Table of Contents

Blake2b Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Blake2b.cs

Computes a hash using the BLAKE2b cryptographic hash algorithm, designed by Jean-Philippe Aumasson, Samuel Neves, Zooko Wilcox-O'Hearn, and Christian Winnerlein. Supports output sizes of 128, 160, 192, 224, 256, 384, or 512 bits. This class cannot be inherited.

public sealed class Blake2b : KeyedDeferredFinalBlockHashAlgorithm, ICryptoTransform, IDisposable
Inheritance
Blake2b
Implements
Inherited Members
Extension Methods

Examples

// Unkeyed hash
using var blake2b = new Blake2b(512);
byte[] digest = blake2b.ComputeHash(message);

// Keyed MAC (BLAKE2b-MAC-512)
using var mac = new Blake2b(512) { Key = myKey };
byte[] tag = mac.ComputeHash(message);

Remarks

BLAKE2b is specified in RFC 7693 and is optimized for 64-bit platforms. It operates on 128-byte (1024-bit) blocks and maintains eight 64-bit state words, applying 12 rounds of the BLAKE2 G mixing function per block.

This implementation inherits its residual buffer, byte-counter and lookahead-buffering loop from KeyedDeferredFinalBlockHashAlgorithm: the final message block is not compressed until HashFinal() is called, at which point the finalization flag is set and the output bytes are serialized in little-endian order then truncated to the configured output length.

Supplying a non-empty Key switches the instance into the keyed BLAKE2b-MAC mode defined in RFC 7693 Section 2.8. The key (1-64 bytes) is zero-padded to 128 bytes and prepended as the first message block, and the key length is encoded into the parameter block so that keyed and unkeyed digests of the same message are always distinct.

Parameters at a glance.

  • Output size: configurable - 128, 160, 192, 224, 256, 384, or 512 bits.
  • Block size: 128 bytes (1024 bits); 8 × 64-bit state words; 12 rounds.
  • Optional key: 1-64 bytes for BLAKE2b-MAC mode (RFC 7693 §2.8).
  • Specification: RFC 7693; optimized for 64-bit hosts.

When to choose BLAKE2b. The right pick on 64-bit platforms when SHA-2 / SHA-3 throughput matters but compatibility with those standards is not required - BLAKE2b is faster than SHA-512 in software while offering the same security level. Use Blake2s on 32-bit hosts or for output sizes up to 32 bytes. For tree-hashing or genuinely large parallel workloads Blake3 is faster again. As a keyed MAC, BLAKE2b-MAC is competitive with HMAC-SHA-256 / Poly1305 and avoids the double-hash overhead of HMAC.

Constructors

Blake2b()

Initializes a new instance of the Blake2b class with a 512-bit output hash size.

public Blake2b()

Blake2b(int)

Initializes a new instance of the Blake2b class with the specified output size.

public Blake2b(int hashSize)

Parameters

hashSize int

The desired output size in bits. Must be one of 128, 160, 192, 224, 256, 384, or 512.

Exceptions

ArgumentOutOfRangeException

hashSize is not one of the supported output sizes.

Fields

MaxKeySize

Maximum accepted key length for the keyed BLAKE2b-MAC mode is 512 bits (64 bytes).

public const int MaxKeySize = 512

Field Value

int

Properties

AlgorithmName

Gets the canonical, fully-qualified algorithm name for this instance, including any size or variant qualifiers (for example, "Tiger/192", "Skein-512-256", "BLAKE2b-512", "ASCON-HASH256", "SipHash-2-4-64").

public override string AlgorithmName { get; }

Property Value

string

A string identifying the algorithm and its current configuration.

Remarks

Derived classes implement this property to expose a stable, consumer-facing identifier suitable for logging, telemetry, registry keys, or interop with hash-name catalogues. Implementations should be pure and side-effect-free - the value may be queried before any input has been consumed and after disposal as part of error reporting.

CanReuseTransform

Gets a value indicating whether the current transform can be reused.

public override bool CanReuseTransform { get; }

Property Value

bool

Always true.

CanTransformMultipleBlocks

When overridden in a derived class, gets a value indicating whether multiple blocks can be transformed.

public override bool CanTransformMultipleBlocks { get; }

Property Value

bool

true if multiple blocks can be transformed; otherwise, false.

HashSize

Gets or sets the size, in bits, of the final computed hash output.

public int HashSize { get; set; }

Property Value

int

The output size in bits; must be one of 128, 160, 192, 224, 256, 384, or 512.

Remarks

The full BLAKE2b compression is always run using all 512 bits of internal state. Shorter output lengths are produced by truncating the serialized state after finalization. The property may only be changed before hashing has begun; once TransformBlock(byte[], int, int, byte[], int) or a ComputeHash overload has been called, the value is immutable until Initialize() is called.

Exceptions

ArgumentOutOfRangeException

The assigned value is not one of 128, 160, 192, 224, 256, 384, or 512.

ObjectDisposedException

The algorithm instance has been disposed.

CryptographicUnexpectedOperationException

A hash computation is already in progress.

Methods

Dispose(bool)

Releases the unmanaged resources used by the HashAlgorithm and optionally releases the managed resources.

protected override void Dispose(bool disposing)

Parameters

disposing bool

true to release both managed and unmanaged resources; false to release only unmanaged resources.

Remarks

Clears the chaining state, releases the framework HashValue array, and zeros HashSizeValue when disposing is true.

Retained key material owned by KeyedDeferredFinalBlockHashAlgorithm is cleared by the base implementation when this method delegates to base.Dispose(disposing). The inherited residual buffer is cleared further down the dispose chain.

InitializeHashState()

Resets the algorithm-specific chaining variables to their initialization values and encodes any configuration parameters (such as digest length and key length) into the parameter block. Called by the sealed Initialize() before key-block injection.

protected override void InitializeHashState()

Remarks

Implementations should read KeyValue to determine the key length (kk) for parameter-block encoding, as KeyValue is already updated to the new value before Initialize() runs.

ProcessBlock(ReadOnlySpan<byte>, ulong, bool)

Compresses a single 128-byte block using the BLAKE2b F compression function. Invoked by DeferredFinalBlockHashAlgorithm with isFinal set to true for the last call (which inverts the finalization flag word) and to false otherwise.

protected override void ProcessBlock(ReadOnlySpan<byte> block, ulong totalBytesIncludingThisBlock, bool isFinal)

Parameters

block ReadOnlySpan<byte>

The 128-byte block to compress.

totalBytesIncludingThisBlock ulong

The cumulative byte count including the bytes in block. Used as the per-block counter (the BLAKE2 t0 input).

isFinal bool

true if this is the final block; causes the finalization flag word to be inverted.

Remarks

Compression runs on the kernel Bodu.Security.Cryptography.Blake2bCore selects: AVX-512, then AVX2, then SSSE3 on x64, and the scalar kernel on ARM64, where it ran faster than the AdvSimd kernel, and everywhere else; each gate honors the process-wide SIMD opt-out.

ProcessFinalBlock()

Extracts the digest from the algorithm's chaining variables after ProcessBlock(ReadOnlySpan<byte>, ulong, bool) has been called with isFinal: true for the last time.

protected override byte[] ProcessFinalBlock()

Returns

byte[]

A byte array containing the final computed hash value.

Remarks

This method is invoked once per HashFinal() call, immediately after the final compression. It reads from the internal hash state and serializes the result to a byte array in the format expected by consumers of the algorithm (typically little-endian for Blake-family hashes).

Applies to

ProductVersions
.NET8, 10

See Also