Class CryptographicOperations
- Namespace
- CryptoHives.Foundation.Security.Cryptography
- Assembly
- CryptoHives.Foundation.Security.Cryptography.dll
Operations on secret data that a compiler is not permitted to optimize: erasing a buffer, and comparing two in constant time.
public static class CryptographicOperations
- Inheritance
-
CryptographicOperations
- Inherited Members
Remarks
Prefer ZeroMemory(Span<byte>) over Clear(Array, int, int)
or Span<T>.Clear() for anything secret. Clearing a buffer you are about to
discard is a dead store: nothing reads the zeros back, so a compiler or JIT is entitled
to delete the write entirely and leave the key, password or plaintext sitting in memory.
Likewise prefer FixedTimeEquals(ReadOnlySpan<byte>, ReadOnlySpan<byte>) over SequenceEqual when checking a MAC or
a tag, so the comparison cannot leak how many leading bytes matched.
Methods
FixedTimeEquals(ReadOnlySpan<byte>, ReadOnlySpan<byte>)
Compares two byte spans in constant time, to prevent timing attacks.
public static bool FixedTimeEquals(ReadOnlySpan<byte> left, ReadOnlySpan<byte> right)
Parameters
leftReadOnlySpan<byte>First span to compare.
rightReadOnlySpan<byte>Second span to compare.
Returns
ZeroMemory(byte[])
Fills an array with zeros in a way that is not subject to compiler optimizations.
public static void ZeroMemory(byte[] buffer)
Parameters
ZeroMemory(char[])
Fills a character array with zeros in a way that is not subject to compiler optimizations.
public static void ZeroMemory(char[] buffer)
Parameters
ZeroMemory(Span<byte>)
Fills a span with zeros in a way that is not subject to compiler optimizations.
public static void ZeroMemory(Span<byte> buffer)
Parameters
ZeroMemory(Span<char>)
Fills a character span with zeros in a way that is not subject to compiler optimizations.
public static void ZeroMemory(Span<char> buffer)