MuntashirAkon/AppManager · error · IOException
Unsupported encryption method: " + encryptionName
Error message
Unsupported encryption method: " + encryptionName
What it means
IOException from AndroidBackupHeader.decodeAesHeaderAndInitialize: the encryption algorithm name in the backup header does not match the supported AES-256/CBC algorithm name (ENCRYPTION_ALGORITHM_NAME), so decryption cannot proceed.
Solutions
- Re-create the backup using standard adb backup (AES-256 encryption) or no encryption
- Compare the header's encryption line against the expected algorithm name to identify the producer
- Use the original tool that encrypted the backup to decrypt it first, then feed plaintext to the extractor
- Check for header line misalignment caused by earlier corruption
Example fix
// before // header line: AES-128-CBC-1.2 (from a non-standard tool) -> throws InputStream tar = header.toTar(); // after (decrypt externally with the original tool first) InputStream plain = thirdPartyToolDecrypt(abFile, password); InputStream tar = new AndroidBackupHeader(plain, null).toTar();
Defensive patterns
Strategy: validation
Validate before calling
String encLine = readHeaderLine(abFile, 3); // encryption algorithm line
if (!"AES-256-CBC-1.2".equals(encLine) && !"none".equals(encLine)) {
throw new IOException("Unsupported backup encryption: " + encLine);
} Try / catch
try {
InputStream tar = header.toTar();
} catch (IOException e) {
if (e.getMessage().startsWith("Unsupported encryption method")) {
Log.e(TAG, "Backup encrypted with a non-standard algorithm; decrypt with the original tool", e);
} else throw e;
} Prevention
- Create backups with standard adb (AES-256) or unencrypted
- Log the header encryption line when debugging restores
- Decrypt third-party-encrypted backups before using this extractor
- Check the actual (exact) algorithm name, not just 'encrypted'
When it happens
Trigger: The header's encryption line (line 4) contains a value other than the supported constant — typically "none" mismarked, or a cipher name from a different backup tool; occurs when the header says encrypted but with an unrecognized algorithm.
Common situations: Backups produced by modified adb implementations or third-party tools with custom encryption; corrupted header line shifting values; spoofed/hand-edited headers.
Related errors
- Archive is encrypted but no password given
- Checksums for master key did not match.
- Couldn't delete old file
- Couldn't get misc.am.tsv for generating checksum
- Failed to decrypt
AI-assisted analysis of MuntashirAkon/AppManager@0152f468fc (2026-09-12).
Data as JSON: /api/errors/9a1ac056c1e5053e.
Report an issue: GitHub.
Appendix: source
Thrown at app/src/main/java/io/github/muntashirakon/AppManager/backup/adb/AndroidBackupHeader.java:237
mkOut.writeByte(mk.length);
mkOut.write(mk);
mkOut.writeByte(checksum.length);
mkOut.write(checksum);
mkOut.flush();
byte[] encryptedMk = mkC.doFinal(blob.toByteArray());
headerbuf.append(byteArrayToHex(encryptedMk));
headerbuf.append('\n');
return finalOutput;
}
@NonNull
private static InputStream decodeAesHeaderAndInitialize(char[] decryptPassword,
@NonNull String encryptionName,
boolean pbkdf2Fallback,
@NonNull InputStream rawInStream) throws Exception {
if (!encryptionName.equals(ENCRYPTION_ALGORITHM_NAME)) {
throw new IOException("Unsupported encryption method: " + encryptionName);
}
String userSaltHex = readHeaderLine(rawInStream); // 5
byte[] userSalt = hexToByteArray(userSaltHex);
String ckSaltHex = readHeaderLine(rawInStream); // 6
byte[] ckSalt = hexToByteArray(ckSaltHex);
int rounds = Integer.parseInt(readHeaderLine(rawInStream)); // 7
String userIvHex = readHeaderLine(rawInStream); // 8
String encryptionKeyBlobHex = readHeaderLine(rawInStream); // 9
// decrypt the encryption key blob
try {
return attemptEncryptionKeyDecryption(decryptPassword, PBKDF_CURRENT, userSalt,
ckSalt, rounds, userIvHex, encryptionKeyBlobHex, rawInStream);
} catch (Exception e) {View on GitHub (pinned to 0152f468fc)