Depending on the application, it is usually recommended to use KMS to store encryption keys. If KMS is unavailable due to budget constraints or something else, key containers are the next best option. After your key is protected, you can store the variables either in the encrypted sections of the configuration file, as suggested, or as encrypted byte arrays in the assembly itself.
lukiffer
source share