logo

Database

Go Key Derived Iv Nonce

Description

This detector identifies improper initialization vector (IV) or nonce derivation in Go cryptographic operations. When using AEAD (Authenticated Encryption with Associated Data) ciphers, deriving IVs/nonces directly from keys creates predictable values that compromise encryption security, as the same key-data combination will always produce identical IVs.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • Scans Go source code files that import AEAD cryptographic modules (such as crypto/cipher or related encryption libraries)

    • Analyzes cryptographic function calls and operations within the imported AEAD modules

    • Detects patterns where initialization vectors (IVs) or nonces are derived directly from cryptographic keys rather than being generated randomly

    • Reports vulnerabilities when key-derived IV/nonce generation is identified, indicating weak cryptographic implementation that could lead to predictable encryption patterns

Vulnerable code example

package main

import (
	"crypto/aes"
	"crypto/cipher"
)

func encryptData(key, plaintext []byte) ([]byte, error) {...

✅ Secure code example

package main

import (
	"crypto/aes"
	"crypto/cipher"
	"crypto/rand"
	"io"
)...