Advanced Encryption Standard (AES): What It Is and How It Works – Hashed Out by The SSL Store – Hashed Out by The SSL Store
Understanding advanced encryption standard on basic level doesnt require a higher degree in computer science or Matrix-level consciousness lets break AES encryption down into laymans terms
Hey, all. We know of security of information to be a hot topic since, well, forever. We entrust our personal and sensitive information to lots of major entities and still have problems with data breaches, data leaks, etc. Some of this happens because of security protocols in networking, or bad practices of authentication management but, really, there are many ways that data breaches can occur. However, the actual process of decrypting a ciphertext without a key is far more difficult. For that, we can thank the encrypting algorithms like the popular advanced encryption standard and the secure keys that scramble our data into indecipherable gibberish.
Lets look into how AES works and different applications for it. Well be getting a little into some Matrix-based math so, grab your red pills and see how far this rabbit hole goes.
Lets hash it out.
You may have heard of advanced encryption standard, or AES for short but may not know the answer to the question what is AES? Here are four things you need to know about AES:
The National Institute of Standards and Technology (NIST) established AES as an encryption standard nearly 20 years ago to replace the aging data encryption standard (DES). After all, AES encryption keys can go up to 256 bits, whereas DES stopped at just 56 bits. NIST could have chosen a cipher that offered greater security, but the tradeoff would have required greater overhead that wouldnt be practical. So, they went with one that had great all-around performance and security.
AESs results are so successful that many entities and agencies have approved it and utilize it for encrypting sensitive information. The National Security Agency (NSA), as well as other governmental bodies, utilize AES encryption and keys to protect classified or other sensitive information. Furthermore, AES is often included in commercial based products, including but limited to:
Although it wouldnt literally take forever, it would take far longer than any of our lifetimes to crack an AES 256-bit encryption key using modern computing technology. This is from a brute force standpoint, as in trying every combination until we hear the click/unlocking sound. Certain protections are put in place to prevent stuff from like this happening quickly, such as a limit on password attempts before a lockdown, which may or may not include a time lapse, to occur before trying again. When we are dealing with computation in milliseconds, waiting 20 minutes to try another five times would seriously add to the time taken to crack a key.
Just how long would it take? We are venturing into a thousand monkeys working on a thousand typewriters to write A Tale of Two Cities territory. The possible combinations for AES 256-bit encryption is 2256. Even if a computer can do multiple quadrillions of instructions per second, then we are still in that eagles-wings-eroding-Mount-Everest time frame.
Needless to say, its waaaaaaaaaaaaaaaaaaay (theres not enough memory on our computers to support the number of a letters that I want to convey) longer than our current universe has been in existence. And thats just for a 16-byte block of data. So, as you can see, brute forcing AES even if it is 128 bits AES is futile.
That would likely change, though, once quantum computing becomes a little more mainstream, available, and effective. Quantum computing is expected to break AES encryption and require other methods to protect our data but thats still a ways down the road.
Manage Digital Certificates like a Boss
14 Certificate Management Best Practices to keep your organization running, secure and fully-compliant.
To better understand what AES is, you need to understand how it works. But in order to see how the advanced encryption standard actually works, however, we first need to look at how this is set up and the rules concerning the process based on the users selection of encryption strength. Typically, when we discuss using higher bit levels of security, were looking at things that are more secure and more difficult to break or hack. While the data blocks are broken up into 128 bits, the key size have a few varying lengths: 128 bits, 196 bits, and 256 bits. What does this mean? Lets back it up for a second here.
We know that encryption typically deals in the scrambling of information into something unreadable and an associated key to decrypt the scramble. AES scramble procedures use four scrambling operations in rounds, meaning that it will perform the operations, and then repeat the process based off of the previous rounds results X number of times. Simplistically, if we put in X and get out Y, that would be one round. We would then put Y through the paces and get out Z for round 2. Rinse and repeat until we have completed the specified number of rounds.
The AES key size, specified above, will determine the number of rounds that the procedure will execute. For example:
As mentioned, each round has four operations.
So, youve arrived this far. Now, you may be asking: why, oh why, didnt I take the blue pill?
Before we get to the operational parts of advanced encryption standard, lets look at how the data is structured. What we mean is that the data that the operations are performed upon is not left-to-right sequential as we normally think of it. Its stacked in a 44 matrix of 128 bits (16 bytes) per block in an array thats known as a state. A state looks something like this:
So, if your message was blue pill or red, it would look something like this:
So, just to be clear, this is just a 16-byte block so, this means that every group of 16 bytes in a file are arranged in such a fashion. At this point, the systematic scramble begins through the application of each AES encryption operation.
As mentioned earlier, once we have our data arrangement, there are certain linked operations that will perform the scramble on each state. The purpose here is to convert the plaintext data into ciphertext through the use of a secret key.
The four types of AES operations as follows (note: well get into the order of the operations in the next section):
As mentioned earlier, the key size determines the number of rounds of scrambling that will be performed. AES encryption uses the Rjindael Key Schedule, which derives the subkeys from the main key to perform the Key Expansion.
The AddRoundKey operation takes the current state of the data and executes the XOR Boolean operation against the current round subkey. XOR means Exclusively Or, which will yield a result of true if the inputs differ (e.g. one input must be 1 and the other input must be 0 to be true). There will be a unique subkey per round, plus one more (which will run at the end).
The SubBytes operation, which stands for substitute bytes, will take the 16-byte block and run it through an S-Box (substitution box) to produce an alternate value. Simply put, the operation will take a value and then replace it by spitting out another value.
The actual S-Box operation is a complicated process, but just know that its nearly impossible to decipher with conventional computing. Coupled with the rest of AES operations, it will do its job to effectively scramble and obfuscate the source data. The S in the white box in the image above represents the complex lookup table for the S-Box.
The ShiftRows operation is a little more straightforward and is easier to understand. Based off the arrangement of the data, the idea of ShiftRows is to move the positions of the data in their respective rows with wrapping. Remember, the data is arranged in a stacked arrangement and not left to right like most of us are used to reading. The image provided helps to visualize this operation.
The first row goes unchanged. The second row shifts the bytes to the left by one position with row wrap around. The third row shifts the bytes one position beyond that, moving the byte to the left by a total of two positions with row wrap around. Likewise, this means that the fourth row shifts the bytes to the left by a total of three positions with row wrap around.
The MixColumns operation, in a nutshell, is a linear transformation of the columns of the dataset. It uses matrix multiplication and bitwise XOR addition to output the results. The column data, which can be represented as a 41 matrix, will be multiplied against a 44 matrix in a format called the Gallois field, and set as an inverse of input and output. That will look something like the following:
As you can see, there are four bytes in that are ran against a 44 matrix. In this case, matrix multiplication has each input byte affecting each output byte and, obviously, yields the same size.
Now that we have a decent understanding of the different operations utilized to scramble our data via AES encryption, we can look at the order in which these operations execute. It will be as such:
Note: The MixColumns operation is not in the final round. Without getting into the actual math of this, theres no additional benefit to performing this operation. In fact, doing so would simply make the decryption process a bit more taxing in terms of overhead.
If we consider the number of rounds and the operations per round that are involved, by the end of it, you should have a nice scrambled block. And that is only a 16-byte block. Consider how much information that equates to in the big picture. Its miniscule when compared to todays file/packet sizes! So, if each 16-byte block has seemingly no discernable pattern at least, any pattern that can be deciphered in a timely manner Id say AES has done its job.
We know the advanced encryption standard algorithm itself is quite effective, but its level of effectiveness depends on how its implemented. Unlike the brute force attacks mentioned above, effective attacks are typically launched on the implementation and not on the algorithm itself. This can be equated to attacking users as in phishing attacks versus attacking the technology behind the service/function that may be hard to breach. These can be considered side-channel attacks where the attacks are being carried out on other aspects of the entire process and not the focal point of the security implementation.
While I always advocate going with a reasonable/effective security option, a lot of AES encryption is happening without you even knowing it. Its locking down spots of the computing world that would otherwise be wide open. In other words, there would be many more opportunities for hackers to capture data if advanced encryption standard wasnt implemented at all. We just need to know how to identify the open holes and figure out how to plug them. Some may be able to use AES and others may need another protocol or process.
Appreciate the encryption implementations we have, use the best ones when needed, and happy scrutinizing!
- Roundtable: Quantum Computing Scenario Implementation & Emergence If Quantum Computing Power Is Available Tomorrow, Who Will Be the First... - September 15th, 2026 [September 15th, 2026]
- Quantum Computing Inc. Expands Global Quantum Adoption Through New Hamad Bin Khalifa University Framework Agreement - PR Newswire - September 15th, 2026 [September 15th, 2026]
- Keynote Speech: Breaking Boundaries Quantum Computing Advances into Deep Industrial Application Waters The Next Mile of Quantum Computing | 36Kr... - September 15th, 2026 [September 15th, 2026]
- CloudHill Capital Partner Song Xuwen: Quantum Computing Advances Engineering & Industrialization in Parallel - Inflection Point Near | 36Kr 2026... - September 15th, 2026 [September 15th, 2026]
- Why Quantum Computing Could Break the Internets Security And What Comes Next - European Business Magazine - September 15th, 2026 [September 15th, 2026]
- Quantum Computing expands global quantum adoption via accord with university in Qatar - ROI-NJ - September 15th, 2026 [September 15th, 2026]
- Phasecraft and NVIDIA expand collaboration to advance quantum computing research - New Electronics - September 15th, 2026 [September 15th, 2026]
- Quantum Dice and North Wales Police Test Probabilistic Computing for Emergency Response - The Quantum Insider - September 15th, 2026 [September 15th, 2026]
- Quantum Computing Inc. Signs Three-Year Agreement With Hamad Bin Khalifa University - Yahoo Finance - September 15th, 2026 [September 15th, 2026]
- Quantum Computing and the Rise of the Breachless Data Breach - Law.com - September 15th, 2026 [September 15th, 2026]
- If I Could Only Buy 1 Quantum Computing Stock, This Would Be It - Yahoo Finance - September 13th, 2026 [September 13th, 2026]
- BigBear.ai vs. IonQ: Weighing Whether to Invest in the Artificial Intelligence Company or the Quantum Computing Giant - The Motley Fool - September 13th, 2026 [September 13th, 2026]
- IBM and Lockheed Martin Partner with ETH Zurich to Deploy Switzerlands First IBM Quantum System Two - Quantum Computing Report - September 13th, 2026 [September 13th, 2026]
- BWT Alpine Formula One Team and SEALSQ Expand Quantum Partnership into Multiphysics Simulation - Quantum Computing Report - September 13th, 2026 [September 13th, 2026]
- If I Could Only Buy 1 Quantum Computing Stock, This Would Be It - The Motley Fool - September 13th, 2026 [September 13th, 2026]
- 3 Quantum Computing Stocks Have Issued a $63 Million Warning This Year That Wall Street Cannot Ignore - The Motley Fool - September 13th, 2026 [September 13th, 2026]
- BigBear.ai vs. IonQ: Weighing Whether to Invest in the Artificial Intelligence Company or the Quantum Computing Giant - The Globe and Mail - September 13th, 2026 [September 13th, 2026]
- Why quantum computing stocks are soaring today while the rest of the market falls - Yahoo Finance - September 13th, 2026 [September 13th, 2026]
- Is the Quantum Computing Threat to Bitcoin Overblown? These New Developments Suggest That's the Case. - The Motley Fool - September 8th, 2026 [September 8th, 2026]
- AI models using quantum computing will be tested on live currency data - Stock Titan - September 8th, 2026 [September 8th, 2026]
- The US is pouring hundreds of millions more into quantum computing. This is only the beginning - XTB.com - September 8th, 2026 [September 8th, 2026]
- Quantum Motion Raises Additional Funding for Silicon Quantum Computing - The Quantum Insider - September 4th, 2026 [September 4th, 2026]
- George Mason University Partners with TreQ to Install $7.7M Open-Architecture Quantum QPU in Virginia - Quantum Computing Report - September 4th, 2026 [September 4th, 2026]
- Rigetti and Purdue University Demonstrate Quantum Preconditioning Framework for Constrained Optimization - Quantum Computing Report - September 4th, 2026 [September 4th, 2026]
- George Mason and TreQ Bring Open-Architecture Quantum Computing to Virginia - HPCwire - September 4th, 2026 [September 4th, 2026]
- IBM Releases Nighthawk r2 QPU Featuring Active Dissipative Qubit Reset and 25x Circuit Throughput - Quantum Computing Report - September 4th, 2026 [September 4th, 2026]
- Why everyone in quantum computing is buzzing about Googles move into neutral atoms - Fast Company - September 2nd, 2026 [September 2nd, 2026]
- Bitcoin May Already be Resistant to Quantum Computing Attacks - extremetech.com - September 2nd, 2026 [September 2nd, 2026]
- Anyon Systems and KMT Technologies Partner to Expand Quantum Computing Deployment - The Quantum Insider - September 2nd, 2026 [September 2nd, 2026]
- Yaqumo and SCREEN Holdings Partner on NEDO Project to Build Optical Modules for Neutral-Atom QPUs - Quantum Computing Report - September 2nd, 2026 [September 2nd, 2026]
- NSF awards $37M to its UC Berkeley-led quantum computing research - Daily Cal - September 2nd, 2026 [September 2nd, 2026]
- Anyon Systems and Matrix Group Partner to Accelerate International Quantum Supercomputing Deployments - Quantum Computing Report - September 2nd, 2026 [September 2nd, 2026]
- Diffraqtion Caps Pre-Seed Round at $10M+ with Strategic Backing from Lockheed Martin and Presidio Ventures - Quantum Computing Report - September 2nd, 2026 [September 2nd, 2026]
- Anyon Systems and KMT Technologies Partner to Accelerate International Deployment of Quantum Computing - HPCwire - September 2nd, 2026 [September 2nd, 2026]
- A Major Quantum Computing Problem May Finally Have an Answer: Can We Trust the Results? - SciTechDaily - September 2nd, 2026 [September 2nd, 2026]
- S-Transistors Raises 2.6 Million ($3 Million USD) Pre-Seed Round to Build Superconducting Quantum Control Motherboards - Quantum Computing Report - September 2nd, 2026 [September 2nd, 2026]
- How Quantum Hardware Rollouts And NHanced Deal At Quantum Computing (QUBT) Have Changed Its Investment Story - simplywall.st - September 2nd, 2026 [September 2nd, 2026]
- Can IBM's HRL Acquisition Boost Its Quantum Computing Capabilities? - The Globe and Mail - September 2nd, 2026 [September 2nd, 2026]
- Anyon Systems And Matrix Group Team Up To Expand Quantum Computing Access - Quantum Zeitgeist - September 2nd, 2026 [September 2nd, 2026]
- Quantum Computing Use Cases for the Oil and Gas Industry - JPT Homepage - August 31st, 2026 [August 31st, 2026]
- Quantum computing: Where we stand in 2026 - Constellation Research - August 31st, 2026 [August 31st, 2026]
- Quantum Computing Inc Stock (QUBT) Opinions on Revenue Surge and Analyst Upgrade - Quiver Quantitative - August 31st, 2026 [August 31st, 2026]
- Quantum Computing (QUBT) Stock Looks Reasonable On Book Value While Returns Look Stretched - simplywall.st - August 31st, 2026 [August 31st, 2026]
- Quantum Computing (QUBT) Looks Undervalued On Paper, Is The Pullback A Buying Opportunity? - simplywall.st - August 31st, 2026 [August 31st, 2026]
- Quantum Computing Is Raising the Stakes for Cybersecurity: 5 Stocks to Watch - Yahoo Finance - August 31st, 2026 [August 31st, 2026]
- The Dream of Quantum Computing Is Both Dead and Alive - Bloomberg - August 27th, 2026 [August 27th, 2026]
- Quantum Datacenter Alliance Announces Second Annual Forum on Scaling Quantum Computing - The Quantum Insider - August 27th, 2026 [August 27th, 2026]
- Why Quantum Computing Is a Threat to Cybersecurity - WSJ - August 27th, 2026 [August 27th, 2026]
- Its time to stop sleeping on quantum computing: 48 experts on what to watch for next - Fast Company - August 27th, 2026 [August 27th, 2026]
- Bitcoin now has a quantum computing escape route, but 7 million BTC may still be exposed - CryptoSlate - August 27th, 2026 [August 27th, 2026]
- Quantum Computing Inc Stock (QBTS) Opinions on CFO Resignation - Quiver Quantitative - August 27th, 2026 [August 27th, 2026]
- Pasqal and Eleven Ventures Form Joint Venture for Quantum Computing in Saudi Arabia - The Quantum Insider - August 27th, 2026 [August 27th, 2026]
- 1 Quantum Computing Stock Everyone's Ignoring While IonQ Gets the Headlines - The Motley Fool - August 27th, 2026 [August 27th, 2026]
- Quantum Stocks Unwind a Revenue-Headline Rally: Rigetti Computing and Infleqtion Down 7%, IonQ Down 6% - 24/7 Wall St. - August 27th, 2026 [August 27th, 2026]
- Quantum Datacenter Alliance Announces 2nd Annual Forum on Scaling Quantum Computing - HPCwire - August 27th, 2026 [August 27th, 2026]
- IonQ vs. Quantum Computing Inc.: Which Quantum Computing Stock Is a Better Buy in 2026? - The Motley Fool - August 27th, 2026 [August 27th, 2026]
- Quantum Computing Stocks IonQ, Rigetti Computing, and D-Wave Quantum Have Put Wall Street on Notice With This $863 Million Warning - The Motley Fool - August 27th, 2026 [August 27th, 2026]
- IonQ Expands Cloud Quantum Computing Access Through Canadian FABrIC Sandbox - The Fast Mode - August 23rd, 2026 [August 23rd, 2026]
- IonQ (NYSE: IONQ) Emerges As The Standout Pure-Play Quantum Computing Stock To Watch - foreignpolicyjournal.com - August 23rd, 2026 [August 23rd, 2026]
- The Quantum Computing Race Is Heating Up: The Top 3 Stocks to Buy Right Now - Yahoo Finance - August 23rd, 2026 [August 23rd, 2026]
- Reddit vs. Rigetti Computing: Which High-Growth Stock Is a Better Buy in 2026, the Social Media Giant or Rising Quantum Computing Company? - Yahoo... - August 23rd, 2026 [August 23rd, 2026]
- 1 Quantum Computing Stock That Looks Like a Screaming Buy Right Now - The Motley Fool - August 23rd, 2026 [August 23rd, 2026]
- Quantum Computing vs. Red Cat: Which High-Growth Innovation Stock Is a Better Buy in 2026? - The Motley Fool - August 23rd, 2026 [August 23rd, 2026]
- Quantum Computing Finally Delivered, And The Stock May Be Too Cheap (NASDAQ:QUBT) - Seeking Alpha - August 23rd, 2026 [August 23rd, 2026]
- Quantum Computing Stock Jumps 9.6% as Cash Covers 64% of Its Market Value - TechStock - August 23rd, 2026 [August 23rd, 2026]
- D-Wave Quantum vs. Microsoft: Which Is the Better Quantum Computing Stock to Own for the Next 5 Years? - Yahoo Finance - August 23rd, 2026 [August 23rd, 2026]
- A little bit more than magic: The secret to quantum computing may lie in negativity - Phys.org - August 22nd, 2026 [August 22nd, 2026]
- IBM's new 'quantum fridges' are nearly 200 times colder than deep space and could pave the way for fault-tolerant quantum computing - Live Science - August 22nd, 2026 [August 22nd, 2026]
- 3 Quantum Computing Stocks With the Most Upside in August - Yahoo Finance - August 22nd, 2026 [August 22nd, 2026]
- Can IBM Scale Quantum Computing With Its New Cryogenic Systems? - Yahoo Finance - August 22nd, 2026 [August 22nd, 2026]
- EBU and Superpositions Partner to Add Quantum Computing to Business Education - The Quantum Insider - August 22nd, 2026 [August 22nd, 2026]
- IonQ and CMC Microsystems Announce Collaboration to Expand Cloud Quantum Computing Access in Canada - The Quantum Insider - August 22nd, 2026 [August 22nd, 2026]
- New quantum computing facility in South Chicago expected to have economic impact in Illinois - CBS News - August 22nd, 2026 [August 22nd, 2026]
- D-Wave Quantum vs. Microsoft: Which Is the Better Quantum Computing Stock to Own for the Next 5 Years? - The Motley Fool - August 22nd, 2026 [August 22nd, 2026]
- 3 Quantum Computing Stocks With the Most Upside in August - 24/7 Wall St. - August 22nd, 2026 [August 22nd, 2026]
- Quantinuum: Trapped-Ion Quantum Computing Looks To Break Out Of The Quantum Silo - Seeking Alpha - August 22nd, 2026 [August 22nd, 2026]
- FormationQ and Hartree Centre Partner to Advance Quantum Computing in the UK - The Quantum Insider - August 22nd, 2026 [August 22nd, 2026]
- IonQ and CMC Microsystems Announce Collaboration to Expand Cloud Quantum Computing Access in Canada - IonQ - August 18th, 2026 [August 18th, 2026]
- Quantum Computing Inc Stock Short Interest Falls to 32.11% - Quiver Quantitative - August 18th, 2026 [August 18th, 2026]
- The Quantum Opportunity Beyond Computing - Lockheed Martin - August 18th, 2026 [August 18th, 2026]