Categories: Software

Encrypted Future: Microsoft Revamps BitLocker for Speed

As Microsoft moves to enhance BitLocker encryption in Windows, the tech giant has announced hardware acceleration that promises to make the system significantly faster. Though these improvements are poised for future implementation, existing PCs won’t benefit immediately. Starting with the September update of Windows 11 24H2 in 2025 and following with the release of Windows 11 25H2, BitLocker will utilize enhancements in future SoCs and CPUs to improve performance and security for both current and future NVMe drives.

Created by Grok

Hardware-accelerated BitLocker encryption will be supported by processors debuting in 2026, requiring a dedicated cryptographic engine. This engine will handle AES-XTS-256 encryption processing, offloading tasks from the CPU’s main cores. Initially, the new feature will target Intel’s vPro platforms with upcoming Core Ultra Series 300 processors. However, Microsoft aims to expand support to additional manufacturers.

Key advancements include:

  • Cryptographic Offloading – BitLocker transfers core cryptographic operations from the main CPU to a dedicated cryptographic engine. This shift frees CPU resources for other tasks, enhancing both performance and battery life.
  • Hardware-Protected Keys – BitLocker’s bulk encryption keys are hardware-protected, assuming the necessary SoC support. This enhancement boosts security by reducing vulnerability to CPU and memory attacks. It’s an augmentation to the already supported Trusted Platform Module (TPM), safeguarding intermediate BitLocker keys, thereby avoiding the use of BitLocker keys in the CPU and memory entirely.

Performance data indicate that sequential read and write speeds are similar between software and hardware approaches. However, with random operations involving 4K block sizes, hardware acceleration shows significant improvement. In RND4K Q32T1 read-and-write tests, BitLocker hardware acceleration performs 2.3 times faster. For single-queue random read operations, hardware encryption is approximately 40% quicker, and for single-queue random write operations, about 2.1 times faster.

It’s noteworthy that last year, Microsoft enabled default BitLocker encryption for all Windows 11 versions, which adversely affected SSD performance. Remember, just yesterday we explained how to manually activate native NVMe support in Windows 11.

Casey Reed

Casey Reed writes about technology and software, exploring tools, trends, and innovations shaping the digital world.

Share
Published by
Casey Reed

Recent Posts

Laptops Juggle Prices: Memory Spikes and Market Squeezes

Analysts at TrendForce have updated their forecasts concerning the doubling of memory prices, now including…

2 hours ago

PC Price Surge Continues Amid Rising Component Costs

Prices in the PC market apparently show no signs of stopping. Known PC assembler PowerGPU…

2 hours ago

Google’s Operating System Shake-Up: Patience Required as Aluminium OS Wait Extends

Despite screenshots of the Aluminium OS operating system, which Google is developing for PCs, having…

3 hours ago

Minimalism Meets Functionality: ATK Yogo 75 Keyboard Hits Kickstarter

ATK Gear has launched a Kickstarter campaign for their ATK Yogo 75 keyboard. This mechanical…

3 hours ago

Ironic Charge: How the iPhone 17 Loosely Competes with Much Larger Batteries

Publication Cnet has published the comprehensive testing results of the batteries from 35 smartphone models.…

6 hours ago

Intel’s Arc B390: A Powerhouse iGPU Surpassing Old Giants

We've known that the iGPU Arc B390 from Intel is class-leading and capable of competing…

7 hours ago