Skip to content
Network 3: xPSK

xPSK (PPSK, iPSK, DPSK), the Swiss Army knife network

One SSID, a unique key per device, person or tenant, on Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Each key gets its own VLAN, policy and bandwidth limit, and you revoke one without touching the rest. Certificates are the default. xPSK is for everything that cannot hold one.

  • No per-SSID key ceiling
  • Six vendors, one model
  • ~1 million residents on Purple
  • Five-year Murray State deal
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Four jobs, one SSID

  • Things

    Printers, screens, tills, CCTV, sensors and door controllers, each on its own key.
  • Communities

    A private network per resident in MDU, student accommodation, elderly care and build to rent.
  • Concessions

    Each tenant in a mall, airport or venue on its own key and VLAN, live at Vancouver International and Kinetic Melbourne Airport.
  • Contractors

    Time-limited keys with no MDM, from a branded self-service portal or the Purple API.

Per-key control

Every key is its own network

  • Own VLAN, policy and bandwidth limitSet per key, returned by RADIUS at authentication.
  • MAC bindingStops a key becoming a second shared password.
  • No per-SSID key ceilingAdd keys as the estate grows, on the same SSID.
  • Revoke one, keep the restWithdraw a single key and nobody else notices.
Illustration

Add-on: Purple Shield

Make this network safer and faster with Purple Shield

Purple Shield bolts onto Access or runs standalone. Set a different DNS policy per VLAN and by time of day, so staff, guests and residents each get the filtering that fits them, with dashboard analytics. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Common questions

Isn't PSK insecure?

A shared PSK is. A unique key per device, bound to an identity and a VLAN and revocable on its own, is not. Certificates stay the default.

Is xPSK the same as PPSK or iPSK?

Yes. xPSK is our name for the capability every vendor ships under its own name, and Purple runs all of them: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK.

Who runs xPSK on Purple?

Murray State University signed a five-year deal for Purple PSK WiFi, the University of New Brunswick runs iPSK on Purple, and about 1 million students and residents live on Purple community networks. Malls, Vancouver International Airport and Kinetic Melbourne Airport put their concessions on their own keys.

How are xPSK keys issued, rotated and revoked?

Every key is unique to one device, resident or tenant, bound to its own VLAN and policy, and MAC binding ties it to its device, so a key cannot become a second shared password. Issue keys from the console, a branded self-service portal or the Purple API. Rotate or revoke one key and every other device stays connected.

Give every device its own key

Bring the list of what is on your network today, including the devices nobody wants to talk about. We map every one to its own key. All in a 45-minute design session.

  1. Get your three-SSID plan in 45 minutesTell us what runs on your WiFi today, and a Purple network engineer maps it with you.
  2. Map your SSIDs onto threeOpen, secure and xPSK, on the access points you already own. You leave with the plan.
  3. Prove it on one site firstJudge the result on tickets and audit evidence, then roll out.

Your design session

45 minutes. Your estate. A plan you keep.

Led by a Purple network engineer. No slides. You keep the plan.