The Wi-Fi Alliance announced today that WPA2 security certification, the second generation of Wi-Fi Protected Access, is now a mandatory feature for all new Wi-Fi CERTIFIED products. Nearly 600 products have been Wi-Fi CERTIFIED for WPA2 since it was introduced as an optional program in September 2004.
WPA2 is fully compatible with WPA, the first generation of Wi-Fi CERTIFIED security, and brings the technology two generations past WEP (Wired Equivalent Privacy), the original security method for Wi-Fi networks.
“By requiring WPA2 for all Wi-Fi CERTIFIED products, we’re making it easy for people to be confident that the very latest generation of security is there, built in, and ready to use,” said Wi-Fi Alliance Managing Director Frank Hanzlik. “WPA2 helps ensure that only authorized users can access a network, and that the data they send and receive can’t be compromised.”
WPA2 is based upon the full IEEE 802.11i standard, including the Advanced Encryption Standard (AES). WPA2 can also be configured to support the earlier WPA security protocol.
There are two types of WPA2: Personal and Enterprise. WPA2-Personal is designed for consumer use. It encrypts data with AES and uses a password to establish access to the Wi-Fi network.
WPA2-Enterprise encrypts data with AES and verifies the identity of network users using Extensible Authentication Protocol, or EAP. The WPA2-Enterprise program includes testing for five widely-deployed EAP types to cater to a variety of usage scenarios and device types.
A complete list of WPA2 certified products is available at www.wi-fi.org.
WAPI (Wired Authentication and Privacy Infrastructure) is a Chinese National Standard for Wireless LAN. Although it is supposed to work on top of WiFi, compatibility with 802.11i is in dispute. The Chinese WAPI standard, which tried to get inclusion in the 802.11i standard last week at the IEEE, requires the use of a secret symmetric encryption algorithm which many cryptography experts argue is unsafe since it means that the algorithm cannot be peer reviewed.



