fscrypt

Introduction

fscrypt is a tool built directly into the Linux kernel that encrypts individual files and directories instead of the entire hard drive. It transparently scrambles the contents and names of your files when they are saved to disk and unscrambles them when you open them, using a secure key that you provide.

Why use fscrypt

How it Works

File-Level vs. Full Disk Encryption

The Key Management System

fscrypt uses a hierarchy of keys to keep your data safe without slowing down your computer.

The Encryption Process (Reading and Writing)

Runtime Encryption

When you unlock an encrypted folder, you are only handing the decryption key to the Linux kernel. The actual data resting on your hard drive remains scrambled 100% of the time.

Handling Heavy Data

Here is what happens under the hood when you transfer a massive amount of data into an unlocked fscrypt folder

Block-by-Block Processing

The "Page Cache" Buffer

Hardware Acceleration

Bottleneck

What Gets Encrypted

Encrypted

NOT Encrypted (visible to anyone with disk access)

Security Model & Limitations

What It Protects Against

What It Does NOT Protect Against

Full Process Diagram

graph TD
    %% Define styles
    classDef user fill:#e1f5fe,stroke:#01579b,stroke-width:2px;
    classDef meta fill:#fff3e0,stroke:#e65100,stroke-width:2px;
    classDef system fill:#e8f5e9,stroke:#1b5e20,stroke-width:2px;

    %% Nodes
    Input["Your Passphrase or Raw Key"]:::user
    
    Protector["Protector
(The Lockbox)"]:::meta subgraph Policy ["Policy (The Rulebook)"] TrueKey["Master Encryption Key
(The True Key)"]:::meta Rules["Encryption Algorithm Rules"]:::meta end Kernel["Linux Kernel Memory"]:::system Files["Encrypted Files & Directory"]:::system %% Connections Input -->|Step 1: Unlocks| Protector Protector -->|Step 2: Unwraps| TrueKey TrueKey -.->|Step 3: Loaded into| Kernel Policy -->|Step 4: Assigned to| Files Kernel ===>|Step 5: On-the-fly Decryption| Files