Alex Gaynor | af82d5e | 2013-10-29 17:07:24 -0700 | [diff] [blame] | 1 | .. hazmat:: |
Alex Gaynor | 5f3db27 | 2013-10-29 10:56:35 -0700 | [diff] [blame] | 2 | |
| 3 | Padding |
| 4 | ======= |
| 5 | |
Alex Gaynor | b2d5efd | 2013-10-29 11:15:30 -0700 | [diff] [blame] | 6 | .. currentmodule:: cryptography.hazmat.primitives.padding |
Alex Gaynor | 5f3db27 | 2013-10-29 10:56:35 -0700 | [diff] [blame] | 7 | |
Alex Gaynor | 462bd60 | 2014-04-25 07:49:08 -0700 | [diff] [blame] | 8 | Padding is a way to take data that may or may not be a multiple of the block |
Alex Gaynor | 5f3db27 | 2013-10-29 10:56:35 -0700 | [diff] [blame] | 9 | size for a cipher and extend it out so that it is. This is required for many |
| 10 | block cipher modes as they require the data to be encrypted to be an exact |
| 11 | multiple of the block size. |
| 12 | |
| 13 | |
Alex Gaynor | b2d5efd | 2013-10-29 11:15:30 -0700 | [diff] [blame] | 14 | .. class:: PKCS7(block_size) |
Alex Gaynor | 5f3db27 | 2013-10-29 10:56:35 -0700 | [diff] [blame] | 15 | |
| 16 | PKCS7 padding is a generalization of PKCS5 padding (also known as standard |
| 17 | padding). PKCS7 padding works by appending ``N`` bytes with the value of |
| 18 | ``chr(N)``, where ``N`` is the number of bytes required to make the final |
| 19 | block of data the same size as the block size. A simple example of padding |
| 20 | is: |
| 21 | |
| 22 | .. doctest:: |
| 23 | |
Alex Gaynor | 0708278 | 2013-10-29 11:18:23 -0700 | [diff] [blame] | 24 | >>> from cryptography.hazmat.primitives import padding |
Alex Gaynor | 60ad3e1 | 2013-10-29 14:26:11 -0700 | [diff] [blame] | 25 | >>> padder = padding.PKCS7(128).padder() |
David Reid | db616be | 2014-02-12 10:51:56 -0800 | [diff] [blame] | 26 | >>> padded_data = padder.update(b"11111111111111112222222222") |
Alex Gaynor | bae899a | 2013-11-22 16:54:55 -0800 | [diff] [blame] | 27 | >>> padded_data |
David Reid | db616be | 2014-02-12 10:51:56 -0800 | [diff] [blame] | 28 | '1111111111111111' |
David Reid | 50309fb | 2014-02-12 11:16:27 -0800 | [diff] [blame] | 29 | >>> padded_data += padder.finalize() |
| 30 | >>> padded_data |
David Reid | db616be | 2014-02-12 10:51:56 -0800 | [diff] [blame] | 31 | '11111111111111112222222222\x06\x06\x06\x06\x06\x06' |
Alex Gaynor | bae899a | 2013-11-22 16:54:55 -0800 | [diff] [blame] | 32 | >>> unpadder = padding.PKCS7(128).unpadder() |
David Reid | db616be | 2014-02-12 10:51:56 -0800 | [diff] [blame] | 33 | >>> data = unpadder.update(padded_data) |
| 34 | >>> data |
| 35 | '1111111111111111' |
| 36 | >>> data + unpadder.finalize() |
| 37 | '11111111111111112222222222' |
Alex Gaynor | 5f3db27 | 2013-10-29 10:56:35 -0700 | [diff] [blame] | 38 | |
| 39 | :param block_size: The size of the block in bits that the data is being |
| 40 | padded to. |
| 41 | |
Alex Gaynor | b2d5efd | 2013-10-29 11:15:30 -0700 | [diff] [blame] | 42 | .. method:: padder() |
| 43 | |
| 44 | :returns: A padding |
| 45 | :class:`~cryptography.hazmat.primitives.interfaces.PaddingContext` |
| 46 | provider. |
| 47 | |
| 48 | .. method:: unpadder() |
| 49 | |
| 50 | :returns: An unpadding |
| 51 | :class:`~cryptography.hazmat.primitives.interfaces.PaddingContext` |
| 52 | provider. |
| 53 | |
| 54 | |
| 55 | .. currentmodule:: cryptography.hazmat.primitives.interfaces |
| 56 | |
| 57 | .. class:: PaddingContext |
| 58 | |
Alex Gaynor | b481889 | 2014-02-06 10:58:50 -0800 | [diff] [blame] | 59 | When calling ``padder()`` or ``unpadder()`` the result will conform to the |
| 60 | ``PaddingContext`` interface. You can then call ``update(data)`` with data |
| 61 | until you have fed everything into the context. Once that is done call |
| 62 | ``finalize()`` to finish the operation and obtain the remainder of the |
| 63 | data. |
Alex Gaynor | b2d5efd | 2013-10-29 11:15:30 -0700 | [diff] [blame] | 64 | |
| 65 | .. method:: update(data) |
| 66 | |
| 67 | :param bytes data: The data you wish to pass into the context. |
| 68 | :return bytes: Returns the data that was padded or unpadded. |
Alex Stapleton | 425fc04 | 2014-04-25 22:32:01 +0100 | [diff] [blame] | 69 | :raises cryptography.exceptions.AlreadyFinalized: See :meth:`finalize`. |
Alex Gaynor | b2d5efd | 2013-10-29 11:15:30 -0700 | [diff] [blame] | 70 | |
| 71 | .. method:: finalize() |
| 72 | |
Alex Stapleton | 425fc04 | 2014-04-25 22:32:01 +0100 | [diff] [blame] | 73 | Finalize the current context and return the rest of the data. |
| 74 | |
| 75 | After ``finalize`` has been called this object can no longer be used; |
| 76 | :meth:`update` and :meth:`finalize` will raise an |
| 77 | :class:`~cryptography.exceptions.AlreadyFinalized` exception. |
| 78 | |
Alex Gaynor | b2d5efd | 2013-10-29 11:15:30 -0700 | [diff] [blame] | 79 | :return bytes: Returns the remainder of the data. |
Alex Stapleton | 425fc04 | 2014-04-25 22:32:01 +0100 | [diff] [blame] | 80 | :raises ValueError: When trying to remove padding from incorrectly |
| 81 | padded data. |