Table of Contents

Threefish512Cipher Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
ThreefishBlockCipher.512.Avx512.cs

AVX-512 vectorised implementation of Threefish512Cipher. The eight 64-bit state words are split across two Vector256<T> registers - lo holds the even-position words (x0, x2, x4, x6) and hi the odd-position words (x1, x3, x5, x7) - and each round applies a vector add, a per-lane variable rotate (VPROLVQ), an XOR, and a pair of lane shuffles that realign the registers for the next round's MIX pairing.

public sealed class Threefish512Cipher : ThreefishBlockCipher, IBlockCipher, IDisposable
Inheritance
Threefish512Cipher
Implements
Inherited Members
Extension Methods

Examples

// Direct single-block use - most callers should prefer the Threefish512 SymmetricAlgorithm.
byte[] key   = new byte[64];   // 512-bit key
byte[] tweak = new byte[16];   // 128-bit tweak
RandomNumberGenerator.Fill(key);
RandomNumberGenerator.Fill(tweak);

using var cipher = new Threefish512Cipher(key, tweak);

byte[] plaintext  = new byte[64];   // one 512-bit block
byte[] ciphertext = new byte[64];
cipher.Encrypt(plaintext, ciphertext);

byte[] roundtrip = new byte[64];
cipher.Decrypt(ciphertext, roundtrip);
// roundtrip equals plaintext

Remarks

The per-round word permutation in Threefish-512 has a 4-round cycle: between rounds, the even-position register rotates its four lanes left by one (VPERMQ with control 0x39) and the odd-position register swaps lanes 1 and 3 (VPERMQ with control 0x6C). After four such shuffles both registers return to canonical layout, which is exactly the layout the subkey injection expects.

Gated on IsSupported rather than IsSupported because the variable rotate is invoked on Vector256<T> rather than Vector512<T>, which requires the AVX-512 Vector Length extensions. AVX-512VL has been bundled with AVX-512F on every mainstream Intel/AMD CPU shipping it (the only AVX-512F-without-VL parts were the discontinued Knights Landing / Knights Mill server processors).

Constructors

Threefish512Cipher(ReadOnlySpan<byte>, ReadOnlySpan<byte>)

Initializes a new instance of the Threefish512Cipher class using the specified key and tweak.

public Threefish512Cipher(ReadOnlySpan<byte> key, ReadOnlySpan<byte> tweak)

Parameters

key ReadOnlySpan<byte>

The 512-bit (64-byte) key used for encryption and decryption.

tweak ReadOnlySpan<byte>

The 128-bit (16-byte) tweak value used to modify the block cipher behavior.

Fields

KeySize

Length of the Threefish-512 key is 512 bits (64 bytes).

public const int KeySize = 512

Field Value

int

Properties

BlockSize

Gets the block size, in bits, of the cipher (for example, 128 bits / 16 bytes for AES).

public override int BlockSize { get; }

Property Value

int

The block size, in bits.

Remarks

The block size is expressed in bits to align with the BCL convention used by BlockSize. Byte-array operations (encrypt, decrypt, slice) convert to bytes at the call site as BlockSize / 8.

BlockWords

Gets the number of 64-bit words in a single block.

protected override int BlockWords { get; }

Property Value

int

RotationSchedule

Gets the rotation constants used for MIX/UNMIX operations in this cipher variant.

protected override int[] RotationSchedule { get; }

Property Value

int[]

Rounds

Gets the total number of cipher rounds.

protected override int Rounds { get; }

Property Value

int

Methods

Decrypt(ReadOnlySpan<byte>, Span<byte>)

Decrypts a single 64-byte ciphertext block using the Threefish-512 cipher and writes the result to the specified output buffer.

public override void Decrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

The 64-byte ciphertext block to decrypt.

output Span<byte>

The 64-byte buffer to receive the decrypted plaintext block.

Remarks

Dispatches to an AVX-512 vectorised implementation when supported by the host, falling back to a scalar register-resident implementation otherwise. Dispatch is gated by Bodu.Security.Cryptography.SimdCapabilities.Avx512FVL - the kernel rotates 256-bit vectors, which needs the VL extensions - combining the hardware intrinsic with the process-wide SIMD opt-out; on hosts without AVX-512 it still folds to a compile-time constant that removes the branch, otherwise it reduces to a single cached-boolean load.

Exceptions

ObjectDisposedException

Thrown if the cipher has been disposed.

ArgumentException

Thrown if input or output is not 64 bytes.

Encrypt(ReadOnlySpan<byte>, Span<byte>)

Encrypts a single 64-byte plaintext block using the Threefish-512 cipher and writes the result to the specified output buffer.

public override void Encrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

The 64-byte plaintext block to encrypt.

output Span<byte>

The 64-byte buffer to receive the encrypted ciphertext block.

Remarks

Dispatches to an AVX-512 vectorised implementation when supported by the host, falling back to a scalar register-resident implementation otherwise. Dispatch is gated by Bodu.Security.Cryptography.SimdCapabilities.Avx512FVL - the kernel rotates 256-bit vectors, which needs the VL extensions - combining the hardware intrinsic with the process-wide SIMD opt-out; on hosts without AVX-512 it still folds to a compile-time constant that removes the branch, otherwise it reduces to a single cached-boolean load.

Exceptions

ObjectDisposedException

Thrown if the cipher has been disposed.

ArgumentException

Thrown if input or output is not 64 bytes.

Applies to

ProductVersions
.NET8, 10

See Also