A Timestamp Authority (TSA) is a trusted third party that issues cryptographically signed timestamps attesting that a particular piece of data existed at or before a specified point in time, in accordance with the RFC 3161 Internet X.509 Public Key Infrastructure Time-Stamp Protocol. The TSA receives a hash of the document or data, signs it together with the current time using its private key, and returns a TimeStampToken that can be independently verified by any party holding the TSA’s public key certificate. Timestamp tokens are widely used in digital signature workflows to prove long-term validity—establishing that signatures were made before certificate revocation or expiry. Under eIDAS regulation in Europe, qualified TSAs form part of trust service infrastructure with legal standing equivalent to notarisation.
Content
- The RFC 3161 protocol operates as a simple request-response exchange: the client computes a cryptographic hash of the data to be timestamped (SHA-256 is typical), sends a TimeStampRequest containing the hash and a policy OID to the TSA, and receives a TimeStampResponse containing the signed TimeStampToken. The token embeds the hash, the time of signing (in UTC), the TSA’s certificate chain, and a sequence number for non-repudiation. The token can be stored alongside the document and verified independently without communicating with the TSA again.
- Under the eIDAS Regulation (EU 910/2014) and its successor eIDAS 2.0, qualified electronic timestamps issued by Qualified Trust Service Providers (QTSPs) carry a legal presumption of accuracy of the time and integrity of the data to which they refer. This gives them legal equivalence to notarised timestamps in many EU member states and enables their use in regulated workflows including electronic contracting, customs declarations, and healthcare record archiving. ETSI TS 119 421 provides technical requirements for qualified TSA operation.
- Blockchain-based timestamping represents an alternative to traditional TSA infrastructure, using the immutability and decentralisation of distributed ledgers to anchor document hashes in publicly verifiable block data. Bitcoin’s OpenTimestamps protocol uses Bitcoin block headers as timestamp proofs, providing censorship-resistant, trust-minimised timestamping without reliance on a central TSA. However, blockchain timestamps lack the legal standing of qualified eIDAS timestamps and have confirmation latency determined by block times.
- Long-term archival scenarios require careful management of TSA certificate expiry. As TSA certificates approach their end of life, archived timestamp tokens must be re-timestamped before expiry to preserve verifiability—a process called timestamp renewal or re-timestamping. Standards-based document formats including PDF/A-3 with PAdES baseline signatures and XML-based XAdES integrate TSA tokens natively and define long-term validation data structures that embed the entire certificate chain and revocation evidence needed for future verification without online lookups.