A method, system, medium and product for constructing a private network for a guest room based on a WiFi system

By generating unique virtual network identifiers and configuring virtual tunnel endpoints for hotel rooms, a logically isolated private network for each room is constructed, solving the problem of devices being unable to communicate under traditional client isolation mechanisms. This achieves a secure and convenient device linkage experience and improves the stability and management efficiency of the hotel Wi-Fi system.

CN121442446BActive Publication Date: 2026-05-12BEIJING ZHONGLIAN NORTH INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING ZHONGLIAN NORTH INFORMATION TECH CO LTD
Filing Date
2025-10-23
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In hotel Wi-Fi networks, traditional client isolation mechanisms prevent devices from communicating with each other, affecting the user experience of interconnected devices and failing to guarantee network security.

Method used

By generating a unique virtual network identifier for each guest room, configuring virtual tunnel endpoints, constructing a logically isolated private network for the guest rooms, and establishing a binding relationship after the client device connects, seamless communication and secure isolation between devices are achieved.

Benefits of technology

It achieves seamless interconnection and interoperability between devices while ensuring network security, enhances the passenger's device interaction experience, and prevents network congestion through periodic monitoring and automated management, ensuring system stability and robustness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121442446B_ABST
    Figure CN121442446B_ABST
Patent Text Reader

Abstract

A room private network construction method, system, medium and product based on a WiFi system, relate to the WiFi technical field. The core technical feature of the method is that a unique virtual network identifier is generated for a room identifier; a virtual tunnel endpoint is configured on a wireless access point serving the room, and is associated with the identifier; when a client device accesses, it is bound with the virtual network identifier, thereby dynamically constructing a room-specific, logically isolated private network. Through the present application, the "one-size-fits-all" limitation of traditional client isolation is effectively broken, and under the premise of ensuring network security isolation between different rooms, safe and reliable interconnection of devices within the same room is realized, thereby providing hotel guests with a convenient wireless screen projection, file sharing and other device linkage experience like a home network, significantly improving service quality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of WiFi technology, and in particular to a method, system, medium and product for constructing a private network for guest rooms based on a WiFi system. Background Technology

[0002] In hotels and other similar settings, guests typically bring multiple personal smart devices, such as smartphones, laptops, tablets, wireless screen mirroring devices, and portable smart speakers. These devices can easily form an interconnected ecosystem within a home network environment. Therefore, achieving this convenient device connectivity experience while ensuring the network security and privacy of each guest presents new and higher demands on hotel Wi-Fi network services.

[0003] To ensure guest data security in public network environments, current hotel Wi-Fi network solutions generally employ a client isolation mechanism. This mechanism, deployed on network devices such as wireless access points (APs) or wireless controllers (ACs), works as follows: when a guest's terminal device connects to the wireless network, the network device controls access to the data frames it sends. Specifically, the network device only allows data frames destined for a preset gateway address to be forwarded normally to the upstream network. For data frames destined for other terminal devices within the same wireless network, an interception policy is implemented, thereby blocking direct communication paths between wireless clients at the data link layer.

[0004] While client-side isolation mechanisms in related technologies meet traditional security requirements, they restrict device interconnection for travelers within a network environment. The working principle of device interconnection in these technologies involves sending broadcast messages within the local area network (LAN) so that other devices on the network can receive and respond. However, in networks employing client-side isolation technology, when user devices attempt to interconnect, the broadcast messages sent by the user devices are intercepted by network devices because their destination address is not the network gateway, leading to interconnection failure and a degraded traveler experience. Summary of the Invention

[0005] This application provides a method, system, medium, and product for constructing a private network in a guest room based on a WiFi system, which solves the problem of devices being unable to communicate with each other under traditional client isolation mechanisms, and achieves an effective balance between network security and user experience.

[0006] In a first aspect, this application provides a method for constructing a private network in a guest room based on a WiFi system. The method is applied to a server in the WiFi system, which also includes a wireless controller and wireless access points deployed in the guest rooms. The method includes: upon receiving a check-in event trigger signal containing a guest room identifier, generating a unique virtual network identifier for the guest room identifier and establishing a first binding relationship between the guest room identifier and the virtual network identifier; determining a target wireless access point deployed in the corresponding guest room based on the guest room identifier; and, according to the first binding relationship, sending the virtual network identifier to the target wireless access point; instructing the target wireless access point to configure a virtual tunnel endpoint for the virtual network identifier to construct the private network in the guest room identified by the virtual network identifier; after a client device accesses the target wireless access point and completes authentication, obtaining the media access control address of the client device and determining it as the client identifier; and establishing a second binding relationship between the client identifier and the virtual network identifier, the second binding relationship being used to identify that the client device belongs to the private network in the guest room.

[0007] By adopting the above technical solution, the server automatically generates a unique Virtual Network Identifier (VNI) for a specific guest room by listening to check-in events and establishes a first binding relationship with the guest room, ensuring a precise correspondence between the logical network and the physical space. Next, a Virtual Tunnel Endpoint (VTEP) associated with this VNI is configured on the wireless access point (AP) within the guest room, thus constructing a logically independent private network boundary for the guest room. When a guest's device connects to the AP, a second binding relationship assigns the device to the corresponding private network within the guest room. Therefore, the previously open and shared WiFi environment is dynamically and on-demand divided into multiple isolated private networks. Without increasing user intervention, this solves the problem of device incompatibility under traditional client-side isolation mechanisms while ensuring security between different guest room networks, achieving an effective balance between network security and user experience.

[0008] In conjunction with some embodiments of the first aspect, in some embodiments, after establishing a second binding relationship between the client identifier and the virtual network identifier, the method further includes: receiving an original data frame from the client device, encapsulating the original data frame in a virtual tunnel message with a virtual tunnel endpoint, and sending the virtual tunnel message to the wireless controller; obtaining a device member list of other client devices belonging to the same virtual network identifier through the wireless controller according to the second binding relationship; and sending the virtual tunnel message to the other client devices in the device member list.

[0009] By adopting the above technical solution, this application, based on the construction of a private guest room network, further clarifies the communication path between client devices. The wireless access point encapsulates the raw data frames sent by the client devices in virtual tunnel messages, and marks the data frames with a unique identity tag specific to the private guest room network through the encapsulation operation. Based on this identity tag and second binding relationship, the wireless controller identifies all other device members belonging to the same private guest room network and forwards the received virtual tunnel messages to these device members, thereby bypassing the broadcast restrictions of traditional client isolation and realizing communication such as device interconnection that relies on Layer 2 broadcast. Simultaneously, the forwarding of virtual tunnel messages is based on the device member list, ensuring that data only flows within the private guest room network and is not leaked, achieving secure and controllable device interconnection.

[0010] In conjunction with some embodiments of the first aspect, in some embodiments, before sending the virtual tunnel message to other client devices in the device member list, the method further includes: monitoring and counting the number of virtual tunnel messages within a preset statistical period to obtain the broadcast message count value of the corresponding virtual network identifier; if the broadcast message count value exceeds a preset broadcast traffic threshold, discarding subsequently received virtual tunnel messages belonging to the same virtual network identifier within a preset suppression period.

[0011] By adopting the above technical solution, this application achieves interconnectivity within the guest room's private network while adding a network protection barrier within that private network. The server proactively senses the health of network traffic by periodically monitoring and counting the number of broadcast packets within a specific private network. When an abnormal surge in the number of broadcast packets (i.e., a broadcast storm) caused by equipment failure or malicious behavior is detected, exceeding a preset broadcast traffic threshold, the server immediately activates a suppression mechanism, proactively discarding subsequent broadcast packets from that guest room's private network within a predetermined period. This confines the risk of network congestion to the individual guest room's private network, effectively preventing localized problems from spreading to the entire hotel's WiFi system. This enhances the guest's device interconnection experience while ensuring the stability and robustness of the overall wireless network.

[0012] In conjunction with some embodiments of the first aspect, in some embodiments, after instructing the target wireless access point to configure a virtual tunnel endpoint for the virtual network identifier to construct a private network for a guest room identified by the virtual network identifier, the method further includes: when receiving a check-out event trigger signal containing the guest room identifier, releasing the first binding relationship and the second binding relationship, and instructing the target wireless access point to remove the virtual tunnel endpoint corresponding to the virtual network identifier, thereby destroying the private network for the guest room.

[0013] By adopting the above technical solution, the server automatically triggers the network destruction process upon receiving a check-out event signal, achieving automated closed-loop management of the guest room's private network lifecycle. By disabling the first and second binding relationships, the server logically severs the connection between the guest room, devices, and the virtual network, ensuring that information is no longer exchanged. It also instructs the wireless access point to remove the corresponding virtual tunnel endpoint, further removing the configuration of the guest room's private network at the physical network device level. Therefore, while avoiding the tediousness and risk of omissions associated with manual configuration, it ensures the guest's network privacy and security, reduces the operational burden of the WiFi system, and improves the efficiency and security of WiFi system network management.

[0014] In conjunction with some embodiments of the first aspect, in some embodiments, based on the guest room identifier, the target wireless access point deployed in the corresponding guest room is determined; and according to the first binding relationship, the virtual network identifier is sent to the target wireless access point, specifically including: when the guest room corresponding to the guest room identifier has at least two wireless access points deployed, the at least two wireless access points are determined as the target wireless access point set; and according to the first binding relationship, the virtual network identifier is sent to each wireless access point in the target wireless access point set.

[0015] By adopting the above technical solution, this application further considers that for large or complex guest rooms (such as suites), a single AP often cannot achieve full signal coverage, thus requiring multiple APs. By identifying all APs in the guest room as a single target wireless access point set and uniformly distributing the same virtual network identifier, these APs constitute a unified private network domain. Therefore, regardless of which AP a guest's device connects to in the guest room, it will be included in the same private network of that guest room, ensuring that guests can enjoy a consistent network policy and device interconnection experience from any location in the room, thus solving the problems of network segmentation and inconsistent experience in multi-AP scenarios.

[0016] In conjunction with some embodiments of the first aspect, in some embodiments, after the virtual network identifier is sent to the target wireless access point, the method further includes: constructing a roaming domain within the guest room based on the guest room identifier; when the client device first accesses a wireless access point within the roaming domain within the guest room, determining the accessed wireless access point as the first wireless access point, and determining the remaining wireless access points within the roaming domain within the guest room as second wireless access points; generating roaming context information for the client device based on the first wireless access point, the roaming context information including the client identifier and the corresponding virtual network identifier; and synchronizing the roaming context information to the second wireless access point.

[0017] By adopting the above technical solution, this application further optimizes the mobile experience of client devices based on a unified private network for multi-AP guest rooms. By constructing the target AP set as a roaming domain within the guest room and pre-synchronizing the roaming context information of client devices from their currently connected AP (first wireless access point) to all other APs (second wireless access points) in the roaming domain within the guest room, seamless roaming is prepared. This ensures that when a client device moves and needs to switch APs, the target AP already knows the identity and network of the client device, eliminating the need for cumbersome re-authentication and network allocation processes. Therefore, the latency of client device roaming switching is effectively shortened, network interruptions caused by switching are avoided, the continuity of real-time applications such as video calls and online games is guaranteed, and the user experience is improved.

[0018] In conjunction with some embodiments of the first aspect, in some embodiments, after synchronizing the roaming context information to the second wireless access point, the method further includes: when the client device roams from the first wireless access point to the second wireless access point, configuring a virtual tunnel endpoint for the second wireless access point according to the virtual network identifier in the roaming context information; and forwarding residual data frames that have been received by the first wireless access point but have not yet been successfully delivered to the client device to the virtual tunnel endpoint of the second wireless access point.

[0019] By adopting the above technical solution, this application achieves zero data loss and improves the seamless roaming experience. When the client completes the switch from the first AP to the second AP, there may still be residual data frames in the first AP's buffer that have been received but not yet successfully sent to the client. The server forwards these residual data frames to the virtual tunnel endpoint of the second AP via the backend network, and then the second AP sends them to the client device, achieving a smooth data transition during AP switching and improving the reliability of the guest room's private network.

[0020] Secondly, this application provides a server for a WiFi system, the server comprising: one or more processors and a memory; the memory is coupled to one or more processors, the memory being used to store computer program code, the computer program code including computer instructions, and the one or more processors invoking the computer instructions to cause the WiFi system server to perform the method described in the first aspect and any possible implementation thereof.

[0021] Thirdly, this application provides a computer-readable storage medium including instructions that, when executed on a server of a WiFi system, cause the server of the WiFi system to perform the method described in the first aspect and any possible implementation thereof.

[0022] Fourthly, this application provides a computer program product that, when run on a server of a WiFi system, causes the server of the WiFi system to execute the method described in the first aspect and any possible implementation thereof.

[0023] Understandably, the server provided in the second aspect, the computer program product provided in the third aspect, and the computer storage medium provided in the fourth aspect are all used to execute the methods provided in the embodiments of this application. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0024] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:

[0025] 1. By generating a unique virtual network identifier for each guest room, configuring virtual tunnel endpoints, and binding the guest room and the connected client devices to this identifier, a dedicated and logically isolated network space can be dynamically built for each guest room. This effectively solves the technical contradiction in related technologies where client isolation mechanisms, while ensuring security, block the interconnection of devices within the guest room. As a result, a private guest room network that combines security and convenience is achieved, allowing guests to enjoy a home-like device interconnection experience.

[0026] 2. By encapsulating the original data frames in virtual tunnel messages and obtaining the device member list based on the second binding relationship for targeted forwarding, a precise and controllable forwarding path is established for communication within the private network. This effectively solves the problem of device discovery failure and inability to establish connections caused by the interception of broadcast messages by network devices in related technologies. As a result, reliable Layer 2 communication between devices within the guest room private network is realized, ensuring the normal use of functions such as wireless screen projection and file sharing.

[0027] 3. By identifying at least two wireless access points in the guest room as the target wireless access point set and distributing the same virtual network identifier to each wireless access point in the set, multiple physically dispersed APs are logically integrated into a unified private network domain. This effectively solves the problem of inconsistent network affiliation and intermittent device interconnection caused by clients connecting to different APs in large guest rooms in related technologies. As a result, the private network of the guest room is seamlessly extended throughout the physical space, ensuring that users can obtain a stable and consistent device interconnection experience from any location in the guest room. Attached Figure Description

[0028] Figure 1 This is a schematic diagram of a system architecture for a method of constructing a private network for guest rooms based on a WiFi system, as described in this application.

[0029] Figure 2 This is a flowchart illustrating a method for constructing a private guest room network based on a WiFi system, as described in this application.

[0030] Figure 3 This is another flowchart illustrating the method for constructing a private guest room network based on a WiFi system in this application embodiment;

[0031] Figure 4 This is a schematic diagram of the physical device structure of a server in an embodiment of this application. Detailed Implementation

[0032] The terminology used in the following embodiments of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of this application. As used in the specification of this application, the singular expressions “a,” “an,” “the,” “the,” and “this” are intended to include the plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in this application refers to any or all possible combinations including one or more of the listed items.

[0033] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature, and in the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more.

[0034] To facilitate understanding, the following will be combined with Figure 1 This section introduces application scenarios for embodiments of this application. Please refer to [link / reference]. Figure 1 This is a schematic diagram of a system architecture for a method of constructing a private network in a guest room based on a WiFi system in an embodiment of this application. The WiFi system 100 includes: a wireless controller (AC) 101, a wireless access point (AP) 102, a server 103, and a private network in a guest room 104.

[0035] In related technologies, client isolation mechanisms can be used to block Layer 2 communication between different client devices on the same wireless network. In hotel network environments, to ensure data security, client isolation is typically enabled on the wireless access point (AP) 102 or the wireless controller (AC) 101. When multiple devices (such as mobile phones, tablets, and wireless screen projectors) of a guest are connected to the same WiFi network, if the guest attempts to project their screen from their phone to the projector, the broadcast message sent by the phone for device discovery will be blocked by the network device because the target address is not the network gateway. This prevents devices from discovering and communicating with each other, rendering device interconnection functionality ineffective and severely impacting the guest's check-in experience.

[0036] The method for constructing a private guest room network based on a WiFi system, as described in this application, generates a unique virtual network identifier for each guest room and configures a virtual tunnel endpoint on the target wireless access point 102. This enables the construction of a logically isolated private guest room network 104 for each guest room, allowing internal devices to communicate with each other. This not only ensures network security isolation between different guest rooms, but also, when a guest checks in, the hotel management system sends a check-in event trigger signal to the server 103. The server 103 then automatically creates a dedicated private guest room network 104 for that guest room. When a guest's mobile phone, tablet, screen mirroring device, or other device connects to the wireless access point 102 in the guest room, it is automatically added to this private guest room network 104. At this time, when a guest initiates screen mirroring from their mobile phone, their broadcast message is encapsulated in a virtual tunnel message and accurately forwarded to the screen mirroring device belonging to the same private guest room network 104, thereby achieving seamless discovery and interconnection between devices and providing a convenient experience similar to a home network.

[0037] As can be seen, the dynamic virtual network construction method in this application can effectively protect the network security of devices while also solving the problem of device interconnection failure caused by the interception of Layer 2 broadcast messages under the traditional client isolation mechanism, thereby achieving an effective balance between network security and user experience convenience.

[0038] To facilitate understanding, the method provided in this implementation will be described in detail below, using the above scenario as an example. Please refer to [link / reference]. Figure 2 This is a flowchart illustrating a method for constructing a private guest room network based on a WiFi system in an embodiment of this application.

[0039] S201. When a check-in event trigger signal containing a room identifier is received, a unique virtual network identifier is generated for the room identifier, and a first binding relationship is established between the room identifier and the virtual network identifier.

[0040] Among them, the check-in event trigger signal refers to a data signal automatically sent by an external system (such as a hotel management system, PMS) to the WiFi system server when a guest's check-in procedure is completed. This signal must contain unique identification information for the guest room. The guest room identifier represents a specific string or number that can uniquely identify a guest room within the hotel, such as room number "8808" or internal management number "RM-A-8808". The Virtual Network Identifier (VNI) is a globally unique logical label assigned by the server to each guest room's private network, used to isolate network traffic from different guest rooms at the data level. The first binding relationship represents the mapping relationship between the guest room identifier and the virtual network identifier established and maintained by the server in the internal database or memory, ensuring that the server knows which virtual network belongs to which physical room. For example, storing a record as (Guest Room Identifier: 8808, Virtual Network Identifier: 1001).

[0041] This step is executed when a guest completes check-in at the hotel front desk. Specifically, when the room status in the Hotel Management System (PMS) changes to "occupied," a check-in event trigger signal is sent to the WiFi system server via a pre-configured interface (such as an API call). The server continuously listens for signals from the PMS. Upon receiving the check-in event trigger signal, the server first parses the signal content and extracts the room identifier. Next, the server allocates an unused virtual network identifier from the preset VNI pool, or dynamically generates a globally unique virtual network identifier using an algorithm. After allocation, the server immediately creates a new record in its configuration database or status table, associating the room identifier with the virtual network identifier to establish the initial binding relationship.

[0042] It is understandable that other methods can be used to assign VNIs to guest rooms and establish the first binding relationship, which is not limited here.

[0043] S202. Based on the guest room identifier, determine the target wireless access point deployed in the corresponding guest room; and according to the first binding relationship, send the virtual network identifier to the target wireless access point;

[0044] The Target Wireless Access Point (Target AP) is a hardware device physically installed in the guest room specified by the guest room identifier to provide WiFi signals. It is the network edge execution node for building the guest room's private network.

[0045] After successfully establishing the initial binding relationship, the server further applies the logical network planning to the physical network devices. Specifically, the server first uses the guest room identifier obtained in the previous step to query the physical location information of the wireless access point (AP) deployed in the corresponding guest room, for example (guest room identifier: "8808", AP_MAC: "00-1A-2B-3C-4D-5E"), and identifies the wireless access point in that guest room as the target wireless access point. Next, the server obtains the unique virtual network identifier corresponding to that guest room through the established initial binding relationship. The server communicates with the wireless controller (AC) through its management interface and sends a configuration command to the wireless access point, which contains the identity information of the target wireless access point and the virtual network identifier to be applied.

[0046] S203. Instruct the target wireless access point to configure a virtual tunnel endpoint for the virtual network identifier to construct a private network for the guest room identified by the virtual network identifier;

[0047] Among them, a Virtual Tunnel Endpoint (VTEP) refers to a logical interface created on a network device. It is the start and end point of a network virtualization tunnel and is responsible for encapsulating and decapsulating data frames entering and leaving the tunnel. In this embodiment, the VTEP is bound to a issued virtual network identifier, and all traffic belonging to this virtual network will be processed through this virtual tunnel endpoint. A guest room private network refers to an independent and logically isolated Layer 2 broadcast domain created for a single guest room on top of a shared physical network infrastructure through virtualization technology. Devices within this network can discover and communicate with each other as in a home LAN, but are completely isolated from the private networks of other guest rooms.

[0048] After receiving the configuration command from the server, the target wireless access point constructs the network environment. Specifically, upon receiving the configuration command containing a virtual network identifier from the server (or via the AC), the target wireless access point creates a new logical entity, the Virtual Tunnel Endpoint (VTEP), at its operating system level. This VTEP is closely associated with the virtual network identifier. Then, the target wireless access point logically bridges its guest room-facing wireless RF interface or specific SSID to this newly created VTEP, completing the construction of the guest room's private network. At this point, any data traffic from any device connected to the target wireless access point will be directed to this VTEP for tunnel encapsulation, thus achieving effective isolation from other network traffic.

[0049] S204. After the client device accesses the target wireless access point and completes authentication, obtain the media access control address of the client device and determine it as the client identifier;

[0050] In this context, "client device" refers to a smart terminal device carried by a guest that can connect to a WiFi network, such as a smartphone, laptop, or tablet. "Authentication" refers to the security verification process between the client device and the target wireless access point, including but not limited to WPA2-PSK authentication, Portal authentication, and 802.1X authentication, used to ensure that only authorized users can access the network. "Media Access Control Address (MAC Address)" refers to a globally unique 48-bit hardware address assigned to each network device at the factory, such as "00:11:22:33:44:55," used to uniquely identify a network interface at the data link layer. "Client Identifier" refers to the identifier used by the server to uniquely identify a client device within the WiFi system; in this embodiment, the device's MAC address is directly used as the client identifier.

[0051] The server executes this step after the client device successfully connects to the target wireless access point's WiFi network and completes the required authentication process. Specifically, when the client device scans the SSID broadcast by the target wireless access point, it initiates an association request. Upon receiving the request, the target wireless access point initiates a pre-configured authentication process. During authentication, the client device needs to provide correct credentials (such as a password). After successful authentication, the target wireless access point notifies the server of this event and reports the client device's MAC address and other information. After receiving this information, the server stores the MAC address as a client identifier in its management database for subsequent network management and traffic control.

[0052] S205. Establish a second binding relationship between the client identifier and the virtual network identifier. The second binding relationship is used to identify that the client device belongs to the private network of the guest room.

[0053] The second binding relationship refers to the mapping relationship between the client identifier (i.e., the device MAC address) and the virtual network identifier (VNID) established by the server in its database, for example (client identifier: "00:11:22:33:44:55", virtual network identifier: 1001).

[0054] After obtaining the client identifier, the server includes the newly connected client device within the private network management scope of that specific guest room. Specifically, the server first checks if the client device already exists in any existing binding relationships; if so, it needs to unbind the existing binding. Next, the server searches for the virtual network identifier associated with the current target wireless access point through the first binding relationship. Then, the server creates a new record in its database, associating the client identifier with the found virtual network identifier to form a second binding relationship. This second binding relationship will be used to control the network traffic forwarding of the client device, ensuring that the client device can only communicate directly with other devices within the same guest room's private network.

[0055] S206. When a check-out event trigger signal containing the guest room identifier is received, the first binding relationship and the second binding relationship are released, and the target wireless access point is instructed to remove the virtual tunnel endpoint corresponding to the virtual network identifier, thereby destroying the guest room private network.

[0056] Among them, the check-out event trigger signal refers to the notification signal sent by the hotel management system (PMS) to the WiFi system server when the guest completes the check-out procedure, which is used to indicate that the status of a specific room has changed to checked out; unbinding relationship means deleting or invalidating the first and second binding relationships established before the deletion in the server database; destruction means completely terminating the operation of a room's private network, including releasing all related system resources, disconnecting all connected client devices, and clearing all related configuration information.

[0057] The server executes this step after the guest completes check-out at the hotel front desk. Specifically, upon receiving a check-out event trigger signal, the server first searches the database for the corresponding first binding relationship based on the room identifier contained in the signal, retrieving the virtual network identifier used by that room. Then, the server queries all second binding relationships associated with that virtual network identifier to obtain a list of all client devices that need to be disconnected. Next, the server marks these binding relationships as invalid or deletes them directly from the database. Afterward, the server sends a configuration command to the target wireless access point, requesting it to stop using the virtual network identifier, delete the corresponding virtual tunnel endpoint configuration, and return the virtual network identifier to the VNI pool for subsequent allocation.

[0058] In this embodiment, a unique virtual network identifier is generated for the guest room identifier and a first binding relationship is established upon guest check-in. Then, a virtual tunnel endpoint is configured on the target wireless access point to construct a private network for the guest room. After the guest's client device connects, a second binding relationship is established between the client identifier and the virtual network identifier. Finally, when the guest checks out, the network is destroyed by unbinding the relationship and removing the virtual tunnel endpoint. Therefore, the entire lifecycle management of a private network dedicated to a guest room and logically isolated from guest check-in and check-out events can be automatically completed. This effectively solves the "one-size-fits-all" security restriction caused by the static client isolation strategy in related technologies, which sacrifices the convenience of interconnection of devices within the same room while ensuring cross-room security. This achieves a dynamic, on-demand, and secure "one person, one network" exclusive network service for each guest, allowing guests to enjoy a seamless and convenient smart device linkage experience like at home in the hotel.

[0059] Based on the above embodiments, the method provided in this embodiment will be described in further detail below. Please refer to... Figure 3 This is another flowchart illustrating the method for constructing a private guest room network based on a WiFi system in this application embodiment.

[0060] S301. When the guest room corresponding to the guest room identifier has at least two wireless access points deployed, the at least two wireless access points shall be identified as the target set of wireless access points.

[0061] The target wireless access point set refers to the logical combination of multiple wireless access points deployed in the same guest room to provide seamless WiFi coverage for the guest room.

[0062] The server performs this step when identifying the target wireless access point. Specifically, the server first queries its network asset management database to obtain information on all deployed wireless access points within the room based on the room identifier, including the MAC address, IP address, and location information of each access point. When multiple wireless access points are found in the room, the server integrates their information to form a target wireless access point set. All wireless access points in this set will be managed uniformly to provide WiFi service to the room.

[0063] S302. Based on the first binding relationship, the virtual network identifier is sent to each wireless access point in the target wireless access point set;

[0064] The server executes this step after determining the target set of wireless access points. Specifically, the server first finds the virtual network identifier corresponding to the current guest room identifier through the first binding relationship. Then, the server iterates through each wireless access point in the target set, sending the virtual network identifier as a configuration parameter to each wireless access point via a network management protocol or API interface. The server waits and confirms that each wireless access point has successfully received and applied the configuration to ensure that the network environment configuration of the entire guest room is consistent.

[0065] S303. Based on the guest room identifier, construct the target set of wireless access points into a roaming domain within the guest room;

[0066] Among them, the roaming domain refers to a logically interconnected group of wireless access points that supports seamless roaming of client devices between the wireless access points within the group;

[0067] The server executes this step after issuing the virtual network identifier. Specifically, the server first assigns a unique roaming domain identifier to the target set of wireless access points within the guest room. Then, the server issues this roaming domain identifier, along with necessary roaming parameters (such as roaming trigger conditions, handover thresholds, etc.), to all wireless access points in the set. Upon receiving the configuration, each wireless access point establishes a communication channel with each other, preparing for subsequent roaming control message exchange. Through this roaming domain within the guest room, when client devices move within the guest room, they can smoothly switch between different wireless access points, maintaining network connectivity continuity.

[0068] Optionally, the server can employ a distributed roaming control approach. The server configures a neighbor table for each AP in the target wireless access point set, containing information such as the MAC address, channel, and load of other APs. The server enables the 802.11k radio resource measurement protocol, allowing APs to collect information about surrounding APs. The server configures the 802.11r fast roaming protocol, enabling clients to quickly authenticate and switch between APs. Each AP directly exchanges roaming control messages via multicast or P2P channels.

[0069] It is understandable that other methods can be used to build roaming domains within guest rooms, such as through SDN controllers, proprietary roaming protocols, etc., which are not limited here.

[0070] S304. When the client device first accesses a wireless access point in the roaming domain of the guest room, the accessed wireless access point is identified as the first wireless access point, and the remaining wireless access points in the roaming domain of the guest room are identified as the second wireless access points.

[0071] The first access refers to the first time a client device establishes a wireless connection with any wireless access point within the roaming domain after entering a guest room; the first wireless access point refers to the wireless access point that the client device is currently actually connected to, serving as the primary service node for the client device; the second wireless access point refers to other wireless access points within the roaming domain besides the first wireless access point, serving as potential roaming target nodes.

[0072] The server performs this step when a client device first connects to the guest room WiFi network. Specifically, when the client device scans the SSID of any wireless access point within the roaming domain and initiates a connection request, the server receives a new client access event reported by that access point. The server immediately marks that access point as the first wireless access point and updates its status in the internally maintained guest room roaming domain topology. Simultaneously, the server marks other wireless access points in the guest room roaming domain as second wireless access points; these access points will serve as candidate targets for the client device's subsequent roaming.

[0073] It is understandable that other methods can be used to determine and manage the role of wireless access points, such as distributed caching, message buses, etc., which are not limited here.

[0074] S305. Based on the first wireless access point, generate roaming context information for the client device, the roaming context information including the aforementioned client identifier and the corresponding virtual network identifier; synchronize the roaming context information to the second wireless access point;

[0075] Roaming context information refers to a set of various status information and configuration parameters required to support smooth switching of client devices between different wireless access points, including client identifiers, virtual network identifiers, security keys, QoS parameters, etc.; synchronization means copying and distributing the roaming context information to all second wireless access points to ensure that they have the necessary information to receive roaming clients.

[0076] The server performs this step after determining the first and second wireless access points. Specifically, the server first collects all necessary information related to the client device from the first wireless access point, including authentication status, encryption key, QoS configuration, etc. Then, the server packages this information together with the client identifier and virtual network identifier to form complete roaming context information. Next, the server sends this context information to all second wireless access points through the in-room roaming domain transmission mechanism. Each second wireless access point, upon receiving the information, stores it in its local cache and sends an acknowledgment message to the server.

[0077] Optionally, the server can employ a distributed synchronization approach. The server creates a dedicated context information channel within the Redis cluster. The server serializes client information collected from the first wireless access point and publishes it to this channel. All second wireless access points, acting as subscribers, receive context updates in real time. The server uses Redis's transaction mechanism to ensure atomic updates of the context information. The server periodically checks the context information version number of each access point to ensure synchronization consistency.

[0078] It is understandable that other methods can be used to generate and synchronize roaming context information, such as through P2P protocols, blockchain, etc., which are not limited here.

[0079] S306. Receive the raw data frame from the client device, encapsulate the raw data frame in a virtual tunnel message with the virtual tunnel endpoint, and send the virtual tunnel message to the wireless controller.

[0080] The original data frame refers to the original 802.11 wireless data packet sent by the client device, which contains information such as the source MAC address, destination MAC address, and data payload; the virtual tunnel message refers to a new data packet with encapsulation header information such as virtual network identifier added to the outside of the original data frame, which is used to transmit virtual network data on the physical network.

[0081] The server executes this process when a client device transmits data through a wireless access point. Specifically, when the wireless access point receives a raw data frame from a client device, it first forwards it to the server. The server checks the source MAC address of the data frame to confirm that it belongs to an authenticated client device. Then, the server constructs a virtual tunnel encapsulation header based on the virtual network identifier associated with the client device. Next, the server combines the raw data frame and the encapsulation header into a virtual tunnel message and sends it to the wireless controller through a pre-established tunnel connection, where the controller performs subsequent forwarding processing.

[0082] Optionally, in some embodiments, the server may perform this step using a VXLAN tunneling method. After receiving the original data frame, the server extracts key fields from the frame header. The server constructs a VXLAN header, filling the Virtual Network Identifier (VNI) field with the VXLAN header. The server assembles the VXLAN header and the original data frame into a complete tunnel packet. The server sends the tunnel packet to the VTEP endpoint of the wireless controller via the UDP protocol.

[0083] It is understandable that other methods can be used to encapsulate and forward data frames, such as tunneling protocols like GENEVE and STT, but this is not a limitation here.

[0084] S307. Based on the second binding relationship, obtain a list of device members of other client devices belonging to the same virtual network identifier through the wireless controller;

[0085] The device member list refers to the collection of all client devices that share the same virtual network identifier, including information such as each device's MAC address, IP address, and connection status.

[0086] The server performs this step after receiving the virtual tunnel message from the client device. Specifically, the server first extracts the virtual network identifier from the received virtual tunnel message. Then, the server queries all client device information under that virtual network identifier through the management interface of the wireless controller (AC). The server compiles the query results into a device member list, which contains detailed information on all communicable devices except the sending client device.

[0087] Optionally, in some embodiments, the server may employ a real-time query method. The server sends a query request to the wireless controller via the SNMP protocol to obtain client entries for a specified virtual network identifier. The server parses the SNMP response message to extract the MAC address and status information of each client device. The server organizes this information into a standard-formatted device list and indexes it in memory for easy and fast lookup.

[0088] S308. Within a preset statistical period, monitor and count the number of virtual tunnel messages to obtain the broadcast message count value corresponding to the virtual network identifier.

[0089] The statistical period refers to the time interval for conducting traffic statistics, which is usually set to 1-5 minutes and can be adjusted according to network size and performance requirements; the broadcast message count value represents the cumulative number of broadcast or multicast data packets generated in a virtual network within a statistical period.

[0090] Optionally, in some embodiments, the statistical period can be set using the following scheme: The statistical period can be set to a dynamically adjustable time interval based on network size and performance requirements. When the network load is light (total traffic less than 1Gbps), a longer statistical period (e.g., 5 minutes) is used to reduce system overhead; when the network load is heavy (total traffic greater than 1Gbps), it automatically switches to a shorter statistical period (e.g., 1 minute) to provide more timely traffic monitoring. Simultaneously, when a sudden surge in traffic is detected (e.g., traffic increases exceeding 50% within a unit of time), the statistical period can be temporarily shortened to 30 seconds, and then restored to the original period after the traffic returns to normal.

[0091] The server continuously performs this step while processing virtual tunnel packets. Specifically, the server maintains an independent counter for each virtual network identifier. When the server processes a virtual tunnel packet, it first determines whether the packet is a broadcast or multicast type. If so, it increments the counter for the corresponding virtual network identifier. At the end of each statistical period, the server records the current count value, resets the counter to zero, and begins a new round of statistics. These statistics will be used for subsequent traffic control decisions.

[0092] Optionally, in some embodiments, the server can perform this step using a streaming processing approach. The server sends the processing events of the virtual tunnel packets to the Kafka streaming system. The server deploys a Flink job and uses a sliding time window to count the number of broadcast packets for each virtual network identifier. The server writes the statistical results to the monitoring system in real time and sets alarm thresholds. The server visualizes the statistical data using tools such as Grafana.

[0093] S309. If the broadcast message count exceeds the preset broadcast traffic threshold, within the preset suppression period, discard any subsequently received virtual tunnel messages belonging to the same virtual network identifier.

[0094] The broadcast traffic threshold refers to the maximum number of broadcast messages allowed by the system, which is usually set to 1,000-5,000 messages per minute. The specific value needs to be determined based on the network scale and application characteristics. The suppression period indicates the duration of broadcast suppression, which is usually set to 30 seconds to 5 minutes to prevent broadcast storms from having a lasting impact on the network.

[0095] Optionally, in some embodiments, the broadcast traffic threshold can be set using the following scheme: setting the broadcast traffic threshold as a combination of a base value and a dynamically adjusted value. The base threshold is set to 2000 broadcast messages per minute, while being dynamically adjusted according to the number of devices in the virtual network: for every 10 additional devices, the threshold increases by 200 messages, with a maximum of 5000 messages per minute.

[0096] Optionally, in some embodiments, the suppression period can be set using the following scheme: upon initial triggering, the suppression period is set to 30 seconds; if it is triggered again within 5 minutes after the suppression ends, the next suppression period is extended to 60 seconds, with a maximum of 5 minutes. If there is no further triggering within 24 hours, the period is reset to the initial value of 30 seconds.

[0097] The server performs this step after completing the broadcast message statistics. Specifically, the server compares the currently obtained broadcast message count with a preset broadcast traffic threshold. If the broadcast message count exceeds the threshold, the server immediately initiates a broadcast suppression mechanism. This includes recording the current timestamp and marking the virtual network identifier as entering a suppressed state within a preset suppression period. For virtual network identifiers marked as suppressed, when the server receives broadcast-type virtual tunnel messages from that virtual network, it will discard them directly without forwarding them, preventing broadcast storms and protecting the normal operation of the network.

[0098] S310. If the broadcast message count value does not exceed the preset broadcast traffic threshold, the virtual tunnel message is sent to other client devices in the device member list.

[0099] The server performs this step after checking that the broadcast message count has not exceeded the threshold. Specifically, the server first confirms that the broadcast traffic of the current virtual network is within the normal range. Then, the server queries the device member list to obtain information on all target devices that need to receive the broadcast message. Next, the server copies the virtual tunnel message multiple times and sends it to each client device in the list. The server tracks the transmission status of each message to ensure that all target devices correctly receive the broadcast data.

[0100] Optionally, in some embodiments, the server may employ a parallel forwarding approach. The server creates a thread pool to process broadcast message forwarding tasks in parallel. The server groups the device member list, assigning each group of devices to a worker thread. Within each thread, the server copies virtual tunnel messages and sends them to the devices within the corresponding group. The server uses a counter synchronization mechanism to ensure all forwarding tasks are completed.

[0101] S311. When the client device roams from the first wireless access point to the second wireless access point, it configures a virtual tunnel endpoint for the second wireless access point according to the virtual network identifier in the roaming context information.

[0102] Roaming refers to the process by which a client device switches from one wireless access point to another while maintaining a network connection.

[0103] The server executes this step when it detects a roaming request from a client device. Specifically, the server monitors the client device's signal strength and connection status to determine whether it has begun the roaming process. When it is confirmed that the client device is about to switch from the first wireless access point to the second wireless access point, the server first extracts the virtual network identifier from the roaming context information. Then, the server creates and configures a new virtual tunnel endpoint on the target second wireless access point, ensuring that it remains consistent with the original virtual network, thus guaranteeing that the client device can maintain its original network connection and communication status after roaming.

[0104] S312. Forward the remaining data frames that the first wireless access point has received but has not yet successfully delivered to the client device to the virtual tunnel endpoint of the second wireless access point.

[0105] Among them, residual data frames refer to data packets that the first wireless access point receives but has not yet been able to successfully send to the client device during the roaming process of the client device.

[0106] The server executes this step immediately after the client device completes the roaming handover. Specifically, the server first queries the first wireless access point's transmit buffer to identify all remaining data frames that have not been delivered. Then, the server reassembles these remaining data frames in their original received order and adds necessary control information. Next, the server sends these remaining data frames to the second wireless access point through a newly configured virtual tunnel endpoint. Upon receiving these remaining data frames, the second wireless access point delivers them to the client device through a newly established wireless connection, thus ensuring the continuity and integrity of data transmission.

[0107] In this embodiment, by constructing multiple wireless access points in the guest room into a unified roaming domain, encapsulating virtual tunnel messages to achieve secure communication between devices, and combining roaming context information synchronization and residual data frame forwarding mechanisms, along with a traffic suppression strategy based on broadcast message counts, the three core functions of seamless roaming, lossless data switching, and network stability assurance can be integrated within a logically isolated private network. This effectively solves the multiple technical bottlenecks of related technical solutions in large guest room multi-AP coverage scenarios, such as service interruption and data loss due to client movement, and broadcast storms easily caused by the lack of intelligent traffic management. Thus, it provides guests with a secure, convenient, stable, and efficient carrier-grade wireless network experience, comprehensively improving the service quality and competitiveness of hotel WiFi.

[0108] The server in the embodiments of this invention is described below from the perspective of hardware processing. Please refer to [link / reference]. Figure 4 This is a schematic diagram of the physical device structure of a server in an embodiment of this application.

[0109] It should be noted that, Figure 4 The server structure shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.

[0110] like Figure 4 As shown, the server includes a CPU 401, which can perform various appropriate actions and processes based on a program stored in the read-only memory ROM 402 or a program loaded from the storage section 408 into the random access memory RAM 403, such as performing the methods described in the above embodiments. The RAM 403 also stores various programs and data required for system operation. The CPU 401, ROM 402, and RAM 403 are interconnected via a bus 404. An I / O interface 405 is also connected to the bus 404.

[0111] The following components are connected to I / O interface 405: input section 406 including audio input devices, push-button switches, etc.; output section 407 including a liquid crystal display (LCD) and audio output devices, indicator lights, etc.; storage section 408 including a hard disk, etc.; and communication section 409 including a network interface card such as a LAN (Local Area Network) card, modem, etc. Communication section 409 performs communication processing via a network such as the Internet. Drive 410 is also connected to I / O interface 405 as needed. Removable media 411, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 410 as needed so that computer programs read from them can be installed into storage section 408 as needed.

[0112] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing computer programs for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 409, and / or installed from removable medium 411. When the computer program is executed by CPU 401, it performs the various functions defined in the present invention.

[0113] It should be noted that specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0114] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. Each block in a flowchart or block diagram may represent a module, program segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those shown in the drawings.

[0115] Specifically, the server in this embodiment includes a processor and a memory. The memory stores a computer program. When the computer program is executed by the processor, it implements the method for constructing a private guest room network based on a WiFi system provided in the above embodiment.

[0116] In another aspect, the present invention also provides a computer-readable storage medium, which may be included in the server described in the above embodiments; or it may exist independently and not assembled into the server. The storage medium carries one or more computer programs that, when executed by a processor of the server, cause the server to implement the method for constructing a private guest room network based on a WiFi system provided in the above embodiments.

[0117] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

[0118] As used in the above embodiments, depending on the context, the term "when..." can be interpreted as meaning "if...", "after...", "in response to determining...", or "in response to detecting...". Similarly, depending on the context, the phrase "when determining..." or "if (the stated condition or event) is interpreted as meaning "if determining...", "in response to determining...", "when (the stated condition or event) is detected", or "in response to detecting (the stated condition or event)".

[0119] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.

Claims

1. A method for constructing a private network in a guest room based on a WiFi system, applied to a server of a WiFi system, wherein the WiFi system further includes a wireless controller and wireless access points deployed in the guest room, characterized in that, include: When a check-in event trigger signal containing a room identifier is received, a unique virtual network identifier is generated for the room identifier, and a first binding relationship is established between the room identifier and the virtual network identifier; Based on the guest room identifier, the target wireless access point deployed in the corresponding guest room is determined; And based on the first binding relationship, the virtual network identifier is sent to the target wireless access point; The instruction specifies that the target wireless access point should configure a virtual tunnel endpoint for the virtual network identifier to construct a private network for the guest room identified by the virtual network identifier. After the client device connects to the target wireless access point and completes authentication, the media access control address of the client device is obtained and determined as the client identifier; A second binding relationship is established between the client identifier and the virtual network identifier, the second binding relationship being used to identify that the client device belongs to the guest room private network; The system receives raw data frames from the client device, encapsulates the raw data frames in a virtual tunnel message at the virtual tunnel endpoint, and sends the virtual tunnel message to the wireless controller. Based on the second binding relationship, the wireless controller obtains a list of device members belonging to the same virtual network identifier for other client devices. Send the virtual tunnel message to other client devices in the device member list; Before sending the virtual tunnel message to other client devices in the device member list, the number of the virtual tunnel messages is monitored and counted within a preset statistical period to obtain the broadcast message count value corresponding to the virtual network identifier. If the broadcast message count exceeds a preset broadcast traffic threshold, then within a preset suppression period, any subsequently received virtual tunnel messages belonging to the same virtual network identifier will be discarded.

2. The method according to claim 1, characterized in that, After configuring a virtual tunnel endpoint for the virtual network identifier at the target wireless access point to construct a guest room private network identified by the virtual network identifier, the method further includes: When a check-out event trigger signal containing the guest room identifier is received, the first binding relationship and the second binding relationship are released, and the target wireless access point is instructed to remove the virtual tunnel endpoint corresponding to the virtual network identifier, thereby destroying the guest room private network.

3. The method according to claim 1 or 2, characterized in that, Based on the guest room identifier, the target wireless access point deployed in the corresponding guest room is determined; And based on the first binding relationship, the virtual network identifier is sent to the target wireless access point, specifically including: When the guest room corresponding to the guest room identifier has at least two wireless access points deployed, the at least two wireless access points are determined as the target wireless access point set; Based on the first binding relationship, the virtual network identifier is sent to each wireless access point in the target wireless access point set.

4. The method according to claim 3, characterized in that, After the virtual network identifier is sent to the target wireless access point, the method further includes: Based on the guest room identifier, the set of target wireless access points is constructed as a roaming domain within the guest room; When the client device first connects to a wireless access point in the roaming domain of the guest room, the connected wireless access point is designated as the first wireless access point, and the remaining wireless access points in the roaming domain of the guest room are designated as the second wireless access points. Based on the first wireless access point, roaming context information of the client device is generated, the roaming context information including the aforementioned client identifier and the corresponding virtual network identifier; The roaming context information is synchronized to the second wireless access point.

5. The method according to claim 4, characterized in that, After synchronizing the roaming context information to the second wireless access point, the method further includes: When the client device roams from the first wireless access point to the second wireless access point, it configures a virtual tunnel endpoint for the second wireless access point according to the virtual network identifier in the roaming context information; The remaining data frames that the first wireless access point has received but has not yet successfully delivered to the client device are forwarded to the virtual tunnel endpoint of the second wireless access point.

6. A server for a WiFi system, characterized in that, The server of the WiFi system includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code including computer instructions, and the one or more processors call the computer instructions to cause the server of the WiFi system to perform the method as described in any one of claims 1-5.

7. A computer-readable storage medium comprising instructions, characterized in that, When the instruction is executed on the server of the WiFi system, the server of the WiFi system performs the method as described in any one of claims 1-5.

8. A computer program product, characterized in that, When the computer program product is run on the server of the WiFi system, the server of the WiFi system performs the method as described in any one of claims 1-5.