Padding Oracle Attack
Padding Oracle Attack: Decryption without the key by observing whether a system accepts a ciphertext’s padding as valid. The attack is a protocol-level side channelSide-Channel AttackAttack that exploits indirect information such as timing, power consumption, or electromagnetic emissions. and needs no weakness in the cipher itself.
How it works and where it fits
Block ciphers in CBC mode pad the final message to a full block length, and decryption verifies that padding. If the system distinguishes observably between invalid padding and another error — through different messages, differing status codes, or measurably different response times — it becomes an oracle. The attacker modifies bytes of the preceding block and reads from the response when the padding validates. Byte by byte the entire plaintext can be reconstructed, at roughly 128 requests per byte.
Practical security relevance
Protection lies not in better error messages but in the construction: authenticated encryption such as AES-GCM, or a strict encrypt-then-MAC where integrity is verified before decryption happens at all. Error paths must be indistinguishable — same message, same code, same timing. Historically, variants of this attack hit TLS (Lucky 13, POODLE) and numerous application protocols with home-grown cryptography.
Related concepts
- Block CipherBlock CipherSymmetric encryption method that processes data in fixed-length blocks.: Symmetric encryption method that processes data in fixed-length blocks.
- CryptographyCryptographyMethods for protecting information through encryption, signatures, and hash functions.: Methods for protecting information through encryption, signatures, and hash functions.
- Side-Channel AttackSide-Channel AttackAttack that exploits indirect information such as timing, power consumption, or electromagnetic emissions.: Attack that exploits indirect information such as timing, power consumption, or electromagnetic emissions.
- EncryptionEncryptionConverts plaintext into unreadable ciphertext using a key.: Converts plaintext into unreadable ciphertext using a key.