ISO/IEC 18014-2:2021
Information security — Time-stamping services — Part 2: Mechanisms producing independent tokens
Information security — Time-stamping services — Part 2: Mechanisms producing independent tokens
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 22
- Дата публикации:
- 9 сентября 2021 г.
- Издание:
- ISO/IEC IS 18014 edition 3 version 1
- ICS:
- 35.030
This document specifies mechanisms that generate, renew, and verify independent time-stamps. In order to verify an independent time-stamp token, time-stamp verifiers do not need access to any other time-stamp tokens. That is, such time-stamp tokens are not linked.
Abstract
Overview
ISO/IEC 18014-2:2021 defines mechanisms for generating, renewing and verifying independent time‑stamp tokens used in information security and time‑stamping services. Unlike linked timestamp schemes, an independent time‑stamp token can be verified on its own - verifiers do not need access to any other time‑stamp tokens. The standard is part of the ISO/IEC 18014 series and references ISO/IEC 18014‑1 (framework) and the ISO/IEC 10118 family for collision‑resistant hash functions.
Key technical topics and requirements
- Time‑stamp token contents: Each token must include one or more hash‑codes of the data, a point in time, and a reference to the applicable time‑stamping policy. Optional but recommended fields include TSA identification, accuracy indication, ordering indication, format version, serial number and a reference to the requester’s request.
- Generation model: Tokens are expressed as the triplet <{H(D)}, t, P> where H(D) is the collision‑resistant hash‑code(s), t is the time value and P is the time‑stamping policy.
- Verification rules: A time‑stamp verifier checks that the token is syntactically correct, that the included hash‑codes match the data, that the cryptographic protection is valid, and that the time value meets the verifier’s acceptance criteria (including any tolerance ε).
- Renewal and renewal verification: The document specifies how independent tokens can be renewed (to extend assurance over time) and how renewal tokens are verified without requiring linkage to prior tokens.
- Protection mechanisms: Multiple integrity/authentication mechanisms are defined, including:
- Digital signatures (SignedData and SignerInfo forms)
- Message authentication codes (MACs) (AuthenticatedData)
- Archival protection methods
- Syntax and encodings: Annex A provides an ASN.1 module for time‑stamping objects; DER encoding is referenced for ASN.1 values. Annex B covers cryptographic syntax.
Practical applications and users
ISO/IEC 18014‑2 is intended for:
- Time‑Stamping Authorities (TSAs) and Time‑Stamping Units (TSUs) implementing timestamp services
- PKI engineers and software developers building timestamp generation and verification tools
- Archivists, records managers and legal/forensic practitioners who require verifiable proof of data existence at a point in time
- Security architects and auditors who assess integrity, non‑repudiation and long‑term evidence preservation
Typical applications include proving document or data existence, securing logs and software artifacts, supporting non‑repudiation and long‑term archival validation workflows.
Related standards
- ISO/IEC 18014‑1 - Information security - Time‑stamping services - Part 1: Framework
- ISO/IEC 10118 series - Collision‑resistant hash‑function standards
- ASN.1 and DER encodings referenced in Annex A (for implementers)
Keywords: ISO/IEC 18014-2, time-stamping, time-stamp tokens, independent tokens, TSA, timestamp verification, digital signatures, MAC, collision-resistant hash-function, ASN.1, DER, time-stamping services.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 18014-2:2021
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 18014-2:2021-TC
ДействующийTracked Changes. Information security. Time-stamping services. Mechanisms producing independent tokens.
ISO/IEC 18014-1:2008/Amd 1:2025
ДействующийInformation technology — Security techniques — Time-stamping services — Part 1: Framework — Amendment 1
Overview ISO/IEC 18014-1:2008/Amd 1:2025 is an amendment to the international standard addressing information technology security techniques specifically for time-stamping services. This amendment up…