You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET 7数据保护密钥跨机器使用时解密异常原因排查

.NET Data Protection跨机器使用DPAPI加密密钥文件报错:CryptographicException

两台开发机器运行相同的.NET 7 Web项目,均启用.NET Data Protection且配置一致。将其中一台机器的密钥文件(XML)复制到另一台后,目标机器使用该密钥文件时抛出System.Security.Cryptography.CryptographicException: Error occurred during a cryptographic operation异常。

日志追踪信息如下:

trce: Microsoft.AspNetCore.DataProtection.KeyManagement.KeyRingBasedDataProtector[5]
      Performing unprotect operation to key {[REMOVED]} with purposes ('[REMOVED]', '[REMOVED]').
dbug: Microsoft.AspNetCore.DataProtection.TypeForwardingActivator[0]
      Forwarded activator type request from Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor, Microsoft.AspNetCore.DataProtection, Version=6.0.0.0, Culture=neutral, PublicKeyToken=adb9793829ddae60 to Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor, Microsoft.AspNetCore.DataProtection, Culture=neutral, PublicKeyToken=adb9793829ddae60
dbug: Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor[51]
      Decrypting secret element using Windows DPAPI.
fail: Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor[43]
      An exception occurred while trying to decrypt the element.
      System.Security.Cryptography.CryptographicException: Error occurred during a cryptographic operation.
         at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapiCore(Byte* pbProtectedData, UInt32 cbProtectedData, Byte* pbOptionalEntropy, UInt32 cbOptionalEntropy)
         at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapi(Byte[] protectedSecret)
         at Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor.Decrypt(XElement encryptedElement)
fail: Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager[24]
      An exception occurred while processing the key element '<key id="[REMOVED]" version="1" />'.
      System.Security.Cryptography.CryptographicException: Error occurred during a cryptographic operation.
         at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapiCore(Byte* pbProtectedData, UInt32 cbProtectedData, Byte* pbOptionalEntropy, UInt32 cbOptionalEntropy)
         at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapi(Byte[] protectedSecret)
         at Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor.Decrypt(XElement encryptedElement)
         at Microsoft.AspNetCore.DataProtection.XmlEncryption.XmlEncryptionExtensions.DecryptElement(XElement element, IActivator activator)
         at Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager.Microsoft.AspNetCore.DataProtection.KeyManagement.Internal.IInternalXmlKeyManager.DeserializeDescriptorFromKeyElement(XElement keyElement)
trce: Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager[25]
      An exception occurred while processing the key element '<key id="[REMOVED]" version="1">
        <creationDate>2022-09-15T01:32:44.1371668Z</creationDate>
        <activationDate>2022-09-15T01:32:44.1270795Z</activationDate>
        <expirationDate>2022-12-14T01:32:44.1270795Z</expirationDate>
        <descriptor deserializerType="Microsoft.AspNetCore.DataProtection.AuthenticatedEncryption.ConfigurationModel.AuthenticatedEncryptorDescriptorDeserializer, Microsoft.AspNetCore.DataProtection, Version=6.0.0.0, Culture=neutral, PublicKeyToken=adb9793829ddae60">
          <descriptor>
            <encryption algorithm="AES_256_CBC" />
            <validation algorithm="HMACSHA256" />
            <encryptedSecret decryptorType="Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor, Microsoft.AspNetCore.DataProtection, Version=6.0.0.0, Culture=neutral, PublicKeyToken=adb9793829ddae60" xmlns="http://schemas.asp.net/2015/03/dataProtection">
              <encryptedKey xmlns="">
                <!-- This key is encrypted with Windows DPAPI. -->
                <value>[REMOVED]</value>
              </encryptedKey>
            </encryptedSecret>
          </descriptor>
        </descriptor>
      </key>'.
      System.Security.Cryptography.CryptographicException: Error occurred during a cryptographic operation.
         at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapiCore(Byte* pbProtectedData, UInt32 cbProtectedData, Byte* pbOptionalEntropy, UInt32 cbOptionalEntropy)
         at Microsoft.AspNetCore.DataProtection.Cng.DpapiSecretSerializerHelper.UnprotectWithDpapi(Byte[] protectedSecret)
         at Microsoft.AspNetCore.DataProtection.XmlEncryption.DpapiXmlDecryptor.Decrypt(XElement encryptedElement)
         at Microsoft.AspNetCore.DataProtection.XmlEncryption.XmlEncryptionExtensions.DecryptElement(XElement element, IActivator activator)
         at Microsoft.AspNetCore.DataProtection.KeyManagement.XmlKeyManager.Microsoft.AspNetCore.DataProtection.KeyManagement.Internal.IInternalXmlKeyManager.DeserializeDescriptorFromKeyElement(XElement keyElement)

经确认两台机器的密钥文件内容完全一致,导致异常的可能原因如下:

  • DPAPI加密范围不匹配:默认情况下,.NET Data Protection生成密钥时使用用户范围的DPAPI加密,只有生成密钥的Windows用户账号才能解密。如果两台机器运行项目的用户账号不同(比如一台用LocalSystem,另一台用域账号,或者同域不同用户名),就会触发解密失败。
  • 未配置机器范围的DPAPI加密:若要实现跨机器共享密钥,需要显式配置Data Protection使用机器范围的DPAPI加密。默认生成的用户级密钥无法跨机器用户解密。
  • 域信任边界问题:如果是域环境,用户级DPAPI加密依赖域的信任关系。若两台机器不在同一个域,或者域信任失效,即使用户名相同,也无法解密对方用户加密的数据。
  • 密钥文件权限不足:目标机器上的密钥文件没有被运行项目的用户授予读取权限,导致DPAPI解密时无法正确访问密钥数据,触发加密操作异常。
  • 系统加密组件差异:两台机器的Windows版本、加密组件更新不一致(比如一台是Windows Server 2022,另一台是Windows 10),或者加密算法支持存在差异,也会导致解密失败。

内容的提问来源于stack exchange,提问作者MaxP

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 17:00:07