
On October 1, 2026, Measures for the Supervision and Inspection of Cyberspace Security (Ministry of Public Security Order No.176) officially takes effect, while Order No.151 issued in 2018 is repealed simultaneously.
For office buildings, behind this regulatory name change lies a fundamental shift in supervision logic. Decree No.176 explicitly lists public internet service providers as subjects of supervision and inspection. Article 7 prioritizes inspection of whether operators “record and retain user registration information and internet access logs in accordance with the law”. Inspection methods have also evolved from on-site manual ledger checks to a combination of online patrols, remote vulnerability scanning and penetration testing.
When office buildings provide public WiFi for tenants and visitors, they are legally defined as public internet service providers. Real-name authentication and log retention are no longer optional best practices, but statutory obligations. Inspectors may remotely detect missing real-name records for a specific IP address or incomplete log records for certain dates.
Many office buildings adopt a “scan QR code to get password” workflow. However, the QR code only returns a universal shared password without any real-name identity verification. Visitors’ network access cannot be bound to specific individuals, leaving no accountable party when security incidents occur. Decree No.176 requires retention of “user registration information”, while a shared password provides no valid registered user data.
Visitor network logs in traditional deployments are often distributed across routers, AC controllers and authentication gateways, with inconsistent data formats and varying storage cycles. When inspectors request complete six-month internet records, property management can only provide fragmented data and fail to present a full audit trail showing who connected, at what time, from which terminal, and what websites were accessed.
In many office buildings, visitor WiFi and office networks share the same VLAN. Once visitors connect to WiFi, they can scan internal network devices and access shared folders. Article 7 of Decree No.176 mandates inspection of technical safeguards against computer viruses, network attacks and intrusions. The lack of isolation between visitor and internal networks constitutes a direct compliance vulnerability.
AINOPOL’s Integrated Communication & Encryption solution embeds compliance capabilities into the underlying network architecture instead of adding standalone appliances afterwards. One Dream Gateway integrates routing, AC controller, firewall, audit, authentication and logging functions, forming a closed loop from real-name authentication to compliance report generation within a single device.
When visitors connect to visitor WiFi, a Portal authentication page pops up automatically. Multiple verification methods including WeChat QR code scanning and SMS verification codes are supported. Visitors complete real-name internet access by entering mobile numbers and verification codes. Underlying session binding technology natively links authenticated accounts with online behaviours, and real-name information runs through the whole process. All visitors must complete identity verification before access, eliminating anonymous connections.
Administrators can customize account validity periods in the backend. After real-name authentication, the system automatically generates time-limited temporary network accounts. Upon expiry, network permissions are revoked and accounts are fully deleted automatically without manual operations. This eliminates leftover access rights when visitors leave, and removes the workload of manual account deletion for IT teams.
Every online behaviour of visitors — real-name information, login/logout timestamps, IP addresses, MAC addresses and accessed URLs — is automatically recorded and encrypted locally. The Dream series gateway comes with built-in local hard disks for rolling log storage of no less than 180 days. Logs are complete, tamper-proof and exportable. Pre-built standard report templates meeting regulatory requirements allow one-click export during inspections, avoiding last-minute log assembly.
The all-optical network completely separates visitor WiFi from office networks via VLAN logical isolation. Visitor WiFi only grants internet access and fully isolates internal office assets. Visitors cannot scan internal devices, open shared folders or penetrate OA systems.
The biggest concern for office building visitor network compliance renovation is service interruption for tenants. AINOPOL supports hybrid IP-POL deployment, enabling parallel operation of old and new networks. Floor or zone-based phased cutover allows debugging at night while keeping services available during daytime. Rollback to the original network is instantly available if cutover anomalies occur, with no impact on daily operations. Optical fiber can reuse existing pipelines without wall chiselling or trenching.
For property management teams, post-renovation O&M is simpler than traditional solutions. The EAAS cloud platform delivers a real-time online user dashboard, displaying MAC addresses, IPs, authenticated accounts and online duration of connected devices for quick verification during inspections. For multi-floor deployments, property managers can centrally manage logs from all floors and generate unified compliance reports with consistent data standards.
The enforcement of Decree No.176 has moved public WiFi in office buildings from a minor administrative matter to a core compliance priority. Real-name authentication, log retention and network isolation all carry clear inspection standards and may result in penalties upon remote detection. The compliant approach is not to patch systems after inspections, but to build compliance into the underlying network. The full closed-loop workflow: visitors complete authentication via QR code → system assigns temporary permissions → visitors access isolated network zone → online behaviours are automatically recorded → abnormal activities detected promptly → logs retained uniformly for audit. Once this closed loop is established, compliance stops being a burden and becomes a native capability of the network.
Q: What specific requirements does Decree No.176 impose on public WiFi in office buildings?
A: Article 7 of Decree No.176 identifies public internet service providers as inspection targets, focusing on whether operators record and retain user registration information and internet access logs in accordance with law. Office buildings offering public WiFi must implement two core obligations: real-name authentication and log retention.
Q: How long should visitor logs be retained?
A: In practice, public security authorities require log retention of no less than 180 days (6 months) for public internet venues. Logs must contain core fields including real-name information, login/logout timestamps, IP addresses, MAC addresses and accessed URLs.
Q: Is the “scan QR code to obtain password” method compliant?
A: No. Scanning QR codes to receive a universal password without real-name verification fails to meet the requirement of “recording and retaining user registration information”. The deployment must implement one account per person with traceable real identities.