Table of Contents

Tiger Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Tiger.SBoxConstants.cs

Computes a hash using the Tiger cryptographic hash algorithm by Ross Anderson and Eli Biham (1996), optimized for 64-bit platforms. Supports output sizes of 128, 160, or 192 bits and both the original Tiger and Tiger2 padding variants. This class cannot be inherited.

public sealed class Tiger : BlockHashAlgorithm, ICryptoTransform, IDisposable
Inheritance
Tiger
Implements
Inherited Members
Extension Methods

Examples

using var tiger = new Tiger(192) { Variant = TigerHashingVariant.Tiger2 };
byte[] digest = tiger.ComputeHash(message);

Remarks

Tiger processes input in 512-bit (64-byte) blocks using three 64-bit internal state variables. Each block is mixed into the state by three passes, and each pass performs eight S-box driven mixing rounds separated by a key schedule applied to the block words.

The full 192-bit digest is always computed internally; shorter outputs (Tiger/128 and Tiger/160) are produced by truncation after finalization. The padding byte is selected via Variant: Tiger uses 0x01 (the original specification) and Tiger2 uses 0x80.

Although no longer recommended for new security-sensitive applications, Tiger has not been broken in the classical collision sense and is still useful for legacy interoperability and as a fast integrity hash.

Parameters at a glance.

  • Output size: 128, 160, or 192 bits - internally always 192 bits, then truncated.
  • Block size: 64 bytes (512 bits); three 64-bit state variables.
  • Three passes per block, eight S-box rounds per pass; optimized for 64-bit hosts.
  • Padding variant: Tiger (0x01) or Tiger2 (0x80).

When to choose Tiger. Pick Tiger only for legacy interoperability - TigerTree (Merkle hash of Tiger-192 leaves) is still seen in older P2P and content-addressed storage systems. For any new security design use a SHA-2 family member or Blake2b; for fast non-cryptographic fingerprinting the algorithms in Bodu.IO.Hashing are usually a better fit.

This implementation is constant-time in its control flow, but the S-box lookup tables are read at message-dependent indices, so hashing secret data (for example inside a keyed construction) is not hardened against timing or cache-based side-channel attacks.

Constructors

Tiger()

Initializes a new instance of the Tiger class with a 192-bit output hash size.

public Tiger()

Tiger(int)

Initializes a new instance of the Tiger class with the specified output size.

public Tiger(int hashSize)

Parameters

hashSize int

The desired output size in bits. Must be one of 128, 160, or 192.

Exceptions

ArgumentOutOfRangeException

Thrown if hashSize is not valid.

Properties

AlgorithmName

Gets the fully qualified algorithm name, including the variant and hash output size.

public override string AlgorithmName { get; }

Property Value

string

A string in the form Tiger/x, where x is the number of bits in the final hash output.

Remarks

The name follows the convention Tiger/x, where x is the number of output bits-typically 128, 160, or 192. These correspond to the standard Tiger variants: Tiger/128, Tiger/160, and Tiger/192.

The full 192-bit internal state is always computed. If a shorter output length is selected, the result is truncated after finalization to match the configured HashSize.

CanReuseTransform

Gets a value indicating whether the current transform can be reused.

public override bool CanReuseTransform { get; }

Property Value

bool

Always true.

CanTransformMultipleBlocks

When overridden in a derived class, gets a value indicating whether multiple blocks can be transformed.

public override bool CanTransformMultipleBlocks { get; }

Property Value

bool

true if multiple blocks can be transformed; otherwise, false.

HashSize

Gets or sets the size, in bits, of the final computed hash output.

public int HashSize { get; set; }

Property Value

int

Remarks

Valid values are 128, 160, or 192. This determines how many bits of the internal state are returned in the final digest. Larger sizes increase output strength but may reduce compatibility with some Tiger implementations.

Exceptions

ArgumentOutOfRangeException

Thrown if the value is not 128, 160, or 192.

ObjectDisposedException

The algorithm instance has been disposed.

CryptographicUnexpectedOperationException

Thrown if the hash computation has already started.

Variant

Gets or sets the Tiger variant to use when computing the hash value.

public TigerHashingVariant Variant { get; set; }

Property Value

TigerHashingVariant

Remarks

The TigerHashingVariant determines the padding byte used in the final message block:

  • Tiger uses a padding byte of 0x01 as per the original Tiger specification.
  • Tiger2 uses a padding byte of 0x80 as introduced in the Tiger2 variant to match typical Merkle�Damg�rd padding semantics.

The variant must be specified before hash computation begins. Changing it after processing has started will throw an exception.

Exceptions

ArgumentOutOfRangeException

Thrown if the assigned value is not a valid TigerHashingVariant enumeration value.

ObjectDisposedException

Thrown if the hash algorithm instance has already been disposed.

CryptographicUnexpectedOperationException

Thrown if the hash algorithm has already started processing input and is in an immutable state.

Methods

Dispose(bool)

Releases resources used by the algorithm and clears the internal state variables.

protected override void Dispose(bool disposing)

Parameters

disposing bool

true to release both managed and unmanaged resources; false to release only unmanaged resources.

Initialize()

Resets the algorithm to its initial state by clearing the residual buffer and the running byte total. Derived classes override this method, call base.Initialize() first, and then reset their own algorithm-specific state (chaining variables, IV, key-derived schedule).

public override void Initialize()

Remarks

This method does not reset the State property explicitly on .NET 6+ targets — the framework manages that transition. On earlier targets, derived classes that need the already-finalized guard should reset their _finalized backing field from their own Initialize override.

Derived classes that need to validate state before the reset (for example, a keyed MAC that refuses to be re-initialized when no key has been set) should perform that validation before calling base.Initialize(). Once the base call returns, the residual buffer is empty, Bodu.Security.Cryptography.BufferedBlockHashAlgorithm._residualBytes is 0, and Bodu.Security.Cryptography.BufferedBlockHashAlgorithm._totalBytes is 0.

Exceptions

ObjectDisposedException

The instance has been disposed.

PadBlock(ReadOnlySpan<byte>, ulong, Span<byte>)

Pads the final partial block of input data into destination and appends the encoded total message length, without allocating a padded copy on the heap.

protected override int PadBlock(ReadOnlySpan<byte> block, ulong messageLength, Span<byte> destination)

Parameters

block ReadOnlySpan<byte>

The final block of unprocessed input, typically containing 0 to BlockSize-1 bytes.

messageLength ulong

The total number of message bytes consumed by the algorithm, including the bytes in block. This is the value most Merkle-Damgård length encodings append.

destination Span<byte>

The span receiving the padded block or blocks; at least two blocks (2 × BlockSize / 8 bytes) long. The caller clears the span after processing.

Returns

int

The number of bytes written - one or two whole blocks, ready for ProcessBlock(ReadOnlySpan<byte>).

Remarks

The default implementation delegates to the array-returning PadBlock(ReadOnlySpan<byte>, ulong) overload and clears the intermediate array; see that overload's remarks for the override contract.

ProcessBlock(ReadOnlySpan<byte>)

Transforms a complete block of input data and updates the internal hash state.

protected override void ProcessBlock(ReadOnlySpan<byte> block)

Parameters

block ReadOnlySpan<byte>

The input block to process. Its length must match the algorithm's configured block size.

Remarks

This method performs the core transformation logic of the hash algorithm. It is called repeatedly with aligned input blocks and is not responsible for padding or finalization steps.

Exceptions

ArgumentException

Thrown if the block is not the expected size.

ProcessFinalBlock()

Finalizes the hash computation and returns the digest, truncated to HashSize / 8 bytes where applicable.

protected override byte[] ProcessFinalBlock()

Returns

byte[]

A byte array of 16, 20, or 24 bytes corresponding to the configured hash size (128, 160, or 192 bits).

Applies to

ProductVersions
.NET8, 10

See Also