eSign.AIeSign.AI

อภิธานศัพท์

Electronic Timestamps and Long-Term Validation (LTV)

A หมายเวลาที่น่าเชื่อถือ บันทึกเวลาที่ลายลักษณ์อักษรถูกสร้างขึ้น LTV ทำให้สามารถตรวจสอบได้ต่อไปหลังหนังสือรับรองหมดอายุ

ทีมวิจัยความน่าเชื่อถือดิจิทัล eSign.AIอ่าน 5 นาที

ทำไม้หมายเหตุเวลาสำคัญสำหรับหมายเหตุ

หมายเหตุดิจิตอลแสดงว่าใครที่ลงลายมือชื่อและว่าเอกสารไม่ได้ถูกแก้ไข แต่แต่ละอย่างโดยไม่มีหมายเหตุเวลาที่น่าเชื่อถือ คุณไม่สามารถแสดงว่าหมายเหตุได้ถูกสร้างขึ้นเมื่อไหร่ นี่สำคัญเพราะหนังสือรับรองหมดอายุ ถูกถอดถอน และอัลกอริทึมการเคล็ดลับจะอ่อนแอลงเมื่อผ่านเวลา หมายเหตุเวลาที่น่าเชื่อถือจาก Time Stamping Authority (TSA) แสดงว่าหมายเหตุนั้นมีอยู่ในจุดเวลาที่เฉพาะโดยแน่นอน — สำคัญสำหรับหลักฐานทางกฎหมายและการตรวจสอบระยะยาว

TSA

Time Stamping Authority ออกหมายเหตุเวลา

RFC 3161

รูปแบบหมายเหตุเวลามาตรฐาน

LTV

การตรวจสอบระยะยาวขยายอายุหมายเหตุ

LTA

การจัดเก็บระยะยาว — อายุไม่จำกัด

วิธีที่หมายเหตุเวลาที่น่าเชื่อถือทำงาน

TSA ให้หลักฐานที่สามารถตรวจสอบด้วยวิธีเคล็ดลับว่าข้อมูลมีอยู่ในจุดเวลาที่เฉพาะ

01

การส่งข้อมูลหาญ

02

โปรแกรมลงลายมือชื่อส่งหาญของเอกสารที่ลงลายมือชื่อ (ไม่ใช่เอกสารตัวเอง) ไปยัง TSA นี้ปกป้องความปลอดภัยของเอกสาร

03

TSA สร้างหมายเหตุเวลาที่มีรูปแบบ RFC 3161 ซึ่งประกอบด้วยหาญของเอกสาร เวลาปัจจุบัน (จากนาฬิกาที่เปิดระบบของ TSA) และลายมือชื่อของ TSA ทั้งสอง หมายเหตุเวลานี้แสดงว่าหาญ — และดังนั้นเอกสาร — มีอยู่ในจุดเวลาที่กล่าว

04

เมื่อตรวจสอบหมายเหตุ ผู้ตรวจสอบตรวจสอบ: (a) หาญของหมายเหตุตรงกับเอกสาร (b) หมายเหตุเวลาแสดงว่ามันมีอยู่ก่อนหน้าที่หนังสือรับรองหมดอายุ (c)หนังสือรับรองของ TSA มีผลบังคับใช้ในตอนที่หมายเหตุเวลา

การตรวจสอบระยะยาว (LTV):หมายเหตุที่มีชีวิตนานกว่าหนังสือรับรอง

Signing certificates expire. Without LTV, signatures become unverifiable after expiry.

The expiry problem

A standard digital signature is verifiable only while the signing certificate is valid (typically 1-5 years). After expiry, you cannot confirm whether the signature was created during validity — unless a trusted timestamp proves it.

LTV solution

LTV embeds all validation data within the signature: the signing certificate, its chain, revocation data (CRL/OCSP), and the timestamp. This allows verification even after the certificate expires — because the embedded data proves everything was valid at signing time.

PAdES levels B → T → LT → LTA

Level B: basic signature. T: adds trusted timestamp. LT: adds validation data (certificates, revocation). LTA: adds periodic re-timestamping for indefinite validity. For contracts and regulatory documents, LT or LTA is recommended.

Archival requirements

Many regulations require document retention for years (employment: 2-7 years, financial: 5-10 years, medical: up to 30 years). Without LTV, signatures on archived documents may become unverifiable. LTV ensures the evidence remains valid for the entire retention period.

Timestamp data points: what to verify and what it costs

Specific data points for trusted timestamp implementation in signing workflows.

TSA accreditation and RFC 3161

Qualified timestamps must come from a Time Stamping Authority accredited under eIDAS Article 40 (EU) or equivalent national framework. The timestamp token must conform to RFC 3161 (Time-Stamp Protocol). TSA certificate validity is typically 4-6 years; timestamps must be renewed before certificate expiry for continued validation.

Cost of qualified timestamps

Qualified timestamp pricing: $0.01-0.05 per timestamp at volume (100K+/month), $0.10-0.50 per timestamp at low volume. Some QTSPs bundle timestamps with QES subscriptions at no additional cost. Annual TSA service contracts start at $2,000-5,000/year for enterprise usage.

PAdES B-LT vs B-LTA: storage impact

B-LT embeds revocation data (CRL/OCSP) at signing time, adding 10-50 KB per signature. B-LTA adds archival timestamps, growing the document by 5-15 KB per re-timestamp. For a 100-signature approval chain over 10 years, B-LTA storage reaches 5-8 MB — significant for high-volume archival systems.

TSAlite vs qualified timestamp: legal weight

A TSAlite (non-qualified) timestamp provides evidence of existence but does not receive the presumption of validity under eIDAS Article 41. In EU litigation, only qualified timestamps receive the same evidentiary presumption as QES. Outside the EU, courts evaluate timestamp weight case-by-case regardless of qualification status.

When timestamps matter most: regulatory and evidentiary use cases

Specific scenarios where trusted timestamps are not optional but legally or operationally required.

Regulatory filings with timestamp mandates

EU MiCA (Markets in Crypto-Assets Regulation): requires timestamped records for crypto-asset transactions. FDA 21 CFR Part 11.50: requires date and time stamps for all electronic signature manifestations. China's Electronic Signature Law: timestamps strengthen evidence of signing time but are not mandatory. Singapore MAS guidelines: financial transaction records should include trusted timestamps for audit trails.

Evidence chain and dispute scenarios

In contract disputes, the critical question is often "when was this signed?" A qualified timestamp from an accredited TSA provides presumption of accuracy under eIDAS Article 41. Without a trusted timestamp, the signing time relies on platform server logs — which are less convincing in court. For cross-border agreements where parties are in different time zones, UTC timestamps with timezone conversion records prevent ambiguity.

LTV archival timestamp renewal

For documents requiring decades of verifiability (real estate, patents, government records), PAdES B-LTA archival timestamps must be renewed before each timestamp certificate expires. This creates a chain of timestamps proving the document existed at each point in time. eSign.AI's archival system automates this renewal process, ensuring signatures remain verifiable for the full retention period required by law.

Common questions

A cryptographic proof, issued by a Time Stamping Authority (TSA), that data existed at a specific point in time. The TSA signs a token containing the data hash and the time. Anyone can later verify the token using the TSA's public certificate.

How eSign.AI applies this in practice

eSign.AI embeds RFC 3161 trusted timestamps from accredited TSAs and includes PAdES B-LT validation data in every PDF signature by default, ensuring long-term verifiability.

ทีมกำลังหารือแนวทาง eSignature ที่เหมาะกับธุรกิจ

สำรวจแนวทาง eSignature ที่เหมาะกับธุรกิจของคุณ

พูดคุยกับทีมของเราเกี่ยวกับข้อกำหนด eSignature ประเด็นด้านการปฏิบัติตามกฎระเบียบ และเวิร์กโฟลว์เอกสารในตลาดเป้าหมายของคุณ