Linux Encrypted File Systems and Buffer

I am currently using Berkeley DBs that go to Java server for high performance hard disk cache. If you warm it up before letting it encounter live traffic, your refresh rate is slow and your working set fits in memory, the Linux buffer cache does a great job. This is noticeably faster than memcache, in part because you don't need to switch context to memcached and back to read. We are very pleased with the work.

We're going to add some data to the cache that we are not comfortable leaving on disk in plain text. We have measured and are dissatisfied with the decryption performance during request processing, so we are looking for solutions that only decrypt when data is loaded from disk and then stored in memory.

Before building something that does this, I wanted to find out if we can just stick in the encrypted filesystem and continue to rely on the OS to manage the cache for us. I haven't found any documentation that tells me at what level the decryption is done.

So my question is, can anyone tell me, for any particular Linux-encrypted FS, whether (en | de) cryption will be done below the buffer cache (and therefore the cache contains the plaintext) or higher (and the cache contains cipher text)?

+1


a source to share


2 answers


The buffer cache is below the actual filesystem, so it will cache encrypted data. See Diagram on IBM Anatomy of a File System . Since you want to cache unencrypted data, if your encrypted filesystem was created using a "loop" device, the buffer cache will also contain an unencrypted copy of your data, and therefore must be fast (at the expense of more memory for FS buffers in use).



+3


a source


I haven't played with this, but I'm pretty sure the buffer cache and VM are not aware of encryption, so you should see comparable performance with your usage.



0


a source







All Articles