Delphi ActiveX Requires Chilkat v11.0.0+
Delphi ActiveX
Aadhaar Paperless Offline e-kyc
See more XML Digital Signatures Examples
Opens an encrypted .zip containing Aadhaar Paperless Offline e-KYC XML. Gets the XML and validates the digital signature. Then computes the hash for the mobile number and Email ID.Chilkat Delphi ActiveX Downloads
var
success: Integer;
zip: TChilkatZip;
entry: TChilkatZipEntry;
sharePhrase: WideString;
bdXml: TChilkatBinData;
dsig: TChilkatXmlDSig;
cert: TChilkatCert;
pubKey: TPublicKey;
bVerifyReferenceDigests: Integer;
bVerified: Integer;
crypt: TChilkatCrypt2;
strToHash: WideString;
bdHash: TChilkatBinData;
numTimesToHash: Integer;
i: Integer;
tmpStr: WideString;
xml: TChilkatXml;
m_hash: WideString;
tmpStr: WideString;
e_hash: WideString;
begin
success := 0;
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Open the .zip containing the Aadhaar Paperless Offline e-KYC XML.
// The .zip is encrypted using the "Share Phrase".
zip := TChilkatZip.Create(Self);
success := zip.OpenZip('qa_data/xml_dsig/offline_paperless_kyc.zip');
if (success = 0) then
begin
Memo1.Lines.Add(zip.LastErrorText);
Exit;
end;
// The .zip should contain 1 XML file.
entry := TChilkatZipEntry.Create(Self);
success := zip.EntryAt(0,entry.ControlInterface);
if (success = 0) then
begin
Memo1.Lines.Add(zip.LastErrorText);
Exit;
end;
// To get the contents, we need to specify the Share Phrase.
sharePhrase := 'Lock@487';
zip.DecryptPassword := sharePhrase;
bdXml := TChilkatBinData.Create(Self);
// The XML file will be unzipped into the bdXml object.
success := entry.UnzipToBd(bdXml.ControlInterface);
if (success = 0) then
begin
Memo1.Lines.Add(entry.LastErrorText);
Exit;
end;
// First verify the XML digital signature.
dsig := TChilkatXmlDSig.Create(Self);
success := dsig.LoadSignatureBd(bdXml.ControlInterface);
if (success = 0) then
begin
Memo1.Lines.Add(dsig.LastErrorText);
Exit;
end;
// The UIDAI XML signature does not contain the KeyInfo, so we must load the uidai certificate
// and indicate that its public key is to be used for verifying the signature.
cert := TChilkatCert.Create(Self);
success := cert.LoadFromFile('qa_data/xml_dsig/uidai_auth_sign_prod_2023.cer');
if (success = 0) then
begin
Memo1.Lines.Add(cert.LastErrorText);
Exit;
end;
// Get the certificate's public key.
pubKey := TPublicKey.Create(Self);
cert.GetPublicKey(pubKey.ControlInterface);
dsig.SetPublicKey(pubKey.ControlInterface);
// The XML in this example contains only 1 signature.
bVerifyReferenceDigests := 1;
bVerified := dsig.VerifySignature(bVerifyReferenceDigests);
if (bVerified = 0) then
begin
Memo1.Lines.Add(dsig.LastErrorText);
Memo1.Lines.Add('The signature was not valid.');
Exit;
end;
Memo1.Lines.Add('The XML digital signature is valid.');
// Let's compute the hash for the Mobile Number.
// Hashing logic for Mobile Number :
// Sha256(Sha256(Mobile+SharePhrase))*number of times last digit of Aadhaar number
// (Ref ID field contains last 4 digits).
//
// Example :
// Mobile: 1234567890
// Aadhaar Number:XXXX XXXX 3632
// Passcode : Lock@487
// Hash: Sha256(Sha256(1234567890Lock@487))*2
// In case of Aadhaar number ends with Zero we will hashed one time.
crypt := TChilkatCrypt2.Create(Self);
crypt.HashAlgorithm := 'sha256';
crypt.EncodingMode := 'hexlower';
strToHash := '1234567890Lock@487';
bdHash := TChilkatBinData.Create(Self);
success := bdHash.AppendString(strToHash,'utf-8');
// Hash a number of times equal to the last digit of your Aadhaar number.
// If the Aadhaar number ends with 0, then hash one time.
// For this example, we'll just set the number of times to hash
// for the case where an Aadhaar number ends in "9"
numTimesToHash := 9;
for i := 1 to numTimesToHash do
begin
tmpStr := crypt.HashBdENC(bdHash.ControlInterface);
bdHash.Clear();
bdHash.AppendString(tmpStr,'utf-8');
end;
Memo1.Lines.Add('Computed Mobile hash = ' + bdHash.GetString('utf-8'));
// Let's get the mobile hash stored in the XML and compare it with our computed hash.
xml := TChilkatXml.Create(Self);
success := xml.LoadBd(bdXml.ControlInterface,1);
m_hash := xml.ChilkatPath('UidData|Poi|(m)');
Memo1.Lines.Add('Stored Mobile hash = ' + m_hash);
// Now do the same thing for the email hash:
strToHash := 'abc@gm.comLock@487';
bdHash.Clear();
success := bdHash.AppendString(strToHash,'utf-8');
for i := 1 to numTimesToHash do
begin
tmpStr := crypt.HashBdENC(bdHash.ControlInterface);
bdHash.Clear();
bdHash.AppendString(tmpStr,'utf-8');
end;
Memo1.Lines.Add('Computed Email hash = ' + bdHash.GetString('utf-8'));
e_hash := xml.ChilkatPath('UidData|Poi|(e)');
Memo1.Lines.Add('Stored Email hash = ' + e_hash);