Salt Struct
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- Salt.cs
Represents a salt supplied to a key-derivation or password-hashing operation.
public readonly struct Salt : IEquatable<Salt>
- Implements
- Inherited Members
- Extension Methods
Examples
// Generate a 16-byte salt for password hashing and persist it next to the derived value.
Salt salt = Salt.Random(16);
byte[] derived = Rfc2898DeriveBytes.Pbkdf2(
password, salt.AsSpan(), iterations: 100_000, HashAlgorithmName.SHA256, outputLength: 32);
// The salt is not secret: reload it alongside the stored hash to recompute the value later.
Salt reloaded = Salt.FromBytes(storedSaltBytes);
Remarks
A salt diversifies derivation output so identical inputs do not produce identical results; it is unique per derivation but not secret, and is typically stored alongside the derived value. Using a dedicated type keeps salts from being confused with keys, nonces, or derived output in APIs that would otherwise accept several look-alike byte buffers.
Salt carries its bytes by defensive copy, and the default instance (default(Salt)) is the
empty value: Length is 0 and IsEmpty is true.
Properties
IsEmpty
Gets a value indicating whether the salt is empty.
public bool IsEmpty { get; }
Property Value
Length
Gets the number of bytes in the salt.
public int Length { get; }
Property Value
- int
The salt length in bytes, or
0for the empty value.
Methods
AsSpan()
Returns a read-only view over the salt bytes.
public ReadOnlySpan<byte> AsSpan()
Returns
- ReadOnlySpan<byte>
A read-only span over the value; empty for the empty value.
Equals(Salt)
Determines whether this salt equals another.
public bool Equals(Salt other)
Parameters
otherSaltThe salt to compare against.
Returns
Remarks
The comparison runs through
FixedTimeEquals(ReadOnlySpan<byte>, ReadOnlySpan<byte>) for a uniform,
content-independent duration across the secret-bearing value types, though a salt is not itself a secret. A
length mismatch returns false immediately. No dedicated FixedTimeEquals member is
offered: a salt is a public value and is not verified against attacker-supplied input, so exposing one would
wrongly imply a secret-comparison contract.
Equals(object?)
Determines whether this salt equals the specified object.
public override bool Equals(object? obj)
Parameters
objobjectThe object to compare against.
Returns
FromBytes(ReadOnlySpan<byte>)
Creates a Salt from the provided bytes.
public static Salt FromBytes(ReadOnlySpan<byte> value)
Parameters
valueReadOnlySpan<byte>The salt bytes to copy. An empty span yields the empty value.
Returns
GetHashCode()
Returns a hash code computed over the salt bytes.
public override int GetHashCode()
Returns
- int
A hash code consistent with Equals(Salt).
Random(int)
Creates a Salt of the specified length filled with cryptographically secure random bytes.
public static Salt Random(int length)
Parameters
lengthintThe number of random bytes to generate.
Returns
Exceptions
- ArgumentOutOfRangeException
length≤ 0.
ToArray()
Copies the salt bytes into a new array.
public byte[] ToArray()
Returns
- byte[]
A new array containing the salt bytes; an empty array for the empty value.
ToString()
Returns the lowercase hexadecimal representation of the salt.
public override string ToString()
Returns
Remarks
Salts are not secrets, so the content is intentionally included in the string representation.
Operators
operator ==(Salt, Salt)
Determines whether two salts are equal.
public static bool operator ==(Salt left, Salt right)
Parameters
Returns
operator !=(Salt, Salt)
Determines whether two salts are not equal.
public static bool operator !=(Salt left, Salt right)
Parameters
Returns
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |