Table of Contents

Argon2i Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Argon2i.cs

Computes the Argon2i password-hashing and key-derivation function (RFC 9106) - the variant that uses data-independent memory addressing, making it resistant to side-channel timing attacks. This class cannot be inherited.

public sealed class Argon2i : Argon2
Inheritance
Argon2i
Inherited Members
Extension Methods

Remarks

Argon2i is preferred where memory access patterns may be observed by an attacker but offers weaker time-memory trade-off resistance than Argon2d; for most password-hashing scenarios Argon2id is recommended.

Constructors

Argon2i(Argon2Parameters)

Initializes a new instance of the Argon2i class with the specified cost parameters.

public Argon2i(Argon2Parameters parameters)

Parameters

parameters Argon2Parameters

The cost and auxiliary parameters governing the derivation.

Remarks

Each derivation may use up to Parallelism threads, bounded by the processor count, when its lanes are large enough to be worth dividing; see MaxDegreeOfParallelism.

Exceptions

ArgumentNullException

parameters is null.

ArgumentOutOfRangeException

A cost parameter in parameters falls outside the range permitted by RFC 9106.

ArgumentException

The version code in parameters is neither 0x10 nor 0x13.

Argon2i(Argon2Parameters, int)

Initializes a new instance of the Argon2i class with the specified cost parameters and bound on the threads each derivation may use.

public Argon2i(Argon2Parameters parameters, int maxDegreeOfParallelism)

Parameters

parameters Argon2Parameters

The cost and auxiliary parameters governing the derivation.

maxDegreeOfParallelism int

The greatest number of threads one derivation may use, the calling thread included; -1 lets the library choose.

Remarks

1 confines every derivation to the calling thread, which suits a service that already runs many derivations at once; a larger value caps the threads. The tag never depends on the bound.

Exceptions

ArgumentNullException

parameters is null.

ArgumentOutOfRangeException

A cost parameter in parameters falls outside the range permitted by RFC 9106, or maxDegreeOfParallelism is zero or less than -1.

ArgumentException

The version code in parameters is neither 0x10 nor 0x13.

Methods

DeriveKey(ReadOnlySpan<byte>, ReadOnlySpan<byte>, Argon2Parameters)

Derives a tag from a password and salt using the supplied parameters in a single call.

public static byte[] DeriveKey(ReadOnlySpan<byte> password, ReadOnlySpan<byte> salt, Argon2Parameters parameters)

Parameters

password ReadOnlySpan<byte>

The password / message to derive from.

salt ReadOnlySpan<byte>

The salt; must be at least 8 bytes.

parameters Argon2Parameters

The cost and auxiliary parameters.

Returns

byte[]

The derived tag.

Hash(ReadOnlySpan<byte>, ReadOnlySpan<byte>, Argon2Parameters)

Derives a password hash and returns it as a PHC encoded-hash string in a single call.

public static string Hash(ReadOnlySpan<byte> password, ReadOnlySpan<byte> salt, Argon2Parameters parameters)

Parameters

password ReadOnlySpan<byte>

The password to hash.

salt ReadOnlySpan<byte>

The salt to embed; must be at least 8 bytes.

parameters Argon2Parameters

The cost and auxiliary parameters.

Returns

string

The PHC encoded-hash string.

Verify(string, ReadOnlySpan<byte>)

Verifies a password against an Argon2i PHC encoded-hash string.

public static bool Verify(string encoded, ReadOnlySpan<byte> password)

Parameters

encoded string

The PHC encoded-hash string; must name the argon2i variant.

password ReadOnlySpan<byte>

The password to verify.

Returns

bool

true if the string names Argon2i and the password matches; otherwise, false.

Verify(string, ReadOnlySpan<byte>, ReadOnlySpan<byte>)

Verifies a password against an Argon2i PHC encoded-hash string using the supplied secret key.

public static bool Verify(string encoded, ReadOnlySpan<byte> password, ReadOnlySpan<byte> secret)

Parameters

encoded string

The PHC encoded-hash string; must name the argon2i variant.

password ReadOnlySpan<byte>

The password to verify.

secret ReadOnlySpan<byte>

The secret key used when the hash was produced.

Returns

bool

true if the string names Argon2i and the password matches; otherwise, false.

Applies to

ProductVersions
.NET8, 10