Cover lesson · Computer Science · Year 9 · Advanced

Cracking a Caesar cipher with letter frequencies

DCF: Interacting and collaborating → Storing and sharing

Name: Class: Date:

Cover teacher: you need no subject knowledge and no computers

What this practises: digital competence in Computer Science. Pupils learn what encryption is for and why a weak cipher does not keep shared data safe, then decide when data should be encrypted before it is stored or sent. It also practises numeracy: in Step 4 pupils tally letters, turn counts into percentages, draw a bar chart and compare it with a chart of normal English to find the key. Their tally, percentages, chart and written comparison show how well they interpret data.

Print: this sheet, one per pupil, and the stimulus sheet “Clwb Codio Conwy: the intercepted message”, one between two. Pupils need a calculator and a ruler. Seat pupils in pairs for Step 4: one counts lines 1 and 2, the other counts lines 3 and 4, then they add their counts together.

Run: 5 min read stimulus sections 1 to 3 · 6 min Step 1 · 4 min Step 2 · 6 min Step 3 · 20 min Step 4, frequency analysis · 7 min Step 5 · 10 min Step 6 and success criteria. Total 58 minutes.

Collect: this sheet. The worked example has every answer. Checkpoints: Step 1 gives QJFAJ FY IFBS; Step 3 key is 3; in Step 4 the most common ciphertext letter is L (33 out of 184 letters), so the key is 7 and line 1 begins THE TEAM WILL MEET.

What you are doing

Encryption scrambles data so that only someone with the key can read it. People rely on it every time they send a password, a bank card number or a medical form. But encryption is only useful if it is hard to break. You will use a Caesar cipher, break it two different ways, and then decide which kinds of data really need strong encryption before they are stored or shared.

Step 1: encrypt

Encrypt LEAVE AT DAWN with key 5. Use the alphabet strip in section 3 of the stimulus. The first letter is done for you.

PlaintextLEAVEATDAWN
CiphertextQ

(b) Show the MOD working for the letter W: (position of W + 5) MOD 26 = ?

Step 2: decrypt

Rhodri sent Nia this message with key 4. Decrypt it by moving each letter back 4 places.

XLI OIC MW YRHIV XLI QEX

(b) Rhodri wrote “key = 4” at the bottom of the same note. Why does that make the encryption useless?

Step 3: brute force

Nia sent this, but nobody knows the key: PHHW DW QRRQ

Try keys on the first word only, moving each letter back. Stop when you get a real word.

Key triedPHHW becomesReal word?
1OGGVNo
2
3
4

(b) Use the key you found to decrypt the whole message.

(c) What is the greatest number of keys you would ever need to try for a Caesar cipher? Explain why.

Step 4: frequency analysis

The long message in section 4 of the stimulus has a key nobody knows. Instead of trying every key, you will use data.

(a) Count. With your partner, one of you tallies lines 1 and 2, the other lines 3 and 4. Count every letter. Then add your two counts.

LetterABCDEFGHIJKLM
Count
LetterNOPQRSTUVWXYZ
Count

(b) Check. Add up all your counts. The total should be 94 + 90 = 184. My total: ______. If it is not 184, recount the line that is out.

(c) Percentages. For your 5 most common letters, work out the percentage of all 184 letters. Round to 1 decimal place.

LetterCountWorking: count ÷ 184 × 100%

(d) Draw. Draw a bar chart of your 5 letters, most common first. Label both axes and use a scale of 1 square = 2%.

(e) Compare. Put your chart next to the English chart in section 5 of the stimulus. Which ciphertext letter most likely stands for E? Use the alphabet strip to work out how many places E has moved. That is your key.

(f) Test. Check your key on your 2nd and 3rd most common letters. Do they decrypt to letters that are also common in English (look at the chart)? Then check the word that appears most often in the message.

(g) Decrypt line 1 of the message.

(h) Your E percentage is not exactly 12.7%. Give two reasons why a single message does not match the English chart exactly, and explain why frequency analysis would not work on Nia’s 3-word message in Step 3.

Step 5: how long would brute force take?

A computer can try about 1,000,000,000 (109) keys every second. There are about 31,500,000 seconds in a year.

What is being guessedNumber of possible keysWorkingLongest time to try them all
Caesar cipher key25
8 lower-case letters, such as a password like ffrwdlan268 = 208,827,064,576
128-bit AES keyabout 3.4 × 1038

Give each time in a sensible unit (seconds, minutes or years).

Step 6: when should data be encrypted?

(a) For each situation, say whether the data should be encrypted when it is stored or sent, and give a reason.

SituationEncrypt? Yes or noReason
1. A parent fills in an online form telling the school nurse about their child’s medical condition.
2. The school posts the date of the summer concert on its public website.
3. A teacher copies pupils’ reports onto a USB memory stick to work on at home.
4. You type your bank card number into a shop’s website.
5. The code club shares the answer to a puzzle that everyone has already finished.

(b) Write a short explanation (3 to 5 sentences) for a Year 7 pupil: what the padlock and https in a web address mean, why modern encryption is safe when a Caesar cipher is not, and one thing the padlock does not tell you. Use your answers to Steps 4 and 5 as evidence.

Step by step

  1. 5 min Read sections 1 to 3 of the stimulus.
  2. 6 min Step 1: encrypt with key 5.
  3. 4 min Step 2: decrypt with key 4.
  4. 6 min Step 3: brute force Nia’s message.
  5. 20 min Step 4: count, work out percentages, draw, compare and decrypt.
  6. 7 min Step 5: how long brute force would take.
  7. 10 min Step 6, then tick the success criteria you have met.

Success criteria

If you finish early