Interface IAeadCipher
- Namespace
- CryptoHives.Foundation.Security.Cryptography.Cipher
- Assembly
- CryptoHives.Foundation.Security.Cryptography.dll
Defines an Authenticated Encryption with Associated Data (AEAD) cipher.
public interface IAeadCipher : IDisposable
- Inherited Members
Remarks
AEAD ciphers provide both confidentiality (encryption) and authenticity (integrity verification) in a single operation. They also support authenticating additional data that is not encrypted.
Common AEAD algorithms:
- AES-GCM (Galois/Counter Mode)
- ChaCha20-Poly1305
- AES-CCM (Counter with CBC-MAC)
Properties
AlgorithmName
Gets the algorithm name.
string AlgorithmName { get; }
Property Value
KeySizeBytes
Gets the key size in bytes.
int KeySizeBytes { get; }
Property Value
NonceSizeBytes
Gets the nonce size in bytes.
int NonceSizeBytes { get; }
Property Value
TagSizeBytes
Gets the authentication tag size in bytes.
int TagSizeBytes { get; }
Property Value
Methods
Decrypt(ReadOnlySpan<byte>, ReadOnlySpan<byte>, ReadOnlySpan<byte>)
Decrypts the ciphertext (with appended tag) and verifies authenticity.
byte[] Decrypt(ReadOnlySpan<byte> nonce, ReadOnlySpan<byte> ciphertextWithTag, ReadOnlySpan<byte> associatedData = default)
Parameters
nonceReadOnlySpan<byte>The nonce used during encryption.
ciphertextWithTagReadOnlySpan<byte>The ciphertext with appended authentication tag.
associatedDataReadOnlySpan<byte>Additional authenticated data (must match encryption).
Returns
- byte[]
The decrypted plaintext.
Exceptions
- CryptographicException
Authentication failed - the data has been tampered with or the wrong key/nonce was used.
Decrypt(ReadOnlySpan<byte>, ReadOnlySpan<byte>, ReadOnlySpan<byte>, Span<byte>, ReadOnlySpan<byte>)
Decrypts the ciphertext and verifies the authentication tag.
bool Decrypt(ReadOnlySpan<byte> nonce, ReadOnlySpan<byte> ciphertext, ReadOnlySpan<byte> tag, Span<byte> plaintext, ReadOnlySpan<byte> associatedData = default)
Parameters
nonceReadOnlySpan<byte>The nonce used during encryption.
ciphertextReadOnlySpan<byte>The encrypted data.
tagReadOnlySpan<byte>The authentication tag to verify.
plaintextSpan<byte>The output buffer for decrypted data (same size as ciphertext).
associatedDataReadOnlySpan<byte>Additional authenticated data (must match encryption).
Returns
- bool
True if decryption and authentication succeeded; false if authentication failed.
Exceptions
- ArgumentException
nonceortagis not the correct size, orplaintextbuffer is too small.
Encrypt(ReadOnlySpan<byte>, ReadOnlySpan<byte>, ReadOnlySpan<byte>)
Encrypts the plaintext and returns ciphertext with appended tag.
byte[] Encrypt(ReadOnlySpan<byte> nonce, ReadOnlySpan<byte> plaintext, ReadOnlySpan<byte> associatedData = default)
Parameters
nonceReadOnlySpan<byte>The unique nonce for this encryption.
plaintextReadOnlySpan<byte>The data to encrypt.
associatedDataReadOnlySpan<byte>Additional data to authenticate (optional).
Returns
- byte[]
The ciphertext with authentication tag appended.
Encrypt(ReadOnlySpan<byte>, ReadOnlySpan<byte>, Span<byte>, Span<byte>, ReadOnlySpan<byte>)
Encrypts the plaintext and computes the authentication tag.
void Encrypt(ReadOnlySpan<byte> nonce, ReadOnlySpan<byte> plaintext, Span<byte> ciphertext, Span<byte> tag, ReadOnlySpan<byte> associatedData = default)
Parameters
nonceReadOnlySpan<byte>The unique nonce for this encryption.
plaintextReadOnlySpan<byte>The data to encrypt.
ciphertextSpan<byte>The output buffer for ciphertext (same size as plaintext).
tagSpan<byte>The output buffer for the authentication tag.
associatedDataReadOnlySpan<byte>Additional data to authenticate (optional).
Exceptions
- ArgumentException
nonceis not the correct size, orciphertextortagbuffers are too small.