AI summary
Native Android tool to unlock, browse, read, and write Microsoft BitLocker encrypted drives via USB OTG. Supports NTFS, exFAT, and FAT32 with full CRUD operations. Offers dual-mode architecture: non-root via Android USB Host API and SAF integration, or rooted with FUSE global mount and faster kernel block access.
Generated by AI. May contain inaccuracies.
About this app
A native Android application to unlock, browse, read, and write Microsoft BitLocker encrypted drives (NTFS, FAT32, exFAT) on mobile devices.
BitLockerDroid (application display name BitUnlocker) is an Android application designed to access and manage Microsoft BitLocker encrypted drives on mobile devices. It enables unlocking, browsing, reading, and writing to external storage media (USB OTG flash drives, external HDDs/SSDs, and SD cards).
Filesystem Support: Full CRUD operations (browse, create, modify, rename, delete) on NTFS, exFAT, and FAT32 partitions. Authentication Credentials: Supports user passwords (PBKDF2/SHA-256) and 48-digit numerical recovery keys. System Integration: Integrated with the Android Storage Access Framework (SAF DocumentsProvider) for file management directly within the system "Files" app. Global POSIX Virtual Mount (Root): Leverages FUSE to mount decrypted volumes to /storage/XXXX-XXXX, enabling third-party apps to access files via standard Linux absolute paths. Dual Operation Modes: Supports both Non-Root (Android USB Host API) and Root (direct kernel block device access) underlying architectures.
Dual-Mode Architecture The application provides two distinct driver architectures, seamlessly switchable in Settings (dirty data is flushed and active sessions are cleanly unmounted before switching):
Dimension Non-Root Mode (USB Host API) Root Mode (KernelSU / Magisk / APatch) Privilege Requirement USB device permission only; no Root required Root permission (su) Device Support USB OTG external storage devices USB OTG devices, multi-partition disks, kernel block nodes I/O Channel Android USB Host API + user-space SCSI driver Linux kernel block device nodes (/dev/block/vold/*) Read Throughput Sequential read ~35 to 50 MB/s Sequential read up to 140+ MB/s Mount Form SAF DocumentsProvider (system Files app) SAF DocumentsProvider + Global FUSE (/storage/XXXX-XXXX) Dirty Repair & Diagnostics Read-only structural diagnostics & clean unmount 1-Click Dirty Bit reset & deep structural integrity diagnostics System False Alerts Notification listener suppresses system format prompts Privileged suppression of false format notifications
Key Features ARMv8 CE Hardware Cryptography Acceleration: Harnesses ARMv8-A Cryptography Extensions (PMULL, AES, SHA2) for native hardware execution of AES-XTS, AES-CBC, and PBKDF2 SHA-256 key stretching (accelerating volume unlock by 4.75x, down to ~104 ms). Includes automatic runtime CPU capability detection (getauxval(AT_HWCAP)), vector self-tests, and graceful software fallback. Double-Buffered Asynchronous Write Pipeline: Decouples SAF document streaming from underlying USB Mass Storage protocol transfer via background ring buffering, improving continuous write throughput by up to 39.5% and reducing 4K random write latency. 16 KB Page Alignment (Android 15+): Fully conforms to the Google Android 15+ 16 KB ELF page size standard — useLegacyPackaging = false plus an explicit -Wl,-z,max-page-size=16384 link option on every native CMake target (the ANDROID_SUPPORT_FLEXIBLE_PAGE_SIZES CMake flag is a no-op under the pinned NDK r26d). Ensures maximum virtual memory mapping efficiency and future-proof compatibility. Transparent Filesystem Read/Write: Custom optimized libntfs-3g (with sector write barriers protecting -FVE-FS- metadata), exFAT driver (supporting files >4GB), and FatFs (full Long File Name / LFN support). Delivers complete CRUD operations and native system search integration. Accurate Multi-Partition Scanning: Analyzes hardware topology to distinguish parent disk devices from partition nodes, preventing duplicate drive listings and supporting concurrent auto-unlocking. Dirty Volume Repair & Structural Diagnostics: 1-Click Dirty Bit Reset: Instantly resets unclean unmount flags across NTFS, FAT32, and exFAT partitions caused by hot-unplugging, restoring full read/write access without requiring a PC. Deep Structural Integrity Diagnostics: Sub-50ms non-destructive metadata integrity scan covering NTFS (MFT USN/Fixup torn-write validation, $MFTMirr consistency, $INDEX_ROOT B-Tree index), FAT32 (Sector 0 vs Sector 6 backup boot sector, FSInfo signature, FAT1 vs FAT2 consistency, directory loop detection), and exFAT (Microsoft-compliant 11-sector cyclic redundancy boot checksum, Sector 12 backup comparison, MediaFailure hardware flag, root directory stream parsing). Pre-Flight Safety Barrier: Automatically validates volume health prior to dirty bit reset. Displays high-risk warning banners and prevents accidental writes if true structural corruption is detected. Data Safety & Eject Protection: Hardware-level read-only protection toggle intercepts all write operations at driver level. Safe eject forces two-level cache flush and clears filesystem Dirty Bits to prevent Windows from prompting "Scan and fix drive". Warns on unclean unmounted volumes. Global POSIX Virtual Mount: In Root mode, injects a FUSE mount into the PID 1 mount namespace (/storage/XXXX-XXXX), enabling direct access via standard Linux paths in MT Manager, Termux, media players, and terminal utilities. Non-Destructive Drive Benchmark: Built-in read-only benchmark tool to measure sequential read throughput (MB/s), 4K random read latency (IOPS), and negotiated USB bus speed (USB 2.0 / USB 3.0 5Gbps / USB 3.1+ 10Gbps). Biometric Credential Vault: Safeguards BitLocker passwords and recovery keys using Android Keystore hardware-backed encryption. Features an independent toggle in Settings, requiring biometric (fingerprint/face) or lockscreen credentials to inspect saved credentials. Dynamically enforces window FLAG_SECURE to prevent sensitive key leakage in screenshots, screen recordings, or recent apps overview. Metadata Backup & Image Export: Precise FVE Metadata Backup & Emergency Restore (.fvemeta): Extracts Sector 0 (VBR) and all three 64KB FVE metadata blocks into an integrity-verified container (SHA-256 and CRC-32). Allows emergency low-level sector writeback if volume headers become corrupted. Strict Capacity Safety Barrier: During metadata restoration, the engine strictly compares the physical partition capacity and sector size against the backup header. If any mismatch is detected, writes are unconditionally blocked to protect other drives and partitions. Dual-Mode Volume Dump Service: Streams either a decrypted virtual volume image (.img) directly mountable on PC without BitLocker, or a raw encrypted block partition (.raw) for forensic backup. Equipped with an Android Foreground Service (dataSync), partial WakeLock, real-time throughput monitoring (MB/s), ETA calculation, and clean cancellation. LAN Wireless Sharing (Dual Web & WebDAV Protocols): Zero-Client Native OS Mounting: Fully compliant WebDAV server allows Windows ("Map Network Drive"), macOS Finder ("Connect to Server"), and iOS/iPadOS "Files" to mount the decrypted volume directly as a network disk with fast read/write throughput. Modern Responsive Web Portal: Automatically hosts an adaptive light/dark web interface with QR code quick access, folder hierarchy navigation, multi-threaded resume (HTTP 206 Partial Content), inline multimedia streaming, and drag-and-drop batch file uploads. Granular Security & Lifecycle Guard: Configurable custom port, read-only tamper protection, and HTTP Basic authentication; protected by Android Foreground Service (dataSync), High-Performance Wi-Fi Lock, and CPU WakeLock, with automatic cleanup on drive detachment or unexpected unmount. Native Unencrypted Volume Coexistence: Intelligently identifies unencrypted USB flash drives (FAT32, exFAT, NTFS), relinquishing USB Host exclusivity to Android OS in non-root mode to prevent redundant permission prompts; clearly displays volume status and disk usage with 1-click navigation to system file managers. False Alert Filter: Automatically filters Android system notifications falsely claiming the encrypted drive is corrupted or needs formatting.
License
GPL-2.0
About this version
- Version
- 1.0.5 (71)
- Size
- 29.82 MB
- Requires Android
- 13
- Target SDK
- 33
- Architecture
- arm64-v8a, armeabi-v7a, x86_64
- Downloads
- 16
- Updated
- Oct 3, 2026
- Package
- com.bitlockerdroid
Similar apps
Ratings & reviews
- 50
- 40
- 30
- 20
- 10