Mastodon Mastodon Mastodon Mastodon

Advanced Encryption Standard (AES) [AES]

Updated: · CyberSecureFox Editorial Team

The Advanced Encryption Standard (AES) is the symmetric block cipher standardised by NIST in FIPS 197 and used worldwide to encrypt data, from web traffic and Wi-Fi to disks and messengers.

How AES works

AES is a symmetric encryption algorithm: the same key encrypts and decrypts. It processes data in 128-bit blocks and supports three key lengths:

  • AES-128 – 10 rounds of transformation;
  • AES-192 – 12 rounds;
  • AES-256 – 14 rounds.

Each round substitutes bytes, shifts rows, mixes columns and adds a round key derived from the main key. Because AES is a block cipher, it is used in modes of operation; GCM is the most common today because it also authenticates data, while older CBC mode needs extra integrity protection.

The algorithm, originally named Rijndael, was designed by Belgian cryptographers Joan Daemen and Vincent Rijmen. NIST selected it in 2000 after an open international competition that began in 1997, and published the standard in 2001 to replace the ageing DES.

Why AES matters

More than two decades of public cryptanalysis have found no practical attack on the full algorithm. AES protects TLS and HTTPS connections, WPA2 and WPA3 Wi-Fi, VPN tunnels, BitLocker and FileVault full disk encryption, and encrypted messengers. Modern processors include dedicated AES instructions (AES-NI on x86), making it very fast. US government policy approves AES with 192- or 256-bit keys for TOP SECRET information.

Real-world failures come from implementation mistakes: reused GCM nonces, cache-timing side channels, hard-coded or weakly derived keys. Ransomware families also rely on AES to lock victims’ files, which shows its strength from the opposite side.

Best practices

  • Use AES-GCM from a vetted library instead of writing your own implementation.
  • Choose AES-256 for long-term confidentiality.
  • Derive keys from passwords with a slow KDF such as Argon2 or PBKDF2 and keep keys out of source code.
Synonyms:
advanced encryption standard, rijndael, aes encryption