Pkcs7Padding Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- Pkcs7Padding.cs
Implements the PKCS#7 padding scheme (RFC 5652), which appends N bytes of value N to align the input
to the cipher block size.
public sealed class Pkcs7Padding : IPaddingStrategy
- Inheritance
-
Pkcs7Padding
- Implements
- Inherited Members
- Extension Methods
Examples
using Bodu.Security.Cryptography;
IPaddingStrategy padding = new Pkcs7Padding();
byte[] padded = padding.Pad(plaintext, blockSize: 128); // 128 bits = 16 bytes
// padded.Length is a multiple of 16; the trailing N bytes each equal N.
byte[] recovered = padding.Unpad(padded, blockSize: 128);
Remarks
A full block of padding is always added when the input length is already a multiple of the block size, so that
Unpad(ReadOnlySpan<byte>, int) can unambiguously recover the original plaintext length. Valid values of N lie in the
range 1..blockSize. Unpad(ReadOnlySpan<byte>, int) validates in constant time to resist padding-oracle side channels.
When to choose PKCS7. The default for confidentiality-only block-cipher modes (CBC, ECB) - PKCS#7 is the padding that every mainstream cryptographic library ships as the default, and what every interoperable file format expects. For ISO/EMV environments use Iso7816_4Padding; when integrating with code that emits trailing zeros use ZeroPadding; when the surrounding mode (CTR, CTS, AEAD) provides its own alignment use NoPadding.
caution
PKCS#7 unpadding under CBC is the canonical setting for the padding-oracle attack. Always pair PKCS#7-padded CBC with a separate authenticator (HMAC over the ciphertext) or, preferably, replace the whole construction with an AEAD mode such as GcmModeTransform or EaxModeTransform.
Constructors
Pkcs7Padding()
public Pkcs7Padding()
Properties
StripsPaddingOnUnpad
Gets a value indicating whether Unpad(ReadOnlySpan<byte>, int) inspects the final block and may return fewer bytes than it received. Self-describing schemes such as PKCS#7, ANSI X.923, ISO 10126 and ISO/IEC 7816-4 return true; pass-through schemes such as zero padding and no padding return false.
public bool StripsPaddingOnUnpad { get; }
Property Value
Remarks
Streaming block-cipher transforms use this flag to decide whether the final ciphertext block must be deferred during decryption so that padding validation and removal can happen at the stream boundary.
Methods
Pad(ReadOnlySpan<byte>, int)
Applies PKCS#7 padding to the input data, ensuring the total output is a multiple of the block size.
public byte[] Pad(ReadOnlySpan<byte> input, int blockSize)
Parameters
inputReadOnlySpan<byte>The data to pad.
blockSizeintThe block size in bits. Must be a positive multiple of 8.
Returns
- byte[]
The padded data as a byte array.
Exceptions
- ArgumentOutOfRangeException
Thrown if
blockSizeis not a positive multiple of 8.
Unpad(ReadOnlySpan<byte>, int)
Validates and removes PKCS#7 padding from the specified input data.
public byte[] Unpad(ReadOnlySpan<byte> input, int blockSize)
Parameters
inputReadOnlySpan<byte>The padded data.
blockSizeintThe block size in bits. Must be a positive multiple of 8.
Returns
- byte[]
The unpadded data as a byte array.
Exceptions
- ArgumentOutOfRangeException
Thrown if
blockSizeis not a positive multiple of 8.- ArgumentException
Thrown if
inputis empty or not aligned to the block size.- CryptographicException
Thrown if the padding is invalid or malformed.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |