Sample code for 30+ languages & platforms
Lianja

Aadhaar Paperless Offline e-kyc

See more XML Digital Signatures Examples

Opens an encrypted .zip containing Aadhaar Paperless Offline e-KYC XML. Gets the XML and validates the digital signature. Then computes the hash for the mobile number and Email ID.

Chilkat Lianja Downloads

Lianja
llSuccess = .F.

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// Open the .zip containing the Aadhaar Paperless Offline e-KYC XML.
// The .zip is encrypted using the "Share Phrase".
loZip = createobject("CkZip")
llSuccess = loZip.OpenZip("qa_data/xml_dsig/offline_paperless_kyc.zip")
if (llSuccess = .F.) then
    ? loZip.LastErrorText
    release loZip
    return
endif

// The .zip should contain 1 XML file.
loEntry = createobject("CkZipEntry")
llSuccess = loZip.EntryAt(0,loEntry)
if (llSuccess = .F.) then
    ? loZip.LastErrorText
    release loZip
    release loEntry
    return
endif

// To get the contents, we need to specify the Share Phrase.
lcSharePhrase = "Lock@487"
loZip.DecryptPassword = lcSharePhrase

loBdXml = createobject("CkBinData")
// The XML file will be unzipped into the bdXml object.
llSuccess = loEntry.UnzipToBd(loBdXml)
if (llSuccess = .F.) then
    ? loEntry.LastErrorText
    release loZip
    release loEntry
    release loBdXml
    return
endif

// First verify the XML digital signature.
loDsig = createobject("CkXmlDSig")
llSuccess = loDsig.LoadSignatureBd(loBdXml)
if (llSuccess = .F.) then
    ? loDsig.LastErrorText
    release loZip
    release loEntry
    release loBdXml
    release loDsig
    return
endif

// The UIDAI XML signature does not contain the KeyInfo, so we must load the uidai certificate
// and indicate that its public key is to be used for verifying the signature.
loCert = createobject("CkCert")
llSuccess = loCert.LoadFromFile("qa_data/xml_dsig/uidai_auth_sign_prod_2023.cer")
if (llSuccess = .F.) then
    ? loCert.LastErrorText
    release loZip
    release loEntry
    release loBdXml
    release loDsig
    release loCert
    return
endif

// Get the certificate's public key.
loPubKey = createobject("CkPublicKey")
loCert.GetPublicKey(loPubKey)

loDsig.SetPublicKey(loPubKey)

// The XML in this example contains only 1 signature.
llBVerifyReferenceDigests = .T.
llBVerified = loDsig.VerifySignature(llBVerifyReferenceDigests)
if (llBVerified = .F.) then
    ? loDsig.LastErrorText
    ? "The signature was not valid."
    release loZip
    release loEntry
    release loBdXml
    release loDsig
    release loCert
    release loPubKey
    return
endif

? "The XML digital signature is valid."

// Let's compute the hash for the Mobile Number.

// 	Hashing logic for Mobile Number :
// 	Sha256(Sha256(Mobile+SharePhrase))*number of times last digit of Aadhaar number
// 	(Ref ID field contains last 4 digits).
// 
// 	Example :
// 	Mobile: 1234567890
// 	Aadhaar Number:XXXX XXXX 3632
// 	Passcode : Lock@487
// 	Hash: Sha256(Sha256(1234567890Lock@487))*2
// 	In case of Aadhaar number ends with Zero we will hashed one time.

loCrypt = createobject("CkCrypt2")
loCrypt.HashAlgorithm = "sha256"
loCrypt.EncodingMode = "hexlower"

lcStrToHash = "1234567890Lock@487"
loBdHash = createobject("CkBinData")
llSuccess = loBdHash.AppendString(lcStrToHash,"utf-8")

// Hash a number of times equal to the last digit of your Aadhaar number.
// If the Aadhaar number ends with 0, then hash one time.
// For this example, we'll just set the number of times to hash
// for the case where an Aadhaar number ends in "9"
lnNumTimesToHash = 9

for i = 1 to lnNumTimesToHash
    lcTmpStr = loCrypt.HashBdENC(loBdHash)
    loBdHash.Clear()
    loBdHash.AppendString(lcTmpStr,"utf-8")
next

? "Computed Mobile hash = " + loBdHash.GetString("utf-8")

// Let's get the mobile hash stored in the XML and compare it with our computed hash.
loXml = createobject("CkXml")
llSuccess = loXml.LoadBd(loBdXml,.T.)
lcM_hash = loXml.ChilkatPath("UidData|Poi|(m)")

? "Stored Mobile hash   = " + lcM_hash

// Now do the same thing for the email hash:

lcStrToHash = "abc@gm.comLock@487"
loBdHash.Clear()
llSuccess = loBdHash.AppendString(lcStrToHash,"utf-8")

for i = 1 to lnNumTimesToHash
    lcTmpStr = loCrypt.HashBdENC(loBdHash)
    loBdHash.Clear()
    loBdHash.AppendString(lcTmpStr,"utf-8")
next

? "Computed Email hash = " + loBdHash.GetString("utf-8")

lcE_hash = loXml.ChilkatPath("UidData|Poi|(e)")
? "Stored Email hash   = " + lcE_hash


release loZip
release loEntry
release loBdXml
release loDsig
release loCert
release loPubKey
release loCrypt
release loBdHash
release loXml