AES-GCM
An authenticated-encryption mode combining AES counter-mode encryption with Galois-field authentication for high-throughput confidentiality and integrity.
Cryptographic Context
AES-GCM combines counter-mode encryption with a Galois-field authentication function, allowing encryption and authentication work to be parallelized efficiently on hardware that accelerates AES. It is widely used in network-security protocols, including TLS.
Security Boundary
Nonce reuse under the same key is a critical failure condition. Using AES alone is also not equivalent to using GCM: the authentication tag must be generated and verified correctly for the construction to provide authenticated encryption.
Related Cryptographic Concepts
- AEAD
- AES
- Nonce
- Authentication Tag