# Historical Cost Structure of Trust Signal Production

- **Artifact ID:** CHQ-EX-2026-004
- **Public record:** https://record.cybersecurityhq.com/exhibits/chq-ex-2026-004
- **Machine-record SHA-256:** `28891e25888fe081d1fd6f6ef4a329c25efc108650aae914ca8a2fec63ea8561`

## Complete structured record

```json
{
  "id": "CHQ-EX-2026-004",
  "title": "Historical Cost Structure of Trust Signal Production",
  "subtitle": "Observed costs, resource requirements, and asymmetries in the fabrication and verification of trust signals across credential presentation, identity assertion, and behavioral indicators prior to large-scale AI deployment",
  "classification_notice": [
    "This document is published as a CHQ Exhibit. It records historical conditions, economic structures, and industry practices as they existed during the periods described. This Exhibit records observed cost relationships, resource requirements, and asymmetry conditions as documented in industry research, security literature, and operational reporting during the stated period.",
    "This document does not address present conditions and carries no current applicability. No evaluation of past practices is intended or implied. No causal language, synthesis, or advisory implication is present.",
    "CHQ Exhibits are not superseded by later artifacts unless explicitly invalidated for factual error."
  ],
  "metadata": {
    "artifact_class": "EXHIBIT",
    "temporal_scope": "HISTORICAL (2010–2022)",
    "authority_level": "NON-JUDGMENTAL",
    "reliance_status": "CONTEXT ONLY",
    "update_policy": "ERRATA ONLY",
    "temporal_start": "2010-01-01",
    "temporal_end": "2022-12-31"
  },
  "sections": [
    {
      "heading": "I. Cost Structure of Credential Fabrication (2010–2022)",
      "content": [
        "Fabrication of false credentials during this period required access to resources not uniformly available. Phishing kits, available on underground marketplaces, ranged in price from tens to hundreds of dollars during this period. More capable kits with evasion features and infrastructure were documented at higher price points. Academic and industry research into phishing economics from 2010 through 2022 recorded these cost structures.",
        "Business Email Compromise operations, documented in FBI Internet Crime Complaint Center annual reports from 2015 through 2022, required social engineering capability and organizational research. These operations were attributed to organized groups. The upfront investment in targeting, infrastructure, and execution was recorded as a barrier to casual entry.",
        "Synthetic identity construction, combining real and fabricated identity elements, required coordination across multiple data sources. Industry reports from this period described the data acquisition costs associated with building synthetic profiles. Credit bureau and financial industry publications documented synthetic identity fraud as a distinct category from stolen identity fraud, noting the different resource profiles involved.",
        "Deepfake video and audio generation for identity fraud purposes was documented in security research from approximately 2018 onward. Research papers from this period recorded the computational resources, training data requirements, and technical expertise required to produce artifacts of sufficient quality for use in fraud scenarios. GPU compute costs and dataset acquisition costs were recorded components of this resource profile.",
        "This Exhibit does not assess these cost structures."
      ]
    },
    {
      "heading": "II. Cost Structure of Identity Verification (2010–2022)",
      "content": [
        "Identity verification in enterprise authentication during this period involved password-based systems, hardware tokens, and multi-factor authentication mechanisms. FIDO U2F hardware security keys, introduced around 2014, carried per-unit costs in the range of fifteen to fifty dollars. Enterprise deployment at scale required procurement, provisioning, and lifecycle management overhead in addition to unit costs.",
        "Knowledge-based authentication systems, used by financial institutions and credit bureaus, operated through databases of personal history questions. Maintenance of these databases, including data acquisition, update cycles, and fraud monitoring, represented ongoing operational costs. Industry research documented the accuracy and fraud resistance characteristics of knowledge-based authentication during this period.",
        "Biometric verification systems, deployed in mobile devices from approximately 2013 onward and in enterprise access control environments, required hardware integration, enrollment processes, and template storage infrastructure. Fingerprint, facial recognition, and iris scan systems each carried distinct hardware and operational cost profiles. Liveness detection as an anti-spoofing measure added additional processing requirements.",
        "Document verification for remote onboarding, including government-issued identity document checks, involved manual review, automated optical character recognition, and third-party verification service fees. Industry vendors offering identity document verification services priced these on a per-check basis. Enterprise customers paid volume-based rates documented in commercial agreements from this period.",
        "This Exhibit does not assess verification cost structures."
      ]
    },
    {
      "heading": "III. Behavioral Trust Signal Production and Verification",
      "content": [
        "Behavioral biometrics, including keystroke dynamics, mouse movement patterns, and device interaction signatures, were developed and commercialized during this period. Vendors offering behavioral biometric products marketed them on the basis of passive, continuous authentication. The computational infrastructure required to collect, model, and score behavioral signals represented a fixed and per-user cost profile.",
        "User and Entity Behavior Analytics platforms, which appeared as a distinct product category around 2015, required data collection pipelines, storage infrastructure, and baseline modeling periods. Industry analyst firms including Gartner and Forrester published market analyses of UEBA platforms during this period. Deployment timelines for behavioral baseline establishment were documented as weeks to months in vendor and industry literature.",
        "Network behavioral analysis, including NetFlow analysis and east-west traffic inspection, required packet capture or metadata collection infrastructure and analysis platforms. Storage requirements for behavioral data retention were documented in product specifications and compliance discussions. The cost of storing behavioral telemetry at enterprise scale was a recorded procurement consideration.",
        "Threat intelligence services providing context for behavioral anomaly scoring were priced on subscription and volume models. Integration of external threat intelligence into internal behavioral analysis platforms required engineering resources. The total cost of a behavioral trust signal production and verification environment included platform licensing, infrastructure, integration, and analyst labor.",
        "This Exhibit does not assess these systems."
      ]
    },
    {
      "heading": "IV. Asymmetry Conditions in the Pre-LLM Period",
      "content": [
        "Security research and industry literature from 2010 through 2022 recorded a consistent observation: the cost of producing a convincing false trust signal was higher than the cost of producing a legitimate one in most authentication contexts. This observation appeared in fraud economics research, penetration testing literature, and authentication design rationale documentation.",
        "Social engineering remained the documented exception to cost asymmetry. Verizon Data Breach Investigations Reports from 2010 through 2022 recorded phishing and pretexting as consistently represented attack vectors. The barrier to social engineering was characterized in this literature as organizational and behavioral rather than technical or economic.",
        "Voice-based fraud, including vishing and SIM swapping, was documented as a lower-cost attack path against authentication systems that relied on voice verification or SMS delivery. Telecom industry and financial industry publications from this period recorded SIM swap fraud volumes and associated losses. The cost structure of SIM swap attacks, involving social engineering of carrier representatives, was described in consumer protection and industry research publications.",
        "Generative AI capabilities for text, image, audio, and video were the subject of active academic research throughout this period. Publications from research institutions documented capability progression and computational resource requirements. Commercial deployment of generative AI at scale had not occurred across the consumer and enterprise markets by the end of this period in 2022.",
        "This Exhibit does not assess asymmetry conditions."
      ]
    },
    {
      "heading": "V. Authentication Architecture Assumptions of the Period",
      "content": [
        "Authentication system design during 2010 through 2022 incorporated cost asymmetry as an implicit premise. Multi-factor authentication designs combined possession, knowledge, and inherence factors on the basis that simultaneous compromise of multiple factors carried higher cost than single-factor attacks. This design rationale appeared in NIST Special Publication 800-63, published in revised form in 2017, and in industry authentication guidance documents.",
        "Risk-based authentication systems, deployed by financial institutions and enterprise software vendors, incorporated behavioral signals and contextual factors to adjust authentication requirements. The scoring models underlying these systems were calibrated against observed fraud patterns from this period. Model training and recalibration required ongoing operational investment.",
        "Zero Trust architecture frameworks, documented in NIST SP 800-207 published in 2020 and in industry publications from major technology vendors, described continuous verification principles. These frameworks referenced behavioral signals, device posture, and contextual factors as inputs to access decisions. The cost of implementing continuous verification infrastructure was addressed in adoption guides and vendor documentation from this period.",
        "Industry certification and standards bodies including FIDO Alliance, OpenID Foundation, and OATH published authentication specifications during this period. These specifications addressed interoperability, security properties, and implementation guidance. The economic assumptions embedded in these specifications reflected the cost structures observed during the period of their development.",
        "This Exhibit does not assess authentication architectures."
      ]
    }
  ],
  "closing_statement": "This Exhibit records historical conditions during the period 2010 through 2022.\n\nNo present applicability.\n\nNo evaluative conclusions.",
  "hash_scope": "Full exhibit content body",
  "hash_generated": "2026-02-18"
}
```
