PKCS#5 padding scheme is designed specifically for 8-byte block ciphers like DES. Each padding byte contains the number of padding bytes added. This is essentially identical to PKCS#7 but restricted to 8-byte blocks only. It was developed for password-based encryption systems.
| Property | Value |
|---|---|
| Category | Padding Schemes |
| Sub-category | Password-Based Padding |
| Security status | π‘οΈ Secure |
| Complexity | Not specified |
| Inventor | RSA Laboratories |
| Year | 1993 |
| Origin | πΊπΈ United States |
| Source | algorithms/padding/pkcs.js |
| Flag | Value |
|---|---|
IsLengthIncluded |
No |
Status: π‘οΈ Secure
| Issue | Description | Mitigation |
|---|---|---|
| Padding Oracle Attack | Like PKCS#7, PKCS#5 can be vulnerable to padding oracle attacks if error messages reveal padding validity. | β |
| Block Size Limitation | PKCS#5 is restricted to 8-byte blocks only, limiting its applicability to modern ciphers. | β |
| Legacy Cipher Usage | Primarily used with DES, which is now considered cryptographically broken. | β |
3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β PKCS#5 padding with 3 bytes needed
Source: RFC 2898
| Field | Value |
|---|---|
blockSize |
8 |
input |
6bc1bee22e |
expected |
6bc1bee22e030303 |
Vector 2 β PKCS#5 padding for full block
Source: RFC 2898
| Field | Value |
|---|---|
blockSize |
8 |
input |
6bc1bee22e409f96 |
expected |
6bc1bee22e409f960808080808080808 |
Vector 3 β PKCS#5 padding with 7 bytes needed
Source: RFC 2898
| Field | Value |
|---|---|
blockSize |
8 |
input |
6bc1bee22e409f96e9 |
expected |
6bc1bee22e409f96e907070707070707 |