Updated · By Pete Bromfield, IB examiner

IA idea · Cryptography & number theory

Breaking a cipher with letter frequencies and chi-squared

AI SLAA SLAI HLAA HL Accessible Also in: Statistics

Research question

How short can a message be before frequency analysis stops breaking a Caesar or affine cipher reliably, using a chi-squared statistic to score each possible key?

Adapt it: change the place, the data or the comparison until the question is yours.

Free: the A–E checklist an examiner uses, by email ↓

Why it makes a good exploration

Frequency analysis is a real attack with a real statistical core. Measuring how its success depends on message length turns a code-breaking game into a quantitative investigation.

The mathematics you'll need

  • Letter frequencies from a large reference text
  • Chi-squared statistic as a goodness-of-fit score
  • Affine functions mod 26 and which keys are valid (counting)
  • Proportion of successes against message length
  • Fitting a model to the success curve

Course labels show where a technique sits; using maths from outside your course is fine if you explain it clearly and say it is new to you.

Where the data comes from

Build reference frequencies from a public-domain book on Project Gutenberg; test on messages of different lengths from other texts.

  • Project Gutenberg — 70,000+ free public-domain books as plain text — ideal for letter and word frequency counts.
  • Desmos graphing calculator — Free graphing and regression (y₁ ~ ax₁ + b) — fit models to your data and show residuals.

Cite every source in a footnote where you use it and in your bibliography. Check the licence of any dataset you download.

A possible outline

  1. Explain the cipher and count the valid keys.
  2. Build reference frequencies.
  3. Score every key with chi-squared and pick the best.
  4. Test many messages of each length and record the success rate.
  5. Model the success rate and reflect on what makes short messages hard.

Pitfalls that cost marks

  • Using chi-squared as a test with a p-value when it is really being used as a score; say which.
  • Testing on the same text you built frequencies from.
  • Too few messages per length.

Showing personal engagement

  • Encrypt messages for friends and break theirs.
  • Compare languages you speak.
  • Find the shortest message you can still break.

See Criterion C: personal engagement for what examiners look for.

Which course is it for?

CourseFitMaths to lean on
AA SLGood fitLetter frequencies from a large reference text; Chi-squared statistic as a goodness-of-fit score
AA HLFits, but add an HL techniqueLetter frequencies from a large reference text; Chi-squared statistic as a goodness-of-fit score
AI SLGood fitLetter frequencies from a large reference text; Chi-squared statistic as a goodness-of-fit score
AI HLFits, but add an HL techniqueLetter frequencies from a large reference text; Chi-squared statistic as a goodness-of-fit score

Level: Accessible. A good first extended piece of maths, with room to go deeper. See how the IA differs between AA and AI, SL and HL.

How this idea reaches the top bands

Personal engagement (C)

Build and break your own small cipher or code, invent examples to test each result, and record the conjectures you made and the ones that turned out to be false.

Reflection (D)

Reflect on what each result guarantees and what it doesn't: which errors a check digit misses, which attacks a cipher survives, and how the answer depends on the size of the numbers. For this idea, start with: using chi-squared as a test with a p-value when it is really being used as a score; say which — say how it affects your answer.

Use of mathematics (E)

SL: Counting principles, probability or frequency statistics used correctly; any number theory (modular arithmetic, primes) introduced with your own small worked examples and explained, not quoted.

HL: Rigorous proofs (by contradiction or induction) of the number-theory facts you rely on, counting arguments made general, or a statistical attack tested formally.

Criteria A and B (presentation and communication) work the same way for every idea: see the guides to Criterion A and Criterion B.

Taking it further

Attack a Vigenère cipher by splitting it into Caesar ciphers, or compare chi-squared with another score.

Extending it for HL

Prove the key result in general (why the check digit catches every single-digit error, why the decryption undoes the encryption) rather than checking examples.

Before you start: the checklist an examiner uses

Every check for Criteria A–E in a 4-page PDF, the mistakes that cost the most marks and a self-assessment grid. We'll email it with a short IA tip every few days, timed to your deadline if you give it. Free — no account, no payment.

Turn this idea into your IA

Similar ideas

All cryptography ideas · AI SL ideas · AA SL ideas · AI HL ideas · AA HL ideas · All 239 IA ideas