Sample code for 30+ languages & platforms
Xbase++

JWE using PBES2 Key Wrapping

See more JSON Web Encryption (JWE) Examples

Demonstrates how to create and decrypt a JWE that using PBES2 key wrapping.

This example demonstrates PBES2 with HMAC SHA-256 and A128KW wrapping. It is also possible to do the following by simply changing the "alg" parameter:

  • PBES2 with HMAC SHA-384 and A192KW wrapping
  • PBES2 with HMAC SHA-512 and A256KW wrapping

Note: This example requires Chilkat v9.5.0.66 or greater.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL cPlaintext
LOCAL oJwe
LOCAL oJweProtHdr
LOCAL oPrng
LOCAL nRecipientIndex
LOCAL cStrJwe
LOCAL oJwe2
LOCAL cOriginalPlaintext

nSuccess := 0

//  This requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  Note: This example requires Chilkat v9.5.0.66 or greater.

cPlaintext := "Live long and prosper."

oJwe := CreateObject("Chilkat.Jwe")

//  First build the JWE Protected Header..
oJweProtHdr := CreateObject("Chilkat.JsonObject")
oJweProtHdr:AppendString("alg", "PBES2-HS256+A128KW")
oJweProtHdr:AppendString("enc", "A128GCM")

//  PBES2 requires two additional parameters:
//  1) A random salt parameter ("p2s") containing 8 or more bytes in base64url format.
//  2) An iteration count parameter ("p2c").  A minimum count of 1000 is recommended.
//     The iteration count is intended to make the PBES2 computation more expensive (time consuming)
//     to prevent brute-force attacks.
oPrng := CreateObject("Chilkat.Prng")
oJweProtHdr:AppendString("p2s", oPrng:GenRandom(16, "base64url"))
oJweProtHdr:AppendString("p2c", "1000")

? "JWE Protected Header: " + oJweProtHdr:Emit()
? "--"

//  Don't forget to actually provide the protected header to the JWE object:
oJwe:SetProtectedHeader(oJweProtHdr)

//  Set the PBES2 password
nRecipientIndex := 0
oJwe:SetPassword(nRecipientIndex, "top secret")

//  Encrypt and return the JWE:
cStrJwe := oJwe:Encrypt(cPlaintext, "utf-8")
IF (oJwe:LastMethodSuccess != 1)
    ? oJwe:LastErrorText
    oJwe:destroy()
    oJweProtHdr:destroy()
    oPrng:destroy()
    RETURN
ENDIF

//  Show the JWE we just created:
? cStrJwe

//  Decrypt the JWE.
oJwe2 := CreateObject("Chilkat.Jwe")
nSuccess := oJwe2:LoadJwe(cStrJwe)
IF (nSuccess != 1)
    ? oJwe2:LastErrorText
    oJwe:destroy()
    oJweProtHdr:destroy()
    oPrng:destroy()
    oJwe2:destroy()
    RETURN
ENDIF

//  Set the PBES2 password
oJwe2:SetPassword(nRecipientIndex, "top secret")

//  Decrypt.
cOriginalPlaintext := oJwe2:Decrypt(0, "utf-8")
IF (oJwe2:LastMethodSuccess != 1)
    ? oJwe2:LastErrorText
    oJwe:destroy()
    oJweProtHdr:destroy()
    oPrng:destroy()
    oJwe2:destroy()
    RETURN
ENDIF

? "original text: "
? cOriginalPlaintext

//  Sample output:

//  JWE Protected Header: {"alg":"PBES2-HS256+A128KW","enc":"A128GCM","p2s":"z39rTEfRy1T1Yn_D1mZRlg","p2c":"1000"}
//  --
//  eyJhbGciOiJQQkVTMi1IUzI1NitBMTI4S1ciLCJlbmMiOiJBMTI4R0NNIiwicDJzIjoiejM5clRFZlJ5MVQxWW5fRDFtWlJsZyIsInAyYyI6IjEwMDAifQ.koYt6PrFmYwcwdcT7ZcvXHA1d-Xez5h4.luGlbvEnZp-7IsBOj42Yhw.YMTcfLf8Qe4zazozGV2OAu3cUdQ8Kg.rWub47ESWkc6IqZJTvSTmg
//  original text: 
//  Live long and prosper.

oJwe:destroy()
oJweProtHdr:destroy()
oPrng:destroy()
oJwe2:destroy()