Table of Contents

Threefish256Cipher Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
ThreefishBlockCipher.256.Avx512.cs

AVX-512 vectorised implementation of Threefish256Cipher. The four 64-bit state words are split across two Vector128<T> registers - lo holds the even-position words (b0, b2) and hi the odd-position words (b1, b3). Each round performs a vector add, a per-lane variable rotate (VPROLVQ ), an XOR, and a single 64-bit lane swap on hi that realigns it for the next round's MIX pairing.

public sealed class Threefish256Cipher : ThreefishBlockCipher, IBlockCipher, IDisposable
Inheritance
Threefish256Cipher
Implements
Inherited Members
Extension Methods

Examples

// Direct single-block use - most callers should prefer the Threefish256 SymmetricAlgorithm.
byte[] key   = new byte[32];   // 256-bit key
byte[] tweak = new byte[16];   // 128-bit tweak
RandomNumberGenerator.Fill(key);
RandomNumberGenerator.Fill(tweak);

using var cipher = new Threefish256Cipher(key, tweak);

byte[] plaintext  = new byte[32];   // one 256-bit block
byte[] ciphertext = new byte[32];
cipher.Encrypt(plaintext, ciphertext);

byte[] roundtrip = new byte[32];
cipher.Decrypt(ciphertext, roundtrip);
// roundtrip equals plaintext

Remarks

Threefish-256 alternates between two MIX pair patterns within a 4-round group: (0,1)(2,3) at rounds 0 and 2, and (0,3)(2,1) at rounds 1 and 3. With the state split into even/odd halves, the alternation reduces to a single swap of hi's two lanes - applied four times in a row, the swaps cycle back to canonical layout, which is exactly where the subkey injection lands.

Gated on IsSupported because the per-lane variable rotate runs on Vector128<T>. SIMD gain on Threefish-256 is the smallest of the three variants - the 128-bit working width matches scalar register count and the per-instruction overhead is high relative to the work - but the implementation keeps the family pattern consistent and provides a measured reduction in scalar instruction count per round.

Constructors

Threefish256Cipher(ReadOnlySpan<byte>, ReadOnlySpan<byte>)

Initializes a new instance of the Threefish256Cipher class using the specified key and tweak.

public Threefish256Cipher(ReadOnlySpan<byte> key, ReadOnlySpan<byte> tweak)

Parameters

key ReadOnlySpan<byte>

The 256-bit (32-byte) key used for encryption and decryption.

tweak ReadOnlySpan<byte>

The 128-bit (16-byte) tweak value used to modify the block cipher behavior.

Fields

KeySize

Length of the Threefish-256 key is 256 bits (32 bytes).

public const int KeySize = 256

Field Value

int

Properties

BlockSize

Gets the block size, in bits, of the cipher (for example, 128 bits / 16 bytes for AES).

public override int BlockSize { get; }

Property Value

int

The block size, in bits.

Remarks

The block size is expressed in bits to align with the BCL convention used by BlockSize. Byte-array operations (encrypt, decrypt, slice) convert to bytes at the call site as BlockSize / 8.

BlockWords

Gets the number of 64-bit words in a single block.

protected override int BlockWords { get; }

Property Value

int

RotationSchedule

Gets the rotation constants used for MIX/UNMIX operations in this cipher variant.

protected override int[] RotationSchedule { get; }

Property Value

int[]

Rounds

Gets the total number of cipher rounds.

protected override int Rounds { get; }

Property Value

int

Methods

Decrypt(ReadOnlySpan<byte>, Span<byte>)

Decrypts a single 32-byte ciphertext block using the Threefish-256 cipher and writes the result to the specified output buffer.

public override void Decrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

The 32-byte ciphertext block to decrypt.

output Span<byte>

The 32-byte buffer to receive the decrypted plaintext block.

Remarks

Dispatches to an AVX-512 vectorised implementation when supported by the host, falling back to a scalar register-resident implementation otherwise. Dispatch is gated by Bodu.Security.Cryptography.SimdCapabilities.Avx512FVL, which combines the hardware intrinsic with the process-wide SIMD opt-out; on hosts without AVX-512 it still folds to a compile-time constant that removes the branch, otherwise it reduces to a single cached-boolean load.

Exceptions

ObjectDisposedException

Thrown if the cipher has been disposed.

ArgumentException

Thrown if input or output is not 32 bytes.

Encrypt(ReadOnlySpan<byte>, Span<byte>)

Encrypts a single 32-byte plaintext block using the Threefish-256 cipher and writes the result to the specified output buffer.

public override void Encrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

The 32-byte plaintext block to encrypt.

output Span<byte>

The 32-byte buffer to receive the encrypted ciphertext block.

Remarks

Dispatches to an AVX-512 vectorised implementation when supported by the host, falling back to a scalar register-resident implementation otherwise. Dispatch is gated by Bodu.Security.Cryptography.SimdCapabilities.Avx512FVL, which combines the hardware intrinsic with the process-wide SIMD opt-out; on hosts without AVX-512 it still folds to a compile-time constant that removes the branch, otherwise it reduces to a single cached-boolean load.

Exceptions

ObjectDisposedException

Thrown if the cipher has been disposed.

ArgumentException

Thrown if input or output is not 32 bytes.

Applies to

ProductVersions
.NET8, 10

See Also