Website Maintenance Announcement – September 19–21
Activities begin at 6:00 PM CT on Friday, September 19 and continue through Sunday, September 21.
During this time, Product functionality will be unavailable
Website Maintenance Announcement – September 19–21
Activities begin at 6:00 PM CT on Friday, September 19 and continue through Sunday, September 21.
During this time, Product functionality will be unavailable
Multi-dwelling unit (MDU) owners and managers must meet the growing demands of the market. This requires the best product from Internet Service Providers (ISPs), Managed Service Providers (MSPs), and vendors to succeed and win competitive bids. This article explains how RUCKUS One®, utilizing RUCKUS DPSK3 and RUCKUS AI, stands out as the all-in-one network solution for MDU environments.
Internet connectivity through Wi-Fi has become the "fourth utility." Reliable internet access is now as essential to daily life as traditional utilities like electricity, water, and gas. This is perhaps the main reason why Real Estate Developers have chosen the pre-installed nature of "Managed Wi-Fi solutions" using Network Segmentation over the conventional physical residential gateway per unit, where each resident or tenant must wait for the next available truck roll, which can sometimes take weeks. People today want and expect reliable, high-performance Internet connectivity ready on Day One.
Managed Wi-Fi in a multi-dwelling units (MDU) property typically involves a Managed Service Provider (MSP) overseeing the deployment and operation of Wi-Fi services, with costs included in the association fees paid by unit owners or tenants' rent. The provider strategically plans and installs access points for optimal coverage, based on a comprehensive professional design, reducing interference and ensuring consistent Wi-Fi access throughout the complex. This reliable infrastructure not only attracts and retains tenants but also supports 'Smart Home' solutions and enhances facility management efficiencies, offering tangible business benefits.
Managed Wi-Fi solutions often leverage network segmentation to enhance security, performance, and management efficiency.
Network segmentation entails breaking down a network into smaller subnetworks, effectively isolating users' end devices from each other to improve IT security and user experience. Devices are placed into separate virtual networks, preventing threats to enter the network from moving laterally across segments to other devices. This approach is particularly effective for MDU, such as apartment buildings, college dormitories, senior living facilities, or anywhere residents live communally. The cornerstone of Wi-Fi network segmentation is per-user/per-device PSKs.
Per-user/per-device PSKs (Pre-Shared Keys) are proprietary PSKs solutions, designed to address the vulnerabilities associated with traditional PSK authentication, particularly in environments like MDU. The primary concern with using a single PSK for all devices on a WLAN is the vulnerability to social engineering. If the PSK is shared, whether inadvertently or deliberately, with unauthorized individuals, it jeopardizes the security of the entire WLAN.
Per-user/per-device PSKs offer a solution by assigning a unique PSK to each device or user. This means that each device uses its own unique PSK for connecting to the WLAN, and the MAC address or multiple MAC addresses (due to MAC randomization) of each device are mapped to a unique personal passphrase. These individual PSKs can be created dynamically or manually and are tied to a single SSID. This approach provides unique identity credentials for each device while keeping the simplicity of using a single SSID, enhancing security by isolating each device's access credentials.
Dynamic PSK is a CommScope-patented technology that enhances network security by providing unique encryption keys for each user or device connecting to the RUCKUS network. Users can obtain their unique Wi-Fi passwords either through self-service or from an IT administrator, making the connection process intuitive and like home network setups. Unlike conventional PSKs, the Dynamic PSK solution allows administrators to define access policies and revoke access for individual users without affecting others. Wireless traffic is encrypted using WPA2™-Personal or WPA3™-SAE, optimizing a robust network and data security. The Dynamic PSK solution is a key part for RUCKUS Network Segmentation.
When the 6 GHz band was opened for unlicensed use in April 2020, the Wi-Fi Alliance mandated Wi-Fi Protected Access® 3 (WPA3) and Opportunistic Wireless Encryption (OWE) as the standards for Wi-Fi security for all Wi-Fi 6E devices and any future devices using the greenfield 6 GHz band. This posed a challenge for per-user, per-device PSKs implementations, as WPA3-SAE inherently prevents the use of multiple keys, eliminating the possibility of reverse-engineering the passphrase used in traditional Dynamic PSK and other vendor solutions.
However, there's no need to be disheartened. Initially, there was no per-user per-device PSK solution for 6 GHz (WPA3-SAE mandatory), but in early 2023, RUCKUS introduced a groundbreaking innovation. The magic unfolds as the "RUCKUS Team" turns the impossible dream into reality with per-user, per-device PSKs on the 6 GHz band. After rigorous testing by the Development and Quality Assurance Teams, RUCKUS released the patented "Dynamic SAE (DSAE) or DPSK3." This innovation made per-user, per-device PSKs possible in the 6 GHz band using WPA3-SAE, positioning RUCKUS as the first vendor in the industry to offer a multiple password solution on the new 6 GHz band without RADIUS (Remote Authentication Dial-In User Service). RUCKUS DPSK3 extends the successful Dynamic PSK technology to support WPA3, delivering all the benefits of the Dynamic PSK solution while keeping robust WPA3 security.
The purpose of this POC Lab was to deliver a "Single Pane of Glass" Managed Wi-Fi Solution on 6 GHz to a long-standing ISP/MDU Partner. This partner successfully implemented Network Segmentation using the RUCKUS Dynamic PSK solution across multiple properties, including MDUs, hotels, and university environments. However, as mentioned, with the introduction of 6 GHz and the requirement for WPA3, the Dynamic PSK solution was challenged, but the RUCKUS Team embraced this challenge and developed the DPSK3 solution.
Now, the partner’s requirements were not just about network security, they also needed an affordable and easy to deploy solution. Typically, with most vendors, achieving all three is difficult, often resulting in a compromise of one or two of the three. To provide a Wi-Fi network that is both reasonably secure and easy to deploy, customers often need to invest in expensive advanced gateways and/or costly RADIUS servers, increasing CapEx and reducing competitiveness. Alternatively, opting for a cheaper solution typically compromises security and performance. However, the RUCKUS solution offers partners all three benefits: security, affordability, and ease of deployment, along with RUCKUS's unmatched RF performance. Configuration can be automated using the template capabilities built into the RUCKUS One solution, facilitating "cookie-cutter" future deployments.
In addition to the above requirements, the partner, being an ISP, needed different Bandwidth Service Tier levels per user, such as:
The RUCKUS Engineering and Development Team returned to the drawing board and undertook significant coding efforts to provide the Partner with the requested Rate Limiting option. At that point, the RUCKUS One solution became the single, cloud-based platform to manage all network components across all properties; enabling the partner to monitor, configure, and optimize networks remotely using the following features:
The RUCKUS One solution provides a single, unified platform for managing both wired and wireless networks, with automation tools for configuration, updates, and monitoring to enhance efficiency and reduce manual workload.
The platform leverages Artificial Intelligence (AI) and Machine Learning (ML) for real-time network analytics, predictive maintenance, and robust security features, including intrusion detection and automated updates, to proactively manage and secure network performance.
Designed to scale with organizational growth, the RUCKUS One solution supports remote monitoring and management, allowing for efficient network optimization and bandwidth management across all properties.
The animation below illustrates the customer's mobile phone in UNIT 104, initially connected on 6 GHz within their unit, roaming to different APs and bands, eventually reaching the pool area and going back to 6 GHz. Throughout this process, the device remains connected to its own private VLAN704. (Note: Hopefully, the phone is indeed water-resistant—just a lighthearted remark!)
Enables the creation of an unlimited number of units for the MDU. For example, the system can accommodate a property with 500 units/ identities.
The RUCKUS Resident Portal feature provides a user-friendly interface for managing network access in MDU. It allows property managers to create and manage multiple units, offering residents seamless connectivity and secure access to the network. The portal supports self-service options for residents to obtain, change/reset unique Wi-Fi credentials and control devices connected to their private network.
Rate Limiting based on RADIUS Attributes for the different Tiers Services (Bulk: 100x100, Silver 500x500, Gold:1000x1000).
NOC, Engineering and others
Facilitates cell phone calling in areas with low or no cellular signal.
This feature was a requirement from the MDU developers, enabling their users to automatically connect to Wi-Fi across multiple properties and roam seamlessly through OpenRoaming™.
RUCKUS DPSK3, when deployed within the RUCKUS One solution, emerges as the most versatile and comprehensive solution for MDU environments. It provides a single platform that fulfills all the requirements a Managed Service Provider (MSP) needs to offer a Managed Wi-Fi Solution on all bands, including 6 GHz. All the features discussed in this publication are integrated into the RUCKUS One solution, serving as a single pane of glass to monitor, manage, and control Access Points, Switches, RUCKUS Edge™, Property Units, Residential Portals, and Policies for Rate Limiting, Service Scheduling, and more. Additionally, it offers RUCKUS AI RRM, Analytics, and Reports, with upcoming support for features like PON (Passive Optical Networks) management and IoT integration.
© 2025 CommScope, LLC. All rights reserved. CommScope and the CommScope logo are registered trademarks of CommScope and/or its affiliates in the U.S. and other countries. For additional trademark information see https://www.commscope.com/trademarks. Wi-Fi, Wi-Fi 6E, WPA2, WPA3 and Wi-Fi Protected Access are trademarks of the Wi-Fi Alliance. OpenRoaming is a trademark of the Wireless Broadband Alliance. All product names, trademarks and registered trademarks are property of their respective owners.
Sign up for exclusive insights from RUCKUS Networks.