Sample code for 30+ languages & platforms
Java

Set JWE Additional Authenticated Data from BinData

See more JSON Web Encryption (JWE) Examples

Demonstrates Jwe.SetAadBd, which sets external Additional Authenticated Data (AAD) to the exact bytes held in a BinData.

Background. AAD is integrity-protected but not encrypted. Passing an empty BinData clears any previously configured AAD.

Chilkat Java Downloads

Java
import com.chilkatsoft.*;

public class ChilkatExample {

  static {
    try {
        System.loadLibrary("chilkat");
    } catch (UnsatisfiedLinkError e) {
      System.err.println("Native code library failed to load.\n" + e);
      System.exit(1);
    }
  }

  public static void main(String argv[])
  {
    boolean success = false;

    CkJwe jwe = new CkJwe();

    //  Protected header: AES key-wrap with AES-256-GCM content encryption.
    CkJsonObject header = new CkJsonObject();
    header.UpdateString("alg","A256KW");
    header.UpdateString("enc","A256GCM");
    success = jwe.SetProtectedHeader(header);
    if (success == false) {
        System.out.println(jwe.lastErrorText());
        return;
        }

    //  The 256-bit key-wrapping key (base64) for recipient index 0.  In production, obtain the key from a
    //  secure source rather than hard-coding it.
    String base64Key = "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=";
    success = jwe.SetWrappingKey(0,base64Key,"base64");
    if (success == false) {
        System.out.println(jwe.lastErrorText());
        return;
        }

    //  Set external Additional Authenticated Data (AAD) to the exact bytes in a BinData.  Passing an empty
    //  BinData clears any previously configured AAD.
    CkBinData bdAad = new CkBinData();
    bdAad.AppendString("context-info-v1","utf-8");
    success = jwe.SetAadBd(bdAad);
    if (success == false) {
        System.out.println(jwe.lastErrorText());
        return;
        }

    CkStringBuilder sbContent = new CkStringBuilder();
    sbContent.Append("This is the secret content.");
    CkStringBuilder sbJwe = new CkStringBuilder();
    success = jwe.EncryptSb(sbContent,"utf-8",sbJwe);
    if (success == false) {
        System.out.println(jwe.lastErrorText());
        return;
        }

    System.out.println(sbJwe.getAsString());
  }
}