Table of Contents

IAeadTransform Interface

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
IAeadTransform.cs

Represents an authenticated encryption with associated data (AEAD) transform - the construction-neutral surface shared by block-cipher AEAD modes (IAeadBlockCipherModeTransform) and stream-cipher AEADs ( IStreamAeadTransform). A single call encrypts or decrypts a message together with its associated data; associated data is optional and defaults to empty.

public interface IAeadTransform : IDisposable
Inherited Members
Extension Methods

Remarks

This is the recommended surface for new code: it does not require a separate associated-data step, mirroring the shape of the BCL's AesGcm and ChaCha20Poly1305 APIs. Implementations remain single-use per message and not thread-safe; construct a fresh instance for every message.

The emitted wire format is ciphertext ‖ tag - the ciphertext followed immediately by the TagSize / 8 byte authentication tag.

Properties

TagSize

Gets the authentication-tag size, in bits.

int TagSize { get; }

Property Value

int

The authentication-tag size, in bits.

Methods

Decrypt(ReadOnlySpan<byte>, Span<byte>, ReadOnlySpan<byte>)

Verifies the authentication tag of ciphertextWithTag against associatedData and writes the recovered plaintext to output.

int Decrypt(ReadOnlySpan<byte> ciphertextWithTag, Span<byte> output, ReadOnlySpan<byte> associatedData = default)

Parameters

ciphertextWithTag ReadOnlySpan<byte>

The ciphertext followed by its TagSize / 8 byte tag.

output Span<byte>

Receives the recovered plaintext. Must be at least ciphertextWithTag.Length - (TagSize / 8) bytes long.

associatedData ReadOnlySpan<byte>

The data that must match what was supplied at encryption time. Defaults to empty.

Returns

int

Bytes written: ciphertextWithTag.Length - (TagSize / 8).

Exceptions

CryptographicException

The authentication tag did not match.

ArgumentException

ciphertextWithTag is shorter than the tag, output is too small, or the buffers partially overlap.

InvalidOperationException

The instance has already processed a message.

Encrypt(ReadOnlySpan<byte>, Span<byte>, ReadOnlySpan<byte>)

Encrypts plaintext, authenticates it together with associatedData, and writes the ciphertext followed by the authentication tag to output.

int Encrypt(ReadOnlySpan<byte> plaintext, Span<byte> output, ReadOnlySpan<byte> associatedData = default)

Parameters

plaintext ReadOnlySpan<byte>

The data to encrypt.

output Span<byte>

Receives the ciphertext followed by the TagSize / 8 byte tag. Must be at least plaintext.Length + (TagSize / 8) bytes long.

associatedData ReadOnlySpan<byte>

The data authenticated but not encrypted. Defaults to empty.

Returns

int

Total bytes written: plaintext.Length + (TagSize / 8).

Exceptions

ArgumentException

output is too small, or the buffers partially overlap.

InvalidOperationException

The instance has already processed a message.

Applies to

ProductVersions
.NET8, 10