skip to content

What is a Cipher transformation string in Java, and what do its parts mean (e.g. "AES/GCM/NoPadding")?

level: juniorimportance: must knowfreq 70%

answer

  1. algorithm / mode / padding
  2. AES = block cipher, 16-byte blocks
  3. GCM and CTR use NoPadding (stream/AEAD)
  4. bare "AES" => provider picks ECB => insecure
  5. always specify all three parts

basics

~10 s

It is the text you pass to Cipher.getInstance to choose encryption. It has three parts separated by slashes: the algorithm, the mode of operation, and the padding, like "AES/GCM/NoPadding".

solid answer

~40 s

A transformation string tells Java which encryption to build when you call Cipher.getInstance(transformation). The full form is "algorithm/mode/padding", for example "AES/CBC/PKCS5Padding" or "AES/GCM/NoPadding". The algorithm is the cipher itself (AES); the mode is how blocks are chained (CBC, GCM, CTR, ECB); the padding fills the final partial block so the input length is a multiple of the block size (PKCS5Padding) or NoPadding for stream-like and AEAD modes such as GCM. You may also pass just the bare algorithm name ("AES"), but then the provider picks the mode and padding for you, which is dangerous. Always specify all three parts explicitly so behavior is deterministic and reviewable. GCM and CTR use NoPadding because they turn the block cipher into a stream.

code

java · 6 lines
java
// Good: all three parts explicit
Cipher gcm = Cipher.getInstance("AES/GCM/NoPadding");
Cipher cbc = Cipher.getInstance("AES/CBC/PKCS5Padding");

// Bad: bare name -> provider default is AES/ECB/PKCS5Padding (insecure)
Cipher bad = Cipher.getInstance("AES");

go deeper

for a junior

Can name the three parts (algorithm/mode/padding) and read a string like AES/GCM/NoPadding.

for a middle

Knows GCM/CTR need NoPadding and CBC needs PKCS5Padding, and that bare "AES" defaults to insecure ECB.

for a senior

Explains provider-dependent defaults, can justify mode/padding pairings, and treats bare algorithm names as a review blocker.

for a principal

Sets org-wide crypto conventions (always full transformation, prefer AEAD), wires static-analysis rules, and reasons about provider portability across JDKs/FIPS.

## What problem this solves In Java, the `javax.crypto.Cipher` class is the single entry point for symmetric and asymmetric encryption. You do not construct a cipher with `new`; instead you ask a factory for one: `Cipher.getInstance(String transformation)`. The **transformation string** is how you tell that factory exactly what you want. ## The three parts The canonical form is: ``` algorithm/mode/padding ``` - **algorithm** — the cipher primitive itself. The common modern choice is `AES` (Advanced Encryption Standard), a *block cipher* that encrypts fixed 16-byte (128-bit) blocks. Older/other names you may see: `DES`, `DESede` (Triple DES), `RSA` (asymmetric), `ChaCha20`. - **mode** (mode of operation) — a block cipher only knows how to encrypt one 16-byte block. To encrypt a longer message you need a *mode* that decides how successive blocks relate. Common modes: - `ECB` (Electronic Codebook): each block encrypted independently. **Insecure** — identical plaintext blocks produce identical ciphertext blocks, leaking patterns. - `CBC` (Cipher Block Chaining): each block is XORed with the previous ciphertext block before encryption; needs an **IV** (initialization vector) for the first block. - `CTR` (Counter): turns the block cipher into a stream cipher by encrypting a counter; needs a nonce/IV. - `GCM` (Galois/Counter Mode): an **AEAD** mode (Authenticated Encryption with Associated Data) — it both encrypts *and* produces an authentication tag that detects tampering. Built on CTR internally. - **padding** — block-cipher modes like CBC require the plaintext length to be an exact multiple of the block size. Padding adds bytes to the last block to reach that multiple, and removes them on decrypt. Common values: - `PKCS5Padding` (in practice PKCS#7 for AES's 16-byte block): the standard padding for CBC/ECB. - `NoPadding`: no padding is added. Required for **stream-like** modes (CTR) and **AEAD** modes (GCM), because they consume the data byte-by-byte and do not need full blocks. Also used when you pad yourself. So `AES/GCM/NoPadding` = AES cipher, GCM mode, no padding (correct for GCM). `AES/CBC/PKCS5Padding` = AES, CBC mode, PKCS5 padding (correct for CBC). ## The bare-name shorthand and why it is dangerous You *can* write `Cipher.getInstance("AES")` with only the algorithm. Java then lets the security **provider** choose the mode and padding defaults. On the default Oracle/OpenJDK provider this resolves to `AES/ECB/PKCS5Padding` — and **ECB is insecure**. Because the default depends on the installed provider and JDK version, the behavior is non-deterministic across environments. The fix is simple: **always specify all three parts.** Static analyzers (SpotBugs, SonarQube, error-prone) flag bare algorithm names for exactly this reason. ## Putting it together ```java Cipher cipher = Cipher.getInstance("AES/GCM/NoPadding"); ``` This call does not yet encrypt anything; it just selects the transformation. You then `init` the cipher with a key and parameters, and finally `doFinal` to process data. The transformation string is purely the *what*; the key and IV/nonce are supplied separately at init time. With this, a reader at any level can read a transformation string, name each part, explain why GCM uses NoPadding, and explain why a bare `"AES"` is a red flag.

  • Why does GCM use NoPadding while CBC uses PKCS5Padding?
    GCM is built on CTR mode, which turns AES into a stream cipher consuming bytes one at a time, so there is no last-block to pad. CBC operates on whole blocks, so the final partial block must be padded to a full 16 bytes.
  • What does Cipher.getInstance("AES") actually resolve to on the default JDK provider?
    AES/ECB/PKCS5Padding. ECB is insecure because identical plaintext blocks map to identical ciphertext, so you should never rely on this default.

A transformation string is like ordering a coffee by spec: bean (algorithm), brew method (mode), and milk (padding). Just saying 'coffee' (bare "AES") lets the barista pick defaults you may not want.

saying these in an interview costs you the question

  • Thinking the slashes are optional decoration rather than algorithm/mode/padding
  • Believing "AES" alone is safe because 'AES is a strong algorithm' — the mode (ECB default) is what's broken
  • Confusing padding with the IV/nonce — padding fills the last block, the IV is a separate init parameter
  • Assuming NoPadding means 'less secure' — it is required and correct for GCM/CTR

context