We are committed to providing fast, efficient, and affordable software solutions that set new standards in the software development industry.
  • R-Drive Image Home Page
  • R-Drive Image Technical Documentation

BitLocker Drive Encryption


BitLocker Drive Encryption , or BitLocker , is a data protection feature introduced by Microsoft since Windows Vista. It implements some hard/software measures to encrypt either USB external flash drives or internal system SSD/HDD devices. You may read more about BitLocker Drive Encryption on the Microsoft site or Wikipedia .

 

There are following encryption methods (protectors in the Microsoft terms) that can be utilized in the BitLocker protection:

A TPM/TPM+PIN chip

A USB key (a flash drive containing a .bek file)

A user's password (not to confuse with a user's logon password) / recovery key

These methods can be used either individually or as a combination thereof. If they are used as a combination, knowing the decryption information for only one method is enough to unlock the device.

 

R‑Drive Image can unlock devices encrypted with BitLocker provided that all the necessary information is known.

 

Important: When you backup a BitLocker container already unlocked by the system, it will be backed up unlocked. If the container isn't unlocked by the system, R‑Drive Image will backup it locked, or will ask for its password/key to unlock the volume.

BitLocker ToGo and BitLocker-Encrypted Non-System Disks

This is the method used to lock external removable devices and non-system disks. The password or a recovery key is necessary to know to unlock the device. A recovery key may be in the printed form or contained in a file. A name of such a file has the following pattern: BitLocker Recovery Key 600397A9-48AA-4DE4-B775-C71EB130EA1B.txt , where the last characters is the BitLocker container identifier. That file contains the BitLocker container identifier and a recovery key.

 

When R‑Drive Image backups a locked BitLocker container,

Click to enlarge

Locked BitLocker ToGo volume

it creates the image with locked BitLocker container

Click to enlarge

BitLocker ToGo volume's password/key

If the BitLocker container is already unlocked, by the system or R‑Drive Image ,

Click to enlarge

Locked BitLocker ToGo volume

the image will contain the unlocked partition.

Click to enlarge

Image with unlocked BitLocker ToGo container

Restoring data from an image with a BitLocker container

When restoring data from images with BitLocker containers, R‑Drive Image renders the following results.

Target BitLocker container

Source (Image with BitLocker container)

Result

Unlocked

Unlocked

Unlocked

Unlocked

Locked

Locked

Locked

Unlocked

Unlocked

Locked

Locked

Locked

R‑Drive Image can unlock a locked container or image by itself

Double-click the locked BitLocker container and enter its password or recovery key.

Click to enlarge

BitLocker ToGo volume's password/key

Please note that R‑Drive Image unlocks BitLocker containers/images only for itself. They remain locked for the system.

BitLocker System Drive Encryption

This is the method used to lock internal system drives.

Depending on what methods are used, the following information is necessary to know to unlock the drive.

A recovery key in the printed form or in a file. A name of such a file has the following pattern: BitLocker Recovery Key FDA7B96C-635E-45AA-BE63-00C3DB3771EE.txt , where the last characters is the BitLocker container identifier. That file contains the BitLocker container identifier and a recovery key.

A password used to start the preboot process. It shouldn't be confused with the password for the user's logon.

 

R‑Drive Image always shows the system partition (usually Disc C:) unlocked.

 

Click to enlarge

BitLocker System Drive Encryption

 

and creates images with the unlocked (unencrypted) BitLocker r container.

Click to enlarge

BitLocker System Drive Encryption

Use the startup version to create an image with a locked BitLocker container with a system disk. It increases data security but makes image recovery on another computer harder or even not possible.

Data recovery to a system disk is possible on when the startup version is used.