Relic
Get Relic free
Clipboard security & privacy

Types of ciphers, from Caesar to AES

Most ciphers you meet in puzzles belong to a few families. Substitution ciphers swap letters and transposition ciphers shuffle them. Polyalphabetic ciphers keep changing the swap as they go, which made them much harder to crack. Modern ciphers like AES work on bits, and they are the only kind that protects real data today.

Jordan Gibbs October 7, 2026 8 min read

What is a cipher?

A cipher is a fixed method for scrambling a message so only someone with the key can read it. The method can be public, as long as the key stays secret. In a Caesar cipher the method is “shift every letter” and the key is how far. In AES the key is a 128, 192 or 256 bit number. Reversing the scramble with the key is called decrypting.

People often call any secret writing a code, but a code and a cipher are different things. Morse code swaps letters for dots and dashes using a table anyone can look up, and there is no key. So Morse is an encoding. The same goes for binary and Base64. Our Morse code translator is handy for a puzzle, but it hides nothing from a person who has seen the chart.

Substitution ciphers

A substitution cipher replaces each letter with another letter, and the replacement never changes through the message. If A becomes Q once, A becomes Q everywhere. These are the oldest ciphers we have written records of.

Caesar cipher

Shift every letter the same number of places. The Roman writer Suetonius says Julius Caesar wrote private letters this way, and that to read them you “substitute the fourth for the first letter, as d for a”. That is a shift of 3. There are only 25 useful shifts, so anyone can try them all in a minute. The Caesar cipher tool does exactly that in its brute force panel. ROT13 is the same cipher with the shift fixed at 13, which is why running it twice gives the text back.

Atbash

Write the alphabet backwards and swap each letter for its mirror: A and Z, B and Y, all the way to M and N. It has no key at all. Atbash comes from Hebrew, and its name spells out the first swaps (alef with tav, bet with shin). Oxford’s Faculty of Theology and Religion points to Jeremiah 25:26, where the word Sheshach is Atbash for Babel. Try it in the Atbash cipher tool. HELLO comes out as SVOOL.

General substitution

Now scramble the alphabet any way you like, so A might become K, B might become W, and so on. There are 26 factorial ways to do that, about 403 million billion billion. Trying them all is out of the question. It still falls apart fast, and the reason is letter frequency. English uses some letters far more than others. In one Cornell sample of 40,000 words, E made up 12.02% of all letters, T 9.10%, and Z only 0.07%. Swapping the letters doesn’t change how often each one shows up. So the most common symbol in a long message is probably E.

This trick goes back a long way. The Arab scholar al-Kindi described it in the 9th century, in a book known as A Manuscript on Deciphering Cryptographic Messages. It is the first known written method for breaking ciphers. The cryptogram puzzles in newspapers are general substitution ciphers, and they get solved the same way.

Polyalphabetic ciphers: the Vigenère cipher

The fix for frequency analysis was to keep changing the substitution. A polyalphabetic cipher uses several alphabets in turn, so an E in one spot and an E a few letters later come out as different letters. The most famous is the Vigenère cipher. You pick a keyword, write it over and over under your message, and shift each letter by its key letter. With the key LEMON, ATTACK AT DAWN becomes LXFOPV EF RNHR. Both Ts in ATTACK come out differently: one as X, the other as F.

The name is a mistake that stuck. Giovan Battista Bellaso described the keyword method in 1553, and Blaise de Vigenère got the credit later. It held up for about three centuries. Then in 1863 Friedrich Kasiski, a Prussian officer, published a way to find the key length from repeated chunks in the cipher text. Once you know the key is 5 letters long, every 5th letter is a plain Caesar cipher, and frequency counts break each one. Try your own keyword in the Vigenère cipher tool, which also shows the key under every letter and the full Vigenère table.

Transposition ciphers: the rail fence

A transposition cipher keeps every letter as it is and changes the order. The rail fence is the simplest one to do by hand. Write the message in a zigzag across a few rows (the rails), then read each row left to right. Here is WE ARE DISCOVERED FLEE AT ONCE on three rails:

Rail fence, 3 rails
W . . . E . . . C . . . R . . . L . . . T . . . E
. E . R . D . S . O . E . E . F . E . A . O . C .
. . A . . . I . . . V . . . D . . . E . . . N . .

WECRLTE ERDSOEEFEAOC AIVDEN

Run the three rows together and you get WECRLTEERDSOEEFEAOCAIVDEN. To decrypt, you work out how many letters go on each rail, fill them back in, and read the zigzag. The weak spot is that the letters themselves never change. A long rail fence message still has E as its most common letter, which tells a solver right away that the letters were only moved around.

The one-time pad, the cipher that can’t be broken

Take the Vigenère idea and push it to the limit. Use a key that is truly random, as long as the message, and used only once. With the key XMCKL, HELLO becomes EQNVZ. Because the key could have been anything, EQNVZ could just as well be any other five-letter word. Claude Shannon proved in his 1949 paper Communication Theory of Secrecy Systems that this kind of perfect secrecy is possible, and that it needs at least as much key as there is message.

Gilbert Vernam at AT&T patented an electric version for telegraph messages, granted in July 1919. The catch is all in the key. The Crypto Museum’s rules are strict: random characters, only two copies, used once, then destroyed. Reuse a pad and it can be attacked. Getting that much secret key safely to the other person is hard, which is why one-time pads never became the everyday way to protect data.

Enigma, briefly

Enigma was a German cipher machine that looked like a typewriter. Inside, a set of rotors turned every time a key was pressed, so the substitution changed with each letter. A plugboard on the front swapped pairs of letters as well. Bletchley Park puts the number of possible settings at 103 sextillion. So Enigma was a polyalphabetic cipher with an enormous, mechanical key.

It had a quirk. Because of the way current bounced back through the rotors, a letter could never be encoded as itself. That sounds harmless. It meant a codebreaker with a guessed word could rule out every position where a letter in the guess matched the cipher text. Polish mathematicians first broke Enigma in 1932, and in 1939 they shared their work with the British. Bletchley Park built on it through the war.

What types of ciphers are used today?

Modern ciphers work on bits instead of letters, and they come in two kinds.

  • Symmetric ciphers use one key to lock and unlock. AES is the standard one. NIST published it as FIPS 197 in November 2001. It scrambles data 128 bits at a time with a 128, 192 or 256 bit key. Our explainer on what AES encryption is goes through it in plain terms.
  • Public-key ciphers use a pair of keys. You can hand out one of them to anyone, and only the other one can undo what it locks. Whitfield Diffie and Martin Hellman set out the idea in their 1976 paper New Directions in Cryptography. On the web the two work as a team. In TLS 1.3, the protocol behind HTTPS, the handshake sets up a shared secret key, and a symmetric cipher such as AES protects the page itself.

Hashing often gets lumped in here too. A hash is a one-way fingerprint with no key and no way back, so it isn’t a cipher. Hashing vs encryption explains the difference. If you want to see a real cipher run, the Encrypt Text tool locks a message with AES-256 and a password, right in your browser.

How can you tell which cipher a message uses?

This is what cipher identifier sites do, and most of it you can do by eye. Start with what the characters are, then count letters.

What you seeTry this first
Only 0s and 1s, in groups of 8Binary, an encoding (binary translator)
Dots, dashes and slashesMorse code, also an encoding
Letters, digits, + and /, often ending in = or ==Base64, an encoding
Letters only, and the letter-count pattern looks like English slid along the alphabetCaesar or ROT13: try all 25 shifts
Letters only, and THE shows up as GSVAtbash
E, T and A are still the most common lettersA transposition, like the rail fence
A few letters are very common, but they aren't E, T and AGeneral substitution: solve by frequency
Letter counts are fairly even and no letter stands outVigenère or another polyalphabetic cipher
Long hex, or Base64 that decodes to gibberish bytesModern encryption. Without the key, stop here

A few more checks help narrow it down:

  • Count the letters. If the most common one makes up about 12% of the message, you likely have one alphabet (substitution or transposition). If nothing stands out, more than one alphabet is in play.
  • Look at the short words. In English a one-letter word is nearly always A or I, so if the spaces were kept, a single letter gives away a swap or two.
  • Look for repeats. In a long Vigenère message, the same three or four letters often turn up more than once. Measure the gaps between them. The key length usually divides those gaps, which is Kasiski’s method.
  • Check for an encoding first. Some puzzles stack an encoding on top of a cipher, like Caesar text that was then Base64 encoded. Decode with the Base64 tool, then see what’s left.
A quick way to rule things out: paste the message into the Caesar tool and the Atbash tool. Between them that covers 26 simple ciphers in a few seconds. If none of the lines read as words, move on to counting letters.

None of these checks work on AES. A modern cipher gives flat, random-looking output whatever went in, so letter counts and repeats tell you nothing. With a message like that, you need the key.

Sources

Written by
Jordan GibbsFounder, Relic

Jordan Gibbs is the founder of Relic, an end-to-end encrypted, permanent, searchable memory for everything you copy. He writes widely about AI, agents, and practical tooling on Medium, where he is read by tens of thousands, and builds privacy-first software. Here he covers how everyday tools like the clipboard actually work, and how to use them without handing your data to someone else.

MediumGitHubLinkedIn
Part of
Clipboard security & privacy
Keep reading
8 min

What is AES encryption?

AES is the encryption behind most of the secure data you touch daily, yet few people know what it is. How it works, what AES-256 means, and how secure it really is.

Read
7 min

Hashing vs encryption: what is the difference?

Hashing and encryption sound interchangeable but solve opposite problems: one is one-way, the other is meant to be undone. The difference, and why it matters.

Read
8 min

What is end-to-end encryption, in plain English

End-to-end encryption gets thrown around in marketing, but the idea is simple: only you hold the key, so nobody in the middle can read your data. How it actually works, minus the jargon.

Read
encryptionsecurity