Skip to content

Aadhaar E-Sign

Definition

India's authentication-linked electronic signature service in which the user's Aadhaar biometric or OTP authentication triggers the generation of a short-validity signing certificate by a licensed Certifying Authority, which is used to sign the document and then immediately discarded. Authorised under the Electronic Signature Rules 2015.

Country
India
Trigger
Aadhaar biometric or OTP authentication
Certificate lifespan
Short-validity, single use
Legal basis
Electronic Signature Rules 2015

Common questions

How does this differ from a conventional digital signature certificate?+

A conventional certificate is issued once and held by the user for repeated use. Aadhaar e-Sign instead generates a fresh, short-validity certificate at the moment of signing and discards it immediately afterward.

What happens to the certificate after a document is signed?+

It is not retained. The Certifying Authority generates it only for that single signing event and discards it once the signature is applied, so it cannot be reused for a later document.

Related terms

ESIGN Act (Electronic Signatures in Global and National Commerce Act)
US federal legislation (2000) providing that no electronic signature may be denied legal effect solely because it is in electronic form. Technology-neutral:...
EU Trusted List (EUTL)
The authoritative list maintained by the European Commission listing all Trust Service Providers per EU member state that are supervised to issue...
Long-Term Validation (LTV)
A PDF signature profile (PAdES-LTV, ETSI EN 319 102-1) in which the OCSP responses, CRL data, and TSA certificate chain information are...
OCSP (Online Certificate Status Protocol)
A real-time certificate revocation protocol in which the verifier queries the CA's OCSP responder with the certificate's serial number and receives a...
Public Key Infrastructure (PKI)
The system of hardware, software, policies, and standards that manage digital certificates and public-key encryption. Provides the trust architecture underpinning all cryptographic...
QSCD (Qualified Signature Creation Device)
A hardware or remote HSM-based device that stores the signer's private key such that it cannot be extracted, ensuring sole control under...
Qualified Electronic Signature (QES)
The highest tier of electronic signature under EU eIDAS Regulation 910/2014. Created by a Qualified Signature Creation Device (QSCD), backed by a...
TSA Timestamp (Timestamp Authority)
A cryptographically protected record of the time at which a signature was created, issued by a Timestamp Authority (TSA) whose own certificate...
X.509 Certificate
A digitally signed data structure that binds a public key to a named identity (subject) and is issued by a Certificate Authority....

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.