Modes Of Operation: Electronic Codebook (ECB), Cipher Block Chaining (CBC), Output Feedback (OFB), And Counter (CTR) Modes

Back To Page


  Category:  CRYPTOGRAPHY | 6th October 2026, Tuesday

techk.org, kaustub technologies

Modes Of Operation: ECB, CBC, OFB, And CTR

Introduction

A Block Cipher Is A Symmetric-key Cryptographic Algorithm That Encrypts Information In Fixed-size Blocks. Examples Include The Advanced Encryption Standard (AES) And The Older Data Encryption Standard (DES). AES Operates On 128-bit Blocks, While DES Operates On 64-bit Blocks.

Real-world Messages Are Usually Much Longer Than One Block. A Mechanism Is Therefore Required To Apply A Block Cipher Repeatedly To An Entire Message. These Mechanisms Are Called modes Of Operation.

A Mode Of Operation Specifies How Plaintext Blocks, Ciphertext Blocks, Initialization Vectors, Nonces, Counters, And Cryptographic Keys Interact. Different Modes Have Different Properties Regarding Confidentiality, Error Propagation, Parallel Processing, Padding, And Security.

Four Important Classical Modes Are:

  1. Electronic Codebook (ECB)

  2. Cipher Block Chaining (CBC)

  3. Output Feedback (OFB)

  4. Counter (CTR)

ECB Encrypts Each Block Independently. CBC Links Plaintext Blocks Through Previous Ciphertext. OFB Generates A Feedback-based Keystream, While CTR Generates A Keystream From Counter Values.

The Following Sections Explain Each Mode And Provide Worked Examples.

Basic Notation

The Following Notation Is Used Throughout:

  • P? = Plaintext Block

  • C? = Ciphertext Block

  • K = Secret Key

  • E?(X) = Encryption Of X Using Key K

  • D?(X) = Decryption Of X Using Key K

  • IV = Initialization Vector

  • N = Nonce

  • ⊕ = XOR Operation

For Simplicity, The Worked Examples Use Small Hexadecimal Values Such As 3A And 7F. These Are toy Examples Intended To Demonstrate The Mode's Operation. In A Real System, The Block Cipher Would Perform A Much More Complex Transformation Such As AES.

XOR Operation

XOR Is Particularly Important In CBC, OFB, And CTR.

The Basic Rules Are:

A B A ⊕ B
0 0 0
0 1 1
1 0 1
1 1 0

For Hexadecimal Values, XOR Is Performed Bit By Bit.

For Example:

3A XOR 5C

Convert Them To Binary:

3A = 0011 1010
5C = 0101 1100

XOR:

0011 1010
0101 1100
---------
0110 0110

Therefore:

3A ⊕ 5C = 66

Another Example:

66 ⊕ 66 = 00

This Property Is Important Because:

A ⊕ B ⊕ B = A

Electronic Codebook (ECB) Mode

Definition

Electronic Codebook (ECB) Is The Simplest Block-cipher Mode. Each Plaintext Block Is Encrypted Independently Using The Same Key.

The Encryption Equation Is:

C? = E?(P?)

The Decryption Equation Is:

P? = D?(C?)

There Is No Chaining Between Blocks And No IV.

The Structure Is:

P1 ??> E(K) ??> C1

P2 ??> E(K) ??> C2

P3 ??> E(K) ??> C3

Worked ECB Encryption Example

To Demonstrate ECB, Suppose A Simplified Block Cipher Produces The Following Results:

E(K, 2A) = 91
E(K, 7F) = 34
E(K, 2A) = 91

Suppose The Plaintext Consists Of Three Blocks:

P1 = 2A
P2 = 7F
P3 = 2A

Step 1: Encrypt P?

C1 = E(K, P1)

C1 = E(K, 2A)

C1 = 91

Step 2: Encrypt P?

C2 = E(K, P2)

C2 = E(K, 7F)

C2 = 34

Step 3: Encrypt P?

C3 = E(K, P3)

C3 = E(K, 2A)

C3 = 91

Therefore:

Plaintext:  2A | 7F | 2A
Ciphertext: 91 | 34 | 91

Notice That:

P1 = P3

and Consequently:

C1 = C3

This Demonstrates The Major Weakness Of ECB.

Important Observation

ECB Reveals Repeated Plaintext Patterns:

P1 = P3
        ↓
C1 = C3

An Attacker May Therefore Learn Structural Information About The Plaintext Even Without Knowing The Encryption Key.

This Is Why ECB Should Generally not Be Used For Encrypting Structured Sensitive Data.

Cipher Block Chaining (CBC)

Definition

Cipher Block Chaining Connects Each Plaintext Block To The Previous Ciphertext Block.

The First Block Uses An Initialization Vector:

C? = E?(P? ⊕ IV)

For Subsequent Blocks:

C? = E?(P? ⊕ C???)

The Structure Is:

          IV
           |
           V
P1 -----> XOR -----> E(K) -----> C1
                                  |
                                  V
P2 ----------------> XOR ------> E(K) -----> C2
                                               |
                                               V
P3 --------------------------------> XOR ----> E(K) -----> C3

Worked CBC Encryption Example

Consider The Following Simplified Example:

IV = 5C

P1 = 3A
P2 = 7F
P3 = 12

Assume Our Toy Block Cipher Produces:

E(K, 66) = A1
E(K, DE) = 45
E(K, 57) = 92

We Now Perform CBC Encryption Step By Step.

Step 1: Encrypt The First Block

The First Plaintext Block Is XORed With The IV:

P1 ⊕ IV
= 3A ⊕ 5C
= 66

Now Encrypt The Result:

C1 = E(K, 66)

C1 = A1

Therefore:

C1 = A1

Step 2: Encrypt The Second Block

The Second Plaintext Block Is XORed With The Previous Ciphertext:

P2 ⊕ C1
= 7F ⊕ A1

Convert To Binary:

7F = 0111 1111
A1 = 1010 0001

XOR:

0111 1111
1010 0001
---------
1101 1110

Therefore:

7F ⊕ A1 = DE

Now Encrypt:

C2 = E(K, DE)

C2 = 45

Therefore:

C2 = 45

Step 3: Encrypt The Third Block

Now XOR P? With C?:

P3 ⊕ C2
= 12 ⊕ 45
= 57

Then Encrypt:

C3 = E(K, 57)

C3 = 92

Therefore:

C3 = 92

Final CBC Ciphertext

IV = 5C

Plaintext:
3A | 7F | 12

Ciphertext:
A1 | 45 | 92

The Complete Calculation Is:

C1 = E(K, 3A ⊕ 5C)
   = E(K, 66)
   = A1

C2 = E(K, 7F ⊕ A1)
   = E(K, DE)
   = 45

C3 = E(K, 12 ⊕ 45)
   = E(K, 57)
   = 92

This Demonstrates The chaining Principle.

CBC Decryption Example

The Same Example Can Be Reversed.

We Have:

IV = 5C

C1 = A1
C2 = 45
C3 = 92

Assume:

D(K, A1) = 66
D(K, 45) = DE
D(K, 92) = 57

Recover P?

P1 = D(K, C1) ⊕ IV

P1 = 66 ⊕ 5C

P1 = 3A

Recover P?

P2 = D(K, C2) ⊕ C1

P2 = DE ⊕ A1

P2 = 7F

Recover P?

P3 = D(K, C3) ⊕ C2

P3 = 57 ⊕ 45

P3 = 12

Therefore:

Recovered Plaintext:

3A | 7F | 12

This Verifies The CBC Encryption Process.

Advantages And Disadvantages Of CBC

Advantages

  • Hides Repeated Plaintext Patterns Better Than ECB.

  • Widely Supported In Legacy Cryptographic Systems.

  • Provides Strong Confidentiality When Correctly Implemented.

  • Can Be Combined With A Separate Authentication Mechanism.

Disadvantages

  • Encryption Is Sequential.

  • Requires Padding For Non-block-aligned Plaintext.

  • Requires Careful IV Generation.

  • Does Not Provide Authentication By Itself.

  • Poor Implementations May Be Vulnerable To Padding Oracle Attacks.

  • Ciphertext Modification Can Affect Multiple Plaintext Blocks.

Output Feedback (OFB) Mode

Output Feedback Mode Converts A Block Cipher Into A Stream-like Cipher.

Instead Of Feeding Ciphertext Back Into The Cipher, OFB Feeds The output Of The Block Cipher Back Into The Next Encryption Operation.

The First Output Is:

O? = E?(IV)

Then:

O? = E?(O?)

O? = E?(O?)

The Plaintext Is XORed With These Outputs:

C? = P? ⊕ O?

C? = P? ⊕ O?

C? = P? ⊕ O?

Worked OFB Encryption Example

Suppose:

IV = 10

and The Toy Block Cipher Produces:

E(K, 10) = A5
E(K, A5) = 3C
E(K, 3C) = F1

Suppose The Plaintext Is:

P1 = 2A
P2 = 7F
P3 = 12

Step 1: Generate First Keystream Value

O1 = E(K, IV)

O1 = E(K, 10)

O1 = A5

Now Encrypt P?:

C1 = P1 ⊕ O1

C1 = 2A ⊕ A5

C1 = 8F

Generate Second Keystream Value

Feed O? Back Into The Block Cipher:

O2 = E(K, O1)

O2 = E(K, A5)

O2 = 3C

Encrypt P?:

C2 = P2 ⊕ O2

C2 = 7F ⊕ 3C

C2 = 43

Generate Third Keystream Value

O3 = E(K, O2)

O3 = E(K, 3C)

O3 = F1

Encrypt P?:

C3 = P3 ⊕ O3

C3 = 12 ⊕ F1

C3 = E3

Final Result

IV = 10

Plaintext:
2A | 7F | 12

Keystream:
A5 | 3C | F1

Ciphertext:
8F | 43 | E3

The Important Point Is That The Ciphertext Itself Is not Fed Back.

Instead:

IV → E(K) → O1 → E(K) → O2 → E(K) → O3

OFB Decryption Example

OFB Uses The Same Keystream For Decryption.

We Have:

Ciphertext:
8F | 43 | E3

Keystream:
A5 | 3C | F1

Recover P?:

P1 = C1 ⊕ O1

P1 = 8F ⊕ A5

P1 = 2A

Recover P?:

P2 = C2 ⊕ O2

P2 = 43 ⊕ 3C

P2 = 7F

Recover P?:

P3 = C3 ⊕ O3

P3 = E3 ⊕ F1

P3 = 12

Therefore:

Recovered Plaintext:

2A | 7F | 12

This Demonstrates Why OFB Can Use The Same Process For Encryption And Decryption.

Important OFB Security Requirement

OFB Must Not Reuse The Same IV With The Same Key In A Way That Causes The Same Keystream To Be Reused.

Suppose:

C1 = P1 ⊕ S
C2 = P2 ⊕ S

where S Is The Same Keystream.

Then:

C1 ⊕ C2
= (P1 ⊕ S) ⊕ (P2 ⊕ S)

Since:

S ⊕ S = 0

we Obtain:

C1 ⊕ C2 = P1 ⊕ P2

This Can Reveal Relationships Between The Plaintexts.

Counter (CTR) Mode

Counter Mode Generates A Keystream By Encrypting Successive Counter Values.

A Simplified Construction Is:

S? = E?(N || Counter?)

The Plaintext Is Then XORed With The Resulting Keystream:

C? = P? ⊕ S?

Unlike CBC, Each Counter Value Can Be Processed Independently.

Worked CTR Encryption Example

Suppose:

Nonce = 20

and Counters Are:

Counter1 = 01
Counter2 = 02
Counter3 = 03

Assume The Toy Block Cipher Produces:

E(K, 2001) = B4
E(K, 2002) = 6A
E(K, 2003) = D1

Suppose:

P1 = 2A
P2 = 7F
P3 = 12

Step 1: Generate First Keystream Block

S1 = E(K, 2001)

S1 = B4

Encrypt P?:

C1 = P1 ⊕ S1

C1 = 2A ⊕ B4

C1 = 9E

Step 2: Generate Second Keystream Block

S2 = E(K, 2002)

S2 = 6A

Encrypt P?:

C2 = P2 ⊕ S2

C2 = 7F ⊕ 6A

C2 = 15

Step 3: Generate Third Keystream Block

S3 = E(K, 2003)

S3 = D1

Encrypt P?:

C3 = P3 ⊕ S3

C3 = 12 ⊕ D1

C3 = C3

Final CTR Ciphertext

Nonce = 20

Plaintext:
2A | 7F | 12

Counter:
01 | 02 | 03

Keystream:
B4 | 6A | D1

Ciphertext:
9E | 15 | C3

CTR Decryption Example

CTR Decryption Generates Exactly The Same Keystream.

Given:

C1 = 9E
C2 = 15
C3 = C3

and:

S1 = B4
S2 = 6A
S3 = D1

Recover P?:

P1 = C1 ⊕ S1

P1 = 9E ⊕ B4

P1 = 2A

Recover P?:

P2 = C2 ⊕ S2

P2 = 15 ⊕ 6A

P2 = 7F

Recover P?:

P3 = C3 ⊕ S3

P3 = C3 ⊕ D1

P3 = 12

Therefore:

Recovered Plaintext:

2A | 7F | 12

Why CTR Supports Parallel Processing

Consider:

Counter1 → E(K) → S1
Counter2 → E(K) → S2
Counter3 → E(K) → S3
Counter4 → E(K) → S4

Each Encryption Is Independent.

Therefore, Multiple Counter Blocks Can Be Encrypted Simultaneously.

CBC Cannot Normally Do This During Encryption Because:

C2 Depends On C1
C3 Depends On C2
C4 Depends On C3

CTR Therefore Has An Important Performance Advantage On Modern Processors.

CTR Random Access

CTR Also Supports Random Access.

Suppose A Large File Has Thousands Of Encrypted Blocks And An Application Needs Block 500.

With CTR, The Application Can Determine The Counter Corresponding To Block 500 And Generate The Appropriate Keystream Block Directly.

It Does Not Have To Decrypt Blocks 1 Through 499 First.

This Makes CTR Useful For Large Files, Storage Systems, Databases, And High-speed Communication.

Worked Comparison Of The Four Examples

The Four Examples Can Now Be Summarized.

ECB

P1 → E(K) → C1
P2 → E(K) → C2
P3 → E(K) → C3

No Relationship Exists Between Blocks.

CBC

P1 ⊕ IV → E(K) → C1
P2 ⊕ C1 → E(K) → C2
P3 ⊕ C2 → E(K) → C3

Each Block Depends On The Previous Ciphertext.

OFB

IV → E(K) → O1
O1 → E(K) → O2
O2 → E(K) → O3

P1 ⊕ O1 → C1
P2 ⊕ O2 → C2
P3 ⊕ O3 → C3

The Block-cipher Output Is Fed Back.

CTR

Nonce+1 → E(K) → S1
Nonce+2 → E(K) → S2
Nonce+3 → E(K) → S3

P1 ⊕ S1 → C1
P2 ⊕ S2 → C2
P3 ⊕ S3 → C3

Counter Values Generate Independent Keystream Blocks.

Comparison Table

Property ECB CBC OFB CTR
Basic Technique Independent Encryption Ciphertext Chaining Feedback Keystream Counter-generated Keystream
IV/Nonce Not Required IV Required IV Required Unique Nonce/counter Required
Padding Usually Required Required Not Required Not Required
Encryption Parallelism Excellent Poor Limited Excellent
Random Access Excellent Limited Limited Excellent
Repeated-pattern Protection Poor Good Good Good
Error Propagation One Block Two Blocks Typically Affected Bit-level Bit-level
Authentication No No No No
Stream-like No No Yes Yes
Modern Suitability Generally Avoid Mostly Legacy Mostly Legacy Useful Primitive, But Needs Authentication

Confidentiality And Integrity

An Important Distinction Must Be Made Between encryption And authentication.

Encryption Provides Confidentiality. It Attempts To Prevent Unauthorized Users From Reading The Plaintext.

Authentication And Integrity Protection Attempt To Ensure That The Ciphertext Has Not Been Modified And That It Came From An Authorized Source.

ECB, CBC, OFB, And CTR Do Not Inherently Provide Authentication.

For Example, An Attacker May Modify A CTR Ciphertext:

C = P ⊕ S

Changing C Causes The Corresponding Plaintext Bit To Change:

C' = C ⊕ Δ

and Therefore:

P' = P ⊕ Δ

Without Authentication, The Receiver May Not Know That This Modification Occurred.

Modern Authenticated Encryption

Modern Applications Often Use Authenticated Encryption With Associated Data (AEAD) Rather Than A Confidentiality-only Mode.

Common Examples Include:

  • AES-GCM

  • ChaCha20-Poly1305

An AEAD Construction Provides:

Plaintext
    |
    V
Authenticated Encryption
    |
    +---- Ciphertext
    |
    +---- Authentication Tag

The Receiver Verifies The Authentication Tag Before Accepting The Plaintext.

This Provides Significantly Stronger Protection Against Ciphertext Manipulation Than Using ECB, CBC, OFB, Or CTR Alone.

Advantages And Disadvantages Summary

ECB

Advantages:

  • Simple

  • Fast

  • Parallelizable

  • No IV Required

Disadvantages:

  • Reveals Repeated Patterns

  • Not Suitable For Structured Data

  • No Authentication

CBC

Advantages:

  • Conceals Repeated Patterns

  • Widely Supported

  • Strong Confidentiality When Properly Implemented

Disadvantages:

  • Sequential Encryption

  • Requires Padding

  • Requires Secure IV Handling

  • No Built-in Authentication

  • Vulnerable To Padding-oracle Problems If Poorly Implemented

OFB

Advantages:

  • Stream-like Operation

  • No Conventional Padding

  • Limited Error Propagation

  • Same Basic Operation For Encryption And Decryption

Disadvantages:

  • Requires Careful IV Management

  • Sequential Keystream Generation

  • No Built-in Authentication

  • Keystream Reuse Is Dangerous

CTR

Advantages:

  • No Padding

  • Highly Parallelizable

  • Fast

  • Random Access

  • Same XOR-based Process For Encryption And Decryption

Disadvantages:

  • Nonce Reuse Is Dangerous

  • No Built-in Authentication

  • Requires Reliable Counter Management

Practical Security Recommendations

When Designing A Modern Cryptographic System:

  1. Do Not Use ECB For General-purpose Encryption Of Structured Data.

  2. Use A Secure And Properly Generated IV For CBC Or OFB.

  3. Never Reuse A CTR Nonce/counter Sequence With The Same Key.

  4. Never Reuse An OFB Keystream.

  5. Handle CBC Padding Securely.

  6. Do Not Assume Encryption Automatically Provides Integrity.

  7. Prefer Authenticated-encryption Modes For New Applications.

  8. Use Established Cryptographic Libraries Rather Than Implementing AES Or Cryptographic Modes From Scratch.

  9. Protect Encryption Keys Using Secure Key-management Mechanisms.

  10. Avoid Revealing Detailed Cryptographic Errors To Attackers.

Conclusion

Modes Of Operation Determine How A Block Cipher Can Securely Process Data Longer Than A Single Block. ECB, CBC, OFB, And CTR Demonstrate Four Different Approaches.

ECB Encrypts Each Block Independently. Its Simplicity And Parallelism Are Attractive, But Identical Plaintext Blocks Produce Identical Ciphertext Blocks, Making ECB Unsuitable For Most General-purpose Data Encryption.

CBC Introduces Chaining. Each Plaintext Block Is XORed With The Previous Ciphertext Block Before Encryption. The Worked Example Showed:

C1 = E(K, P1 ⊕ IV)
C2 = E(K, P2 ⊕ C1)
C3 = E(K, P3 ⊕ C2)

This Hides Repeated Plaintext Patterns Better Than ECB But Requires Padding And Careful IV Handling.

OFB Generates A Keystream Through Feedback:

O1 = E(K, IV)
O2 = E(K, O1)
O3 = E(K, O2)

The Plaintext Is Then XORed With This Keystream. OFB Does Not Require Conventional Padding, But Its IV Must Not Be Improperly Reused.

CTR Generates Independent Keystream Blocks From Counter Values:

S1 = E(K, Nonce || Counter1)
S2 = E(K, Nonce || Counter2)
S3 = E(K, Nonce || Counter3)

The Worked Example Demonstrated How These Keystream Blocks Are XORed With Plaintext. CTR Provides Excellent Parallelism And Random-access Capabilities, But Nonce Reuse Can Seriously Compromise Confidentiality.

The Most Important Practical Point Is That These Four Modes Primarily Address confidentiality. They Do Not Automatically Provide Integrity Or Authentication. For Modern Applications, Authenticated-encryption Modes Such As AES-GCM And ChaCha20-Poly1305 Are Generally Preferred.

Nevertheless, ECB, CBC, OFB, And CTR Remain Fundamental Topics In Cryptography. The Worked Examples Make Their Central Differences Clear:

ECB → Independent Blocks

CBC → Previous Ciphertext Affects Next Block

OFB → Previous Cipher Output Generates Next Keystream Block

CTR → Counter Values Generate Independent Keystream Blocks

Understanding These Principles Provides A Strong Foundation For Studying Modern Symmetric Cryptography And Authenticated-encryption Systems.

Tags:
Modes Of Operation: Electronic Codebook (ECB), Cipher Block Chaining (CBC), Output Feedback (OFB), And Counter (CTR) Modes

Links 1 Links 2 Products Pages Follow Us
Home Founder Gallery Contact Us
About Us MSME CouponPat Sitemap
Cookies Privacy Policy Kaustub Study Institute
Disclaimer Terms of Service