الإصدار التجاريCommercial release · GA-20260811

نظام تشغيل شبكي احترافي بهوية مستقلة وترخيص تجاري كامل A professional networking OS with independent identity and a full commercial licence engine

ستة أجهزة مدعومة جاهزة، تحديثات OTA موقّعة Ed25519/usign، محرك ترخيص وتفعيل آلي عبر السحابة، ولوحة إدارة عربية/إنجليزية بالكامل — بدون أي أثر لعلامة تجارية خارجية. Six supported devices, Ed25519/usign-signed OTA, a cloud licence and auto-activation engine, and a fully bilingual admin center — with no third-party branding left anywhere.

5أجهزة جاهزة للتوزيعdevices ready to ship
Ed25519توقيع الترخيص والتحديثlicence + update signing
AR / ENلوحة إدارة كاملةfull admin center
0 →تفعيل آلي بلا تدخلhands-off activation
الترخيص مفعّلLicense active الحالة: مفعّل · مدى الحياةStatus: activated · Lifetime
stage 0
الحرارةTemp
68°C
طبيعية (< 80°C)Normal (< 80°C)
الذاكرةMemory
56 MB
118 MB
العملاءClients
6
Wi-Fi
OTA
usign

لقطة حقيقية من مركز الإدارة بعد التفعيل — الشريط الأخضر يعني ترخيصاً دائماً. A real Admin Center state after activation — the green banner means a perpetual licence.

القدراتCapabilities

لماذا nysiaa-OSWhy nysiaa-OS

منصّة واحدة لكل العتاد المدعوم: هوية، أمان، إدارة، وترخيص تجاري. One platform across every supported board: identity, security, management and commercial licensing.

هوية مستقلة كاملةFull independent identity

اسم الجهاز والإصدار والشعار وسجلات النظام كلها بهوية nysiaa-OS، وتُحدَّد من اللوحة نفسها (board-first) فلا تظهر تسمية خاطئة عند نقل الإعدادات. Device label, version, branding and logs all carry the nysiaa-OS identity, resolved board-first so a migrated config can never mislabel the unit.

تحديثات OTA موقّعةSigned OTA updates

كل إصدار موقّع ومُتحقَّق ببصمة الملف قبل التثبيت، وقناة كل جهاز منفصلة تماماً — لا فلاش متبادل بين اللوحات. Every release is signed and checksum-verified before install, with a separate channel per device — no cross-flashing between boards.

محرك ترخيص تجاريCommercial licence engine

مراحل تجربة (30/90 يوماً) بعدّاد موقّع HMAC، ثم ترخيص دائم أو باشتراك مع حدّ مقاعد، وربط الشهادة ببصمة الجهاز. Trial stages (30/90 days) on an HMAC-signed counter, then a perpetual or subscription licence with seat limits and a certificate bound to the device fingerprint.

تفعيل آليAutomatic activation

الجهاز يطلب التفعيل بنفسه ويسحب الشهادة عند الموافقة، أو يفعّل فوراً بحساب شريك — بدون إدخال مفاتيح يدوياً في الحالة الاعتيادية. The device raises its own request and pulls the certificate on approval, or activates instantly with a partner account — no manual key entry in the normal path.

محرك Smart RFSmart RF engine

اختيار قناة تلقائي، توجيه نطاق، مساعدة تجوال، وتبديل قناة CSA دون قطع العملاء، مع حماية من أنماط غير مدعومة على الشرائح القديمة. Auto channel selection, band steering, roam assist and CSA channel switching without dropping clients, with clamps for modes older radios cannot serve.

إعداد آمن بالتراجعSafe config with rollback

كل تغيير حسّاس (VLAN، وضع لاسلكي، رفع WAN) يمر بـ Commit-Confirm مع رجوع تلقائي إذا انقطعت الإدارة — لا تفقد الوصول للجهاز. Every risky change (VLAN, wireless mode, WAN profile) goes through Commit-Confirm with automatic rollback if management drops — you never lose the device.

الأجهزة المدعومةSupported devices

الأجهزة المدعومة وإصداراتهاSupported devices and their releases

الإصدارات تُقرأ مباشرة من خادم التحديثات — ما تراه هنا هو ما يُنزَّل فعلاً. لكل جهاز إصدار خاص به: Core للنشر القياسي وPro للبيئات الاحترافية. Releases are read straight from the update server — what you see here is exactly what downloads. Each device has its own release: Core for standard deployments, Pro for professional environments.

عزل العتاد:Hardware isolation: كل صورة مخصّصة لجهازها فقط ولا تُثبَّت على لوحة أخرى. فايكوم / K2P في Breed: التخطيط 斐讯 (0xA0000) فقط — الافتراضي 0x50000 لا يُقلع. Xiaomi CR6607 في PandoraBox: ارفع firmware.bin — ملف التحديث العادي لا يُقلع من صفحة الاسترداد. Qihoo 360T7 من QWRT: ملف التثبيت الأول .bin — صفحة U-Boot fail.html ترفض صورة التحديث .itb. 360 T7 Lite (لوحة 360,t7 / 108M): ملف المصنع 108M أولاً ثم طبقة التحديث — ليست صورة Qihoo 360T7. Each image is for its own device and will not install on a different board. Phicomm K2P already in Breed: layout 斐讯/phicomm (0xA0000) only — Breed default 0x50000 will not boot. Xiaomi CR6607 in PandoraBox: upload firmware.bin — the ordinary update file will not boot from the recovery page. Qihoo 360T7 from QWRT: use the first-install .bin — the U-Boot fail.html page rejects the .itb update image. 360 T7 Lite (board 360,t7 / 108M): use the 108M factory file first, then the overlay — not the Qihoo 360T7 image.
محاكيSimulator

محاكي واجهات مركز الإدارةAdmin Center UI simulator

تجوّل في الواجهة الحقيقية قبل الشراء: اختر الجهاز ثم تنقّل بين الصفحات. البيانات هنا تجريبية والمحاكي يعمل داخل المتصفح فقط. Walk the real interface before buying: pick a device, then move between pages. Data here is sample data and the simulator runs entirely in your browser.

192.168.1.1/nysiaa/admin/index.html
HTTPS · محليlocal
الترخيصLicensing

آلية طلب الترخيص والتفعيل الآليLicence request and automatic activation

ثلاثة مسارات معتمدة، كلها موقّعة ومربوطة ببصمة الجهاز — والمفتاح الخاص لا يترك الخادم أبداً. Three supported paths, all signed and bound to the device fingerprint — the private key never leaves the server.

1

طلب من الجهازRequest from the device

من مركز الإدارة → الترخيص → «إرسال طلب تفعيل». يُفتح طلب في السحابة، وعند الموافقة يسحب الجهاز الشهادة ويصبح مفعّلاً تلقائياً. Admin Center → License → “Send activation request”. A cloud request opens; on approval the device pulls its certificate and activates itself.

2

الحساب الموثّقCertified account

من أداة admin nysiaaOS 4.0: سجّل دخول حسابك الموثّق. كل تفعيل يخصم من سقف مقاعد رقمي واحد. لا تفعيل من أدوات أقدم ولا بكلمة مرور المحفظة القديمة. From admin nysiaaOS 4.0: sign in with your certified account. Every activation deducts from one numeric seat quota. Older tools and legacy wallet passwords cannot activate.

3

مفتاح مباشرDirect key

للبيئات المغلقة: يُلصق مفتاح موقّع في صفحة الترخيص ويُطبَّق دون إنترنت، مع تحقق محلي من التوقيع. For closed environments: paste a signed key into the licence page and apply it offline, with local signature verification.

طلب ترخيص تجاريRequest a commercial licence

يُفتح لك تذكرة لدى فريق الترخيص. لا يستهلك هذا الطلب أي مقعد ولا يُصدر مفتاحاً تلقائياً. This opens a ticket with the licensing team. It consumes no seat and issues no key automatically.

تتبّع حالة التفعيلTrack activation status

أدخل الرقم التسلسلي الظاهر في صفحة الترخيص على الجهاز. Enter the serial shown on the device licence page.

الأمان:Security: الشهادة موقّعة Ed25519 ومربوطة ببصمة الجهاز ورقمه التسلسلي، والمقاعد محدودة على مستوى المفتاح مع سجل تدقيق لكل تفعيل. المفتاح الخاص للترخيص يبقى على الخادم فقط ولا يوجد في أي صورة. Certificates are Ed25519-signed and bound to the device fingerprint and serial, seats are enforced per key, and every activation is written to an audit trail. The licence private key stays on the server and ships in no image.
الأدواتTools

تطبيق سطح المكتبDesktop Application

أداة سطح مكتب لإدارة الأجهزة في الشبكة المحلية — حتى عندما يكون عنوان الجهاز غير معروف أو خارج نطاقك. A desktop tool for managing units on the local network — even when a device IP is unknown or outside your subnet.

ما تقوم به الأداةWhat it does

  • اكتشاف — استماع mDNS على _nysiaa._tcp.local وفحص IPv4 (بوابة / .1 / .254 / ARP). الاستماع لـ MNDP/SSDP/NNDP اختياري؛ طبعات GA لا ترسل NNDP/RoMON. تغيير رنج الحاسوب يُظهر ◐ خارج نطاقك لا «غير متصل». فتح الواجهة IPv4 فقط — لا IPv6 ولا fe80. Discovery — mDNS listen on _nysiaa._tcp.local plus an IPv4 LAN probe (gateway / .1 / .254 / ARP). MNDP/SSDP/NNDP listen is optional; GA images do not send NNDP/RoMON. A different PC subnet shows ◐ off-subnet, not "offline". Opening Admin is IPv4 only — no IPv6, no fe80.
  • فحص الشبكات المحلية (بوابة، .1/.254، ARP) وبحث مباشر بالـ IP عند الحاجة. Local LAN probe (gateway, .1/.254, ARP) and direct IP search when you already know the address.
  • تعديل عنوان الإدارة وإعادة الضبط بكلمة مرور المسؤول. دفع التحديثات وتفعيل التراخيص عبر update.nysiaa.com. Edit the management address and factory-reset with the admin password. Push firmware and activate licences through update.nysiaa.com.
  • استعادة الوصول بعنوان MAC — إن كانت الوحدة تُعلن عن نفسها ولا تردّ على ARP، تضيف الأداة عنوان الحاسوب على المنفذ الموصول إن لزم وتزرع مدخل الجار بالماك المُعلن — بلا إدخال يدوي. يعود ICMP ولوحة الإدارة و SSH. الجدول يعرض هذه الحالة صريحةً: ◍ حيّ · لا يردّ ARP — لا «غير متصل». Access recovery from the MAC — when a unit announces itself yet answers no ARP, the tool adds a host address on the connected NIC if needed and plants a neighbour entry from the announced MAC — no manual addressing. ICMP, Admin and SSH come back. The table names that state outright: ◍ alive · no ARP reply, not "offline".
  • تهيئة مسار الإدارة الطارئة — أثناء اتصال IP تزرع الأداة ماك هذا الحاسوب على الجهاز. يظهر في تبويب الاسترداد كبطاقة (تفعيل/تعطيل/حظر/تثبيت دائم/حذف). بلا تثبيت دائم يُمسح عند إعادة التشغيل. Emergency path enrol — while the unit answers on IP the tool plants this PC's MAC on the device. The Recovery tab shows a card (enable/disable/block/install permanently/delete). Without a permanent install the record dies on reboot.
  • بطاقة الجهاز — اسم يدوي وموقع/عنوان ومسؤول ووسوم وملاحظات، كلها اختيارية وتُحفظ على حاسوبك ولا تُرسل إلى الجهاز، مع زر حذف للصفوف القديمة. Device card — an optional label, site/address, contact, tags and notes, kept on your workstation and never sent to the device, plus a delete button for stale rows.
  • نفق RoMON الإضطراري وكيل محلي إلى عنوان IPv4 قابل للوصول (آخر IP أو ترحيل 2222). ليست جلسة ماك فقط بلا أي عنوان — ذلك المسار غير مشحون. Emergency RoMON tunnel is a local proxy to a reachable IPv4 (last IP or relay 2222). It is not a MAC-only session with no IP assigned — that path is not shipped.

التنزيلDownload

ملف تنفيذي أصلي لـ Windows ومثبّت Inno LZMA — اكتشاف mDNS، ووسيط ترخيص من الحاسوب، وفلاش keep-settings. الإصدار 3.13.0. IPv4 فقط. A native Windows executable plus an Inno LZMA installer — mDNS discovery, PC-side licence proxy, and keep-settings flash. Version 3.13.0. IPv4 only.

الأمانSecurity

كيف تُحمى السلسلة من الخادم إلى الجهازHow the chain is protected, server to device

بناء محكوم ببواباتGated build

كل صورة تُبنى من مصدر حقيقة واحد، وتمر ببوابة تتحقق من وجود طبقة الترخيص والتفعيل ومن خلو الصورة من أي مفتاح خاص أو رمز أسطول. Every image is built from a single source of truth and passes a gate that asserts the licence/activation layer is present and that no private key or fleet token is baked in.

توقيع ونشرSigning and publishing

التوقيع يحدث على الخادم بمفتاح لا يُنسخ خارجه، وتُسجَّل بصمة الملف والحجم في بيان النشر. كل جهاز له قناة تحديث خاصة به. Signing happens on the server with a key that is never copied out, and the file digest plus size are recorded in the publish manifest. Each device has its own update channel.

تحقق على الجهازOn-device verification

عميل OTA يرفض أي حزمة توقيعها أو مجموعها الاختباري غير مطابق، ويرفض أي موديل عتاد مختلف، قبل لمس ذاكرة الفلاش. The OTA client rejects any package whose signature or checksum does not match, and any different hardware model, before it touches flash.

ترخيص مربوط بالعتادHardware-bound licence

الشهادة تحمل بصمة الجهاز ورقمه التسلسلي وحدّ المقاعد؛ نسخها إلى جهاز آخر لا يُفعّله، وكل عملية تفعيل أو سحب مفتاح تُدوَّن في سجل تدقيق. The certificate carries the device fingerprint, serial and seat limit; copying it to another unit will not activate it, and every activation or key pull is written to an audit trail.

FAQ

أسئلة متكررةFrequent questions

هل يعمل التفعيل بدون إنترنت على الجهاز؟Does activation work without internet on the device?

نعم. كثير من نقاط الوصول تُدار على شبكة معزولة، لذلك يستطيع متصفح الفني إتمام الطلب والتفعيل ثم تطبيق الشهادة محلياً على الجهاز، كما يمكن لصق مفتاح موقّع دون أي اتصال. Yes. Many access points run on an isolated network, so the technician's browser can complete the request and activation and then apply the certificate locally, and a signed key can also be pasted fully offline.

ماذا يحدث عند انتهاء فترة التجربة؟What happens when the trial ends?

يبقى الجهاز يعمل ويعرض تنبيهاً متدرجاً حسب المرحلة، مع بقاء قناة الإدارة والترخيص متاحة دائماً حتى لا يُحجب الوصول عن العميل. The unit keeps running and shows a staged notice, while the management and licensing channels always stay reachable so a customer is never locked out.

هل يمكن نقل الترخيص إلى جهاز بديل؟Can a licence move to a replacement unit?

نعم عبر Ops: يُسحب المقعد من البصمة القديمة ويُخصَّص للرقم التسلسلي الجديد، ثم يفعّل الجهاز البديل نفسه تلقائياً. Yes, through Ops: the seat is released from the old fingerprint and assigned to the new serial, then the replacement unit activates itself.

هل الصور مفتوحة للتنزيل العام؟Are images openly downloadable?

نعم، ملفات الأجهزة المدعومة متاحة للتنزيل المباشر، أما التشغيل الكامل فيتطلب ترخيصاً مفعّلاً؛ وقناة OTA الموقّعة مقصورة على الأجهزة المسجّلة. Commercial edition images are downloadable with published checksums, while full operation requires an activated licence; the signed OTA channel stays limited to enrolled devices.

LEGAL

اتفاقية ترخيص المستخدم النهائيEnd User License Agreement

هذه هي النسخة المنشورة والسارية من الاتفاقية. الموافقة عليها شرط لإصدار أي ترخيص تجاري، وتُسجَّل بصمة النسخة التي وافقتم عليها مع طلبكم. This is the published, in-force agreement. Accepting it is a condition of issuing any commercial licence, and the checksum of the version you accepted is recorded with your request.

يجري تحميل نص الاتفاقية…Loading the agreement…

يتضمّن سوفتوير nysiaaOS مكوّنات مفتوحة المصدر تخضع لرخصها الأصلية (GPL‑2.0 وغيرها)، وهي منشورة داخل الجهاز تحت /etc/nysiaa-legal/. لا تنتقص هذه الاتفاقية من حقوقكم بموجب تلك الرخص، وتنطبق حصراً على المكوّنات المملوكة لشركة نيسيا. nysiaaOS includes open-source components under their own licences (GPL-2.0 and others), published on the device under /etc/nysiaa-legal/. This agreement does not reduce your rights under those licences and applies only to Nysiaa's proprietary components.