Table of Contents

Blake2s Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Blake2s.cs

Computes a hash using the BLAKE2s cryptographic hash algorithm, designed by Jean-Philippe Aumasson, Samuel Neves, Zooko Wilcox-O'Hearn, and Christian Winnerlein. Supports output sizes of 128, 160, 192, 224, or 256 bits. This class cannot be inherited.

public sealed class Blake2s : KeyedDeferredFinalBlockHashAlgorithm, ICryptoTransform, IDisposable
Inheritance
Blake2s
Implements
Inherited Members
Extension Methods

Examples

// Unkeyed hash
using var blake2s = new Blake2s(256);
byte[] digest = blake2s.ComputeHash(message);

// Keyed MAC (BLAKE2s-MAC-256)
using var mac = new Blake2s(256) { Key = myKey };
byte[] tag = mac.ComputeHash(message);

Remarks

BLAKE2s is specified in RFC 7693 and is optimized for 8-bit to 32-bit platforms. It operates on 64-byte (512-bit) blocks and maintains eight 32-bit state words, applying 10 rounds of the BLAKE2 G mixing function per block.

This implementation inherits its residual buffer, byte-counter and lookahead-buffering loop from KeyedDeferredFinalBlockHashAlgorithm: the final message block is not compressed until HashFinal() is called, at which point the finalization flag is set and the output bytes are serialized in little-endian order then truncated to the configured output length.

Supplying a non-empty Key switches the instance into the keyed BLAKE2s-MAC mode defined in RFC 7693 Section 2.8. The key (1-32 bytes) is zero-padded to 64 bytes and prepended as the first message block, and the key length is encoded into the parameter block so that keyed and unkeyed digests of the same message are always distinct.

Parameters at a glance.

  • Output size: configurable - 128, 160, 192, 224, or 256 bits.
  • Block size: 64 bytes (512 bits); 8 × 32-bit state words; 10 rounds.
  • Optional key: 1-32 bytes for BLAKE2s-MAC mode (RFC 7693 §2.8).
  • Specification: RFC 7693; optimized for 8/16/32-bit hosts.

When to choose BLAKE2s. Pick BLAKE2s on 32-bit hosts, embedded targets, or any time the output is at most 32 bytes - the 32-bit-word design beats Blake2b on those platforms. On 64-bit hosts and for outputs longer than 32 bytes, Blake2b is faster. For very large parallel workloads Blake3 is faster still and supports tree hashing natively.

Constructors

Blake2s()

Initializes a new instance of the Blake2s class with a 256-bit output hash size.

public Blake2s()

Blake2s(int)

Initializes a new instance of the Blake2s class with the specified output size.

public Blake2s(int hashSize)

Parameters

hashSize int

The desired output size in bits. Must be one of 128, 160, 192, 224, or 256.

Exceptions

ArgumentOutOfRangeException

hashSize is not one of the supported output sizes.

Fields

MaxKeySize

Maximum accepted key length for the keyed BLAKE2s-MAC mode is 256 bits (32 bytes).

public const int MaxKeySize = 256

Field Value

int

Properties

AlgorithmName

Gets the canonical, fully-qualified algorithm name for this instance, including any size or variant qualifiers (for example, "Tiger/192", "Skein-512-256", "BLAKE2b-512", "ASCON-HASH256", "SipHash-2-4-64").

public override string AlgorithmName { get; }

Property Value

string

A string identifying the algorithm and its current configuration.

Remarks

Derived classes implement this property to expose a stable, consumer-facing identifier suitable for logging, telemetry, registry keys, or interop with hash-name catalogues. Implementations should be pure and side-effect-free - the value may be queried before any input has been consumed and after disposal as part of error reporting.

CanReuseTransform

Gets a value indicating whether the current transform can be reused.

public override bool CanReuseTransform { get; }

Property Value

bool

Always true.

CanTransformMultipleBlocks

When overridden in a derived class, gets a value indicating whether multiple blocks can be transformed.

public override bool CanTransformMultipleBlocks { get; }

Property Value

bool

true if multiple blocks can be transformed; otherwise, false.

HashSize

Gets or sets the size, in bits, of the final computed hash output.

public int HashSize { get; set; }

Property Value

int

The output size in bits; must be one of 128, 160, 192, 224, or 256.

Remarks

The full BLAKE2s compression is always run using all 256 bits of internal state. Shorter output lengths are produced by truncating the serialized state after finalization. The property may only be changed before hashing has begun; once TransformBlock(byte[], int, int, byte[], int) or a ComputeHash overload has been called, the value is immutable until Initialize() is called.

Exceptions

ArgumentOutOfRangeException

The assigned value is not one of 128, 160, 192, 224, or 256.

ObjectDisposedException

The algorithm instance has been disposed.

CryptographicUnexpectedOperationException

A hash computation is already in progress.

Methods

Dispose(bool)

Releases the unmanaged resources used by the HashAlgorithm and optionally releases the managed resources.

protected override void Dispose(bool disposing)

Parameters

disposing bool

true to release both managed and unmanaged resources; false to release only unmanaged resources.

Remarks

Clears the chaining state, releases the framework HashValue array, and zeros HashSizeValue when disposing is true.

Retained key material owned by KeyedDeferredFinalBlockHashAlgorithm is cleared by the base implementation when this method delegates to base.Dispose(disposing). The inherited residual buffer is cleared further down the dispose chain.

InitializeHashState()

Resets the algorithm-specific chaining variables to their initialization values and encodes any configuration parameters (such as digest length and key length) into the parameter block. Called by the sealed Initialize() before key-block injection.

protected override void InitializeHashState()

Remarks

Implementations should read KeyValue to determine the key length (kk) for parameter-block encoding, as KeyValue is already updated to the new value before Initialize() runs.

ProcessBlock(ReadOnlySpan<byte>, ulong, bool)

Compresses a single 64-byte block using the BLAKE2s F compression function. Invoked by DeferredFinalBlockHashAlgorithm with isFinal set to true for the last call (which inverts the finalization flag word) and to false otherwise.

protected override void ProcessBlock(ReadOnlySpan<byte> block, ulong totalBytesIncludingThisBlock, bool isFinal)

Parameters

block ReadOnlySpan<byte>

The 64-byte block to compress.

totalBytesIncludingThisBlock ulong

The cumulative byte count including the bytes in block. Used as the per-block counter (the BLAKE2 t0 / t1 input pair).

isFinal bool

true if this is the final block; causes the finalization flag word to be inverted.

Remarks

Compression runs on the kernel Bodu.Security.Cryptography.Blake2sCore selects: AVX-512, then SSSE3 on x64, and the scalar kernel on ARM64, where it ran faster than the AdvSimd kernel, and everywhere else; each gate honors the process-wide SIMD opt-out.

ProcessFinalBlock()

Extracts the digest from the algorithm's chaining variables after ProcessBlock(ReadOnlySpan<byte>, ulong, bool) has been called with isFinal: true for the last time.

protected override byte[] ProcessFinalBlock()

Returns

byte[]

A byte array containing the final computed hash value.

Remarks

This method is invoked once per HashFinal() call, immediately after the final compression. It reads from the internal hash state and serializes the result to a byte array in the format expected by consumers of the algorithm (typically little-endian for Blake-family hashes).

Applies to

ProductVersions
.NET8, 10

See Also