What is Wi-Fi Security Standard

1. The Evolution of Standard

YearStandardCipherCurrent StatusTypical use cases
1997OpenNA or RC4still used with portal or MAC authenticationIn public place, airport, mall, exhibtion, hotel …
1997WEPRC4 (40/104-bit)Fully deprecated; crackable in minutesdon’t suggest to use now
2003WPA (interim fix)TKIP + Michael MICDeprecated; TKIP has been brokendon’t suggest to use now
2004WPA2 (IEEE 802.11i)CCMP-128 (AES)Current mainstream; secure but structurally weakat home, small office, IoT devices …
2018WPA3 (Wi-Fi Alliance certification)CCMP-128 / GCMP-256Latest standard; rolling out graduallyenterprise, home, ….

WPA was an emergency stopgap released after WEP collapsed — it kept RC4 and bolted on TKIP for key mixing. WPA2 was the real fix that moved to AES. And WPA3 is not a new protocol — it is a Wi-Fi Alliance certification program that mandates replacing PSK with SAE and making PMF compulsory.

2. The Acronym of some key words

AcronymFull NameWhat It Is
WEPWired Equivalent PrivacyThe original 1997 Wi-Fi encryption, based on RC4. Broken; never use it
WPAWi-Fi Protected Access2003 interim replacement for WEP. Used TKIP. Also deprecated
WPSWi-Fi Protected SetupNot an encryption protocol — a convenience feature for easy device pairing (PIN or push-button). Its 8-digit PIN is brute-forceable; disable it
TKIPTemporal Key Integrity ProtocolWPA’s cipher. Wraps RC4 with per-packet key mixing + Michael MIC. Broken; caps throughput at 54 Mbps
CCMPCounter Mode with Cipher Block Chaining Message Authentication Code ProtocolWPA2’s cipher. Built on AES-CCM — provides both confidentiality and integrity. The “good” one
GCMPGalois/Counter Mode ProtocolBuilt on AES-GCM. Used in WPA3-Enterprise 192-bit mode as GCMP-256. Faster and stronger than CCMP
PSKPre-Shared KeyWPA2-Personal’s authentication method: one shared passphrase for the whole network. This is what SAE replaces
AESAdvanced Encryption StandardThe underlying block cipher (Rijndael), 128/192/256-bit keys. CCMP and GCMP are both modes of operation built on top of AES
SAESimultaneous Authentication of EqualsWPA3-Personal’s key agreement, based on the Dragonfly PAKE (RFC 7664). Blocks offline dictionary attacks and provides forward secrecy
PMFProtected Management FramesIEEE 802.11w. Encrypts and integrity-protects management frames. Optional in WPA2, mandatory in WPA3. Blocks forged deauth attacks

3. Why recommend WPA3

ItemsWPA2-PSKWPA3-SAE
PMK originDerived directly from password + SSID, fixed and unchangingEphemeral random values participate in every handshake; different each time
Offline cracking✅ Capture one handshake, retry forever❌ Each exchange is fresh; captured data is useless
Cost of a guessNone — the AP never learnsEvery attempt must complete a live exchange with the AP, which can rate-limit and log it
Forward secrecyNone✅ Yes
DimensionWPA2-PersonalWPA3-Personal
Key agreementPSK + 4-way handshakeSAE (Dragonfly PAKE) + 4-way handshake
Resists offline dictionary❌ Capture one handshake, retry forever✅ Must attempt online; rate-limitable and detectable
Forward secrecy❌✅
PMF (management-frame protection)OptionalMandatory
Cipher suiteCCMP-128 (can degrade to TKIP)CCMP-128 (TKIP not permitted)
Open-network encryptionNoneOWE
Consequence of a weak passwordCatastrophic (offline crack in seconds)Greatly mitigated, but not invulnerable
Device compatibilityEssentially all devicesMid-to-high-end devices from 2019 onward; much IoT unsupported
Handshake overheadMinimalHigher (slower association on low-end devices)

4. What to Choose in Practice

Ideal case: every device supports it → run pure WPA3, disable transition mode, eliminate the downgrade vector.

Real-world case: there is always some legacy gear in the house (smart plugs, old printers, early robot vacuums, an old TV) that flatly refuses to join WPA3. The recommended workaround is a dual-SSID setup:

Primary SSID: WPA3-Personal + strong passphrase
              → phones, laptops, tablets

IoT SSID:     WPA2-PSK (AES) + PMF forced on
              → smart plugs, printers, cameras, other legacy gear
              → placed on a separate VLAN, barred from the main subnet

This keeps your primary devices secure without sacrificing compatibility, while isolating the least trustworthy IoT equipment — and IoT is precisely the layer of a home network most often used as a pivot point.

If transition mode is unavoidable: at minimum confirm the router firmware is current (so the Dragonblood-related implementation fixes are in place), and use a passphrase of 16+ random characters.

Enterprise environments: WPA3-Enterprise + EAP-TLS client certificates + mandatory server-certificate validation on clients. That last point matters enormously — many organisations deploy 802.1X yet leave “do not validate server certificate” selected on the client side, which effectively leaves the man-in-the-middle door wide open.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top