Mastering CNG: Exploring NCryptOpenStorageProvider and Modern Key Storage Architectures
It allows easy integration with TPM (Trusted Platform Module) for keys that never leave secure hardware, often enabled by setting MS_PLATFORM_CRYPTO_PROVIDER . ncryptopenstorageprovider new