Table of Contents

SkipjackBlockCipher Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
SkipjackBlockCipher.cs

Provides a managed implementation of the Skipjack block cipher engine, operating on 64-bit blocks with an 80-bit key over 32 rounds. Skipjack was designed by the United States National Security Agency (NSA) and declassified in 1998; the key schedule and Rule A / Rule B alternation are binary-compatible with the NSA reference implementation published in FIPS PUB 185 (1994).

public sealed class SkipjackBlockCipher : IBlockCipher, IDisposable
Inheritance
SkipjackBlockCipher
Implements
Inherited Members
Extension Methods

Examples

// Direct single-block use. Skipjack is a legacy 80-bit-key cipher - use only for legacy
// compatibility, never for new systems.
byte[] key = new byte[10];   // 80-bit key
RandomNumberGenerator.Fill(key);

using var cipher = new SkipjackBlockCipher(key);

byte[] plaintext  = new byte[8];   // one 64-bit block
byte[] ciphertext = new byte[8];
cipher.Encrypt(plaintext, ciphertext);

byte[] roundtrip = new byte[8];
cipher.Decrypt(ciphertext, roundtrip);
// roundtrip equals plaintext

Remarks

Skipjack is a legacy symmetric block cipher whose 32 rounds alternate between two nonlinear rules known as Rule A and Rule B. In this implementation the round-key byte pointer advances by one per round and each round uses a constant equal to k + 1.

This cipher is included for compatibility and historical purposes only. Due to its small key and block sizes, Skipjack is not considered secure for use in new systems or applications.

  • Block size:8 bytes (64 bits)
  • Key size:10 bytes (80 bits)
  • Rounds:32 (16 × Rule A + 16 × Rule B)

This implementation is constant-time in its control flow, but the S-box lookup table remains data-dependent. As such, this implementation is not hardened against timing or cache-based side-channel attacks.

Most callers should prefer the higher-level Skipjack class, which exposes the standard SymmetricAlgorithm contract. Use SkipjackBlockCipher directly only when composing the raw block primitive with an IBlockCipherModeTransform (for example via BlockCipherModeFactory) or with an IPaddingStrategy.

Constructors

SkipjackBlockCipher(ReadOnlySpan<byte>)

Initializes a new instance of the SkipjackBlockCipher class using the supplied 80-bit key.

public SkipjackBlockCipher(ReadOnlySpan<byte> keyBytes)

Parameters

keyBytes ReadOnlySpan<byte>

Exactly 10 bytes of key material.

Exceptions

ArgumentException

Thrown if keyBytes is not exactly 10 bytes long.

Fields

KeySize

Length of the Skipjack key is 80 bits (10 bytes).

public const int KeySize = 80

Field Value

int

Properties

BlockSize

Gets the block size, in bits, of the cipher (for example, 128 bits / 16 bytes for AES).

public int BlockSize { get; }

Property Value

int

The block size, in bits.

Remarks

The block size is expressed in bits to align with the BCL convention used by BlockSize. Byte-array operations (encrypt, decrypt, slice) convert to bytes at the call site as BlockSize / 8.

Methods

Decrypt(ReadOnlySpan<byte>, Span<byte>)

Decrypts a single 64-bit ciphertext block.

public void Decrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

Ciphertext of exactly 8 bytes.

output Span<byte>

Buffer that receives the decrypted plaintext. Must be exactly 8 bytes.

Remarks

Mirrors the FIPS PUB 185 decrypt sequence, including the word-order swap in the input/output stages. Decryption applies the inverse round rules in reverse round-key order, using H as the inverse of G.

Exceptions

ArgumentException

Thrown if input or output is not exactly 8 bytes.

ObjectDisposedException

The cipher instance has been disposed.

Dispose()

Securely clears key material and marks the instance as disposed.

public void Dispose()

Encrypt(ReadOnlySpan<byte>, Span<byte>)

Encrypts a single 64-bit block.

public void Encrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

The plaintext block to encrypt. Must be exactly 8 bytes.

output Span<byte>

Buffer that receives the 8-byte ciphertext. Must be exactly 8 bytes.

Remarks

The routine implements the FIPS PUB 185 Skipjack schedule: the key pointer advances by four key bytes inside G for each round, and the rule counter injected into each round is k + 1.

Exceptions

ArgumentException

Thrown if input or output is not exactly 8 bytes.

ObjectDisposedException

The cipher instance has been disposed.

Applies to

ProductVersions
.NET8, 10

See Also