Table of Contents

IPaddingStrategy Interface

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
IPaddingStrategy.cs

Defines methods for applying and removing padding to data blocks in block cipher operations.

public interface IPaddingStrategy
Extension Methods

Remarks

Block ciphers typically require input to be a multiple of a fixed block size. This interface provides a strategy pattern to apply or remove padding schemes such as PKCS#7, zero-padding, or no padding.

Implementations must ensure that padding is applied correctly and that unpadding validates or strips padding bytes in accordance with the scheme’s rules.

Built-in implementations.

Choosing a scheme. Pick Pkcs7Padding for any new design that requires length-recoverable padding under a confidentiality-only mode (CBC, ECB). Pick Iso7816_4Padding when interoperating with smartcard / EMV / ISO crypto tooling. Pick ZeroPadding only when the plaintext format itself encodes its length (so the trailing zeros can be discarded by the application layer) - and prefer one of the self-describing schemes otherwise. NoPadding is appropriate when the surrounding mode handles alignment itself (CTR, CTS, AEAD modes).

Most callers go through Padding (which dispatches via PaddingFactory) rather than constructing implementations directly. Direct use is appropriate when wiring custom transforms that do not extend SymmetricAlgorithm. Implementations are stateless and safe to share across threads.

Properties

StripsPaddingOnUnpad

Gets a value indicating whether Unpad(ReadOnlySpan<byte>, int) inspects the final block and may return fewer bytes than it received. Self-describing schemes such as PKCS#7, ANSI X.923, ISO 10126 and ISO/IEC 7816-4 return true; pass-through schemes such as zero padding and no padding return false.

bool StripsPaddingOnUnpad { get; }

Property Value

bool

Remarks

Streaming block-cipher transforms use this flag to decide whether the final ciphertext block must be deferred during decryption so that padding validation and removal can happen at the stream boundary.

Methods

Pad(ReadOnlySpan<byte>, int)

Applies padding to the input data to align it with the specified block size.

byte[] Pad(ReadOnlySpan<byte> input, int blockSize)

Parameters

input ReadOnlySpan<byte>

The input data to be padded.

blockSize int

The block size in bits that the padded output must align to. Must be a positive multiple of 8.

Returns

byte[]

A new byte array containing the padded data. The byte length of the result will be a multiple of blockSize / 8.

Exceptions

ArgumentOutOfRangeException

Thrown if blockSize is less than or equal to zero.

Unpad(ReadOnlySpan<byte>, int)

Removes padding from the input data based on the strategy's padding rules.

byte[] Unpad(ReadOnlySpan<byte> input, int blockSize)

Parameters

input ReadOnlySpan<byte>

The padded input data to unpad. Its byte length must be a multiple of blockSize / 8.

blockSize int

The block size in bits used during the original padding operation. Must be a positive multiple of 8.

Returns

byte[]

A new byte array containing the unpadded data.

Exceptions

ArgumentException

Thrown if the input does not conform to the expected padding scheme or its byte length is not a multiple of blockSize / 8.

Applies to

ProductVersions
.NET8, 10