Sample code for 30+ languages & platforms
Dart Requires Chilkat v11.0.0+

Aadhaar Paperless Offline e-kyc

See more XML Digital Signatures Examples

Opens an encrypted .zip containing Aadhaar Paperless Offline e-KYC XML. Gets the XML and validates the digital signature. Then computes the hash for the mobile number and Email ID.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  // Open the .zip containing the Aadhaar Paperless Offline e-KYC XML.
  // The .zip is encrypted using the "Share Phrase".
  final zip = CkZip();
  try {
    zip.openZip('qa_data/xml_dsig/offline_paperless_kyc.zip');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // The .zip should contain 1 XML file.
  final entry = CkZipEntry();
  try {
    zip.entryAt(0, entry);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // To get the contents, we need to specify the Share Phrase.
  final sharePhrase = 'Lock@487';
  zip.decryptPassword = sharePhrase;

  final bdXml = CkBinData();
  // The XML file will be unzipped into the bdXml object.
  try {
    entry.unzipToBd(bdXml);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // First verify the XML digital signature.
  final dsig = CkXmlDSig();
  try {
    dsig.loadSignatureBd(bdXml);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // The UIDAI XML signature does not contain the KeyInfo, so we must load the uidai certificate
  // and indicate that its public key is to be used for verifying the signature.
  final cert = CkCert();
  try {
    cert.loadFromFile('qa_data/xml_dsig/uidai_auth_sign_prod_2023.cer');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Get the certificate's public key.
  final pubKey = CkPublicKey();
  cert.getPublicKey(pubKey);

  dsig.setPublicKey(pubKey);

  // The XML in this example contains only 1 signature.
  final bVerifyReferenceDigests = true;
  try {
    dsig.verifySignature(bVerifyReferenceDigests);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    print('The signature was not valid.');
    return;
  }

  print('The XML digital signature is valid.');

  // Let's compute the hash for the Mobile Number.

  // 	Hashing logic for Mobile Number :
  // 	Sha256(Sha256(Mobile+SharePhrase))*number of times last digit of Aadhaar number
  // 	(Ref ID field contains last 4 digits).
  // 
  // 	Example :
  // 	Mobile: 1234567890
  // 	Aadhaar Number:XXXX XXXX 3632
  // 	Passcode : Lock@487
  // 	Hash: Sha256(Sha256(1234567890Lock@487))*2
  // 	In case of Aadhaar number ends with Zero we will hashed one time.

  final crypt = CkCrypt2();
  crypt.hashAlgorithm = 'sha256';
  crypt.encodingMode = 'hexlower';

  var strToHash = '1234567890Lock@487';
  final bdHash = CkBinData();
  bdHash.appendString(strToHash, 'utf-8');

  // Hash a number of times equal to the last digit of your Aadhaar number.
  // If the Aadhaar number ends with 0, then hash one time.
  // For this example, we'll just set the number of times to hash
  // for the case where an Aadhaar number ends in "9"
  final numTimesToHash = 9;
  for (var i = 1; i <= numTimesToHash; i++) {
    final tmpStr = crypt.hashBdENC(bdHash);
    bdHash.clear();
    bdHash.appendString(tmpStr, 'utf-8');
  }

  print('Computed Mobile hash = ${bdHash.getString('utf-8')}');

  // Let's get the mobile hash stored in the XML and compare it with our computed hash.
  final xml = CkXml();
  xml.loadBd(bdXml, true);
  final mHash = xml.chilkatPath('UidData|Poi|(m)');

  print('Stored Mobile hash   = $mHash');

  // Now do the same thing for the email hash:

  strToHash = 'abc@gm.comLock@487';
  bdHash.clear();
  bdHash.appendString(strToHash, 'utf-8');

  for (var i = 1; i <= numTimesToHash; i++) {
    final tmpStr = crypt.hashBdENC(bdHash);
    bdHash.clear();
    bdHash.appendString(tmpStr, 'utf-8');
  }

  print('Computed Email hash = ${bdHash.getString('utf-8')}');

  final eHash = xml.chilkatPath('UidData|Poi|(e)');
  print('Stored Email hash   = $eHash');
}