# Has this variant of a ‘book cipher’ ever been used?

**URL:** <https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837>\
**Category:** Factual Questions\
**Created:** [September 8, 2025, 4:26am UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837 "2025-09-08T04:26:45Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ferris](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ferris/32/11573_2.png) [@Ferris](https://boards.straightdope.com/u/Ferris)\
**Post date:** [September 8, 2025, 4:26am UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/1 "2025-09-08T04:26:45Z")

</div>

I’ve been mildly interested in book ciphers ever since learning about the [Beale ciphers](https://en.m.wikipedia.org/wiki/Beale_ciphers) and I recently started thinking about using a ‘Word Finder’ puzzle grid and relative coordinates in place of a book and ‘page/line/word’ instructions.

How it would work is:

Grid can be any size. Let’s take a 20x20 one as an example. Starting letter ‘H’ might be in eight separate places on the grid, but we select the one at coordinates 18,12. Our second letter, ‘E’ could be in any of maybe twenty three places, but we choose the one at 7,7. The relative coordinates from the ‘H’ are -10,-5 but instead we treat the grid like a ‘wraparound’ screen, so go 9 rows ‘forwards’ and 15 columns ‘up’.

The coded message for ‘He’ becomes ‘18120915’.

Where (if ever) has this type of ‘coordinate’ coding been used before (either real life or fiction)?

Possibly more suited to the IMHO forum, but would this cipher rate as strong? My guess is it would, since number frequency doesn’t necessarily correlate with letter frequency. There’s still the same weakness as with any book code, of course.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [September 8, 2025, 1:03pm UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/2 "2025-09-08T13:03:58Z")

</div>

If you didn’t use relative addressing, so the “E” in your example would be “0707” then you just have a simple letter substitution cipher. So negligible security. Adding in that e.g. H’s and E’s occur multiple times and you can select which encoding to use at random blunts the letter frequency statistics but does not erase them. So it might take 2x or 10x as much ciphertext to break the code, but it’ll break trivially once the enemy has enough to work with.

You adding the relative addressing idea is sneaky. That obfuscates the fixed one-to-many mapping I described in the prior paragraph. But also introduces challenges for the legit recipient in that any mistake in encoding, transmission, or reception, means the entire rest of the decoding train is totally derailed into gibberish. From your example imagine trying to decode a much longer message that begins with “he” but the recipient received as “181209 **14** …” with the rest received correctly. Oops. Not only is the second letter, the “e” wrong, but so is every subsequent letter.

One comment: when you’re filling your encoding grid with letters, how secure it will be will change depending on whether you fill it with letters according to English letter frequency stats, same number of each letter, or even the opposite, where “e” is rare and “z” is common in your grid.

Sorta bottom line:  
None of this sort of ciphering is strong in the modern 21st century computer-driven codebreaking sense of strong. But would this have kept folks in the 1910s out of your secret bidness? Better than a plain Caesar cipher for sure, but it still suffers from the fact that by encrypting at the letter level, you’re preserving some echo of the natural letter frequency. Which is enough of a leg up for it to be broken in principle - So decipherable given enough ciphertext and enough stubby pencil work.

---

<div class="post-metadata">

**Author:** ![CalMeacham](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/calmeacham/32/35_2.png) [@CalMeacham](https://boards.straightdope.com/u/CalMeacham)\
**Post date:** [September 8, 2025, 2:01pm UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/3 "2025-09-08T14:01:19Z")

</div>

You want your correspondent to have access to the same book you’re using. That’s why they used an almanac in Sherlock Holmes’ _Valley of Fear_ and they used law books (instead of the implied book of the bible) in _Manhunter/Red Dragon_.

- Both of those were deduced by people “breaking” the cipher by trying to figure out which books the two correspondents would be likely to have access to. If I understand your description, this one would require both of them to have access to the same “word search” puzzle. I could see this if they’d arranged beforehand to use the same edition of a word search from the same publisher, or to always use the puzzle from Tuesday of that week found in a particular newspaper. But misunderstandings could render the cipher unusable to the receiver.

And, of course, it’s an archaic code for this day of computer-driven encryption, as **LSL** pointed out.

---

<div class="post-metadata">

**Author:** ![Saint\_Cad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/saint_cad/32/18907_2.png) [@Saint\_Cad](https://boards.straightdope.com/u/Saint_Cad)\
**Post date:** [September 8, 2025, 3:16pm UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/4 "2025-09-08T15:16:02Z")

</div>

redacted

---

<div class="post-metadata">

**Author:** ![markn\_1](https://avatars.discourse-cdn.com/v4/letter/m/f9ae1b/32.png) [@markn\_1](https://boards.straightdope.com/u/markn_1)\
**Post date:** [September 8, 2025, 4:26pm UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/5 "2025-09-08T16:26:09Z")

</div>

Both versions of the proposed cipher are [polyalphabetic ciphers](https://en.wikipedia.org/wiki/Polyalphabetic_cipher). It is more secure than some classical ciphers because of the size of the key; many classical ciphers use a key small enough to memorize. The book cipher uses a whole book as the key, which would make it more secure, except that guessing the book reveals the whole key. The OP’s cipher is somewhere in between: it uses a 400 letter key, which is too long to memorize so must be written down by both parties, and can’t be easily guessed, but because it is written down it could be stolen. Nevertheless, cryptanalysis would not be very difficult. Techniques like those used to cryptanalyze the [Vigenère cipher](https://en.wikipedia.org/wiki/Vigen%25C3%25A8re_cipher#Cryptanalysis) would probably work, given enough ciphertext to work with.

---

<div class="post-metadata">

**Author:** ![TroutMan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/troutman/32/6721_2.png) [@TroutMan](https://boards.straightdope.com/u/TroutMan)\
**Post date:** [September 8, 2025, 5:14pm UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/6 "2025-09-08T17:14:19Z")

</div>

> [@LSLGuy](#):
>
> You adding the relative addressing idea is sneaky. That obfuscates the fixed one-to-many mapping I described in the prior paragraph.

You’re right, but any advantage of the relative addressing is out the window once the codebreaker knows the size of the grid. At that point, the security is identical to using absolute addresses.

And determining the grid size is probably pretty easy by looking at the range of numbers in the code. You could further obfuscate that by wrapping around multiple times, but I still suspect it wouldn’t be difficult to figure it out.

---

<div class="post-metadata">

**Author:** ![markn\_1](https://avatars.discourse-cdn.com/v4/letter/m/f9ae1b/32.png) [@markn\_1](https://boards.straightdope.com/u/markn_1)\
**Post date:** [September 8, 2025, 7:10pm UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/7 "2025-09-08T19:10:27Z")

</div>

I just noticed that some Discourse or copy/paste issue apparently corrupted the URL that I entered for Vigenère cipher. It should be [Vigenère cipher - Wikipedia](https://en.wikipedia.org/wiki/Vigen%C3%A8re_cipher#Cryptanalysis).

---

<div class="post-metadata">

**Author:** ![Ferris](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ferris/32/11573_2.png) [@Ferris](https://boards.straightdope.com/u/Ferris)\
**Post date:** [September 8, 2025, 9:05pm UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/8 "2025-09-08T21:05:30Z")

</div>

> [@LSLGuy](#):
>
> You adding the relative addressing idea is sneaky. That obfuscates the fixed one-to-many mapping I described in the prior paragraph. But also introduces challenges for the legit recipient in that any mistake in encoding, transmission, or reception, means the entire rest of the decoding train is totally derailed into gibberish.

That’s an excellent point I hadn’t considered. The risk of error probably makes it impractical for anything but short non-vital messages.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [September 8, 2025, 9:28pm UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/9 "2025-09-08T21:28:03Z")

</div>

Plenty of historically-used ciphers also had the problem of a single error propagating through the whole message. That was also a feature of the Enigma, for instance.

---

<div class="post-metadata">

**Author:** ![Dr.Strangelove](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dr.strangelove/32/6613_2.png) [@Dr.Strangelove](https://boards.straightdope.com/u/Dr.Strangelove)\
**Post date:** [September 8, 2025, 10:12pm UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/10 "2025-09-08T22:12:12Z")

</div>

> [@markn\_1](#):
>
> The OP’s cipher is somewhere in between: it uses a 400 letter key, which is too long to memorize so must be written down by both parties

Not at all. Assuming the 400 letters form a passage of text, that’s only ~80 words, which almost anyone could memorize with a little practice. It’s just a few sentences. Of course, you’d want it to cover all the letters, but pangrams of that length are easy.

Having the key be human-readable text lowers the entropy vs. random letters, but this isn’t exactly a secure system to start with.

This post is just over 400 characters. Easy.

---

<div class="post-metadata">

**Author:** ![Ferris](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ferris/32/11573_2.png) [@Ferris](https://boards.straightdope.com/u/Ferris)\
**Post date:** [September 8, 2025, 11:22pm UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/11 "2025-09-08T23:22:59Z")

</div>

> [@Dr.Strangelove](#):
>
> Assuming the 400 letters form a passage of text, that’s only ~80 words, which almost anyone could memorize with a little practice.

Agree with the point about memorising. Even though a typical Word Finder grid is designed to look like a random collection of letters, I’d neglected to consider that it does contain plenty of non-random actual words. That probably would aid memorisation.

---

<div class="post-metadata">

**Author:** ![Dr.Strangelove](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dr.strangelove/32/6613_2.png) [@Dr.Strangelove](https://boards.straightdope.com/u/Dr.Strangelove)\
**Post date:** [September 8, 2025, 11:43pm UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/12 "2025-09-08T23:43:45Z")

</div>

There are varying degrees of randomness you could include. Even 400 random letters wouldn’t be _that_ difficult to memorize, particularly in some earlier era where people are more used to memorizing long passages (just come up with a word for each letter and memorize that). A series of totally random words would be significantly easier, and an actual sensible passage of text easier yet.

You could add a bit of challenge by having a few different geometries: zig-zag, spiral, boustrophedonic, etc. Still no challenge to a computer but would increase the workload a bit for someone doing it manually (in the non-random-letter case, that is).

---

<div class="post-metadata">

**Author:** ![Tim\_T-Bonham.net](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@Tim\_T-Bonham.net](https://boards.straightdope.com/u/Tim_T-Bonham.net)\
**Post date:** [September 9, 2025, 4:02am UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/13 "2025-09-09T04:02:48Z")

</div>

There is also the fact that this cipher considerably expands the length of the coded transmission – your 2-character plaintext becomes 8 digits when encoded. (Note that this is not true in a book cipher – 3 numbers, usually 6-7 digits, would encode a full word. Still some expansion, since the average English word is about 5 characters. Though skipping articles would improve that. An advantage of the Enigma machine was that the ciphered text was the same length as the original plaintext.)

A longer coded transmission can cause practical problems in use. Longer messages are harder to conceal in some secret method. And such messages are often sent via clandestine transmitters – a longer transmission gives the enemy more time to notice and radio-locate the source.

Also, a longer cipher increases the chances for a simple mistake in ciphering, transmitting, receiving, or deciphering. And several respondents have already pointed out, such a mistake can garble much of the intended message.

---

<div class="post-metadata">

**Author:** ![Dr.Strangelove](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dr.strangelove/32/6613_2.png) [@Dr.Strangelove](https://boards.straightdope.com/u/Dr.Strangelove)\
**Post date:** [September 9, 2025, 4:13am UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/14 "2025-09-09T04:13:47Z")

</div>

If, instead of using numbers, you just encoded 0-\>A, 1-\>B, etc., it would only require two symbols per character.

---

<div class="post-metadata">

**Author:** ![TokyoBayer](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tokyobayer/32/13989_2.png) [@TokyoBayer](https://boards.straightdope.com/u/TokyoBayer)\
**Post date:** [September 12, 2025, 12:25am UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/15 "2025-09-12T00:25:13Z")

</div>

> [@markn\_1](#):
>
> The book cipher uses a whole book as the key, which would make it more secure, except that guessing the book reveals the whole key.

There was a German nationality in Japan during WWII named Richard Sorge. He was secretly a communist and spied for the USSR.

He successfuly used a [book cipher](https://www.kaspersky.com/blog/ww2-zorge-book-cipher/8638/):

> [@](#):
>
> Sorge used the German Statistics Almanac, which was an ideal match for his purpose: different numbers in the tables’ columns were united into the chains which, in turn, served the gamma to decipher messages. It was random enough for Sorge’s messages to evade the Japanese counterintelligence’s interception until they questioned Sorge’s radio operator, Max Clausen.
> 
> It was Sorge’s forced error, as he had to use only one person as a radio operator and a coder, due to massive volumes of data transmitted, and the difficulty of engaging more people into the intelligence operations in Japan.
> 
> The cryptography historians noted that the Soviet intelligence service succeeded in creation and use of the so-called ‘manual ciphers’ which did not require any machinery.

---

<div class="post-metadata">

**Author:** ![markn\_1](https://avatars.discourse-cdn.com/v4/letter/m/f9ae1b/32.png) [@markn\_1](https://boards.straightdope.com/u/markn_1)\
**Post date:** [September 12, 2025, 1:50am UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/16 "2025-09-12T01:50:24Z")

</div>

Yes, a book cipher can be quite secure if the adversary does not know the book or has no access to it, and the book itself has no correlations between different words. (For example, a dictionary, whose words are in alphabetical order, would not be a good choice.) And if the user ensures that they never encode a word or letter with the same ciphertext more than once, its security approaches that of a one-time pad.

---

<div class="post-metadata">

**Author:** ![TokyoBayer](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tokyobayer/32/13989_2.png) [@TokyoBayer](https://boards.straightdope.com/u/TokyoBayer)\
**Post date:** [September 12, 2025, 4:01am UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/17 "2025-09-12T04:01:34Z")

</div>

The Japanese sucked at breaking codes, and they never broke his code. However, after the ring was discovered, they were able to go back and decode the messages using the original book.

---

<div class="post-metadata">

**Author:** ![Ferris](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ferris/32/11573_2.png) [@Ferris](https://boards.straightdope.com/u/Ferris)\
**Post date:** [September 12, 2025, 6:45am UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/18 "2025-09-12T06:45:40Z")

</div>

> [@Tim\_T-Bonham.net](#):
>
> There is also the fact that this cipher considerably expands the length of the coded transmission – your 2-character plaintext becomes 8 digits when encoded.

Another point I hadn’t considered, thanks. I can see the practical disadvantages of a longer coding, but then I’m not sure how it could be determined that ‘2 becomes 8’ from an encoded sequence of numbers. The message could be sent in random blocks (to look more like words), or include non-coding dots, hyphens or X’s to further disguise it. Adds to the length even more, though.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [September 13, 2025, 1:00am UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/19 "2025-09-13T01:00:23Z")

</div>

2 becomes 8 does not (in itself) make it more secure. It just makes it less efficient. And a longer coded message takes more time to transmit, meaning more opportunity to catch you transmitting it (which, while not as bad as cracking it, is still bad).

---

<div class="post-metadata">

**Author:** ![dtilque](https://avatars.discourse-cdn.com/v4/letter/d/d6d6ee/32.png) [@dtilque](https://boards.straightdope.com/u/dtilque)\
**Post date:** [September 13, 2025, 2:14am UTC](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837/20 "2025-09-13T02:14:27Z")

</div>

> [@Chronos](#):
>
> And a longer coded message takes more time to transmit, meaning more opportunity to catch you transmitting it (which, while not as bad as cracking it, is still bad).

That’s not as much of an issue these days. It’s not like spies are transmitting messages via Morse Code on hand-operated radios like they did in WWII.

[Next page](https://boards.straightdope.com/t/has-this-variant-of-a-book-cipher-ever-been-used/1022837.md?page=2)
