Table of Contents

AsconHash Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
AsconHash.cs

Abstract base class for ASCON cryptographic hash algorithms as defined in NIST SP 800-232. Implements the shared sponge construction, padding, and Ascon-p permutation used by all fixed-output ASCON hash variants.

public abstract class AsconHash : BlockHashAlgorithm, ICryptoTransform, IDisposable
Inheritance
AsconHash
Implements
Derived
Inherited Members
Extension Methods

Remarks

All ASCON hash algorithms share a 320-bit internal state comprising five 64-bit words, a 64-bit (8-byte) rate, and a 256-bit output. They differ in their pre-computed initialization state and in the number of Ascon-p rounds applied after each absorbed block. The initial squeeze always uses the full 12-round permutation (Ascon-p12); subsequent squeeze blocks use the same round count as absorption.

Padding follows the Ascon convention: the byte immediately after the last input byte is set to 0x01 (the little-endian sentinel bit), and the remaining rate bytes are zero. A padding block is always appended, even when the message length is a multiple of the eight-byte rate.

Concrete derived types supply the five pre-computed post-initialization state words and the absorption round count via the protected constructor. No further overrides are required.

Constructors

AsconHash(ulong, ulong, ulong, ulong, ulong, int, string)

Initializes a new instance of the AsconHash class with the specified algorithm parameters.

protected AsconHash(ulong iv0, ulong iv1, ulong iv2, ulong iv3, ulong iv4, int absorptionRounds, string algorithmName)

Parameters

iv0 ulong

Pre-computed initial state word 0 (result of applying Ascon-p12 to the raw IV).

iv1 ulong

Pre-computed initial state word 1.

iv2 ulong

Pre-computed initial state word 2.

iv3 ulong

Pre-computed initial state word 3.

iv4 ulong

Pre-computed initial state word 4.

absorptionRounds int

The number of Ascon-p rounds applied after each absorbed block. Must be between 1 and 12 inclusive.

algorithmName string

The canonical algorithm identifier string as defined in NIST SP 800-232. Must not be null.

Exceptions

ArgumentNullException

algorithmName is null.

ArgumentOutOfRangeException

absorptionRounds is less than 1 or greater than 12.

Properties

AlgorithmName

Gets the canonical algorithm name for this hash function variant as defined in NIST SP 800-232.

public override string AlgorithmName { get; }

Property Value

string

A string such as "ASCON-HASH256" or "ASCON-HASHA256" identifying the variant.

Exceptions

ObjectDisposedException

The algorithm instance has been disposed.

CanReuseTransform

Gets a value indicating whether the current transform can be reused.

public override bool CanReuseTransform { get; }

Property Value

bool

Always true.

CanTransformMultipleBlocks

When overridden in a derived class, gets a value indicating whether multiple blocks can be transformed.

public override bool CanTransformMultipleBlocks { get; }

Property Value

bool

true if multiple blocks can be transformed; otherwise, false.

Methods

Dispose(bool)

Releases the resources used by this instance and clears the internal sponge state.

protected override void Dispose(bool disposing)

Parameters

disposing bool

true to release both managed and unmanaged resources; false to release only unmanaged resources.

Initialize()

Resets the algorithm to its initial state by clearing the residual buffer and the running byte total. Derived classes override this method, call base.Initialize() first, and then reset their own algorithm-specific state (chaining variables, IV, key-derived schedule).

public override void Initialize()

Remarks

This method does not reset the State property explicitly on .NET 6+ targets — the framework manages that transition. On earlier targets, derived classes that need the already-finalized guard should reset their _finalized backing field from their own Initialize override.

Derived classes that need to validate state before the reset (for example, a keyed MAC that refuses to be re-initialized when no key has been set) should perform that validation before calling base.Initialize(). Once the base call returns, the residual buffer is empty, Bodu.Security.Cryptography.BufferedBlockHashAlgorithm._residualBytes is 0, and Bodu.Security.Cryptography.BufferedBlockHashAlgorithm._totalBytes is 0.

Exceptions

ObjectDisposedException

The instance has been disposed.

PadBlock(ReadOnlySpan<byte>, ulong, Span<byte>)

Pads the final partial input block according to the Ascon padding rule.

protected override int PadBlock(ReadOnlySpan<byte> block, ulong messageLength, Span<byte> destination)

Parameters

block ReadOnlySpan<byte>

The residual input bytes (zero to seven bytes) remaining after all complete 8-byte blocks have been processed.

messageLength ulong

The total number of input bytes consumed before this call. Not used by Ascon padding.

destination Span<byte>

The span receiving the padded block or blocks; at least two blocks long.

Returns

int

An 8-byte array containing the residual bytes followed by 0x01 at the next position and zero bytes thereafter, matching the little-endian word representation used throughout the Ascon sponge state.

ProcessBlock(ReadOnlySpan<byte>)

Absorbs a single 8-byte rate block into the sponge state and applies the Ascon-p permutation. Full message blocks use the configured absorption round count; the final padded block always uses 12 rounds to match the reference squeeze initialization.

protected override void ProcessBlock(ReadOnlySpan<byte> block)

Parameters

block ReadOnlySpan<byte>

The 8-byte input block to absorb. Its length must equal the configured block size.

ProcessFinalBlock()

Squeezes the 256-bit hash output from the sponge state by extracting four successive 64-bit words, with _absorptionRounds Ascon-p permutation rounds applied between each extraction.

protected override byte[] ProcessFinalBlock()

Returns

byte[]

A 32-byte array containing the final hash digest.

Applies to

ProductVersions
.NET8, 10