WPA3 R3 Support

SAE Hash to Element (H2E)

Instead of generating password with ECC/FFC groups by looping, H2E provides a way for direct hashing to obtain the ECC/FFC password element.

An AP that supports H2E sets the SAE H2E bit in Extended RSN Capabilities field in Beacon and Probe Response.

Transition Disable Indication

Tansition Disable Indication

  • Transition on/off option is provided in the Encryption Options.

  • Beacon Protection

    Beacon Protection can only be enabled when PMF is enabled. When Beacon Protection is enabled, the bit 84 in Extended Capability IE should be set to 1. AP should protect Beacon via adding MMIE in all Beacon frames. The BIGTK (Beacon Integrity Group Temporal Key) and BIPN (BIGTK Packet Number) is used for this purpose.

    BIGTK should be renewed whenever there are GTK (Group Temporal Key) updates.

  • Operating Channel Validation (OCV)

    AP and STA need to include OCI (Operating Channel Information) as below if it indicates it is OCV Capable.

    • Set bit 14 (OCVC) in RSN capability in RSNE.
    • Add OCI KDE (00-0F-AC-13) in EAPOL M2/M3 and group key update M1/M2 frames. If OCI KDE is incorrect, AP should silently discard the frame.