logo

Database

Elixir Key Derived Iv Nonce

Description

This detector identifies Elixir code that uses key-derived initialization vectors (IVs) or nonces in encryption operations. Using the same key to derive both the encryption key and IV/nonce creates predictable patterns that can compromise the security of the encryption scheme, making it vulnerable to cryptographic attacks.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • Scans Elixir source code for encryption function calls that may use key-derived IVs or nonces

    • Identifies function calls where the same cryptographic key material is used to generate both the encryption key and the initialization vector

    • Reports vulnerabilities when encryption operations use predictable or key-derived initialization vectors instead of random values

    • Focuses on cryptographic library calls in Elixir that implement symmetric encryption with potentially weak IV generation

Vulnerable code example

defmodule VulnerableExample do
  def encrypt_data(data) do
    key = :crypto.strong_rand_bytes(16)
    
    # VULNERABLE: IV reuses the same bytes as the key
    :crypto.crypto_one_time(:aes_128_ctr, key, key, data, true)
  end
...

✅ Secure code example

defmodule SecureExample do
  def encrypt_data(data) do
    key = :crypto.strong_rand_bytes(16)
    
    # SAFE: IV generated independently, not reusing key bytes
    iv = :crypto.strong_rand_bytes(16)
    :crypto.crypto_one_time(:aes_128_ctr, key, iv, data, true)
  end...