Blowfish Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- Blowfish.cs
Provides a managed implementation of the Blowfish symmetric block cipher. This class cannot be inherited.
public sealed class Blowfish : ExtendedSymmetricAlgorithm, IDisposable
- Inheritance
-
Blowfish
- Implements
- Inherited Members
- Extension Methods
Examples
using System.Security.Cryptography;
using Bodu.Security.Cryptography;
using Bodu.Security.Cryptography.Extensions;
// Legacy interop only.
using var blowfish = new Blowfish();
blowfish.Key = legacyKeyMaterial; // 4-56 bytes
blowfish.IV = RandomNumberGenerator.GetBytes(8); // matches the 64-bit block
byte[] ciphertext = blowfish.Encrypt(legacyPlaintext);
Remarks
Blowfish is a symmetric-key block cipher designed by Bruce Schneier in 1993. It operates on 64-bit (8-byte) blocks and accepts a variable-length key of between 32 and 448 bits (4 to 56 bytes). The cipher applies a 16-round Feistel network using four 256-entry S-boxes and an 18-entry P-array, all initialized from the hexadecimal digits of pi (π). The key schedule is computationally intensive by design, making brute-force attacks significantly more expensive.
This class integrates with the .NET SymmetricAlgorithm framework and supports standard block cipher modes via the BlockMode property. The default mode is CBC with PKCS7 padding.
For further details on the algorithm, see https://www.schneier.com/academic/blowfish/.
Parameters at a glance.
- Block size: 64 bits (8 bytes).
- Key size: variable, 32-448 bits (4-56 bytes).
- 16-round Feistel network with key-dependent S-boxes initialized from the digits of π.
- Default mode: CBC; default padding: PKCS7.
When to choose Blowfish. Pick Blowfish only for interoperability with legacy systems that already use it - its 64-bit block size invites SWEET32 birthday-bound attacks once roughly 32 GiB has been encrypted under one key. For new designs use Aes; bcrypt-style password hashing schemes that derive from Blowfish are not in scope of this class.
important
Blowfish has a 64-bit block size, which makes it vulnerable to birthday-bound attacks (SWEET32) when large volumes of data are encrypted under the same key. For new applications, a cipher with a 128-bit or larger block size (such as AES) should be preferred.
The underlying block-cipher implementation is constant-time in its control flow, but the four key-dependent S-boxes are read at data-dependent indices on every round. As such, it is not hardened against timing or cache-based side-channel attacks.
Constructors
Blowfish()
Initializes a new instance of the Blowfish class with default parameters.
public Blowfish()
Remarks
The default configuration uses a 64-bit block, a 128-bit (16-byte) key, CBC cipher mode, and PKCS7 padding. Call GenerateKey() and GenerateIV() to produce random key material, or assign Key and IV directly before calling CreateEncryptor(byte[], byte[]?) or CreateDecryptor(byte[], byte[]?).
Methods
Create()
Creates a new Blowfish instance with default parameters.
public static Blowfish Create()
Returns
CreateDecryptor(byte[], byte[]?)
Creates a symmetric Blowfish decryptor using the specified key and initialization vector.
public override ICryptoTransform CreateDecryptor(byte[] rgbKey, byte[]? rgbIV)
Parameters
rgbKeybyte[]The secret key for the symmetric algorithm. Must be between Bodu.Security.Cryptography.Blowfish.MinKeySize and Bodu.Security.Cryptography.Blowfish.MaxKeySize bytes in length. Must not be null.
rgbIVbyte[]The initialization vector. Must be exactly 8 bytes (64 bits) in length and must not be null for any cipher mode other than ECB.
Returns
- ICryptoTransform
A symmetric Blowfish decryptor object implementing ICryptoTransform.
Exceptions
- ObjectDisposedException
The current instance has been disposed.
- ArgumentNullException
rgbKeyorrgbIVis null.- CryptographicException
rgbKeyis not within the permitted key size range, orrgbIVhas an invalid length for the configured BlockMode.
CreateEncryptor(byte[], byte[]?)
Creates a symmetric Blowfish encryptor using the specified key and initialization vector.
public override ICryptoTransform CreateEncryptor(byte[] rgbKey, byte[]? rgbIV)
Parameters
rgbKeybyte[]The secret key for the symmetric algorithm. Must be between Bodu.Security.Cryptography.Blowfish.MinKeySize and Bodu.Security.Cryptography.Blowfish.MaxKeySize bytes in length. Must not be null.
rgbIVbyte[]The initialization vector. Must be exactly 8 bytes (64 bits) in length and must not be null for any cipher mode other than ECB.
Returns
- ICryptoTransform
A symmetric Blowfish encryptor object implementing ICryptoTransform.
Exceptions
- ObjectDisposedException
The current instance has been disposed.
- ArgumentNullException
rgbKeyorrgbIVis null.- CryptographicException
rgbKeyis not within the permitted key size range, orrgbIVhas an invalid length for the configured BlockMode.
Dispose(bool)
Releases the unmanaged resources used by the Blowfish instance and, optionally, the managed resources.
protected override void Dispose(bool disposing)
Parameters
disposingbooltrue to release both managed and unmanaged resources; false to release only unmanaged resources.
Remarks
Clears any cached key material and initialization vector before delegating to the base implementation. This method is idempotent and safe to call multiple times.
GenerateIV()
Generates a cryptographically random initialization vector (IV) suitable for use with the Blowfish algorithm.
public override void GenerateIV()
Remarks
The generated IV length is determined by the algorithm block size.
The generated IV is assigned to IV.
A new IV should be generated for each independent encryption operation when reusing a Blowfish instance with the same key.
Exceptions
- ObjectDisposedException
The current instance has been disposed.
GenerateKey()
Generates a cryptographically random key for use with the Blowfish algorithm using the currently configured KeySize.
public override void GenerateKey()
Remarks
Exceptions
- ObjectDisposedException
The current instance has been disposed.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |