Hello,
I have two Nitrokey HSM2, but I’m consistently getting different performance times on the same operations.
In particular both of them slow down with the increase of the number of stored key pairs (RSA4096) in performing the following operations:
- Key deletion
- Certificate generation
- Certificate storing
- Signing
- Signature verification
but one of them is much slower than the other on these operations from the beginning, and the total time accumulates, becoming very impactful (about the same total time on performing the operations on the first key, double the cumulative time when generating and storing 5 key pairs).
Can anyone help me understand the cause of this discrepancy between the two Nitrokey?
When you frequently erase objects, then the Java garbage collection kicks in and reorganizes memory. That can take a couple of milliseconds. Also the 4.x version with JCOP4 is considerable faster than the 2.x and 3.x versions (JCOP2/JCOP3). JCOP4 used flash memory, while JCOP2 and JCOP3 use EEPROM cells.
What surprises me is that the slower one is version 4.1 on JCOP4, the faster one is version 3.6 on JCOP3.
Thank you for the clarification on deleting keys, I don’t know if that’s enough to explain the difference though, the cumulative time for all the operations is around 14 minutes for the fast Nitrokey
Performance should be somewhere in the range of the datasheet.
It also matters how you interact with the device. If you do this on the command line, e.g. using the pkcs11-tool, then every time you start the tool the PKCS#11 module will detect and read all meta-data and public objects from the device. The more keys and data objects you have, the longer it takes.
There is no session management between invocations of command line tools. The whole process of detecting objects and login are repeated at each start.
That is why we generally recommend to use a scripting framework like OpenSCDP, where multiple operations can be performed in a single session.