Table of Contents

TwofishBlockCipher Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
TwofishBlockCipher.cs

Provides the core Twofish block cipher engine, implementing low-level encryption and decryption of individual 128-bit blocks.

public sealed class TwofishBlockCipher : IBlockCipher, IDisposable
Inheritance
TwofishBlockCipher
Implements
Inherited Members
Extension Methods

Examples

// Direct single-block use. For most workloads prefer the Twofish SymmetricAlgorithm wrapper.
byte[] key = new byte[32];   // 128, 192, or 256 bits
RandomNumberGenerator.Fill(key);

using var cipher = new TwofishBlockCipher(key);

byte[] plaintext  = new byte[16];   // one 128-bit block
byte[] ciphertext = new byte[16];
cipher.Encrypt(plaintext, ciphertext);

byte[] roundtrip = new byte[16];
cipher.Decrypt(ciphertext, roundtrip);
// roundtrip equals plaintext

Remarks

This class implements the raw Twofish block primitive. It operates on 128-bit blocks and supports 128-bit, 192-bit, and 256-bit keys.

Most callers should prefer the higher-level Twofish class, which exposes the standard SymmetricAlgorithm contract.

This implementation is constant-time in its control flow, but the precomputed key-dependent S-box/MDS tables are read at data-dependent indices on every round. As such, this implementation is not hardened against timing or cache-based side-channel attacks.

Constructors

TwofishBlockCipher(ReadOnlySpan<byte>)

Initializes a new instance of the TwofishBlockCipher class using the specified key.

public TwofishBlockCipher(ReadOnlySpan<byte> key)

Parameters

key ReadOnlySpan<byte>

The encryption key. Must be 16, 24, or 32 bytes in length. Must not be null.

Exceptions

ArgumentException

key is not 16, 24, or 32 bytes in length.

Properties

BlockSize

Gets the block size, in bits, of the cipher (for example, 128 bits / 16 bytes for AES).

public int BlockSize { get; }

Property Value

int

The block size, in bits.

Remarks

The block size is expressed in bits to align with the BCL convention used by BlockSize. Byte-array operations (encrypt, decrypt, slice) convert to bytes at the call site as BlockSize / 8.

Methods

Decrypt(ReadOnlySpan<byte>, Span<byte>)

Decrypts a single block of ciphertext into the specified output span.

public void Decrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

A read-only span containing the ciphertext block. Its byte length must equal BlockSize / 8.

output Span<byte>

A writable span that receives the plaintext block. Its byte length must equal BlockSize / 8.

Remarks

In-place decryption (passing the same buffer as both input and output) is supported only when the implementation explicitly permits it; otherwise the spans must not overlap.

Exceptions

ArgumentException

Thrown if the length of input or output does not match BlockSize.

Dispose()

Performs application-defined tasks associated with freeing, releasing, or resetting unmanaged resources.

public void Dispose()

Encrypt(ReadOnlySpan<byte>, Span<byte>)

Encrypts a single block of plaintext into the specified output span.

public void Encrypt(ReadOnlySpan<byte> input, Span<byte> output)

Parameters

input ReadOnlySpan<byte>

A read-only span containing the plaintext block. Its byte length must equal BlockSize / 8.

output Span<byte>

A writable span that receives the ciphertext block. Its byte length must equal BlockSize / 8.

Remarks

In-place encryption (passing the same buffer as both input and output) is supported only when the implementation explicitly permits it; otherwise the spans must not overlap.

Exceptions

ArgumentException

Thrown if the length of input or output does not match BlockSize.

Applies to

ProductVersions
.NET8, 10

See Also