What Encryption Modes Are Available in VeraCrypt?
VeraCrypt supports only one encryption mode: XTS (XEX‑based tweaked‑codebook mode with ciphertext stealing), implemented via either OpenSSL or WolfCrypt backends depending on the build configuration.
The veracrypt/VeraCrypt repository maintains a straightforward approach to disk encryption by standardizing on a single, secure mode across all supported ciphers. When examining the encryption modes available in VeraCrypt, the source code reveals that the implementation focuses exclusively on XTS, with compile‑time options determining the underlying cryptographic library rather than the mode itself.
XTS: The Exclusive Encryption Mode
VeraCrypt implements XTS as its sole encryption mode. This design applies universally to every supported block cipher, including AES, Serpent, and Twofish. While users can select different algorithms for encryption, VeraCrypt always pairs them with XTS mode.
The mode implementation remains independent of the specific cipher algorithm. Whether you configure a volume to use AES‑256 or Serpent, the underlying mode is XTS, as defined in the volume layout registration logic.
Backend Implementation Classes
Although VeraCrypt offers only one functional mode, the codebase contains two distinct C++ classes that implement XTS. The build system selects the appropriate backend at compile time.
OpenSSL Backend (Default)
The default configuration utilizes the OpenSSL cryptographic library via the EncryptionModeXTS class.
- Source file:
src/Volume/EncryptionModeXTS.cpp - Class:
EncryptionModeXTS - Build condition: Default when
WOLFCRYPT_BACKENDis undefined
WolfCrypt Backend
When compiled with the WOLFCRYPT_BACKEND preprocessor definition, VeraCrypt switches to the WolfCrypt library implementation.
- Source file:
src/Volume/EncryptionModeWolfCryptXTS.cpp - Class:
EncryptionModeWolfCryptXTS - Build condition: When
WOLFCRYPT_BACKENDis defined
Mode Enumeration Factory
The static method EncryptionMode::GetAvailableModes() serves as the central factory for discovering supported modes at runtime. Located in src/Volume/EncryptionMode.cpp, this method returns a list containing exactly one mode object:
EncryptionModeList EncryptionMode::GetAvailableModes ()
{
EncryptionModeList l;
#ifdef WOLFCRYPT_BACKEND
l.push_back (shared_ptr<EncryptionMode>(new EncryptionModeWolfCryptXTS()));
#else
l.push_back (shared_ptr<EncryptionMode>(new EncryptionModeXTS()));
#endif
return l;
}
This factory pattern ensures that consuming code receives a compatible EncryptionMode interface pointer regardless of the backend implementation details.
Volume Layout Integration
Each volume layout—whether normal or hidden—registers the encryption mode during construction. In src/Volume/VolumeLayout.cpp, the constructors populate the SupportedEncryptionModes vector with the appropriate XTS implementation:
SupportedEncryptionModes.push_back (shared_ptr<EncryptionMode>(new EncryptionModeXTS()));
// or, when compiled with WolfCrypt:
SupportedEncryptionModes.push_back (shared_ptr<EncryptionMode>(new EncryptionModeWolfCryptXTS()));
This registration occurs consistently across all volume layout types, reinforcing that VeraCrypt offers only XTS mode for volume encryption.
Code Examples
The following examples demonstrate how to interact with the encryption mode system programmatically.
Listing Available Modes at Runtime
To retrieve the list of supported encryption modes programmatically, call the factory method:
#include "Volume/EncryptionMode.h"
int main ()
{
auto modes = VeraCrypt::EncryptionMode::GetAvailableModes();
for (const auto &mode : modes)
{
// All modes derive from EncryptionMode and expose a name
std::cout << "Supported mode: " << mode->GetName() << std::endl;
}
return 0;
}
This code instantiates mode objects via GetAvailableModes() and outputs their names, which will be "XTS" for both backend implementations.
Querying an Opened Volume's Mode
Once a volume is mounted, inspect which encryption mode it utilizes:
VeraCrypt::Volume volume; // Assume the volume is already opened
auto mode = volume.GetEncryptionMode(); // Returns a shared_ptr<EncryptionMode>
std::cout << "Volume uses mode: " << mode->GetName() << std::endl;
The Volume::GetEncryptionMode() method returns the mode stored in the volume header. As VeraCrypt exclusively uses XTS, this will always return the XTS implementation regardless of the underlying cipher.
Key Source Files
src/Volume/EncryptionMode.cpp: Contains theGetAvailableModes()factory and the baseEncryptionModeclass implementation.src/Volume/EncryptionModeXTS.cpp: Implements the OpenSSL‑based XTS mode.src/Volume/EncryptionModeWolfCryptXTS.cpp: Implements the WolfCrypt‑based XTS variant.src/Volume/VolumeLayout.cpp: Registers the supported mode for each volume layout type.
Summary
- VeraCrypt supports exactly one encryption mode: XTS, regardless of the selected cipher algorithm (AES, Serpent, Twofish, etc.).
- The codebase provides two backend implementations:
EncryptionModeXTSfor OpenSSL andEncryptionModeWolfCryptXTSfor WolfCrypt, selected at compile time via theWOLFCRYPT_BACKENDflag. - The factory method
EncryptionMode::GetAvailableModes()insrc/Volume/EncryptionMode.cppreturns a singleton list containing the configured XTS implementation. - All volume layouts register XTS as their supported mode during construction in
src/Volume/VolumeLayout.cpp.
Frequently Asked Questions
Does VeraCrypt support CBC or other encryption modes?
No. According to the veracrypt/VeraCrypt source code, the GetAvailableModes() factory explicitly returns only the XTS implementation. Unlike some other disk encryption tools, VeraCrypt does not offer CBC, LRW, or other historical modes, having standardized exclusively on XTS for its security properties regarding disk encryption.
What is the difference between EncryptionModeXTS and EncryptionModeWolfCryptXTS?
The difference is purely the underlying cryptographic library, not the mode itself. EncryptionModeXTS utilizes the OpenSSL backend by default, while EncryptionModeWolfCryptXTS interfaces with the WolfCrypt library when VeraCrypt is compiled with the WOLFCRYPT_BACKEND flag. Both implement the same XTS mode specification and provide identical security guarantees.
Can I change the encryption mode of an existing VeraCrypt volume?
No. The encryption mode is determined at volume creation time and stored in the volume header. To change modes, you would need to create a new volume and migrate data, as VeraCrypt only supports XTS mode and does not provide mechanisms to convert between different modes (nor would this be meaningful since only one mode is available).
Why does VeraCrypt use XTS mode exclusively?
XTS mode is specifically designed for disk encryption and provides protection against targeted ciphertext manipulation attacks that could occur with simpler modes like CBC. By standardizing on XTS across all ciphers in src/Volume/VolumeLayout.cpp, VeraCrypt ensures consistent security semantics regardless of whether the user selects AES, Serpent, or Twofish as the underlying block cipher.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →