Cybersecurity: Encryption Using Shift Ciphers
An example of student-created decoder wheelCopyright Dowain SwainStudents explore the fundamental role of cryptography and encryption in cybersecurity by investigating how information can be protected from unauthorized access. They examine the historical origins of encryption through the Caesar cipher, learn the basics of symmetric and asymmetric encryption, and use cipher wheels to encode and decode secret messages in collaborative activities. Throughout the activity, students connect these historical techniques to modern cybersecurity applications, including secure websites, messaging apps, online banking, and password protection. Class discussions and reflection activities reinforce the importance of secure communication and data protection in today's digital world. By the end of the activity, students understand how the basic principles behind the Caesar cipher evolved into the advanced encryption technologies that cybersecurity engineers use to safeguard information and communications.
Cybersecurity engineers design, build, and protect the computer systems that keep our digital world running safely. They develop secure networks and software, identify vulnerabilities before hackers can exploit them, and respond to cyberattacks when they occur. Using computer science, mathematics, and engineering principles, cybersecurity engineers create encryption systems, firewalls, and other security technologies that protect sensitive information such as financial records, medical data, and personal communications. Their work is essential for safeguarding individuals, businesses, and governments from constantly evolving cyber threats.
After this activity, students should be able to:
- Explain the role of encryption in protecting digital information and communications.
- Encode and decode messages using a Caesar cipher.
- Compare the Caesar cipher to modern encryption methods used in cybersecurity.
- Describe how encryption helps secure online communications and sensitive information.
- CCSS.Math.Practice.MP1 Make sense of problems and persevere in solving them.
Grades K-12
Do you agree with this alignment? - CCSS.Math.Practice.MP2 Reason abstractly and quantitatively.
Grades K-12
Do you agree with this alignment?
- STEL-3J Connect technological progress to the advancement of other areas of knowledge and vice versa.
Grades 9-12
Do you agree with this alignment?
Each student needs:
- 1 Blank Decoder Wheel (PDF) or Blank Alphabet Chart (PDF) (blank handouts for building cipher tools)
- 1 brass faster for each wheel
- 1 Pre-Assessment (PDF) worksheet
- (optional) 1 Post Assessment (PDF) worksheet
- (optional) 1 Cryptography Background Reading (PDF)
Each pair needs:
- 1 Encoding-Decoding Practice (PDF)sheet
- 1 Encrypted Message Sheet (PDF)
- (optional) laptop/tablet with internet access for digital extension
For the class to share:
- laptop or tablet with projector to show the Encryption Using Shift Ciphers Presentation (PPTX)
- Encryption Using Shift Ciphers Presentation (pptx)
- Encryption Using Shift Ciphers Presentation (pdf)
- Blank Alphabet Chart (docx)
- Blank Alphabet Chart (pdf)
- Pre-Assessment (docx)
- Pre-Assessment (pdf)
- Pre-Assessment Answer Key (docx)
- Pre-Assessment Answer Key (pdf)
- Encrypted Message Sheet (docx)
- Encrypted Message Sheet (pdf)
- Encrypted Message Sheet Answer Key (docx)
- Encrypted Message Sheet Answer Key (pdf)
- Blank Decoder Wheel (docx)
- Blank Decoder Wheel (pdf)
- Encoding-Decoding Practice (docx)
- Encoding-Decoding Practice (pdf)
- Encoding-Decoding Practice Answer Key (docx)
- Encoding-Decoding Practice Answer Key (pdf)
- Cryptography Background Reading (docx)
- Cryptography Background Reading (pdf)
- Post Assessment (docx)
- Post Assessment (pdf)
- Post Assessment Answer Key (docx)
- Post Assessment Answer Key (pdf)
Students should have: ·
- Basic computer and internet skills.
- Basic understanding of cybersecurity and the importance of protecting information in today's digital world.
- Understanding that personal information (e.g., passwords, usernames, dates of birth, and financial information) should be kept private and secure.
Good morning, everyone! I have a challenge to kick off today's class.
Imagine you're all secret agents on a high-stakes mission. A mysterious encrypted message has just been intercepted, and it's your job to figure out what it says before time runs out.
(Write on the board: Wklv lv d whvw phvvdjh. Answer: "This is a test message." The message uses a Caesar cipher with a shift of 3.)
Take a moment to study the message. What do you notice? Does anyone have a guess about what it might say? (Pause and encourage students to share observations. Possible responses: The letters are scrambled; it uses the alphabet, but something seems off; some words look familiar; it seems like a pattern.)
Great observations! You've just encountered one of history's earliest encryption methods: the Caesar cipher. More than 2,000 years ago, Julius Caesar used this simple code to send confidential military messages. By shifting each letter a certain number of places in the alphabet, he could keep his instructions hidden from enemies.
Today, Caesar's cipher is no longer secure, but it introduced a powerful idea: protecting information by transforming it into something only the intended recipient can understand. That same basic concept is the foundation of modern encryption, which protects everything from your text messages and online banking to medical records and national security.
Now think about your own life. Have you ever created a secret code with a friend? Hidden a message so someone else couldn't read it? What could happen if someone guessed your phone password or gained access to one of your online accounts? (Invite students to briefly share experiences. Acknowledge responses and connect them to digital security.)
These are the kinds of questions that cryptographers and cybersecurity engineers work on every day. They ask questions such as these:
- How can we protect information from people who shouldn't have access to it?
- How can we turn ordinary messages into codes that are nearly impossible to crack?
- How do we balance security with making information easy for the right people to access?bn
Today, you'll step into the role of a cybersecurity engineer. You'll decode secret messages, build and use your own cipher tools, and explore how a simple coding technique developed by a Roman general eventually led to the sophisticated encryption systems that keep our digital world secure today. By the end of the activity, you'll understand not only how encryption works, but also why it plays such an important role in our everyday lives.
Background Information
Cryptography is the practice of protecting information by converting readable messages (plaintext) into coded messages (ciphertext) that can only be read by authorized users with the correct key. Derived from the Greek word meaning "hidden writing," cryptography has evolved from ancient techniques such as Julius Caesar's cipher into an essential cybersecurity tool that protects digital communications, financial transactions, and other sensitive information.
Modern cryptography is built on four key principles: confidentiality, integrity, authentication, and non-repudiation. These principles ensure that only authorized users can access information, that data cannot be secretly altered, that users' identities can be verified, and that senders cannot deny creating or sending a message. These protections are critical for secure communication in today's digital world.
Cryptography is used in many everyday technologies, including password protection, secure websites, online banking, electronic signatures, cryptocurrencies, messaging apps, and email. It helps safeguard personal information, prevents fraud, and protects sensitive government and business data from cyberattacks.
There are two main types of encryption: symmetric and asymmetric cryptography. Symmetric encryption uses a single shared key for both encryption and decryption, making it fast and efficient for large amounts of data. Asymmetric encryption uses a pair of keys—a public key for encryption and a private key for decryption—which provides greater security but requires more computing power. Many modern security systems combine both methods.
Strong cryptographic keys are essential for keeping information secure. Modern encryption uses long, complex keys that make brute-force attacks—where a computer tries every possible key—practically impossible. Cryptographic algorithms, digital signatures, and hash functions work together to encrypt data, verify identities, and ensure that information has not been altered.
As technology advances, cryptography continues to evolve. New approaches such as elliptic curve cryptography (ECC) provide stronger security with smaller, more efficient keys, while quantum cryptography uses the principles of quantum physics to create highly secure communication systems. Although quantum cryptography is still being developed, these emerging technologies are expected to play a major role in protecting digital information from future cyber threats.
See the Cryptography Background Reading (PDF) for more details.
Before the Activity
- Print the following
- Blank Decoder Wheel (PDF)or Blank Alphabet Chart (PDF)(1 per student)
- Pre-Assessment worksheet (1 per student)
- (optional) Post Assessment (PDF) worksheet (1 per student)
- (optional) Cryptography Background Reading (PDF) (1 per student)
- Encrypted Message Sheet (PDF) (1 per pair)
- Encoding-Decoding Practice (PDF) (1 per pair)
- Review and prepare to present the Encryption Using Shift Ciphers Presentation (PPTX) to the class.
- Write the following encrypted message on the board before students arrive: Wklv lv d whvw phvvdjh. (Answer: "This is a test message.")
- Optional: Assign the Cryptography Background Reading (PDF) as homework.
With the Students
Part 1: Pre-Assessment and Introduction (15 minutes)
- Distribute one Pre-Assessment (PDF) worksheet to each student.
- Give students 5 minutes to complete the worksheet.
- After students finish the worksheet, tell them that they have intercepted a mysterious encrypted message and must determine what it says. (See the Introduction and Motivation section for teacher script.)
- Direct students' attention to the message written on the board: Wklv lv d whvw phvvdjh. (Answer: "This is a test message.")
- Ask:
- What do you think is happening here?
- What do you notice about this message?
- Have you ever tried to keep a message secret?
- What does the word encryption mean to you?
- Invite students to share their ideas before explaining that the message is encrypted using a Caesar cipher.
- Explain that encryption is used every day to protect sensitive information such as text messages, passwords, banking information, and online purchases.
Part 2: What Is a Caesar Cipher? (25 minutes)
- Present the Encryption Using Shift Ciphers Presentation (PPTX) to the class.
- Define encryption. (Slide 4)
- Define cryptography. (Slide 5)
- Define a Caesar cipher as a substitution cipher in which each letter is shifted a fixed number of places in the alphabet. (Slide 6)
- Demonstrate a simple shift, such as:
A → D
B → E
C → F
- Explain that the number of positions each letter moves is called the key.
- Introduce Julius Caesar and explain how he used the Caesar cipher to send secret military messages. (Slide 7)
- As a class, use a Caesar cipher to decode the encrypted message on Slide 8. (Answer: When you wish upon a star makes no difference who you are anything your heart desires will come to you.)
- Introduce the concepts of symmetric and asymmetric encryption. (Slides 9-10)
- Explain that Caesar ciphers are considered symmetric encryption because the same key is used to encrypt and decrypt a message.
- Use a shift of 13 (ROT13) to demonstrate that the same transformation both encrypts and decrypts a message:
A ↔ N
- Explain that for other Caesar cipher shifts, decrypting a message requires reversing the original shift. For example:
Encryption: A → D (shift +3)
Decryption: D → A (shift −3 or +23)
- Explain that although decrypting a Caesar cipher requires reversing the shift, it is still considered a symmetric cipher because both the sender and receiver must know the same secret key. Contrast this with modern asymmetric encryption, which uses two mathematically related keys: a public key for encryption and a private key for decryption.
- Explain that cybersecurity engineers use much more advanced encryption algorithms than Caesar ciphers, but they are based on the same fundamental goal: protecting information so that only authorized users can read it.
Part 3: Guided Practice: Encrypting and Decrypting Messages (50 minutes)
Activity 1: Build a Cipher Tool (10 minutes)
- Distribute one Blank Decoder Wheel (PDF) or Blank Alphabet Chart (PDF) to each student.
- Have students construct their own cipher wheel or complete their shift chart.
An example of student-created decoder wheelCopyright Dowain SwainActivity 2: Create and Exchange Secret Messages (10 minutes)
- Have students encode their names or a short phrase using a Caesar shift of their choice.
Student using decoder wheel to encrypt decrypt messagesCopyright Dowain Swain- Put students into pairs.
- Have partners exchange encrypted messages and decode each other's messages.
Activity 3: Decode Practice Exercises (10 minutes)
- Distribute one Encoding-Decoding Practice (PDF) sheet to each pair.
- Have students use their cipher tools to determine the correct key and decode the messages.
- Once each pair has completed the worksheet, review the decoded messages as a class.
Activity 4: Engineering Design Encryption Challenge (20 minutes)
- Distribute one Encrypted Message Sheet (PDF) to each pair.
- Have each pair complete Part 1.
- Tell students that they are now taking on the role of cybersecurity engineers who must design secure communication systems that protect information while allowing authorized users to access it.
- Challenge each pair to design an encryption system that allows two people to communicate securely while making it difficult for an unauthorized person to decode the message. Have students test their encryption system with another group, if time permits, and evaluate its strengths and weaknesses.
- Review the protocols (constraints) for encoding the message:
- When you convert your message, you must follow these rules:
ii. You can only send 3 words at a time.
iii. You must include a cipher number with your message.
iv. The encoded message must be in all caps.
- Ask students to answer the questions in the Reflection section of the Encrypted Message Sheet (PDF).
Part 4: Connecting to Cybersecurity and Post Assessment (30 minutes)
- Give students 5 minutes to Think-Pair-Share the following questions.
- Why is encryption important today? (Potential answers below.)
- How is Caesar’s idea still used in modern technology? (Potential answers below.)
- Bring the class back together and explain that although Caesar ciphers are no longer considered secure, they introduced the basic concepts on which modern encryption systems are built. Guide students to make the connection between the historical Caesar cipher and modern cybersecurity.
- Introduce examples of modern encryption technologies, including:
- HTTPS websites – Encrypt data sent between your web browser and a website (look for the padlock icon).
- End-to-end encrypted messaging apps – Apps such as Signal, WhatsApp, and iMessage encrypt messages so only the sender and recipient can read them.
- Online banking and mobile payment apps – Protect financial transactions and account information.
- Online shopping (e-commerce) – Encrypt credit card numbers and personal information during purchases.
- Wi-Fi security (WPA2/WPA3) – Encrypts data sent over wireless networks.
- Virtual Private Networks (VPNs) – Encrypt internet traffic to protect privacy on public networks.
- Password managers – Encrypt stored passwords so only the user can access them.
- Email encryption – Protects sensitive emails from unauthorized access.
- Digital signatures – Verify the authenticity of electronic documents and software.
- Cryptocurrencies (e.g., Bitcoin) – Use cryptographic techniques to secure transactions and verify ownership.
- Cloud storage services – Encrypt files stored online to protect them from unauthorized access.
- Device encryption – Smartphones, tablets, and computers encrypt stored data to protect it if the device is lost or stolen.
- Optional: Distribute one Post Assessment worksheet to each student and give students 5 minutes to complete the worksheet.
- Optional: Have each student complete the Exit Ticket on Slide 15.
Here is one example of how you could use classroom resources such as a projector or tv to help student engagement.Copyright Dowain Swain- Discuss why today's encryption algorithms are much stronger than simple substitution ciphers. Lead a class discussion using questions such as:
- Why is encryption important today?
Potential answers: To protect personal information and privacy; to secure passwords; to protect online banking and credit card information; to secure text messages, emails, and online communications; to prevent identity theft and fraud; to protect medical records and other sensitive data; to secure online shopping and digital payments; to ensure only authorized users can access information. - How is Julius Caesar's idea still used in modern cybersecurity?
Potential answers: Modern encryption still converts readable information into coded information; encryption uses keys to encode and decode data; advanced mathematical algorithms have replaced simple letter shifts; secure websites (HTTPS), messaging apps, online banking, and password protection all rely on encryption; Caesar's cipher introduced the basic concept of protecting information by encoding it. - Why are simple ciphers no longer considered secure?
Potential answers: They are easy for computers to break; they use predictable patterns; they have too few possible keys; hackers can use brute-force attacks to try every possible key; modern computers can decode simple ciphers in seconds; they do not provide enough protection for sensitive information. - How do stronger encryption methods help protect personal and sensitive information?
Potential answers: They use longer, more complex keys; they are much harder for hackers to crack; they protect data while it is stored and transmitted; they help prevent unauthorized access, identity theft, and fraud; they keep online communications, financial transactions, and personal information secure.
- Why is encryption important today?
- Conclude by emphasizing that cybersecurity engineers continue to build on the same fundamental idea introduced by the Caesar cipher, which is to keep information private by transforming it into a form that only authorized users can read.
(optional) Digital Extension (15 minutes)
- Option 1:
- Have students use an online Caesar cipher tool to try encrypting and decrypting messages faster: https://www.dcode.fr/caesar-cipher
- Challenge: Have students try to brute-force a Caesar cipher by checking all 25 possible shifts.
- Option 2:
- Have students learn about asymmetric and symmetric keys for encoding data: https://www.kerryveenstra.com/cryptosystem.html
- Challenge: Can students send encrypted messages to friends without others intercepting the message?
- asymmetric encryption
- One key encrypts; a different key decrypts.
- caesar cipher
- An encryption method in which each letter of the message is shifted by a certain amount, called the key.
- cryptography
- Scrambling digital information into an unreadable form. Only those with verified authority (password, key, etc.) can unscramble it to read it.
- decryption
- The conversion of encrypted data into its original form.
- key (cyber)
- A shared secret that allows the recipient to convert ciphertext into plaintext.
- public-key encryption
- A type of asymmetric encryption that uses one key to encrypt the information and a different key to decrypt the information.
- symmetric encryption
- The same key is used to encrypt and decrypt.
Pre-Activity Assessment
Pre-Assessment Questions: Before beginning the activity, have students complete the Pre-Assessment (PDF) worksheet to assess their prior knowledge of cryptography, encryption, cybersecurity, and secure communications. Use students' responses to identify misconceptions and guide classroom discussions throughout the activity.
Introduction Discussion Questions: After students complete the pre-assessment, present the encrypted message "Wklv lv d whvw phvvdjh." Lead a class discussion using the following questions to activate prior knowledge and generate curiosity about encryption:
- What do you think is happening here?
- What do you notice about this message?
- Have you ever tried to keep a message secret?
- What does the word encryption mean to you?
Formative Assessment
Guided Practice Activities: Monitor students as they construct cipher wheels, encode and decode Caesar cipher messages, and complete the Encoding-Decoding Practice (PDF) sheet. Observe students' ability to correctly identify cipher keys, encrypt and decrypt messages, and explain how the Caesar cipher works.
Engineering Design Encryption Challenge: Evaluate students as they design, test, and evaluate their own encryption systems. Encourage students to explain their design decisions, identify the strengths and weaknesses of their encryption methods, and consider how their systems could be improved to better protect information.
Class Discussions: Throughout the activity, ask students to explain the purpose of encryption, compare symmetric and asymmetric encryption, and describe how cybersecurity engineers use encryption to protect sensitive information. Use student responses to assess conceptual understanding and address misconceptions before moving on.
Post-Activity (Summative) Assessment
Think-Pair-Share Discussion: Have students work with a partner to discuss the following questions before sharing their responses with the class:
- Why is encryption important today?
- How is Julius Caesar's idea still used in modern cybersecurity?
- Why are simple ciphers no longer considered secure?
- How do stronger encryption methods help protect personal and sensitive information?
Use students' responses to evaluate their understanding of the role of encryption in cybersecurity and their ability to connect historical cryptography to modern encryption technologies.
(optional) Post Assessment Questions: Distribute the Post Assessment (PDF) worksheet to evaluate students' understanding of encryption, Caesar ciphers, cryptography, symmetric and asymmetric encryption, and the role of encryption in modern cybersecurity. Compare students' responses with the pre-assessment to measure learning gains.
(optional) Exit Ticket: Have students complete the Exit Ticket on Slide 15 to summarize one new concept they learned about encryption, explain one real-world application of cybersecurity, or describe how cybersecurity engineers use encryption to protect digital information. Use students' responses to identify any remaining misconceptions and inform future instruction.
- There are no significant physical safety hazards associated with this activity.
- Students may initially struggle to understand how letters shift in a Caesar cipher. Demonstrate several examples as a class before asking students to work independently.
- Encourage students to use their cipher wheels or alphabet charts systematically rather than guessing letter substitutions.
- If students become confused about encryption and decryption, remind them that decrypting a Caesar cipher simply requires reversing the original shift.
- Some students may have difficulty distinguishing between symmetric and asymmetric encryption. Emphasize that the Caesar cipher uses the same shared key for both encryption and decryption, whereas modern asymmetric encryption uses a public key for encryption and a private key for decryption.
- During the Engineering Design Encryption Challenge, encourage students to focus on developing a logical and repeatable encryption method rather than creating an overly complex system. Remind them that another group should be able to decode the message if given the correct instructions.
- If students finish early, challenge them to create longer encrypted messages, use different shift values, or attempt to crack another group's cipher without knowing the key.
https://www.ibm.com/think/topics/cryptography
https://www.ibm.com/think/topics/asymmetric-encryption
https://www.ibm.com/think/topics/symmetric-encryption
https://www.ibm.com/docs/en/sia?topic=osdc-private-keys-public-keys-digital-certificates-27
Contributors
Dowain Swain Mentors: Jake Herweg BS, CSE and Jack Donelson University of Nevada, Reno PI: Dr. Shamik Sengupta and Co-PI: Dr.
Supporting Program
RET Site: Research Experience in Cybersecurity for Nevada Teachers (RECNT) University of Nevada, Reno
Acknowledgements
This curriculum was developed under National Science Foundation RET grant number #2302187. Any opinions, findings, and conclusions or recommendations expressed in this material are those of the authors and do not necessarily reflect the views of the National Science Foundation.
Copyright
2026 by Regents of the University of Colorado; original © 2025 University of Nevada, Reno
