In the scenario you describe (private key is sitting on the smart card) the signature will be done on *this* smart card no matter what simply because you are not allowed (most of the time) to export private key from the smart card. Aleksey