- Community Home
- >
- HPE Networking
- >
- Networking
- >
- Simplify IoT Authentication with Multiple Pre-Shar...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Receive email notifications
- Printer Friendly Page
- Report Inappropriate Content
Simplify IoT Authentication with Multiple Pre-Shared Key (MPSK)
Network administrators are dealing with an explosion of IoT devices from surveillance cameras and environmental sensors to medical devices to smart shelves. For those IoT devices that support 802.1X authentication, the path for joining the network in a secure manner is clear: Use a secure, device-bound credential. This allows clients to securely authenticate and join the network using a strong user and/or device identity.
Figure 1. Traditional deployment with WPA-PSK.
However, many IoT devices are โheadlessโ and are unable to support network security functionality like 802.1X. When dealing with headless IoT devices, the story is clearly different. The most commonly used method of authentication is WPA2-PSK. Although using WPA2-PSK is far more secure than using open or WEP, it is still exposing the network to security vulnerabilities.
WPA2-PSK has several limitations:
- The WPA2-PSK passphrase is shared among all devices associating with the same SSID. If the key is compromised, security breaches are sure to follow.
- The operational aspect of replacing the key is manual and laborious for IT.
- Overcoming the single WPA-PSK passphrase problem with multiple SSID results in inefficient RF utilization.
MSPK is a Better Solution for IoT
Multi Pre-Shared Key (MPSK) is a better option. Aruba ClearPass 6.8 and Aruba OS 8.4 take advantage of new standards such as WPA3 and Opportunistic Wireless Encryption to overcome the pre-shared key problem.
Specifically, MPSK enables device-specific and group-specific passphrases, which enhances security and deployment flexibility for headless IoT devices. Passphrases can be administratively assigned to groups of devices based on common attributes like profiling data or uniquely assigned to each device registration with ClearPass Policy Manager.
Now, multiple pre-shared keys can be supported on the same SSID. Using a single SSID also improves the RF bandwidth utilization, delivering a better user experience. Using MPSK reduces the time and effort for the IT department to secure the network. And providing multiple PSKs across different platform types ensures better security.
MPSK has several benefits. First, because it establishes a one-to-one associated relationship between devices (i.e. the MAC address) and a specific user, it provides visibility, accountability and management for a single user. In Aruba, this is enabled through ClearPass self-service device registration.
Secondly, MPSK can be used to associate a device with a group of users, for example, a smart TV thatโs used by the marketing team. This is enabled through enforcement policy by the ClearPass administrator.
Figure 2 Arubaโs Multi Pre-Shared Key deployment model.
MPSK does not replace secure authentication methods like EAP-TLS for traditional mobile devices like laptops, tablets and smartphones. However, MPSK provides a far better way to ensure that IoT devices are authenticated and legitimately connected to the network, without any IT involvement.
Related Content
See what else is new in ClearPass 6.8.
- Back to Blog
- Newer Article
- Older Article
-
AI-Powered
23 -
AI-Powered Networking
20 -
Analytics and Assurance
4 -
Aruba Unplugged
7 -
Cloud
9 -
Corporate
3 -
customer stories
4 -
Data Center
20 -
data center networks
19 -
digital workplace
2 -
Edge
4 -
Enterprise Campus
9 -
Events
5 -
Government
10 -
Healthcare
2 -
Higher Education
2 -
Hospitality
4 -
Industries
1 -
IoT
8 -
Large Public Venue
1 -
Location Services
3 -
Manufacturing
1 -
midsize business
1 -
mobility
17 -
Network as a Service (NaaS)
12 -
Partner Views
4 -
Primary Education
1 -
Retail
1 -
SASE
21 -
SD-WAN
12 -
Security
97 -
small business
1 -
Solutions
7 -
Technical
5 -
Uncategorized
1 -
Wired Wireless WAN
86 -
women in technology
2
- « Previous
- Next »