Get 30 days free when you sign up now.

Strong VPN encryption and security explained

VPN encryption is hard, and it generally relies on well-tested implementation of advanced mathematics. Read on to learn a little bit about how ExpressVPN uses strong encryption to protect your data and communications.

VPN encryption

Video: How VPNs use tunneling and encryption

How VPNs use tunneling and encryption

How secure is ExpressVPN encryption?

Besides hiding your IP address and mixing your traffic with that of other users, ExpressVPN also encrypts your traffic between secure VPN servers and your computer, so that it can’t be read by third parties in between, such as your internet service provider or your local Wi-Fi operator.

ExpressVPN uses AES (Advanced Encryption Standard) with 256-bit keys—also known as AES-256. It’s the same encryption standard adopted by the U.S. government and used by security experts worldwide to protect classified information.

Encrypt your connection with a VPN.

256-bit keys means 2^256 or 1.1 x 10^77 possible combinations. That’s 115,​792,​089,​237,​316,​195,​423,​570,​985,​008,​687,​907,​853,​269,​984,​665,​640,​560,​000,​000,​000,​000,​000,​000,​000,​000 combinations! A brute-force attack on a 256-bit keyspace is simply infeasible, even if all the world’s most powerful supercomputers ran for as long as the universe has existed so far, billions and billions of times over.

VPN protocols: OpenVPN (TCP and UDP)

ExpressVPN offers a variety of VPN protocols to implement strong encryption between your computer and the VPN server location you connect to. When you use the ExpressVPN app, you can easily switch between the protocols, although it’s recommended that you choose the automatic setting, which will select the protocol optimal for your speed and security.

VPN Protocol Settings

(When connecting through a third-party app such as Tunnelblick for Mac OS X or Network Manager or Terminal on Linux, you also have a variety of options for encryption with OpenVPN.)

Here are some of the features of ExpressVPN encryption with OpenVPN:

Server authentication

OpenVPN functions similar to TLS or HTTPS, which is why it might be referred to as a TLS VPN. (HTTPS is the secure version of the basic internet protocol HTTP, used to protect site authenticity on the internet. Your browser has certificates pre-installed that allow it to verify the integrity of a website, as long as it uses HTTPS. You can verify that a site uses HTTPS properly by looking for the green lock in your browser’s address bar.)

Just like HTTPS, OpenVPN uses certificates to protect the user against man-in-the-middle attacks. With HTTPS there are centralized registrars called Certificate Authorities (CAs). They are cryptographically trusted by your operating system or browser, and they issue and sign certificates for websites. This works in HTTPS because there are common standards to issue and revoke certificates, as well as to attribute the domains they are issued for to a specific owner. OpenVPN clients require you to install the VPN’s certificate yourself, usually by simply saving it on your computer and instructing the OpenVPN client where the file is located.

ExpressVPN uses an RSA certificate identified by the hashing algorithm SHA-512, of the SHA-2 family. The RSA key belonging to the certificate is 4,096 bits long. On modern operating systems, ExpressVPN apps use, at minimum, AES-256 for encryption and SHA-256 for packet authentication.

HMAC authentication

HMAC stands for keyed-Hash Message Authentication Code. A Message Authentication Code is a protection against data being altered in transit by an attacker who has the ability to read the data in real-time. Out of many possibilities on how to reliably authenticate messages, TLS and OpenVPN use hashes (hence the H in HMAC).

Control-channel encryption

To ensure the integrity and confidentiality of encrypted data even on low-powered hardware, ExpressVPN uses AES-256-GCM. AES is one of the most widely used symmetric encryption standards, based on the Rijndael cipher developed by Belgian cryptographers Joan Daemen and Vincent Rijmen in 1998. The 256 refers to the fixed size of each encrypted block, 256 bits. GCM (Galois/Counter Mode) allows your computer to encrypt multiple packages at once, ensuring that your connection never hangs even for a short moment.

Data-channel encryption

Data-channel encryption protects against your information being visible to the parties that your data travels through. ExpressVPN uses a symmetric encryption scheme, in which the key is negotiated using the elliptic curve Diffie-Hellman key exchange. The ExpressVPN server and your VPN app use clever mathematics to negotiate and verify a secret key that is then used to encrypt the data for the entire session.

Perfect forward secrecy

Perfect forward secrecy means that even if a dedicated adversary were able to compromise your computer or the VPN server during one session, the attacker would not be able to decrypt any traffic from past sessions. That’s because ExpressVPN negotiates a new secret key every time you connect. Even if you remain connected to the VPN for an extended period of time, ExpressVPN automatically negotiates a new key every 60 minutes.

This 60-minute re-keying process guarantees your “forward secrecy,” so the most an adversary could obtain, if they managed to compromise your keys, would be up to 60 minutes of data. The rest is secret going forward.

Learn more about using a VPN

Man with a laptop protected by a VPN.
What is a VPN?

Get to know how a VPN protects your online traffic from snooping

Learn more

A man at his laptop using ExpressVPN.
Browse anonymously

Hide your IP address and mask your location online

Learn more

Women unlocking padlock on browser.
Unblock websites

Access your favorite web services and defeat censorship

Learn more


Ready to try the best encrypted VPN?

VPN encryption is essential. Give ExpressVPN a try. You’re 100% covered by our 30-day money-back guarantee.
Get ExpressVPN