AsconXof<T> Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- AsconXof{T}.cs
Abstract base class for ASCON extendable output functions (XOFs) as defined in NIST SP 800-232. Implements the shared sponge construction, residual-buffer management, padding, and Ascon-p permutation used by AsconXof128 and AsconCxof128.
public abstract class AsconXof<T> : IDisposable where T : AsconXof<T>, new()
Type Parameters
TThe concrete XOF type derived from this class.
- Inheritance
-
AsconXof<T>
- Implements
- Derived
- Inherited Members
- Extension Methods
Examples
// Consume through a concrete derivative - produce a 32-byte digest from "hello".
using var xof = new AsconXof128();
xof.Absorb("hello"u8);
byte[] digest = new byte[32];
xof.Squeeze(digest);
// Squeeze additional output of any length - the XOF can produce as many bytes as needed.
byte[] more = new byte[64];
xof.Squeeze(more);
// Reuse the instance for a new message via Initialize.
xof.Initialize();
xof.Absorb("world"u8);
xof.Squeeze(digest);
Remarks
All ASCON XOF algorithms share a 320-bit internal state of five 64-bit words, a 64-bit (8-byte) rate, and a variable-length output. They differ in their pre-computed initialization state, in the number of absorption rounds (pb), and in whether a customization string may be supplied before absorption.
The lifecycle of an instance is:
- Optionally customize (only AsconCxof128).
- Call Absorb(ReadOnlySpan<byte>) zero or more times to supply input data.
- Call Squeeze(Span<byte>) one or more times to produce output of any length. Once squeezing has begun, no further data may be absorbed.
- Call Initialize() to reset the instance and reuse it for a new message.
Padding follows the Ascon convention: the byte immediately after the last absorbed byte is XORed with 0x01,
and the remaining rate bytes retain their current state values. The transition from absorption to squeezing always
applies the full 12-round permutation (Ascon-p12). Subsequent squeeze blocks use pb rounds between extractions.
Don't derive from this class directly. Use one of the two concrete XOFs that extend it:
- AsconXof128Plain Ascon XOF - variable-length output without a customization string.
- AsconCxof128 Customizable Ascon XOF - accepts a customization string before absorption to domain-separate output families.
For fixed-length Ascon hashing use AsconHash256 or AsconHashA256; for the AEAD member of the Ascon suite use AsconAead128.
The concrete type T must expose a public parameterless constructor to satisfy the base
class's new() constraint.
Constructors
AsconXof(ulong, ulong, ulong, ulong, ulong, int, string)
Initializes a new instance of the AsconXof<T> class with the specified algorithm parameters.
protected AsconXof(ulong iv0, ulong iv1, ulong iv2, ulong iv3, ulong iv4, int absorptionRounds, string algorithmName)
Parameters
iv0ulongPre-computed initial state word 0 (result of applying Ascon-p12 to the raw IV).
iv1ulongPre-computed initial state word 1.
iv2ulongPre-computed initial state word 2.
iv3ulongPre-computed initial state word 3.
iv4ulongPre-computed initial state word 4.
absorptionRoundsintNumber of Ascon-p rounds applied after each absorbed block and between squeeze blocks. Must be between 1 and 12.
algorithmNamestringThe canonical algorithm identifier string as defined in NIST SP 800-232. Must not be null.
Exceptions
- ArgumentNullException
algorithmNameis null.- ArgumentOutOfRangeException
absorptionRoundsis less than 1 or greater than 12.
Properties
AlgorithmName
Gets the canonical algorithm name for this XOF variant as defined in NIST SP 800-232.
public string AlgorithmName { get; }
Property Value
- string
A string such as
"ASCON-XOF128"or"ASCON-CXOF128".
Exceptions
- ObjectDisposedException
The instance has been disposed.
Methods
Absorb(ReadOnlySpan<byte>)
Absorbs data into the sponge state. May be called multiple times before the first
Squeeze(Span<byte>).
public virtual void Absorb(ReadOnlySpan<byte> data)
Parameters
dataReadOnlySpan<byte>The input data to absorb. May be empty.
Exceptions
- ObjectDisposedException
The instance has been disposed.
- InvalidOperationException
Squeeze(Span<byte>) has already been called; call Initialize() to reset and start over.
Create()
Creates a new instance of T using its public parameterless constructor.
public static T Create()
Returns
- T
A new, uninitialized
Tinstance.
Dispose()
Releases the resources used by this instance and clears the internal sponge state.
public void Dispose()
Dispose(bool)
Releases managed resources and clears the sponge state.
protected virtual void Dispose(bool disposing)
Parameters
FinalizeAbsorptionPhase()
Finalizes a sponge absorption phase by padding the residual buffer with 0x01 at the next unused byte
position, absorbing the padded block, and applying Bodu.Security.Cryptography.AsconXof`1._absorptionRounds Ascon-p rounds. Resets the
residual counter to zero so that the next call to Absorb(ReadOnlySpan<byte>) starts from a clean state.
protected void FinalizeAbsorptionPhase()
Remarks
Derived classes (specifically AsconCxof128) call this to close the customization phase before injecting a domain-separation constant.
GetHash(int)
Squeezes exactly outputLength bytes and returns them as a new array.
public byte[] GetHash(int outputLength)
Parameters
outputLengthintThe number of bytes to produce. Must be greater than zero.
Returns
- byte[]
A new byte array of length
outputLengthcontaining the squeezed output.
Exceptions
- ObjectDisposedException
The instance has been disposed.
- ArgumentOutOfRangeException
outputLengthis less than or equal to zero.
HashData(ReadOnlySpan<byte>, int)
Hashes source in a single pass and returns outputLength bytes.
public static byte[] HashData(ReadOnlySpan<byte> source, int outputLength)
Parameters
sourceReadOnlySpan<byte>The input data to hash.
outputLengthintThe number of output bytes to produce. Must be greater than zero.
Returns
- byte[]
A byte array of length
outputLengthcontaining the XOF output.
Exceptions
- ArgumentOutOfRangeException
outputLengthis less than or equal to zero.
Initialize()
Resets the instance to its initial state, discarding any absorbed data or squeezed output, so that it is ready to accept a new message.
public virtual void Initialize()
Exceptions
- ObjectDisposedException
The instance has been disposed.
Squeeze(Span<byte>)
Squeezes output.Length bytes from the sponge into output. May be
called multiple times to produce an unbounded output stream.
public void Squeeze(Span<byte> output)
Parameters
Exceptions
- ObjectDisposedException
The instance has been disposed.
ThrowIfDisposed()
Throws an ObjectDisposedException if the algorithm instance has been disposed.
protected void ThrowIfDisposed()
Exceptions
- ObjectDisposedException
Thrown when any public method or property is accessed after the instance has been disposed.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |