vic115维多利亚·手机平台

Business Support

Technical Support

About Guangxun

About Ainopol

Decree No.176 Takes Effect in October. Visitor Networks of Enterprise Parks Included in Regular Inspections, All-Optical Networks Deliver One-Stop Compliance Rectification
2026-09-18 17:25:57 39

Decree No.176 Takes Effect in October. Visitor Networks of Enterprise Parks Included in Regular Inspections, All-Optical Networks Deliver One-Stop Compliance Rectification

On October 1, 2026, Decree No.176 of the Ministry of Public Security, Measures for the Supervision and Inspection of Cyberspace Security by Public Security Organs, officially comes into force. This is far more than a simple regulatory name change. The supervised entities have expanded from two categories — “internet service providers” and “internet-connected users” — to eight types including network operators, data processors and personal information processors. Inspection methods have also evolved from “onsite ledger reviews” to a combination of online patrols, remote vulnerability scanning and penetration testing.

For enterprise parks that provide public Wi-Fi for tenants and visitors, this means visitor network management is now subject to regular inspections. The old practice of “posting a password at the front desk” no longer merely carries a risk of occasional inspections; remote scans may happen at any time under the new regulation.

I. What Changes Does Decree No.176 Bring to Visitor Network Inspections

Inspections shift from onsite ledger checks to anytime remote testing

Article 4 of the new regulation clarifies that public security authorities may conduct online inspections via information patrols, vulnerability detection and penetration testing. If park visitor networks feature open high-risk ports, weak passwords or non-compliant log retention, these flaws will be uncovered during remote scanning. There will be no grace period to prepare after receiving inspection notices.

Inspection scope expands from network security to network, data and information security

Among key inspection items listed in Article 7, obligations for data security protection and personal information protection are added alongside traditional network security safeguards. Visitor internet behavior data and personal information have become explicit targets for public security inspections for the first time.

“Public internet access service providers” are explicitly designated as inspection targets

As network operators and public Wi-Fi service providers, park operators fall under supervision as long as they operate networks, process data or handle personal information. Visitor networks are no longer a peripheral business; they are an integral part of compliance audits.

II. Compliance Blind Spots of Park Visitor Networks

Scanning QR codes for passwords is not equivalent to real-name authentication

Many parks adopt a QR-code password retrieval process, yet visitors receive a universal shared password with no real-name verification throughout the flow. Visitor identities cannot be bound to specific individuals, leaving no accountable party when incidents occur. The regulation requires retention of “user registration information”, which cannot be fulfilled by a generic shared password.

Logs scattered across multiple devices fail to form a complete evidence chain

In traditional visitor networks, logs may be stored separately on routers, AC controllers and authentication gateways with inconsistent data fields and varying retention cycles. When inspectors request complete internet records for the past six months, parks can only provide fragmented data and cannot present the full audit trail of “who accessed what, from where and at what time”.

No isolation boundary between visitor networks and office networks

Many parks place visitor Wi-Fi and office networks within the same VLAN. Once connected, visitors can scan internal network devices and access shared folders. Article 7 of the regulation requires verification of “technical measures adopted to guard against computer viruses, network attacks and network intrusions”. The lack of segregation between visitor and internal networks constitutes a direct compliance vulnerability.

Fully manual account management exhausts operators

Reception staff manually register visitor identities and notify IT teams to create temporary accounts manually, distributing passwords via handwritten notes or WeChat. After visitors leave, O&M staff must manually batch-delete inactive accounts. During peak visiting hours, front desk and IT workload surges, accompanied by human errors such as mis-sent passwords and undeleted accounts.

III. How All-Optical Networks Deliver One-Stop Visitor Network Compliance Rectification

AINOPOL’s Integrated Communication & Security solution embeds compliance capabilities deep into the network foundation, instead of adding appliances after network deployment. A single Dream Gateway integrates routing, AC, firewall, auditing, authentication and logging functions, forming a closed loop from real-name authentication to compliance reporting within one device.

Self-service real-name authentication for visitors with zero manual intervention

After connecting to the park visitor Wi-Fi, visitors are automatically redirected to a Portal authentication page, supporting multiple verification methods including WeChat QR scan and SMS verification codes. Visitors complete real-name internet access by entering their mobile numbers and receiving verification codes. Authentication accounts are natively associated with internet behaviors through underlying session binding technology, with real-name information retained across the whole workflow. All visitors must complete identity verification before access, eliminating anonymous connections.

Automatic account revocation; permissions expire once access ends

Administrators can customize account validity periods in the backend. After visitors finish real-name authentication, the system automatically generates time-limited temporary network accounts. When the preset validity expires, the system reclaims network permissions and permanently deletes accounts automatically, requiring no manual work. This eliminates leftover permissions where accounts remain active after visitors leave and removes the burden of manual account deletion for IT teams.

Full log retention for 180 days with one-click export of compliance reports

Every visitor internet activity — real-name information, login/logout timestamps, IP addresses, MAC addresses and accessed URLs — is automatically recorded and encrypted locally. Dream-series gateways feature built-in local hard drives to retain rolling logs for no less than 180 days, with complete, tamper-proof and exportable data fields. The system comes with pre-built standard report templates aligned with regulatory requirements. Reports can be exported in one click via the EAAS cloud platform during audits without last-minute log assembly.

VLAN logical isolation keeps visitors away from internal networks

The all-optical network fully segregates visitor Wi-Fi from office networks via VLAN logical isolation. Visitor Wi-Fi only grants internet access and completely isolates corporate internal assets. Visitors cannot scan internal devices, open shared folders or penetrate OA systems. Combined with MAC binding on ONU physical ports, unauthorized devices cannot gain access even if network cables are plugged in.

Native integrated communication & security: security capabilities built into the network

AINOPOL’s Integrated Communication & Security architecture natively embeds security capabilities such as real-name authentication, log auditing and slice isolation into the all-optical network, instead of adding them as aftermarket overlays. Business frames are encrypted frame by frame at the PON link layer using AES-128, with independent keys negotiated for each ONU. Device access control, behavior auditing and log retention are activated upon network deployment. Traceability requirements for internet access under Decree No.176 are fulfilled simultaneously within the all-optical architecture, with no need for later hardware additions or policy configuration.

The rollout of Decree No.176 elevates park visitor networks from a minor administrative item to a core compliance priority. Real-name authentication, log retention and network isolation each carry clear inspection standards and may result in demerits during remote testing. Compliance cannot be achieved by rushing to patch gaps after inspections. Instead, compliance capabilities should be embedded into the network foundation so that the baseline is ready once the network goes live. Visitors complete authentication via QR scan, the system reclaims account permissions automatically, the network isolates visitors from internal assets, and logs are retained for audit. Once this closed-loop system is in place, compliance ceases to be a burden.

FAQ

Q: When will Decree No.176 officially take effect?
A: Decree No.176 was issued on August 6, 2026 and shall come into force on October 1, 2026, while Decree No.151 issued in 2018 is repealed concurrently.

Q: How long must visitor logs be retained?
A: In practice, public security authorities generally require log retention of no less than six months (180 days) for public internet venues. Log fields need to cover core data including real-name information, login/logout timestamps, IP addresses, MAC addresses and accessed URLs.

Q: What will remote inspections focus on?
A: Public security authorities may perform remote testing via vulnerability detection and penetration testing, prioritizing high-risk ports, weak passwords and known unpatched vulnerabilities. Visitor networks with such risks will be exposed during remote scans.