跳至主要內容

什麼是 Hotspot 2.0 (Passpoint)?

作者:Devi Jina
29 November 2023
閱讀時間 3 分鐘
什麼是 Hotspot 2.0 (Passpoint)?
Interactive Carrier Offload & Roaming Tool

Hotspot 2.0 & Passpoint offload and roaming planner

Model cellular data offload capacity, IEEE 802.11u ANQP query rates, and zero-touch auto-connect retention across enterprise AP hardware.

250,000 visitors
5,000 (Boutique)250,000 (Airport / Mall)1,000,000+ (Transit Network)
78% of visitors
20% (Conservative)65% (Industry Standard)95% (Carrier Partnered)
2.0 hours
30 mins (Quick Visit)2.0 hrs (Transit / Retail)8.0 hrs (Conference / Hotel)

Calculated Cellular Offload & Roaming Metrics

Total Offloaded Data
167.4 TB
171,387 GB / month
Connected Roaming Users
195,000
78% of total footfall
Zero-Touch Auto-Connect
95%
No portal login screen
Drop-Offs Prevented
+81,900
+42% user retention
Peak ANQP Rate
2 q/s
802.11u pre-assoc
Selected AP Infrastructure:Cisco Meraki & Catalyst 9800
Standard: Native IEEE 802.11u / Hotspot 2.0 Release 2 | Auth: EAP-TLS, EAP-TTLS (MSCHAPv2), EAP-SIM, EAP-AKA
Implementation: Enable Hotspot 2.0 under SSID Wireless Options; bind Purple RADIUS server profile with NAI Realm list.
## 執行摘要 Hotspot 2.0(也稱為 Passpoint 或 IEEE 802.11u)是由 WiFi Alliance 開發的公共與企業 WiFi 標準。它使行動裝置能夠自動發現、驗證並連接到安全的 WiFi 網路,無需使用者介入或手動透過快顯畫面登入。透過利用 WPA2/3-Enterprise 加密和基於 EAP 的驗證,Hotspot 2.0 將開放式場域 WiFi 轉化為零點擊、電信級的網路體驗。 ## 什麼是 Hotspot 2.0 (IEEE 802.11u Passpoint)? Hotspot 2.0 建立了在行動網路與 WiFi 存取點之間無縫漫遊的技術架構。Hotspot 2.0 基於 IEEE 802.11u 修正案,允許行動裝置在發起連線之前,向可用的存取點查詢網路服務、領域功能和漫遊協議。 與需要手動選擇 SSID 和網頁入口網站驗證的傳統開放式訪客 WiFi 網路不同,Hotspot 2.0 直接在用戶端裝置上部署安全的數位設定檔。當使用者進入支援的場域時,其裝置會透過企業級 RADIUS 伺服器進行自動驗證。 ### Hotspot 2.0 的關鍵技術支柱 * **存取網路查詢協定 (ANQP):** 允許用戶端裝置在關聯之前發現網路功能、電信業者漫遊合作夥伴以及網際網路連線狀態。 * **WPA2/3-Enterprise 安全性:** 以強制性的 AES 加密取代開放、未加密的 WiFi 網路,消除竊聽和中間人攻擊。 * **EAP-TLS / EAP-TTLS 驗證:** 利用數位憑證或 SIM 卡認證資訊來驗證裝置身分,無需預先共用金鑰或密碼。 * **行動網路分流:** 允許行動網路營運商 (MNO) 將數據流量從擁擠的 LTE/5G 基地台分流到高速的場域 WiFi。 ## Hotspot 2.0 與傳統公共 WiFi 網路的比較 從未加密的傳統熱點過渡到 Hotspot 2.0,消除了登入摩擦,同時顯著加強了整個場域資產的安全防護力。 | 功能與能力 | 傳統開放式公共 WiFi | Hotspot 2.0 (Passpoint) 網路 | | :--- | :--- | :--- | | **驗證方式** | 手動網頁 Captive Portal 登入 | 自動背景 802.1X 握手 | | **空中傳輸加密** | 無(未加密開放 / 可選 OWE) | WPA2-Enterprise / WPA3-Enterprise (AES) | | **使用者體驗** | 繁瑣(重定向、表單、重新登入) | 零點擊(即時自動連線) | | **重複訪問連線** | 需要入口網站重新驗證 | 跨位置無縫自動漫遊 | | **行動分流支援** | 不支援 | 原生基於 SIM 的 EAP-SIM / EAP-AKA 分流 | | **惡意 AP 防範** | 易受邪惡雙生子 AP 攻擊 | 透過雙向憑證驗證進行保護 | ## Hotspot 2.0 對企業場域的主要優勢 ### 1. 無摩擦的訪客體驗 訪客不再需要搜尋網路名稱、向工作人員詢問密碼,或填寫重複的網頁表單。裝置在進入場地後會自動連接,提供即時的網際網路連線。 ### 2. 企業級無線安全 公開的開放式 WiFi 網路會使使用者流量面臨封包監聽與工作階段劫持的風險。Hotspot 2.0 使用 WPA2/3-Enterprise 協定,為每個連線的工作階段強制執行個別加密金鑰,即使在公共網路上也能確保使用者資料的安全。 ### 3. 跨場地物業的多站點漫遊 對於企業連鎖店、零售購物中心、飯店集團和交通樞紐,單一 Hotspot 2.0 設定檔即可讓裝置在數百個實體位置之間進行漫遊,而無需重新驗證。 ### 4. 適用於電信營運商的 SIM 基礎行動網路分流 行動營運商部署 Passpoint 設定檔,以將體育場、機場和購物中心等高密度場地內飽和的行動基地台資料流量進行分流。場地可以與營運商合作,將基礎設施變現並改善室內覆蓋率。 ## Hotspot 2.0 技術架構:IEEE 802.11u 與 ANQP Hotspot 2.0 的技術基礎依賴於關聯前探索。標準 WiFi 要求裝置在探索網路服務之前先與 AP 關聯。Hotspot 2.0 則使用存取網路查詢協定(ANQP)訊框,在裝置仍處於探測狀態時交換功能資訊。 ### ANQP 資訊元素交換 * **網域名稱:** 識別網路營運商與領域資訊。 * **漫遊聯盟唯一識別碼(OI):** 比對營運商漫遊協議,以驗證使用者的訂閱是否允許免費存取。 * **NAI 領域列表:** 指定支援的驗證方法(例如 EAP-TLS、EAP-TTLS、EAP-SIM)。 * **IP 位址類型可用性:** 確認連線時分配的是 IPv4 還是 IPv6 位址。 ## 如何部署 Hotspot 2.0 與 Passpoint 網路 在企業級存取點設備中部署 Hotspot 2.0 需要相容的無線基礎設施與雲端 RADIUS 驗證服務。 ### 1. 驗證硬體與韌體相容性 確保您的無線存取點和 WLAN 控制器支援 Hotspot 2.0 Release 2 或 Release 3。領先的企業級 AP 廠商(包括 Cisco Meraki、HPE Aruba、Ruckus Wireless、Juniper Mist、Ubiquiti UniFi 和 Fortinet)皆提供原生的 Passpoint 設定模組。 ### 2. 設定 RADIUS 身分與 EAP 伺服器 Hotspot 2.0 需要 802.1X RADIUS 伺服器來驗證裝置憑證或身分代碼。像 Purple 這樣的雲端原生平台可以直接與現有的身分識別提供者(Entra ID、Okta、Google Workspace)以及 RADIUS 叢集整合,而無需本地端伺服器硬體。 ### 3. 發佈 OSU(線上登記)與 Passpoint 設定檔 線上註冊(OSU)伺服器允許新使用者透過網頁入口網站、QR code 或行動應用程式下載安全的 Passpoint WiFi 設定檔。安裝完成後,該設定檔將保持啟用狀態,以便日後進行自動連線。 ## 檢查 Hotspot 2.0 的裝置相容性 現代行動作業系統皆提供內建的 Passpoint 支援: * **iOS 與 iPadOS:** Apple 裝置自 iOS 7 起便原生支援 Hotspot 2.0。Passpoint 設定檔可透過 MDM 或網頁下載進行部署。 * **Android:** 執行 Android 6.0+ 的 Android 裝置在進階 WiFi 偏好設定中包含原生 Passpoint(HS2.0)設定。 * **Windows 與 macOS:** Windows 10/11 與 macOS Monterey+ 支援 802.11u 預先關聯偵測與企業級設定檔管理。 ## 關於 Hotspot 2.0 的常見問答 ### Hotspot 2.0 與 Passpoint 有何不同? Hotspot 2.0 是由 WiFi Alliance 基於 IEEE 802.11u 開發的底層技術標準。Passpoint 則是 WiFi Alliance 管理的官方品牌與認證計畫,用於驗證不同硬體廠商之間的互通性。 ### Hotspot 2.0 比開放式訪客 WiFi 更安全嗎? 是的。傳統的開放式訪客 WiFi 在空中傳輸未經加密的資料。Hotspot 2.0 強制執行 WPA2/WPA3 企業級加密,為每台裝置產生唯一的加密金鑰,以防止竊聽。 ### 部署 Hotspot 2.0 需要更換硬體嗎? 在大多數情況下不需要。來自 Cisco、Aruba、Ruckus、Mist 與 UniFi 的企業級無線基地台皆可透過標準韌體更新支援 Hotspot 2.0。像 Purple 這樣的雲端管理平台可在現有硬體上管理 Passpoint RADIUS 設定檔。 ## 利用 Purple 加速 Hotspot 2.0 部署 Purple 提供雲端原生訪客 WiFi 與 Passpoint 平台,以無摩擦、身分導向的 802.1X 驗證,取代繁瑣的入口登入畫面。Purple 相容於所有主流企業級 WLC 與無線基地台廠商,使場域能夠部署 Passpoint、安全訪客存取與位置分析。

常見問題

What is Hotspot 2.0 and how does it automate WiFi network discovery?

Hotspot 2.0 (based on IEEE 802.11u) is a wireless networking standard that allows mobile devices to automatically discover and evaluate access points prior to association. Using Access Network Query Protocol (ANQP), client devices query network capabilities, cellular roaming consortia, and realm identity parameters before transmitting association frames, enabling instant zero-touch roaming without manual SSID selection.

What is the difference between Hotspot 2.0, Passpoint, and OpenRoaming?

Hotspot 2.0 is the underlying IEEE 802.11u wireless standard. Passpoint (WiFi CERTIFIED Passpoint) is the industry certification program that validates device and access point interoperability. OpenRoaming, developed by the Wireless Broadband Alliance (WBA), is the global roaming federation that connects identity providers (telecom carriers, identity platforms, universities) with venue networks using Passpoint as the underlying radio standard.

How does Passpoint improve enterprise WiFi security compared to open captive portals?

Standard public captive portals use unencrypted open SSIDs that transmit data frames in cleartext, exposing users to eavesdropping and rogue AP attacks. In contrast, Passpoint mandates WPA2 or WPA3-Enterprise 802.1X authentication. Every client session generates unique cryptographic session keys via EAP-TLS or EAP-TTLS, providing encrypted over-the-air protection across public and guest venues.

How does cellular carrier offload work with Hotspot 2.0 in high-density venues?

High-density venues like stadiums and airports suffer from macro-cell cellular spectrum congestion. Hotspot 2.0 enables mobile network operators (MNOs) to automatically authenticate subscriber SIM credentials (EAP-SIM or EAP-AKA) or provisioned eSIM profiles onto enterprise WiFi networks. This offloads high data volume from saturated LTE and 5G cellular towers while providing visitors with high-speed connectivity.

Which enterprise wireless access points support Hotspot 2.0 and ANQP profiles?

Most modern enterprise wireless hardware vendors support Hotspot 2.0 Release 2, including Cisco Catalyst 9800, Cisco Meraki MR, HPE Aruba Central, Ruckus SmartZone, Juniper Mist, and Fortinet FortiAP. Network administrators configure 802.11u ANQP parameters, NAI Home Realms, and Roaming Consortium Organization Identifiers (RCOIs) directly within controller WLAN templates.

Can venues combine Hotspot 2.0 roaming with captive portal marketing?

Yes. Venues can broadcast a dual-layer strategy. First-time visitors without a Passpoint profile connect via a standard branded captive portal to complete registration and accept terms. During onboarding, the Purple platform pushes an encrypted Passpoint profile or provisioning link to the user's device, enabling all subsequent visits to auto-connect with zero splash screen friction.

為您的員工 WiFi 網路進行基準測試

透過我們的免費評估,了解您的網路與 Purple 的銅級、銀級和金級標準相比如何,並獲取專屬報告,協助您的 IT 團隊規劃下一次升級。

獲取免費 WiFi 基準測試

準備好開始了嗎?

預約專家演示,了解 Purple 如何協助您達成業務目標。

諮詢專家