Table of Contents

SerpentBlockCipher Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
SerpentBlockCipher.cs

Serves as the abstract base class for the non-standard wide-block tweakable Serpent engines ( Serpent256Cipher, Serpent512Cipher, Serpent1024Cipher).

public abstract class SerpentBlockCipher : SerpentBlockCipherBase, IBlockCipher, IDisposable
Inheritance
SerpentBlockCipher
Implements
Derived
Inherited Members
Extension Methods

Remarks

This type extends SerpentBlockCipherBase with a 128-bit tweak schedule expressed as five cycling 32-bit entries [T0, T1, T2, T3, T0 ^ T1 ^ T2 ^ T3] (the 32-bit analogue of the Threefish [T0, T1, T0 ^ T1] layout) and with a round-key schedule sized to match the variant's block width. Derived classes specify the state width (in 32-bit words) and round count; this class builds the expanded round keys and folds the tweak schedule into them.

The round function keeps the Serpent-style structure of key XOR, S-box layer, and linear diffusion, then extends it across wider states by applying each Serpent operation to four-word groups and adding a word-rotation permutation between groups. Tweak material is injected into the tail of the state every four rounds.

important

The wide-block tweakable Serpent family is a non-standard, experimental construction developed for this library. It is not interoperable with canonical Serpent implementations at any block size, and its cryptographic properties have not been externally analyzed. Use the canonical Serpent128Cipher when Serpent compatibility is required.

This implementation computes each S-box as a Boolean circuit (Osvik's) and the linear transform with rotations, shifts and XOR, so it reads no tables and takes no branches that depend on the key or the data: its running time does not depend on either.

The rounds run in Bodu.Security.Cryptography.SerpentCore, eight at a time, one per S-box. Serpent-256's eight words stay in locals throughout, so the word rotation is a renaming; the wider states pass through each round a four-word group at a time. The tweak material is folded into the round keys when the key is set: each injection is followed at once by the next round's key, so adding it to that key gives the same rounds.

Methods

Decrypt(ReadOnlySpan<byte>, Span<byte>)

Decrypts a single block of ciphertext into the specified output span.

public override void Decrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

A read-only span containing the ciphertext block. Its byte length must equal BlockSize / 8.

output Span<byte>

A writable span that receives the plaintext block. Its byte length must equal BlockSize / 8.

Remarks

In-place decryption (passing the same buffer as both input and output) is supported only when the implementation explicitly permits it; otherwise the spans must not overlap.

Exceptions

ArgumentException

Thrown if the length of input or output does not match BlockSize.

Dispose(bool)

Releases all internal buffers and sensitive material.

protected override void Dispose(bool disposing)

Parameters

disposing bool

true when invoked from Dispose(); false when invoked from the finalizer.

Remarks

The base implementation records the disposed state. Derived Serpent implementations should override this method to clear expanded round keys, tweak material, and other sensitive buffers before calling base.Dispose(disposing).

Encrypt(ReadOnlySpan<byte>, Span<byte>)

Encrypts a single block of plaintext into the specified output span.

public override void Encrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

A read-only span containing the plaintext block. Its byte length must equal BlockSize / 8.

output Span<byte>

A writable span that receives the ciphertext block. Its byte length must equal BlockSize / 8.

Remarks

In-place encryption (passing the same buffer as both input and output) is supported only when the implementation explicitly permits it; otherwise the spans must not overlap.

Exceptions

ArgumentException

Thrown if the length of input or output does not match BlockSize.

Applies to

ProductVersions
.NET8, 10