Table of Contents

Blowfish Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Blowfish.cs

Provides a managed implementation of the Blowfish symmetric block cipher. This class cannot be inherited.

public sealed class Blowfish : ExtendedSymmetricAlgorithm, IDisposable
Inheritance
Blowfish
Implements
Inherited Members
Extension Methods

Examples

using System.Security.Cryptography;
using Bodu.Security.Cryptography;
using Bodu.Security.Cryptography.Extensions;

// Legacy interop only.
using var blowfish = new Blowfish();
blowfish.Key = legacyKeyMaterial; // 4-56 bytes
blowfish.IV = RandomNumberGenerator.GetBytes(8); // matches the 64-bit block
byte[] ciphertext = blowfish.Encrypt(legacyPlaintext);

Remarks

Blowfish is a symmetric-key block cipher designed by Bruce Schneier in 1993. It operates on 64-bit (8-byte) blocks and accepts a variable-length key of between 32 and 448 bits (4 to 56 bytes). The cipher applies a 16-round Feistel network using four 256-entry S-boxes and an 18-entry P-array, all initialized from the hexadecimal digits of pi (π). The key schedule is computationally intensive by design, making brute-force attacks significantly more expensive.

This class integrates with the .NET SymmetricAlgorithm framework and supports standard block cipher modes via the BlockMode property. The default mode is CBC with PKCS7 padding.

For further details on the algorithm, see https://www.schneier.com/academic/blowfish/.

Parameters at a glance.

  • Block size: 64 bits (8 bytes).
  • Key size: variable, 32-448 bits (4-56 bytes).
  • 16-round Feistel network with key-dependent S-boxes initialized from the digits of π.
  • Default mode: CBC; default padding: PKCS7.

When to choose Blowfish. Pick Blowfish only for interoperability with legacy systems that already use it - its 64-bit block size invites SWEET32 birthday-bound attacks once roughly 32 GiB has been encrypted under one key. For new designs use Aes; bcrypt-style password hashing schemes that derive from Blowfish are not in scope of this class.

important

Blowfish has a 64-bit block size, which makes it vulnerable to birthday-bound attacks (SWEET32) when large volumes of data are encrypted under the same key. For new applications, a cipher with a 128-bit or larger block size (such as AES) should be preferred.

The underlying block-cipher implementation is constant-time in its control flow, but the four key-dependent S-boxes are read at data-dependent indices on every round. As such, it is not hardened against timing or cache-based side-channel attacks.

Constructors

Blowfish()

Initializes a new instance of the Blowfish class with default parameters.

public Blowfish()

Remarks

The default configuration uses a 64-bit block, a 128-bit (16-byte) key, CBC cipher mode, and PKCS7 padding. Call GenerateKey() and GenerateIV() to produce random key material, or assign Key and IV directly before calling CreateEncryptor(byte[], byte[]?) or CreateDecryptor(byte[], byte[]?).

Methods

Create()

Creates a new Blowfish instance with default parameters.

public static Blowfish Create()

Returns

Blowfish

A new Blowfish instance.

CreateDecryptor(byte[], byte[]?)

Creates a symmetric Blowfish decryptor using the specified key and initialization vector.

public override ICryptoTransform CreateDecryptor(byte[] rgbKey, byte[]? rgbIV)

Parameters

rgbKey byte[]

The secret key for the symmetric algorithm. Must be between Bodu.Security.Cryptography.Blowfish.MinKeySize and Bodu.Security.Cryptography.Blowfish.MaxKeySize bytes in length. Must not be null.

rgbIV byte[]

The initialization vector. Must be exactly 8 bytes (64 bits) in length and must not be null for any cipher mode other than ECB.

Returns

ICryptoTransform

A symmetric Blowfish decryptor object implementing ICryptoTransform.

Exceptions

ObjectDisposedException

The current instance has been disposed.

ArgumentNullException

rgbKey or rgbIV is null.

CryptographicException

rgbKey is not within the permitted key size range, or rgbIV has an invalid length for the configured BlockMode.

CreateEncryptor(byte[], byte[]?)

Creates a symmetric Blowfish encryptor using the specified key and initialization vector.

public override ICryptoTransform CreateEncryptor(byte[] rgbKey, byte[]? rgbIV)

Parameters

rgbKey byte[]

The secret key for the symmetric algorithm. Must be between Bodu.Security.Cryptography.Blowfish.MinKeySize and Bodu.Security.Cryptography.Blowfish.MaxKeySize bytes in length. Must not be null.

rgbIV byte[]

The initialization vector. Must be exactly 8 bytes (64 bits) in length and must not be null for any cipher mode other than ECB.

Returns

ICryptoTransform

A symmetric Blowfish encryptor object implementing ICryptoTransform.

Exceptions

ObjectDisposedException

The current instance has been disposed.

ArgumentNullException

rgbKey or rgbIV is null.

CryptographicException

rgbKey is not within the permitted key size range, or rgbIV has an invalid length for the configured BlockMode.

Dispose(bool)

Releases the unmanaged resources used by the Blowfish instance and, optionally, the managed resources.

protected override void Dispose(bool disposing)

Parameters

disposing bool

true to release both managed and unmanaged resources; false to release only unmanaged resources.

Remarks

Clears any cached key material and initialization vector before delegating to the base implementation. This method is idempotent and safe to call multiple times.

GenerateIV()

Generates a cryptographically random initialization vector (IV) suitable for use with the Blowfish algorithm.

public override void GenerateIV()

Remarks

The generated IV length is determined by the algorithm block size.

The generated IV is assigned to IV.

A new IV should be generated for each independent encryption operation when reusing a Blowfish instance with the same key.

Exceptions

ObjectDisposedException

The current instance has been disposed.

GenerateKey()

Generates a cryptographically random key for use with the Blowfish algorithm using the currently configured KeySize.

public override void GenerateKey()

Remarks

The generated key length is determined by KeySize.

The generated key is assigned to Key.

Exceptions

ObjectDisposedException

The current instance has been disposed.

Applies to

ProductVersions
.NET8, 10

See Also