WPA3 and the SAE Handshake
Chapter One Hundred Six
Syllabus topic Module 2, "Wireless Network Security and Authentication Mechanisms: Compare WEP, WPA, WPA2, WPA3 protocols"
Pages 488 to 491 of 578
In one line
WPA3 is the current standard, and its central improvement is a new handshake, SAE, designed so that capturing it does not enable offline guessing of the passphrase, fixing exactly WPA2's main weakness. It keeps AES, and adds forward secrecy and protected management frames.
In examination wording: WPA3 is the current wireless security standard, retaining AES encryption but replacing the four-way handshake's key establishment with Simultaneous Authentication of Equals, which resists offline dictionary attack because each guess requires a fresh interaction with the network; it also provides forward secrecy and mandatory protection of management frames.
WPA3 as the answer to a specific weakness
The previous chapter left WPA2 with one main practical weakness: capturing the four-way handshake lets an attacker guess the passphrase offline, at full speed on their own hardware, so a weak passphrase falls. WPA3's central purpose is to fix exactly that weakness, and teaching it as the targeted answer is the cleanest way to understand it.
WPA3 keeps what WPA2 got right, the strong AES cipher, and changes what WPA2 got wrong, the handshake. So the comparison the block builds resolves neatly: WEP broken, WPA a stop-gap, WPA2 sound but for its handshake and passphrase, WPA3 the same soundness with the handshake weakness removed.
The SAE handshake
WPA3-Personal replaces the key-establishment step with a handshake called SAE (Simultaneous Authentication of Equals, sometimes called the Dragonfly handshake). The concept-level point is not the cryptographic detail but what it achieves:
Under WPA2, capturing the handshake gave the attacker something they could take away and test guesses against offline, so the attacker could try millions of passphrases per second without further contact with the network. Under SAE, capturing the handshake does not give the attacker that: the design requires that each passphrase guess involve a fresh interaction with the network, so an attacker cannot grind millions of guesses against a captured file offline. They would have to make each guess by actually interacting with the access point, which is slow, detectable, and rate-limitable.
So SAE removes the offline-guessing attack. The consequence is that a captured WPA3 handshake is not the springboard for offline passphrase cracking that a WPA2 handshake is, which is the central security improvement and the reason WPA3 exists. It also means that even a somewhat weaker passphrase is far more resistant under WPA3 than under WPA2, because the attacker cannot use offline speed against it, though a strong passphrase is still recommended.
The other improvements
WPA3 adds two more protections a student should know:
Forward secrecy. WPA3 provides forward secrecy, the property from the encryption chapters: each session's keys are derived so that compromising the passphrase later does not decrypt previously captured traffic. Under this, an attacker who records encrypted traffic and only later obtains the passphrase cannot go back and decrypt the recorded traffic, because the session keys were not simply derivable from the passphrase. This limits the damage of a passphrase compromise, exactly as forward secrecy limited the damage of the Heartbleed key exposure.
WPA3 and the SAE Handshake
Protected management frames. WPA3 makes protection of management frames mandatory. The wireless-basics chapter noted that some management frames are, in older standards, unauthenticated, which enables attacks like deauthentication (the next chapter). Protecting management frames defends against a class of those attacks, hardening the network against forced disconnection and certain spoofing.
WPA3 also improves the experience of open networks (with opportunistic encryption for networks that have no passphrase) and strengthens the Enterprise mode, but the examinable core is the SAE handshake, forward secrecy, and protected management frames.
The completed comparison
The four standards, side by side, which is MU's explicit request:
| WEP | WPA | WPA2 | WPA3 | |
|---|---|---|---|---|
| Cipher | RC4 (broken use) | RC4 + TKIP | AES (CCMP) | AES |
| Key establishment | (weak) | (improved) | Four-way handshake | SAE |
| Offline passphrase guessing from a capture | n/a (key recovered) | possible | possible (the weakness) | prevented |
| Forward secrecy | No | No | No | Yes |
| Management-frame protection | No | No | Optional | Mandatory |
| Status | Broken; never use | Superseded | Long standard; acceptable | Current; preferred |
Read across the "offline passphrase guessing" row and the story of the block is visible: WEP surrenders the key, WPA2 leaves the passphrase guessable offline, and WPA3 closes that. WPA3 is the current standard and the preferred choice where the hardware supports it.
A worked example, framed defensively
An assessor reviews a client's wireless standards and recommends the target state, from beacons (passive), on the client's own networks with authorisation.
- The main network is WPA2-AES. Acceptable, but its security rests on the passphrase because of the four-way handshake's offline-guessing weakness. Recommendation: move to WPA3 where the access points and devices support it, because SAE removes the offline-guessing weakness, and WPA3 adds forward secrecy and protected management frames.
- Some older devices support only WPA2. The assessor notes the practical reality: a transition period may run WPA2/WPA3 mixed mode, and until all devices support WPA3, a strong passphrase remains essential because WPA2's weakness still applies to the WPA2 clients.
- The assessor recommends management-frame protection (mandatory in WPA3, available as an option on WPA2) to defend against the deauthentication attacks of the next chapter.
- The assessor does not capture handshakes or attempt cracking; the recommendation follows from the standards in use and their known properties.
The report resolves the block's comparison for the client: WPA3 is the target because it fixes WPA2's offline-guessing weakness and adds forward secrecy and management-frame protection, with a strong passphrase essential during any WPA2 transition. The assessor establishes everything from the advertised standards, not by attacking the network.
WPA3 and the SAE Handshake
What beginners get wrong
- Not knowing what WPA3 specifically fixes. Its central improvement is the SAE handshake, which prevents the offline passphrase guessing that capturing a WPA2 handshake enables; that is the point of WPA3.
- Thinking WPA3 changed the cipher. It keeps AES; it changed the key establishment (SAE) and added forward secrecy and management-frame protection.
- Believing SAE lets an attacker read traffic from a captured handshake. It prevents offline guessing by requiring each guess to involve a fresh interaction with the network, so a captured handshake is not a springboard for offline cracking.
- Overlooking forward secrecy. WPA3 ensures that obtaining the passphrase later does not decrypt previously captured traffic, limiting the damage of a passphrase compromise.
- Ignoring management-frame protection. WPA3 makes it mandatory, defending against deauthentication and certain spoofing attacks that exploit unauthenticated management frames.
- Assuming a strong passphrase no longer matters on WPA3. SAE makes even a weaker passphrase far more resistant, but a strong passphrase is still recommended, and it remains essential wherever WPA2 clients are present.
Quick revision
- WPA3 is the current standard; it keeps AES and replaces the key establishment with the SAE handshake.
- SAE's central improvement: capturing the handshake does not enable offline passphrase guessing, because each guess requires a fresh interaction with the network, so the attacker cannot grind millions of guesses against a captured file. This fixes exactly WPA2's main weakness.
- Also: forward secrecy (obtaining the passphrase later does not decrypt previously captured traffic) and mandatory protected management frames (defends against deauthentication and spoofing).
- Comparison resolved: WEP broken, WPA superseded, WPA2 sound but offline-guessable via the handshake, WPA3 closes the offline-guessing weakness and is preferred. During a WPA2 transition, a strong passphrase remains essential.
Test yourself
- What weakness of WPA2 does WPA3 specifically fix, and how?
WPA3 fixes WPA2's weakness that capturing the four-way handshake lets an attacker guess the passphrase offline at full speed. It does so by replacing the key establishment with the SAE handshake, which is designed so that each passphrase guess requires a fresh interaction with the network, so an attacker cannot take a captured handshake away and grind millions of guesses against it offline, removing the offline-guessing attack.
- Does WPA3 change the encryption cipher, and what does it change?
No; WPA3 retains AES, the strong cipher that WPA2 already used correctly. What it changes is the key establishment, replacing the four-way handshake with the SAE handshake to prevent offline passphrase guessing, and it adds forward secrecy and makes protection of management frames mandatory. The soundness of WPA2's cipher was not the problem, so it was kept.
- What does forward secrecy provide in WPA3, and why does it matter?
WPA3 and the SAE Handshake
Forward secrecy ensures that each session's keys are derived so that compromising the passphrase at a later time does not allow decryption of traffic captured earlier. It matters because an attacker who records encrypted traffic and only afterwards obtains the passphrase cannot go back and decrypt the recorded traffic, so a passphrase compromise does not retrospectively expose past sessions, limiting its damage in the same way forward secrecy limited the impact of the Heartbleed key exposure.
- What is the security value of mandatory protected management frames in WPA3?
Because some management frames were unauthenticated in older standards, they could be forged, enabling attacks such as deauthentication that force a device to disconnect, and certain spoofing. WPA3 makes protection of management frames mandatory, which authenticates them and defends against that class of attacks, hardening the network against forced disconnection and related manipulation.
- Why does a strong passphrase remain essential during a transition to WPA3?
Because until all devices support WPA3 a network may run in a mixed mode that still serves WPA2 clients, and for those clients the WPA2 weakness applies: capturing their four-way handshake enables offline passphrase guessing. So while SAE protects WPA3 clients, a weak passphrase would still be crackable through the WPA2 clients, making a strong passphrase essential until the network is fully WPA3.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.