WPA vs WEP: How your Choice Affects your Wireless Network Security
An exploration of the reasons why WPA provides stronger wireless security than WEP in your wireless network
What is WPA?
WiFi Protected Access (WPA) is the new security standard adopted by the WiFi Alliance consortium. WiFi compliance ensures interoperability between different manufacturer’s equipment.
WPA delivers a level of security way beyond anything that WEP can offer, bridges the gap between WEP and 802.11i networks, and has the advantage that the firmware in older equipment may be upgradeable.
How does WPA work?
WPA uses Temporal Key Integrity Protocol (TKIP). TKIP is designed to allow WEP to be upgraded. This means that all the main building blocks of WEP are present, but corrective measures have been added to address security problems.
How WPA improves on WEP
The weaknesses in WEP have been well publicized. TKIP’s improvements are described below.
IV values can be reused/IV length is too short
The length of the IV has been increased from 24bits to 48bits. Rollover of the counter is eliminated. Reuse of keys is less likely.
In addition IVs are now used as a sequence counter, the TSC (TKIP Sequence Counter), protecting against replaying of data, a major vulnerability in WEP.
Weak IV values are susceptible to attack
WPA avoids using known weak IV values. A different secret key is used for each packet, and the way the key is scrambled with the secret key is more complex.
Master keys are used directly in WEP
Master Keys are never used directly in WPA. A hierarchy of keys is used, all derived from the Master. Cryptographically this is a much more secure practice.
Key Management and updating is poorly provided for in WEP
Secure key management is built-in to WPA, so key management isn’t an issue with WPA.
Message integrity checking is ineffective
WEP message integrity proved to be ineffective. WPA uses a Message Integrity Check (MIC) called, Michael! Due to the hardware constraints the check has to be relatively simple. In theory there is a one in a million chance of guessing the correct MIC. In practice any changed frames would first need to pass the TSC and have the correct packet encryption key even to reach the point where Micheal comes into operation. As further security Michael can detect attacks and performs countermeasures to block new attacks.
Conclusion
WPA (TKIP) is a great solution, providing much stronger security than WEP, addressing all the weaknesses and allowing compatibility and upgrades with older equipment.
Related articles:
- Wireless Network Security vs Wire Based Network Security
- Analysing Wireless Networks
- What Types of Network Security Attacks are Perpetrated?
- Who Perpetrates Network Security Attacks?
- Network Security Attacks
- Retina Network Security Scanner
- Why is WEP crackable? How WEP weaknesses affect your wireless network security
- What is WiFi? An Introduction to Wireless Networks for the Small/Medium Enterprise
- Wireless Network Planning and Deploying
- WPA vs WPA2 (802.11i): How your Choice Affects your Wireless Network Security






Comments
WPA
assh.... give some examples that newbees can work out from..........
Speed
If you want speed use a wire solution
IPOD touch runs on WEP , Vista computers on WPA
what do I do? can't have best of both worlds?
If you update to the newest
If you update to the newest firmware on your itouch, it should run on wpa. Mines wpa.
playstation3
where would i find wpa key
wpa vs wep
is the data transfer is slower in wep yhan wpa?
wpa vs wpa2
whats the difference between wpa and wpa2. whats the difference between personal and enterprise. is there any security level difference?
We've written an article
We've written an article comparing WPA vs WPA2. Hopefully that will answer some of your questions.
Jack Hughes co-founded OPENXTRA Limited and serves on the company board as Chief Technical Officer. Jack also blogs as The Tech Teapot.
reply
being a teacher i wanted to make a note for teh new IGCSE o/l syllabus.. ur article was very helpful.
that is very good gold star
that is very good gold star
I like how you didn't mention
I like how you didn't mention that WPA slows down your connection speed quite noticably compared to WEP.
Speed over security
Yeah... speed is much more important than security...
WPA vs WEP
speed might be important but not at the risk of your privacy and data integrity. I would rather have a relatively average speed where my data is secure and my privacy is guarded instead of a blazingly fast speed where my data integrity and my privacy are at the mercy of the identity thief or hacker!
wep v wap
I just read your article and the easy way you discribed the differences was easy to understand. Thanks for the tips... Willow... from the UK
Great article
Great! I based my assignment from one of my networking units on that! Thanks! :)
wep vs wpa
I just wanted a quick look at how does it work and it was good enough to give me understanding.
Thank You!
Post new comment