You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AesCng持久化密钥导出/导入异常:导入触发CryptographicException句柄无效

Troubleshooting "The supplied handle is invalid" When Importing CngKey Blob for AES-CNG

Hey, I’ve dealt with this exact CryptographicException before when syncing persisted AES keys via CngKey between servers. Let’s walk through the most common culprits and fixes that got me past this error:

1. Mismatched Blob Formats Between Export/Import

This is the #1 cause I’ve seen. When exporting your AES key, you must use the exact same CngKeyBlobFormat when importing it later. For AES symmetric keys, the correct format is usually CngKeyBlobFormat.GenericBlob—avoid mixing this up with formats like GenericPublicBlob or Pkcs8PrivateBlob (those are for asymmetric keys).

Example of correct export code:

// Assume you have an existing persisted CngKey for AES
using var aesKey = CngKey.Open("YourAesKeyName", CngProvider.MicrosoftSoftwareKeyStorageProvider);
byte[] keyBlob = aesKey.Export(CngKeyBlobFormat.GenericBlob);
// Save this blob to a secure file/transfer to other servers

And matching import code:

// Retrieve the blob bytes from storage/transfer
byte[] keyBlob = ...;

var creationParams = new CngKeyCreationParameters
{
    Provider = CngProvider.MicrosoftSoftwareKeyStorageProvider, // Match original provider
    KeyCreationOptions = CngKeyCreationOptions.PersistKey, // If you want the imported key to persist
    ExportPolicy = CngExportPolicies.AllowPlaintextExport // Match original key's export policy
};

try
{
    var importedKey = CngKey.Import(keyBlob, CngKeyBlobFormat.GenericBlob, creationParams);
    // Use the key with AesCng
    using var aes = new AesCng(importedKey);
    // ... your encryption/decryption logic
}
catch (CryptographicException ex)
{
    // Check inner exception for more details!
    Console.WriteLine($"Error: {ex.Message}, Inner: {ex.InnerException?.Message}");
}

2. Mismatched CngProvider

If your original key was created with a specific provider (like MicrosoftSoftwareKeyStorageProvider for software-based keys, or a hardware provider like an HSM), you must specify that same provider in CngKeyCreationParameters when importing. Using a different provider will result in an invalid handle error because the blob is tied to the original provider's format.

3. Corrupted or Incomplete Blob Data

Double-check that the blob bytes you’re importing are identical to the ones you exported. It’s easy to accidentally truncate the blob during file saving, network transfer, or serialization (e.g., converting to a base64 string incorrectly). Compare the length of the exported blob and imported blob—if they don’t match, that’s a red flag.

4. Incorrect Key Creation Parameters

The original key’s properties (like export policies, persistence settings, or key usage) need to be mirrored in the import’s CngKeyCreationParameters. For example:

  • If your original key wasn’t marked as exportable, don’t set AllowPlaintextExport during import.
  • If you don’t want the imported key to persist, omit CngKeyCreationOptions.PersistKey.

Mismatched properties can cause the crypto service provider to reject the blob, resulting in the invalid handle error.

5. Debug with System Logs

If none of the above fixes work, check the Windows Event Viewer for more details. Look under Windows Logs > Application and filter for events from the Cryptographic Services source—these logs often include specific error codes or context about why the handle was rejected (e.g., missing permissions, unsupported key type).


内容的提问来源于stack exchange,提问作者L_E_R

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:26:39