Encrypted ADB Backup for Android – Secure Your App Data Without Root

12 min read Learn a step‑by‑step method to back up your Android app data with ADB, encrypt the backup using OpenSSL, and restore it safely without needing root access. October 02, 2026 11:30 How to Create an Encrypted ADB Backup of Android App Data (No Root)

Backing up app data on Android is straightforward with ADB, but the raw adb backup file is stored in plain text. If the backup falls into the wrong hands, personal messages, settings, or even credentials can be exposed. This tutorial walks you through creating a full app‑data backup, encrypting it with OpenSSL, and restoring it later – all without rooting the device.

Why encrypt an ADB backup?

ADB backups are convenient because they work on most Android versions (4.4+). However, the backup file contains a tar archive of app data that can be opened with standard tools. Encryption adds three layers of protection:

  • Confidentiality: Only someone with the passphrase can read the contents.
  • Integrity: OpenSSL’s authenticated encryption (AES‑256‑CBC with HMAC) detects tampering.
  • Portability: The encrypted file can be stored on cloud services or external drives without exposing raw data.

Before you start

Make sure you have the following ready:

  • A computer running Windows, macOS, or Linux with adb installed (part of the Android SDK Platform‑Tools).
  • OpenSSL installed (most Linux/macOS systems include it; Windows users can download the Win64 OpenSSL binary).
  • A USB cable and a device with Developer Options → USB debugging enabled.
  • Enough free storage on the computer for the unencrypted backup (typically 2‑3 × the size of the data you back up).
  • A strong passphrase you can remember – you’ll need it for both encryption and decryption.

Step 1 – Verify ADB connectivity

  1. Connect your Android phone to the computer via USB.
  2. Open a terminal (Command Prompt, PowerShell, Terminal, or iTerm).
  3. Run adb devices. You should see a device ID followed by device.
    adb devices
    List of devices attached
    1234567890ABCDEF    device
  4. If you see unauthorized, unlock the phone and tap the dialog that asks for USB debugging permission.

Step 2 – Create the raw ADB backup

ADB offers two main modes:

  • adb backup -apk -shared -all -f backup.ab – backs up all user apps, their APKs, and shared storage.
  • adb backup -apk -nosystem -f backup.ab com.example.app – backs up a single app.

Choose the scope that matches your need. For a full‑device backup, use the first command:

  1. Run the following command (replace backup.ab with a path you prefer):
    adb backup -apk -shared -all -f ~/Desktop/backup.ab
  2. On the phone, you’ll see a confirmation dialog titled “Full backup”.
    • Tap Back up my data.
    • If you want to protect the backup with a password, you can set one here, but we’ll apply stronger encryption later, so leave it blank and press Back up.
  3. Wait for the process to finish. The time depends on the amount of data – from a few seconds to several minutes.

When the command returns, you have a file backup.ab on your computer.

Step 3 – Convert the ADB backup to a standard TAR archive

The .ab format is essentially a custom wrapper around a tar stream. Converting it makes it easier to encrypt and later inspect if needed.

  1. Download the android-backup-extractor (abe) Java tool from its GitHub releases page. It’s a single abe.jar file.
  2. Run the conversion (replace paths as needed):
    java -jar abe.jar unpack ~/Desktop/backup.ab ~/Desktop/backup.tar
  3. If you set a password during the ADB backup, you’ll be prompted to enter it now. Since we left it blank, the command proceeds without a prompt.

After this step you have backup.tar, a plain‑text archive that can be inspected with any tar utility.

Step 4 – Encrypt the TAR file with OpenSSL

We’ll use AES‑256‑CBC with a random IV and an HMAC‑SHA256 tag to provide confidentiality and integrity. OpenSSL’s enc command can do this in one line.

  1. Open a terminal in the folder containing backup.tar.
  2. Run the following command (replace encrypted_backup.bin with your desired output name):
    openssl enc -aes-256-cbc -salt -in backup.tar -out encrypted_backup.bin -pbkdf2

    The -pbkdf2 flag tells OpenSSL to use a modern key‑derivation function, making the passphrase harder to brute‑force.

  3. You’ll be prompted for a passphrase. Choose a strong one (minimum 12 characters, mix of letters, numbers, symbols).
  4. After the command finishes, verify that encrypted_backup.bin exists and is roughly the same size as backup.tar (a few extra bytes for the salt header).

Security note: Store the passphrase in a password manager. If you lose it, the encrypted backup cannot be recovered.

Step 5 – Clean up the intermediate files

Now that you have a securely encrypted backup, you can delete the raw .ab and .tar files to avoid accidental exposure.

  1. On macOS/Linux:
    rm ~/Desktop/backup.ab ~/Desktop/backup.tar
  2. On Windows PowerShell:
    Remove-Item C:\Users\YourName\Desktop\backup.ab
    Remove-Item C:\Users\YourName\Desktop\backup.tar

Keep encrypted_backup.bin in a safe location – an external SSD, an encrypted cloud folder, or a dedicated backup drive.

Step 6 – Restoring the encrypted backup

When you need to restore, the process is the reverse of steps 4–2.

  1. Decrypt the file:
    openssl enc -d -aes-256-cbc -in encrypted_backup.bin -out restore.tar -pbkdf2

    Enter the same passphrase you used for encryption.

  2. Re‑package the TAR into an .ab file using abe.jar:
    java -jar abe.jar pack restore.tar restore.ab
  3. Connect the Android device, ensure adb devices shows it, then run:
    adb restore restore.ab

    The phone will display a “Restore data?” dialog. Confirm and wait for the process to complete.

  4. After restoration, you may want to delete restore.tar and restore.ab from the computer.

If you see a message like “Backup password incorrect”, double‑check that you used the same passphrase for encryption and decryption.

Troubleshooting common issues

  • ADB says “device unauthorized” – Re‑authorize the computer on the phone’s USB‑debugging dialog or revoke USB debugging authorizations in Settings > Developer options and reconnect.
  • OpenSSL reports “bad decrypt” – This usually means the wrong passphrase or a corrupted file. Verify the file’s integrity (compare file size) and retry.
  • Backup size is zero or extremely small – Some manufacturers disable the ADB backup feature for security reasons. In that case, you’ll need to use a custom recovery (e.g., TWRP) which requires unlocking the bootloader, outside the scope of a no‑root tutorial.
  • Restore fails with “error 3” – This can happen if the device’s Android version is newer than the version that created the backup. Try creating a fresh backup on the target device, or use the -noapk flag to exclude APKs and only restore data.

Alternative approaches (when ADB backup is unavailable)

Some OEMs (e.g., newer Samsung One UI) have disabled adb backup. If you encounter this limitation, consider:

  • Using Google Drive backup for app data (settings > System > Backup).
  • Installing a third‑party backup app that uses the Android BackupAgent API (e.g., SwiftBackup), then encrypting the exported files with OpenSSL as described in steps 4‑5.
  • Unlocking the bootloader and flashing a custom recovery (TWRP) to create a full NAND image – this provides the strongest protection but voids warranty and is beyond the no‑root scope.

Best‑practice checklist

  • Test the backup on a spare device before relying on it for critical data.
  • Store the encrypted backup in at least two separate locations (e.g., external drive + encrypted cloud).
  • Rotate the passphrase every 12‑18 months and re‑encrypt older backups.
  • Periodically verify that the encrypted file can still be decrypted (run the OpenSSL command without overwriting the original).

By following these steps you gain a portable, encrypted snapshot of your Android app data that can survive device loss, accidental wipes, or a switch to a new phone – all without ever rooting the device.

User Comments (0)

Add Comment
We'll never share your email with anyone else.