Table of Contents

CamelliaBlockCipher Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
CamelliaBlockCipher.cs

Provides the core Camellia block cipher engine, implementing low-level encryption and decryption of individual 128-bit blocks. This class cannot be inherited.

public sealed class CamelliaBlockCipher : IBlockCipher, IDisposable
Inheritance
CamelliaBlockCipher
Implements
Inherited Members
Extension Methods

Examples

// Direct single-block use. For most workloads prefer the Camellia SymmetricAlgorithm wrapper.
byte[] key = new byte[16];   // 128, 192, or 256 bits
RandomNumberGenerator.Fill(key);

using var cipher = new CamelliaBlockCipher(key);

byte[] plaintext  = new byte[16];   // one 128-bit block
byte[] ciphertext = new byte[16];
cipher.Encrypt(plaintext, ciphertext);

byte[] roundtrip = new byte[16];
cipher.Decrypt(ciphertext, roundtrip);
// roundtrip equals plaintext

Remarks

Camellia is a symmetric-key block cipher jointly developed by NTT and Mitsubishi Electric and specified in RFC 3713. It operates on a fixed 128-bit block size and accepts 128-bit, 192-bit, and 256-bit keys. The 128-bit key variant applies 18 Feistel rounds (three 6-round groups separated by FL/FL−1 layers), while the 192-bit and 256-bit key variants apply 24 rounds (four 6-round groups).

This implementation keeps the RFC 3713 model visible: the S-box material is represented by the published SBOX1 table, SBOX2/SBOX3/SBOX4 are derived exactly as specified, the SIGMA constants are stored as their 64-bit values, and whitening keys (kw1..kw4) are kept separate from round keys (k1..k18 or k1..k24) and FL/FL−1 keys (ke1..ke4 or ke1..ke6).

The block operation follows the RFC Feistel structure directly: input whitening, repeated applications of the 64-bit F function, periodic FL/FLINV layers, final half swap, and output whitening. Decryption reverses the same schedule using the same subkeys in reverse order and swaps FL with FLINV.

This type exposes the raw Camellia block primitive. Most callers should prefer the higher-level Camellia class, which exposes the standard SymmetricAlgorithm contract. Use CamelliaBlockCipher directly only when composing the raw block primitive with an IBlockCipherModeTransform or IPaddingStrategy.

  • Block size: 16 bytes (128 bits)
  • Key sizes: 16 bytes (128 bits), 24 bytes (192 bits), 32 bytes (256 bits)
  • Rounds: 18 (128-bit key) or 24 (192/256-bit key)

This implementation is constant-time in its control flow, but the fixed S-box lookup tables are read at data-dependent indices. As such, this implementation is not hardened against timing or cache-based side-channel attacks.

Constructors

CamelliaBlockCipher(ReadOnlySpan<byte>)

Initializes a new instance of the CamelliaBlockCipher class using the specified key.

public CamelliaBlockCipher(ReadOnlySpan<byte> key)

Parameters

key ReadOnlySpan<byte>

The encryption key. Must be 16, 24, or 32 bytes (128, 192, or 256 bits) in length.

Exceptions

ArgumentException

key is not 16, 24, or 32 bytes in length.

Properties

BlockSize

Gets the block size, in bits, of the cipher (for example, 128 bits / 16 bytes for AES).

public int BlockSize { get; }

Property Value

int

The block size, in bits.

Remarks

The block size is expressed in bits to align with the BCL convention used by BlockSize. Byte-array operations (encrypt, decrypt, slice) convert to bytes at the call site as BlockSize / 8.

Methods

Decrypt(ReadOnlySpan<byte>, Span<byte>)

Decrypts a single 128-bit ciphertext block.

public void Decrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

The ciphertext block to decrypt. Must be exactly 16 bytes.

output Span<byte>

The buffer that receives the plaintext block. Must be exactly 16 bytes.

Remarks

Decryption reverses the Feistel schedule used by Encrypt(ReadOnlySpan<byte>, Span<byte>). Because the FL layer and its inverse are paired asymmetrically during encryption, decryption applies FLINV to the left half and FL to the right half at each reversed FL/FLINV layer boundary.

Exceptions

ArgumentException

input or output is not exactly 16 bytes in length.

ObjectDisposedException

The cipher instance has been disposed.

Dispose()

Securely clears all expanded subkey material and marks the instance as disposed.

public void Dispose()

Encrypt(ReadOnlySpan<byte>, Span<byte>)

Encrypts a single 128-bit plaintext block.

public void Encrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

The plaintext block to encrypt. Must be exactly 16 bytes.

output Span<byte>

The buffer that receives the ciphertext block. Must be exactly 16 bytes.

Remarks

Encryption follows RFC 3713 directly: input whitening, groups of six Feistel rounds separated by FL/FLINV layers, then a final half swap and output whitening.

Exceptions

ArgumentException

input or output is not exactly 16 bytes in length.

ObjectDisposedException

The cipher instance has been disposed.

Applies to

ProductVersions
.NET8, 10

See Also