Student apartment access early warning system and method based on dynamic authority
The dynamic access control system solves the problems of lagging access configuration and insufficient early warning function in traditional student dormitory access control systems, realizes real-time access control and accurate early warning, and improves the efficiency and reliability of student dormitory security management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHEJIANG FINANCIAL COLLEGE
- Filing Date
- 2026-02-05
- Publication Date
- 2026-05-01
AI Technical Summary
Traditional student dormitory access control systems use static permission management, which cannot respond to changes in student status in real time. This results in lagging permission configuration, numerous management loopholes, and a lack of intelligent identification and classification in the early warning function, making it difficult to meet the needs of refined security management.
Design a student dormitory access warning system based on dynamic permissions, including modules for permission preset, state adaptation, strategy reconstruction, rule matching and warning generation. Through multi-dimensional rule matching and intelligent analysis, dynamic adaptation of permissions and accurate warnings are achieved.
It achieves seamless synchronization of permissions and student status, improves the accuracy and real-time performance of access control, generates structured early warning reports, reduces the cost of manual intervention, and supports intelligent and refined security management.
Smart Images

Figure CN121963437A_ABST
Abstract
Description
A student dormitory access warning system and method based on dynamic permissions Technical Field
[0001] This invention relates to the field of identity recognition technology, and in particular to a student dormitory access warning system and method based on dynamic permissions. Background Technology
[0002] Traditional student dormitory access control systems mostly employ static permission management mechanisms, with permission configurations typically set once based on students' fixed identity attributes. When faced with dynamically changing student attendance statuses, these systems suffer from severe lag in permission updates, requiring manual adjustments. This is not only inefficient but also prone to management loopholes or misoperations. Due to the lack of real-time data integration with academic affairs and student affairs management systems, the system cannot detect real-time changes in student status, leading to a disconnect between actual access permissions and students' true status, posing risks of inaccurate authorization and ineffective control. Furthermore, existing systems' early warning functions are mostly limited to simple unauthorized entry alarms, failing to intelligently identify and tieredly warn against complex violation patterns. This results in a crude management response, making it difficult to meet the needs of refined security management.
[0003] Existing technical solutions have significant shortcomings in addressing the dynamic, real-time, and complex nature of student dormitory access management. Most systems can only record access events, failing to effectively predict and intervene in time-sensitive anomalies such as "failure to return when required" or "unauthorized lingering." Their rigid permission models cannot dynamically combine and adapt to multi-dimensional factors such as time, location, and personnel status, leading to a mismatch between management rules and real-world scenarios. Early warning mechanisms lack deep integration and intelligent analysis of multi-source information, generating only simplistic alerts that cannot provide tiered and categorized decision support for management personnel, hindering the shift from a passive response to a proactive prevention management model. Therefore, a new technical solution capable of dynamic permission adaptation, intelligent matching analysis, and accurate early warning is urgently needed. Thus, improving the efficiency of a dynamic permission-based student dormitory access early warning system has become a pressing issue. Summary of the Invention
[0004] This invention provides a student dormitory access warning system and method based on dynamic permissions to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, this invention provides a student dormitory access warning system based on dynamic permissions. The system comprises a permission presetting module, a state adaptation module, a strategy reconstruction module, a rule matching module, an access determination module, and a warning generation module. Specifically: the permission presetting module is used to perform permission association mapping on a standardized dataset of original identity recognition data based on a preset permission mapping rule library, obtaining a static permission configuration table for the standardized dataset; the state adaptation module is used to adjust the scene parameter adaptability between the state update information of the student management database and the access rules in the static permission configuration table, obtaining a state adaptation parameter set for the static permission association table; the strategy reconstruction module is used to adjust the state adaptation parameter set based on the state adaptation parameter set... The system employs a data set to dynamically reconstruct the basic access rules in the static access configuration table, thereby obtaining the real-time dynamic access policy of the static access association table. The rule matching module performs multi-dimensional access rule matching based on the real-time dynamic access policy, analyzing the spatiotemporal characteristics of current access requests in the target student dormitory to obtain the access matching analysis result of the current access request. The access determination module confirms the access compliance status of the access matching analysis result and the current access request, obtaining the accessibility determination result of the current access request. The early warning generation module, based on a preset early warning policy library, structurally integrates access requests with violation determination results to obtain a standardized early warning report for the violation access requests.
[0006] In a preferred embodiment, when the permission presetting module performs permission association mapping on a standardized dataset of original identity recognition data based on a preset permission mapping rule base to obtain a static permission configuration table for the standardized dataset, it specifically performs the following steps: standardizing the format of the original identity recognition data to obtain a standardized dataset of the original identity recognition data; extracting multi-dimensional features from the standardized dataset to obtain an identity feature vector set of the standardized dataset; performing a unique encoding deterministic mapping on the identity feature vector set based on a student management database to obtain the subject identity code of the identity feature vector set; and performing basic permission rule mapping on the subject identity code based on the preset permission mapping rule base to obtain a static permission configuration table for the standardized dataset.
[0007] In a preferred embodiment, when the state adaptation module performs scenario parameter adaptation adjustment on the state update information of the student management database and the access rules in the static permission configuration table to obtain the state adaptation parameter set of the static permission association table, it specifically performs the following: performs multimodal semantic parsing on the state update information of the student management database to obtain a state change event description of the state update information; performs parameter association parsing on the access rules in the static permission configuration table based on the state type and influence domain in the state change event description to obtain a set of rule parameters to be adjusted for the access rules; performs dynamic parameter adjustment on the set of rule parameters to be adjusted based on the timeliness attribute and logical constraints in the state change event description to obtain an adaptation parameter set for the state change event description; and restructures the adaptation parameter set and the set of rule parameters to be adjusted to obtain the state adaptation parameter set of the static permission configuration table.
[0008] In a preferred embodiment, when the policy reconstruction module performs dynamic rule reconstruction on the basic admission rules in the static permission configuration table based on the state adaptation parameter set to obtain the real-time dynamic permission policy of the static permission association table, it specifically performs the following steps: based on the state adaptation parameter set, it performs deterministic retrieval of influence rules on the static permission configuration table to obtain the target basic admission rules of the state adaptation parameter set, and performs topological relationship deduction on the target basic admission rules to obtain the dynamic reconstruction rule association table of the static permission configuration table; based on the dynamic reconstruction rule association table, it performs logical semantic parsing on the target basic admission rules, and uses the core admission judgment of the target basic admission rules as the root node to establish an aggregate rule logical dependency tree of the target basic admission rules; based on the state adaptation parameter set, it performs parameter-driven distributed logic calculation on the aggregate rule logical dependency tree to obtain the preliminary dynamic rules of the state adaptation parameter set; and it performs policy consistency fusion on the preliminary dynamic rules to obtain the real-time dynamic permission policy of the static permission association table.
[0009] In a preferred embodiment, when the strategy reconstruction module performs parameter-driven distributed logic computation on the aggregated rule logical dependency tree based on the state adaptation parameter set to obtain preliminary dynamic rules for the state adaptation parameter set, it specifically performs the following: constructing a topology network for the aggregated rule logical dependency tree and the state adaptation parameter set to obtain a parallel computation task scheduling graph for the state adaptation parameter set; loading parameter values in parallel for the state adaptation parameter set and the aggregated rule logical dependency tree based on the parallel computation task scheduling graph to obtain a parameter instantiation dependency tree for the state adaptation parameter set; performing multi-path logic deduction on the parameter instantiation dependency tree to obtain multi-branch logical paths of the parameter instantiation dependency tree, and performing state vectorization encoding on the multi-branch logical paths to obtain logical state vectors of the multi-branch logical paths; and reconstructing the rule logic of the parameter instantiation dependency tree based on the distribution characteristics of the logical state vectors to obtain preliminary dynamic rules for the state adaptation parameter set.
[0010] In a preferred embodiment, when the rule matching module performs multi-dimensional permission rule matching on the spatiotemporal features of the current access request in the target student dormitory based on the real-time dynamic permission policy to obtain the permission matching analysis result of the current access request, it specifically performs the following: feature tensor quantization on the spatiotemporal features of the current access request in the target student dormitory to obtain a composite feature tensor of the current access request; based on the multi-dimensional rule structure of the real-time dynamic permission policy, cross-dimensional rule similarity measurement is performed on the composite feature tensor to obtain a multi-dimensional rule matching vector set of the composite feature tensor, and logical conflict marking is applied to the multi-dimensional rule matching vector set to obtain a multi-dimensional rule matching vector set with conflict marking; policy weighted fusion is performed on the multi-dimensional rule matching vector set with conflict marking to obtain a comprehensive rule matching degree of the current access request; and structured encapsulation is performed on the comprehensive permission matching degree, the multi-dimensional rule matching vector set with conflict marking, and the composite feature tensor to obtain the permission matching analysis result of the current access request.
[0011] In a preferred embodiment, the rule matching module performs a policy-weighted fusion of the multi-dimensional rule matching vector set with conflict markers to obtain the comprehensive rule matching degree of the current inbound / outbound request, wherein the formula for calculating the comprehensive rule matching degree is as follows: In the formula, This indicates the overall rule matching degree of the current inbound / outbound request. It represents three dimensions: time, space, and behavior. Indicates the first Conflict-adjusted weights for each dimension This represents the preset conflict reduction coefficient of the multidimensional rule matching vector set. Indicates the first The severity of conflict in each dimension Indicates the first Maximum matching degree in each dimension Represents a linear fusion function. Represents the smoothing constant. This represents the maximum value function.
[0012] In a preferred embodiment, when the access determination module performs access compliance status confirmation on the permission matching analysis result and the current access request to obtain the accessibility determination result of the current access request, it specifically performs the following steps: comparing the comprehensive permission matching degree in the permission matching analysis result with a preset access threshold to obtain the preliminary access status of the current access request; based on the real-time dynamic permission policy, performing rule conflict verification on the permission matching analysis result to obtain conflicting rules that contradict the preliminary access status, and extracting the violation features of the conflicting rules; making conflict resolution decisions on the preliminary access status and the conflict verification result to obtain the final access status of the current access request; and integrating the final access status with the violation features to obtain the accessibility determination result of the current access request.
[0013] In a preferred embodiment, when the early warning generation module performs structured integration of access requests with violation results based on a preset early warning strategy library to obtain a standardized early warning report for the violation access requests, it specifically performs the following: encapsulates the access determination result and the access requests with violation results into related data to obtain a violation event record of the access determination result; retrieves response rules from the preset early warning strategy library based on the violation characteristics in the violation event record to obtain an early warning response rule corresponding to the structured violation event record; performs structured integration of the structured violation event record based on the early warning response rule to obtain a preliminary early warning report; and performs format standardization verification on the preliminary early warning report to obtain a standardized early warning report for the violation access requests.
[0014] To address the aforementioned problems, this invention also provides a student dormitory access warning method based on dynamic permissions. The method includes: S1, performing permission association mapping on a standardized dataset of original identity recognition data based on a preset permission mapping rule base to obtain a static permission configuration table for the standardized dataset; S2, adjusting the scene parameter adaptability between the status update information of the student management database and the access rules in the static permission configuration table to obtain a status adaptation parameter set for the static permission association table; S3, dynamically adjusting the basic access rules in the static permission configuration table based on the status adaptation parameter set. S4. Based on the real-time dynamic permission policy, the spatiotemporal characteristics of the current access request in the target student dormitory are matched with multi-dimensional permission rules to obtain the permission matching analysis result of the current access request; S5. The access compliance status of the permission matching analysis result and the current access request is confirmed to obtain the accessibility determination result of the current access request; S6. Based on the preset early warning policy library, the access requests with the accessibility determination result of violation are structurally integrated to obtain the standardized early warning report of the violation access request.
[0015] Compared with existing technologies, this invention has the following beneficial effects: 1. By establishing a dynamic generation and adaptation mechanism for permissions, the accuracy and real-time performance of student dormitory access management are significantly improved. The system can automatically respond to real-time changes in student status, instantly converting the status updates of the student affairs system into precise permission adjustment parameters, achieving seamless synchronization between permissions and individual real status. By constructing a multi-dimensional rule matching and intelligent analysis engine, the system can perform refined permission verification for complex access scenarios, identify potential rule conflicts, and output structured matching analysis reports, providing a reliable basis for accurate decision-making. This technical approach fundamentally solves the problems of lagging and rigid traditional static permission management, ensuring that the management goal of "those who should enter can enter, and those who should not enter cannot enter" is intelligently achieved.
[0016] 2. Furthermore, through a standardized early warning generation process, the system achieves standardization and closed-loop management of safety management responses. Based on the deep characteristics of violations, the system can automatically match early warning strategies and generate standardized early warning reports with complete structure and elements, significantly improving the readability, operability, and traceability of early warning information. The entire technical solution forms a fully automated closed loop from status perception, dynamic authorization, real-time matching, intelligent judgment to accurate early warning, greatly reducing the cost of manual intervention and the risk of operational errors, providing core technical support for building a smart, refined, and highly efficient student dormitory safety management system. Attached Figure Description
[0017] Figure 1 is a system architecture diagram of a student dormitory access warning system based on dynamic permissions according to an embodiment of the present invention; Figure 2 is a flowchart of a student dormitory access warning method based on dynamic permissions according to an embodiment of the present invention.
[0018] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments belong to some, but not all, embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] The terminology used in the embodiments of this invention is for the purpose of describing particular embodiments only and is not intended to limit the invention. The singular forms “said” and “the” as used in the embodiments of this invention and the appended claims are also intended to include the plural forms, and “multiple” generally includes at least two unless the context clearly indicates otherwise.
[0021] Depending on the context, the word "if" or "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."
[0022] Furthermore, the timing of the steps in the following method embodiments is merely an example and not a strict limitation.
[0023] In practice, the server-side equipment deployed in a student dormitory access control system based on dynamic permissions may consist of one or more devices. This system can be implemented as a business instance, a virtual machine, or hardware devices. For example, it can be implemented as a business instance deployed on one or more devices in a cloud node. Simply put, it can be understood as software deployed on a cloud node to provide a dynamic permission-based access control system for each user. Alternatively, it can be implemented as a virtual machine deployed on one or more devices in a cloud node, with application software installed to manage each user. Or, it can also be implemented as a server composed of numerous identical or different types of hardware devices, with one or more devices configured to provide a dynamic permission-based access control system for each user.
[0024] In terms of implementation, a student dormitory access control system based on dynamic permissions and its user client are mutually compatible. Specifically, if the system is implemented as an application installed on a cloud service platform, the user client acts as a client establishing a communication connection with that application; or if the system is implemented as a website, the user client acts as a webpage; or if the system is implemented as a cloud service platform, the user client acts as a mini-program within an instant messaging application.
[0025] Figure 1 shows a system architecture diagram of a student dormitory access warning system based on dynamic permissions provided in an embodiment of the present invention.
[0026] The student dormitory access warning system 100 based on dynamic permissions described in this invention can be set up in a cloud server. In terms of implementation, it can be implemented as one or more service devices, or as an application installed in the cloud (e.g., a mobile service operator's server, server cluster, etc.), or it can be developed as a website. Depending on the implemented functions, the student dormitory access warning system 100 based on dynamic permissions may include a permission preset module 101, a state adaptation module 102, a strategy reconstruction module 103, a rule matching module 104, an access determination module 105, and a warning generation module 106. The modules described in this invention can also be called units, referring to a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, stored in the memory of the electronic device.
[0027] In this embodiment of the invention, a student dormitory access control system based on dynamic permissions allows each of the aforementioned modules to be implemented independently and to call other modules. This "calling" can be understood as a module connecting to multiple modules of another type and providing corresponding services to those connected modules. This embodiment of the invention provides a student dormitory access control system based on dynamic permissions that allows for adjustments to the system's architecture without modifying the program code. This is achieved by adding modules and directly calling them, enabling cluster-based horizontal expansion and flexibly expanding the system. In practical applications, these modules can be located on the same or different devices, or in virtual devices, such as service instances on a cloud server.
[0028] The following describes, with reference to specific embodiments, the various components and specific workflows of a student dormitory access warning system based on dynamic permissions: The permission presetting module 101 is used to perform permission association mapping on a standardized dataset of original identity recognition data based on a preset permission mapping rule base to obtain a static permission configuration table of the standardized dataset; In this embodiment of the invention, when the permission presetting module performs permission association mapping on a standardized dataset of original identity recognition data based on a preset permission mapping rule base to obtain a static permission configuration table of the standardized dataset, it is specifically used for: performing format normalization processing on the original identity recognition data to obtain a standardized dataset of the original identity recognition data; performing multi-dimensional feature extraction on the standardized dataset to obtain an identity feature vector set of the standardized dataset; performing unique encoding deterministic mapping on the identity feature vector set based on a student management database to obtain the subject identity code of the identity feature vector set; and performing basic permission rule mapping on the subject identity code based on a preset permission mapping rule base to obtain a static permission configuration table of the standardized dataset.
[0029] The system receives raw identity verification data from various identification devices, which may include student ID strings, photo files, or card swipe records. This diverse data type and format is then uniformly converted into a standard format agreed upon internally by the system. Specifically, text information is encoded into fixed-length strings, image information is decoded into a pixel matrix of uniform resolution, and timestamps are converted into a standard time format. The resulting dataset after format conversion and cleaning is the standardized dataset, ensuring that all subsequent processing is based on a consistent data structure.
[0030] Discriminating features are extracted from each data item in the standardized dataset. For image data, geometric relationships or texture features of facial key points are extracted. For text data, pattern or statistical features of character sequences are extracted. For time data, periodic or sequence features are extracted. All feature values extracted from each data item are concatenated into a long array in a fixed order. This set of feature arrays for all data items is the identity feature vector set, where each vector represents a multi-dimensional quantitative description of the corresponding original data.
[0031] Each feature vector in the identity feature vector set is compared one by one with the pre-stored registered student feature templates in the student management database. The comparison process involves calculating the similarity score between the vector to be identified and each template vector. The template with the highest similarity score exceeding a preset threshold is selected as the student's unique identifier. This identifier is the subject identity code, which explicitly associates the feature vector with a specific student individual.
[0032] Based on the student individual corresponding to the subject identity code, all access rules applicable to that student are searched in the permission mapping rule base. These rules define the operations that the student can perform at different times and locations. These found rules are then bound to the student's subject identity code and organized in a fixed tabular format to form a permission list for that student. This complete list constitutes the static permission configuration table of the standardized dataset, establishing an initial set of basic permission rules for the student that does not consider real-time status changes.
[0033] The beneficial effect is that format standardization unifies the diverse and heterogeneous original identity data into a standard structure, laying the data foundation for subsequent processing. Multi-dimensional features are systematically extracted from the standardized data and organized into vector sets, achieving a quantitative representation of identity information. By accurately comparing and mapping the feature vectors with database templates, a unique and definite subject identifier is assigned to each identified identity. Based on the subject identifier, corresponding basic permissions are mapped from the rule base and organized into a configuration table, establishing a clear association between identity and static permissions.
[0034] The state adaptation module 102 is used to adjust the scene parameters of the state update information of the student management database and the access rules in the static permission configuration table to obtain the state adaptation parameter set of the static permission association table. When performing the scene parameter adaptation adjustment of the state update information of the student management database and the access rules in the static permission configuration table to obtain the state adaptation parameter set of the static permission association table, the state adaptation module specifically performs the following: multimodal semantic parsing of the state update information of the student management database to obtain a state change event description of the state update information; parameter association parsing of the access rules in the static permission configuration table based on the state type and influence domain in the state change event description to obtain a set of rule parameters to be adjusted for the access rules; dynamic parameter adjustment of the set of rule parameters to be adjusted based on the timeliness attribute and logical constraints in the state change event description to obtain an adaptation parameter set for the state change event description; and structured recombination of the adaptation parameter set and the set of rule parameters to be adjusted to obtain the state adaptation parameter set of the static permission configuration table.
[0035] Analyze update information from the student management database and interpret descriptions of student status changes. Identify specific events that occurred from the update text, such as student registration, dormitory changes, or disciplinary records. Extract the type of this specific event, the scope of those involved, and its core content to form a clear statement. This statement is the status change event description, which summarizes the core semantics of this update in natural language.
[0036] Based on the event type and affected student group range mentioned in the state change event description, locate the relevant admission rules in the static permission configuration table. Examine the conditions defined in each rule to identify parameters whose values or judgment logic might change due to this event. Collect all these potentially affected or re-evaluated parameters. This collected set of parameters constitutes the set of admission rule parameters to be adjusted.
[0037] By combining the time-sensitive attributes such as the event's effective time and duration in the state change event description, as well as any logical constraints that the event itself may have, the values of various parameters or the judgment logic in the set of rules to be adjusted are modified. For example, the effective time window of a parameter can be set based on the event's validity period, or the threshold of a parameter can be adjusted based on the severity of the event. This adjustment process generates a new set of parameter values or logical definitions that match the current event description. This newly generated set of parameters is the adaptation parameter set for the state change event description.
[0038] The newly generated set of adaptive parameters is merged and integrated with the original set of rules to be adjusted. During the merging process, the new parameter values in the adaptive parameter set overwrite the corresponding old values in the original parameter set, while parameters in the original parameter set that were not affected by this event remain unchanged. This results in a complete and unified parameter set, which includes parameters specifically adjusted in response to this state update, as well as the original parameters that do not require adjustment. This final complete parameter set is the state adaptation parameter set of the static permission configuration table.
[0039] The beneficial effect is that by parsing database update information, a clear event description is obtained, providing clear semantic input for subsequent rule adjustments. Based on event type and scope of impact, the set of parameters requiring adjustment in relevant rules is accurately located, ensuring that adjustments are targeted. Parameters are dynamically adjusted by combining the event's timeliness and logical constraints, generating a new parameter set that matches the current event. The old and new parameter sets are then structurally reorganized to form the final adapted parameter set, achieving synchronous updates and adaptation of permission rule parameters with database state changes.
[0040] The policy reconstruction module 103 is used to dynamically reconstruct the basic access rules in the static permission configuration table based on the state adaptation parameter set, to obtain the real-time dynamic permission policy of the static permission association table. When the policy reconstruction module performs dynamic rule reconstruction based on the state adaptation parameter set to obtain the real-time dynamic permission policy of the static permission association table, it is specifically used to: perform deterministic retrieval of influence rules in the static permission configuration table based on the state adaptation parameter set, to obtain the target basic access rule of the state adaptation parameter set, and to... The admission rules are used to deduce topological relationships, resulting in a dynamic reconstruction rule association table for the static permission configuration table. Based on the dynamic reconstruction rule association table, the target basic admission rules are subjected to logical semantic parsing, and the core admission judgment of the target basic admission rules is used as the root node to establish an aggregate rule logical dependency tree for the target basic admission rules. Based on the state adaptation parameter set, parameter-driven distributed logic calculation is performed on the aggregate rule logical dependency tree to obtain preliminary dynamic rules for the state adaptation parameter set. The preliminary dynamic rules are then subjected to policy consistency fusion to obtain the real-time dynamic permission policy for the static permission association table.
[0041] When the strategy reconstruction module performs parameter-driven distributed logic computation on the aggregated rule logical dependency tree based on the state adaptation parameter set to obtain preliminary dynamic rules for the state adaptation parameter set, it specifically performs the following: constructing a topology network for the aggregated rule logical dependency tree and the state adaptation parameter set to obtain a parallel computation task scheduling graph for the state adaptation parameter set; loading parameter values in parallel for the state adaptation parameter set and the aggregated rule logical dependency tree based on the parallel computation task scheduling graph to obtain a parameter instantiation dependency tree for the state adaptation parameter set; performing multi-path logic deduction on the parameter instantiation dependency tree to obtain multi-branch logical paths of the parameter instantiation dependency tree, and performing state vectorization encoding on the multi-branch logical paths to obtain logical state vectors of the multi-branch logical paths; and reconstructing the rule logic of the parameter instantiation dependency tree based on the distribution characteristics of the logical state vectors to obtain preliminary dynamic rules for the state adaptation parameter set.
[0042] Based on the state adaptation parameter set, the static permission configuration table is searched for rules whose effective conditions match the state described by that parameter set. These retrieved rules are called target basic admission rules. The implicit hierarchical or dependency relationships between these target basic admission rules are analyzed, and these relationships are clarified and organized into a table. This table is the dynamic refactoring rule association table, which describes the topological structure between rules.
[0043] Based on the relationships revealed in the dynamic reconstruction rule association table, the admission conditions and conclusions expressed by each target basic admission rule are analyzed one by one. Taking the final core admission judgment conclusion of each rule as the logical starting point, its preconditions are used as child nodes, and related rules are connected according to the dependencies between rules. In this way, a tree structure is constructed for each target basic admission rule, displaying its complete logical premises and associated rules. The collection of all these trees is the aggregate rule logical dependency tree.
[0044] The specific values from the state adaptation parameter set are substituted into the conditions of each node in the aggregation rule logical dependency tree for judgment. This process requires creating independent computation tasks and arranging the execution order for the parallel computation logical branches in the tree, forming a parallel computation task scheduling graph. Based on this scheduling graph, parameter values are simultaneously loaded into multiple logical branches, generating a new tree where all nodes have been instantiated with specific parameter values, i.e., the parameter instantiation dependency tree. All possible judgment paths from the root node to each leaf node in the parameter instantiation dependency tree are deduced, recording the logical truth / false state sequence generated when passing through nodes on each path. These logical state sequences are encoded into vectors with a fixed format, obtaining the logical state vectors of the multi-branch logical paths. Based on the distribution pattern of all logical state vectors, the logical structure of the parameter instantiation dependency tree is merged, simplified, and reconstructed to form a new set of rules adapted to the current parameter state. This new set of rules is the preliminary dynamic rule set for the state adaptation parameter set.
[0045] The initial dynamic rules are compared and integrated with the existing static permission association table. Any inconsistencies in permission determination between the new rules and the existing static rules are checked, and these inconsistencies are resolved according to preset strategies. Finally, all consistent and effective rules, including the newly calculated rules and compatible existing static rules, are unified and organized. This final, organized set of the latest complete rules applicable to the current state constitutes the real-time dynamic permission policy of the static permission association table.
[0046] The beneficial effect is that the basic rules are accurately retrieved and their interrelationships are clarified through state parameters, laying a structural foundation for subsequent logical analysis. The logical semantics and dependencies of the rules are constructed into a tree model, achieving a clear expression and structured organization of complex rule systems. Parameter-driven instantiation and parallel computation of the logic tree efficiently deduce multiple logical paths adaptable to specific states. Preliminary dynamic rules are reconstructed based on the encoding results of the logical paths, enabling the rules to flexibly respond to state changes. Finally, the new rules are consistently integrated with the original strategy to generate a complete and self-consistent real-time dynamic permission strategy, realizing the dynamic adjustment and optimization of the permission strategy.
[0047] The rule matching module 104 is used to perform multi-dimensional permission rule matching on the spatiotemporal features of the current access request in the target student dormitory based on the real-time dynamic permission policy, and obtain the permission matching analysis result of the current access request; when the rule matching module performs multi-dimensional permission rule matching on the spatiotemporal features of the current access request in the target student dormitory based on the real-time dynamic permission policy, it is specifically used to: perform feature tensor quantization on the spatiotemporal features of the current access request in the target student dormitory, and obtain the composite feature tensor of the current access request; based on the real-time dynamic permission policy, the rule matching module performs multi-dimensional permission rule matching on the spatiotemporal features of the current access request in the target student dormitory, and obtains the permission matching analysis result .... The multi-dimensional rule structure of the dynamic permission policy is used to perform cross-dimensional rule similarity measurement on the composite feature tensor to obtain a multi-dimensional rule matching vector set of the composite feature tensor. Logical conflict marking is then applied to the multi-dimensional rule matching vector set to obtain a conflict-marked multi-dimensional rule matching vector set. Policy-weighted fusion is performed on the conflict-marked multi-dimensional rule matching vector set to obtain the comprehensive rule matching degree of the current access request. The comprehensive permission matching degree, the conflict-marked multi-dimensional rule matching vector set, and the composite feature tensor are then structurally encapsulated to obtain the permission matching analysis result of the current access request.
[0048] The rule matching module performs a policy-weighted fusion of the multi-dimensional rule matching vector set with conflict markers to obtain the comprehensive rule matching degree of the current inbound / outbound request. The formula for calculating the comprehensive rule matching degree is as follows: In the formula, This indicates the overall rule matching degree of the current inbound / outbound request. It represents three dimensions: time, space, and behavior. Indicates the first Conflict-adjusted weights for each dimension This represents the preset conflict reduction coefficient of the multidimensional rule matching vector set. Indicates the first The severity of conflict in each dimension Indicates the first Maximum matching degree in each dimension Represents a linear fusion function. Represents the smoothing constant. This represents the maximum value function.
[0049] The parameters in the formula are derived from the intermediate results generated during the multi-dimensional rule matching process of the current inbound / outbound request and the system's preset configuration values. The conflict-adjusted weights are obtained by adjusting the original weights of each dimension using a conflict reduction coefficient and conflict severity. The maximum matching degree is the highest matching value calculated for each dimension during the rule matching process. The linear fusion function and smoothing constant are preset values used to control the calculation method of the comprehensive rule matching degree. The maximum value function is used to select the largest conflict-adjusted weight from all dimensions.
[0050] The formula is used to calculate the overall rule matching degree of the current inbound / outbound request. It integrates the matching contributions of the three dimensions through a combination of linear weighting and geometric mean. The first part involves a weighted sum and normalization of the products of the conflict-adjusted weights of the time, space, and behavior dimensions and the maximum matching degree. The second part calculates the geometric mean of the standardized and smoothed values of the three dimensions. The final overall rule matching degree is a weighted mixture of the results from these two parts, with the weights determined by a linear fusion function. The entire calculation process considers the conflict adjustment of the weights for each dimension and the matching degree, aiming to balance the influence of each dimension and smooth out extreme values, thereby obtaining a comprehensive and stable rule matching evaluation value.
[0051] Extract the time, location, and behavioral information of the current entry / exit request as raw features. Transform these raw features into numerical form and combine them into a multidimensional array. This multidimensional array is the composite feature tensor, which fully represents the quantized state of the request in the time, space, and behavioral dimensions. This composite feature tensor will serve as the input for subsequent rule matching.
[0052] The composite feature tensor is compared one by one with the spatiotemporal behavioral conditions of each rule in the real-time dynamic permission policy. The comparison process calculates the closeness of the composite feature tensor's value in each dimension to the corresponding dimensional condition range of the rule; this closeness is a value between zero and one. Each rule generates a vector containing the matching degree across three dimensions for the current request. The set of these vectors generated by all rules constitutes the multidimensional rule matching vector set. Next, it is checked whether different rules in the multidimensional rule matching vector set give diametrically opposed matching conclusions in the same dimension. Matching vectors with such obvious logical contradictions are specially marked. The result of this process is a multidimensional rule matching vector set with conflict markers.
[0053] From the set of multi-dimensional rule matching vectors with conflict markers, the highest matching score for each dimension is selected as the representative value for that dimension. The pre-assigned weights for each dimension are adjusted based on the presence or absence of conflict markers. A weighted average of the representative matching scores for the three dimensions is calculated using these adjusted weights to obtain a preliminary result. Simultaneously, the geometric mean of the three representative matching scores, after standardization and smoothing, is calculated as another result. The weighted average and geometric mean results are combined using a preset fusion ratio. The final value obtained from this combination is the comprehensive rule matching score for the current inbound / outbound request.
[0054] The calculated comprehensive rule matching degree is combined with the multi-dimensional rule matching vector set with conflict markers generated in the previous steps and the initially constructed composite feature tensor. This information is then encapsulated into a structured record according to a fixed data format. This record fully contains the feature matching process of the request and the final evaluation result. This encapsulated structured record is the permission matching analysis result of the current access request.
[0055] The beneficial effect is that by transforming the features of inbound and outbound requests into standardized tensor data, a precise description of the request status is achieved. Cross-dimensional similarity comparison is performed between the composite feature tensor and multi-dimensional rules, and logical conflicts are marked, ensuring the comprehensiveness of the rule matching process and the identification of contradictions. The matching results marked with conflicts are strategically weighted and fused to ultimately generate a stable and balanced comprehensive rule matching degree. All key data and process results are structured and encapsulated to form a complete and traceable permission matching analysis result, providing a clear and reliable basis for subsequent permission decisions.
[0056] The access determination module 105 is used to confirm the access compliance status of the permission matching analysis result and the current access request to obtain the accessibility determination result of the current access request. Specifically, when performing the access compliance status confirmation of the permission matching analysis result and the current access request to obtain the accessibility determination result of the current access request, the access determination module is used to: compare the comprehensive permission matching degree in the permission matching analysis result with a preset access threshold to obtain the preliminary access status of the current access request; based on the real-time dynamic permission policy, perform rule conflict verification on the permission matching analysis result to obtain conflicting rules that contradict the preliminary access status, and extract the violation characteristics of the conflicting rules; make a conflict resolution decision on the preliminary access status and the conflict verification result to obtain the final access status of the current access request; and integrate the final access status with the violation characteristics to obtain the accessibility determination result of the current access request.
[0057] When comparing the overall permission matching degree in the permission matching analysis result with the preset admission threshold, the system reads the quantified overall permission matching degree value from the permission matching analysis result. Simultaneously, the system retrieves the preset admission threshold, which is a clearly defined numerical boundary. The system performs a numerical comparison operation; if the overall permission matching degree is greater than or equal to the admission threshold, a preliminary admission status marked as "passed" is generated; if the overall permission matching degree is less than the admission threshold, a preliminary admission status marked as "rejected" is generated. This comparison process directly generates a clear binary judgment result based on the numerical relationship, namely the preliminary admission status of the current access request.
[0058] When performing rule conflict checks on the permission matching analysis results based on the real-time dynamic permission policy, the system first extracts detailed dimension matching details and potential conflict markers from the permission matching analysis results. Simultaneously, the system retrieves all currently effective global or high-level constraint rules in the real-time dynamic permission policy. The system logically compares the initial access status with these constraint rules to check for situations where the initial access status indicates permission, but a high-level constraint rule determines prohibition based on certain dimension details in the permission matching analysis results. When such a logical contradiction is found, the system locates the constraint rule that directly contradicts the initial access status; this rule is the conflicting rule. The system further analyzes the specific conditions violated by the conflicting rule, transforming them into a readable violation description, thereby extracting the violation characteristics of the conflicting rule.
[0059] When making conflict resolution decisions regarding the preliminary access status and the conflict check results, the system handles the contradictions between the preliminary access status and the conflict check results according to a set of preset conflict resolution criteria. These criteria explicitly state that when a conflict rule is detected, the security status indicated by the conflict rule takes precedence, regardless of the preliminary access status. Therefore, if the conflict check results indicate the existence of a prohibitive conflict rule, the system overrides the current request's decision to a prohibited status; if the conflict check finds no contradiction or the conflict rule supports passage, the preliminary access status is maintained. By applying this criterion for adjudication, the system generates a definite and unique decision, namely the final access status of the current access request.
[0060] When integrating the final access status with the violation characteristics, the system creates a structured data container to hold the access determination result. The system fills in the final access status as the core conclusion field of this container. Simultaneously, it associates the violation characteristics extracted from conflict checks as detailed violation reason fields. Furthermore, the system integrates a summary of key information on which this determination is based, such as the conflict rule identifier that triggered the decision, as a determination basis field into this data structure. By organizing these discrete information elements into a unified structure with fixed field definitions, the system completes information integration and generates the access determination result for the current access request.
[0061] The beneficial effects are reflected in the construction of a well-structured and security-redundant intelligent access control mechanism. The system achieves efficient preliminary adjudication by comparing quantified matching degrees with fixed thresholds, providing a clear starting point for subsequent complex analyses. The introduction of real-time policy-based rule conflict verification can identify and locate potential contradictions between the preliminary judgment and higher-level security constraints, effectively preventing access vulnerabilities. The use of preset conflict resolution criteria for authoritative arbitration of discovered contradictions ensures the uniqueness and high reliability of the final adjudication result. Finally, through structured information integration, the adjudication conclusion, the reasons for violation, and the basis for judgment are merged into a standardized judgment result, achieving transparency in the decision-making process and interpretability of the results.
[0062] The early warning generation module 106 is used to structurally integrate the access control requests that are deemed to be in violation of the access control criteria based on a preset early warning strategy library, and obtain a standardized early warning report for the in violation access control requests.
[0063] When the early warning generation module executes a pre-set early warning strategy library to structurally integrate access requests with violation results to obtain a standardized early warning report for the violation access requests, it specifically performs the following steps: encapsulates the access determination result and the access requests with violation results into related data to obtain a violation event record of the access determination result; retrieves response rules from the pre-set early warning strategy library based on the violation characteristics in the violation event record to obtain the early warning response rules corresponding to the structured violation event record; structurally integrates the structured violation event record based on the early warning response rules to obtain a preliminary early warning report; and performs format standardization verification on the preliminary early warning report to obtain a standardized early warning report for the violation access requests.
[0064] When encapsulating the accessibility determination result and the access request that is deemed a violation, the system associates and merges the final access status, violation characteristics, and risk level contained in the accessibility determination result with the spatiotemporal characteristics and subject identifier contained in the violation access request. The system generates a unique event identifier for this event and organizes all the aforementioned data items as attribute values under this identifier, forming a complete and self-describing structured data record. This structured data record is the violation event record of the accessibility determination result, and its internal data structure ensures that each attribute has a clearly defined field.
[0065] When retrieving response rules from a pre-defined early warning strategy library based on the violation characteristics in the violation event records, the system extracts violation feature values representing the violation type and risk level from the violation event records. These feature values are used as composite query conditions and input into the early warning strategy library for precise matching. The early warning strategy library is a predefined set of rules, each rule defining the early warning action, notification recipient, and report template to be taken for a specific combination of violation type and risk level. By comparison, the system retrieves the early warning response rule that perfectly matches or best matches the current violation characteristics; this rule is the early warning response rule corresponding to the structured violation event record.
[0066] When the system integrates the structured violation event records based on the aforementioned warning response rules, it first reads the report template specified in the rules. This template is a pre-defined framework that defines the chapter structure of the warning report, fixed text, and variable placeholders that need to be dynamically filled. The system then parses the structured violation event records, extracting corresponding data, such as the event time, location, involved entity identification, and specific violation description, and fills them into the corresponding variable placeholders in the report template. Based on the warning actions and notification recipient information defined in the rules, the system generates specific handling suggestions and a distribution list in the corresponding chapter of the report. By combining the specific data with the fixed template, the system generates a preliminary warning report that is complete in content but whose format is yet to be finalized.
[0067] When performing format standardization verification on the preliminary warning report, the system checks each item according to a predefined report format specification. This check includes verifying that all required fields are filled, the data format meets requirements, the chapter order is correct, and there are no logical inconsistencies. For example, the system verifies whether the time field is a valid timestamp format and whether the text description of the risk level matches the numerical level. If any non-compliance with the format specification or logical errors are found, the system will automatically adjust it according to preset correction rules or mark it as requiring manual review. After all verifications are passed, the system outputs a standardized warning report for the violation request that is formatted correctly, accurate in content, and ready for direct distribution.
[0068] The beneficial effects are reflected in the construction of a complete automated processing chain from violation event identification to standardized early warning report generation. The system uses precise data association and encapsulation technology to fuse discrete judgment results and request information into structured event records, laying the data foundation for subsequent intelligent processing. A feature-matching-based rule retrieval mechanism can quickly locate the most suitable early warning response strategy, ensuring the relevance and timeliness of the handling plan. A template-driven structured integration method injects specific event data into a standardized framework, efficiently generating comprehensive preliminary reports. Finally, a rigorous format standardization verification process ensures the standardization and reliability of the output reports, achieving standardization and closed-loop management of the early warning information production process.
[0069] Referring to Figure 2, it is a flowchart illustrating a student dormitory access warning method based on dynamic permissions according to an embodiment of the present invention. In this embodiment, the student dormitory access warning method based on dynamic permissions includes: S1, performing permission association mapping on a standardized dataset of original identity recognition data based on a preset permission mapping rule library to obtain a static permission configuration table of the standardized dataset; S2, adjusting the scene parameter adaptability of the status update information of the student management database with the access rules in the static permission configuration table to obtain a status adaptation parameter set of the static permission association table; S3, dynamically reconstructing the basic access rules in the static permission configuration table based on the status adaptation parameter set to obtain a real-time dynamic permission strategy of the static permission association table; S4, performing multi-dimensional permission rule matching on the spatiotemporal features of the current access request in the target student dormitory based on the real-time dynamic permission strategy to obtain a permission matching analysis result of the current access request; S5, confirming the access compliance status of the permission matching analysis result and the current access request to obtain an accessibility determination result of the current access request; S6, performing structured integration on the accessibility determination result of the access request based on a preset warning strategy library to obtain a standardized warning report of the access violation request.
[0070] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0071] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0072] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A student dormitory access warning system based on dynamic permissions, characterized in that, The system includes a permission presetting module, a state adaptation module, a strategy reconstruction module, a rule matching module, an access determination module, and an early warning generation module. Specifically: the permission presetting module is used to perform permission association mapping on a standardized dataset of original identity recognition data based on a preset permission mapping rule base, obtaining a static permission configuration table for the standardized dataset; the state adaptation module is used to adjust the scene parameter adaptability between the state update information of the student management database and the access rules in the static permission configuration table, obtaining a state adaptation parameter set for the static permission association table; the strategy reconstruction module is used to adjust the basic access rules in the static permission configuration table based on the state adaptation parameter set. The system then performs dynamic rule reconstruction to obtain the real-time dynamic permission policy of the static permission association table. The rule matching module is used to perform multi-dimensional permission rule matching on the spatiotemporal characteristics of the current access request in the target student dormitory based on the real-time dynamic permission policy, and obtain the permission matching analysis result of the current access request. The access determination module is used to confirm the access compliance status of the permission matching analysis result and the current access request, and obtain the accessibility determination result of the current access request. The early warning generation module is used to perform structured integration on the accessibility determination result of the access request as a violation based on a preset early warning policy library, and obtain a standardized early warning report of the violation access request.
2. The student dormitory access warning system based on dynamic permissions as described in claim 1, characterized in that, When the permission pre-setting module executes permission association mapping on the standardized dataset of the original identity recognition data based on a preset permission mapping rule base to obtain a static permission configuration table of the standardized dataset, it is specifically used for: performing format normalization processing on the original identity recognition data to obtain a standardized dataset of the original identity recognition data; and performing multi-dimensional feature extraction on the standardized dataset to obtain an identity feature vector set of the standardized dataset. Based on the student management database, a unique encoding deterministic mapping is performed on the identity feature vector set to obtain the subject identity code of the identity feature vector set; Based on a preset permission mapping rule base, basic permission rule mapping is performed on the subject identity code to obtain a static permission configuration table for the standardized dataset.
3. The student dormitory access warning system based on dynamic permissions as described in claim 1, characterized in that, When the state adaptation module performs scenario parameter adaptation adjustment on the state update information of the student management database and the access rules in the static permission configuration table to obtain the state adaptation parameter set of the static permission association table, it specifically performs the following: multimodal semantic parsing on the state update information of the student management database to obtain a state change event description of the state update information; parameter association parsing on the access rules in the static permission configuration table based on the state type and influence domain in the state change event description to obtain a set of rule parameters to be adjusted for the access rules; dynamic parameter adjustment on the set of rule parameters to be adjusted based on the timeliness attribute and logical constraints in the state change event description to obtain an adaptation parameter set for the state change event description; and structured reorganization of the adaptation parameter set and the set of rule parameters to be adjusted to obtain the state adaptation parameter set of the static permission configuration table.
4. The student dormitory access warning system based on dynamic permissions as described in claim 1, characterized in that, When the policy reconstruction module performs dynamic rule reconstruction on the basic admission rules in the static permission configuration table based on the state adaptation parameter set to obtain the real-time dynamic permission policy of the static permission association table, it is specifically used for: performing deterministic retrieval of influence rules on the static permission configuration table based on the state adaptation parameter set to obtain the target basic admission rules of the state adaptation parameter set, and performing topological relationship deduction on the target basic admission rules to obtain the dynamic reconstruction rule association table of the static permission configuration table; performing logical semantic parsing on the target basic admission rules based on the dynamic reconstruction rule association table, and establishing an aggregate rule logical dependency tree of the target basic admission rules with the core admission judgment of the target basic admission rules as the root node; Based on the state adaptation parameter set, parameter-driven distributed logic calculation is performed on the aggregation rule logical dependency tree to obtain the preliminary dynamic rules of the state adaptation parameter set; policy consistency fusion is performed on the preliminary dynamic rules to obtain the real-time dynamic permission policy of the static permission association table.
5. The student dormitory access warning system based on dynamic permissions as described in claim 4, characterized in that, When the strategy reconstruction module performs parameter-driven distributed logic computation on the aggregation rule logical dependency tree based on the state adaptation parameter set to obtain the preliminary dynamic rules of the state adaptation parameter set, it is specifically used for: constructing a topology network for the aggregation rule logical dependency tree and the state adaptation parameter set to obtain a parallel computation task scheduling graph for the state adaptation parameter set; and loading parameter values in parallel for the state adaptation parameter set and the aggregation rule logical dependency tree based on the parallel computation task scheduling graph to obtain a parameter instantiation dependency tree for the state adaptation parameter set. Multi-path logic deduction is performed on the parameter instantiation dependency tree to obtain multi-branch logical paths of the parameter instantiation dependency tree, and state vectorization encoding is performed on the multi-branch logical paths to obtain logical state vectors of the multi-branch logical paths; based on the distribution characteristics of the logical state vectors, rule logic reconstruction is performed on the parameter instantiation dependency tree to obtain preliminary dynamic rules of the state adaptation parameter set.
6. The student dormitory access warning system based on dynamic permissions as described in claim 1, characterized in that, When the rule matching module executes multi-dimensional permission rule matching based on the real-time dynamic permission policy to obtain the permission matching analysis result of the current access request in the target student dormitory, it specifically performs the following: feature tensor quantization on the spatiotemporal features of the current access request in the target student dormitory to obtain a composite feature tensor of the current access request; based on the multi-dimensional rule structure of the real-time dynamic permission policy, cross-dimensional rule similarity measurement is performed on the composite feature tensor to obtain a multi-dimensional rule matching vector set of the composite feature tensor, and logical conflict marking is applied to the multi-dimensional rule matching vector set to obtain a multi-dimensional rule matching vector set with conflict marking; policy-weighted fusion is performed on the multi-dimensional rule matching vector set with conflict marking to obtain a comprehensive rule matching degree of the current access request; and structured encapsulation is performed on the comprehensive permission matching degree, the multi-dimensional rule matching vector set with conflict marking, and the composite feature tensor to obtain the permission matching analysis result of the current access request.
7. The student dormitory access warning system based on dynamic permissions as described in claim 6, characterized in that, The rule matching module performs a policy-weighted fusion of the multi-dimensional rule matching vector set with conflict markers to obtain the comprehensive rule matching degree of the current inbound / outbound request. The formula for calculating the comprehensive rule matching degree is as follows: In the formula, This indicates the overall rule matching degree of the current inbound / outbound request. It represents three dimensions: time, space, and behavior. Indicates the first Conflict-adjusted weights for each dimension This represents the preset conflict reduction coefficient of the multidimensional rule matching vector set. Indicates the first The severity of conflict in each dimension Indicates the first Maximum matching degree in each dimension Represents a linear fusion function. Represents the smoothing constant. This represents the maximum value function.
8. The student dormitory access warning system based on dynamic permissions as described in claim 1, characterized in that, When the access determination module performs access compliance status confirmation on the permission matching analysis result and the current access request to obtain the accessibility determination result of the current access request, it is specifically used to: compare the comprehensive permission matching degree in the permission matching analysis result with a preset access threshold to obtain the preliminary access status of the current access request; based on the real-time dynamic permission policy, perform rule conflict verification on the permission matching analysis result to obtain conflicting rules that contradict the preliminary access status, and extract the violation characteristics of the conflicting rules; A conflict resolution decision is made between the preliminary access status and the conflict check result to obtain the final access status of the current access request; The final access status is integrated with the violation characteristics to obtain the accessibility determination result of the current access request.
9. The student dormitory access warning system based on dynamic permissions as described in claim 1, characterized in that, When the early warning generation module executes a pre-set early warning strategy library to structurally integrate access requests with violation results to obtain a standardized early warning report for the violation access requests, it specifically performs the following steps: encapsulates the access determination result and the access requests with violation results into related data to obtain a violation event record of the access determination result; retrieves response rules from the pre-set early warning strategy library based on the violation characteristics in the violation event record to obtain the early warning response rules corresponding to the structured violation event record; and structurally integrates the structured violation event record based on the early warning response rules to obtain a preliminary early warning report. The preliminary warning report is validated for format standardization to obtain a standardized warning report for the unauthorized access request.
10. A student dormitory access warning method based on dynamic permissions, characterized in that, For use in a student dormitory access warning system based on dynamic permissions as described in claim 1, the method includes: S1, performing permission association mapping on a standardized dataset of original identity recognition data based on a preset permission mapping rule base to obtain a static permission configuration table of the standardized dataset; S2. Adjust the scenario parameters of the status update information of the student management database and the access rules in the static permission configuration table to obtain the status adaptation parameter set of the static permission association table; S3. Based on the status adaptation parameter set, reconstruct the basic access rules in the static permission configuration table to obtain the real-time dynamic permission policy of the static permission association table. S4. Based on the real-time dynamic permission policy, perform multi-dimensional permission rule matching on the spatiotemporal characteristics of the current access request in the target student dormitory to obtain the permission matching analysis result of the current access request; S5. Confirm the access compliance status of the permission matching analysis result and the current access request to obtain the accessibility determination result of the current access request. S6. Based on the preset early warning strategy library, the access control decisions that result in violations are structurally integrated to obtain a standardized early warning report for the violations.