Visual Basic 6.0 Requires Chilkat v11.6.0+
Visual Basic 6.0
Derive a Key from a Password with Argon2
Demonstrates Crypt2.Argon2DeriveKey, which derives a key from a password using Argon2. The options JSON requires a salt (chosen and stored by the application) and accepts the cost parameters variant, version, iterations, memoryCostKb, parallelism, and keyLen.
Background. Argon2 (RFC 9106) is a memory-hard function that is deliberately expensive in CPU time and memory, which is what makes brute-forcing the password space costly. The
argon2id variant is recommended unless there is a specific reason to choose argon2i or argon2d. memoryCostKb does the most to make an attack expensive. The salt, cost parameters, and options must be stored so the same key can be re-derived.Chilkat Visual Basic 6.0 Downloads
Dim success As Long
success = 0
Dim crypt As New ChilkatCrypt2
' The password should come from a secure source rather than being hard-coded.
Dim password As String
password = "correct horse battery staple"
' A key-derivation salt is chosen and stored by the application. Generate 16 random bytes and use
' them (base64) as the salt. The salt encoding defaults to base64.
crypt.EncodingMode = "base64"
Dim saltB64 As String
saltB64 = crypt.GenRandomBytesENC(16)
' Build the Argon2 options JSON. Only "salt" is required; every other member is optional and shown
' here with a typical explicit value:
' variant argon2id (default), argon2i, or argon2d
' version 19 (default, 0x13) or 16 (0x10)
' iterations passes over memory (t), >= 1, default 3
' memoryCostKb memory in KB (m), >= 8*parallelism, default 65536 (64 MB)
' parallelism lanes (p), default 1
' keyLen derived key length in bytes, 4..1048576, default 32
Dim json As New ChilkatJsonObject
success = json.UpdateString("variant","argon2id")
success = json.UpdateInt("version",19)
success = json.UpdateInt("iterations",3)
success = json.UpdateInt("memoryCostKb",65536)
success = json.UpdateInt("parallelism",1)
success = json.UpdateInt("keyLen",32)
success = json.UpdateString("salt",saltB64)
' Derive the key. The derived key is returned in the BinData (cleared first).
Dim bdKey As New ChilkatBinData
success = crypt.Argon2DeriveKey(password,json.Emit(),bdKey)
If (success = 0) Then
Debug.Print crypt.LastErrorText
Exit Sub
End If
' The application stores the salt and cost parameters so the same key can be re-derived later.
Dim keyHex As String
keyHex = bdKey.GetEncoded("hex")
If (bdKey.LastMethodSuccess = 0) Then
Debug.Print bdKey.LastErrorText
Exit Sub
End If
Debug.Print "Derived " & bdKey.NumBytes & "-byte key: " & keyHex