Blake2b Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- Blake2b.cs
Computes a hash using the BLAKE2b cryptographic hash algorithm, designed by Jean-Philippe Aumasson, Samuel
Neves, Zooko Wilcox-O'Hearn, and Christian Winnerlein. Supports output sizes of 128, 160, 192, 224, 256, 384, or 512
bits. This class cannot be inherited.
public sealed class Blake2b : KeyedDeferredFinalBlockHashAlgorithm, ICryptoTransform, IDisposable
- Inheritance
-
Blake2b
- Implements
- Inherited Members
- Extension Methods
Examples
// Unkeyed hash
using var blake2b = new Blake2b(512);
byte[] digest = blake2b.ComputeHash(message);
// Keyed MAC (BLAKE2b-MAC-512)
using var mac = new Blake2b(512) { Key = myKey };
byte[] tag = mac.ComputeHash(message);
Remarks
BLAKE2b is specified in RFC 7693 and is optimized for
64-bit platforms. It operates on 128-byte (1024-bit) blocks and maintains eight 64-bit state words, applying 12
rounds of the BLAKE2 G mixing function per block.
This implementation inherits its residual buffer, byte-counter and lookahead-buffering loop from
KeyedDeferredFinalBlockHashAlgorithm: the final message block is not compressed until
HashFinal() is called, at which point the finalization flag is set and the output
bytes are serialized in little-endian order then truncated to the configured output length.
Supplying a non-empty Key switches the instance into the keyed
BLAKE2b-MAC mode defined in RFC 7693 Section 2.8. The key (1-64 bytes) is zero-padded to 128 bytes and
prepended as the first message block, and the key length is encoded into the parameter block so that keyed and
unkeyed digests of the same message are always distinct.
Parameters at a glance.
- Output size: configurable - 128, 160, 192, 224, 256, 384, or 512 bits.
- Block size: 128 bytes (1024 bits); 8 × 64-bit state words; 12 rounds.
- Optional key: 1-64 bytes for BLAKE2b-MAC mode (RFC 7693 §2.8).
- Specification: RFC 7693; optimized for 64-bit hosts.
When to choose BLAKE2b. The right pick on 64-bit platforms when SHA-2 / SHA-3 throughput matters but compatibility with those standards is not required - BLAKE2b is faster than SHA-512 in software while offering the same security level. Use Blake2s on 32-bit hosts or for output sizes up to 32 bytes. For tree-hashing or genuinely large parallel workloads Blake3 is faster again. As a keyed MAC, BLAKE2b-MAC is competitive with HMAC-SHA-256 / Poly1305 and avoids the double-hash overhead of HMAC.
Constructors
Blake2b()
Initializes a new instance of the Blake2b class with a 512-bit output hash size.
public Blake2b()
Blake2b(int)
Initializes a new instance of the Blake2b class with the specified output size.
public Blake2b(int hashSize)
Parameters
hashSizeintThe desired output size in bits. Must be one of 128, 160, 192, 224, 256, 384, or 512.
Exceptions
- ArgumentOutOfRangeException
hashSizeis not one of the supported output sizes.
Fields
MaxKeySize
Maximum accepted key length for the keyed BLAKE2b-MAC mode is 512 bits (64 bytes).
public const int MaxKeySize = 512
Field Value
Properties
AlgorithmName
Gets the canonical, fully-qualified algorithm name for this instance, including any size or variant qualifiers
(for example, "Tiger/192", "Skein-512-256", "BLAKE2b-512", "ASCON-HASH256",
"SipHash-2-4-64").
public override string AlgorithmName { get; }
Property Value
- string
A string identifying the algorithm and its current configuration.
Remarks
Derived classes implement this property to expose a stable, consumer-facing identifier suitable for logging, telemetry, registry keys, or interop with hash-name catalogues. Implementations should be pure and side-effect-free - the value may be queried before any input has been consumed and after disposal as part of error reporting.
CanReuseTransform
Gets a value indicating whether the current transform can be reused.
public override bool CanReuseTransform { get; }
Property Value
CanTransformMultipleBlocks
When overridden in a derived class, gets a value indicating whether multiple blocks can be transformed.
public override bool CanTransformMultipleBlocks { get; }
Property Value
HashSize
Gets or sets the size, in bits, of the final computed hash output.
public int HashSize { get; set; }
Property Value
- int
The output size in bits; must be one of 128, 160, 192, 224, 256, 384, or 512.
Remarks
The full BLAKE2b compression is always run using all 512 bits of internal state. Shorter output lengths are
produced by truncating the serialized state after finalization. The property may only be changed before hashing
has begun; once TransformBlock(byte[], int, int, byte[], int) or a ComputeHash overload has been called,
the value is immutable until Initialize() is called.
Exceptions
- ArgumentOutOfRangeException
The assigned value is not one of 128, 160, 192, 224, 256, 384, or 512.
- ObjectDisposedException
The algorithm instance has been disposed.
- CryptographicUnexpectedOperationException
A hash computation is already in progress.
Methods
Dispose(bool)
Releases the unmanaged resources used by the HashAlgorithm and optionally releases the managed resources.
protected override void Dispose(bool disposing)
Parameters
disposingbooltrue to release both managed and unmanaged resources; false to release only unmanaged resources.
Remarks
Clears the chaining state, releases the framework HashValue array, and zeros
HashSizeValue when disposing is true.
Retained key material owned by KeyedDeferredFinalBlockHashAlgorithm is cleared by the base
implementation when this method delegates to base.Dispose(disposing). The inherited residual buffer is
cleared further down the dispose chain.
InitializeHashState()
Resets the algorithm-specific chaining variables to their initialization values and encodes any configuration parameters (such as digest length and key length) into the parameter block. Called by the sealed Initialize() before key-block injection.
protected override void InitializeHashState()
Remarks
Implementations should read KeyValue to determine the key length (kk) for parameter-block
encoding, as KeyValue is already updated to the new value before Initialize() runs.
ProcessBlock(ReadOnlySpan<byte>, ulong, bool)
Compresses a single 128-byte block using the BLAKE2b F compression function. Invoked by
DeferredFinalBlockHashAlgorithm with isFinal set to true
for the last call (which inverts the finalization flag word) and to false otherwise.
protected override void ProcessBlock(ReadOnlySpan<byte> block, ulong totalBytesIncludingThisBlock, bool isFinal)
Parameters
blockReadOnlySpan<byte>The 128-byte block to compress.
totalBytesIncludingThisBlockulongThe cumulative byte count including the bytes in
block. Used as the per-block counter (the BLAKE2t0input).isFinalbooltrue if this is the final block; causes the finalization flag word to be inverted.
Remarks
Compression runs on the kernel Bodu.Security.Cryptography.Blake2bCore selects: AVX-512, then AVX2, then SSSE3 on x64, and the scalar kernel on ARM64, where it ran faster than the AdvSimd kernel, and everywhere else; each gate honors the process-wide SIMD opt-out.
ProcessFinalBlock()
Extracts the digest from the algorithm's chaining variables after ProcessBlock(ReadOnlySpan<byte>, ulong, bool) has been called
with isFinal: true for the last time.
protected override byte[] ProcessFinalBlock()
Returns
- byte[]
A byte array containing the final computed hash value.
Remarks
This method is invoked once per HashFinal() call, immediately after the final compression. It reads from the internal hash state and serializes the result to a byte array in the format expected by consumers of the algorithm (typically little-endian for Blake-family hashes).
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |