Step-Up Authentication vs 2FA: Implementing Additional Verification for Sensitive Operations in Corporate Systems
Two-factor authentication (2FA) has become a standard for protecting corporate systems, yet it often proves insufficient for handling personal data or other high-risk operations. While 2FA verifies identity only at login and then grants access for the duration of the trusted session, modern attacks increasingly target already-active sessions. This limitation prompted the adoption of Step-Up Authentication, which requests additional confirmation precisely when a user attempts a sensitive action.
Why Standard 2FA Falls Short
Common second factors include SMS or Email OTP, TOTP from authenticator apps such as Yandex Key, Google Authenticator, Microsoft Authenticator, or Authy, and other one-time codes. These methods protect the login process effectively but do not re-verify identity during an ongoing session. As a result, prolonged sessions or shared devices can expose critical resources without further checks.
What Step-Up Authentication Provides
Step-Up Authentication differs by triggering extra verification only at the point of elevated-risk operations. Typical scenarios include work on shared devices, long-lived sessions, or access requests that demand a higher trust level than the initial login provided. In the described project, this mechanism was applied specifically when users attempted to retrieve salary information, requiring re-authentication only for selected APIs.
The technical foundation relies on ACR (Authentication Context Class Reference) values embedded in tokens. These values indicate whether login occurred with password alone or with an additional OTP. Applications inspect the ACR claim and either grant access or redirect the user for further authentication.
Project Implementation Challenges and Solution
Although Keycloak and WSO2 both support Step-Up Authentication out of the box, the project’s business requirements exceeded standard capabilities. The PIN code had to remain valid for six months, external systems needed to treat it as a user password, and verification had to occur at a separate gateway layer independent of the Identity Provider. These constraints made heavy customization of WSO2 impractical.
The team therefore created an independent PIN-code service and a dedicated gateway-2fa microservice. Only requests to protected APIs pass through this gateway; all other traffic follows the normal route. The flow works as follows:
- The web application directs the user to the PIN service to generate a code.
- The service creates an encrypted PIN, stores it, and delivers it via email and SMS.
- After successful entry, the service issues a signed cookie with a defined TTL confirming Step-Up completion.
- On subsequent protected calls, gateway-2fa validates the cookie and cross-checks key JWT fields; mismatches result in denial of access.
User Experience and Monitoring
From the user’s perspective, the additional step appears only when accessing protected data. A 401 response prompts PIN entry; successful validation sets the cookie, after which the user can work with sensitive resources until the TTL expires (set to 20 minutes in this implementation). Incorrect PIN attempts simply keep the resource inaccessible.
Usage statistics are collected in Matomo and technical metrics in ELK, enabling early detection of performance issues or unusual patterns.
Key Considerations for Deployment
Successful rollout requires careful definition of TTL duration, strong encryption for stored PINs, load testing of the additional service, and logging that supports incident investigation without exposing sensitive user data. The resulting architecture strengthens protection for critical operations while preserving a seamless login experience and supporting Zero Trust principles.
Related articles
Neuromorphic Chips: Event-Driven Architectures Aim to Cut Energy Use in Always-On AI and Sensor Systems
Modern processors and GPUs excel at massive parallel math yet remain inefficient for continuous sensor streams where little changes most of the time. Neuromorphic chips borrow principles such as local memory, sparse spiking communication and threshold-based activation from biological nervous systems to reduce data movement and idle computation. The approach replaces constant matrix multiplications with asynchronous spikes that propagate only when meaningful events occur, lowering both power and latency for edge devices. Spiking neural networks encode information in the timing and frequency of pulses rather than dense numeric tensors, making them suitable for vibration monitoring, robotic vision and wearable health sensors. Hybrid systems are expected to pair conventional CPUs and NPUs for heavy training workloads with neuromorphic accelerators that stay dormant until events arrive. The architecture does not replace existing accelerators but targets the niche of always-on, battery-constrained perception tasks where conventional von Neumann designs hit the memory wall.
Russia Boosts Digitalization Budget by 58% Using Telecom Operators' Universal Service Fund
The Russian government has significantly increased allocations for digital projects from the universal service reserve funded by telecom operators. In the 2027 draft budget, 16.3 billion rubles are earmarked for digital solutions, up 58% from the previously planned 10.3 billion rubles. The funds will support the national project Data Economy and the state program Information Society, covering state information systems, digital platforms, cloud infrastructure, AI projects, and quantum technologies. The operator contribution rate remains unchanged at 2% of revenue, with no new levies under consideration. Funding for connecting small settlements to the internet stays at 19.3 billion rubles, while allocations from traffic fines for digitalization are being reduced.
GigaChat Creates New Continuation of Gogol's Dead Souls Under Expert Supervision
Sber's GigaChat generative AI model has produced a new version of the second volume of Nikolai Gogol's Dead Souls, which the author himself destroyed in 1852. The project involved training the model on Gogol's writings, letters, drafts, works by his contemporaries, and philosophical and religious texts that may have influenced the writer. Historians, literary scholars, linguists, and engineers guided the process to ensure the creation of original images and meanings rather than recycled phrases. Experts reviewed every fragment of the generated text for authenticity and quality. Illustrations were also produced by an AI model based on the style of Alexander Agin, who illustrated the first volume during Gogol's lifetime. Sber states the goals are to demonstrate AI as a creative and analytical tool in the hands of specialists and to attract younger readers to Russian classics. Vladislav Kreynin noted that the work does not resolve debates about the lost original manuscript.
Why Defending a Company Costs Millions While Attacks Can Succeed for Just Hundreds of Dollars
In the latest episode of Belyaev Podcast, CISO Vyacheslav Kasimov of Tochka Bank and Boris Evdokimov of ASNA pharmacy chain discussed the persistent asymmetry in cybersecurity spending. Attackers increasingly rely on affordable cloud services, automation, and rented infrastructure, while defenders must invest heavily in monitoring, access controls, backups, and skilled teams. The experts stressed that the absence of known breaches does not equal security, as undetected incidents or delayed discovery remain common risks. They advocated shifting from a "no" culture to risk-based decision making that helps business leaders understand potential losses, mitigation costs, and residual risk. The conversation also covered responsible use of AI in SOC operations and the long-term damage caused by loss of customer trust after incidents.