1e41f4b71Sopenharmony_ci# Encryption and Decryption with an AES Symmetric Key (CBC Mode) (ArkTS)
2e41f4b71Sopenharmony_ci
3e41f4b71Sopenharmony_ci
4e41f4b71Sopenharmony_ciFor details about the algorithm specifications, see [AES](crypto-sym-encrypt-decrypt-spec.md#aes).
5e41f4b71Sopenharmony_ci
6e41f4b71Sopenharmony_ci
7e41f4b71Sopenharmony_ci**Encryption**
8e41f4b71Sopenharmony_ci
9e41f4b71Sopenharmony_ci
10e41f4b71Sopenharmony_ci1. Use [cryptoFramework.createSymKeyGenerator](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#cryptoframeworkcreatesymkeygenerator) and [SymKeyGenerator.generateSymKey](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#generatesymkey-1) to generate a 128-bit AES symmetric key (**SymKey**).
11e41f4b71Sopenharmony_ci   
12e41f4b71Sopenharmony_ci   In addition to the example in this topic, [AES](crypto-sym-key-generation-conversion-spec.md#aes) and [Randomly Generating a Symmetric Key](crypto-generate-sym-key-randomly.md) may help you better understand how to generate an AES symmetric key. Note that the input parameters in the reference documents may be different from those in the example below.
13e41f4b71Sopenharmony_ci
14e41f4b71Sopenharmony_ci2. Use [cryptoFramework.createCipher](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#cryptoframeworkcreatecipher) with the string parameter **'AES128|CBC|PKCS7'** to create a **Cipher** instance. The key type is **AES128**, block cipher mode is **CBC**, and the padding mode is **PKCS7**.
15e41f4b71Sopenharmony_ci
16e41f4b71Sopenharmony_ci3. Use [Cipher.init](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#init-1) to initialize the **Cipher** instance. In the **Cipher.init** API, set **opMode** to **CryptoMode.ENCRYPT_MODE** (encryption), **key** to **SymKey** (the key for encryption), and **params** to **IvParamsSpec** corresponding to the CBC mode.
17e41f4b71Sopenharmony_ci
18e41f4b71Sopenharmony_ci4. If the data to be encrypted is short, you can use [Cipher.doFinal](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#dofinal-1) after **Cipher.init** to obtain the encrypted data.
19e41f4b71Sopenharmony_ci
20e41f4b71Sopenharmony_ci
21e41f4b71Sopenharmony_ci**Decryption**
22e41f4b71Sopenharmony_ci
23e41f4b71Sopenharmony_ci
24e41f4b71Sopenharmony_ci1. Use [Cipher.init](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#init-1) to initialize the **Cipher** instance. In the **Cipher.init** API, set **opMode** to **CryptoMode.DECRYPT_MODE** (decryption), **key** to **SymKey** (the key for decryption), and **params** to **IvParamsSpec** corresponding to the CBC mode.
25e41f4b71Sopenharmony_ci
26e41f4b71Sopenharmony_ci2. If the data to be decrypted is short, you can use [Cipher.doFinal](../../reference/apis-crypto-architecture-kit/js-apis-cryptoFramework.md#dofinal-1) after **Cipher.init** to obtain the decrypted data.
27e41f4b71Sopenharmony_ci
28e41f4b71Sopenharmony_ci
29e41f4b71Sopenharmony_ci- Example (using asynchronous APIs):
30e41f4b71Sopenharmony_ci
31e41f4b71Sopenharmony_ci  ```ts
32e41f4b71Sopenharmony_ci  import { cryptoFramework } from '@kit.CryptoArchitectureKit';
33e41f4b71Sopenharmony_ci  import { buffer } from '@kit.ArkTS';
34e41f4b71Sopenharmony_ci
35e41f4b71Sopenharmony_ci  function genIvParamsSpec() {
36e41f4b71Sopenharmony_ci    let arr = [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]; // 16 bytes
37e41f4b71Sopenharmony_ci    let dataIv = new Uint8Array(arr);
38e41f4b71Sopenharmony_ci    let ivBlob: cryptoFramework.DataBlob = { data: dataIv };
39e41f4b71Sopenharmony_ci    let ivParamsSpec: cryptoFramework.IvParamsSpec = {
40e41f4b71Sopenharmony_ci      algName: "IvParamsSpec",
41e41f4b71Sopenharmony_ci      iv: ivBlob
42e41f4b71Sopenharmony_ci    };
43e41f4b71Sopenharmony_ci    return ivParamsSpec;
44e41f4b71Sopenharmony_ci  }
45e41f4b71Sopenharmony_ci  // Encrypt the message.
46e41f4b71Sopenharmony_ci  async function encryptMessagePromise(symKey: cryptoFramework.SymKey, plainText: cryptoFramework.DataBlob) {
47e41f4b71Sopenharmony_ci    let cipher = cryptoFramework.createCipher('AES128|CBC|PKCS7');
48e41f4b71Sopenharmony_ci    let iv = genIvParamsSpec();
49e41f4b71Sopenharmony_ci    await cipher.init(cryptoFramework.CryptoMode.ENCRYPT_MODE, symKey, iv);
50e41f4b71Sopenharmony_ci    let cipherData = await cipher.doFinal(plainText);
51e41f4b71Sopenharmony_ci    return cipherData;
52e41f4b71Sopenharmony_ci  }
53e41f4b71Sopenharmony_ci  // Decrypt the message.
54e41f4b71Sopenharmony_ci  async function decryptMessagePromise(symKey: cryptoFramework.SymKey, cipherText: cryptoFramework.DataBlob) {
55e41f4b71Sopenharmony_ci    let decoder = cryptoFramework.createCipher('AES128|CBC|PKCS7');
56e41f4b71Sopenharmony_ci    let iv = genIvParamsSpec();
57e41f4b71Sopenharmony_ci    await decoder.init(cryptoFramework.CryptoMode.DECRYPT_MODE, symKey, iv);
58e41f4b71Sopenharmony_ci    let decryptData = await decoder.doFinal(cipherText);
59e41f4b71Sopenharmony_ci    return decryptData;
60e41f4b71Sopenharmony_ci  }
61e41f4b71Sopenharmony_ci
62e41f4b71Sopenharmony_ci  async function genSymKeyByData(symKeyData: Uint8Array) {
63e41f4b71Sopenharmony_ci    let symKeyBlob: cryptoFramework.DataBlob = { data: symKeyData };
64e41f4b71Sopenharmony_ci    let aesGenerator = cryptoFramework.createSymKeyGenerator('AES128');
65e41f4b71Sopenharmony_ci    let symKey = await aesGenerator.convertKey(symKeyBlob);
66e41f4b71Sopenharmony_ci    console.info('convertKey success');
67e41f4b71Sopenharmony_ci    return symKey;
68e41f4b71Sopenharmony_ci  }
69e41f4b71Sopenharmony_ci
70e41f4b71Sopenharmony_ci  async function aesCBC() {
71e41f4b71Sopenharmony_ci    try {
72e41f4b71Sopenharmony_ci      let keyData = new Uint8Array([83, 217, 231, 76, 28, 113, 23, 219, 250, 71, 209, 210, 205, 97, 32, 159]);
73e41f4b71Sopenharmony_ci      let symKey = await genSymKeyByData(keyData);
74e41f4b71Sopenharmony_ci      let message = "This is a test";
75e41f4b71Sopenharmony_ci      let plainText: cryptoFramework.DataBlob = { data: new Uint8Array(buffer.from(message, 'utf-8').buffer) };
76e41f4b71Sopenharmony_ci      let encryptText = await encryptMessagePromise(symKey, plainText);
77e41f4b71Sopenharmony_ci      let decryptText = await decryptMessagePromise(symKey, encryptText);
78e41f4b71Sopenharmony_ci      if (plainText.data.toString() === decryptText.data.toString()) {
79e41f4b71Sopenharmony_ci        console.info('decrypt ok');
80e41f4b71Sopenharmony_ci        console.info('decrypt plainText: ' + buffer.from(decryptText.data).toString('utf-8'));
81e41f4b71Sopenharmony_ci      } else {
82e41f4b71Sopenharmony_ci        console.error('decrypt failed');
83e41f4b71Sopenharmony_ci      }
84e41f4b71Sopenharmony_ci    } catch (error) {
85e41f4b71Sopenharmony_ci      console.error(`AES CBC "${error}", error code: ${error.code}`);
86e41f4b71Sopenharmony_ci    }
87e41f4b71Sopenharmony_ci  }
88e41f4b71Sopenharmony_ci  ```
89e41f4b71Sopenharmony_ci
90e41f4b71Sopenharmony_ci- Example (using synchronous APIs):
91e41f4b71Sopenharmony_ci
92e41f4b71Sopenharmony_ci  ```ts
93e41f4b71Sopenharmony_ci  import { cryptoFramework } from '@kit.CryptoArchitectureKit';
94e41f4b71Sopenharmony_ci  import { buffer } from '@kit.ArkTS';
95e41f4b71Sopenharmony_ci
96e41f4b71Sopenharmony_ci  function genIvParamsSpec() {
97e41f4b71Sopenharmony_ci    let arr = [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]; // 16 bytes
98e41f4b71Sopenharmony_ci    let dataIv = new Uint8Array(arr);
99e41f4b71Sopenharmony_ci    let ivBlob: cryptoFramework.DataBlob = { data: dataIv };
100e41f4b71Sopenharmony_ci    let ivParamsSpec: cryptoFramework.IvParamsSpec = {
101e41f4b71Sopenharmony_ci      algName: "IvParamsSpec",
102e41f4b71Sopenharmony_ci      iv: ivBlob
103e41f4b71Sopenharmony_ci    };
104e41f4b71Sopenharmony_ci    return ivParamsSpec;
105e41f4b71Sopenharmony_ci  }
106e41f4b71Sopenharmony_ci  // Encrypt the message.
107e41f4b71Sopenharmony_ci  function encryptMessage(symKey: cryptoFramework.SymKey, plainText: cryptoFramework.DataBlob) {
108e41f4b71Sopenharmony_ci    let cipher = cryptoFramework.createCipher('AES128|CBC|PKCS7');
109e41f4b71Sopenharmony_ci    let iv = genIvParamsSpec();
110e41f4b71Sopenharmony_ci    cipher.initSync(cryptoFramework.CryptoMode.ENCRYPT_MODE, symKey, iv);
111e41f4b71Sopenharmony_ci    let cipherData = cipher.doFinalSync(plainText);
112e41f4b71Sopenharmony_ci    return cipherData;
113e41f4b71Sopenharmony_ci  }
114e41f4b71Sopenharmony_ci  // Decrypt the message.
115e41f4b71Sopenharmony_ci  function decryptMessage(symKey: cryptoFramework.SymKey, cipherText: cryptoFramework.DataBlob) {
116e41f4b71Sopenharmony_ci    let decoder = cryptoFramework.createCipher('AES128|CBC|PKCS7');
117e41f4b71Sopenharmony_ci    let iv = genIvParamsSpec();
118e41f4b71Sopenharmony_ci    decoder.initSync(cryptoFramework.CryptoMode.DECRYPT_MODE, symKey, iv);
119e41f4b71Sopenharmony_ci    let decryptData = decoder.doFinalSync(cipherText);
120e41f4b71Sopenharmony_ci    return decryptData;
121e41f4b71Sopenharmony_ci  }
122e41f4b71Sopenharmony_ci
123e41f4b71Sopenharmony_ci  async function genSymKeyByData(symKeyData: Uint8Array) {
124e41f4b71Sopenharmony_ci    let symKeyBlob: cryptoFramework.DataBlob = { data: symKeyData };
125e41f4b71Sopenharmony_ci    let aesGenerator = cryptoFramework.createSymKeyGenerator('AES128');
126e41f4b71Sopenharmony_ci    let symKey = await aesGenerator.convertKey(symKeyBlob);
127e41f4b71Sopenharmony_ci    console.info('convertKey success');
128e41f4b71Sopenharmony_ci    return symKey;
129e41f4b71Sopenharmony_ci  }
130e41f4b71Sopenharmony_ci
131e41f4b71Sopenharmony_ci  async function main() {
132e41f4b71Sopenharmony_ci    try {
133e41f4b71Sopenharmony_ci      let keyData = new Uint8Array([83, 217, 231, 76, 28, 113, 23, 219, 250, 71, 209, 210, 205, 97, 32, 159]);
134e41f4b71Sopenharmony_ci      let symKey = await genSymKeyByData(keyData);
135e41f4b71Sopenharmony_ci      let message = "This is a test";
136e41f4b71Sopenharmony_ci      let plainText: cryptoFramework.DataBlob = { data: new Uint8Array(buffer.from(message, 'utf-8').buffer) };
137e41f4b71Sopenharmony_ci      let encryptText = encryptMessage(symKey, plainText);
138e41f4b71Sopenharmony_ci      let decryptText = decryptMessage(symKey, encryptText);
139e41f4b71Sopenharmony_ci      if (plainText.data.toString() === decryptText.data.toString()) {
140e41f4b71Sopenharmony_ci        console.info('decrypt ok');
141e41f4b71Sopenharmony_ci        console.info('decrypt plainText: ' + buffer.from(decryptText.data).toString('utf-8'));
142e41f4b71Sopenharmony_ci      } else {
143e41f4b71Sopenharmony_ci        console.error('decrypt failed');
144e41f4b71Sopenharmony_ci      }
145e41f4b71Sopenharmony_ci    } catch (error) {
146e41f4b71Sopenharmony_ci      console.error(`AES CBC "${error}", error code: ${error.code}`);
147e41f4b71Sopenharmony_ci    }
148e41f4b71Sopenharmony_ci  }
149e41f4b71Sopenharmony_ci  ```
150