Skip to content
Travel and venues: Airports

Airports: passengers on the portal, staff on EAP-TLS, airlines, handlers and concessions on personal WiFi keys

One terminal, many employers. Each organization lands on its own role and VLAN over shared access points, scanners and gate readers get MAC-bound keys with no certificate to renew, and passengers use the portal.

  • Vancouver International Airport
  • Kinetic Melbourne Airport
  • 80,000+ venues in 90 countries
  • 99.9% RADIUS uptime SLA
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the airports network

Who is on the terminal network, and the lane each one gets

Airlines, handlers, concessions and agencies share one terminal's access points and nothing else: a role and VLAN per organization, keys for scanners and kiosks, passengers on the portal.

Who is on the terminal network, and the lane each one gets
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
PassengersOpenCaptive portal sign-in, consent recorded (or SSO, social, SMS)Guest VLAN, client isolation onConsent recorded at sign-in, session ends at the timeout you set
Returning passengers and crewSecurePasspoint or OpenRoaming profileGuest VLAN, with no portal on returnProfile installed once, valid at every site that runs it
Operator, airline, ground-handler and agency staffSecureEAP-TLS, certificate from your MDM over SCEP (each organization's own MDM and directory)A role and VLAN per organizationEnds when the employer disables the account, or the contract ends
Seasonal, agency and contractor staffxPSKIndividual key, MAC-bound (issued in bulk, no MDM)The employer's VLAN, with a bandwidth limit per keyEnds on the date set, at season end or contract end
Retail and food concession staff and registersxPSKIndividual key, MAC-boundA key set and VLAN per concessionRevoked when the lease ends, one concession at a time
Scanners, check-in kiosks, gate readers and common-use check-in kitxPSKIndividual key, MAC-boundA locked-down device VLAN per classOne key per device, revoked when it is swapped

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Airports: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Passengers and staff phones: portal and onboarding lane

The public lane. Sign-in is a branded portal per terminal, and staff who bring their own phone onboard through the same lane.

  • Passengers on the portal. SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA, and under 15 minutes to add the splash URL and RADIUS to a controller. Returning passengers roam on a Passpoint profile with no portal.
  • Staff on personal phones, no MDM. Sign in once in the Purple app and a WiFi pass installs on Windows, macOS, Linux, iOS and Android, so a handler's own phone never touches an MDM.
Illustration

Lifecycle

Key lifecycle: onboard, place, operate, end

The same four moves serve a scanner and a seasonal starter, driven from lists you already keep: a roster and your device register.

Issue from a roster, in bulk

Import the starters list or the device register and each line becomes a key with an end date, bound to the device's MAC where there is one.

Illustration

Place on the organization's lane

RADIUS returns the organization's VLAN, role or group policy, depending on your vendor, with a bandwidth limit per key. Your access points enforce it and your gateway holds shared-service rules.

Illustration

Operate one log for the whole terminal

Every accept and reject carries the organization, the method and the reason, so "whose device is this" is a query, and the log streams to your SIEM.

Illustration

End one key, one worker or one lease

A swapped scanner loses its key alone, and a concession that leaves has its keys revoked with nobody else touched. RADIUS CoA ends live sessions on access points that support it.

Illustration

One authentication log

One authentication log across every terminal and employer

Operator, airline, handler, concession and passenger traffic lands in one log, so who is on the network is a query and not a walk-round.

  • Which organization each device belongs to, and which VLAN it landed on.
  • Which seasonal keys are still live after the season's end date.
  • Which concession registers authenticated today, and which were rejected and why.
  • Which scanners have not authenticated since the last shift.
Illustration

Audit

Concession payments apart from the terminal: what each assessor tests

Each concession is its own merchant with its own assessor. Purple never touches card data, and segmentation gives each assessor that concession's VLAN map and log.

  • PCI DSS v4.0.1 Req 2.3.2

    Wireless keys must change when anyone who knows them leaves. A key per device makes that one rotation, and never a whole concession's registers.
  • PCI DSS Req 8 and 10

    Every authentication is logged with the identity and the reason, and streamed to your SIEM as evidence.

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Airports run on it

Vancouver
International Airport runs on Purple, concessions on their own keys
Melbourne
Kinetic Melbourne Airport runs on Purple, concessions on their own keys
80,000+
venues run on Purple, in 90 countries
99.9%
cloud RADIUS uptime SLA, in your contract

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

How do airlines, handlers and concessions stay apart on shared access points?

Each organization gets its own role and VLAN, returned by RADIUS at authentication. Your access points enforce the lane and your gateway holds the inter-VLAN rules.

Do we need new access points in the terminal?

No. Purple Access is a cloud overlay on the access points your terminals already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

How does a handheld scanner or gate reader with no supplicant get on?

To the device its key is an ordinary WPA2-Personal passphrase, so there is no supplicant, certificate or portal. The per-device key is held on the access point side under each vendor's name for it (Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK).

Does xPSK take our WiFi out of PCI scope?

Purple never touches payment card data. Each register and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.

How are seasonal and contractor staff switched off at season end?

Each key is issued with an end date, so access stops on that day with no ticket. To end one early, revoke that key alone.

Book a demo: we issue and revoke a key on a live network

Bring a register, a scanner, a kiosk and a starter. We issue each a key or certificate, place it in its lane and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.