Wired Equivalent Privacy (WEP)
The original IEEE 802.11 wireless encryption, built on RC4 with a short initialisation vector and a static shared key; broken, and not to be used.
Wired Equivalent Privacy was the security mechanism in the original IEEE 802.11 standard of 1997. Its aim was confidentiality roughly equal to a cable’s. It encrypted each frame with the RC4 stream cipher, using a static key shared by every device on the network (40 or 104 bits) combined with a 24-bit initialisation vector (IV) sent in the clear, and it checked integrity with a CRC-32 value.
Each of those choices proved weak. A 24-bit IV repeats quickly on a busy network, and repeated IVs mean repeated keystreams. Published cryptanalysis from 2001 onward showed that the way WEP fed IVs into RC4 lets an attacker recover the key itself from enough captured traffic. CRC-32 is not a cryptographic check, so frames can be altered without detection. With no key management, one static key is shared by everyone and rarely changed. The result is that WEP is broken and must not be used. WPA replaced it as an interim fix.
Exam relevance: a scenario is likely to describe a network where traffic was decrypted after an attacker simply collected enough of it, or to list WEP among options. Candidates are expected to recognise WEP as the broken choice, to tie its failure to the short IV and weak key handling, not key length, and to recommend WPA2 or WPA3.