India · · 3 min read
Aadhaar Secure QR and Offline e-KYC, explained
What the two UIDAI-signed offline artefacts contain, how their signatures are verified, and how to handle them without storing Aadhaar numbers.
UIDAI offers residents two ways to share their Aadhaar details offline, without anyone calling UIDAI's authentication service: the Secure QR printed on Aadhaar letters and e-Aadhaar, and the Offline e-KYC ZIP that residents download from UIDAI. Both are digitally signed by UIDAI. Verifying that signature is what makes them trustworthy, and it needs only UIDAI's public certificate.
Secure QR
The Secure QR encodes one very large decimal number. Converted to bytes and decompressed, it yields a sequence of fields separated by a delimiter byte, followed by a 256-byte RSA signature over everything before it.
- A reference id: the last four digits of the Aadhaar number followed by the generation timestamp. The full number is not in the code.
- Name, date of birth (or year), gender and address fields.
- A photo, encoded as JPEG 2000.
- Indicators and hashes for the registered mobile number and email.
KYCVerify decodes the number (in the browser from a camera scan, or on the server from an image), decompresses it, splits the fields and verifies the trailing signature against every UIDAI certificate it has loaded, reporting which one verified.
QR text
one very large base-10 integer
Big-endian bytes
a GZIP stream (zlib accepted)
Decompress and split
fields delimited by 0xFF, then photo and hashes
RSA-2048 verify
SHA256withRSA over every byte before the last 256
Record
last 4 digits, demographics, photo
- indicator0-3
- reference idlast 4 + timestamp
- name · dob · genderdemographics
- address11 fields
- photoJPEG 2000
- hashesemail, mobile
- signature256 bytes
Offline e-KYC XML
The resident downloads a password-protected ZIP from UIDAI and chooses a share code (now a free-form share phrase) that unlocks it. Inside is an XML document, OfflinePaperlessKyc, with the reference id, the demographic data, a JPEG photo and the contact hashes, wrapped in an enveloped XML-DSig signature.
- Open the ZIP with the share code (ZipCrypto or AES).
- Parse the XML and canonicalise the signed content.
- Check the digest of the signed content, then the RSA signature over the signed info, with UIDAI's certificate.
- If the document was altered after signing, the digest does not match, and KYCVerify reports exactly that.
ZIP + share phrase
ZipCrypto or AES; wrong phrase is reported
OfflinePaperlessKyc
reference id, Poi, Poa, Pht, Signature
Digest check
enveloped-signature transform, C14N, compare DigestValue
Signature check
RSA PKCS#1 v1.5 over SignedInfo, UIDAI certificates only
Age check
generated within max_xml_age_days (3)
The certificate inside the XML's KeyInfo is ignored: trust comes only from the UIDAI certificates you install in certs/uidai.
The generation time in the reference id lets you refuse stale files. KYCVerify's default is to accept an Offline XML at most 3 days old (max_xml_age_days).
Contact hashes
Neither artefact contains the mobile number or email in clear. They carry a SHA-256 hash, iterated a number of times keyed on the last digit of the Aadhaar number; in the XML the hash also includes the share code. Given a number or email the resident claims, you can recompute the hash and confirm it is the one registered with UIDAI, without ever learning it otherwise.
Certificates rotate
UIDAI changes its signing key every few years, and an artefact stays signed by the key that was current when it was generated: an e-Aadhaar printed years ago carries an old signature. Keep every UIDAI offline-signing certificate, including expired ones, in the certificate directory.
Handling Aadhaar data minimally
- Neither format contains the full 12-digit number, and KYCVerify keeps only the last four digits from them.
- Organisations that store full Aadhaar numbers are expected to keep them in an Aadhaar Data Vault. The offline formats never give you one. A photographed Aadhaar card does show it: if a workflow accepts card photos, the encrypted image holds the full number until purge, so review that with counsel.
- Photos and demographics are encrypted at rest with AES-256-GCM, and purged with the session by the retention worker.
- With
require_signatureon (the default), an artefact whose signature cannot be verified does not pass.
Offline verification versus authentication
| Offline verification | Aadhaar authentication / e-KYC | |
|---|---|---|
| How | Resident shares a UIDAI-signed artefact | Request to UIDAI's CIDR through a licensed AUA/KUA |
| Network call to UIDAI | None | Yes |
| Proves | UIDAI issued this data for this reference id | UIDAI confirms the resident's OTP or biometric |
| What KYCVerify does | Yes, both formats | No |