AES Key Strength Analyzer
Paste a hex or base64 AES key to instantly check its length, entropy, and common weaknesses.
Use the AES Key Strength Analyzer
AES Key Input
Quick Examples
Paste an AES key and click Analyze
Supports hex and base64 — 128, 192, or 256-bit keys
Overall Strength
Weakness Checks
Byte Distribution
Each column represents 16 byte values (0x00–0x0F, 0x10–0x1F, …). Uniform height indicates good randomness.
Decoded Key (hex)
Summary
AES Key Strength Analyzer decodes hex or base64 key material and evaluates it against three criteria: correct bit length (128, 192, or 256 bits), sample Shannon entropy normalized for the short key length, and absence of degenerate patterns such as all-zero keys, all-same-byte keys, or sequential byte runs. These checks can detect obvious mistakes but cannot prove that a key came from a cryptographically secure random generator.
How it works
- Paste your AES key as a hex string (e.g. a1b2c3d4...) or base64 string into the input field.
- The tool auto-detects the encoding format and decodes the raw bytes.
- Key length is checked: valid AES sizes are 128-bit (16 bytes), 192-bit (24 bytes), or 256-bit (32 bytes).
- Sample Shannon entropy is normalized against log₂(key bytes), the maximum observable value in a 16–32 byte sample.
- Weakness patterns are tested: all-zero bytes, all-same-byte, sequential ramps, and low unique byte count.
- A combined strength score and pass/fail report is displayed with actionable recommendations.
Use cases
- Validate AES keys generated by your application before deploying to production.
- Audit legacy configuration files for weak or placeholder encryption keys.
- Verify that a key derivation function (KDF) is producing high-entropy output.
- Check manually typed keys for accidental patterns or truncation errors.
- Teach developers how key entropy and bit length affect AES security.
- Quickly confirm a 256-bit key is exactly 32 bytes (64 hex characters).