GCM
Galois/Counter Mode provides authenticated encryption by combining CTR mode encryption with GHASH authentication using GF(2^128) arithmetic. Widely used in TLS, IPsec, and other security protocols. Provides both confidentiality and authenticity but catastrophically fails if nonces are reused.
Properties
| Property |
Value |
| Category |
Cipher Modes |
| Sub-category |
Authenticated Encryption |
| Security status |
π‘οΈ Secure |
| Complexity |
Advanced |
| Inventor |
David A. McGrew, John Viega |
| Year |
2005 |
| Origin |
πΊπΈ United States |
| Source |
algorithms/modes/gcm.js |
Parameters
| Parameter |
Supported values |
| Tag sizes |
4 bytes (32 bits) to 16 bytes (128 bits) |
Capabilities
| Flag |
Value |
SupportsDetached |
Yes |
Security
Status: π‘οΈ Secure
Known vulnerabilities
| Issue |
Description |
Mitigation |
| Nonce Reuse Attack |
Reusing nonce with same key completely breaks confidentiality and authenticity. Authentication key can be recovered. Always use unique nonces. |
β |
| Forbidden Attack |
With very long messages (near 2^39 bits), confidentiality degrades. Limit message lengths in practice. |
β |
| Authentication Forgery |
With nonce reuse, arbitrary messages can be forged after key recovery. |
β |
Documentation
References
Test vectors
5 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β GCM Test Case 2 - AES-128, one zero block, no AAD
| Field |
Value |
cipher |
AES |
key |
00000000000000000000000000000000 |
iv |
000000000000000000000000 |
aad |
(empty) |
input |
00000000000000000000000000000000 |
expected |
0388dace60b6a392f328c2b971b2fe78ab6e47d42cec13bdf53a67b21257bddf |
Vector 2 β GCM Test Case 3 - AES-128, 64-byte plaintext, no AAD
| Field |
Value |
cipher |
AES |
key |
feffe9928665731c6d6a8f9467308308 |
iv |
cafebabefacedbaddecaf888 |
aad |
(empty) |
input |
d9313225f88406e5a55909c5aff5269a 86a7a9531534f7da2e4c303d8a318a72 1c3c0c95956809532fcf0e2449a6b525 b16aedf5aa0de657ba637b391aafd255 |
expected |
42831ec2217774244b7221b784d0d49c e3aa212f2c02a4e035c17e2329aca12e 21d514b25466931c7d8f6a5aac84aa05 1ba30b396a0aac973d58e091473f5985 4d5c2af327cd64a62cf35abd2ba6fab4 |
Vector 3 β GCM Test Case 4 - AES-128, 60-byte plaintext with AAD
| Field |
Value |
cipher |
AES |
key |
feffe9928665731c6d6a8f9467308308 |
iv |
cafebabefacedbaddecaf888 |
aad |
feedfacedeadbeeffeedfacedeadbeefabaddad2 |
input |
d9313225f88406e5a55909c5aff5269a 86a7a9531534f7da2e4c303d8a318a72 1c3c0c95956809532fcf0e2449a6b525 b16aedf5aa0de657ba637b39 |
expected |
42831ec2217774244b7221b784d0d49c e3aa212f2c02a4e035c17e2329aca12e 21d514b25466931c7d8f6a5aac84aa05 1ba30b396a0aac973d58e0915bc94fbc 3221a5db94fae95ae7121a47 |
Vector 4 β GCM Test Case 14 - AES-192, 64-byte plaintext, no AAD
| Field |
Value |
cipher |
AES |
key |
feffe9928665731c6d6a8f9467308308feffe9928665731c |
iv |
cafebabefacedbaddecaf888 |
aad |
(empty) |
input |
d9313225f88406e5a55909c5aff5269a 86a7a9531534f7da2e4c303d8a318a72 1c3c0c95956809532fcf0e2449a6b525 b16aedf5aa0de657ba637b391aafd255 |
expected |
3980ca0b3c00e841eb06fac4872a2757 859e1ceaa6efd984628593b40ca1e19c 7d773d00c144c525ac619d18c84a3f47 18e2448b2fe324d9ccda2710acade256 9924a7c8587336bfb118024db8674a14 |
Vector 5 β GCM Test Case 16 - AES-256, 60-byte plaintext with AAD
| Field |
Value |
cipher |
AES |
key |
feffe9928665731c6d6a8f9467308308feffe9928665731c6d6a8f9467308308 |
iv |
cafebabefacedbaddecaf888 |
aad |
feedfacedeadbeeffeedfacedeadbeefabaddad2 |
input |
d9313225f88406e5a55909c5aff5269a 86a7a9531534f7da2e4c303d8a318a72 1c3c0c95956809532fcf0e2449a6b525 b16aedf5aa0de657ba637b39 |
expected |
522dc1f099567d07f47f37a32a84427d 643a8cdcbfe5c0c97598a2bd2555d1aa 8cb08e48590dbb3da7b08b1056828838 c5f61e6393ba7a0abcc9f66276fc6ece 0f4e1768cddf8853bb2d551b |
β All algorithms