aes-gcm
Pure Rust AES-GCM authenticated encryption with optional hardware acceleration
Repository Health
Technical Analysis
aes-gcm is a pure-Rust implementation of AES-GCM (Galois/Counter Mode), an Authenticated Encryption with Associated Data (AEAD) cipher widely used for TLS, disk encryption, and secure messaging protocols. It is one of the flagship crates in the RustCrypto AEADs workspace, which also hosts related ciphers such as ChaCha20Poly1305, AES-SIV, and CCM behind a shared aead trait interface.
The crate implements the encryption/decryption traits defined by the aead crate, supports no_std environments for embedded use, and can take advantage of architecture-specific hardware acceleration (AES-NI on x86/x86_64, ARMv8 crypto extensions) via the underlying aes crate, falling back to a constant-time software implementation otherwise. It is downloaded well over 100 million times, making it one of the most widely used cryptography primitives in the Rust ecosystem.
What You Get
- A pure-Rust AES-GCM implementation conforming to the shared
aeadcrate’sAead/AeadInPlacetraits - Optional hardware acceleration (AES-NI, ARMv8 crypto extensions) via the underlying
aescrate, with constant-time software fallback no_stdsupport for embedded and constrained environments- Optional
zeroizeintegration for securely clearing key material from memory - Interoperability with sibling AEAD crates (ChaCha20Poly1305, AES-SIV, CCM, EAX) through a consistent API
- Dual Apache-2.0/MIT licensing for flexible integration into both open-source and commercial projects
Common Use Cases
- Encrypting data at rest (files, database fields) with authenticated encryption to detect tampering
- Implementing custom secure transport or messaging protocols that need AEAD guarantees
- Embedded and IoT applications requiring
no_stdcryptography with hardware-accelerated performance - Building higher-level cryptographic libraries or key-management systems on top of a vetted AEAD primitive
Under The Hood
Architecture - aes-gcm is one crate within the RustCrypto AEADs Cargo workspace, which groups a dozen related AEAD cipher implementations (aes-gcm, aes-gcm-siv, aes-siv, chacha20poly1305, ccm, eax, mgm, deoxys, ascon) under a shared workspace and a common aead trait crate maintained separately. The aes-gcm crate itself is compact (~390 lines in lib.rs), implementing the GCM authenticated-encryption mode over a generic block cipher parameter, with counter-mode encryption (via the ctr crate) combined with GHASH-based authentication (via the ghash crate). Tech Stack - Pure Rust with no_std support by default; optional dependencies gate in the aes crate for hardware-accelerated (AES-NI/ARMv8) or portable software implementations, and zeroize for secure memory clearing; edition 2024, MSRV 1.85. Code Quality - The core crate has no inline unit tests in src/, relying instead on the workspace’s tests/ directory (e.g. aes128gcm.rs, aes256gcm.rs, other_ivlen.rs) which exercises official NIST/RFC test vectors — a common and appropriate pattern for cryptography crates where correctness is verified against published test vectors rather than ad hoc unit tests; the crate is maintained by the RustCrypto organization with heavy scrutiny given its security-critical nature. API Design - The API surface is deliberately minimal and consistent with sibling AEAD crates via the shared aead trait, so switching between AES-GCM, ChaCha20Poly1305, or AES-SIV requires little code change; documentation links to docs.rs and the crate emphasizes correct nonce handling, a common pitfall for AEAD ciphers.
Used by 23 apps in this directory
Stalwart
Collaboration
All-in-one secure mail and collaboration server covering IMAP, JMAP, SMTP, CalDAV, CardDAV, and WebDAV in a single memory-safe Rust binary.
Svix
Automation · Developer Tools
Open source, self-hostable webhook infrastructure that handles delivery, retries, HMAC signing, and multi-tenant event management so you never have to build a webhooks system from scratch.
tabularis
Databases · Developer Tools
Open-source desktop SQL workspace with built-in PostgreSQL, MySQL, and SQLite drivers, SQL notebooks, a visual query builder, and a built-in MCP server for AI agents like Claude and Cursor.
Temps
Analytics · Devops · Monitoring
A self-hosted Rust PaaS that replaces Vercel, Sentry, PostHog, Pingdom, Resend, and E2B with one binary — plus 440+ CLI operations agents like Claude Code can drive directly.
Vibe Kanban
AI Agents · AI Code Assistants · Project Management
A kanban board for planning work and dispatching Claude Code, Codex, Gemini CLI, and eight other coding agents into isolated git worktrees, then reviewing and merging their diffs from one UI.