Table of Contents

XSalsa20 Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
XSalsa20.cs

Provides a managed implementation of the extended-nonce XSalsa20 stream cipher specified by Daniel J. Bernstein. This class cannot be inherited.

public sealed class XSalsa20 : SymmetricStreamAlgorithm, IDisposable
Inheritance
XSalsa20
Implements
Inherited Members
Extension Methods

Examples

using Bodu.Security.Cryptography;
using Bodu.Security.Cryptography.Extensions;

using var xsalsa = new XSalsa20();
xsalsa.GenerateKey(); // 256-bit
xsalsa.GenerateNonce(); // 192-bit nonce - safe to choose at random
byte[] ciphertext = xsalsa.Encrypt(plaintext);
byte[] roundTrip  = xsalsa.Decrypt(ciphertext);

Remarks

XSalsa20 extends Salsa20 from a 64-bit nonce to a 192-bit nonce. The longer nonce is large enough to choose at random per message without meaningful collision risk, which makes XSalsa20 the safer default for protocols that cannot guarantee a unique 64-bit counter - the construction underlying NaCl / libsodium's crypto_stream_xsalsa20.

The construction is a thin shell over Salsa20: the first 128 bits of the 192-bit nonce are combined with the key via HSalsa20 to derive a 256-bit subkey, and the cipher then runs as ordinary Salsa20 under that subkey with the remaining 64 bits of the original nonce. All keystream generation, partial-block carry, and counter-overflow protection are inherited from the shared Bodu.Security.Cryptography.StreamCipherTransform / Bodu.Security.Cryptography.Salsa20StreamCipher stack, so XSalsa20 contains no duplicate cipher logic.

Parameters at a glance.

  • Key size: 256 bits (32 bytes).
  • Nonce (IV) size: 192 bits (24 bytes).
  • Block counter: 64-bit, starting at InitialCounter (default 0).

Like Salsa20 this is the raw, confidentiality-only cipher and is self-inverse. For authenticated encryption, pair it with a MAC such as Poly1305.

Constructors

XSalsa20()

Initializes a new instance of the XSalsa20 class with default parameters.

public XSalsa20()

Remarks

The default configuration uses a 256-bit key and a 192-bit nonce, with the block counter starting at 0.

Properties

InitialCounter

Gets or sets the initial 64-bit block counter used when generating the keystream.

public ulong InitialCounter { get; set; }

Property Value

ulong

The starting block-counter value. The default is 0.

Remarks

libsodium's crypto_stream_xsalsa20 starts the counter at 0. Set this before creating an encryptor or decryptor when matching an external counter convention.

Methods

Create()

Creates a new XSalsa20 instance with default parameters.

public static XSalsa20 Create()

Returns

XSalsa20

A new XSalsa20 instance.

CreateStreamCipher(byte[], byte[])

Builds a configured IStreamCipher engine from the validated key and nonce.

protected override IStreamCipher CreateStreamCipher(byte[] key, byte[] nonce)

Parameters

key byte[]

The key, already validated to the algorithm's key size.

nonce byte[]

The nonce, already validated to the algorithm's nonce size.

Returns

IStreamCipher

A new IStreamCipher engine positioned at the start of its keystream.

Remarks

Implementations receive a key and nonce whose lengths have already been checked by the base class, so they need only construct their engine. Ownership of the returned engine transfers to the caller.

Applies to

ProductVersions
.NET8, 10

See Also