Initialization Vector

Also known as:IV

Initialization Vector: Starting value for a block cipher mode that makes identical plaintexts produce different ciphertexts. Without a correctly chosen IV, even a strong block cipherBlock CipherSymmetric encryption method that processes data in fixed-length blocks. loses its security guarantees.

How it works and where it fits

A block cipher on its own always maps identical inputs to identical outputs. Modes such as CBC, CTR, or GCM therefore add a starting value that feeds the encryption of the first block or the counter construction. The IV need not be secret and is usually transmitted in the clear — but it must be unique under a given key. CBC additionally requires unpredictability; CTR and GCM only require uniqueness, but a repeat there is especially damaging.

Practical security relevance

The classic mistake is a hard-coded IV or one derived from metadata. If the same IV is reused with the same key, stream-cipher-like modes produce an identical keystream and therefore a two-time padKeystream ReuseReusing the same keystream, making the encrypted messages recoverable.; with GCM the authentication key becomes attackable as well. What is safe is a freshly drawn random value per message, or a strictly increasing counter with a documented key-rollover limit.

  • CryptographyCryptographyMethods for protecting information through encryption, signatures, and hash functions.: Methods for protecting information through encryption, signatures, and hash functions.
  • Block CipherBlock CipherSymmetric encryption method that processes data in fixed-length blocks.: Symmetric encryption method that processes data in fixed-length blocks.
  • EncryptionEncryptionConverts plaintext into unreadable ciphertext using a key.: Converts plaintext into unreadable ciphertext using a key.
  • NonceNonceA value intended for use only once in a cryptographic context.: A value intended for use only once in a cryptographic context.