Trust Relationship (iOS)
Definition
The pairing between an iOS device and a computer established when the user taps 'Trust' after connecting. A forensic logical or file-system extraction via the backup API requires a trust relationship; without it, only minimal data is accessible.
- Trigger
- User taps Trust after connecting device to computer
- Required for
- Logical and file-system extraction via the backup API
- Without it
- Only minimal data is accessible
- Platform
- iOS
Common questions
What can an examiner still recover from a locked iOS device with no trust relationship?+
Access is typically limited to whatever the connection protocol exposes without pairing, such as basic device information, rather than the file system or backup-based data that a trusted pairing unlocks.
Can an examiner establish a trust relationship without the passcode?+
Generally no, since establishing trust requires unlocking the device to tap Trust on the prompt. Some acquisition methods use existing pairing records or lockdown files recovered from a previously trusted computer to bypass re-pairing.
Related terms
- AFC (Apple File Conduit)
- The iOS service that exposes the media partition for file transfer during synchronisation. In standard form it only surfaces the media partition;...
- Android Debug Bridge (ADB)
- A command-line tool included in the Android SDK that allows communication with an Android device over USB or Wi-Fi. Used for logical...
- File-System Extraction
- A deeper form of extraction that retrieves the full accessible directory tree by mounting the file system or using a privileged API...
- iTunes Backup Protocol
- Apple's proprietary protocol for transferring device data to a computer. Used by forensic tools to conduct logical acquisition of iOS devices; backup...
- Logical Acquisition
- An extraction method that uses the device's own operating system interfaces, such as iTunes backup or Android Debug Bridge, to export the...