Sample code for 30+ languages & platforms
C

Set JWE Additional Authenticated Data

See more JSON Web Encryption (JWE) Examples

Demonstrates Jwe.SetAad, which sets external Additional Authenticated Data (AAD) for a JWE being encrypted, encoding the supplied text with the given charset.

Background. AAD is integrity-protected but not encrypted, binding external context to the ciphertext. The same AAD must be supplied again when decrypting.

Chilkat C Downloads

C
#include <C_CkJwe.h>
#include <C_CkJsonObject.h>
#include <C_CkStringBuilder.h>

void ChilkatSample(void)
    {
    BOOL success;
    HCkJwe jwe;
    HCkJsonObject header;
    const char *base64Key;
    HCkStringBuilder sbContent;
    HCkStringBuilder sbJwe;

    success = FALSE;

    jwe = CkJwe_Create();

    //  Protected header: AES key-wrap with AES-256-GCM content encryption.
    header = CkJsonObject_Create();
    CkJsonObject_UpdateString(header,"alg","A256KW");
    CkJsonObject_UpdateString(header,"enc","A256GCM");
    success = CkJwe_SetProtectedHeader(jwe,header);
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        return;
    }

    //  The 256-bit key-wrapping key (base64) for recipient index 0.  In production, obtain the key from a
    //  secure source rather than hard-coding it.
    base64Key = "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=";
    success = CkJwe_SetWrappingKey(jwe,0,base64Key,"base64");
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        return;
    }

    //  Set external Additional Authenticated Data (AAD).  The AAD is integrity-protected but not
    //  encrypted, and must be supplied again when decrypting.
    success = CkJwe_SetAad(jwe,"context-info-v1","utf-8");
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        return;
    }

    sbContent = CkStringBuilder_Create();
    CkStringBuilder_Append(sbContent,"This is the secret content.");
    sbJwe = CkStringBuilder_Create();
    success = CkJwe_EncryptSb(jwe,sbContent,"utf-8",sbJwe);
    if (success == FALSE) {
        printf("%s\n",CkJwe_lastErrorText(jwe));
        CkJwe_Dispose(jwe);
        CkJsonObject_Dispose(header);
        CkStringBuilder_Dispose(sbContent);
        CkStringBuilder_Dispose(sbJwe);
        return;
    }

    printf("%s\n",CkStringBuilder_getAsString(sbJwe));


    CkJwe_Dispose(jwe);
    CkJsonObject_Dispose(header);
    CkStringBuilder_Dispose(sbContent);
    CkStringBuilder_Dispose(sbJwe);

    }