Simultaneous Authentication of Equals (SAE)
The password-based key exchange in the IEEE 802.11 standard that WPA3-Personal uses in place of pre-shared key authentication, commonly described as resisting offline guessing.
Simultaneous Authentication of Equals (SAE) is a password-authenticated key exchange defined in the IEEE 802.11 standard, based on the Dragonfly key exchange that RFC 7664 also describes. “Equals” reflects its design: the two parties run the same exchange as peers, and either may start it. Each proves knowledge of the shared password without sending it, and together they derive a fresh key for the session. The four-way handshake that follows is kept.
SAE matters because of WPA3. WPA3-Personal replaces the pre-shared key authentication of WPA2 Personal with SAE. Under WPA2 Personal, an attacker who records one handshake can try passphrases offline at leisure; SAE is commonly described as resisting that offline guessing and as giving forward secrecy, so a password learned later does not decrypt earlier recorded sessions. It does not make a weak passphrase safe, because online guessing still works. WPA3 transition mode, which also admits WPA2 clients, leaves those clients on the weaker method. For open networks with no password at all, the comparable feature is Opportunistic Wireless Encryption (Wi-Fi Enhanced Open), which encrypts without authenticating anyone.
Exam relevance: a scenario about protecting a passphrase-based wireless network against captured-handshake cracking is likely to point to SAE through WPA3-Personal. Candidates are expected to remember that passphrase strength still matters.