Identity & security

x/mfa — MFA

On-chain multi-factor authentication policies for sensitive operations.

Reference

What it does

The mfa module brings multi-factor authentication into consensus: accounts can enroll additional factors, and designated sensitive operations — account recovery among them — require satisfying an on-chain MFA policy before they execute.

Because the policy check happens in the state machine rather than in a client app, MFA cannot be stripped by a malicious interface: a transaction that doesn't carry the required factors simply fails validation.

Why it exists: Key compromise is the dominant failure mode of blockchain accounts. For a chain that carries identity records and payment streams, single-signature security is not enough — MFA enforced by the protocol itself closes the gap between wallet security and account security.

State

Primary objects

ConceptDefinition
Factor enrollmentRegistering an additional authentication factor against an on-chain account.
Step-up authenticationRequiring stronger factors for higher-risk operations like recovery.

Messages

Messages & queries

Message and query surfaces are documented at implementation level in the module docs ↗ and the source ↗. The objects above are the state those messages create and transition.

Connections

Module interactions

Flows

Core flow

  1. Enroll — Register factors. Additional authentication factors are enrolled against the on-chain account.
  2. Govern — Policy names operations. Chain configuration designates which operations demand MFA — recovery, privileged roles, and their kin.
  3. Step up — Sensitive flows challenge. High-risk operations require satisfying the on-chain policy before they execute.
  4. Fail closed — Missing factors fail. Non-compliant transactions fail validation regardless of which client submitted them.

Questions

Asked about x/mfa

Why put MFA on-chain instead of in wallets?

Key compromise is the dominant account failure mode, and for a chain carrying identity records and payment streams, single-signature security is not enough. Protocol-enforced factors close the gap between wallet security and account security.

What is step-up authentication?

Requiring stronger factors for higher-risk operations like account recovery — the policy escalates with the stakes of the action.

How does MFA relate to VEID?

MFA layers on VEID identity for step-up verification on sensitive flows, and privileged role-holding accounts can be required to carry stronger authentication.

x/veid module

More questions → FAQ

Related

Related modules