# SignCloud Architecture

## 1. Executive Overview

SignCloud is a remote digital signature system designed to enable the enrolment and use of PKI-based remote digital identities.

The platform allows users to sign documents remotely by leveraging a Secure Element hosted in certified HSM devices, removing the need for physical smart cards or USB cryptographic tokens.

The system is designed to operate as a Qualified Signature Creation Device (QSCD) in a secure operational environment and complies with:

- eIDAS Regulation (EU 910/2014)
- CEN EN 419 241 (TW4S – Trustworthy System Supporting Server Signing)
- CEN EN 419 221-5
- FIPS 140-2 Level 3
- Common Criteria EAL 4+


When deployed by a Qualified Trust Service Provider (QTSP), SignCloud enables remote Qualified Electronic Signatures and Seals.

## 2. Logical Architecture Overview

SignCloud is an enterprise-grade client-server solution to expand a PKI infrastructure with remote digital signature functionality.

SignCloud provides both a lightweight desktop agent, named Universal Key Chain (UKC), and a mobile application for the remote signature on mobile devices. The UKC client interoperates seamlessly with any web browser and third-party desktop application through widespread and well accepted digital signature standards. SignCloud makes remote digital signature possible in the widest range of mobile and non-mobile scenarios.

The SignCloud server, as represented in figure 1, integrates the following functionalities:

- **Credentials Manager**
- **Digital Signature Engine**
- **Secure DBMS**
- **HSM**
- **Log and Audit System**


Functional Architecture of SignCloud Server
The SignCloud Client (UKC) ensures abstraction and remote access to a secure signature creation device for third-party applications, through several standard interfaces (PKCS#11, CSP, tokenD) and advanced high-level APIs. It represents a solution for all the applications requesting a digital signature service or the creation of a new a digital identity (key-pair and related X.509 digital certificate).

The Authentication Server module supports several Authenticators means such as:

- Physical OTP device
- Mobile App OTPs
- SMS OTPs
- Biometric-based (on request)


SignCloud is able to work with existing PKI infrastructures and Credential Management Systems, as far as they can interoperate with PKCS#11-compliant devices. This integration is achieved by a lightweight Registration Authority (RA) Client Connector (UKC for RA), which extends the RA functionalities to enrol new remote certificates and key-pairs on the SignCloud platform. The platform is natively integrated with Namirial’s Universal Identity Manager Registration Authority (Namirial UIM RA), Credential Management System (CMS) and RA platforms.

SignCloud is scalable both vertically, by integrating a more powerful HSM, and horizontally, by clustering the SignCloud servers to ensure not only increased performance but also fault tolerance and load balancing.

SignCloud features an advanced secure logging system to keep track of performed transactions. Audit trail is sequentially hashed and digitally signed in order to guarantee both the integrity of the single records and of their sequence.

High-level architecture of the SignCloud System and interfacing with external entities
## 3. Server Functional Modules

### 3.1 Credentials Manager

Responsible for:

- Virtual Token lifecycle management
- PIN/PUK verification
- Error counters
- Lockout logic
- OTP seed storage
- User identity association


### 3.2 Digital Signature Engine

Handles:

- RSA key-pair generation
- Private key usage
- Document or hash signing
- Key wrapping and unwrapping
- Certificate association


All operations occur inside the HSM boundary.

### 3.3 Secure DBMS

The database stores:

- TokenID
- Password hash (PBKDF2)
- Wrapped private RSA keys
- Wrapped AES keys
- Hash of derived wrapping keys (hKVT)
- OTP seed and counter
- Error counters
- Audit metadata


The DB never stores:

- PIN
- PUK
- Plaintext private keys


### 3.4 Hardware Security Module (HSM)

Certified:

- FIPS 140-2 Level 3
- CEN EN 419 221-5 CC EAL4+


Responsibilities:

- AES-256 key generation
- RSA key generation (4096/2048/1024)
- PBKDF2-derived key import
- XOR key derivation
- Key wrapping
- Digital signing
- ACL enforcement


HSM supports both:

- Embedded PCI HSM
- External network HSM (higher throughput)


### 3.5 Authentication Server

Supports multiple authenticators:

- Physical OTP devices
- Mobile App OTP
- SMS OTP
- Biometric authentication (optional)


Authentication can replace or complement static PIN-based access.

## 4. Client Architecture

### 4.1 Universal Key Chain (UKC)

Acts as a remote smart card abstraction layer.

Exposes:

- PKCS#11
- CSP (Crypto Service Provider)
- tokenD
- High-level APIs


Functions:

- Key-pair generation
- Signing requests
- PIN change
- PIN unlock via PUK
- Identity management


### 4.2 Mobile Client

Enables:

- Push notification-based signing
- Document preview
- Certificate selection
- PIN/OTP authentication
- Secure HTTPS communication


## 5. Scalability

SignCloud supports:

### Vertical Scaling

Upgrading HSM performance.

### Horizontal Scaling

Clustering servers for:

- Load balancing
- Fault tolerance
- Disaster recovery
- Increased signing throughput


## 6. Logging and Audit

Each transaction:

- Logged sequentially
- Hashed
- Digitally signed


Guarantees:

- Record integrity
- Sequence integrity
- Forensic traceability