# Remote Digital Signature on Desktop

## 1. Desktop Architecture

SignCloud provides the Universal Key Chain (UKC) desktop client.

UKC acts as a remote smart card middleware, exposing certificates via:

- CSP (Crypto Service Provider) for Windows
- PKCS#11 for cross-platform environments
- tokenD interface


This allows remote certificates to appear exactly like physical smart cards.

## 2. Login Process

User authenticates using:

- UserID
- Password


[1] Connection of the UKC Client to the SignCloud Platform; [2] Display of the available digital identities in to the UKC
br
After successful login, certificates are displayed inside the UKC interface.

## 3. Smart Card Manager Functions

UKC allows:

- Viewing available certificates
- Changing PIN
- Unlocking PIN using PUK
- Managing multiple identities


## 4. Signing Workflow Example (Microsoft Word)

1. User opens a document.
2. Word detects available certificates via CSP.
3. User selects remote certificate.
4. UKC prompts for PIN or authenticator.
5. Signing request sent to SignCloud.
6. Signature executed inside HSM.
7. Signed document returned to Word.


The workflow mirrors traditional smart card signing.

Adding a digital signature to a Word document. The certificate is made available by the UKC through the CSP library
The decision to sign the document produces the PIN request from the UKC client exactly in the same fashion as it would happen if a physical smart card is used
## 5. Application Compatibility

SignCloud supports any application requiring:

- PKCS#11 library
- CSP interface


Examples:

- Microsoft Office
- Firefox
- Custom enterprise applications