มาตรฐานหลักฐานเวลาที่มีความเชื่อถือ
ทำไมลงลายมือชื่อที่ไม่มีหลักฐานเวลาจะมีวันหมดอายุ
ลงลายมือชื่อดิจิตอลขึ้นอยู่กับหนังสือรับรองที่ออกโดยหน่วยรับรองหนังสือรับรอง (CA) หนังสือรับรองนี้มีระยะอายุที่เหมาะสม —โดยทั่วไปคือ 1 ถึง 5 ปี หลังจากวันหมดอายุ ลงลายมือชื่อจะไม่สามารถตรวจสอบได้ด้วยเครื่องมือมาตรฐาน แม้ว่าลงลายมือชื่อนั้นจะมีความถูกต้องเมื่อมีการใช้งาน หลักฐานเวลาที่มีความเชื่อถือจากหน่วยรับรองหลักฐานเวลา (TSA) แก้ปัญหานี้: มันบันทึกว่าลงลายมือชื่อนั้นมีอยู่ก่อนที่หนังสือรับรองจะหมดอายุ ทำให้ลงลายมือชื่อสามารถตรวจสอบได้ตลอดไป
หน่วยรับรองหลักฐานเวลา
ระดับ LTV ของ PAdES/XAdES
ระยะการตรวจสอบกับ LTV
ลงลายมือชื่อที่มีและไม่มีหลักฐานเวลาที่มีความเชื่อถือ
| Without timestamp | With qualified timestamp | |
|---|---|---|
| ระยะการตรวจสอบ | เฉพาะระหว่างหนังสือรับรองมีผลบังคับ | ไม่จำกัด —สามารถตรวจสอบได้หลังหนังสือรับรองหมดอายุ |
| หลักฐานเวลา | บันทึกบันเทิงของเซิร์ฟเวอร์ (หลักฐานที่ไม่มีความเชื่อถือ) | หลักฐานเวลาที่ทำปิดด้วยการลงลายมือชื่อของ TSA |
| ความสามารถในการนำเสนอต่อศาล | ลดลงหลังหนังสือรับรองหมดอายุ | รักษาไว้ตลอดไป |
| Best for | การโดยสารระยะสั้น | Contracts, compliance records, archival |
How a trusted timestamp works
A TSA timestamp is not just a date string — it is a cryptographic proof that specific signed data existed at a specific time.
After the signer applies their digital signature, the signing platform computes a cryptographic hash of the signed data (document + signature).
The hash is sent to a Time Stamping Authority. The TSA does not see the document — only the hash. This preserves document confidentiality.
The TSA creates a timestamp token (RFC 3161 format) that binds the hash to the TSA's clock. The token is signed by the TSA's qualified certificate.
The timestamp token is embedded in the signed document (e.g. as a PAdES Level T signature). Future validators can verify that the signature existed at the TSA's timestamped time.
Qualified timestamp vs advanced timestamp
Advanced electronic timestamp
An advanced timestamp binds the data to a time in a way that prevents undetected alteration. It does not require a qualified TSA certificate. Acceptable as evidence but does not carry the eIDAS legal presumption.
Qualified electronic timestamp
A qualified timestamp is issued by a qualified TSA (QTSP-accredited) using a qualified certificate. Under eIDAS Article 41, a qualified electronic timestamp enjoys the presumption of the accuracy of the date and time it indicates, and the integrity of the data to which the date and time are bound.
Why qualified matters for legal evidence
For contracts that may need enforcement in EU courts years after signing, a qualified timestamp ensures the timing evidence holds up. Non-qualified timestamps are admissible but may be challenged on the accuracy of timing.
Implementing LTV in your signing workflow
To ensure signatures remain verifiable for the full retention period, configure your signing platform with these settings.
Enable TSA timestamping
Configure the signing platform to request a timestamp from a qualified TSA for every signed document. Most platforms support TSA configuration out of the box.
Set PAdES/XAdES level to LT or LTA
Level LT embeds validation material (certificates, CRLs, OCSP responses) in the document. Level LTA adds periodic archival timestamps for ultra-long-term records.
Configure revocation checking
Ensure the platform fetches and embeds CRL or OCSP responses at signing time. This proves the certificate was not revoked when the signature was applied.
Test long-term validation
Use a validation tool (e.g. DSS Demo WebApp, Adobe Reader signature validation) to verify the signed document passes LTV checks. The validation report should confirm the timestamp and embedded validation material.
Set retention policy
Define how long signed documents must be retained. For regulated industries, this may be 7-10 years or longer. Ensure storage can accommodate signed documents with embedded LTV material.
How eSign.AI implements trusted timestamps and LTV
eSign.AI embeds RFC 3161 trusted timestamps and LTV data in every signed document by default.
Timestamp from accredited TSA
Every eSign.AI signature includes a trusted timestamp from an accredited Time Stamping Authority. The timestamp proves the signature existed at a specific time — essential for long-term enforceability.
PAdES B-LT by default
All PDF signatures produced by eSign.AI include PAdES Baseline B-LT data: signing certificate, certificate chain, revocation data, and timestamp. This ensures signatures remain verifiable after certificate expiry.
Frequently asked questions
Without a trusted timestamp, the signature may become unverifiable after certificate expiry — a validator cannot confirm the signature was created during the certificate's validity window. With a qualified timestamp, the validator can confirm the signature predated expiry, so it remains valid indefinitely.







