AesCng持久化密钥导出/导入异常:导入触发CryptographicException句柄无效
Hey, I’ve dealt with this exact CryptographicException before when syncing persisted AES keys via CngKey between servers. Let’s walk through the most common culprits and fixes that got me past this error:
1. Mismatched Blob Formats Between Export/Import
This is the #1 cause I’ve seen. When exporting your AES key, you must use the exact same CngKeyBlobFormat when importing it later. For AES symmetric keys, the correct format is usually CngKeyBlobFormat.GenericBlob—avoid mixing this up with formats like GenericPublicBlob or Pkcs8PrivateBlob (those are for asymmetric keys).
Example of correct export code:
// Assume you have an existing persisted CngKey for AES using var aesKey = CngKey.Open("YourAesKeyName", CngProvider.MicrosoftSoftwareKeyStorageProvider); byte[] keyBlob = aesKey.Export(CngKeyBlobFormat.GenericBlob); // Save this blob to a secure file/transfer to other servers
And matching import code:
// Retrieve the blob bytes from storage/transfer byte[] keyBlob = ...; var creationParams = new CngKeyCreationParameters { Provider = CngProvider.MicrosoftSoftwareKeyStorageProvider, // Match original provider KeyCreationOptions = CngKeyCreationOptions.PersistKey, // If you want the imported key to persist ExportPolicy = CngExportPolicies.AllowPlaintextExport // Match original key's export policy }; try { var importedKey = CngKey.Import(keyBlob, CngKeyBlobFormat.GenericBlob, creationParams); // Use the key with AesCng using var aes = new AesCng(importedKey); // ... your encryption/decryption logic } catch (CryptographicException ex) { // Check inner exception for more details! Console.WriteLine($"Error: {ex.Message}, Inner: {ex.InnerException?.Message}"); }
2. Mismatched CngProvider
If your original key was created with a specific provider (like MicrosoftSoftwareKeyStorageProvider for software-based keys, or a hardware provider like an HSM), you must specify that same provider in CngKeyCreationParameters when importing. Using a different provider will result in an invalid handle error because the blob is tied to the original provider's format.
3. Corrupted or Incomplete Blob Data
Double-check that the blob bytes you’re importing are identical to the ones you exported. It’s easy to accidentally truncate the blob during file saving, network transfer, or serialization (e.g., converting to a base64 string incorrectly). Compare the length of the exported blob and imported blob—if they don’t match, that’s a red flag.
4. Incorrect Key Creation Parameters
The original key’s properties (like export policies, persistence settings, or key usage) need to be mirrored in the import’s CngKeyCreationParameters. For example:
- If your original key wasn’t marked as exportable, don’t set
AllowPlaintextExportduring import. - If you don’t want the imported key to persist, omit
CngKeyCreationOptions.PersistKey.
Mismatched properties can cause the crypto service provider to reject the blob, resulting in the invalid handle error.
5. Debug with System Logs
If none of the above fixes work, check the Windows Event Viewer for more details. Look under Windows Logs > Application and filter for events from the Cryptographic Services source—these logs often include specific error codes or context about why the handle was rejected (e.g., missing permissions, unsupported key type).
内容的提问来源于stack exchange,提问作者L_E_R

