Table of Contents

Serpent128 Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Serpent128.cs

Provides a managed implementation of the canonical Serpent symmetric block cipher, which operates on 128-bit (16-byte) blocks using a 128, 192, or 256-bit key. This class cannot be inherited.

public sealed class Serpent128 : ExtendedSymmetricAlgorithm, IDisposable
Inheritance
Serpent128
Implements
Inherited Members
Extension Methods

Examples

using System.Security.Cryptography;
using Bodu.Security.Cryptography;
using Bodu.Security.Cryptography.Extensions;

using var serpent = new Serpent128();
serpent.GenerateKey(); // 256-bit by default
serpent.GenerateIV();
byte[] ciphertext = serpent.Encrypt(plaintext);
byte[] roundTrip = serpent.Decrypt(ciphertext);

Remarks

Serpent is an Advanced Encryption Standard (AES) finalist by Ross Anderson, Eli Biham, and Lars Knudsen, first published in 1998 (NESSIE submission, Serpent: A Proposal for the Advanced Encryption Standard). It is a 32-round substitution-permutation network that combines eight 4-bit S-boxes with a bitsliced linear transform, and is widely regarded as one of the most conservative designs among the AES finalists.

This class integrates with the standard SymmetricAlgorithm framework and supports the extended block-cipher modes exposed by CipherModeKind. The default configuration uses CBC with PKCS7.

For larger block sizes with tweak support, see Serpent256, Serpent512, and Serpent1024. Those variants are a non-standard Serpent-derived construction; the type on this page is the canonical, externally vetted 128-bit cipher.

Parameters at a glance.

  • Block size: 128 bits (16 bytes).
  • Key sizes: 128, 192, or 256 bits.
  • Default mode: CBC; default padding: PKCS7.
  • 32 rounds, 8 × 4-bit S-boxes, bitsliced linear transform.

When to choose Serpent128. Pick Serpent when a deliberately conservative AES alternative is wanted - the 32-round design has a wider security margin than AES's 14 rounds at 256-bit key, at the cost of noticeably lower throughput. For general-purpose encryption with hardware acceleration prefer Aes; for an alternative AES finalist with better software performance prefer Twofish. Use Camellia when ISO/IEC, CRYPTREC, or NESSIE approval is a procurement requirement.

The underlying block-cipher implementation computes each S-box as a Boolean circuit (Osvik's) and the linear transform with rotations, shifts and XOR, so it reads no tables and takes no branches that depend on the key or the data: its running time does not depend on either.

Constructors

Serpent128()

Initializes a new instance of the Serpent128 class with default parameters.

public Serpent128()

Remarks

The default configuration uses a 128-bit block, a 128-bit key, CBC cipher mode, and PKCS7 padding. Call GenerateKey() and GenerateIV() to produce random key material, or assign Key and IV directly before calling CreateEncryptor(byte[], byte[]?) or CreateDecryptor(byte[], byte[]?).

Methods

Create()

Creates a new Serpent128 instance with default parameters.

public static Serpent128 Create()

Returns

Serpent128

A new Serpent128 instance.

CreateDecryptor(byte[], byte[]?)

When overridden in a derived class, creates a symmetric decryptor object with the specified Key property and initialization vector (IV).

public override ICryptoTransform CreateDecryptor(byte[] rgbKey, byte[]? rgbIV)

Parameters

rgbKey byte[]

The secret key to use for the symmetric algorithm.

rgbIV byte[]

The initialization vector to use for the symmetric algorithm.

Returns

ICryptoTransform

A symmetric decryptor object.

CreateEncryptor(byte[], byte[]?)

When overridden in a derived class, creates a symmetric encryptor object with the specified Key property and initialization vector (IV).

public override ICryptoTransform CreateEncryptor(byte[] rgbKey, byte[]? rgbIV)

Parameters

rgbKey byte[]

The secret key to use for the symmetric algorithm.

rgbIV byte[]

The initialization vector to use for the symmetric algorithm.

Returns

ICryptoTransform

A symmetric encryptor object.

Dispose(bool)

Releases the unmanaged resources used by the SymmetricAlgorithm and optionally releases the managed resources.

protected override void Dispose(bool disposing)

Parameters

disposing bool

true to release both managed and unmanaged resources; false to release only unmanaged resources.

GenerateIV()

When overridden in a derived class, generates a random initialization vector (IV) to use for the algorithm.

public override void GenerateIV()

GenerateKey()

When overridden in a derived class, generates a random key (Key) to use for the algorithm.

public override void GenerateKey()

Applies to

ProductVersions
.NET8, 10

See Also