logo

Database

C Sharp Key Derived Iv Nonce

Description

Detects cryptographic implementations that use key-derived Initialization Vectors (IVs) or nonces in C# applications. This vulnerability creates predictable IVs/nonces that reduce cryptographic strength, as the same key will always generate identical IVs, making encrypted data vulnerable to pattern analysis and chosen-plaintext attacks.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • Scans C# source code that imports the System.Security.Cryptography library

    • Identifies cryptographic operations where IVs or nonces are derived from encryption keys through property access patterns

    • Detects CreateEncryptor method calls that use key-derived IVs for symmetric encryption algorithms

    • Flags AEAD (Authenticated Encryption with Associated Data) encrypt operations that derive nonces from keys

    • Reports violations when cryptographic implementations generate predictable IVs/nonces instead of using random values

Vulnerable code example

using System;
using System.Security.Cryptography;

public class VulnerableEncryption
{
    public byte[] EncryptData(byte[] data)
    {
        byte[] key = RandomNumberGenerator.GetBytes(16);...

✅ Secure code example

using System;
using System.Security.Cryptography;

public class SecureEncryption
{
    public (byte[] EncryptedData, byte[] IV) EncryptData(byte[] data)
    {
        byte[] key = RandomNumberGenerator.GetBytes(16);...