Tiger Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- Tiger.SBoxConstants.cs
Computes a hash using the Tiger cryptographic hash algorithm by Ross Anderson and Eli Biham (1996), optimized
for 64-bit platforms. Supports output sizes of 128, 160, or 192 bits and both the original
Tiger and Tiger2 padding variants. This class
cannot be inherited.
public sealed class Tiger : BlockHashAlgorithm, ICryptoTransform, IDisposable
- Inheritance
-
Tiger
- Implements
- Inherited Members
- Extension Methods
Examples
using var tiger = new Tiger(192) { Variant = TigerHashingVariant.Tiger2 };
byte[] digest = tiger.ComputeHash(message);
Remarks
Tiger processes input in 512-bit (64-byte) blocks using three 64-bit internal state variables. Each block is mixed into the state by three passes, and each pass performs eight S-box driven mixing rounds separated by a key schedule applied to the block words.
The full 192-bit digest is always computed internally; shorter outputs (Tiger/128 and Tiger/160) are
produced by truncation after finalization. The padding byte is selected via Variant:
Tiger uses 0x01 (the original specification) and
Tiger2 uses 0x80.
Although no longer recommended for new security-sensitive applications, Tiger has not been broken in the classical collision sense and is still useful for legacy interoperability and as a fast integrity hash.
Parameters at a glance.
- Output size: 128, 160, or 192 bits - internally always 192 bits, then truncated.
- Block size: 64 bytes (512 bits); three 64-bit state variables.
- Three passes per block, eight S-box rounds per pass; optimized for 64-bit hosts.
-
Padding variant: Tiger (
0x01) or Tiger2 (0x80).
When to choose Tiger. Pick Tiger only for legacy interoperability - TigerTree (Merkle hash of
Tiger-192 leaves) is still seen in older P2P and content-addressed storage systems. For any new security design use
a SHA-2 family member or Blake2b; for fast non-cryptographic fingerprinting the algorithms in
Bodu.IO.Hashing are usually a better fit.
This implementation is constant-time in its control flow, but the S-box lookup tables are read at message-dependent indices, so hashing secret data (for example inside a keyed construction) is not hardened against timing or cache-based side-channel attacks.
Constructors
Tiger()
Initializes a new instance of the Tiger class with a 192-bit output hash size.
public Tiger()
Tiger(int)
Initializes a new instance of the Tiger class with the specified output size.
public Tiger(int hashSize)
Parameters
hashSizeintThe desired output size in bits. Must be one of 128, 160, or 192.
Exceptions
- ArgumentOutOfRangeException
Thrown if
hashSizeis not valid.
Properties
AlgorithmName
Gets the fully qualified algorithm name, including the variant and hash output size.
public override string AlgorithmName { get; }
Property Value
- string
A string in the form
Tiger/x, wherexis the number of bits in the final hash output.
Remarks
The name follows the convention Tiger/x, where x is the number of output bits-typically 128, 160,
or 192. These correspond to the standard Tiger variants: Tiger/128, Tiger/160, and
Tiger/192.
The full 192-bit internal state is always computed. If a shorter output length is selected, the result is truncated after finalization to match the configured HashSize.
CanReuseTransform
Gets a value indicating whether the current transform can be reused.
public override bool CanReuseTransform { get; }
Property Value
CanTransformMultipleBlocks
When overridden in a derived class, gets a value indicating whether multiple blocks can be transformed.
public override bool CanTransformMultipleBlocks { get; }
Property Value
HashSize
Gets or sets the size, in bits, of the final computed hash output.
public int HashSize { get; set; }
Property Value
Remarks
Valid values are 128, 160, or 192. This determines how many bits of the internal state are
returned in the final digest. Larger sizes increase output strength but may reduce compatibility with some Tiger
implementations.
Exceptions
- ArgumentOutOfRangeException
Thrown if the value is not 128, 160, or 192.
- ObjectDisposedException
The algorithm instance has been disposed.
- CryptographicUnexpectedOperationException
Thrown if the hash computation has already started.
Variant
Gets or sets the Tiger variant to use when computing the hash value.
public TigerHashingVariant Variant { get; set; }
Property Value
Remarks
The TigerHashingVariant determines the padding byte used in the final message block:
-
Tiger uses a padding byte of
0x01as per the original Tiger specification. -
Tiger2 uses a padding byte of
0x80as introduced in the Tiger2 variant to match typical Merkle�Damg�rd padding semantics.
The variant must be specified before hash computation begins. Changing it after processing has started will throw an exception.
Exceptions
- ArgumentOutOfRangeException
Thrown if the assigned value is not a valid TigerHashingVariant enumeration value.
- ObjectDisposedException
Thrown if the hash algorithm instance has already been disposed.
- CryptographicUnexpectedOperationException
Thrown if the hash algorithm has already started processing input and is in an immutable state.
Methods
Dispose(bool)
Releases resources used by the algorithm and clears the internal state variables.
protected override void Dispose(bool disposing)
Parameters
Initialize()
Resets the algorithm to its initial state by clearing the residual buffer and the running byte total. Derived
classes override this method, call base.Initialize() first, and then reset their own algorithm-specific
state (chaining variables, IV, key-derived schedule).
public override void Initialize()
Remarks
This method does not reset the State property explicitly on .NET 6+ targets —
the framework manages that transition. On earlier targets, derived classes that need the already-finalized guard
should reset their _finalized backing field from their own Initialize override.
Derived classes that need to validate state before the reset (for example, a keyed MAC that refuses to be
re-initialized when no key has been set) should perform that validation before calling base.Initialize().
Once the base call returns, the residual buffer is empty, Bodu.Security.Cryptography.BufferedBlockHashAlgorithm._residualBytes is 0, and
Bodu.Security.Cryptography.BufferedBlockHashAlgorithm._totalBytes is 0.
Exceptions
- ObjectDisposedException
The instance has been disposed.
PadBlock(ReadOnlySpan<byte>, ulong, Span<byte>)
Pads the final partial block of input data into destination and appends the encoded total
message length, without allocating a padded copy on the heap.
protected override int PadBlock(ReadOnlySpan<byte> block, ulong messageLength, Span<byte> destination)
Parameters
blockReadOnlySpan<byte>The final block of unprocessed input, typically containing 0 to BlockSize-1 bytes.
messageLengthulongThe total number of message bytes consumed by the algorithm, including the bytes in
block. This is the value most Merkle-Damgård length encodings append.destinationSpan<byte>The span receiving the padded block or blocks; at least two blocks (
2 × BlockSize / 8bytes) long. The caller clears the span after processing.
Returns
- int
The number of bytes written - one or two whole blocks, ready for ProcessBlock(ReadOnlySpan<byte>).
Remarks
The default implementation delegates to the array-returning PadBlock(ReadOnlySpan<byte>, ulong) overload and clears the intermediate array; see that overload's remarks for the override contract.
ProcessBlock(ReadOnlySpan<byte>)
Transforms a complete block of input data and updates the internal hash state.
protected override void ProcessBlock(ReadOnlySpan<byte> block)
Parameters
blockReadOnlySpan<byte>The input block to process. Its length must match the algorithm's configured block size.
Remarks
This method performs the core transformation logic of the hash algorithm. It is called repeatedly with aligned input blocks and is not responsible for padding or finalization steps.
Exceptions
- ArgumentException
Thrown if the
blockis not the expected size.
ProcessFinalBlock()
Finalizes the hash computation and returns the digest, truncated to HashSize / 8 bytes where applicable.
protected override byte[] ProcessFinalBlock()
Returns
- byte[]
A byte array of 16, 20, or 24 bytes corresponding to the configured hash size (128, 160, or 192 bits).
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |