Trusted timestamping is the process of securely recording the time at which a piece of data existed, using a trusted third party that cryptographically binds a hash of the data to an authoritative time and signs the result. Standardised by RFC 3161, it produces a timestamp token that proves data integrity and existence-by-time without revealing the data, and is used in digital signatures, legal record-keeping, intellectual-property protection, and regulatory compliance. It establishes a verifiable temporal ordering that survives even after signing keys expire.
Content
- Trusted timestamping answers a question that ordinary file metadata cannot answer credibly: when did this data demonstrably exist? A filesystem timestamp is trivially forgeable, but a trusted timestamp is backed by a third party whose signed assertion, anchored to a reliable clock, is difficult to repudiate. This converts a claim about timing into evidence that holds up to scrutiny in audits, disputes, and legal proceedings.
- The standard protocol, RFC 3161, is privacy-preserving by design. The client computes a cryptographic hash of its document and sends only that hash to a Time-Stamping Authority; the authority never sees the underlying content. The authority appends its current trusted time, signs the hash-and-time combination, and returns a token. Anyone can later re-hash the document and verify the authority’s signature to confirm both that the document is unaltered and that it existed by the stated time.
- Trust concentrates in the authority’s clock and signing key, so reputable services traceably synchronise their clocks to national time standards and protect signing keys in hardware security modules. Some implementations chain or aggregate timestamps — linking tokens together or publishing periodic Merkle roots — so that even a later compromise of the authority cannot retroactively alter the established ordering, strengthening the guarantee beyond a single signature.
- The most important practical role of trusted timestamping is preserving the long-term validity of digital signatures. A signature is only verifiable while its certificate is valid and its key uncompromised, but documents must often remain provably authentic for decades. A trusted timestamp applied at signing time proves the signature existed while the certificate was valid, so the signature retains evidential weight long after the key expires — the foundation of long-term archival signature formats mandated in many regulatory and governmental record-keeping regimes.