The problem · KYC without ZK

Verify by oversharing

The Aadhaar Secure QR proves it's genuine because UIDAI signed it. But the signature covers the whole record, so to let HDFC Bank check it, you hand over everything inside. Watch what one "are you real?" check actually costs you.

What HDFC Bank actually needs

Most checks are a single yes/no. Pick what HDFC Bank genuinely needs to know:

How does HDFC perform eKYC?

It scans your Aadhaar Secure QR and verifies UIDAI's signature on it. But the QR is two things glued together: your data, and the signature over that data.

SECURE QR data name · DOB · gender address · pincode photo (biometric) σ · signature Verify signature with UIDAI public key

The irony: it's called the Secure QR, yet proving it's genuine means handing over everything inside it.

Hand over the Secure QR

Drop in your real e-Aadhaar PDF to see exactly what HDFC Bank receives.

Upload your e-Aadhaar PDF or QR image Drag & drop, or click to choose
…or paste the QR contents

Runs entirely in your browser; nothing is uploaded. Upload an e-Aadhaar PDF or paste its QR contents to continue.

Activity

HDFC Bank · server log

        

The shunya way

A zero-knowledge proof flips this. The math checks UIDAI's signature on your device, and HDFC Bank receives only the one answer it asked for, plus an app-scoped nullifier so it can still block duplicates. Your name, photo, date of birth and address never leave your phone.

With a ZK proof, HDFC Bank learns only your answer, and nothing else.