Table of Contents

Using Threefish-1024

Threefish1024 is the largest variant in the Threefish family: 1024-bit (128-byte) blocks with a 1024-bit (128-byte) key and a 128-bit (16-byte) tweak. Reach for Threefish-1024 when you want the widest plausible block size - for example in domains that demand very large key/block margins, or where you want to encrypt a chunk that's naturally 128 bytes wide without chaining overhead per inner field.

Threefish round function - MIX, word permutation, and subkey injection

Note

Encrypt/decrypt ships an AVX-512 fast path that engages automatically on supporting hardware. See Hardware acceleration & SIMD opt-out for when it runs and how to force the scalar path.

Fixed sizes at a glance

Parameter Size Notes
Block size 1024 bits (128 bytes) Ciphertext is a multiple of 128 bytes (except in stream modes).
Key size 1024 bits (128 bytes) Fixed.
Tweak size 128 bits (16 bytes) Fixed across the Threefish family.
IV size 1024 bits (128 bytes) Always matches the block size.

Encrypt and decrypt - CBC + PKCS7

using System.Diagnostics;
using System.Linq;
using System.Security.Cryptography;
using System.Text;
using Bodu.Security.Cryptography;
using Bodu.Security.Cryptography.Extensions;

byte[] plaintext = Encoding.UTF8.GetBytes("a substantial payload that benefits from a 128-byte block");

byte[] key, iv, tweak, ciphertext;
using (var alg = new Threefish1024 { BlockMode = CipherModeKind.CBC, Padding = PaddingMode.PKCS7 })
{
    alg.GenerateKey();
    alg.GenerateIV();
    alg.GenerateTweak();

    key   = alg.Key;     // 128 bytes
    iv    = alg.IV;      // 128 bytes
    tweak = alg.Tweak;   // 16 bytes

    ciphertext = alg.Encrypt(plaintext);
}

byte[] recovered;
using (var alg = new Threefish1024 { BlockMode = CipherModeKind.CBC, Padding = PaddingMode.PKCS7,
                                      Key = key, IV = iv, Tweak = tweak })
{
    recovered = alg.Decrypt(ciphertext);
}

Debug.Assert(plaintext.SequenceEqual(recovered));

Encrypt and decrypt - CTR (stream mode)

using var alg = new Threefish1024
{
    BlockMode = CipherModeKind.CTR,
    Padding   = PaddingMode.None,
};
alg.GenerateKey();
alg.GenerateIV();
alg.GenerateTweak();

byte[] ciphertext = alg.Encrypt(plaintext);
byte[] recovered  = alg.Decrypt(ciphertext);

Debug.Assert(plaintext.SequenceEqual(recovered));

Trade-offs worth knowing

  • Most rounds in the family. Threefish-1024 runs 80 rounds over sixteen 64-bit words, injecting a subkey every four rounds plus a final injection - 21 subkeys in all. That is the largest key schedule of the family and therefore the largest per-instance memory footprint. Throughput is roughly half of Threefish-512 on the same CPU.
  • Padding waste. A PKCS7 round-up to the next 128-byte boundary costs more than the 32-byte Threefish-256 round-up. If your plaintexts are short, Threefish-256 produces smaller ciphertexts.
  • Same 128-bit tweak. The tweak does not scale with the block - it is 16 bytes here exactly as in Threefish-256/512, so the per-context domain-separation pattern (Threefish-256) carries over unchanged.
  • When to prefer it. When your natural record size is already ≥ 128 bytes, when you want a single-block encryption of a large structured field, or when you want the widest defensive margin against future block-size attacks. For everyday use Threefish-512 is the better balance.

The raw primitive

Threefish1024Cipher is the underlying IBlockCipher - a 128-byte key and 16-byte tweak in its constructor, one 128-byte block per Encrypt / Decrypt call. Use it for hand-composed pipelines; see Composing primitives. Like the rest of the family its 128-byte block is far too wide for the 128-bit-block AEAD transforms, so authenticate with encrypt-then-MAC or use the AES-based AEAD modes.

Where to go next