eIDAS vs. RFC 3161: How Digital Timestamps Work in Europe, the United States and Canada
eIDAS vs. RFC 3161: How Digital Timestamps Work in Europe, the United States and Canada
When we talk about proving that a file existed at a specific point in time, terms such as eIDAS, RFC 3161, timestamp, TSA or qualified electronic timestamp quickly appear.
The problem is that they do not all mean the same thing.
The technology used to cryptographically link a file to a specific date and time can be used almost anywhere in the world. What changes from one country to another is the legal framework that recognises that evidence.
RFC 3161: the technical foundation
RFC 3161 is an international standard for creating cryptographic timestamps.
In simplified form, the process works like this:
file → cryptographic hash → timestamp authority → verifiable timestamp
The timestamp authority — TSA, or Time Stamping Authority — receives the file hash, links it to a date and time, and returns a digitally signed proof.
The original file does not necessarily need to be sent to the TSA.
This makes it possible to verify two fundamental things later: that the file already existed when the timestamp was issued and that it has not been modified since.
RFC 3161 does not belong to the European Union. It is an international technical standard.
So what does eIDAS add?
Europe also has the eIDAS Regulation.
eIDAS defines different trust services and introduces the concept of a qualified electronic timestamp.
This is where an important distinction appears.
An electronic timestamp cannot be denied legal effect simply because it is electronic. But a qualified electronic timestamp also benefits from a legal presumption regarding the accuracy of the date and time and the integrity of the data linked to it.
That is why an RFC 3161 timestamp issued by a qualified European trust service provider can have a particularly strong legal position within the European Union.
The cryptography may be the same. What eIDAS adds is the legal trust framework around it.
What about the United States?
The United States does not have a direct equivalent to the European concept of a qualified electronic timestamp.
Federal E-SIGN legislation establishes that a signature, contract or record cannot lose legal validity simply because it is electronic.
However, this does not create a national category equivalent to the qualified eIDAS timestamp.
An RFC 3161 timestamp can still provide verifiable technical evidence: it can demonstrate that specific data was linked to a cryptographic fingerprint at a particular point in time.
The legal weight given to that evidence depends on the context, the type of proceeding and the applicable law.
For this reason, in the United States it often makes more sense to use terms such as verifiable timestamp, proof of existence or tamper-evident digital evidence rather than “eIDAS”.
What about Canada?
Canada does not have a direct copy of the eIDAS model either.
Canadian legislation recognises different forms of electronic signatures and, for certain uses, a category of secure electronic signature based on public-key cryptography.
The Canadian framework places importance on properties such as document integrity, cryptographic verification and certificate validity.
But again, there is no figure identical to the European qualified electronic timestamp.
One technology, different legal frameworks
This makes the distinction easier to understand.
In Europe, we can have:
RFC 3161 + qualified trust service provider + eIDAS requirements = qualified eIDAS timestamp
Outside Europe, the same RFC 3161 mechanism can still provide verifiable cryptographic evidence, even though its legal effects are assessed under the laws of each country.
The technical proof does not disappear when it crosses a border.
What changes is the legal presumption or evidential weight that each jurisdiction gives to that proof.
What does Sellat do?
Sellat allows you to create verifiable digital evidence without necessarily storing the original file.
For qualified European timestamps, the file is cryptographically linked using SHA-256 to an RFC 3161 timestamp issued by a qualified timestamp authority.
Later, anyone who has the original file and the timestamp can verify that the file matches the certified hash, that the timestamp has not been altered and that the date and time form part of the proof signed by the timestamp authority.
In Europe, when the corresponding qualified service is used, that proof can also benefit from the legal framework provided by eIDAS.
Outside Europe, it remains verifiable cryptographic evidence based on an international standard.
The important difference
There is no real “global eIDAS”.
What exists is something more useful: an international technical standard for proving integrity and existence, combined with different legal frameworks that determine how that evidence is assessed.
In Europe, that framework is eIDAS.
In other countries, the name, legislation and legal effect may be different.
But the cryptographic principle remains the same: being able to prove what file existed and when, without having to rely solely on the person presenting the evidence.
Want to verify a timestamp? You can check a file and its timestamp for free using the Sellat verifier.