It seem like if we take the OS(kernel) to be safe, then the proposed can be achieved by name spacing, and there is no need for encryption. Besides, simply not having a key won't stop malware from garbling the files. If we take the OS to be infected, then the malware can just read the keys, and we are back to square one.