Sello de tiempo digital (RFC 3161): qué es y por qué tu backup lo necesitaDigital timestamp (RFC 3161): what it is and why your backup needs one
Sin un tercero independiente que certifique la fecha, cualquier documento o backup "demuestra" solo lo que su propio dueño quiere que demuestre. El sello de tiempo cierra esa grieta.
Without an independent third party certifying the date, a document or backup only "proves" whatever its owner wants it to prove. A timestamp closes that gap.
Cuando un backup o un documento firmado tiene que sostenerse frente a un tercero — un auditor, un juez, un cliente — la pregunta que casi siempre surge es: ¿cómo sé que esto se creó cuándo dices que se creó? La respuesta técnica a esa pregunta se llama sello de tiempo digital, y el estándar que la mayoría del mundo usa para implementarla es RFC 3161.
Qué es un sello de tiempo digital
Un sello de tiempo digital es una prueba criptográfica, emitida por una autoridad de tiempo independiente (Time Stamping Authority, TSA), de que un documento — o más exactamente, su huella digital — existía en un momento exacto. La clave está en la palabra "independiente": ni siquiera el propio autor o poseedor del documento puede alterar esa fecha después, porque no depende de su reloj de sistema ni de su palabra, sino de la certificación de un tercero ajeno a él.
Cómo funciona el estándar RFC 3161
A alto nivel, el proceso es sencillo: el cliente calcula el hash (la huella digital) del documento y envía únicamente ese hash a la autoridad de tiempo — nunca el documento completo. Esto es importante: la TSA jamás llega a ver el contenido real, solo una cadena de caracteres que representa de forma única a ese contenido. La autoridad añade la fecha y hora actuales, firma digitalmente ese conjunto, y devuelve un token de sello de tiempo. Cualquiera que tenga el documento original y ese token puede verificar, de forma matemática, que el documento existía tal cual en ese instante — y que no ha cambiado ni un solo byte desde entonces.
Por qué importa para un backup o un documento firmado
Sin sello de tiempo, la fecha de un archivo depende enteramente de metadatos que su propio poseedor controla: el reloj del sistema operativo, las propiedades del archivo, incluso el registro interno de la aplicación que lo generó. En teoría, cualquiera de esos elementos se puede manipular — adelantar o atrasar un reloj y "demostrar" así una fecha que no es real. Con un sello de tiempo de un tercero independiente, esa vía de manipulación queda completamente descartada: la fecha ya no depende de la palabra de quien guarda el documento, sino de la firma criptográfica de una autoridad externa.
Sello simple vs. sello cualificado eIDAS
Conviene distinguir dos niveles. Un sello RFC 3161 simple — gratuito, emitido por servicios de terceros como freetsa.org — ya aporta una prueba real de tiempo de un tercero independiente del interesado, y es perfectamente válido como evidencia técnica en muchos contextos. Un sello cualificado bajo el reglamento eIDAS de la UE, en cambio, lo emite un prestador de servicios de confianza cualificado, tiene un coste asociado, y goza de una presunción legal reforzada de exactitud e integridad ante los tribunales europeos.
Hay que ser honestos: uno no sustituye legalmente al otro por completo. El sello cualificado tiene un respaldo normativo específico que el simple no tiene. Pero el sello simple ya aporta algo que muchísimos sistemas ni siquiera ofrecen — una prueba de tiempo verificable, generada por un tercero que nadie controla, en lugar de una fecha que descansa únicamente en la confianza hacia quien guarda el archivo.
Cómo lo aplica TitanVault
TitanVault sella automáticamente cada informe pericial con RFC 3161 en el momento de su generación, sin pasos manuales. Y lo más importante: cualquier persona puede verificar ese sello de forma completamente independiente, sin depender de la palabra de NyxqLab ni de acceso a nuestros sistemas — la prueba se sostiene por sí misma, con matemáticas, no con confianza.
Preguntas frecuentes
¿Qué es un sello de tiempo digital?
Prueba criptográfica de un tercero independiente de que un documento existía en un momento exacto.
¿Cómo funciona RFC 3161?
Se envía el hash del documento a una autoridad de tiempo, que devuelve un token firmado con la fecha, sin ver nunca el contenido.
¿Sello simple o cualificado eIDAS?
El simple es gratuito y ya aporta prueba de tercero independiente; el cualificado tiene presunción legal reforzada pero tiene coste. No son intercambiables al 100%.
When a backup or a signed document has to hold up in front of a third party — an auditor, a judge, a client — the question that almost always comes up is: how do I know this was created when you say it was? The technical answer is called a digital timestamp, and the standard most of the world uses to implement it is RFC 3161.
What a digital timestamp is
A digital timestamp is a cryptographic proof, issued by an independent time authority (Time Stamping Authority, TSA), that a document — or more precisely, its fingerprint — existed at an exact moment. The key word is "independent": not even the document's own author or holder can alter that date afterward, because it doesn't depend on their system clock or their word, but on the certification of an unrelated third party.
How the RFC 3161 standard works
At a high level, the process is simple: the client computes the document's hash (its digital fingerprint) and sends only that hash to the time authority — never the full document. This matters: the TSA never actually sees the real content, just a string that uniquely represents it. The authority adds the current date and time, digitally signs that bundle, and returns a timestamp token. Anyone holding the original document and that token can mathematically verify that the document existed exactly as-is at that instant — and hasn't changed by a single byte since.
Why it matters for a backup or signed document
Without a timestamp, a file's date depends entirely on metadata its own holder controls: the OS clock, file properties, even the generating application's internal log. In theory, any of those can be manipulated — moving a clock forward or back to "prove" a false date. With a timestamp from an independent third party, that manipulation path is completely closed off: the date no longer rests on the word of whoever holds the document, but on the cryptographic signature of an external authority.
Simple timestamp vs. qualified eIDAS timestamp
Two levels are worth distinguishing. A simple RFC 3161 timestamp — free, issued by third-party services like freetsa.org — already provides real proof of time from a party independent of the interested one, and is perfectly valid technical evidence in many contexts. A qualified timestamp under the EU's eIDAS regulation, by contrast, is issued by a qualified trust service provider, comes at a cost, and carries a reinforced legal presumption of accuracy and integrity before European courts.
To be honest: one doesn't fully legally replace the other. The qualified timestamp has specific regulatory backing that the simple one lacks. But the simple timestamp already provides something many systems don't even offer — verifiable proof of time, generated by a third party nobody controls, instead of a date that rests solely on trust in whoever holds the file.
How TitanVault applies it
TitanVault automatically timestamps every expert report with RFC 3161 at the moment it's generated, no manual steps needed. And most importantly: anyone can verify that timestamp completely independently, without relying on NyxqLab's word or access to our systems — the proof stands on its own, on math, not trust.
FAQ
What is a digital timestamp?
Cryptographic proof from an independent third party that a document existed at an exact moment.
How does RFC 3161 work?
The document's hash is sent to a time authority, which returns a signed token with the date, without ever seeing the content.
Simple or qualified eIDAS timestamp?
The simple one is free and already provides independent third-party proof; the qualified one has reinforced legal presumption but costs money. They aren't 100% interchangeable.