Essentially, a ciphertext is a piece of text where the individual letters have been transformed according to a rule system – substitution cipher rules replace the shape of the letters (as if you had just changed the font), while transposition cipher rules manipulate the order of the letters.

THIS IS A CIPHER —> UIKT KT B DKQIFS  (substitute each letter with the one after it in the alphabet)

THIS IS A CIPHER —> SIHT SI A REHPIC (transpose the letters, writing each word back-to-front)

So, as long as (a) you know [or can crack!] the rules by which the “plaintext” (the original unenciphered text) was transformed, and (b) those rules can be played out in reverse, then you can decipher the ciphertext.

OK so far… but if you’re looking at historical ciphers, there’s a problem.

Prior to 1400, transposition ciphers were extremely rare, partly because words themselves were rare. Many documents were written without spaces – and without spaces, where do words begin and end? Effectively, this meant that in-word transposition ciphers (such as reversing syllables, as the Florentines Antonio Averlino and Leonardo da Vinci both used) would only happen in those few places (such as Florence) where people had a modern concept of what words were. A well-known modern example is “Pig Latin“, a (20th century) humorous in-word transposition cipher: and there’s the 19th century “loucherbem” in French, too.

Round about 1465, these flowered into some kind of complex system (by an unknown practitioner, and now apparently lost forever): Alberti, writing in Rome during 1465-1467, mentioned a number of ideas for a complex transposition system, though he recommended his own cipher wheel in preference to them.

Yet after 1500, these basically disappeared into the historical footnotes of cryptographic works. What replaced them (circa 1550) was the “rail-fence” Renaissance notion of transposition cipher: this was instead grounded in the print-centric culture of movable type. This saw messages as sequences of characters tick-tocking away to a metronomic beat (i.e. one per tick), and transposition ciphers not as a way of disrupting word contents, but instead as a way of disrupting (& subverting) the metronomic pulse of letters – a very different beast indeed.


THIS IS A CIPHER ---> T I I A I H R    (Railfence cipher)
                      H S S C P E X

It is this latter (16th century) two-dimensional transposition cipher that is widely used in modern cipher-systems, not the late medieval ‘anagrammatical’ transposition cipher.


Older histories of cryptography tended to situate all these cipher techniques within what I call a  “progressivist mythology” – the mistaken notion that every new idea not only flows out of all previous ideas, but also improves and refines them. In practice, of course, that’s not how things work : many brief local flowerings of ideas (basically, all the cipher varieties marked in italic above) made almost no impression on contemporary cryptographic practice. Even Vigenère’s autokey cipher (taught on every modern cipher course) did not get picked up by cryptography practitioners for more than two hundred years!

And now for the punchline of this post: if you discard the progressivist mythology, the range of possible local enciphering strategies for a given ciphertext is sharply constrained by the date and position of a document.

I argue that the Voynich Manuscript ciphertext is likely a prime example of this: its internal evidence dates it no earlier than 1450 and no later than 1470 – right at the time of the brief flowering of the kind of syllabic and interline transposition ciphers mentioned by Alberti in his De Componendis Cyfris (1467).

And so, if we seek to apply “pure” modern substitution cipher analytical techniques to something built around an unknown transposition cipher system, we would surely fail to make any sense of it – and this is, I believe, what has happened in the case of the VMs… why it has remained a “cipher mystery” for so long.

9 thoughts on “What is a ciphertext?

  1. WOW!!! Nick, this certainly seems spot on! As you say, it fits the time period and lack of historical attestation perfectly! However, given the low entropies and repeated clusters seen in Voynich text, how do you think the Voynich cipher would be a transposition cipher? Do you think that the repeated clusters were then transposed by the system? Or do you think the Voynich system was a mixed transposition/substitution system?

    So far I’ve thought that the Voynich system was a nomenclator that somehow made use of the repeated clusters. Am I mistaken?


  2. Hi Dennis,

    If all people are looking for is substitution mechanisms, then even a small amount of transposition would be enough to undo their best efforts.

    No, I don’t think it’s a “pure” transposition cipher – but I also don’t think it’s a “pure” substitution cipher. “A little bit of both” is my best guess. 🙂

    Cheers, ….Nick P….

  3. Hi Nick! In fact my current hypothesis is that the Voynich system is a nomenclator with a word transposition on top. The prefix-root-suffix structure of Voynichese “words” would provide the coordinates in the nomenclator. The word transposition would explain the line structure seen by Currier and also the apparent lack of syntax detected by Marke Finche.

    Marke said that simply scrambling lines randomly still doesn’t give the degree of disorder seen in his syntax (WPPA) analyses. So it would be on a scale somewhat larger than a line. I’ve also thought that there might be different regions of the nomenclator for use at line beginnings, middles, and ends.

    That might agree with your historical observation here. What do you think?

    Cheers, Dennis S.

  4. Hi Dennis,

    I strongly suspect that the line-initial letter-patterns indicate (as Philip Neal tentatively suggested a long time ago) an additional column added to the front of words; and that the line-final letter-patterns (mainly m and am) indicate something like a hyphen. So, I’m not currently convinced about the need to invoke multiple nomenclators to explain what we see.

    “Neal Keys” (horizontal and vertical) could well be part of an interesting kind of transposition cipher, consistent with the kind of thing described by Alberti: but that’s only ever going to be part of the story.

    Cheers, ….Nick P….

  5. Prashant Verma on November 6, 2009 at 6:49 am said:

    I would like to know that why we call encrypted text as “Cipher ” Text?

  6. “encrypted” = made hidden
    “enciphered” = made hidden, one letter at a time according to an algorithm
    “encoded” = made hidden, one words at a time according to a dictionary

    Of course, there are plenty of variations on all these themes… 🙂

  7. David Ewald on March 11, 2013 at 10:49 pm said:

    Have you ever heard of a cipher combining text from both sides of a page to create a message? I have found some very intriguing examples of this, but have not found any literature supporting it. There is a prime example of it here in this link:;jsessionid=9A6CCD73222CDC2C2CC6B41B2B2D5F6D?trs=4&qvq=q%3Ashakespeare+sonnets%3Bsort%3AReference_Number%2CImage_Sequence_Number%2CPage%2CTitle%3Blc%3AManchester%7E91%7E1&mi=2&cic=Manchester%7E91%7E1

  8. Nick check out your new font type on the ipad
    The formatting of underlined, bold etc is wrong.
    Words flow into each other and it becomes un-readable.

    Technical: there is something wrong in the style sheet of that font?

    Ex. because words

  9. D: I’ll have a look over the weekend. I thought it was all working… but maybe it isn’t. *sigh* 🙁

Leave a Reply

Your email address will not be published. Required fields are marked *

Post navigation