XChaCha20 Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- XChaCha20.cs
Provides a managed implementation of the extended-nonce XChaCha20 stream cipher. This class cannot be inherited.
public sealed class XChaCha20 : SymmetricStreamAlgorithm, IDisposable
- Inheritance
-
XChaCha20
- Implements
- Inherited Members
- Extension Methods
Examples
using Bodu.Security.Cryptography;
using Bodu.Security.Cryptography.Extensions;
using var xchacha = new XChaCha20();
xchacha.GenerateKey(); // 256-bit
xchacha.GenerateNonce(); // 192-bit nonce - safe to choose at random
byte[] ciphertext = xchacha.Encrypt(plaintext);
byte[] roundTrip = xchacha.Decrypt(ciphertext);
Remarks
XChaCha20 extends RFC 8439 ChaCha20 to a 192-bit nonce, following draft-irtf-cfrg-xchacha. The longer nonce
is large enough to choose at random per message without meaningful collision risk, which makes XChaCha20 the safer
default for protocols that cannot guarantee a unique 96-bit counter - the use case behind libsodium's
crypto_stream_xchacha20.
The construction is a thin shell over ChaCha20: the first 128 bits of the 192-bit nonce are combined with the key via HChaCha20 to derive a 256-bit subkey, and the cipher then runs as ordinary ChaCha20 under that subkey with a 96-bit nonce formed as four zero bytes followed by the remaining 64 bits of the original nonce. All keystream generation, partial-block carry, and counter-overflow protection are inherited from the shared Bodu.Security.Cryptography.StreamCipherTransform / Bodu.Security.Cryptography.ChaCha20StreamCipher stack, so XChaCha20 contains no duplicate cipher logic.
Parameters at a glance.
- Key size: 256 bits (32 bytes).
- Nonce (IV) size: 192 bits (24 bytes).
- Block counter: 32-bit, starting at InitialCounter (default 0).
Like ChaCha20 this is the raw, confidentiality-only cipher and is self-inverse - encryptor and decryptor are interchangeable. For authenticated encryption, pair it with a MAC such as Poly1305.
Constructors
XChaCha20()
Initializes a new instance of the XChaCha20 class with default parameters.
public XChaCha20()
Remarks
The default configuration uses a 256-bit key and a 192-bit nonce, with the block counter starting at 0.
Properties
InitialCounter
Gets or sets the initial 32-bit block counter used when generating the keystream.
public uint InitialCounter { get; set; }
Property Value
- uint
The starting block-counter value. The default is 0.
Remarks
libsodium's crypto_stream_xchacha20 starts the counter at 0. Set this before creating an encryptor or
decryptor when matching an external counter convention.
Methods
Create()
Creates a new XChaCha20 instance with default parameters.
public static XChaCha20 Create()
Returns
CreateStreamCipher(byte[], byte[])
Builds a configured IStreamCipher engine from the validated key and nonce.
protected override IStreamCipher CreateStreamCipher(byte[] key, byte[] nonce)
Parameters
keybyte[]The key, already validated to the algorithm's key size.
noncebyte[]The nonce, already validated to the algorithm's nonce size.
Returns
- IStreamCipher
A new IStreamCipher engine positioned at the start of its keystream.
Remarks
Implementations receive a key and nonce whose lengths have already been checked by the base class, so they need only construct their engine. Ownership of the returned engine transfers to the caller.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |