CamelliaBlockCipher Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- CamelliaBlockCipher.cs
Provides the core Camellia block cipher engine, implementing low-level encryption and decryption of individual 128-bit blocks. This class cannot be inherited.
public sealed class CamelliaBlockCipher : IBlockCipher, IDisposable
- Inheritance
-
CamelliaBlockCipher
- Implements
- Inherited Members
- Extension Methods
Examples
// Direct single-block use. For most workloads prefer the Camellia SymmetricAlgorithm wrapper.
byte[] key = new byte[16]; // 128, 192, or 256 bits
RandomNumberGenerator.Fill(key);
using var cipher = new CamelliaBlockCipher(key);
byte[] plaintext = new byte[16]; // one 128-bit block
byte[] ciphertext = new byte[16];
cipher.Encrypt(plaintext, ciphertext);
byte[] roundtrip = new byte[16];
cipher.Decrypt(ciphertext, roundtrip);
// roundtrip equals plaintext
Remarks
Camellia is a symmetric-key block cipher jointly developed by NTT and Mitsubishi Electric and specified in RFC 3713. It operates on a fixed 128-bit block size and accepts 128-bit, 192-bit, and 256-bit keys. The 128-bit key variant applies 18 Feistel rounds (three 6-round groups separated by FL/FL−1 layers), while the 192-bit and 256-bit key variants apply 24 rounds (four 6-round groups).
This implementation keeps the RFC 3713 model visible: the S-box material is represented by the published
SBOX1 table, SBOX2/SBOX3/SBOX4 are derived exactly as specified, the SIGMA
constants are stored as their 64-bit values, and whitening keys (kw1..kw4) are kept separate from round keys
(k1..k18 or k1..k24) and FL/FL−1 keys (ke1..ke4 or ke1..ke6).
The block operation follows the RFC Feistel structure directly: input whitening, repeated applications of the 64-bit
F function, periodic FL/FLINV layers, final half swap, and output whitening. Decryption
reverses the same schedule using the same subkeys in reverse order and swaps FL with FLINV.
This type exposes the raw Camellia block primitive. Most callers should prefer the higher-level Camellia class, which exposes the standard SymmetricAlgorithm contract. Use CamelliaBlockCipher directly only when composing the raw block primitive with an IBlockCipherModeTransform or IPaddingStrategy.
- Block size: 16 bytes (128 bits)
- Key sizes: 16 bytes (128 bits), 24 bytes (192 bits), 32 bytes (256 bits)
- Rounds: 18 (128-bit key) or 24 (192/256-bit key)
This implementation is constant-time in its control flow, but the fixed S-box lookup tables are read at data-dependent indices. As such, this implementation is not hardened against timing or cache-based side-channel attacks.
Constructors
CamelliaBlockCipher(ReadOnlySpan<byte>)
Initializes a new instance of the CamelliaBlockCipher class using the specified key.
public CamelliaBlockCipher(ReadOnlySpan<byte> key)
Parameters
keyReadOnlySpan<byte>The encryption key. Must be 16, 24, or 32 bytes (128, 192, or 256 bits) in length.
Exceptions
- ArgumentException
keyis not 16, 24, or 32 bytes in length.
Properties
BlockSize
Gets the block size, in bits, of the cipher (for example, 128 bits / 16 bytes for AES).
public int BlockSize { get; }
Property Value
- int
The block size, in bits.
Remarks
The block size is expressed in bits to align with the BCL convention used by
BlockSize. Byte-array operations (encrypt,
decrypt, slice) convert to bytes at the call site as BlockSize / 8.
Methods
Decrypt(ReadOnlySpan<byte>, Span<byte>)
Decrypts a single 128-bit ciphertext block.
public void Decrypt(ReadOnlySpan<byte> input, Span<byte> output)
Parameters
inputReadOnlySpan<byte>The ciphertext block to decrypt. Must be exactly 16 bytes.
outputSpan<byte>The buffer that receives the plaintext block. Must be exactly 16 bytes.
Remarks
Decryption reverses the Feistel schedule used by Encrypt(ReadOnlySpan<byte>, Span<byte>). Because the FL layer and its inverse
are paired asymmetrically during encryption, decryption applies FLINV to the left half and FL to
the right half at each reversed FL/FLINV layer boundary.
Exceptions
- ArgumentException
inputoroutputis not exactly 16 bytes in length.- ObjectDisposedException
The cipher instance has been disposed.
Dispose()
Securely clears all expanded subkey material and marks the instance as disposed.
public void Dispose()
Encrypt(ReadOnlySpan<byte>, Span<byte>)
Encrypts a single 128-bit plaintext block.
public void Encrypt(ReadOnlySpan<byte> input, Span<byte> output)
Parameters
inputReadOnlySpan<byte>The plaintext block to encrypt. Must be exactly 16 bytes.
outputSpan<byte>The buffer that receives the ciphertext block. Must be exactly 16 bytes.
Remarks
Encryption follows RFC 3713 directly: input whitening, groups of six Feistel rounds separated by FL/FLINV layers, then a final half swap and output whitening.
Exceptions
- ArgumentException
inputoroutputis not exactly 16 bytes in length.- ObjectDisposedException
The cipher instance has been disposed.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |