Table of Contents

ChaCha20 Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
ChaCha20.cs

Provides a managed implementation of the raw ChaCha20 stream cipher defined by RFC 8439. This class cannot be inherited.

public sealed class ChaCha20 : SymmetricStreamAlgorithm, IDisposable
Inheritance
ChaCha20
Implements
Inherited Members
Extension Methods

Examples

using System.Security.Cryptography;
using Bodu.Security.Cryptography;
using Bodu.Security.Cryptography.Extensions;

using var chacha = new ChaCha20();
chacha.GenerateKey(); // 256-bit
chacha.GenerateNonce(); // 96-bit nonce
byte[] ciphertext = chacha.Encrypt(plaintext);
byte[] roundTrip  = chacha.Decrypt(ciphertext);

Remarks

ChaCha20 is an additive stream cipher designed by Daniel J. Bernstein. It uses a 256-bit key, a 96-bit nonce, and a 32-bit block counter to generate a keystream that is XORed with the plaintext. This class exposes the raw keystream cipher - confidentiality only, with no authentication. For authenticated encryption use the BCL's ChaCha20Poly1305; the raw cipher exists for libsodium-, Noise-, and age-style protocols that build their own authentication layer or use ChaCha20 as a keystream primitive.

This cipher is self-inverse: CreateEncryptor() and CreateDecryptor() are interchangeable. The nonce is supplied through the Nonce property.

Parameters at a glance.

  • Key size: 256 bits (32 bytes).
  • Nonce (IV) size: 96 bits (12 bytes).
  • Block counter: 32-bit, starting at InitialCounter (default 0).

Nonce reuse is catastrophic. A given (key, nonce) pair must encrypt at most one message. The 96-bit nonce is too short to generate randomly at high volume without collision risk; for random nonces prefer the extended-nonce XChaCha20 variant. The cipher tracks the 32-bit counter and throws CryptographicException rather than reuse keystream if it would overflow (after roughly 256 GiB under a single nonce).

No cipher block. A stream cipher has no block, mode, or padding. The transform processes data one byte at a time and imposes no alignment requirement on callers, so it composes naturally with CryptoStream and any other consumer of the ICryptoTransform contract.

Constructors

ChaCha20()

Initializes a new instance of the ChaCha20 class with default parameters.

public ChaCha20()

Remarks

The default configuration uses a 256-bit key and a 96-bit nonce, with the block counter starting at 0.

Properties

InitialCounter

Gets or sets the initial 32-bit block counter used when generating the keystream.

public uint InitialCounter { get; set; }

Property Value

uint

The starting block-counter value. The default is 0.

Remarks

RFC 8439 keystream examples start the counter at 0 or 1 depending on the construction; libsodium's raw crypto_stream_chacha20_ietf starts at 0. Set this before creating an encryptor or decryptor when matching an external counter convention.

Methods

Create()

Creates a new ChaCha20 instance with default parameters.

public static ChaCha20 Create()

Returns

ChaCha20

A new ChaCha20 instance.

CreateStreamCipher(byte[], byte[])

Builds a configured IStreamCipher engine from the validated key and nonce.

protected override IStreamCipher CreateStreamCipher(byte[] key, byte[] nonce)

Parameters

key byte[]

The key, already validated to the algorithm's key size.

nonce byte[]

The nonce, already validated to the algorithm's nonce size.

Returns

IStreamCipher

A new IStreamCipher engine positioned at the start of its keystream.

Remarks

Implementations receive a key and nonce whose lengths have already been checked by the base class, so they need only construct their engine. Ownership of the returned engine transfers to the caller.

Applies to

ProductVersions
.NET8, 10

See Also