Demystifying Full-Disk Encryption
Published: 01/07/2017
Transparent full-disk encryption uses techniques found almost nowhere else in cryptography, such as ESSIV and XTS-AES. Why must designers resort to building a custom cryptosystem rather than relying on standard techniques with typical security guarantees? This paper explores the constraints under which a full-disk encryption must operate, questioning the performance reasons for avoiding more standard cryptography yet finding them to hold. I introduce the reader familiar with cryptography but not the operation of disks to this problem, explain the high-level workings of ESSIV and XTS-AES, and review the attacks and limitations that these approaches face.