What is iPSK?
Definition
iPSK, the identity pre-shared key, gives each user or device its own WiFi passphrase while everyone connects to the same SSID. IT can revoke a single device without changing a network-wide password. Vendors use different names for it, including PPSK, DPSK and MPSK, but the mechanism is the same.
iPSK explained
A standard WPA2-Personal network has one password for everyone. With iPSK, the network holds many keys. When a device connects, the Wireless LAN Controller or RADIUS server identifies which key it used, and therefore who it belongs to, and applies that user’s policy, such as a specific VLAN. The device sees an ordinary password network.
That makes iPSK the practical middle ground between shared PSK and full 802.1X. It works with devices that cannot do enterprise authentication, including smart TVs, games consoles, printers and IoT sensors. That is why it is standard in build-to-rent, student accommodation and other multi-dwelling units, where each resident needs a private network bubble with their own devices visible only to them.
Naming varies by vendor: iPSK on Cisco, PPSK on HPE Aruba, DPSK on Ruckus, and Personal Private Network on Cisco Meraki. Per-device keys can also cut the number of SSIDs a venue broadcasts, which recovers airtime. MAC randomisation is the main thing to plan for, because some implementations tie a key to a device’s MAC address.
Guides on iPSK
- Technical guideiPSK explained: identity pre-shared keys for WiFi access
- Technical guidePPSK WiFi: comparing features and deployment models
- Technical guideHow to deploy iPSK on Cisco Meraki, HPE Aruba and Ruckus
Where it fits
- Pillar guideMulti-tenant WiFi guide
- Purple productPer-device keys (xPSK)
- Free tooliPSK subnet designer
Related terms
Need more than a definition?
Talk to our team about how Purple combines guest WiFi, captive portals, RADIUS, and analytics into a single platform that runs on the access points you already own.