Skip to main content

What is Hotspot 2.0 (Passpoint)?

By Devi Jina
29 November 2023
6 min read
What is Hotspot 2.0 (Passpoint)?
Interactive Carrier Offload & Roaming Tool

Hotspot 2.0 & Passpoint offload and roaming planner

Model cellular data offload capacity, IEEE 802.11u ANQP query rates, and zero-touch auto-connect retention across enterprise AP hardware.

250,000 visitors
5,000 (Boutique)250,000 (Airport / Mall)1,000,000+ (Transit Network)
78% of visitors
20% (Conservative)65% (Industry Standard)95% (Carrier Partnered)
2.0 hours
30 mins (Quick Visit)2.0 hrs (Transit / Retail)8.0 hrs (Conference / Hotel)

Calculated Cellular Offload & Roaming Metrics

Total Offloaded Data
167.4 TB
171,387 GB / month
Connected Roaming Users
195,000
78% of total footfall
Zero-Touch Auto-Connect
95%
No portal login screen
Drop-Offs Prevented
+81,900
+42% user retention
Peak ANQP Rate
2 q/s
802.11u pre-assoc
Selected AP Infrastructure:Cisco Meraki & Catalyst 9800
Standard: Native IEEE 802.11u / Hotspot 2.0 Release 2 | Auth: EAP-TLS, EAP-TTLS (MSCHAPv2), EAP-SIM, EAP-AKA
Implementation: Enable Hotspot 2.0 under SSID Wireless Options; bind Purple RADIUS server profile with NAI Realm list.
## Executive summary Hotspot 2.0 (also known as Passpoint or IEEE 802.11u) is a public and enterprise WiFi standard developed by the WiFi Alliance. It enables mobile devices to automatically discover, authenticate, and connect to secure WiFi networks without user intervention or manual splash screen logins. By leveraging WPA2/3-Enterprise encryption and EAP-based authentication, Hotspot 2.0 transforms open venue WiFi into a zero-click, carrier-grade network experience. ## What is Hotspot 2.0 (IEEE 802.11u Passpoint)? Hotspot 2.0 establishes a technical framework for seamless roaming between cellular networks and WiFi access points. Built upon the IEEE 802.11u amendment, Hotspot 2.0 allows mobile devices to query available access points for network services, realm capabilities, and roaming agreements before initiating a connection. Unlike traditional open guest WiFi networks that require manual SSID selection and web portal authentication, Hotspot 2.0 provisions secure digital profiles directly on client devices. When a user enters a supported venue, their device authenticates automatically via enterprise-grade RADIUS servers. ### Key technical pillars of Hotspot 2.0 * **Access Network Query Protocol (ANQP):** Enables client devices to discover network capabilities, carrier roaming partners, and Internet connectivity status prior to association. * **WPA2/3-Enterprise security:** Replaces open, unencrypted WiFi networks with mandatory AES encryption, eliminating eavesdropping and man-in-the-middle attacks. * **EAP-TLS / EAP-TTLS authentication:** Utilizes digital certificates or SIM card credentials to verify device identity without pre-shared keys or passwords. * **Cellular offloading:** Allows mobile network operators (MNOs) to offload data traffic from congested LTE/5G towers to high-speed venue WiFi. ## Hotspot 2.0 vs traditional public WiFi networks The transition from unencrypted legacy hot spots to Hotspot 2.0 eliminates login friction while dramatically strengthening security posture across venue estates. | Feature & Capability | Legacy Open Public WiFi | Hotspot 2.0 (Passpoint) Network | | :--- | :--- | :--- | | **Authentication method** | Manual web captive portal login | Automatic background 802.1X handshake | | **Over-the-air encryption** | None (Unencrypted Open / OWE optional) | WPA2-Enterprise / WPA3-Enterprise (AES) | | **User experience** | Frictional (Redirects, forms, re-logins) | Zero-click (Instant automatic connection) | | **Repeat visit connection** | Requires portal re-authentication | Seamless automatic roaming across locations | | **Cellular offload support** | Not supported | Native SIM-based EAP-SIM / EAP-AKA offloading | | **Rogue AP prevention** | Vulnerable to Evil Twin AP attacks | Protected via mutual certificate authentication | ## Key benefits of Hotspot 2.0 for enterprise venues ### 1. Frictionless guest experience Visitors no longer need to search for network names, ask staff for passwords, or fill out repetitive web forms. Devices automatically connect upon entering the venue, providing immediate Internet connectivity. ### 2. Enterprise-grade wireless security Public open WiFi networks expose user traffic to packet sniffing and session hijacking. Hotspot 2.0 enforces individual encryption keys for every connected session using WPA2/3-Enterprise protocols, securing user data even on public networks. ### 3. Multi-site roaming across venue estates For enterprise chains, retail malls, hotel groups, and transit hubs, a single Hotspot 2.0 profile enables devices to roam across hundreds of physical locations without re-authenticating. ### 4. SIM-based cellular offloading for telecom carriers Mobile operators deploy Passpoint profiles to offload data traffic from saturated cellular towers inside high-density venues like stadiums, airports, and shopping centers. Venues can partner with carriers to monetize infrastructure and improve indoor coverage. ## Hotspot 2.0 technical architecture: IEEE 802.11u and ANQP The technical foundation of Hotspot 2.0 relies on pre-association discovery. Standard WiFi requires a device to associate with an AP before discovering network services. Hotspot 2.0 uses Access Network Query Protocol (ANQP) frames to exchange capability information while the device is still in the probing state. ### ANQP information elements exchange * **Domain Name:** Identifies the network operator and realm information. * **Roaming Consortium Unique Identifier (OI):** Matches carrier roaming agreements to verify if a user's subscription allows free access. * **NAI Realm List:** Specifies supported authentication methods (e.g., EAP-TLS, EAP-TTLS, EAP-SIM). * **IP Address Type Availability:** Confirms whether IPv4 or IPv6 addresses are assigned upon connection. ## How to deploy Hotspot 2.0 and Passpoint networks Deploying Hotspot 2.0 across an enterprise access point estate requires compatible wireless infrastructure and a cloud RADIUS authentication service. ### 1. Verify hardware and firmware compatibility Ensure your wireless access points and WLAN controllers support Hotspot 2.0 Release 2 or Release 3. Leading Enterprise AP vendors including Cisco Meraki, HPE Aruba, Ruckus Wireless, Juniper Mist, Ubiquiti UniFi, and Fortinet provide native Passpoint configuration modules. ### 2. Configure RADIUS identity and EAP servers Hotspot 2.0 requires an 802.1X RADIUS server to validate device certificates or identity tokens. Cloud-native platforms like Purple integrate directly with existing identity providers (Entra ID, Okta, Google Workspace) and RADIUS clusters without requiring on-premises server hardware. ### 3. Publish OSU (Online Sign-Up) and Passpoint profiles An Online Sign-Up (OSU) server allows new users to download secure Passpoint WiFi profiles via a web portal, QR code, or mobile application. Once installed, the profile remains active for automatic future connections. ## Checking device compatibility for Hotspot 2.0 Modern mobile operating systems provide built-in Passpoint support: * **iOS and iPadOS:** Apple devices have supported Hotspot 2.0 natively since iOS 7. Passpoint profiles can be deployed via MDM or web download. * **Android:** Android devices running Android 6.0+ include native Passpoint (HS2.0) settings under advanced WiFi preferences. * **Windows and macOS:** Windows 10/11 and macOS Monterey+ support 802.11u pre-association discovery and enterprise profile management. ## Frequently asked questions about Hotspot 2.0 ### What is the difference between Hotspot 2.0 and Passpoint? Hotspot 2.0 is the underlying technical standard developed by the WiFi Alliance based on IEEE 802.11u. Passpoint is the official brand and certification program managed by the WiFi Alliance to verify hardware interoperability across vendors. ### Is Hotspot 2.0 more secure than open guest WiFi? Yes. Legacy open guest WiFi transmits data unencrypted across the air. Hotspot 2.0 enforces WPA2/WPA3-Enterprise encryption, generating unique encryption keys for every device to prevent eavesdropping. ### Does Hotspot 2.0 require hardware replacement? In most cases, no. Enterprise access points from Cisco, Aruba, Ruckus, Mist, and UniFi support Hotspot 2.0 via standard firmware updates. Cloud management platforms like Purple manage Passpoint RADIUS profiles on existing hardware. ## Accelerate Hotspot 2.0 deployment with Purple Purple provides a cloud-native Guest WiFi and Passpoint platform that replaces friction-heavy splash screens with zero-click, identity-driven 802.1X authentication. Compatible with all major enterprise WLC and access point vendors, Purple enables venues to deploy Passpoint, secure guest access, and location analytics.

Frequently asked questions

What is Hotspot 2.0 and how does it automate WiFi network discovery?

Hotspot 2.0 (based on IEEE 802.11u) is a wireless networking standard that allows mobile devices to automatically discover and evaluate access points prior to association. Using Access Network Query Protocol (ANQP), client devices query network capabilities, cellular roaming consortia, and realm identity parameters before transmitting association frames, enabling instant zero-touch roaming without manual SSID selection.

What is the difference between Hotspot 2.0, Passpoint, and OpenRoaming?

Hotspot 2.0 is the underlying IEEE 802.11u wireless standard. Passpoint (WiFi CERTIFIED Passpoint) is the industry certification program that validates device and access point interoperability. OpenRoaming, developed by the Wireless Broadband Alliance (WBA), is the global roaming federation that connects identity providers (telecom carriers, identity platforms, universities) with venue networks using Passpoint as the underlying radio standard.

How does Passpoint improve enterprise WiFi security compared to open captive portals?

Standard public captive portals use unencrypted open SSIDs that transmit data frames in cleartext, exposing users to eavesdropping and rogue AP attacks. In contrast, Passpoint mandates WPA2 or WPA3-Enterprise 802.1X authentication. Every client session generates unique cryptographic session keys via EAP-TLS or EAP-TTLS, providing encrypted over-the-air protection across public and guest venues.

How does cellular carrier offload work with Hotspot 2.0 in high-density venues?

High-density venues like stadiums and airports suffer from macro-cell cellular spectrum congestion. Hotspot 2.0 enables mobile network operators (MNOs) to automatically authenticate subscriber SIM credentials (EAP-SIM or EAP-AKA) or provisioned eSIM profiles onto enterprise WiFi networks. This offloads high data volume from saturated LTE and 5G cellular towers while providing visitors with high-speed connectivity.

Which enterprise wireless access points support Hotspot 2.0 and ANQP profiles?

Most modern enterprise wireless hardware vendors support Hotspot 2.0 Release 2, including Cisco Catalyst 9800, Cisco Meraki MR, HPE Aruba Central, Ruckus SmartZone, Juniper Mist, and Fortinet FortiAP. Network administrators configure 802.11u ANQP parameters, NAI Home Realms, and Roaming Consortium Organization Identifiers (RCOIs) directly within controller WLAN templates.

Can venues combine Hotspot 2.0 roaming with captive portal marketing?

Yes. Venues can broadcast a dual-layer strategy. First-time visitors without a Passpoint profile connect via a standard branded captive portal to complete registration and accept terms. During onboarding, the Purple platform pushes an encrypted Passpoint profile or provisioning link to the user's device, enabling all subsequent visits to auto-connect with zero splash screen friction.

Benchmark your staff WiFi network

Use our free assessment to see how your network compares against Purple's Bronze, Silver and Gold tiers - and get a personalised report your IT team can use to plan the next upgrade.

Get the free WiFi benchmark

Ready to get started?

Book a demo with one of our experts to see how Purple can help you achieve your business goals.

Speak to an expert