Kotlin Key Derived Iv Nonce
Description
This vulnerability detector identifies instances in Kotlin code where cryptographic initialization vectors (IVs) or nonces are derived from the same key material. Using key-derived IVs/nonces severely compromises cryptographic security by making encrypted data predictable and potentially allowing attackers to break encryption schemes.
Detection Strategy
• The detector only activates when GCM (Galois/Counter Mode) cryptographic libraries are imported in the codebase
• It examines all selected code nodes to identify cryptographic initialization patterns
• A vulnerability is reported when key-derived initialization is detected in conjunction with GCM library usage
• The detection focuses on scenarios where the same cryptographic key is used to generate both encryption keys and initialization vectors
Vulnerable code example
import java.security.MessageDigest
import javax.crypto.Cipher
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.SecretKeySpec
fun encryptWithWeakIV(data: ByteArray): ByteArray {
val key = ByteArray(16) { 0x42 }
val keySpec = SecretKeySpec(key, "AES")...✅ Secure code example
import java.security.SecureRandom
import javax.crypto.Cipher
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.SecretKeySpec
fun encryptWithWeakIV(data: ByteArray): ByteArray {
val key = ByteArray(16) { 0x42 }
val keySpec = SecretKeySpec(key, "AES")...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.