Safety protection system for engineering project management

By introducing a dual-factor authentication mechanism in the project management system, combining operation permissions and MAC permission levels, dynamically adjusting the verification frequency and quantity, the problem of login information leakage is solved, and efficient and secure access control and management is achieved.

CN120498715APending Publication Date: 2025-08-15POWERCHINA HUADONG ENG CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510470050.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The existing engineering project management system does not consider multiple authentications, and there is a risk of login information leakage.

Method used

The two-factor authentication mechanism is adopted, and the login authentication is combined with the operation permission level and the MAC permission level. The comprehensive permission level is determined through the user analysis module and the address analysis module, and the verification frequency and verification quantity are adjusted according to the comprehensive permission level, and dynamic verification is performed in combination with the historical operation log.

Benefits of technology

It significantly improves the security and management efficiency of the system, ensures the accuracy of access control, optimizes the user experience, and enhances the scalability and customizability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498715A_ABST
    Figure CN120498715A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to a safety protection system for engineering project management, which comprises an information acquisition module, a user analysis module, an address analysis module, a login authentication module and a user verification module, the login authentication module determines the operation content and the comprehensive permission level of the corresponding login user according to the operation permission level and the MAC permission level; and the user verification module determines the verification frequency and the single verification number after login according to the comprehensive authority level, determines the verification content according to the historical operation log of the login user, and determines the subsequent work according to the single verification result or the accumulated verification result. According to the system, by integrating a dual authentication mechanism, flexible user authority management, an intelligent dynamic verification strategy and an automatic risk response function, the security and management efficiency of the system are remarkably improved, the accuracy of access control is ensured, meanwhile, the user experience is optimized, and high expandability and customizability are shown.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular to a safety protection system for engineering project management. Background Art

[0002] With the rapid development of information technology and the deepening of digital transformation, security and protection systems for engineering project management have emerged. This is due to the challenges faced by traditional engineering project management models, including inefficiency, poor information sharing, and insufficient decision-making support. To address these challenges, improve project management efficiency and quality, and reduce project risks and costs, security and protection systems for engineering project management integrate advanced technologies such as big data, cloud computing, the Internet of Things, and artificial intelligence, enabling intelligent, visual, and collaborative management throughout the project lifecycle. By automatically processing massive amounts of data, this system provides real-time and accurate project progress tracking, optimized resource allocation, risk warning and response strategies, and data-driven intelligent decision support, revolutionizing engineering project management.

[0003] Chinese Patent Publication No. CN116629784A discloses an integrated university scientific research project management service system integration application platform, which relates to the field of scientific research project management technology. Among them, the vertical scientific research project module and the horizontal scientific research project module manage multiple scientific research projects from multiple dimensions; the scientific research funding module respectively handles the accounting, funding withdrawal, funding execution and early warning management of multiple scientific research project funds; the scientific research platform resource module manages and maintains scientific research personnel information and organizational structure information; the system integration module is connected to the university service hall system and the scientific research platform resource module respectively; the system integration module obtains a unified login authentication source, obtains basic information of teachers, scientific researchers and students, and applies for and approves the use of seals for scientific research business; the present invention improves the connection between various departments in the management of university scientific research projects by setting up a scientific research project business collaboration module, reduces the information island situation, and improves the rationality of scientific research project management. It can be seen that the invention has the following problems: Failure to consider multi-factor authentication of login information to confirm whether the current login is risky to avoid the possibility of information leakage. Summary of the Invention

[0004] To this end, the present invention provides a security protection system for engineering project management, which is used to overcome the problems of login risks and information leakage caused by the prior art that multiple authentication of login information is not considered.

[0005] To achieve the above objectives, the present invention provides a safety protection system for engineering project management, comprising: The information collection module includes a user information collection unit for obtaining logged-in user information and historical operation logs, and an address collection unit for obtaining the MAC address of the logged-in user; A user analysis module connected to the user information collection unit, for determining the operation authority level of the logged-in user based on the logged-in user information; An address analysis module, connected to the address collection unit, for determining a MAC permission level based on the MAC address of the logged-in user; a login authentication module, connected to the user analysis module and the address analysis module respectively, for determining the operation content and comprehensive authority level of the corresponding logged-in user according to the operation authority level and the MAC authority level; The user verification module is connected to the login authentication module and the information collection module respectively, and is used to determine the verification frequency and the number of single verifications after login according to the comprehensive authority level, and to determine the verification content according to the historical operation log of the logged-in user, and to determine the subsequent work according to the single verification result or the cumulative verification result, including: The current login status is determined based on whether a single verification result or a cumulative verification result meets the alarm protection condition, and the issuance of alarm information and data protection measures are determined based on the judgment result of the current login status, and whether the verification frequency is adjusted is determined based on whether a single verification result or a cumulative verification result meets the frequency change condition.

[0006] Furthermore, the user analysis module is preset with several user lists of operation authority levels, and is used to determine the operation authority level corresponding to the logged-in user information by matching the logged-in user information with each user list.

[0007] Furthermore, the address analysis module is preset with a plurality of MAC address lists of MAC authority levels, and is used to determine the MAC authority level corresponding to the logged-in user by matching the MAC address of the logged-in user with each MAC address list.

[0008] Furthermore, the number of operation authority levels is equal to the number of MAC authority levels.

[0009] Furthermore, the login authentication module determines the operation content of the corresponding login user according to the operation authority level and the MAC authority level, wherein: If the operation permission level is greater than the MAC permission level, the operation content of the logged-in user is determined to correspond to the operation content of the MAC permission level; If the operation authority level is lower than the MAC authority level, the operation content of the logged-in user is determined to correspond to the operation content of the operation authority level; If the operation authority level is equal to the MAC authority level, the operation content of the logged-in user is determined to include the operation content of the operation authority level and the MAC authority level.

[0010] Furthermore, the login authentication module determines a comprehensive authority level according to the operation authority level and the MAC authority level; The comprehensive authority level is the sum of the operation authority level and the MAC authority level.

[0011] Furthermore, the user verification module determines the verification frequency and the number of single verifications after login based on the comprehensive authority level; Among them, the verification frequency is positively correlated with the comprehensive authority level, and the single verification quantity is positively correlated with the comprehensive authority level.

[0012] Furthermore, the user verification module determines subsequent work based on a single verification result or cumulative verification results, including: If the single verification result or the cumulative verification result meets the alarm protection condition, the current login status is determined to be an abnormal login status, an alarm message is issued, and data protection measures are taken; If the single verification result or the cumulative verification result meets the no-alarm protection condition, the current login status is determined to be a normal login status; The alarm protection condition is that the accuracy of a single verification result is lower than a single reference value or the accuracy of a cumulative verification result is lower than an overall reference value.

[0013] Furthermore, the user verification module determines subsequent work based on a single verification result or cumulative verification results, including in the normal login state, If the single verification result or the cumulative verification result meets the frequency change condition, determining to adjust the verification frequency so that the adjusted verification frequency is higher than the verification frequency before the adjustment; If the single verification result or the cumulative verification result does not meet the frequency change condition, it is determined that the verification frequency will not be adjusted; The frequency change condition is that the accuracy of a single verification result is lower than a single preset value or the accuracy of the cumulative verification results is lower than an overall preset value; The single reference value is smaller than the single preset value; The overall reference value is smaller than the overall preset value.

[0014] Furthermore, the data protection measure is to randomly replace each data with its corresponding historical data in the current login state.

[0015] Compared with the existing technology, the beneficial effect of the present invention is that the security protection system for engineering project management provided by the present invention significantly improves the security and management efficiency of the system by integrating a dual authentication mechanism (operation authority level and MAC authority level), flexible user authority management, intelligent dynamic verification strategy and automated risk response function, ensures the accuracy of access control, and optimizes the user experience, showing a high degree of scalability and customizability.

[0016] Furthermore, the design of the user analysis module and the address analysis module brings significant beneficial effects such as refined permission control, enhanced security, clear permission division, flexible configuration capabilities, efficient permission management and promotion of compliance.

[0017] Furthermore, the login authentication module achieves fine-grained management of user permissions and flexible security control by introducing comprehensive permission levels and determining the verification frequency and number of single verifications based on them. This not only enhances the security of the system, but also improves the user experience and the system's configurability and scalability.

[0018] Furthermore, the user verification module achieves strict monitoring of user login behavior by setting single preset values, overall preset values, single reference values and overall reference values: when the verification result meets the frequency change conditions but does not meet the alarm protection conditions, the system automatically adjusts the verification frequency to enhance security; if the alarm protection conditions are further met, it is determined to be an abnormal login and an immediate alarm is issued and data protection measures are taken; this dynamic adjustment and timely response mechanism not only effectively improves the system's sensitivity to potential security threats, but also ensures the minimization of information leakage risks, providing a solid guarantee for the organization's information security. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 A connection diagram of a security protection system for engineering project management according to an embodiment of the present invention; Figure 2 This is a workflow diagram of a security protection system for engineering project management according to an embodiment of the present invention; Figure 3 This is a flowchart of a user verification module according to an embodiment of the present invention determining subsequent work based on a single verification result or cumulative verification results. DETAILED DESCRIPTION

[0020] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are merely used to explain the present invention and are not intended to limit the present invention.

[0021] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0022] It should be noted that, in the description of the present invention, terms such as "up", "down", "left", "right", "inside", and "outside" indicating directions or positional relationships are based on the directions or positional relationships shown in the accompanying drawings. This is only for the convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it cannot be understood as a limitation on the present invention.

[0023] Furthermore, it should be noted that, in the description of the present invention, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; mechanical connections or electrical connections; direct connections or indirect connections through an intermediate medium; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.

[0024] See also Figure 1 and Figure 2 As shown in FIG, they are respectively a connection diagram of a security protection system for engineering project management according to an embodiment of the present invention and a workflow diagram of a security protection system for engineering project management according to an embodiment of the present invention. An embodiment of the present invention provides a security protection system for engineering project management, comprising: The information collection module includes a user information collection unit for obtaining logged-in user information and historical operation logs, and an address collection unit for obtaining the MAC address of the logged-in user; A user analysis module, which is connected to the user information collection unit of the information collection module, is used to determine the operation permission level of the logged-in user based on the logged-in user information. It is understood that the operation permission level here refers to the permission level of each account. In practice, each new employee will have their own login intranet account created when they join the company; An address analysis module, which is connected to the address collection unit of the information collection module, is used to determine the MAC permission level based on the MAC address of the logged-in user. It can be understood that the MAC permission level here refers to the permission level of each client (computer). In practice, the corresponding MAC permission level is set for the computer equipped by the new employee when he or she joins the company; a login authentication module, connected to the user analysis module and the address analysis module respectively, for determining the operation content and comprehensive authority level of the corresponding logged-in user according to the operation authority level and the MAC authority level; The user verification module is connected to the login authentication module and the information collection module respectively, and is used to determine the verification frequency and the number of single verifications (i.e., the number of verification questions in each verification) after login based on the comprehensive authority level, and to determine the verification content based on the historical operation log of the logged-in user, and to determine the subsequent work based on the single verification results or the cumulative verification results, including: The current login status is determined based on whether a single verification result or a cumulative verification result meets the alarm protection condition, and the issuance of alarm information and data protection measures are determined based on the judgment result of the current login status. Also, whether to adjust the verification frequency is determined based on whether a single verification result or a cumulative verification result meets the frequency change condition, and the adjusted verification frequency is determined when it is determined that the verification frequency is adjusted.

[0025] It can be understood that the adjusted verification frequency is 1.1 times the verification frequency before adjustment to 1.3 times the verification frequency before adjustment; in implementation, it is determined according to the accuracy of the cumulative verification results, and the adjusted verification frequency = adjustment coefficient × current verification frequency × accuracy of cumulative verification results ÷ overall preset value, and the adjustment coefficient ∈ [1, 2], preferably 1.5; if the calculated adjusted verification frequency is not within the range of 1.1 times the verification frequency before adjustment to 1.3 times the verification frequency before adjustment, when the calculated adjusted verification frequency is less than 1.1 times the verification frequency before adjustment, 1.1 times the verification frequency before adjustment is taken, and when the calculated adjusted verification frequency is greater than 1.3 times the verification frequency before adjustment, 1.3 times the verification frequency before adjustment is taken; It is understood that the security protection system for engineering project management provided by the present invention effectively enhances system security by combining the user's operational permission level and the client's (MAC address) permission level for dual authentication. This multi-factor authentication mechanism enables more precise control of access rights to reduce the risk of unauthorized access. The system supports dynamic adjustment of user operational permission levels based on their actual roles and needs (automatically creating accounts and assigning permissions when new employees join the company), simplifying management processes and improving management efficiency. The user verification module intelligently adjusts the verification frequency and content based on the user's comprehensive permission level and historical operation logs, ensuring system security while avoiding unnecessary frequent verification. The system dynamically adjusts the verification frequency based on single or cumulative verification results and, when necessary, issues alarms and implements data protection measures. This real-time security response mechanism can quickly respond to potential security threats and protect the system from malicious attacks. By setting frequency change conditions and alarm protection conditions, it automatically identifies and responds to high-risk behaviors, effectively managing security risks and reducing the possibility of security incidents. The entire system, from user login, permission allocation, verification policy adjustment, to alarm protection, is highly automated, reducing manual intervention and improving management efficiency and accuracy.

[0026] Specifically, the user analysis module presets a user list with several operation permission levels, and is used to determine the operation permission level corresponding to the logged-in user information by matching the logged-in user information with each user list; Among them, the higher the operation authority level, the more content that can be operated.

[0027] It is understandable that the number of operation authority levels is ≥2.

[0028] In one implementation, there are three levels of operating authority, including level one operating authority, level two operating authority, and level three operating authority, wherein the operable content of level one operating authority is less than the operable content of level two operating authority and less than the operable content of level three operating authority; in one implementation, the operable content of level one operating authority only includes viewing and downloading public files (non-confidential files), the operable content of level two operating authority includes viewing, downloading, modifying, uploading public files (non-confidential files) and viewing and downloading confidential files, and the operable content of level three operating authority includes viewing, downloading, modifying, uploading public files (non-confidential files) and viewing, downloading, modifying, and uploading confidential files.

[0029] Specifically, the address analysis module is pre-set with a number of MAC address lists with different MAC permission levels, and is used to determine the MAC permission level corresponding to the logged-in user by matching the MAC address of the logged-in user with each MAC address list; Among them, the higher the operation authority level, the more content that can be operated.

[0030] Specifically, the number of operation authority levels is equal to the number of MAC authority levels, and the operable contents corresponding to each level are also the same.

[0031] It can be understood that the number of MAC authority levels = the number of operation authority levels ≥ 2.

[0032] It can be understood that there are three levels of operation authority, including level one operation authority, level two operation authority and level three operation authority, where the operable content of level one operation authority is less than the operable content of level two operation authority and less than the operable content of level three operation authority; then there are also three levels of MAC authority, including level one MAC authority, level two MAC authority and level three MAC authority, where the operable content of level one MAC authority is less than the operable content of level two MAC authority and less than the operable content of level three MAC authority; It can be understood that the corresponding operable content at each level is also the same, that is, the operable content of the first-level operation authority is the same as the operable content of the first-level MAC authority, the operable content of the second-level operation authority is the same as the operable content of the second-level MAC authority, and the operable content of the third-level operation authority is the same as the operable content of the third-level MAC authority; in one implementation, the operable content of the first-level MAC authority only includes viewing and downloading public files (non-confidential files), the operable content of the second-level MAC authority includes viewing, downloading, modifying, uploading public files (non-confidential files) and viewing and downloading confidential files, and the operable content of the third-level MAC authority includes viewing, downloading, modifying, uploading public files (non-confidential files) and viewing, downloading, modifying, and uploading confidential files.

[0033] It is understandable that the system has achieved refined permission control for users and clients by presetting different levels of operation permission levels and MAC permission levels. This hierarchical management not only ensures the security of sensitive data and key operations, but also improves the flexibility and adaptability of the system, and can assign corresponding permissions according to the needs and roles of different users or clients; by matching the logged-in user information with the preset user list, and matching the logged-in user's MAC address with the preset MAC address list, the system can accurately identify the user's identity and the client's permission level, thereby effectively preventing unauthorized access and malicious operations. This dual authentication mechanism significantly enhances the security of the system; the system supports based on actual The system can adjust the number of permission levels and the corresponding operational content as needed. This flexible configuration capability enables the system to adapt to different application scenarios and changing needs (for example, as the company expands or the business scope expands, new permission levels can be added or the operational content of existing permissions can be modified); through the automated permission matching and verification process, the system can efficiently manage user permissions, which not only reduces the administrator's workload, but also improves the accuracy and timeliness of permission management. Administrators can easily monitor and manage user permission usage to ensure the safe and stable operation of the system; by restricting access to sensitive data and modification permissions, the system can reduce the risk of illegal operations and protect the company's reputation and interests.

[0034] Specifically, the login authentication module determines the operation content of the corresponding login user according to the operation authority level and the MAC authority level, wherein: If the operation permission level is greater than the MAC permission level, the operation content of the logged-in user is determined to correspond to the operation content of the MAC permission level; If the operation authority level is lower than the MAC authority level, the operation content of the logged-in user is determined to correspond to the operation content of the operation authority level; If the operation authority level is equal to the MAC authority level, the operation content of the logged-in user is determined to include the operation content of the operation authority level and the MAC authority level.

[0035] It is understandable that a company / institution / social group has its own internal employee network for employees to log in and operate, and the MAC address of each employee's commonly used login terminal (computer) should be the same, that is, each employee's operating permission level should be the same as the MAC permission level of the login terminal he uses.

[0036] In implementation, if the operation permission level is greater than the MAC permission level, in order to prevent the login information of the high operation permission level from being misused and causing internal information leakage, even if the account uses a computer with a low MAC permission level to log in to the account with a high operation permission level, it can only perform operations corresponding to the MAC permission level; if the operation permission level is lower than the MAC permission level, in order to prevent the login information of the low operation permission level from wanting to perform operations through a computer with a high MAC permission level and causing internal information leakage, even if the account uses a low operation permission level to log in to a computer with a high MAC permission level, it can only perform operations corresponding to the low operation permission level.

[0037] During implementation, the login authentication module effectively limits the user's operation scope by comparing the operation permission level and the MAC permission level. This dual verification mechanism greatly enhances the security of the system, prevents high-privilege accounts from being abused or low-privilege accounts from attempting to illegally elevate permissions, thereby reducing the risk of internal information leakage; in environments that require strict compliance with information security and compliance requirements (such as financial institutions, government agencies, etc.), the login authentication module helps ensure that all user operations comply with established security standards and policies, and promotes organizational compliance.

[0038] Specifically, the login authentication module determines the comprehensive authority level according to the operation authority level and the MAC authority level; The comprehensive authority level is the sum of the operation authority level and the MAC authority level.

[0039] It can be understood that if there are three levels of operation authority levels and three levels of MAC authority levels, then the value range of the comprehensive authority level is: 2≤comprehensive authority level≤6.

[0040] Specifically, the user verification module determines the verification frequency and the number of single verifications after login based on the comprehensive authority level; Among them, the verification frequency is positively correlated with the comprehensive authority level, and the single verification quantity is positively correlated with the comprehensive authority level.

[0041] It is understandable that the higher the comprehensive authority level, the more corresponding operations it corresponds to. Therefore, user verification is required after a single account login to prevent account information from being stolen and to avoid internal information leakage; it is understandable that several verifications can be performed after a single account login.

[0042] Generally, 1 verification frequency every 5 minutes ≤ 1 verification frequency every 30 minutes, 2 ≤ the number of single verifications ≤ 10; Preferably, (1) if the comprehensive authority level is ≤0.4×(the number of operation authority levels + the number of MAC authority levels), it is determined that no verification is performed; (2) if the comprehensive authority level is ≤0.5×(the number of operation authority levels + the number of MAC authority levels), the verification frequency is once every 30 minutes, and the number of single verifications is 2; (3) if the comprehensive authority level is ≤0.8×(the number of operation authority levels + the number of MAC authority levels), the verification frequency is once every 20 minutes, and the number of single verifications is 4; (4) if the comprehensive authority level is greater than 0.8×(the number of operation authority levels + the number of MAC authority levels), the verification frequency is once every 15 minutes, and the number of single verifications is 6.

[0043] It is understandable that the security of the system is significantly improved by introducing comprehensive authority levels and determining the verification frequency and number of single verifications after login accordingly; among them, users with high comprehensive authority levels face more frequent verifications and more single verifications, which greatly reduces the risk of account theft or internal information leakage; the verification strategy that dynamically adjusts the verification frequency and number of single verifications according to the comprehensive authority level not only ensures the security of high-authority accounts but also avoids unnecessary interference with low-authority accounts. This differentiated processing enables the system to run more efficiently.

[0044] See also Figure 3 As shown, it is a flow chart of the user verification module according to an embodiment of the present invention determining subsequent work based on a single verification result or cumulative verification results. Specifically, the user verification module determines subsequent work based on a single verification result or cumulative verification results, including: If the alarm protection conditions are met according to the single verification result or the cumulative verification result, the current login status is determined to be an abnormal login status, an alarm message is issued to the preset address, and data protection measures are taken; If the alarm protection condition is not met according to the single verification result or the cumulative verification result, the current login state is determined to be a normal login state; The alarm protection condition is that the accuracy of a single verification result is lower than a single reference value or the accuracy of a cumulative verification result is lower than an overall reference value.

[0045] It can be understood that the preset address is a MAC login terminal (computer) with the same MAC authority level and an account with a higher operation authority level. If the operation authority level is already the highest level, an alarm message will be sent to the account with the same operation level.

[0046] In implementation, generally, 50%≤single reference value≤90%, 50%≤overall reference value≤80%; preferably, single reference value=60%, overall reference value=70%.

[0047] Specifically, the user verification module determines subsequent work based on a single verification result or cumulative verification results, including in the normal login state, If the single verification result or the cumulative verification result meets the frequency change condition, determining to adjust the verification frequency so that the adjusted verification frequency is higher than the verification frequency before the adjustment; If the single verification result or the cumulative verification result does not meet the frequency change condition, it is determined that the verification frequency will not be adjusted; The frequency change condition is that the accuracy of a single verification result is lower than a single preset value or the accuracy of the cumulative verification results is lower than an overall preset value. The single reference value is smaller than the single preset value; The overall reference value is smaller than the overall preset value.

[0048] In implementation, generally, 90%<single preset value<100%, 85%<overall preset value<95%; preferably, single preset value=95%, overall preset value=90%.

[0049] It can be understood that, the larger the values of the single reference value, the single preset value, the overall reference value and the overall preset value, the greater the ability to prevent information leakage.

[0050] It can be understood that the user verification module achieves strict monitoring of user login behavior by setting single preset values, overall preset values, single reference values and overall reference values: when the verification result meets the frequency change conditions but does not meet the alarm protection conditions, the system automatically adjusts the verification frequency to enhance security; if the alarm protection conditions are further met, it is determined to be an abnormal login and an immediate alarm is issued and data protection measures are taken; this dynamic adjustment and timely response mechanism not only effectively improves the system's sensitivity to potential security threats, but also ensures the minimization of information leakage risks, providing a solid guarantee for the organization's information security.

[0051] Specifically, the data protection measure is to randomly replace each data with its corresponding historical data in the current login state.

[0052] During implementation, historical operation logs of a preset number of logins are obtained, and the content of the single verification question is determined based on the historical operation logs.

[0053] In implementation, the problem is to determine the operation content recorded in the historical operation log (such as modifying **, publishing **, viewing **, downloading ** and modifying ** data, etc.); in implementation, only the historical operation logs of the preset number of logins are taken, generally the historical operation logs of the last 3 to 10 logins are taken, and the historical operation logs of the last 5 logins are taken first; it is understandable that if the preset number of logins is too large, the accuracy of the verification problem will increase due to individual differences (employees' own memory errors, poor current status), resulting in a lower probability of judgment errors.

[0054] It is understandable that the current login status has a known login account and a known login computer, and the corresponding historical operation log can be obtained based on the known login account; in implementation, the account owner himself and other users with the same operation authority level cannot view the account owner's historical operation log, and only users with higher operation authority levels can view the historical operation logs of lower operation authority levels; if the operation authority level is already the highest level, accounts with the same operation level can view the historical operation logs of the highest level account, but they need to have at least two accounts with the same authority operation level to verify before they can view it.

[0055] Thus far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.

[0056] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that the present invention is susceptible to various modifications and variations. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.

Claims

1. A safety protection system for engineering project management, characterized in that: include: The information collection module includes a user information collection unit for obtaining logged-in user information and historical operation logs, and an address collection unit for obtaining the MAC address of the logged-in user; A user analysis module connected to the user information collection unit, for determining the operation authority level of the logged-in user based on the logged-in user information; An address analysis module, connected to the address collection unit, for determining a MAC permission level based on the MAC address of the logged-in user; a login authentication module, connected to the user analysis module and the address analysis module respectively, for determining the operation content and comprehensive authority level of the corresponding logged-in user according to the operation authority level and the MAC authority level; The user verification module is connected to the login authentication module and the information collection module respectively, and is used to determine the verification frequency and the number of single verifications after login according to the comprehensive authority level, and to determine the verification content according to the historical operation log of the logged-in user, and to determine the subsequent work according to the single verification result or the cumulative verification result, including: The current login status is determined based on whether a single verification result or a cumulative verification result meets the alarm protection condition, and the issuance of alarm information and data protection measures are determined based on the judgment result of the current login status, and whether the verification frequency is adjusted is determined based on whether a single verification result or a cumulative verification result meets the frequency change condition.

2. The safety protection system for engineering project management according to claim 1, characterized in that: The user analysis module is pre-set with several user lists of operation authority levels, and is used to determine the operation authority level corresponding to the logged-in user information by matching the logged-in user information with each user list.

3. The safety protection system for engineering project management according to claim 1, characterized in that: The address analysis module is preset with a MAC address list of several MAC authority levels, and is used to determine the MAC authority level corresponding to the logged-in user by matching the MAC address of the logged-in user with each MAC address list.

4. The safety protection system for engineering project management according to claim 1, characterized in that: The number of the operation authority level is equal to the number of the MAC authority level.

5. The safety protection system for engineering project management according to claim 1, characterized in that: The login authentication module determines the operation content of the corresponding login user according to the operation authority level and the MAC authority level, wherein: If the operation permission level is greater than the MAC permission level, the operation content of the logged-in user is determined to correspond to the operation content of the MAC permission level; If the operation authority level is lower than the MAC authority level, the operation content of the logged-in user is determined to correspond to the operation content of the operation authority level; If the operation authority level is equal to the MAC authority level, the operation content of the logged-in user is determined to include the operation content of the operation authority level and the MAC authority level.

6. The safety protection system for engineering project management according to claim 1, characterized in that: The login authentication module determines the comprehensive authority level according to the operation authority level and the MAC authority level; The comprehensive authority level is the sum of the operation authority level and the MAC authority level.

7. The safety protection system for engineering project management according to claim 1, characterized in that: The user verification module determines the verification frequency and the number of single verifications after login based on the comprehensive authority level; Among them, the verification frequency is positively correlated with the comprehensive authority level, and the number of single verifications is positively correlated with the comprehensive authority level.

8. The safety protection system for engineering project management according to claim 1, characterized in that: The user verification module determines subsequent work based on a single verification result or cumulative verification results, including: If the single verification result or the cumulative verification result meets the alarm protection condition, the current login status is determined to be an abnormal login status, an alarm message is issued, and data protection measures are taken; If the single verification result or the cumulative verification result meets the no-alarm protection condition, the current login status is determined to be a normal login status; The alarm protection condition is that the accuracy of a single verification result is lower than a single reference value or the accuracy of a cumulative verification result is lower than an overall reference value.

9. The safety protection system for engineering project management according to claim 8, characterized in that: The user verification module determines subsequent work based on a single verification result or cumulative verification results, and also includes in a normal login state, If the single verification result or the cumulative verification result meets the frequency change condition, determining to adjust the verification frequency so that the adjusted verification frequency is higher than the verification frequency before the adjustment; If the single verification result or the cumulative verification result does not meet the frequency change condition, it is determined that the verification frequency will not be adjusted; The frequency change condition is that the accuracy of a single verification result is lower than a single preset value or the accuracy of the cumulative verification results is lower than an overall preset value; The single reference value is smaller than the single preset value; The overall reference value is smaller than the overall preset value.

10. The safety protection system for engineering project management according to claim 9, characterized in that: The data protection measure is to randomly replace each data with its corresponding historical data in the current login state.

Citation Information

Patent Citations

  • Integrated application platform of integrated college scientific research project management service system

    CN116629784A