Overview
ISO/IEC TR 29149:2012 - "Information technology - Security techniques - Best practices for the provision and use of time‑stamping services" - provides practical guidance for operating and using time‑stamping services so that time‑stamp tokens (TSTs) reliably support timeliness, data integrity, and non‑repudiation. The report complements ISO/IEC 18014 by describing how requesters, time‑stamping authorities (TSAs) and verifiers should behave, which algorithms and parameters to consider, and how to manage token renewal and long‑term verification.
Key technical topics and requirements
- Time‑stamp service lifecycle: generation, renewal and verification of time‑stamp tokens (TSTs) and handling of time‑stamp packets (TSPs).
- Roles and entities: time‑stamp requester, time‑stamp verifier, Time‑Stamping Authority (TSA) and trusted third parties (TTPs).
- Security and trust: recommended good practices for TSAs to deserve trust (operational policies, custody of evidence, service continuity and availability).
- Cryptographic considerations: use and selection of hash functions, message authentication codes (MAC/HMAC) and signature algorithms to ensure TSTs remain verifiable throughout their validity period. The report highlights risks from weak cryptography and guidance on avoiding them.
- TST renewal and verification: procedures for renewing tokens to extend validity and for validating individual TSTs as well as sequences of renewed TSTs.
- Non‑repudiation usage: practical use cases showing how timestamps support evidence generation and verification when combined with digital signatures and policies.
Practical applications and who should use it
ISO/IEC TR 29149 is intended for practitioners implementing or relying on time‑stamping for legal, audit or integrity purposes:
- Time‑Stamping Authorities (TSAs) - operational, policy and cryptographic best practices to earn trust and guarantee service quality.
- PKI and signing service providers - guidance on integrating reliable time‑stamps with digital signatures and certificates.
- Software developers - implementing token generation, renewal and verification workflows.
- Legal, compliance and records management teams - understanding how time‑stamps support non‑repudiation and evidence custody.
- Auditors and security architects - assessing service continuity, evidence retention and cryptographic adequacy.
Related standards
- ISO/IEC 18014 (time‑stamping services specification)
- ISO/IEC 10118 (hash functions)
- ISO/IEC 13888 (non‑repudiation)
- Other PKI and signature standards referenced for certificates and verification procedures
ISO/IEC TR 29149:2012 is a practical resource for organizations that need robust, verifiable time‑stamping to support integrity, auditability and non‑repudiation in digital workflows. Keywords: time‑stamping, time‑stamp tokens, TST, TSA, non‑repudiation, data integrity, timestamp renewal, ISO/IEC 29149:2012.