Overview
ISO/IEC 18014-2:2021/Cor 1:2024 is a Technical Corrigendum to Part 2 of the ISO/IEC 18014 series on information security - time-stamping services. It updates the specification for mechanisms producing independent tokens, clarifying the structure of a time-stamp token and strengthening requirements for a verifiable binding between the hash-codes of data and the point in time. The corrigendum was prepared by ISO/IEC JTC 1/SC 27 (Information security, cyber security, and privacy protection).
Key topics and requirements
- Time-stamp token structure: The corrigendum defines the time-stamp token TST(t) as comprising four components:
- {H(D)} - a set of one or more hash-codes on the data D
- t - the asserted point in time
- C - a verifiable binding between {H(D)} and t
- P - additional token information (as previously defined)
- Verifiable binding (C):
- Must be a valid, verifiable binding between the hash-codes and the time.
- The corrigendum explicitly adds this as a required token element and clarifies its role.
- Protection mechanisms:
- Clause title revised to “Protection mechanisms for verifiable binding.”
- The verifiability of the binding must be satisfied using a protection mechanism that can be chosen by the time-stamp requester and/or imposed by the time-stamping authority (TSA).
- Consistency and evidence:
- The corrigendum reinforces that C provides verifiable evidence linking data fingerprints to a specific timestamp, improving the token’s evidentiary value.
Applications and who uses it
ISO/IEC 18014-2:2021/Cor 1:2024 applies to organizations and practitioners who need trustworthy time-stamping services:
- Time-stamping authorities (TSAs) and service operators implementing independent token mechanisms.
- Security architects and system designers integrating reliable timestamps into applications.
- Software developers building integrity and non-repudiation features.
- Legal, compliance, and audit teams relying on time-stamp evidence for regulatory or forensic purposes.
- Organizations using secure logging, digital notarization, or archival services where provable binding of data to time is required.
Related standards
- ISO/IEC 18014 series (other parts of the time-stamping standard)
- Work by ISO/IEC JTC 1/SC 27 on information security and privacy protection
This corrigendum is essential reading for implementers and evaluators of time-stamping services who require clarity on token composition, verifiability, and protection mechanism responsibilities. Keywords: ISO/IEC 18014-2:2021/Cor 1:2024, time-stamping services, time-stamp token, verifiable binding, independent tokens, information security, time-stamping authority.