Table of Contents

Argon2id Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Argon2id.cs

Computes the Argon2id password-hashing and key-derivation function (RFC 9106) - the hybrid variant that uses data-independent addressing for the first half of the first pass and data-dependent addressing thereafter. This is the RECOMMENDED default for password hashing. This class cannot be inherited.

public sealed class Argon2id : Argon2
Inheritance
Argon2id
Inherited Members
Extension Methods

Remarks

Argon2id combines the side-channel resistance of Argon2i with the time-memory trade-off resistance of Argon2d, and is the variant any RFC 9106 implementation is required to support.

Constructors

Argon2id(Argon2Parameters)

Initializes a new instance of the Argon2id class with the specified cost parameters.

public Argon2id(Argon2Parameters parameters)

Parameters

parameters Argon2Parameters

The cost and auxiliary parameters governing the derivation.

Remarks

Each derivation may use up to Parallelism threads, bounded by the processor count, when its lanes are large enough to be worth dividing; see MaxDegreeOfParallelism.

Exceptions

ArgumentNullException

parameters is null.

ArgumentOutOfRangeException

A cost parameter in parameters falls outside the range permitted by RFC 9106.

ArgumentException

The version code in parameters is neither 0x10 nor 0x13.

Argon2id(Argon2Parameters, int)

Initializes a new instance of the Argon2id class with the specified cost parameters and bound on the threads each derivation may use.

public Argon2id(Argon2Parameters parameters, int maxDegreeOfParallelism)

Parameters

parameters Argon2Parameters

The cost and auxiliary parameters governing the derivation.

maxDegreeOfParallelism int

The greatest number of threads one derivation may use, the calling thread included; -1 lets the library choose.

Remarks

1 confines every derivation to the calling thread, which suits a service that already runs many derivations at once; a larger value caps the threads. The tag never depends on the bound.

Exceptions

ArgumentNullException

parameters is null.

ArgumentOutOfRangeException

A cost parameter in parameters falls outside the range permitted by RFC 9106, or maxDegreeOfParallelism is zero or less than -1.

ArgumentException

The version code in parameters is neither 0x10 nor 0x13.

Methods

DeriveKey(ReadOnlySpan<byte>, ReadOnlySpan<byte>, Argon2Parameters)

Derives a tag from a password and salt using the supplied parameters in a single call.

public static byte[] DeriveKey(ReadOnlySpan<byte> password, ReadOnlySpan<byte> salt, Argon2Parameters parameters)

Parameters

password ReadOnlySpan<byte>

The password / message to derive from.

salt ReadOnlySpan<byte>

The salt; must be at least 8 bytes.

parameters Argon2Parameters

The cost and auxiliary parameters.

Returns

byte[]

The derived tag.

Hash(ReadOnlySpan<byte>, ReadOnlySpan<byte>, Argon2Parameters)

Derives a password hash and returns it as a PHC encoded-hash string in a single call.

public static string Hash(ReadOnlySpan<byte> password, ReadOnlySpan<byte> salt, Argon2Parameters parameters)

Parameters

password ReadOnlySpan<byte>

The password to hash.

salt ReadOnlySpan<byte>

The salt to embed; must be at least 8 bytes.

parameters Argon2Parameters

The cost and auxiliary parameters.

Returns

string

The PHC encoded-hash string.

Verify(string, ReadOnlySpan<byte>)

Verifies a password against an Argon2id PHC encoded-hash string.

public static bool Verify(string encoded, ReadOnlySpan<byte> password)

Parameters

encoded string

The PHC encoded-hash string; must name the argon2id variant.

password ReadOnlySpan<byte>

The password to verify.

Returns

bool

true if the string names Argon2id and the password matches; otherwise, false.

Verify(string, ReadOnlySpan<byte>, ReadOnlySpan<byte>)

Verifies a password against an Argon2id PHC encoded-hash string using the supplied secret key.

public static bool Verify(string encoded, ReadOnlySpan<byte> password, ReadOnlySpan<byte> secret)

Parameters

encoded string

The PHC encoded-hash string; must name the argon2id variant.

password ReadOnlySpan<byte>

The password to verify.

secret ReadOnlySpan<byte>

The secret key used when the hash was produced.

Returns

bool

true if the string names Argon2id and the password matches; otherwise, false.

Applies to

ProductVersions
.NET8, 10