Skip to content
xPSK use case

Devices with no screen: a personal WiFi key each, bound to the device and placed on its VLAN

A printer, a sensor or a door controller cannot complete a captive portal or hold a certificate. xPSK (iPSK, PPSK, DPSK, MPSK) gives each one its own WPA2-Personal key, bound by MAC and placed on a device VLAN, so a leaked key exposes one device and not the building. Everything that can do better stays on the secure and open networks.

  • 80,000+ venues in 90 countries
  • 99.9% RADIUS uptime SLA
  • 8 to 10 SSIDs use 15 to 25% of channel airtime
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

The problem

A shared password on a printer is the weakest credential in the building

Headless devices are the part of the estate that cannot do better than a passphrase, so what matters is whose passphrase it is and how far it travels.

  • One passphrase is typed into every printer, sensor and controller, so a single leaked or photographed key exposes every device on it.
  • These devices run for years. The key never changes, because changing it means a visit to each device.
  • The usual fix is an SSID per device class, and it costs airtime: 8 to 10 SSIDs use 15 to 25% of channel airtime.
  • There is no supplicant to run 802.1X and no portal to click through, so the usual controls have nothing to attach to.
  • The log cannot say which device a connection was, because every device presented the same key.

How it works

Issue, bind, place, rotate or revoke: one device at a time

The device does nothing new. Every control lives on the access point and RADIUS side.

Create the key outside the device

A key comes from the console, a bulk import of a device list or the Purple API, and is typed into the device's WiFi settings once, like any WPA2-Personal passphrase. The device needs no agent, no supplicant and no portal.

Illustration

Bind to the MAC, place on a device VLAN

MAC binding ties the key to the device, so a copied key does not work on another one. RADIUS returns a VLAN or role for the device class with a bandwidth limit, and your access points enforce it. What may talk to what is a rule on your gateway or firewall.

Illustration

Operate by class, not by exception

Every authentication is logged with the key, device, VLAN and outcome, so a failing sensor is a log search and a rogue device is a Reject with a reason. The log streams to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

Rotate or revoke one device

Rotate a key at the device's next service visit, or revoke it when the device is replaced. Withdrawing one key drops one device, with RADIUS CoA ending the live session on access points that support it.

Illustration

Open, secure or xPSK

Which of the three networks, for which kind of device and person

Which of the three networks, for which kind of device and person
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Staff phones with no MDMOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the staff group's VLANEnds with the directory account
Visitors and contractors' phonesOpenCaptive portal sign-in, consent recordedA guest VLAN with client isolation onSession and consent recorded at sign-in
Managed tablets, handhelds and laptops that can hold a certificateSecureEAP-TLS, certificate from your MDM over SCEP (certificates stay the default)VLAN by directory group or device roleCertificate delivered and renewed by your MDM
Printers, screens and displaysxPSKIndividual key, MAC-boundA device VLAN per class, apart from peopleOne key per device, rotated or revoked alone
Sensors, door controllers and CCTVxPSKIndividual key, MAC-boundA building-systems VLAN, with its own bandwidth limitRevoked with the device when it is replaced

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

What it covers

What you can do with it

  • A VLAN per device class

    Printers, signage, CCTV, building controls and payment terminals each land on the VLAN for their class, so what a camera can reach is decided once per class and not once per device.
  • A bandwidth limit per key

    A limit per key stops one chatty device or a firmware loop from taking the uplink. It is a cap, not a guarantee.
  • Voice assistants on keys, not SSIDs

    A voice assistant in every room is a key per device on the xPSK SSID, which avoids an extra network for each one and the airtime that goes with it.
  • Bulk issue for a refit

    Import a device list and each entry gets a key with its own end date and VLAN, so replacing every device on a floor is a batch job.

Where it matters

The industries that run into this most

Proof

The platform under the devices

80,000+ venues in 90 countries run on Purple, with a 99.9% cloud RADIUS SLA in the contract.

80,000+
venues run on Purple, in 90 countries
99.9%
cloud RADIUS uptime SLA, in your contract
500M
logins a year

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Why not certificates for everything?

Certificates stay the default for every device that can hold one: staff laptops and phones on EAP-TLS, delivered by your MDM over SCEP. xPSK is for everything that cannot, such as devices with no 802.1X supplicant, no screen or no certificate store.

What does the device see?

An ordinary WPA2-Personal passphrase, so nothing on the device changes. The per-device key lives on the access point side, such as Cisco iPSK on Meraki or HPE Aruba MPSK, and Purple runs each vendor's version on one mixed estate.

What happens if one device key leaks?

One device is exposed and not the estate. The key is bound to that device by MAC, lands only on its class VLAN and can be revoked alone, with the live session ended by RADIUS CoA on access points that support it.

Why not an SSID per device class?

Each SSID adds beacons and management traffic: 8 to 10 SSIDs use 15 to 25% of channel airtime. One xPSK SSID carries every class, each on its own VLAN, with no per-SSID key ceiling.

How do keys rotate on devices nobody visits?

Set an end date at issue and rotate at the device's service interval. Revoking one key never touches another device, so rotation is scheduled per device and never an estate-wide event.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Book a demo: we issue and revoke a key on a live network

Bring the list of what is plugged in at a typical site, including the devices nobody wants to talk about. We bind one to a key, place it on its VLAN and revoke it live.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.