Worked example · Computer Science · Year 9

Cracking a Caesar cipher with letter frequencies

DCF: Interacting and collaborating → Storing and sharing

What this is

A complete, secure Year 9 answer, annotated against the success criteria. It is also the answer key. Headline answers: Step 1 gives QJFAJ FY IFBS; Step 2 is THE KEY IS UNDER THE MAT; Step 3 is key 3, MEET AT NOON; in Step 4 the most common ciphertext letter is L (33 of 184 letters, 17.9%), so the key is 7. The numeracy in Step 4 (the tally, the percentages, the bar chart and the written comparison) is where you can judge how well a pupil interprets data.

Step 1: encrypt

PlaintextLEAVEATDAWN
CiphertextQJFAJFYIFBS

(b) W is position 22. (22 + 5) MOD 26 = 27 MOD 26 = 1, which is B. V also wraps round: (21 + 5) MOD 26 = 26 MOD 26 = 0, which is A.

V and W both go past Z and wrap back to the start. Pupils who write a symbol or a blank for these have not wrapped. Evidences criterion 1.

Step 2: decrypt

THE KEY IS UNDER THE MAT

(b) Anyone who picks up the note gets the ciphertext and the key, so they can decrypt it as easily as Nia can. The key must be shared a different way, for example agreed in person beforehand.

The point is that encryption is only as safe as the key. Evidences criterion 2.

Step 3: brute force

Key triedPHHW becomesReal word?
1OGGVNo
2NFFUNo
3MEETYes
4LDDSNo

(b) Key 3: MEET AT NOON.

(c) 25. There are 26 letters, so there are only 26 possible shifts, and a shift of 0 (or 26) leaves the message unchanged. Trying 25 keys by hand takes a few minutes; a computer does it in far less than a second.

Pupils who only stop at key 3 still score; checking key 4 shows the method is systematic. Evidences criterion 2.

Step 4: frequency analysis

(a) Counts (lines 1 and 2 add up to 94; lines 3 and 4 add up to 90)

LetterABCDEFGHIJKLM
Count2212716016437334
LetterNOPQRSTUVWXYZ
Count5111001841382088

(b) Total = 184. Line by line: lines 1, 2, 3 and 4 contain 60, 34, 25 and 65 letters. Small slips of 1 or 2 in a tally do not change the answer.

(c) Percentages

LetterCountWorking%
L3333 ÷ 184 × 100 = 17.93…17.9
A2222 ÷ 184 × 100 = 11.95…12.0
H1616 ÷ 184 × 100 = 8.69…8.7
U1313 ÷ 184 × 100 = 7.06…7.1
O1111 ÷ 184 × 100 = 5.97…6.0

(d) A bar chart with letters L, A, H, U, O along the horizontal axis (labelled “Ciphertext letter”) and “Percentage of letters” up the vertical axis from 0 to 18 or 20, bars of equal width with gaps, heights 17.9, 12.0, 8.7, 7.1 and 6.0.

(e) L is by far the most common ciphertext letter, just as E is by far the most common English letter, so L most likely stands for E. E is position 4 and L is position 11. 11 − 4 = 7, so the key is 7.

(f) With key 7, A decrypts to T (position 0 − 7 + 26 = 19) and H decrypts to A (7 − 7 = 0). T and A are the 2nd and 3rd most common English letters, so the pattern of the three tallest bars matches the English chart moved 7 places along. The word AOL appears 8 times and decrypts to THE, the most common English word. Three separate pieces of evidence agree, so I am confident the key is 7.

(g) Line 1: THE TEAM WILL MEET AT THE GATE OF CONWY CASTLE AT SEVEN ON TUESDAY EVENING.

The whole message: THE TEAM WILL MEET AT THE GATE OF CONWY CASTLE AT SEVEN ON TUESDAY EVENING. BRING THE MAP, THE TORCH AND THE SPARE KEYS. TELL NOBODY WHERE WE ARE GOING. IF THE WEATHER IS BAD WE WILL MEET IN THE LIBRARY INSTEAD AND SET OFF THE NEXT DAY.

(h) The English chart is an average of a huge amount of text, but this message is only 184 letters, so a few repeated words change the percentages a lot. This message uses THE 8 times and words such as MEET, SEVEN and EVENING, which push E up to 17.9%, well above 12.7%. Nia’s message in Step 3 has only 10 letters, which is far too small a sample: no letter stands out reliably, so brute force is the better method there.

The total is checked, every percentage shows its working and is rounded correctly, and the key is not just guessed from one bar: it is tested on three letters and a common word. Part (h) explains why a small sample differs from the reference data. Evidences criteria 3 and 4.

Step 5: how long would brute force take?

What is being guessedNumber of keysWorkingLongest time
Caesar cipher key2525 ÷ 1,000,000,0000.000000025 s (2.5 × 10−8 s): instant
8 lower-case letters208,827,064,576208,827,064,576 ÷ 1,000,000,000 = 208.8 s; 208.8 ÷ 60about 3.5 minutes
128-bit AES key3.4 × 10383.4 × 1038 ÷ 109 = 3.4 × 1029 s; ÷ 31,500,000about 1.1 × 1022 years

For comparison, the universe is about 13,800,000,000 (1.38 × 1010) years old, so trying every AES key would take nearly a trillion times longer than that.

Units are converted to something meaningful. Pupils who write 1.1 × 1022 years or “about 11,000,000,000,000,000,000,000 years” are both right. Evidences criterion 2.

Step 6: when should data be encrypted?

SituationEncrypt?Reason
1. Medical form for the school nurseYesHealth information is sensitive personal data. If someone intercepted it they could learn private facts about the child.
2. Concert date on the public websiteNoIt is meant for everyone to read, so there is nothing to keep secret. (The website connection may still use https, which protects people from changed pages.)
3. Pupils’ reports on a USB stickYesUSB sticks are easily lost. If it is encrypted, whoever finds it cannot read the pupils’ personal information without the key.
4. Bank card number on a shop websiteYesAnyone who intercepts a card number could spend money. Only type it into a page that uses https.
5. Puzzle answer everyone has finishedNoIt is no longer secret and has no value to anyone who intercepts it.

(b) Model explanation for a Year 7 pupil: When a web address starts with https and shows a padlock, everything you send to that website, such as a password, is encrypted on the way, so anyone who intercepts it only sees scrambled data. A Caesar cipher is not safe because it has only 25 keys, which a computer can try in a fraction of a second, and because its letter patterns give the key away: I found the key in our message just by counting letters. Modern encryption such as AES has about 3.4 × 1038 keys, which would take about 1022 years to try, and it hides letter patterns. However, the padlock only protects the data while it travels. It does not tell you the website is honest, because a scam website can have a padlock too.

Decisions depend on how sensitive the data is and what happens if it is lost or intercepted, not on whether it “sounds important”. The explanation uses evidence from Steps 4 and 5 and states a limit of the padlock. Evidences criterion 5.

If you finish early: answers

Why this response is secure