2 ENIGMA 37 of possible initial rotor settings by a factor of 26. 3 putative rotor settings remaining. 3 can be extended to more than two cycles, in which case we obtain a proportionally greater reduction in the number of surviving keys. With a sufficient number of cycles, we can uniquely identify the initial rotor settings. In fact, with n pairs of cycles we expect to reduce the number of possible keys by a factor of 26”. Therefore, with a sufficient number of cycles, we can recover the key. Amazingly, by recovering the initial rotor settings in this manner, stecker values are also recovered-essentially for free.

The Hill cipher, with an invertible matrix A (mod 26) and block length n, can be viewed as a substitution cipher utilizing an alphabet of 26n possible “letters” and the expected letter frequency distribution in the ciphertext is far more uniform than that of the plaintext. This makes a ciphertext only attack generally impractical. However, the Hill cipher is highly vulnerable to a known plaintext attack. Suppose that Trudy suspects Alice of using a Hill cipher with an n x n encryption matrix A .

8. Suppose that Trudy intercepts C = 110 101 111. a. Find a putative key K’ such that the corresponding putative plaintext P’ yields the word GET. b. Find anot,her putative key K” such that the corresponding putative plaintext is TAG. CLASSIC CIPHERS 24 16. 9 and the additive sequence A0 188,900, A1 = 92,331, A2 = 23,546 encrypt and decrypt the plaintext message folgender Frieden Februar. Assume that the additive arithmetic is taken modulo 100,000. Show all intermediate steps. 17. Consider two ciphers, Cipher A and Cipher B, and suppose that Cipher A has a 64-bit key, while Cipher B has a 128-bit key.

