Table of Contents

Salt Struct

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Salt.cs

Represents a salt supplied to a key-derivation or password-hashing operation.

public readonly struct Salt : IEquatable<Salt>
Implements
Inherited Members
Extension Methods

Examples

// Generate a 16-byte salt for password hashing and persist it next to the derived value.
Salt salt = Salt.Random(16);
byte[] derived = Rfc2898DeriveBytes.Pbkdf2(
    password, salt.AsSpan(), iterations: 100_000, HashAlgorithmName.SHA256, outputLength: 32);

// The salt is not secret: reload it alongside the stored hash to recompute the value later.
Salt reloaded = Salt.FromBytes(storedSaltBytes);

Remarks

A salt diversifies derivation output so identical inputs do not produce identical results; it is unique per derivation but not secret, and is typically stored alongside the derived value. Using a dedicated type keeps salts from being confused with keys, nonces, or derived output in APIs that would otherwise accept several look-alike byte buffers.

Salt carries its bytes by defensive copy, and the default instance (default(Salt)) is the empty value: Length is 0 and IsEmpty is true.

Properties

IsEmpty

Gets a value indicating whether the salt is empty.

public bool IsEmpty { get; }

Property Value

bool

true if the salt contains no bytes; otherwise, false.

Length

Gets the number of bytes in the salt.

public int Length { get; }

Property Value

int

The salt length in bytes, or 0 for the empty value.

Methods

AsSpan()

Returns a read-only view over the salt bytes.

public ReadOnlySpan<byte> AsSpan()

Returns

ReadOnlySpan<byte>

A read-only span over the value; empty for the empty value.

Equals(Salt)

Determines whether this salt equals another.

public bool Equals(Salt other)

Parameters

other Salt

The salt to compare against.

Returns

bool

true if both values contain identical bytes; otherwise, false.

Remarks

The comparison runs through FixedTimeEquals(ReadOnlySpan<byte>, ReadOnlySpan<byte>) for a uniform, content-independent duration across the secret-bearing value types, though a salt is not itself a secret. A length mismatch returns false immediately. No dedicated FixedTimeEquals member is offered: a salt is a public value and is not verified against attacker-supplied input, so exposing one would wrongly imply a secret-comparison contract.

Equals(object?)

Determines whether this salt equals the specified object.

public override bool Equals(object? obj)

Parameters

obj object

The object to compare against.

Returns

bool

true if obj is a Salt with identical bytes; otherwise, false.

FromBytes(ReadOnlySpan<byte>)

Creates a Salt from the provided bytes.

public static Salt FromBytes(ReadOnlySpan<byte> value)

Parameters

value ReadOnlySpan<byte>

The salt bytes to copy. An empty span yields the empty value.

Returns

Salt

A new Salt containing a defensive copy of value.

GetHashCode()

Returns a hash code computed over the salt bytes.

public override int GetHashCode()

Returns

int

A hash code consistent with Equals(Salt).

Random(int)

Creates a Salt of the specified length filled with cryptographically secure random bytes.

public static Salt Random(int length)

Parameters

length int

The number of random bytes to generate.

Returns

Salt

A new Salt of length random bytes.

Exceptions

ArgumentOutOfRangeException

length ≤ 0.

ToArray()

Copies the salt bytes into a new array.

public byte[] ToArray()

Returns

byte[]

A new array containing the salt bytes; an empty array for the empty value.

ToString()

Returns the lowercase hexadecimal representation of the salt.

public override string ToString()

Returns

string

The salt bytes as lowercase hexadecimal text; Empty for the empty value.

Remarks

Salts are not secrets, so the content is intentionally included in the string representation.

Operators

operator ==(Salt, Salt)

Determines whether two salts are equal.

public static bool operator ==(Salt left, Salt right)

Parameters

left Salt

The first salt.

right Salt

The second salt.

Returns

bool

true if the values contain identical bytes; otherwise, false.

operator !=(Salt, Salt)

Determines whether two salts are not equal.

public static bool operator !=(Salt left, Salt right)

Parameters

left Salt

The first salt.

right Salt

The second salt.

Returns

bool

true if the values differ; otherwise, false.

Applies to

ProductVersions
.NET8, 10