Private networks for every resident: one personal WiFi key, one household, one building network
Casting and smart speakers break on shared or guest-style WiFi, because discovery traffic is blocked between clients or visible to everyone. With a personal WiFi key per household on one xPSK SSID (iPSK, PPSK, DPSK, MPSK), a household's devices find each other and no neighbor's appear.
- ~1 million residents on Purple
- 60% fewer helpdesk tickets at move-in
- University of New Brunswick on iPSK
The problem
Casting needs discovery, and shared WiFi gives you the wrong kind
AirPlay and Chromecast find a TV with multicast discovery. Client isolation blocks it, and no isolation shows every household's devices to every other.
- Client isolation, the right setting for a guest network, stops a resident's phone from finding their own TV.
- Turning isolation off puts every household's speakers and TVs in each other's cast lists.
- An SSID per household would fix discovery and costs airtime: 8 to 10 SSIDs use 15 to 25% of channel airtime.
- Residents fall back on their own routers and extenders, which add interference to the building's radios.
How it works
A household is a segment: key, VLAN or role, and discovery inside it
The building keeps one set of access points and one SSID. The household's boundary is drawn by the key.
Issue a key per household
Create the household's key from the console, a bulk import or the Purple API, and hand it to the resident in the Purple app or a branded self-service portal. Each additional device gets its own key under the same household.
Place the household on its own segment
RADIUS returns the household's VLAN or role with its own bandwidth limit, and mDNS reflection keeps AirPlay and Chromecast discovery inside that segment. Your gateway decides what, if anything, crosses between households.
Support from one log
Every accept and reject is logged with the key, device, VLAN and reason, so "my speaker will not join" is a search on the household and not a visit.
Revoke the household at move-out
Withdraw the household's keys and RADIUS CoA ends their live sessions on access points that support it. Every other household stays connected.
Open, secure or xPSK
Which of the three networks, for which party in a building
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Prospects, visitors and event guests | Open | Captive portal sign-in, consent recorded | A guest VLAN with client isolation on | Session and consent recorded at sign-in |
| On-site team and maintenance staff | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled in the directory ends access |
| Residents' phones, TVs and speakers | xPSK | Individual key, MAC-bound | A VLAN or role per household, discovery kept inside it | Issued at move-in, revoked at move-out |
| Locks, thermostats and leak sensors | xPSK | Individual key, MAC-bound | A building-systems VLAN, apart from every household | One key per device, revoked alone |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
What it covers
What you can do with it
Casting that works in the household
mDNS reflection keeps AirPlay and Chromecast inside a household's own segment.Neighbors never appear
Another household's TV is not in the cast list, because it is not on the segment.No router per flat
Residents stay on the building's access points, so the estate is not carpeted in personal routers.
Where it matters
The industries that run into this most
Build to rent
One SSID per building and one key per household, each returning its own segment.Multifamily and apartments
Bulk internet delivered per unit across a mixed access point estate: the unit is a segment, not a router.Student accommodation
Students' own devices find each other inside their segment while eduroam keeps doing identity.Co-living
A private segment per member for the length of the stay, with shared rooms on their own VLAN.Serviced apartments and long stay
A guest's own devices work for the length of the booking, then the key ends.
Proof
Resident networks at scale
About 1 million students and residents run on Purple community networks, and the University of New Brunswick runs iPSK on Purple.
- ~1M
- students and residents on Purple community networks
- 60%
- fewer helpdesk tickets at move-in, US university housing across 40 buildings
- iPSK
- University of New Brunswick runs iPSK on Purple
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Why does casting break on shared WiFi?
Casting finds the receiver with multicast discovery. Client isolation blocks it between clients, and without isolation every household sees every other. A segment per household gives discovery a boundary that matches the home.
Is xPSK one SSID or one per household, tenant or device?
One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.
What does mDNS reflection do here?
It carries discovery traffic between devices that sit on the same household segment, so AirPlay and Chromecast work inside it. It does not carry discovery between households.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your buildings already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Book a demo: we issue and revoke a key on a live network
Bring a floor plan and the devices residents bring. We key one household, cast to a TV and revoke it live, on the access points you already own.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.