Table of Contents

Twofish Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
Twofish.cs

Provides a managed implementation of the Twofish symmetric block cipher. This class cannot be inherited.

public sealed class Twofish : ExtendedSymmetricAlgorithm, IDisposable
Inheritance
Twofish
Implements
Inherited Members
Extension Methods

Examples

using System.Security.Cryptography;
using Bodu.Security.Cryptography;
using Bodu.Security.Cryptography.Extensions;

using var twofish = new Twofish();
twofish.GenerateKey(); // 256-bit by default
twofish.GenerateIV();
byte[] ciphertext = twofish.Encrypt(plaintext);
byte[] roundTrip = twofish.Decrypt(ciphertext);

Remarks

Twofish is a symmetric-key block cipher designed by Bruce Schneier, John Kelsey, Doug Whiting, David Wagner, Chris Hall, and Niels Ferguson, and submitted as one of the five finalists in the Advanced Encryption Standard (AES) competition. The reference paper, Twofish: A 128-Bit Block Cipher (1998), specifies a 16-round Feistel network with key-dependent S-boxes, an MDS-based linear layer, and a Pseudo-Hadamard Transform providing diffusion across the Feistel halves. Twofish operates on 128-bit blocks and supports 128-bit, 192-bit, and 256-bit keys.

This class integrates with the .NET SymmetricAlgorithm framework and supports standard block cipher modes via the BlockMode property. The default mode is CBC with PKCS7 padding.

Parameters at a glance.

  • Block size: 128 bits (16 bytes).
  • Key sizes: 128, 192, or 256 bits.
  • 16-round Feistel structure with key-dependent S-boxes and an MDS-based linear layer.
  • Default mode: CBC; default padding: PKCS7.

When to choose Twofish. Pick Twofish when interoperability with existing Twofish-based code or formats is required, or when you want an AES finalist with strong software performance and a different design philosophy from AES. For new general-purpose work, Aes is the right default - hardware acceleration on most modern CPUs makes it the fastest option as well as the most widely vetted. Reach for Serpent128 when you specifically want the higher round count conservatism of that AES finalist.

important

For new general-purpose application encryption, prefer Aes unless Twofish compatibility is specifically required.

The underlying block-cipher implementation is constant-time in its control flow, but the precomputed key-dependent S-box/MDS tables are read at data-dependent indices on every round. As such, it is not hardened against timing or cache-based side-channel attacks.

Constructors

Twofish()

Initializes a new instance of the Twofish class with default parameters.

public Twofish()

Remarks

The default configuration uses a 128-bit block, a 256-bit key, CBC cipher mode, and PKCS7 padding.

Methods

Create()

Creates a new Twofish instance with default parameters.

public static Twofish Create()

Returns

Twofish

A new Twofish instance.

CreateDecryptor(byte[], byte[]?)

When overridden in a derived class, creates a symmetric decryptor object with the specified Key property and initialization vector (IV).

public override ICryptoTransform CreateDecryptor(byte[] rgbKey, byte[]? rgbIV)

Parameters

rgbKey byte[]

The secret key to use for the symmetric algorithm.

rgbIV byte[]

The initialization vector to use for the symmetric algorithm.

Returns

ICryptoTransform

A symmetric decryptor object.

CreateEncryptor(byte[], byte[]?)

When overridden in a derived class, creates a symmetric encryptor object with the specified Key property and initialization vector (IV).

public override ICryptoTransform CreateEncryptor(byte[] rgbKey, byte[]? rgbIV)

Parameters

rgbKey byte[]

The secret key to use for the symmetric algorithm.

rgbIV byte[]

The initialization vector to use for the symmetric algorithm.

Returns

ICryptoTransform

A symmetric encryptor object.

Dispose(bool)

Releases the unmanaged resources used by the SymmetricAlgorithm and optionally releases the managed resources.

protected override void Dispose(bool disposing)

Parameters

disposing bool

true to release both managed and unmanaged resources; false to release only unmanaged resources.

GenerateIV()

When overridden in a derived class, generates a random initialization vector (IV) to use for the algorithm.

public override void GenerateIV()

GenerateKey()

When overridden in a derived class, generates a random key (Key) to use for the algorithm.

public override void GenerateKey()

Applies to

ProductVersions
.NET8, 10

See Also