eSign.AIeSign.AI

คู่มือโซลูชัน

หมายเหตุเวลาที่มีคุณสมบัติและการรับรองการลงนามยาวนาน

หมายเหตุเวลาที่น่าเชื่อถือแสดงว่าหมายเหตุเวลาถูกใช้เมื่อไหร่ นี่คือวิธีที่หมายเหตุเวลาที่มีคุณสมบัติทำงานและทำไม่ใช่มันสำคัญสำหรับหลักฐานยาวนาน

ทีมโซลูชัน eSign.AIอ่าน 7 นาที

ทำไมลงลายมือชื่อที่ไม่มีหลักฐานเวลาจะมีวันหมดอายุ

ลงลายมือชื่อดิจิตอลขึ้นอยู่กับหนังสือรับรองที่ออกโดยหน่วยรับรองหนังสือรับรอง (CA) หนังสือรับรองนี้มีระยะอายุที่เหมาะสม —โดยทั่วไปคือ 1 ถึง 5 ปี หลังจากวันหมดอายุ ลงลายมือชื่อจะไม่สามารถตรวจสอบได้ด้วยเครื่องมือมาตรฐาน แม้ว่าลงลายมือชื่อนั้นจะมีความถูกต้องเมื่อมีการใช้งาน หลักฐานเวลาที่มีความเชื่อถือจากหน่วยรับรองหลักฐานเวลา (TSA) แก้ปัญหานี้: มันบันทึกว่าลงลายมือชื่อนั้นมีอยู่ก่อนที่หนังสือรับรองจะหมดอายุ ทำให้ลงลายมือชื่อสามารถตรวจสอบได้ตลอดไป

RFC 3161

มาตรฐานหลักฐานเวลาที่มีความเชื่อถือ

TSA

หน่วยรับรองหลักฐานเวลา

ระดับ T / LT / LTA

ระดับ LTV ของ PAdES/XAdES

ไม่จำกัด

ระยะการตรวจสอบกับ LTV

ลงลายมือชื่อที่มีและไม่มีหลักฐานเวลาที่มีความเชื่อถือ

Without timestampWith qualified timestamp
ระยะการตรวจสอบเฉพาะระหว่างหนังสือรับรองมีผลบังคับไม่จำกัด —สามารถตรวจสอบได้หลังหนังสือรับรองหมดอายุ
หลักฐานเวลาบันทึกบันเทิงของเซิร์ฟเวอร์ (หลักฐานที่ไม่มีความเชื่อถือ)หลักฐานเวลาที่ทำปิดด้วยการลงลายมือชื่อของ TSA
ความสามารถในการนำเสนอต่อศาลลดลงหลังหนังสือรับรองหมดอายุรักษาไว้ตลอดไป
Best forการโดยสารระยะสั้นContracts, compliance records, archival

How a trusted timestamp works

A TSA timestamp is not just a date string — it is a cryptographic proof that specific signed data existed at a specific time.

01

After the signer applies their digital signature, the signing platform computes a cryptographic hash of the signed data (document + signature).

02

The hash is sent to a Time Stamping Authority. The TSA does not see the document — only the hash. This preserves document confidentiality.

03

The TSA creates a timestamp token (RFC 3161 format) that binds the hash to the TSA's clock. The token is signed by the TSA's qualified certificate.

04

The timestamp token is embedded in the signed document (e.g. as a PAdES Level T signature). Future validators can verify that the signature existed at the TSA's timestamped time.

Qualified timestamp vs advanced timestamp

Advanced electronic timestamp

An advanced timestamp binds the data to a time in a way that prevents undetected alteration. It does not require a qualified TSA certificate. Acceptable as evidence but does not carry the eIDAS legal presumption.

Qualified electronic timestamp

A qualified timestamp is issued by a qualified TSA (QTSP-accredited) using a qualified certificate. Under eIDAS Article 41, a qualified electronic timestamp enjoys the presumption of the accuracy of the date and time it indicates, and the integrity of the data to which the date and time are bound.

Why qualified matters for legal evidence

For contracts that may need enforcement in EU courts years after signing, a qualified timestamp ensures the timing evidence holds up. Non-qualified timestamps are admissible but may be challenged on the accuracy of timing.

Implementing LTV in your signing workflow

To ensure signatures remain verifiable for the full retention period, configure your signing platform with these settings.

01

Enable TSA timestamping

Configure the signing platform to request a timestamp from a qualified TSA for every signed document. Most platforms support TSA configuration out of the box.

02

Set PAdES/XAdES level to LT or LTA

Level LT embeds validation material (certificates, CRLs, OCSP responses) in the document. Level LTA adds periodic archival timestamps for ultra-long-term records.

03

Configure revocation checking

Ensure the platform fetches and embeds CRL or OCSP responses at signing time. This proves the certificate was not revoked when the signature was applied.

04

Test long-term validation

Use a validation tool (e.g. DSS Demo WebApp, Adobe Reader signature validation) to verify the signed document passes LTV checks. The validation report should confirm the timestamp and embedded validation material.

05

Set retention policy

Define how long signed documents must be retained. For regulated industries, this may be 7-10 years or longer. Ensure storage can accommodate signed documents with embedded LTV material.

How eSign.AI implements trusted timestamps and LTV

eSign.AI embeds RFC 3161 trusted timestamps and LTV data in every signed document by default.

Timestamp from accredited TSA

Every eSign.AI signature includes a trusted timestamp from an accredited Time Stamping Authority. The timestamp proves the signature existed at a specific time — essential for long-term enforceability.

PAdES B-LT by default

All PDF signatures produced by eSign.AI include PAdES Baseline B-LT data: signing certificate, certificate chain, revocation data, and timestamp. This ensures signatures remain verifiable after certificate expiry.

Frequently asked questions

Without a trusted timestamp, the signature may become unverifiable after certificate expiry — a validator cannot confirm the signature was created during the certificate's validity window. With a qualified timestamp, the validator can confirm the signature predated expiry, so it remains valid indefinitely.

ทีมกำลังหารือแนวทาง eSignature ที่เหมาะกับธุรกิจ

สำรวจแนวทาง eSignature ที่เหมาะกับธุรกิจของคุณ

พูดคุยกับทีมของเราเกี่ยวกับข้อกำหนด eSignature ประเด็นด้านการปฏิบัติตามกฎระเบียบ และเวิร์กโฟลว์เอกสารในตลาดเป้าหมายของคุณ