Full-Disk Encryption (FDE)
Definition
A storage protection model in which the entire partition is encrypted with a key derived from the user's passcode and hardware-bound identifiers. A physical image of an FDE device is unreadable ciphertext without the key.
- Scope
- Entire storage partition
- Key source
- User passcode plus hardware-bound identifiers
- Effect on physical image
- Unreadable ciphertext without the key
- Examples
- BitLocker, FileVault, Android FBE, iOS Data Protection
Common questions
How do examiners get around full-disk encryption in practice?+
Rather than attacking the encryption directly, investigators typically look for the device unlocked at seizure, obtain the passcode through legal process, extract keys from a live or memory-resident session, or use vendor-assisted or exploit-based extraction tools where a vulnerability exists.
Does FDE protect data once the device is unlocked and imaged live?+
No. FDE protects data at rest against an offline physical image. Once a device is unlocked, the operating system decrypts data on access, so a live logical or file-system extraction from an unlocked device bypasses the disk-level protection entirely.
Related terms
- Bootloader
- Firmware that runs immediately after power-on to verify, load, and hand control to the operating system. A locked bootloader refuses to execute...
- Chip-Off Acquisition
- A physical extraction method in which the flash memory chip is desoldered from the device's circuit board and read directly with specialised...
- EDL Mode (Emergency Download Mode)
- A Qualcomm diagnostic protocol embedded in the Primary Boot Loader (PBL) that activates before the main OS and accepts raw memory read...
- File-Based Encryption (FBE)
- An Android encryption model introduced in Android 7.0 in which each file is encrypted with a separate key derived from the user...
- NAND Flash
- The type of non-volatile memory used in all modern mobile device storage. Data is written to pages grouped into blocks; erasure operates...