AES-GCM (Advanced Encryption Standard – Galois/Counter Mode) is an authenticated encryption with associated data (AEAD) cipher mode that combines the AES block cipher operating in Counter Mode with the Galois Message Authentication Code. It provides both confidentiality and data integrity in a single pass, making it the dominant symmetric encryption scheme in modern secure communications.
Content
- AES-GCM was standardised by NIST in Special Publication 800-38D (2007), drawing on Galois/Counter Mode work by McGrew and Viega. It emerged as a response to the operational complexity of combining separate encryption and authentication algorithms, unifying both functions with a provably secure construction under chosen-ciphertext attack models. Its incorporation into TLS 1.2 cipher suites drove rapid adoption across the internet infrastructure.
- Technically, AES-GCM operates by encrypting a counter block with AES for each 128-bit plaintext block (CTR mode), XORing the result with plaintext to produce ciphertext. The authentication tag is computed over associated data and ciphertext using multiplication in GF(2¹²⁸), keyed by a block derived from AES applied to a zero counter. Hardware acceleration via Intel AES-NI and ARM Crypto Extensions allows encryption speeds exceeding 10 Gbit/s on modern processors, making it practical for high-throughput applications.
- AES-GCM is the mandated cipher suite in TLS 1.3, DTLS, IPsec, and SSH, and is specified in numerous IETF RFCs. Cloud storage providers, VPN gateways, and messaging platforms rely on it for bulk data encryption. The 96-bit nonce is typically constructed as a combination of a fixed sender identifier and a monotonically increasing counter, managed through disciplined Cryptographic Key Management pipelines. Libraries including OpenSSL, BoringSSL, and libsodium expose stable APIs for safe use.
- As of 2024–2025, AES-GCM remains the gold standard for symmetric authenticated encryption in classical computing environments. Research into Post-Quantum Cryptography does not displace AES-GCM directly, as AES-256-GCM is considered quantum-resistant under Grover’s algorithm with its effective 128-bit quantum security. Efforts focus on pairing post-quantum key encapsulation mechanisms (KEMs) with AES-GCM for hybrid schemes. Nonce-misuse-resistant alternatives such as AES-GCM-SIV are gaining traction in contexts where nonce uniqueness is difficult to guarantee.