Table of Contents

Pkcs7Padding Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Pkcs7Padding.cs

Implements the PKCS#7 padding scheme (RFC 5652), which appends N bytes of value N to align the input to the cipher block size.

public sealed class Pkcs7Padding : IPaddingStrategy
Inheritance
Pkcs7Padding
Implements
Inherited Members
Extension Methods

Examples

using Bodu.Security.Cryptography;

IPaddingStrategy padding = new Pkcs7Padding();
byte[] padded = padding.Pad(plaintext, blockSize: 128); // 128 bits = 16 bytes

// padded.Length is a multiple of 16; the trailing N bytes each equal N.
byte[] recovered = padding.Unpad(padded, blockSize: 128);

Remarks

A full block of padding is always added when the input length is already a multiple of the block size, so that Unpad(ReadOnlySpan<byte>, int) can unambiguously recover the original plaintext length. Valid values of N lie in the range 1..blockSize. Unpad(ReadOnlySpan<byte>, int) validates in constant time to resist padding-oracle side channels.

When to choose PKCS7. The default for confidentiality-only block-cipher modes (CBC, ECB) - PKCS#7 is the padding that every mainstream cryptographic library ships as the default, and what every interoperable file format expects. For ISO/EMV environments use Iso7816_4Padding; when integrating with code that emits trailing zeros use ZeroPadding; when the surrounding mode (CTR, CTS, AEAD) provides its own alignment use NoPadding.

caution

PKCS#7 unpadding under CBC is the canonical setting for the padding-oracle attack. Always pair PKCS#7-padded CBC with a separate authenticator (HMAC over the ciphertext) or, preferably, replace the whole construction with an AEAD mode such as GcmModeTransform or EaxModeTransform.

Constructors

Pkcs7Padding()

public Pkcs7Padding()

Properties

StripsPaddingOnUnpad

Gets a value indicating whether Unpad(ReadOnlySpan<byte>, int) inspects the final block and may return fewer bytes than it received. Self-describing schemes such as PKCS#7, ANSI X.923, ISO 10126 and ISO/IEC 7816-4 return true; pass-through schemes such as zero padding and no padding return false.

public bool StripsPaddingOnUnpad { get; }

Property Value

bool

Remarks

Streaming block-cipher transforms use this flag to decide whether the final ciphertext block must be deferred during decryption so that padding validation and removal can happen at the stream boundary.

Methods

Pad(ReadOnlySpan<byte>, int)

Applies PKCS#7 padding to the input data, ensuring the total output is a multiple of the block size.

public byte[] Pad(ReadOnlySpan<byte> input, int blockSize)

Parameters

input ReadOnlySpan<byte>

The data to pad.

blockSize int

The block size in bits. Must be a positive multiple of 8.

Returns

byte[]

The padded data as a byte array.

Exceptions

ArgumentOutOfRangeException

Thrown if blockSize is not a positive multiple of 8.

Unpad(ReadOnlySpan<byte>, int)

Validates and removes PKCS#7 padding from the specified input data.

public byte[] Unpad(ReadOnlySpan<byte> input, int blockSize)

Parameters

input ReadOnlySpan<byte>

The padded data.

blockSize int

The block size in bits. Must be a positive multiple of 8.

Returns

byte[]

The unpadded data as a byte array.

Exceptions

ArgumentOutOfRangeException

Thrown if blockSize is not a positive multiple of 8.

ArgumentException

Thrown if input is empty or not aligned to the block size.

CryptographicException

Thrown if the padding is invalid or malformed.

Applies to

ProductVersions
.NET8, 10