Table of Contents

SipHash64 Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
SipHash.64.cs

Computes a 64-bit keyed hash using the SipHash algorithm by Aumasson and Bernstein. Produces an 8-byte authentication tag from a 128-bit key and is intended to protect hash tables against collision-based denial-of-service attacks. This class cannot be inherited.

public sealed class SipHash64 : SipHash, ICryptoTransform, IDisposable
Inheritance
SipHash64
Implements
Inherited Members
Extension Methods

Examples

using Bodu.Security.Cryptography;

// 16-byte secret key - keep it private to your process; SipHash assumes attackers cannot guess it.
byte[] hashTableKey = RandomNumberGenerator.GetBytes(16);
using var sip = new SipHash64 { Key = hashTableKey };
byte[] tag = sip.ComputeHash(System.Text.Encoding.UTF8.GetBytes("user-supplied-key"));

Remarks

SipHash64 is parameterized as SipHash-c-d, where c is the number of compression rounds and d is the number of finalization rounds. The default configuration corresponds to SipHash-2-4; stronger parameterizations such as SipHash-4-8 may be selected via CompressionRounds and FinalizationRounds.

See SipHash for a description of the round structure.

Parameters at a glance.

  • Tag size: 64 bits (8 bytes).
  • Key size: 128 bits (16 bytes).
  • Default parameterization: SipHash-2-4 (2 compression rounds, 4 finalization rounds).
  • Multi-message key reuse is supported - unlike Poly1305.

When to choose SipHash64. The right keyed hash for protecting in-memory hash tables and bloom filters against collision-based denial-of-service attacks - fast, fixed cost, and the de-facto standard in language runtimes (Python, Ruby, Rust, Perl). For 128-bit tag width or stronger long-term authentication guarantees pick SipHash128; for protocol-level message authentication use HMAC-SHA-256 or Blake2b-MAC.

Constructors

SipHash64()

Initializes a new instance of the SipHash64 class with a fixed 64-bit output size, the default SipHash-2-4 parameterization, and a freshly generated random key.

public SipHash64()

Remarks

The instance is created with the following defaults:

PropertyDefault Value
CompressionRoundsMinCompressionRounds (2)
FinalizationRoundsMinFinalizationRounds (4)
HashSize64
KeyCryptographically random 16-byte key containing no zero bytes.

Applies to

ProductVersions
.NET8, 10

See Also