Give every user their own private network bubble
One login places every device a user owns - phone, laptop, console, smart TV - inside a secure Private Area Network that follows them around the venue, invisible to everyone else. Built on Purple's Identity-Based Networks.

Trusted by leading brands worldwide















What is a Private Area Network (PAN)?
A Private Area Network is a secure, private bubble created around each user on a shared WiFi network. In multi-tenant environments like student accommodation, hotels, or care homes, the user logs in once and all their devices are placed inside their own bubble: the devices can find and talk to each other, but remain invisible to every other user. Purple creates PANs through Identity-Based Networks, with iPSK for devices that cannot sign in through a browser.
TL;DR / Key Takeaways
- A Private Area Network (PAN) gives every user their own secure network bubble on shared WiFi: their devices can find each other, and nobody else's can.
- Each user sits in their own micro-segment, so the resident in Room 101 can never see the devices of the resident in Room 102.
- Smart TVs and game consoles join the bubble with a unique iPSK, without weakening the 802.1X network architecture.
- Onboarding and offboarding sync to a live directory automatically, removing shared passwords and manual credential management.

One secure bubble per user, on one shared network
Purple creates a personal Private Area Network for each user. They log in once, and all their devices are placed inside a secure, private bubble that follows them around the venue.
- Micro-segmentation isolates every user: the resident in Room 101 can never see the devices in Room 102
- The bubble follows the user across the building and between sites
- mDNS reflection keeps casting and AirPlay working inside the bubble, and only inside it

One login covers every device they own
Identity decides access, not a network-wide passphrase. Phones and laptops sign in once; everything else joins with a key that belongs to that user alone.
- Unique PSK (Pre-Shared Key) for smart TVs and game consoles: no browser needed
- Revoke one user's key without affecting anyone else on the network
- The 802.1X and WPA3-Enterprise architecture stays intact throughout

Simple for residents, automatic for IT
Onboarding and offboarding sync to a live directory, so access is granted and revoked automatically, even when hundreds of residents move in at once.
- Joiners, movers, and leavers handled without manual credential management
- Residents of every age and ability connect once and it works like home WiFi
- Up to an 80% reduction in IT helpdesk requests once shared passwords go
Shared-password WiFi vs Private Area Networks
| Capability | Shared-password WiFi | Private Area Networks |
|---|---|---|
| Device isolation | Every device can see every other device on the network | Each user's devices live in their own isolated bubble |
| Revoking access | Rotate the passphrase for everyone | Revoke one user's key with no impact on anyone else |
| Smart TVs and consoles | Join the same flat network as every other device | Join the user's own bubble with a unique iPSK |
| Onboarding and offboarding | Manual credential management | Automatic, synced to a live directory |
| Casting and discovery | AirPlay finds every TV in the building | mDNS reflection keeps discovery inside the bubble |
| Audit trail | One anonymous shared credential | Every connection tied to a named identity |
Private Area Network FAQs
What is a Private Area Network (PAN)?
A Private Area Network is a secure, private bubble created around each user on a shared WiFi network. In multi-tenant environments like student accommodation, hotels, or care homes, the user logs in once and all their devices are placed inside their own bubble: the devices can find and talk to each other, but remain invisible to every other user. Purple creates PANs through Identity-Based Networks, with iPSK for devices that cannot sign in through a browser.
How is a Private Area Network different from a VLAN per room?
A VLAN-per-room design is static: it has to be pre-provisioned, it is tied to a place rather than a person, and it does not follow the user. A Private Area Network is created dynamically per user at login, applies wherever they connect in the venue, and runs on a single SSID.
Is this the same as a personal area network like Bluetooth?
No. In networking textbooks, a personal area network describes short-range links between nearby devices, such as Bluetooth. Purple's Private Area Network is enterprise WiFi segmentation: each user gets an isolated bubble on shared venue infrastructure, enforced by the network rather than by radio range.
What is iPSK and how does it relate to PANs?
iPSK (Identity Pre-Shared Key) gives each user or device its own unique pre-shared key on a single SSID. It is how browserless devices like smart TVs and game consoles join a user's Private Area Network without weakening the WPA3-Enterprise architecture.
What is the difference between iPSK and PPSK?
They deliver the same thing under different vendor names. iPSK (Identity Pre-Shared Key) is the term most associated with Cisco; PPSK (Private Pre-Shared Key) is the Aruba term. Both provide per-user or per-device unique pre-shared keys, and both can underpin Private Area Networks.
Does this work on our existing hardware?
Yes. Purple is hardware agnostic and layers on top of your existing infrastructure, including Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme, and Fortinet. No rip and replace required.
Can users cast to their own TV without seeing their neighbour's?
Yes. mDNS reflection scopes device discovery to each user's bubble, so AirPlay, Chromecast, and screen sharing find the user's own devices and nothing outside the bubble.
What happens when a resident moves out?
Access is synced to a live directory, so joiners, movers, and leavers are handled automatically. When a resident moves out, their key is revoked and their devices drop off the network, with no effect on any other user.
How secure and compliant is a Private Area Network?
PANs preserve the 802.1X and WPA3-Enterprise architecture rather than replacing it with shared passwords. Purple is ISO 27001 certified, Cyber Essentials Plus accredited, GDPR and CCPA compliant, and has had zero data breaches since 2012.
Last reviewed:
Private Area Networks for your industry
See how Private Area Networks works in venues like yours, and how Purple compares to alternatives.
See a Private Area Network built live
We'll walk you through how the private network bubbles are created, show you the resident's simple onboarding experience, and outline the steps for a multi-site deployment.