Access control authority dynamic management method and system for traditional Chinese medicine clinical practical training
By constructing a dynamic management system, utilizing genetic algorithms and multi-dimensional matching algorithms, combined with big data and isolated forest algorithms, the dynamic adaptation problem of permission management in TCM clinical training was solved, improving training efficiency and security, and realizing personalized permission management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-08
- Publication Date
- 2026-04-07
AI Technical Summary
Existing access control systems cannot adapt to dynamically changing scenarios in TCM clinical training, resulting in low training efficiency, numerous security risks, and a lack of personalized permission management. They also fail to meet the characteristics of multiple parallel projects and diverse personnel roles, leading to low accuracy in permission matching.
A dynamic management system based on TCM clinical training is constructed. It adopts a permission conflict handling module, a training load analysis module, a control strength analysis module, and an abnormal permission detection module. It utilizes genetic algorithms and multi-dimensional matching algorithms, combined with big data and isolated forest algorithms, to achieve dynamic adjustment and security optimization of permissions.
It improves the efficiency of resolving permission conflicts, realizes dynamic adaptation of permission modes, enhances security and resource utilization efficiency, reduces the false negative rate of anomaly detection, and ensures that core training needs are met first.
Smart Images

Figure CN121811528A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of access control management, in particular to an access control permission dynamic management method and system for traditional Chinese medicine clinical training. BACKGROUND
[0002] Traditional Chinese medicine clinical training is a core link of traditional Chinese medicine talent training, covering acupuncture and moxibustion operation, Chinese medicine processing, and massage and physiotherapy, and the training area often involves precise training equipment, high-risk processing raw materials and special teaching resources. The access control permission management is directly related to the training safety, teaching order and rational use of resources. With the expansion of traditional Chinese medicine education and the diversified development of training mode, the existing access control permission management technology has been difficult to meet the special needs of traditional Chinese medicine clinical training, and many technical problems need to be solved.
[0003] The existing access control permission management adopts fixed permission allocation and single verification process, and lacks the adaptation ability to the dynamic changes of traditional Chinese medicine clinical training scenes. During the peak training period, a large number of students enter the training area, and the fixed verification process is long, which causes traffic congestion and seriously affects the training efficiency. In the non-training period or the high-risk training area of Chinese medicine processing, the single verification strength cannot effectively prevent illegal intrusion, and there are safety hazards such as equipment damage and raw material loss. At the same time, the existing technology has a simple way to deal with permission conflicts, which mostly adopts the way of queuing and waiting or directly rejecting, without considering the reservation priority, role permission level and training project correlation of traditional Chinese medicine training, resulting in low conflict resolution efficiency, and even the situation that the personnel of core training project cannot enter in time.
[0004] In addition, the control strength of the existing access control system lacks flexible adjustment mechanism, and the risk difference of traditional Chinese medicine training projects and the change of personnel flow density are not considered. The same control standard is adopted for low-risk routine training and high-risk processing training, resulting in resource waste or insufficient control. In the aspect of abnormal permission detection, the existing technology mostly relies on single threshold judgment, which is difficult to identify complex abnormal situations such as high-frequency verification in non-training period, mismatch of permission level and training project, and lacks deep analysis and closed-loop optimization of abnormal reasons, which cannot prevent safety risks from the root.
[0005] At the same time, traditional Chinese medicine clinical training has the characteristics of multiple project parallel, personnel role diversity and reservation management, and the existing access control system does not construct special management logic for these characteristics, resulting in low permission matching accuracy and inability to realize personalized permission management. These technical problems are interwoven, which seriously affects the teaching quality and safety guarantee level of traditional Chinese medicine clinical training, and an access control permission management method and system which can adapt to the characteristics of traditional Chinese medicine clinical training scene and realize dynamic, accurate and safe management is urgently needed. SUMMARY
[0006] The purpose of the present application is to provide a dynamic management method and system for access control permissions for traditional Chinese medicine clinical training, to solve the problems raised in the background art, the present application is based on the dynamic characteristics and management requirements of traditional Chinese medicine clinical training scene, constructs the whole process dynamic management logic of "perception-analysis-decision-optimization", the core principle is as follows:
[0007] Permission conflict processing principle: through the access control communication module to collect personnel identity, reservation information and role permission and other multi-dimensional data, extract conflict characteristic index, introduce genetic algorithm to construct double objective optimization model (minimize average verification waiting time, maximize permission matching accuracy), at the same time, combined with multi-dimensional permission matching algorithm to construct rule base, realize the accurate identification and efficient resolution of conflict, break through the limitation of traditional single conflict processing.
[0008] Permission mode adaptation principle: based on the training scene monitoring data, calculate the permission verification response time, passing efficiency, conflict rate and other load indexes, construct load trend chart, divide different load scenes through preset threshold, adapt fast, normal and strict three kinds of permission mode, realize the dynamic matching of verification process and training load.
[0009] Control intensity optimization principle: extract scene characteristics such as time period, risk level and personnel density, calculate control demand intensity, combine big data to search similar training scene permission management curve, select the optimal curve through similarity matching, realize the periodization and fine adjustment of control intensity.
[0010] Abnormal detection and optimization principle: time series processing is carried out on the monitoring data, the feature space is constructed by using isolation forest algorithm, the abnormal score is calculated by path length, the complex abnormal permission request is accurately identified, combined with abnormal reason analysis model and safety control rule, form the closed loop management of "detection-analysis-optimization".
[0011] In order to solve the above technical problems, the present application provides the following technical scheme:
[0012] A dynamic management system for access control permissions for traditional Chinese medicine clinical training, the system comprises: permission verification and conflict processing module, training load analysis and permission mode adjustment module, control intensity analysis and permission control module, and abnormal permission detection and safety control optimization module;
[0013] The permission verification and conflict processing module undertakes permission verification request sending, permission feedback information collection, permission conflict detection and conflict resolution and permission dynamic allocation work;
[0014] The training load analysis and permission mode adjustment module is responsible for carrying out training scene monitoring information analysis, training load evaluation and permission mode adaptation adjustment work;
[0015] The control intensity analysis and permission control module is responsible for implementing the access control system control intensity analysis and optimal permission management curve formulation and permission control work.
[0016] The abnormal permission detection and security control optimization module is responsible for completing the abnormal permission identification and access control system security control upgrade optimization work.
[0017] A door access permission dynamic management method for traditional Chinese medicine clinical training, the method comprising the following steps:
[0018] Sending permission verification request information, obtaining permission feedback information, detecting permission conflicts according to the permission feedback information, and obtaining conflict detection information;
[0019] According to the conflict detection information, the conflict is processed, the corresponding permission is verified, and the dynamic adjustment of the permission allocation is carried out;
[0020] Obtain training scene monitoring information, analyze the training load according to the training scene monitoring information, and adjust the permission mode according to the analysis result;
[0021] According to the training scene monitoring information, the control intensity analysis of the target access control system is carried out, and the optimal permission management curve is formulated to control the permission of the target access control system;
[0022] According to the training scene monitoring information, abnormal permission detection is carried out, and the security control optimization of the target access control system is carried out.
[0023] Preferably, the sending permission verification request information, obtaining permission feedback information, detecting permission conflicts according to the permission feedback information, and obtaining conflict detection information, comprise:
[0024] Based on the target access control communication module, the permission verification request information is sent to the entrance and exit of the training area, and the identity of the personnel, the training reservation information, the role permission level are verified and activated through the permission verification request information;
[0025] Receive the permission response signal of the personnel, mark the receiving order, time and identity association information of each response signal, and assign a unique verification identifier to obtain the permission feedback information;
[0026] According to the permission feedback information, the permission conflict detection is carried out, the number of permission verification requests in a unit of time, the number of permission level cross times are extracted, and the preset conflict threshold is judged;
[0027] If the number of permission verification requests in a unit of time is less than the preset conflict threshold and the number of permission level cross times is zero, no permission conflict occurs;
[0028] If the number of permission verification requests in a unit of time is greater than a preset conflict threshold or the number of permission level crossing times is greater than zero, a permission conflict situation occurs, and conflict detection information is generated.
[0029] Preferably, the conflict processing according to the conflict detection information, verification of corresponding permissions, and dynamic adjustment of permission allocation include:
[0030] Obtain the conflict detection information, extract the conflicting permission types, conflict personnel roles, and training project association relationships according to the conflict detection information, extract the permission levels, training reservation priorities, and personnel identity identifiers, and obtain the conflict permission feature information.
[0031] Build a verification efficiency optimization model, take the minimization of average verification waiting time and the maximization of permission matching accuracy as double optimization objectives, introduce a genetic algorithm for optimization, obtain permission feedback information, input the permission feedback information into the verification efficiency optimization model for analysis, and obtain verification optimization information.
[0032] Introduce a multi-dimensional permission matching algorithm for permission verification, build an optimal permission matching rule library according to the verification optimization information, combine the conflict permission feature information for permission verification, and obtain permission verification result information.
[0033] Obtain real-time conflict monitoring information, extract the conflict frequency and conflict type of real-time permission verification according to the real-time conflict monitoring information, take the conflict frequency and conflict type as adjustment indexes, judge the adjustment indexes with a preset adjustment threshold, and obtain judgment result information.
[0034] According to the judgment result information, formulate a permission allocation strategy and dynamically adjust the permission allocation.
[0035] Preferably, the training load analysis is performed according to the analysis result, and the permission mode is adjusted, including:
[0036] Obtain training scene monitoring information, perform training efficiency analysis according to the training scene monitoring information, calculate the permission verification response time, training personnel passage efficiency, permission conflict rate, and scene load coefficient, and obtain efficiency analysis information.
[0037] According to the training scene monitoring information, extract the verification request number of the target access control system, the training project type, and the personnel flow period, combine the efficiency analysis information to build a training load trend chart, perform training load analysis, and obtain training load analysis information.
[0038] Three types of permission modes are preset, which are a fast verification mode, a normal verification mode, and a strict verification mode, and corresponding enablement judgment thresholds are set for each permission mode.
[0039] The rapid verification mode is suitable for peak training period, single project centralized training scene, and is used for simplifying the verification process and verifying the core permission preferentially;
[0040] The normal verification mode is suitable for regular training period, multi-project parallel training scene, and is used for complete verification of basic permissions;
[0041] The strict verification mode is suitable for non-training period and high-risk training area, and is used for strengthening identity verification and authorization approval process;
[0042] The training load analysis information is judged with the enabling judgment threshold, and the corresponding permission mode is selected according to the judgment result to work, and the permission mode selection information is obtained;
[0043] According to the permission mode selection information, the permission mode of the target access control system is adjusted, and the training load analysis information is used as the mode switching judgment index for real-time judgment, and the permission mode is dynamically adjusted according to the judgment result, and the verification process parameters of the target access control system are optimized.
[0044] Preferably, the target access control system is controlled according to the training scene monitoring information, and an optimal permission management curve is developed to control the target access control system, including:
[0045] Obtain the training scene monitoring information, extract the number of permission verification requests, training project risk level and personnel flow density information of the target access control system in each time period, calculate the control demand intensity of each time period, and obtain the scene characteristic information;
[0046] A plurality of control intensity judgment thresholds are preset, the scene characteristic information is judged with the control intensity judgment threshold, the control intensity demand of each period of the target access control system is analyzed, and the control intensity analysis information is obtained;
[0047] According to the control intensity analysis information, each time period of the target access control system is divided, a plurality of time period division thresholds are preset, the control intensity analysis information is judged with the time period division threshold, each time period is divided according to the judgment result, and the division result information is obtained;
[0048] The classification of the division result information is: high-frequency control period, normal control period and low-frequency control period;
[0049] Based on big data retrieval, the permission management curve of each type of traditional Chinese medicine training scene and the control intensity and training scene characteristic information corresponding to each management curve are obtained to form a training instance data set;
[0050] The control strength analysis information and the division result information are subjected to similarity calculation with the practical training instance data set, a similarity value is obtained and subjected to judgment with a preset similarity threshold value, a permission management curve is selected according to a judgment result, and candidate management curve information is obtained;
[0051] The similarity values of each candidate management curve are extracted, sorted, and the optimal permission management curve is selected according to the sorting result to control the permissions of the target access control system.
[0052] Preferably, the abnormal permission detection according to the practical training scene monitoring information and the security control optimization of the target access control system comprise:
[0053] The practical training scene monitoring information is obtained, data cleaning, removal of abnormal values and missing value supplement preprocessing are performed on the practical training scene monitoring information, and the preprocessed practical training scene monitoring information is subjected to time series processing, the corresponding monitoring data is sorted according to time sequence, and time series processing information is obtained;
[0054] The isolation forest algorithm is introduced to detect the abnormality of the permission running state of the target access control system, the feature extraction and feature space construction are performed on the time series processing information, and an isolation tree is constructed by randomly selecting a feature and a corresponding feature vector;
[0055] The path length of each data point on the corresponding isolation tree is calculated as an abnormal score, a preset abnormal score judgment threshold value is set, the abnormal score of each data point is judged with the abnormal score judgment threshold value, and the data points greater than the abnormal score judgment threshold value are selected as abnormal data, and abnormal permission detection information is obtained;
[0056] The abnormal data includes non-practical training period high-frequency verification request, permission level and practical training project mismatch request, expired appointment permission verification request;
[0057] The permission type, request time and personnel identification of each abnormal data point are extracted according to the abnormal permission detection information, the deviation degree from normal permission request is calculated, and first analysis information is obtained;
[0058] The abnormal permission request reasons and corresponding abnormal features of the traditional Chinese medicine practical training access control are obtained based on big data retrieval, an abnormal permission data set is constituted, an abnormal reason analysis model is constructed, and the abnormal reason analysis model is subjected to deep learning and training through the abnormal permission data set;
[0059] The abnormal permission detection information and the first analysis information are input into the abnormal reason analysis model for analysis, and abnormal reason analysis information is obtained;
[0060] The safety management optimization rule is constructed based on the TCM training safety management specification, the abnormal reason analysis information and the first analysis information are judged with the safety management optimization rule, the influence of the abnormal reason and the corresponding deviation degree on the training safety is analyzed, whether the management and control need to be strengthened is judged, and safety optimization analysis information is obtained;
[0061] The safety management strategy is formulated according to the safety optimization analysis information, the safety management optimization of the target access control system is carried out through the safety management strategy, including permission level upgrade, verification process strengthening and abnormal early warning linkage, and the running data after optimization is monitored to judge whether the expected safety effect is achieved, if not, manual intervention warning is carried out.
[0062] Compared with the prior art, the beneficial effects achieved by the present application are:
[0063] The permission conflict processing mechanism of ''genetic algorithm + multi-dimensional matching algorithm'' is adopted, the limitation of the single conflict processing mode of the prior art is broken through, not only the rapid resolution of the conflict is realized, but also the reservation priority and the project association of the TCM training are combined to ensure that the core training demand is preferentially met, and the conflict resolution efficiency and the matching accuracy can be improved.
[0064] Three types of permission modes suitable for different training scenes are designed, dynamic switching is realized through load analysis, the contradiction between congestion in peak period and safety shortage in low peak period in the prior art is solved, dynamic balance of efficiency and safety is realized, and the differential design can adapt to the dynamic change characteristics of the TCM training scene.
[0065] An optimal permission management curve formulation method based on big data retrieval and similarity matching is proposed, the periodization and fine adjustment of the management and control intensity are realized, the risk difference and personnel flow rule of the TCM training project are more in line with the existing uniform management and control mode, the pertinence and rationality of management and control are greatly improved, which is helpful to improve the efficiency of management and control.
[0066] The Isolation Forest algorithm is adopted to realize accurate identification of complex abnormal permissions, and an abnormal reason analysis model and a closed-loop optimization mechanism are constructed to prevent safety risks from the root, solve the problems of high false positive and false negative rates of abnormal detection in the prior art, and the optimized safety management strategy has continuous iteration capability. BRIEF DESCRIPTION OF DRAWINGS
[0067] The accompanying drawings are used to provide a further understanding of the present application, and constitute a part of the specification, together with the embodiments of the present application, to explain the present application, and do not constitute a limitation on the present application.
[0068] Figure 1 is a step schematic diagram of a TCM clinical training oriented access control permission dynamic management method. DETAILED DESCRIPTION
[0069] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0070] In the first embodiment: a dynamic management system for access control permissions of TCM clinical training is provided, which comprises: a permission verification and conflict processing module, a training load analysis and permission mode adjustment module, a control intensity analysis and permission control module, and an abnormal permission detection and security control optimization module;
[0071] The permission verification and conflict processing module is responsible for sending permission verification requests, collecting permission feedback information, detecting and resolving permission conflicts, and dynamically adjusting permissions.
[0072] The training load analysis and permission mode adjustment module is responsible for analyzing training scene monitoring information, evaluating training load, and adjusting permission mode.
[0073] The control intensity analysis and permission control module is responsible for analyzing the control intensity of the access control system, formulating an optimal permission management curve, and controlling permissions.
[0074] The abnormal permission detection and security control optimization module is responsible for identifying abnormal permissions and optimizing the security control of the access control system.
[0075] Please refer to Figure 1 In the second embodiment: a dynamic management method for access control permissions of TCM clinical training is provided, which is applicable to the first embodiment. The second embodiment is applied to a clinical training center of a certain TCM university, which includes three core areas: acupuncture training area, high-risk Chinese medicine processing training area, and massage training area. Training personnel are divided into teachers (role permission level 1), graduate students (level 2), and undergraduate students (level 3). The training period is from 8:00 to 12:00 (peak period, single project concentrated training), 14:00 to 17:00 (regular period, multiple projects parallel training), and after 17:00 (non-training period). Training projects include routine acupuncture training (low risk level), Chinese medicine processing training (high risk level), and massage operation training (medium risk level). The reservation system is adopted, and the daily reservation training number is about 300 person-times.
[0076] Conflict threshold: The preset conflict threshold for the number of permission verification requests per unit time (1 minute) is 20 times, and the preset conflict threshold for the number of permission level crossings is 3 times.
[0077] Threshold of permission mode enabling: scene load coefficient ≥ 0.7, enabling fast verification mode, 0.3 ≤ scene load coefficient < 0.7, enabling normal verification mode, scene load coefficient < 0.3, enabling strict verification mode;
[0078] Threshold of control intensity: high-frequency control period (the number of permission verification requests ≥ 15 times / hour and the risk level is high), normal control period (5 ≤ the number of requests < 15 times / hour and the risk level is medium), low-frequency control period (the number of requests < 5 times / hour and the risk level is low);
[0079] Threshold of abnormal score judgment: 0.8, greater than the threshold to determine abnormal data;
[0080] The method comprises the following steps:
[0081] Sending permission verification request information, obtaining permission feedback information, performing permission conflict detection according to the permission feedback information, and obtaining conflict detection information;
[0082] According to the conflict detection information, the conflict is processed, the corresponding permission is verified, and the dynamic adjustment of the permission allocation is performed;
[0083] Obtaining real training scene monitoring information, performing real training load analysis according to the real training scene monitoring information, and adjusting the permission mode according to the analysis result;
[0084] According to the real training scene monitoring information, the control intensity of the target access control system is analyzed, and the optimal permission management curve is formulated to control the target access control system;
[0085] According to the real training scene monitoring information, the abnormal permission is detected, and the safety control optimization of the target access control system is performed.
[0086] In this embodiment, the permission verification request information is sent, the permission feedback information is obtained, the permission conflict detection is performed according to the permission feedback information, and the conflict detection information is obtained, which is specifically:
[0087] Based on the target access control communication module, the permission verification request information is sent to the entrance and exit of the real training area, and the identity of the personnel entering and exiting, the real training reservation information, and the role permission level are verified and activated through the permission verification request information;
[0088] Receiving the permission response signal of the personnel entering and exiting, marking the receiving order, time and identity association information of each response signal, and assigning a unique verification identifier to obtain the permission feedback information;
[0089] According to the permission feedback information, the number of permission verification requests in a unit time and the number of permission level cross times are extracted, and the preset conflict threshold is judged;
[0090] If the number of permission verification requests per unit time is less than the preset conflict threshold and the number of permission level intersections is zero, no permission conflict occurs.
[0091] If the number of permission verification requests per unit time is greater than the preset conflict threshold or the number of permission level intersections is greater than zero, a permission conflict occurs, and conflict detection information is generated.
[0092] For example, sending a permission verification request: sending a permission verification request to the acupuncture training area entrance through the target access control communication module, verifying the identity of 25 undergraduate students, acupuncture training reservation information, and level 3 permissions at 8:30 (peak period), and activating the verification process.
[0093] Permission conflict detection: after receiving the response signal, mark the receiving order, time, and identity association information, assign a unique verification identifier, and count the number of permission verification requests within 1 minute (25 times > 20 times), the number of permission level intersections (4 times > 3 times), and generate conflict detection information.
[0094] Conflict processing and permission adjustment: extract conflict permission feature information (conflict type is number overload, conflict personnel role is undergraduate, and associated project is acupuncture training), optimize the average verification waiting time to ≤3 seconds through genetic algorithm, permission matching accuracy ≥98%, build an optimal permission matching rule library, and complete permission verification with a multi-dimensional matching algorithm.
[0095] In this embodiment, conflict processing is performed according to the conflict detection information, the corresponding permissions are verified, and dynamic adjustment of permission allocation is performed, specifically:
[0096] Obtain conflict detection information, extract the type of conflicting permissions, the role of conflicting personnel, and the association between training projects, extract the permission level, training reservation priority, and personnel identity, and obtain conflict permission feature information;
[0097] Build a verification efficiency optimization model, set the minimum average verification waiting time and the maximum permission matching accuracy as the dual optimization objectives, introduce genetic algorithm for optimization, obtain permission feedback information, input it into the verification efficiency optimization model for analysis, and obtain verification optimization information;
[0098] Introduce a multi-dimensional permission matching algorithm for permission verification, build an optimal permission matching rule library according to the verification optimization information, and perform permission verification based on the conflict permission feature information to obtain permission verification result information;
[0099] Obtain real-time conflict monitoring information, extract the conflict frequency and conflict type of real-time permission verification conflicts based on the real-time conflict monitoring information as adjustment indicators, and judge them against the preset adjustment threshold to obtain judgment result information;
[0100] Formulate a permission allocation strategy according to the judgment result information, and dynamically adjust the permission allocation;
[0101] For example, obtain the real training scene monitoring information: collect the monitoring data of the acupuncture real training area from 8:00 to 12:00, calculate the permission verification response time of 2.8 seconds, the real training personnel passing efficiency of 10 people / minute, the permission conflict rate of 1.2%, and the scene load coefficient of 0.8;
[0102] Load analysis and mode selection: construct a real training load trend chart, analyze that it is in a high load state, the scene load coefficient is 0.8≥0.7, enable the fast verification mode, simplify the verification process, and only verify the identity and real training reservation information core permissions.
[0103] In this embodiment, real training load analysis is performed, and the permission mode is adjusted according to the analysis result, specifically:
[0104] Obtain the real training scene monitoring information, perform real training efficiency analysis according to the real training scene monitoring information, calculate the permission verification response time, the real training personnel passing efficiency, the permission conflict rate, and the scene load coefficient, and obtain the efficiency analysis information;
[0105] According to the real training scene monitoring information, the verification request quantity of the target access control system, the real training project type, and the personnel flow period are extracted, the efficiency analysis information is combined to construct a real training load trend chart, the real training load analysis is performed, and real training load analysis information is obtained;
[0106] Three types of permission modes are preset, which are fast verification mode, normal verification mode and strict verification mode, and corresponding enablement judgment thresholds are set for each permission mode;
[0107] The fast verification mode is suitable for real training peak period and single project concentrated real training scene, and is used to simplify the verification process and preferentially verify the core permissions;
[0108] The normal verification mode is suitable for regular real training period and multi-project parallel real training scene, and is used to verify the basic permissions completely;
[0109] The strict verification mode is suitable for non-real training period and high-risk real training area, and is used to strengthen the identity verification and authorization approval process;
[0110] Judge the real training load analysis information and the enablement judgment threshold, select the corresponding permission mode according to the judgment result, and obtain permission mode selection information;
[0111] According to the permission mode selection information, the permission mode of the target access control system is adjusted, the real training load analysis information is used as a mode switching judgment index, real-time judgment is performed, the permission mode is dynamically adjusted according to the judgment result, and the verification process parameters of the target access control system are optimized.
[0112] In this embodiment, the monitoring intensity of the target access control system is analyzed according to the training scene monitoring information, and the optimal permission management curve is formulated to control the permissions of the target access control system. Specifically,
[0113] The training scene monitoring information is obtained, the number of permission verification requests in each time period, the risk level of the training project, and the personnel flow density information of the target access control system are extracted, the control demand intensity of each time period is calculated, and the scene characteristic information is obtained.
[0114] A plurality of control intensity judgment thresholds are preset, the scene characteristic information is judged with the control intensity judgment threshold, the control intensity demand of each time period of the target access control system is analyzed, and the control intensity analysis information is obtained.
[0115] According to the control intensity analysis information, each time period of the target access control system is divided, a plurality of time period division thresholds are preset, the control intensity analysis information is judged with the time period division threshold, each time period is divided according to the judgment result, and the division result information is obtained.
[0116] The classification of the division result information is: high-frequency control period, normal control period and low-frequency control period.
[0117] Based on big data retrieval, the permission management curves of various traditional Chinese medicine training scenes and the control intensity and training scene characteristic information corresponding to each management curve are obtained to form a training instance data set.
[0118] The control intensity analysis information and the division result information are subjected to similarity calculation with the training instance data set, the similarity value is obtained and judged with the preset similarity threshold, the permission management curve is selected according to the judgment result, and the candidate management curve information is obtained.
[0119] The similarity values of each candidate management curve are extracted, sorted, and the optimal permission management curve is selected according to the sorting result to control the permissions of the target access control system.
[0120] For example, the scene characteristic information is obtained: the monitoring data of Chinese medicine processing training area from 9:00 to 11:00 is obtained, the number of permission verification requests is 22 times / hour, the risk level of the training project is high, and the personnel flow density is 18 people / 100 square meters.
[0121] Control intensity analysis: the control demand intensity is calculated as 0.9, and it is determined as a high-frequency control period; 100 groups of permission management curves of traditional Chinese medicine high-risk training scenes are obtained by big data retrieval, and the curve with a similarity of 0.92 is selected as the optimal permission management curve.
[0122] In this embodiment, the abnormal permission detection is performed according to the training scene monitoring information, and the security control optimization of the target access control system is performed. Specifically,
[0123] Obtain the real training scene monitoring information, preprocess the real training scene monitoring information by data cleaning, removing outliers and filling missing values, and time sequence the preprocessed real training scene monitoring information. The corresponding monitoring data is sorted in chronological order to obtain time sequence processing information.
[0124] An isolation forest algorithm is introduced to detect anomalies in the running state of the target access control system. Feature extraction is performed on the time sequence processing information and a feature space is constructed. A feature and the corresponding feature vector are randomly selected to construct an isolation tree.
[0125] The path length of each data point on the corresponding isolation tree is calculated as an anomaly score. A preset anomaly score judgment threshold is used to judge the anomaly score of each data point. Data points with anomaly scores greater than the anomaly score judgment threshold are selected as abnormal data to obtain abnormal access detection information.
[0126] Abnormal data includes high-frequency verification requests during non-training periods, requests with unmatched access levels and training projects, and expired appointment access verification requests.
[0127] According to the abnormal access detection information, the access type, request time, and personnel identification of each abnormal data point are extracted, and the deviation degree from normal access requests is calculated to obtain first analysis information.
[0128] Based on big data retrieval, the reasons for abnormal access requests for traditional Chinese medicine training access control and the corresponding abnormal features are obtained to form an abnormal access data set. An abnormal reason analysis model is constructed, and the abnormal reason analysis model is learned and trained through the abnormal access data set.
[0129] The abnormal access detection information and the first analysis information are input into the abnormal reason analysis model for analysis to obtain abnormal reason analysis information.
[0130] Based on the safety management specifications of traditional Chinese medicine training, safety control optimization rules are constructed. The abnormal reason analysis information and the first analysis information are judged against the safety control optimization rules to analyze the influence of abnormal reasons and corresponding deviations on training safety, and to determine whether enhanced control is needed to obtain safety optimization analysis information.
[0131] According to the safety optimization analysis information, safety control strategies are developed to optimize the safety control of the target access control system, including access level upgrade, verification process enhancement, and abnormal early warning linkage. The optimized running data is monitored to determine whether the desired safety effect is achieved. If not, manual intervention is required for early warning.
[0132] Data preprocessing: obtain the real training scene monitoring information from 18:30 to 19:00, carry out data cleaning, outlier removal and missing value supplement, and obtain time series processing information after time series processing and time sorting. Abnormal detection: introduce the isolated forest algorithm to construct the feature space, randomly select the verification request frequency, the matching degree of the permission level and other characteristics to construct the isolated tree, calculate the abnormal score corresponding to the permission verification request path length of a non-appointment personnel 0.89 (> 0.8), and determine that it is abnormal data (high-frequency verification request in non-training period).
[0133] The computer storage medium of the embodiment of the application can adopt any combination of one or more computer readable media. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples (non-exhaustive list) of the computer readable storage medium include: an electrical connection with one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or component.
[0134] The computer readable signal medium can include a data signal propagating in a baseband or as a part of a carrier wave propagating in a baseband, in which a computer readable program code is carried. Such a propagating data signal can take various forms, including but not limited to electromagnetic signals, optical signals or any suitable combination thereof. The computer readable signal medium can also be any computer readable medium other than the computer readable storage medium, which can send, propagate or transmit a program for use by or in conjunction with an instruction execution system, device or component.
[0135] The computer readable media on which the program code can be carried by any suitable medium, including but not limited to wireless, wired, optical fiber cable, or any suitable combination of the above. Computer program code for carrying out operations of the present application can be written in one or more programming languages, or combinations of languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0136] The above description is only the preferred embodiment of the present application, and is not intended to limit the present application in any form. Although the present application has been disclosed as above with the preferred embodiment, it is not intended to limit the present application, and any person skilled in the art can make some changes or modifications to the above disclosed technical content to make equivalent embodiments with equivalent changes, without departing from the technical solution of the present application. Any simple modification, equivalent change and modification of the above embodiments made according to the technical essence of the present application, without departing from the technical solution of the present application, still belongs to the scope of the technical solution of the present application.
Claims
1. A dynamic access control management method for clinical training in Traditional Chinese Medicine, characterized in that, The method includes the following steps: Send permission verification request information, obtain permission feedback information, perform permission conflict detection based on the permission feedback information, and obtain conflict detection information; Conflicts are handled based on conflict detection information, corresponding permissions are verified, and permission allocation is dynamically adjusted. Acquire training scenario monitoring information, perform training load analysis based on the training scenario monitoring information, and adjust the permission mode based on the analysis results; Based on the monitoring information of the training scenario, the control intensity of the target access control system is analyzed, and the optimal access control curve is formulated to control the access of the target access control system. Based on the monitoring information from the training scenario, abnormal permission detection is performed, and security control optimization is carried out on the target access control system.
2. The method for dynamic access control management for TCM clinical training according to claim 1, characterized in that, The process of sending a permission verification request, obtaining permission feedback information, and performing permission conflict detection based on the permission feedback information to obtain conflict detection information includes: Based on the target access control communication module, permission verification request information is sent to the entrance and exit of the training area. The permission verification request information is used to verify and activate the identity of the personnel entering and exiting, the training appointment information, and the role permission level. Receive access control response signals from personnel entering and exiting, mark the receiving order, time, and identity association information of each response signal, assign a unique verification identifier, and obtain access control feedback information; Based on the permission feedback information, perform permission conflict detection, extract the number of permission verification requests and the number of permission level overlaps per unit time, and compare them with the preset conflict threshold; If the number of permission verification requests per unit time is less than the preset conflict threshold and the number of permission level crossovers is zero, then no permission conflict has occurred. If the number of permission verification requests per unit time exceeds the preset conflict threshold or the number of permission level crossovers is greater than zero, a permission conflict will occur, and conflict detection information will be generated.
3. The method for dynamic access control management for clinical training in traditional Chinese medicine according to claim 1, characterized in that, The step of handling conflicts based on conflict detection information, verifying corresponding permissions, and dynamically adjusting permission allocation includes: Obtain conflict detection information, and extract the conflicting permission type, conflicting personnel role, and training project association based on the conflict detection information. Extract the permission level, training appointment priority, and personnel identity identifier to obtain conflict permission feature information. A verification efficiency optimization model is constructed, with minimizing the average verification waiting time and maximizing the permission matching accuracy as the dual optimization objectives. A genetic algorithm is introduced for optimization, and permission feedback information is obtained and input into the verification efficiency optimization model for analysis to obtain verification optimization information. A multi-dimensional permission matching algorithm is introduced for permission verification. An optimal permission matching rule base is constructed based on the verification optimization information. Permission verification is performed in combination with the conflict permission feature information to obtain permission verification result information. Obtain real-time conflict monitoring information, extract the conflict frequency and conflict type of real-time permission verification based on the real-time conflict monitoring information, use them as adjustment indicators, judge them against preset adjustment thresholds, and obtain judgment result information; Based on the judgment results, a permission allocation strategy is formulated, and the permission allocation is dynamically adjusted.
4. The method for dynamic access control management for TCM clinical training according to claim 1, characterized in that, The process of conducting training load analysis and adjusting permission modes based on the analysis results includes: Acquire training scenario monitoring information, perform training performance analysis based on the training scenario monitoring information, calculate permission verification response time, trainee access efficiency, permission conflict rate and scenario load coefficient, and obtain performance analysis information; Based on the monitoring information of the training scenario, extract the number of verification requests, training project types, and personnel flow time periods of the target access control system. Combine the performance analysis information to construct a training load trend chart, conduct training load analysis, and obtain training load analysis information. Three permission modes are preset: quick verification mode, normal verification mode, and strict verification mode, and corresponding activation thresholds are set for each permission mode. The rapid verification mode is suitable for peak training periods and concentrated training scenarios for single projects. It is used to simplify the verification process and prioritize the verification of core permissions. The normal verification mode is applicable to regular training periods and multi-project parallel training scenarios, and is used to fully verify basic permissions. The strict verification mode is applicable to non-training periods and high-risk training areas, and is used to strengthen identity verification and authorization approval processes. The training load analysis information is compared with the activation judgment threshold, and the corresponding permission mode is selected for operation based on the judgment result to obtain permission mode selection information. Based on the permission mode selection information, the permission mode of the target access control system is adjusted, and the training load analysis information is used as the mode switching judgment indicator for real-time judgment. The permission mode is dynamically adjusted according to the judgment result to optimize the verification process parameters of the target access control system.
5. The method for dynamic access control management for TCM clinical training according to claim 1, characterized in that, Based on the monitoring information from the training scenario, the control intensity of the target access control system is analyzed, and an optimal access control curve is developed to control access to the target access control system, including: Acquire monitoring information of the training scenario, extract the number of permission verification requests, risk level of the training project, and personnel flow density of the target access control system in each time period, calculate the intensity of control demand in each time period, and obtain scenario feature information; Several control intensity judgment thresholds are preset, and the scene feature information is judged against the control intensity judgment thresholds to analyze the control intensity requirements of the target access control system at different times and obtain control intensity analysis information. The control intensity analysis information is used to divide the target access control system into different time periods. Several time period division thresholds are preset. The control intensity analysis information and the time period division thresholds are compared. Based on the comparison results, the time periods are divided to obtain the division result information. The classification categories in the classification results information are: high-frequency control period, normal control period, and low-frequency control period; Based on big data retrieval, permission management curves and control intensity and training scenario characteristic information of various TCM training scenarios are obtained, forming a training instance dataset. The control intensity analysis information, the segmentation result information and the training example dataset are compared with the similarity to obtain the similarity value and judged against the preset similarity threshold. Based on the judgment result, the permission management curve is selected to obtain the candidate management curve information. Extract the similarity values of each candidate access control curve, sort them, and select the optimal access control curve based on the sorting results to control access to the target access control system.
6. The method for dynamic access control management for TCM clinical training according to claim 1, characterized in that, The step of detecting abnormal permissions based on the monitoring information of the training scenario and optimizing the security control of the target access control system includes: Acquire training scenario monitoring information, perform data cleaning, outlier removal and missing value supplementation preprocessing on the training scenario monitoring information, and perform time-series processing on the preprocessed training scenario monitoring information, sort the corresponding monitoring data in chronological order to obtain time-series processed information; An isolated forest algorithm is introduced to detect anomalies in the access control system's permission operation status. Features are extracted from the time-series processing information and a feature space is constructed. An isolated tree is constructed by randomly selecting a feature and its corresponding feature vector. Calculate the path length of each data point on the corresponding isolated tree as the anomaly score. Set an anomaly score judgment threshold. Compare the anomaly score of each data point with the anomaly score judgment threshold. Select data points with an anomaly score judgment threshold as abnormal data to obtain abnormal permission detection information. The abnormal data includes high-frequency verification requests outside of training periods, requests whose permission levels do not match the training projects, and verification requests for expired reservation permissions. Based on the abnormal permission detection information, extract the permission type, request time, and personnel identifier of each abnormal data point, calculate the deviation from the normal permission request, and obtain the first analysis information; Based on big data retrieval, the reasons for abnormal permission requests and corresponding abnormal characteristics of TCM training access control are obtained, an abnormal permission dataset is constructed, an abnormal cause analysis model is built, and the abnormal cause analysis model is trained by deep learning through the abnormal permission dataset; The abnormal permission detection information and the first analysis information are input into the abnormal cause analysis model for analysis to obtain abnormal cause analysis information. Based on the safety management standards for TCM training, safety control optimization rules are constructed. The abnormal cause analysis information and the first analysis information are compared with the safety control optimization rules to analyze the impact of abnormal causes and corresponding deviations on training safety, and to determine whether control needs to be strengthened, thereby obtaining safety optimization analysis information. Based on the security optimization analysis information, a security control strategy is formulated, and the target access control system is optimized through the security control strategy, including upgrading the permission level, strengthening the verification process, and linking abnormal early warning. The optimized operating data is monitored to determine whether the expected security effect has been achieved. If not, manual intervention and early warning are initiated.
7. A dynamic access control system for TCM clinical training, implementing the dynamic access control method for TCM clinical training as described in claim 1, characterized in that... The system includes a permission verification and conflict handling module, a training load analysis and permission mode adjustment module, a control strength analysis and permission control module, and an abnormal permission detection and security control optimization module. The permission verification and conflict handling module is responsible for sending permission verification requests, collecting permission feedback information, detecting and resolving permission conflicts, and dynamically allocating permissions. The training load analysis and permission mode adjustment module is responsible for analyzing training scenario monitoring information, evaluating training load, and adjusting permission modes. The control intensity analysis and access control module is responsible for assessing the control intensity of the access control system and formulating the optimal access management curve and controlling access. The abnormal permission detection and security management optimization module is responsible for completing the abnormal permission identification and security management upgrade and optimization of the access control system.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a control program suitable for a dynamic access control management method for TCM clinical training. When the control program is executed by a processor, it implements the steps of the dynamic access control management method for TCM clinical training as described in any one of claims 1 to 6.