AES-256
In short: AES with a 256-bit key: the strong standard of symmetric encryption.
In more detail: AES (Advanced Encryption Standard) is a block cipher that the US institute NIST standardised in 2001 as the successor of DES (the Rijndael algorithm from Belgium). It processes blocks of 128 bits; the AES-256 variant uses a 256-bit key and 14 rounds.
In Depth
Properties
- Symmetric: the same key is used to encrypt and decrypt.
- Very fast, especially with the hardware support AES-NI in modern processors.
- No practically known attacks that shortcut the key space.
Modes of operation
The algorithm alone is not enough, the mode matters. GCM (Galois/Counter Mode) encrypts and checks integrity. ECB is insecure because identical blocks are encrypted identically.
AES-256 or AES-128?
Both are considered secure. AES-256 offers more headroom, also against future quantum attacks (Grover’s algorithm roughly halves the effective key length). Used in TLS, Wi-Fi (WPA2/3), disk encryption, 7-Zip, password managers.
See also: AES-128, Encryption, Session Key, RSA-2048