From WEP to WPA3: The History of Wireless Security Protocols
In today’s digital age, ensuring the security of each wireless network is critical. But how did we reach the level of security we enjoy today? What were the pivotal stages in enhancing wireless communication security? Wireless network security protocols have come a long way from the insecure WEP to the robust and continually evolving WPA3. The evolution continues to adapt to constantly emerging threats and technological advancements in wireless communication.
In this article, I will take you on a journey to uncover the development of wireless security protocols. These are the tools and techniques that have evolved over time to protect our wireless connections from different potential threats.
What is a security protocol
A security protocol is like a set of rules and procedures that protect a Wi-Fi connection from unauthorised access. This is a sort of secret handshake between devices and the router to ensure that only users who knows that secret code have access to the network. This protocol helps encrypt data transmitted over Wi-Fi, so it’s like sending information in a locked box that only you and your devices can open.
WEP
WEP stands for Wired Equivalent Privacy. It was formally released 1997 and 1999 and designed to provide some level of privacy and data security over wireless networks that was considered equivalent to the security of wired networks. However, WEP had serious security flaws and is now considered highly vulnerable. It used 40-bit encryption key, and weak initialisation vectors (IVs) that repeat over time, making it easier for hackers to decipher the static encryption key.
Note that some older devices and legacy systems may still rely on WEP for compatibility reasons, but in general, using WEP in modern networks is strongly discouraged due to its security weaknesses, so replace your old wireless device with a new one.
WPA
WPA stands for Wi-Fi Protected Access. It is a security protocol designed to address the vulnerabilities and weaknesses of its predecessor, WEP (Wired Equivalent Privacy). WPA uses TKIP (Temporal Key Integrity Protocol) as its encryption algorithm which dynamically generates unique encryption keys for each data packet, making it much harder for attackers to crack the encryption compared to the static keys used in WEP.
WPA offers a PSK (Pre Shared Key) mode, also known as WPA-PSK or WPA Personal, which allows home users and small businesses to use a passphrase as a shared secret key for authentication purposes, simplifying network setup. WPA also supports an enterprise mode, known as WPA-EAP or WPA-Enterprise, which is typically used in larger organisations. It integrates with authentication servers like RADIUS (Remote Authentication Dial-In User Service) for more secure and scalable user authentication.
WPA also had some security vulnerabilities, so it was replaced by WPA2.
WPA2
WPA2, stand for Wi-Fi Protected Access 2. It is widely used security protocol for wireless networks. It represents a significant improvement over its predecessor, WPA. Here are some important features of WPA2.
This protocol uses the Advanced Encryption Standard (AES) protocol, which is considered highly secure. AES is a symmetric key encryption algorithm that encrypts data with a 256-bit key, making it extremely difficult for attackers to decipher intercepted data.
It also improved key management in comparison to previous WPA. It utilises a 4-way handshake process to securely exchange encryption keys between the client device and the wireless access point (AP). This process boost security.
WPA2 offers both PSK (WPA2-PSK or WPA2-Personal) and Enterprise (WPA2-EAP or WPA2-Enterprise) modes. In PSK mode, a pre-shared passphrase is used for authentication, while Enterprise mode employs a RADIUS (Remote Authentication Dial-In User Service) server for more robust and scalable user authentication.
Over time, some vulnerabilities in the WPA2 protocol have been discovered, such as the KRACK attack (key reinstallation attack). To mitigate the problem, security patches/updates have been developed. WPA2 is the industry standard – a widely used and recognised wireless security protocol, compatible with all modern Wi-Fi devices.
It is worth noting that as technology evolves, new safety standards are introduced, such as WPA3. As it is the newest one, it is not compatible with older devices.
WPA3
WPA3 introduced a significant improvement in comparison to WPA2 in terms of security and privacy features, such as stronger encryption, personalised data protection, high resistance to offline attacks and improved long-term security with forward secrecy. WPA3 will become widely used and integrated into new devices and routers some point in the future. However, please note that the current availability of WPA3 support depends on network hardware and devices, so it is worth checking compatibility when updating your network.
If you are interested, you can read an article with comprehensive comparison WPA2 and WPA3
