Devices with no screen: a personal WiFi key each, bound to the device and placed on its VLAN
A printer, a sensor or a door controller cannot complete a captive portal or hold a certificate. xPSK (iPSK, PPSK, DPSK, MPSK) gives each one its own WPA2-Personal key, bound by MAC and placed on a device VLAN, so a leaked key exposes one device and not the building. Everything that can do better stays on the secure and open networks.
- 80,000+ venues in 90 countries
- 99.9% RADIUS uptime SLA
- 8 to 10 SSIDs use 15 to 25% of channel airtime
The problem
A shared password on a printer is the weakest credential in the building
Headless devices are the part of the estate that cannot do better than a passphrase, so what matters is whose passphrase it is and how far it travels.
- One passphrase is typed into every printer, sensor and controller, so a single leaked or photographed key exposes every device on it.
- These devices run for years. The key never changes, because changing it means a visit to each device.
- The usual fix is an SSID per device class, and it costs airtime: 8 to 10 SSIDs use 15 to 25% of channel airtime.
- There is no supplicant to run 802.1X and no portal to click through, so the usual controls have nothing to attach to.
- The log cannot say which device a connection was, because every device presented the same key.
How it works
Issue, bind, place, rotate or revoke: one device at a time
The device does nothing new. Every control lives on the access point and RADIUS side.
Create the key outside the device
A key comes from the console, a bulk import of a device list or the Purple API, and is typed into the device's WiFi settings once, like any WPA2-Personal passphrase. The device needs no agent, no supplicant and no portal.
Bind to the MAC, place on a device VLAN
MAC binding ties the key to the device, so a copied key does not work on another one. RADIUS returns a VLAN or role for the device class with a bandwidth limit, and your access points enforce it. What may talk to what is a rule on your gateway or firewall.
Operate by class, not by exception
Every authentication is logged with the key, device, VLAN and outcome, so a failing sensor is a log search and a rogue device is a Reject with a reason. The log streams to Microsoft Sentinel, Splunk, Elastic or Datadog.
Rotate or revoke one device
Rotate a key at the device's next service visit, or revoke it when the device is replaced. Withdrawing one key drops one device, with RADIUS CoA ending the live session on access points that support it.
Open, secure or xPSK
Which of the three networks, for which kind of device and person
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Staff phones with no MDM | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the staff group's VLAN | Ends with the directory account |
| Visitors and contractors' phones | Open | Captive portal sign-in, consent recorded | A guest VLAN with client isolation on | Session and consent recorded at sign-in |
| Managed tablets, handhelds and laptops that can hold a certificate | Secure | EAP-TLS, certificate from your MDM over SCEP (certificates stay the default) | VLAN by directory group or device role | Certificate delivered and renewed by your MDM |
| Printers, screens and displays | xPSK | Individual key, MAC-bound | A device VLAN per class, apart from people | One key per device, rotated or revoked alone |
| Sensors, door controllers and CCTV | xPSK | Individual key, MAC-bound | A building-systems VLAN, with its own bandwidth limit | Revoked with the device when it is replaced |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
What it covers
What you can do with it
A VLAN per device class
Printers, signage, CCTV, building controls and payment terminals each land on the VLAN for their class, so what a camera can reach is decided once per class and not once per device.A bandwidth limit per key
A limit per key stops one chatty device or a firmware loop from taking the uplink. It is a cap, not a guarantee.Voice assistants on keys, not SSIDs
A voice assistant in every room is a key per device on the xPSK SSID, which avoids an extra network for each one and the airtime that goes with it.Bulk issue for a refit
Import a device list and each entry gets a key with its own end date and VLAN, so replacing every device on a floor is a batch job.
Where it matters
The industries that run into this most
Smart buildings and IoT
One leaked shared password exposes every device on it. A key and VLAN per device means one leak opens one device.Hospitals and healthcare
Infusion pumps and telemetry cannot hold a certificate, so each gets a MAC-bound key and a locked-down VLAN.Warehouses and logistics
Scanners, robots and vehicle terminals on device keys, with no certificates to renew across a fleet.Retail chains
Card terminals, scanners and signage isolated by device type, from one key and VLAN template per store.Hotels
Room TVs, thermostats and minibars on a device VLAN that guests never reach.Senior living
Nurse call, fall detection and wander alarms on their own keys, apart from residents' streaming.
Proof
The platform under the devices
80,000+ venues in 90 countries run on Purple, with a 99.9% cloud RADIUS SLA in the contract.
- 80,000+
- venues run on Purple, in 90 countries
- 99.9%
- cloud RADIUS uptime SLA, in your contract
- 500M
- logins a year
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Why not certificates for everything?
Certificates stay the default for every device that can hold one: staff laptops and phones on EAP-TLS, delivered by your MDM over SCEP. xPSK is for everything that cannot, such as devices with no 802.1X supplicant, no screen or no certificate store.
What does the device see?
An ordinary WPA2-Personal passphrase, so nothing on the device changes. The per-device key lives on the access point side, such as Cisco iPSK on Meraki or HPE Aruba MPSK, and Purple runs each vendor's version on one mixed estate.
What happens if one device key leaks?
One device is exposed and not the estate. The key is bound to that device by MAC, lands only on its class VLAN and can be revoked alone, with the live session ended by RADIUS CoA on access points that support it.
Why not an SSID per device class?
Each SSID adds beacons and management traffic: 8 to 10 SSIDs use 15 to 25% of channel airtime. One xPSK SSID carries every class, each on its own VLAN, with no per-SSID key ceiling.
How do keys rotate on devices nobody visits?
Set an end date at issue and rotate at the device's service interval. Revoking one key never touches another device, so rotation is scheduled per device and never an estate-wide event.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Book a demo: we issue and revoke a key on a live network
Bring the list of what is plugged in at a typical site, including the devices nobody wants to talk about. We bind one to a key, place it on its VLAN and revoke it live.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.