HpkeSuite Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- HpkeSuite.cs
Describes a complete HPKE cipher suite - the combination of a Key Encapsulation Mechanism (KEM), a Key Derivation Function (KDF), and an Authenticated Encryption with Associated Data (AEAD) function - and exposes the derived element lengths defined by RFC 9180. Instances are immutable.
public sealed class HpkeSuite
- Inheritance
-
HpkeSuite
- Inherited Members
- Extension Methods
Examples
HpkeSuite suite = HpkeSuite.X25519_HkdfSha256_Aes128Gcm;
// or, explicitly:
var custom = new HpkeSuite(HpkeKem.X25519HkdfSha256, HpkeKdf.HkdfSha256, HpkeAead.ChaCha20Poly1305);
Remarks
A suite fixes every algorithm an HPKE exchange uses. The X25519HkdfSha256 KEM is the only KEM this implementation supports; it is paired with any of the HKDF-SHA2 KDFs and any of the registered AEADs. Use one of the pre-configured static properties for the common RFC 9180 combinations, or construct a custom suite directly.
Constructors
HpkeSuite(HpkeKem, HpkeKdf, HpkeAead)
Initializes a new instance of the HpkeSuite class from the specified KEM, KDF, and AEAD identifiers.
public HpkeSuite(HpkeKem kem, HpkeKdf kdf, HpkeAead aead)
Parameters
kemHpkeKemThe key encapsulation mechanism.
kdfHpkeKdfThe key derivation function.
aeadHpkeAeadThe authenticated-encryption function.
Exceptions
- ArgumentOutOfRangeException
kem,kdf, oraeadis not a supported value.
Properties
Aead
Gets the authenticated-encryption function of this suite.
public HpkeAead Aead { get; }
Property Value
- HpkeAead
The AEAD identifier.
AeadKeySizeInBytes
Gets the length, in bytes, of the AEAD key (Nk).
public int AeadKeySizeInBytes { get; }
Property Value
- int
The AEAD key length, or 0 for an export-only suite.
AeadNonceSizeInBytes
Gets the length, in bytes, of the AEAD nonce (Nn).
public int AeadNonceSizeInBytes { get; }
Property Value
- int
The AEAD nonce length, or 0 for an export-only suite.
AeadTagSizeInBytes
Gets the length, in bytes, of the AEAD authentication tag (Nt).
public int AeadTagSizeInBytes { get; }
Property Value
- int
The AEAD tag length, or 0 for an export-only suite.
EncapsulationSizeInBytes
Gets the length, in bytes, of the KEM encapsulated key (Nenc).
public int EncapsulationSizeInBytes { get; }
Property Value
- int
32 for the X25519 KEM.
IsExportOnly
Gets a value indicating whether this suite is export-only and rejects encryption and decryption.
public bool IsExportOnly { get; }
Property Value
- bool
true when Aead is ExportOnly; otherwise false.
Kdf
Gets the key derivation function of this suite.
public HpkeKdf Kdf { get; }
Property Value
- HpkeKdf
The KDF identifier.
Kem
Gets the key encapsulation mechanism of this suite.
public HpkeKem Kem { get; }
Property Value
- HpkeKem
The KEM identifier.
SharedSecretSizeInBytes
Gets the length, in bytes, of the KEM shared secret (Nsecret).
public int SharedSecretSizeInBytes { get; }
Property Value
- int
32 for the X25519 KEM.
X25519_HkdfSha256_Aes128Gcm
Gets the DHKEM(X25519, HKDF-SHA256) / HKDF-SHA256 / AES-128-GCM suite.
public static HpkeSuite X25519_HkdfSha256_Aes128Gcm { get; }
Property Value
- HpkeSuite
The pre-configured suite
0x0020, 0x0001, 0x0001.
X25519_HkdfSha256_Aes256Gcm
Gets the DHKEM(X25519, HKDF-SHA256) / HKDF-SHA256 / AES-256-GCM suite.
public static HpkeSuite X25519_HkdfSha256_Aes256Gcm { get; }
Property Value
- HpkeSuite
The pre-configured suite
0x0020, 0x0001, 0x0002.
X25519_HkdfSha256_ChaCha20Poly1305
Gets the DHKEM(X25519, HKDF-SHA256) / HKDF-SHA256 / ChaCha20Poly1305 suite.
public static HpkeSuite X25519_HkdfSha256_ChaCha20Poly1305 { get; }
Property Value
- HpkeSuite
The pre-configured suite
0x0020, 0x0001, 0x0003.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |