A chemical reagent operation management method and system based on role permissions

By matching biometrics and reagent identification information to obtain role permissions, generating temporary operation tokens, and monitoring reagent operation behavior in real time and isolating abnormal storage, the problem of permission overstepping and difficulty in tracing responsibility in laboratory reagent management is solved, thereby improving security and management efficiency.

CN121997309BActive Publication Date: 2026-07-31SUZHOU BIENSI EXPERIMENTAL EQUIP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SUZHOU BIENSI EXPERIMENTAL EQUIP CO LTD
Filing Date
2026-04-07
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

The existing laboratory management system lacks a dynamic identity authentication and permission binding mechanism in reagent operation management, which leads to difficulties in access control and accountability. Abnormal logs are stored together with normal logs, making it difficult to quickly locate the responsible person and specific process.

Method used

By matching biometric identification and reagent identification information to obtain role permissions, generating temporary operation tokens, monitoring reagent operation behavior in real time, identifying permission overstepping deviations and isolating and storing abnormal behaviors, and constructing a hierarchical storage responsibility traceability path.

Benefits of technology

It enables dynamic access control for reagent operations and rapid identification and accountability for abnormal behavior, thereby improving operational safety and management efficiency, and reducing management loopholes and security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121997309B_ABST
    Figure CN121997309B_ABST
Patent Text Reader

Abstract

This invention discloses a role-based access control method for chemical reagent operation management, comprising: collecting operator biometric data and reagent identification information, and matching and obtaining role-based access control configuration files; extracting reagent operation type restrictions and determining the permitted operation range; generating temporary operation tokens and registering them as authorized operation records by associating them with timestamps; extracting key event nodes to identify access violation deviations; if access violation deviations exist, isolating and storing the key event nodes and associated data in an independent storage partition, marking them as abnormal log entries, forming a hierarchically stored behavior record set; performing log aggregation processing on the hierarchically stored behavior record set, determining the responsibility tracing path based on the time sequence and role-based access control information, and generating audit report data. This invention can achieve precise access control through dynamic authorization and real-time isolation of abnormal behavior, and automatically construct responsibility tracing paths based on hierarchically stored abnormal logs, thereby improving operational security and audit efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of chemical reagent operation management technology, and in particular to a chemical reagent operation management method and system based on role-based access control. Background Technology

[0002] In the field of laboratory management, the safety and standardization of reagent handling are directly related to the health and safety of laboratory personnel and the accuracy of experimental data. This is especially true when hazardous chemicals are involved, as any operational oversight can lead to serious safety accidents. With the expansion of laboratory scale and increased personnel turnover, how to achieve refined management of the entire reagent handling process has become a focus of industry attention. Currently, laboratories have generally established some level of information management systems, using methods such as account and password logins and hierarchical access control to initially manage operators. Some systems have also introduced functions such as reagent barcode scanning and electronic ledger recording to attempt to achieve traceability of operational behavior. These measures have improved management efficiency to some extent and reduced the arbitrariness of manual registration.

[0003] However, existing technologies still have significant shortcomings in addressing sophisticated access control and accountability in complex laboratory environments. The biggest problem lies in the lack of a closed-loop management mechanism that can dynamically bind and hierarchically isolate operator identities, role permissions, reagent handling behaviors, and operation records. Specifically, most existing systems are based on static account permissions, which cannot verify in real time whether operators are qualified to perform the current reagent operation, making it easy for situations such as overstepping permissions or identity theft to occur. At the same time, various operation logs are stored in a mixed manner, lacking the ability to independently isolate and correlate abnormal behaviors. This makes it difficult to quickly locate the responsible person, operation time, and specific steps from massive amounts of logs when abnormal events such as reagent misuse or preparation errors occur, resulting in unclear accountability traceability paths and frequent management loopholes.

[0004] To address these issues, existing technologies attempt to strengthen identity authentication by introducing biometric recognition or to conduct post-event auditing by centrally storing operation logs. However, these improvements are often isolated, lacking a dynamic matching mechanism between identity authentication and operation permissions. Although log storage is centralized, it does not perform anomaly isolation or structured analysis, resulting in the system's inability to promptly identify and record violations of permissions. This necessitates extensive manual investigation afterward, leading to inefficiency and the risk of overlooking critical information. Summary of the Invention

[0005] Therefore, the technical problem to be solved by the present invention is to overcome the defects in the prior art, such as the lack of dynamic binding between identity authentication and operation permissions, and the difficulty in tracing responsibility due to the mixed storage of abnormal logs and normal logs. The present invention provides a chemical reagent operation management method and system based on role permissions, which can achieve precise control of permissions through dynamic authorization and real-time isolation of abnormal behavior, and automatically construct a responsibility tracing path based on hierarchically stored abnormal logs, thereby improving operation security and audit efficiency.

[0006] To address the aforementioned technical problems, this invention provides a method for managing the operation of chemical reagents based on role-based access control, comprising the following steps: The device collects the operator's biometric data and reagent identification information, and retrieves the corresponding role and permission configuration file from a pre-established database to obtain the authentication result. If the authentication result conforms to the preset role-based access control model, the reagent operation type restriction is extracted from the configuration file to determine the scope of operations that the operator is allowed to perform for the reagent corresponding to the reagent identification information. Based on the determined scope of operation and the collected reagent identification information, a temporary operation token is generated, and the temporary operation token is associated with the current timestamp and registered as an authorized operation record; Based on the authorized operation record, monitor real-time reagent operation behavior, extract key event nodes from the real-time behavior data obtained from the monitoring, and determine whether the key event nodes exceed the operation scope in order to identify whether there is an overreach of authority. If an out-of-bounds permission deviation is identified, the corresponding key event nodes and related data will be isolated and stored in an independent storage partition, and marked as abnormal log entries, forming a hierarchical storage behavior record set; Log aggregation processing is performed on the hierarchically stored behavior record set. Based on the temporal relationship between each abnormal log entry in the aggregation result and the corresponding operator role and permission information, the responsibility tracing path is determined. Based on the accountability tracing path, extract the operator's identity information, reagent identification information, and time information from the abnormal log entries to generate audit report data.

[0007] In one embodiment of the present invention, the biometric data includes fingerprint data or iris data, and the reagent identification information includes reagent barcode information or reagent QR code information; the scanning device includes a fingerprint reader or iris reader for collecting biometric data, and a barcode scanner or QR code scanner for collecting reagent identification information.

[0008] In one embodiment of the present invention, the configuration file pre-stores the operator's job level information, qualification certification information and training record information, and the reagent operation type restrictions in the configuration file include requisition operation restrictions, preparation operation restrictions, disposal operation restrictions and transfer operation restrictions.

[0009] In one embodiment of the present invention, generating a temporary operation token includes: Extract the operation type code corresponding to the operation scope, the reagent code corresponding to the reagent identification information, and the current timestamp; The operation type code and reagent code are concatenated into a first string in a preset order. The current timestamp is converted into a Unix timestamp and concatenated with the first string to generate a second string. The second string is calculated using a hash algorithm. The calculated hash value is used as a temporary operation token, and the difference between the validity period of the temporary operation token and the current timestamp is set to not exceed a preset validity period threshold.

[0010] In one embodiment of the present invention, monitoring real-time reagent operation behavior based on authorized operation records includes: Real-time image data of operator's hand movements is collected by image acquisition devices deployed at reagent storage devices or workbenches; The weight change data of the reagent containers is collected in real time by weight sensors deployed at the reagent storage device; Real-time data on the on / off status of reagent storage devices is collected by door magnetic sensors deployed at the devices. The collected hand motion image data, weight change data, and switch status data are compared with the permitted operation range in the authorized operation record to determine whether there are any unauthorized operations.

[0011] In one embodiment of the present invention, key event nodes include: operation start node, operation end node, reagent weight change node, and permission verification failure node; The steps for extracting key event nodes from real-time behavioral data obtained from monitoring include: when the image acquisition device detects that the operator's hand enters the preset operation area, the current time is recorded as the operation start node; when the image acquisition device detects that the operator's hand leaves the preset operation area, the current time is recorded as the operation end node; when the weight change data collected by the weight sensor exceeds the preset threshold, the current time and the weight change value are recorded as the reagent weight change node.

[0012] In one embodiment of the present invention, the corresponding key event nodes and associated data are isolated and stored in an independent storage partition, including: Create an exception log table in the database that is separate from the normal log table; When an out-of-bounds permission deviation is identified, the operator's identity information, reagent identification information, operation time information, and out-of-bounds type information corresponding to the key event node are inserted into the exception log table; In the normal log table, a pointer field pointing to the primary key identifier of the corresponding record in the abnormal log table is added to the record row corresponding to the key event node, forming a hierarchical set of behavior records.

[0013] In one embodiment of the present invention, log aggregation processing is performed on the hierarchically stored behavior record set, including: Extract exception log entries from independent storage partitions from the hierarchical storage behavior record set; Based on the operation time information recorded in each abnormal log entry, sort the multiple abnormal log entries corresponding to the same reagent identification information in chronological order; The sorted abnormal log entries are grouped according to the operator's identity information. The operator's identity information in adjacent groups is checked in turn to see if they are the same. If they are different, a responsibility transfer mark is inserted between the adjacent groups to form an abnormal event chain based on the reagent.

[0014] In one embodiment of the present invention, a responsibility tracing path is determined based on the temporal relationship between each abnormal log entry in the aggregation result and the corresponding operator role and permission information, including: Extract the operator's identity information and operation time information corresponding to the first abnormal log entry from the abnormal event chain, and use them as the initial responsible person and the initial responsibility start time; Read each abnormal log entry sequentially along the time sequence of the abnormal event chain. When a responsibility transfer mark is detected, set the responsibility end time of the previous operator's identity information to the time point corresponding to the current responsibility transfer mark, take the current operator's identity information as the next responsible person, and take their operation time information as the start time of the next responsibility. The process iterates sequentially until all responsibility transfer markers in the abnormal event chain have been processed, generating a traceability path that includes the sequence of responsible persons and the time period of each person's responsibility.

[0015] To address the aforementioned technical problems, this invention also provides a role-based access control system for chemical reagent operation, used to implement the above method, comprising: The data acquisition module is used to collect the operator's biometric data and reagent identification information through the scanning device, match and obtain the corresponding role and permission configuration file from the pre-established database, and obtain the authentication result. The permission determination module is used to extract reagent operation type restrictions from the configuration file when the authentication result conforms to the preset role-based access control model, and determine the scope of operations that the operator is allowed to perform for the reagent corresponding to the reagent identification information. The authorization module is used to generate a temporary operation token based on the determined operation scope and the collected reagent identification information, and to associate the temporary operation token with the current timestamp and register it as an authorized operation record; The monitoring module is used to monitor real-time reagent operation behavior based on authorized operation records, extract key event nodes from the real-time behavior data obtained from the monitoring, and determine whether the key event nodes exceed the operation scope in order to identify whether there is an overreach of authority. The isolated storage module is used to isolate and store the corresponding key event nodes and related data in an independent storage partition when an out-of-bounds permission deviation is identified, and mark them as abnormal log entries to form a hierarchical storage behavior record set; The traceability module is used to perform log aggregation processing on the hierarchically stored behavior record set, and determine the responsibility traceability path based on the temporal relationship between each abnormal log entry in the aggregation result and the corresponding operator role and permission information; The audit module is used to extract operator identity information, reagent identification information, and time information from abnormal log entries based on the responsibility tracing path, and generate audit report data.

[0016] The technical solution of the present invention has the following advantages compared with the prior art: The role-based access control method and system for chemical reagent operation management described in this invention effectively solves the problems of imprecise access control and easy access violation in existing laboratory reagent management by introducing dynamic identity verification, real-time access control determination, and operation behavior monitoring mechanisms. Through hierarchical isolation and storage of abnormal behavior data and log aggregation analysis, access violation deviations can be clearly identified, and the path of responsibility can be quickly determined. This significantly improves the standardization, security, and traceability of chemical reagent operation management, and reduces management loopholes and security risks. Attached Figure Description

[0017] To make the content of this invention easier to understand, the invention will be further described in detail below with reference to specific embodiments and accompanying drawings, wherein: Figure 1 This is a flowchart of the steps of the chemical reagent operation management method based on role-based access control of the present invention; Figure 2 This is a flowchart illustrating the steps involved in generating a temporary operation token according to the present invention; Figure 3 This is a flowchart illustrating the steps of extracting key event nodes from real-time behavioral data according to the present invention. Figure 4 This is a flowchart illustrating the steps of the present invention to isolate and store key event nodes and related data in an independent storage partition; Figure 5 This is a flowchart of the steps involved in log aggregation processing and determining the path of responsibility tracing in this invention. Detailed Implementation

[0018] The present invention will be further described below with reference to the accompanying drawings and specific embodiments, so that those skilled in the art can better understand and implement the present invention. However, the embodiments described are not intended to limit the present invention.

[0019] Reference Figure 1 As shown, this invention discloses a role-based access control method for chemical reagent operation management. First, a scanning device collects the operator's biometric data and reagent identification information. Then, it retrieves the corresponding role-based access control configuration file from the database to complete identity verification. This process binds the operator's physical identity to the system's role-based access control in real time, ensuring that subsequent operations are based on verified identity.

[0020] Specifically, biometric data refers to data used to uniquely identify an individual's physiological or behavioral characteristics. In this embodiment, biometric data specifically includes fingerprint data or iris data. Fingerprint data is a digital representation of the detailed features of an operator's fingerprints, such as the ridges, breaks, and intersections, and possesses uniqueness and stability. Iris data is a digital representation of the texture, spots, and stripes of an operator's iris. Both types of biometric data can provide a high level of security for authentication, effectively preventing impersonation and forgery.

[0021] Reagent identification information is coded data used to uniquely identify chemical reagents. In this embodiment, reagent identification information specifically includes reagent barcode information or reagent QR code information. Reagent barcode information typically consists of a series of parallel lines and gaps between them, using variations in width and spacing to represent data. It is commonly used to store basic information such as batch number, production date, and expiration date. Reagent QR code information is a two-dimensional matrix barcode that can store more data, such as detailed reagent composition, Safety Data Sheet (SDS) links, storage conditions, etc., and has higher fault tolerance. Both types of identification information can efficiently and accurately link to specific chemical reagents, enabling refined reagent management.

[0022] In this embodiment, the scanning device includes a fingerprint reader or iris reader for collecting biometric data, and a barcode scanner or QR code scanner for collecting reagent identification information. The fingerprint reader can be optical, capacitive, or ultrasonic, acquiring a fingerprint image or feature points by sensing the ridge features of the fingerprint. The iris reader typically uses a near-infrared light source to illuminate the iris and a high-resolution camera to capture the iris image, then extracts its unique texture features. The barcode scanner can be a laser scanner or a CCD (charge-coupled device) scanner, decoding the barcode by emitting light and receiving reflected light. The QR code scanner is typically a camera based on image recognition technology, capable of capturing and parsing QR code images. These dedicated scanning devices ensure the accuracy, speed, and convenience of data collection, forming the basis for efficient and reliable operation and management.

[0023] After successful authentication and compliance with the role-based access control model, the system extracts reagent operation type restrictions from the configuration file, determines the scope of operations permitted for the current operator regarding that reagent, and generates a temporary operation token accordingly. This token is then associated with the current timestamp and registered as an authorized operation record. The temporary operation token is not a static permission but a dynamic authorization credential generated for the current operator, the current reagent, and the current time, preventing abuse of permissions at the source.

[0024] Specifically, the configuration file pre-stores the operator's job level information, qualification certification information, and training record information. The reagent operation type restrictions in the configuration file include restrictions on requisition operations, preparation operations, disposal operations, and transfer operations.

[0025] The operator's job level information refers to their rank or position within the organizational structure, such as junior lab technician, senior researcher, or laboratory director. This reflects their experience level and scope of responsibility, serving as a crucial basis for authorization determination. Certification information refers to specific operational qualification certificates obtained by operators through professional assessments or training, such as hazardous chemical handling certificates or qualifications for operating specific large instruments. This information directly relates to whether the operator possesses the legality and professionalism to perform specific operations. Training records refer to the training courses, content, duration, and assessment results related to chemical reagent handling that the operator has received. This information demonstrates the operator's familiarity with specific operating procedures and safety awareness. This information can be stored in a database as structured data and associated with the operator's role identifier. When the configuration file is loaded, this detailed information can be parsed and used for more granular authorization calculations.

[0026] Meanwhile, the restrictions on reagent operation types in the configuration file have been further refined. Requisition operation restrictions constrain operators' permissions to retrieve reagents from the reagent library, such as limiting the scope of personnel or the quantity of specific high-risk reagents that can be retrieved at one time. Preparation operation restrictions constrain operators' permissions to perform reagent preparation (such as dilution, mixing, and reaction), such as stipulating that certain complex or hazardous preparation processes require specific qualifications. Disposal operation restrictions constrain operators' permissions to handle waste reagents (such as collection, sorting, and preliminary treatment), ensuring that waste disposal complies with environmental and safety regulations. Transfer operation restrictions constrain operators' permissions to move reagents from one location to another, such as restricting the transfer path, quantity, or personnel for specific reagents. These restrictions can be stored in the configuration file as Boolean values, enumeration types, or numerical ranges, and associated with specific reagent categories or operator roles, thereby achieving precise control over various reagent operation behaviors.

[0027] Subsequently, the system monitors real-time reagent operation behavior based on authorized operation records, extracts key event nodes from the real-time behavior data, and determines whether the operation exceeds the scope to identify any permission violations. Once an out-of-bounds behavior is identified, the system immediately isolates the event node and related data to an independent storage partition and marks it as an abnormal log entry, forming a hierarchical set of behavior records. This abnormal isolation mechanism breaks the traditional mixed log storage model, separating normal operations from abnormal behaviors at the storage level, ensuring the integrity of normal records while providing a clear set of abnormal data for subsequent auditing.

[0028] Based on this, the system performs log aggregation processing on the hierarchically stored behavior record set. According to the temporal relationship between each abnormal log entry and the corresponding operator role and permission information, it determines the responsibility tracing path. Since the abnormal logs are stored independently by event node and retain key fields such as operator identity, reagent information, and timestamps, the system can automatically construct the complete chain of abnormal event occurrence through temporal analysis and permission information association, clearly identifying the responsible party at each stage. Finally, the system extracts operator identity information, reagent identification information, and time information based on this tracing path to generate audit report data, providing managers with clear and traceable audit evidence.

[0029] Through the above technical solutions, this method achieves a complete closed loop from identity authentication, permission matching, dynamic authorization, behavior monitoring, anomaly isolation to accountability tracing. Compared with existing technologies, its beneficial effects are reflected in the following aspects: First, by matching biometric features with role permissions in real time, combined with a dynamic authorization mechanism using temporary operation tokens, the possibility of permission overreach and identity impersonation is fundamentally eliminated, improving operational security; Second, by identifying and independently storing abnormal behaviors in real time, the mixing of abnormal logs with normal logs is avoided, significantly improving the efficiency of data location during audits; Third, through log aggregation analysis based on time sequence relationships and role permission information, an accountability tracing path for abnormal events can be automatically constructed, solving the problems of unclear responsibility attribution and difficulty in tracing in existing technologies, and providing reliable technical support for the compliant operation of laboratories.

[0030] In some of the embodiments described above in this application, a method for generating temporary operation tokens to authorize operators to perform reagent operations is proposed. However, in the implementation process, how to ensure that the generated temporary operation tokens have sufficient security and uniqueness, and effectively control their validity period to prevent unauthorized tampering or long-term abuse, is a technical problem that needs further consideration.

[0031] Reference Figure 2 As shown, this application further proposes a specific method for generating temporary operation tokens, including: First, extracting the operation type code corresponding to the operation scope, the reagent code corresponding to the reagent identification information, and the current timestamp. The operation type code is used to precisely identify the types of reagent operations that are allowed to be performed, such as requisitioning, preparing, discarding, or transferring reagents. It is usually represented by a predefined numeric or alphanumeric code, and its function is to clearly define the specific actions that the operator is authorized to perform. The reagent code serves as a unique representative of the reagent identification information, ensuring the specificity of the operation; that is, the token is only valid for a specific reagent. The current timestamp records the precise time point when the token was generated, providing a basis for subsequent validity period management and ensuring the token's timeliness.

[0032] Subsequently, the operation type code and the reagent code are concatenated into a first string in a preset order. This preset order ensures the consistency and predictability of the concatenation result; for example, it can be agreed upon as the format "operation type code_reagent code," which is crucial for the determinism of subsequent hash calculations. Next, the current timestamp is converted to a Unix timestamp and concatenated with the first string to generate a second string. Converting the current timestamp to a standardized Unix timestamp helps ensure the uniformity and compactness of time information, ensuring that the second string contains all key elements such as the operation type, reagent information, and timestamp, laying the foundation for the uniqueness and tamper-proof nature of the token.

[0033] Finally, a hash algorithm is used to calculate the second string, and the resulting hash value is used as a temporary operation token. A hash algorithm is a one-way encryption function that can map input data of arbitrary length to a fixed-length output value, and it possesses high collision resistance and irreversibility. Generating tokens using a hash algorithm effectively guarantees the token's uniqueness, integrity, and tamper-proof nature. Any minor modification to any element in the second string will cause a significant change in the hash value, thus preventing forged or tampered tokens from passing verification. Simultaneously, the difference between the temporary operation token's validity period and the current timestamp is set to not exceed a preset validity period threshold. This means that when generating the token, the system sets a clear expiration time, such as adding a preset number of minutes or hours to the current timestamp, thereby strictly limiting the token's usage period and preventing long-term holding or misuse after accidental disclosure.

[0034] In some of the embodiments described above in this application, a method for monitoring real-time reagent operation behavior based on authorized operation records is proposed. However, in its implementation, how to specifically and accurately collect the real-time behavior data of operators and effectively compare it with the authorized operation records to identify potential deviations in authority is a technical problem that needs to be elaborated in detail. The lack of specific monitoring methods may lead to inaccurate judgments of actual operation behavior, thereby affecting the effectiveness of the management method.

[0035] Reference Figure 3 As shown, this application further proposes a specific implementation method for monitoring real-time reagent operation behavior based on authorized operation records, which includes: real-time acquisition of hand movement image data of the operator through image acquisition devices deployed at the reagent storage device or operating table; real-time acquisition of weight change data of reagent containers through weight sensors deployed at the reagent storage device; real-time acquisition of the on / off status data of the reagent storage device through door magnetic sensors deployed at the reagent storage device; and comparison of the acquired hand movement image data, weight change data, and on / off status data with the permitted operation range in the authorized operation record to determine whether there is any unauthorized operation.

[0036] Specifically, to achieve precise monitoring of real-time reagent handling, this application employs a multimodal sensor collaborative approach. The image acquisition device is an electronic device capable of capturing and recording visual information, such as a high-definition camera, infrared camera, or depth sensor. This image acquisition device is deployed above or to the side of the reagent storage device or operating table to ensure clear, real-time acquisition of hand gestures during reagent handling. Analysis of this image data allows for the identification of the operator's posture, the object being handled, and key actions during the process, such as picking up, placing, and pouring reagents.

[0037] Meanwhile, weight sensors are deployed at the reagent storage device to collect real-time data on changes in the weight of the reagent containers. These weight sensors convert the weight of an object into an electrical signal output; for example, they can be load cells, pressure sensors, or strain gauges. By continuously monitoring the weight of the reagent containers, the system can accurately quantify the amount of reagent used or added, thereby determining whether the actual operation matches the expected reagent consumption or replenishment amount in the authorized operation record.

[0038] In addition, door magnetic sensors are also deployed at reagent storage devices to collect real-time data on the opening and closing status of these devices. These sensors detect the opening and closing of doors and windows by sensing changes in the magnetic field; examples include reed switch type, Hall effect type, and wireless type. This allows the system to record every access to the reagent storage device, including the opening and closing times and duration, providing objective evidence for determining whether the storage device has been accessed within the authorized time period.

[0039] After collecting the aforementioned hand movement image data, weight change data, and switch status data, the system compares this real-time behavioral data with the permitted operation range in the authorized operation record to determine if any unauthorized operations exist. The specific comparison process may include: performing image recognition analysis on the image data to determine if the operator's hand movements conform to the authorized operation type and to identify whether the object being operated on is an authorized reagent; comparing the real-time weight change data with the expected reagent consumption or addition amount in the authorized operation record to determine if it is within the allowable error range; and comparing the storage device's opening / closing time with the allowed access time period in the authorized operation record, and whether it occurred during the authorized operation period. The system can comprehensively analyze this multi-source data, for example, through a preset rule engine or machine learning model, to determine the compliance of the operational behavior. For example, if the authorized operation is "retrieving reagent A," the system expects that within a specific time period, the image recognition shows hand contact with reagent A, the weight sensor detects a decrease in the weight of reagent A container, and the door magnetic sensor shows that the storage device was opened. Any behavior that does not conform to these expectations may be marked as an unauthorized operation.

[0040] However, in real-time operating environments, real-time behavioral data is continuous and complex. Directly comparing and analyzing all the raw data is not only computationally intensive and inefficient, but also makes it difficult to accurately locate key turning points and potential abnormal behaviors in the operation process, which may lead to misjudgment or omission of important permission overstepping deviations.

[0041] To address this, this application further proposes extracting key event nodes from real-time behavioral data obtained from monitoring and determining whether these key event nodes exceed the operational scope to identify any permission breaches. Key event nodes include operation start nodes, operation end nodes, reagent weight change nodes, and permission verification failure nodes. The steps for extracting key event nodes from real-time behavioral data obtained from monitoring include: when the image acquisition device detects the operator's hand entering the preset operation area, recording the current moment as the operation start node; when the image acquisition device detects the operator's hand leaving the preset operation area, recording the current moment as the operation end node; and when the weight change data collected by the weight sensor exceeds a preset threshold, recording the current moment and the weight change value as the reagent weight change node.

[0042] Specifically, the operation start node indicates the initial moment when the operator begins handling the reagent. Its detection typically relies on image acquisition equipment to recognize the operator's hand movements; when the hand enters the preset operation area, it is recorded as the operation start node. The operation end node indicates the final moment when the operator completes the reagent handling. Similar to the operation start node, its detection also relies on image acquisition equipment; when the hand leaves the preset operation area, it is recorded as the operation end node. The reagent weight change node indicates the moment and amount of significant change in the reagent weight within the reagent container. This node monitors the reagent container's weight data in real time through a weight sensor; it is triggered when the weight change exceeds a preset threshold, recording the current moment and the specific weight change value. The authorization verification failure node indicates the event point where the operator's authentication or authorization verification failed before attempting to handle the reagent. This node is typically generated during system authentication and authorization verification; once verification fails, it is recorded as an authorization verification failure node, serving as important evidence for subsequent behavior monitoring and traceability.

[0043] In the step of extracting key event nodes from real-time behavioral data obtained from monitoring, when the image acquisition device detects an operator's hand entering a preset operating area, it records the current moment as the start node of the operation. The image acquisition device continuously acquires video streams or image sequences of the operating area. Using image processing techniques, such as background subtraction, object detection, or deep learning models, the presence and location of the operator's hand are identified. When the hand first enters the preset space related to reagent operation (e.g., in front of the reagent cabinet door, above the operating table), the system precisely records this moment and marks it as the start node of the operation. The preset operating area can be defined through system configuration, such as setting a three-dimensional coordinate range or delineating a region of interest in the image. When the image acquisition device detects the operator's hand leaving the preset operating area, it records the current moment as the end node of the operation. Similarly, the image acquisition device continuously monitors the operating area. When it detects that the operator's hand has moved out of the preset operating area and has not re-entered it within a certain period, the system records the moment the hand left and marks it as the end node of the operation. This helps to define the start and end times of a complete operation, providing a time boundary for subsequent behavioral analysis. When the weight change data collected by the weight sensor exceeds a preset threshold, the current moment and the weight change value are recorded as a reagent weight change node. The weight sensor continuously monitors the weight of the reagent container placed on it. The system periodically reads the weight data and compares it with the previous moment or a baseline weight. When the absolute value of the detected weight difference (whether an increase or decrease) exceeds a preset, configurable threshold (e.g., the weight corresponding to 5 grams or 10 milliliters), the system immediately records the current moment of the change and the specific weight change value. This threshold is designed to filter out minor, non-operational weight fluctuations, ensuring that only meaningful reagent dispensing or adding actions are recorded.

[0044] When monitoring real-time reagent operation behavior based on authorized operation records, it is necessary to properly record and manage these abnormal events when deviations from authorized access are identified. However, if all operation behaviors, including normal and abnormal operations, are stored in a single log system, the identification, isolation, and subsequent tracing of abnormal events may become complicated, making it difficult to quickly locate key abnormal information, and may also affect the query efficiency and data integrity of normal operation logs.

[0045] Reference Figure 4As shown, this application proposes a method for isolating and storing corresponding key event nodes and related data in an independent storage partition. Specifically, this includes creating an exception log table in the database, independent of the normal log table. This refers to establishing a dedicated log table with an independent structure and storage space in a database system used to store and manage reagent operation data, specifically for recording permission violation events. The normal log table typically records all reagent operation behaviors that comply with permission regulations, such as operator authentication, reagent requisition, preparation, and disposal. The exception log table, however, focuses on storing permission violation events. Its function is to physically and logically separate exception events from normal operation events, avoiding interference from exception data to the normal operation log, thereby improving the retrieval efficiency and management convenience of exception events. In practical implementation, a new table can be defined in a relational database using Data Definition Language (DDL) statements. The field design of this table should be specifically tailored to the characteristics of exception events, such as including exception type, occurrence time, involved personnel, and reagent information.

[0046] When an out-of-authority deviation is identified, the operator's identity information, reagent identification information, operation time information, and out-of-authority type information corresponding to the key event node are inserted into the exception log table. An out-of-authority deviation refers to an operator performing reagent operations beyond their authorized scope. Key event nodes are important time points identified in real-time monitoring data that indicate the occurrence or change of an operation. Operator identity information uniquely identifies the person performing the operation, reagent identification information uniquely identifies the chemical reagent being handled, operation time information records the exact moment the out-of-authority deviation occurred, and out-of-authority type information describes the specific nature of the deviation, such as unauthorized requisition, exceeding the preparation quantity, or illegal disposal. Inserting this information into the exception log table is the core step in achieving detailed recording of exception events, providing comprehensive and accurate raw data for subsequent accountability and auditing. During implementation, when the monitoring module determines that an out-of-authority deviation exists, the system triggers a data write operation, inserting the extracted key information as a new record into the pre-created exception log table through the database interface.

[0047] Building upon this, a pointer field is added to the record rows in the normal log table corresponding to key event nodes, pointing to the primary key identifier of the corresponding record in the exception log table, forming a hierarchically stored set of behavior records. The normal log table records all operational behaviors, including initial operation records that are ultimately determined to be permission out-of-bounds deviations. The primary key identifier is a field in the database table used to uniquely identify each record. The pointer field is a field in the normal log table whose stored value is the primary key identifier of the corresponding exception record in the exception log table. In this way, a reference to the exception event is retained in the normal log table, logically linking normal operation records with exception event records, forming a hierarchically stored set of behavior records that is both independent and related. Its purpose is that even if the exception event is stored in isolation, its corresponding exception details can still be traced from the context of the normal operation, ensuring data integrity and the continuity of the traceability chain. During implementation, a nullable field can be added to the structure of the normal log table. When an operation is identified as a permission out-of-bounds deviation and inserted into the exception log table, the primary key ID of the new record in the exception log table is then populated back into the field of the corresponding operation record in the normal log table.

[0048] In some of the above implementations, although key event nodes and related data of storage permission violations can be identified and isolated to form a hierarchical set of behavior records, these original abnormal log entries are scattered and lack structured correlation. When the same reagent involves multiple abnormal events or multiple operators, how to efficiently sort out a clear event context from these discrete records and accurately define the scope of responsibility of different operators is a key challenge to achieving effective accountability.

[0049] Reference Figure 5 As shown, this application further proposes a method for log aggregation processing of hierarchically stored behavior record sets. This process aims to transform scattered abnormal log entries into a structured, easily traceable event chain. Specifically, firstly, abnormal log entries are extracted from independent storage partitions within the hierarchically stored behavior record set. This step is achieved by accessing a database table or partition specifically designed for storing abnormal logs; for example, a specific database query can be executed to efficiently retrieve all records marked as abnormal, thereby avoiding the processing of large amounts of normal operation logs and ensuring the targeted and efficient nature of subsequent processing.

[0050] Subsequently, based on the operation time information recorded in each exception log entry, multiple exception log entries corresponding to the same reagent identification information are sorted in chronological order. For example, for a specific reagent, the system collects all exception log entries related to it and sorts them in ascending order using their internally recorded timestamps (operation time information). This ensures that for any chemical reagent, all its exception operation events can be accurately reconstructed in the actual chronological order of occurrence, laying the foundation for understanding the evolution of the events.

[0051] Based on this, the sorted exception log entries are grouped according to the operator's identity information. During the grouping process, the system sequentially checks whether the operator's identity information is the same in adjacent groups. If the operator's identity information is different in adjacent groups, a responsibility transfer marker is inserted between the adjacent groups. For example, when traversing the reagent exception event sequence sorted by time, if it is found that the operator of the current event is different from the operator of the previous event, the system will logically or physically insert a special marker between them, which clearly indicates the change of responsible person. This marker can be a special data structure or a Boolean flag, used to identify the responsibility boundary in subsequent processing. Through the above steps, an exception event chain is finally formed with the reagent as the dimension. This exception event chain is a structured data sequence that not only contains all the exception operation events related to a specific reagent, but also clearly delineates the responsibility intervals of different operators in these events through responsibility transfer markers, thus providing a clear, coherent, and clearly defined event context for subsequent responsibility tracing.

[0052] Furthermore, the steps for determining the responsibility tracing path based on the temporal relationship between each abnormal log entry in the aggregation result and the corresponding operator role and permission information specifically include: extracting the operator identity information and operation time information corresponding to the first abnormal log entry from the abnormal event chain as the initial responsible person and the initial responsibility start time; sequentially reading each abnormal log entry along the temporal order of the abnormal event chain; when a responsibility transfer marker is detected, setting the responsibility end time of the previous operator identity information as the time point corresponding to the current responsibility transfer marker, taking the current operator identity information as the next responsible person, and taking its operation time information as the next responsibility start time; iterating sequentially until all responsibility transfer markers in the abnormal event chain are processed, generating a tracing path containing the responsible person sequence and the responsibility time period of each responsible person.

[0053] After log aggregation, a chain of abnormal events is formed, arranged chronologically. The first abnormal log entry in this chain, containing the operator's identity information and the operation time information, is considered the starting point of the entire abnormal event sequence. The operator's identity information is established as the initial responsible party, and the operation time information is established as the initial responsibility start time, laying the foundation for subsequent responsibility allocation. This ensures a clear logical starting point for the tracing process and avoids ambiguity in the chain of responsibility.

[0054] The accountability process follows a pre-ordered chain of exception events. The system reads each exception log entry sequentially and continuously tracks the current responsible party. Once a responsibility transfer marker generated by log aggregation (as described above) is detected, it indicates a change in the operator's identity. At this point, the previous operator's responsibility end time is precisely set to the time corresponding to the responsibility transfer marker, thus clarifying their responsibility range. Subsequently, the operator's identity information after the responsibility transfer marker is established as the new responsible party, and their operation time information becomes the new responsibility start time. This mechanism ensures that when the responsible party changes, the start and end points of responsibility can be accurately defined, avoiding overlapping or gaps in responsibility.

[0055] The logic of responsibility allocation and transfer described above will continue to execute iteratively until all exception log entries and responsibility transfer markers in the exception event chain have been processed. Ultimately, the system will generate a complete traceability path that clearly lists the sequence of all responsible parties involved in the exception event and specifies the corresponding time period for each responsible party. This traceability path provides a direct and actionable basis for subsequent auditing, accountability, and management, greatly improving the efficiency and accuracy of responsibility tracing.

[0056] The steps for determining the responsibility tracing path based on the temporal relationship between each abnormal log entry in the aggregation result and the corresponding operator role and permission information specifically include: extracting the operator identity information and operation time information corresponding to the first abnormal log entry from the abnormal event chain as the initial responsible person and the initial responsibility start time; sequentially reading each abnormal log entry along the temporal order of the abnormal event chain; when a responsibility transfer marker is detected, setting the responsibility end time of the previous operator identity information as the time point corresponding to the current responsibility transfer marker, taking the current operator identity information as the next responsible person, and taking its operation time information as the next responsibility start time; iterating sequentially until all responsibility transfer markers in the abnormal event chain are processed, generating a tracing path containing the responsible person sequence and the responsibility time period of each responsible person.

[0057] After log aggregation, a chain of abnormal events is formed, arranged chronologically. The first abnormal log entry in this chain, containing the operator's identity information and the operation time information, is considered the starting point of the entire abnormal event sequence. The operator's identity information is established as the initial responsible party, and the operation time information is established as the initial responsibility start time, laying the foundation for subsequent responsibility allocation. This ensures a clear logical starting point for the tracing process and avoids ambiguity in the chain of responsibility.

[0058] The accountability process follows a pre-ordered chain of exception events. The system reads each exception log entry sequentially and continuously tracks the current responsible party. Once a responsibility transfer marker generated by log aggregation (as described above) is detected, it indicates a change in the operator's identity. At this point, the previous operator's responsibility end time is precisely set to the time corresponding to the responsibility transfer marker, thus clarifying their responsibility range. Subsequently, the operator's identity information after the responsibility transfer marker is established as the new responsible party, and their operation time information becomes the new responsibility start time. This mechanism ensures that when the responsible party changes, the start and end points of responsibility can be accurately defined, avoiding overlapping or gaps in responsibility.

[0059] The logic of responsibility allocation and transfer described above will continue to execute iteratively until all exception log entries and responsibility transfer markers in the exception event chain have been processed. Ultimately, the system will generate a complete traceability path that clearly lists the sequence of all responsible parties involved in the exception event and specifies the corresponding time period for each responsible party. This traceability path provides a direct and actionable basis for subsequent auditing, accountability, and management, greatly improving the efficiency and accuracy of responsibility tracing.

[0060] This application also proposes a role-based access control system for chemical reagent operation to implement the above method. The system includes a data acquisition module, an access control module, an authorization module, a monitoring module, an isolation storage module, a traceability module, and an auditing module.

[0061] The data acquisition module is responsible for collecting the operator's biometric data and reagent identification information through scanning devices, and retrieving the corresponding role and permission configuration file from a pre-established database to obtain the authentication result. This module typically includes hardware interfaces and software drivers for communicating with scanning devices such as fingerprint readers, iris readers, barcode scanners, or QR code scanners. For example, when an operator places their finger on a fingerprint reader, the acquisition module captures the fingerprint image and extracts its feature data; simultaneously, when a reagent's barcode or QR code is scanned, the module parses the reagent's unique identification information. This acquired data is then used to search the database for a matching operator identity and their corresponding role and permission configuration file to complete the initial authentication.

[0062] The permission determination module extracts reagent operation type restrictions from the configuration file when the authentication result conforms to the preset role-based access control model, thereby determining the scope of operations that an operator is allowed to perform for the reagent corresponding to the reagent identification information. This module queries the pre-configured access control policies based on the authentication result provided by the data acquisition module. For example, a junior lab technician role may be restricted to only receiving reagents, while a senior researcher may be allowed to prepare and transfer reagents. The permission determination module accurately calculates the specific operation types and scope that the operator can perform in the current context based on the operator's role, rank, qualification certification information, training records, and the characteristics of the reagent.

[0063] The authorization module generates a temporary operation token based on the defined operation scope and collected reagent identification information, and registers the temporary operation token with the current timestamp as an authorized operation record. After authorization verification, this module provides a temporary, verifiable credential for legitimate operations. Specifically, it extracts the operation type code corresponding to the operation scope, the reagent code corresponding to the reagent identification information, and the current timestamp. Then, it concatenates the operation type code and reagent code in a preset order to form a first string, converts the current timestamp to a Unix timestamp, and concatenates it with the first string to generate a second string. Next, it calculates a hash value for the second string using a hash algorithm, and uses this hash value as the temporary operation token. Simultaneously, this module sets the validity period of the temporary operation token, ensuring that the difference between the token and the current timestamp does not exceed a preset validity period threshold, thereby guaranteeing the timeliness and security of authorization.

[0064] The monitoring module monitors real-time reagent handling behavior based on authorized operation records. It extracts key event nodes from the real-time behavior data and determines whether these nodes exceed the permitted scope of operation to identify any breaches of authorization. This module uses image acquisition devices deployed at reagent storage devices or workbenches to collect real-time images of operator hand movements; weight sensors deployed at reagent storage devices to collect real-time data on reagent container weight changes; and door magnetic sensors deployed at reagent storage devices to collect real-time data on the opening and closing status of the reagent storage devices. This multi-source data is aggregated in real-time and compared with authorized operation records generated by the authorization module. For example, when the image acquisition device detects an operator's hand entering a preset operating area, it records the current moment as the start of the operation; when the image acquisition device detects an operator's hand leaving the preset operating area, it records the current moment as the end of the operation; and when the weight change data collected by the weight sensor exceeds a preset threshold, it records the current moment and the weight change value as a reagent weight change node. Through continuous comparison, the monitoring module can promptly detect any operations that deviate from the authorized scope, such as unauthorized reagent handling or unauthorized preparation.

[0065] The isolation storage module is used to isolate and store the corresponding key event nodes and related data in an independent storage partition when an access violation is detected. These are marked as abnormal log entries, forming a hierarchical set of behavior records. When the monitoring module detects an access violation, the isolation storage module responds immediately by creating an abnormal log table in the database, independent of the normal log table. It inserts the operator's identity information, reagent identification information, operation time information, and access violation type information corresponding to the key event node into the abnormal log table. Simultaneously, a pointer field pointing to the primary key identifier of the corresponding record in the abnormal log table is added to the record row in the normal log table corresponding to the key event node. This hierarchical storage mechanism ensures the integrity and independence of abnormal events, prevents abnormal data from contaminating normal operation records, and provides a clear data source for subsequent traceability and auditing.

[0066] The traceability module performs log aggregation on the hierarchically stored behavior record set. Based on the temporal relationship between abnormal log entries and the corresponding operator role and permission information in the aggregation result, it determines the responsibility traceability path. This module extracts abnormal log entries from independent storage partitions in the hierarchically stored behavior record set and sorts multiple abnormal log entries corresponding to the same reagent identification information in chronological order according to the operation time information recorded in each abnormal log entry. Subsequently, the sorted abnormal log entries are grouped according to operator identity information, and the identity information of adjacent groups is checked sequentially. If they are different, a responsibility transfer marker is inserted between the adjacent groups, forming an abnormal event chain based on the reagent dimension. Based on this, the tracing module extracts the operator's identity information and operation time information corresponding to the first abnormal log entry from the abnormal event chain, which serves as the initial responsible person and the initial responsibility start time. It then reads each abnormal log entry sequentially along the time order of the abnormal event chain. When a responsibility transfer marker is detected, the responsibility end time of the previous operator's identity information is set as the time point corresponding to the current responsibility transfer marker. The current operator's identity information is then used as the next responsible person, and their operation time information is used as the next responsibility start time. This process is iterated until all responsibility transfer markers in the abnormal event chain are processed, ultimately generating a tracing path that includes the sequence of responsible persons and the responsibility time periods for each responsible person.

[0067] The audit module extracts operator identification information, reagent identification information, and time information from anomaly log entries based on the accountability tracing path, generating audit report data. This module is the final output of the entire system. It utilizes the accountability tracing path generated by the tracing module to accurately extract the required information from isolated anomaly log entries. This information includes, but is not limited to, the operator's identity, the type and batch of reagents involved, and the exact time the anomaly occurred. The audit module organizes and formats this key data, generating a detailed and objective audit report to provide management with decision-making support, compliance checks, incident investigations, and safety management improvements.

[0068] Obviously, the above embodiments are merely illustrative examples for clear explanation and are not intended to limit the implementation. Those skilled in the art will recognize that other variations or modifications can be made based on the above description. It is neither necessary nor possible to exhaustively list all possible implementations here. However, obvious variations or modifications derived therefrom are still within the scope of protection of this invention.

Claims

1. A role-based chemical reagent operation management method, characterized by, Includes the following steps: The device collects the operator's biometric data and reagent identification information, and retrieves the corresponding role and permission configuration file from a pre-established database to obtain the authentication result. If the authentication result conforms to the preset role-based access control model, the reagent operation type restriction is extracted from the configuration file to determine the scope of operations that the operator is allowed to perform for the reagent corresponding to the reagent identification information. Based on the determined scope of operation and the collected reagent identification information, a temporary operation token is generated, and the temporary operation token is associated with the current timestamp and registered as an authorized operation record; Based on the authorized operation record, monitor real-time reagent operation behavior, extract key event nodes from the real-time behavior data obtained from the monitoring, and determine whether the key event nodes exceed the operation scope in order to identify whether there is an overreach of authority. If an out-of-bounds permission deviation is identified, the corresponding key event nodes and related data will be isolated and stored in an independent storage partition, and marked as abnormal log entries, forming a hierarchical storage behavior record set; Log aggregation processing is performed on the hierarchical storage behavior record set, including: extracting abnormal log entries from independent storage partitions from the hierarchical storage behavior record set; sorting multiple abnormal log entries corresponding to the same reagent identification information according to the operation time information recorded in each abnormal log entry in chronological order; grouping the sorted abnormal log entries according to the operator's identity information, and checking whether the operator's identity information in adjacent groups is the same. If they are different, a responsibility transfer marker is inserted between the adjacent groups to form an abnormal event chain with the reagent as the dimension. Based on the temporal relationship between each abnormal log entry in the aggregation result and the corresponding operator role and permission information, the responsibility tracing path is determined, including: extracting the operator identity information and operation time information corresponding to the first abnormal log entry from the abnormal event chain as the initial responsible person and the initial responsibility start time; sequentially reading each abnormal log entry along the temporal order of the abnormal event chain; when a responsibility transfer marker is detected, setting the responsibility end time of the previous operator identity information as the time point corresponding to the current responsibility transfer marker, taking the current operator identity information as the next responsible person, and taking its operation time information as the next responsibility start time; iterating sequentially until all responsibility transfer markers in the abnormal event chain are processed, generating a tracing path containing the responsible person sequence and the responsibility time period of each responsible person; Based on the accountability tracing path, extract the operator's identity information, reagent identification information, and time information from the abnormal log entries to generate audit report data. 2.The role-based chemical reagent operation management method of claim 1, wherein: Biometric data includes fingerprint or iris data, and reagent identification information includes reagent barcode or reagent QR code information; scanning devices include fingerprint or iris readers for collecting biometric data, and barcode or QR code scanners for collecting reagent identification information. 3.The role-based chemical reagent operation management method of claim 1, wherein: The configuration file pre-stores the operator's job level, qualification certification information, and training record information. The reagent operation type restrictions in the configuration file include restrictions on requisition operations, preparation operations, disposal operations, and transfer operations. 4.The role-based chemical reagent operation management method of claim 1, wherein: Generate a temporary operation token, including: Extract the operation type code corresponding to the operation scope, the reagent code corresponding to the reagent identification information, and the current timestamp; The operation type code and reagent code are concatenated into a first string in a preset order. The current timestamp is converted into a Unix timestamp and concatenated with the first string to generate a second string. The second string is calculated using a hash algorithm. The calculated hash value is used as a temporary operation token, and the difference between the validity period of the temporary operation token and the current timestamp is set to not exceed a preset validity period threshold. 5.The role-based chemical reagent operation management method of claim 1, wherein: Real-time reagent handling behavior is monitored based on authorized operation records, including: Real-time image data of operator's hand movements is collected by image acquisition devices deployed at reagent storage devices or workbenches; The weight change data of the reagent containers is collected in real time by weight sensors deployed at the reagent storage device; Real-time data on the on / off status of reagent storage devices is collected by door magnetic sensors deployed at the devices. The collected hand motion image data, weight change data, and switch status data are compared with the permitted operation range in the authorized operation record to determine whether there are any unauthorized operations. 6.The role-based chemical reagent operation management method of claim 5, wherein: Key event nodes include: operation start node, operation end node, reagent weight change node, and permission verification failure node; The steps for extracting key event nodes from real-time behavioral data obtained from monitoring include: when the image acquisition device detects that the operator's hand enters the preset operation area, the current time is recorded as the operation start node; when the image acquisition device detects that the operator's hand leaves the preset operation area, the current time is recorded as the operation end node; when the weight change data collected by the weight sensor exceeds the preset threshold, the current time and the weight change value are recorded as the reagent weight change node. 7.The role-based chemical reagent operation management method of claim 1, wherein: The corresponding key event nodes and related data are isolated and stored in independent storage partitions, including: Create an exception log table in the database that is separate from the normal log table; When an out-of-bounds permission deviation is identified, the operator's identity information, reagent identification information, operation time information, and out-of-bounds type information corresponding to the key event node are inserted into the exception log table; In the normal log table, a pointer field pointing to the primary key identifier of the corresponding record in the abnormal log table is added to the record row corresponding to the key event node, forming a hierarchical set of behavior records.

8. A role-based chemical reagent operation management system for implementing the method of any one of claims 1 to 7, characterized in that: include: The data acquisition module is used to collect the operator's biometric data and reagent identification information through the scanning device, match and obtain the corresponding role and permission configuration file from the pre-established database, and obtain the authentication result. The permission determination module is used to extract reagent operation type restrictions from the configuration file when the authentication result conforms to the preset role-based access control model, and determine the scope of operations that the operator is allowed to perform for the reagent corresponding to the reagent identification information. The authorization module is used to generate a temporary operation token based on the determined operation scope and the collected reagent identification information, and to associate the temporary operation token with the current timestamp and register it as an authorized operation record; The monitoring module is used to monitor real-time reagent operation behavior based on authorized operation records, extract key event nodes from the real-time behavior data obtained from the monitoring, and determine whether the key event nodes exceed the operation scope in order to identify whether there is an overreach of authority. The isolated storage module is used to isolate and store the corresponding key event nodes and related data in an independent storage partition when an out-of-bounds permission deviation is identified, and mark them as abnormal log entries to form a hierarchical storage behavior record set; The traceability module is used to perform log aggregation processing on the hierarchically stored behavior record set, and determine the responsibility traceability path based on the temporal relationship between each abnormal log entry in the aggregation result and the corresponding operator role and permission information; The audit module is used to extract operator identity information, reagent identification information, and time information from abnormal log entries based on the responsibility tracing path, and generate audit report data.