AES-256, explained simply
What AES-256 is, what the 256 means, what happens inside the cipher, and why real-world failures come from key handling rather than the algorithm.
On this page 9 sections
AES-256 is the Advanced Encryption Standard used with a 256-bit key: a public, heavily studied symmetric cipher that nobody can break by guessing keys. It is the most widely used encryption algorithm in the world. The label alone says little, though, because real-world security depends on the mode it runs in, how the keys are handled and what happens after decryption.
"Protected with AES-256 encryption" appears on password managers, cloud drives, VPN adverts and video platforms. Here's what the number means, how the cipher works inside, and which questions separate real security from a marketing line.
What AES is
AES stands for the Advanced Encryption Standard. It is a symmetric cipher, meaning the same secret key encrypts and decrypts.
Its origin story explains why it is trusted. By the late 1990s, the old US standard, DES, had become too weak: its 56-bit key was short enough that a purpose-built machine could find one in a matter of days. So the US National Institute of Standards and Technology (NIST) ran an open, international competition for a replacement. Cryptographers submitted designs and attacked each other's entries in public. The winner, announced in 2000, was Rijndael, created by two Belgian cryptographers, Joan Daemen and Vincent Rijmen. It became the official standard in 2001.
A quarter of a century of public scrutiny later, AES remains unbroken in any practical sense. It protects HTTPS traffic, Wi-Fi networks, phone and laptop storage, messaging apps and most commercial video protection.
What the "256" means
AES comes in three key sizes: 128, 192 and 256 bits. The number in the name is the length of the key. The data itself is always processed in blocks of 128 bits, or 16 bytes, whatever the key size.
A 256-bit key means there are 2 to the power 256 possible keys, a number 78 digits long. To get a feel for that, imagine an attacker with 10 billion computers, each testing a trillion keys every second. Trying every possible AES-128 key would take them around a billion years. Trying every AES-256 key would take a number of years that is itself 48 digits long, more than ten trillion trillion trillion times the age of the universe.
These figures are illustrative, but the conclusion isn't: nobody breaks AES by guessing keys.
What happens inside AES
You don't need the maths to understand the shape of it. AES arranges each 16-byte block into a four-by-four grid of bytes and runs it through a series of rounds: 10 rounds for a 128-bit key, 12 for 192 bits and 14 for 256 bits. Each round applies four steps:
- Substitute bytes. Every byte is swapped for another using a fixed lookup table, so the relationship between input and output stops being simple.
- Shift rows. The rows of the grid are rotated by different amounts, moving bytes into new columns.
- Mix columns. The four bytes in each column are blended together, so every output byte depends on several input bytes.
- Add the round key. The grid is combined with a round key derived from your main key.
The final round skips the column-mixing step. Think of it as kneading dough to a pattern that only the key-holder knows. After a couple of rounds, changing a single bit of the input or the key affects the whole block, and by the end roughly half of the output bits flip. Cryptographers call this the avalanche effect, and it is why AES output looks like pure noise.
Modes: how AES handles more than 16 bytes
On its own, AES encrypts exactly one 16-byte block. A lecture video or a database backup is millions of blocks, so AES is always used in a mode of operation that defines how the blocks are handled together. The mode matters as much as the key size.
| Mode | How it works | Where you'll meet it |
|---|---|---|
| ECB | Encrypts every block independently, so identical blocks give identical output and patterns show through | Nowhere, ideally. It's a classic mistake |
| CBC | Mixes each block with the previous encrypted block, starting from a random value | Older systems, standard HLS video encryption and, in a pattern-based variant, one of the two common DRM schemes |
| CTR | Encrypts a running counter and combines the result with the data, turning AES into a stream cipher | Media encryption, including the other common DRM scheme; also the engine inside GCM |
| GCM | Counter mode plus a built-in tamper check, called an authentication tag | The usual choice for HTTPS and most modern systems |
GCM's tamper check matters. Encryption alone keeps data secret, but it doesn't stop someone altering the ciphertext; authenticated modes like GCM detect any change. They come with one strict rule: never reuse the same nonce, a number meant to be used once, with the same key, or the protection can collapse. So "AES-256" alone is an incomplete description, while "AES-256-GCM" tells you much more. Our comparison of AES-GCM and AES-CBC covers the two modes you'll meet most.
Is AES-256 better than AES-128?
Both are secure. The best known attack on the full cipher in normal use, published in 2011, is only marginally faster than brute force; for AES-256 it shaves less than two bits off the 256, which changes nothing in practice. AES-128 is perfectly adequate for most purposes and is widely used for HTTPS; our guide on whether AES-128 is still secure works through the numbers.
So why choose 256 bits? Mainly for extra margin:
- Future quantum computers. In theory, Grover's algorithm could speed up a brute-force search enough to roughly halve the effective key length. AES-256 would still keep about 128 bits of security. In practice the attack is so hard to run that NIST expects even AES-128 to stay secure for decades.
- Long-lived secrets and regulation. Data that must stay confidential for decades, and some government standards, call for 256-bit keys.
The cost is small. AES-256 runs 14 rounds instead of 10, roughly 40 per cent more work per block. On processors with built-in AES instructions, which most laptops, servers and recent phones have, both are fast enough that users never notice. On older budget phones without that hardware, systems often switch to ChaCha20, a stream cipher designed to run fast in ordinary software.
How AES "gets broken" in the real world
When encrypted data is exposed, the algorithm is almost never the culprit. The usual suspects, covered in more depth in can encrypted data be hacked?, are:
- Leaked keys. Keys hard-coded in a mobile app, pushed to a code repository, written to logs or stored beside the data they protect.
- Weak keys from weak passwords. A key derived from "coaching@123" is only as strong as that password, unless a deliberately slow key-derivation function is used.
- Misuse. ECB mode, reused nonces in GCM, or home-made encryption code that leaks information through timing.
- The decryption point. Data has to be decrypted to be used. A video player must decrypt every segment, so the real question is how well the key is protected on the student's device, and what happens to the lecture once it is on screen.
Questions to ask when a product says "AES-256"
- Which mode is used, and does it include tamper detection?
- Where are the keys stored, and which people or systems can use them?
- How are keys delivered to devices, and could they be extracted there?
- Are keys rotated, and what happens if one leaks?
- Is the data also encrypted in transit, and what protects it once it's decrypted on screen?
A vendor that answers these clearly takes encryption seriously. One that only repeats "military-grade AES-256" may not.
Key takeaways
- AES is a public, heavily studied symmetric cipher and the global standard for encrypting data.
- The 256 is the key length. Brute-forcing a 256-bit key is physically out of reach, and so is a 128-bit one.
- AES-256 mainly adds safety margin, including against future quantum computers, at a small performance cost.
- The mode of operation, such as GCM, and key management matter more than the key size.
- Real-world failures come from leaked keys, misuse and unprotected decryption points, not from the algorithm.
AES-256 deserves its reputation; it is one of the most thoroughly tested pieces of engineering in computing. But it is a component, not a complete security system. How much protection any "AES-256" product really offers depends on everything around the cipher: how keys are created, stored, delivered and retired, and what happens to the data once it has been decrypted.
Frequently asked questions
Can AES-256 be cracked?
Not by brute force. There are 2 to the power 256 possible keys, and the best known attack on the full cipher is barely faster than trying them all, which is physically out of reach. AES-256 data gets exposed in other ways: a key derived from a weak password, a key left in an app or a repository, a misused mode, or a device where the data has already been decrypted.
What is the difference between AES-128 and AES-256?
The key length and the number of rounds. AES-128 uses a 128-bit key and 10 rounds; AES-256 uses a 256-bit key and 14 rounds, roughly 40 per cent more work per block. Both are secure against any known attack. AES-256 mainly adds safety margin for long-lived secrets, regulations that require it and possible future quantum computers.
Is AES-256 safe from quantum computers?
As far as anyone knows, yes. The main quantum attack on symmetric ciphers, Grover's algorithm, could at best roughly halve the effective key length, leaving AES-256 with about 128 bits of security, which is still far beyond brute force. Quantum computers mainly threaten asymmetric methods such as RSA and elliptic-curve cryptography, not AES.
What does AES-256-GCM mean?
It means AES with a 256-bit key, running in Galois/Counter Mode. GCM encrypts data in counter mode and adds an authentication tag, so any change to the ciphertext is detected when it is decrypted. It is the usual choice for HTTPS and most modern systems, with one strict rule: never reuse a nonce with the same key.