Skip to content
xPSK use case

Private networks for every resident: one personal WiFi key, one household, one building network

Casting and smart speakers break on shared or guest-style WiFi, because discovery traffic is blocked between clients or visible to everyone. With a personal WiFi key per household on one xPSK SSID (iPSK, PPSK, DPSK, MPSK), a household's devices find each other and no neighbour's appear.

  • ~1 million residents on Purple
  • 60% fewer helpdesk tickets at move-in
  • University of New Brunswick on iPSK
Illustration
Book my design session

The problem

Casting needs discovery, and shared WiFi gives you the wrong kind

AirPlay and Chromecast find a TV with multicast discovery. Client isolation blocks it, and no isolation shows every household's devices to every other.

  • Client isolation, the right setting for a guest network, stops a resident's phone from finding their own TV.
  • Turning isolation off puts every household's speakers and TVs in each other's cast lists.
  • An SSID per household would fix discovery and costs airtime: 8 to 10 SSIDs use 15 to 25% of channel airtime.
  • Residents fall back on their own routers and extenders, which add interference to the building's radios.

How it works

A household is a segment: key, VLAN or role, and discovery inside it

The building keeps one set of access points and one SSID. The household's boundary is drawn by the key.

Issue a key per household

Create the household's key from the console, a bulk import or the Purple API, and hand it to the resident in the Purple app or a branded self-service portal. Each additional device gets its own key under the same household.

Illustration

Place the household on its own segment

RADIUS returns the household's VLAN or role with its own bandwidth limit, and mDNS reflection keeps AirPlay and Chromecast discovery inside that segment. Your gateway decides what, if anything, crosses between households.

Illustration

Support from one log

Every accept and reject is logged with the key, device, VLAN and reason, so "my speaker will not join" is a search on the household and not a visit.

Illustration

Revoke the household at move-out

Withdraw the household's keys and RADIUS CoA ends their live sessions on access points that support it. Every other household stays connected.

Illustration

Open, secure or xPSK

Which of the three networks, for which party in a building

Which of the three networks, for which party in a building
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Prospects, visitors and event guestsOpenCaptive portal sign-in, consent recordedA guest VLAN with client isolation onSession and consent recorded at sign-in
On-site team and maintenance staffSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory groupAccount disabled in the directory ends access
Residents' phones, TVs and speakersxPSKIndividual key, MAC-boundA VLAN or role per household, discovery kept inside itIssued at move-in, revoked at move-out
Locks, thermostats and leak sensorsxPSKIndividual key, MAC-boundA building-systems VLAN, apart from every householdOne key per device, revoked alone

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

What it covers

What you can do with it

  • Casting that works in the household

    mDNS reflection keeps AirPlay and Chromecast inside a household's own segment.
  • Neighbours never appear

    Another household's TV is not in the cast list, because it is not on the segment.
  • No router per flat

    Residents stay on the building's access points, so the estate is not carpeted in personal routers.

Where it matters

The industries that run into this most

Proof

Resident networks at scale

About 1 million students and residents run on Purple community networks, and the University of New Brunswick runs iPSK on Purple.

~1M
students and residents on Purple community networks
60%
fewer helpdesk tickets at move-in, US university housing across 40 buildings
iPSK
University of New Brunswick runs iPSK on Purple

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Why does casting break on shared WiFi?

Casting finds the receiver with multicast discovery. Client isolation blocks it between clients, and without isolation every household sees every other. A segment per household gives discovery a boundary that matches the home.

Is xPSK one SSID or one per household, tenant or device?

One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.

What does mDNS reflection do here?

It carries discovery traffic between devices that sit on the same household segment, so AirPlay and Chromecast work inside it. It does not carry discovery between households.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Book a demo: we issue and revoke a key on a live network

Bring a floor plan and the devices residents bring. We key one household, cast to a TV and revoke it live, on the access points you already own.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.