The Playfair Cipher
Chapter Eleven
Syllabus topic Module 1, "Classical Encryption Techniques: Substitution Techniques"
Pages 51 to 56 of 678
In one line
Encrypt two letters at a time, using a five by five square of letters built from a keyword. Encrypting pairs rather than single letters flattens the letter frequencies, which is why Playfair survived long after the monoalphabetic ciphers were useless.
In the wording a student can write in an examination: the Playfair cipher is a multiple-letter, or digraph, substitution cipher invented by Charles Wheatstone in 1854 and promoted by Lord Playfair. It treats digrams in the plaintext as single units and translates them into ciphertext digrams, using a 5 by 5 matrix of letters constructed from a keyword, with I and J counted as one letter.
Why encrypting pairs is a real improvement
A monoalphabetic cipher has 26 units to disguise, and English gives each of them a distinctive frequency. Playfair has 26 times 26, that is 676 digrams to disguise, and the frequencies of digrams are much flatter and much harder to count reliably. Relative frequencies of individual letters in Playfair ciphertext show far less variation than the plaintext alphabet's, so the direct attack of the last chapter does not work.
That is why Playfair was used as the British Army's field cipher in the First World War and by the United States Army and other Allied forces in the Second. It is also why it is still in the syllabus: it is the first cipher on this course that is not broken by simply counting letters.
It is broken all the same, and the reason is arithmetic. A few hundred letters of ciphertext give enough digram structure to work with, and the cipher leaves large clues: a plaintext digram and its reverse encrypt to a ciphertext digram and its reverse, and the letters of a pair are never both unchanged.
Building the square
Step 1. Take the keyword. Write its letters into a 5 by 5 grid, left to right and top to bottom, skipping any letter that has already been written.
Step 2. Fill the remaining cells with the rest of the alphabet in order, again skipping letters already present.
Step 3. Because there are 26 letters and only 25 cells, I and J share a cell. The convention taken here, and the one in MU's reading list, is that J is treated as I throughout.
For the keyword MONARCHY the square is built in the program below. Note what the keyword contributes: every letter of MONARCHY is distinct, so all eight go in, and the rest of the alphabet follows from B.
Encrypting: the three rules, and the two preparations
Preparation 1: split the plaintext into pairs. If both letters of a pair are the same, insert a filler letter, conventionally X, between them and start again. So BALLOON becomes BA LX LO ON, because the two Ls would otherwise form a pair.
The Playfair Cipher
Preparation 2: if the plaintext has an odd number of letters, add a filler at the end.
Now the three rules. For a pair of plaintext letters:
Rule 1, same row. Replace each by the letter to its right, wrapping round from the last column to the first.
Rule 2, same column. Replace each by the letter below it, wrapping round from the bottom row to the top.
Rule 3, neither. Each letter is replaced by the letter in its own row and in the other letter's column. In other words, the two letters mark two corners of a rectangle and you take the other two corners, keeping each letter on its own row.
Rule 3 is the one that goes wrong, and it goes wrong in one specific way: students take the corners in the wrong order. The first ciphertext letter is on the first plaintext letter's row. Keeping to that removes the error entirely.
The program, which shows which rule it used
ALPHABET = "ABCDEFGHIJKLMNOPQRSTUVWXYZ"
def square(key):
seen, out = set(), []
for c in (key + ALPHABET).upper().replace("J", "I"):
if c in ALPHABET and c not in seen:
seen.add(c)
out.append(c)
return [out[r * 5:r * 5 + 5] for r in range(5)]
def digraphs(plain):
t = "".join(c for c in plain.upper() if c in ALPHABET).replace("J", "I")
pairs, i = [], 0
while i < len(t):
a = t[i]
b = t[i + 1] if i + 1 < len(t) else "X"
if a == b:
pairs.append(a + "X")
i += 1
else:
pairs.append(a + b)
i += 2
return pairs
def find(sq, c):
for r in range(5):
for k in range(5):
if sq[r][k] == c:
return r, k
def crypt(sq, pairs, step):
out = []
for a, b in pairs:
ra, ca = find(sq, a)
rb, cb = find(sq, b)
if ra == rb:
out.append(sq[ra][(ca + step) % 5] + sq[rb][(cb + step) % 5])
elif ca == cb:
out.append(sq[(ra + step) % 5][ca] + sq[(rb + step) % 5][cb])
else:
out.append(sq[ra][cb] + sq[rb][ca])
return out
sq = square("MONARCHY")
print("the square for the keyword MONARCHY:")
for row in sq:
print(" " + " ".join(row))
print()
plain = "BALLOON"
pairs = digraphs(plain)
print("plaintext :", plain)
print("digraphs :", " ".join(pairs))
enc = crypt(sq, pairs, +1)
print("ciphertext :", "".join(enc))
print()
print("rule used for each pair:")
for p, c in zip(pairs, enc):
ra, ca = find(sq, p[0]); rb, cb = find(sq, p[1])
if ra == rb:
rule = "same row, move right"
elif ca == cb:
rule = "same column, move down"
else:
rule = "rectangle, swap columns"
print(" %s -> %s %s" % (p, c, rule))
print()
back = crypt(sq, [(c[0], c[1]) for c in enc], -1)
print("decrypted :", "".join(back))The Playfair Cipher
the square for the keyword MONARCHY:
M O N A R
C H Y B D
E F G I K
L P Q S T
U V W X Z
plaintext : BALLOON
digraphs : BA LX LO ON
ciphertext : IBSUPMNA
rule used for each pair:
BA -> IB same column, move down
LX -> SU rectangle, swap columns
LO -> PM rectangle, swap columns
ON -> NA same row, move right
decrypted : BALXLOONRead four things out of the run.
BA is a same-column pair. B is in row 1, column 3; A is in row 0, column 3. Same column, so each moves down: B becomes I and A becomes B. This is the pair students misread, because B and A look like they should form a rectangle.
ON is a same-row pair. Both are in row 0, so each moves right: O becomes N and N becomes A. Notice that the ciphertext NA contains a letter from the plaintext, which is normal and not an error.
Two pairs used rule 3, and in both the first ciphertext letter came from the first plaintext letter's row: for LO, L is row 3 and O is column 1, giving row 3 column 1, which is P.
The decryption returns BALXLOON, not BALLOON. The filler X is still there. The receiver has to notice that LXL is not a word and remove the X. That is a genuine weakness of the scheme and a genuine examination trap: when asked to decrypt, remove the fillers and say that you did.
Decrypting
Decryption uses the same three rules with the direction reversed: same row, move left; same column, move up; rectangle, unchanged, because taking the other two corners twice returns you to where you started. That last point is worth stating in an answer, because it explains why rule 3 needs no reversal.
A second worked example, by hand
Encrypt HIDE THE GOLD with the same square.
Pairs: HI DE TH EG OL DX. The last pair needed a filler because the letter count is odd.
HI: H is row 1 column 1, I is row 2 column 3. Rectangle. H takes row 1 column 3, which is B; I takes row 2 column 1, which is F. SoBF.DE: D is row 1 column 4, E is row 2 column 0. Rectangle. D takes row 1 column 0, which is C; E takes row 2 column 4, which is K. SoCK.TH: T is row 3 column 4, H is row 1 column 1. Rectangle. T takes row 3 column 1, which is P; H takes row 1 column 4, which is D. SoPD.EG: E is row 2 column 0, G is row 2 column 2. Same row, move right: F and I. SoFI.OL: O is row 0 column 1, L is row 3 column 0. Rectangle. O takes row 0 column 0, which is M; L takes row 3 column 1, which is P. SoMP.DX: D is row 1 column 4, X is row 4 column 3. Rectangle. D takes row 1 column 3, which is B; X takes row 4 column 4, which is Z. SoBZ.
The Playfair Cipher
Ciphertext: BFCKPDFIMPBZ.
What an attacker gets from the structure
Playfair leaks in ways worth knowing, because a question about its weaknesses expects more than "it is old".
A digram and its reverse give a ciphertext digram and its reverse. If AB encrypts to RS, then BA encrypts to SR. So the pairs AB and BA are visibly related in the ciphertext, and English has many such pairs (ER and RE, ON and NO, ES and SE).
No letter ever maps to itself. Every rule moves both letters, so a ciphertext letter is never in the same place as its plaintext letter. That halves the candidate space at every step.
Doubled letters cannot appear in the ciphertext. The preparation eliminated them from the plaintext, so LL never appears in the output. A ciphertext with no doubled letters at all is a signature of Playfair.
676 digrams, and about 600 keys' worth of square. Digram frequency analysis on a few hundred letters recovers enough of the square to guess the keyword, and the keyword then gives the rest.
Distinctions that carry marks
| Monoalphabetic | Playfair | |
|---|---|---|
| Unit encrypted | one letter | two letters |
| Units to disguise | 26 | 676 |
| Key | a permutation of 26 letters | a 5 by 5 square, from a keyword |
| Frequencies in the ciphertext | the plaintext language's, relabelled | much flatter |
| Broken by | single-letter frequency analysis | digram frequency analysis, a few hundred letters |
| Used in war | no | yes, by the British Army in the First World War |
| Rule | Condition | Encryption | Decryption |
|---|---|---|---|
| 1 | same row | move right, wrapping | move left, wrapping |
| 2 | same column | move down, wrapping | move up, wrapping |
| 3 | neither | other two corners, each on its own row | the same operation |
What beginners get wrong here
The order in rule 3. The first ciphertext letter stays on the first plaintext letter's row. Swapping them is the commonest error in this topic.
Forgetting to split a doubled pair. BALLOON is BA LX LO ON, not BA LL OO N. Missing the filler shifts every subsequent pair and destroys the answer.
The Playfair Cipher
Forgetting that I and J share a cell. A plaintext J becomes I before encryption, and on decryption an I may be either. The receiver decides from context.
Thinking Playfair is unbreakable because the frequencies look flat. They are flatter, not flat. A few hundred letters is enough.
Leaving the fillers in on decryption. The recovered text is BALXLOON, and the answer is BALLOON. Say that you removed it.
Quick revision
- Playfair: digram substitution using a 5 by 5 square from a keyword, I and J sharing a cell. Wheatstone, 1854.
- 676 digrams to disguise instead of 26 letters, so the letter frequencies are much flatter.
- Preparation: split a doubled pair with an X, and pad an odd length.
- Three rules: same row move right; same column move down; otherwise the other two corners, first ciphertext letter on the first plaintext letter's row.
- Decryption: left, up, and rule 3 unchanged.
BALLOONunderMONARCHYisIBSUPMNA, and decrypting givesBALXLOON: strip the filler.- Leaks: a reversed digram gives a reversed ciphertext digram; no letter maps to itself; no doubled letters in the ciphertext.
- Broken by digram frequency analysis on a few hundred letters.
Test yourself
1. Construct the Playfair square for the keyword SECURITY. Row by row: S E C U R; I T Y A B; D F G H K; L M N O P; Q V W X Z. The keyword's distinct letters come first, then the remaining letters in order, with I and J sharing the I cell.
2. Encrypt MEET with the MONARCHY square. Pairs are ME and ET. M is row 0 column 0 and E is row 2 column 0, so they share a column: M becomes C and E becomes L, giving CL. E is row 2 column 0 and T is row 3 column 4, a rectangle: E takes row 2 column 4, which is K, and T takes row 3 column 0, which is L, giving KL. The ciphertext is CLKL.
3. Why is Playfair harder to break than a monoalphabetic cipher? Because it encrypts two letters at a time, so the attacker must work with 676 digrams rather than 26 letters, and digram frequencies are much flatter and need far more ciphertext to distinguish reliably. Single-letter frequency analysis, which breaks a monoalphabetic cipher at once, does not work.
4. State the three encryption rules and how each is reversed. Same row: move each letter one place right, wrapping; reversed by moving left. Same column: move each letter one place down, wrapping; reversed by moving up. Neither: take the other two corners of the rectangle, each ciphertext letter on its own plaintext letter's row; reversed by the same operation, because applying it twice returns the original.
The Playfair Cipher
5. What is done with a doubled letter in the plaintext, and what must the receiver do? A filler letter, conventionally X, is inserted between the two, so the pair is split. On decryption the receiver recovers the filler as part of the text and must remove it by inspection, since BALXLOON is plainly BALLOON.
6. Name three structural weaknesses of Playfair that help an attacker. A plaintext digram and its reverse encrypt to a ciphertext digram and its reverse, so related pairs are visible. No letter is ever encrypted to itself, which halves the possibilities at each step. Doubled letters never occur in the ciphertext, which both identifies the cipher and constrains the plaintext.
7. Why does rule 3 need no separate decryption rule? Because it maps the two letters to the other two corners of the same rectangle, each staying on its own row. Applying that operation to the ciphertext pair returns the original corners, so encryption and decryption are the same step.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.