TSA · DIGITAL TRUST PRODUCT / SOLUTION PROFILE

Trusted PQC TSA & Long-Term Evidence
Controlled pilot

Preserve trusted time, validation material and renewal evidence across algorithm and certificate lifecycles.

CUSTOMER PROBLEM

Preserve trusted time, validation material and renewal evidence across algorithm and certificate lifecycles.

Long-lived documents need trusted time, revocation material and renewal evidence that survive certificate expiry and future algorithm transitions.

Controlled pilot
Portfolio class
Digital trust product / solution profile
Public profile
2026.07
Version rule
Confirmed in quotation / release record

PRODUCT-SPECIFIC IMPLEMENTATION FLOW

How Trusted PQC TSA & Long-Term Evidence operates from input to evidence.

TSA, OCSP/CRL, evidence stores, signing services and long-term verification. Timestamp samples, validation reports, renewal tests and trusted-time control records.

01

Receive hash and timestamp policy

RFC 3161 timestamp service profiles

02

Validate request and trusted time

PAdES/CAdES/XAdES LT and LTA

03

HSM signs RFC 3161 token

OCSP/CRL evidence embedding

04

Embed certificate and status evidence

Archive timestamp and evidence renewal

05

Verify LT/LTA completeness

Trusted-time source and HSM controls

06

Renew evidence before expiry or weakness

Verification after certificate or algorithm transition

NAMED COMPONENTS AND RESPONSIBILITIES

What Trusted PQC TSA & Long-Term Evidence contains and what each component does.

The descriptions below state concrete technical behaviour rather than generic support language.

01

RFC 3161 timestamp service profiles

Defines RFC 3161 policies, accepted hash algorithms, request validation, serial handling, accuracy, ordering and response profiles.

02

PAdES/CAdES/XAdES LT and LTA

Builds PAdES, CAdES and XAdES LT/LTA evidence with certificates, OCSP/CRL responses, timestamp chains and validation context.

03

OCSP/CRL evidence embedding

Captures revocation evidence at the correct validation time and records how unavailable or stale status information is handled.

04

Archive timestamp and evidence renewal

Schedules archive timestamp or evidence renewal before certificates, algorithms or status records become unsuitable for future validation.

05

Trusted-time source and HSM controls

Protects TSA signing keys in HSMs and monitors trusted-time sources, drift, redundancy, alarms and continuity procedures.

06

Verification after certificate or algorithm transition

Replays verification after certificate expiry, CA/TSA rollover and algorithm transition to prove that preserved evidence remains usable.

CUSTOMER OUTCOMES
  • Timestamp profile design
  • PAdES/CAdES/XAdES LT/LTA
  • Archive renewal policy
INTEGRATION BOUNDARY

TSA, OCSP/CRL, evidence stores, signing services and long-term verification.

DEPLOYMENT PATTERNS

On-premises trust service

CA, signing, TSA or release components run in a customer-controlled trust boundary with protected keys.

Dedicated private platform

Service components run in a dedicated private-cloud or appliance topology with HSM/QSCD integration.

Coexistence migration

Classical and target profiles are introduced in phases with relying-party testing, evidence and rollback gates.

EVIDENCE REQUIRED
  • Timestamp samples, validation reports, renewal tests and trusted-time control records.
  • Version and configuration manifest for: TSA, OCSP/CRL, evidence stores, signing services and long-term verification.
  • Negative, failure and recovery tests for “Verify LT/LTA completeness” and “Renew evidence before expiry or weakness”.
  • Signed acceptance record, accountable owner, published limitations and next review date.
STANDARDS & PROFILES
  • RFC 3161
  • ETSI PAdES / CAdES / XAdES
  • OCSP / CRL
  • Evidence renewal and archive timestamp profiles

PRODUCT-SPECIFIC BOUNDARIES

Conditions that must remain true for Trusted PQC TSA & Long-Term Evidence.

These points come from the product profile, not from a shared disclaimer.

NEXT STEP

Define a controlled pilot: Trusted PQC TSA & Long-Term Evidence

Select one application, exact versions, measurable acceptance criteria and rollback.