WAP, WTLS, WML — and sitting an exam older than its textbook
◈ 9 cardsThe mobile web that came before the mobile web: WAP, decks and cards, WTLS and the gateway that sees plaintext — plus the skill of recognising when a question is written in a vocabulary the current text has moved past.
Read this first: why this lesson exists
This lesson is quarantined on purpose. None of its content is in your textbook, and the technology it describes is genuinely obsolete — nobody has deployed it this decade. It is here because the sample examination paper is older than the fifth edition, and four of its fifty multiple-choice questions ask about this material directly. Four marks out of fifty in Part One, for perhaps twenty minutes of reading.
So study it the way you would study a short list of historical dates: know the definitions, do not build anything on them, and do not spend an evening hunting Chapter 24 for a WAP section that does not exist. Everything below is sourced from the WAP Forum / Open Mobile Alliance specifications, and it is labelled as history because that is what it is.
WAP — the mobile web before the mobile web
The Wireless Application Protocol is the standard that put the web and telephony services onto a handset — a whole protocol suite, plus a gateway that translates between it and the ordinary Internet. Read that definition carefully, because the discriminating phrase is "access to services": WAP is a service architecture, not a cipher and not a link-layer scheme. WEP and WPA are encryption; WAP is a whole stack.
It was designed for a device profile that has since vanished: small displays, limited input (a numeric keypad), restricted memory and processing power, low bandwidth and intermittent connectivity. Its answer was a protocol suite paralleling the Internet stack — an application environment, a session layer, a transaction layer, a security layer and a datagram layer — plus a gateway that translated between the wireless side and ordinary HTTP on the Internet side.
WML — decks and cards
WAP's content format is the Wireless Markup Language, and its content is organised into decks and cards.
A deck is the unit of content transmission. It is identified by a URL, and it is therefore the direct analogue of an HTML page. A card is one screen's worth of interaction within a deck, and a deck holds one or more cards.
The design rationale makes the pair memorable, so learn it rather than the bare definitions: a radio round trip on a 1999 mobile network was slow and expensive, so bundling several cards into a single deck let a whole short interaction — ask, choose, confirm — be delivered in one fetch. The card is what the user sees; the deck is what is fetched. When a question describes "the unit of content transmission, identified by a URL", it is describing the deck, and "card" is the trap.
WTLS — and the gap it leaves
WAP puts its security in WTLS, Wireless Transport Layer Security, which protects exactly one leg of the path: the handset to the WAP gateway, and no further. It is a TLS derivative adapted for a low-bandwidth, high-latency, datagram-capable link, and its structure mirrors TLS's: above a record layer sit three protocols — the Handshake Protocol, the Change Cipher Spec Protocol, and the Alert Protocol. The Alert Protocol is the one that conveys WTLS-related alerts to the peer entity.
If you know the TLS architecture from earlier in this course, you can reconstruct all of that from first principles, which is the one genuine intellectual payoff here.
The meta-skill, which is worth more than the four marks
The real lesson is transferable, and it applies across the whole paper. Recognise when a question's vocabulary comes from a generation the current textbook has moved past, and answer in that generation's terms rather than substituting the modern equivalent.
Concretely: when a question names WAP, WTLS or WML, it is not asking about 802.11i. When it names certificate classes, it is not asking about Basic Constraints. When it names a gauge or a clandestine user, it is not asking about multivariate anomaly models or about hacktivists. When it says "SSL", answer about SSL.
And conversely — this half matters just as much — three questions that feel legacy do have current answers and must be answered from the book: identity management (which the fifth edition covers as ICAM), multivariate anomaly detection models, and the named worms (Code Red, Slammer, Sobig.F, Mydoom are all still in the current worm history).
The failure mode this lesson exists to prevent is specific and common. A well-prepared learner meets a WTLS question, recognises nothing from the textbook, and picks CCMP or TKIP because those at least sound like wireless security. The distractors are drawn from the topic you did study, which is exactly why the legacy material has to be taught rather than guessed at.
One honest caveat to end on: the paper you actually sit may be a newer one, drawn entirely from the current edition. This lesson is insurance. Its cost is a handful of definitions; it is not a reason to doubt anything else in the course.
source WAP Forum / Open Mobile Alliance specifications (WAP architecture, WTLS)
source WAP Forum / Open Mobile Alliance specifications (WAP architecture, WML, WTLS)
source WAP Forum / Open Mobile Alliance specifications (WAP architecture)
source WAP Forum / Open Mobile Alliance WML specification
source WAP Forum / Open Mobile Alliance WTLS specification
source WAP Forum / Open Mobile Alliance WTLS specification
source WAP Forum / Open Mobile Alliance specifications (WAP architecture, WTLS)