What Is a Block Cipher & How Does It Work?

Updated on Oct 7, 2026 by Sayb Saad

Block ciphers help protect everything from files on your device to data moving across the internet. They turn readable information into encrypted data that should be useless to anyone who doesn’t have the right key.

The cipher itself works on fixed-size pieces of data and is only one part of that process. A mode of operation tells it how to handle a full message and whether to check for tampering. In this guide, we’ll explain how those pieces fit together, why we use block ciphers, and how they compare with stream ciphers.


Block Cipher Explained

A block cipher encrypts data in fixed-size pieces called blocks. It turns a block of readable data, called plaintext, into an encrypted piece of the same size, called ciphertext.

This process uses a secret value called an encryption key to transform the data into ciphertext and then back into the original data.

Block ciphers work with bits, which are the 0s and 1s computers use to store information. The cipher doesn’t need to know what those bits represent. They could form part of a message, an image, or any other type of data. It accepts a block that fits the required size and transforms it using the secret key.

Block Size vs. Key Size

Block size and key size describe two separate parts of a block cipher. Block size tells you how much plaintext the algorithm can process in one operation. Key size tells you the length of the secret value that controls how it encrypts the plaintext.

Key size determines how difficult it would be to test every possible key until the system finds the correct one. Block size affects how much data some encryption modes can process with one key. Smaller blocks increase the risk of repeated encrypted block values, which can reveal patterns or other information about the data.

A good example is the Advanced Encryption Standard (AES) – a widely used block cipher found in some VPN protocols. AES always processes data in 128-bit blocks with either a 128-bit, 192-bit, or 256-bit key. The number in the AES name (e.g., AES-256) refers to the key size, not the block size.1

How Does a Block Cipher Work?

Diagram showing a plaintext block passing through repeated key-controlled encryption rounds to become a same-size ciphertext block.

Block ciphers use mathematical designs, but the basic process is similar. The cipher takes one block of plaintext and transforms it through several rounds before producing ciphertext.

The cipher also derives a separate key value for each round from the original encryption key, known as a round key.

  1. The cipher loads the plaintext block: The algorithm places the input bits into an internal layout it can process. AES arranges them into a four-by-four grid of bytes known as the cipher’s state.
  1. The algorithm prepares the round keys: It uses the original encryption key to create a distinct key value for each stage of the process. This is known as the key schedule.
  1. The block passes through repeated rounds: Each round changes the current state and combines it with the round key for that stage. The algorithm determines how many rounds to perform.
  1. The cipher produces the ciphertext: After the final round, the cipher outputs the encrypted block. Recovering the plaintext without the correct key should require an impractical amount of computing work.
  1. Decryption restores the plaintext: The receiver uses the same secret key to apply the inverse operations. The correct key restores the original block exactly, while an incorrect key produces unrelated data.

What Happens Inside an Encryption Round?

AES uses several operations to break the visible relationship between the plaintext, the ciphertext, and the secret key:

  • Substitution: Replaces each value according to a defined lookup rule. 
  • Rearrangement: Moves values to new positions.
  • Mixing: Combines them so changes spread across the block. The cipher also combines the current state with the round key for that stage.

Together, these operations make patterns in the original data much harder to trace in the encrypted result. One operation hides the relationship between the encryption key and the ciphertext. Another spreads each small change in the plaintext across many parts of the ciphertext.

Cryptographers call these effects confusion and diffusion. The spreading effect also helps create the avalanche effect, where changing even one input bit can change many bits in the encrypted output. Other block ciphers may use various operations, but they aim for the same broad result: making the ciphertext reveal as little as possible about the original input or key.

Why Do Block Ciphers Need Modes of Operation?

A raw block cipher only defines how to encrypt one fixed-size block, but real data is usually much larger, and a single message may contain thousands or even millions of blocks. A mode of operation provides the rules for processing all of them as one piece of encrypted data.

Overview showing how block cipher modes can provide basic encryption, authenticated encryption, or storage encryption.

The mode determines whether blocks depend on one another or can be processed at the same time. It also controls how the system handles a final piece of data that doesn’t fill a complete block. 

Depending on the mode, encryption may need an extra value that changes how it processes each message. For example, some modes use an initialization vector (IV) or nonce so the cipher doesn’t process every message in exactly the same way.

An IV is a starting value used when encrypting the first block, so the same plaintext doesn’t always produce the same encrypted result. A nonce serves a similar purpose, but its key requirement is that it must be used only once with the same encryption key. Some modes also let the receiver detect whether there was a change in the encrypted data.

This is why AES and AES-GCM aren’t the same thing. AES is the underlying cipher, while GCM defines how AES processes a complete message and checks it for tampering.

Confidentiality-Only Block Cipher Modes

Traditional modes can encrypt data without providing a built-in way to check whether someone changed it. They’re sometimes called confidentiality-only modes because their main job is to hide the contents.

Some modes can only process complete blocks. If the final piece of plaintext is too short, the system can add padding (extra data) to fill the block. The system removes this extra data after decryption.

ModeData ProcessingPartial Final DataParallel ProcessingRequired Input
Electronic Codebook (ECB)Encrypts each plaintext block independentlyUsually adds padding to fill the blockEncryption and decryption can run in parallelNo initialization vector
Cipher Block Chaining (CBC)Combines each plaintext block with the previous ciphertext blockUsually adds padding to fill the blockEncryption runs in sequenceUnpredictable initialization vector
Cipher Feedback (CFB)Encrypts earlier cipher output and combines it with smaller plaintext unitsCan process it without filling the blockUsually runs in sequenceUnpredictable initialization vector
Output Feedback (OFB)Encrypts an internal value to generate a keystreamCan process it without filling the blockKeystream can be prepared in advanceUnique initialization input
Counter (CTR)Encrypts a sequence of counter values to generate a keystreamCan process it without filling the blockEncryption and decryption can run in parallelUnique counter sequence 

None of these modes can verify by themselves that the ciphertext arrived unchanged. An attacker may alter the encrypted data without the receiver immediately knowing. Systems that use these modes therefore need a separate authentication check to detect tampering.2

Authenticated Encryption Modes

Authenticated encryption hides the data and also lets the receiver check whether there  was a change. It produces encrypted data plus a small value called an authentication tag. The receiver checks this tag before accepting the message.

Some authenticated modes can also protect information that needs to remain visible, such as a message header, against unauthorized changes.

  • Galois/Counter Mode (GCM): GCM combines counter-based encryption with an authentication calculation. In AES-GCM, AES provides the block cipher while GCM defines how it encrypts and verifies the complete message. Each encryption with the same key must use a previously unused nonce with that key.
  • Counter with CBC-MAC (CCM): CCM combines counter-based encryption with a separate block-cipher check that authenticates the data. It appears in standards such as Bluetooth and IEEE 802.11.3
  • Synthetic Initialization Vector (SIV) modes: SIV modes calculate an extra value from the message before encrypting it. Their design can limit some of the security problems caused if they accidentally reuse a nonce, although they still need to be implemented correctly.

XTS for Storage Encryption

XTS-AES is a mode designed for encrypting data on storage devices such as hard drives. It takes the data’s location on the drive into account, so identical data stored in alternate places won’t produce identical encrypted results.

XTS also keeps the encrypted data the same size as the original data. This makes it suitable for drive storage, where each piece of data has to fit back into the same amount of space.

The mode protects an unauthorized user from reading the contents, but it doesn’t provide a built-in way to verify that someone hasn’t changed the encrypted data.

What Are Common Block Cipher Algorithms?

Here are some common block ciphers you may already be using.

Advanced Encryption Standard (AES)

The Advanced Encryption Standard is the standardized version of Rijndael, the algorithm selected by the US National Institute of Standards and Technology after an open competition. It has since become the main block cipher used in modern encryption.

AES encryption rounds repeatedly replace, rearrange, and mix values. This structure forms a substitution-permutation network. The three AES variants differ in how many rounds they perform: AES-128 uses 10, AES-192 uses 12, and AES-256 uses 14.1

Many modern CPUs include dedicated instructions for AES. These instructions can speed up AES and reduce the need for software lookup tables, which can lower the risk of some timing and cache-based side-channel attacks.4

AES also has broad support across operating systems and cryptographic libraries. This makes it easier for developers to use established implementations instead of building one from scratch.

Other Block Cipher Algorithms

Several other block ciphers remain important for historical context, though they don’t all meet current security needs. Here are some of them:

AlgorithmBlock SizeKey Size
Data Encryption Standard (DES)64 bits56 effective bits
Triple DES (3DES)64 bitsMultiple-key variants
Blowfish64 bitsUp to 448 bits
Twofish128 bitsUp to 256 bits
Camellia128 bits128, 192, or 256 bits

Blowfish, Twofish, and Camellia are separate block cipher algorithms unrelated to AES. Note that DES and Triple DES are older designs that are no longer suitable for many modern uses.

Where Are Block Ciphers Used?

Block ciphers can protect data while it travels across the internet and while it’s stored on a device. They can also protect encryption keys or help check whether someone altered a message.

Where block cipher protection applies to data in transit, data at rest, cryptographic keys, and message integrity, and where that protection ends.

Protecting Data in Transit

Block ciphers can protect data as it travels over the internet, helping to prevent third parties eavesdropping on the connection and reading the sent information.

When you visit an HTTPS website, your browser uses Transport Layer Security (TLS) to protect the connection to the website. TLS can use block cipher modes like AES-GCM or AES-CCM to both encrypt the traffic and detect changes to protected data.5 

Protecting Data at Rest

File encryption can protect individual files or groups of files stored together in encrypted form. The file format can store the extra information needed to decrypt the data and confirm that it remains unchanged.

Full-disk encryption protects the entire drive instead of selected files. It protects the contents of a drive while the device remains locked or switched off. Disk-encryption systems may use XTS-AES because it can encrypt fixed-size storage sectors without changing their length.

These methods don’t replace access controls. Software that has permission to decrypt the data might still read it while the system is running.

Protecting Keys and Verifying Messages

Block ciphers can protect cryptographic keys, which are the secret values used by encryption systems. AES Key Wrap keeps these keys confidential and detects changes while they’re stored or transferred.

A Cipher-based Message Authentication Code (CMAC) uses a block cipher to create a value that lets the receiver check whether there was a change to a message and whether the shared key generated the tag.

CMAC itself doesn’t encrypt the message. Its purpose is to help verify its integrity and authenticity.

Block Cipher vs. Stream Cipher

A block cipher breaks data into fixed-size pieces for encryption, while a stream cipher processes data in a continuous stream. The difference lies in how each cipher handles the input, rather than whether it protects stored data or network traffic.

What Is a Stream Cipher?

A stream cipher encrypts data using a generated sequence of values called a keystream. The sequence looks random, but the cipher can reproduce it from the correct encryption key and nonce.

The cipher combines this keystream with the plaintext using a reversible bit-by-bit operation called exclusive OR (XOR). During decryption, the receiver generates the same keystream and applies XOR again, which restores the original plaintext.

In modern nonce-based stream ciphers such as ChaCha20, a unique nonce makes the cipher generate a unique keystream for each message using the same key.

Side-by-side diagram showing a block cipher dividing data into fixed-size blocks while a stream cipher combines continuous data with a generated keystream.

Block Cipher vs. Stream Cipher: Key Differences

The table below shows how these designs affect message handling and implementation.

Message HandlingBlock CipherStream Cipher
Full-message encryptionNeeds a mode of operation to process data beyond one blockProcesses the message through its built-in keystream design
Incomplete final dataSome modes need padding while others don’tDoesn’t require block padding
Extra inputThe mode may call for an initialization vector, nonce, or counterMany modern designs demand a unique nonce for each message
Parallel processingDepends on the mode; CTR and GCM can process blocks in parallelDepends on the cipher’s design
AuthenticationMust come from an authenticated mode or a separate mechanismNeeds an authenticated design, such as ChaCha20-Poly1305

Neither type has a universal performance advantage. AES can run efficiently on CPUs with built-in AES instructions. ChaCha20 performs well in software, even on devices that don’t have those instructions.6

Common Block Cipher Security Risks

Block cipher security depends on more than the algorithm itself. Problems with the mode, key handling, or software implementation can weaken the wider encryption system.

  • Unsafe modes can reveal patterns: ECB mode produces the same ciphertext whenever identical plaintext blocks appear under one key. This can expose repeated shapes or structures even when the attacker can’t read the data.
  • Missing authentication can allow tampering: Some encryption modes don’t detect when a person or system has changed the encrypted data. An attacker could therefore modify the ciphertext in ways that affect the decrypted result.
  • Padding errors: can expose information: If a system reveals whether altered encrypted data contains valid padding, attackers may use those responses to glean information about the protected data. This is known as a padding-oracle attack.7
  • Nonce or initialization vector mistakes can break security: These values must follow the exact rules of the selected mode. Reusing a nonce with the same GCM key can expose relationships between plaintexts and undermine the authentication and integrity protection provided by that key.2
  • Small blocks create data limits: With 64-bit block ciphers, repeated encrypted block values become likely much sooner than with 128-bit blocks. Increasing the key length doesn’t remove this block-size limit.
  • Key or software failures can defeat the cipher: A stolen encryption key may let an attacker decrypt data protected with it. Weakly generated keys can also make attacks easier. Software can undermine the cipher if it fails to check authentication tags or leaks information about encryption through its behavior.

Can Quantum Computers Break Block Ciphers?

Quantum computers affect block ciphers like AES in different ways from public-key encryption systems such as RSA and elliptic-curve cryptography. Public-key systems use separate public and private keys, whereas AES uses one shared encryption key.

A quantum method called Shor’s algorithm threatens the mathematical problems used by RSA and elliptic-curve cryptography, but it doesn’t break AES.

Grover’s algorithm is the main known theoretical quantum approach for speeding up a brute-force search for an AES key. In theory, it could reduce the amount of work needed, although practical quantum hardware would face major limitations.

According to the National Institute of Standards and Technology (NIST), current applications can continue using AES-128, AES-192, or AES-256.8

AES-256 would still need much more work to brute-force than AES-128 under this type of quantum attack. So, it’s pretty safe to say that AES-256 provides a larger security buffer against advances in quantum computing than to describe any cipher as quantum-proof.

FAQ

What is a block cipher?

A block cipher is an encryption algorithm that turns fixed-size plaintext blocks into ciphertext blocks of the same size. It uses the same secret key for both encryption and decryption.

How does a block cipher work?

A block cipher works by passing one plaintext block through several key-controlled transformations to produce ciphertext. For longer data, a mode of operation defines how the cipher processes each block as part of the complete message.

What is the difference between a block cipher and a stream cipher?

A block cipher transforms fixed-size blocks, while a stream cipher generates a keystream that combines with the plaintext. Neither type is faster or more secure, as this depends on the full construction and its implementation.

What are common examples of block ciphers?

AES is the most common block cipher used in modern encryption. Other examples include DES, Triple DES, Blowfish, Twofish, and Camellia, though several of these are now only relevant in legacy systems.

When should you use a block cipher instead of a stream cipher?

Use a block-cipher construction when the relevant protocol, storage format, or security standard specifies one. For example, XTS-AES is for storage devices, while AES-GCM supports protocols such as Transport Layer Security (TLS).

How are block ciphers used in modern encryption protocols?

Modern protocols use block ciphers with modes that handle complete messages and may also add authentication. Transport Layer Security (TLS) and Internet Protocol Security (IPsec) can use AES-GCM, which encrypts the data and produces a tag that lets the receiver detect changes.

Resources:

  1. FIPS 197, Advanced Encryption Standard (AES) – CSRC 
  2. SP 800-38A, Recommendation for Block Cipher Modes of Operation: Methods and Techniques – CSRC 
  3. NIST SP 800-38C, Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality – NIST
  4. SP 800-38E, Recommendation for Block Cipher Modes of Operation: the XTS-AES Mode for Confidentiality on Storage Devices – CSRC 
  5. Intel® Advanced Encryption Standard Instructions (AES-NI) – Intel 
  6. SP 800-38B, Recommendation for Block Cipher Modes of Operation: the CMAC Mode for Authentication – CSRC 
  7. Timing vulnerabilities with CBC-mode symmetric decryption using padding – Microsoft 
  8. Post-Quantum Cryptography – CSRC