TECH ROUNDUP

Microsoft uses hardware to accelerate BitLocker speed.

Microsoft Dùng Phần Cứng Để Tăng Tốc Độ Cho Bitlocker

First introduced alongside the Windows Vista operating system in 2006, BitLocker has long been Microsoft‘s “in-house” solution for managing fully encrypted partitions and storage drives. Although it is a vital security tool, this technology has also been notorious for certain controversial issues regarding reliability, and particularly the decline in computer performance when activated. However, the Redmond software giant is currently working to resolve all these issues at once, with the prerequisite that users must be ready to upgrade to next-generation computer hardware.

Resolving the Bottleneck on High-Speed NVMe Drives

According to the latest information, Microsoft will soon begin the process of “accelerating” input/output (I/O) operations for BitLocker-encrypted drives on personal computer (PC) systems equipped with compatible hardware components. The company initially introduced this landmark change at the Ignite conference last month, and they have now provided further key technical details on how hardware-accelerated encryption will actually work in practice.

According to Rafal Sosnowski, an expert at Microsoft, hardware-accelerated BitLocker solutions are designed to bring significant improvements in both performance and security to encrypted setups. This technology is expected to thoroughly resolve issues arising with modern Non-Volatile Memory Express (NVMe) storage technology. Modern NVMe drives are capable of achieving much higher I/O performance levels than previous generations, which inadvertently creates significant pressure on legacy encryption systems.

https://www.youtube.com/watch?v=lVqg079JgrA

Specifically, a modern NVMe SSD can move massive amounts of data and files at extremely high speeds. As a result, BitLocker’s encryption algorithms are forced to demand a large number of CPU cycles to keep up with that speed. Mr. Sosnowski stated that, if not properly optimized, this additional performance cost could become a serious issue in specific applications. Computers will become sluggish because the CPU is busy processing encryption instead of running applications.

Microsoft has listed professional tasks such as video editing on large clip files, compiling massive source codebases for developers, and especially gaming as storage scenarios that could be heavily affected by this potential computational overhead. The hardware acceleration feature is expected to help BitLocker minimize the impact on performance by offloading most of the encryption activities from the main CPU to a dedicated “crypto engine” located within the System on a Chip (SoC). Furthermore, this feature will also protect encryption keys from prying eyes through an appropriate hardware encapsulation process.

Impressive Performance and Hardware Requirements

In terms of software implementation, the components of the BitLocker acceleration feature are already available in Windows 11, starting from the September 2025 update (version 24H2) and Windows 11 25H2. However, at the current time, this feature is only supported on Intel vPro systems based on the upcoming Core Ultra Series 3 processor lineup. Nevertheless, Microsoft is also considering expanding support to other processor vendors and platforms in the near future to popularize this technology.

Microsoft explained that by offloading encryption activities to a dedicated SoC component, BitLocker can achieve truly incredible performance improvements. A drive using hardware-accelerated BitLocker is expected to have speeds comparable to an NVMe drive that does not use BitLocker encryption. Meanwhile, the number of CPU cycles required to manage I/O is many times lower than traditional software-based encryption methods.

However, the company also noted that customers interested in using the hardware-accelerated encryption feature must comply with certain specific prerequisites. This feature will only work when drives are encrypted using the XTS-AES-256 algorithm. In the future, other algorithms supported by SoC vendors will also be added. Additionally, for enterprise environments, IT administrators can proactively customize or disable this feature through specific management policies to ensure compatibility with the organization’s infrastructure.

Share: 𝕏 P in
Question and answer (0 comments)

Table of contents
  1. Top