BlowfishBlockCipher Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
Provides the core Blowfish block cipher engine, implementing low-level encryption and decryption of individual 64-bit blocks.
public sealed class BlowfishBlockCipher : IBlockCipher, IDisposable
- Inheritance
-
BlowfishBlockCipher
- Implements
- Inherited Members
- Extension Methods
Remarks
This class implements the Blowfish symmetric block cipher designed by Bruce Schneier. It operates on 64-bit (8-byte) blocks and accepts a variable-length key of between 32 and 448 bits (4 to 56 bytes). The cipher uses a 16-round Feistel network with four 256-entry, 32-bit S-boxes and an 18-entry 32-bit P-array, all initialized from the hexadecimal digits of pi (π).
The block operation follows the Blowfish specification directly: split the 64-bit block into two big-endian 32-bit halves, apply 16 Feistel rounds using the expanded P-array and the four key-dependent S-boxes, undo the final Feistel swap, and apply the final two P-array words as output whitening. Decryption walks the same Feistel structure in reverse P-array order.
Key schedule expansion is performed in full during construction. The pi-derived P-array is first XORed with cyclic 32-bit key words, then the all-zero block is repeatedly encrypted to replace every P-array entry and every S-box entry with key-dependent values. All sensitive expanded state is zeroed securely on disposal.
Most callers should prefer the higher-level Blowfish class, which exposes the standard SymmetricAlgorithm contract. Use BlowfishBlockCipher directly only when composing the raw block primitive with an IBlockCipherModeTransform (for example via BlockCipherModeFactory) or with an IPaddingStrategy.
This implementation is constant-time in its control flow, but the four key-dependent S-boxes are read at data-dependent indices on every round. As such, this implementation is not hardened against timing or cache-based side-channel attacks.
Constructors
BlowfishBlockCipher(ReadOnlySpan<byte>)
Initializes a new instance of the BlowfishBlockCipher class using the specified key.
public BlowfishBlockCipher(ReadOnlySpan<byte> key)
Parameters
keyReadOnlySpan<byte>The encryption key. Must be between 4 and 56 bytes (32 to 448 bits) in length.
Remarks
The full Blowfish key schedule - including XOR of the P-array with the key bytes and repeated encryption of the all-zeros block to expand the P-array and all four S-boxes - is performed in full during construction.
Exceptions
- ArgumentException
keyis fewer than 4 bytes or more than 56 bytes in length.
Properties
BlockSize
Gets the block size, in bits, of the cipher (for example, 128 bits / 16 bytes for AES).
public int BlockSize { get; }
Property Value
- int
The block size, in bits.
Remarks
The block size is expressed in bits to align with the BCL convention used by
BlockSize. Byte-array operations (encrypt,
decrypt, slice) convert to bytes at the call site as BlockSize / 8.
Methods
Decrypt(ReadOnlySpan<byte>, Span<byte>)
Decrypts a single 64-bit block using the Blowfish cipher and writes the plaintext to output.
public void Decrypt(ReadOnlySpan<byte> input, Span<byte> output)
Parameters
inputReadOnlySpan<byte>A read-only span containing the ciphertext block to decrypt. Must be at least BlockSize / 8 bytes in length.
outputSpan<byte>A writable span to receive the decrypted plaintext block. Must be at least BlockSize / 8 bytes in length.
Exceptions
- ArgumentException
inputoroutputis shorter than BlockSize / 8 bytes.- ObjectDisposedException
The instance has been disposed.
Dispose()
Performs application-defined tasks associated with freeing, releasing, or resetting unmanaged resources.
public void Dispose()
Encrypt(ReadOnlySpan<byte>, Span<byte>)
Encrypts a single 64-bit block using the Blowfish cipher and writes the ciphertext to output
.
public void Encrypt(ReadOnlySpan<byte> input, Span<byte> output)
Parameters
inputReadOnlySpan<byte>A read-only span containing the plaintext block to encrypt. Must be at least BlockSize / 8 bytes in length.
outputSpan<byte>A writable span to receive the encrypted ciphertext block. Must be at least BlockSize / 8 bytes in length.
Exceptions
- ArgumentException
inputoroutputis shorter than BlockSize / 8 bytes.- ObjectDisposedException
The instance has been disposed.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |