Urgent.News

What's breaking now, across thousands of outlets.

Tech

Trusted Timestamps (RFC 3161): How to Anchor a Hash Chain So No One Can Rewrite the Past

A hash chain proves a record was not modified after it was written. It does not prove when it was written, and it does nothing against someone who controls the server and can re-sign the whole chain. RFC 3161 trusted timestamps close that gap. This is a practical look at what they are, how to wire them in, and where the footguns are. The gap a hash chain leaves open If you hash-chain your records…

Hash chains provide a way to ensure the integrity of data by creating a sequence of hashes. Each hash links to the previous one, so altering any record would break the chain. However, a hash chain alone cannot prove when the data was created or stop a server operator from re-signing the entire chain.

RFC 3161 introduces trusted timestamps, which address these limitations. A Time Stamp Authority (TSA) is a trusted third party that vouches for the existence of a specific hash at a particular time. The process involves hashing the data, sending the hash to the TSA, receiving a Time Stamp Token (a CMS signature), and storing the token with the data or at the chain's head.

The TSA only attests to the hash and not the data itself. The timestamp proves the existence of the hash at a specific time, not the data itself. If an attacker controls the server and the signing keys, they cannot forge a valid token for a hash dated before they took over unless they also compromised the TSA.

There are two main strategies for anchoring hashes:

1. Per-record stamping: Stamp every record as it arrives. This provides maximum granularity but requires more TSA calls, suitable for low-volume, high-value events.

2. Periodic chain-head stamping: At regular intervals, stamp the current head hash. This is usually the preferred approach, as it amortizes the TSA calls over many records and still proves the entire chain up to that point.

To implement per-record stamping using Bouncy Castle (Java), generate a request with the SHA-256 algorithm, send it to the TSA, receive the Time Stamp Token, and store the token. For verification, recompute the hash of the data and validate the token against the stored hash and the TSA's root certificate. This ensures the token's authenticity and the integrity of the data at the time of the timestamp.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Sunday 11 October →