Table of Contents

Iso10126Padding Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Iso10126Padding.cs

Implements the ISO 10126 padding scheme, which appends N - 1 cryptographically random bytes followed by a trailing byte holding the padding length N.

public sealed class Iso10126Padding : IPaddingStrategy
Inheritance
Iso10126Padding
Implements
Inherited Members
Extension Methods

Examples

using Bodu.Security.Cryptography;

// Legacy interop only - padding bytes are random; only the final length byte is validated.
IPaddingStrategy padding = new Iso10126Padding();
byte[] padded = padding.Pad(plaintext, blockSize: 128); // 128 bits = 16 bytes
byte[] recovered = padding.Unpad(padded, blockSize: 128);

Remarks

A full block of padding is always added when the input is already block-aligned so that Unpad(ReadOnlySpan<byte>, int) can unambiguously recover the original length. The interior pad bytes are not reconstructable on decryption, so only the trailing length byte is validated. ISO 10126 was withdrawn by ISO in 2007; it is supported for interoperability with existing ciphertexts.

When to choose ISO 10126. Only for legacy interop. The random pad bytes carry no security benefit over Pkcs7Padding and the standard has been formally withdrawn. For new designs use PKCS#7 with an authenticated mode, or pair an AEAD mode with NoPadding.

Constructors

Iso10126Padding()

public Iso10126Padding()

Properties

StripsPaddingOnUnpad

Gets a value indicating whether Unpad(ReadOnlySpan<byte>, int) inspects the final block and may return fewer bytes than it received. Self-describing schemes such as PKCS#7, ANSI X.923, ISO 10126 and ISO/IEC 7816-4 return true; pass-through schemes such as zero padding and no padding return false.

public bool StripsPaddingOnUnpad { get; }

Property Value

bool

Remarks

Streaming block-cipher transforms use this flag to decide whether the final ciphertext block must be deferred during decryption so that padding validation and removal can happen at the stream boundary.

Methods

Pad(ReadOnlySpan<byte>, int)

Applies ISO 10126 padding to the input data, ensuring the total output is a multiple of the block size.

public byte[] Pad(ReadOnlySpan<byte> input, int blockSize)

Parameters

input ReadOnlySpan<byte>

The data to pad.

blockSize int

The block size in bits. Must be a positive multiple of 8.

Returns

byte[]

The padded data as a byte array.

Exceptions

ArgumentOutOfRangeException

Thrown if blockSize is not a positive multiple of 8.

Unpad(ReadOnlySpan<byte>, int)

Validates and removes ISO 10126 padding from the specified input data.

public byte[] Unpad(ReadOnlySpan<byte> input, int blockSize)

Parameters

input ReadOnlySpan<byte>

The padded data.

blockSize int

The block size in bits. Must be a positive multiple of 8.

Returns

byte[]

The unpadded data as a byte array.

Remarks

Unlike its siblings, ISO 10126 validation is deliberately not masked into a constant-time walk of the final block: the interior pad bytes are random by construction, so the trailing length byte is the only byte that can be checked at all. Masking that single range check would buy nothing - the resulting exception is observable to an attacker either way, which is exactly the padding-oracle surface. As with every strippable padding, authenticate the ciphertext before depadding.

Exceptions

ArgumentOutOfRangeException

Thrown if blockSize is not a positive multiple of 8.

ArgumentException

Thrown if input is empty or not aligned to the block size.

CryptographicException

Thrown if the trailing length byte is out of range.

Applies to

ProductVersions
.NET8, 10