Let be a Cryptosystem.
Let and be random variables taking values in
finite and
Let
The unicity distance is the least such that

(i.e. given encrypted messages, we can find )
If doesn’t exist, then
Now:

Assume:

  1. all keys are equally likely, so
  2. where (i.e. msgs are independent)
  3. All ciphertext is equally likely so

So we get:

and: