Autokey — A short primer starts the key and the plaintext itself continues it, so the key never repeats.
Key = short primer followed by the plaintext itself. Solved by chain decomposition.
A worked example§
Encrypting a sample with the cipher itself, at build time:
MEET ME BY THE OLD CLOCK TOWER AT DAWN
Key: QUEEN
produces the ciphertext
CYIX ZQ FC MTI PJW JPCNN VZKGB TH ZENN
This example is generated by running the cipher when the page is built, and the round trip is checked, so it always matches what the solver does.
How it is broken§
No period to find, which defeats the standard attack. Instead the key is unwound in chains: guess the primer, and each recovered letter reveals the next key letter.
History and context§
Vigenere's own contribution, in 1586 — the genuinely strong idea in the book, and the one that did not catch on, because a single error destroys everything after it.
See also§
Vigenère · Beaufort · Variant Beaufort · Gronsfeld · Porta · Quagmire III (keyed alphabet)
Browse every cipher in the Polyalphabetic ciphers family, read the history of codebreaking, or return to the wiki main page.
Frequently asked questions§
How is the Autokey broken?
No period to find, which defeats the standard attack. Instead the key is unwound in chains: guess the primer, and each recovered letter reveals the next key letter.
What key does the Autokey use?
primer word. The keyspace is unbounded in practice.
How much ciphertext do I need?
At least 40 characters for this solver to attempt it; short messages can be readable and still not be proof.
Can I break a Autokey on this page?
Yes — the browser solver on this page handles it directly. Paste the ciphertext into the solver and press the button.