Blake2s Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- Blake2s.cs
Computes a hash using the BLAKE2s cryptographic hash algorithm, designed by Jean-Philippe Aumasson, Samuel
Neves, Zooko Wilcox-O'Hearn, and Christian Winnerlein. Supports output sizes of 128, 160, 192, 224, or 256 bits.
This class cannot be inherited.
public sealed class Blake2s : KeyedDeferredFinalBlockHashAlgorithm, ICryptoTransform, IDisposable
- Inheritance
-
Blake2s
- Implements
- Inherited Members
- Extension Methods
Examples
// Unkeyed hash
using var blake2s = new Blake2s(256);
byte[] digest = blake2s.ComputeHash(message);
// Keyed MAC (BLAKE2s-MAC-256)
using var mac = new Blake2s(256) { Key = myKey };
byte[] tag = mac.ComputeHash(message);
Remarks
BLAKE2s is specified in RFC 7693 and is optimized for 8-bit
to 32-bit platforms. It operates on 64-byte (512-bit) blocks and maintains eight 32-bit state words, applying 10
rounds of the BLAKE2 G mixing function per block.
This implementation inherits its residual buffer, byte-counter and lookahead-buffering loop from
KeyedDeferredFinalBlockHashAlgorithm: the final message block is not compressed until
HashFinal() is called, at which point the finalization flag is set and the output
bytes are serialized in little-endian order then truncated to the configured output length.
Supplying a non-empty Key switches the instance into the keyed
BLAKE2s-MAC mode defined in RFC 7693 Section 2.8. The key (1-32 bytes) is zero-padded to 64 bytes and
prepended as the first message block, and the key length is encoded into the parameter block so that keyed and
unkeyed digests of the same message are always distinct.
Parameters at a glance.
- Output size: configurable - 128, 160, 192, 224, or 256 bits.
- Block size: 64 bytes (512 bits); 8 × 32-bit state words; 10 rounds.
- Optional key: 1-32 bytes for BLAKE2s-MAC mode (RFC 7693 §2.8).
- Specification: RFC 7693; optimized for 8/16/32-bit hosts.
When to choose BLAKE2s. Pick BLAKE2s on 32-bit hosts, embedded targets, or any time the output is at most 32 bytes - the 32-bit-word design beats Blake2b on those platforms. On 64-bit hosts and for outputs longer than 32 bytes, Blake2b is faster. For very large parallel workloads Blake3 is faster still and supports tree hashing natively.
Constructors
Blake2s()
Initializes a new instance of the Blake2s class with a 256-bit output hash size.
public Blake2s()
Blake2s(int)
Initializes a new instance of the Blake2s class with the specified output size.
public Blake2s(int hashSize)
Parameters
hashSizeintThe desired output size in bits. Must be one of 128, 160, 192, 224, or 256.
Exceptions
- ArgumentOutOfRangeException
hashSizeis not one of the supported output sizes.
Fields
MaxKeySize
Maximum accepted key length for the keyed BLAKE2s-MAC mode is 256 bits (32 bytes).
public const int MaxKeySize = 256
Field Value
Properties
AlgorithmName
Gets the canonical, fully-qualified algorithm name for this instance, including any size or variant qualifiers
(for example, "Tiger/192", "Skein-512-256", "BLAKE2b-512", "ASCON-HASH256",
"SipHash-2-4-64").
public override string AlgorithmName { get; }
Property Value
- string
A string identifying the algorithm and its current configuration.
Remarks
Derived classes implement this property to expose a stable, consumer-facing identifier suitable for logging, telemetry, registry keys, or interop with hash-name catalogues. Implementations should be pure and side-effect-free - the value may be queried before any input has been consumed and after disposal as part of error reporting.
CanReuseTransform
Gets a value indicating whether the current transform can be reused.
public override bool CanReuseTransform { get; }
Property Value
CanTransformMultipleBlocks
When overridden in a derived class, gets a value indicating whether multiple blocks can be transformed.
public override bool CanTransformMultipleBlocks { get; }
Property Value
HashSize
Gets or sets the size, in bits, of the final computed hash output.
public int HashSize { get; set; }
Property Value
- int
The output size in bits; must be one of 128, 160, 192, 224, or 256.
Remarks
The full BLAKE2s compression is always run using all 256 bits of internal state. Shorter output lengths are
produced by truncating the serialized state after finalization. The property may only be changed before hashing
has begun; once TransformBlock(byte[], int, int, byte[], int) or a ComputeHash overload has been called,
the value is immutable until Initialize() is called.
Exceptions
- ArgumentOutOfRangeException
The assigned value is not one of 128, 160, 192, 224, or 256.
- ObjectDisposedException
The algorithm instance has been disposed.
- CryptographicUnexpectedOperationException
A hash computation is already in progress.
Methods
Dispose(bool)
Releases the unmanaged resources used by the HashAlgorithm and optionally releases the managed resources.
protected override void Dispose(bool disposing)
Parameters
disposingbooltrue to release both managed and unmanaged resources; false to release only unmanaged resources.
Remarks
Clears the chaining state, releases the framework HashValue array, and zeros
HashSizeValue when disposing is true.
Retained key material owned by KeyedDeferredFinalBlockHashAlgorithm is cleared by the base
implementation when this method delegates to base.Dispose(disposing). The inherited residual buffer is
cleared further down the dispose chain.
InitializeHashState()
Resets the algorithm-specific chaining variables to their initialization values and encodes any configuration parameters (such as digest length and key length) into the parameter block. Called by the sealed Initialize() before key-block injection.
protected override void InitializeHashState()
Remarks
Implementations should read KeyValue to determine the key length (kk) for parameter-block
encoding, as KeyValue is already updated to the new value before Initialize() runs.
ProcessBlock(ReadOnlySpan<byte>, ulong, bool)
Compresses a single 64-byte block using the BLAKE2s F compression function. Invoked by
DeferredFinalBlockHashAlgorithm with isFinal set to true
for the last call (which inverts the finalization flag word) and to false otherwise.
protected override void ProcessBlock(ReadOnlySpan<byte> block, ulong totalBytesIncludingThisBlock, bool isFinal)
Parameters
blockReadOnlySpan<byte>The 64-byte block to compress.
totalBytesIncludingThisBlockulongThe cumulative byte count including the bytes in
block. Used as the per-block counter (the BLAKE2t0/t1input pair).isFinalbooltrue if this is the final block; causes the finalization flag word to be inverted.
Remarks
Compression runs on the kernel Bodu.Security.Cryptography.Blake2sCore selects: AVX-512, then SSSE3 on x64, and the scalar kernel on ARM64, where it ran faster than the AdvSimd kernel, and everywhere else; each gate honors the process-wide SIMD opt-out.
ProcessFinalBlock()
Extracts the digest from the algorithm's chaining variables after ProcessBlock(ReadOnlySpan<byte>, ulong, bool) has been called
with isFinal: true for the last time.
protected override byte[] ProcessFinalBlock()
Returns
- byte[]
A byte array containing the final computed hash value.
Remarks
This method is invoked once per HashFinal() call, immediately after the final compression. It reads from the internal hash state and serializes the result to a byte array in the format expected by consumers of the algorithm (typically little-endian for Blake-family hashes).
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |