AES-GCM (AES in Galois/Counter Mode)

Also known as: AES Galois Counter Mode

AES-GCM (NIST SP 800-38D) is an authenticated encryption with associated data (AEAD) mode combining AES-CTR with a GHASH authenticator. It is the mandatory-to-implement AEAD in TLS 1.3, IKEv2/IPsec ESP, SRTP for VoLTE/VoNR media, and MACsec, offering high performance on modern CPUs when nonce uniqueness is preserved.

Categories: Security ControlsProtocols and StandardsOperations and Business

AES-GCM in context

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

Telecom security is written into standards from 3GPP, GSMA, ETSI, IETF and ITU-T. Understanding which body owns which specification, and how they interlock, is essential for both design and audit work.

To place AES-GCM in the wider telecom-security picture, review VPN, 3G, 3GPP, 6G, AES and A5/1 — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.