logo

Database

Typescript Key Derived Iv Nonce

Description

This vulnerability detector identifies cryptographic implementations in TypeScript that derive initialization vectors (IVs) or nonces from encryption keys, which is cryptographically insecure. Using key-derived IVs/nonces can lead to predictable or repeated values, compromising encryption security and potentially allowing attackers to decrypt data or perform cryptographic attacks.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • Scans TypeScript source code for cryptographic operations that generate initialization vectors (IVs) or nonces

    • Identifies patterns where IVs or nonces are derived from encryption keys rather than being randomly generated

    • Triggers when cryptographic functions use keys as input to generate IVs or nonces, violating cryptographic best practices

    • Reports violations where the same key is used both for encryption and IV/nonce generation, creating security weaknesses

Vulnerable code example

import * as crypto from 'crypto';

function encryptWithSameIV(data: Buffer): Buffer {
  const key = crypto.randomBytes(16);
  
  // VULNERABLE: IV reuses the same bytes as the encryption key
  const cipher = crypto.createCipheriv('aes-128-cbc', key, key);
  return Buffer.concat([cipher.update(data), cipher.final()]);...

✅ Secure code example

import * as crypto from 'crypto';

function encryptWithRandomIV(data: Buffer): Buffer {
  const key = crypto.randomBytes(16);
  
  // SECURE: Generate IV independently from key
  const iv = crypto.randomBytes(16);
  const cipher = crypto.createCipheriv('aes-128-cbc', key, iv);...