In one sentence
Password-based AES encryption is a standard way to scramble and unscramble data using a single secret key that's created from a password you choose.
The problem it solves
Ever since humans started writing things down, we've wanted to write things down that other people can't read. From Roman generals shifting letters in a message (the Caesar cipher) to spies using one-time pads in the Cold War, the goal has always been the same: confidentiality. If the message falls into the wrong hands, it should be gibberish.
In the digital age, this problem is everywhere. Your data flies across sketchy public Wi-Fi, sits on servers owned by giant corporations, and gets backed up to hard drives that might end up in a landfill. How do you ensure your private message, your list of API keys, or your secret cookie recipe remains secret?
The old-school ciphers were easy to crack, especially with computers that can try billions of combinations per second. We needed something better. Much better. Enter the Advanced Encryption Standard, or AES.
In the late 1990s, the U.S. National Institute of Standards and Technology (NIST) held a public competition to find a replacement for the aging Data Encryption Standard (DES). They weren't looking for a secret algorithm cooked up in a government basement; they wanted a transparent, public, and brutally-tested cipher that the whole world could trust. After years of cryptographic cage matches, a Belgian algorithm named "Rijndael" (a portmanteau of its inventors' names, Rijmen and Daemen) was crowned the winner in 2001.
It was fast, efficient, and, most importantly, had withstood a global onslaught of attempts to break it. It became AES, the standard we use today to lock down everything from secure websites (HTTPS) to encrypted hard drives and sensitive files. It solves the ancient problem of secret-keeping with modern mathematical rigor.
How it works under the hood
AES seems like magic: you mumble a secret phrase, and your text turns into an unreadable mess. Mumble it again, and it's back. But under the hood, it's just a series of clever, repeatable mathematical steps.
Symmetric vs. Asymmetric
First, a key concept. Encryption comes in two main flavors. AES is symmetric, meaning the same key is used to both lock (encrypt) and unlock (decrypt) the data. It's like your house key—it locks the door, and the very same key unlocks it. This is fast and efficient.
The other flavor is asymmetric (or public-key) cryptography. This uses two different keys: a public key to lock the data and a private key to unlock it. It's like a mailbox: anyone can drop a letter in (using the public slot), but only you have the private key to open it and read the mail. This is great for when you can't securely share a secret key beforehand, but it's much slower than symmetric encryption.
Password-based encryption uses the symmetric model because you and whoever needs to decrypt the data will share the same password.
From Password to Key: The KDF
Here's a critical detail: your password, "SuperSecretP@ssw0rd123", is not the encryption key. Human-memorable passwords aren't random enough or long enough to be secure cryptographic keys.
Instead, your password is fed into a Key Derivation Function (KDF). Think of a KDF as a special-purpose algorithm designed to turn a password into a strong, fixed-size cryptographic key. Modern KDFs like PBKDF2 (Password-Based Key Derivation Function 2) or Argon2 do three important things:
- Add a Salt: A salt is a random piece of data generated for each new encryption. It's mixed in with your password before being processed. This means that even if two users have the same password, the resulting encryption keys will be totally different. This single-handedly defeats "rainbow table" attacks, where hackers use precomputed tables of common passwords and their resulting hashes. The salt is stored alongside the encrypted data; it's not a secret, just a unique ingredient.
- Stretch the Key: The KDF runs the password and salt through a hashing algorithm (like SHA-256) not once, but thousands, or even millions, of times. This is called "iterations" or "work factor". It makes the process deliberately slow. For you, waiting a few hundred milliseconds is no big deal. For an attacker trying to brute-force your password, it's a nightmare, making it computationally expensive to try billions of guesses.
- Produce the Key: After all that work, the KDF spits out a key of the desired length (e.g., 256 bits) that looks like pure random noise. This is the actual key used by AES.
Your Password + Random Salt + Many Iterations -> Strong Encryption Key
("hunter2" + "a3f9d..." + 100,000 rounds) -> 256-bit AES Key
The AES Cipher Itself: A State and Rounds
Now for the main event. AES operates on fixed-size blocks of data—always 128 bits (16 bytes) at a time. Your plaintext message is chopped up into these 16-byte blocks. Each block is loaded into a 4x4 grid of bytes called the state matrix.
This state then goes through a series of identical transformations called rounds. The number of rounds depends on the key size:
- AES-128: 10 rounds
- AES-192: 12 rounds
- AES-256: 14 rounds
Each round (except the last) consists of four steps:
- SubBytes: Each byte in the state matrix is swapped for a different one using a standard lookup table (the "Rijndael S-box"). This is the main non-linear step that introduces confusion.
- ShiftRows: The bytes in each row of the matrix are shifted cyclically. The first row isn't shifted, the second is shifted by one, the third by two, and the fourth by three. This shuffles the data around.
- MixColumns: A mathematical operation is performed on each column, mixing the bytes together. This provides diffusion, spreading the influence of a single plaintext byte over the entire block.
- AddRoundKey: A portion of the main encryption key (a "round key" specific to this round) is XORed with the state. This is where the secret key actually gets mixed into your data.
This SubBytes -> ShiftRows -> MixColumns -> AddRoundKey sequence is repeated over and over. Each round further scrambles the data until, after the final round, the state matrix is a block of completely garbled ciphertext. To decrypt, you just run the steps in reverse with the same key.
Putting It All Together: Cipher Modes and Padding
AES only knows how to encrypt a single 16-byte block. What about your 500-byte message? This is where modes of operation come in. A mode of operation is a recipe for using a block cipher to encrypt a stream of data of any length.
Older modes like CBC (Cipher Block Chaining) had some security gotchas. The modern, recommended mode is GCM (Galois/Counter Mode). GCM is an "authenticated encryption" mode, which is a fancy way of saying it provides two things for the price of one:
- Confidentiality: It encrypts your data so nobody can read it.
- Authenticity: It produces a short "authentication tag". If a single bit of the ciphertext is flipped or tampered with during transit, the tag won't match when you decrypt, and the process will fail. This tells you not only that the data was secret, but also that it wasn't messed with.
Real-world stories
The Freelancer's Client Secret
A UX designer, Anya, needed to send a mockup for a new, unannounced product to her client. The mockup file contained sensitive branding and strategic information. Emailing it felt risky—email is notoriously insecure. Setting up a secure file transfer portal was overkill for a one-off delivery. Instead, Anya encrypted the ZIP file containing her work using a password. She then called the client and told them the password over the phone. She could now safely email the encrypted file, knowing only the client could open it.
Lesson: Password-based encryption is a fantastic tool for ad-hoc, secure sharing of sensitive files between two people without complex infrastructure.
The Developer's Config File
Ben was building a web application that connected to a database and used a third-party payment API. The database password and API key were stored in a config.json file. He needed to commit his code to a shared Git repository, but committing the config file with plain-text secrets would be a catastrophic security breach. So, he encrypted config.json to create config.json.enc. The password for decryption was not stored in the code. In development, he'd just decrypt the file locally. In production, the password was securely passed to the application as an environment variable, which the app used to decrypt the config on startup.
Lesson: Encrypting configuration files allows you to safely store "secrets at rest" alongside your code, separating the secret data from the secret key needed to unlock it.
The Journalist's Notes in the Cloud
Maria, an investigative journalist, was working on a sensitive story. She kept her interview notes and research in a folder that was synced to a popular cloud storage service. While she trusted the service's security, she was worried about potential threats: a rogue employee at the cloud company, a government subpoena, or a major data breach. To protect her sources, she encrypted each document with a strong, unique password before saving it to the synced folder. Now, even if her entire cloud account was compromised, her notes would just be unreadable gibberish.
Lesson: Encryption provides a personal layer of "zero-trust" security, ensuring your data remains private even when it's stored on systems you don't control.
Common mistakes and traps
- Using a weak password. AES-256 is for all practical purposes unbreakable by brute force. But the KDF that generates the key from your password is vulnerable if the password is "12345" or "password". The security of the entire system collapses to the strength of your password. Use a long, random, and unique passphrase.
- Forgetting the password. With password-based encryption, there is no "Forgot your password?" link. The password is the key. If you lose it, the data is gone forever. It's not just locked; the key has been vaporized. Store your passwords securely in a password manager.
- Rolling your own crypto. This is the cardinal sin of software security. You might know what AES, GCM, and PBKDF2 are, but combining them securely is full of pitfalls. Did you use a cryptographically secure random number generator for the salt? Is your authentication tag properly handled? Always use a well-respected, peer-reviewed cryptographic library for your programming language. Don't build the lock yourself; buy one from a master locksmith.
- Reusing a salt or IV. The salt (for the KDF) and the IV/nonce (for the cipher mode) must be random and unique for every single encryption operation with the same key. Reusing them can catastrophically break the security of the cipher. Good libraries handle this for you, but it's a trap to be aware of.
Why it belongs on your radar
If you're a developer, you will handle secrets. It's inevitable. Whether it's a database connection string, an API key, a user's personal information, or just a sensitive log file, you will have data that must not be exposed.
Password-based AES is your go-to tool for ensuring confidentiality at rest. It's the standard, battle-tested solution for:
- Encrypting application secrets in your codebase.
- Securing backups before sending them to cloud storage.
- Protecting sensitive data fields in a database (e.g., encrypting a Social Security Number before storing it).
- Creating a simple, secure way for a user to send you a sensitive file.
It's the fundamental building block for keeping secrets secret in a world where data gets copied, shared, and stored in more places than we can count.
Go deeper
- FIPS PUB 197: The official standard from NIST defining AES (Rijndael). It's dense, but it's the source of truth.
- Wikipedia: Advanced Encryption Standard: A comprehensive and highly readable overview of AES's history, design, and security analysis.
- Wikipedia: PBKDF2: A deep dive into the most common Key Derivation Function used with passwords.
- NIST Special Publication 800-38D: The official specification for the GCM mode of operation.
- Cryptography I (Coursera/Stanford): A free university-level course by Dan Boneh that provides a rock-solid foundation in applied cryptography.