WPA3 (Wi-Fi Protected Access 3)

Wi-Fi Protected Access 3 (Wi-Fi Alliance, 2018) replaces WPA2's weaknesses by using Simultaneous Authentication of Equals (SAE) instead of the four-way handshake, defeating offline dictionary attacks and providing forward secrecy in personal mode. WPA3-Enterprise adds 192-bit cryptography options. WPA3 is the recommended baseline for new deployments.

Categories: Core NetworkIdentity and SubscriberSecurity Controls

WPA3 in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Subscriber identifiers (IMSI, SUPI, MSISDN, IMEI) anchor authentication, charging and lawful interception. Any protocol that leaks a permanent identifier is treated as a privacy defect, which is why 5G introduced SUCI concealment on the air interface.

To place WPA3 in the wider telecom-security picture, review NIST, UDM, WPA, SBA Token Forgery, 2G and 5G SBA — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.