Create an Encrypted Android Backup with ADB, Verify, and Cloud‑Store

17 min read Learn a step‑by‑step method to back up your Android device with ADB, encrypt the backup file, verify its integrity, and upload it to a cloud service for long‑term safety. September 28, 2026 07:00 How to Create an Encrypted Android Backup with ADB, Verify It, and Store It Safely in the Cloud

Backing up an Android phone without rooting can feel risky because the built‑in backup options are often tied to Google services. Using adb you can create a local .ab backup, encrypt it yourself, verify that the file is intact, and then store it in a cloud drive you control. This tutorial walks you through every step, explains why each action matters, and gives troubleshooting tips for the most common hiccups.

Before you start

  • PC requirements: Windows 10/11, macOS 10.15+, or a recent Linux distro with adb and openssl installed.
  • Device requirements: Android 6.0 (Marshmallow) or newer, USB debugging enabled, and at least 1 GB of free internal storage for the temporary .ab file.
  • Power & connectivity: Keep the phone charged (or plugged in) and use a reliable USB‑C or micro‑USB cable. A stable Wi‑Fi connection is needed for the final cloud upload.
  • Backup password: Choose a strong passphrase (12+ characters, mixed case, numbers, symbols). You will need it to encrypt and later decrypt the backup.
If you have never used adb before, the Platform‑Tools package can be downloaded from the official Android developer site.

Step 1 – Install and verify ADB and OpenSSL on your computer

  1. Download the Android SDK Platform‑Tools zip for your OS and extract it to a folder you can access (e.g., C:\adb or ~/adb).
  2. Open a terminal (Command Prompt, PowerShell, Terminal, or your favorite shell) and navigate to that folder.
  3. Run adb version. You should see something like Android Debug Bridge version 1.0.41. If the command is not recognized, add the folder to your system PATH.
    • Windows: setx PATH "%PATH%;C:\adb" then restart the terminal.
    • macOS / Linux: add export PATH=$PATH:~/adb to ~/.bash_profile or ~/.zshrc.
  4. Check OpenSSL: openssl version. Most modern OSes ship with OpenSSL already; if missing, install it via your package manager (e.g., brew install openssl on macOS or sudo apt install openssl on Ubuntu).

Step 2 – Enable USB debugging and allow the computer

  1. On the phone, open Settings → About phone → tap Build number seven times to unlock Developer options.
  2. Return to Settings → System → Developer options → toggle USB debugging on.
  3. Connect the phone to the PC with the USB cable. When prompted on the device, tap Allow for the RSA key fingerprint. Optionally tick “Always allow from this computer” to avoid repeated prompts.
  4. Verify the connection: run adb devices. You should see a line like RZ8M5C7L device. If the state shows unauthorized, re‑check the prompt on the phone.

Step 3 – Create a full backup file with ADB

  1. Decide where to store the temporary backup. For this tutorial we use the desktop folder: ~/Desktop (macOS/Linux) or C:\Users\YourName\Desktop (Windows).
  2. Run the following command, replacing backup.ab with your desired filename:
    adb backup -apk -shared -all -f "backup.ab"
    • -apk includes the APK files of installed apps.
    • -shared backs up files on the shared storage (photos, downloads, etc.).
    • -all backs up all user apps and their data.
    • -f specifies the output file.
  3. On the phone, a dialog titled “Full backup” will appear. It asks for a password – this password protects the .ab file. Enter the strong passphrase you prepared earlier. You may also leave it blank, but then the file is stored unencrypted on the PC, which defeats the purpose of this guide.
  4. Tap Back up my data. The process can take several minutes depending on the amount of data. You will see a progress bar on the phone and a growing file size on the PC.
  5. When the backup finishes, the phone will display a “Backup completed” toast. Verify the file size – it should be several hundred megabytes for a typical device.

Step 4 – Convert the .ab file to a standard archive (optional but recommended)

The .ab format is a proprietary Android wrapper. Converting it to a .tar archive makes inspection and selective restoration easier.

  1. Download the abe.jar utility from the open‑source Android Backup Extractor project. Place abe.jar in the same folder as your backup.
  2. Run the conversion (replace backup.ab and backup.tar as needed):
    java -jar abe.jar unpack backup.ab backup.tar
    You will be asked for the same password you used in Step 3. Enter it.
  3. After the command finishes, you will have backup.tar. You can list its contents with tar -tf backup.tar to confirm the extraction succeeded.

Step 5 – Encrypt the archive with OpenSSL

We will use AES‑256‑CBC encryption, which is widely supported and provides strong confidentiality.

  1. Open a terminal in the folder containing backup.tar.
  2. Run the following command (replace encrypted_backup.bin with your preferred name):
    openssl enc -aes-256-cbc -salt -in backup.tar -out encrypted_backup.bin -pbkdf2
    • -aes-256-cbc selects the cipher.
    • -salt adds a random salt to thwart dictionary attacks.
    • -pbkdf2 uses the modern PBKDF2 key‑derivation function.
  3. OpenSSL will prompt for a password. Enter the same passphrase you used for the ADB backup. Using the same password simplifies later decryption, but you may choose a different one if you prefer.
  4. When the command completes, verify the encrypted file size – it should be roughly the same as the original backup.tar plus a small overhead.

Step 6 – Verify the encrypted backup’s integrity

It is good practice to generate a checksum before you upload the file. If the cloud copy gets corrupted, you can detect it immediately.

  1. Generate a SHA‑256 hash of the encrypted file:
    openssl dgst -sha256 encrypted_backup.bin
    The output will look like SHA256(encrypted_backup.bin)= a3f5…. Copy the hash string and store it in a secure note (e.g., a password manager).
  2. After the upload (next step), you can download the file back to a temporary location and run the same command to compare hashes.

Step 7 – Upload the encrypted backup to a cloud storage service

Any service that supports file uploads (Google Drive, Dropbox, OneDrive, pCloud, etc.) works. The key point is that the file is already encrypted, so the cloud provider never sees the raw data.

  1. Open your preferred cloud client or web UI.
  2. Create a folder named AndroidBackups (or similar) to keep things organized.
  3. Drag‑and‑drop encrypted_backup.bin into that folder.
  4. Wait for the upload to finish. Most services display a progress bar and a final “Upload complete” message.
  5. Once uploaded, right‑click the file and select “Copy link” (or “Get shareable link”). Store the link in a secure place – you will need it for future restores.

Step 8 – Clean up local temporary files

After you have confirmed the upload succeeded, you can delete the unencrypted backup.tar and the plain backup.ab files to reduce the risk of accidental exposure.

  1. On Windows: del backup.ab and del backup.tar.
  2. On macOS/Linux: rm backup.ab backup.tar.
  3. Keep encrypted_backup.bin only in the cloud (or on an encrypted external drive) unless you need a local copy for quick testing.

Troubleshooting common issues

ADB reports “device unauthorized”

  • Make sure you accepted the RSA fingerprint dialog on the phone. If you missed it, disconnect and reconnect the USB cable.
  • On some OEM skins (e.g., Samsung One UI), the dialog appears under Settings → Biometric and security → Other security settings → USB debugging → Allow USB debugging.
  • Revoke all USB debugging authorizations (Settings → Developer options → Revoke USB debugging authorizations) and try again.

Backup stops halfway or reports “insufficient space”

  • Check the free space on the PC’s destination drive. The temporary .ab file needs roughly the same size as the data on the phone.
  • If the phone’s internal storage is low, consider freeing up space or using the -nosystem flag to exclude system apps (they are not usually needed for personal restores).
  • For very large media libraries, you can omit -shared and back up only app data, then copy photos separately via adb pull /sdcard/DCIM.

OpenSSL says “bad decrypt” when encrypting or decrypting

  • Make sure you typed the password exactly the same as during the ADB backup step. Passwords are case‑sensitive.
  • If you used a different password for encryption, remember it – you will need the exact same string to decrypt later.
  • Check that the input file (backup.tar) is not corrupted. Re‑run the tar -tf backup.tar command to list its contents.

Restoring the backup later fails with “cannot parse backup”

  • Confirm you are using the same version of abe.jar that matches the Android version you backed up from. Newer Android releases may add features that older extractors don’t understand.
  • If the .ab file was encrypted twice (e.g., you ran OpenSSL on the original .ab instead of the .tar), you need to decrypt it twice before feeding it to abe.jar.
  • As a last resort, you can try the built‑in adb restore command directly on the encrypted .ab (after decrypting it back to its original form).

Restoring the encrypted backup (quick reference)

  1. Download encrypted_backup.bin from the cloud to a trusted PC.
  2. Decrypt it:
    openssl enc -d -aes-256-cbc -in encrypted_backup.bin -out backup.tar -pbkdf2
    Enter the encryption password when prompted.
  3. If you kept the original .ab file, skip the next step. Otherwise, re‑package the .tar back into .ab using abe.jar pack:
    java -jar abe.jar pack backup.tar backup.ab
  4. Connect the target Android device, enable USB debugging, and run:
    adb restore backup.ab
    Confirm the restore dialog on the phone and enter the original backup password.

Why this workflow is safer than the default Google backup

  • Full control of encryption keys: Only you know the passphrase; Google never sees the raw data.
  • Portability: The .ab/.tar pair can be restored on any Android device, regardless of the Google account attached.
  • Selective restoration: By extracting the .tar you can pick individual app data folders or media files without reinstalling every app.
  • Auditability: The checksum step guarantees that what you uploaded is exactly what you created.

Final checklist

  • ✅ USB debugging enabled and device authorized.
  • ✅ Strong backup password chosen.
  • ✅ adb backup completed without errors.
  • ✅ abe.jar successfully unpacked the .ab file.
  • ✅ Encrypted file created with OpenSSL.
  • ✅ SHA‑256 hash recorded and verified after upload.
  • ✅ Unencrypted temporary files securely deleted.

With these steps you now have a reliable, encrypted snapshot of your Android device that lives safely in the cloud and can be restored whenever you need it – all without rooting or installing third‑party backup apps.

User Comments (0)

Add Comment
We'll never share your email with anyone else.