Sample code for 30+ languages & platforms
Visual FoxPro

AES-GCM Encryption / Decryption

See more Encryption Examples

Demonstrates AES-GCM encryption. Afterwards, the encrypted bytes, the authentication tag, and the IV are concatenated into one byte array and encoded to base64. For decryption, we decode the base64, extract the IV, authentication tag, and encrypted bytes, and then perform AES-GCM decryption.

Chilkat Visual FoxPro Downloads

Visual FoxPro
LOCAL lnSuccess
LOCAL loCrypt
LOCAL K
LOCAL lcIV
LOCAL lcAAD
LOCAL lcPT
LOCAL lcCipherText
LOCAL lcAuthTag
LOCAL loBdEncrypted
LOCAL lcConcatenatedGcmOutput
LOCAL loDecrypt
LOCAL loBdFromEncryptor
LOCAL lnSz
LOCAL lcExtractedIV
LOCAL lcExtractedCipherText
LOCAL lcExpectedAuthTag
LOCAL lcDecryptedText

lnSuccess = 0

* This example assumes the Chilkat API to have been previously unlocked.
* See Global Unlock Sample for sample code.

loCrypt = CreateObject('Chilkat.Crypt2')

loCrypt.CryptAlgorithm = "aes"
loCrypt.CipherMode = "gcm"
loCrypt.KeyLength = 256

K = "000102030405060708090A0B0C0D0E0F000102030405060708090A0B0C0D0E0F"
lcIV = "000102030405060708090A0B0C0D0E0F"
lcAAD = "feedfacedeadbeeffeedfacedeadbeefabaddad2"
lcPT = "This is the text to be AES-GCM encrypted."

loCrypt.SetEncodedIV(lcIV,"hex")
loCrypt.SetEncodedKey(K,"hex")

lnSuccess = loCrypt.SetEncodedAad(lcAAD,"hex")

* Return the encrypted bytes as base64
loCrypt.EncodingMode = "base64"
loCrypt.Charset = "utf-8"
lcCipherText = loCrypt.EncryptStringENC(lcPT)
IF (loCrypt.LastMethodSuccess <> 1) THEN
    ? loCrypt.LastErrorText
    RELEASE loCrypt
    CANCEL
ENDIF

* Get the GCM authenticated tag computed when encrypting.
lcAuthTag = loCrypt.GetEncodedAuthTag("base64")

? "Cipher Text: " + lcCipherText
? "Auth Tag: " + lcAuthTag

* Let's send the IV, CipherText, and AuthTag to the decrypting party.
* We'll send them concatenated like this: [IV || Ciphertext || AuthTag]
* In base64 format.
loBdEncrypted = CreateObject('Chilkat.BinData')
loBdEncrypted.AppendEncoded(lcIV,"hex")
loBdEncrypted.AppendEncoded(lcCipherText,"base64")
loBdEncrypted.AppendEncoded(lcAuthTag,"base64")

lcConcatenatedGcmOutput = loBdEncrypted.GetEncoded("base64")
? "Concatenated GCM Output: " + lcConcatenatedGcmOutput

* Sample output so far:

* -------------------------------------------------------------------------------------
* Now let's GCM decrypt...
* -------------------------------------------------------------------------------------

loDecrypt = CreateObject('Chilkat.Crypt2')

* The values shared and agreed upon by both sides beforehand are: algorithm, cipher mode, secret key, and AAD.
* Sometimes the IV can be a value already known and agreed upon, but in this case the encryptor sends the IV to the decryptor.
loDecrypt.CryptAlgorithm = "aes"
loDecrypt.CipherMode = "gcm"
loDecrypt.KeyLength = 256
loDecrypt.SetEncodedKey(K,"hex")
loDecrypt.SetEncodedAad(lcAAD,"hex")

loBdFromEncryptor = CreateObject('Chilkat.BinData')
loBdFromEncryptor.AppendEncoded(lcConcatenatedGcmOutput,"base64")

lnSz = loBdFromEncryptor.NumBytes

* Extract the parts.
lcExtractedIV = loBdFromEncryptor.GetEncodedChunk(0,16,"hex")
lcExtractedCipherText = loBdFromEncryptor.GetEncodedChunk(16,lnSz - 32,"base64")
lcExpectedAuthTag = loBdFromEncryptor.GetEncodedChunk(lnSz - 16,16,"base64")

* Before GCM decrypting, we must set the authenticated tag to the value that is expected.
* The decryption will fail if the resulting authenticated tag is not equal to the expected result.
lnSuccess = loDecrypt.SetEncodedAuthTag(lcExpectedAuthTag,"base64")

* Also set the IV.
loDecrypt.SetEncodedIV(lcExtractedIV,"hex")

* Decrypt..
loDecrypt.EncodingMode = "base64"
loDecrypt.Charset = "utf-8"
lcDecryptedText = loDecrypt.DecryptStringENC(lcExtractedCipherText)
IF (loDecrypt.LastMethodSuccess <> 1) THEN
    * Failed.  The resultant authenticated tag did not equal the expected authentication tag.
    ? loDecrypt.LastErrorText
    RELEASE loCrypt
    RELEASE loBdEncrypted
    RELEASE loDecrypt
    RELEASE loBdFromEncryptor
    CANCEL
ENDIF

? "Decrypted: " + lcDecryptedText

* Sample output:

* Cipher Text: cYspSW4GuSj0Msho4OgZZ0AwspDEpTF5Br8NlA+qT3f+g3nQo+xalmU=
* Auth Tag: z/N82vdj/ZsM0WnHNCnPPw==
* Concatenated GCM Output: AAECAwQFBgcICQoLDA0OD3GLKUluBrko9DLIaODoGWdAMLKQxKUxeQa/DZQPqk93/oN50KPsWpZlz/N82vdj/ZsM0WnHNCnPPw==
* Decrypted: This is the text to be AES-GCM encrypted.

RELEASE loCrypt
RELEASE loBdEncrypted
RELEASE loDecrypt
RELEASE loBdFromEncryptor