Backing up app data on Android is straightforward with ADB, but the raw adb backup file is stored in plain text. If the backup falls into the wrong hands, personal messages, settings, or even credentials can be exposed. This tutorial walks you through creating a full app‑data backup, encrypting it with OpenSSL, and restoring it later – all without rooting the device.
ADB backups are convenient because they work on most Android versions (4.4+). However, the backup file contains a tar archive of app data that can be opened with standard tools. Encryption adds three layers of protection:
Make sure you have the following ready:
adb installed (part of the Android SDK Platform‑Tools).adb devices. You should see a device ID followed by device.
adb devices
List of devices attached
1234567890ABCDEF device
unauthorized, unlock the phone and tap the dialog that asks for USB debugging permission.ADB offers two main modes:
adb backup -apk -shared -all -f backup.ab – backs up all user apps, their APKs, and shared storage.adb backup -apk -nosystem -f backup.ab com.example.app – backs up a single app.Choose the scope that matches your need. For a full‑device backup, use the first command:
backup.ab with a path you prefer):
adb backup -apk -shared -all -f ~/Desktop/backup.ab
When the command returns, you have a file backup.ab on your computer.
The .ab format is essentially a custom wrapper around a tar stream. Converting it makes it easier to encrypt and later inspect if needed.
android-backup-extractor (abe) Java tool from its GitHub releases page. It’s a single abe.jar file.java -jar abe.jar unpack ~/Desktop/backup.ab ~/Desktop/backup.tar
After this step you have backup.tar, a plain‑text archive that can be inspected with any tar utility.
We’ll use AES‑256‑CBC with a random IV and an HMAC‑SHA256 tag to provide confidentiality and integrity. OpenSSL’s enc command can do this in one line.
backup.tar.encrypted_backup.bin with your desired output name):
openssl enc -aes-256-cbc -salt -in backup.tar -out encrypted_backup.bin -pbkdf2
The -pbkdf2 flag tells OpenSSL to use a modern key‑derivation function, making the passphrase harder to brute‑force.
encrypted_backup.bin exists and is roughly the same size as backup.tar (a few extra bytes for the salt header).Security note: Store the passphrase in a password manager. If you lose it, the encrypted backup cannot be recovered.
Now that you have a securely encrypted backup, you can delete the raw .ab and .tar files to avoid accidental exposure.
rm ~/Desktop/backup.ab ~/Desktop/backup.tar
Remove-Item C:\Users\YourName\Desktop\backup.ab
Remove-Item C:\Users\YourName\Desktop\backup.tar
Keep encrypted_backup.bin in a safe location – an external SSD, an encrypted cloud folder, or a dedicated backup drive.
When you need to restore, the process is the reverse of steps 4–2.
openssl enc -d -aes-256-cbc -in encrypted_backup.bin -out restore.tar -pbkdf2
Enter the same passphrase you used for encryption.
.ab file using abe.jar:
java -jar abe.jar pack restore.tar restore.ab
adb devices shows it, then run:
adb restore restore.ab
The phone will display a “Restore data?” dialog. Confirm and wait for the process to complete.
restore.tar and restore.ab from the computer.If you see a message like “Backup password incorrect”, double‑check that you used the same passphrase for encryption and decryption.
-noapk flag to exclude APKs and only restore data.Some OEMs (e.g., newer Samsung One UI) have disabled adb backup. If you encounter this limitation, consider:
BackupAgent API (e.g., SwiftBackup), then encrypting the exported files with OpenSSL as described in steps 4‑5.By following these steps you gain a portable, encrypted snapshot of your Android app data that can survive device loss, accidental wipes, or a switch to a new phone – all without ever rooting the device.









