AES-GCM is an authenticated encryption mode that encrypts with AES in counter mode and adds a tag, usually 16 bytes, proving the ciphertext and associated data are unchanged. GCM stands for Galois/Counter Mode and is defined in NIST SP 800-38D. RFC 8446 says a TLS 1.3 application must implement TLS_AES_128_GCM_SHA256 unless a profile says otherwise, so it is the default for web traffic.
GCM combines two parts that share one AES key. The first is counter mode, which encrypts a counter sequence and XORs it with the plaintext. The second is GHASH, a keyed function over the associated data and ciphertext. The tag is the GHASH result XORed with an AES encryption of the first counter block.
The inputs and sizes are:
Decryption recomputes the tag first and rejects the message if it does not match. Libraries return the tag appended to the ciphertext, so the output is the plaintext length plus 16 bytes.
The example uses Python's cryptography package with a 128-bit key, an all-zero IV (only for a repeatable demo) and the associated data hdr. A Node.js run of the same inputs gave identical bytes.
from cryptography.hazmat.primitives.ciphers.aead import AESGCM
from cryptography.exceptions import InvalidTag
key = bytes(range(16)); iv = bytes(12)
g = AESGCM(key)
out = g.encrypt(iv, b"hello", b"hdr")
print(len(out), out.hex())
print("ct", out[:5].hex(), "tag", out[5:].hex())
bad = bytearray(out); bad[0] ^= 1
try:
g.decrypt(iv, bytes(bad), b"hdr")
except InvalidTag as e:
print("InvalidTag", repr(str(e)))
21 21b3eb3ff680ba59a0ce79e52695c7f780b98426c2
ct 21b3eb3ff6 tag 80ba59a0ce79e52695c7f780b98426c2
InvalidTag ''
An AES-GCM IV should be 96 bits, which is 12 bytes. NIST SP 800-38D recommends restricting implementations to that length for interoperability and speed. Other lengths work in most libraries, but GCM then has to hash the IV into a counter block, so NIST recommends 96 bits for interoperability and efficiency.
No. Reusing a key and IV pair leaks the XOR of the plaintexts, and NIST warns that a repeated IV makes forgery attacks possible. Two messages encrypted with the same key and IV, attack at dawn and retreat at six, produced the XOR 13110013060a5441155444121e16, which is the XOR of the plaintexts. When IVs are random, NIST requires the total number of encryptions under one key to stay at or below 2^32.