Polygraphic substitution / modulo 26

Hill cipher

Encrypt or decrypt uppercase letter blocks with a checked 2×2 or 3×3 integer key matrix and a visible modular inverse.

01 / Workspace

Encrypt a message

2×2 / column vectors
Mode

The selected direction is always used. The tool does not guess a matrix, alphabet, or orientation.

Entries are read across each row. Message blocks are column vectors.

2 × 2 key matrix

Use signed ASCII decimal integers from −1,000,000 through 1,000,000. Each entry is reduced to 0–25 modulo 26.

Matrix check

det(K)
Not available
det(K) mod 26
Not available
gcd(det, 26)
Not available

Normalized K

Not available

Inverse K−1 mod 26

Not available

Checking the matrix.

0 / 10,000 code points

ASCII letters are kept and uppercased; every other code point is omitted. Encryption appends X only when needed to complete the final block.

Keyboard: press Ctrl+Enter or Command+Enter anywhere in the tool to run the selected mode.

Status: Ready to encrypt.

02 / Result

Result

No result yet

Output is ungrouped uppercase ASCII. Any nonletters from the input are not represented.

03 / Exact convention

How this Hill cipher variant works

  1. Number the alphabet. ASCII A through Z become 0 through 25. Lowercase ASCII is uppercased. Whitespace, punctuation, digits, accents, emoji, combining marks, and every other non-ASCII code point are omitted.
  2. Read the key by rows. The visible entries form K from left to right, top to bottom. Signed entries are reduced with nonnegative modulo 26, so −1 becomes 25 and 1,000,000 becomes 14.
  3. Use column vectors. Consecutive pairs or triples form P. Encryption calculates C = K·P mod 26. If the final plaintext block is short, X values are appended until it is full.
  4. Decrypt with the inverse. Decryption calculates P = K−1·C mod 26. Ciphertext letter count must already be a multiple of the matrix size, and a final X is never removed automatically because it may be genuine text.
  5. Require a reversible key. This tool runs only when gcd(det(K), 26) = 1. It computes K−1 = det(K)−1·adj(K) mod 26 and refuses a noninvertible matrix in either mode.

Known-answer checks

2×2 key
[[3,3],[2,5]] maps HELP to HIAT; its inverse is [[15,17],[20,9]].
3×3 key
[[6,24,1],[13,16,10],[20,17,15]] maps ACT to POH.
Padding
With the 2×2 key above, CAT is prepared as CATX, encrypts to GEWX, and decrypts to CATX.

Limits and interpretation

  • This is a fixed 26-letter variant with A=0, numeric row-major keys, column message vectors, and X padding. It does not support A=1 numbering, row message vectors, custom alphabets, keyword keys, affine offsets, key recovery, or cryptanalysis.
  • Input is limited to 10,000 Unicode code points and 20,000 UTF-16 code units. Matrix entries are limited to 12 UTF-16 code units and the inclusive numeric range −1,000,000 through 1,000,000. Invalid input produces no partial result.
  • Filtering is irreversible: case and all omitted characters are not recoverable. Browser text controls also normalize CR and CRLF line endings to LF before processing.
  • A decrypted trailing X may be padding or an original X. The tool leaves it visible so that interpretation remains with the user.