Create a Secure Encrypted ADB Backup on Android (No Root)
18 min read
Step‑by‑step guide to back up your Android apps and data with ADB, then encrypt the backup using OpenSSL for safe offline storage.
October 08, 2026 22:30
When you need a reliable snapshot of your Android phone – for travel, a device upgrade, or peace of mind – the built‑in ADB backup command is a handy tool. However, the raw .ab file is stored in clear text on your computer, which poses a privacy risk if the storage medium is ever compromised. This tutorial shows you how to create a full ADB backup, encrypt it with OpenSSL (AES‑256‑CBC), verify the result, and restore it later – all without rooting the device.
Before you start
- Computer requirements: Windows, macOS, or Linux with
adb and openssl installed.
- Phone requirements: Android 4.4 (KitKat) or newer, USB debugging enabled, and enough free storage for the backup (usually 1‑2× the used space on the device).
- Backup destination: An external drive or a folder that is not synced to the cloud, unless you plan to encrypt the file before uploading.
- Safety note: The backup will contain app data, which may include personal messages, credentials, or cached files. Treat the encrypted archive like a password manager – keep the decryption password safe and never share it.
Tip: If you already have adb from Android Studio, you can skip the platform‑tools download step.
1. Install the required tools
- Download the Android SDK Platform‑Tools package for your OS from the official Android developer site.
- Windows: unzip to
C:\adb and add that folder to PATH.
- macOS/Linux: extract to
~/adb and add export PATH=~/adb:$PATH to your shell profile.
- Verify the installation by opening a terminal (or Command Prompt) and typing:
adb version
You should see something like Android Debug Bridge version 1.0.41.
- Install OpenSSL if it is not already present.
- Windows: download the Win64 installer and follow the wizard.
- macOS:
brew install openssl (Homebrew required).
- Linux:
sudo apt-get install openssl (Debian/Ubuntu) or the equivalent for your distro.
2. Enable USB debugging on your Android device
- Open Settings → About phone.
- Scroll to Build number and tap it seven times. You will see a toast saying “You are now a developer!”.
- Return to the main Settings screen, then go to System → Developer options (the path may differ on Samsung, Xiaomi, etc.).
- Toggle USB debugging on.
- If a prompt appears, confirm the computer’s RSA fingerprint by tapping Allow.
Warning: Leaving USB debugging on all the time can expose your device to malicious USB attacks. Turn it off after you finish the backup if you do not need it regularly.
3. Create an unencrypted ADB backup
The adb backup command can back up apps, app data, and (optionally) the system settings. We will first generate an unencrypted .ab file, then encrypt it ourselves – this gives us full control over the encryption algorithm and password handling.
- Connect the phone to the computer via a USB cable. Verify the connection:
adb devices
You should see a line like xxxxxxxxxxxx device. If you see unauthorized, check the phone for the RSA prompt.
- Decide what you want to back up. The most common options are:
-apk – include the APK files of installed apps (useful for reinstall without Play Store).
-shared – back up the internal shared storage (photos, downloads, etc.).
-all – back up all user apps and their data.
- Run the backup command. Example that backs up everything except system apps:
adb backup -apk -shared -all -f ~/android_backup_unencrypted.ab
- Replace
~/ with an appropriate folder on Windows, e.g., C:\backups\.
- When the phone displays the “Full backup mode” screen, you can optionally set a password for the ADB backup itself. Leave it blank – we will encrypt later.
- Wait for the process to finish. A progress bar appears on the phone; on the computer you will see the command return to the prompt.
- The time required depends on the amount of data. Expect 5‑30 minutes for a typical user device.
Note: Some OEMs (e.g., Huawei, Xiaomi) disable the ADB backup feature on newer Android versions. If the command returns “Backup failed: device not authorized”, check the manufacturer’s developer options or consider using a custom recovery for a full image.
4. Encrypt the backup with OpenSSL
OpenSSL provides strong, battle‑tested encryption. We will use AES‑256‑CBC with a passphrase‑derived key and a random salt.
- Open a terminal in the folder containing
android_backup_unencrypted.ab.
- Run the following command, replacing
myStrongPassword with a password you can remember but that is not easy to guess:
openssl enc -aes-256-cbc -salt -in android_backup_unencrypted.ab -out android_backup_encrypted.ab -pbkdf2
- The
-pbkdf2 flag tells OpenSSL to use PBKDF2 (Password‑Based Key Derivation Function 2) with 10 000 iterations, which makes brute‑force attacks harder.
- You will be prompted twice for the password – once for encryption and once for verification.
- After the command finishes, verify that the encrypted file exists and is larger than the original (the salt and padding add a few bytes).
ls -lh android_backup_*.ab
- Securely delete the unencrypted file to avoid accidental exposure. On macOS/Linux use
shred or srm; on Windows use sdelete:
shred -u android_backup_unencrypted.ab
- If you do not have these utilities, a simple overwrite with random data followed by deletion is better than nothing.
Warning: If you lose the encryption password, the backup is unrecoverable. Store the password in a reputable password manager or write it down in a secure location.
5. Verify the encrypted backup
Before you consider the job done, test that the archive can be decrypted and restored on a test device or emulator.
- Decrypt the file to a temporary location (do not overwrite the original encrypted file):
openssl enc -d -aes-256-cbc -in android_backup_encrypted.ab -out test_decrypted.ab -pbkdf2
You will be asked for the password you used in step 4.
- Check that the decrypted file is a valid ADB backup by inspecting its header:
head -c 12 test_decrypted.ab
The output should start with ANDROID BACKUP.
- If the header looks correct, you can optionally restore it to a secondary device (or the same device after a factory reset) using:
adb restore test_decrypted.ab
Follow the on‑screen prompts on the phone. After a successful restore, verify that apps and data are present.
- After verification, securely delete the temporary
test_decrypted.ab file.
6. Restoring an encrypted backup
When you need to bring the data back, the process is the reverse of encryption.
- Connect the target device and enable USB debugging as described in section 2.
- Decrypt the archive on your computer:
openssl enc -d -aes-256-cbc -in android_backup_encrypted.ab -out android_backup_to_restore.ab -pbkdf2
- Initiate the restore:
adb restore android_backup_to_restore.ab
The phone will show a “Full restore mode” screen. Tap Restore.
- Wait for the operation to finish. A progress bar appears on the device; the terminal returns to the prompt when done.
- After the restore, reboot the phone and check that apps launch correctly and that personal files (photos, messages) are present.
7. Troubleshooting common issues
7.1 ADB reports “Backup failed: device not authorized”
- Ensure the RSA fingerprint dialog on the phone was accepted.
- On some devices, you must toggle USB debugging (Security settings) in Developer options.
- Try a different USB cable or USB‑C port; cheap cables sometimes lack data lines.
7.2 Backup stops abruptly with “Error: device offline”
- Run
adb kill-server then adb start-server and reconnect the phone.
- On Windows, disable any USB selective suspend power‑saving options.
7.3 Encrypted file cannot be decrypted (wrong password error)
- Double‑check that you used the same OpenSSL command line (including
-pbkdf2).
- Copy‑paste the password to avoid typing mistakes; watch out for trailing spaces.
7.4 Restored apps refuse to start (crash on launch)
- Some apps encrypt their own data with a device‑specific key; after a restore to a different device they may appear corrupted. In such cases, reinstall the app from Play Store and let it recreate its internal data.
- Clear the app’s cache via Settings → Apps → App name → Storage → Clear cache, then retry.
8. Edge cases and manufacturer quirks
While the ADB backup command works on most stock Android builds, a few manufacturers have disabled it for security or privacy reasons.
- Huawei / Honor (EMUI 10+): The backup service is hidden. You can re‑enable it via
adb shell settings put global adb_enabled 1 only on devices with an unlocked bootloader.
- Samsung (One UI 3+): The command works, but
-shared may skip the DCIM folder. Manually copy photos after the backup if needed.
- Pixel devices on Android 12+: System apps are excluded by default. Use
-system flag if you truly need them, but be aware that restoring system apps may require a factory reset.
If the built‑in backup is blocked, the alternative is to flash a custom recovery (e.g., TWRP) and create a NANDroid image, but that requires an unlocked bootloader and is outside the scope of this no‑root guide.
9. Security best practices for encrypted backups
- Use a strong, unique password. Aim for at least 12 characters with mixed case, numbers, and symbols.
- Store the password separately. A password manager (Bitwarden, KeePassXC) is ideal.
- Keep the encrypted file in an offline location. An external HDD that is not always connected reduces the attack surface.
- Periodically rotate the backup. Create a fresh backup every few months; encryption algorithms evolve, and older backups may become vulnerable.
- Verify integrity. After each backup, compute a SHA‑256 hash and store it alongside the encrypted file:
sha256sum android_backup_encrypted.ab > android_backup_encrypted.sha256
Later, you can verify the file has not been tampered with.
10. Frequently asked questions
- Can I back up apps that are installed from the Play Store? Yes – the
-apk flag includes the APK files, so you can reinstall them without internet. However, licensing data (e.g., in‑app purchases) is tied to your Google account and will be validated on first launch.
- Will the backup include WhatsApp messages? WhatsApp stores its chat database in
/sdcard/WhatsApp/Databases. Using -shared captures those files, but for a fully portable backup you should also use WhatsApp’s native export feature.
- Is AES‑256‑CBC still considered safe? Yes, when combined with a strong password and PBKDF2. For even higher assurance you could use
-aes-256-gcm (authenticated encryption) if your OpenSSL version supports it.
- Can I automate the backup with a script? Absolutely. A simple Bash or PowerShell script can call the ADB and OpenSSL commands, then copy the resulting
.ab file to a cloud folder (after encryption).
Wrap‑up
By following this tutorial you have created a portable, encrypted snapshot of your Android device that can survive loss, theft, or accidental re‑flashing. The workflow – raw ADB backup → OpenSSL encryption → secure storage – gives you full control over the cryptographic parameters and the location of the backup, something that built‑in cloud services cannot guarantee.
Remember: the strongest security chain is only as good as its weakest link. Keep your decryption password safe, store the encrypted file in a trusted place, and test the restore process at least once a year. With these habits, you’ll always have a reliable safety net for your Android data.