
Effective October 1, 2026, the Measures for Public Security Organs' Supervision and Inspection of Cyberspace Security (Order No.176 of the Ministry of Public Security) officially comes into force, while the 2018 Order No.151 of the Ministry of Public Security is repealed concurrently.
Compared with the old regulation, the new rules go beyond inspections focused merely on traditional "Internet security". The scope of supervision and inspection is further extended to network security, data security, personal information protection and other fields. Particularly for hotels, which run multiple services including guest Wi-Fi, office systems, room management, video surveillance and access control, existing network deployments — even those already completed — need to be re-evaluated against the new compliance requirements.
So if a hotel has already deployed an all-optical network, what additional compliance items are required? How can capabilities be supplemented through network architecture and security features?
Judging from actual inspection items, hotels need to focus not simply on "network availability", but on building a full closed loop covering user identity, online behavior, security defense and data protection within the network.
Order No.176 explicitly includes "whether user registration information and internet access logs are recorded and retained in accordance with the law" within the scope of supervision and inspection.
Therefore, hotel Wi-Fi must achieve more than basic authentication. It is critical to establish a clear mapping between user identities and network access. For hotels already equipped with all-optical networks, Portal-based real-name authentication can be added to the existing infrastructure. Guests complete identity verification via mobile phone numbers or other methods before gaining network access permission.
This brings user identities formally into the hotel network management system, instead of relying solely on shared Wi-Fi passwords.
Order No.176 lists the recording and retention of user registration information and internet access logs as inspection items.
Hotels need to build a comprehensive log system that correlates and preserves users, IP addresses, authentication timestamps and network access records. It is insufficient to keep scattered logs isolated on individual devices. Instead, a centrally managed system that supports easy query and traceability with anti-tampering protection for logs is required.
In short, compliance requirements have evolved from simply "having logs" toward ensuring logs are complete, correlated and traceable.
This means hotel networks cannot rely only on basic access controls; security defense capabilities must be enhanced.
Hotel networks host a wide variety of endpoints including guest terminals, office PCs, servers, cameras, access controllers and information display devices. Without effective segmentation between public Wi-Fi and internal business networks, a compromised terminal may trigger risks spreading to other business systems.
The existing all-optical network therefore needs additional security capabilities such as intrusion prevention, web application protection, network isolation and vulnerability remediation to form a robust cybersecurity boundary.
For hotels already running all-optical networks, compliance rectification does not require tearing down and rebuilding the entire network. A more practical approach is to gradually add authentication, logging and security protection capabilities on the existing all-optical infrastructure.
After guests connect to Wi-Fi, they complete identity authentication through the Portal page, and authentication information is associated with network access permissions. The Mengxiang Gateway centrally manages authentication policies and network access control, making network users identifiable and manageable.
Compared with traditional shared-password Wi-Fi, this method establishes an identity foundation for subsequent log traceability. When cybersecurity incidents arise, hotels are no longer limited to viewing only an IP address; they can correlate traffic records with verified users.
User authentication data is correlated with IP addresses, access timestamps and other network information, and records are retained in line with compliance requirements. When cybersecurity incidents occur, logs support query and traceability to help hotels quickly locate relevant users and network activities.
Log management is more than just data storage. It must guarantee log integrity and anti-tampering protection to prevent unauthorized modification or deletion of critical records. This creates an end-to-end traceability chain: identifying who the user is → tracking which network resources they access → enabling investigation after incidents.
AINOPOL uses the Mengxiang Gateway as the security node at the network egress, equipped with IPS, WAF and other security features to defend against cyberattacks, abnormal traffic and web application-layer risks. Access control and security policies are applied to isolate different business systems.
At the underlying network layer, leveraging OLT and ONU devices of the all-optical network, guest Wi-Fi is properly segmented from hotel office, surveillance, access control and other business networks to reduce cross-network risk propagation.
In this way, the original all-optical network is no longer merely for "network connectivity". It evolves into an integrated network architecture supporting real-name authentication, log traceability, security defense and service isolation.
Following the replacement of Order No.151 by Order No.176, hotel network compliance focuses have shifted from basic requirements such as "Wi-Fi availability and log existence". Regulators now prioritize verifiable identities, traceable behaviors, effective network protection and vulnerability remediation throughout network operation.
Hotels with existing all-optical networks do not need standalone hardware. Instead, they should enhance the all-optical foundation by implementing Portal real-name authentication, log management, IPS/WAF security protection and service isolation.
From this perspective, the next phase of hotel all-optical network development is shifting from "network connectivity" toward "security compliance + unified management". Without altering the underlying all-optical architecture, adding authentication, logging and security modules helps hotels meet cyberspace supervision requirements after Order No.176 takes effect.
Q: What is the biggest difference between Order No.176 and Order No.151?
A: Three fundamental changes: the scope of regulated entities expands from 2 categories to 8; hotels are classified simultaneously as "public internet access service providers", "network operators" and "personal information processors". Remote detection technologies including vulnerability scanning and penetration testing are added to inspection methods. The body of supporting higher-level laws expands from 2 to more than 7, including newly added Data Security Law and Personal Information Protection Law.
Q: Will internal hotel systems without Internet access also be inspected?
A: Yes. Order No.176 explicitly brings network operators, data processors and personal information processors under inspection scope. PMS, financial systems, guest control systems, surveillance systems — all internal systems involving data and information security are subject to inspection. No internet access does not mean exemption from inspection.
Q: What does personal information protection mean for hotels?
A: Hotels store large volumes of guests’ personal information, including ID numbers, mobile phone numbers and check-in records, which are now subject to compliance reviews for personal information protection. SMS verification alone is insufficient. Hotels must achieve "consistency between person and ID document" — proving that the person accessing the network is the registered guest who completed check-in.