Conference centres: delegates on the portal, staff on EAP-TLS, a personal WiFi key per exhibitor stand
Import the exhibitor list and every stand gets its own network and keys, with the show's end date on each. Production and AV crews sit on their own VLAN, delegates use the portal, and the whole show is one log.
- Meydenbauer Center
- 80,000+ venues in 90 countries
- 500 million logins a year
- 99.9% RADIUS uptime SLA
Who is on the conference centres and events network
Who is on the show network, and the lane each one gets
An exhibitor network per stand, created in bulk from the exhibitor list and ended at close, with AV and production crews on their own VLAN, off delegate WiFi.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Delegates and speakers | Open | Captive portal sign-in, consent recorded (or SSO, social, SMS) | Delegate VLAN, client isolation on | Consent recorded, session ends at the timeout you set |
| Venue operations, security and IT | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Organisers and their event staff | xPSK | Individual key, MAC-bound (per event, no MDM) | An organiser VLAN per event, apart from delegates | Ends when the show closes |
| Exhibitors on each stand | xPSK | Individual key, MAC-bound | A network per stand: its own VLAN and key set | Created in bulk, ended when the event closes |
| AV, production and broadcast crews | xPSK | Individual key, MAC-bound | A production VLAN, apart from delegates and exhibitors | Ends with the load-out |
| Build, breakdown and catering contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A VLAN and bandwidth limit per key | Ends on the day the contract does |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Conference centres and events: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Delegates and staff phones: portal and onboarding lane
The delegate lane, branded per event, and the BYOD lane for the venue's own staff who bring a phone.
- A portal per event. SSO, Google, Apple, Facebook or SMS with consent recorded for GDPR and CCPA, and under 15 minutes to add the splash URL and RADIUS to a controller.
- Venue staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs on Windows, macOS, Linux, iOS and Android.
Venue operations: EAP-TLS and groups
One WPA-Enterprise SSID for the venue's own managed devices. Cloud RADIUS checks the directory and returns the VLAN for the group.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once.
- Operations by directory group. Entra ID, Okta or Google Workspace over SAML and SCIM, so a leaver is disabled once and every hall stops authenticating them.
Exhibitors, production crews and kit: a key each
Hundreds of stands set up in a day, with no time for a certificate or a portal. Keys come from the exhibitor list, and each stand lands on its own VLAN.
- A private network per exhibitor stand. Each stand's laptops, card readers and demo kit see each other and nothing else, on one SSID, so 300 stands add keys and no beacons.
- Keys in bulk from the exhibitor list. Import the list and each stand gets its key set, with the event's end date on every key, so nothing outlives the show.
- AV and production crews off delegate WiFi. Show control, streaming encoders and production laptops on their own VLAN, so a delegate crowd never competes with the main stage feed.
Lifecycle
Key lifecycle: import, place, run the show, close
The unit is the show: the exhibitor list is the system of record and every key ends at close.
Issue from the exhibitor list
Import the exhibitor list before the build days and every stand gets a network and its keys, with the event's end date on each. Stand staff enter a key like any WPA2-Personal passphrase, with nothing to install.
Place each stand on its own VLAN
RADIUS returns the stand's VLAN, role or group policy, depending on your vendor, with a bandwidth limit per key. Your access points enforce it and shared services live on your gateway.
Operate the show from one log
Every accept and reject carries the stand, the crew and the reason, so a stand that cannot connect is a lookup on the log and not a walk to hall 3.
Close the show, end every key
Keys stop on the closing date, with nothing to clear. To end one early, revoke that key alone, and RADIUS CoA ends the live session on access points that support it.
One authentication log
One authentication log from the foyer to the loading dock
Delegates, stands, crews and venue systems share one log per event, so the post-event debrief is a query.
- Which stands have connected, and which have not yet.
- Which VLAN and key each stand's devices landed on.
- Which production and AV devices are online, and on which VLAN.
- Which authentications were rejected, and why.
Audit
Stand card readers apart from delegates: what the assessor tests
Exhibitors take cards on the venue's access points. Purple never touches card data, and segmentation gives each assessor the stand's VLAN map and log.
PCI DSS v4.0.1 Req 2.3.2
Wireless keys must change when anyone who knows them leaves. A key per stand ends with the show, so the next exhibitor never inherits it.PCI DSS Req 8 and 10
Every authentication is logged with the identity and the reason, and streamed to your SIEM as evidence.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Convention centres run on it
- Meydenbauer
- Center runs on Purple
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- 99.9%
- cloud RADIUS uptime SLA, in your contract
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Does each stand need its own SSID?
No. Every stand shares one xPSK SSID and gets its own VLAN and key set from RADIUS, so 300 stands add 300 sets of keys and no beacons.
Do we need new access points in the halls?
No. Purple Access is a cloud overlay on the access points your halls already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
What stops an exhibitor's key working at next month's show?
Every key is issued with the event's end date, so it stops authenticating when the show closes. A new show is a new import, and last year's key is rejected and logged.
How do demo kit and card readers with no supplicant connect?
To the device a key is an ordinary WPA2-Personal passphrase, so there is no supplicant, certificate or portal. The per-device key is held on the access point side under each vendor's name for it (Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK).
Does xPSK take our WiFi out of PCI scope?
Purple never touches payment card data. Each till and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.
Book a demo: we issue and revoke a key on a live network
Bring one show's worth of lanes: an exhibitor list, a production crew and a delegate's phone. We issue the stands' keys in bulk, place each stand on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.