Published September 28, 2021 | Version v1
Conference paper Open

Reviewing ISO/IEC Standard for Time-stamping Services

  • 1. University of Surrey

Description

Time-stamping services are used to prove that a data item existed at a given point in time. This proof is represented by a time-stamp token that is created by a time-stamping authority. ISO/IEC 18014 specifies time-stamping services and requires them holding the following two properties: (1) The data being time-stamped is not disclosed to the time-stamping authority, hash values of the data are provided to the authority instead. (2) A time-stamp token can be renewed, as a result the validity duration of a time-stamp token is not restricted by the lifetimes of underlying algorithms or policies. In this paper, we review this standard and discover several issues: Due to inconsistent writing or information missing, a time-stamping service, following the standard specification, may not be able to achieve these designed properties. We provide a solution to each issue.

Files

Reviewing-ISO-IEC-Standard-for-Time-Stamping-Services.pdf

Files (247.0 kB)

Additional details

Funding

European Commission
ASSURED - Future Proofing of ICT Trust Chains: Sustainable Operational Assurance and Verification Remote Guards for Systems-of-Systems Security and Privacy 952697