AsconHash Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- AsconHash.cs
Abstract base class for ASCON cryptographic hash algorithms as defined in NIST SP 800-232. Implements the shared sponge construction, padding, and Ascon-p permutation used by all fixed-output ASCON hash variants.
public abstract class AsconHash : BlockHashAlgorithm, ICryptoTransform, IDisposable
- Inheritance
-
AsconHash
- Implements
- Derived
- Inherited Members
- Extension Methods
Remarks
All ASCON hash algorithms share a 320-bit internal state comprising five 64-bit words, a 64-bit (8-byte) rate, and a 256-bit output. They differ in their pre-computed initialization state and in the number of Ascon-p rounds applied after each absorbed block. The initial squeeze always uses the full 12-round permutation (Ascon-p12); subsequent squeeze blocks use the same round count as absorption.
Padding follows the Ascon convention: the byte immediately after the last input byte is set to 0x01 (the
little-endian sentinel bit), and the remaining rate bytes are zero. A padding block is always appended, even when
the message length is a multiple of the eight-byte rate.
Concrete derived types supply the five pre-computed post-initialization state words and the absorption round count via the protected constructor. No further overrides are required.
Constructors
AsconHash(ulong, ulong, ulong, ulong, ulong, int, string)
Initializes a new instance of the AsconHash class with the specified algorithm parameters.
protected AsconHash(ulong iv0, ulong iv1, ulong iv2, ulong iv3, ulong iv4, int absorptionRounds, string algorithmName)
Parameters
iv0ulongPre-computed initial state word 0 (result of applying Ascon-p12 to the raw IV).
iv1ulongPre-computed initial state word 1.
iv2ulongPre-computed initial state word 2.
iv3ulongPre-computed initial state word 3.
iv4ulongPre-computed initial state word 4.
absorptionRoundsintThe number of Ascon-p rounds applied after each absorbed block. Must be between 1 and 12 inclusive.
algorithmNamestringThe canonical algorithm identifier string as defined in NIST SP 800-232. Must not be null.
Exceptions
- ArgumentNullException
algorithmNameis null.- ArgumentOutOfRangeException
absorptionRoundsis less than 1 or greater than 12.
Properties
AlgorithmName
Gets the canonical algorithm name for this hash function variant as defined in NIST SP 800-232.
public override string AlgorithmName { get; }
Property Value
- string
A string such as
"ASCON-HASH256"or"ASCON-HASHA256"identifying the variant.
Exceptions
- ObjectDisposedException
The algorithm instance has been disposed.
CanReuseTransform
Gets a value indicating whether the current transform can be reused.
public override bool CanReuseTransform { get; }
Property Value
CanTransformMultipleBlocks
When overridden in a derived class, gets a value indicating whether multiple blocks can be transformed.
public override bool CanTransformMultipleBlocks { get; }
Property Value
Methods
Dispose(bool)
Releases the resources used by this instance and clears the internal sponge state.
protected override void Dispose(bool disposing)
Parameters
Initialize()
Resets the algorithm to its initial state by clearing the residual buffer and the running byte total. Derived
classes override this method, call base.Initialize() first, and then reset their own algorithm-specific
state (chaining variables, IV, key-derived schedule).
public override void Initialize()
Remarks
This method does not reset the State property explicitly on .NET 6+ targets —
the framework manages that transition. On earlier targets, derived classes that need the already-finalized guard
should reset their _finalized backing field from their own Initialize override.
Derived classes that need to validate state before the reset (for example, a keyed MAC that refuses to be
re-initialized when no key has been set) should perform that validation before calling base.Initialize().
Once the base call returns, the residual buffer is empty, Bodu.Security.Cryptography.BufferedBlockHashAlgorithm._residualBytes is 0, and
Bodu.Security.Cryptography.BufferedBlockHashAlgorithm._totalBytes is 0.
Exceptions
- ObjectDisposedException
The instance has been disposed.
PadBlock(ReadOnlySpan<byte>, ulong, Span<byte>)
Pads the final partial input block according to the Ascon padding rule.
protected override int PadBlock(ReadOnlySpan<byte> block, ulong messageLength, Span<byte> destination)
Parameters
blockReadOnlySpan<byte>The residual input bytes (zero to seven bytes) remaining after all complete 8-byte blocks have been processed.
messageLengthulongThe total number of input bytes consumed before this call. Not used by Ascon padding.
destinationSpan<byte>The span receiving the padded block or blocks; at least two blocks long.
Returns
- int
An 8-byte array containing the residual bytes followed by
0x01at the next position and zero bytes thereafter, matching the little-endian word representation used throughout the Ascon sponge state.
ProcessBlock(ReadOnlySpan<byte>)
Absorbs a single 8-byte rate block into the sponge state and applies the Ascon-p permutation. Full message blocks use the configured absorption round count; the final padded block always uses 12 rounds to match the reference squeeze initialization.
protected override void ProcessBlock(ReadOnlySpan<byte> block)
Parameters
blockReadOnlySpan<byte>The 8-byte input block to absorb. Its length must equal the configured block size.
ProcessFinalBlock()
Squeezes the 256-bit hash output from the sponge state by extracting four successive 64-bit words, with
_absorptionRounds Ascon-p permutation rounds applied between each extraction.
protected override byte[] ProcessFinalBlock()
Returns
- byte[]
A 32-byte array containing the final hash digest.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |