Wi-Fi Protected Access (WPA)

The 2003 transitional replacement for WEP, using TKIP so existing hardware could be upgraded by firmware; itself now deprecated in favour of WPA2 and WPA3.

Wi-Fi Protected Access was introduced by the Wi-Fi Alliance in 2003 as an interim answer to the failures of WEP, while the IEEE was still completing the 802.11i security amendment. It had to run on hardware already built for WEP, often after only a firmware update. It therefore kept the RC4 cipher but wrapped it in the Temporal Key Integrity Protocol (TKIP), which mixes a fresh key for each packet and adds an integrity check and replay counter. Like its successors, it came in a Personal mode with a shared passphrase and an Enterprise mode that authenticates each user through IEEE 802.1X.

WPA was a transitional fix, and weaknesses in TKIP were later published. TKIP has since been deprecated, and current guidance is not to use WPA or TKIP at all. The completed 802.11i design arrived as WPA2, which made AES-based CCMP mandatory, and was followed by WPA3. Candidates commonly confuse the names: WPA is the certification, TKIP is its encryption protocol, and CCMP belongs to WPA2.

Exam relevance: a scenario is likely to present a legacy wireless network and ask which option is acceptable. Candidates are expected to place WPA with TKIP as better than WEP but no longer adequate, and to recommend WPA2 with CCMP as a minimum and WPA3 where the devices support it.