Hotspot 2.0 & Passpoint Venue Readiness Estimator
Configure your venue parameters to evaluate Passpoint auto-connect rates, cellular offload potential, and enterprise WiFi security benefits.
Hotel Guest & Loyalty Passpoint Architecture
Key takeaways: Hotspot 2.0, Passpoint, and NGH
- Zero-Touch Onboarding: Hotspot 2.0 (IEEE 802.11u) and Passpoint allow mobile devices to discover and authenticate with secure enterprise networks automatically without captive portal splash screens or manual SSID selection.
- WPA3-Enterprise Encryption: All client transmissions on Passpoint networks are encrypted using 802.1X protocols ( EAP-TLS , EAP-TTLS, EAP-SIM) and WPA2/WPA3-Enterprise, eliminating eavesdropping and rogue access point spoofing.
- ANQP Discovery: Access Network Query Protocol (ANQP) queries network capabilities, roaming consortium identifiers, and cellular carrier relationships before the device completes association.
- Carrier Cellular Offloading: Mobile network operators automatically offload congested LTE and 5G cellular traffic onto venue WiFi networks in high-density environments like airports, stadiums, and transit stations.
- Hybrid Architecture: Venues combine Passpoint for frictionless repeat visits with Purple Captive Portal for first-time visitor marketing opt-ins and demographic data capture.
Public WiFi onboarding has historically presented a fundamental tradeoff between security and convenience. Traditional guest networks rely on open, unencrypted SSIDs paired with web-based captive portals . While web splash pages capture marketing consent, manual browser logins create user friction, increase connection drop-offs, and leave unauthenticated radio frames vulnerable to packet sniffing and man-in-the-middle attacks.
Hotspot 2.0, WiFi CERTIFIED Passpoint, and Next Generation Hotspot (NGH) architectures resolve this conflict. By standardizing pre-association network discovery and certificate-based 802.1X authentication, these standards deliver cellular-style roaming where devices connect securely and automatically the moment they enter signal range.
What is Hotspot 2.0, Passpoint, and Next Generation Hotspot?
Although frequently used interchangeably, Hotspot 2.0, Passpoint, and NGH refer to distinct layers of the technical ecosystem:
- Hotspot 2.0 (IEEE 802.11u): The baseline wireless protocol amendment published by the IEEE. It defines how access points broadcast network metadata and how client devices query upstream network capabilities before establishing an RF association.
- Passpoint (WiFi CERTIFIED Passpoint): The interoperability testing and certification programme managed by the WiFi Alliance. Passpoint standardizes profile provisioning, SIM authentication, and certificate validation across device manufacturers (Apple iOS, Google Android, Windows) and enterprise access point vendors (Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist).
- Next Generation Hotspot (NGH): An industry initiative developed by the Wireless Broadband Alliance (WBA) that defines commercial roaming agreements, operator billing frameworks, and federated identity exchanges, serving as the basis for global OpenRoaming architectures.
How the IEEE 802.11u and ANQP connection process works
On legacy WiFi networks, a device cannot determine whether a network offers internet access or supports its credentials until after associating and requesting a DHCP lease. Hotspot 2.0 solves this inefficiency using Access Network Query Protocol (ANQP) during pre-association:
- Beacon and Probe Response: Access points transmit 802.11 beacon frames containing an Interworking Element (IE) indicating Hotspot 2.0 capability, venue group classification, and network access type.
- ANQP Query Exchange: Prior to associating, the client sends Generic Advertisement Service (GAS) request frames to query the AP for Roaming Consortium Organization Identifiers (OIs), Network Access Identifier (NAI) realm lists, and 3GPP cellular operator codes.
- Profile Matching: The device matches the AP capabilities against installed Passpoint profiles (installed via mobile apps, enterprise MDM, or SIM card profiles).
- 802.1X Authentication: If a match is found, the device associates and executes an EAP authentication handshake (EAP-TLS with client certificates, EAP-TTLS with MSCHAPv2, or EAP-SIM/AKA using cellular SIM credentials).
- Encrypted Tunneling: The RADIUS server validates credentials and establishes individual dynamic encryption keys (CCMP/GCMP) via WPA2 or WPA3-Enterprise, ensuring end-to-end data privacy.
Comparison: Hotspot 2.0 / Passpoint vs Captive Portal vs OpenRoaming
Security architecture: why Passpoint eliminates MITM attacks
Standard open public WiFi networks transmit data frames in cleartext, enabling eavesdropping via passive packet capture. Attackers can also deploy "Evil Twin" access points with identical SSIDs to intercept login credentials and financial transactions.
Passpoint eliminates these vulnerabilities through three security mechanisms:
- Server Certificate Validation: The client validates the server identity certificate against trusted root Certificate Authorities (CAs), preventing rogue AP impersonation.
- Mutual Authentication: Enterprise EAP protocols ensure both the network and the client verify identities before establishing network access.
- Individual Per-User Encryption: Pairwise Transient Keys (PTK) encrypt every frame between the client and the access point, preventing other connected devices in the venue from intercepting network traffic.
Carrier offload and high-density venue economics
High-density venues such as international airports (like Manchester Airports Group and AGS Airports), sports stadiums, and transport interchanges face severe cellular network congestion. Indoor cellular macro signals struggle to penetrate modern building materials, while 5G millimeter wave coverage remains localized.
Passpoint enables mobile operators to offload cellular data onto existing enterprise WiFi infrastructure seamlessly. When an operator subscriber enters the venue, their smartphone identifies the operator Consortium OI via ANQP and authenticates automatically using the device SIM card. This reduces cellular tower congestion while providing passengers with reliable high-speed data.
Hybrid venue strategy: combining Passpoint with Purple Captive Portals
While Passpoint delivers friction-free connectivity, venue marketing and operations teams still require first-party customer insights, marketing opt-ins, and visitor demographics. Modern enterprises implement a hybrid architecture:
- First-Time Visitors: Connect via a branded Purple Captive Portal , completing registration, selecting communication preferences, and accepting GDPR/CCPA terms.
- Passpoint Provisioning: Upon completing the captive portal flow, the Purple platform generates and installs a secure Passpoint configuration profile onto the visitor device.
- Subsequent Visits: On all return visits across any venue in the brand network, the device connects automatically via encrypted Passpoint without presenting splash pages again.
- Telemetry & Analytics: The venue captures comprehensive dwell time, frequency, and zone movement data via Purple WiFi Analytics while delivering a seamless visitor experience.
Enterprise access point vendor configuration
Passpoint and Hotspot 2.0 can be enabled across major enterprise wireless hardware platforms that support IEEE 802.11u:
- Cisco Meraki & Catalyst: Configure Hotspot 2.0 profiles within Dashboard or Catalyst WLC, assigning NAI realms, 3GPP cellular networks, and RADIUS accounting endpoints.
- HPE Aruba Networking: Deploy Passpoint configurations via Aruba Central or AirWave, specifying Roaming Consortium Identifiers and Venue Name ANQP elements.
- Ruckus Wireless: Enable Hotspot 2.0 within SmartZone or ZoneDirector controllers with automated Online Signup (OSU) server mapping.
- Juniper Mist: Configure AI-driven Passpoint WLAN profiles with cloud RADIUS authentication and zero-touch profile management.
Frequently asked questions
What is Hotspot 2.0 and how does it work?
Hotspot 2.0 (IEEE 802.11u) is a wireless standard that enables mobile devices to automatically discover, query, and authenticate with compatible public and enterprise WiFi networks using pre-association ANQP queries without user intervention.
What is the difference between Hotspot 2.0 and Passpoint?
Hotspot 2.0 is the underlying technical standard developed by the IEEE and WiFi Alliance, while Passpoint (WiFi CERTIFIED Passpoint) is the formal certification program ensuring cross-vendor interoperability for seamless, encrypted zero-touch roaming.
How does Passpoint improve enterprise WiFi security compared to open captive portals?
Unlike open captive portals that transmit unencrypted traffic, Passpoint encrypts all client transmissions using WPA2/WPA3-Enterprise (802.1X with EAP-TLS or EAP-TTLS), eliminating man-in-the-middle eavesdropping and rogue AP attacks.
What is Next Generation Hotspot (NGH) and OpenRoaming?
Next Generation Hotspot (NGH) is the Wireless Broadband Alliance initiative standardizing cellular offload and seamless WiFi roaming across global transport hubs, hotels, and venues, which forms the foundation of modern OpenRoaming federations.
Can venues deploy Passpoint alongside captive portal marketing?
Yes. Hybrid deployments use Hotspot 2.0/Passpoint for instant, frictionless return visits and staff onboarding while directing first-time guest connections through a branded captive portal for data capture and marketing opt-ins.




