Sample code for 30+ languages & platforms
Xojo Plugin

Example: Crypt2.RandomizeIV method

Demonstrates using a random initialization vector for AES GCM encryption.

Chilkat Xojo Plugin Downloads

Xojo Plugin
Dim success As Boolean
success = False

// This example assumes the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

Dim crypt As New Chilkat.Crypt2

crypt.CryptAlgorithm = "aes"
crypt.CipherMode = "gcm"
crypt.KeyLength = 256

Dim K As String
K = "000102030405060708090A0B0C0D0E0F000102030405060708090A0B0C0D0E0F"
Dim AAD As String
AAD = "feedfacedeadbeeffeedfacedeadbeefabaddad2"
Dim PT As String
PT = "This is the text to be AES-GCM encrypted."

// Generate a random IV.
crypt.RandomizeIV 
Dim IV As String
IV = crypt.GetEncodedIV("hex")

crypt.SetEncodedKey K,"hex"

success = crypt.SetEncodedAad(AAD,"hex")

// Return the encrypted bytes as base64
crypt.EncodingMode = "base64"
crypt.Charset = "utf-8"
Dim cipherText As String
cipherText = crypt.EncryptStringENC(PT)
If (crypt.LastMethodSuccess <> True) Then
    System.DebugLog(crypt.LastErrorText)
    Return
End If

// Get the GCM authenticated tag computed when encrypting.
Dim authTag As String
authTag = crypt.GetEncodedAuthTag("base64")

System.DebugLog("Cipher Text: " + cipherText)
System.DebugLog("Auth Tag: " + authTag)

// Let's send the IV, CipherText, and AuthTag to the decrypting party.
// We'll send them concatenated like this: [IV || Ciphertext || AuthTag]
// In base64 format.
Dim bdEncrypted As New Chilkat.BinData
success = bdEncrypted.AppendEncoded(IV,"hex")
success = bdEncrypted.AppendEncoded(cipherText,"base64")
success = bdEncrypted.AppendEncoded(authTag,"base64")

Dim concatenatedGcmOutput As String
concatenatedGcmOutput = bdEncrypted.GetEncoded("base64")
System.DebugLog("Concatenated GCM Output: " + concatenatedGcmOutput)

// Sample output so far:

// -------------------------------------------------------------------------------------
// Now let's GCM decrypt...
// -------------------------------------------------------------------------------------

Dim decrypt As New Chilkat.Crypt2

// The values shared and agreed upon by both sides beforehand are: algorithm, cipher mode, secret key, and AAD.
// Sometimes the IV can be a value already known and agreed upon, but in this case the encryptor sends the IV to the decryptor.
decrypt.CryptAlgorithm = "aes"
decrypt.CipherMode = "gcm"
decrypt.KeyLength = 256
decrypt.SetEncodedKey K,"hex"
success = decrypt.SetEncodedAad(AAD,"hex")

Dim bdFromEncryptor As New Chilkat.BinData
success = bdFromEncryptor.AppendEncoded(concatenatedGcmOutput,"base64")

Dim sz As Int32
sz = bdFromEncryptor.NumBytes

// Extract the parts.
Dim extractedIV As String
extractedIV = bdFromEncryptor.GetEncodedChunk(0,16,"hex")
Dim extractedCipherText As String
extractedCipherText = bdFromEncryptor.GetEncodedChunk(16,sz - 32,"base64")
Dim expectedAuthTag As String
expectedAuthTag = bdFromEncryptor.GetEncodedChunk(sz - 16,16,"base64")

// Before GCM decrypting, we must set the authenticated tag to the value that is expected.
// The decryption will fail if the resulting authenticated tag is not equal to the expected result.
success = decrypt.SetEncodedAuthTag(expectedAuthTag,"base64")

// Also set the IV.
decrypt.SetEncodedIV extractedIV,"hex"

// Decrypt..
decrypt.EncodingMode = "base64"
decrypt.Charset = "utf-8"
Dim decryptedText As String
decryptedText = decrypt.DecryptStringENC(extractedCipherText)
If (decrypt.LastMethodSuccess <> True) Then
    // Failed.  The resultant authenticated tag did not equal the expected authentication tag.
    System.DebugLog(decrypt.LastErrorText)
    Return
End If

System.DebugLog("Decrypted: " + decryptedText)