logo

Database

Kotlin Key Derived Iv Nonce

Description

This vulnerability detector identifies instances in Kotlin code where cryptographic initialization vectors (IVs) or nonces are derived from the same key material. Using key-derived IVs/nonces severely compromises cryptographic security by making encrypted data predictable and potentially allowing attackers to break encryption schemes.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • The detector only activates when GCM (Galois/Counter Mode) cryptographic libraries are imported in the codebase

    • It examines all selected code nodes to identify cryptographic initialization patterns

    • A vulnerability is reported when key-derived initialization is detected in conjunction with GCM library usage

    • The detection focuses on scenarios where the same cryptographic key is used to generate both encryption keys and initialization vectors

Vulnerable code example

import java.security.MessageDigest
import javax.crypto.Cipher
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.SecretKeySpec

fun encryptWithWeakIV(data: ByteArray): ByteArray {
    val key = ByteArray(16) { 0x42 }
    val keySpec = SecretKeySpec(key, "AES")...

✅ Secure code example

import java.security.SecureRandom
import javax.crypto.Cipher
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.SecretKeySpec

fun encryptWithWeakIV(data: ByteArray): ByteArray {
    val key = ByteArray(16) { 0x42 }
    val keySpec = SecretKeySpec(key, "AES")...