调用BCryptExportKey时出现STATUS_NOT_SUPPORTED错误求助
问题:BCryptExportKey返回STATUS_NOT_SUPPORTED(C00000BB)错误
我尝试使用BCrypt的BCryptEncrypt、BCryptDecrypt进行加解密操作,需要先导出再导入密钥,但调用BCryptExportKey时返回状态码3221225659(十六进制C00000BB),对应NTSTATUS的STATUS_NOT_SUPPORTED(请求不受支持)。
错误原因
代码存在两个核心问题:
- 错误的Blob类型匹配:第一次调用
BCryptExportKey时使用了"ECCPUBLICBLOB",但ECC是椭圆曲线加密算法的Blob格式,你当前创建的是AES对称密钥,AES不支持该Blob类型,直接触发了STATUS_NOT_SUPPORTED错误。 - Blob类型前后不一致:第二次调用又换成了
"KeyDataBlob",AES对称密钥导出的正确Blob类型应为"PLAINTEXTKEYBLOB"。
修复后的代码
using System.Runtime.InteropServices; using System.Text; namespace TestConsoleApp { internal class Program { static void Main(string[] args) { ExportImportKey(); } internal static void ExportImportKey() { string keyString = "12345678abcdefgh"; // 16 byte byte[] key = Encoding.UTF8.GetBytes(keyString); byte[] exportedKey = ExportKey(key); // 可在此添加导入密钥的测试逻辑 } internal static byte[] ExportKey(byte[] key) { IntPtr phAlgorithm = IntPtr.Zero; IntPtr hKey = IntPtr.Zero; byte[] exportedKey = null; try { uint statusCode = BCryptOpenAlgorithmProvider(out phAlgorithm, "AES", "Microsoft Primitive Provider", 0); if (statusCode != 0) throw new System.Exception($"BCryptOpenAlgorithmProvider failed: 0x{statusCode:X8}"); statusCode = BCryptGenerateSymmetricKey(phAlgorithm, out hKey, IntPtr.Zero, 0, key, key.Length, 0); if (statusCode != 0) throw new System.Exception($"BCryptGenerateSymmetricKey failed: 0x{statusCode:X8}"); int keySize = 0; // 使用AES支持的PLAINTEXTKEYBLOB类型 statusCode = BCryptExportKey(hKey, IntPtr.Zero, "PLAINTEXTKEYBLOB", null, 0, out keySize, 0); if (statusCode != 0) throw new System.Exception($"BCryptExportKey (get size) failed: 0x{statusCode:X8}"); exportedKey = new byte[keySize]; statusCode = BCryptExportKey(hKey, IntPtr.Zero, "PLAINTEXTKEYBLOB", exportedKey, exportedKey.Length, out keySize, 0); if (statusCode != 0) throw new System.Exception($"BCryptExportKey failed: 0x{statusCode:X8}"); } finally { // 释放资源避免内存泄漏 if (hKey != IntPtr.Zero) BCryptDestroyKey(hKey); if (phAlgorithm != IntPtr.Zero) BCryptCloseAlgorithmProvider(phAlgorithm, 0); } return exportedKey; } [DllImport("bcrypt.dll")] public static extern uint BCryptOpenAlgorithmProvider(out IntPtr phAlgorithm, [MarshalAs(UnmanagedType.LPWStr)] string pszAlgId, [MarshalAs(UnmanagedType.LPWStr)] string pszImplementation, uint dwFlags); [DllImport("bcrypt.dll")] public static extern uint BCryptCloseAlgorithmProvider(IntPtr phAlgorithm, uint dwFlags); [DllImport("bcrypt.dll")] public static extern uint BCryptExportKey(IntPtr hKey, IntPtr hExportKey, [MarshalAs(UnmanagedType.LPWStr)] string pszBlobType, byte[] pbOutput, int cbOutput, out int pcbResult, uint dwFlags); [DllImport("bcrypt.dll")] public static extern uint BCryptGenerateSymmetricKey(IntPtr phAlgorithm, out IntPtr phKey, IntPtr pbKeyObject, int cbKeyObject, byte[] pbSecret, int cbSecret, uint dwFlags); [DllImport("bcrypt.dll")] public static extern uint BCryptDestroyKey(IntPtr hKey); } }
额外注意事项
- 资源释放:新增
BCryptDestroyKey调用及finally块,确保密钥和算法提供者句柄被正确释放,避免内存泄漏。 - 参数签名修正:调整了
BCryptExportKey等函数的参数类型(如dwFlags改为uint、pszBlobType添加MarshalAs(UnmanagedType.LPWStr)),保证与原生API签名一致。 - 错误检查:添加了状态码校验逻辑,便于快速定位后续可能出现的问题。
内容的提问来源于stack exchange,提问作者Md. Faisal Habib
相关产品推荐
相关产品推荐

