Aerohive Networks - Aerohive unleashes the potential of enterprise Wi-FiAuthentication with Private Pre-Shared Key

Technology Behind the Solution

Aerohive's patent-pending Private PSK provides the ease of PSK with many of the advantages of 802.1X solutions. The IT manager can provide unique passphrases to each user on a single SSID, which creates a one-to-one relationship between the key and user instead of the one-to-many paradigm of classic PSK, thus providing the ability to truly authenticate each individual. This enables 802.1X-like capabilities even though it appears like only a PSK is required on the laptop or Wi-Fi device. While classic PSK does not allow the revocation of a single user's credentials since all users share the same passphrase, Private PSK offers a unique PSK per individual and therefore enables the administrator to revoke a single set of credentials. Furthermore, since Private PSK, like 802.1X, allows a means to identify individual users on a single SSID, each can be granted different user profiles. This allows all users to connect to the same network, but get unique levels of service based on their roles.

Authentication with Private Pre-Shared Key Diagram

Benefits

Wireless LAN Requirement & Features PSK - WPA/WPA2 Personal Private PSK - WPA/WPA2 Personal IEEE802.1X - WPA/WPA2 Enterprise
No complex configuration required for clients Yes Yes No
Unique Keys Per User on Single SSID No Yes Yes
Can revoke an individual user's key or credentials when they leave the company or their wireless device is compromised, lost or stolen No Yes Yes
Supports different VLAN, QoS, Firewall or Tunnel policy for different users on same SSID No Yes Yes
Does not require certificates to be installed on clients Yes Yes No
Uses 802.11i standard mechanisms for securing the SSID Yes Yes Depends on Client
Keys are dynamically created for users upon login to the network and are rotated frequently No No Yes
Can be used to perform machine authentication No No Yes
If one user is compromised, no other users keys can be compromised No Yes Yes