Method for intelligently controlling hotel through optical modem
By embedding dual network cards and a hardware isolation chip in the optical modem, combined with protocol whitelisting and port isolation, a three-level permission system is established, which solves the problem of insufficient security in the integrated control solution of the optical modem, realizes the secure isolation and emergency response of hotel intelligent control, and ensures the normal operation of the equipment and data security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 新疆恒信技术服务有限公司
- Filing Date
- 2025-12-19
- Publication Date
- 2026-04-17
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In existing hotel smart control solutions, the integrated control function of optical modems has security flaws. The lack of physical isolation results in insufficient data transmission security between the guest network and the control network. Furthermore, insufficient access control and security monitoring pose risks of malware intrusion and data leakage.
Physical isolation is achieved by using a dedicated optical modem with built-in dual network cards and a hardware isolation chip. Combined with protocol whitelists, port isolation, and hierarchical permissions, a three-level permission system is established. A security protection module is integrated for triple isolation, and the system automatically switches to offline control mode in case of abnormal access, enabling security monitoring and emergency response.
It achieves physical isolation between the guest network and the control network, blocks unauthorized access, ensures the security and continuity of equipment control, reduces the risk of malicious attacks, and improves hotel operational security and privacy protection.
Smart Images

Figure CN121887455A_ABST
Abstract
Description
Technical Field
[0008] , , , , ,
[0010] ,
[0009]
[0001] The present invention belongs to the technical field of sewage treatment, and specifically relates to a method for intelligent control of hotels through a light modem. Background Art
[0002] The intelligentization of hotel rooms has become the core direction for enhancing the accommodation experience and operation efficiency. Existing hotel intelligent control solutions are mainly divided into two categories:
[0003] Traditional centralized control solution: With the room controller RCU as the core, various intelligent devices are connected to achieve local linkage. However, this solution has complex wiring, high construction costs, and the RCU needs to deploy a communication module separately, forming functional redundancy with the existing light modems and routers in the hotel, increasing the hardware procurement and maintenance costs;
[0004] Light modem integrated control solution: To solve the problem of device redundancy, some solutions propose integrating intelligent control functions into the light modem to achieve integration of network access and device control. However, this solution has a fatal security flaw: The light modem simultaneously carries data transmission for both guest networks and control networks, which is equivalent to removing the firewall between the two, lacking physical or protocol-level isolation.
[0005] When a guest's terminal device is poisoned or遭受网络攻击时, malicious software can directly invade the intelligent control system through the local area network, causing malfunctions of a large number of guest room devices, and even illegally obtaining sensitive data such as door lock status and guest check-in information, seriously threatening the hotel operation security and guest privacy. In traditional RCU or wireless gateway solutions, the control network and the guest network are physically or protocol-level isolated, which can effectively avoid such security risks.
[0006] In addition, existing light modem integrated solutions also have problems of lack of permission control and insufficient security monitoring: Guests may access control functions beyond their authority through technical means, and there is no rapid emergency response mechanism when an attack occurs, resulting in an expansion of security risks.
[0007] In view of this, the present invention is specifically proposed. Summary of the Invention
[0008] To solve the above technical problems, the basic concept of the technical solution adopted by the present invention is:
[0009] A method for intelligent control of hotels through a light modem, comprising the following steps:
[0010] Step S1: System architecture construction: A dedicated light modem is internally provided with a first network card and a second network card, and the two network cards are physically isolated through a hardware isolation chip; the first network card is connected to guest terminals through the hotel local area network, the second network card is connected to guest room intelligent devices through wired and wireless means, and the dedicated light modem establishes encrypted communication with the hotel management platform and the PMS system through the backbone network;
[0011] Step S2: Security Isolation Configuration: Enable triple isolation mechanism for the security protection module:
[0012] d. Hardware isolation: The two network cards independently occupy different PCIe channels, and the hardware isolation chip blocks direct data transmission across network cards;
[0013] e. Protocol isolation: Pre-defined whitelist of control protocols to block data from protocols not on the whitelist;
[0014] f. Port isolation: The second network card only opens the dedicated control port and closes all redundant ports. The ports of the first network card and the second network card are not mapped to each other.
[0015] Step S3: Hierarchical Access Control: Establish a three-tier access control system.
[0016] d. Guest permissions: Only allowed to access the Internet through the first network card; access to the second network card and control of the network are prohibited.
[0017] e. Operation and maintenance permissions: Secondary authentication through the hotel management platform is required to access the device status query and control functions of the second network card;
[0018] f. Administrator privileges: Possess full-function operation permissions, and operation logs are uploaded to the hotel management platform in real time for record-keeping;
[0019] Step S4: Intelligent linkage control: The intelligent control module receives the room status data from the PMS system, combines it with the environmental data collected by the sensors, triggers the preset scene linkage logic, and sends control commands to the intelligent devices through the second network card to realize local and remote control;
[0020] Step S5: Security Monitoring and Emergency Response: The security protection module monitors the data transmission status of the dual network cards in real time. When abnormal access is detected, an emergency response is immediately triggered: blocking the attack source IP, closing the corresponding port, and sending an early warning message to the hotel management platform. If the control network is subjected to continuous attacks, it automatically switches to offline control mode and maintains normal operation of the device based on locally stored logic.
[0021] As a preferred embodiment of the present invention, in step S1, the dedicated optical modem has a built-in ARM Cortex-A76 processor and a 16GB encrypted storage unit.
[0022] As a preferred embodiment of the present invention, the connection method of the smart devices in step S1 is as follows: the air conditioner controller and door lock are wired to the second network card through the RJ45 interface, and the light switch, curtain motor and sensor are wirelessly connected to the second network card through Wi-Fi or Bluetooth. The Wi-Fi signals of the guest network and the control network use different channels and encryption methods.
[0023] As a priority of the present invention, the protocol whitelist in step S2 supports custom updates. Administrators can add and delete control protocols through the hotel management platform. Update operations require dual authentication and log retention.
[0024] As a preferred embodiment of the present invention, the secondary authentication in step S3 adopts a dual authentication mode of account password and dynamic verification code. The dynamic verification code generates a log of all permission operations through the mobile terminal bound by the administrator, including the operator, operation time, operation content and device response result.
[0025] As a priority of the present invention, the preset scene linkage logic in step S4 includes at least the following: Check-in scene: In response to the door lock being legally opened, automatically start the air conditioner to the preset temperature and turn on the designated lights to the welcome mode; Sleep scene: In response to a sleep command, automatically turn off the main lighting, close the curtains, and switch the air conditioner to sleep mode; Check-out scene: In response to check-out confirmation, automatically turn off all controlled devices, lock the door, and send a notification to the cleaning system; Energy-saving scene: When the room remains unoccupied for more than 30 minutes, automatically cut off the power to non-essential devices.
[0026] As a preferred embodiment of the present invention, the predefined rules for the abnormal access behavior include: within a 1-minute time window, the number of non-whitelisted protocol access attempts detected from the same IP reaches or exceeds 3 times; within a 1-minute time window, the number of scanning behaviors on the second network card port is detected reaches or exceeds 5 times; within a 1-minute time window, the number of password verification failures against the system or device reaches or exceeds 3 times; when an emergency response is triggered, the blocking of the attack source will continue until the system administrator manually lifts it, or the system detects that the attack source has stopped attacking for more than 1 hour.
[0027] As a priority of this invention, the dedicated optical modem also has a built-in VPN encryption module. Communication with the hotel management platform uses IPsec VPN encryption, with the data encryption standard being AES-256-GCM, and the key is automatically updated every 24 hours.
[0028] As a preferred embodiment of the present invention, in the offline control mode of step S5, the intelligent control module operates based on the locally stored room status and scene logic. After the network is restored, the device status is automatically synchronized to the hotel management platform, and the operation logs during the offline period are retransmitted.
[0029] As a preferred embodiment of the present invention, the method further includes a periodic security audit step: the hotel management platform automatically generates a security audit report every week, which at least summarizes abnormal access events, all permission operation records and device control flow during the period, and can perform scanning and risk warning based on a vulnerability database.
[0030] Compared with the prior art, the present invention has the following advantages:
[0031] This invention achieves physical isolation between the customer network and the control network by integrating dual network cards and a hardware isolation chip into the optical modem, overcoming the technical bottleneck of existing optical modem solutions that lack physical isolation. It combines protocol whitelisting, port isolation, and access control to form a logical isolation system, blocking unauthorized access from three dimensions: data transmission protocol, port, and access control, thus solving the problem of insufficient protection from a single isolation method. It integrates security monitoring and emergency response into the intelligent control process, automatically switching to offline mode when an attack occurs to ensure the continuity of device control, achieving a balance between security and practicality.
[0032] The specific embodiments of the present invention will now be described in further detail with reference to the accompanying drawings. Attached Figure Description
[0033] In the attached diagram:
[0034] Figure 1 This is a flowchart of a method for intelligent hotel control via an optical modem. Detailed Implementation
[0035] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments will be clearly and completely described below with reference to the accompanying drawings. The following embodiments are used to illustrate the present invention.
[0036] A method for intelligent hotel control via an optical modem includes the following steps:
[0037] Step S1: System Architecture Setup: The dedicated optical modem has a built-in first network card and a second network card, and the two network cards are physically isolated through a hardware isolation chip; the first network card connects to the guest terminal through the hotel's local area network, and the second network card connects to the smart devices in the guest room through wired and wireless means; the dedicated optical modem establishes encrypted communication with the hotel management platform and PMS system through the backbone network.
[0038] Step S2: Security Isolation Configuration: Enable triple isolation mechanism for the security protection module:
[0039] g. Hardware isolation: The two network cards independently occupy different PCIe channels, and the hardware isolation chip blocks direct data transmission across network cards;
[0040] h. Protocol isolation: Pre-defined whitelist of control protocols to block data from protocols not on the whitelist;
[0041] i. Port isolation: The second network card only opens the dedicated control port and closes all redundant ports. The ports of the first network card and the second network card are not mapped to each other.
[0042] Step S3: Hierarchical Access Control: Establish a three-tier access control system.
[0043] g. Guest permissions: Only allowed to access the Internet through the first network card, and prohibited from accessing the second network card and controlling the network;
[0044] h. Operation and maintenance permissions: Access to the device status query and control functions of the second network card is required only after secondary authentication through the hotel management platform;
[0045] i. Administrator privileges: Possess full functional operation permissions, and operation logs are uploaded to the hotel management platform in real time for record-keeping;
[0046] Step S4: Intelligent linkage control: The intelligent control module receives the room status data from the PMS system, combines it with the environmental data collected by the sensors, triggers the preset scene linkage logic, and sends control commands to the intelligent devices through the second network card to realize local and remote control;
[0047] Step S5: Security Monitoring and Emergency Response: The security protection module monitors the data transmission status of the dual network cards in real time. When abnormal access is detected, an emergency response is immediately triggered: blocking the attack source IP, closing the corresponding port, and sending an early warning message to the hotel management platform. If the control network is subjected to continuous attacks, it automatically switches to offline control mode and maintains normal operation of the device based on locally stored logic.
[0048] Furthermore, in step S1, the dedicated optical modem has a built-in ARM Cortex-A76 processor and a 16GB encrypted storage unit. The connection method of the smart devices in step S1 is as follows: the air conditioner controller and door lock are wired to the second network card through the RJ45 interface, and the light switch, curtain motor and sensor are wirelessly connected to the second network card through Wi-Fi or Bluetooth. The Wi-Fi signals of the guest network and the control network use different channels and encryption methods.
[0049] As a priority of the present invention, the protocol whitelist in step S2 supports custom updates. Administrators can add and delete control protocols through the hotel management platform. Update operations require dual authentication and log retention.
[0050] Furthermore, in step S3, the secondary authentication adopts a dual verification mode of account password and dynamic verification code. The dynamic verification code generates a log of all permission operations through the mobile terminal bound to the administrator, including the operator, operation time, operation content, and device response result. The preset scene linkage logic in step S4 includes at least the following: Check-in scenario: In response to the door lock being legally opened, automatically start the air conditioner to the preset temperature and turn on the designated lights to welcome mode; Sleep scenario: In response to the sleep command, automatically turn off the main lighting, close the curtains, and switch the air conditioner to sleep mode; Check-out scenario: In response to check-out confirmation, automatically turn off all controlled devices, lock the door, and send a notification to the cleaning system; Energy-saving scenario: When the room remains unoccupied for more than 30 minutes, automatically cut off the power to non-essential devices.
[0051] Furthermore, the predefined rules for abnormal access behavior include: within a 1-minute time window, the number of non-whitelisted protocol access attempts detected from the same IP reaches or exceeds 3 times; within a 1-minute time window, the number of scans of the second network card port detected reaches or exceeds 5 times; within a 1-minute time window, the number of password verification failures against the system or device reaches or exceeds 3 times; when an emergency response is triggered, the blocking of the attack source will continue until the system administrator manually lifts it, or the system detects that the attack source has stopped attacking for more than 1 hour. The dedicated optical modem also has a built-in VPN encryption module, and communication with the hotel management platform uses IPsec VPN encrypted transmission. The data encryption standard is AES-256-GCM, and the key is automatically updated every 24 hours. In the offline control mode in step S5, the intelligent control module operates based on the locally stored room status and scene logic. After the network is restored, the device status is automatically synchronized to the hotel management platform, and the operation logs during the offline period are re-uploaded.
[0052] Furthermore, the method also includes a regular security audit step: the hotel management platform automatically generates a security audit report every week, which at least summarizes abnormal access events, all permission operation records and device control flow during the period, and can perform scanning and risk warnings based on a vulnerability database.
[0053] Core processor: Utilizes an ARM Cortex-A76 processor, supporting multi-threaded concurrent processing to ensure that control instructions and safety monitoring run in parallel without performance loss;
[0054] Dual NIC isolation design: It has a built-in first NIC (guest network NIC) and a second NIC (control network NIC). The two NICs independently occupy the PCIe 4.0 lane and are physically isolated through a PCIe dual-port isolation chip. The isolation latency is ≤1μs, ensuring that data cannot be directly transmitted across NICs.
[0055] Security protection module: integrates firewall chip, intrusion detection chip and encryption module, supports real-time traffic monitoring, anomaly identification and data encryption;
[0056] Storage unit: 16GB encrypted storage unit, used to store control logic, security policies, operation logs and offline operation data, with data encryption method of AES-256.
[0057] Hardware isolation: By blocking direct data interaction between the two network cards through the isolation chip, the guest network data can only be transmitted to the control network after being filtered by the security protection module of the optical modem (only whitelisted protocols are allowed), thus preventing illegal intrusion at the physical level;
[0058] Protocol isolation: A whitelist of control protocols is preset, allowing only necessary protocols such as Modbus (device control), MQTT (data transmission), and TCP / IP (restricted ports) to pass through, while automatically blocking risky protocols such as HTTP and UDP (non-control purposes) to avoid malicious protocol attacks;
[0059] Port isolation: The second network card (control network) only opens dedicated ports such as 8080 (device control) and 8883 (MQTT encrypted communication), and closes redundant ports such as 21 (FTP) and 23 (Telnet). Furthermore, the ports are not mapped to external ports to reduce attack entry points.
[0060] Access control is hierarchically divided into three levels: guest, operations and maintenance, and administrator. Guest access is limited to internet access and cannot control the network. Operations and maintenance access requires two-factor authentication through the hotel management platform using "account password + dynamic verification code" and can only perform device queries and routine control operations. Administrator access has full-function operation permissions, and all operations are logged in real time.
[0061] Authentication protection: Dynamic verification codes are generated through a dedicated APP and are valid for ≤5 minutes to prevent the verification codes from being stolen and reused; operation logs include the operator, time, content, and device response results and are retained for ≥1 year to facilitate security audits and accountability.
[0062] Data Interaction: The dedicated optical modem communicates with the PMS system and hotel management platform through an IPsec VPN encrypted channel to synchronize data such as room check-in status and check-out time in real time; environmental data collected by sensors (human body detection, temperature and humidity) is transmitted to the intelligent control module through the second network card;
[0063] Real-time monitoring: The security protection module scans the traffic data of the two network cards every 10ms, and the monitoring indicators include protocol type, port access count, IP connection status, and password verification count;
[0064] Anomaly detection: When non-whitelisted protocol access is detected ≥3 times / minute, port scan is detected ≥5 times / minute, or password verification fails ≥3 times, it is determined as abnormal access;
[0065] Emergency Response: Immediately block the attack source IP, close the corresponding port, and send an early warning message to the hotel management platform (including attack type, attack source IP, and affected port); if the attack lasts for ≥5 minutes, automatically switch to offline control mode, maintain device operation based on local storage logic, and automatically synchronize data after the network is restored;
[0066] Security Audit: The hotel management platform generates a security audit report every week, which includes statistics on abnormal access, records of authorized operations, and vulnerability scan results, allowing administrators to trace security risks.
[0067] Experiment Example 1: Security Isolation Performance Test
[0068] 1. Experimental Environment
[0069] Test group: The dedicated optical modem system (dual network card isolation) in Example 1;
[0070] Control group 1: Traditional RCU protocol (physical isolation);
[0071] Control group 2: Single network card optical modem integrated solution (no isolation);
[0072] Attack source: Simulated infected client terminals (10 units) to launch port scanning, protocol injection, and password brute-force attacks.
[0073]
[0074] The security isolation performance of this invention is on par with traditional RCU solutions, significantly better than single-NIC solutions without isolation, and achieves an attack interception rate of 100%.
[0075] Experiment Example 2: Comparison Test of Control Performance and Energy Consumption
[0076] 1. Experimental Design
[0077] Test subjects: Example 1 system (Group A), traditional RCU system (Group B), single network card optical modem system (Group C);
[0078] Test period: 30 days. Monitoring indicators include control response delay, average daily energy consumption, and equipment failure rate.
[0079] The test results are shown in the table below.
[0080]
[0081]
[0082] As can be seen from the trademark, this invention is superior to traditional solutions in terms of control response speed and energy consumption optimization, and has a lower failure rate.
Claims
1. A method for hotel intelligent control through an optical cat, characterized in that, Includes the following steps: Step S1: System Architecture Setup: The dedicated optical modem has a built-in first network card and a second network card, and the two network cards are physically isolated through a hardware isolation chip; the first network card connects to the guest terminal through the hotel's local area network, and the second network card connects to the smart devices in the guest room through wired and wireless means; the dedicated optical modem establishes encrypted communication with the hotel management platform and PMS system through the backbone network. Step S2: Security Isolation Configuration: Enable triple isolation mechanism for the security protection module: a. Hardware isolation: The two network cards independently occupy different PCIe channels, and the hardware isolation chip blocks direct data transmission across network cards; b. Protocol isolation: Pre-defined whitelist of control protocols to block data from protocols not on the whitelist; c. Port isolation: The second network card only opens the dedicated control port and closes all redundant ports. The ports of the first network card and the second network card are not mapped to each other. Step S3: Hierarchical Access Control: Establish a three-tier access control system. a. Guest permissions: Only allowed to access the Internet through the first network card, and prohibited from accessing the second network card and controlling the network; b. Operation and maintenance permissions: Access to the device status query and control functions of the second network card is required only after secondary authentication through the hotel management platform; c. Administrator privileges: Possess full functional operation permissions, and operation logs are uploaded to the hotel management platform in real time for record-keeping; Step S4: Intelligent linkage control: The intelligent control module receives the room status data from the PMS system, combines it with the environmental data collected by the sensors, triggers the preset scene linkage logic, and sends control commands to the intelligent devices through the second network card to realize local and remote control; Step S5: Security Monitoring and Emergency Response: The security protection module monitors the data transmission status of the dual network cards in real time. When abnormal access is detected, an emergency response is immediately triggered: blocking the attack source IP, closing the corresponding port, and sending an early warning message to the hotel management platform. If the control network is subjected to continuous attacks, it automatically switches to offline control mode and maintains normal operation of the device based on locally stored logic.
2. The method for intelligent hotel control via an optical modem according to claim 1, characterized in that, In step S1, the dedicated optical modem has a built-in ARM Cortex-A76 processor and a 16GB encrypted storage unit.
3. The method for hotel intelligent control through optical cat according to claim 1, characterized in that, In step S1, the smart devices are connected as follows: the air conditioner controller and door lock are wired to the second network card via RJ45 interface, and the light switch, curtain motor, and sensor are wirelessly connected to the second network card via Wi-Fi or Bluetooth. The Wi-Fi signals of the guest network and the control network use different channels and encryption methods.
4. The method for hotel intelligent control through optical cat according to claim 1, characterized in that, In step S2, the protocol whitelist supports custom updates. Administrators can add and delete control protocols through the hotel management platform. Update operations require dual authentication and log retention.
5. The method for hotel intelligent control through optical cat according to claim 1, characterized in that, In step S3, the secondary authentication adopts a dual authentication mode of account password and dynamic verification code. The dynamic verification code generates a log of all permission operations through the mobile terminal bound by the administrator, including the operator, operation time, operation content and device response result.
6. The method for hotel intelligent control through optical cat according to claim 1, characterized in that, The preset scene linkage logic in step S4 includes at least the following: Check-in scene: In response to the door lock being legally opened, automatically start the air conditioner to the preset temperature and turn on the designated lights to welcome mode; Sleep scene: In response to a sleep command, automatically turn off the main lighting, close the curtains, and switch the air conditioner to sleep mode; Check-out scene: In response to check-out confirmation, automatically turn off all controlled devices, lock the door, and send a notification to the cleaning system; Energy-saving scene: When the room remains unoccupied for more than 30 minutes, automatically cut off the power to non-essential devices.
7. The method for hotel intelligent control through optical cat according to claim 1, characterized in that, The predefined rules for the abnormal access behavior include: within a 1-minute time window, the number of non-whitelisted protocol access attempts detected from the same IP reaches or exceeds 3 times; within a 1-minute time window, the number of scans of the second network card port detected reaches or exceeds 5 times; within a 1-minute time window, the number of password verification failures against the system or device detected reaches or exceeds 3 times; when an emergency response is triggered, the blocking of the attack source will continue until the system administrator manually lifts it, or the system detects that the attack source has stopped attacking for more than 1 hour.
8. The method for hotel intelligent control through optical cat according to claim 1, characterized in that, The dedicated optical modem also has a built-in VPN encryption module. Communication with the hotel management platform uses IPsec VPN encryption, with data encryption standard AES-256-GCM and the key is automatically updated every 24 hours.
9. A method for intelligent hotel control via an optical modem according to claim 1, characterized in that, In step S5, under offline control mode, the intelligent control module operates based on the locally stored room status and scene logic. After the network is restored, the device status is automatically synchronized to the hotel management platform, and the operation logs during the offline period are re-uploaded.
10. A method for intelligent hotel control via an optical modem according to claim 1, characterized in that, The method also includes a regular security audit step: the hotel management platform automatically generates a security audit report every week. This report summarizes at least the abnormal access events, all permission operation records and device control flow during the period, and can perform scanning and risk warnings based on the vulnerability database.