Is AES-256 Quantum Safe?
Correctly used AES-256 resists known quantum attacks. Learn why its secret key and the way that key is exchanged still matter.
Free video lesson · 1:31
Is AES-256 Quantum Safe?
Quantum Computing & Encryption for Beginners
Music: “Thinking Music” by Kevin MacLeod. Creative Commons Attribution 4.0.
Known quantum attacks do not make correctly used AES-256 practical to break.
Read the video transcript
AES-256 is considered resistant to known quantum attacks when it is used correctly. It is a method of encrypting data: scrambling it with a secret key so someone without that key cannot read it.
The 256 describes the key size. A bit is a zero-or-one value, and this key contains 256 bits. Together they allow an enormous number of possible keys. An attacker cannot simply try a few and expect to find it.
A known quantum search method can reduce the work needed to guess a key. But reducing an enormous search does not automatically make it practical. For AES-256, the remaining work is still far beyond known practical attacks.
There is a separate catch. If someone steals the key, they do not need to defeat AES. The way a system stores or shares that key matters too. A strong method cannot fix every weakness around it.
So AES-256 can remain a strong part of a system facing quantum threats. That does not make the whole system quantum-safe. You also need to check the other methods that protect and exchange its keys.
Which methods face a different risk? Watch Can Quantum Computers Break Encryption? For a way to establish keys, watch What Is Hybrid Key Exchange?
The short answer
AES-256 is considered resistant to known quantum attacks when it is used correctly. It is a method of encrypting data: scrambling it with a secret key so someone without that key cannot read it.
A simple example
The 256 describes the key size. A bit is a zero-or-one value, and this key contains 256 bits. Together they allow an enormous number of possible keys. An attacker cannot simply try a few and expect to find it.
A known quantum search method can reduce the work needed to guess a key. But reducing an enormous search does not automatically make it practical. For AES-256, the remaining work is still far beyond known practical attacks.
There is a separate catch. If someone steals the key, they do not need to defeat AES. The way a system stores or shares that key matters too. A strong method cannot fix every weakness around it.
So AES-256 can remain a strong part of a system facing quantum threats. That does not make the whole system quantum-safe. You also need to check the other methods that protect and exchange its keys.
Check the whole system
AES-256 protects data with a shared secret key. The software may use a different method to agree on that key. Check both parts: protecting the data and establishing the key are separate jobs. A strong cipher also needs safe software and careful key handling.
Check your understanding
Does using AES-256 tell you how the app agreed on its secret key?
Answer
No. You must check the key-exchange method separately.
Keep learning
Follow the free video course one question at a time. For help applying these ideas at work, explore team training or a cryptography audit.