A PKCS#11 Driver for Cryptography in the Cloud
Iulian Aciobăniţei, Lorena Leahu, Mihai-Lică Pura · 2018
During the last years several server-side/cloud signatures solutions have been proposed and implemented. Because no standards exist yet in this field, each such solution exposes its own API for performing keys/certificates management and cryptographic operations. This means that a client application wanting to implement the remote signing process, has to do so separately for each of the solutions it needs to support. This paper proposed a solution to this problem that would also assure interoperability with the local signing applications: the use of PKCS#11 (Public Key Cryptography Standards) drivers for performing server-side/cloud signatures. Just as in the case of smart cards, if each server-side signatures provider would implement a PKCS#11 driver for their solution, would allow any client working with this standard to make use of their functionalities without any change in the source code. A proof of concept has been implemented.