Microsoft Accelerates BitLocker: Windows 11 Encryption Shifts to Hardware Level

Microsoft Accelerates BitLocker: Windows 11 Encryption Shifts to Hardware Level

Arkadiy Andrienko

Microsoft has rolled out a significant update to the built-in BitLocker encryption system in current Windows 11 builds. The changes aim to solve a long-standing issue — the performance hit on storage drives when data protection is active. The update leverages hardware security modules (HSM) and trusted execution environments (TEE). These components, built into modern processors, take over the resource-intensive tasks of real-time data encryption and decryption.

This new approach can reduce central processor usage cycles in input/output operations by approximately 70% compared to the traditional software-based implementation, which is especially noticeable when working with fast NVMe drives. In the first phase, BitLocker hardware acceleration is only available for Intel vPro business platforms using Intel Core Ultra Series 3 processors, with Microsoft promising a gradual expansion of the list of supported systems.

Microsoft Accelerates BitLocker: Windows 11 Encryption Shifts to Hardware Level

Beyond performance, the update enhances the security level. Encryption keys are now stored and processed directly within the hardware modules, minimizing their vulnerability to potential attacks via memory or the central processor. This complements the existing protection based on the Trusted Platform Module (TPM).

It's important to note that the system will automatically revert to the software encryption method in several cases: if an unsupported algorithm is used, if a key size is manually specified, if corporate policies with incompatible settings are in effect, or if FIPS mode is enabled while the hardware module lacks the corresponding certification.

Microsoft Accelerates BitLocker: Windows 11 Encryption Shifts to Hardware Level

The introduction of hardware acceleration for BitLocker marks a gradual shift away from purely software-based cryptographic protection methods toward solutions tightly integrated with the hardware platform. This aligns with the general trend of enhancing both security and efficiency in modern computing systems without compromising user convenience.

    About the author
    Comments0