Sample code for 30+ languages & platforms
Delphi ActiveX Requires Chilkat v11.0.0+

Aadhaar Paperless Offline e-kyc

See more XML Digital Signatures Examples

Opens an encrypted .zip containing Aadhaar Paperless Offline e-KYC XML. Gets the XML and validates the digital signature. Then computes the hash for the mobile number and Email ID.

Chilkat Delphi ActiveX Downloads

Delphi ActiveX
var
success: Integer;
zip: TChilkatZip;
entry: TChilkatZipEntry;
sharePhrase: WideString;
bdXml: TChilkatBinData;
dsig: TChilkatXmlDSig;
cert: TChilkatCert;
pubKey: TPublicKey;
bVerifyReferenceDigests: Integer;
bVerified: Integer;
crypt: TChilkatCrypt2;
strToHash: WideString;
bdHash: TChilkatBinData;
numTimesToHash: Integer;
i: Integer;
tmpStr: WideString;
xml: TChilkatXml;
m_hash: WideString;
tmpStr: WideString;
e_hash: WideString;

begin
success := 0;

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  Open the .zip containing the Aadhaar Paperless Offline e-KYC XML.
//  The .zip is encrypted using the "Share Phrase".
zip := TChilkatZip.Create(Self);
success := zip.OpenZip('qa_data/xml_dsig/offline_paperless_kyc.zip');
if (success = 0) then
  begin
    Memo1.Lines.Add(zip.LastErrorText);
    Exit;
  end;

//  The .zip should contain 1 XML file.
entry := TChilkatZipEntry.Create(Self);
success := zip.EntryAt(0,entry.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(zip.LastErrorText);
    Exit;
  end;

//  To get the contents, we need to specify the Share Phrase.
sharePhrase := 'Lock@487';
zip.DecryptPassword := sharePhrase;

bdXml := TChilkatBinData.Create(Self);
//  The XML file will be unzipped into the bdXml object.
success := entry.UnzipToBd(bdXml.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(entry.LastErrorText);
    Exit;
  end;

//  First verify the XML digital signature.
dsig := TChilkatXmlDSig.Create(Self);
success := dsig.LoadSignatureBd(bdXml.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(dsig.LastErrorText);
    Exit;
  end;

//  The UIDAI XML signature does not contain the KeyInfo, so we must load the uidai certificate
//  and indicate that its public key is to be used for verifying the signature.
cert := TChilkatCert.Create(Self);
success := cert.LoadFromFile('qa_data/xml_dsig/uidai_auth_sign_prod_2023.cer');
if (success = 0) then
  begin
    Memo1.Lines.Add(cert.LastErrorText);
    Exit;
  end;

//  Get the certificate's public key.
pubKey := TPublicKey.Create(Self);
cert.GetPublicKey(pubKey.ControlInterface);

dsig.SetPublicKey(pubKey.ControlInterface);

//  The XML in this example contains only 1 signature.
bVerifyReferenceDigests := 1;
bVerified := dsig.VerifySignature(bVerifyReferenceDigests);
if (bVerified = 0) then
  begin
    Memo1.Lines.Add(dsig.LastErrorText);
    Memo1.Lines.Add('The signature was not valid.');
    Exit;
  end;

Memo1.Lines.Add('The XML digital signature is valid.');

//  Let's compute the hash for the Mobile Number.

//  	Hashing logic for Mobile Number :
//  	Sha256(Sha256(Mobile+SharePhrase))*number of times last digit of Aadhaar number
//  	(Ref ID field contains last 4 digits).
//  
//  	Example :
//  	Mobile: 1234567890
//  	Aadhaar Number:XXXX XXXX 3632
//  	Passcode : Lock@487
//  	Hash: Sha256(Sha256(1234567890Lock@487))*2
//  	In case of Aadhaar number ends with Zero we will hashed one time.

crypt := TChilkatCrypt2.Create(Self);
crypt.HashAlgorithm := 'sha256';
crypt.EncodingMode := 'hexlower';

strToHash := '1234567890Lock@487';
bdHash := TChilkatBinData.Create(Self);
success := bdHash.AppendString(strToHash,'utf-8');

//  Hash a number of times equal to the last digit of your Aadhaar number.
//  If the Aadhaar number ends with 0, then hash one time.
//  For this example, we'll just set the number of times to hash
//  for the case where an Aadhaar number ends in "9"
numTimesToHash := 9;

for i := 1 to numTimesToHash do
  begin
    tmpStr := crypt.HashBdENC(bdHash.ControlInterface);
    bdHash.Clear();
    bdHash.AppendString(tmpStr,'utf-8');
  end;

Memo1.Lines.Add('Computed Mobile hash = ' + bdHash.GetString('utf-8'));

//  Let's get the mobile hash stored in the XML and compare it with our computed hash.
xml := TChilkatXml.Create(Self);
success := xml.LoadBd(bdXml.ControlInterface,1);
m_hash := xml.ChilkatPath('UidData|Poi|(m)');

Memo1.Lines.Add('Stored Mobile hash   = ' + m_hash);

//  Now do the same thing for the email hash:

strToHash := 'abc@gm.comLock@487';
bdHash.Clear();
success := bdHash.AppendString(strToHash,'utf-8');

for i := 1 to numTimesToHash do
  begin
    tmpStr := crypt.HashBdENC(bdHash.ControlInterface);
    bdHash.Clear();
    bdHash.AppendString(tmpStr,'utf-8');
  end;

Memo1.Lines.Add('Computed Email hash = ' + bdHash.GetString('utf-8'));

e_hash := xml.ChilkatPath('UidData|Poi|(e)');
Memo1.Lines.Add('Stored Email hash   = ' + e_hash);