Aadhaar E-Sign
Definition
India's authentication-linked electronic signature service in which the user's Aadhaar biometric or OTP authentication triggers the generation of a short-validity signing certificate by a licensed Certifying Authority, which is used to sign the document and then immediately discarded. Authorised under the Electronic Signature Rules 2015.
- Country
- India
- Trigger
- Aadhaar biometric or OTP authentication
- Certificate lifespan
- Short-validity, single use
- Legal basis
- Electronic Signature Rules 2015
Common questions
How does this differ from a conventional digital signature certificate?+
A conventional certificate is issued once and held by the user for repeated use. Aadhaar e-Sign instead generates a fresh, short-validity certificate at the moment of signing and discards it immediately afterward.
What happens to the certificate after a document is signed?+
It is not retained. The Certifying Authority generates it only for that single signing event and discards it once the signature is applied, so it cannot be reused for a later document.
Related terms
- ESIGN Act (Electronic Signatures in Global and National Commerce Act)
- US federal legislation (2000) providing that no electronic signature may be denied legal effect solely because it is in electronic form. Technology-neutral:...
- EU Trusted List (EUTL)
- The authoritative list maintained by the European Commission listing all Trust Service Providers per EU member state that are supervised to issue...
- Long-Term Validation (LTV)
- A PDF signature profile (PAdES-LTV, ETSI EN 319 102-1) in which the OCSP responses, CRL data, and TSA certificate chain information are...
- OCSP (Online Certificate Status Protocol)
- A real-time certificate revocation protocol in which the verifier queries the CA's OCSP responder with the certificate's serial number and receives a...
- Public Key Infrastructure (PKI)
- The system of hardware, software, policies, and standards that manage digital certificates and public-key encryption. Provides the trust architecture underpinning all cryptographic...
- QSCD (Qualified Signature Creation Device)
- A hardware or remote HSM-based device that stores the signer's private key such that it cannot be extracted, ensuring sole control under...
- Qualified Electronic Signature (QES)
- The highest tier of electronic signature under EU eIDAS Regulation 910/2014. Created by a Qualified Signature Creation Device (QSCD), backed by a...
- TSA Timestamp (Timestamp Authority)
- A cryptographically protected record of the time at which a signature was created, issued by a Timestamp Authority (TSA) whose own certificate...
- X.509 Certificate
- A digitally signed data structure that binds a public key to a named identity (subject) and is issued by a Certificate Authority....