Python Key Derived Iv Nonce
Description
This vulnerability detector identifies cryptographic functions that derive initialization vectors (IVs) or nonces from encryption keys. Using key-derived IVs/nonces is a cryptographic weakness that can lead to predictable encryption patterns and potential data exposure, as the same key will always produce the same IV/nonce, compromising the randomness required for secure encryption.
Detection Strategy
• The method first checks if any Python cryptographic libraries (such as Crypto, cryptography, or similar packages) are imported in the code
• It then examines function calls within the imported cryptographic libraries
• For each function call, it analyzes whether the call represents an encryption operation where the initialization vector (IV) or nonce parameter is derived from the encryption key
• A vulnerability is reported when an encryption function call uses a key-derived value for its IV or nonce parameter instead of using a properly random or unique value
Vulnerable code example
from Crypto.Cipher import AES
def encrypt_data(data):
key = b'0123456789ABCDEF' # 16-byte key
# VULNERABLE: IV reuses the same bytes as the encryption key
cipher = AES.new(key, AES.MODE_CBC, key)
return cipher.encrypt(data)✅ Secure code example
from Crypto.Cipher import AES
from Crypto.Random import get_random_bytes
def encrypt_data(data):
key = b'0123456789ABCDEF' # 16-byte key
# SAFE: IV is generated randomly, not reused from key
iv = get_random_bytes(16)...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.