Skip to content

Device Trust

Device Trust is a continuously evaluated state reflecting the degree to which a device’s observed behavior aligns with expected behavior, derived from accumulated evidence over time.

Device Trust is not static. It is re-evaluated continuously as new evidence is collected, and it can increase, decrease, or remain stable based on observed behavior.

Trust reflects observed consistency and alignment with expected behavior.


Traditional approaches treat trust as binary and static:

  • Device authenticates → trusted
  • Device connects → trusted
  • Device enrolled → trusted forever

This assumption model fails because:

  • Devices change over time
  • Devices can be compromised after authentication
  • Behavior drift is invisible to authentication systems

Device Trust in KYD® recognizes that trust is:

  • continuous (evaluated over time, not once)
  • evidence-based (derived from observation, not assumption)
  • dynamic (can change as device behavior changes)

Device Trust in KYD®:

  1. Is continuously evaluated, not established once
  2. Accumulates evidence over time (history matters)
  3. Can degrade in the absence of positive evidence or presence of drift
  4. Is explainable (the system can explain why a device is trusted or not)
  5. Is independent of authentication (authentication grants access; trust evaluates behavior)

  • Device Identity - Trust is evaluated per Device Identity
  • Baseline - Expected behavior against which trust is evaluated
  • Device Drift - Deviations from expected behavior that affect trust
  • Trust Score - Numerical representation of Device Trust
  • Proof Over Time - Historical record of trust evaluations

This term is defined normatively in:

KYD® Specification v1.0

  • Section 3.3: Definition of Device Trust
  • Section 4.4: Trust Evaluation Requirements

All usage of “Device Trust” in KYD® materials MUST align with this definition.