Shopping malls: shoppers on the portal, center staff on EAP-TLS, a personal WiFi key and VLAN per store
The landlord runs the access points once. Each retailer's registers and card terminals get MAC-bound keys on the retailer's own VLAN, shoppers sign in on the portal and the center team sits on EAP-TLS, so one log covers the center and every tenant.
- Vancouver International Airport
- Kinetic Melbourne Airport
- 80% fewer IT helpdesk requests at McDonald's
- 80,000+ venues in 90 countries
Who is on the shopping malls network
Who connects, and where each one lands
Each retailer is its own merchant on the mall landlord's access points, so each gets its own VLAN and key set while shoppers stay on the portal and the center team keeps one log across every tenant.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Shoppers | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on | Consent recorded at sign-in |
| Returning shoppers | Secure | Passpoint or OpenRoaming profile | Guest VLAN, with no portal on return | Profile installed once, valid at every center that runs it |
| Landlord, facilities and center management staff | Secure | EAP-TLS, certificate from your MDM over SCEP | Staff VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Retailers' registers and card terminals | xPSK | Individual key, MAC-bound | A payments VLAN per retailer, apart from shoppers and the center | Revoked when a terminal is swapped or the lease ends |
| Retailers' back-office PCs and stock handhelds | xPSK | Individual key, MAC-bound | The retailer's back-office VLAN | One key per device, rotated or revoked alone |
| Pop-ups and kiosks | xPSK | Individual key, MAC-bound | A VLAN and key set per unit | Keys issued before opening, revoked when the unit closes |
| Fit-out contractors | xPSK | Individual key, MAC-bound (one unit, time-limited) | The unit's VLAN with a bandwidth limit | Ends on the fit-out's last day |
| Digital signage, parking lot systems, CCTV and wayfinding | xPSK | Individual key, MAC-bound | A center-systems VLAN apart from every retailer | Revoked when the device is replaced |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Shopping malls: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Shoppers and returning visitors: portal and Passpoint
The guest lane for the footfall, with a way for a returning shopper to rejoin without the portal.
- One branded portal for the center. SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA. The splash URL and RADIUS go onto a controller in under 15 minutes.
- Shoppers apart from every retailer. Access points place portal guests on a guest-only VLAN with client isolation on, so a shopper's phone never sees a register.
- A lane from portal to Passpoint. A device starts on the open network and can graduate to a Passpoint profile, so the shopper who comes back is not asked to sign in again.
Center team and returning shoppers: EAP-TLS and Passpoint
One WPA-Enterprise SSID. Cloud RADIUS checks the directory or the Passpoint profile and returns the VLAN for whoever matched.
- EAP-TLS for the center team. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP to facilities and management devices. Setup is five to ten minutes, once.
- Directory groups for the center's own staff. Entra ID, Okta or Google Workspace over SAML and SCIM. Disable a leaver once and the center stops authenticating them.
- Passpoint and OpenRoaming for returning shoppers. OpenRoaming is free through the Connect license, across 5 million+ hotspots worldwide.
Retailer kit, pop-ups and fit-out crews: a key each, on the unit's VLAN
One xPSK SSID for the whole center, with a key and VLAN per tenant device and no SSID per retailer.
- registers and card terminals, per retailer. Each on a MAC-bound key and the retailer's payments VLAN, apart from shoppers and center systems. Purple never touches card data.
- No SSID per retailer. 8 to 10 SSIDs use 15 to 25% of channel airtime, so a key per device on one SSID replaces an SSID per tenant. There is no per-SSID key ceiling.
- Pop-ups and kiosks trading on day one. Keys and a VLAN are issued before opening, so the unit trades with no broadband order to place.
- Fit-out contractors for one unit. A time-limited key on that unit's VLAN, from the self-service portal or the Purple API, ending with the fit-out.
- Signage, parking lot and CCTV in their own lane. Each device on a MAC-bound key and a center-systems VLAN apart from every retailer. Inter-VLAN rules live on your gateway.
Lifecycle
Key lifecycle: sign the lease, key the unit, hand it back
The systems of record are your lettings schedule and the retailer's device list. The unit is what you issue against.
Issue against the unit
Key a retailer's terminals and PCs before opening: from the console, in bulk from a device list or through the Purple API. Each key is bound to the device's MAC address.
Place on the retailer's VLAN
RADIUS returns the VLAN, role or group policy for the unit, depending on your vendor. Your access points enforce it, and the gateway holds the rules between VLANs.
Operate from one center log
Every accept and reject carries the retailer, the device and the reason, across the whole center, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
End a terminal, a fit-out or a lease
Replace a card terminal and you revoke one key. A fit-out key ends on its last day, and a retailer that leaves has its keys revoked with nobody else touched.
One authentication log
One log across every unit in the center
Shoppers, center staff, retailer terminals and building systems land in one log, so the center team sees which unit each device belongs to without visiting it.
- Which devices are on which retailer's VLAN, and which keys are live after a retailer has left.
- Which fit-out and contractor keys are live today, and when each ends.
- Which registers authenticated from a MAC address they are not bound to, and were rejected.
- How many shoppers signed in through the portal, by hour and day, with MAC addresses anonymized.
Audit
Payments apart from shoppers and the center
Purple never touches card data. Each retailer's terminals sit on their own key and VLAN, apart from shoppers and the center team, and every authentication is logged.
PCI DSS v4.0.1 Req 2.3.2
Wireless keys must change when anyone who knows them leaves. A key per terminal makes that one rotation, not every register in the unit.PCI DSS Req 8 and 10
Every authentication is logged with the identity and the reason, and streamed to your SIEM.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Concessions on their own keys, live at scale
Vancouver International Airport and Kinetic Melbourne Airport run concessions on their own keys, the design a center uses for its tenants.
- Vancouver
- International Airport runs on Purple, concessions on their own keys
- Melbourne
- Kinetic Melbourne Airport runs on Purple, concessions on their own keys
- 80%
- fewer IT helpdesk requests at McDonald's
- 80,000+
- venues run on Purple, in 90 countries
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your centers already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Do we need an SSID per retailer?
No. One xPSK SSID carries the whole center, and RADIUS returns each retailer's VLAN at authentication. 8 to 10 SSIDs use 15 to 25% of channel airtime, which is why an SSID per tenant does not scale.
Does xPSK take the center's WiFi out of PCI scope?
Purple never touches payment card data. Each retailer's terminals sit on their own key and their own VLAN, apart from shoppers and the center team, and every authentication is logged with its identity and reason. Inter-VLAN rules live on your gateway.
Will our registers and payment terminals work with a key each?
Yes. To a register, its xPSK key is an ordinary WPA2-Personal passphrase, so nothing on the register changes. The per-device key lives on the access point side, whether it is Cisco iPSK on Meraki or HPE Aruba MPSK, and Purple runs every vendor's version on one mixed estate.
How does a pop-up trade on day one with no broadband order?
Its terminals and PCs join your access points with keys you issue, so there is no line to order. RADIUS returns the unit's VLAN and your access points enforce it.
What happens to a retailer's access when the lease ends?
You revoke that unit's keys and nobody else is touched. RADIUS CoA ends live sessions on access points that support it, and the unit's VLAN has no key left to authenticate.
What does revoking one key do to everyone else?
Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.
Book a demo: we issue and revoke a key on a live network
Bring one unit's worth of devices: a card terminal, a back-office PC, a pop-up key and a fit-out crew. We issue each a key, place it on the unit's VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.