Sample code for 30+ languages & platforms
Visual Basic 6.0

AES-GCM Encryption / Decryption

See more Encryption Examples

Demonstrates AES-GCM encryption. Afterwards, the encrypted bytes, the authentication tag, and the IV are concatenated into one byte array and encoded to base64. For decryption, we decode the base64, extract the IV, authentication tag, and encrypted bytes, and then perform AES-GCM decryption.

Chilkat Visual Basic 6.0 Downloads

Visual Basic 6.0
Dim success As Long
success = 0

' This example assumes the Chilkat API to have been previously unlocked.
' See Global Unlock Sample for sample code.

Dim crypt As New ChilkatCrypt2

crypt.CryptAlgorithm = "aes"
crypt.CipherMode = "gcm"
crypt.KeyLength = 256

Dim K As String
K = "000102030405060708090A0B0C0D0E0F000102030405060708090A0B0C0D0E0F"
Dim IV As String
IV = "000102030405060708090A0B0C0D0E0F"
Dim AAD As String
AAD = "feedfacedeadbeeffeedfacedeadbeefabaddad2"
Dim PT As String
PT = "This is the text to be AES-GCM encrypted."

crypt.SetEncodedIV IV,"hex"
crypt.SetEncodedKey K,"hex"

success = crypt.SetEncodedAad(AAD,"hex")

' Return the encrypted bytes as base64
crypt.EncodingMode = "base64"
crypt.Charset = "utf-8"
Dim cipherText As String
cipherText = crypt.EncryptStringENC(PT)
If (crypt.LastMethodSuccess <> 1) Then
    Debug.Print crypt.LastErrorText
    Exit Sub
End If

' Get the GCM authenticated tag computed when encrypting.
Dim authTag As String
authTag = crypt.GetEncodedAuthTag("base64")

Debug.Print "Cipher Text: " & cipherText
Debug.Print "Auth Tag: " & authTag

' Let's send the IV, CipherText, and AuthTag to the decrypting party.
' We'll send them concatenated like this: [IV || Ciphertext || AuthTag]
' In base64 format.
Dim bdEncrypted As New ChilkatBinData
success = bdEncrypted.AppendEncoded(IV,"hex")
success = bdEncrypted.AppendEncoded(cipherText,"base64")
success = bdEncrypted.AppendEncoded(authTag,"base64")

Dim concatenatedGcmOutput As String
concatenatedGcmOutput = bdEncrypted.GetEncoded("base64")
Debug.Print "Concatenated GCM Output: " & concatenatedGcmOutput

' Sample output so far:

' -------------------------------------------------------------------------------------
' Now let's GCM decrypt...
' -------------------------------------------------------------------------------------

Dim decrypt As New ChilkatCrypt2

' The values shared and agreed upon by both sides beforehand are: algorithm, cipher mode, secret key, and AAD.
' Sometimes the IV can be a value already known and agreed upon, but in this case the encryptor sends the IV to the decryptor.
decrypt.CryptAlgorithm = "aes"
decrypt.CipherMode = "gcm"
decrypt.KeyLength = 256
decrypt.SetEncodedKey K,"hex"
success = decrypt.SetEncodedAad(AAD,"hex")

Dim bdFromEncryptor As New ChilkatBinData
success = bdFromEncryptor.AppendEncoded(concatenatedGcmOutput,"base64")

Dim sz As Long
sz = bdFromEncryptor.NumBytes

' Extract the parts.
Dim extractedIV As String
extractedIV = bdFromEncryptor.GetEncodedChunk(0,16,"hex")
Dim extractedCipherText As String
extractedCipherText = bdFromEncryptor.GetEncodedChunk(16,sz - 32,"base64")
Dim expectedAuthTag As String
expectedAuthTag = bdFromEncryptor.GetEncodedChunk(sz - 16,16,"base64")

' Before GCM decrypting, we must set the authenticated tag to the value that is expected.
' The decryption will fail if the resulting authenticated tag is not equal to the expected result.
success = decrypt.SetEncodedAuthTag(expectedAuthTag,"base64")

' Also set the IV.
decrypt.SetEncodedIV extractedIV,"hex"

' Decrypt..
decrypt.EncodingMode = "base64"
decrypt.Charset = "utf-8"
Dim decryptedText As String
decryptedText = decrypt.DecryptStringENC(extractedCipherText)
If (decrypt.LastMethodSuccess <> 1) Then
    ' Failed.  The resultant authenticated tag did not equal the expected authentication tag.
    Debug.Print decrypt.LastErrorText
    Exit Sub
End If

Debug.Print "Decrypted: " & decryptedText

' Sample output:

' Cipher Text: cYspSW4GuSj0Msho4OgZZ0AwspDEpTF5Br8NlA+qT3f+g3nQo+xalmU=
' Auth Tag: z/N82vdj/ZsM0WnHNCnPPw==
' Concatenated GCM Output: AAECAwQFBgcICQoLDA0OD3GLKUluBrko9DLIaODoGWdAMLKQxKUxeQa/DZQPqk93/oN50KPsWpZlz/N82vdj/ZsM0WnHNCnPPw==
' Decrypted: This is the text to be AES-GCM encrypted.