Table of Contents

AsconCxof128 Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
AsconCxof128.cs

Computes a variable-length output using the Ascon-CXOF128 customizable extendable output function (CXOF) as defined in NIST SP 800-232. Supports an optional customization string that domain-separates outputs from AsconXof128. This class cannot be inherited.

public sealed class AsconCxof128 : AsconXof<AsconCxof128>, IDisposable
Inheritance
AsconCxof128
Implements
Inherited Members
Extension Methods

Examples

using var cxof = new AsconCxof128();
cxof.Customize(Encoding.UTF8.GetBytes("my-app-v1"));
cxof.Absorb(message);
byte[] output = cxof.GetHash(32);

Remarks

Ascon-CXOF128 extends AsconXof128 with a customization phase. The customization string Z is absorbed before any message data, using a dedicated domain-separation constant to ensure that different customization strings produce independent output functions. An empty customization string does not produce the same output as AsconXof128.

If no customization string is required, prefer AsconXof128 directly. Use Ascon-CXOF128 when you need distinct output functions for different application contexts (for example, key derivation vs. masking) from a single primitive.

The lifecycle is:

  1. Optionally call Customize(ReadOnlySpan<byte>) (before any Absorb(ReadOnlySpan<byte>) call).
  2. Call Absorb(ReadOnlySpan<byte>) zero or more times.
  3. Call Squeeze(Span<byte>) to produce output.
  4. Call Initialize() to reset for reuse.

Parameters at a glance.

  • Output size: variable, any positive multiple of 8 bits.
  • Customization string: optional bytes absorbed before message data, domain-separates outputs.
  • State: 320-bit sponge; rate: 8 bytes (64 bits).
  • Permutation: Ascon-p12 for every absorption, transition, and squeeze round.
  • Specification: NIST SP 800-232 (ASCON family).

When to choose Ascon-CXOF128. Pick the customizable XOF when you need multiple independent output streams from one primitive - KMAC-style domain separation per protocol layer, per-purpose KDFs (signing-key vs. encryption-key vs. binding-tag), or hash-based DRBGs that must not collide across applications. For uncustomized XOF output use AsconXof128; for fixed-length 256-bit hashes use AsconHash256; for the AEAD member of the suite use AsconAead128.

Constructors

AsconCxof128()

Initializes a new instance of the AsconCxof128 class.

public AsconCxof128()

Methods

Absorb(ReadOnlySpan<byte>)

Absorbs data into the sponge state. May be called multiple times before the first Squeeze(Span<byte>).

public override void Absorb(ReadOnlySpan<byte> data)

Parameters

data ReadOnlySpan<byte>

The input data to absorb. May be empty.

Exceptions

ObjectDisposedException

The instance has been disposed.

InvalidOperationException

Squeeze(Span<byte>) has already been called; call Initialize() to reset and start over.

Customize(ReadOnlySpan<byte>)

Absorbs a customization string that domain-separates this instance from other uses of the same primitive. Must be called before any call to Absorb(ReadOnlySpan<byte>).

public void Customize(ReadOnlySpan<byte> customization)

Parameters

customization ReadOnlySpan<byte>

The customization string. May be empty to indicate the default (un-customized) domain. Calling this method with an empty span is distinct from not calling it at all.

Remarks

Per NIST SP 800-232, the customization phase absorbs the bit length of Z encoded as a 64-bit little-endian integer, immediately followed by the bytes of Z, through the standard Ascon rate-8 sponge pipeline. The phase is then closed with Ascon padding and the full 12-round permutation before message absorption begins.

Exceptions

ObjectDisposedException

The instance has been disposed.

InvalidOperationException

Customize(ReadOnlySpan<byte>) has already been called on this instance. Call Initialize() to reset.

Initialize()

Resets the instance to its initial state, discarding any absorbed data or squeezed output, so that it is ready to accept a new message.

public override void Initialize()

Exceptions

ObjectDisposedException

The instance has been disposed.

Applies to

ProductVersions
.NET8, 10

See Also