Sample code for 30+ languages & platforms
B4X

JWE using AES Key Wrap and AES_128_CBC_HMAC_SHA_256

See more JSON Web Encryption (JWE) Examples

This example duplicates the example A.3 in RFC 7516 for JSON Web Encryption (JWE).

Note: This example requires Chilkat v9.5.0.66 or greater.

Chilkat B4X Downloads

B4X
Dim success As Boolean = False

'  This requires the Chilkat API to have been previously unlocked.
'  See Global Unlock Sample for sample code.

'  Note: This example requires Chilkat v9.5.0.66 or greater.

Dim plaintext As String = "Live long and prosper."

Dim jwe As ChilkatJwe
jwe.Initialize

'  First build the JWE Protected Header: {"alg":"A128KW","enc":"A128CBC-HS256"}
Dim jweProtHdr As ChilkatJsonObject
jweProtHdr.Initialize
jweProtHdr.AppendString("alg", "A128KW")
jweProtHdr.AppendString("enc", "A128CBC-HS256")
jwe.SetProtectedHeader(jweProtHdr)

Log("JWE Protected Header: " & jweProtHdr.Emit)
Log("--")

'  The example A.3 in RFC 7516 uses the following 128-bit AES key,
'  specified in JWK (JSON Web Key) format:
'       {"kty":"oct",
'        "k":"GawgguFyGrWKav7AX4VKUg"
'       }
'  This is just a way of saying: The key type ("kty") is 
'  a bunch of octets ("k") in base64url encoding.
'  We can simply set the AES wrapping key like this:
Dim aesWrappingKey As String = "GawgguFyGrWKav7AX4VKUg"
jwe.SetWrappingKey(0, aesWrappingKey, "base64url")

'  Encrypt and return the JWE:
Dim strJwe As String = jwe.Encrypt(plaintext, "utf-8")
If jwe.LastMethodSuccess <> True Then
    Log(jwe.LastErrorText)
    Return
End If


'  Show the JWE we just created:
Log(strJwe)

'  Decrypt the JWE that was just produced.
'  1) Load the JWE.
'  2) Set the AES wrapping key.
'  3) Decrypt.
Dim jwe2 As ChilkatJwe
jwe2.Initialize
success = jwe2.LoadJwe(strJwe)
If success <> True Then
    Log(jwe2.LastErrorText)
    Return
End If

'  Set the AES wrap key.
jwe2.SetWrappingKey(0, aesWrappingKey, "base64url")

'  Decrypt.
Dim originalPlaintext As String = jwe2.Decrypt(0, "utf-8")
If jwe2.LastMethodSuccess <> True Then
    Log(jwe2.LastErrorText)
    Return
End If


Log("original text: ")
Log(originalPlaintext)

'  ---------------------------------------------------------------------------------
'  It should also be possible to decrypt the JWE as shown in RFC 7516, Appendix A.3.7
'  because it was produced using the same AES Wrap key.

Dim sbJwe As ChilkatStringBuilder
sbJwe.Initialize
sbJwe.Append("eyJhbGciOiJBMTI4S1ciLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0.")
sbJwe.Append("6KB707dM9YTIgHtLvtgWQ8mKwboJW3of9locizkDTHzBC2IlrT1oOQ.")
sbJwe.Append("AxY8DCtDaGlsbGljb3RoZQ.")
sbJwe.Append("KDlTtXchhZTGufMYmOYGS4HffxPSUrfmqCHXaI9wOGY.")
sbJwe.Append("U0m_YmjN04DJvceFICbCVQ")

success = jwe2.LoadJweSb(sbJwe)
If success <> True Then
    Log(jwe2.LastErrorText)
    Return
End If


jwe2.SetWrappingKey(0, aesWrappingKey, "base64url")

'  Decrypt.
originalPlaintext = jwe2.Decrypt(0, "utf-8")
If jwe2.LastMethodSuccess <> True Then
    Log(jwe2.LastErrorText)
    Return
End If


Log(originalPlaintext)