Table of Contents

CfbModeTransform Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
CfbModeTransform.cs

Applies the Cipher Feedback (CFB) mode transformation to an underlying IBlockCipher, turning it into a self-synchronizing stream cipher.

public sealed class CfbModeTransform : IBlockCipherModeTransform, IDisposable
Inheritance
CfbModeTransform
Implements
Inherited Members
Extension Methods

Examples

using System.Security.Cryptography;
using Bodu.Security.Cryptography;

// Most callers should set SymmetricAlgorithm.Mode = CipherBlockMode.CFB instead of using this directly.
using IBlockCipher cipher = new AesBlockCipher(key);
byte[] iv = RandomNumberGenerator.GetBytes(cipher.BlockSize / 8);
IBlockCipherModeTransform cfb = new CfbModeTransform(cipher, iv);
byte[] ciphertext = new byte[plaintext.Length];
int written = cfb.Transform(plaintext, ciphertext, encrypt: true);

Remarks

CFB panel - the previous ciphertext is fed back as the cipher input; its encryption produces a keystream XORed with plaintext.

Both directions use the cipher's encryption primitive: encryption computes Cᵢ = Pᵢ ⊕ E(IVᵢ) and decryption Pᵢ = Cᵢ ⊕ E(IVᵢ), with IV₀ supplied by the caller and IVᵢ₊₁ = Cᵢ for subsequent blocks. See panel 3 of the diagram above: the dashed feedback lines carry ciphertext blocks back into the next cipher input - the cipher runs the same direction (encrypt) for both encryption and decryption, and the plaintext simply XORs into or out of the resulting keystream.

The initialization vector must equal the cipher block size in length and should be unique and unpredictable per message under a given key.

When to use CFB. Pick CFB only for interoperability with legacy formats - it was the stream-cipher mode of choice in PGP / OpenPGP and certain disk-encryption layouts. CFB removes the padding requirement that CbcModeTransform imposes, but inherits the same lack of authentication and adds bit-flip propagation across multiple blocks. For new code prefer CtrModeTransform for stream-cipher behavior, or an AEAD mode (GcmModeTransform, EaxModeTransform) for authenticated encryption.

CFB is sequential at the block level: each ciphertext block must be produced before the next can be computed, so the mode does not parallelize within a message.

Constructors

CfbModeTransform(IBlockCipher, byte[])

Initializes a new instance of the CfbModeTransform class with the specified cipher and initialization vector.

public CfbModeTransform(IBlockCipher cipher, byte[] iv)

Parameters

cipher IBlockCipher

The block cipher over which CFB is applied.

iv byte[]

The initialization vector used as the feedback register for the first block. A defensive copy is taken.

Exceptions

ArgumentNullException

Thrown if cipher or iv is null.

Methods

Dispose()

Releases the resources used by this instance and zeroes the running feedback register so that key-equivalent state does not linger in memory after disposal. The underlying IBlockCipher is not disposed by this type - ownership remains with the caller.

public void Dispose()

Remarks

Idempotent.

Transform(ReadOnlySpan<byte>, Span<byte>, bool)

Transforms input under the mode's chaining strategy and writes the result to output.

public int Transform(ReadOnlySpan<byte> input, Span<byte> output, bool encrypt)

Parameters

input ReadOnlySpan<byte>

The input data to transform. Its length must be a positive multiple of the underlying cipher block size.

output Span<byte>

The destination span. Its length must be greater than or equal to the length of input.

encrypt bool

true to encrypt the input; false to decrypt.

Returns

int

The number of bytes written to output.

Exceptions

ArgumentException

Thrown when input's length is not a multiple of the block size or when output is too small.

Applies to

ProductVersions
.NET8, 10

See Also