eSign.AIeSign.AI

Glossary

Electronic Timestamps and Long-Term Validation (LTV)

A trusted timestamp proves when a signature was created. LTV keeps it verifiable after certificates expire.

eSign.AI Digital Trust Research Team5 min read

Why timestamps matter for signatures

A digital signature links a signer or certificate holder to signed data and makes later changes detectable. A trusted timestamp adds independent evidence that the data existed at a stated time. This becomes important when certificates expire or are revoked and when a verifier must reconstruct the historical validation context.

TSA

Time Stamping Authority issues timestamps

RFC 3161

Standard timestamp token format

LTV

Long-Term Validation extends signature validity

LTA

Long-Term Archival — indefinite validity

How trusted timestamping works

A TSA provides a cryptographically verifiable proof that data existed at a specific time.

01

The signing software sends a hash of the signed document (not the document itself) to the TSA. This protects document confidentiality.

02

The TSA creates a timestamp token (RFC 3161 format) that includes the document hash, the current time (from the TSA's synchronised clock), and the TSA's signature over both. The token proves the hash — and therefore the document — existed at the stated time.

03

The timestamp token is embedded in the signature (PAdES level T and above). Future validators can verify the timestamp independently using the TSA's public certificate.

04

When validating a signature, the verifier checks: (a) the signature hash matches the document, (b) the timestamp proves it existed before the certificate expired, and (c) the TSA certificate was valid at the time of timestamping.

Long-Term Validation (LTV): signatures that outlive certificates

Signing certificates expire. Without LTV, signatures become unverifiable after expiry.

The expiry problem

A signature may become harder to validate after certificate expiry when historical certificate status and validation material are unavailable. A trusted timestamp and preserved revocation evidence help a verifier establish that the signature existed while the relevant credentials were valid.

LTV solution

LTV embeds all validation data within the signature: the signing certificate, its chain, revocation data (CRL/OCSP), and the timestamp. This allows verification even after the certificate expires — because the embedded data proves everything was valid at signing time.

PAdES levels B → T → LT → LTA

Level B: basic signature. T: adds trusted timestamp. LT: adds validation data (certificates, revocation). LTA: adds periodic re-timestamping for indefinite validity. For contracts and regulatory documents, LT or LTA is recommended.

Archival requirements

Retention periods vary by jurisdiction, document type, and sector. LTV profiles preserve technical validation material for later verification, but they do not by themselves determine legal validity or replace the organisation's records-retention policy.

Timestamp data points: what to verify and what it costs

Specific data points for trusted timestamp implementation in signing workflows.

TSA accreditation and RFC 3161

Qualified timestamps must come from a Time Stamping Authority accredited under eIDAS Article 40 (EU) or equivalent national framework. The timestamp token must conform to RFC 3161 (Time-Stamp Protocol). TSA certificate validity is typically 4-6 years; timestamps must be renewed before certificate expiry for continued validation.

Qualified timestamp procurement factors

Timestamp pricing depends on qualification status, volume, service level, geographic coverage, validation endpoints, and whether timestamps are bundled with another trust service. Request a dated quote and test the commercial model against expected signing and re-timestamping volume.

PAdES B-LT vs B-LTA: storage impact

B-LT embeds revocation data (CRL/OCSP) at signing time, adding 10-50 KB per signature. B-LTA adds archival timestamps, growing the document by 5-15 KB per re-timestamp. For a 100-signature approval chain over 10 years, B-LTA storage reaches 5-8 MB — significant for high-volume archival systems.

TSAlite vs qualified timestamp: legal weight

A TSAlite (non-qualified) timestamp provides evidence of existence but does not receive the presumption of validity under eIDAS Article 41. In EU litigation, only qualified timestamps receive the same evidentiary presumption as QES. Outside the EU, courts evaluate timestamp weight case-by-case regardless of qualification status.

When timestamps matter most: regulatory and evidentiary use cases

Specific scenarios where trusted timestamps are not optional but legally or operationally required.

Regulatory filings with timestamp mandates

EU MiCA (Markets in Crypto-Assets Regulation): requires timestamped records for crypto-asset transactions. FDA 21 CFR Part 11.50: requires date and time stamps for all electronic signature manifestations. China's Electronic Signature Law: timestamps strengthen evidence of signing time but are not mandatory. Singapore MAS guidelines: financial transaction records should include trusted timestamps for audit trails.

Evidence chain and dispute scenarios

In contract disputes, the critical question is often "when was this signed?" A qualified timestamp from an accredited TSA provides presumption of accuracy under eIDAS Article 41. Without a trusted timestamp, the signing time relies on platform server logs — which are less convincing in court. For cross-border agreements where parties are in different time zones, UTC timestamps with timezone conversion records prevent ambiguity.

LTV archival timestamp renewal

For documents requiring long-term verifiability, an archival profile may add new timestamps before earlier evidence becomes too weak to validate. The organisation should define who monitors cryptographic change, when evidence is augmented, and how the process is tested; automation availability must be confirmed for the deployed platform.

Common questions

A cryptographic proof, issued by a Time Stamping Authority (TSA), that data existed at a specific point in time. The TSA signs a token containing the data hash and the time. Anyone can later verify the token using the TSA's public certificate.

How eSign.AI applies this in practice

eSign.AI can be configured to include RFC 3161 timestamps and long-term validation material in supported signing workflows. Confirm the TSA, qualification status, signature profile, revocation-data capture, and archival process for the selected deployment.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.