OfbModeTransform Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- OfbModeTransform.cs
Applies the Output Feedback (OFB) mode transformation to an underlying IBlockCipher, turning it into a synchronous stream cipher in which encryption and decryption are identical operations.
public sealed class OfbModeTransform : IBlockCipherModeTransform, IDisposable
- Inheritance
-
OfbModeTransform
- Implements
- Inherited Members
- Extension Methods
Examples
using System.Security.Cryptography;
using Bodu.Security.Cryptography;
// Most callers should set SymmetricAlgorithm.Mode = CipherBlockMode.OFB instead of using this directly.
using IBlockCipher cipher = new AesBlockCipher(key);
byte[] iv = RandomNumberGenerator.GetBytes(cipher.BlockSize / 8); // unique per message
IBlockCipherModeTransform ofb = new OfbModeTransform(cipher, iv);
byte[] ciphertext = new byte[plaintext.Length];
int written = ofb.Transform(plaintext, ciphertext, encrypt: true);
Remarks
The keystream is produced by repeatedly encrypting the feedback register: Oᵢ = E(Oᵢ₋₁) with O₀ = IV,
and the output is Pᵢ ⊕ Oᵢ. See panel 4 of the diagram above: the dashed feedback arrows run between
cipher output and the next cipher input - in contrast to CFB (panel 3), where feedback runs from
ciphertext. That structural difference is what makes OFB a synchronous stream cipher - the keystream is independent
of the plaintext - and immune to bit-flip propagation.
The initialization vector must equal the cipher block size in length and must never be reused under the same key, otherwise keystreams collide and confidentiality is lost.
When to use OFB. Pick OFB only for legacy interop. For stream-cipher behavior CtrModeTransform is the modern default - it parallelizes, supports random access, and is the mode used by every major AEAD construction. OFB's main historical advantage was that bit errors in transmission do not propagate, but unauthenticated stream ciphers cannot detect those errors at all, so the guarantee is rarely useful in practice. As with CFB, OFB has no built-in authentication; reach for an AEAD mode ( GcmModeTransform, EaxModeTransform) when integrity matters.
OFB's keystream depends only on the IV and the key, so it is sequential at generation but the resulting keystream can be precomputed and cached if needed.
Constructors
OfbModeTransform(IBlockCipher, byte[])
Initializes a new instance of the OfbModeTransform class with the specified cipher and initialization vector.
public OfbModeTransform(IBlockCipher cipher, byte[] iv)
Parameters
cipherIBlockCipherThe block cipher used to generate the keystream.
ivbyte[]The initialization vector used to seed the feedback register. A defensive copy is taken.
Exceptions
- ArgumentNullException
Thrown if
cipherorivis null.
Methods
Dispose()
Releases the resources used by this instance and zeroes the running feedback register so that key-equivalent keystream state does not linger in memory after disposal. The underlying IBlockCipher is not disposed by this type - ownership remains with the caller.
public void Dispose()
Remarks
Idempotent.
Transform(ReadOnlySpan<byte>, Span<byte>, bool)
Transforms input under the mode's chaining strategy and writes the result to
output.
public int Transform(ReadOnlySpan<byte> input, Span<byte> output, bool encrypt)
Parameters
inputReadOnlySpan<byte>The input data to transform. Its length must be a positive multiple of the underlying cipher block size.
outputSpan<byte>The destination span. Its length must be greater than or equal to the length of
input.encryptbool
Returns
- int
The number of bytes written to
output.
Exceptions
- ArgumentException
Thrown when
input's length is not a multiple of the block size or whenoutputis too small.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |