IAeadTransform Interface
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- IAeadTransform.cs
Represents an authenticated encryption with associated data (AEAD) transform - the construction-neutral surface shared by block-cipher AEAD modes (IAeadBlockCipherModeTransform) and stream-cipher AEADs ( IStreamAeadTransform). A single call encrypts or decrypts a message together with its associated data; associated data is optional and defaults to empty.
public interface IAeadTransform : IDisposable
- Inherited Members
- Extension Methods
Remarks
This is the recommended surface for new code: it does not require a separate associated-data step, mirroring the shape of the BCL's AesGcm and ChaCha20Poly1305 APIs. Implementations remain single-use per message and not thread-safe; construct a fresh instance for every message.
The emitted wire format is ciphertext ‖ tag - the ciphertext followed immediately by the
TagSize / 8 byte authentication tag.
Properties
TagSize
Gets the authentication-tag size, in bits.
int TagSize { get; }
Property Value
- int
The authentication-tag size, in bits.
Methods
Decrypt(ReadOnlySpan<byte>, Span<byte>, ReadOnlySpan<byte>)
Verifies the authentication tag of ciphertextWithTag against
associatedData and writes the recovered plaintext to output.
int Decrypt(ReadOnlySpan<byte> ciphertextWithTag, Span<byte> output, ReadOnlySpan<byte> associatedData = default)
Parameters
ciphertextWithTagReadOnlySpan<byte>The ciphertext followed by its TagSize / 8 byte tag.
outputSpan<byte>Receives the recovered plaintext. Must be at least
ciphertextWithTag.Length - (TagSize / 8)bytes long.associatedDataReadOnlySpan<byte>The data that must match what was supplied at encryption time. Defaults to empty.
Returns
- int
Bytes written:
ciphertextWithTag.Length - (TagSize / 8).
Exceptions
- CryptographicException
The authentication tag did not match.
- ArgumentException
ciphertextWithTagis shorter than the tag,outputis too small, or the buffers partially overlap.- InvalidOperationException
The instance has already processed a message.
Encrypt(ReadOnlySpan<byte>, Span<byte>, ReadOnlySpan<byte>)
Encrypts plaintext, authenticates it together with associatedData, and
writes the ciphertext followed by the authentication tag to output.
int Encrypt(ReadOnlySpan<byte> plaintext, Span<byte> output, ReadOnlySpan<byte> associatedData = default)
Parameters
plaintextReadOnlySpan<byte>The data to encrypt.
outputSpan<byte>Receives the ciphertext followed by the TagSize / 8 byte tag. Must be at least
plaintext.Length + (TagSize / 8)bytes long.associatedDataReadOnlySpan<byte>The data authenticated but not encrypted. Defaults to empty.
Returns
- int
Total bytes written:
plaintext.Length + (TagSize / 8).
Exceptions
- ArgumentException
outputis too small, or the buffers partially overlap.- InvalidOperationException
The instance has already processed a message.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |