Securing Home Wi-Fi with WPA3 Personal

Защита домашних сетей Wi-Fi с использованием WPA3 Personal
Erik P. Lamers, Raoul Dijksman, Arjan van der Vegt, Mayur Sarode, Cees de Laat
2021-01-09

WPA2WPA3 Personaldowngrade attacksmutual authenticationtransition mode
Wi-Fi Protected Access 3 (WPA3) became a mandatory part of the Wi-Fi certification on July 1st2020. Therefore, the adoption rate of WPA3 is expected to grow soon. In this paper, we focus on WPA3 personal transition mode, in particular the security of this mode. We argue that transition mode is a requirement in home environments for the foreseeable future. We investigate whether it is possible to secure a WPA3 personal transition mode network in such a way that downgrade attacks are not feasible. We find that even with the security recommendations that the Wi-Fi Alliance recently issued for WPA3, common implementations running in transition mode can still be downgraded to WPA2. In our experiments, we can see that there are differences between WPA3 implementations in terms of security. The Wi-Fi Alliance has already announced upcoming additions to the WPA3 standard. These additions offer essential improvements to the security of WPA3 personal transition mode networks. We believe that the WPA3 certification should be extended to include the recently announced additions to WPA3. In addition to this, we make several recommendations to ensure the safe operation of WPA3. Together these changes will resolve most of the implementation differences we observed. Furthermore, we argue that mutual authentication is an essential stepping stone towards a more secure Wi-Fi ecosystem and discuss two mechanisms.
1
Announced additions to the WPA3 standard provide essential security improvements and resolve most observed implementation differences.
2
Common WPA3 transition-mode implementations remain vulnerable to downgrade attacks to WPA2, even when following Wi-Fi Alliance security recommendations.
3
Experiments reveal security differences among WPA3 implementations operating in transition mode.
4
The paper recommends extending WPA3 certification to include these additions and emphasizes mutual authentication as a foundation for a more secure Wi-Fi ecosystem.
5
WPA3 Personal transition mode is expected to remain necessary in home environments because WPA2 and WPA3 devices must coexist.

WPA3 Personal transition-mode home Wi-Fi networks

Security of the transition mode, particularly resistance to downgrade attacks and implementation differences between WPA3 implementations

Publication Details
Publication Date
2021-01-09
Journal
Publisher
ISSN
Cited by
13
Access Type
Author Information
Authors
Erik P. Lamers
Raoul Dijksman
Arjan van der Vegt
Mayur Sarode
Cees de Laat
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%