Table of Contents

XSalsa20Poly1305Aead Class

Definition

Namespace
Bodu.Security.Cryptography
Assembly
Bodu.Security.Cryptography.dll
Package
Bodu.Security.Cryptography 1.2.0
Source
XSalsa20Poly1305Aead.cs

Provides authenticated encryption with associated data (AEAD) using the XSalsa20 stream cipher with the RFC 8439 Poly1305 framing. Accepts a 256-bit key and a 192-bit nonce and produces a 128-bit authentication tag. This class cannot be inherited.

public sealed class XSalsa20Poly1305Aead : Poly1305AeadTransform, IStreamAeadTransform, IAeadTransform, IDisposable
Inheritance
XSalsa20Poly1305Aead
Implements
Inherited Members
Extension Methods

Remarks

Bodu-defined construction. This is not an IETF-standardised AEAD: there is no RFC, no IETF registry assignment, and no published interoperability vector for XSalsa20 combined with the RFC 8439 Poly1305 framing. It is also not wire-compatible with NaCl / libsodium crypto_secretbox. Use it only when both peers are Bodu, or when a protocol explicitly specifies this hybrid. For interoperable choices use XChaCha20Poly1305 (AEAD with associated data) or XSalsa20Poly1305 (secretbox).

The construction mirrors XChaCha20Poly1305 but substitutes the XSalsa20 keystream: a 256-bit subkey is derived from the key and the first 128 bits of the nonce via HSalsa20, and Salsa20 runs under that subkey with the trailing 64 bits of the nonce. The counter-0 keystream block yields the one-time Poly1305 key, the message is encrypted from counter 1 onward, and the tag authenticates AAD ‖ pad16(AAD) ‖ ciphertext ‖ pad16(ciphertext) ‖ le64(|AAD|) ‖ le64(|ciphertext|).

Each instance is single-use. A new instance must be created for every message. Reusing a nonce under the same key destroys confidentiality and authenticity. Associated data is passed directly to Encrypt(ReadOnlySpan<byte>, Span<byte>, ReadOnlySpan<byte>) or Decrypt(ReadOnlySpan<byte>, Span<byte>, ReadOnlySpan<byte>) and defaults to empty; the emitted wire format is ciphertext ‖ tag.

Key separation. Do not reuse a key across this construction, the raw XSalsa20 stream cipher, the XSalsa20Poly1305 secretbox, or any other AEAD construction unless an external key- separation scheme derives an independent key for each use.

Constructors

XSalsa20Poly1305Aead(byte[], byte[])

Initializes a new instance of the XSalsa20Poly1305Aead class with the specified key and nonce.

public XSalsa20Poly1305Aead(byte[] key, byte[] nonce)

Parameters

key byte[]

The 256-bit (32-byte) secret key. Must not be null.

nonce byte[]

The 192-bit (24-byte) nonce. Must be unique for every message encrypted under the same key. Must not be null.

Exceptions

ArgumentNullException

key or nonce is null.

ArgumentException

key is not exactly 32 bytes, or nonce is not exactly 24 bytes.

XSalsa20Poly1305Aead(ReadOnlySpan<byte>, ReadOnlySpan<byte>)

Initializes a new instance of the XSalsa20Poly1305Aead class with the specified key and nonce spans.

public XSalsa20Poly1305Aead(ReadOnlySpan<byte> key, ReadOnlySpan<byte> nonce)

Parameters

key ReadOnlySpan<byte>

The 256-bit (32-byte) secret key.

nonce ReadOnlySpan<byte>

The 192-bit (24-byte) nonce. Must be unique for every message encrypted under the same key.

Exceptions

ArgumentException

key is not exactly 32 bytes, or nonce is not exactly 24 bytes.

Fields

KeySize

Length of the XSalsa20-Poly1305 key is 256 bits (32 bytes).

public const int KeySize = 256

Field Value

int

NonceSize

Length of the XSalsa20-Poly1305 nonce is 192 bits (24 bytes).

public const int NonceSize = 192

Field Value

int

Methods

CreateEngine()

Creates the keystream engine for a single message, positioned at block counter 0.

protected override IStreamCipher CreateEngine()

Returns

IStreamCipher

A freshly constructed IStreamCipher bound to Key and Nonce.

Remarks

The caller owns the returned engine and disposes it after the message completes.

Applies to

ProductVersions
.NET8, 10

See Also