A scrambled alphabet, used consistently§
In a monoalphabetic substitution cipher, each plaintext letter maps to one different ciphertext letter for the entire message. A key might map A to Q, B to W and so on, but it need not follow any keyboard or keyword pattern. Unlike Caesar, there is no small numerical key to enumerate.
Why it still falls§
English is highly redundant. E remains the commonest plaintext letter even after it is
renamed; THE retains the pattern of three distinct letters; and HELLO
retains the pattern 0-1-2-2-3. Word boundaries make newspaper cryptograms easier,
but continuous ciphertext still contains n-gram frequencies such as TH, HE and ING.
From hand solving to hill climbing§
A hand solver starts with frequency counts, one-letter words, doubled letters and likely short words. An automatic solver starts similarly, then scores the decrypted text with a language model. It swaps two assignments in a candidate alphabet, keeps swaps that improve quadgram fitness, and restarts from perturbed keys to escape local optima. The result is a search guided by English rather than a futile walk through every permutation.
Use enough text§
With fewer than about 60 letters, the statistical evidence is thin; with 150 or more, common patterns repeat and recovery becomes much steadier. Do not treat a beautifully English-shaped 30-letter output as proof. Verify that the recovered key consistently transforms the full message.
For a pair-based cipher whose statistics are less familiar, continue to Playfair.
Frequently asked questions§
How many keys does a substitution cipher have?
A full mixed alphabet has 26 factorial possible permutations, about 4 × 10 to the power of 26. Exhaustive search is impractical, which is why substitution is more interesting than Caesar despite using the same basic idea.
What patterns survive a substitution?
Every occurrence of a plaintext letter becomes the same ciphertext letter, so word lengths, repeated letters and repeated word patterns survive. THE and THAT have different letter-pattern signatures, and doubled letters strongly constrain guesses.
Why do solvers sometimes miss rare letters?
A ciphertext that never uses Q, J or Z contains almost no evidence about where that plaintext letter maps. Several keys can decrypt the observed text equally well; context, a crib or more ciphertext resolves the ambiguity.