Virtual Aadhaar ID, Limited KYC, UID Token System

Yup. Porting is happening without copies because they have automated the system. The problem is that it doesn't work for people like my dad whose fingerprints are not working anymore. They are not processing requests using otp from maadhaar app.
 
LOOK
It is so easy to rectify the leaks upto acceptable degree -
First create new private UID tokens for each Aadhaar individual in UIDAI private database. Those UIDAI UID tokens can't be known by anyone...Aadhaar holder, customer representatives, Aadhaar Centre...no one. Its so easy to create them with a software tweak.
Then having the same UIDAI UID token as base re-create the Aadhaar numbers for all users. Users can know their new Aadhaar number either via UIDAI portal or through the Centres.
THEN, they can use their VIDs with all companies whereby companies will also then have to create their own UID tokens for each customer...all without knowing the new Aadhaar numbers.
 
Last edited:
what are you going to do at places which do not have a system to accept virtual ids? places where they take a copy of your aadhaar card printout? virtual ids only work at places which require one time authentication and has the proper machinery to verify your id on the spot. it does not work at ration card stores and tons of other places. it does not fix anything unless it becomes the ONLY way companies/government can ask for you to authenticate yourself using aadhaar. i would personally not mind if they can implement such a system. but it is just not possible.

and not to mention. it does not work for people who do not have access to a mobile device that can be used to create virtual ids. and it retains the problem where one mobile number is used for multiple family members. it takes the power out of the hands of the family members who do not have access to that phone. the owner of the phone can authenticate on behalf of any of the member of the family.
 
Well...for that UIDAI can start providing institution-wise UID tokens itself.
Only registered institutions can use offline/printouts from cutomers, governement or regarding authority should pass a rule for this. The customers can feed institutions name in UIDAI portal and their new Aadhaar/VID and can get the institution specific UID token printed.
 
Source

Above UIDAI circular dated 16th May says:
"ONLY GLOBAL AUAs will have access to full e-KYC with Aadhaar number, while other entities viz. LOCAL AUAs shall have access to Limited e-KYC and will NOT be allowed to STORE Aadhaar number. UIDAI has already provided new API v2.5 documents for implementation of Virtual ID, UID Token and full / limited e-KYC."
"Local AUAs MUST use VID for performing OTP based authentication. They may however use Aadhaar number for biometric authentication. They shall NOT be allowed to store Aadhaar number in their databases." --->> so although Local ones can use Aadhaar for authentication (only if you provide them Aadhaar number) but EVEN THEN they can NOT STORE that Aadhaar number, they can only store the UNIQUE 72 character alphanumeric TOKEN. For a particular Aadhaar number different AUAs/Sub-AUAs will have different UID Tokens. These Tokens are given by UIDAI in response of successfull authentication.
The current list of Global and Local AUAs is given in pdf. Currently there are mostly Banks (regulated by RBI) in Global and many telecom operators are considered Local AUAs. So it seems, Telecom Operators will now have to delete Aadhaar number linkages from their databases and store only Unique Tokens given to them by UIDAI for each individual, and all numbers which are held by a particular customer will be linked to that single Token in respective Operator's database.
"As per this office circular dated 1.05.2018, all AUAs shall have to fully migrate to the new system by 1.07.2018, failing which their authentication services will be discontinued and financial disincentives will be imposed."

EDIT:
One more helpful document, released on 1st May, prior to above circular:
"All Local AUAs/KUAs shall ensure to REPLACE Aadhaar numbers with UID Tokens and delete all Aadhaar numbers from their database including transaction logs by 31.08.2018"
And it was in this circular that they "decided to extend the timeline for implementation of Virtual ID, UID Token and Limited e-KYC by one month to 01st July 2018 for all AUAs/KUAs and ASAs."
I went to Vodafone and Airtel Stores yesterday on 28th May and asking them about VID implementation remembering the previous date which was 1st June 2018. They knew nothing about this concept and ofcourse nothing about this extention of date.
source: Source
 
Last edited:

Top