US5136646A — Digital document time-stamping with catenate certificate

Bitcoin Research — Law, Regulation, Markets & Origins (2026)

Patents

1991-03-08

Document text

Research, not advice. Part of the Bitcoin research archive (October 2026). Claims labelled unverified, contested or fringe are reported, not endorsed; statuses of bills and rules are as of the date checked. Government, court and patent records are public domain; the research notes are CC BY 4.0.

USOO5136646A
United States Patent (19)                                                          11) Patent Number:                5,136,646
Haber et al.                                                                       45) Date of Patent:              Aug. 4, 1992
54 DIGITAL DOCUMENT TIME-STAMPING                                            Attorney, Agent, or Firm-Leonard Charles Suchyta;
       WITH CAT ENATE CERT FICATE                                            Lionel N. White
75) Inventors: Stuart A. Haber, New York, N.Y.;                              57.                  ABSTRACT
                        Wakefield S. Stornetta, Jr.,                         A system for time-stamping a digital document, for
                        Morristown, N.J.                                     example any alphanumeric, video, audio, or pictorial
73) Assignee: Bell Communications Research, Inc.,                            data, protects the secrecy of the document text and
              Livingston, N.J.                                               provides a tamper-proof time seal establishing an au
(21) Appl. No.: 666,896                                                      thor's claim to the temporal existence of the document.
                                                                             Initially, the document may be condensed to a single
(22 Filed:         Mar. 8, 1991                                              number by means of a one-way hash function, thereby
                                                                             fixing a unique representation of the document text. The
 51) Int, C. .......................... H04L 9/00; H04L 9/30                 document representation is transmitted to an outside
 52 U.S. C. ........................................ 380/49; 380/23;         agency where the current time is added to form a re
                                                      380/25; 380/30         ceipt. The agency then certifies the receipt by adding
 58) Field of Search ........................................ 380/3-5,       and hashing the receipt data with the current record
                                     380/9, 10, 28, 30, 49, 50               catenate certificate which itself is a number obtained as
56)                       References Cited                                   a result of the sequential hashing of each prior receipt
                                                                             with the extant catenate certificate. The certified re
             U.S. PATENT DOCUMENTS                                           ceipt bearing the time data and the catenate certificate
      4,145,568 3/1979 Ehrat ................................ 380/50 X       number is then returned to the author as evidence of the
      4,625,076 11/1986 Okamoto et al. ...                ... 380/30 X       document's existence. In later proof of such existence,
      4,868,877 9/1989 Fischer .....                       ... 380/30 X      the certificate is authenticated by repeating the certifi
      4,881,264. 11/1989 Merkle.                                380/50 X.    cation steps with the representation of the alleged docu
      4,972,474 11/1990 Sabin ..................................... 380/28   ment, the alleged time data, and the catenate certificate
      5,001,752 3/1991 Fischer ............................. 380/30 X        number appearing in the agency's records immediately
                 OTHER PUBLICATIONS                                          prior to the certificate number in question. Only if the
"The MD4 Message Digest Algorithm", R. L. Rivest,                            alleged document is identical to the original document
Crypto '90 Abstracts, Aug. 1990, pp. 281-291.                                will the original and repeat certificate numbers match.
Primary Examiner-Bernarr E. Gregory                                                        13 Claims, 2 Drawing Sheets
U.S. Patent   Aug. 4, 1992            Sheet 1 of 2             5,136,646
                                                          11
                               Author Prepares
                               Digital Document

                       f------------------- - 12
                                   Document           r
                                  Condensed
                                 e.g., Hashed

                             DOCunent TranSmitted
                                     TO TSA

                                   TSAAdds
                                 Time Data TO
                                 Create Receipt

                                   TSAAdds
                              Receipt To Current
                                 Catenate Value

                                  TSA HaShes
                             Composite To Create
                              New Catenate Value

                              TSA TranSmits New
                                Cafenate Value. In
                              Certificate To Author

        FIG. 1
U.S. Patent   Aug 4, 1992           Sheet 2 of 2    5,136,646
                               Obtain Present
                                 DOCunent
                               Representation

                               Add Cafenate
                                  Value For
                             Previous DOCunent

                            Hash Composite To
                            Create Catenate Value
                            For Present DOCunent

                                Obtain Next
                                 DOCument
                               Representation

                               Add Cafenate
                                 Value For
                             Present DOCurrent

                            Hash Composite. To
                            Create Cafenate Value
                             For Next DOCurrent

        FIG. 2
                                                    5,136,646
                                                                                           2
                                                               substantially unlimited number of system subscribers
 DIGITAL DOCUMENT TIMESTAMPING WITH                            who are unknown to one another, but for a public direc
            CATENATE CERTFCATE                                 tory, verifiable communications remain bilateral. These
                                                               limitations persist, since although a public key, "signa
     BACKGROUND OF THE INVENTION                           5ture", such as that which entails public key decryption
  In many situations there is a need to establish the date of a message encrypted with the private key of the
on which a document was created and to prove that the transmitter, provides any member of the unlimited uni
text of a document in question is in fact the same as that verse with significant evidence of the identity of the
of the original dated document. For example, in intel O transmitter of the message, only a given message recipi
lectual property matters it is often crucial to verify the ent can be satisfied that the message existed at least as
date on which a person first put into writing the sub early as the time of its receipt Such receipt does not,
stance of an invention. A common procedure for thus however, provide the whole universe with direct evi
"time-stamping" an inventive concept comprises daily dence of time of the message's existence Testimony of a
notations of one's work in a laboratory notebook. Indel such a recipient in conjunction with the received mes
ibly dated and signed entries are made one after another 15 sage could advance the proof of message content and
on each page of the notebook where the sequentially time of its existence, but such evidence falls victim to
numbered, sewn-in pages make it difficult to revise the the basic problem of ready manipulation of electronic
record without leaving telltale signs. The validity of the digital document content, whether by originator or
record is further enhanced by the regular review and witness
signed witnessing by a generally disinterested third           Thus, the prospect of a world in which all documents
party. Should the time of the concept become a matter are in easily modifiable digital form threatens the very
for later proof, both the physical substance of the note substance of existing procedures for establishing the
book and the established recording procedure serve as credibility of such documents. As a means of providing
effective evidence in substantiating the fact that the 25 an answer to this burgeoning problem, we disclosed in
concept existed at least as early as the notebook witness our copending U.S. Pat. application Ser. No.
date.
  The increasingly widespread use of electronic docu 07/561,888,
                                                            which  a
                                                                        file Aug. 2, 1990, a system of verification by
                                                                     digital document may be so fixed in time and
ments, which include not only digital representations of content that it can
readable text but also of video, audio, and pictorial data, rently recognized inpresent,  at least to the extent cur
                                                                                   tangible   documents, direct evi
now poses a serious threat to the viability of the "note 30 dence on those issues.
book' concept of establishing the date of any such doc        The method described there entails transmittal of a
ument. Because electronic digital documents are so
easily revised, and since such revisions may be made document         to an outside agency where current time data
without telltale sign, there is available limited credible representation of with
                                                           are incorporated         at least a portion of a digital
                                                                               the document. In order to prevent
evidence that a given document truly states the date on 35 collusive misstamping   by the agency, one or more agen
which it was created or the message it originally car cies are selected at random        or an agency is required to
ried. For the same reasons there even arises serious
doubt as to the authenticity of a verifying signature.     incorporate  into the time stamp  receipt at least the time
Without an effective procedure for ensuring against the and     a portion of identifying data from one or more
surreptitious revision of digital documents, a basic lack temporally
                                                           accomplishes
                                                                       adjacent receipts Although this procedure
                                                                           the two-fold goals of effective time
of system credibility prevents the efficiencies of elec
tronic documentation from being more widely imple stamping, i.e., to fix the time and content of a document
mented.                                                    and to prevent collusive misdeeds of author and agent
   Some procedures are presently available for verifying witness, any subsequent personal interaction between
electronic document transmissions; however, such pro 45 participating authors may be burdensome, particularly
cedures are limited in application to bilateral communi in later proof stages where the comparison of contem
                                                               porary receipts is required.
cations. That is, in such communications the sender
essentially desires to verify to the receiver the source                SUMMARY OF THE INVENTION
and original content of the transmitted document. For        The present invention represents an improvement on
example, "private key” cryptographic schemes have
long been employed for message transmission between        our above-mentioned system and provides a reliable and
or among a limited universe of individuals who are more          adaptable method of time-stamping digital docu
known to one another and who alone know the de ments that continues to maintain the two essential char
crypting key. Encryption of the message ensures against acteristics of accepted document verification. First, the
tampering, and the fact that application of the private 55 content of a document and a time stamp of its existence
key reveals the "plaintext" of the transmitted message are "indelibly" incorporated into the digital data of the
serves as proof that the message was transmitted by one document so that it is not possible to change any bit of
of the defined universe. The time of creation of the the resulting time-stamped data without such a change
message is only collaterally established, however, as being apparent. In this manner, the state of the docu
being not later than its receipt by the addressee. This ment content is fixed at the instant of time-stamping.
practice thus fails to provide time-stamp evidence that Second, the time at which the digital document is
would be useful in an unlimited universe at a later date. stamped is certified by a cryptographic summary, or
  A more broadly applicable verifying communication catenation, procedure that deters the incorporation of a
procedure, that of "public key” cryptography, has been false time statement. In essence, the method transfers
described by Diffie and Hellman ("New Directions in 65 control of the time-stamping step from the author to an
Cryptography", IEEE Transactions On Information independent agent and removes from the author the
Theory, Vol IT-22, November 1976, pp. 644-654). ability to influence the agent in the application of other
While this scheme expands the utilizing universe to a than a truthful time stamp.
                                                      5,136,646
                        3                                                                  4.
  One embodiment of the present invention presumes a           value as is contained in the author's certificate, assum
number of document authors distributed throughout a            ing use of the original hashing algorithm.
communication network. Such authors may be individ               Any available deterministic function, e.g. a one-way
uals, companies, company departments, etc., each rep           hash function such as that described by Rivest ("The
resenting a distinct and identifiable, e.g., by ID number      MD4 Message Digest Algorithm", Advances in Cryp
or the like, member of the author universe. This uni           tology-Crypto '90, Springer-Verlag, LNCS, to appear),
verse would be supported by a central record reposi            incorporated herein by reference, may be used in the
tory and would, in essence, constitute the clientele of        present procedure. In the practice of the invention, such
such an outside time-stamping agency (TSA).                    a hashing operation is optionally employed by the au
   In this particular application, as depicted in FIG. 1 of O thor  to obtain the noted benefit of transmission security,
                                                              although    it might be effected by the TSA if the docu
the drawing, the method entails an author's preparation
of a digital document, which may broadly comprise any ment were received in plaintext form. In whatever such
alphanumeric, audio, or pictorial presentation, and the manner the document content and incorporated time
transmission of the document, preferably in a condensed 15 data
                                                              step,
                                                                    are fixed against revision, there remains the further
                                                                     in order to promote the credibility of the system,
representative form, to the TSA. The TSA time-stamps of certifying
the document to create a receipt by adding digital data universe that tothethereceipt members of an as yet unidentified
                                                                                            was in fact prepared by the
signifying the current time, concatenates the receipt TSA, rather than by the author,
with the current cryptographic catenation of its prior cation is correct, i.e., that it has and     not,
                                                                                                         that the time indi
                                                                                                         for instance, been
time stamp receipts, and creates a new catenation from fraudulently stated by the TSA in collusion                 with the
the composite document by means of a deterministic author.
function, such as discussed in greater detail below. The         To satisfy these concerns, the TSA maintains a re
resulting catenate value is then included with time and cord
other identifying data in a document, now a certificate addingofeach     its sequential time-stamping transactions by
                                                                               new receipt to its current catenation and
of the temporal existence of the original document,
which is transmitted back to the author where it will be 25 applying       its deterministic function, e.g. hashing, the
                                                              composite to obtain a new catenation. This catenation,
held for later use in any required proof of such exis itself         a value resulting from the hashing process, is in
tence,
   To ensure against interception of confidential docu thor andon serves
                                                              cluded        the receipt or certificate returned to the au
                                                                                   to certify the indicated time stamp.
ment information during transmission to the TSA, and 30 Confirmation of the            certificate at a later time involves
to reduce the digital bandwidth required for transmis rehashing the combination of the author's time receipt
sion of an entire document, the author may optionally
convert the digital document string to a unique value and           the next previous catenate value in the TSA re
                                                              cords. The resulting generation of the author's catenate
having vastly condensed digital size by means of a de certificate value proves to the author and to the uni
terministic function which may, for example, be any one 35 verse at large that the certificate originated with the
of a number of algorithms known in the art as "one-way TSA. This result also proves the veracity of the time
hash functions'. Such an application of hash functions stamp itself, since all original elements of the original
has been described, among others, by Damgard in his receipt must be repeated in order to again generate, by
discussions on the improvement of security in document the hashing function, the original catenate certificate
signing techniques ("Collision-Free Hash Functions value.
and Public Key Signature Schemes', Advances in Cryp              The process of the invention relies upon the relatively
 tology-Eurocrypt '87, Springer-Verlag, LNCS, 1988, continuous flow of documents from the universe of
Vol. 304, pp. 203-217). In practice of the present inven authors through the facilities of the TSA. For each
tion, however, the "one-way' characteristic typical of a given processed document D, from an author, Ak, the
 hashing algorithm serves an additional purpose; that is, TSA generates a time-stamp receipt which includes, for
to provide assurance that the document cannot be se 45 example, a sequential receipt transaction number, r, the
cretly revised subsequent to the time the TSA applies its identity of the author, for example by ID number IDk,
 time stamp and incorporates the document into the or the like, a digital representation, e.g. the hash, Hk, of
 catenate certificate.                                        the document, and the current time, t. The TSA then
   A hashing function provides just such assurance, SO includes these receipt data, or any representative part
 since at the time a document, such as an author's origi thereof, with the catenate certificate value, C-1, of the
 nal work or a composite receipt catenation, is hashed immediately preceding processed document D-1, of
 there is created a representative "fingerprint' of its author, Ak-1, thereby bounding the time-stamp of docu
 original content from which it is virtually impossible to ment Dk, by the independently established earlier re
 recover that document. Therefore, the time-stamped 55 ceipt time, t-1.
 document is not susceptible to revision by any adver            The composite data string, r, IDk, Hk, t, C-1), is
 sary of the author. Nor is the author able to apply an then hashed to a new catenate value, Ck, that is entered
 issued time-stamp certificate to a revised form of the with transaction number, r, in the records of the TSA,
 document, since any change in the original document and is also transmitted to Ak, as the catenate certificate
 content, even to the extent of a single word or a single value, with the time-stamp receipt data. In like manner,
 bit of digital data, results in a different document that a certificate value derived from the hashing of C with
 would hash to a completely different fingerprint value. time stamp elements of the receipt for document Dk-1,
 Although a document cannot be recovered from its would be transmitted to author, Ak-1. Thus, each of
 representative hash value, a purported original docu the time-stamped catenate certificates issued by the
 ment can nonetheless be proven in the present time 65 TSA is fixed in the continuum of time and none can be
 stamping procedure by the fact that a receipt concate falsely prepared by the TSA, since any attempt to re
 nation comprising a true copy of the original document generate a catenate certificate number from a hash with
 representation will always hash to the same catenate the next prior certificate would reveal the discrepancy.
                                                     5,136,646
                           5                                                              6
  In a more general application of the invention, as          the following excerpt is amply representative of a docu
shown in FIG. 2, the representation, e.g., a hash, of a       ment, Dk, for which time-stamping is desired:
particular document is simply concatenated with the              . . . the idea in which affirmation of the world and
catenate certificate value of the next previous document         ethics are contained side by side... the ethical accep
and the deterministic function representation, again a           tance of the world and of life, together with the ideals
hash, for example, of this composite is then generated           of civilization contained in this concept ... truth has
and retained as the record catenate value for the partic         no special time of its own. Its hour is now-always.
ular document Each subsequent document in the grow                    Schweitzer
ing series is similarly processed to expand the record           If the author so desires, the document, Dk, may, for
which itself would serve as a reliable certification of the 10 the purposes of security as well as to reduce the re
position each such document occupies in the series, or for     quired transmission bandwidth, be condensed by means,
more broadly viewed, in the continuum of time. This optional,      example, of the mdé algorithm. As indicated by the
embodiment of the invention provides a reliable method                   dashed step 12, the document is thus hashed to
by which an organization, for instance, could readily 15 pressed inHk,
                                                               a value,      of a standard 128 bit format which, ex
                                                                          base 16, appears as:
certify the sequence and continuity of its digital business
documents and records.
  Additional variations in the process of the invention
might include the accumulation of documents, prefera It should be noted at this point that the hexadecimal and
bly in hashed or other representative form, generated other numerical value representations used in this exam
within an author organization over a period of time, e.g.
a day or more depending upon the extent of activity, ple       are not in such form crucial to the implementation of
                                                            the invention. That is to say, any portion or other dis
with the collection being hashed to present a single tinct representation of those values selected according
convenient document for time-stamping and certifica to a given procedure would function as well.
tion. As an alternative, an organizational designee might 25 Author, Ak, whose assigned identification number,
serve as a resident "outside' agency who would main IDk, is 634 in a 1000 member author universe, then
tain a catenate certificate record of organization docu transmits the document, at step 13, to the system TSA in
ments by means of the present procedure and on a regu the identifying message, (IDk, Hk), which appears:
lar basis would transmit the then current catenate certif.
icate to a TSA. In this manner the sequence of an orga 30
nization's business records would be established both
within the organization and externally through the     as a request that the document be time-stamped.
TSA                                                      The TSA, at step 14, prepares the receipt for docu
  Also, the implementation of process embodiments ment, Dk, by adding a sequential receipt transaction
might readily be automated in simple computer pro 35 number, r, of 1328, for example, and a statement of the
grams which would directly carry out the various steps current time, t. This time statement might be a standard
of hashing, transmitting, and concatenating original binary representation of computer clock time or simply
document representations, applying current time a literal statement, e.g., 19:46:28 Greenwich Mean Time
stamps, generating and recording catenate certificate on Mar. 6, 1991, in order to allow the final time-stamp
values, and providing receipt certificates.            certificate to be easily read. The receipt then comprises
                                                       the string, (rk, tk, IDk, Hk), which appears as follows;
                   THE ORAWING
   The present invention will be described with refer
 ence to the accompanying drawing of which:
   FIG. 1 is a flow diagram of an embodiment of the 45 In accordance with the invention, the records of the
 time-stamping process according to the invention; and TSA
   FIG. 2 is a flow diagram of the general catenation receiptat transactions
                                                                    this time contain a catenation of all its prior
                                                                                 in the form, for example, of the
 process according to the invention.                       values resulting from the hashing of each consecutive
        DESCRIPTION OF THE INVENTION                       receipt with the record catenation to that time. This
                                                           catenate
   The following exemplary application of the present follows. The   record would thus have been developed as
 invention, as depicted in the steps of the drawing, will hashed with anreceipt     of first transaction (rk) was
                                                                           initial datum value, e.g., the hash of the
 serve to further describe the time-stamping process. For identification of the TSA, to yield the first catenate
 convenience in the presentation of this example, the value, C1, which was then used as the certificate value
 deterministic function employed is the mdd hashing 55 for that first transaction. In the next transaction, the
 algorithm described by Rivest, as mentioned above; receipt was concatenated with Cand the composite
 however, the function actually selected by a TSA could hashed to yield the second catenate certificate value,
 be any of various available algorithms. Whatever algo C2, and so on through the entire history of the TSA
 rithm is implemented, records of its identity and period time-stamping operation.
 of use must be maintained for later proof of certified      Assume now that the document, D-1, immediately
 receipts.                                                 preceding that of the present example had been pro
    The present time-stamping procedure begins, as at cessed by the TSA, in its 1327th receipt transaction, to
 step 11 of the drawing, with the preparation of a digital yield as the catenate certificate value, C-1:
 document by the author, e.g. Ak. As previously noted,
 this digital document may be the digital form or repre 65
 sentation of any alphanumeric text or video, audio,
 pictorial or other form of fixed data. Although the pres In step 15 of the process, the TSA now concatenates
 ent process may be used with documents of any length, with this value the receipt for Dk to obtain:
                                                      5,136,646
                            7                                                              8
                                                                would hash to a catenate certificate value different from
                                                                that stated in the certificate of transaction number 1329.
                                                                  If further proof were demanded, for example upon an
                                                                adversary allegation that C-1 had been falsified after
This composite is then hashed by the TSA, at step 16, to        the fact of a document revision, the certificate and the ,
yield as the new catenate certificate value, Ck:              submitted, e.g. hashed, document of Ak, who is identi
                                                              fied from TSA records, would be employed in an at
     46fid75ffbeassessfc384,7228cal                           tempt to regenerate the subsequent, questioned certifi
                                                            O
                                                              cate value, Ck-1. If that value were correct, D-1
  The TSA then adds this value to its records and pre           would be proved. As an alternative, the certificate
pares and transmits to author, Ak, at step 17, a time           value, Ck-1, could be proved by the regeneration of the
stamp certificate, including this catenate certificate          subsequent catenate certificate value, C-2, from the
value, which might appear as:                                   certificate data and submitted document of Ak-2, since
                                                                no feasible revision could be made to that later docu
                                                           15 ment which would result in a match of C-2 if Ck-1
   Transaction Number:     1328
   Client D Number:        634                                  were not the same as existed at the time of the transac
   Time:                   19:46:28 Greenwich Mean Time       tion, 1330, processing Dk-2.
   Date:                   06 March 1991
   Certificate Number:     4677SObe9596fc3847.228cal             In the more general record catenation procedure
                                                           20
                                                              depicted in FIG. 2, the documents in a growing series
                                                              are processed, within an organization or by a TSA, as
  The procedure would be repeated by the TSA for each is generated. At step 21, a new document represen
each subsequent time stamp request. Assuming the next tation, such as would be generated by a hashing deter
request from Akt-1 was received with the document in ministic function algorithm, becomes available and, at
the form of its hash Hk-1, as:
                                                           25 step 22, is concatenated with the current record cate
      201, 882653eeO4.d51dbb5e06883aa27300b                   nate value that was generated in the processing of the
                                                              previous document. This composite is then processed,
at 19:57:52 GMT on Mar. 6, 1991, the composite con e.g., hashed, at step 23, to generate the new catenate
catenation would appear:                                      value for the present document. This value may be
                                                           30 separately recorded and utilized for inclusion in a certif
      467750fbea9Se96fc38472aa28cal, 329,                     icate, or simply retained in the processing system for
         195752GMTO6MAR1991, 201,                             application to the next document which is presented at
         882653e045 dbb5e06883aa27300b
                                                              step 24. The subsequent processing steps 25, 26 are
and the certificate returned to Aki would read:               applied to this document representation, and the pro
                                                           35 cess repeats with each new document in its turn.
                                                                 The procedures described and variants suggested
    Transaction Number: . 1329                                herein for the practice of this time-stamping process and
    Client D Number:         201                              the various other embodiments which will become ap
    Time:                    19:57:52 Greenwich Mean Tine
    Date:                    06 March 1991                    parent to the skilled artisan in the light of the foregoing
    Certificate Number:      d9bb1b1158bb09c2763e.95bb83ad 40 description are all nonetheless to be included within the
                                                              scope of the present invention as defined by the ap
   When, at a later date, author, Aki, desires to prove pended          claims.
                                                                 What is claimed is:
the authenticity of document, Dk-1, as that which was            1. A method of certifying the temporal sequence of
received and dated by the TSA on Mar. 6, 1991 at 45 digital
19:57:52, the records of the TSA are examined to obtain terized documents          in a series of such documents charac
                                                                       in that said method comprises:
the catenate certificate value, Ck, of the next previous            a) generating a digital representation of a specified
transaction, 1328, which appears as:                                   one of the documents in said series; and
                                                                     b) generating a catenate certificate value represen
                                                                       tation for said specified document by applying a
The alleged document is then reduced to the form in                    selected deterministic function algorithm to a
which it was transmitted to the TSA, e.g, as its hash,                 catenation comprising said digital representation
and this value is then concatenated with Ck and the                    and the catenate certificate value representation
remaining data from the certificate of Ak-1. The result                for the document immediately prior in said series
ing composite, assuming the alleged document to be 55                  to said specified document.
authentic, now appears as:                                        2. A method according to claim 1
                                                                  characterized in that the method further comprises
     467d75ffbeassessfc384,7228cal, 329,
       1957.52GMTO6MAR1991, 201,
                                                                    repeating the recited steps with each subsequent
       882653e04.d.Sldbb5e06883aa27300b                              document in said series.
                                                                  3. A method according to claim 2
which, when hashed, produces the correct catenate                 characterized in that said method further comprises
certificate value:                                                   maintaining a sequential record of said series docu
                                                                     ments with their respective catenate certificate
                                                                     value representations.
                                                           65     4. A method according to claim 2
thereby proving the alleged document to be Dk-1.                  characterized in that each said digital representation
Otherwise, a revised document would hash to a differ                is generated by applying to said document one or
ent value and the composite of which it is an element               another deterministic function algorithm which
                                                    5,136,646
                            9                                                                10
     may be the same as or different from said selected            characterized in that said prior certificate value rep
     deterministic function algorithm,                               resentation comprises at least a portion of the cate
  5. A method according to claim 4                                   nate certificate value of the immediately preceding
  characterized in that said one or another determinis-               recording time-stamping transaction.
     tic function algorithm is any one-way hashing algo- 5         10. A method of time-stamping a digital document
     rithm.                                                      according to claim 7
  6. A method according to claim 2                                 characterized in that said selected deterministic func
  characterized in that said selected deterministic func-            tion algorithm is any one-way hashing algorithm.
     tion algorithm is any one-way hashing algorithm.        11. A method of time-stamping a digital document
  7. A method of time-stamping a digital document 10 according to claim 7
which comprises transmitting a digital representation of     characterized in that said transmitted digital docu
said document to an outside agency, creating at said           ment representation comprises at least a portion of
outside agency a receipt comprising a digital represen-        the digital representation of the value derived by
tation of then current time and at least a portion of a        applying to said digital document one or another
digital representation of said digital document, and cer- 15   deterministic function algorithm which may be the
tifying said receipt at said outside agency                    same as or different from said selected determinis
   characterized in that the certifying of said receipt        tic function algorithm.
     comprises:                                              12. A method of time-stamping a digital document
     a) concatenating a digital representation of said according to claim 7
        receipt with a representation of a prior catenate 20 characterized in that said receipted digital document
        certificate value to form a composite; and              representation comprises at least a portion of the
     b) generating a catenate certificate value for said        digital representation of the value derived by ap
        receipt by applying a selected deterministic func-      plying to said digital document one or another
        tion algorithm to said composite.                       deterministic function algorithm which may be the
   8. A method of time-stamping a digital document 25           same as or different from said selected determinis
according to claim 7                                            tic function algorithm.
   characterized in that said outside agency maintains a     13. A method of time-stamping a digital document
      record comprising the catenate certificate values of according to claim 12
     prior time-stamping transactions.                       characterized in that said one or another determinis
   9. A method of time-stamping a digital document 30           tic function is any one-way hashing algorithm.
according to claim 7                                                                 as   x

                                                            35

                                                            40

                                                            45

                                                            50

                                                            55

                                                            60

                                                            65