logo

Database

Scala Key Derived Iv Nonce

Description

This vulnerability detector identifies cryptographic implementations in Scala that use key-derived initialization vectors (IVs) or nonces, which is a dangerous practice. Using the same key to derive both the encryption key and IV creates predictable patterns that significantly weaken encryption security and can lead to data exposure.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • Scans Scala source code files that import javax.crypto cryptographic libraries

    • Identifies method calls or initializations that appear to derive initialization vectors or nonces from the same key used for encryption

    • Reports violations when cryptographic code uses key-derived IVs instead of randomly generated values

    • Triggers when the code pattern suggests the same cryptographic key is being used to generate both encryption keys and initialization parameters

Vulnerable code example

import javax.crypto.Cipher
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.SecretKeySpec

object VulnerableEncryption {
  def encrypt(keyBytes: Array[Byte], data: Array[Byte]): Array[Byte] = {
    val keySpec = new SecretKeySpec(keyBytes, "AES")
    val cipher = Cipher.getInstance("AES/CBC/PKCS5Padding")...

✅ Secure code example

import java.security.SecureRandom
import javax.crypto.Cipher
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.SecretKeySpec

object SecureEncryption {
  def encrypt(keyBytes: Array[Byte], data: Array[Byte]): Array[Byte] = {
    val keySpec = new SecretKeySpec(keyBytes, "AES")...