A port-based network access control standard that authenticates each device before granting network access — the basis of WPA2/WPA3-Enterprise.
AAA framework for intelligently controlling access to computer resources, enforcing policies, and auditing usage. In Cloud NAC, it ensures only authorized users connect and their access is logged.
A hardware device that allows WiFi-compatible devices to connect to a wired network. In enterprise environments, multiple APs work together to provide seamless roaming. Cloud4Wi is hardware-independent across AP vendors.
A core software component that uses machine-learning algorithms to analyze large datasets, identify patterns, and optimize network performance.
The application of artificial intelligence to manage and optimize wireless networks. It allows for "self-healing" networks that can automatically adjust to interference or high-density traffic to ensure a seamless guest experience.
A set of rules that lets Cloud4Wi exchange data with other software, such as Salesforce or HubSpot, so WiFi data flows into your workflows.
A technology used in dual-band Access Points that encourages dual-band-capable clients (like modern smartphones) to connect to the faster, less congested 5GHz band instead of the 2.4GHz band.
The maximum capacity of a network link to transmit data over a specific connection in a given amount of time. Cloud4Wi allows businesses to set bandwidth limits per user to ensure a fair and high-quality experience for everyone.
A policy allowing employees or guests to use personal devices on the network. Cloud4Wi simplifies BYOD with secure, automated onboarding — no MDM required.
The (often branded) web page users see when first connecting to a WiFi network — the primary tool for collecting marketing opt-ins, presenting terms, or offering login options.
The client-side mechanism (built into iOS, Android, Windows) that automatically detects a captive portal and opens the sign-in page.
A captive portal is the whole system that intercepts a device and enforces sign-on before granting WiFi access; a splash page is the branded screen the user actually sees on that portal. Every splash page is part of a captive portal, but the portal includes much more.
A California statute enhancing privacy rights and consumer protection. Like GDPR, it requires transparency about data collected via WiFi.
Change of Authorization (CoA) is a RADIUS extension defined in RFC 5176 that lets a server change or end an active session without making the user reconnect. It is used to push new access policy, quarantine a device, or disconnect a session in real time.
The ability to configure, monitor, and manage your WiFi network and user data from a centralized online dashboard rather than having to manage each piece of hardware locally.
A right-sized, cloud-delivered Network Access Control approach that provides identity-based WiFi access for employees, contractors, and visitors — with no RADIUS server, no MDM, and no enterprise NAC project.
A security architecture designed specifically for the cloud environment. It moves away from traditional hardware-based firewalls, offering scalable, real-time protection that updates automatically to defend against evolving cyber threats.
Pre-built integrations that link a WiFi platform directly to external software (like Salesforce, Mailchimp, or Adobe), automating the flow of guest data into business tools without custom code.
Adherence to legal frameworks (such as GDPR or CCPA) governing how personal data collected via WiFi is stored and processed.
A network management protocol used to dynamically assign an IP Address to any new device that connects to the network. In guest WiFi environments, a robust DHCP server is essential to handle the constant flow of users joining and leaving the network.
A key metric in location analytics representing the duration a visitor stays within a specific area. This helps retailers and venue owners understand customer engagement levels.
Extensible Authentication Protocol–Transport Layer Security: a certificate-based 802.1X method considered the gold standard for enterprise WiFi authentication, as it uses digital certificates instead of passwords.
A high-performance wireless network for large-scale environments (offices, malls, stadiums), built for hundreds of concurrent users, seamless roaming, and centralized cloud management.
A technology used to categorize visitor behavior in real-time, such as distinguishing between a "passer-by" (outside the venue) and a "visitor" (inside the venue).
The EU framework ensuring personal data is collected and processed transparently and with explicit consent.
A dedicated wireless network for visitors, isolated from the corporate network for security while providing internet access and engagement opportunities.
Hardware Independence — Also called "vendor agnostic": a software platform's ability to work across hardware brands (Cisco, Aruba, Meraki, and more) without proprietary equipment. See supported vendors.
A visual representation of data showing where visitors congregate most frequently within a physical space, generated using WiFi signal strength and presence data.
Hotspot 2.0 is the technical specification, based on IEEE 802.11u, that lets WiFi devices discover and securely join networks automatically. It is the standard behind the Wi-Fi Alliance's Passpoint certification and enables a cellular-like WiFi experience.
A system that creates and manages identity information. In enterprise WiFi, an IdP (like Okta, Microsoft Entra ID, or Google) verifies users before granting access. See Cloud NAC.
A network of devices used to locate people or objects inside a building where GPS is ineffective, typically utilizing WiFi or Bluetooth signals.
A unique numerical label assigned to each device connected to a computer network. While WiFi platforms use IP addresses for routing, they often rely on other identifiers for marketing and analytics.
A suite of protocols used to secure internet communication by authenticating and encrypting each IP packet in a data stream. It is commonly used to create secure "tunnels" (VPNs) between a venue's local network and a centralized cloud controller.
Identity PSK (iPSK) is Cisco's implementation of per-device pre-shared keys on a single SSID. Each key is tied to an identity and authorized through a RADIUS server, bringing unique-key security to devices that cannot run 802.1X.
The process of collecting and analyzing data regarding the physical movement of people within a venue to improve operational efficiency and marketing ROI.
A unique identifier assigned to a network interface. Because modern devices use MAC randomization for privacy, passive MAC-based tracking is unreliable; Cloud4Wi uses consent-based, authenticated connections for accurate visitor recognition instead.
MAC Authentication Bypass (MAB) is a network access method that authenticates a device by its MAC address when the device cannot run 802.1X. The switch or access point sends the MAC address to a RADIUS server, which checks it against an allowed list and grants or denies access.
Mobile Device Management (MDM) is software that configures, secures and monitors an organization's mobile devices from a central console. It can enforce policies, install apps, and push WiFi profiles and certificates, which makes it a key partner to network access control.
A residential building with multiple separate units — apartments, student housing, senior living.
MDU WiFi is property-wide managed WiFi for multi-dwelling units such as apartments, student housing, condos and senior living. It gives each resident a private, secure network on shared infrastructure, usually delivered as a managed amenity by the property.
A security technique that enables fine-grained security policies to be assigned to individual data center workloads or user groups. In a WiFi context, it allows you to isolate a guest's device not just from the corporate network, but also from other guest devices on the same network.
Multi Pre-Shared Key (MPSK) is Aruba's method for assigning multiple unique pre-shared keys to a single SSID, each mapped to a role or device. Like PPSK and iPSK, it provides per-device keys and policy without 802.1X supplicants.
A security solution that enforces policies on devices attempting to join a network, ensuring only authorized, compliant users connect. See Cloud NAC.
A cloud-based model for delivering enterprise network services. It allows businesses to operate their entire network without owning or maintaining the physical "box-and-wire" infrastructure, often on a subscription basis.
OpenRoaming is a Wireless Broadband Alliance federation that lets devices roam automatically and securely between participating WiFi networks using a single trusted identity. It builds on Passpoint and RadSec to remove logins and passwords across thousands of networks.
Opt-in — The process by which a user gives explicit permission for a business to collect their data or send marketing communications.
A protocol that lets mobile devices discover and authenticate to WiFi hotspots automatically, for a "cellular-like" experience with no manual network selection or password. See Passpoint.
A private, isolated network "bubble" for a single user within a shared WiFi environment: their devices can talk to each other (phone and wireless printer) but stay invisible to other users. Cloud4Wi creates a PAN per resident in MDU WiFi.
The process of defining and enforcing rules for network usage. This includes setting bandwidth limits, session durations, and access schedules for different groups (e.g., guests vs. employees).
A method giving each user or device a unique WiFi password on the same SSID, providing per-user security and tracking without a full RADIUS server. See PPSK.
RADIUS (Remote Authentication Dial-In User Service) is a protocol that centralizes authentication, authorization and accounting (AAA) for network access. It verifies user and device credentials, applies access policy and logs sessions across wired, wireless and VPN connections.
RadSec (RADIUS over TLS, defined in RFC 6614) secures RADIUS traffic by carrying it inside an encrypted TCP/TLS tunnel instead of plain UDP. It protects authentication data in transit, adds reliable delivery and makes cloud-hosted RADIUS practical across the public internet.
A system used to track the immediate location of people or assets within a venue. Unlike historical analytics, RTLS provides "right now" data, enabling use cases like wayfinding or instant staff alerts.
An open standard for exchanging authentication and authorization data between an Identity Provider (IdP) and a service provider. This is the technology that allows "Single Sign-On" (SSO), enabling users to log into the WiFi using their existing corporate or social credentials.
A rigorous auditing procedure that ensures your service provider securely manages your data to protect the interests of your organization and the privacy of its clients.
A feature letting guests log in with social-media credentials, simplifying login while providing demographic data.
A simple welcome or landing page shown on WiFi connection, often for branding or terms acceptance, typically without full authentication.
An SSID (Service Set Identifier) is the name of a WiFi network — the label devices show when you search for available connections. It can be up to 32 characters, is broadcast by access points, and is how users and devices identify which wireless network to join.
An authentication scheme that allows a user to log in with a single ID to any of several related, but independent, software systems.
A private, secure wireless network reserved exclusively for employees and internal business operations (such as Point-of-Sale systems or inventory scanners). It is typically hidden or encrypted and is kept strictly separate from the Guest WiFi to ensure maximum security and performance for business-critical tasks.
The process of analyzing the behavior of specific users or groups on the network. It tracks how often they visit, which areas they frequent, and how they interact with the digital touchpoints of the venue.
The administrative task of managing user profiles, permissions, and access levels within a WiFi platform or organization.
A logical sub-group of devices within a larger physical network. Using VLANs allows a venue to keep "Guest WiFi" traffic completely separate from "Staff" or "Point-of-Sale" traffic for better security.
A restricted set of websites or IP addresses a user can reach before fully authenticating through the captive portal.
A global standard (Wireless Broadband Alliance) enabling users to roam between WiFi networks automatically and securely with a single trusted identity.
A method for one application to send another real-time information — e.g., triggering a CRM alert the moment a VIP connects.
A product or service produced by one company that other companies brand as their own. Cloud4Wi's platform can be white-labeled so that the end-user only sees the branding of the venue or service provider.
The latest generations of the WiFi standard (802.11ax / 802.11be), delivering higher speeds, lower latency, and better high-density performance.
The ability to connect to the internet or a local network wirelessly.
The practice of using a guest WiFi network to collect data, display targeted advertisements, and send personalized messages to customers during or after their visit.
A set of software development tools that allows developers to embed WiFi-based location services and "one-click" login features directly into a brand’s own mobile app.
The strategy of generating revenue from a WiFi network. This can be done through direct means (paid access) or indirect means (data collection, targeted ads, and increased customer loyalty).
A WPA2 mode that authenticates each user individually via 802.1X and a RADIUS server, enabling per-user identity and revocation. See WPA2-Enterprise explained.
The WPA2 mode where all devices share one pre-shared key (the WiFi password), encrypted with AES-CCMP. Simple and universal, but a single shared key can't identify or revoke individual users. See the WPA2-PSK Personal guide.
WPA3-Enterprise is the latest business-grade WiFi security mode. Like WPA2-Enterprise it uses 802.1X and RADIUS for per-user authentication, but it adds mandatory protected management frames, stronger encryption and an optional 192-bit mode for high-security networks.
A security framework based on the principle of "never trust, always verify." It requires every user and device to be authenticated and authorized continuously, regardless of whether they are inside or outside the corporate network.
Ready to reimagine your WiFi?
Spin up your 30-day free trial in minutes, or book time with our team
of WiFi experts to scope an enterprise rollout.
