Key Nonce Nonce

Encryption 32 octets EAPOL-Key descriptor unverified

A number used once. The AP's in message 1, the station's in message 2.

Reading a capture

Thirty-two octets, more than a quarter of the whole descriptor, and the reason two sessions with the same passphrase get different keys. Both nonces go into the key derivation along with both MAC addresses; anyone who captures both can derive the session key IF they also know the passphrase, which is exactly why capturing a handshake is the first step in cracking one.

Where it sits

EAPOL-Key > Key Nonce

Accuracy

Clause
802.11-2024 §12.7.2
Verified
Not verified against the standard. Treat this as a claim, not a fact.