How does an affine shift cipher work?
The Mystery Of The Missing Silver › Forums › The Mystery Of The Missing Silver › How does an affine shift cipher work?
Tagged: Affine shift, challenge, cipher
- This topic has 4 replies, 4 voices, and was last updated 17 hours, 30 minutes ago by Alfie-Caldew.
-
AuthorPosts
-
-
1st October 2026 at 9:59 pm #155878l3op4rdx_xParticipant
Hello, I am a newcomer and I am very confused as to how an affine shift cipher works. If you could explain it in the simplest terms possible down below that would be great as the training resources available are a bit confusing. Thanks for the help
-
2nd October 2026 at 11:01 am #156190CrackerjackParticipant
Do you understand how the encryption and numbers mod 26 work? One way to think about the affine cipher is just a caesar cipher with an extra step.
Caesar, as a reminder: turn each letter into a number (A=0, B=1, … Z=25), add the shift, and “wrap around” past Z. E.g. with a shift of 5: H=7 —> 7+5=12 → M
“Wrapping around” just means that if the number is 26 or more, take away 26 until it’s between 0 and 25. That’s the same as taking the remainder when you divide by 26. Negative numbers work the other way: add 26 until you’re back in range. The formal term for this is modulo 26, or “mod 26” for short.
Affine: we do exactly the same thing, but first multiply by a number a, then apply the shift b. E.g. with a=3 and b=5: H=7—> 3*7=21 —> 21+5=26 —> wrap around —> 0 —> A
In Caesar, every letter moves by the same distance, so the alphabet just slides along. With affine, the multiplication scrambles the order of the alphabet before the shift, which is why you can’t crack it just by trying all 26 shifts.
If you look at the BOSS tools, you’ll notice that for affine you can only pick the odd numbers except 13 (1, 3, 5, … 11, 15, … 25). With any other value, two letters would encrypt to the same letter, and you couldn’t decrypt the message. For the sake of argument, pick an even multiplier, like a=2. Any number times 2 is even, and wrapping around by 26 (also even) keeps it even. So every letter lands on an even number, which leaves only 13 possible results for 26 letters: A=0 —> 2*0=0 N=13 —> 2*13=26 —> wrap —> 0
A and N become the same letter, so when you decrypt you can’t tell which one it was (13 fails for the same reason: 13 × 2 = 26 wraps straight back to 0)Decrypting means doing the steps in reverse. So undo the shift first, then undo the multiplication. Undoing the shift is easy: just subtract b. Undoing the multiplication is a bit trickier, because you can’t divide normally. Instead, you multiply by an “undo” number (formally called the inverse of a), which is the number that, when multiplied by a, wraps round to exactly 1.
Using our earlier example (a=3, b= 5), decrypting A = 0 —> 0 − 5 = −5
−5 is less than 0, so wrap around by adding 26: −5+26=21
Encryption multiplied by 3, so we multiply by its undo number 9 (9*3=27, which wraps round to 1): 21*9=189
189 is too big, so wrap around: 189 − 26*7 = 189-182=7 is H, which is exactly the letter we encrypted! To find the undo number for other values of a, just try multiplying a by 1, 3, 5, 7… until the answer wraps round to 1.Does that make sense? Is there anything specific you’re confused about from the training resources?
-
6th October 2026 at 1:59 pm #158339l3op4rdx_xParticipant
Hi sorry I’m still confused on how you find what a and b is. Really sorry
-
6th October 2026 at 4:52 pm #1585211234player1234Participant
so give every different letter a value corresponding to where it is in the alphabet. the affine shift will have an encryption key, like (3,4). In this case you will multiply the number that corresponds to the original letter’s position in the alphabet by the first number in the encryption key (this first value in the encryption key is A) after multiplying it, you add the second value in the encryption key (B) and number’s corresponding letter in the alphabet is the encrypted letter.
If the number somehow goes below A it will go to the back of the alphabet and continue going down from there, and likewise if it goes above z
-
8th October 2026 at 7:18 am #159948Alfie-CaldewParticipant
Firstly, this cipher is monoalphabetic (a simpler one that only uses 1 alphabet), which means that if you run frequency analysis, you will probably find 2 values that are a lot higher than the others. These are probably E and T respectively. From there, because this cipher is very maths based, you can use simultaneous equations to find a and b, using the equations: 4a + b = x mod 26, 19a + b = y mod 26. 4 and 19 comes from e and t’s positions in the alphabet, and x and y are the positions of the ciphertext equivalents in the alphabet.
For example, if ciphertext O maps to plaintext E and ciphertext F maps to plaintext T:
14a + b = 14 mod 26
19a + b = 5 mod 26 (subtract the first equation from the second to eliminate b)
15a = -9 = 17 mod 26
a = 17 * 7 (modular inverse of 15 is 7)
a = 119 = 15 mod 26
Then you can substitute a back into on of the equations to find b:
4a + b = 14 mod 26 -> 60 + b = 14 mod 26 -> 8 mod 26 + b = 14 mod 26 -> b = 6. a = 15, b = 6
-
-
-
AuthorPosts
- You must be logged in to reply to this topic.