Table of Contents

BlowfishBlockCipher Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
BlowfishBlockCipher.Tables.cs

Provides the core Blowfish block cipher engine, implementing low-level encryption and decryption of individual 64-bit blocks.

public sealed class BlowfishBlockCipher : IBlockCipher, IDisposable
Inheritance
BlowfishBlockCipher
Implements
Inherited Members
Extension Methods

Remarks

This class implements the Blowfish symmetric block cipher designed by Bruce Schneier. It operates on 64-bit (8-byte) blocks and accepts a variable-length key of between 32 and 448 bits (4 to 56 bytes). The cipher uses a 16-round Feistel network with four 256-entry, 32-bit S-boxes and an 18-entry 32-bit P-array, all initialized from the hexadecimal digits of pi (π).

The block operation follows the Blowfish specification directly: split the 64-bit block into two big-endian 32-bit halves, apply 16 Feistel rounds using the expanded P-array and the four key-dependent S-boxes, undo the final Feistel swap, and apply the final two P-array words as output whitening. Decryption walks the same Feistel structure in reverse P-array order.

Key schedule expansion is performed in full during construction. The pi-derived P-array is first XORed with cyclic 32-bit key words, then the all-zero block is repeatedly encrypted to replace every P-array entry and every S-box entry with key-dependent values. All sensitive expanded state is zeroed securely on disposal.

Most callers should prefer the higher-level Blowfish class, which exposes the standard SymmetricAlgorithm contract. Use BlowfishBlockCipher directly only when composing the raw block primitive with an IBlockCipherModeTransform (for example via BlockCipherModeFactory) or with an IPaddingStrategy.

This implementation is constant-time in its control flow, but the four key-dependent S-boxes are read at data-dependent indices on every round. As such, this implementation is not hardened against timing or cache-based side-channel attacks.

Constructors

BlowfishBlockCipher(ReadOnlySpan<byte>)

Initializes a new instance of the BlowfishBlockCipher class using the specified key.

public BlowfishBlockCipher(ReadOnlySpan<byte> key)

Parameters

key ReadOnlySpan<byte>

The encryption key. Must be between 4 and 56 bytes (32 to 448 bits) in length.

Remarks

The full Blowfish key schedule - including XOR of the P-array with the key bytes and repeated encryption of the all-zeros block to expand the P-array and all four S-boxes - is performed in full during construction.

Exceptions

ArgumentException

key is fewer than 4 bytes or more than 56 bytes in length.

Properties

BlockSize

Gets the block size, in bits, of the cipher (for example, 128 bits / 16 bytes for AES).

public int BlockSize { get; }

Property Value

int

The block size, in bits.

Remarks

The block size is expressed in bits to align with the BCL convention used by BlockSize. Byte-array operations (encrypt, decrypt, slice) convert to bytes at the call site as BlockSize / 8.

Methods

Decrypt(ReadOnlySpan<byte>, Span<byte>)

Decrypts a single 64-bit block using the Blowfish cipher and writes the plaintext to output.

public void Decrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

A read-only span containing the ciphertext block to decrypt. Must be at least BlockSize / 8 bytes in length.

output Span<byte>

A writable span to receive the decrypted plaintext block. Must be at least BlockSize / 8 bytes in length.

Exceptions

ArgumentException

input or output is shorter than BlockSize / 8 bytes.

ObjectDisposedException

The instance has been disposed.

Dispose()

Performs application-defined tasks associated with freeing, releasing, or resetting unmanaged resources.

public void Dispose()

Encrypt(ReadOnlySpan<byte>, Span<byte>)

Encrypts a single 64-bit block using the Blowfish cipher and writes the ciphertext to output .

public void Encrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

A read-only span containing the plaintext block to encrypt. Must be at least BlockSize / 8 bytes in length.

output Span<byte>

A writable span to receive the encrypted ciphertext block. Must be at least BlockSize / 8 bytes in length.

Exceptions

ArgumentException

input or output is shorter than BlockSize / 8 bytes.

ObjectDisposedException

The instance has been disposed.

Applies to

ProductVersions
.NET8, 10

See Also