Table of Contents

OfbModeTransform Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
OfbModeTransform.cs

Applies the Output Feedback (OFB) mode transformation to an underlying IBlockCipher, turning it into a synchronous stream cipher in which encryption and decryption are identical operations.

public sealed class OfbModeTransform : IBlockCipherModeTransform, IDisposable
Inheritance
OfbModeTransform
Implements
Inherited Members
Extension Methods

Examples

using System.Security.Cryptography;
using Bodu.Security.Cryptography;

// Most callers should set SymmetricAlgorithm.Mode = CipherBlockMode.OFB instead of using this directly.
using IBlockCipher cipher = new AesBlockCipher(key);
byte[] iv = RandomNumberGenerator.GetBytes(cipher.BlockSize / 8); // unique per message
IBlockCipherModeTransform ofb = new OfbModeTransform(cipher, iv);
byte[] ciphertext = new byte[plaintext.Length];
int written = ofb.Transform(plaintext, ciphertext, encrypt: true);

Remarks

OFB panel - the cipher's output keystream feeds forward into the next cipher input, independent of plaintext.

The keystream is produced by repeatedly encrypting the feedback register: Oᵢ = E(Oᵢ₋₁) with O₀ = IV, and the output is Pᵢ ⊕ Oᵢ. See panel 4 of the diagram above: the dashed feedback arrows run between cipher output and the next cipher input - in contrast to CFB (panel 3), where feedback runs from ciphertext. That structural difference is what makes OFB a synchronous stream cipher - the keystream is independent of the plaintext - and immune to bit-flip propagation.

The initialization vector must equal the cipher block size in length and must never be reused under the same key, otherwise keystreams collide and confidentiality is lost.

When to use OFB. Pick OFB only for legacy interop. For stream-cipher behavior CtrModeTransform is the modern default - it parallelizes, supports random access, and is the mode used by every major AEAD construction. OFB's main historical advantage was that bit errors in transmission do not propagate, but unauthenticated stream ciphers cannot detect those errors at all, so the guarantee is rarely useful in practice. As with CFB, OFB has no built-in authentication; reach for an AEAD mode ( GcmModeTransform, EaxModeTransform) when integrity matters.

OFB's keystream depends only on the IV and the key, so it is sequential at generation but the resulting keystream can be precomputed and cached if needed.

Constructors

OfbModeTransform(IBlockCipher, byte[])

Initializes a new instance of the OfbModeTransform class with the specified cipher and initialization vector.

public OfbModeTransform(IBlockCipher cipher, byte[] iv)

Parameters

cipher IBlockCipher

The block cipher used to generate the keystream.

iv byte[]

The initialization vector used to seed the feedback register. A defensive copy is taken.

Exceptions

ArgumentNullException

Thrown if cipher or iv is null.

Methods

Dispose()

Releases the resources used by this instance and zeroes the running feedback register so that key-equivalent keystream state does not linger in memory after disposal. The underlying IBlockCipher is not disposed by this type - ownership remains with the caller.

public void Dispose()

Remarks

Idempotent.

Transform(ReadOnlySpan<byte>, Span<byte>, bool)

Transforms input under the mode's chaining strategy and writes the result to output.

public int Transform(ReadOnlySpan<byte> input, Span<byte> output, bool encrypt)

Parameters

input ReadOnlySpan<byte>

The input data to transform. Its length must be a positive multiple of the underlying cipher block size.

output Span<byte>

The destination span. Its length must be greater than or equal to the length of input.

encrypt bool

true to encrypt the input; false to decrypt.

Returns

int

The number of bytes written to output.

Exceptions

ArgumentException

Thrown when input's length is not a multiple of the block size or when output is too small.

Applies to

ProductVersions
.NET8, 10

See Also