Enhanced Open (Opportunistic Wireless Encryption)

A Wi-Fi mode that encrypts traffic on an open network with no password, using a key exchange at association, but authenticates neither the user nor the access point.

Enhanced Open is the Wi-Fi Alliance certification name for Opportunistic Wireless Encryption (OWE), defined in RFC 8110 (2017). It addresses the open hotspot, where anyone can join and traffic travels unencrypted. With OWE, the client and the access point run a Diffie-Hellman key exchange as the client associates, so each client ends up with its own encryption key. Others nearby can no longer read a user’s traffic by passive packet sniffing.

What OWE does not do is authenticate anyone. The user proves nothing, and the client has no way to verify that the access point is the genuine one, so an evil twin can offer Enhanced Open just as easily as the real network can, and the encryption then runs to the attacker. That places it beside WPA3 rather than inside it: WPA3-Personal authenticates with a password through SAE, and WPA3-Enterprise authenticates through 802.1X, while Enhanced Open is the answer for networks meant to have no credentials at all. A captive portal may sit on top, but adds no encryption.

Exam relevance: a scenario is likely to describe a public network that must stay password-free while protecting users from eavesdropping, which points to Enhanced Open. Candidates are expected to know that it encrypts without authenticating, so it gives no assurance that the network is legitimate.