(1)After collecting the Jan-Aadhaar ID or any other identifier provided by the requesting entity or a person which is mapped to Jan-Aadhaar ID and necessary identity information and/ or One Time Pin from the Jan- Aadhaar ID holder, the client application shall immediately package and encrypt these input parameters into Jan-Aadhaar ID block before any transmission, as per the specifications laid down by the Authority, and shall send it to server of the requesting entity or a person using secure protocols as may be laid down by the Authority for this purpose.
(2) After validation, the server of a requesting entity or a person shall pass the authentication request to the Jan-Aadhaar Resident Data Repository, through the server of the Authentication Service Agency or a person as per the specifications laid down by the Authority. The authentication request shall be digitally signed or e-signed by the requesting entity and/or by the Authentication Service Agency, as per the mutual agreement between them.
(3) Based on the mode of authentication request, the Jan-Aadhaar Resident Data Repository shall validate the input parameters against the data stored therein and return a digitally signed or e-signed Yes or No authentication response, or a digitally signed or e-signed e-FA/e-MA authentication response with encrypted e-FA/e-MA data, 85 the case may 06, along with other technical details related to the authentication transaction.
(4) In all modes of authentication, the Jan-Aadhaar ID is mandatory and is submitted along with the input parameters specified in sub-rule (1) above such that authentication is always reduced to a 1:1 match.
(5) A requesting entity shall ensure that encryption of Jan-Aadhaar ID Block takes place at the time of capture on the authentication device as per the processes and specifications laid down by the Authority.