Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

How to Generate an Elliptic Curve Shared Secret

See more ECC Examples

Demonstrates how to generate an ECC (Elliptic Curve Cryptography) shared secret. Imagine a cilent has one ECC private key, the server has another. A shared secret is computed by each side providing it's public key to the other. The private keys are kept private.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oPrngClient
LOCAL oEccClient
LOCAL oPrivKeyClient
LOCAL oPubKeyClient
LOCAL oPrngServer
LOCAL oEccServer
LOCAL oPrivKeyServer
LOCAL oPubKeyServer
LOCAL oPubKeyFromServer
LOCAL cSharedSecret1
LOCAL oPubKeyFromClient
LOCAL cSharedSecret2

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  This example includes both client-side and server-side code.
//  Each code segment is marked as client-side or server-side.
//  Imagine these segments are running on separate computers...

//  -----------------------------------------------------------------
//  (Client-Side) Generate an ECC key, save the public part to a file.
//  -----------------------------------------------------------------
oPrngClient := CreateObject("Chilkat.Prng")
oEccClient := CreateObject("Chilkat.Ecc")
oPrivKeyClient := CreateObject("Chilkat.PrivateKey")
nSuccess := oEccClient:GenKey("secp256r1", oPrngClient, oPrivKeyClient)
IF (nSuccess == 0)
    ? oEccClient:LastErrorText
    oPrngClient:destroy()
    oEccClient:destroy()
    oPrivKeyClient:destroy()
    RETURN
ENDIF

oPubKeyClient := CreateObject("Chilkat.PublicKey")
oPrivKeyClient:ToPublicKey(oPubKeyClient)
oPubKeyClient:SavePemFile(0, "qa_output/eccClientPub.pem")

//  -----------------------------------------------------------------
//  (Server-Side) Generate an ECC key, save the public part to a file.
//  -----------------------------------------------------------------
oPrngServer := CreateObject("Chilkat.Prng")
oEccServer := CreateObject("Chilkat.Ecc")
oPrivKeyServer := CreateObject("Chilkat.PrivateKey")
oEccServer:GenKey("secp256r1", oPrngServer, oPrivKeyServer)

oPubKeyServer := CreateObject("Chilkat.PublicKey")
oPrivKeyServer:ToPublicKey(oPubKeyServer)
oPubKeyServer:SavePemFile(0, "qa_output/eccServerPub.pem")

//  -----------------------------------------------------------------
//  (Client-Side) Generate the shared secret using our private key, and the other's public key.
//  -----------------------------------------------------------------

//  Imagine that the server sent the public key PEM to the client.
//  (This is simulated by loading the server's public key from the file.
oPubKeyFromServer := CreateObject("Chilkat.PublicKey")
oPubKeyFromServer:LoadFromFile("qa_output/eccServerPub.pem")
cSharedSecret1 := oEccClient:SharedSecretENC(oPrivKeyClient, oPubKeyFromServer, "base64")

//  -----------------------------------------------------------------
//  (Server-Side) Generate the shared secret using our private key, and the other's public key.
//  -----------------------------------------------------------------

//  Imagine that the client sent the public key PEM to the server.
//  (This is simulated by loading the client's public key from the file.
oPubKeyFromClient := CreateObject("Chilkat.PublicKey")
oPubKeyFromClient:LoadFromFile("qa_output/eccClientPub.pem")
cSharedSecret2 := oEccServer:SharedSecretENC(oPrivKeyServer, oPubKeyFromClient, "base64")

//  ---------------------------------------------------------
//  Examine the shared secrets.  They should be the same.
//  Both sides now have a secret that only they know.
//  ---------------------------------------------------------
? cSharedSecret1
? cSharedSecret2

oPrngClient:destroy()
oEccClient:destroy()
oPrivKeyClient:destroy()
oPubKeyClient:destroy()
oPrngServer:destroy()
oEccServer:destroy()
oPrivKeyServer:destroy()
oPubKeyServer:destroy()
oPubKeyFromServer:destroy()
oPubKeyFromClient:destroy()