Ensuring document immutability and using timestamps

Modified on Tue, 15 Sep at 11:44 AM

The eIDAS requirement for document immutability

As a service providing electronic signatures under the EU eIDAS regulation, SIGNI must ensure document immutability from the moment of signing (see eIDAS, Section IV, Article 26 d), sometimes also referred to as "time-anchoring of the document". In practice this means that after signing, the document must be closed against further changes and provided with an electronic seal and a timestamp.

How does Signi ensure it?

  • The document for signing is created and modified exclusively in the controlled Signi environment. The user cannot influence the data about its changes, e.g. by changing the time on their computer or mobile at the time of signing.
  • The time data about the changes, i.e. who signed the document, when and where, is available to Signi users in the document's so-called Audit trail. This audit trail can then be used, for example, by a forensic expert, or it can be provided to a supervisory authority such as the tax office or the labour office as information about the times of creation and changes to the document.
  • During changes, a so-called "hash" is inserted into the document, which is a condensed content of the document. If someone subsequently changed the content of the document, the manipulation would be detected because the document content would not match its hash. In this case the electronic seal is broken, making it clear that the document content has changed.

Before we mention advanced methods

Before we mention advanced methods of ensuring document immutability, one important thing must be realized. Not all documents are equal even in the paper world:

  • we throw away a receipt from a bakery immediately,
  • many companies store invoices in an office where anyone can steal them or where they can burn in a fire,
  • invoices or delivery notes from ten years back are kept by a company in binders or, even worse, in boxes in a warehouse,
  • only some documents are stored in special archives with security, flood protection and strict fire-prevention measures.

The reason is simple - long-term high-level protection of documents costs money and does not always make business sense. Exactly the same applies in the world of electronic documents.

Advanced methods - timestamps from certification authorities

An advanced way to prove that a document has not changed since the time of signing is the so-called qualified timestamps provided by an independent, state-supervised certification authority.

A timestamp proves that a document already existed at a certain time and in a certain form. How is this ensured?

  1. A timestamp consists of the so-called "document hash", i.e. the content of the document condensed into a long text string + a time value from a qualified trust service provider + the signature of the qualified trust service provider.
  2. The timestamp is created and inserted into the document by the certification authority.
  3. If the document were subsequently changed, its content would not match its hash, which is part of the timestamp. This will again be confirmed by the certification authority.

By design, it is not possible to obtain a timestamp from a previous period from certification authorities and thus backdate a certain state of a document to an earlier date.

How do I verify that a timestamp from an independent certification authority is embedded in the document? For example, in Adobe Reader, the Signature Panel next to the electronic seal will show "The signature includes an embedded timestamp".

Renewing timestamps, electronic seals, or electronic signatures with certificates

Electronic timestamps, seals or signatures with certificates have a limited validity, typically 1 - 5 years. The main reason is the concern that the computing power of computers is growing and the ciphers used could be decrypted by someone, for example after 9 years, and thus retroactively change all the electronic information created with them.

Does this mean that embedded electronic signatures with certificates must be constantly renewed in electronic documents? It does not, and in practice it is not even feasible. For signature certificates, the rule is that if the certificate is valid at the time the document is signed, the document is validly signed. Every signature certificate on a document will eventually expire, but that is fine and has no effect on the validity of the signature or the document.

If we need a high level of certainty that no one has changed the document over time, the document or set of documents must be provided with a continuous series of timestamps valid at the given time.

Ensuring the immutability of a document or set of documents through a sequence of timestamps.

Providing documents or sets of documents with timestamps is handled by so-called "trusted archives". Such a trusted archive, including the function of renewing timestamps, is also provided by Signi. Likewise, companies can store documents from Signi in their own archives, where they also store other documents, for example issued invoices that no one signs. Whether to use an archive and for which documents or sets of documents is then the choice of each company, similar to how it decides whether to keep documents in a binder in an unsecured office, in a safe or in a professional archive.

What happens when ...

...your electronic document is not provided with a timestamp at the time of signing?

  1. You will not be able to prove with 100% certainty when the document was signed. The time on the signer's end device or on the server can be changed. The time value of the timestamp cannot.
  2. Signi is a controlled environment for electronic signing and guarantees the insertion of a qualified timestamp into the document at the moment of signing. Therefore, you will always be able to prove when the document was signed.
  3. If needed, Signi will provide a forensic expert or a supervisory authority with the necessary information about the immutability of the document and the time of closing.

.. you do not repeatedly provide your document or set of documents with valid timestamps?

  • The certification authority - the trust service provider - is obliged to provide information on whether the document, or the certificates it provided for electronic signatures, seals and timestamps, were valid at a certain time.
  • If needed, the certification authority will provide a forensic expert or a supervisory authority with the necessary information about the immutability of the document. In the event of a dispute, the court will take its statement into account, even if the electronic document is not provided with currently valid electronic signatures, seals or timestamps and is therefore not valid at the time of the dispute.
  • However, this may have certain limitations. PDF readers may report that the document is not up to date; it will not be possible to convert the document into paper form if this service requires the current validity of the electronic seal or timestamp.

How to solve long-term archiving of documents signed in Signi

Each signer receives their own original of the electronic document with the electronic signatures. Each signer is then responsible for the long-term archiving of this document - similar to a paper document.

When using Signi there are two options:

  • Use the archiving module in Signi, where documents from Signi are moved after a set period of time.
  • Signi connects to the company archive via the Signi API, where Signi will be one of the sources of archived documents.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article