Description
Reusing an IV or nonce with the same key can reveal repeated plaintext prefixes in CBC and compromise the confidentiality of different messages in CTR and GCM. In GCM, reuse also weakens authentication-tag protection.
Potential impact
- Exposure of repeated plaintext patterns
- Increased opportunity for ciphertext analysis
- Greater risk of data recovery with the same key and weakened GCM authentication
Remediation
- Generate a cryptographically secure random IV or nonce for each encryption operation.
- IVs and nonces need not be secret, but must not be reused with the same key.
- Prefer APIs that handle nonce generation, such as CryptoKit's AES-GCM.
Examples
Before
swift
let aes = try AES(
key: key,
blockMode: CBC(iv: Array<UInt8>(repeating: 0, count: AES.blockSize)))
After
swift
import Foundation
import CryptoKit
func encryptWithFreshNonce(
data: Data,
key: SymmetricKey
) throws -> AES.GCM.SealedBox {
return try AES.GCM.seal(data, using: key)
}
Explanation:
- Before: A fixed IV can reveal relationships between ciphertexts when input repeats.
- After: Omitting the nonce from
AES.GCM.seallets the API generate a fresh random nonce.