What Is a Block Cipher & How Does It Work?
Block ciphers help protect everything from files on your device to data moving across the internet. They turn readable information into encrypted data that should be useless to anyone who doesn’t have the right key.
The cipher itself works on fixed-size pieces of data and is only one part of that process. A mode of operation tells it how to handle a full message and whether to check for tampering. In this guide, we’ll explain how those pieces fit together, why we use block ciphers, and how they compare with stream ciphers.
Block Cipher Explained
A block cipher encrypts data in fixed-size pieces called blocks. It turns a block of readable data, called plaintext, into an encrypted piece of the same size, called ciphertext.
This process uses a secret value called an encryption key to transform the data into ciphertext and then back into the original data.
Block ciphers work with bits, which are the 0s and 1s computers use to store information. The cipher doesn’t need to know what those bits represent. They could form part of a message, an image, or any other type of data. It accepts a block that fits the required size and transforms it using the secret key.
Block Size vs. Key Size
Block size and key size describe two separate parts of a block cipher. Block size tells you how much plaintext the algorithm can process in one operation. Key size tells you the length of the secret value that controls how it encrypts the plaintext.
Key size determines how difficult it would be to test every possible key until the system finds the correct one. Block size affects how much data some encryption modes can process with one key. Smaller blocks increase the risk of repeated encrypted block values, which can reveal patterns or other information about the data.
A good example is the Advanced Encryption Standard (AES) – a widely used block cipher found in some VPN protocols. AES always processes data in 128-bit blocks with either a 128-bit, 192-bit, or 256-bit key. The number in the AES name (e.g., AES-256) refers to the key size, not the block size.1
How Does a Block Cipher Work?

Block ciphers use mathematical designs, but the basic process is similar. The cipher takes one block of plaintext and transforms it through several rounds before producing ciphertext.
The cipher also derives a separate key value for each round from the original encryption key, known as a round key.
- The cipher loads the plaintext block: The algorithm places the input bits into an internal layout it can process. AES arranges them into a four-by-four grid of bytes known as the cipher’s state.
- The algorithm prepares the round keys: It uses the original encryption key to create a distinct key value for each stage of the process. This is known as the key schedule.
- The block passes through repeated rounds: Each round changes the current state and combines it with the round key for that stage. The algorithm determines how many rounds to perform.
- The cipher produces the ciphertext: After the final round, the cipher outputs the encrypted block. Recovering the plaintext without the correct key should require an impractical amount of computing work.
- Decryption restores the plaintext: The receiver uses the same secret key to apply the inverse operations. The correct key restores the original block exactly, while an incorrect key produces unrelated data.
What Happens Inside an Encryption Round?
AES uses several operations to break the visible relationship between the plaintext, the ciphertext, and the secret key:
- Substitution: Replaces each value according to a defined lookup rule.
- Rearrangement: Moves values to new positions.
- Mixing: Combines them so changes spread across the block. The cipher also combines the current state with the round key for that stage.
Together, these operations make patterns in the original data much harder to trace in the encrypted result. One operation hides the relationship between the encryption key and the ciphertext. Another spreads each small change in the plaintext across many parts of the ciphertext.
Cryptographers call these effects confusion and diffusion. The spreading effect also helps create the avalanche effect, where changing even one input bit can change many bits in the encrypted output. Other block ciphers may use various operations, but they aim for the same broad result: making the ciphertext reveal as little as possible about the original input or key.
Why Do Block Ciphers Need Modes of Operation?
A raw block cipher only defines how to encrypt one fixed-size block, but real data is usually much larger, and a single message may contain thousands or even millions of blocks. A mode of operation provides the rules for processing all of them as one piece of encrypted data.

The mode determines whether blocks depend on one another or can be processed at the same time. It also controls how the system handles a final piece of data that doesn’t fill a complete block.
Depending on the mode, encryption may need an extra value that changes how it processes each message. For example, some modes use an initialization vector (IV) or nonce so the cipher doesn’t process every message in exactly the same way.
An IV is a starting value used when encrypting the first block, so the same plaintext doesn’t always produce the same encrypted result. A nonce serves a similar purpose, but its key requirement is that it must be used only once with the same encryption key. Some modes also let the receiver detect whether there was a change in the encrypted data.
This is why AES and AES-GCM aren’t the same thing. AES is the underlying cipher, while GCM defines how AES processes a complete message and checks it for tampering.
Confidentiality-Only Block Cipher Modes
Traditional modes can encrypt data without providing a built-in way to check whether someone changed it. They’re sometimes called confidentiality-only modes because their main job is to hide the contents.
Some modes can only process complete blocks. If the final piece of plaintext is too short, the system can add padding (extra data) to fill the block. The system removes this extra data after decryption.
| Mode | Data Processing | Partial Final Data | Parallel Processing | Required Input |
| Electronic Codebook (ECB) | Encrypts each plaintext block independently | Usually adds padding to fill the block | Encryption and decryption can run in parallel | No initialization vector |
| Cipher Block Chaining (CBC) | Combines each plaintext block with the previous ciphertext block | Usually adds padding to fill the block | Encryption runs in sequence | Unpredictable initialization vector |
| Cipher Feedback (CFB) | Encrypts earlier cipher output and combines it with smaller plaintext units | Can process it without filling the block | Usually runs in sequence | Unpredictable initialization vector |
| Output Feedback (OFB) | Encrypts an internal value to generate a keystream | Can process it without filling the block | Keystream can be prepared in advance | Unique initialization input |
| Counter (CTR) | Encrypts a sequence of counter values to generate a keystream | Can process it without filling the block | Encryption and decryption can run in parallel | Unique counter sequence |
None of these modes can verify by themselves that the ciphertext arrived unchanged. An attacker may alter the encrypted data without the receiver immediately knowing. Systems that use these modes therefore need a separate authentication check to detect tampering.2
Authenticated Encryption Modes
Authenticated encryption hides the data and also lets the receiver check whether there was a change. It produces encrypted data plus a small value called an authentication tag. The receiver checks this tag before accepting the message.
Some authenticated modes can also protect information that needs to remain visible, such as a message header, against unauthorized changes.
- Galois/Counter Mode (GCM): GCM combines counter-based encryption with an authentication calculation. In AES-GCM, AES provides the block cipher while GCM defines how it encrypts and verifies the complete message. Each encryption with the same key must use a previously unused nonce with that key.
- Counter with CBC-MAC (CCM): CCM combines counter-based encryption with a separate block-cipher check that authenticates the data. It appears in standards such as Bluetooth and IEEE 802.11.3
- Synthetic Initialization Vector (SIV) modes: SIV modes calculate an extra value from the message before encrypting it. Their design can limit some of the security problems caused if they accidentally reuse a nonce, although they still need to be implemented correctly.
XTS for Storage Encryption
XTS-AES is a mode designed for encrypting data on storage devices such as hard drives. It takes the data’s location on the drive into account, so identical data stored in alternate places won’t produce identical encrypted results.
XTS also keeps the encrypted data the same size as the original data. This makes it suitable for drive storage, where each piece of data has to fit back into the same amount of space.
The mode protects an unauthorized user from reading the contents, but it doesn’t provide a built-in way to verify that someone hasn’t changed the encrypted data.
What Are Common Block Cipher Algorithms?
Here are some common block ciphers you may already be using.
Advanced Encryption Standard (AES)
The Advanced Encryption Standard is the standardized version of Rijndael, the algorithm selected by the US National Institute of Standards and Technology after an open competition. It has since become the main block cipher used in modern encryption.
AES encryption rounds repeatedly replace, rearrange, and mix values. This structure forms a substitution-permutation network. The three AES variants differ in how many rounds they perform: AES-128 uses 10, AES-192 uses 12, and AES-256 uses 14.1
Many modern CPUs include dedicated instructions for AES. These instructions can speed up AES and reduce the need for software lookup tables, which can lower the risk of some timing and cache-based side-channel attacks.4
AES also has broad support across operating systems and cryptographic libraries. This makes it easier for developers to use established implementations instead of building one from scratch.
Other Block Cipher Algorithms
Several other block ciphers remain important for historical context, though they don’t all meet current security needs. Here are some of them:
| Algorithm | Block Size | Key Size |
| Data Encryption Standard (DES) | 64 bits | 56 effective bits |
| Triple DES (3DES) | 64 bits | Multiple-key variants |
| Blowfish | 64 bits | Up to 448 bits |
| Twofish | 128 bits | Up to 256 bits |
| Camellia | 128 bits | 128, 192, or 256 bits |
Blowfish, Twofish, and Camellia are separate block cipher algorithms unrelated to AES. Note that DES and Triple DES are older designs that are no longer suitable for many modern uses.
Where Are Block Ciphers Used?
Block ciphers can protect data while it travels across the internet and while it’s stored on a device. They can also protect encryption keys or help check whether someone altered a message.

Protecting Data in Transit
Block ciphers can protect data as it travels over the internet, helping to prevent third parties eavesdropping on the connection and reading the sent information.
When you visit an HTTPS website, your browser uses Transport Layer Security (TLS) to protect the connection to the website. TLS can use block cipher modes like AES-GCM or AES-CCM to both encrypt the traffic and detect changes to protected data.5
Protecting Data at Rest
File encryption can protect individual files or groups of files stored together in encrypted form. The file format can store the extra information needed to decrypt the data and confirm that it remains unchanged.
Full-disk encryption protects the entire drive instead of selected files. It protects the contents of a drive while the device remains locked or switched off. Disk-encryption systems may use XTS-AES because it can encrypt fixed-size storage sectors without changing their length.
These methods don’t replace access controls. Software that has permission to decrypt the data might still read it while the system is running.
Protecting Keys and Verifying Messages
Block ciphers can protect cryptographic keys, which are the secret values used by encryption systems. AES Key Wrap keeps these keys confidential and detects changes while they’re stored or transferred.
A Cipher-based Message Authentication Code (CMAC) uses a block cipher to create a value that lets the receiver check whether there was a change to a message and whether the shared key generated the tag.
CMAC itself doesn’t encrypt the message. Its purpose is to help verify its integrity and authenticity.
Block Cipher vs. Stream Cipher
A block cipher breaks data into fixed-size pieces for encryption, while a stream cipher processes data in a continuous stream. The difference lies in how each cipher handles the input, rather than whether it protects stored data or network traffic.
What Is a Stream Cipher?
A stream cipher encrypts data using a generated sequence of values called a keystream. The sequence looks random, but the cipher can reproduce it from the correct encryption key and nonce.
The cipher combines this keystream with the plaintext using a reversible bit-by-bit operation called exclusive OR (XOR). During decryption, the receiver generates the same keystream and applies XOR again, which restores the original plaintext.
In modern nonce-based stream ciphers such as ChaCha20, a unique nonce makes the cipher generate a unique keystream for each message using the same key.

Block Cipher vs. Stream Cipher: Key Differences
The table below shows how these designs affect message handling and implementation.
| Message Handling | Block Cipher | Stream Cipher |
| Full-message encryption | Needs a mode of operation to process data beyond one block | Processes the message through its built-in keystream design |
| Incomplete final data | Some modes need padding while others don’t | Doesn’t require block padding |
| Extra input | The mode may call for an initialization vector, nonce, or counter | Many modern designs demand a unique nonce for each message |
| Parallel processing | Depends on the mode; CTR and GCM can process blocks in parallel | Depends on the cipher’s design |
| Authentication | Must come from an authenticated mode or a separate mechanism | Needs an authenticated design, such as ChaCha20-Poly1305 |
Neither type has a universal performance advantage. AES can run efficiently on CPUs with built-in AES instructions. ChaCha20 performs well in software, even on devices that don’t have those instructions.6
Common Block Cipher Security Risks
Block cipher security depends on more than the algorithm itself. Problems with the mode, key handling, or software implementation can weaken the wider encryption system.
- Unsafe modes can reveal patterns: ECB mode produces the same ciphertext whenever identical plaintext blocks appear under one key. This can expose repeated shapes or structures even when the attacker can’t read the data.
- Missing authentication can allow tampering: Some encryption modes don’t detect when a person or system has changed the encrypted data. An attacker could therefore modify the ciphertext in ways that affect the decrypted result.
- Padding errors: can expose information: If a system reveals whether altered encrypted data contains valid padding, attackers may use those responses to glean information about the protected data. This is known as a padding-oracle attack.7
- Nonce or initialization vector mistakes can break security: These values must follow the exact rules of the selected mode. Reusing a nonce with the same GCM key can expose relationships between plaintexts and undermine the authentication and integrity protection provided by that key.2
- Small blocks create data limits: With 64-bit block ciphers, repeated encrypted block values become likely much sooner than with 128-bit blocks. Increasing the key length doesn’t remove this block-size limit.
- Key or software failures can defeat the cipher: A stolen encryption key may let an attacker decrypt data protected with it. Weakly generated keys can also make attacks easier. Software can undermine the cipher if it fails to check authentication tags or leaks information about encryption through its behavior.
Can Quantum Computers Break Block Ciphers?
Quantum computers affect block ciphers like AES in different ways from public-key encryption systems such as RSA and elliptic-curve cryptography. Public-key systems use separate public and private keys, whereas AES uses one shared encryption key.
A quantum method called Shor’s algorithm threatens the mathematical problems used by RSA and elliptic-curve cryptography, but it doesn’t break AES.
Grover’s algorithm is the main known theoretical quantum approach for speeding up a brute-force search for an AES key. In theory, it could reduce the amount of work needed, although practical quantum hardware would face major limitations.
According to the National Institute of Standards and Technology (NIST), current applications can continue using AES-128, AES-192, or AES-256.8
AES-256 would still need much more work to brute-force than AES-128 under this type of quantum attack. So, it’s pretty safe to say that AES-256 provides a larger security buffer against advances in quantum computing than to describe any cipher as quantum-proof.
FAQ
What is a block cipher?
A block cipher is an encryption algorithm that turns fixed-size plaintext blocks into ciphertext blocks of the same size. It uses the same secret key for both encryption and decryption.
How does a block cipher work?
A block cipher works by passing one plaintext block through several key-controlled transformations to produce ciphertext. For longer data, a mode of operation defines how the cipher processes each block as part of the complete message.
What is the difference between a block cipher and a stream cipher?
A block cipher transforms fixed-size blocks, while a stream cipher generates a keystream that combines with the plaintext. Neither type is faster or more secure, as this depends on the full construction and its implementation.
What are common examples of block ciphers?
AES is the most common block cipher used in modern encryption. Other examples include DES, Triple DES, Blowfish, Twofish, and Camellia, though several of these are now only relevant in legacy systems.
When should you use a block cipher instead of a stream cipher?
Use a block-cipher construction when the relevant protocol, storage format, or security standard specifies one. For example, XTS-AES is for storage devices, while AES-GCM supports protocols such as Transport Layer Security (TLS).
How are block ciphers used in modern encryption protocols?
Modern protocols use block ciphers with modes that handle complete messages and may also add authentication. Transport Layer Security (TLS) and Internet Protocol Security (IPsec) can use AES-GCM, which encrypts the data and produces a tag that lets the receiver detect changes.
Resources:
- FIPS 197, Advanced Encryption Standard (AES) – CSRC
- SP 800-38A, Recommendation for Block Cipher Modes of Operation: Methods and Techniques – CSRC
- NIST SP 800-38C, Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality – NIST
- SP 800-38E, Recommendation for Block Cipher Modes of Operation: the XTS-AES Mode for Confidentiality on Storage Devices – CSRC
- Intel® Advanced Encryption Standard Instructions (AES-NI) – Intel
- SP 800-38B, Recommendation for Block Cipher Modes of Operation: the CMAC Mode for Authentication – CSRC
- Timing vulnerabilities with CBC-mode symmetric decryption using padding – Microsoft
- Post-Quantum Cryptography – CSRC