AES Encrypt

Encrypt or decrypt with AES. A one-way digest is the hash generator

What this page encrypts

AES is a block cipher. This page runs it in the browser in ECB, CBC, CTR, OFB, CFB or GCM, with a key of 16, 24 or 32 bytes. A one-way fingerprint of a password belongs on the hash generator.

How to use it

  1. Paste the input. Mode starts at CBC. Padding starts at pkcs7padding. Charset starts at UTF-8.
  2. Key format and IV format start as Text. Input format starts as Text. Output format starts as hex. ECB hides the IV. GCM shows Tag length and AAD, and forces nopadding.
  3. Encrypt runs encryption. Decrypt runs decryption. Show Example fills hello, CBC, pkcs7padding, UTF-8, key 1234567890abcdef, IV 1234567890abcdef, and hex output 7e6347a62a0a976373e79b1bd586363d.
  4. Swap copies the result into the input and sets Input format to the format just produced. Set Output format to Text, then Decrypt. The same key and IV return hello.
  5. Clear All empties the boxes and restores CBC, pkcs7padding, UTF-8, Text formats and hex output. Copy Result copies the output.

Key, IV, padding and tag

Text is turned into bytes with the charset. hex and Base64 are already bytes, so the charset is not applied to them. The key must then be 16, 24 or 32 bytes, which is AES-128, AES-192 or AES-256. A 16-character UTF-8 key such as 1234567890abcdef is 16 bytes.

CBC, CFB, OFB and CTR need a 16-byte IV. ECB does not use an IV. GCM accepts any non-empty IV, and 12 bytes is the usual length. pkcs5padding and pkcs7padding are the same here: both add 1 to 16 bytes so the length is a multiple of 16. nopadding leaves the bytes alone, so ECB and CBC then need a multiple of 16. GCM only allows nopadding.

The GCM tag is appended to the ciphertext. Tag length is 128 bits unless you pick another length. AAD is checked and is not encrypted. Decrypt refuses a Text input, and Encrypt refuses a Text output. A wrong key, a wrong IV, a bad tag or bad padding fails.

Where people use it

  • Checking a CBC ciphertext against another AES tool.
  • Reading a GCM result whose tag sits on the end of the hex.
  • Switching the key between text, hex and Base64.

Questions

Why is pkcs5 the same as pkcs7 here?

AES blocks are 16 bytes. Both paddings fill the last block with the same byte count.

Does the same text always give the same hex?

Yes, when the mode, padding, key and IV stay the same. Show Example is 7e6347a62a0a976373e79b1bd586363d.