Sample code for 30+ languages & platforms
Lianja Requires Chilkat v11.0.0+

How to Generate an Elliptic Curve Shared Secret

See more ECC Examples

Demonstrates how to generate an ECC (Elliptic Curve Cryptography) shared secret. Imagine a cilent has one ECC private key, the server has another. A shared secret is computed by each side providing it's public key to the other. The private keys are kept private.

Chilkat Lianja Downloads

Lianja
llSuccess = .F.

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  This example includes both client-side and server-side code.
//  Each code segment is marked as client-side or server-side.
//  Imagine these segments are running on separate computers...

//  -----------------------------------------------------------------
//  (Client-Side) Generate an ECC key, save the public part to a file.
//  -----------------------------------------------------------------
loPrngClient = createobject("CkPrng")
loEccClient = createobject("CkEcc")
loPrivKeyClient = createobject("CkPrivateKey")
llSuccess = loEccClient.GenKey("secp256r1",loPrngClient,loPrivKeyClient)
if (llSuccess = .F.) then
    ? loEccClient.LastErrorText
    release loPrngClient
    release loEccClient
    release loPrivKeyClient
    return
endif

loPubKeyClient = createobject("CkPublicKey")
loPrivKeyClient.ToPublicKey(loPubKeyClient)
loPubKeyClient.SavePemFile(.F.,"qa_output/eccClientPub.pem")

//  -----------------------------------------------------------------
//  (Server-Side) Generate an ECC key, save the public part to a file.
//  -----------------------------------------------------------------
loPrngServer = createobject("CkPrng")
loEccServer = createobject("CkEcc")
loPrivKeyServer = createobject("CkPrivateKey")
loEccServer.GenKey("secp256r1",loPrngServer,loPrivKeyServer)

loPubKeyServer = createobject("CkPublicKey")
loPrivKeyServer.ToPublicKey(loPubKeyServer)
loPubKeyServer.SavePemFile(.F.,"qa_output/eccServerPub.pem")

//  -----------------------------------------------------------------
//  (Client-Side) Generate the shared secret using our private key, and the other's public key.
//  -----------------------------------------------------------------

//  Imagine that the server sent the public key PEM to the client.
//  (This is simulated by loading the server's public key from the file.
loPubKeyFromServer = createobject("CkPublicKey")
loPubKeyFromServer.LoadFromFile("qa_output/eccServerPub.pem")
lcSharedSecret1 = loEccClient.SharedSecretENC(loPrivKeyClient,loPubKeyFromServer,"base64")

//  -----------------------------------------------------------------
//  (Server-Side) Generate the shared secret using our private key, and the other's public key.
//  -----------------------------------------------------------------

//  Imagine that the client sent the public key PEM to the server.
//  (This is simulated by loading the client's public key from the file.
loPubKeyFromClient = createobject("CkPublicKey")
loPubKeyFromClient.LoadFromFile("qa_output/eccClientPub.pem")
lcSharedSecret2 = loEccServer.SharedSecretENC(loPrivKeyServer,loPubKeyFromClient,"base64")

//  ---------------------------------------------------------
//  Examine the shared secrets.  They should be the same.
//  Both sides now have a secret that only they know.
//  ---------------------------------------------------------
? lcSharedSecret1
? lcSharedSecret2


release loPrngClient
release loEccClient
release loPrivKeyClient
release loPubKeyClient
release loPrngServer
release loEccServer
release loPrivKeyServer
release loPubKeyServer
release loPubKeyFromServer
release loPubKeyFromClient