logo

Database

Java Key Derived Iv Nonce

Description

Detects when cryptographic initialization vectors (IVs) or nonces are derived from encryption keys in Java applications using javax.crypto.spec library. This practice is cryptographically unsafe as it reduces randomness and can lead to predictable encryption patterns that compromise data confidentiality.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • Scans Java source code for imports of the javax.crypto.spec library package

    • Identifies initialization patterns where IVs or nonces are derived from cryptographic keys

    • Flags code locations where key-derived initialization occurs as this violates cryptographic best practices

Vulnerable code example

import javax.crypto.Cipher;
import javax.crypto.spec.IvParameterSpec;
import javax.crypto.spec.SecretKeySpec;

public class VulnerableEncryption {
    
    public static byte[] encrypt(String data, byte[] keyBytes) throws Exception {
        SecretKeySpec keySpec = new SecretKeySpec(keyBytes, "AES");...

✅ Secure code example

import java.security.SecureRandom;
import javax.crypto.Cipher;
import javax.crypto.spec.IvParameterSpec;
import javax.crypto.spec.SecretKeySpec;

public class SecureEncryption {
    
    public static byte[] encrypt(String data, byte[] keyBytes) throws Exception {...