Zero padding scheme fills remaining bytes with zero values to reach the block size. This is the simplest padding method but has ambiguity issues when the original data ends with zero bytes, making it impossible to distinguish padding from actual data during removal. Such input is rejected rather than padded, because unpadding would silently return short data.
| Property | Value |
|---|---|
| Category | Padding Schemes |
| Sub-category | Simple Padding |
| Security status | 🎓 Educational Only |
| Complexity | Not specified |
| Inventor | N/A |
| Year | 1970 |
| Origin | Not specified |
| Restricted input domain | data whose last byte is not zero |
| Source | algorithms/padding/zero.js |
| Flag | Value |
|---|---|
IsLengthIncluded |
No |
Status: 🎓 Educational Only
| Issue | Description | Mitigation |
|---|---|---|
| Ambiguous Padding Removal | Cannot distinguish between padding zeros and actual data zeros, leading to potential data corruption during unpadding. | — |
| Data Loss Risk | If original data ends with zeros, those zeros will be incorrectly removed during unpadding. | — |
| Protocol Vulnerabilities | The ambiguity can be exploited in certain protocols where message length matters. | — |
3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — Zero padding with 17 bytes needed
Source: Zero padding specification
| Field | Value |
|---|---|
blockSize |
32 |
input |
6bc1bee22e409f96e93d7e11739317 |
expected |
6bc1bee22e409f96e93d7e117393170000000000000000000000000000000000 |
Vector 2 — Zero padding for exact block size
Source: Zero padding specification
| Field | Value |
|---|---|
blockSize |
16 |
input |
6bc1bee22e409f96e93d7e117393172a |
expected |
6bc1bee22e409f96e93d7e117393172a |
Vector 3 — Zero padding with 3 bytes needed
Source: Zero padding specification
| Field | Value |
|---|---|
blockSize |
8 |
input |
6bc1bee22e |
expected |
6bc1bee22e000000 |