Performance difference in Nitrokey HSM2 key generation

Hello,
I have two Nitrokey HSM2, but I’m consistently getting different performance times on the same operations.
In particular both of them slow down with the increase of the number of stored key pairs (RSA4096) in performing the following operations:
- Key deletion
- Certificate generation
- Certificate storing
- Signing
- Signature verification
but one of them is much slower than the other on these operations from the beginning, and the total time accumulates, becoming very impactful (about the same total time on performing the operations on the first key, double the cumulative time when generating and storing 5 key pairs).

Can anyone help me understand the cause of this discrepancy between the two Nitrokey?

What firmware version is this ?

When you frequently erase objects, then the Java garbage collection kicks in and reorganizes memory. That can take a couple of milliseconds. Also the 4.x version with JCOP4 is considerable faster than the 2.x and 3.x versions (JCOP2/JCOP3). JCOP4 used flash memory, while JCOP2 and JCOP3 use EEPROM cells.

What surprises me is that the slower one is version 4.1 on JCOP4, the faster one is version 3.6 on JCOP3.

Thank you for the clarification on deleting keys, I don’t know if that’s enough to explain the difference though, the cumulative time for all the operations is around 14 minutes for the fast Nitrokey

Performance should be somewhere in the range of the datasheet.

It also matters how you interact with the device. If you do this on the command line, e.g. using the pkcs11-tool, then every time you start the tool the PKCS#11 module will detect and read all meta-data and public objects from the device. The more keys and data objects you have, the longer it takes.

There is no session management between invocations of command line tools. The whole process of detecting objects and login are repeated at each start.

That is why we generally recommend to use a scripting framework like OpenSCDP, where multiple operations can be performed in a single session.

Ok that’s great to know, thank you very much, I’m executing from command line with either pkcs11-tool or OpenSSL with the pkcs11 engine.

Do you also have an explanation for the difference in performances between the two Nitrokey HSM?

Could be a communication issue between the smartcard chip and the Nitrokey reader firmware. But that is something Nitrokey would need to look at.

For the JCOP4 chip and the SmartCard-HSM applet we have not seen such an issue.