Filesystem-level encryption
form of disk encryption where individual files or directories are encrypted by the file system itself

Filesystem-level encryption, often called file-based encryption, FBE, or file/folder encryption, is a form of disk encryption where individual files or directories are encrypted by the file system itself.
This is in contrast to the full disk encryption where the entire partition or disk, in which the file system resides, is encrypted.
Types of filesystem-level encryption include:
the use of a 'stackable' cryptographic filesystem layered on top of the main file system
a single general-purpose file system with encryption
The advantages of filesystem-level encryption include:
flexible file-based key management, so that each file can be and usually is encrypted with a separate encryption key
individual management of encrypted files e.g. incremental backups of the individual changed files even in encrypted form, rather than backup of the entire encrypted volume
access control can be enforced through the use of public-key cryptography, and
the fact that cryptographic keys are only held in memory while the file that is decrypted by them is held open.
General-purpose file systems with encryption
Unlike cryptographic file systems or full disk encryption, general-purpose file systems that include filesystem-level encryption do not typically encrypt file system metadata, such as the directory structure, file names, sizes or modification timestamps. This can be problematic if the metadata itself needs to be kept confidential. In other words, if files are stored with identifying file names, anyone who has access to the physical disk can know which documents are stored on the disk, although not the contents of the documents.
One exception to this is the encryption support being added to the ZFS filesystem. Filesystem metadata such as filenames, ownership, ACLs, extended attributes are all stored encrypted on disk. The ZFS metadata relating to the storage pool is stored in plaintext, so it is possible to determine how many filesystems (datasets) are available in the pool, including which ones are encrypted.
Begin with the source’s own compact description: “Filesystem-level encryption” is form of disk encryption where individual files or directories are encrypted by the file system itself. The dossier treats that line as a proposition to test through Filesystem-level, encryption and form, not as a finished interpretation.
Why this record matters
The phrase “form of disk encryption where individual files or directories are encrypted by the file system itself” supplies a clear boundary for inquiry. It also exposes the unanswered questions: who defined that boundary, when it became stable and which sources sit outside it.
Named sources, stable identifiers and responsible institutions provide the strongest route from overview to verifiable evidence. The source revision retrieved here is dated Nov 8, 2025. The linked authority identifier is Q5448402. None of the 0 selected statements returned an explicit reference.
A concise general-reference account can conceal disagreements about scope, terminology or the weight assigned to individual sources. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “Filesystem-level encryption”, its source revision and the description used here.
- Expand the search: follow Filesystem-level encryption primary sources, Filesystem-level encryption archive and Filesystem-level research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Filesystem-level encryption”?
- Which institution is responsible for the underlying evidence?
- Which cited source is closest to the event, object or claim?
Search terms from this dossier
This entry incorporates text from “Filesystem-level encryption” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.