Intelligent electronic work card and data management system thereof

Through the multi-level integration of facial verification module, clock-in compliance module, behavior assessment module and permission isolation module, the deficiencies in the analysis of the correlation between identity determination and behavior trajectory in the intelligent electronic work badge system have been solved, dynamic identification of identity authenticity and behavior trajectory and hierarchical management of sensitive data access have been achieved, and the risk response and intelligent early warning capabilities of attendance management have been improved.

CN120656248AInactive Publication Date: 2025-09-16ANHUI YUANZE INTELLIGENT TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511043595.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-28
Publication Date
2025-09-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing intelligent electronic work badge system has deficiencies in identity determination and behavioral trajectory correlation analysis, making it difficult to effectively identify identity theft and unauthorized access, leading to misjudgment of attendance results and management blind spots, increasing data security and personnel management risks.

Method used

It adopts facial verification module, punch-in compliance module, behavior assessment module and permission isolation module, and realizes dynamic identification of identity authenticity and behavior trajectory and hierarchical management of sensitive data access through multi-level fusion of facial feature point comparison and time series collaborative verification of attendance behavior data, combined with device ownership determination and sensitive label trigger mechanism.

Benefits of technology

It improves the timeliness and refinement of risk response in attendance management, can reflect the types and risk levels of abnormal behaviors in multiple dimensions, and enhances intelligent early warning capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120656248A_ABST
    Figure CN120656248A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of attendance management, in particular to an intelligent electronic work card and a data management system thereof, the system comprises a face verification module, a card punching scale block, a behavior evaluation module, an authority isolation module and a risk push module, and based on collected face key point images, key point boundaries and archive standard images are compared point by point. According to the invention, through multi-level fusion of face feature point comparison and attendance behavior data and time sequence cooperative verification of card punching records and identity verification data, dynamic identification of identity authenticity and behavior track association is realized, and through combination of equipment affiliation determination and a sensitive label triggering mechanism, hierarchical management of sensitive data access is enhanced. According to the invention, the method supports the active push of abnormal operation based on the man-hour and track comprehensive discrimination process, can reflect the types and risk levels of abnormal behaviors in multiple dimensions, enhances the timeliness and refinement degree of risk response, and improves the application capability of intelligent early warning in attendance management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of attendance management, and in particular to an intelligent electronic work badge and a data management system thereof. Background Art

[0002] Attendance management primarily involves various software and hardware systems used to record, count, and manage employee or personnel attendance, absences, overtime, and other information. This field covers the development of various attendance methods based on paper sign-ins, magnetic card punching, IC cards, RFID, fingerprints, facial recognition, and smart mobile terminals. With the advancement of informatization and intelligentization, modern attendance management systems typically integrate technologies such as artificial intelligence, the Internet of Things, cloud computing, and big data analysis, achieving automated data collection, real-time monitoring, intelligent early warning, data statistical analysis, and seamless integration with corporate human resources, payroll, and other systems. This has greatly improved the efficiency and accuracy of attendance work and helped companies achieve intelligent human resources management. Among them, traditional intelligent electronic work badges and their data management systems use electronic work badges to achieve employee identity recognition, attendance punching, and data collection, and upload relevant attendance and behavior data to a data management platform, achieving efficient recording and analysis of employee attendance, working hours, and turnover information.

[0003] Existing technologies are mostly limited to the collection and statistics of attendance data in a single dimension, lacking the correlation analysis between identity determination and behavioral trajectories. In the face of scenarios such as identity theft and unauthorized access, it is difficult to achieve effective identification and dynamic management. In actual applications, common problems such as inconsistency between clock-in information and behavioral information, unclear equipment ownership, and difficulty in timely detection of abnormal operations can easily lead to misjudgment of attendance results, create management blind spots, and increase the risks of data security and personnel management. Summary of the Invention

[0004] The purpose of the present invention is to solve the shortcomings of the prior art and to propose an intelligent electronic work badge and its data management system.

[0005] In order to achieve the above objectives, the present invention adopts the following technical solution: a smart electronic work badge and its data management system, the system comprising: The face verification module compares the key point boundaries with the archival standard image based on the collected facial key point images. By comparing the image overlap area and edge density, it screens the data group that determines the identity features to be consistent and obtains the feature overlap judgment value. The punch-in compliance module analyzes the time series of the work badge punch-in records based on the feature overlap determination, determines the synchronization consistency of the punch-in data and the identity verification, compares the punch-in time sequence with the sign-in image, identifies synchronization anomaly groups, and obtains a time series consistency identifier; Based on the time sequence consistency identifier, the behavior assessment module analyzes the distribution of clock-in trajectory nodes, determines the trend of activity point changes, compares the Bluetooth log with the work time record, filters the offset nodes and integrates the data to obtain the trajectory offset distribution characteristics; The permission isolation module determines the ownership of the terminal device based on the trajectory offset distribution characteristics, analyzes the relationship between the device list and the tag level directory, identifies unauthorized sensitive access, optimizes the permission verification results and locates anomalies, and obtains sensitive access trigger marks.

[0006] The improvements of the present invention are that the feature overlap judgment amount includes facial feature comparison data, identity verification result identifier, and abnormal identification factor; the time series consistency identifier includes attendance record timestamp, data synchronization status, and abnormal punch-in mark; the trajectory offset distribution feature includes trajectory offset type, behavior pattern analysis item, and abnormal trajectory label; the sensitive access trigger mark includes sensitive behavior identification item, unauthorized access indication, and data security classification identifier.

[0007] The present invention is improved in that the face verification module includes: The key point acquisition submodule marks the positions of key feature points at the corners of the eyes, nose tip, and mouth corners based on the collected facial key point images. It combines the structural clues of the image edges, summarizes the feature contour information, and obtains the key point boundary data. The contour comparison submodule compares the key point boundary data with the structural correspondence of the archival standard image, analyzes the matching consistency of the boundary lines of each group of images, calculates the coordination of the spatial distribution of the overlapping areas, obtains the average amplitude of the structural matching difference, and obtains the contour comparison density trend; The coincidence screening submodule screens the data group with the best pairing coordination according to the contour comparison density trend, determines the similarity of the data group in structural distribution, and obtains the feature coincidence judgment value by summarizing the boundary point pairing concentration area.

[0008] The present invention is improved in that the punch-in compliance module includes: The time overlap comparison submodule analyzes the time information of the work badge punch-in record and the personnel sign-in image capture based on the feature overlap judgment quantity, compares the occurrence time of the corresponding events, determines whether there is a temporal correspondence between the two groups of events, and calculates the statistical characteristics of the temporal correspondence to obtain the time interval difference sequence; The synchronization determination submodule compares the time status of each set of work badge punching and sign-in images based on the time interval difference sequence, determines the events with inconsistent time correspondence, and counts the time matching of each data group within the specified range to obtain the time matching ratio index; The abnormal group identification submodule calculates the time and space correspondence of each group of data based on the time matching ratio indicator and the location information of each punch-in record, compares the clustering and abnormal dispersion of event distribution, and screens event groups with time and space deviation characteristics to obtain a temporal consistency identifier.

[0009] The present invention is improved in that the behavior assessment module includes: The trajectory node identification submodule analyzes the temporal sequence and spatial trajectory of the clock-in behavior based on the temporal consistency identifier, determines the continuity and correlation between each clock-in event and the previous and next locations, filters out spatial offsets or temporal anomalies between nodes, optimizes the distribution characteristics between nodes, and generates node interval distribution information; The operation record comparison submodule compares the temporal and spatial overlap of device operations and trajectory nodes in the Bluetooth operation log based on the node interval distribution information, determines the corresponding relationship between operation types and nodes, screens the association between high-frequency operation events and trajectory nodes, and obtains the corresponding structure of node operations; The trajectory feature generation submodule screens the change trends in the activity point records and working time sequences based on the node operation corresponding structure, determines the offset phenomenon and distribution status between trajectory nodes, optimizes the correlation characteristics of the trajectory sequence, and obtains the trajectory offset distribution characteristics.

[0010] The present invention is improved in that the permission isolation module includes: The device attribution identification submodule compares the trajectory offset distribution characteristics with the registration information in the device list, analyzes the device identification data of the terminal device during the data extraction behavior, determines the consistency between the device location and the operation time and space, filters out data with attribution anomalies, and obtains the attribution verification offset; The tag permission comparison submodule compares the permission requirements of the sensitive tag with the device authorization information based on the attribution verification offset, filters access data with insufficient device permissions or attribution anomalies, optimizes the permission mapping between the sensitive tag and the device, and obtains the tag access anomaly matching degree; The sensitive behavior determination submodule calculates the access frequency, device permission status and tag sensitivity of various sensitive tags in the data access log according to the tag access anomaly matching degree, and obtains the sensitive access trigger coefficient. ,Filter the behaviors of sensitive tags being frequently accessed by unauthorized devices and obtain sensitive access trigger marks.

[0011] The present invention is improved in that the system further comprises: The risk push module analyzes the frequency of isolation operations in the badge behavior overview based on the sensitive access trigger mark, compares access reminders and isolation behaviors in combination with the management review record period, screens employees who frequently perform isolation operations, and obtains abnormal operation push results; The abnormal operation push results include abnormal event entries, risk personnel lists, and management review prompt items.

[0012] The present invention is improved in that the risk push module includes: The isolation frequency analysis submodule categorizes and sorts employee isolation operation events based on the sensitive access trigger tags and the overall employee badge behavior. By counting the number of occurrences and distribution patterns of each employee's isolation operation, it determines the concentration of isolation behaviors of different employees and obtains isolation operation statistics. The tag comparison submodule calls the isolation operation statistics, combines the access event time data in the management review record book, compares the tag access reminder information with the corresponding isolation behavior, performs pairing identification based on the operation time interval, determines the association between the tag reminder and the isolation behavior, and obtains the operation association matching result; The employee screening submodule determines employees who have multiple label associations in a short period of time based on the operation association matching results, the types of labels involved in the employee isolation behavior and the frequency of their occurrence, analyzes the frequently associated behavior patterns, integrates the distribution and density information, and obtains the abnormal operation push results.

[0013] Compared with the prior art, the advantages and positive effects of the present invention are: In the present invention, by integrating the multi-level comparison of facial feature points with the attendance behavior data, and using the time-series collaborative verification of clock-in records and identity verification data, dynamic identification of the association between identity authenticity and behavior trajectory is achieved. Combined with the device ownership determination and sensitive label trigger mechanism, the hierarchical management of access to sensitive data is strengthened. Relying on the comprehensive judgment process of working hours and trajectories, it supports the active push of abnormal operations, can reflect the type and risk level of abnormal behavior in multiple dimensions, enhances the timeliness and refinement of risk response, and improves the application ability of intelligent early warning in attendance management. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 is a system flow chart of the present invention; Figure 2 This is a flowchart of the face verification module in the present invention; Figure 3 This is a flowchart of the punch-in compliance module in the present invention; Figure 4 is a flow chart of the behavior assessment module in the present invention; Figure 5 This is a flowchart of the permission isolation module in the present invention; Figure 6 This is a flow chart of the risk push module in the present invention. DETAILED DESCRIPTION

[0015] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0016] In the description of the present invention, it should be understood that the terms "length", "width", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating directions or positional relationships, are based on the directions or positional relationships shown in the accompanying drawings and are only for the convenience of describing the present invention and simplifying the description. They do not indicate or imply that the devices or elements referred to must have a specific direction, be constructed and operate in a specific direction, and therefore should not be understood as limiting the present invention. In addition, in the description of the present invention, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined. Example

[0017] See also Figure 1 The present invention provides a technical solution: a smart electronic work badge and its data management system including: The face verification module compares the key point boundaries with the archival standard images based on the collected facial key point images. By determining the area of ​​overlap in each set of images, comparing the edge density and overlap distribution range, the module selects the key overlap data set and obtains the feature overlap determination value. The punch-in compliance module analyzes the time series distribution of work badge punch-in records based on feature overlap determination, determines the synchronization between punch-in records and identity verification data, compares the time consistency of attendance punch-in occurrence times with personnel sign-in image information, identifies data groups with time and location synchronization anomalies, and obtains a time consistency identifier; The behavior assessment module analyzes the distribution of clock-in behavior trajectory nodes based on temporal consistency identification, determines the changing trend of activity point records, compares the time between Bluetooth operation logs and work time superposition records, filters data groups that have offsets between trajectory nodes, and integrates changes in activity and work time sequences to obtain trajectory offset distribution characteristics; The permission isolation module determines the terminal device attribution of data extraction behavior based on trajectory offset distribution characteristics, analyzes the correspondence between the device list and the tag-level index directory, identifies data access operations involving sensitive tags and unauthorized device behavior, optimizes permission verification results, locates anomalies, and obtains sensitive access trigger marks; The risk push module analyzes the frequency of isolation operations in the badge behavior overview within a week based on sensitive access trigger tags. Combined with the time statistics of the management review record book, it compares the tag access reminder information and the occurrence of isolation behavior, screens employees who frequently perform isolation operations, and obtains abnormal operation push results.

[0018] Feature overlap determination quantities include facial feature comparison data, identity verification result identification, and abnormal identification factors; temporal consistency identification includes attendance record timestamp, data synchronization status, and abnormal punch-in mark; trajectory offset distribution characteristics include trajectory offset type, behavioral pattern analysis items, and abnormal trajectory labels; sensitive access trigger marks include sensitive behavior identification items, unauthorized access indications, and data security classification identifications; abnormal operation push results include abnormal event entries, risk personnel lists, and management audit prompt items.

[0019] In the face verification module, the facial key point image refers to the image data containing the main feature points of the face (such as the coordinate information of the corners of the eyes, the tip of the nose, the corners of the mouth, etc.) collected through the electronic work badge or related equipment, which is used for subsequent identity verification and image analysis; the key point boundary refers to the boundary line composed of key feature points (such as the outline of the facial features) in the face image, which is used to assist in comparing the structural differences between different faces; the archival standard image refers to the standard face picture collected and archived in advance when the employee enters the system, which is used for comparison with the real-time collected image; contour comparison refers to comparing the real-time collected face boundary points with the boundary points of the archival standard image The points are analyzed for one-to-one correspondence and overlap to determine the consistency between the two; the area of ​​the image overlap region refers to the size of the area jointly covered by the two groups of facial contours after comparison, which is used to quantify the accuracy of the comparison; the edge density refers to the distribution density of feature points at the boundary of the facial image, which is a parameter reflecting the detailed degree of the image structure; the overlap distribution refers to the specific distribution of the image overlap area in the entire facial image, which helps to determine whether the key positions of the comparison are consistent; the overlap key refers to the data group whose overlap index meets the judgment standard among all the comparison groups, that is, the data group with the most reliable identity verification results.

[0020] In the clock-in compliance module, time series distribution refers to a set of time-series data formed by chronologically arranged work badge clock-in events, which is used to analyze the regularity and continuity of employee clock-in times. Time series consistency refers to the degree to which clock-in records can be synchronized with corresponding identity verification data (such as facial photography and positioning) in terms of time and sequence. Synchronous anomaly data sets refer to data sets where clock-in records do not match identity verification information in time or space, and are usually used to identify risks such as pseudo-clocking and abnormal sign-in.

[0021] In the behavior assessment module, the node distribution of the clock-in behavior trajectory refers to the distribution of nodes (i.e., the specific location / time of each clock-in) in the geographical or temporal dimensions of employees' continuous clock-in records; the activity point record refers to the location point data of employees when they move or participate in activities in the office area, which is used to restore their daily activity routes; the Bluetooth operation log refers to the operation record of the work badge interacting or communicating with other devices via Bluetooth, which is an auxiliary data source for analyzing personnel flow and interaction; the working time superposition record refers to the continuity and integrity data set of information such as employees' daily working hours and on-the-job hours; the trajectory node refers to the specific data of each time point and location point recorded in the employee attendance system, which is the basic unit for restoring the action trajectory; the offset data group refers to the data set with abnormal changes in position, time, etc. in the trajectory node sequence (such as sudden jumps or deviations from the normal path), which is used to identify abnormal behavior; the activity and working time sequence refers to the combined data set formed by all employee activity point data and corresponding working time data sorted in time, which facilitates overall behavior analysis.

[0022] In the permission isolation module, terminal device ownership refers to the identity and usage rights of the device used for data access or operation, and determines whether the device is authorized by the employee himself or the company; the equipment list refers to the details of various types of work badges, computers, mobile terminals and other equipment registered by the company for employees, which is used to verify permissions and ownership relationships; the label-level index directory refers to the labels assigned to data within the enterprise according to sensitivity levels (such as ordinary, important, confidential, etc.), and the index directory formed is used for permission management and access control; sensitive labels refer to high-sensitivity level labels assigned to data, which require strengthened access review and isolation management; positioning anomalies refer to data usage or access anomalies discovered during permission verification or behavior analysis, such as unauthorized devices accessing sensitive data.

[0023] In the risk push module, the ID card behavior overview refers to the overall record of all operations, attendance, data access and other behaviors generated by employee ID cards within a period of time (such as a week); the frequency of isolated operations refers to the number of times data access or operation behaviors are detected that need to be isolated or restricted, which is an important indicator for assessing risk levels; the management review record book refers to the process record document of company managers manually reviewing and handling employee ID card-related behaviors; label access reminder information refers to the data label access prompt or warning information automatically generated by the system, which is used to promptly remind managers to pay attention to sensitive operations; isolation behavior refers to data access or operation behavior that is identified and forcibly interrupted, restricted or isolated by the system, which is common in scenarios such as unauthorized access and frequent sensitive operations.

[0024] See also Figure 2 , the face verification module includes: The key point acquisition submodule marks the positions of key feature points at the corners of the eyes, nose tip, and mouth corners based on the collected facial key point images. It combines the structural clues of the image edges, summarizes the feature contour information, and obtains the key point boundary data. The positions of the key feature points of the corners of the eyes, the tip of the nose and the corners of the mouth are marked. First, the camera component integrated in the work badge equipment is called to capture the frontal image of the employee with an image resolution of 640×480 pixels. After the image is acquired, grayscale conversion and edge enhancement processing are performed. The area with the most obvious brightness gradient change in the entire image is extracted and framed as the candidate area of ​​the facial features. The eye area is usually distributed between the 100th and 160th rows of the image and the width is between 50 and 90 columns. Then, a contour fitting operation is performed within this range. The rising turning point of the pixel grayscale change curve is used as the reference to locate the extreme coordinate points of the outer edge of the corner of the eye. In the sample, the positions of the left and right corners of the eye are extracted, respectively (58, 122) and (104, 124). The nose tip recognition area is located in the 120th to 160th rows near the vertical midline of the image. By traversing the brightness value and edge closure index in the area, the image is identified. The largest position point confirms that the coordinates of the nose tip are (82, 144), and the corner of the mouth area is located below the 160th line of the image. The boundary of the upper and lower lips is extracted by the contour line separation algorithm, and the brightness gradient breakpoint is identified at the end and its endpoint is determined to be the position of the corner of the mouth in combination with the boundary trend. The final coordinates of the corner of the mouth are extracted as (63, 182) and (101, 183) respectively. Next, the five key points extracted above are connected by coordinate interpolation to generate the initial facial contour line, which is extended to cover the entire mandible and facial contour, and the edge detection results are superimposed to generate a complete boundary data point set. In the actual sample, the total number of key point boundary data formed in the image is 276, which are mainly concentrated in the eye, nose and lip areas of the image. The boundary data density is an average of 19 key points per 100 pixels. The contour data can be used for subsequent image comparison and identity verification.

[0025] The contour comparison submodule compares the key point boundary data with the structural correspondence of the archival standard image, analyzes the matching consistency of the boundary lines of each group of images, and calculates the coordination of the spatial distribution of the overlapping areas using the formula: ; Get the average magnitude of structural pairwise differences , we get the contour comparison density trend, where Represents the total number of data groups, Indicates the The area of ​​overlap between the boundary lines of the group images, Indicates the Edge density data for group boundaries, Indicates the The number of spatial coverage levels of the group overlap area, Indicates the archival standard image in structural benchmark pairwise differences within the groups; The key point sequences extracted from the acquired image and the standard image are matched by number. For example, the tip of the nose in the acquired image is numbered 1, the left corner of the eye is numbered 2, and the right corner of the mouth is numbered 3. These correspond to the same numbered points in the standard image. The geometric shape of the boundary direction between the key points is analyzed. The connection path of the boundary line segments is established in each group of images. The area formed by the boundary line points is called and its geometric contour is determined. Then, the degree of structural matching and the area of ​​the overlapping area are calculated for each group of images. Measured in pixels squared, edge density Measured by the number of boundary points per unit pixel length, the number of spatial coverage levels Characterize the structural hierarchy of overlapping contours between regions and the difference in structural benchmark pairing It comes from the paired offset difference between the key point contour curves of the standard image and the captured image. All parameters are normalized and then entered into the formula. Taking three sets of image data as an example, the original parameters and normalized values ​​are as follows: Group 1: Pixel 2, corresponding to the normalized value of 0.89, Points / pixel, the corresponding normalized value is 0.75, , , the normalized value is 0.68; Group 2: Pixel 2, corresponding to the normalized value of 0.95, Points / pixel, the corresponding normalized value is 0.62, , , the normalized value is 0.61; Group 3: Pixel 2, corresponding to the normalized value of 0.93, Points / pixel, corresponding to a normalized value of 0.80, , , the normalized value is 0.72; Substitute the formula into the calculation as follows: Item 1: ; Item 2: ; Item 3: ; Calculate the average of the three sets of data above: ; The results show that in the current comparison image group, the average amplitude of the structural pairing difference is 0.3677. The lower the value, the higher the spatial coordination of the structural boundary. This parameter will serve as the key basis for judging the image coincidence coordination trend. It will be used in the screening module for structural comparison optimization judgment to obtain the contour comparison density trend. The formula uniformly quantifies the three types of structural features with different dimensions and embeds them into the root structure, so that the overall calculation result is simultaneously affected by the overlapping area, edge distribution and pairing offset, effectively reflecting the comprehensive characteristics of the structural consistency between images.

[0026] The coincidence screening submodule selects the data group with the best pairing coordination according to the contour comparison density trend, judges the similarity of the data group in structural distribution, and obtains the feature coincidence judgment value by summarizing the concentrated area of ​​boundary point pairing.

[0027] The average magnitude of structural pairing differences refers to the overall parameter obtained by comparing all image groups to be analyzed, statistically analyzing the differences in each group's boundary structure pairing, and aggregating the differences through weighted averaging or ordinary averaging. It is a statistical indicator used to quantify and compare the overall similarity of boundary pairings of multiple groups of images.

[0028] Filter the data group with the best pairing coordination and judge the similarity of the data group in structural distribution. First, establish 5 groups of image pairings from the current collected image and the standard image of the employee file. Extract 5 main feature points and a complete boundary data set from each group of images, and pair the adjacent points in the two images one-to-one according to the key point correspondence rule. Then compare the coordinate positions of each group of paired images and record the horizontal and vertical offsets of the key points. In the sample, the average position offset between the five points of the corners of the eyes, the tip of the nose and the corners of the mouth in the first group of images is 7.2 pixels, 5.1 pixels for the second group, 2.4 pixels for the third group, 9.8 pixels for the fourth group, and 4.7 pixels for the fifth group. By comparison, it is found that the third group of data has the smallest offset value. Then, the concentrated distribution area of ​​the key point pairings in each group is counted. For example, in the third group, the number of pixels above 4.7 is 4.8. More than 73% of the key point pairs fall within the eyebrow and lip areas of the standard image. The total area of ​​the area is 3200 pixels², the number of key point pairs is 36 pairs, and the corresponding density is 1.125 pairs of key points per 100 pixel area, which meets the high-density matching judgment condition (greater than 1.0). Then the structural distribution similarity is judged and divided according to the structural area. If the average offset of the paired key points in the three areas of eyes, nose and lips is less than 4 pixels and the arrangement order is consistent, the structural distribution is considered to be similar. In the third group of images, the average offset of the eye area is 2.1 pixels, the nose area is 2.3 pixels, and the lip area is 1.9 pixels, all of which meet the conditions. Finally, the third group is selected from the above 5 groups as the pairing group with the best overlap. The average offset of the key points, matching density and structural distribution consistency are extracted as components to form the feature overlap judgment amount of this group of images.

[0029] See also Figure 3 , the Punch Compliance Module includes: The time overlap comparison submodule analyzes the time information of the work badge punch-in record and the personnel sign-in image capture based on the feature overlap judgment quantity, compares the occurrence time of the corresponding events, determines whether there is a temporal correspondence between the two groups of events, and calculates the statistical characteristics of the temporal correspondence to obtain the time interval difference sequence; Analyze the time information of the work badge punch-in record and the personnel sign-in image acquisition. First, extract the event label for each attendance data record, and obtain the punch-in timestamp information from the work badge database with time accuracy accurate to the second level, such as 08:29:56 on June 3, 2025. At the same time, retrieve the sign-in image acquisition time adjacent to this time period from the face recognition subsystem, such as 08:30:01 on June 3, 2025. Match the two time values ​​one by one on the time axis and generate an event pairing group. Then calculate the time interval for each group of paired data. The calculation method is to subtract the previous event time from the later event time, and record it as the time difference. For example, the time interval in this example is 5 seconds. After completing all data pairing, a list of time intervals is formed. The list is statistically summarized and the maximum time difference, minimum time difference, average time difference and standard deviation are calculated respectively. If the average time difference in a group of data is less than 10 seconds, it is judged that the time series correspondence is good. On the contrary, if the average value exceeds 30 seconds and the standard deviation is greater than 15 seconds, it is marked as a group with significant deviation. In the test example, a user punched in 6 times in one day, with time intervals of 3 seconds, 5 seconds, 7 seconds, 8 seconds, 11 seconds and 14 seconds respectively. The average time difference of this group of data is summarized as 8 seconds and the standard deviation is 3.6 seconds. Since all values ​​are within the lower limit of the set threshold, there is a clear time consistency between the user's punch-in record and the image data. All data are combined to form a complete time interval difference sequence for subsequent synchronization determination processing.

[0030] The synchronization determination submodule compares the time status of each set of work badge punch-in and sign-in images based on the time interval difference sequence, identifies events with inconsistent time correspondence, and counts the time matching of each data group within the specified range to obtain the time matching ratio index; Perform a judgment operation on each data in the time interval difference sequence, set the time matching upper limit threshold of synchronization judgment to 15 seconds, compare each group of time differences with the threshold one by one, if the time difference is less than or equal to 15 seconds, it is counted as a synchronization event, if the time difference is greater than 15 seconds, it is recorded as an asynchronous event, and then count the number of synchronization events and the total number of events in all clock-in events of the current user. For example, in the test sample, an employee clocked in a total of 8 times on June 4, 2025, with time intervals of 4 seconds, 6 seconds, 12 seconds, 9 seconds, 17 seconds, 14 seconds, 18 seconds and 5 seconds respectively, of which 6 records are less than 1 5 seconds, and 2 records are longer than 15 seconds, then the number of synchronized events is determined to be 6, and the total number of events is 8. The synchronization ratio is further calculated to be 6 / 8, or 75%. If the synchronization ratio is greater than or equal to 70%, the employee's data on that day is determined to have normal time matching. If it is lower than this ratio, it is marked as abnormal time matching. The matching ratio indicator is set to be divided into the following criteria: above 90% is "high match", 70% to 90% is "moderate match", and below 70% is "low match". In the above test, the employee's matching ratio is 75%, which is determined to be a moderate match. Finally, the complete time matching ratio indicator result is generated based on this standard.

[0031] The abnormal group identification submodule calculates the time and space correspondence of each data set based on the time matching ratio indicator and the location information of each punch-in record, compares the clustering and abnormal dispersion of event distribution, and screens event groups with time and space deviation characteristics using the formula: ; Get the timing consistency flag ,in, Indicates the number of event groups, For the Time synchronization characteristic parameters of group events, is the mean of the time synchronization characteristic parameters of all event groups, represents the standard deviation of the time synchronization characteristic parameters of all event groups, For the Position characteristic parameters of group events, is the mean of the location characteristic parameters of all event groups, For the The frequency of abnormal events of group events, is the reference frequency of abnormal events.

[0032] The temporal consistency indicator refers to a data indicator generated after analyzing multi-source data such as work badge punch-in records and personnel sign-in images, which reflects whether the punch-in events are synchronized in the two dimensions of time and location and whether there are any abnormal deviations. It is the system's comprehensive judgment result on the synchronization and deviation status of work badge punch-in and identity verification data in time and space. It is a data feature used to identify and mark abnormal synchronization in the attendance process.

[0033] Combine the spatial coordinate information of each group of events for calculation processing. The calculation content covers the matching deviation of events in the time dimension, the position offset in the spatial dimension, and the abnormal frequency in the behavioral dimension. Three types of normalized participation items are constructed in turn, corresponding to the formula 、 、 , while setting standardized reference items 、 、 、 In order to achieve a joint solution of different dimensional participants under a unified scale and obtain data scoring indicators for multi-dimensional deviations, the event group data collected in the actual scene are combined, and the indicators of each group of events are normalized and entered into the formula. A total of 5 groups of event data are set, and the parameter assignments are as follows: Group 1: , , ; Group 2: , , ; Group 3: , , ; Group 4: , , ; Group 5: , , ; Unified settings: , , , ; but: Group 1: ; ; ; total: ;; Group 2: ; ; ; total: ; Group 3: ; ; ; total: ; Group 4: ; ; ; total: ; Group 5: ; ; ; total: ; Average the totals of the five groups: ; The results show that there are obvious time offsets and abnormal behavior frequency concentrations in multiple groups of events, which collectively form a temporal consistency marker for identification. The higher the value, the greater the synchronization deviation of this group of data under the unified time and space standard. This parameter can directly participate in subsequent behavior deviation modeling and abnormal access isolation strategies.

[0034] See also Figure 4 , behavioral assessment modules include: The trajectory node identification submodule analyzes the temporal sequence and spatial trajectory of clocking-in behaviors based on temporal consistency identification, determines the continuity and correlation between each clocking-in event and the preceding and following locations, filters out spatial offsets or temporal anomalies between nodes, optimizes the distribution characteristics between nodes, and generates node interval distribution information. First, the timestamp and corresponding positioning data point of each employee punch-in record are extracted from the attendance system to form a spatiotemporal data set. Each data contains the punch-in time and the location coordinates recorded by the corresponding punch-in device in the spatial positioning. Then, the data are arranged in ascending order according to the timestamp to form a complete time sequence. The time interval and spatial coordinate offset between two adjacent punch-in records in the sequence are compared to determine whether there is a sudden jump. Node pairs with a time interval greater than 240 seconds or a spatial distance greater than 100 meters are marked as discontinuous nodes. In the test sample, in the records of an employee punching in at 09:00, 09:10, and 09:22, the time interval between the first two nodes is 10 minutes, and the position change is 18 meters. The time interval between the last two nodes is 12 minutes, but the spatial position change is 162 meters. The latter is judged as a spatial offset anomaly. The spatiotemporal continuity between all nodes is further compared. All data groups marked as temporal or spatial anomalies were screened out, and after re-adjusting and sorting the groups, the clock-in trajectory was segmented. Each segment consisted of continuous nodes, and node segment numbers were generated for each segment. The density of location points and the distribution of time intervals were further analyzed within each segment. The average spacing and average time difference of nodes in the same segment were calculated. If the average spacing was less than 20 meters and the average time difference was less than 5 minutes, the segment was determined to be a stable trajectory area. Conversely, if the spacing was greater than 50 meters or the time difference was greater than 15 minutes, it was a drifting segment. In the case of six clock-ins in a day, if the average distances between nodes were 10 meters, 12 meters, 160 meters, 14 meters, and 18 meters, respectively, and the average time differences were 3 minutes, 4 minutes, 11 minutes, 3 minutes, and 4 minutes, respectively, then the third node and the previous and next nodes constituted an abnormal segment, and the rest constituted a stable trajectory. The relationships between all segments and nodes were combined into node interval distribution information.

[0035] The operation record comparison submodule compares the temporal and spatial overlap of device operations and trajectory nodes in the Bluetooth operation log based on the node interval distribution information, determines the correspondence between operation types and nodes, screens the association between high-frequency operation events and trajectory nodes, and obtains the corresponding structure of node operations; Compare the temporal and spatial overlap of device operations and trajectory nodes in the Bluetooth operation log. First, extract each device operation record from the Bluetooth interaction log, obtain the corresponding operation device number, operation time and device positioning data, and match it with the time and position of the trajectory node. The data pairs with a time difference of less than 60 seconds and a spatial distance of less than 15 meters are defined as operation-node overlap pairs. In the test data, an employee had a total of 15 Bluetooth device interactions that day, 10 of which occurred within ±30 seconds of the clock-in node, and the position overlap range was within 10 meters, meeting the matching conditions. Then, determine the operation type for each overlap pair, such as Bluetooth door opening, access control check-in, near-field communication, etc., and encode the operation type to classify the same type of events. Summarize at the node. For example, if a node records a total of 3 Bluetooth communication events within 5 minutes, 2 of which are access control identification and 1 is near-field information reading, the node operation category is clustered as "access control-dominated". Then count the number of operation events in all nodes, and select nodes with an operation number exceeding the average value of the day as "high-frequency operation nodes". For example, an employee has 10 clocking-in nodes in a day, and a total of 21 Bluetooth operations are recorded, with an average of 2.1 times per day. Any node with an operation number greater than 3 is marked as a high-frequency node. In this example, there are 2 nodes with an operation frequency of 4 and 5 times, which meet the high-frequency standard. Finally, the spatiotemporal position, operation number and operation type of each node are combined into an operation correspondence structure to form a node operation correspondence structure.

[0036] The trajectory feature generation submodule is based on the node operation corresponding structure, screens the change trend in the activity point records and working time sequence, determines the offset phenomenon and distribution state between trajectory nodes, optimizes the correlation characteristics of the trajectory sequence, and obtains the trajectory offset distribution characteristics; Filter the changing trends in the activity point records and the working time sequence, and judge the offset phenomenon and distribution status between the trajectory nodes. First, extract all the activity points in the employee's movement trajectory in chronological order. The activity point source is the static and moving position points recorded in the positioning system every 5 minutes. Then, divide the time slices marked as "effective working time period" in the working time sequence into segments according to the same time dimension. Match the activity time period to which each node belongs according to its timestamp and perform position coincidence judgment on the activity point and node coordinates. If the distance between the node position and the activity point is within 20 meters, it is recorded as a consistent trajectory. If the distance between the two is greater than 50 meters, it is a trajectory deviation. Then, according to whether the distance between the node pair is greater than 50 meters, it is recorded as a trajectory deviation. A trajectory offset sequence is constructed by continuously being in a consistent or deviated state, and the offset segments are counted and their lengths calculated. For example, an employee has 12 trajectory nodes from 09:00 to 12:00, of which 9 nodes coincide with the activity point positions and 3 nodes are offset. The offset time period is concentrated between 10:15 and 10:45. A time cross-comparison is then performed on the working time records of the offset nodes. If no on-the-job working hours are recorded during the offset time period, the segment is marked as a non-working time offset segment. On the contrary, if there are valid working time records at the same time, it is marked as an on-the-job offset segment. The start and end times of the offset segment, node distribution density, and working time labels are combined and output, and the trajectory offset distribution characteristics are output according to the time axis.

[0037] See also Figure 5 , the permission isolation module includes: The device attribution identification submodule compares the trajectory offset distribution characteristics with the registered information in the device list, analyzes the device identification data of the terminal device during data extraction, determines the consistency between the device location and the operation time and space, filters out data with attribution anomalies, and obtains the attribution verification offset; Extract all punch-in nodes and their corresponding spatial locations and time tags from the offset features, and then extract the terminal device information registered under the name of the employee from the equipment list, where each device contains a unique device number, registrant number, authorized use range, device registration time and attribution location parameters. Then, according to the actual operation time and location information of the device in the punch-in node, a time-space correspondence judgment is made with the device attribution location information registered in the list. If the device operation time recorded in a certain data is outside the employee's authorized use time, or the operation location is more than 50 meters away from the device's registered attribution location, the device attribution is judged to be abnormal. In an actual sample, employee A registered device number is D2025A001, the authorized use time period is 08:00 to 18:00, and the attribution location is Set to the west side of the first floor of Office Building No. 3, it is recorded that the device extracted Bluetooth data at the southeast gate of Building No. 5 at 07:25. The operation time is earlier than the authorization time, and the spatial offset distance is 263 meters. Therefore, this behavior is marked as an attribution offset. All data marked as abnormal will be classified and sorted according to the device and personnel number. Then, the time offset value and spatial offset value of each abnormal data are calculated. If the time offset exceeds 15 minutes or the spatial offset exceeds 100 meters, it is set as the abnormal threshold. Finally, the attribution verification offset is calculated based on the device number, time offset value and spatial position difference. In the above example, the device offset time is 35 minutes and the offset space is 263 meters, which meets both offset conditions. Therefore, it is recorded as a high-level attribution abnormality item and the attribution verification offset is output.

[0038] The tag permission comparison submodule compares the permission requirements of sensitive tags with the device authorization information based on the attribution verification offset, filters access data with insufficient device permissions or abnormal attribution, optimizes the permission mapping between sensitive tags and devices, and obtains the tag access anomaly matching degree; Read the device number and user identity associated with each attribution offset record, extract all data entries accessed by the device in the sensitive data access log, and extract the corresponding data tags in the entries to form an access tag set. Each tag has a corresponding access level, user role level requirements, and authorized device list in the tag permission directory. Then compare the actual role level of the device user with the tag access level item by item. If the access data tag permission level is "confidential" and the device user role level is "ordinary employee", it is directly judged as insufficient permission. If the device is not in the authorized device list corresponding to the tag, it is also judged as abnormal permission access. For example, a device D2025A007 was used by employee B to access the database item "Financial Monthly Report April 2025". The data is marked with the "Confidential" label and the authorization level requirement is "Department Manager and Above", while Employee B's role level is "Ordinary Employee". Therefore, there is an access rights conflict. Combined with the fact that the spatial offset of device D2025A007 when accessing the data is 182 meters and the time offset is 27 minutes, both exceeding the set threshold standards for device attribution matching, this behavior is recorded as a double overriding operation. Subsequently, a matching rate statistical analysis is performed on all data access records under permission mismatch or attribution offset conditions, and the proportion of abnormal access behaviors in all sensitive accesses is calculated. A total of 18 sensitive data access behaviors were detected in this example, of which 6 met the aforementioned insufficient permission or attribution abnormality conditions. The calculated label access abnormality matching degree is 33.3%.

[0039] The sensitive behavior determination submodule calculates the access frequency, device permission status, and label sensitivity of various sensitive labels in the data access log based on the label access anomaly matching degree, using the formula: ; Get sensitive access trigger coefficient ,Filter the behaviors of sensitive tags being frequently accessed by unauthorized devices and obtain sensitive access trigger marks, where, represents the label sensitivity parameter, Represents the frequency of tag access, Represents the device permission level, Representative Item label path level number, Representative Item device attribution offset score, Represents the number of tags with consistent permissions in the access record. The total number of access tags.

[0040] The sensitive access trigger coefficient refers to the comprehensive behavioral intensity of sensitive tags being accessed by unauthorized or abnormally affiliated devices within a certain period of time through joint analysis and calculation of multiple parameters such as tag sensitivity, tag access frequency, device permission level, tag path level number, device ownership offset score, and the number of tags with consistent permissions. The higher the coefficient value, the greater the risk of the corresponding data access behavior in terms of sensitivity, frequency, and device authorization status. It is a direct criterion for determining whether there is a security anomaly in data access behavior and whether further security policies or reviews need to be triggered.

[0041] According to the aforementioned tag access anomaly matching degree, the access frequency of sensitive tags, the relationship between device permission level and tag sensitivity are calculated. Indicates the sensitivity parameter of the label, which is normalized according to the security level defined in the classification directory. For example, the first-level label is originally level 4, which is set to , the fourth-level label is the lowest, set to ; Indicates the frequency of the device accessing the tag. Before normalization, it is 8 times, and after normalization, it is set to ; Indicates the permission level corresponding to the device. The original permission level is 2, which is normalized to 1. ; In the label path sub-item, there are three access paths, namely L987, L931 and L722, whose path level numbers are 4, 3 and 2 respectively. The corresponding normalized values ​​are 、 、 ; The attribution offset scores of the device when accessing the tag are 0.25, 0.32 and 0.41 respectively, corresponding to 、 、 ; The number of permission consistent records is 1, that is ; The total number of label paths is 3, namely ; Substitute the above normalized parameters into the formula for actual calculation: First calculation: ; Second calculation: ; ; synthesis: ; The result shows that the sensitive access trigger coefficient of the device in this period is When the coefficient is within the upper limit of the preset trigger response interval (usually defined as ≥0.85 by experience), it can be determined that the sensitive data access behavior has the risk of superimposed attribution anomalies and permission deviations, thereby directly generating a sensitive access trigger mark for subsequent data isolation or review tasks.

[0042] See also Figure 6 , the risk push module includes: The isolation frequency analysis submodule categorizes and organizes employee isolation operation events based on sensitive access trigger tags and an overview of employee badge behavior. By counting the number of occurrences and distribution patterns of each employee's isolation operation, it determines the concentration of isolation behaviors among different employees and generates isolation operation statistics. Extract all recorded isolation operation event data from the behavior overview database, filter fields include employee number, isolation operation time, operation device number, trigger reason and corresponding data label, then group by employee number, sort events in each group in ascending order by time, count the total number of isolation operation events for each employee in a natural week, and perform cluster archiving on the time period when the operations are concentrated. For example, if an employee performs 5 isolation operations within 3 days and the operation time is concentrated between 14:00 and 15:00 every day, it is classified as "high-frequency time-concentrated behavior". Then perform coordinate comparison on the event distribution location. If 4 out of 5 isolation events in a week occur For the server room in Building 3, it is recorded as "single-area high-frequency behavior." The judgment criteria are set as follows: a total of 4 isolation operations per week is considered "frequent," 3 or more operations concentrated on a single day is considered "time-concentrated," and 3 or more operations concentrated in the same geographical location is considered "location-concentrated." If all three conditions are met, it is determined to be "concentrated high-frequency isolation behavior." For example, employee X performed 6 isolation operations in a week, 4 of which were concentrated on Wednesdays, 5 of which were performed in the east computer room of the data center, and the operation time was concentrated between 13:00 and 14:00. The three concentration criteria are met and the individual is classified as "concentrated." The operation frequency and distribution characteristics of all employees are output in a structured manner to form isolation operation statistics.

[0043] The tag comparison submodule calls the isolation operation statistics, combines the access event time data in the management review record book, compares the tag access reminder information with the corresponding isolation behavior, and identifies the pairing according to the operation time interval, determines the association between the tag reminder and the isolation behavior, and obtains the operation association matching result; All registered sensitive label access events are read from the audit log. The employee number, access time, label name, and reminder type are extracted from each record. Then, the isolation operation records under the same employee number are retrieved from the isolation operation statistics. The timestamps of the two types of events are compared. The matching threshold is set to 5 minutes. If the difference between the isolation operation time and the label access reminder time is within 5 minutes, it is marked as "time corresponding". Then, whether the label name is consistent is determined. If the label names in the two records are consistent, they are marked as "label corresponding". Events that meet both "time corresponding" and "label corresponding" conditions are classified as valid matching events. In the actual sample, employee Y accessed the label at 14:22 on July 4. For data with the ID "HR_Confidential", a reminder was issued at that time, and the isolation action was triggered at 2:25 PM. Because the time interval was 3 minutes and the tags were consistent, it was determined to be a valid matching event. The number of valid matching operations for each employee in a week was then counted. If it exceeded 3 times, it was judged to be "frequent label association". For example, employee Y had 7 isolation operations in a week, 4 of which occurred within 5 minutes of the label reminder and the tags were completely matched. The matching ratio for this employee was recorded as 57.1%. The judgment criteria were set as matching ratios ≥ 50% for "high association", 30% to 50% for "medium association", and < 30% for "low association". The process outputs the operation association matching results.

[0044] The employee screening submodule uses the operation association matching results, the types of tags involved in the employee isolation behavior, and their frequency of occurrence to identify employees who have multiple tag associations within a short period of time. It then analyzes the frequently associated behavior patterns, integrates distribution and density information, and obtains abnormal operation push results. Based on the types of labels involved in employee isolation behavior and their frequency of occurrence, employees with multiple label associations in a short period of time are identified. The number of label types involved and the number of visits to each label for each employee with a high matching ratio (≥50%) are summarized. If the number of labels is ≥3 and a certain label is visited ≥3 times, it is defined as "label concentration". The number of isolation operations performed by such employees within 3 consecutive days is counted. If the total number of isolation operations within 3 days is ≥4 times, it is determined to be "short-term high-frequency behavior". Employees who meet the above two criteria are screened out as key targets. In the sample, employee Z is associated with "financial budget", "salary report" and "employee level". Class labels, among which the "financial budget" label was accessed 4 times within a week, and 3 of the isolation operations corresponded to this label, and 3 occurred between July 2nd and 4th, meeting the two conditions of label concentration and short-term high frequency. We further extracted the time and location information of all isolation events of the employee, constructed density information to analyze the operation distribution, and counted its operation density in the 7×24-hour time grid. The number of records in the time grid 14:00-15:00 and the location grid "East Server Room" were 4 and 5 respectively, both exceeding the set density threshold 3 times. The employee's behavior pattern was determined to be "high-density short-term concentrated", and the abnormal operation push result was output.

[0045] The above are merely preferred embodiments of the present invention and do not limit the present invention in any other form. Any technician familiar with the profession may use the technical content disclosed above to change or modify it into an equivalent embodiment with equivalent changes and apply it to other fields. However, any simple modification, equivalent change and modification made to the above embodiment based on the technical essence of the present invention without departing from the content of the technical solution of the present invention shall still fall within the scope of protection of the technical solution of the present invention.

Claims

1. A smart electronic work badge and its data management system, characterized by: The system comprises: The face verification module compares the key point boundaries with the archival standard image based on the collected facial key point images. By comparing the image overlap area and edge density, it screens the data group that determines the identity features to be consistent and obtains the feature overlap judgment value. The punch-in compliance module analyzes the time series of the work badge punch-in records based on the feature overlap determination, determines the synchronization consistency of the punch-in data and the identity verification, compares the punch-in time sequence with the sign-in image, identifies synchronization anomaly groups, and obtains a time series consistency identifier; Based on the time sequence consistency identifier, the behavior assessment module analyzes the distribution of clock-in trajectory nodes, determines the trend of activity point changes, compares the Bluetooth log with the work time record, filters the offset nodes and integrates the data to obtain the trajectory offset distribution characteristics; The permission isolation module determines the ownership of the terminal device based on the trajectory offset distribution characteristics, analyzes the relationship between the device list and the tag level directory, identifies unauthorized sensitive access, optimizes the permission verification results and locates anomalies, and obtains sensitive access trigger marks.

2. The intelligent electronic ID card and its data management system according to claim 1 is characterized in that: The feature overlap judgment quantity includes facial feature comparison data, identity verification result identifier, and abnormal identification factor; the time consistency identifier includes attendance record timestamp, data synchronization status, and abnormal punch-in mark; the trajectory offset distribution feature includes trajectory offset type, behavior pattern analysis item, and abnormal trajectory label; the sensitive access trigger mark includes sensitive behavior identification item, unauthorized access indication, and data security classification identifier.

3. The intelligent electronic ID card and its data management system according to claim 1 is characterized in that: The face verification module includes: The key point acquisition submodule marks the positions of key feature points at the corners of the eyes, nose tip, and mouth corners based on the collected facial key point images. It combines the structural clues of the image edges, summarizes the feature contour information, and obtains the key point boundary data. The contour comparison submodule compares the key point boundary data with the structural correspondence of the archival standard image, analyzes the matching consistency of the boundary lines of each group of images, calculates the coordination of the spatial distribution of the overlapping areas, obtains the average amplitude of the structural matching difference, and obtains the contour comparison density trend; The coincidence screening submodule screens the data group with the best pairing coordination according to the contour comparison density trend, determines the similarity of the data group in structural distribution, and obtains the feature coincidence judgment value by summarizing the boundary point pairing concentration area.

4. The intelligent electronic ID card and its data management system according to claim 1 is characterized in that: The punch-in compliance module includes: The time overlap comparison submodule analyzes the time information of the work badge punch-in record and the personnel sign-in image capture based on the feature overlap judgment quantity, compares the occurrence time of the corresponding events, determines whether there is a temporal correspondence between the two groups of events, and calculates the statistical characteristics of the temporal correspondence to obtain the time interval difference sequence; The synchronization determination submodule compares the time status of each set of work badge punching and sign-in images based on the time interval difference sequence, determines the events with inconsistent time correspondence, and counts the time matching of each data group within the specified range to obtain the time matching ratio index; The abnormal group identification submodule calculates the time and space correspondence of each group of data based on the time matching ratio indicator and the location information of each punch-in record, compares the clustering and abnormal dispersion of event distribution, and screens event groups with time and space deviation characteristics to obtain a temporal consistency identifier.

5. The intelligent electronic ID card and its data management system according to claim 1 is characterized in that: The behavior assessment module includes: The trajectory node identification submodule analyzes the temporal sequence and spatial trajectory of the clock-in behavior based on the temporal consistency identifier, determines the continuity and correlation between each clock-in event and the previous and next locations, filters out spatial offsets or temporal anomalies between nodes, optimizes the distribution characteristics between nodes, and generates node interval distribution information; The operation record comparison submodule compares the temporal and spatial overlap of device operations and trajectory nodes in the Bluetooth operation log based on the node interval distribution information, determines the corresponding relationship between operation types and nodes, screens the association between high-frequency operation events and trajectory nodes, and obtains the corresponding structure of node operations; The trajectory feature generation submodule screens the change trends in the activity point records and working time sequences based on the node operation corresponding structure, determines the offset phenomenon and distribution status between trajectory nodes, optimizes the correlation characteristics of the trajectory sequence, and obtains the trajectory offset distribution characteristics.

6. The intelligent electronic work badge and its data management system according to claim 1 is characterized in that: The permission isolation module includes: The device attribution identification submodule compares the trajectory offset distribution characteristics with the registration information in the device list, analyzes the device identification data of the terminal device during the data extraction behavior, determines the consistency between the device location and the operation time and space, filters out data with attribution anomalies, and obtains the attribution verification offset; The tag permission comparison submodule compares the permission requirements of the sensitive tag with the device authorization information based on the attribution verification offset, filters access data with insufficient device permissions or attribution anomalies, optimizes the permission mapping between the sensitive tag and the device, and obtains the tag access anomaly matching degree; The sensitive behavior determination submodule calculates the access frequency, device permission status and tag sensitivity of various sensitive tags in the data access log according to the tag access anomaly matching degree, and obtains the sensitive access trigger coefficient. ,Filter the behaviors of sensitive tags being frequently accessed by unauthorized devices and obtain sensitive access trigger marks.

7. The intelligent electronic ID card and its data management system according to claim 1 is characterized in that: The system further comprises: The risk push module analyzes the frequency of isolation operations in the badge behavior overview based on the sensitive access trigger mark, compares access reminders and isolation behaviors in combination with the management review record period, screens employees who frequently perform isolation operations, and obtains abnormal operation push results; The abnormal operation push results include abnormal event entries, risk personnel lists, and management review prompt items.

8. The intelligent electronic ID card and its data management system according to claim 7 is characterized in that: The risk push module includes: The isolation frequency analysis submodule categorizes and sorts employee isolation operation events based on the sensitive access trigger tags and the overall employee badge behavior. By counting the number of occurrences and distribution patterns of each employee's isolation operation, it determines the concentration of isolation behaviors of different employees and obtains isolation operation statistics. The tag comparison submodule calls the isolation operation statistics, combines the access event time data in the management review record book, compares the tag access reminder information with the corresponding isolation behavior, performs pairing identification based on the operation time interval, determines the association between the tag reminder and the isolation behavior, and obtains the operation association matching result; The employee screening submodule determines employees who have multiple label associations in a short period of time based on the operation association matching results, the types of labels involved in the employee isolation behavior and the frequency of their occurrence, analyzes the frequently associated behavior patterns, integrates the distribution and density information, and obtains the abnormal operation push results.

Citation Information

Cited By

  • Downhole person card consistency verification method based on identity recognition

    CN122286739A