Securing Home Wi-Fi with WPA3 Personal
Защита домашних сетей Wi-Fi с использованием WPA3 Personal
2021-01-09
SCID: 54.1/gu8nd4xt
Discuss with AI
WPA2WPA3 Personaldowngrade attacksmutual authenticationtransition mode
Figures from the paper
Abstract (AI)
Wi-Fi Protected Access 3 (WPA3) became a mandatory part of the Wi-Fi certification on July 1st2020. Therefore, the adoption rate of WPA3 is expected to grow soon. In this paper, we focus on WPA3 personal transition mode, in particular the security of this mode. We argue that transition mode is a requirement in home environments for the foreseeable future. We investigate whether it is possible to secure a WPA3 personal transition mode network in such a way that downgrade attacks are not feasible. We find that even with the security recommendations that the Wi-Fi Alliance recently issued for WPA3, common implementations running in transition mode can still be downgraded to WPA2. In our experiments, we can see that there are differences between WPA3 implementations in terms of security. The Wi-Fi Alliance has already announced upcoming additions to the WPA3 standard. These additions offer essential improvements to the security of WPA3 personal transition mode networks. We believe that the WPA3 certification should be extended to include the recently announced additions to WPA3. In addition to this, we make several recommendations to ensure the safe operation of WPA3. Together these changes will resolve most of the implementation differences we observed. Furthermore, we argue that mutual authentication is an essential stepping stone towards a more secure Wi-Fi ecosystem and discuss two mechanisms.
Key Findings
1
Announced additions to the WPA3 standard provide essential security improvements and resolve most observed implementation differences.
2
Common WPA3 transition-mode implementations remain vulnerable to downgrade attacks to WPA2, even when following Wi-Fi Alliance security recommendations.
3
Experiments reveal security differences among WPA3 implementations operating in transition mode.
4
The paper recommends extending WPA3 certification to include these additions and emphasizes mutual authentication as a foundation for a more secure Wi-Fi ecosystem.
5
WPA3 Personal transition mode is expected to remain necessary in home environments because WPA2 and WPA3 devices must coexist.
Research Object
WPA3 Personal transition-mode home Wi-Fi networks
Research Subject
Security of the transition mode, particularly resistance to downgrade attacks and implementation differences between WPA3 implementations
Publication Details
Publication Date
2021-01-09
Journal
Publisher
ISSN
Cited by
13
Access Type
Author Information
Download PDF
Subscribe to digest