Glossary

AES

AES stands for Advanced Encryption Standard, a symmetric block cipher that encrypts data in 128-bit blocks with a key of 128, 192 or 256 bits. NIST published it as FIPS 197 on November 26, 2001 and updated it on May 9, 2023. It is the default cipher for TLS, disk encryption and most application encryption, and no practical attack on full AES is known.

How it works

AES is a member of the Rijndael family. FIPS 197 specifies three variants, which all use the same 128-bit block and differ in key length and number of rounds:

  • AES-128: 128-bit key, 10 rounds.
  • AES-192: 192-bit key, 12 rounds.
  • AES-256: 256-bit key, 14 rounds.

The 16-byte block is arranged as a 4 by 4 grid of bytes called the state. Each round applies byte substitution, a row shift, a column mix and addition of a round key derived from the main key. The last round skips the column mix. Decryption runs the inverse steps.

A block cipher on its own handles exactly one 16-byte block. To encrypt longer data you need a mode of operation, and the mode matters as much as the key size. CBC chains blocks with an initialization vector (IV) and needs padding. GCM turns AES into a stream-like mode and adds an authentication tag so tampering is detected. ECB encrypts each block independently and should not be used for real data.

The commands below encrypt one 16-byte block with a single key and show why ECB leaks patterns. The key is 000102...0f for AES-128 and 000102...1f for AES-256.

echo 00112233445566778899aabbccddeeff | python3 -c "import sys;sys.stdout.buffer.write(bytes.fromhex(sys.stdin.read().strip()))" | openssl enc -aes-128-ecb -K 000102030405060708090a0b0c0d0e0f -nopad | od -An -tx1 | tr -d ' \n'
69c4e0d86a7b0430d8cdb78070b4c55a

The same plaintext block under the 256-bit key 000102...1f gave 8ea2b7ca516745bfeafc49904b496089. Encrypting 32 bytes of the letter A in ECB mode gave two identical 16-byte blocks, dd4b1a0b47daa7067d0b59d95d58a6ae, repeated twice. Equal plaintext blocks always give equal ciphertext blocks in ECB.

How long is an AES key and block?

An AES key is 128, 192 or 256 bits long, which is 16, 24 or 32 bytes, and the block is always 128 bits, or 16 bytes. The block size does not change with the key. Any other key length is rejected by libraries: Python's cryptography package raises "AESGCM key must be 128, 192, or 256 bits." for a 20-byte key. AES-GCM output is the ciphertext plus a 16-byte tag, so a 5-byte message encrypts to 21 bytes.

Common pitfalls

  • Using ECB: it hides nothing about repeated blocks, as the repeated output above shows. Use GCM, or CBC with a separate MAC.
  • Reusing a nonce with GCM: repeating a key and nonce pair breaks both confidentiality and authentication. Generate a fresh random or counter nonce for each message.
  • Using a password as the key: a typed password is not 32 random bytes. Derive the key with PBKDF2 or another password hashing function.
  • Skipping authentication with CBC: unauthenticated CBC allows ciphertext tampering and padding oracle attacks. Add an HMAC or switch to GCM.
  • Mixing up key size and block size: AES-256 does not use a 256-bit block. It always uses 128-bit blocks.
  • Storing the key beside the data: encryption only helps if the key lives somewhere separate.

Related terms

  • DES — the older 56-bit-key cipher that AES replaced.
  • GHASH — the authentication function inside AES-GCM.
  • PBKDF2 — derives an AES key from a password.
  • HMAC — authenticates data when you use a mode without built-in authentication.
  • SHA-256 — a hash often used for key derivation and integrity, not for encryption.

See also