React Native
React Native
Example: Crypt2.RandomizeIV method
Demonstrates using a random initialization vector for AES GCM encryption.Chilkat React Native Downloads
import { BinData, Crypt2 } from '@chilkat/react-native'
function chilkatExample() {
// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
const crypt = new Crypt2();
crypt.cryptAlgorithm = 'aes';
crypt.cipherMode = 'gcm';
crypt.keyLength = 256;
const k = '000102030405060708090A0B0C0D0E0F000102030405060708090A0B0C0D0E0F';
const aad = 'feedfacedeadbeeffeedfacedeadbeefabaddad2';
const pt = 'This is the text to be AES-GCM encrypted.';
// Generate a random IV.
crypt.randomizeIV();
const iv = crypt.getEncodedIV('hex');
crypt.setEncodedKey(k, 'hex');
crypt.setEncodedAad(aad, 'hex');
// Return the encrypted bytes as base64
crypt.encodingMode = 'base64';
crypt.charset = 'utf-8';
let cipherText: string;
try {
cipherText = crypt.encryptStringENC(pt);
} catch {
console.log(crypt.lastErrorText);
return;
}
// Get the GCM authenticated tag computed when encrypting.
const authTag = crypt.getEncodedAuthTag('base64');
console.log(`Cipher Text: ${cipherText}`);
console.log(`Auth Tag: ${authTag}`);
// Let's send the IV, CipherText, and AuthTag to the decrypting party.
// We'll send them concatenated like this: [IV || Ciphertext || AuthTag]
// In base64 format.
const bdEncrypted = new BinData();
bdEncrypted.appendEncoded(iv, 'hex');
bdEncrypted.appendEncoded(cipherText, 'base64');
bdEncrypted.appendEncoded(authTag, 'base64');
const concatenatedGcmOutput = bdEncrypted.getEncoded('base64');
console.log(`Concatenated GCM Output: ${concatenatedGcmOutput}`);
// Sample output so far:
// -------------------------------------------------------------------------------------
// Now let's GCM decrypt...
// -------------------------------------------------------------------------------------
const decrypt = new Crypt2();
// The values shared and agreed upon by both sides beforehand are: algorithm, cipher mode, secret key, and AAD.
// Sometimes the IV can be a value already known and agreed upon, but in this case the encryptor sends the IV to the decryptor.
decrypt.cryptAlgorithm = 'aes';
decrypt.cipherMode = 'gcm';
decrypt.keyLength = 256;
decrypt.setEncodedKey(k, 'hex');
decrypt.setEncodedAad(aad, 'hex');
const bdFromEncryptor = new BinData();
bdFromEncryptor.appendEncoded(concatenatedGcmOutput, 'base64');
const sz = bdFromEncryptor.numBytes;
// Extract the parts.
const extractedIV = bdFromEncryptor.getEncodedChunk(0, 16, 'hex');
const extractedCipherText = bdFromEncryptor.getEncodedChunk(16, sz - 32, 'base64');
const expectedAuthTag = bdFromEncryptor.getEncodedChunk(sz - 16, 16, 'base64');
// Before GCM decrypting, we must set the authenticated tag to the value that is expected.
// The decryption will fail if the resulting authenticated tag is not equal to the expected result.
decrypt.setEncodedAuthTag(expectedAuthTag, 'base64');
// Also set the IV.
decrypt.setEncodedIV(extractedIV, 'hex');
// Decrypt..
decrypt.encodingMode = 'base64';
decrypt.charset = 'utf-8';
let decryptedText: string;
try {
decryptedText = decrypt.decryptStringENC(extractedCipherText);
} catch {
// Failed. The resultant authenticated tag did not equal the expected authentication tag.
console.log(decrypt.lastErrorText);
return;
}
console.log(`Decrypted: ${decryptedText}`);
}