WPA2/WPA3 Protocols
Wireless networks rely on cryptographic protocols to secure data transmission and authenticate devices. WPA2 and WPA3 are the two most prevalent standards, each with distinct cryptographic mechanisms that define their security posture. Understanding these protocols is critical for both offensive analysis and defensive hardening. This section explores their cryptographic foundations, including Pre-Shared Key (PSK) and Enterprise EAP frameworks.
WPA2 Cryptographic Mechanisms: PSK and 4-Way Handshake¶
WPA2 (Wi-Fi Protected Access 2) uses AES-CCMP (Advanced Encryption Standard with Counter Mode Cipher Block Chaining Message Authentication Code Protocol) for data encryption. The security of WPA2 hinges on the Pre-Shared Key (PSK), a shared secret between the client and the access point. Here’s how it works:
- PSK Derivation: The PSK is used to compute the Pairwise Master Key (PMK) via the PBKDF2 function.
- 4-Way Handshake: During connection, a 4-way handshake establishes the Pairwise Transient Key (PTK), which encrypts data. The handshake involves exchanging nonces (random numbers) and verifying the PMK.
- Encryption: The PTK is split into the Temporal Key (TK) for data encryption and the Key Confirmation Key (KCK) for message integrity.
Example: Capturing a WPA2 handshake with tcpdump:
Vulnerability Note: WPA2’s 4-way handshake is susceptible to the KRACK (Key Reinstallation Attacks), which exploit weak nonce reuse. This highlights the need for firmware updates and stronger key management.
WPA3 Cryptographic Enhancements: SAE and AES-CCMP¶
WPA3 (Wi-Fi Protected Access 3) introduces Simultaneous Authentication of Equals (SAE), also known as Dragonfly key exchange, to replace PSK in personal mode. Key improvements include:
- SAE (Dragonfly): SAE uses a password-based key exchange to derive a shared secret. Unlike PSK, it resists offline dictionary attacks by using a HMAC-based key derivation and mutual authentication.
- AES-CCMP: WPA3 retains AES-CCMP for encryption but adds Individualized Key Rollover (IKR) to allow frequent key changes.
- Opportunistic Wireless Encryption (OWE): Enables secure connections without a PSK by using a pre-shared SSID and a group key, ideal for public hotspots.
Example: Analyzing a WPA3 handshake with Wireshark:
Security Benefit: SAE’s mutual authentication and resistance to offline attacks make WPA3 more robust than WPA2 in personal mode.
Enterprise EAP Frameworks: WPA2-Enterprise vs. WPA3-Enterprise¶
In enterprise environments, WPA2 and WPA3 support EAP (Extensible Authentication Protocol) frameworks for centralized authentication. Key differences:
- WPA2-Enterprise:
- Uses EAP methods like EAP-TLS, EAP-PEAP, or EAP-GTC.
- The client and server exchange certificates to establish a shared secret, which is used to derive the PMK.
-
Requires a RADIUS server for authentication and key distribution.
-
WPA3-Enterprise:
- Integrates SAE as the default EAP method, replacing PSK.
- Maintains compatibility with legacy EAP methods but enhances security through SAE’s mutual authentication.
- Reduces reliance on certificate infrastructure, simplifying deployment.
Example: Configuring WPA3-Enterprise with wpa_supplicant:
network={
ssid="Enterprise-SSID"
auth_alg=SAE
key_mgmt=WPA-EAP
eap=SAE
identity="[email protected]"
password="securepassword"
}
Key takeaways¶
- WPA2 relies on PSK and AES-CCMP, with vulnerabilities like KRACK highlighting its limitations.
- WPA3 introduces SAE (Dragonfly) for personal mode, improving resistance to dictionary attacks, and retains AES-CCMP with IKR for enhanced key management.
- Enterprise EAP frameworks (e.g., EAP-TLS) enable secure, scalable authentication, with WPA3-Enterprise leveraging SAE for mutual authentication.
- Understanding these protocols is essential for both offensive analysis (e.g., cracking handshakes) and defensive strategies (e.g., mitigating vulnerabilities like KRACK).