Sample code for 30+ languages & platforms
React Native

Example: Crypt2.RandomizeIV method

Demonstrates using a random initialization vector for AES GCM encryption.

Chilkat React Native Downloads

React Native
import { BinData, Crypt2 } from '@chilkat/react-native'

function chilkatExample() {
  // This example assumes the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  const crypt = new Crypt2();

  crypt.cryptAlgorithm = 'aes';
  crypt.cipherMode = 'gcm';
  crypt.keyLength = 256;

  const k = '000102030405060708090A0B0C0D0E0F000102030405060708090A0B0C0D0E0F';
  const aad = 'feedfacedeadbeeffeedfacedeadbeefabaddad2';
  const pt = 'This is the text to be AES-GCM encrypted.';

  // Generate a random IV.
  crypt.randomizeIV();
  const iv = crypt.getEncodedIV('hex');

  crypt.setEncodedKey(k, 'hex');

  crypt.setEncodedAad(aad, 'hex');

  // Return the encrypted bytes as base64
  crypt.encodingMode = 'base64';
  crypt.charset = 'utf-8';
  let cipherText: string;
  try {
    cipherText = crypt.encryptStringENC(pt);
  } catch {
    console.log(crypt.lastErrorText);
    return;
  }

  // Get the GCM authenticated tag computed when encrypting.
  const authTag = crypt.getEncodedAuthTag('base64');

  console.log(`Cipher Text: ${cipherText}`);
  console.log(`Auth Tag: ${authTag}`);

  // Let's send the IV, CipherText, and AuthTag to the decrypting party.
  // We'll send them concatenated like this: [IV || Ciphertext || AuthTag]
  // In base64 format.
  const bdEncrypted = new BinData();
  bdEncrypted.appendEncoded(iv, 'hex');
  bdEncrypted.appendEncoded(cipherText, 'base64');
  bdEncrypted.appendEncoded(authTag, 'base64');

  const concatenatedGcmOutput = bdEncrypted.getEncoded('base64');
  console.log(`Concatenated GCM Output: ${concatenatedGcmOutput}`);

  // Sample output so far:

  // -------------------------------------------------------------------------------------
  // Now let's GCM decrypt...
  // -------------------------------------------------------------------------------------

  const decrypt = new Crypt2();

  // The values shared and agreed upon by both sides beforehand are: algorithm, cipher mode, secret key, and AAD.
  // Sometimes the IV can be a value already known and agreed upon, but in this case the encryptor sends the IV to the decryptor.
  decrypt.cryptAlgorithm = 'aes';
  decrypt.cipherMode = 'gcm';
  decrypt.keyLength = 256;
  decrypt.setEncodedKey(k, 'hex');
  decrypt.setEncodedAad(aad, 'hex');

  const bdFromEncryptor = new BinData();
  bdFromEncryptor.appendEncoded(concatenatedGcmOutput, 'base64');

  const sz = bdFromEncryptor.numBytes;

  // Extract the parts.
  const extractedIV = bdFromEncryptor.getEncodedChunk(0, 16, 'hex');
  const extractedCipherText = bdFromEncryptor.getEncodedChunk(16, sz - 32, 'base64');
  const expectedAuthTag = bdFromEncryptor.getEncodedChunk(sz - 16, 16, 'base64');

  // Before GCM decrypting, we must set the authenticated tag to the value that is expected.
  // The decryption will fail if the resulting authenticated tag is not equal to the expected result.
  decrypt.setEncodedAuthTag(expectedAuthTag, 'base64');

  // Also set the IV.
  decrypt.setEncodedIV(extractedIV, 'hex');

  // Decrypt..
  decrypt.encodingMode = 'base64';
  decrypt.charset = 'utf-8';
  let decryptedText: string;
  try {
    decryptedText = decrypt.decryptStringENC(extractedCipherText);
  } catch {
    // Failed.  The resultant authenticated tag did not equal the expected authentication tag.
    console.log(decrypt.lastErrorText);
    return;
  }

  console.log(`Decrypted: ${decryptedText}`);
}