Sample code for 30+ languages & platforms
DataFlex

AES 256-bit CBC using PBKDF2 Generated Secret Key

See more Encryption Examples

First generates a 32-byte secret key using PBKDF2 (with HMAC-SHA256), and then uses the secret key to do 256-bit AES CBC mode decryption.

(Duplicates the following Java code)

public String decrypt(String strToDecrypt) {
        try  {
            // Read the initialization vector from the first bytes for the data
            byte [] rawData = Base64.getDecoder().decode(strToDecrypt);
            byte [] iv = new byte[Config.get().encryptionIVLength()];
            byte [] encryptedData = new byte[rawData.length - iv.length];
            System.arraycopy(rawData, 0, iv, 0, iv.length);
            System.arraycopy(rawData, iv.length, encryptedData, 0, encryptedData.length);
 
            IvParameterSpec ivspec = new IvParameterSpec(iv);
 
            SecretKeyFactory factory = SecretKeyFactory.getInstance("PBKDF2WithHmacSHA256");
            KeySpec spec = new PBEKeySpec(secretKey.toCharArray(), salt.getBytes(), 65536, 256);
            SecretKey tmp = factory.generateSecret(spec);
            SecretKeySpec secretKey = new SecretKeySpec(tmp.getEncoded(), "AES");
 
            Cipher cipher = Cipher.getInstance("AES/CBC/PKCS5PADDING");
            cipher.init(Cipher.DECRYPT_MODE, secretKey, ivspec);
            return new String(cipher.doFinal(encryptedData));
        }
        catch (Exception e) {
            log.error("Could not decrypt the string.", e);
        }
        return null;
    }

Chilkat DataFlex Downloads

DataFlex
Use ChilkatAx-win32.pkg

Procedure Test
    Handle hoCrypt
    String sPassword
    String sSaltHex
    Integer iIterationCount
    Integer iOutputKeyBitLen
    String sSecretKeyHex
    String sIv
    String sStrToDecrypt
    String sDecryptedStr

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    Get Create (RefClass(cComChilkatCrypt2)) To hoCrypt
    If (Not(IsComObjectCreated(hoCrypt))) Begin
        Send CreateComObject of hoCrypt
    End

    Move "some arbitrary length password" To sPassword
    // We have 8 bytes of salt encoded using hex.
    // (The salt can be any number of bytes, in any desired encoding such as base64, hex, etc.)
    Move "0102030405060708" To sSaltHex

    // Generate the 256-bit (32-byte) AES secret key we'll use to decrypt.
    Move 65536 To iIterationCount
    Move 256 To iOutputKeyBitLen
    Get ComPbkdf2 Of hoCrypt sPassword "utf-8" "sha256" sSaltHex iIterationCount iOutputKeyBitLen "hex" To sSecretKeyHex

    // Setup for 256-bit AES CBC decryption.
    Set ComCryptAlgorithm Of hoCrypt To "aes"
    Set ComKeyLength Of hoCrypt To 256
    Set ComCipherMode Of hoCrypt To "cbc"
    Set ComPaddingScheme Of hoCrypt To 0

    // The IV for AES is 16 bytes.
    Move "000102030405060708090A0B0C0D0E0F" To sIv
    Send ComSetEncodedIV To hoCrypt sIv "hex"

    // Set the secret key for 256-bit AES.
    Send ComSetEncodedKey To hoCrypt sSecretKeyHex "hex"

    // AES decrypt
    // assume our string to decrypt is base64
    Move "...." To sStrToDecrypt
    Set ComEncodingMode Of hoCrypt To "base64"
    Get ComDecryptStringENC Of hoCrypt sStrToDecrypt To sDecryptedStr

    Showln sDecryptedStr


End_Procedure