Iso10126Padding Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- Iso10126Padding.cs
Implements the ISO 10126 padding scheme, which appends N - 1 cryptographically random bytes followed by a
trailing byte holding the padding length N.
public sealed class Iso10126Padding : IPaddingStrategy
- Inheritance
-
Iso10126Padding
- Implements
- Inherited Members
- Extension Methods
Examples
using Bodu.Security.Cryptography;
// Legacy interop only - padding bytes are random; only the final length byte is validated.
IPaddingStrategy padding = new Iso10126Padding();
byte[] padded = padding.Pad(plaintext, blockSize: 128); // 128 bits = 16 bytes
byte[] recovered = padding.Unpad(padded, blockSize: 128);
Remarks
A full block of padding is always added when the input is already block-aligned so that Unpad(ReadOnlySpan<byte>, int) can unambiguously recover the original length. The interior pad bytes are not reconstructable on decryption, so only the trailing length byte is validated. ISO 10126 was withdrawn by ISO in 2007; it is supported for interoperability with existing ciphertexts.
When to choose ISO 10126. Only for legacy interop. The random pad bytes carry no security benefit over Pkcs7Padding and the standard has been formally withdrawn. For new designs use PKCS#7 with an authenticated mode, or pair an AEAD mode with NoPadding.
Constructors
Iso10126Padding()
public Iso10126Padding()
Properties
StripsPaddingOnUnpad
Gets a value indicating whether Unpad(ReadOnlySpan<byte>, int) inspects the final block and may return fewer bytes than it received. Self-describing schemes such as PKCS#7, ANSI X.923, ISO 10126 and ISO/IEC 7816-4 return true; pass-through schemes such as zero padding and no padding return false.
public bool StripsPaddingOnUnpad { get; }
Property Value
Remarks
Streaming block-cipher transforms use this flag to decide whether the final ciphertext block must be deferred during decryption so that padding validation and removal can happen at the stream boundary.
Methods
Pad(ReadOnlySpan<byte>, int)
Applies ISO 10126 padding to the input data, ensuring the total output is a multiple of the block size.
public byte[] Pad(ReadOnlySpan<byte> input, int blockSize)
Parameters
inputReadOnlySpan<byte>The data to pad.
blockSizeintThe block size in bits. Must be a positive multiple of 8.
Returns
- byte[]
The padded data as a byte array.
Exceptions
- ArgumentOutOfRangeException
Thrown if
blockSizeis not a positive multiple of 8.
Unpad(ReadOnlySpan<byte>, int)
Validates and removes ISO 10126 padding from the specified input data.
public byte[] Unpad(ReadOnlySpan<byte> input, int blockSize)
Parameters
inputReadOnlySpan<byte>The padded data.
blockSizeintThe block size in bits. Must be a positive multiple of 8.
Returns
- byte[]
The unpadded data as a byte array.
Remarks
Unlike its siblings, ISO 10126 validation is deliberately not masked into a constant-time walk of the final block: the interior pad bytes are random by construction, so the trailing length byte is the only byte that can be checked at all. Masking that single range check would buy nothing - the resulting exception is observable to an attacker either way, which is exactly the padding-oracle surface. As with every strippable padding, authenticate the ciphertext before depadding.
Exceptions
- ArgumentOutOfRangeException
Thrown if
blockSizeis not a positive multiple of 8.- ArgumentException
Thrown if
inputis empty or not aligned to the block size.- CryptographicException
Thrown if the trailing length byte is out of range.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |