XSalsa20Poly1305Aead Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- XSalsa20Poly1305Aead.cs
Provides authenticated encryption with associated data (AEAD) using the XSalsa20 stream cipher with the RFC 8439 Poly1305 framing. Accepts a 256-bit key and a 192-bit nonce and produces a 128-bit authentication tag. This class cannot be inherited.
public sealed class XSalsa20Poly1305Aead : Poly1305AeadTransform, IStreamAeadTransform, IAeadTransform, IDisposable
- Inheritance
-
XSalsa20Poly1305Aead
- Implements
- Inherited Members
- Extension Methods
Remarks
Bodu-defined construction. This is not an IETF-standardised AEAD: there is no RFC, no IETF
registry assignment, and no published interoperability vector for XSalsa20 combined with the RFC 8439 Poly1305
framing. It is also not wire-compatible with NaCl / libsodium crypto_secretbox. Use it only when
both peers are Bodu, or when a protocol explicitly specifies this hybrid. For interoperable choices use
XChaCha20Poly1305 (AEAD with associated data) or XSalsa20Poly1305 (secretbox).
The construction mirrors XChaCha20Poly1305 but substitutes the XSalsa20 keystream: a
256-bit subkey is derived from the key and the first 128 bits of the nonce via HSalsa20, and Salsa20 runs under that
subkey with the trailing 64 bits of the nonce. The counter-0 keystream block yields the one-time
Poly1305 key, the message is encrypted from counter 1 onward, and the tag authenticates
AAD ‖ pad16(AAD) ‖ ciphertext ‖ pad16(ciphertext) ‖ le64(|AAD|) ‖ le64(|ciphertext|).
Each instance is single-use. A new instance must be created for every message. Reusing a nonce under the same key
destroys confidentiality and authenticity. Associated data is passed directly to
Encrypt(ReadOnlySpan<byte>, Span<byte>, ReadOnlySpan<byte>) or Decrypt(ReadOnlySpan<byte>, Span<byte>, ReadOnlySpan<byte>) and defaults to empty; the emitted
wire format is ciphertext ‖ tag.
Key separation. Do not reuse a key across this construction, the raw XSalsa20 stream cipher, the XSalsa20Poly1305 secretbox, or any other AEAD construction unless an external key- separation scheme derives an independent key for each use.
Constructors
XSalsa20Poly1305Aead(byte[], byte[])
Initializes a new instance of the XSalsa20Poly1305Aead class with the specified key and nonce.
public XSalsa20Poly1305Aead(byte[] key, byte[] nonce)
Parameters
keybyte[]The 256-bit (32-byte) secret key. Must not be null.
noncebyte[]The 192-bit (24-byte) nonce. Must be unique for every message encrypted under the same key. Must not be null.
Exceptions
- ArgumentNullException
keyornonceis null.- ArgumentException
keyis not exactly 32 bytes, ornonceis not exactly 24 bytes.
XSalsa20Poly1305Aead(ReadOnlySpan<byte>, ReadOnlySpan<byte>)
Initializes a new instance of the XSalsa20Poly1305Aead class with the specified key and nonce spans.
public XSalsa20Poly1305Aead(ReadOnlySpan<byte> key, ReadOnlySpan<byte> nonce)
Parameters
keyReadOnlySpan<byte>The 256-bit (32-byte) secret key.
nonceReadOnlySpan<byte>The 192-bit (24-byte) nonce. Must be unique for every message encrypted under the same key.
Exceptions
- ArgumentException
keyis not exactly 32 bytes, ornonceis not exactly 24 bytes.
Fields
KeySize
Length of the XSalsa20-Poly1305 key is 256 bits (32 bytes).
public const int KeySize = 256
Field Value
NonceSize
Length of the XSalsa20-Poly1305 nonce is 192 bits (24 bytes).
public const int NonceSize = 192
Field Value
Methods
CreateEngine()
Creates the keystream engine for a single message, positioned at block counter 0.
protected override IStreamCipher CreateEngine()
Returns
- IStreamCipher
A freshly constructed IStreamCipher bound to Key and Nonce.
Remarks
The caller owns the returned engine and disposes it after the message completes.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |