Variant Beaufort — C = P - K. Vigenere's rule run in the decryption direction.
C = P - K: Vigenere encryption with the decryption rule.
A worked example§
Encrypting a sample with the cipher itself, at build time:
MEET ME BY THE OLD CLOCK TOWER AT DAWN
Key: LEMON
produces the ciphertext
BASF ZT XM FUT KZP PAKQW GDSSD NI ZOIA
This example is generated by running the cipher when the page is built, and the round trip is checked, so it always matches what the solver does.
How it is broken§
The same two-stage attack. A message solved under this name also solves under Vigenere with the complementary key, which is why the solver reports the better-known name on a tie.
History and context§
The German army's variant, and a good illustration that a cipher's identity is the algebra, not the label.
See also§
Vigenère · Beaufort · Gronsfeld · Porta · Quagmire III (keyed alphabet) · Sum-clock (additive wheels)
Browse every cipher in the Polyalphabetic ciphers family, read the history of codebreaking, or return to the wiki main page.
Frequently asked questions§
How is the Variant Beaufort broken?
The same two-stage attack. A message solved under this name also solves under Vigenere with the complementary key, which is why the solver reports the better-known name on a tie.
What key does the Variant Beaufort use?
keyword. The keyspace is unbounded in practice.
How much ciphertext do I need?
At least 24 characters for this solver to attempt it; short messages can be readable and still not be proof.
Can I break a Variant Beaufort on this page?
Yes — the browser solver on this page handles it directly. Paste the ciphertext into the solver and press the button.