHAOS gives CHAOSBDEFG…. Swap them and you get a different cipher, not an error. Check which disk a puzzle calls left.

What happens after each letter?

Find the plaintext letter on the right disk. The letter above it on the left disk is the ciphertext. Then both disks move.

The left disk turns until the ciphertext letter sits at the zenith, place 1. The letter after it drops out and goes to the nadir, place 14. Everything in between slides up one.

The right disk turns until the plaintext letter is at the zenith, then one more. Now the third letter drops to the nadir.

Decoding finds the ciphertext letter on the left disk instead. The shuffle is exactly the same. Nice touch: there's one permutation to get right, not two.

Why is it so hard to break?

Every letter gets a fresh alphabet, and which one depends on the text so far. No period, no repeating key. guess sees an index of coincidence as flat as random letters, around 0.037, and lists it with the polyalphabetic ciphers. recover doesn't take it.

The flip side hurts. Lose one letter and the disks fall out of step for good. Drop the first O from the example above and the rest decodes as DTTQELDISTJPCRLPIQISEPRDAQB. Copy puzzle ciphertext carefully.

One thing does repeat. Turn both disks by the same number of places and nothing changes, since only their alignment matters. That's why the keyspace reads 26! × 25! and not 26!².

The rest of the text

Only ASCII letters turn the disks. Spaces and punctuation pass through. Lowercase stays lowercase unless preserveCase is false, and stripNonAlpha drops everything outside A to Z first. The alphabets ignore case and anything that isn't a letter. A missing one is a MissingOptionError, one without letters an InvalidOptionError.