Yep, I'm about to do the same thing. Use a provider like SunJCE or BouncyCastle and use a Cipher to encrypt the cookie value with the algorithm of your choice.
I am having trouble getting Tomcat to recognise JCE though and so far cant get it to work, but to answer your question, Yes, it can be done.