Sample code for 30+ languages & platforms
Tcl

PBES1 Password-Based Encryption (PBE)

See more Encryption Examples

Demonstrates how to implement password-based encryption according to the PKCS #5 v2.0: Password-Based Cryptography Standard (published by RSA Laboratories). This example uses PBES1, which ise based on the PBKDF1 function and an underlying block cipher such as RC2, DES, etc.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

# This example assumes the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.

set crypt [new_CkCrypt2]

# Set properties for PBES1 encryption:

CkCrypt2_put_CryptAlgorithm $crypt "pbes1"
CkCrypt2_put_PbesPassword $crypt "mySecretPassword"

# Set the underlying PBE algorithm (and key length):
# For PBES1, the underlying algorithm must be either
# 56-bit DES or 64-bit RC2 
# (this is according to the PKCS#5 specifications at
# http://www.rsa.com/rsalabs/node.asp?id=2127   )
CkCrypt2_put_PbesAlgorithm $crypt "rc2"
CkCrypt2_put_KeyLength $crypt 64

# The salt for PBKDF1 is always 8 bytes:
CkCrypt2_SetEncodedSalt $crypt "0102030405060708" "hex"

# A higher iteration count makes the algorithm more
# computationally expensive and therefore exhaustive
# searches (for breaking the encryption) is more difficult:
CkCrypt2_put_IterationCount $crypt 1024

# A hash algorithm needs to be set for PBES1:
CkCrypt2_put_HashAlgorithm $crypt "sha1"

# Indicate that the encrypted bytes should be returned
# as a hex string:
CkCrypt2_put_EncodingMode $crypt "hex"

set plainText "To be encrypted."

set encryptedText [CkCrypt2_encryptStringENC $crypt $plainText]

puts "$encryptedText"

# Now decrypt:
set decryptedText [CkCrypt2_decryptStringENC $crypt $encryptedText]

puts "$decryptedText"

delete_CkCrypt2 $crypt