Skip to content
xPSK for things

IoT WiFi: tills, screens and cameras share the network, not the access

IoT devices: printers, screens and TVs, tills and EPOS, CCTV, sensors and door controllers. One SSID, a key per device, each on its own VLAN with its own policy and bandwidth limit.

  • Key per device
  • MAC binding
  • No per-SSID key ceiling
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Everything that cannot hold a certificate

Headless devices cannot complete a captive portal or carry a certificate. They each get their own key instead.

  • Printers, screens and TVs.
  • Tills and EPOS.
  • CCTV, sensors and door controllers.
Illustration

Audit

Take the tills off the shared password

PCI DSS v4.0.1 Req 2.3.2 says wireless keys must change when anyone who knows them leaves. A key per device means rotating one, not all of them.

  • Every device authentication in the log, with its key, VLAN and outcome.
  • Streamed to Sentinel, Splunk, Elastic or Datadog.
Illustration

Add-on: Purple Shield

Make this network safer and faster with Purple Shield

Purple Shield bolts onto Access or runs standalone. Set a different DNS policy per VLAN and by time of day, so staff, guests and residents each get the filtering that fits them, with dashboard analytics. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Common questions

Is there a limit on keys per SSID?

No. There is no per-SSID key ceiling.

What stops a device key being shared?

MAC binding ties a key to its device, so a key cannot become a second shared password.

Does xPSK take our WiFi out of PCI scope?

Purple never touches payment card data. Each till and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.

Will our tills and payment terminals work with a key each?

Yes. To a till, its xPSK key is an ordinary WPA2-Personal passphrase, so nothing on the till changes. The per-device key lives on the access point side, whether it is Cisco iPSK on Meraki or HPE Aruba MPSK, and Purple runs every vendor's version on one mixed estate.

Get the tills off the guest network

Tell us what is plugged in at a typical site. We map every till, screen and camera to its own key and VLAN. All in a 45-minute design session.

  1. Get your three-SSID plan in 45 minutesTell us what runs on your WiFi today, and a Purple network engineer maps it with you.
  2. Map your SSIDs onto threeOpen, secure and xPSK, on the access points you already own. You leave with the plan.
  3. Prove it on one site firstJudge the result on tickets and audit evidence, then roll out.

Your design session

45 minutes. Your estate. A plan you keep.

Led by a Purple network engineer. No slides. You keep the plan.