---
title: "How Does Encryption Work? From Caesar Ciphers to HTTPS"
description: "How encryption works, from the Caesar cipher to HTTPS: build and break ciphers in Python, then see how strangers agree a secret key in public."
slug: how-does-encryption-work
canonical: https://learn.modernagecoders.com/blog/how-does-encryption-work/
date: 2026-09-28
dateModified: 2026-09-28
category: "Programming"
tags: ["Cryptography", "Python", "Computer Science", "Security"]
keywords: ["how does encryption work", "caesar cipher python", "frequency analysis", "what is encryption", "diffie hellman explained simply", "how https works", "encryption for beginners"]
readTime: "9 min read"
author: "Modern Age Coders Team"
---
# How Does Encryption Work? From Caesar Ciphers to HTTPS

> Build a Caesar cipher in Python, break it two different ways, and then see the clever idea that lets your browser agree a secret key with a website while anyone could be listening.

![How encryption works: a padlock above the word HELLO shifted three letters to KHOOR](/images/blog/how-does-encryption-work/00-hero.png)

*By Modern Age Coders Team · 2026-09-28 · 9 min read*

**Quick answer:** Encryption scrambles plaintext into ciphertext using a cipher and a secret key; only the right key reverses it. The Caesar cipher shifts letters by a fixed amount, but with only 26 keys it falls to brute force, and letter substitution falls to frequency analysis because e stays the most common letter. Modern ciphers such as AES use at least 2 to the power 128 keys and leave no patterns. Diffie-Hellman key exchange lets two strangers agree a secret key in public using one-way maths, which is how HTTPS sets up the padlock connection.

Every time you see a padlock next to a website address, send a message on most chat apps, or pay online, encryption is scrambling your data so that anyone who intercepts it sees nonsense. Only someone with the right key can turn it back into the original. The maths behind it is some of the cleverest in computing, but the core ideas can be understood with nothing more than the alphabet and a little Python.

This guide builds up from the oldest cipher in common use, the Caesar cipher, shows two ways to break it, and then explains the big idea that makes modern secure websites possible: two strangers agreeing a secret key while everyone is listening. Every program below was run, and the outputs are real.

## What is encryption?

Encryption turns readable **plaintext** into scrambled **ciphertext** using a **key**. Decryption uses a key to turn it back. The method itself, the **cipher**, is usually public. The security comes from keeping the key secret, and from making the key impossible to guess.

## The Caesar cipher

According to the Roman historian Suetonius, Julius Caesar protected his letters by shifting every letter three places along the alphabet: A becomes D, B becomes E, and so on, with X, Y and Z wrapping round to A, B and C. The key is simply the size of the shift.

![Caesar cipher with a shift of 3: the plain alphabet above the cipher alphabet starting at D, so MEET ME AT THE LIBRARY becomes PHHW PH DW WKH OLEUDUB](/images/blog/how-does-encryption-work/01-shift.png)

*The whole cipher fits on one strip of paper.*

In code, each letter is turned into a number from 0 to 25, the key is added, and the result wraps round using the remainder after dividing by 26. That wrapping is [modular arithmetic](/blog/modular-arithmetic-explained), the same maths as a clock.

**caesar.py**

```python
def shift_text(text, key):
    out = ""
    for ch in text:
        if ch.isalpha():
            base = ord("A") if ch.isupper() else ord("a")
            out += chr((ord(ch) - base + key) % 26 + base)
        else:
            out += ch          # spaces and punctuation stay as they are
    return out

if __name__ == "__main__":
    secret = shift_text("Meet me at the library at noon", 3)
    print("encrypted:", secret)
    print("decrypted:", shift_text(secret, -3))
```

**Output**

```text
encrypted: Phhw ph dw wkh oleudub dw qrrq
decrypted: Meet me at the library at noon
```

## Breaking it: try every key

The Caesar cipher has a fatal weakness: there are only 26 possible keys. An attacker does not need to be clever. They can just try all of them, which is called a **brute-force attack**:

**brute.py**

```python
from caesar import shift_text

intercepted = "Wkh sdvvzrug lv eoxh gudjrq"
for key in range(26):
    print(f"{key:>2}: {shift_text(intercepted, -key)}")
```

**Output**

```text
0: Wkh sdvvzrug lv eoxh gudjrq
 1: Vjg rcuuyqtf ku dnwg ftciqp
 2: Uif qbttxpse jt cmvf esbhpo
 3: The password is blue dragon
 4: Sgd ozrrvnqc hr aktd cqzfnm
 5: Rfc nyqqumpb gq zjsc bpyeml
 6: Qeb mxpptloa fp yirb aoxdlk
 7: Pda lwoosknz eo xhqa znwckj
 8: Ocz kvnnrjmy dn wgpz ymvbji
 9: Nby jummqilx cm vfoy xluaih
10: Max itllphkw bl uenx wktzhg
11: Lzw hskkogjv ak tdmw vjsygf
12: Kyv grjjnfiu zj sclv uirxfe
13: Jxu fqiimeht yi rbku thqwed
14: Iwt ephhldgs xh qajt sgpvdc
15: Hvs doggkcfr wg pzis rfoucb
16: Gur cnffjbeq vf oyhr qentba
17: Ftq bmeeiadp ue nxgq pdmsaz
18: Esp alddhzco td mwfp oclrzy
19: Dro zkccgybn sc lveo nbkqyx
20: Cqn yjbbfxam rb kudn majpxw
21: Bpm xiaaewzl qa jtcm lziowv
22: Aol whzzdvyk pz isbl kyhnvu
23: Znk vgyycuxj oy hrak jxgmut
24: Ymj ufxxbtwi nx gqzj iwflts
25: Xli tewwasvh mw fpyi hveksr
```

![All 26 possible Caesar shifts of an intercepted message; only key 3 gives readable English: The password is blue dragon](/images/blog/how-does-encryption-work/02-brute.png)

*25 lines of nonsense and one that makes sense.*

Only one line is readable English, so the key was 3. A computer does this in a fraction of a second. Modern ciphers defend against brute force by having an astronomically large number of possible keys. AES, used across the internet, allows keys of 128 bits or more: that is 2128 possibilities, a 39-digit number, far too many to try even with every computer on Earth.

## Breaking it smarter: frequency analysis

In the 9th century, the scholar al-Kindi described a cleverer attack that works even on ciphers with many more keys. In English, some letters are far more common than others, with e the most common of all. A cipher that always swaps each letter for the same substitute keeps that pattern. So count the letters in the ciphertext, and the most common one probably stands for e:

**freq.py**

```python
from collections import Counter
from caesar import shift_text

message = ("Every year the school science fair fills the main hall with experiments. "
           "This time the winning entry was a small weather station that measured the "
           "temperature, the wind speed and the rain, then sent the readings to a "
           "website every ten minutes. The team spent three weeks testing it on the "
           "roof, and they were delighted when the judges said it was the best entry "
           "they had seen in several years.")
secret = shift_text(message, 11)

def crack(ciphertext):
    letters = [c for c in ciphertext.lower() if c.isalpha()]
    top = Counter(letters).most_common(1)[0][0]
    key = (ord(top) - ord("e")) % 26        # guess: the most common letter stands for e
    return key, shift_text(ciphertext, -key)

key, guess = crack(secret)
print("most common letters:", Counter(c for c in secret.lower() if c.isalpha()).most_common(5))
print("guessed key:", key)
print("decrypted:", guess[:70], "...")

short = shift_text("Do not open the box", 11)
key2, guess2 = crack(short)
print("short message, guessed key:", key2, "->", guess2)
```

**Output**

```text
most common letters: [('p', 61), ('e', 41), ('s', 24), ('d', 24), ('y', 24)]
guessed key: 11
decrypted: Every year the school science fair fills the main hall with experiment ...
short message, guessed key: 21 -> Te dej efud jxu ren
```

![Letter counts in the encrypted message: the letter p appears 61 times, far more than any other, and p is 11 places after e, revealing the key 11](/images/blog/how-does-encryption-work/03-frequency.png)

*One tall bar gives the whole cipher away.*

In the long message, **p** appeared 61 times, far ahead of any other letter. Since p is 11 places after e, the key is 11, and the whole message decrypts correctly. But look at the last line: on the short message "Do not open the box", the same method guessed key 21 and produced "Te dej efud jxu ren". Five words are not enough for the statistics to work. Frequency analysis needs plenty of text, which is one reason short messages were historically harder to crack.

> **Why this matters today**

> Frequency analysis is why modern ciphers are designed so that the same letter never turns into the same symbol twice in a predictable way. A good cipher's output looks like random noise, with no patterns left to count.

## The key problem, and a brilliant solution

Every cipher so far has the same practical problem: both people need the same secret key before they start. That is fine for spies who meet in person, but you have never met your bank's web server. How can two strangers agree a secret key over the internet, where anyone might be listening?

In 1976, Whitfield Diffie and Martin Hellman published a solution now called **Diffie-Hellman key exchange**. It relies on a one-way calculation: raising a number to a power and taking a remainder is easy, but undoing it is extremely hard when the numbers are huge. Here it is with toy-sized numbers:

**exchange.py**

```python
# Two people agree a secret number over a public channel (Diffie-Hellman, toy sized)
p, g = 23, 5                  # public: everyone can see these

alice_secret = 6              # never sent
bob_secret = 15               # never sent

alice_sends = pow(g, alice_secret, p)     # 5^6 mod 23
bob_sends = pow(g, bob_secret, p)         # 5^15 mod 23
print("sent in public:", alice_sends, "and", bob_sends)

alice_key = pow(bob_sends, alice_secret, p)
bob_key = pow(alice_sends, bob_secret, p)
print("Alice works out:", alice_key)
print("Bob works out:  ", bob_key)
```

**Output**

```text
sent in public: 8 and 19
Alice works out: 2
Bob works out:   2
```

![Diffie-Hellman with toy numbers: public values p = 23 and g = 5; Alice's secret 6 gives 8, Bob's secret 15 gives 19; each combines the other's public number with their own secret and both get 2](/images/blog/how-does-encryption-work/04-exchange.png)

*The secrets 6 and 15 never travel across the network.*

Alice keeps 6 secret and sends 8. Bob keeps 15 secret and sends 19. Each combines the number they received with their own secret, and both arrive at 2, a shared key that was never sent. An eavesdropper sees 23, 5, 8 and 19, but to find the key they would need to work backwards to a secret. With these tiny numbers that is easy to do by trial. Real systems use numbers hundreds of digits long, or a related method based on elliptic curves, where working backwards would take longer than the age of the universe.

## How it all comes together in HTTPS

1. Your browser and the website use a key exchange built on this same idea to agree a fresh secret key, even though every message between them could be seen by others.
2. The website proves it is genuine using a certificate, so you know you agreed the key with the real site and not an impostor.
3. All the data is then encrypted with a fast cipher such as AES using that shared key.
4. The key belongs to that connection only. A later visit normally sets up a fresh one.

That whole process happens in a fraction of a second every time the padlock appears. Many of the ideas in it, including remainders, huge numbers and one-way functions, connect to the maths in our guides to [prime numbers](/blog/prime-numbers-explained) and [binary](/blog/binary-numbers-explained).

| Idea | Weakness or strength |
| --- | --- |
| Caesar cipher | Only 26 keys, so brute force breaks it instantly |
| Letter substitution | Keeps letter patterns, so frequency analysis breaks it |
| AES | 2 to the power 128 or more keys, and output with no usable patterns |
| Diffie-Hellman | Lets strangers agree a key in public, if the numbers are huge |

> A cipher is only as strong as its key is hard to guess. Every advance in cryptography is really a better way to make and share keys.

## How we teach it

Encryption is a good fit for two principles on our [how we teach](/how-we-teach) page. Learning by building: making a cipher, then breaking it, teaches more than any definition. And tracing code line by line until every step can be predicted, which is exactly how the wrap-round from Z back to A starts to make sense. Our [Python course for teens](/courses/python-complete-masterclass-teens) runs one to one or in small groups of 5 to 10.

[Book a free class](/book-demo) [Book a priority demo](/book-demo)

## Frequently asked questions

**How does encryption work in simple terms?**

Encryption uses a method called a cipher and a secret key to scramble readable data into ciphertext. Only someone with the right key can reverse it. The cipher is usually public; the security comes from keeping the key secret and making it impossible to guess.

**What is a Caesar cipher?**

A Caesar cipher shifts every letter a fixed number of places along the alphabet, such as A to D with a shift of 3. It is named after Julius Caesar, who is reported to have used a shift of 3. It is easy to break because there are only 26 possible shifts.

**How do you break a Caesar cipher?**

Try all 26 shifts and look for readable text, which is called brute force. Or use frequency analysis: find the most common letter in the ciphertext, assume it stands for e, and work out the shift. Frequency analysis needs a reasonably long message to work.

**What is frequency analysis?**

It is a code-breaking method that counts how often each symbol appears in a ciphertext and matches the most common ones to the most common letters in the language, such as e in English. It was described by the scholar al-Kindi in the 9th century.

**How can two people share a secret key over the internet?**

They use a key exchange such as Diffie-Hellman. Each person keeps a secret number and sends a value calculated from it. Combining the other person's value with their own secret gives both the same key, while anyone watching cannot work it out if the numbers are large enough.

**What does the padlock in my browser mean?**

It means the site uses HTTPS: your browser agreed a secret key with the website, checked the site's certificate, and is encrypting everything sent between you. It shows the connection is private, not that the website itself is trustworthy.

**Is encryption a good topic for learning to code?**

Yes. A Caesar cipher is a classic early Python project that practises strings, loops and remainders, and breaking it with brute force and frequency analysis is a satisfying next step. It also appears in computer science syllabuses such as GCSE.

---

*Source: https://learn.modernagecoders.com/blog/how-does-encryption-work/*
