Authority management method for smart campus and related equipment thereof

By acquiring user identity information and multi-dimensional contextual features in a smart campus, analyzing static identity tags and dynamic relationship graphs, and performing campus context consistency verification, the system solves the problem of insufficient security of traditional access control mechanisms in complex scenarios, and achieves more reasonable and secure authorization decisions.

CN122093155APending Publication Date: 2026-05-26深圳市思友科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610270821.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-06
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Traditional access control mechanisms are ill-suited to the complex and ever-changing usage scenarios and dynamic interactions in smart campuses, leading to unauthorized or inappropriate access and reducing the security of controlled resources.

Method used

By acquiring user identity information and multi-dimensional contextual features, analyzing static identity tags and dynamic relationship graphs, extracting target related entities, and performing campus context consistency verification, access is only allowed when the access behavior is consistent across the three dimensions of identity compliance, relationship rationality, and context adaptation.

Benefits of technology

It improves the security and management efficiency of controlled resources in smart campuses, prevents unauthorized or inappropriate access, and enhances the rationality and security of authorization decisions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122093155A_ABST
    Figure CN122093155A_ABST
Patent Text Reader

Abstract

The invention discloses a smart campus authority management method and related equipment thereof, and relates to the technical field of Internet of Things. When an authority verification request is triggered, identity information and multi-dimensional context features of a user are synchronously obtained, and a static identity tag and a dynamic relation graph of the user are obtained through analysis according to the identity information; on the premise that the static identity meets a basic access condition, extracting a target associated entity having a preset association relationship with the controlled resource type according to the controlled resource type, and further executing campus situation consistency verification in combination with the current campus situation mode, the target associated entity and a link between a user and the entity; the access behavior is more comprehensively and dynamically judged safely by fusing the multi-dimensional context features, illegal or unsuitable access caused by authorization management only according to the identity attribute of the user is prevented, and the technical problem of low safety of controlled resources in the smart campus can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet of Things (IoT) technology, and in particular to a smart campus access control method and related equipment. Background Technology

[0002] With the rapid development of information technology and the deepening of digital transformation in education, the construction of smart campuses has become an important direction for improving the management efficiency of universities, optimizing the allocation of teaching resources, and ensuring campus security. In a smart campus environment, various controlled resources generally rely on information technology for access control and permission management.

[0003] However, traditional access control mechanisms typically rely on user identity attributes for authorization, which is difficult to adapt to the complex and ever-changing usage scenarios and dynamic interaction relationships in smart campuses. This can lead to unauthorized or inappropriate access, reducing the security of controlled resources in smart campuses. Summary of the Invention

[0004] The main purpose of this application is to provide a method for managing access permissions in a smart campus and related equipment, which aims to solve the technical problem of low security of controlled resources in a smart campus.

[0005] To achieve the above objectives, this application proposes a smart campus access control method, which is applied to a smart campus management platform. In response to a user's access control request for controlled resources within the campus, the method obtains the user's identity information and multi-dimensional contextual features related to the access control request.

[0006] Based on the identity information, the static identity tags and dynamic relationship graph of the user within the campus are analyzed. If the static identity tags meet the basic access conditions, the target associated entities in the dynamic relationship graph that have a preset association relationship with the controlled resource are extracted. Based on the multi-dimensional context features, the current campus context mode is determined. Based on the current campus context mode, the target associated entity, and the link between the user and the target associated entity, the campus context consistency check is performed on the permission verification request. If the campus context consistency check passes, then the permission verification is considered successful.

[0007] In one embodiment, the multi-dimensional context features include time-dimensional features, spatial-dimensional features, event-dimensional features, and behavioral-dimensional features. The spatial-dimensional features include the functional area where the controlled resource is located, and the behavioral-dimensional features include the user's historical behavioral features. The step of performing campus context consistency verification on the permission verification request based on the current campus context mode, the target associated entity, and the link between the user and the target associated entity includes: Based on the current context mode, the functional area where the controlled resource is located, and the user's static identity tag, the corresponding set of normative behaviors is matched from the preset behavior strategy template library; The permission verification request is parsed into a current behavior intent vector. Based on the semantic matching degree between the current behavior intent vector and the behavior patterns in the set of normative behaviors, it is determined whether the current behavior intent conforms to the norm. If it does not meet the requirements, the similarity between the historical behavioral features and the current behavioral intent vector is calculated. If the similarity is greater than the preset similarity threshold, the current behavioral intent is determined to be a reasonable behavioral change, and the link is determined to pass the campus context consistency check.

[0008] In one embodiment, the controlled resources include teaching resources, and after the step of determining whether the current behavioral intention belongs to a reasonable behavioral change based on the historical behavioral characteristics, the method further includes: Obtain the teaching occupancy status of the teaching resources. If the teaching occupancy status is valid, determine that the teaching entity occupying the teaching resources is a temporary authorizing party. The temporary licensor is added to the target associated entity set to form an extended authorization chain, and the allowed behavior boundaries are determined according to the preset authorization constraint template. If the user's current behavioral intent does not exceed the permitted behavior boundary, then the extended authorization link is determined to have passed the campus context consistency check.

[0009] In one embodiment, the step of determining the current campus context mode based on the multi-dimensional context features includes: Based on the time dimension features, spatial dimension features, event dimension features, and behavioral dimension features, multiple candidate events and the confidence level of each candidate event are output through a preset campus context ontology model. The preset campus context ontology model is used to represent the relationship between multi-dimensional context features and campus context patterns. Based on the confidence level and the preset modal weights corresponding to the multi-dimensional context features, the multiple candidate events are weighted and fused to obtain a weighted fusion vector; Based on the weighted fusion vector and the spatiotemporal consistency constraint, the current campus scenario mode is determined.

[0010] In one embodiment, the controlled resource includes teaching resources, and prior to the step of responding to a user's permission verification request for a controlled resource on campus, the method further includes: Obtain verification failure records for different teaching resources, and determine the frequency and identity type distribution of unauthorized users' requests based on the verification failure records; If the frequency of the requests exceeds a preset threshold, and the proportion of the education beneficiary group in the identity type distribution is greater than a preset proportion threshold, then alternative access conditions are set for the teaching resources. The education beneficiary group includes at least one of the following: students who have passed the previous course certification but are not currently taking the course, and students who are not currently taking the course but have authorization from the current course's main lecturer. The step of parsing the user's static identity tags and dynamic relationship graph within the campus based on the identity information further includes: If the static identity tag does not meet the basic access conditions, then it is determined whether the teaching resource meets the alternative access conditions. If it meets the alternative access conditions, then the permission verification is confirmed to be successful.

[0011] In one embodiment, the controlled resource includes teaching resources, and the event dimension feature further includes the user's class scheduling information. When the controlled resource is a teaching resource, before the step of extracting target associated entities in the dynamic relationship graph that have a preset association relationship with the controlled resource, the method further includes: Obtain a temporal graph constructed based on the course scheduling, wherein the temporal graph includes multiple teaching time periods, each teaching time period corresponds to a teaching instance, and the teaching instance consists of a course, an instructor, students enrolled in the course, and a classroom; Based on the current timestamp, a set of teaching examples covering the current moment is selected from the temporal graph; Extract subgraphs related to the set of teaching examples from the dynamic relationship graph, and extract target associated entities with preset association relationships with the teaching resources based on the subgraphs.

[0012] Furthermore, to achieve the above objectives, this application also proposes a smart campus management platform, which includes: The first acquisition module is used to respond to a user's permission verification request for controlled resources within the campus, and to acquire the user's identity information and multi-dimensional contextual features related to the permission verification request. The extraction module is used to parse the user's static identity tags and dynamic relationship graph within the campus based on the identity information. If the static identity tags meet the basic access conditions, the target associated entities in the dynamic relationship graph that have a preset association relationship with the controlled resource are extracted. The verification module is used to determine the current campus context mode based on the multi-dimensional context features, and to perform campus context consistency verification on the permission verification request based on the current campus context mode, the target associated entity, and the link between the user and the target associated entity. The first determining module is used to determine that the permission verification is successful if the campus context consistency verification is successful.

[0013] In addition, to achieve the above objectives, this application also proposes a smart campus access control device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the smart campus access control method described above.

[0014] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the smart campus access control method described above.

[0015] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the smart campus access control method described above.

[0016] One or more technical solutions proposed in this application have at least the following technical effects: The smart campus management platform responds to user permission verification requests for controlled resources within the campus by obtaining the user's identity information and multi-dimensional contextual features related to the permission verification request. Based on the identity information, it parses the user's static identity tags and dynamic relationship graph within the campus. If the static identity tags meet basic access conditions, it extracts target associated entities from the dynamic relationship graph that have a preset association with the controlled resource. Based on the multi-dimensional contextual features, it determines the current campus context mode. Based on the current campus context mode, the target associated entities, and the link between the user and the target associated entities, it performs a campus context consistency check on the permission verification request. If the campus context consistency check passes, the permission verification is deemed successful.

[0017] It is understood that this application, by synchronously acquiring the user's identity information and multi-dimensional contextual features when the permission verification request is triggered, and parsing the user's static identity tag and dynamic relationship graph based on the identity information, and under the premise that the static identity meets the basic access conditions, extracts the target associated entity with a preset relationship with it according to the controlled resource type, and then performs campus context consistency verification by combining the current campus context mode, the target associated entity, and the link between the user and the entity; by integrating multi-dimensional contextual features to make a more comprehensive and dynamic security judgment on access behavior, it prevents illegal or inappropriate access caused by authorization management based solely on the user's identity attributes, and solves the current security deficiency problem. Attached Figure Description

[0018] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0019] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 A flowchart illustrating the first embodiment of the access control method for smart campus in this application; Figure 2 A flowchart illustrating the second embodiment of the access control method for smart campuses in this application; Figure 3 A flowchart illustrating the third embodiment of the access control method for smart campuses in this application; Figure 4 This is a schematic diagram of the module structure of the smart campus management platform according to an embodiment of this application; Figure 5 This is a schematic diagram of the device structure of the hardware operating environment involved in the access management method for a smart campus in this application embodiment.

[0021] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0022] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0023] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0024] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device or smart campus management platform capable of performing the above functions. The following description uses a smart campus management platform as an example to illustrate this embodiment and the subsequent embodiments.

[0025] Based on this, the embodiments of this application provide a method for access control in a smart campus, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the access control method for smart campuses in this application.

[0026] In this embodiment, the access control method for the smart campus includes steps S10 to S40: Step S10: In response to a user's permission verification request for controlled resources on campus, obtain the user's identity information and multi-dimensional contextual features related to the permission verification request; Step S20: Based on the identity information, parse the user's static identity tag and dynamic relationship graph within the campus. If the static identity tag meets the basic access conditions, extract the target associated entities in the dynamic relationship graph that have a preset association relationship with the controlled resource. Step S30: Determine the current campus context mode based on the multi-dimensional context features; and perform campus context consistency verification on the permission verification request based on the current campus context mode, the target associated entity, and the link between the user and the target associated entity. Step S40: If the campus context consistency check passes, then the permission verification is confirmed to be successful.

[0027] It should be noted that users include students, teachers, administrative staff, and other on-campus members, as well as other registered and certified off-campus members. Controlled resources refer to digital or physical resources deployed within the smart campus that require authorization verification for access or use, such as teaching systems, laboratory equipment, classroom access control, and online course materials. An authorization verification request refers to a signal or data packet sent by a smart terminal to the smart campus management platform when a user attempts to access controlled resources on campus, confirming their access privileges; this authorization verification request includes access permission verification requests and usage permission verification requests.

[0028] Specifically, when a user attempts to access controlled resources on campus, the smart campus management platform first listens for and responds to the permission verification request initiated by the user. The platform simultaneously obtains the user's identity information and multi-dimensional contextual features related to the request. The multi-dimensional contextual features may include the time, location, and current campus event status of the request. The identity information includes the user ID, department, role type (e.g., undergraduate student, professor), authentication credentials, etc.

[0029] After obtaining a user's identity information, the smart campus management platform analyzes it to generate a static identity tag and a dynamic relationship graph for that user within the campus. The static identity tag refers to a set of identity attributes extracted from the user's identity information that do not frequently change over time or context, such as the user's role (e.g., undergraduate student, lecturer), department, student status, and job level. The dynamic relationship graph refers to a graph structure data in the smart campus environment, with the user as one of the nodes, constructed through the real-time or historical interaction relationships between the user and entities such as courses, teachers, classmates, classrooms, and project teams. The dynamic relationship graph reflects the dynamic connections of users within the campus social and business networks.

[0030] If the static identity tag meets the basic access conditions set for the currently controlled resource, it is further determined whether the static identity tag meets the basic access conditions set for the controlled resource. If it does, the target associated entity with a preset relationship with the controlled resource is further identified and extracted from the dynamic relationship graph. This ensures that the permission verification does not deviate from the basic identity compliance, and effectively identifies whether the user has a reasonable association with the resource through a legitimate campus role link (such as course selection relationship, teaching arrangement, collaborative project, etc.). This avoids illegal or inappropriate access caused by identity tags alone, which may result in the user having an identity but no legitimate reason for access, and improves the rationality and security of the authorization decision.

[0031] Specifically, basic access conditions refer to the minimum eligibility requirements set for specific controlled resources, such as being limited to students enrolled in this course or requiring faculty / staff status. Pre-defined associations refer to semantic rules or mapping relationships predefined in the smart campus management platform that represent a legitimate or reasonable association between a user or their associated entity and a specific controlled resource. These pre-defined associations are based on campus business logic; for example, there is an access association between enrolled students and course teaching resources, and an operational association between instructors and the access control systems of the classrooms they teach.

[0032] Therefore, the target associated entity that has a preset association with the controlled resource refers to other entities in the dynamic relationship graph that have a preset semantic or functional association with the current controlled resource. For example, when the controlled resource is a classroom, the target associated entity may include the currently scheduled courses, the instructors, or the group of students enrolled in the courses.

[0033] Based on the multi-dimensional contextual features, the current campus situation mode reflecting the current operating status or typical scenarios of the smart campus can be comprehensively inferred. The campus situation mode can be a normal teaching period, an exam week, a holiday closed management, an emergency response to sudden events, etc.

[0034] The link between a user and the target associated entity refers to one or more relational paths that connect the user and the target associated entity in a dynamic relational graph. The link reflects the semantic or business association strength and type between the user and the target associated entity. For example, the path in the link Student A-Elective-Course B-Use-Classroom C constitutes the authorization link between the user and Classroom C.

[0035] Therefore, based on the current campus context, the target associated entity, and the link between the user and the target associated entity, the permission verification request can be checked for campus context consistency. That is, the user's access request is placed within the current campus context, and the link between the user and the target associated entity is used to verify whether the access request meets the rationality and compliance requirements of the current context. This ensures that permission decisions not only rely on static identities and fixed rules but also adapt to dynamic changes in the campus's operational status. For example, in an "exam week" scenario, even if a student's identity is legitimate and they have previously used a laboratory, their access might be denied if their current access behavior is unrelated to the exam schedule. This achieves dynamic and contextualized security judgment of access behavior, avoiding mechanical authorization divorced from real-world scenarios.

[0036] After completing the campus context consistency verification, if the verification result is successful, it means that the user's access request, under the current campus context mode, maintains logical consistency with its static identity tag, target associated entity, and the link between the user and the target associated entity, and complies with preset management rules. Based on this, the smart campus management platform determines that the permission verification has passed, allowing the user to access the requested controlled resources. This ensures timely authorization of legitimate and reasonable access behavior while guaranteeing security and compliance.

[0037] In a specific implementation, when a user initiates an authorization verification request, the platform first responds to the authorization verification request and simultaneously collects two types of key information: obtaining the user's identity information through a unified identity authentication system (such as a campus card or OAuth2.0 interface); and gathering multi-dimensional contextual features related to this request in real time from a multi-source sensing system (such as a positioning base station, academic calendar, behavior log library, or IoT sensor).

[0038] Furthermore, the platform performs structured parsing based on the identity information: it generates static identity tags for users through preset rule mapping and determines whether they meet the basic access conditions set by the controlled resource; it loads a dynamic relationship graph centered on the user from a graph database (such as Neo4j). If the static identity meets the basic requirements, the platform performs a graph traversal query to identify target related entities in the graph that have preset association relationships with the current controlled resource.

[0039] Based on this, the platform utilizes the aforementioned multi-dimensional contextual features, inputting them into a pre-built campus context ontology model (which can be implemented based on semantic ontology or machine learning models). By weightedly fusing the features of each dimension and their confidence levels, it infers the most likely campus context pattern. Then, by combining this context pattern, the extracted target associated entities, and the links between the user and the target associated entities, it performs a campus context consistency check on the permission verification request.

[0040] If the above campus scenario consistency verification result is passed, the platform determines that the permission verification is successful and sends an authorization instruction to the resource control system (such as access control gate, file server) to allow the user to access; at the same time, it records the complete decision context for auditing and model optimization.

[0041] In this embodiment, during the permission verification process, not only is the user's identity information acquired, but multi-dimensional contextual features related to the request are also collected simultaneously. Based on this, static identity tags and dynamic relationship graphs are parsed out. Then, under the premise of meeting basic access conditions, target associated entities with preset associations with controlled resources are extracted. Combined with the current campus context mode inferred from the contextual features and the link between the user and the target associated entities, a campus context consistency check is performed, thereby constructing a multi-dimensional dynamic authorization mechanism that integrates identity, relationship, context, and behavior. This breaks through the limitations of traditional access control that relies solely on static roles or attributes, enabling permission decisions to truly reflect the user's reasonable access needs in specific time, space, and business scenarios.

[0042] Because the entire verification process uses campus context consistency verification as the final authorization basis, it ensures that access is only granted when a user's access behavior is consistent across the three dimensions of identity compliance, relationship rationality, and context adaptation. This effectively prevents unauthorized access (such as entering a laboratory outside of teaching hours) or inappropriate access (such as unauthorized personnel entering the examination area during exams) caused by ignoring context. This improves the security, management efficiency, and user experience of controlled resources in the smart campus.

[0043] Based on the first embodiment of this application, in the second embodiment of this application, the same or similar content as the above embodiment can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 2Step S30 also includes steps S01 to S03: Step S01: Based on the current context mode, the functional area where the controlled resource is located, and the user's static identity tag, match the corresponding set of normative behaviors from the preset behavior strategy template library; Step S02: Parse the permission verification request into a current behavior intent vector. Based on the semantic matching degree between the current behavior intent vector and the behavior patterns in the set of normative behaviors, determine whether the current behavior intent conforms to the norm. Step S03: If it does not meet the requirements, calculate the similarity between the historical behavior features and the current behavior intention vector. If the similarity is greater than the preset similarity threshold, determine that the current behavior intention belongs to a reasonable behavior change and determine that the link passes the campus context consistency check.

[0044] It should be noted that the multi-dimensional context features include time-dimensional features, spatial-dimensional features, event-dimensional features, and behavioral-dimensional features. The spatial-dimensional features include the functional area where the controlled resource is located, and the behavioral-dimensional features include the user's historical behavioral features.

[0045] Time-dimensional features refer to time information related to the moment the permission verification request occurs, including the specific timestamp, day of the week, and whether it is within a teaching week / exam week / holiday, etc. Spatial-dimensional features refer to contextual information related to physical or logical location, including the functional area where the controlled resource is located (e.g., Laboratory Building B, Library Electronic Reading Room, East Gate of the Playground), the user's current location, the relative distance or accessibility between the user and the controlled resource, and the space usage status. Event-dimensional features refer to specific events or states currently occurring on campus, such as school anniversary activities, emergency response, and large academic conferences. These events may temporarily change resource access rules or priorities. Behavioral-dimensional features refer to behavioral pattern data extracted based on the user's past operation records, including the user's historical behavioral characteristics (frequently accessed resource types, access frequency, behavioral sequences, abnormal operation markers, etc.), real-time behavioral information directly related to the current permission verification request, and group behavioral statistical characteristics.

[0046] When performing campus context consistency verification, the system first performs multi-dimensional joint matching in the behavior policy template library based on the established current context mode, the functional area where the controlled resource is located, and the user's static identity label, and retrieves the set of normative behaviors applicable to the current scenario. It can be understood that this set of normative behaviors clearly defines which access behaviors are considered compliant operations under this context, space, and identity conditions.

[0047] Among them, the behavior policy template library refers to a set of rules that are pre-configured and stored in the smart campus management platform. Each template defines the legal access behavior patterns allowed under a specific combination of current context mode, functional area and static identity label.

[0048] The established current context pattern, the functional area where the controlled resource is located, and the user's static identity label are used as joint query conditions and input into the behavior strategy template library; through multi-dimensional index matching or rule engine reasoning, a set of normative behaviors that are fully adapted to the current scenario is retrieved.

[0049] Furthermore, the user's permission verification request is structured and parsed to extract its core semantic elements and encode them into a current behavioral intent vector. For example, the user's permission verification request can be transformed into a numerical vector representation containing semantic information such as action type (e.g., access, download), target resource category, time tendency, and spatial orientation through natural language understanding or feature engineering methods, thus obtaining the current behavioral intent vector.

[0050] The vector is semantically compared with each behavior pattern in the set of normative behaviors, and the corresponding semantic matching degree is calculated. Specifically, the semantic matching degree can be obtained by measuring the degree of semantic consistency between the current behavior intention vector and a certain behavior pattern in the set of normative behaviors through vector similarity calculation (such as cosine similarity) or semantic embedding model (such as BERT). The higher the value of the semantic matching degree, the closer the behavior is to the norm.

[0051] If the matching degree of at least one behavioral pattern is lower than a preset threshold, the current behavioral intent is determined to be non-compliant. When the semantic matching degree between the current behavioral intent vector and the set of compliant behaviors does not meet the compliance standard, the request is not directly rejected. Instead, the historical behavioral features stored in the user profile are further invoked, and they are vectorized and aligned with the current behavioral intent vector to calculate the similarity. If the similarity exceeds the preset similarity threshold, the current behavior is determined to be a reasonable behavioral change. That is, although the user's current behavior does not match the set of compliant behaviors, it is highly similar to its long-term historical behavioral features, indicating that the behavior is a natural extension of the user's individual habits or responsibilities, and is reasonable and acceptable. The link between the user and the target associated entity is confirmed to pass the campus context consistency check.

[0052] It should be noted that the controlled resources include teaching resources, administrative and office resources, and living and public service resources. Teaching resources refer to the controlled resources used in the smart campus to support teaching activities, including online course materials, multimedia courseware, virtual simulation experimental platforms, physical classrooms, and teaching equipment.

[0053] In one feasible implementation, after the step of determining whether the current behavioral intention belongs to a reasonable change in behavior based on the historical behavioral characteristics, the method further includes: The teaching resource occupancy status is obtained. If the teaching occupancy status is valid, the teaching entity occupying the teaching resource is determined to be a temporary authorizing party. The temporary authorizing party is added to the target associated entity set to form an extended authorization link, and the allowed behavior boundary is determined according to the preset authorization constraint template. If the user's current behavioral intent does not exceed the allowed behavior boundary, the extended authorization link is determined to pass the campus context consistency check.

[0054] After determining that the user's current behavioral intent is a reasonable change in behavior, if the controlled resource is a teaching resource, the teaching occupancy status of the teaching resource is further obtained. The teaching occupancy status refers to the status indicator of whether the teaching resource is occupied by formal teaching activities at the current moment, such as being in class, being booked, or being available. The teaching occupancy status is maintained in real time by the academic scheduling system or classroom management system.

[0055] If the status is valid (i.e., it is currently being used by a teaching activity), the teaching entity occupying the resource is identified and designated as the temporary authorizing party. The teaching entity refers to the teaching-related party that is currently legally occupying the teaching resource, including the instructor, teaching assistant, class, and other entities with the right to organize or use the teaching resource. The temporary authorizing party refers to the teaching entity that has temporarily obtained the right to manage or authorize the teaching resource due to the current occupation of the teaching resource, and its authorization is only valid during the period of occupation.

[0056] The temporary authorizer is added to the original set of target associated entities to construct an extended authorization link. Based on the preset authorization constraint template that matches the role of the temporary authorizer, the preset authorization constraint template refers to a set of predefined behavioral restriction rules for different types of temporary authorizers and teaching resources, which is used to define the scope of operations that can be authorized to others (e.g., only viewing courseware is allowed, but downloading is not allowed).

[0057] Specifically, based on the role type of the temporary authorizer (e.g., lecturer, teaching assistant) and the type of teaching resource (e.g., multimedia classroom, online course library), a matching preset authorization constraint template can be retrieved from the template library. Dynamic information from the current teaching occupancy status (e.g., course start / end time, classroom number, course level) is substituted into the variables in the template to generate a specific authorization rule instance. For example, the template "Authorization Time = [Course Start - 10min, Course End + 5min]" is instantiated as "[14:50, 16:35]".

[0058] Based on the preset authorization constraint template, the allowed behavior boundary in the current scenario is calculated. The allowed behavior boundary refers to the maximum range of permissions that the current temporary authorizer can grant to others, calculated based on the preset authorization constraint template; that is, a set of executable operations. The instantiated set of operations is logically combined with the constraints to form a computable allowed behavior boundary: a list of permitted operations (such as {"enter the classroom", "use the projector"}), plus time, space and frequency constraints (such as only between 14:50 and 16:35, and the user is located in teaching building A).

[0059] The system determines whether the user's current behavioral intent falls within the permitted behavior boundary. This is achieved by comparing the user's current behavioral intent vector with the allowed action, such as determining if "entering classroom 302" is within the permitted operation and if the current time is within the valid window. If the user's intent does not exceed the permitted behavior boundary, the extended authorization link is confirmed to have passed the campus context consistency check. This introduces a temporary authorization mechanism in dynamic scenarios where teaching resources are occupied, allowing non-original associated users (e.g., auditors, substitute teaching assistants) to obtain legitimate access within the authorized scope. This provides precise support for temporary and derived access needs in teaching scenarios.

[0060] In one feasible implementation, the specific way to determine the current campus context mode based on the multi-dimensional context features can be: Based on the time-dimensional features, spatial-dimensional features, event-dimensional features, and behavioral-dimensional features, a pre-defined campus context ontology model is used to output multiple candidate events and the confidence level of each candidate event. The pre-defined campus context ontology model is used to represent the correlation between multi-dimensional context features and campus context patterns. Based on the confidence level and the pre-defined modal weights corresponding to the multi-dimensional context features, the multiple candidate events are weighted and fused to obtain a weighted fusion vector. Based on the weighted fusion vector and spatiotemporal consistency constraints, the current campus context pattern is determined.

[0061] Multi-dimensional contextual features are input into a pre-defined campus context ontology model, which can be trained using a graph neural network (GNN) or a Transformer architecture (embedding the multi-dimensional contextual features as vectors, inputting them into a multi-head attention module to learn cross-modal associations, and outputting context category probability distributions). This model is used to learn the semantic mapping rules and probabilistic associations between multi-dimensional contextual features and campus context patterns. The campus context ontology model outputs several candidate events (i.e., possible campus context patterns) and their corresponding confidence scores.

[0062] An attention mechanism is used to dynamically allocate weights (e.g., 0.4 for time, 0.3 for event), and the confidence of each candidate event is adjusted by weighting according to the feature source. A weighted fusion vector is generated through vector concatenation and a fully connected layer. This avoids misjudgment caused by a single feature dominating the evaluation (e.g., judging it as normal teaching simply because the time is on a weekday, ignoring holiday announcements).

[0063] The weighted fusion vector is mapped back to the context space, and spatiotemporal consistency constraints are applied (logical verification is performed through the rule engine) to eliminate contradictory options. Finally, the unique context that meets all constraints and has the highest score is selected as the current campus context mode.

[0064] Specifically, spatiotemporal consistency constraints can be achieved through predefined conflict matrices (e.g., "EmergencyEvacuation" is mutually exclusive with any "NormalAccess") or through spatiotemporal graph verification (if a region is marked as "construction closed," then all scenarios that depend on the openness of that region are excluded). Ultimately, only candidate events that satisfy all hard constraints are retained, and the one with the highest weighted score is selected. It can be understood that logically verifying the fusion results through spatiotemporal consistency constraints can effectively exclude combinations of scenarios that are impossible to coexist in reality (e.g., exam week and school-wide spring outing).

[0065] Before inputting the original multi-dimensional contextual features into the campus context ontology model, a lightweight context screening module (such as a shallow MLP) is used to obtain a rough estimate of the most likely context category. Using this category as an index, the corresponding context sensitivity vector is retrieved from the pre-trained context-modality sensitivity matrix. This context sensitivity vector reflects the typical importance of each modality in this type of context (e.g., in emergency response scenarios, the event dimension has high weight, while the behavior dimension has low weight; in normal teaching scenarios, the time and space dimensions are more critical). This context sensitivity vector is used as a gating signal to modally scale the embedding representation of the original contextual features, generating a weighted context embedding. This weighted context embedding is then input into the main campus context ontology model to output candidate events and their confidence scores. This achieves context-aware feature selection at the model input layer. It allows the contribution weights of multi-dimensional contextual features to be dynamically adjusted according to the current campus operating status, rather than using fixed preset modality weights.

[0066] After obtaining the original embeddings of four modalities—time, space, event, and behavior—they are mapped to a unified semantic-context joint embedding space through modality-specific projection layers (such as fully connected layers) to ensure the comparability of each modality vector. Next, the context-sensitive vectors retrieved from the context-modality sensitivity matrix are input to a shared nonlinear transformation module (such as a two-layer MLP). This module outputs four sets of affine parameters, each corresponding to a modality. An affine transformation is then performed on the embedding of each modality in the joint space. ; in, To control the importance gain of each dimension, To introduce context-dependent semantic biases (e.g., in emergency response, the event embedding is shifted towards semantic directions such as lockdown and evacuation). For the original embedding, The resulting embedding vectors are mapped to a unified semantic-context joint embedding space. All transformed modal embeddings are concatenated or fused according to learnable weights to generate the final weighted context embedding, which serves as input to the main campus context ontology model. This achieves context-driven feature modulation at the embedding representation level, improving the consistency of context recognition.

[0067] After obtaining the weighted fusion vector, the weighted fusion vector can be combined with the spatiotemporal occupancy extracted in real time from the temporal map. Figure 1 The input is fed into a context-spatiotemporal conflict detector. This detector uses a graph attention network to encode the nodes (such as classrooms) and their current occupancy status in the spatiotemporal occupancy graph with relational awareness, and calculates the semantic-logical consistency of each candidate event with the graph. For example, if the candidate event is a school-wide suspension of classes, but the spatiotemporal occupancy graph shows that multiple classrooms are being used for regular classes, the compatibility score will decrease significantly. Conversely, if the candidate event is a competition training day, and multiple laboratories in the occupancy graph are being used by the training team, the score will increase. Only candidate events with a logical compatibility score higher than a preset score threshold are retained, and the one with the highest original confidence is selected as the final current campus context pattern. This ensures that campus context recognition not only relies on the statistical regularity of contextual features but also must conform to the actual usage status of physical resources.

[0068] For example, when the academic affairs office temporarily postpones the exam week but does not update the announcement, the system can still automatically suppress the activation of the exam week scenario based on the actual usage status of the classroom (still in class), thus avoiding the erroneous triggering of the exam room access control policy.

[0069] In this embodiment, after inputting the weighted fusion vector and the spatiotemporal occupancy graph into the context-spatiotemporal conflict detector, a graph attention network is first used to aggregate features of each node (e.g., classroom, laboratory) and its neighboring nodes in the spatiotemporal occupancy graph. Specifically, a multi-head attention mechanism is used to calculate the relationship weight between each node and its neighboring nodes, and an enhanced feature representation of the node is generated based on this. For each candidate event, the corresponding event context embedding vector is retrieved from a pre-trained context semantic embedding library. Then, a shared cross-modal interaction module (e.g., Transformer encoder) is used to establish a bidirectional mapping between node features and event context embeddings to generate context-aware node enhanced representations. Based on the node enhanced representations, an adaptive contrastive loss function is used to quantify the semantic-logical consistency score between each candidate event and the spatiotemporal occupancy graph. Only those candidate events with scores higher than a preset score threshold are retained, and the one with the highest original confidence is selected as the current campus context mode.

[0070] For example, in an exam week scenario, if a classroom is incorrectly scheduled for an extracurricular lecture, the system can automatically detect this conflict using context-aware node augmentation representations and an adaptive contrastive loss function. This allows for adjustments to the context recognition results, preventing misjudgments of permissions due to incorrect scheduling. Furthermore, it can handle dynamically changing teaching activities (such as temporarily added lectures or competition training), ensuring that context recognition remains synchronized with the actual campus operation by updating the spatiotemporal occupancy map in real time and recalculating consistency scores.

[0071] In this embodiment, compliant behavior is automatically identified by semantic matching between a behavior policy template library and the current behavior intent vector. When behavior does not match the norm, a similarity comparison between historical behavior features and the current behavior intent vector is introduced to determine whether it constitutes a reasonable behavior change. Simultaneously, the spatial and behavioral dimensions of multi-dimensional contextual features are utilized to ensure that behavior compliance judgment is both scenario-adaptable and considers individual behavioral habits. This effectively addresses real but non-standard campus access needs such as teaching assistant substitutions and cross-course learning.

[0072] Based on the first and second embodiments of this application, in the third embodiment of this application, the content that is the same as or similar to the above embodiments can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 3 Before step S10, steps A1~A2 are also included: Step A1: Obtain the verification failure records for different teaching resources, and determine the request frequency and identity type distribution of unauthorized users based on the verification failure records; Step A2: If the frequency of requests exceeds a preset threshold and the proportion of the education beneficiary group in the identity type distribution is greater than a preset proportion threshold, then alternative access conditions are set for the teaching resources. The education beneficiary group includes at least one of the following: students who have passed the previous course certification but are not currently taking the course, and students who are not currently taking the course but have authorization from the current course's main lecturer.

[0073] Before a user initiates a permission verification request, the system can periodically or triggerally retrieve verification failure records for different teaching resources from the security audit log library. Then, it can perform aggregate analysis on each type of teaching resource (e.g., Advanced Mathematics A courseware, Computer Network Experiment Platform): count the total number of failed requests from unauthorized users per unit time to obtain the request frequency; at the same time, it can count by user identity type (e.g., undergraduate, graduate, visiting scholar from another university) and calculate the proportion of each category to form the identity type distribution.

[0074] Among them, the verification failure record refers to the log entry generated by the smart campus management platform when it rejects an access request because the user does not meet the access conditions during the permission verification process. It includes fields such as timestamp, user ID, controlled resource identifier, reason for failure, and user identity type. Identity type distribution refers to the proportion of various unauthorized users (such as students who are not students of this course, visitors, teachers of other departments, etc.) in the above verification failure records.

[0075] The statistical results of each teaching resource are subject to dual threshold judgment: if the frequency of requests exceeds the preset threshold (e.g., 30 times / week) and the proportion of the education beneficiary group in the identity type distribution is higher than the preset proportion threshold (e.g., 70%), the strategy update process is automatically triggered.

[0076] Specifically, the system can call the academic affairs database to verify whether the failed users include a large number of students who have "passed prerequisite courses" (by matching the course prerequisite relationship table), or query teacher authorization records (such as digital signatures or authorization tokens) to confirm whether there is valid external authorization. Once the conditions are met, the platform will dynamically generate an alternative access condition for the teaching resource. For example, if a user has passed course ID=CS101 and scored 60 or higher, access to the resource will be allowed, and this rule will be written into the resource metadata or policy engine. This filters out unauthorized access requests with real educational value, opening a flexible access channel for high-demand teaching resources without modifying the global identity system.

[0077] The step of parsing the user's static identity tags and dynamic relationship graph within the campus based on the identity information further includes: If the static identity tag does not meet the basic access conditions, then it is determined whether the teaching resource meets the alternative access conditions. If it meets the alternative access conditions, then the permission verification is confirmed to be successful.

[0078] Specifically, if the basic access conditions are not met (e.g., the user is not a student enrolled in this course), the system further checks whether the teaching resource has been configured with the aforementioned alternative access conditions. If so, the system performs a secondary verification of the user's eligibility based on these conditions (e.g., calling the academic affairs system to verify whether the user has passed the prerequisite courses, or checking for valid authorization from the main lecturer). If the user meets the specific requirements of the alternative access conditions, the system directly determines that the permission verification has passed. There is no need to proceed to the subsequent context consistency verification process.

[0079] When the controlled resource is a teaching resource and the user obtains access through alternative access conditions, the type of educational benefit basis on which this authorization is based is recorded. If the same user accesses different teaching resources with course knowledge chain connections multiple times within a preset period through the same type of educational benefit basis, a cross-course learning path profile of the user is automatically constructed, and this profile is used as a new implicit relationship node in its dynamic relationship graph. In subsequent permission verification for teaching resources downstream of the knowledge chain, if the static identity does not meet the basic access conditions, but the user's learning path profile indicates that the user has systematically mastered the prior knowledge system, then alternative access condition matching is triggered first, and the dependence on explicit authorization from the main lecturer is reduced.

[0080] Educational benefit criteria type refers to the specific qualification certificate category that users rely on when obtaining permissions through alternative access conditions, including passing prerequisite course certification and explicit authorization from the main lecturer. Course knowledge chain association refers to the prerequisite-successor logical relationship between teaching resources (usually corresponding to courses). Cross-course learning path profile refers to the structured learning trajectory automatically summarized by the platform based on users' repeated access to knowledge chain-related courses through educational benefit criteria. Downstream teaching resources in the knowledge chain refer to higher-level teaching resources in the course knowledge chain that are located after the courses currently learned by the user and require prerequisite knowledge support.

[0081] When a user accesses a teaching resource through alternative access conditions because they belong to an educational beneficiary group, the platform not only allows the request but also records the type of educational beneficiary basis they rely on (such as CS101 certification). If, within the following 30 days, the user accesses multiple teaching resources with course knowledge chain connections using the same basis (such as all based on prior course certification) (e.g., accessing C language, data structures, and algorithm design sequentially), the platform automatically aggregates these behaviors, constructs a cross-course learning path profile, and injects it as an implicit relation node into the user's dynamic relationship graph. Subsequently, when the user attempts to access downstream teaching resources in the knowledge chain (such as compiler principles) and the static identity label does not meet the basic access conditions, the platform prioritizes the knowledge completeness demonstrated by the learning path profile when determining whether alternative access conditions apply. Even without explicit authorization from the current course instructor, it can automatically match alternative strategies based on the integrity of the knowledge chain.

[0082] The construction of a cross-course learning path profile is triggered only under specific patterns where users repeatedly access knowledge chain-related courses based on educational benefits. This profile is encoded as implicit relationship nodes in a dynamic relationship graph, enabling the platform to identify and trust the structured knowledge capabilities that users acquire through self-directed learning. Subsequent permission verification reduces reliance on explicit authorization from instructors, thus resolving the issues of heavy authorization burden and delayed response for teachers.

[0083] It should be noted that the event dimension features also include the user's course scheduling information, which refers to the user's course arrangement information in the academic affairs system, including structured data such as the courses taught or selected, class time, location, and week; when the controlled resource is a teaching resource, before the step of extracting the target associated entities in the dynamic relationship graph that have a preset association relationship with the controlled resource, the following steps are also included: Obtain a temporal graph constructed based on the course scheduling, wherein the temporal graph includes multiple teaching time periods, each teaching time period corresponds to a teaching instance, and the teaching instance consists of a course, an instructor, students enrolled in the course, and a classroom; based on the current timestamp, select a set of teaching instances covering the current moment from the temporal graph; extract a subgraph related to the set of teaching instances from the dynamic relationship graph, so as to extract target associated entities with a preset association relationship with the teaching resources based on the subgraph.

[0084] When the controlled resource is a teaching resource, a temporal graph constructed from the school-wide course scheduling is obtained. This temporal graph uses time as the axis and models each class of each course as a teaching instance with a time label. A teaching time period refers to a specific class period defined in the course scheduling plan, with clear start and end timestamps. A teaching instance refers to a teaching activity unit that actually occurs within a certain teaching time period, consisting of a quadruple: {course, instructor, set of students enrolled, classroom}, representing a specific teaching event.

[0085] Read the current system timestamp and filter out the set of teaching instances that contain that moment from the temporal graph, that is, identify which classes are being taught at this moment, who is teaching them, and where they are being taught.

[0086] Furthermore, using all entities (courses, teachers, students, classrooms) in the teaching instance set as seed nodes, subgraph extraction is performed in the global dynamic relationship graph to generate relevant subgraphs. That is, from the global dynamic relationship graph, local graph structures that are directly or indirectly related to any entity in the teaching instance set covering the current moment are extracted. Finally, nodes that have a preset relationship with the current teaching resources are further identified from the subgraph as target related entities.

[0087] Specifically, starting with the current user and ending with the target teaching resource, all reachable semantic paths are searched in the subgraph. Then, for each path, the corresponding credibility decay factor is retrieved based on its contained relation type sequence (e.g., course selection-use), and a cumulative credibility score is calculated based on the path length. If a path's score exceeds a preset threshold (e.g., 0.6), its penultimate node (i.e., the entity directly operating the resource, such as a course or instructor) is identified as the target associated entity, and the path's type is written into the authorization basis metadata. If no path meets the threshold, it is determined that the user has no valid authorization link with the resource. This allows the platform to distinguish between strong associations (e.g., formally enrolled students) and weak associations (e.g., visitors who gain access through three-level forwarding), avoiding over-authorization caused by long-tail weak connections in the graph.

[0088] When calculating the cumulative credibility score for any semantic path, first identify the current campus context pattern (e.g., final exam week) and the target teaching resource type (e.g., standardized examination room system); using the context and resource type as a joint index, query the dynamic adjustment factor corresponding to each relation edge from the context-relation credibility modulation table (e.g., under exam week, the adjustment factor for the invigilator-invigilator-exam room relationship is 1.1, while the adjustment factor for the student-course selection-course relationship is 0.6); multiply the original decay factor and the dynamic adjustment factor element-by-element to obtain the context-adaptive decay factor; substitute it into the context-aware exponential decay formula: ; in, The path's overall reliability score is given, where L is the path length. Let be the basic weight of the i-th edge. λ is the dynamic adjustment factor for the i-th relation edge, and λ is the path length penalty coefficient; This represents the path length tolerance coefficient under the current campus scenario.

[0089] Based on this adaptive factor and path length, the final cumulative credibility score is calculated using a context-aware exponential decay formula.

[0090] In this process, the denominator of the path length penalty term is dynamically scaled by a path length tolerance coefficient (e.g., in exam scenarios, the path length tolerance coefficient = 0.8, with a strong restriction on path length), thereby calculating the final cumulative credibility score. This makes the credibility assessment of semantic paths no longer a static rule, but rather dynamically evolves with the campus's operational status.

[0091] For example, on normal teaching days, the reliability of the teaching assistant-substitute-course-use-classroom path is high; however, during final exam week, the δ value of substitute-substitute relationships is automatically reduced, and the direct link of lecturer-invigilator-exam room is given priority, thereby preventing unauthorized personnel from entering the exam room.

[0092] When a user gains access through a long path, the authorization basis metadata can be fed back into the construction of a cross-course learning path profile, forming a positive cycle of authorization-learning-re-authorization.

[0093] Once a semantic path is used to identify the target associated entity and complete authorization, the system continuously monitors subsequent feedback. If the security module detects that the user has performed a high-risk operation on teaching resources (such as deleting experimental data), or if the user submits an appeal stating that the request should not be rejected, a reinforcement learning sample is generated. This sample is fed into a lightweight policy network, which calculates update suggestions for relevant items in the modulation table (such as the relationship between exam week, exam system, and proctor). Subsequently, the dynamic adjustment factor δ of this item is slightly adjusted (e.g., from 1.1 to 1.05) through a momentum smoothing mechanism. The updated modulation table is immediately used for the next path credibility calculation.

[0094] In this embodiment, since the teaching instance explicitly includes four elements—course, teacher, student, and classroom—and the relevant subgraph is constructed solely from these active entities, the extraction of target related entities is highly focused on the actual participants in the current teaching scenario. Furthermore, because this process completes spatiotemporal alignment early in the permission verification process, it significantly improves the real-time performance and accuracy of campus context consistency verification.

[0095] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the access control method of the smart campus in this application. Any simple modifications based on this technical concept are within the protection scope of this application.

[0096] This application also provides a smart campus management platform; please refer to [reference needed]. Figure 4 The smart campus management platform includes: The first acquisition module 10 is used to respond to a user's permission verification request for controlled resources within the campus, and to acquire the user's identity information and multi-dimensional contextual features related to the permission verification request. Extraction module 20 is used to parse the static identity tag and dynamic relationship graph of the user on campus based on the identity information. If the static identity tag meets the basic access conditions, the target associated entity with a preset association relationship with the controlled resource in the dynamic relationship graph is extracted. The verification module 30 is used to determine the current campus context mode based on the multi-dimensional context features, and to perform campus context consistency verification on the permission verification request based on the current campus context mode, the target associated entity, and the link between the user and the target associated entity. The first determining module 40 is used to determine that the permission verification is passed if the campus context consistency verification is passed.

[0097] In one embodiment, the multi-dimensional context features include time-dimensional features, spatial-dimensional features, event-dimensional features, and behavioral-dimensional features. The spatial-dimensional features include the functional area where the controlled resource is located, and the behavioral-dimensional features include the user's historical behavioral features. The verification module 30 includes: The matching submodule is used to match the corresponding set of normative behaviors from a preset behavior strategy template library based on the current context mode, the functional area where the controlled resource is located, and the user's static identity tag. The first determining submodule is used to parse the permission verification request into a current behavior intent vector, and determine whether the current behavior intent conforms to the norm based on the semantic matching degree between the current behavior intent vector and the behavior patterns in the set of normative behaviors. The calculation submodule is used to calculate the similarity between the historical behavior features and the current behavior intent vector if the behavior does not meet the requirements. If the similarity is greater than a preset similarity threshold, the current behavior intent is determined to be a reasonable behavior change, and the link is determined to pass the campus context consistency check.

[0098] In one embodiment, the controlled resources include teaching resources. After the step of determining whether the current behavioral intention belongs to a reasonable behavioral change based on the historical behavioral characteristics, the smart campus management platform further includes: The second determining module is used to obtain the teaching occupancy status of the teaching resources. If the teaching occupancy status is valid, the teaching entity occupying the teaching resources is determined to be a temporary authorizing party. The third determining module is used to add the temporary authorizing party to the target associated entity set to form an extended authorization link, and to determine the allowed behavior boundary according to the preset authorization constraint template; The fourth determining module is used to determine that the extended authorization link passes the campus context consistency check if the user's current behavioral intent does not exceed the allowed behavior boundary.

[0099] In one embodiment, the verification module 30 includes: The output submodule is used to output multiple candidate events and the confidence level of each candidate event based on the time dimension features, spatial dimension features, event dimension features and behavioral dimension features, through a preset campus context ontology model. The preset campus context ontology model is used to represent the relationship between multi-dimensional context features and campus context patterns. The weighted fusion submodule is used to perform weighted fusion on the multiple candidate events according to the confidence level and the preset modal weights corresponding to the multi-dimensional context features, so as to obtain a weighted fusion vector; The second determining submodule is used to determine the current campus scenario mode based on the weighted fusion vector and the spatiotemporal consistency constraint.

[0100] In one embodiment, the controlled resources include teaching resources, and prior to the step of responding to a user's permission verification request for controlled resources within the campus, the smart campus management platform further includes: The fifth determination module is used to obtain verification failure records for different teaching resources, and to determine the frequency and identity type distribution of unauthorized users' requests based on the verification failure records; The setting module is used to set alternative access conditions for the teaching resources if the frequency of the requests exceeds a preset number threshold and the proportion of the education beneficiary group in the identity type distribution is greater than a preset proportion threshold. The education beneficiary group includes at least one of the following: students who have passed the previous course certification but are not currently taking the course, and students who have authorization from the current course instructor but are not currently taking the course. Following the step of parsing the user's static identity tags and dynamic relationship graph within the campus based on the identity information, the smart campus management platform further includes: The judgment module is used to determine whether the teaching resource meets the alternative access conditions if the static identity tag does not meet the basic access conditions, and if the alternative access conditions are met, the permission verification is determined to be successful.

[0101] In one embodiment, the controlled resource includes teaching resources, and the event dimension feature further includes the user's class scheduling information. When the controlled resource is a teaching resource, before the step of extracting target associated entities in the dynamic relationship graph that have a preset association relationship with the controlled resource, the smart campus management platform further includes: The second acquisition module is used to acquire a temporal graph constructed based on the course scheduling, wherein the temporal graph includes multiple teaching time periods, each teaching time period corresponds to a teaching instance, and the teaching instance consists of a course, an instructor, students enrolled in the course, and a classroom; The filtering module is used to filter out a set of teaching examples covering the current moment from the temporal graph based on the current timestamp; The extraction module is used to extract subgraphs related to the set of teaching instances in the dynamic relationship graph, so as to extract target associated entities that have a preset relationship with the teaching resources based on the subgraphs.

[0102] The smart campus management platform provided in this application adopts the smart campus access control method in the above embodiments, which can solve the technical problem of low security of controlled resources in smart campuses. Compared with the prior art, the beneficial effects of the smart campus management platform provided in this application are the same as those of the smart campus access control method provided in the above embodiments, and other technical features in the smart campus management platform are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0103] This application provides a smart campus access control device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the smart campus access control method in the first embodiment described above.

[0104] The following is for reference. Figure 5The diagram illustrates a structural schematic of a smart campus access control device suitable for implementing embodiments of this application. The smart campus access control device in this application may include, but is not limited to, mobile terminals such as mobile phones, tablets, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital televisions and desktop computers. Figure 5 The smart campus access control device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0105] like Figure 5 As shown, the access control device for a smart campus may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the access control device for the smart campus. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, touchscreens, touchpads, keyboards, mice, image sensors, microphones, accelerometers, gyroscopes, etc.; output devices 1008 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 1003 including, for example, magnetic tapes, hard disks, etc.; and communication devices 1009. Communication device 1009 allows the access control device of a smart campus to communicate wirelessly or wiredly with other devices to exchange data. Although the figure shows access control devices for a smart campus with various systems, it should be understood that implementing or having all of the systems shown is not required. More or fewer systems may be implemented alternatively.

[0106] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0107] The smart campus access management device provided in this application, employing the smart campus access management method described in the above embodiments, can solve the technical problem of low security of controlled resources in smart campuses. Compared with the prior art, the beneficial effects of the smart campus access management device provided in this application are the same as those of the smart campus access management method provided in the above embodiments, and other technical features of this smart campus access management device are the same as those disclosed in the previous embodiment method, and will not be repeated here.

[0108] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0109] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0110] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, which are used to execute the access control method for a smart campus in the above embodiments.

[0111] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0112] The aforementioned computer-readable storage medium may be included in the access control device of the smart campus; or it may exist independently and not be installed in the access control device of the smart campus.

[0113] The aforementioned computer-readable storage medium carries one or more programs, which, when executed by the smart campus access control device, cause the smart campus access control device to execute the aforementioned smart campus access control method.

[0114] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0115] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0116] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0117] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., computer programs) for executing the above-described smart campus access control method, thereby solving the technical problem of low security of controlled resources in smart campuses. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as the beneficial effects of the smart campus access control method provided in the above embodiments, and will not be repeated here.

[0118] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the smart campus access control method described above.

[0119] The computer program product provided in this application can solve the technical problem of low security of controlled resources in smart campuses. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as the beneficial effects of the access control method for smart campuses provided in the above embodiments, and will not be repeated here.

[0120] The above descriptions are merely some embodiments of this application and do not limit the scope of protection of this application. Any equivalent structural transformations made based on the technical concept of this application and the content of this specification and drawings, or direct / indirect applications in other related technical fields, are included within the scope of protection of this application. All actions involving the acquisition of signals, information, or data in this application are performed in accordance with the relevant data protection laws and policies of the country where the application is located and with authorization from the owner of the corresponding device.

Claims

1. A method for access control in a smart campus, characterized in that, The access control method for a smart campus management platform includes: In response to a user's permission verification request for controlled resources on campus, the system obtains the user's identity information and multi-dimensional contextual features related to the permission verification request. Based on the identity information, the static identity tags and dynamic relationship graph of the user within the campus are analyzed. If the static identity tags meet the basic access conditions, the target associated entities in the dynamic relationship graph that have a preset association relationship with the controlled resource are extracted. Based on the multi-dimensional context features, the current campus context mode is determined. Based on the current campus context mode, the target associated entity, and the link between the user and the target associated entity, the campus context consistency check is performed on the permission verification request. If the campus context consistency check passes, then the permission verification is considered successful.

2. The access control method for a smart campus as described in claim 1, characterized in that, The multi-dimensional context features include time-dimensional features, spatial-dimensional features, event-dimensional features, and behavioral-dimensional features. The spatial-dimensional features include the functional area where the controlled resource is located, and the behavioral-dimensional features include the user's historical behavioral features. The step of performing campus context consistency verification on the permission verification request based on the current campus context mode, the target associated entity, and the link between the user and the target associated entity includes: Based on the current context mode, the functional area where the controlled resource is located, and the user's static identity tag, the corresponding set of normative behaviors is matched from the preset behavior strategy template library; The permission verification request is parsed into a current behavior intent vector. Based on the semantic matching degree between the current behavior intent vector and the behavior patterns in the set of normative behaviors, it is determined whether the current behavior intent conforms to the norm. If it does not meet the requirements, the similarity between the historical behavioral features and the current behavioral intent vector is calculated. If the similarity is greater than the preset similarity threshold, the current behavioral intent is determined to be a reasonable behavioral change, and the link is determined to pass the campus context consistency check.

3. The access control method for a smart campus as described in claim 2, characterized in that, The controlled resources include teaching resources. Following the step of determining whether the current behavioral intention constitutes a reasonable change in behavior based on the historical behavioral characteristics, the method further includes: Obtain the teaching occupancy status of the teaching resources. If the teaching occupancy status is valid, determine that the teaching entity occupying the teaching resources is a temporary authorizing party. The temporary authorizing party is added to the target associated entity set to form an extended authorization link, and the allowed behavior boundary is determined according to the preset authorization constraint template; If the user's current behavioral intent does not exceed the permitted behavior boundary, then the extended authorization link is determined to have passed the campus context consistency check.

4. The access control method for a smart campus as described in claim 2, characterized in that, The step of determining the current campus context mode based on the multi-dimensional context features includes: Based on the time dimension features, spatial dimension features, event dimension features, and behavioral dimension features, multiple candidate events and the confidence level of each candidate event are output through a preset campus context ontology model. The preset campus context ontology model is used to represent the relationship between multi-dimensional context features and campus context patterns. Based on the confidence level and the preset modal weights corresponding to the multi-dimensional context features, the multiple candidate events are weighted and fused to obtain a weighted fusion vector; Based on the weighted fusion vector and the spatiotemporal consistency constraint, the current campus scenario mode is determined.

5. The access control method for a smart campus as described in claim 1, characterized in that, The controlled resources include teaching resources, and prior to the step of responding to a user's permission verification request for controlled resources on campus, the method further includes: Obtain verification failure records for different teaching resources, and determine the frequency and identity type distribution of unauthorized users' requests based on the verification failure records; If the frequency of the requests exceeds a preset threshold, and the proportion of the education beneficiary group in the identity type distribution is greater than a preset proportion threshold, then alternative access conditions are set for the teaching resources. The education beneficiary group includes at least one of the following: students who have passed the previous course certification but are not currently taking the course, and students who are not currently taking the course but have authorization from the current course's main lecturer. The step of parsing the user's static identity tags and dynamic relationship graph within the campus based on the identity information further includes: If the static identity tag does not meet the basic access conditions, then it is determined whether the teaching resource meets the alternative access conditions. If it meets the alternative access conditions, then the permission verification is confirmed to be successful.

6. The access control method for a smart campus as described in claim 2, characterized in that, The controlled resources include teaching resources, and the event dimension features also include the user's class scheduling information. When the controlled resource is a teaching resource, before the step of extracting target associated entities in the dynamic relationship graph that have a preset association relationship with the controlled resource, the method further includes: Obtain a temporal graph constructed based on the course scheduling, wherein the temporal graph includes multiple teaching time periods, each teaching time period corresponds to a teaching instance, and the teaching instance consists of a course, an instructor, students enrolled in the course, and a classroom; Based on the current timestamp, a set of teaching examples covering the current moment is selected from the temporal graph; Extract subgraphs related to the set of teaching examples from the dynamic relationship graph, and extract target associated entities with preset association relationships with the teaching resources based on the subgraphs.

7. A smart campus management platform, characterized in that, The smart campus management platform includes: The first acquisition module is used to respond to a user's permission verification request for controlled resources within the campus, and to acquire the user's identity information and multi-dimensional contextual features related to the permission verification request. The extraction module is used to parse the user's static identity tags and dynamic relationship graph within the campus based on the identity information. If the static identity tags meet the basic access conditions, the target associated entities in the dynamic relationship graph that have a preset association relationship with the controlled resource are extracted. The verification module is used to determine the current campus context mode based on the multi-dimensional context features, and to perform campus context consistency verification on the permission verification request based on the current campus context mode, the target associated entity, and the link between the user and the target associated entity. The first determining module is used to determine that the permission verification is successful if the campus context consistency verification is successful.

8. A smart campus access control device, characterized in that, The access control device for the smart campus includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the access control method for the smart campus as described in any one of claims 1 to 6.

9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the access management method for a smart campus as described in any one of claims 1 to 6.

10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the access control method for a smart campus as described in any one of claims 1 to 6.