Overview
ISO 14533-1:2022 specifies profiles for long term signatures based on CMS Advanced Electronic Signatures (CAdES). The standard defines the required elements, data structures and document-level requirements that enable digital signatures to remain verifiable over long periods without changing the underlying signature algorithms. It focuses on interoperability for long-term validation (LTV) by defining two CAdES profiles - CAdES‑T (signature with signing time evidence) and CAdES‑A (archival signatures with information to detect illegal alterations) - and guidance on time-stamping and validation data inclusion.
Key topics and requirements
- Profiles for long term signatures: Defines the CAdES‑T and CAdES‑A profiles to ensure signing time is identifiable and signature-related information (including validation data) can be checked over time.
- Required levels: Uses four requirement levels - M (Mandatory), C (Conditional), O (Optional), P (Prohibited) - to specify which CMS/CAdES elements must be implemented for each profile.
- Signed vs unsigned attributes: Clarifies handling of signed attributes (part of the signature) and unsigned attributes (e.g., signature time‑stamp and archive time‑stamp).
- Time-stamping and TSAs: Specifies use of time-stamp tokens (TSTs) from a Time-Stamping Authority (TSA) to provide proof of existence and signing time; includes references to archive time-stamps used in long-term preservation.
- Validation data: Requires inclusion or linkage to certificate and revocation information (validation data) so signatures remain verifiable as certificate and CRL/OCSP status change.
- Updates in 2022 edition: Adds a new archive time-stamp format archive-time-stamp-v3 (ATSv3) and an associated attribute ats-hash-index-v3, plus alignment with methods from ISO 14533‑4.
Applications
- Ensuring digital signatures remain provably valid for legal, regulatory and archival purposes (e.g., long-term record keeping, e‑government, banking, contracts).
- Implementing long-term validation (LTV) workflows in signing and verification software.
- Designing archival solutions that require tamper-evident signature preservation and periodic timestamping.
Who should use this standard
- Software developers and vendors of signing/verification tools
- PKI operators, Certification Authorities (CAs) and Time‑Stamping Authorities (TSAs)
- Records managers, archivists and compliance officers
- Security architects and systems integrators implementing long-term digital signature solutions
Related standards
- IETF RFC 5652 - Cryptographic Message Syntax (CMS)
- ETSI EN 319 122‑1 - CAdES digital signature definitions
- ISO 14533‑4 - Attributes pointing to external proof-of-existence objects (PoEAttributes)
Keywords: ISO 14533-1:2022, long term signature, CAdES, CMS, CAdES‑T, CAdES‑A, time-stamp, TSA, archive time-stamp, long-term validation, digital signature verification.