跳至主要內容

Hotspot 2.0、Passpoint 與 NGH 詳解:WiFi 指南

Gavin Wheeldon作者:Gavin Wheeldon
11 February 2014
閱讀時間 3 分鐘
Hotspot 2.0、Passpoint 與 NGH 詳解:WiFi 指南
Interactive technical tool

Hotspot 2.0 and Passpoint readiness assessor

Evaluate hardware compatibility, model helpdesk cost reductions, and measure 802.1X encryption benefits for your venue network.

Multi-tenant offices and corporate campuses requiring encrypted guest authentication without sharing corporate credentials.

Supported models: Catalyst 9100 / 9800 WLC, Meraki MR36/MR46/MR56/MR76

15,000
2,000100,000250,000+

Native device compatibility

88%

~13,200 monthly devices support zero-touch Hotspot 2.0 connection.

Recaptured dropped connections

+3,886

Visitors who previously abandoned captive portals now connect automatically.

Wireless security posture comparison

Current setup (captive portal)55/100

Moderate risk (portal spoofing and SSL certificate errors)

Hotspot 2.0 with Purple Cloud RADIUS (WPA2/WPA3-Enterprise)98/100

Per-session dynamic PMK encryption, certificate-based mutual authentication, no shared passwords.

Pre-association discovery (802.11u ANQP)

Hotspot 2.0 uses Access Network Query Protocol (ANQP) before authentication. Client devices automatically discover network capabilities, roaming consortium identifiers, and cellular operator credentials without sending active probe requests on congested channels.

Ready to deploy Hotspot 2.0 and Passpoint across your network?

Purple overlays with your existing Cisco Catalyst & Meraki MR infrastructure in minutes without replacing access points.

Interactive Architecture Tool

Hotspot 2.0 & Passpoint Venue Readiness Estimator

Configure your venue parameters to evaluate Passpoint auto-connect rates, cellular offload potential, and enterprise WiFi security benefits.

Recommended Architecture

Hotel Guest & Loyalty Passpoint Architecture

Zero-Click Auto Connect
94% Automatic Re-Connection across properties
Security Standard
WPA2/WPA3-Enterprise (EAP-TTLS / Passpoint R2)
Cellular Offload Potential
High (80% guest cellular-to-WiFi offload)
Hardware Compatibility
Cisco Meraki / Catalyst WLC (Native Passpoint 2.0 ANQP Support)
Deployment Timeframe: Same Day Cloud ConfigurationPlatform: Purple Cloud RADIUS & Unified Passpoint Profile Manager

關鍵要點:Hotspot 2.0、Passpoint 與 NGH

  • 免手動引導:Hotspot 2.0 (IEEE 802.11u) 與 Passpoint 允許行動裝置自動發現安全的企業網路並進行驗證,無需透過 Captive Portal 歡迎畫面或手動選擇 SSID。
  • WPA3-Enterprise 加密:Passpoint 網路上的所有用戶端傳輸均使用 802.1X 協定 (EAP-TLS, EAP-TTLS, EAP-SIM) 與 WPA2/WPA3-Enterprise 進行加密,消除了竊聽與惡意存取點偽造。
  • ANQP 發現:存取網路查詢協定 (ANQP) 在裝置完成關聯之前,查詢網路功能、漫遊聯盟識別碼以及行動電信商關係。
  • 電信商行動網路分流:行動網路營運商在機場、體育場和轉運站等高密度環境中,會自動將擁擠的 LTE 和 5G 行動流量分流到場地 WiFi 網路上。
  • 混合式架構:場地將用於無縫二次造訪的 Passpoint 與用於首次造訪者行銷同意及人口統計數據收集的 Purple Captive Portal 相結合。

公共 WiFi 的入網流程在過去一直面臨安全性與便利性之間的根本權衡。傳統的訪客網路依賴開放、未加密的 SSID,並搭配網頁式 captive portals。雖然網頁登入畫面可以收集行銷同意書,但手動瀏覽器登入會造成使用者體驗摩擦、增加連線中斷率,並使未經身分驗證的無線訊框容易受到封包監聽與中間人攻擊。

Hotspot 2.0、WiFi CERTIFIED Passpoint 和下一代熱點 (NGH) 架構解決了此衝突。透過將關聯前的網路發現和基於憑證的 802.1X 驗證標準化,這些標準提供了電信商級的漫遊體驗,使裝置在進入訊號範圍的瞬間就能安全且自動地連接。

什麼是 Hotspot 2.0、Passpoint 和 Next Generation Hotspot?

雖然 Hotspot 2.0、Passpoint 和 NGH 經常被混用,但它們分別代表技術生態系統中不同的層級:

  • Hotspot 2.0 (IEEE 802.11u): 由 IEEE 發布的基準無線協定修正案。它定義了基地台如何廣播網路中介資料,以及用戶端裝置在建立射頻關聯之前如何查詢上游網路功能。
  • Passpoint (WiFi CERTIFIED Passpoint): 由 WiFi Alliance 管理的互通性測試與認證計劃。Passpoint 將裝置製造商(Apple iOS、Google Android、Windows)與企業級基地台廠商(Cisco Meraki、HPE Aruba、Ruckus、Juniper Mist)之間的設定檔佈署、SIM 卡驗證及憑證驗證進行了標準化。
  • Next Generation Hotspot (NGH): 由無線寬頻聯盟 (WBA) 開發的產業倡議,定義了商業漫遊協議、營運商計費框架及聯合身分交換,作為全球 OpenRoaming 架構的基礎。

IEEE 802.11u 與 ANQP 連線流程的運作方式

在傳統的 WiFi 網路中,裝置在關聯並請求 DHCP 租約之前,無法確定網路是否提供網際網路存取或支援其憑證。Hotspot 2.0 在預先關聯期間使用存取網路查詢協定 (ANQP) 解決了這一低效問題:

  1. 指標與探測回應:存取點傳送包含互連元件 (IE) 的 802.11 指標訊框,表示 Hotspot 2.0 功能、場地群組分類和網路存取類型。
  2. ANQP 查詢交換:在關聯之前,用戶端會傳送通用廣告服務 (GAS) 請求訊框,向存取點查詢漫遊聯盟組織識別碼 (OI)、網路存取識別碼 (NAI) 領域清單和 3GPP 行動電信商代碼。
  3. 設定檔比對:裝置會將存取點功能與已安裝的 Passpoint 設定檔(透過行動應用程式、企業 MDM 或 SIM 卡設定檔安裝)進行比對。
  4. 802.1X 驗證:如果找到相符項,裝置會進行關聯並執行 EAP 驗證交握(使用用戶端憑證的 EAP-TLS、使用 MSCHAPv2 的 EAP-TTLS,或使用行動 SIM 認證的 EAP-SIM/AKA)。
  5. 加密通道:RADIUS 伺服器驗證認證,並透過 WPA2 或 WPA3-Enterprise 建立個別的動態加密金鑰 (CCMP/GCMP),確保端到端資料隱私。

比較:Hotspot 2.0 / Passpoint 對比 Captive Portal 對比 OpenRoaming

功能 / 能力 傳統 Captive Portal Hotspot 2.0 / Passpoint WBA OpenRoaming
連線體驗 手動選擇 SSID + 瀏覽器入口網頁註冊 免手動操作的背景自動連線 全球聯盟免手動操作自動漫遊
空中介面加密 未加密 (Open) 或共享 PSK WPA2/WPA3-Enterprise (個別動態 AES/GCMP 金鑰) WPA2/WPA3-Enterprise (802.1X EAP-TLS/TTLS)
上網引導機制 網頁表單 / 社群媒體登入 / 簡訊 OTP Passpoint 設定描述檔 (.mobileconfig、OSU) 或 SIM 身分識別提供者 (IDP) 聯盟 / 電信業者 SIM / 應用程式描述檔
電信行動網路分流 不支援 透過 3GPP EAP-SIM/AKA 描述檔支援 在參與的全球電信業者之間完全自動化
行銷數據收集 高 (自訂表單、同意核取方塊、問卷調查) 低 / 間接 (RADIUS 遙測與 MAC 分析) 聯盟身分屬性與場域分析
硬體相容性 通用 (所有標準 AP) 需要支援 IEEE 802.11u 與 Passpoint 認證的 AP 需要 Passpoint Release 2+ 與 WBA 合規性

安全性架構:為什麼 Passpoint 可以消除 MITM 中間人攻擊

標準的開放式公共 WiFi 網路以明文傳輸資料訊框,容易受到被動封包擷取的竊聽。攻擊者還可以部署具有相同 SSID 的「邪惡雙生 (Evil Twin)」存取點,以攔截登入憑證和金融交易。

Passpoint 透過三種安全性機制消除了這些安全漏洞:

  • 伺服器憑證驗證:用戶端會對照受信任的根憑證授權單位 (CA) 驗證伺服器身分憑證,防止惡意 AP 冒充。
  • 雙向身分驗證:Enterprise EAP 協定可確保網路與用戶端在建立網路存取權之前,皆已驗證彼此的身分。
  • 個人單獨加密:成對暫時金鑰 (PTK) 會加密用戶端與存取點之間的每個訊框,防止場域內其他已連線的裝置攔截網路流量。

電信業者流量分流與高密度場域經濟效益

國際機場(例如曼徹斯特機場集團和 AGS Airports)、體育場館及交通轉運站等高密度場域面臨著嚴重的行動網路擁塞問題。室內行動巨集訊號難以穿透現代建築材料,而 5G 毫米波覆蓋範圍仍侷限於特定區域。

Passpoint 讓行動運營商能夠將行動數據無縫分流至現有的企業 WiFi 基礎架構。當運營商訂戶進入場域時,其智慧型手機會透過 ANQP 識別運營商的聯盟 OI,並使用裝置的 SIM 卡自動進行驗證。這既能減輕行動基地台的擁塞,又能為旅客提供可靠的高速數據。

混合場域策略:將 Passpoint 與 Purple Captive Portals 結合

雖然 Passpoint 提供了無縫的連線體驗,但場域行銷與營運團隊仍需要第一手客戶洞察、行銷訂閱同意以及訪客人口統計數據。現代企業採用了混合架構:

  1. 首次造訪者:透過品牌專屬的 Purple Captive Portal 進行連線,完成註冊、選擇通訊偏好並接受 GDPR/CCPA 條款。
  2. Passpoint 佈署:完成 Captive Portal 流程後,Purple 平台會產生安全 Passpoint 設定檔並安裝至訪客裝置。
  3. 後續造訪:在品牌網路中的任何場域再次造訪時,裝置皆會透過加密的 Passpoint 自動連線,無需再次顯示歡迎頁面。
  4. 遙測與分析:場域透過 Purple WiFi Analytics 收集完整的停留時間、頻率及區域移動數據,同時提供無縫的訪客體驗。

企業級存取點廠商設定

可以在支援 IEEE 802.11u 的主要企業級無線硬體平台上啟用 Passpoint 和 Hotspot 2.0:

  • Cisco Meraki & Catalyst: 在 Dashboard 或 Catalyst WLC 中設定 Hotspot 2.0 設定檔,指派 NAI 領域、3GPP 行動網路及 RADIUS 計費端點。
  • HPE Aruba Networking: 透過 Aruba Central 或 AirWave 部署 Passpoint 設定,指定漫遊聯盟識別碼 (RCOI) 與場域名稱 ANQP 元素。
  • Ruckus Wireless: 在 SmartZone 或 ZoneDirector 控制器中啟用 Hotspot 2.0,並搭配自動化線上簽入 (OSU) 伺服器對應。
  • Juniper Mist: 設定具備雲端 RADIUS 驗證與零接觸設定檔管理功能、由 AI 驅動的 Passpoint WLAN 設定檔。

常見問題

什麼是 Hotspot 2.0?它的運作原理為何?

Hotspot 2.0 (IEEE 802.11u) 是一種無線標準,可讓行動裝置使用關聯前的 ANQP 查詢,在無需使用者手動操作的情況下,自動發現相容的公共與企業 WiFi 網路、對其進行查詢並完成身分驗證。

Hotspot 2.0 與 Passpoint 有何不同?

Hotspot 2.0 是由 IEEE 和 WiFi 聯盟開發的底層技術標準,而 Passpoint (WiFi CERTIFIED Passpoint) 則是正式的認證計畫,旨在確保跨廠商的互通性,以實現無縫、加密且無感知的漫遊。

相較於開放式 captive portals,Passpoint 如何提升企業 WiFi 安全性?

與傳輸未加密流量的開放式 captive portals 不同,Passpoint 使用 WPA2/WPA3-Enterprise(搭配 EAP-TLS 或 EAP-TTLS 的 802.1X)對所有用戶端傳輸進行加密,從而消除中間人竊聽與惡意 AP 攻擊。

什麼是 Next Generation Hotspot (NGH) 與 OpenRoaming?

Next Generation Hotspot (NGH) 是無線寬頻聯盟的一項倡議,旨在對全球交通樞紐、飯店與場館的行動網路流量分流與無縫 WiFi 漫遊進行標準化,這構成了現代 OpenRoaming 聯盟的基礎。

場館可以在進行 captive portal 行銷的同時部署 Passpoint 嗎?

是的。混合部署可利用 Hotspot 2.0/Passpoint 實現即時、無摩擦的再次造訪與員工入網,同時將首次連線的訪客導向品牌專屬的 captive portal,以進行資料收集與行銷訂閱。

常見問題

What is the difference between Hotspot 2.0, Passpoint, and Next Generation Hotspot (NGH)?

Hotspot 2.0 is the technical specification developed by the WiFi Alliance based on IEEE 802.11u standards. Passpoint is the official certification program administered by the WiFi Alliance to ensure device interoperability with Hotspot 2.0 protocols. Next Generation Hotspot (NGH) is the Wireless Broadband Alliance (WBA) commercial framework and operator ecosystem that defines federated roaming, security policies, and billing clearinghouses between network operators and enterprises.

How does IEEE 802.11u ANQP work in Passpoint authentication?

IEEE 802.11u introduces the Access Network Query Protocol (ANQP), which allows client devices (smartphones, laptops, tablets) to query access point capabilities before associating. Over Generic Advertisement Service (GAS) frames, the device requests Network Access Identifier (NAI) realm lists, Roaming Consortium Organization Identifiers (RCOIs), and 3GPP cellular network info without needing to join the SSID, conserving airtime and eliminating manual SSID probing.

Why is Passpoint more secure than traditional captive portal guest WiFi?

Traditional captive portals typically operate on open, unencrypted wireless SSIDs where broadcast traffic is susceptible to eavesdropping and man-in-the-middle packet capture. Passpoint mandates WPA2-Enterprise or WPA3-Enterprise 802.1X security with CCMP or GCMP ciphers. Every connected device receives unique, dynamic pairwise master keys (PMK), encrypting all over-the-air traffic between client and access point while preventing rogue portal spoofing.

How does Passpoint eliminate captive portal drop-off rates?

Captive portals require users to complete multi-step web forms, accept browser certificates, or wait for OS Captive Network Assistant (CNA) browser popups, which suffer 30% to 50% abandonment rates. Passpoint installs a cryptographic configuration profile or eSIM credential once; after installation, the device automatically authenticates and connects in under 50 milliseconds every time it enters coverage.

What hardware infrastructure is required to deploy Hotspot 2.0?

Hotspot 2.0 is supported across modern enterprise access points from vendors including Cisco Catalyst, Cisco Meraki, HPE Aruba, Ruckus Wireless, Juniper Mist, Extreme Networks, and Fortinet. The backend requires a RADIUS server supporting RADSEC (RFC 6614 RADIUS over TLS) to communicate with federated identity providers such as Purple Cloud RADIUS and WBA OpenRoaming hubs.

How does Purple integrate with Passpoint and OpenRoaming?

Purple provides an enterprise cloud overlay that manages Passpoint profile distribution, subscriber identity provisioning, and automated RADIUS authentication without requiring controller replacements. Purple bridges Passpoint automated onboarding with GDPR-compliant visitor analytics, customer CRM synchronization, and targeted marketing automation across physical venues.

為您的員工 WiFi 網路進行基準測試

透過我們的免費評估,了解您的網路與 Purple 的銅級、銀級和金級標準相比如何,並獲取專屬報告,協助您的 IT 團隊規劃下一次升級。

獲取免費 WiFi 基準測試

準備好開始了嗎?

預約專家演示,了解 Purple 如何協助您達成業務目標。

諮詢專家
Hotspot 2.0、Passpoint 與 NGH 詳解:WiFi 指南 | Purple