You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用BCryptExportKey时出现STATUS_NOT_SUPPORTED错误求助

问题:BCryptExportKey返回STATUS_NOT_SUPPORTED(C00000BB)错误

我尝试使用BCrypt的BCryptEncrypt、BCryptDecrypt进行加解密操作,需要先导出再导入密钥,但调用BCryptExportKey时返回状态码3221225659(十六进制C00000BB),对应NTSTATUS的STATUS_NOT_SUPPORTED(请求不受支持)。


错误原因

代码存在两个核心问题:

  1. 错误的Blob类型匹配:第一次调用BCryptExportKey时使用了"ECCPUBLICBLOB",但ECC是椭圆曲线加密算法的Blob格式,你当前创建的是AES对称密钥,AES不支持该Blob类型,直接触发了STATUS_NOT_SUPPORTED错误。
  2. Blob类型前后不一致:第二次调用又换成了"KeyDataBlob",AES对称密钥导出的正确Blob类型应为"PLAINTEXTKEYBLOB"。

修复后的代码

using System.Runtime.InteropServices;
using System.Text;

namespace TestConsoleApp
{
    internal class Program
    {
        static void Main(string[] args)
        {
            ExportImportKey();
        }

        internal static void ExportImportKey()
        {
            string keyString = "12345678abcdefgh";  // 16 byte
            byte[] key = Encoding.UTF8.GetBytes(keyString);
            byte[] exportedKey = ExportKey(key);
            // 可在此添加导入密钥的测试逻辑
        }

        internal static byte[] ExportKey(byte[] key)
        {
            IntPtr phAlgorithm = IntPtr.Zero;
            IntPtr hKey = IntPtr.Zero;
            byte[] exportedKey = null;

            try
            {
                uint statusCode = BCryptOpenAlgorithmProvider(out phAlgorithm, "AES", "Microsoft Primitive Provider", 0);
                if (statusCode != 0) throw new System.Exception($"BCryptOpenAlgorithmProvider failed: 0x{statusCode:X8}");

                statusCode = BCryptGenerateSymmetricKey(phAlgorithm, out hKey, IntPtr.Zero, 0, key, key.Length, 0);
                if (statusCode != 0) throw new System.Exception($"BCryptGenerateSymmetricKey failed: 0x{statusCode:X8}");

                int keySize = 0;
                // 使用AES支持的PLAINTEXTKEYBLOB类型
                statusCode = BCryptExportKey(hKey, IntPtr.Zero, "PLAINTEXTKEYBLOB", null, 0, out keySize, 0);
                if (statusCode != 0) throw new System.Exception($"BCryptExportKey (get size) failed: 0x{statusCode:X8}");

                exportedKey = new byte[keySize];
                statusCode = BCryptExportKey(hKey, IntPtr.Zero, "PLAINTEXTKEYBLOB", exportedKey, exportedKey.Length, out keySize, 0);
                if (statusCode != 0) throw new System.Exception($"BCryptExportKey failed: 0x{statusCode:X8}");
            }
            finally
            {
                // 释放资源避免内存泄漏
                if (hKey != IntPtr.Zero) BCryptDestroyKey(hKey);
                if (phAlgorithm != IntPtr.Zero) BCryptCloseAlgorithmProvider(phAlgorithm, 0);
            }

            return exportedKey;
        }

        [DllImport("bcrypt.dll")]
        public static extern uint BCryptOpenAlgorithmProvider(out IntPtr phAlgorithm, [MarshalAs(UnmanagedType.LPWStr)] string pszAlgId, [MarshalAs(UnmanagedType.LPWStr)] string pszImplementation, uint dwFlags);

        [DllImport("bcrypt.dll")]
        public static extern uint BCryptCloseAlgorithmProvider(IntPtr phAlgorithm, uint dwFlags);

        [DllImport("bcrypt.dll")]
        public static extern uint BCryptExportKey(IntPtr hKey, IntPtr hExportKey, [MarshalAs(UnmanagedType.LPWStr)] string pszBlobType, byte[] pbOutput, int cbOutput, out int pcbResult, uint dwFlags);

        [DllImport("bcrypt.dll")]
        public static extern uint BCryptGenerateSymmetricKey(IntPtr phAlgorithm, out IntPtr phKey, IntPtr pbKeyObject, int cbKeyObject, byte[] pbSecret, int cbSecret, uint dwFlags);

        [DllImport("bcrypt.dll")]
        public static extern uint BCryptDestroyKey(IntPtr hKey);
    }
}

额外注意事项

  • 资源释放:新增BCryptDestroyKey调用及finally块,确保密钥和算法提供者句柄被正确释放,避免内存泄漏。
  • 参数签名修正:调整了BCryptExportKey等函数的参数类型(如dwFlags改为uint、pszBlobType添加MarshalAs(UnmanagedType.LPWStr)),保证与原生API签名一致。
  • 错误检查:添加了状态码校验逻辑,便于快速定位后续可能出现的问题。

内容的提问来源于stack exchange,提问作者Md. Faisal Habib

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 17:45:09