Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Disk encryption software</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Disk_encryption_software"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Disk_encryption_software rootpage-Disk_encryption_software skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Disk encryption software</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1251242444">
/* start https://en.wikipedia.org/ */


.mw-parser-output .ambox{border:1px solid #a2a9b1;border-left:10px solid #36c;background-color:#fbfbfb;box-sizing:border-box}.mw-parser-output .ambox+link+.ambox,.mw-parser-output .ambox+link+style+.ambox,.mw-parser-output .ambox+link+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+style+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+link+.ambox{margin-top:-1px}html body.mediawiki .mw-parser-output .ambox.mbox-small-left{margin:4px 1em 4px 0;overflow:hidden;width:238px;border-collapse:collapse;font-size:88%;line-height:1.25em}.mw-parser-output .ambox-speedy{border-left:10px solid #b32424;background-color:#fee7e6}.mw-parser-output .ambox-delete{border-left:10px solid #b32424}.mw-parser-output .ambox-content{border-left:10px solid #f28500}.mw-parser-output .ambox-style{border-left:10px solid #fc3}.mw-parser-output .ambox-move{border-left:10px solid #9932cc}.mw-parser-output .ambox-protection{border-left:10px solid #a2a9b1}.mw-parser-output .ambox .mbox-text{border:none;padding:0.25em 0.5em;width:100%}.mw-parser-output .ambox .mbox-image{border:none;padding:2px 0 2px 0.5em;text-align:center}.mw-parser-output .ambox .mbox-imageright{border:none;padding:2px 0.5em 2px 0;text-align:center}.mw-parser-output .ambox .mbox-empty-cell{border:none;padding:0;width:1px}.mw-parser-output .ambox .mbox-image-div{width:52px}@media(min-width:720px){.mw-parser-output .ambox{margin:0 10%}}@media print{body.ns-0 .mw-parser-output .ambox{display:none!important}}


/* end https://en.wikipedia.org/ */
</style>
<p><b>Disk encryption software</b> is a <a href="Computer_security" title="Computer security">computer security</a> software that protects the confidentiality of data stored on computer media (e.g., a <a href="Hard_disk_drive" title="Hard disk drive">hard disk</a>, <a href="Floppy_disk" title="Floppy disk">floppy disk</a>, or <a href="USB_flash_drive" title="USB flash drive">USB device</a>) by using <a href="Disk_encryption" title="Disk encryption">disk encryption</a>.
</p><p>Compared to access controls commonly enforced by an <a href="Operating_system" title="Operating system">operating system</a> (OS), encryption passively protects data confidentiality even when the OS is not active, for example, if data is read directly from the hardware or by a different OS. In addition, <a href="Crypto-shredding" title="Crypto-shredding">crypto-shredding</a> suppresses the need to erase the data at the end of the disk's lifecycle.
</p><p>Disk encryption generally refers to wholesale encryption that operates on an entire <a href="Volume_(computing)" title="Volume (computing)">volume</a> mostly transparently to the user, the system, and applications. This is generally distinguished from file-level encryption that operates by user invocation on a single file or group of files, and which requires the user to decide which specific files should be encrypted. Disk encryption usually includes all aspects of the disk, including directories, so that an adversary cannot determine content, name or size of any file. It is well suited to portable devices such as <a href="Laptop_computer" class="mw-redirect" title="Laptop computer">laptop computers</a> and <a href="Thumb_drive" class="mw-redirect" title="Thumb drive">thumb drives</a> which are particularly susceptible to being lost or stolen. If used properly, someone finding a lost device cannot penetrate actual data, or even know what files might be present.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Methods">Methods</h2></div>
<p>The disk's data is protected using <a href="Symmetric-key_algorithm" title="Symmetric-key algorithm">symmetric cryptography</a> with the key randomly generated when a disk's encryption is first established. This key is itself encrypted in some way using a password or pass-phrase known (ideally) only to the user. Thereafter, in order to access the disk's data, the user must supply the password to make the key available to the software. This must be done sometime after each operating system start-up before the encrypted data can be used.
</p><p>Done in software, <a href="Encryption" title="Encryption">encryption</a> typically operates at a level between all applications and most system programs and the low-level <a href="Device_driver" title="Device driver">device drivers</a> by "transparently" (from a user's point of view) encrypting data after it is produced by a program but before it is physically written to the disk. Conversely, it decrypts data immediately after being read but before it is presented to a program. Properly done, programs are unaware of these cryptographic operations.
</p><p>Some disk encryption software (e.g., <a href="TrueCrypt" title="TrueCrypt">TrueCrypt</a> or <a href="BestCrypt" title="BestCrypt">BestCrypt</a>) provide features that generally cannot be accomplished with <a href="Disk_encryption_hardware" class="mw-redirect" title="Disk encryption hardware">disk hardware encryption</a>: the ability to mount "container" files as encrypted logical disks with their own <a href="File_system" title="File system">file system</a>; and encrypted logical "inner" volumes which are secretly hidden within the free space of the more obvious "outer" volumes. Such strategies provide <a href="Plausible_deniability" title="Plausible deniability">plausible deniability</a>.
</p><p>Well-known examples of disk encryption software include, <a href="BitLocker_Drive_Encryption" class="mw-redirect" title="BitLocker Drive Encryption">BitLocker</a> for Windows; <a href="FileVault" title="FileVault">FileVault</a> for Apple OS/X; <a href="LUKS" class="mw-redirect" title="LUKS">LUKS</a> a standard free software mainly for <a href="Linux" title="Linux">Linux</a> and <a href="TrueCrypt" title="TrueCrypt">TrueCrypt</a>, a non-commercial freeware application, for Windows, OS/X and Linux.
</p>
<ul><li>A 2008 study found <a href="Data_remanence" title="Data remanence">data remanence</a> in <a href="Dynamic_random_access_memory" class="mw-redirect" title="Dynamic random access memory">dynamic random access memory</a> (DRAM), with data retention of seconds to minutes at room temperature and much longer times when memory chips were cooled to low temperature. The study authors were able to demonstrate a <a href="Cold_boot_attack" title="Cold boot attack">cold boot attack</a> to recover cryptographic keys for several popular disk encryption systems despite some memory degradation, by taking advantage of redundancy in the way keys are stored after they have been expanded for efficient use. The authors recommend that computers be powered down, rather than be left in a "sleep" state, when not under physical control by the computer's legitimate owner. This method of key recovery, however, is suited for controlled laboratory settings and is extremely impractical for "field" use due to the equipment and cooling systems required.<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading2"><h2 id="Other_features">Other features</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Plausible_deniability">Plausible deniability</h3></div>
<p>Some disk encryption systems, such as <a href="VeraCrypt" title="VeraCrypt">VeraCrypt</a>, <a href="CipherShed" class="mw-redirect" title="CipherShed">CipherShed</a> (active open source forks of the discontinued <a href="TrueCrypt" title="TrueCrypt">TrueCrypt</a> project), <a href="BestCrypt" title="BestCrypt">BestCrypt</a> (proprietary trialware), offer levels of <a href="Plausible_deniability#Use_in_cryptography" title="Plausible deniability">plausible deniability</a>, which might be useful if a user is compelled to reveal the password of an encrypted volume.
</p>
<div class="mw-heading mw-heading3"><h3 id="Hidden_volumes">Hidden volumes</h3></div>
<style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">See also: <a href="Deniable_encryption" title="Deniable encryption">Deniable encryption</a></div>
<p>Hidden volumes are a <a href="Steganographic" class="mw-redirect" title="Steganographic">steganographic</a> feature that allows a second, "hidden", volume to reside within the apparent free space of a visible "container" volume (sometimes known as "outer" volume). The hidden volume has its own separate file system, password, and encryption key distinct from the container volume.
</p><p>The content of the hidden volume is encrypted and resides in the free space of the file system of the outer volume—space which would otherwise be filled with random values if the hidden volume did not exist. When the outer container is brought online through the disk encryption software, whether the inner or outer volume is <a href="Mount_(computing)" title="Mount (computing)">mounted</a> depends on the password provided. If the "normal" password/key of the outer volume proves valid, the outer volume is mounted; if the password/key of the hidden volume proves valid, then (and only then) can the existence of the hidden volume even be detected, and it is mounted; otherwise if the password/key does not successfully decrypt either the inner or outer volume descriptors, then neither is mounted.
</p><p>Once a hidden volume has been created inside the visible container volume, the user will store important-looking information (but which the user does not actually mind revealing) on the outer volume, whereas more sensitive information is stored within the hidden volume.
</p><p>If the user is forced to reveal a password, the user can reveal the password to the outer volume, without disclosing the existence of the hidden volume. The hidden volume will not be compromised, if the user takes certain precautions in overwriting the free areas of the "host" disk.<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="No_identifying_features">No identifying features</h3></div>
<p>Volumes, be they stored in a file or a device/partition, may intentionally not contain any discernible "signatures" or unencrypted headers. As cipher algorithms are designed to be indistinguishable from a <a href="Pseudorandom_permutation" title="Pseudorandom permutation">pseudorandom permutation</a> without knowing the <a href="Key_(cryptography)" title="Key (cryptography)">key</a>, the presence of data on the encrypted volume is also undetectable unless there are known weaknesses in the cipher.<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> This means that it is impossible to prove that any file or partition is an encrypted volume (rather than random data) without having the password to mount it. This characteristic also makes it impossible to determine if a volume contains another hidden volume.
</p><p>A file hosted volume (as opposed to partitions) may look out of place in some cases since it will be entirely random data placed in a file intentionally. However, a partition or device hosted volume will look no different from a partition or device that has been wiped with a common disk wiping tool such as <a href="Darik's_Boot_and_Nuke" title="Darik's Boot and Nuke">Darik's Boot and Nuke</a>. One can plausibly claim that such a device or partition has been wiped to clear personal data.
</p><p>Portable or "traveller mode" means the encryption software can be run without installation to the system hard drive. In this mode, the software typically installs a temporary <a href="Device_driver" title="Device driver">driver</a> from the portable media. Since it is installing a driver (albeit temporarily), administrative privileges are still required.
</p>
<div class="mw-heading mw-heading3"><h3 id="Resizable_volumes">Resizable volumes</h3></div>
<p>Some disk encryption software allows encrypted volumes to be resized. Not many systems implement this fully and resort to using "<a href="Sparse_file" title="Sparse file">sparse files</a>" to achieve this.
</p>
<div class="mw-heading mw-heading3"><h3 id="Backups">Backups</h3></div>
<p>Encrypted volumes contain "header" (or "CDB") data, which may be backed up. Overwriting these data will destroy the volume, so the ability to back them up is useful.
</p><p>Restoring the backup copy of these data may reset the volume's password to what it was when the backup was taken.
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Disk_encryption_theory" title="Disk encryption theory">Disk encryption theory</a></li>
<li><a href="Disk_encryption_hardware" class="mw-redirect" title="Disk encryption hardware">Disk encryption hardware</a></li>
<li><a href="Comparison_of_disk_encryption_software" title="Comparison of disk encryption software">Comparison of disk encryption software</a></li>
<li><a href="Data_remanence" title="Data remanence">Data remanence</a></li>
<li><a href="Disk_encryption" title="Disk encryption">Disk encryption</a></li>
<li><a href="On-the-fly_encryption" class="mw-redirect" title="On-the-fly encryption">On-the-fly encryption</a></li>
<li><a href="Cold_boot_attack" title="Cold boot attack">Cold boot attack</a></li>
<li><a href="Ransomware" title="Ransomware">Ransomware</a></li>
<li><a href="Single_sign-on" title="Single sign-on">Single sign-on</a></li>
<li><i><a href="United_States_v._Boucher" class="mw-redirect" title="United States v. Boucher">United States v. Boucher</a></i></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFJ._Alex_Halderman2008" class="citation journal cs1"><a href="J._Alex_Halderman" title="J. Alex Halderman">J. Alex Halderman</a>; et&nbsp;al. (February 2008). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20080514160137/http://citp.princeton.edu.nyud.net/pub/coldboot.pdf">"Lest We Remember: Cold Boot Attacks on Encryption Keys"</a> <span class="cs1-format">(PDF)</span>. Archived from <a rel="nofollow" class="external text" href="http://citp.princeton.edu.nyud.net/pub/coldboot.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 2008-05-14.</cite> <span class="cs1-visible-error citation-comment"><code class="cs1-code">{{cite journal}}</code>: </span><span class="cs1-visible-error citation-comment">Cite journal requires <code class="cs1-code">|journal=</code> (help)</span></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://www.freeotfe.org/docs/Main/plausible_deniability.htm">Plausible Deniability</a> - <a href="FreeOTFE" title="FreeOTFE">FreeOTFE</a> instructions for initializing an encrypted disk such that the presence of a hidden disk cannot be detected</span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text">This is a design criterion of modern ciphers; in other words, ciphers are considered broken if their output is discernible from random.<br><cite id="CITEREFMihir_Bellare,_Phillip_Rogaway2005" class="citation book cs1"><a href="Mihir_Bellare" title="Mihir Bellare">Mihir Bellare</a>, <a href="Phillip_Rogaway" title="Phillip Rogaway">Phillip Rogaway</a> (2005-09-20). "Chapter 3: Pseudorandom functions". <a rel="nofollow" class="external text" href="https://web.archive.org/web/20071011235219/http://www-cse.ucsd.edu/~mihir/cse207/classnotes.html"><i>Introduction to Modern Cryptography</i></a>. p.&nbsp;7. Archived from <a rel="nofollow" class="external text" href="http://www-cse.ucsd.edu/~mihir/cse207/classnotes.html">the original</a> on 2007-10-11<span class="reference-accessdate">. Retrieved <span class="nowrap">2007-09-30</span></span>.</cite></span>
</li>
</ol></div></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-07-28" href="https://en.wikipedia.org/wiki/?title=Disk_encryption_software&amp;oldid=1302909615">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>