ChaCha20 Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- ChaCha20.cs
Provides a managed implementation of the raw ChaCha20 stream cipher defined by RFC 8439. This class cannot be inherited.
public sealed class ChaCha20 : SymmetricStreamAlgorithm, IDisposable
- Inheritance
-
ChaCha20
- Implements
- Inherited Members
- Extension Methods
Examples
using System.Security.Cryptography;
using Bodu.Security.Cryptography;
using Bodu.Security.Cryptography.Extensions;
using var chacha = new ChaCha20();
chacha.GenerateKey(); // 256-bit
chacha.GenerateNonce(); // 96-bit nonce
byte[] ciphertext = chacha.Encrypt(plaintext);
byte[] roundTrip = chacha.Decrypt(ciphertext);
Remarks
ChaCha20 is an additive stream cipher designed by Daniel J. Bernstein. It uses a 256-bit key, a 96-bit nonce, and a 32-bit block counter to generate a keystream that is XORed with the plaintext. This class exposes the raw keystream cipher - confidentiality only, with no authentication. For authenticated encryption use the BCL's ChaCha20Poly1305; the raw cipher exists for libsodium-, Noise-, and age-style protocols that build their own authentication layer or use ChaCha20 as a keystream primitive.
This cipher is self-inverse: CreateEncryptor() and CreateDecryptor() are interchangeable. The nonce is supplied through the Nonce property.
Parameters at a glance.
- Key size: 256 bits (32 bytes).
- Nonce (IV) size: 96 bits (12 bytes).
- Block counter: 32-bit, starting at InitialCounter (default 0).
Nonce reuse is catastrophic. A given (key, nonce) pair must encrypt at most one message. The
96-bit nonce is too short to generate randomly at high volume without collision risk; for random nonces prefer the
extended-nonce XChaCha20 variant. The cipher tracks the 32-bit counter and throws
CryptographicException rather than reuse keystream if it would overflow (after roughly 256 GiB under
a single nonce).
No cipher block. A stream cipher has no block, mode, or padding. The transform processes data one byte at a time and imposes no alignment requirement on callers, so it composes naturally with CryptoStream and any other consumer of the ICryptoTransform contract.
Constructors
ChaCha20()
Initializes a new instance of the ChaCha20 class with default parameters.
public ChaCha20()
Remarks
The default configuration uses a 256-bit key and a 96-bit nonce, with the block counter starting at 0.
Properties
InitialCounter
Gets or sets the initial 32-bit block counter used when generating the keystream.
public uint InitialCounter { get; set; }
Property Value
- uint
The starting block-counter value. The default is 0.
Remarks
RFC 8439 keystream examples start the counter at 0 or 1 depending on the construction; libsodium's raw
crypto_stream_chacha20_ietf starts at 0. Set this before creating an encryptor or decryptor when matching
an external counter convention.
Methods
Create()
Creates a new ChaCha20 instance with default parameters.
public static ChaCha20 Create()
Returns
CreateStreamCipher(byte[], byte[])
Builds a configured IStreamCipher engine from the validated key and nonce.
protected override IStreamCipher CreateStreamCipher(byte[] key, byte[] nonce)
Parameters
keybyte[]The key, already validated to the algorithm's key size.
noncebyte[]The nonce, already validated to the algorithm's nonce size.
Returns
- IStreamCipher
A new IStreamCipher engine positioned at the start of its keystream.
Remarks
Implementations receive a key and nonce whose lengths have already been checked by the base class, so they need only construct their engine. Ownership of the returned engine transfers to the caller.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |