Glossary

Glossary:
Master the language of
enterprise wireless networking

#

802.1X

A port-based network access control standard that authenticates each device before granting network access — the basis of WPA2/WPA3-Enterprise.

A

AAA (Authentication, Authorization, and Accounting)

AAA framework for intelligently controlling access to computer resources, enforcing policies, and auditing usage. In Cloud NAC, it ensures only authorized users connect and their access is logged.

Access Point (AP)

A hardware device that allows WiFi-compatible devices to connect to a wired network. In enterprise environments, multiple APs work together to provide seamless roaming. Cloud4Wi is hardware-independent across AP vendors.

AI Engine

A core software component that uses machine-learning algorithms to analyze large datasets, identify patterns, and optimize network performance.

AI Networking

The application of artificial intelligence to manage and optimize wireless networks. It allows for "self-healing" networks that can automatically adjust to interference or high-density traffic to ensure a seamless guest experience.

API (Application Programming Interface)

A set of rules that lets Cloud4Wi exchange data with other software, such as Salesforce or HubSpot, so WiFi data flows into your workflows.

B

Band Steering

A technology used in dual-band Access Points that encourages dual-band-capable clients (like modern smartphones) to connect to the faster, less congested 5GHz band instead of the 2.4GHz band.

Bandwidth

The maximum capacity of a network link to transmit data over a specific connection in a given amount of time. Cloud4Wi allows businesses to set bandwidth limits per user to ensure a fair and high-quality experience for everyone.

BYOD (Bring Your Own Device)

A policy allowing employees or guests to use personal devices on the network. Cloud4Wi simplifies BYOD with secure, automated onboarding — no MDM required.

C

Captive Portal

The (often branded) web page users see when first connecting to a WiFi network — the primary tool for collecting marketing opt-ins, presenting terms, or offering login options.

Captive Portal Detection

The client-side mechanism (built into iOS, Android, Windows) that automatically detects a captive portal and opens the sign-in page.

Captive Portal vs Splash Page

A captive portal is the whole system that intercepts a device and enforces sign-on before granting WiFi access; a splash page is the branded screen the user actually sees on that portal. Every splash page is part of a captive portal, but the portal includes much more.

CCPA (California Consumer Privacy Act)

 A California statute enhancing privacy rights and consumer protection. Like GDPR, it requires transparency about data collected via WiFi.

Change of Authorization (CoA)

Change of Authorization (CoA) is a RADIUS extension defined in RFC 5176 that lets a server change or end an active session without making the user reconnect. It is used to push new access policy, quarantine a device, or disconnect a session in real time.

Cloud Management

The ability to configure, monitor, and manage your WiFi network and user data from a centralized online dashboard rather than having to manage each piece of hardware locally.

Cloud NAC

A right-sized, cloud-delivered Network Access Control approach that provides identity-based WiFi access for employees, contractors, and visitors — with no RADIUS server, no MDM, and no enterprise NAC project.

Cloud-native Security

A security architecture designed specifically for the cloud environment. It moves away from traditional hardware-based firewalls, offering scalable, real-time protection that updates automatically to defend against evolving cyber threats.

Connectors

Pre-built integrations that link a WiFi platform directly to external software (like Salesforce, Mailchimp, or Adobe), automating the flow of guest data into business tools without custom code.

D

Data Compliance

Adherence to legal frameworks (such as GDPR or CCPA) governing how personal data collected via WiFi is stored and processed.

DHCP (Dynamic Host Configuration Protocol)

A network management protocol used to dynamically assign an IP Address to any new device that connects to the network. In guest WiFi environments, a robust DHCP server is essential to handle the constant flow of users joining and leaving the network.

Dwell Time

A key metric in location analytics representing the duration a visitor stays within a specific area. This helps retailers and venue owners understand customer engagement levels.

E

EAP-TLS

Extensible Authentication Protocol–Transport Layer Security: a certificate-based 802.1X method considered the gold standard for enterprise WiFi authentication, as it uses digital certificates instead of passwords.

Enterprise WiFi

A high-performance wireless network for large-scale environments (offices, malls, stadiums), built for hundreds of concurrent users, seamless roaming, and centralized cloud management.

Event Classifier

A technology used to categorize visitor behavior in real-time, such as distinguishing between a "passer-by" (outside the venue) and a "visitor" (inside the venue).

G

GDPR (General Data Protection Regulation)

The EU framework ensuring personal data is collected and processed transparently and with explicit consent.

Guest WiFi

A dedicated wireless network for visitors, isolated from the corporate network for security while providing internet access and engagement opportunities.

H

Hardware Independence

Hardware Independence — Also called "vendor agnostic": a software platform's ability to work across hardware brands (Cisco, Aruba, Meraki, and more) without proprietary equipment. See supported vendors.

Heatmap

A visual representation of data showing where visitors congregate most frequently within a physical space, generated using WiFi signal strength and presence data.

Hotspot 2.0

Hotspot 2.0 is the technical specification, based on IEEE 802.11u, that lets WiFi devices discover and securely join networks automatically. It is the standard behind the Wi-Fi Alliance's Passpoint certification and enables a cellular-like WiFi experience.

I

Identity Provider (IdP)

A system that creates and manages identity information. In enterprise WiFi, an IdP (like Okta, Microsoft Entra ID, or Google) verifies users before granting access. See Cloud NAC.

Indoor Positioning System (IPS)

A network of devices used to locate people or objects inside a building where GPS is ineffective, typically utilizing WiFi or Bluetooth signals.

IP Address

A unique numerical label assigned to each device connected to a computer network. While WiFi platforms use IP addresses for routing, they often rely on other identifiers for marketing and analytics.

IPsec (Internet Protocol Security)

A suite of protocols used to secure internet communication by authenticating and encrypting each IP packet in a data stream. It is commonly used to create secure "tunnels" (VPNs) between a venue's local network and a centralized cloud controller.

iPSK (Identity PSK)

Identity PSK (iPSK) is Cisco's implementation of per-device pre-shared keys on a single SSID. Each key is tied to an identity and authorized through a RADIUS server, bringing unique-key security to devices that cannot run 802.1X.

L

Location Analytics

The process of collecting and analyzing data regarding the physical movement of people within a venue to improve operational efficiency and marketing ROI.

M

MAC Address

A unique identifier assigned to a network interface. Because modern devices use MAC randomization for privacy, passive MAC-based tracking is unreliable; Cloud4Wi uses consent-based, authenticated connections for accurate visitor recognition instead.

MAC Authentication Bypass (MAB)

MAC Authentication Bypass (MAB) is a network access method that authenticates a device by its MAC address when the device cannot run 802.1X. The switch or access point sends the MAC address to a RADIUS server, which checks it against an allowed list and grants or denies access.

MDM (Mobile Device Management)

Mobile Device Management (MDM) is software that configures, secures and monitors an organization's mobile devices from a central console. It can enforce policies, install apps, and push WiFi profiles and certificates, which makes it a key partner to network access control.

MDU (Multi-Dwelling Unit)

A residential building with multiple separate units — apartments, student housing, senior living.

MDU WiFi (Multi-Dwelling Unit WiFi)

MDU WiFi is property-wide managed WiFi for multi-dwelling units such as apartments, student housing, condos and senior living. It gives each resident a private, secure network on shared infrastructure, usually delivered as a managed amenity by the property.

Microsegmentation

A security technique that enables fine-grained security policies to be assigned to individual data center workloads or user groups. In a WiFi context, it allows you to isolate a guest's device not just from the corporate network, but also from other guest devices on the same network.

MPSK (Multi Pre-Shared Key)

Multi Pre-Shared Key (MPSK) is Aruba's method for assigning multiple unique pre-shared keys to a single SSID, each mapped to a role or device. Like PPSK and iPSK, it provides per-device keys and policy without 802.1X supplicants.

N

NAC (Network Access Control)

A security solution that enforces policies on devices attempting to join a network, ensuring only authorized, compliant users connect. See Cloud NAC.

NaaS (Network as a Service)

A cloud-based model for delivering enterprise network services. It allows businesses to operate their entire network without owning or maintaining the physical "box-and-wire" infrastructure, often on a subscription basis.

O

OpenRoaming

OpenRoaming is a Wireless Broadband Alliance federation that lets devices roam automatically and securely between participating WiFi networks using a single trusted identity. It builds on Passpoint and RadSec to remove logins and passwords across thousands of networks.

Opt-in

Opt-in — The process by which a user gives explicit permission for a business to collect their data or send marketing communications.

P

Passpoint

A protocol that lets mobile devices discover and authenticate to WiFi hotspots automatically, for a "cellular-like" experience with no manual network selection or password. See Passpoint.

Personal Area Network (PAN)

A private, isolated network "bubble" for a single user within a shared WiFi environment: their devices can talk to each other (phone and wireless printer) but stay invisible to other users. Cloud4Wi creates a PAN per resident in MDU WiFi.

Policy Management

The process of defining and enforcing rules for network usage. This includes setting bandwidth limits, session durations, and access schedules for different groups (e.g., guests vs. employees).

PPSK (Private Pre-Shared Key)

A method giving each user or device a unique WiFi password on the same SSID, providing per-user security and tracking without a full RADIUS server. See PPSK.

R

RADIUS (Remote Authentication Dial-In User Service)

RADIUS (Remote Authentication Dial-In User Service) is a protocol that centralizes authentication, authorization and accounting (AAA) for network access. It verifies user and device credentials, applies access policy and logs sessions across wired, wireless and VPN connections.

RadSec

RadSec (RADIUS over TLS, defined in RFC 6614) secures RADIUS traffic by carrying it inside an encrypted TCP/TLS tunnel instead of plain UDP. It protects authentication data in transit, adds reliable delivery and makes cloud-hosted RADIUS practical across the public internet.

Real-Time Location Services (RTLS)

A system used to track the immediate location of people or assets within a venue. Unlike historical analytics, RTLS provides "right now" data, enabling use cases like wayfinding or instant staff alerts.

S

SAML (Security Assertion Markup Language)

An open standard for exchanging authentication and authorization data between an Identity Provider (IdP) and a service provider. This is the technology that allows "Single Sign-On" (SSO), enabling users to log into the WiFi using their existing corporate or social credentials.

SOC 2 (Service Organization Control 2)

A rigorous auditing procedure that ensures your service provider securely manages your data to protect the interests of your organization and the privacy of its clients.

Social WiFi

A feature letting guests log in with social-media credentials, simplifying login while providing demographic data.

Splash Page

A simple welcome or landing page shown on WiFi connection, often for branding or terms acceptance, typically without full authentication.

SSID (Service Set Identifier)

An SSID (Service Set Identifier) is the name of a WiFi network — the label devices show when you search for available connections. It can be up to 32 characters, is broadcast by access points, and is how users and devices identify which wireless network to join.

SSO (Single Sign-On)

An authentication scheme that allows a user to log in with a single ID to any of several related, but independent, software systems.

Staff WiFi

A private, secure wireless network reserved exclusively for employees and internal business operations (such as Point-of-Sale systems or inventory scanners). It is typically hidden or encrypted and is kept strictly separate from the Guest WiFi to ensure maximum security and performance for business-critical tasks.

U

User Analytics

The process of analyzing the behavior of specific users or groups on the network. It tracks how often they visit, which areas they frequent, and how they interact with the digital touchpoints of the venue.

User Management

The administrative task of managing user profiles, permissions, and access levels within a WiFi platform or organization.

V

VLAN (Virtual Local Area Network)

A logical sub-group of devices within a larger physical network. Using VLANs allows a venue to keep "Guest WiFi" traffic completely separate from "Staff" or "Point-of-Sale" traffic for better security.

W

Walled Garden

A restricted set of websites or IP addresses a user can reach before fully authenticating through the captive portal.

WBA OpenRoaming

A global standard (Wireless Broadband Alliance) enabling users to roam between WiFi networks automatically and securely with a single trusted identity.

Webhooks

A method for one application to send another real-time information — e.g., triggering a CRM alert the moment a VIP connects.

White Label

A product or service produced by one company that other companies brand as their own. Cloud4Wi's platform can be white-labeled so that the end-user only sees the branding of the venue or service provider.

Wi-Fi 6 / Wi-Fi 7

The latest generations of the WiFi standard (802.11ax / 802.11be), delivering higher speeds, lower latency, and better high-density performance.

WiFi Access

 The ability to connect to the internet or a local network wirelessly.

WiFi Marketing

The practice of using a guest WiFi network to collect data, display targeted advertisements, and send personalized messages to customers during or after their visit.

WiFi Mobile SDK

A set of software development tools that allows developers to embed WiFi-based location services and "one-click" login features directly into a brand’s own mobile app.

WiFi Monetization

The strategy of generating revenue from a WiFi network. This can be done through direct means (paid access) or indirect means (data collection, targeted ads, and increased customer loyalty).

WPA2-Enterprise

A WPA2 mode that authenticates each user individually via 802.1X and a RADIUS server, enabling per-user identity and revocation. See WPA2-Enterprise explained.

WPA2-PSK (Personal)

The WPA2 mode where all devices share one pre-shared key (the WiFi password), encrypted with AES-CCMP. Simple and universal, but a single shared key can't identify or revoke individual users. See the WPA2-PSK Personal guide.

WPA3-Enterprise

WPA3-Enterprise is the latest business-grade WiFi security mode. Like WPA2-Enterprise it uses 802.1X and RADIUS for per-user authentication, but it adds mandatory protected management frames, stronger encryption and an optional 192-bit mode for high-security networks.

Z

Zero Trust Architecture

A security framework based on the principle of "never trust, always verify." It requires every user and device to be authenticated and authorized continuously, regardless of whether they are inside or outside the corporate network.

ZTNA (Zero Trust Network Access)

A model that grants application access based on verified identity and context rather than network location. Complementary to Cloud NAC (which governs network admission), not a replacement.
— FAQ

Frequently asked questions

Everything you need to know about Cloud4Wi

The Cloud4Wi WiFi Glossary is an A–Z reference defining the essential terms of enterprise wireless networking — from captive portals and SSIDs to PPSK, Passpoint, Cloud NAC, and WPA3. It's written for IT and marketing professionals evaluating or managing guest WiFi, MDU WiFi, and network access, and each entry links to a deeper guide where one is available.

WPA2-PSK Personal uses one shared password for everyone, encrypted with AES-CCMP, and needs no server. WPA2-Enterprise authenticates each user individually via 802.1X and a RADIUS server, giving per-user identity and revocation. "Personal" suits homes and small networks; "Enterprise" suits organizations with the IT infrastructure to run it. Per-user PPSK offers a middle path without RADIUS.

A captive portal is the page shown before internet access, used to authenticate users, capture consent, or present login options. A splash page is a simpler welcome or branding screen, often without full authentication. Both appear on connection, but the captive portal is the gateway that controls access and, on business networks, leads into automatic Passpoint reconnection.

Cloud NAC delivers identity-based network access from the cloud for employees, contractors, and visitors — with no RADIUS server, no MDM, and no multi-month rollout. Traditional NAC (like Cisco ISE or Aruba ClearPass) is powerful but requires appliances, certificate projects, and significant IT effort. Cloud NAC is a right-sized alternative for companies that have outgrown the shared password.

PPSK (Private Pre-Shared Key) gives each user or device a unique WiFi password on one SSID, unlike a single shared key. This adds per-user revocation, segmentation, and privacy without a RADIUS server, and works on devices that can't do 802.1X. Cloud4Wi uses PPSK to give each MDU resident a private, isolated Personal Area Network.

Hardware independence — also called vendor-agnostic — means the software works across different access-point brands (Cisco, Aruba, Meraki, Ruckus, and more) without proprietary equipment. For Cloud4Wi, it means deploying on the infrastructure you already own, with no rip-and-replace, and managing mixed-vendor estates from one dashboard — lowering cost and speeding rollout.

Ready to reimagine your WiFi?

Spin up your 30-day free trial in minutes, or book time with our team
of WiFi experts to scope an enterprise rollout.

  • SOC 2 certified
  • No credit card required
  • GDPR & global compliance
  • No rip-and-replace