Skip to content

drawing/strongbox

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

20 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

strongbox

Introduction

strongbox is used to keep files safe, When the system reads and writes files, strongbox captures the event through the fuse callback, judges the permission of the read and write process, and encrypts and decrypts the read and write persistent storage to ensure file security.

Capability

  • Manage read and write directory/file permissions through process whitelist
  • Encrypt local persistent files

Architecture

graph TD
    user(User/Program)
    filesystem(Linux/Mac/Windows 's Filesystem)
    fuse(Fuse Filesystem)
    subgraph strongbox
        access(Program Access Control)
        encrypt(Encrypted File Content)
        fs(Persistent Storage)
        access --> encrypt
        encrypt --> fs
    end
    user -->|manage files| filesystem
    filesystem --> fuse
    fuse -->|callback| strongbox
Loading

Usage

Start by command

Usage of ./strongbox:
  -c string
        config file. (default "config.yml")
Exmaple:
    strongbox -c ./config.yml

config file description

# target file path
mountPoint: /tmp/w1

secretPath: /tmp/w2/i.db

allowProcess:
  - "/usr/local/Cellar/git/2.29.2/bin/git"
  - "/Applications/Visual Studio Code.app/Contents/MacOS/Electron"
# watchMode=true only prints interception information, does not perform interception operations
watchMode: false

# target mount path
mountPoint: /tmp/w1
backup:
  # encrypted persistent storage path
  path: /tmp/w2/i.db
  # backup in memory
  memory: false
permission:
  defaultAction: deny
  # process whitelist, full binary path
  allowProcess:
    - "/bin/sh"
    - "/bin/ls"
    - "/bin/rm"
    - "/bin/mkdir"
logger:
  level: debug

To start the process, you need to enter a password.

After completion, only the whitelist process can operate the files and directories in /tmp/w1, and other processes have no permission to access. And the files in this directory are encrypted then saved to /tmp/w2/i.db, so there is no need to worry about the risk of leakage.

Use GUI

About

This program is used to keep files safe

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages