Sample code for 30+ languages & platforms
Dart

PKCS11 Import an Existing AES Key onto the HSM

See more PKCS11 Examples

Demonstrates how to import an existing AES symmetric encrytion key onto the smartcard/token. The imported AES key is a session object, and only exists for the duration of the PKCS11 session. (AES keys are typically used for wrapping/unwrapping RSA and EC keys.)

Note: This example requires Chilkat v9.5.0.96 or later.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  // Note: Chilkat's PKCS11 implementation runs on Windows, Linux, Mac OS X, and other supported operating systems.

  final pkcs11 = CkPkcs11();

  // Use the PKCS11 driver (.dll, .so, .dylib) for your particular HSM.
  // (The format of the path will change with the operating system.  Obviously, "C:/" is not used on non-Windows systems.
  pkcs11.sharedLibPath = 'C:/Program Files (x86)/Gemalto/IDGo 800 PKCS#11/IDPrimePKCS1164.dll';

  // Establish a logged-on session.
  final pin = '0000';
  final userType = 1;
  try {
    pkcs11.quickSession(userType, pin);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Generate a 256-bit AES key.
  // (32 bytes is 256 bits)
  // Append 32 bytes of random data in the base64 encoding.
  final sbAesKey = CkStringBuilder();
  sbAesKey.appendRandom(32, 'base64');

  final attrs = CkJsonObject();
  // Specify the type of object, and the type of key.
  attrs.updateString('class', 'CKO_SECRET_KEY');
  attrs.updateString('key_type', 'CKK_AES');
  // Add an optional label if desired.
  attrs.updateString('label', 'My AES wrapping/unwrapping key');
  // Allow the key to be use for wrapping and unwrapping operations.
  attrs.updateBool('wrap', true);
  attrs.updateBool('unwrap', true);

  // Provide the AES key material.
  attrs.updateString('value', sbAesKey.getAsString());

  // Create the object (i.e. create the AES key with the given key material.)
  // Returns the PKCS11 object handle of the created AES session key.
  final objHandle = pkcs11.createPkcs11Object(attrs);
  if (objHandle == 0) {
    print(pkcs11.lastErrorText);
    print('Failed.');
  } else {
    print('PKCS11 object handle = $objHandle');
    print('Successfully created a 256-bit AES session key.');
  }

  // Typically, you would do other things in the PKCS11 session that use the handle of AES key we just created.
  // ...
  // ...

  pkcs11.logout();
  pkcs11.closeSession();
}