Key Takeaways
- AES is a NIST-standardized symmetric block cipher that encrypts 128-bit blocks using 128-, 192-, or 256-bit keys.
- AES-128 and AES-256 both provide strong security, with the appropriate choice depending on security requirements and how long data needs to remain protected.
- Secure AES implementation depends on more than the cipher itself, including the encryption mode, key management, and authentication.
The Advanced Encryption Standard (AES) arrives bundled into protocols IT teams already run, such as Wi-Fi, virtual private network (VPN) tunnels, and disk encryption.
That can make it easy to treat encryption as handled, but there’s more to it. The cipher is one layer of encryption, but other layers determine whether it holds: key length, mode of operation, and who controls the keys.
This guide covers AES encryption, its evolution, how it works, and real-world use cases for modern IT environments.
What Is AES Encryption?
AES, the Advanced Encryption Standard, is a widely used encryption standard for protecting electronic data. The U.S. National Institute of Standards and Technology (NIST) established this standard in 2001.
AES is a symmetric key cipher, meaning the same key is used to both encrypt and decrypt data. It replaced the older Data Encryption Standard (DES) and is now the global benchmark for symmetric encryption, used in everything from Wi-Fi protocols to government classified systems.
AES vs. DES: How the Standard Evolved
The main weakness of DES was its 56-bit key, which became increasingly vulnerable as computing power improved. An attacker using a brute-force approach could eventually test enough possible keys to break DES, making it unsuitable for protecting sensitive information over the long term.
To find a stronger replacement, NIST ran an open competition in 1997 and evaluated 15 candidate algorithms submitted by researchers around the world. In 2000, NIST selected Rijndael, developed by Belgian cryptographers Joan Daemen and Vincent Rijmen, as the basis for the new standard.
NIST published AES as Federal Information Processing Standard (FIPS) 197 in 2001 and formally withdrew the DES standard in 2005. AES has remained the widely adopted successor.
AES Key Sizes: AES-128, AES-192, and AES-256
AES supports three key lengths, each offering a different balance of speed and security:
- AES-128: 128-bit key with 10 encryption rounds, prioritizing speed for low-risk applications
- AES-192: 192-bit key with 12 rounds, offering balanced security and performance
- AES-256: 256-bit key with 14 rounds, providing maximum protection for highly sensitive data
Longer keys increase the number of combinations an attacker would need to test in a brute-force scenario, which is why AES-256 is the standard choice for classified government data and high-value financial systems. For most enterprise use cases, AES-128 and AES-256 are the most common. AES-192 is used less frequently in practice.
Info: AES-128, AES-192, and AES-256 are all approved AES configurations. The right choice depends on the security requirements and how long the data needs to remain protected.
How Does AES Work?
AES operates on fixed-size 128-bit blocks, applying a series of mathematical transformations to each block. The number of rounds depends on the key length: 10 rounds for AES-128, 12 for AES-192 and 14 for AES-256.
- Key expansion: AES first takes the encryption key and expands it into a series of round keys. Each round uses a different round key derived from the original key. The longer the key, the more round keys are generated.
- Initial AddRoundKey: The 128-bit plaintext block is arranged as a 4×4 array of bytes called the state. AES begins by combining the state with the first round key using an XOR operation.
- SubBytes: Each byte in the state is replaced with another byte using a fixed lookup table called the S-box. This introduces nonlinearity, making the relationship between the plaintext, ciphertext and key difficult to analyze.
- ShiftRows: The bytes in each row of the state are shifted by different amounts. This rearranges the data and contributes to diffusion.
- MixColumns: AES mathematically combines the four bytes in each column of the state. This provides diffusion, so changing a single input byte affects multiple bytes as the encryption proceeds.
- AddRoundKey: The transformed state is XORed with the round key for that round. The SubBytes, ShiftRows, MixColumns and AddRoundKey operations are then repeated for the required number of rounds.
The final round omits MixColumns, after which the resulting 128-bit state is the ciphertext. - Decryption: Decryption reverses these transformations using the same secret key. It applies the corresponding inverse operations — InvShiftRows, InvSubBytes, InvMixColumns and AddRoundKey — to recover the original plaintext.
See your security gap before attackers do.
See continuous trust in action on a platform that includes RADIUS, PKI and AI security.
AES Modes of Operation
AES encrypts data in individual 128-bit blocks. A mode of operation determines how those blocks are handled when encrypting a larger message. Which mode an organization chooses can have a significant impact on security, regardless of the strength of the AES key.
NIST defines five confidentiality modes for block ciphers, including:
- Electronic Codebook (ECB)
- Cipher Block Chaining (CBC)
- Cipher Feedback (CFB)
- Output Feedback (OFB)
- Counter (CTR)
Warning: Encryption alone does not guarantee that data has not been modified. The mode of operation determines whether an AES implementation provides confidentiality alone or also verifies data integrity.
Galois/Counter Mode (GCM) provides an additional security feature that those confidentiality modes do not: authentication. In addition to encrypting the data, GCM generates an authentication tag that allows the recipient to detect whether the ciphertext has been modified. This makes GCM an authenticated encryption with associated data (AEAD) mode, a category used by modern protocols such as Transport Layer Security (TLS) 1.3.
The table below compares the four AES modes most relevant to enterprise operations.
| Mode | How it chains blocks | Provides integrity | Typical use |
| ECB | Each block encrypted independently | No | Avoid: identical plaintext blocks produce identical ciphertext |
| CBC | Each block combined with the previous ciphertext block | No | Legacy file and disk encryption |
| CTR | Encrypts a counter, then combines the result with plaintext | No | High-throughput streaming; parallelizable |
| GCM | Counter-style chaining plus an authentication tag | Yes | TLS 1.3 and anything that needs tamper detection |
Real-World Applications of AES
AES protects data across wireless networks (WPA2/WPA3), HTTPS connections, VPNs, cloud storage, financial transactions, password managers, and messaging applications used by government and military systems.
Two of these applications are worth a closer look: HTTPS and wireless networks. HTTPS uses AES-based authenticated encryption to protect data during TLS connections, while WPA2 and WPA3 rely on AES to secure Wi-Fi traffic.
AES in Wi-Fi Security
One of the most common deployments of AES is in Wi-Fi network encryption. The WPA2 and WPA3 protocols — the current standards for securing wireless networks — both use AES as their underlying cipher.
- In WPA2, AES is implemented through the CCMP (Counter Mode CBC-MAC Protocol) encryption mode.
- WPA3-Personal strengthens this further with the Simultaneous Authentication of Equals (SAE) handshake. WPA3-Enterprise keeps the 802.1X/EAP authentication defined in WPA2-Enterprise and adds an optional 192-bit security mode. Both modes still rely on AES for data encryption.
For organizations running enterprise Wi-Fi, AES-based encryption is only as strong as the authentication layer protecting it. Password-based Wi-Fi authentication leaves networks vulnerable to credential theft and over-the-air attacks. Certificate-based 802.1X authentication pairs AES encryption with a cryptographic identity for every device, eliminating the credential attack surface.
What Are the Risks of AES Encryption?
While AES is widely considered the gold standard for symmetric encryption, it still carries risks. Understanding these threats helps organizations deploy AES correctly.
- Brute-force attacks: An attacker who can test every possible key combination could, in theory, break AES. In practice, AES-128 has 2^128 possible keys — a number large enough to make brute force computationally infeasible with current hardware. AES-256 raises that to 2^256, which is considered secure against even quantum computing advances for the foreseeable future.
- Side-channel attacks: Rather than attacking the algorithm directly, side-channel attacks exploit information leaked by the physical implementation — timing differences, power consumption, or electromagnetic emissions. Defending against these attacks is especially important in hardware implementations such as smart cards and embedded systems.
- Key management failures: The most realistic attack vector against AES is not the cipher itself but the management of the keys. Keys stored insecurely, transmitted without protection, or reused across sessions create vulnerabilities that bypass the encryption entirely. Strong key management, trained staff, and advanced randomization techniques are important components of a sound AES deployment.
- Weak modes of operation: AES in ECB mode encrypts identical plaintext blocks into identical ciphertext blocks, creating patterns that can be detected. CBC and GCM address this; GCM is the preferred mode for most modern applications because it also provides authenticated encryption.
Warning: AES cannot protect data if an attacker obtains the encryption key. Secure key generation, storage, distribution, rotation, and access controls are critical for effective encryption.
AES Encryption Key Management Best Practices
Strong encryption depends on more than choosing the right algorithm. If encryption keys are poorly generated, kept in use too long, or shared too broadly, AES cannot provide the protection it was designed to provide.
Three key-management best practices can help with this:
- Use a reliable source of randomness: Encryption keys should be generated using a cryptographically secure source of randomness. A predictable seed can make a key vulnerable to guessing, regardless of its length.
- Set a defined key lifetime: Keys should not remain active indefinitely. Establish a usage period, then retire and replace keys when that period ends.
- Keep encryption separate from identity: A shared secret does not establish which person or device is using it. When the same key or password is shared across multiple devices, it cannot provide unique identity.
This limitation becomes particularly important for wireless networks. AES can protect the data being transmitted, but it does not identify the device sending that data. Shared Wi-Fi passwords address encryption but provide limited device-level identity. A public key infrastructure (PKI) can add that missing layer by issuing individual certificates that identify devices.
The security plan that scales with you.
Our solutions can scale from mid-market to global enterprises. Compare options and see how our solutions protect you from costly breaches and ensure peace of mind.
AES vs. RSA: What’s the Difference?
AES and RSA are both encryption standards in widespread use, but they solve different problems and are typically deployed together rather than as alternatives.
AES is symmetric encryption: One shared secret key encrypts and decrypts the data. This makes AES fast and efficient for bulk data encryption — it is the right tool for encrypting files, disk volumes, network traffic, and database records at scale. The challenge with symmetric encryption is that both parties must already share the key securely before communication begins.
RSA is asymmetric encryption: It uses a mathematically linked public/private key pair. Data encrypted with the public key can only be decrypted by the corresponding private key, and vice versa. RSA does not require a pre-shared secret, which makes it well-suited for establishing trust and exchanging keys between parties who have never communicated before. The tradeoff is that RSA is significantly slower than AES for bulk data.
In practice, most secure systems use both: asymmetric cryptography to establish the session and agree on an AES key — in modern TLS, an ephemeral Diffie-Hellman or elliptic-curve Diffie-Hellman exchange, with RSA or ECDSA signatures authenticating the parties — and AES to encrypt the actual data.TLS handshakes, HTTPS connections, and VPN tunnels all follow this pattern.
Secure Your Wi-Fi With AES-Protected 802.1X Authentication
AES encryption is the backbone of modern Wi-Fi security, but encryption alone does not control who can access a network. Without strong device authentication, attackers who obtain shared credentials may still be able to connect to an AES-protected network.
SecureW2 provides WPA2/WPA3 Enterprise security with certificate-based 802.1X authentication through JoinNow Dynamic PKI and JoinNow Cloud RADIUS:
- Dynamic PKI automates certificate issuance and lifecycle management, giving each device its own unique digital identity.
- Cloud RADIUS uses those certificates to authenticate devices before granting network access, eliminating the need for shared Wi-Fi passwords.
Schedule a demo to see how SecureW2 can help your organization combine AES-protected Wi-Fi with automated certificate management and cloud-based 802.1X authentication.
Frequently Asked Questions
Has AES encryption ever been cracked?
Researchers have found theoretical attacks against AES, but none have produced a practical break of the full cipher. In 2011, cryptographers published key-recovery attacks against AES-128, AES-192, and AES-256 with estimated complexities of about 2^126.1, 2^189.7, and 2^254.4 operations, respectively. Those results were significant from a cryptanalysis perspective but remain far beyond what an attacker could feasibly carry out. AES is not considered practically broken.
Is AES-128 strong enough, or should we standardize on AES-256?
AES-128 remains a strong choice for most applications. NIST continues to recognize AES-128, AES-192, and AES-256 as approved key sizes, and there is no current evidence that AES-128 is approaching practical failure. AES-256 may be appropriate when information needs to remain confidential for a particularly long period or when a specific security or compliance requirement calls for it. Choosing AES-256 does not mean AES-128 is currently inadequate.
Will quantum computers break AES encryption?
Quantum computing does not currently provide a practical way to break AES. Grover's algorithm could theoretically reduce the effective brute-force security of a symmetric cipher, but it does not make AES-256 or AES-128 practically breakable with today's technology. Much of the current post-quantum focus is instead on public-key cryptography, including the algorithms used for key exchange and digital signatures.
Does AES encryption protect data at rest as well as data in transit?
Yes. AES can protect information both while it is stored and while it is being transmitted. It is commonly used for full-disk encryption, encrypted databases, and backups, while TLS uses AES-based symmetric encryption to protect data moving across a network. The underlying cipher can be the same in both cases; what differs is how the encryption is implemented and, critically, how the keys are generated, stored, accessed, and managed.