ISO 14533-4:2019
Processes, data elements and documents in commerce, industry and administration — Long term signature profiles — Part 4: Attributes pointing to (external) proof of existence objects used in long term signature formats (PoEAttributes)
Processes, data elements and documents in commerce, industry and administration — Long term signature profiles — Part 4: Attributes pointing to (external) proof of existence objects used in long term signature formats (PoEAttributes)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 37
- Дата публикации:
- 27 августа 2019 г.
- Издание:
- ISO IS 14533 edition 1 version 1
- ICS:
- 35.240.63
This document specifies the elements defined in the international standards of ISO/ITU-T, ETSI and IETF RFC that enable at least a proof of existence of data objects and digital signatures and the preservation of the validity status of digital signatures over a long period of time used in validation. It provides the definitions of the proof of existence (PoE) attributes and clarification of the usage of (external) PoE objects, with digital signatures and trusted time values, which have already existed and can be used by the PoE attributes pointing to (external) PoE objects used in long term signature validation or preservation.
Abstract
Overview
ISO 14533-4:2019 - Part 4 of the ISO 14533 series - defines PoEAttributes: attributes that point to (external) proof of existence (PoE) objects used in long term signature formats. The standard clarifies how existing objects from IETF, ETSI and ISO/ITU-T (for example RFC 3161 timestamps, RFC 4998 evidence records, OCSP responses) can be referenced and used to preserve and validate the integrity and validity status of digital signatures over long periods (long-term integrity, LTI).
This part supports interoperability for long-term signature validation and preservation by specifying attribute types, object references, and normative syntax elements (including an ASN.1 module and annexes describing CertHash OCSP extensions, container locations, and evidence record syntax).
Key technical topics and requirements
- PoEAttribute concept: Defines an attribute that links data objects (documents, signatures) to external PoE objects which provide trusted time, integrity and status evidence.
- Attribute instances:
- LTI PoEAttribute (based on IETF RFC 3161 timestamps or RFC 4998 / RFC 6283 evidence records)
- ERS PoEAttribute (Evidence Record Syntax based)
- TStOCSP PoEAttribute (timestamp via OCSP)
- Supporting attributes:
- PoEHashIndex
- preservation-integrity-list
- Object identifiers and indirect identifiers: Definitions for DId (document identifier), DSId (document signature identifier) and DTId (document type identifier) for unambiguous referencing and machine processing.
- Types of PoE objects: Essential fields and supported PoE object types (e.g., status at thisUpdate OCSP objects, timestamp/evidence-record based objects).
- Normative elements and annexes: ASN.1 module, CertHash OCSP SingleResponse extension, syntax for embedding PoE objects in ZIP/PDF/DER containers and evidence record syntax (RFC references included).
- Normative references: IETF RFC 3161, 4998, 6283, 6960; ISO/IEC 8825-1; ISO 32000-2; IETF RFC 5652; ETSI and other relevant profiles.
Practical applications and who uses this standard
- Long-term digital signature preservation: Archivists, digital repositories, and records managers use PoEAttributes to maintain proof that a signature and document existed and remained valid at particular times despite evolving cryptographic algorithms.
- PKI and signature software vendors: Implementors integrate PoEAttributes into signature formats (CAdES, PDF, CMS-based profiles) to reference external timestamps, evidence records and OCSP proofs.
- Compliance and legal technology: Legal and compliance teams rely on standardized PoE references to demonstrate signature validity and non-repudiation over time.
- Interoperability testing and systems integrators: Ensures consistent validation semantics across implementations that consume RFC-based timestamps, evidence records or OCSP responses.
Related standards
- ISO 14533 series (long term signature profiles)
- IETF RFC 3161 (Timestamp Protocol), RFC 4998 / RFC 6283 (Evidence Record Syntax), RFC 6960 (OCSP), RFC 5652 (CMS)
- ISO/IEC 8825-1 (ASN.1 BER/CER/DER), ISO 32000-2 (PDF 2.0)
- ETSI specifications referenced in the document
Keywords: ISO 14533-4:2019, PoEAttributes, proof of existence, long term signature, long-term preservation, evidence record, RFC 3161, RFC 4998, OCSP, digital signature validation.
Технические детали
- Технический комитет
- ISO/TC 154 - Processes, data elements and documents in commerce, industry and administration
- SKU
- ISO 14533-4:2019
Похожие стандарты
Стандарты, упомянутые в описании