...but (with respect, Elazar) you missed the whole point.
I believe the original question was concerning 'Whole Drive Encryption'.
What you postulate as your vision is already here. These forms can already be done. To achieve a satisfactory schema one needs external booting and key safe.
(Your early link was to quite a good paper).