Table of Contents

Camellia Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Camellia.cs

Provides a managed implementation of the Camellia symmetric block cipher, exposing the CamelliaBlockCipher engine through the standard SymmetricAlgorithm framework. This class cannot be inherited.

public sealed class Camellia : ExtendedSymmetricAlgorithm, IDisposable
Inheritance
Camellia
Implements
Inherited Members
Extension Methods

Examples

using System.Security.Cryptography;
using Bodu.Security.Cryptography;
using Bodu.Security.Cryptography.Extensions;

using var camellia = new Camellia();
camellia.GenerateKey(); // 256-bit by default
camellia.GenerateIV();
byte[] ciphertext = camellia.Encrypt(plaintext);
byte[] roundTrip = camellia.Decrypt(ciphertext);

Remarks

Camellia is a symmetric-key block cipher jointly developed by NTT and Mitsubishi Electric and specified by RFC 3713. It operates on a fixed 128-bit block size and accepts 128-bit, 192-bit, and 256-bit keys. The 128-bit key variant applies 18 Feistel rounds; the 192-bit and 256-bit key variants apply 24 rounds. Camellia has been evaluated and approved by ISO/IEC, CRYPTREC, and NESSIE.

This class integrates with the .NET SymmetricAlgorithm framework and supports standard block cipher modes via the BlockMode property. The default mode is CBC with PKCS7 padding and a default key size of 256 bits.

Parameters at a glance.

  • Block size: 128 bits (16 bytes).
  • Key sizes: 128 (18 rounds), 192 or 256 bits (24 rounds).
  • Specification: RFC 3713; approved by ISO/IEC, CRYPTREC, and NESSIE.
  • Default mode: CBC; default padding: PKCS7.

When to choose Camellia. Pick Camellia when standards-body approval matters - Japanese CRYPTREC, European NESSIE, and ISO/IEC all list Camellia. It is the standard alternative to AES in many non-US jurisdictions and TLS implementations. Performance characteristics are comparable to AES in software; for new general-purpose work without a procurement constraint Aes is the more widely accelerated default.

The underlying block-cipher implementation is constant-time in its control flow, but the fixed S-box lookup tables are read at data-dependent indices. As such, it is not hardened against timing or cache-based side-channel attacks.

Constructors

Camellia()

Initializes a new instance of the Camellia class with a 256-bit default key size, CBC cipher mode, and PKCS7 padding.

public Camellia()

Remarks

Call GenerateKey() and GenerateIV() to produce random key material, or assign Key and IV directly before calling CreateEncryptor(byte[], byte[]?) or CreateDecryptor(byte[], byte[]?).

The key size can be changed via KeySize to 128, 192, or 256 bits prior to generating or assigning a key.

Methods

Create()

Creates a new Camellia instance with default parameters.

public static Camellia Create()

Returns

Camellia

A new Camellia instance.

CreateDecryptor(byte[], byte[]?)

Creates a symmetric Camellia decryptor using the specified key and initialization vector.

public override ICryptoTransform CreateDecryptor(byte[] rgbKey, byte[]? rgbIV)

Parameters

rgbKey byte[]

The secret key for the symmetric algorithm. Must be exactly 16, 24, or 32 bytes (128, 192, or 256 bits) in length. Must not be null.

rgbIV byte[]

The initialization vector. Must be exactly 16 bytes (128 bits) in length. Must not be null.

Returns

ICryptoTransform

A symmetric Camellia decryptor object implementing ICryptoTransform.

Exceptions

ObjectDisposedException

The current instance has been disposed.

ArgumentNullException

rgbKey or rgbIV is null.

CryptographicException

rgbKey is not 16, 24, or 32 bytes in length, or rgbIV is not exactly 16 bytes in length.

CreateEncryptor(byte[], byte[]?)

Creates a symmetric Camellia encryptor using the specified key and initialization vector.

public override ICryptoTransform CreateEncryptor(byte[] rgbKey, byte[]? rgbIV)

Parameters

rgbKey byte[]

The secret key for the symmetric algorithm. Must be exactly 16, 24, or 32 bytes (128, 192, or 256 bits) in length. Must not be null.

rgbIV byte[]

The initialization vector. Must be exactly 16 bytes (128 bits) in length. Must not be null.

Returns

ICryptoTransform

A symmetric Camellia encryptor object implementing ICryptoTransform.

Exceptions

ObjectDisposedException

The current instance has been disposed.

ArgumentNullException

rgbKey or rgbIV is null.

CryptographicException

rgbKey is not 16, 24, or 32 bytes in length, or rgbIV is not exactly 16 bytes in length.

Dispose(bool)

Releases the unmanaged resources used by the Camellia instance and, optionally, the managed resources.

protected override void Dispose(bool disposing)

Parameters

disposing bool

true to release both managed and unmanaged resources; false to release only unmanaged resources.

Remarks

Clears any cached key material and initialization vector before delegating to the base implementation. This method is idempotent and safe to call multiple times.

GenerateIV()

Generates a cryptographically random initialization vector (IV) suitable for use with the Camellia algorithm.

public override void GenerateIV()

Remarks

The generated IV is 16 bytes (128 bits) - matching the Camellia block size - and is assigned directly to IV.

A new IV should be generated for each independent encryption operation when reusing a Camellia instance with the same key.

Exceptions

ObjectDisposedException

The current instance has been disposed.

GenerateKey()

Generates a cryptographically random key for use with the Camellia algorithm using the currently configured KeySize.

public override void GenerateKey()

Remarks

The generated key length is determined by KeySize, which defaults to 256 bits. The generated key is assigned directly to Key.

Exceptions

ObjectDisposedException

The current instance has been disposed.

Applies to

ProductVersions
.NET8, 10

See Also