PKCS#7 padding scheme where padding bytes contain the number of padding bytes added. This ensures data is padded to block boundary with deterministic padding removal. It is the most widely used padding scheme for block ciphers and supports variable block sizes from 1 to 255 bytes.
| Property | Value |
|---|---|
| Category | Padding Schemes |
| Sub-category | Block Padding |
| Security status | π‘οΈ Secure |
| Complexity | Not specified |
| Inventor | RSA Laboratories |
| Year | 1993 |
| Origin | πΊπΈ United States |
| Source | algorithms/padding/pkcs.js |
| Flag | Value |
|---|---|
IsLengthIncluded |
No |
Status: π‘οΈ Secure
| Issue | Description | Mitigation |
|---|---|---|
| Padding Oracle Attack | When decryption errors reveal padding validity, attackers can decrypt arbitrary ciphertexts byte by byte. Use authenticated encryption modes or ensure error messages donβt distinguish between padding and other decryption errors. | β |
| Length Disclosure | The padding scheme reveals information about the original message length modulo block size. | β |
3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β PKCS#7 padding with 17 bytes needed
Source: RFC 2315
| Field | Value |
|---|---|
blockSize |
32 |
input |
6bc1bee22e409f96e93d7e11739317 |
expected |
6bc1bee22e409f96e93d7e117393171111111111111111111111111111111111 |
Vector 2 β PKCS#7 padding for full block
Source: RFC 2315
| Field | Value |
|---|---|
blockSize |
32 |
input |
6bc1bee22e409f96e93d7e117393172a |
expected |
6bc1bee22e409f96e93d7e117393172a10101010101010101010101010101010 |
Vector 3 β PKCS#7 padding with 3 bytes needed
Source: RFC 2315
| Field | Value |
|---|---|
blockSize |
8 |
input |
6bc1bee22e |
expected |
6bc1bee22e030303 |