A student online time management and control method and system based on an encryption network
By constructing user scenario profiles and multi-stage user adaptation models, differentiated network access control rules are dynamically generated, solving the problem of campus network management that cannot adapt to the daily routines of students at different educational levels in existing technologies. This achieves precise and dynamic access management, improving learning focus and network protection effectiveness.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUNAN ENG POLYTECHNIC
- Filing Date
- 2026-03-11
- Publication Date
- 2026-06-02
AI Technical Summary
The existing campus network management system cannot adapt to the differences in the daily routines of students at different grade levels. As a result, the uniform time restrictions cannot accurately determine whether students are in a proper learning state, and cannot flexibly adjust access permissions according to the teaching progress. This leads to the blocking of learning needs or the inability to effectively restrict non-learning behaviors during certain periods.
By collecting multi-dimensional parameters such as user education stage, time schedule, identity details, group attributes, and access devices, a user scenario profile is constructed. A multi-stage user adaptation model is used to generate differentiated time-period control rules. Combined with identity authentication and temporary key mechanisms, access control is dynamically adjusted to allow access to education-related resources only and to monitor violations in real time.
It achieves precise, dynamic, and intelligent access protection based on different learning stages and device environments, improving learning focus and network protection effectiveness, and reducing the risk of learning interruption caused by device differences.
Smart Images

Figure CN122137643A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of campus network management and control technology, and in particular discloses a method and system for managing student internet access time based on an encrypted network. Background Technology
[0002] Against the backdrop of rapid development in educational informatization, campus networks have become a crucial infrastructure for students' learning, daily life, and information access. Especially in various schools, it has become commonplace for students to use the internet to complete coursework, access information, and submit assignments. At the same time, the internet also serves entertainment and social functions. Therefore, the proper management of students' internet use is directly related to maintaining teaching order, guiding healthy growth, and effectively utilizing campus network resources.
[0003] Current campus network management solutions mostly adopt a uniform time-based restriction strategy, such as specifying fixed time periods for opening or closing network access each day. While this approach is simple to operate, it has revealed significant shortcomings in practical application: it cannot adapt to the significant differences in the daily routines of students at different grade levels, nor can it keep pace with the school's specific teaching arrangements. Elementary and middle school students require stricter anti-addiction protection, high school students face intensive study needs for college entrance examination preparation, and university students have more independent learning and research tasks; at the same time, the needs and restrictions on network use are completely different during different time periods such as class time, evening self-study, weekends, holidays, and winter and summer vacations. Uniform time-based control leads to the incorrect blocking of students' legitimate learning needs during some periods, while non-learning behaviors cannot be effectively restricted during other periods, resulting in a serious disconnect between the control effect and the actual teaching scenario.
[0004] A deeper problem lies in the fact that students' online behavior is influenced by a variety of factors, including their grade level, class, daily schedule, whether they are on holiday or during homework assignments, whether they are using a school computer or a mobile phone, and the real-time verification of their identity. These factors are closely interconnected: the same student's internet needs during weekday classes and on weekend evenings are drastically different, and the management requirements for different devices accessing the same network also need to be differentiated. Relying solely on fixed time rules makes it impossible to accurately determine whether a student is in a proper learning state at a specific moment, or to flexibly adjust access permissions according to the teaching progress. For example, during evening self-study periods, students need to access the school's designated learning platforms and educational resource websites, but if a student is using their mobile phone to watch entertainment videos at the same time, they should be restricted; while during specific periods of holiday homework completion, access to relevant learning websites is allowed, but intervention is necessary if the time exceeds a reasonable limit or if irrelevant content is accessed. This multi-dimensional interplay of factors creates a precise matching challenge, making it difficult for traditional methods to provide the right network access range to the right student at the right time.
[0005] Therefore, how to dynamically generate and execute differentiated rules for controlling online time and access scope based on students' learning stage characteristics, real-time teaching arrangements, and various identity scenario parameters has become a key issue in achieving precise management and healthy guidance of students' online behavior. Summary of the Invention
[0006] This invention provides a method and system for managing student internet access time based on an encrypted network, aiming to solve at least one of the defects existing in the prior art.
[0007] One aspect of the present invention relates to a method for managing student internet access time based on an encrypted network, comprising the following steps: S100: Obtain the time schedule data and course planning information corresponding to the user's current educational stage through the parameter acquisition module. At the same time, collect user identity details, group attributes and the type of currently connected device to obtain a multi-dimensional parameter set containing stage characteristics, time details and device attributes. S200. Input the multi-dimensional parameter set into the pre-built multi-stage user adaptation model. The multi-stage user adaptation model analyzes the time series data according to the learning needs characteristics of different education stages to obtain a time period control requirement description that matches the current stage and schedule, including access restriction specifications. S300: Based on the time-period control requirements description, the access control policy generation module executes the rule derivation process to generate differentiated control rules applicable to the current time. S400 verifies the authentication request initiated by the user through the unified identity authentication mechanism. After successful authentication, it determines whether the current time belongs to the allowed access period based on the differentiated control rules. If it does, it triggers the key generation mechanism to generate a temporary key. S500 uses a temporary key to establish a secure communication link and unlock compliant paths. At the same time, it filters the target resource list according to the access restriction conditions in the differentiated control rules, allowing only access requests for education-related resources. S600 continuously monitors the data flow in real time according to differentiated control rules during the communication link maintenance period. If a violation of the rules is detected, the link is blocked and the restricted state is restored. Behavior records are added to improve the feedback mechanism.
[0008] Further, step S100 includes: S110. Obtain the educational stage information corresponding to the user's identity identifier, and extract the course planning outline and semester teaching calendar data based on the educational stage information. S120: Analyze the course planning outline and semester teaching calendar data to generate a time arrangement sequence containing precise start and end times; S130. Combining the device resolution values of the access devices with the historical interaction behavior patterns of similar user groups, the time schedule sequence is adapted to generate stage feature description data. S140. Vectorize and aggregate the time schedule sequence, hardware attribute parameters of the access device, and stage feature description data to obtain a multi-dimensional parameter set containing stage features, time details, and device attributes.
[0009] Further, step S200 includes: S210. Input the multi-dimensional parameter set into the multi-stage user adaptation model, and the multi-stage user adaptation model parses to obtain the education stage identifier vector. S220. Match the learning demand feature matrix with the educational stage identifier vector, and use the learning demand feature matrix to segment the time series to identify immersive learning periods. S230. Calculate the control intensity coefficient for the immersive learning period based on the device characteristics. If the control intensity coefficient exceeds the limit, generate an access blocking instruction. S240. Obtain the time-period control requirement description and access restriction specifications based on the access blocking instruction.
[0010] Further, step S300 includes: S310. Extract the set of basic constraints based on the time period control requirements and access restriction specifications, and obtain a snapshot of the device status at the current moment containing the application running list; S320. Use the set of basic constraints to compare the current device status snapshot to identify status violations; S330. Calculate the dynamic adjustment factor based on the status violation item, and use the dynamic adjustment factor to correct the preset permission mapping table. S340. Perform logical verification on the revised permission mapping table and generate differentiated control rules applicable to the current moment.
[0011] Further, step S400 includes: S410. Receive an authentication request data packet containing user identity credentials. After the authentication request data packet is verified by the unified identity authentication mechanism, an authentication pass status identifier is generated. S420. Extract the user's unique index key based on the authentication pass status identifier, and use the user's unique index key to load the time period control logic entry from the differentiated control rules. S430. Obtain the timestamp data of the current system running time, compare the timestamp data with the time period control logic entry, and output the time period compliance instruction if the timestamp data is within the allowed access time period. S440. Generate a temporary key based on the time period compliance instruction, combined with the user's unique index key and timestamp data.
[0012] Further, step S500 includes: S510: Receive the temporary key output by the key generation mechanism, and use the temporary key to verify the protocol handshake data to build a secure communication link; S520: Load the path mapping table based on the secure communication link, and unlock compliant paths according to the path mapping table; S530: Listen for resource access requests transmitted via compliant paths, parse the resource access requests to obtain a list of target resources and access restrictions; S540. Input the target resource list and access restriction conditions into the resource filtering matrix, extract specific resource entries with the educational resource tag, and allow access requests only for educational resources.
[0013] Further, step S600 includes: S610: Collect real-time data streams transmitted via compliant paths and extract feature fingerprints from the real-time data streams; S620. Calculate the matching similarity value based on the feature fingerprint. If the matching similarity value exceeds the threshold, generate a link blocking command. S630: Execute the link blocking command to disconnect the link and restore the restricted state, and capture the violation data and restricted state parameters to build a structured behavior record; S640 stores structured behavior records to enable real-time monitoring and blocking feedback of the current data stream.
[0014] Another aspect of the present invention relates to a student internet access time management system based on an encrypted network, used to execute the above-described student internet access time management method based on an encrypted network, comprising: The multidimensional parameter set acquisition module is used to obtain the time arrangement data and course planning information corresponding to the user's educational stage through the parameter acquisition module. At the same time, it collects user identity details, group attributes and the type of currently connected device to obtain a multidimensional parameter set containing stage characteristics, time details and device attributes. The time-segment control requirement description acquisition module is used to input a multi-dimensional parameter set into a pre-built multi-stage user adaptation model. The multi-stage user adaptation model parses the time series data according to the learning needs characteristics of different education stages to obtain a time-segment control requirement description that matches the current stage and schedule, including access restriction specifications. The differentiated control rule generation module is used to generate differentiated control rules applicable to the current time by performing the rule derivation process according to the time period control requirements description and the access control policy generation module. The temporary key generation module is used to verify the authentication request initiated by the user through the unified identity authentication mechanism. After the authentication is successful, it determines whether the current time belongs to the allowed access period based on the differentiated control rules. If it does, the key generation mechanism is triggered to generate a temporary key. The target resource list filtering module is used to establish a secure communication link and unlock compliant paths using temporary keys. At the same time, it filters the target resource list according to the access restriction conditions in the differentiated control rules, allowing only access requests for education-related resources. The feedback mechanism enhancement module is used to continuously monitor the data flow in real time according to differentiated control rules during the communication link maintenance. If a violation of the rules is detected, the link is blocked and the restricted state is restored. Behavior records are added to enhance the feedback mechanism.
[0015] The beneficial effects achieved by this invention are as follows: The present invention provides a method and system for controlling student internet access time based on encrypted networks. This system constructs a comprehensive user scenario profile by collecting multi-dimensional parameters such as user education stage, time schedule, course planning, identity details, group attributes, and access devices. These multi-dimensional parameters are input into a multi-stage user adaptation model. This model performs in-depth analysis of time-series data based on the learning needs characteristics of different education stages, accurately generating differentiated time-segment control requirement descriptions and access restriction specifications that match the current stage and time. Subsequently, based on these differentiated time-segment control requirement descriptions, rule derivation is performed to dynamically generate personalized access control rules applicable to the current time. When a user initiates an authentication request, after unified identity authentication, the system determines whether the current access period is permitted based on the control rules. If permitted, a temporary key generation mechanism is triggered to establish a secure communication link and unlock the compliant path. Simultaneously, target resources are filtered, allowing only education-related content. During the communication period, the system continuously monitors the data stream in real time. Once a violation is detected, the link is immediately blocked, the restricted state is restored, and the behavior is recorded for optimized feedback. This invention effectively solves the integration problems in educational scenarios, such as the large differences in access control needs, static rule failure, mixed resources interfering with learning efficiency, and high security risks caused by different learning stages, time arrangements, and device environments. It achieves precise, dynamic, and intelligent access protection for educational resources and management of learning time periods, significantly improving the effectiveness of online protection for minors and their concentration on learning. Attached Figure Description
[0016] Figure 1 This is a flowchart illustrating an embodiment of the student internet access time management method based on an encrypted network according to the present invention. Figure 2 This is a functional block diagram of an embodiment of the student internet access time management system based on an encrypted network according to the present invention.
[0017] Explanation of icon numbers: 10. Multi-dimensional parameter set acquisition module; 20. Time period control requirement description acquisition module; 30. Differentiated control rule generation module; 40. Temporary key generation module; 50. Target resource list filtering module; 60. Feedback mechanism improvement module. Detailed Implementation
[0018] To better understand the above technical solutions, the following will provide a detailed explanation of the technical solutions in conjunction with the accompanying drawings and specific implementation methods.
[0019] like Figure 1 As shown, the first embodiment of the present invention proposes a method for managing student internet access time based on an encrypted network, including the following steps: Step S100: Obtain the time schedule data and course planning information corresponding to the user's current educational stage through the parameter acquisition module. At the same time, collect user identity details, group attributes and the type of currently connected device to obtain a multi-dimensional parameter set containing stage characteristics, time details and device attributes.
[0020] The system's built-in parameter acquisition module simultaneously acquires two types of core information: first, educational stage time arrangement data and course planning information related to students' learning plans; and second, identity details, group attributes, and current access device types related to user identity and access terminals. The collected heterogeneous data is standardized, integrated, and classified to generate a multi-dimensional parameter set containing stage characteristics, time details, and device attributes. This comprehensively covers the core influencing factors of student internet access management, providing complete and accurate basic data support for subsequent stage-based adaptation and differentiated rule generation. It is a core prerequisite for achieving personalized internet access management.
[0021] Step S200: Input the multi-dimensional parameter set into the pre-built multi-stage user adaptation model. The multi-stage user adaptation model analyzes the time series data according to the learning needs characteristics of different education stages to obtain a time period control requirement description that matches the current stage and schedule, including access restriction specifications.
[0022] The multi-dimensional parameter set constructed in step S100 is input into a multi-stage user adaptation model pre-trained based on the learning characteristics of each educational stage. This multi-stage user adaptation model analyzes and matches the time series data in the parameter set in a targeted manner, taking into account the learning needs, daily routines, and academic goals of different educational stages such as primary school, middle school, and university. Combined with the student's specific course plan and time arrangement, it generates a time-segment control requirement description that is highly matched with the current educational stage and personal learning arrangement. This description clearly includes core access restriction specifications such as time limits for internet access and scope of resource access, realizing a precise transformation from "unified control" to "educational stage adaptation and personal matching", providing a targeted requirement basis for the generation of subsequent control rules.
[0023] Step S300: Based on the time period control requirements description, the access control policy generation module performs the rule derivation process to generate differentiated control rules applicable to the current time.
[0024] Taking the time-segment control requirements output in step S200 as input, the rule derivation algorithm built into the access control policy generation module, combined with the current real-time time and the student's current learning status, concretizes and makes the control requirements executable. Through logical reasoning and rule matching, differentiated control rules applicable to the current moment are generated. The differentiated control rules cover core clauses such as the time-segment thresholds for allowing / prohibiting internet access, the range of types of accessible resources, and the differences in control intensity for different access devices, so as to realize the dynamic adaptation of control rules to the student's real-time scenario and ensure the timeliness and pertinence of the control strategy.
[0025] Step S400: Verify the authentication request initiated by the user through the unified identity authentication mechanism. After successful authentication, determine whether the current time is within the allowed access period based on the differentiated control rules. If it is, trigger the key generation mechanism to generate a temporary key.
[0026] First, the system's unified identity authentication mechanism verifies the identity of network access authentication requests initiated by students, ensuring the authenticity and legality of the user's identity and preventing control circumvention behaviors such as impersonation and account sharing. After successful authentication, the differentiated control rules generated in step S300 are retrieved to determine in real time whether the current time is within the allowed access period defined by the rules. If it is determined to be a compliant access period, the system's built-in key generation mechanism is immediately triggered to randomly generate a valid temporary encryption key, providing an encryption foundation for establishing a secure communication link in the future, and realizing dual access verification of "identity compliance + time period compliance".
[0027] Step S500: Establish a secure communication link using a temporary key and unlock the compliant path. At the same time, filter the target resource list according to the access restriction conditions in the differentiated control rules, and only allow access requests for education-related resources.
[0028] Using the temporary key generated in step S400 as an encryption credential, a secure encrypted communication link is established between the student terminal and the management system. At the same time, the compliant path for network access is unlocked to ensure the security of compliant online data transmission. Simultaneously, based on the access restrictions in the differentiated management rules, the network access requests initiated by students are filtered through the target resource list. Matching and verification are performed through a preset educational resource feature database. Only access requests for educational resources such as online course platforms, academic databases, and teaching resource websites are allowed, while access to non-educational resources such as games, entertainment, and harmful information is blocked, achieving dual management of "encrypted access + resource compliance".
[0029] Step S600: During the communication link maintenance period, continuously monitor the data flow in real time according to the differentiated control rules. If a violation of the rules is detected, block the link and restore the restricted state. Add behavior records to improve the feedback mechanism.
[0030] Throughout the entire internet access process while maintaining a secure communication link, this step involves the system monitoring module continuously monitoring network data flow in real time according to differentiated control rules. This accurately identifies violations such as exceeding the permitted internet access time, accessing non-educational resources, and switching access devices. If a violation is detected, the link blocking mechanism is immediately triggered, severing the secure communication link and restoring the student's network access status to a restricted state. Simultaneously, information such as the time, type, and terminal of the violation is entered into the system behavior database to improve the behavior feedback mechanism. This provides data support for subsequent optimization of control rules and guidance of student internet behavior, forming a complete control loop of "real-time monitoring - immediate handling - data feedback," ensuring the effectiveness and continuity of internet access time control.
[0031] Furthermore, the student internet access time management method based on an encrypted network provided in this embodiment includes step S100 as follows: Step S110: Obtain the educational stage information corresponding to the user's identity identifier, and extract the course planning outline and semester teaching calendar data based on the educational stage information.
[0032] After obtaining the educational stage information corresponding to the user's identity identifier, the system first extracts the curriculum outline and semester teaching calendar data. For example, in one embodiment, for a fourth-grade user, the system obtains the outlines of four main subjects: Chinese, mathematics, English, and science. Chinese includes three modules: classical poetry, reading comprehension, and composition. The semester teaching calendar shows that the first semester is from September 1st to January 15th, which lasts for 18 weeks, with 4 class hours of Chinese per week.
[0033] Step S120: Analyze the course planning outline and semester teaching calendar data to generate a time arrangement sequence containing precise start and end times.
[0034] After analyzing the curriculum outline and semester teaching calendar, a time schedule sequence containing precise start and end times is generated. Preferably, 8:30-11:30 AM and 2:00-4:30 PM from Monday to Friday are designated as school hours. Combined with the science experiment class on Wednesday afternoon and the Chinese reading class on Friday marked in the calendar, the output sequence is as follows: September 4th 8:30-9:15 Chinese classical poetry explanation, 9:25-10:10 math multiplication operation, 10:20-11:05 English vocabulary listening and speaking, etc., with arrangements accurate to the minute.
[0035] Step S130: Combine the device resolution values of the access devices with the historical interaction behavior patterns of similar user groups to adapt the time schedule sequence to generate stage feature description data.
[0036] By combining the device resolution values of the accessed devices with the historical interaction patterns of similar user groups, the time schedule sequence is adapted to generate stage characteristic description data. For example, historical data of fourth-grade elementary school users shows that 80% use tablet devices with a resolution of 1920×1200 or higher and prefer to watch video explanations in landscape mode, while mobile phone users have lower resolutions and mainly use portrait mode. Therefore, for the same math geometry lesson, the tablet version is adjusted to a full 45-minute explanation with more dynamic demonstration graphics, while the mobile version is compressed into a 30-minute concise version with key formulas and examples. At the same time, the stage characteristic description data is labeled as "middle elementary school grades, preference for both text and graphics, attention span of about 35 minutes".
[0037] Historical interaction patterns of similar user groups refer to the set of behaviors generated by the user group in the course of interaction with the system and educational resources within a historical period (default 90 days, configurable) under compliant paths, after the system collects basic user attributes (such as grade, academic stage, and user role) based on the unified identity authentication mechanism and combines them with the hardware parameters of the access device (core of which includes device resolution). These behaviors are statistically significant, regular, and reusable. They are the core basis for subsequent time sequence adaptation and generation of stage feature description data.
[0038] Step S140: Vectorize and aggregate the time schedule sequence, hardware attribute parameters of the access device, and stage feature description data to obtain a multi-dimensional parameter set containing stage features, time details, and device attributes.
[0039] The multidimensional parameter set, which includes stage characteristics, time details, and device attributes, is derived using the following formula: (1) In formula (1), It represents a multidimensional parameter set, which is a unified vector containing time, hardware, and stage characteristics. This indicates a vectorization operation that converts heterogeneous data in non-vector form into a fixed-length vector. It indicates a time schedule sequence, such as students' online time periods or daily routines. This indicates the hardware attribute parameters of the access device, such as device model, operating system, IP address, etc. The data represents the characteristics of the stage, such as the student's academic stage, current semester, and holiday status. The control logic of formula (1) is a multi-source data vectorization aggregation model. The core is to vectorize the three types of heterogeneous data, namely time, hardware, and stage, and then concatenate them into a unified multi-dimensional parameter vector to provide a structured data foundation for subsequent analysis and decision-making.
[0040] By vectorizing and aggregating the time-series learning data, the hardware attributes of the connected devices, and the stage-specific features, a multi-dimensional parameter set is obtained. For example, the time series can be quantified into daily learning duration vectors and weekly distribution vectors. Hardware parameters include resolution values, screen size, and processor type. Stage features are encoded as educational stage labels, attention preference coefficients, and average interaction durations, forming a multi-dimensional vector set of approximately 180 dimensions. For instance, for the same fourth-grade user using a 10.5-inch tablet, this set might reflect features such as high-resolution adaptation for complete animation demonstrations, a 35-minute optimal focus period, and a priority weight of 0.28 for the Chinese reading module. When switching to a mobile phone, the set automatically adjusts to prioritize concise content, a 25-minute focus period, and an increased weight of 0.35 for voice interaction. This multi-dimensional parameter set supports subsequent accurate recommendations of learning content, dynamic adjustment of lesson density, and optimization of interface layout, thereby significantly improving the continuity of learning and the efficiency of knowledge absorption, while reducing experience gaps caused by device differences and effectively improving the overall accuracy of teaching adaptation.
[0041] Preferably, the student internet access time management method based on an encrypted network provided in this embodiment includes step S200: Step S210: Input the multi-dimensional parameter set into the multi-stage user adaptation model, and the multi-stage user adaptation model parses to obtain the education stage identifier vector.
[0042] The educational stage identifier vector is derived using the following formula: (2) In formula (2), This represents an education stage identifier vector, a vector that can uniquely identify the user's education stage (such as primary school, junior high school, or senior high school). The overall function representing the multi-stage user adaptation model is a trained machine learning model used to extract educational stage features from input parameters. This represents all parameters of the multi-stage user adaptation model. arrive Each represents a set of multi-dimensional input parameters, including information such as time schedule, device attributes, and stage characteristics. This represents the total number of multidimensional parameter sets. The control logic of formula (2) is a multi-source data-driven model reasoning process. The core is to input multiple multidimensional parameter sets into a multi-stage user adaptation model, and output a vector that can uniquely identify the user's educational stage through feature extraction and mapping of the model.
[0043] After inputting a multi-dimensional parameter set into a multi-stage user adaptation model, which is a machine learning model pre-trained based on the learning characteristics of each educational stage, the model performs hierarchical analysis and feature extraction on the input multi-dimensional user parameter set to output an identifier vector that accurately represents the user's current educational stage. This multi-stage user adaptation model takes a standardized multi-dimensional parameter vector as input and, through a multi-layer feature analysis structure, extracts key features such as the user's educational stage, semester, subject weight, learning status, and academic pressure layer by layer, ultimately generating an educational stage identifier vector containing labels for several educational stages. This educational stage identifier vector can be directly used for matching and recommending subsequent learning content, learning paths, or learning resources.
[0044] The training process of the multi-stage user adaptation model includes: constructing a sample dataset covering the learning behaviors and attributes of users across multiple educational stages; labeling and engineering the samples with educational stage features; and using a preset loss function and optimization algorithm to achieve model convergence. During the inference stage, only multi-dimensional user parameters need to be input to automatically output structured and quantifiable educational stage representations, thereby achieving accurate adaptation to users at different learning stages. This multi-stage user adaptation model first parses the input vector layer by layer to extract the educational stage identifier vector. This educational stage identifier vector accurately represents the characteristics of the user's current educational stage, such as upper elementary school, the beginning of junior high school, or the high school graduation review period. In one embodiment, for users using the sixth-grade elementary school identifier, the multi-stage user adaptation model outputs an educational stage identifier vector containing core dimensions such as "first semester of sixth grade," "balanced proportion of main subjects," and "initial pressure of college entrance examination," which directly participate in the subsequent matching process.
[0045] Step S220: Match the learning demand feature matrix with the education stage identifier vector, and use the learning demand feature matrix to segment the time series to identify immersive learning periods.
[0046] The following formula can be used to identify periods of immersive learning: (3) In formula (3), Indicates the first Are the learning segments immersive learning periods? Indicates the first The distance between each learning segment and the feature matrix of learning needs. This indicates the preset distance threshold. Indicates the first The duration of each learning segment The formula (3) represents the preset minimum duration threshold. It determines whether a segment belongs to an immersive learning period based on the distance and duration thresholds. The control logic of formula (3) is a double-threshold Boolean judgment model. The core is to determine whether a segment belongs to an immersive learning period by comparing the distance between the learning segment and the learning requirement feature matrix, as well as the duration of the segment.
[0047] Based on the educational stage identifier vector, the system matches the corresponding learning needs feature matrix. This learning needs feature matrix pre-constructs the learning rhythm patterns and content preference weights for different educational stages. For example, the learning needs feature matrix for sixth grade emphasizes in-depth training in Chinese reading comprehension and math word problems, while marking the best daily learning windows as concentrated between 9:00 AM and 11:00 AM and between 3:30 PM and 5:00 PM. Using this learning needs feature matrix, the system intelligently segments the original time series to identify truly suitable learning periods for deep immersion. Specifically, the system divides the originally continuous daily schedule into several independent segments, with 9:20 AM to 10:50 AM marked as a math immersion learning period and 4:00 PM to 5:20 PM marked as an English listening and speaking immersion period. These periods typically have high concentration potential and fewer distractions.
[0048] Step S230: Calculate the control intensity coefficient for the immersive learning period based on the device characteristics. If the control intensity coefficient exceeds the limit, generate an access blocking instruction.
[0049] The control intensity coefficient is obtained by the following formula: (4) In formula (4), Indicates the control intensity coefficient. This indicates the current estimated eye fatigue level of the device. Indicates the maximum fatigue threshold. Indicates the duration of continuous screen viewing. This represents the basic adjustment coefficient. This represents the fatigue nonlinearity index. The duration of the duration affects the baseline. The control logic of formula (4) is a multi-factor nonlinear weighted model. The core is to combine the current estimated value of eye fatigue of the device and the duration of continuous screen viewing to calculate a quantitative control intensity coefficient, which is used to determine whether to trigger the access blocking command.
[0050] Current eye fatigue estimate of the device This can be derived from the following formula: (5) In formula (5), Indicates the baseline blink frequency. Indicates the first The interval between blinks The formula represents the number of blinks, indicating that the current estimated eye fatigue of the device is the inverse multiple of the average blink interval relative to the reference frequency. The control logic of formula (5) is a fatigue quantification model based on blink frequency. The core is to quantify the current degree of eye fatigue by calculating the relative relationship between the average blink interval and the reference blink frequency.
[0051] Based on the identification of immersive learning periods, a control intensity coefficient is calculated in conjunction with device characteristics. Device characteristics mainly include screen size, resolution, processor performance, and historical interaction duration preferences. For example, when using a 10.1-inch high-resolution tablet, the control intensity coefficient tends to be lower, allowing for longer continuous learning windows; conversely, if the access device is a 5.5-inch low-end mobile phone and historical data shows that the user's average single focus time is only 18 minutes, the control intensity coefficient will be significantly higher. In one implementation, the control intensity coefficient for tablet devices typically falls between 0.4 and 0.65, while for mobile devices it may reach above 0.85. When the control intensity coefficient exceeds a preset threshold of 0.8, the system determines that unrestricted access is not appropriate for the current period and generates an access blocking command.
[0052] Step S240: Obtain the time period control requirement description and access restriction specifications based on the access blocking instruction.
[0053] Based on the access blocking command, the system further generates a description of time-segment control requirements and access restriction specifications. For example, for the morning math immersion period, if the control intensity coefficient is 0.92, the description generated is "In-depth training period for sixth-grade math word problems, mobile devices have low concentration maintenance ability," and the corresponding access restriction specifications are "Block access to entertainment applications, allow only learning tools, single continuous use not exceeding 25 minutes, with a mandatory 8-minute break." Preferably, this access restriction specification is also superimposed with a voice reminder mechanism, pushing a "Focus mode is about to end, please save your progress" prompt 3 minutes in advance when approaching the time limit, thereby guiding users to exit in an orderly manner. Through the layer-by-layer analysis of the multi-stage user adaptation model and device adaptation calculation, the system can accurately identify high-value immersion periods and apply differentiated control, avoiding excessive fatigue on inefficient devices while ensuring in-depth absorption of key knowledge points. This mechanism effectively improves the actual arrival rate of learning content, while significantly reducing the risk of interruption caused by device differences, bringing a more stable and continuous learning experience.
[0054] Furthermore, in the student internet access time management method based on an encrypted network provided in this embodiment, step S300 includes: Step S310: Extract the set of basic constraints based on the time period control requirements description and access restriction specifications, and obtain a snapshot of the device status at the current moment containing the application running list.
[0055] The set of basic constraints can be extracted using the following formula: (6) In formula (6), Represents the set of basic constraints. This indicates the application identifier, such as "browser" or "Learning Platform". Indicates access permissions, such as "read", "write", "network access", etc. Indicates the start time of control measures. Indicates the end of the control period. Indicates the current moment. Indicates application Permissions Permitted status, Represents the set of all application identifiers. This represents the set of all access permissions. The control logic of formula (6) is a set definition of multi-dimensional constraints. The core is to extract the basic constraints containing the three elements of application, permission, and time from the time period control requirement description and access restriction specification, which are used for subsequent device status verification and violation identification.
[0056] The set of application running states contained in the current device state snapshot is derived using the following formula: (7) In formula (7), Indicates the current time The application running status set contained in the device status snapshot is an ordered set of application identifiers and their corresponding statuses. This represents an application identifier, such as a unique identifier like "WeChat" or "browser". Indicates the current running status of the application. Indicates time application The actual operating status, Represents the set of all application identifiers. The state value constraint indicates that the application state can only be one of three: running in the foreground, stopped, or running in the background. The control logic of formula (7) is a state snapshot set definition. The core is to collect the running state of all applications at the current moment to generate a device state snapshot set, which is used to reflect the running status of each application on the device in real time.
[0057] Based on the description of time-based control requirements and access restriction specifications, a set of basic constraints is extracted. This process essentially transforms the control strategies described in natural language into structured rules that machines can recognize and execute. For example, for the description "during intensive training sessions on sixth-grade math word problems, mobile devices have low attention spans" and the specification "block access to entertainment apps, allow only learning tools, single continuous use not exceeding 25 minutes, with a mandatory 8-minute break," the system extracts several independent basic constraints. Specifically, these constraints include: the allowed app category whitelist is "learning tools," the prohibited app category blacklist is "entertainment," the upper limit for single continuous use is 25 minutes, and the lower limit for mandatory breaks is 8 minutes. These constraints together constitute a precise benchmark for subsequent comparisons.
[0058] Obtaining a snapshot of the device's current state, containing a list of running applications, is a momentary record of the device's real-time operational status. In one implementation, the state snapshot records not only the processes of applications running in the foreground, such as the "Math Tutor App" and the "Dictionary App," but also active background application services, such as the "Music Player" and the "Instant Messaging Software." Simultaneously, the snapshot is associated with the duration each application has been running; for example, the "Math Tutor App" has been running in the foreground for 20 minutes.
[0059] Step S320: Use the set of basic constraints to compare the current device status snapshot to identify status violations.
[0060] Status violations are calculated using the following formula: (8) In formula (8), This indicates a status violation, which includes all device status elements that are not within any basic constraints. Elements that represent device status, such as application running status and network connection status. This represents a snapshot of the device's current state, which is a collection of all current state elements of the device. This indicates basic constraints, such as "list of allowed applications" or "scope of compliant network connections". This represents the set of basic constraints, which includes all preset compliant state constraints. The formula identifies non-compliant state items that are not within any constraints by comparing the set difference between the current device state snapshot and the union of the basic constraint set. The control logic of formula (8) is a set difference operation model, the core of which is to identify non-compliant state items that are not within any constraint range by calculating the difference between the current device state snapshot and the union of all basic constraint sets.
[0061] The system compares the current device state snapshot with a set of basic constraints to identify states that do not conform to established rules. For example, by comparing the above constraints with the state snapshot, the system may identify two state violations: first, the "music player" running in the background belongs to the "entertainment" category, violating the application category restriction; second, the "math tutoring app" has been running continuously for 20 minutes, which, although not exceeding the 25-minute limit, is close to the critical point. The system may mark this as a "pre-violation" state to trigger an alert or as a reference for dynamic adjustments.
[0062] Step S330: Calculate the dynamic adjustment factor based on the status violation item, and use the dynamic adjustment factor to correct the preset permission mapping table.
[0063] The dynamic adjustment factor is derived using the following formula: (9) In formula (9), Indicates the dynamic adjustment factor. Indicates the first The value of each status violation item. Indicates the total number of status violations. Indicates the first The standard value of each state violation item is used to calculate the dynamic adjustment factor based on the proportion of state violations. The control logic of formula (9) is a linear correction model based on the proportion of violations. The core is to generate a dynamic adjustment factor by calculating the ratio of the actual cumulative value of violations to the standard cumulative value of violations, which is used to subsequently correct the preset permission mapping table.
[0064] The revised permission mapping table is derived using the following formula: (10) In formula (10), This indicates the revised permission mapping table, which represents the dynamically adjusted permission configuration. This indicates the preset permission mapping table, which represents the initial default permission configuration. This represents the decay parameter, used to control the rate at which privileges decay. Indicates the first One status violation item, The formula (10) represents the number of violations. The entire formula is used to calculate a dynamic adjustment factor based on the number of state violations and to correct the preset permission mapping table. The control logic of formula (10) is a dynamic decay correction model based on violations. The core is to calculate an exponentially decaying adjustment factor based on the number of identified state violations and to dynamically correct the preset permission mapping table in order to achieve punitive permission control for violations.
[0065] Calculating a dynamic adjustment factor based on status violations is key to the system's flexible control. This dynamic adjustment factor is not a fixed value but is dynamically generated based on the severity of the violation and the context. For example, when the violation "an entertainment application is running in the background" is identified, the system will further analyze the application's resource usage. If the music player uses very little memory and does not produce audio output, its violation severity is low, and the calculated dynamic adjustment factor may be 1.1, indicating a small adjustment to the original rule. Conversely, if the application is playing video in the foreground and using high CPU, the adjustment factor may reach 1.5 or higher, meaning stricter restrictions are needed. This dynamic adjustment factor will be used to correct the preset permission mapping table, for example, changing the original "block entertainment applications" to "immediately and forcibly terminate the specified entertainment application process and lock its startup permission for 10 minutes."
[0066] Step S340: Perform logical verification on the revised permission mapping table to generate differentiated control rules applicable to the current moment.
[0067] The following formula is used to define the criteria for generating differentiated control rules applicable to the current moment: (11) In formula (11), Indicates the first Does this rule need to trigger differentiated control immediately at the current moment? Indicates the first The expiration time of the rule permissions. Indicates the current system time. This indicates a violation flag detected after logical verification. The value is 1 when a rule has expired and there is a violation. The control logic of formula (11) is a two-condition Boolean judgment model. The core is to determine whether to immediately trigger differentiated control by checking whether the rule has expired and whether there is a violation mark.
[0068] Logical validation of the revised permission mapping table ensures that the newly generated rules are consistent and securely executable. For example, the system checks whether the "force 8-minute break" rule conflicts with any "allow continuous use" rule, and ensures that all application categories are clearly defined and unambiguous. After validation, differentiated control rules applicable to the current moment are generated. This entire mechanism transforms control from a rigid "one-size-fits-all" approach into a dynamic process that senses real-time device status, understands the context of violations, and responds intelligently. It not only instantly corrects behaviors deviating from learning objectives but also applies appropriate interventions based on the specific circumstances of the violation. This ensures a immersive learning experience while maintaining the rationality of rule execution and user acceptance, ultimately improving the actual effectiveness of time-based control and the user experience.
[0069] Preferably, in the student internet access time management method based on an encrypted network provided in this embodiment, step S400 includes: Step S410: Receive an authentication request data packet containing the user's identity credentials. After the authentication request data packet is verified by the unified identity authentication mechanism, an authentication pass status identifier is generated.
[0070] Generate the authentication pass status flag using the following formula: (12) In formula (12), This indicates a successful authentication status. This indicates that the authentication has been successful. This indicates that the authentication failed. This represents the verification result returned by the unified identity authentication mechanism, with a Boolean value of true or false. The control logic of formula (12) is a Boolean mapping model based on the authentication result. The core is to directly map the verification result returned by the unified identity authentication mechanism into a status identifier for subsequent processes.
[0071] Verification result returned by the unified identity authentication mechanism This can be derived from the following formula: (13) In formula (13), This represents the unified authentication verification function, which is the core processing logic of the identity authentication system. This indicates an authentication request data packet, which contains user identity credentials (such as account, password, token, etc.). This represents the set of policy rules for the unified identity authentication mechanism, including verification rules for account validity, password complexity, token validity period, etc. The control logic of formula (13) is a policy-driven authentication verification model. Its core is to verify the authentication request data packet submitted by the user based on the preset unified identity authentication policy and return the verification result of boolean type.
[0072] Authentication request data packet This can be derived from the following formula: (14) In formula (14), This represents a user's identity identifier, such as a student ID or mobile phone number, used to uniquely identify the user. This refers to the identity credentials submitted by the user, such as passwords, dynamic tokens, biometrics, etc. This indicates the timestamp generated by the request, used to prevent replay attacks. The digital signature of the data packet is used to verify the integrity and authenticity of the data packet. The control logic of formula (14) is a structured data encapsulation model. The core of it is to encapsulate the four key information types of user identity, credentials, timestamp and digital signature into a complete authentication request data packet for verification by the unified identity authentication mechanism.
[0073] Upon receiving an authentication request data packet submitted by a user via a mobile device, the authentication request data packet embeds the user's pre-registered identity credentials, such as an account and password combination or a biometric token. The unified identity authentication mechanism performs multiple verifications on these credentials, including signature verification and validity period check. Once all verifications are successful, an authentication pass status flag is generated. This status flag is essentially a binary signal used to allow subsequent processes to proceed.
[0074] The unified identity authentication mechanism is an integrated security authentication system in the multi-stage user adaptation system used to verify the authenticity of user identities and prevent the risks of impersonation and account sharing. Its core function is to receive authentication request data packets submitted by users (including mobile devices), and to perform multiple verifications (including signature verification, validity period verification, etc.) on the user's pre-registered identity credentials (such as account password combinations, biometric tokens, etc.) embedded in the data packets. After all verifications pass, a binary authentication pass status identifier is generated (used for subsequent process approval). If the verification fails, authentication is rejected. At the same time, it achieves seamless integration with the existing campus system, real-time synchronization of user data, and full-process identity control, providing secure and reliable identity support for system resource access and user adaptation.
[0075] Step S420: Extract the user's unique index key based on the authentication pass status identifier, and use the user's unique index key to load the time period control logic entry from the differentiated control rules.
[0076] The time-slot control logic entries are derived using the following formula: (15) In formula (15), Indicates the loaded first Each time period control logic entry is a user-specific rule for internet access time. This represents a differentiated management rule base, which stores the time-period management rules for all users. This represents a user's unique index key, used to uniquely identify the user. This represents the set of time-period control logic entries, which is a subset of rules categorized by time period in the rule base. This indicates the operation of loading the corresponding time period rule from the rule base based on the user's unique index key, which is used to match and extract the corresponding rule from the rule base. The control logic of formula (15) is a rule matching and loading model based on user identity. The core is to accurately load the time period control logic corresponding to the user from the differentiated control rule base based on the user's unique index key.
[0077] User unique index key This can be derived from the following formula: (16) In formula (16), This represents the user's unique index key, which serves as the sole identifier for subsequent loading of personalized control rules. This indicates the authentication status: 1 means authentication passed, and 0 means authentication failed. This indicates the operation of extracting the user's unique index key from the authentication status identifier. The extraction of the index key is only performed when authentication is successful. This represents the user's original unique index key, such as student ID, internal user ID, etc. The control logic of formula (16) is an index extraction model based on authentication status. The core is to extract the user's unique index key from the authentication result for subsequent rule matching, provided that the authentication is successful.
[0078] The system immediately extracts the corresponding user's unique index key based on the authentication success status. This unique index key is typically a hashed string that uniquely corresponds to a user account and has collision-resistant properties. Using this index key, the system accurately loads the time-segment control logic entries bound to that user from the differentiated control rule base. These entries are pre-categorized and stored according to user groups and learning stages; for example, a sixth-grade elementary school user might have specific restriction logic for focused training periods.
[0079] Step S430: Obtain the timestamp data of the current system running time, compare the timestamp data with the time period control logic entry, and output the time period compliance instruction if the timestamp data is within the allowed access time period.
[0080] The final output of the time-period compliance instruction is derived using the following formula: (17) In formula (17), This indicates a time-period compliance instruction. It is only valid when the time period is compliant; otherwise, it is 0. This represents a predefined compliance instruction value, such as the instruction code for "Allow access". The function is an indicator function, which takes the value 1 if the timestamp data of the current system running time is within the allowed access time period, and takes the value 0 otherwise. The entire formula is used to output compliant instructions only when the time period is compliant. The control logic of formula (17) is an instruction generation model based on time interval verification. The core is to determine whether to output compliant instructions by judging whether the current time is within the allowed access time period.
[0081] After obtaining the timestamp data of the current system runtime, the system directly compares it with the loaded time-period control logic entries. Assuming the current timestamp is 16:35 on February 6, 2026, and the user's time-period control logic entry defines 16:00 to 18:00 daily as the permitted access period for in-depth training on math application problems, the comparison result determines that the timestamp is within the allowed range, and the system outputs a time-period compliance instruction. This time-period compliance instruction serves as a clear execution signal, instructing subsequent modules to continue allowing access to relevant learning resources.
[0082] Step S440: Generate a temporary key based on the time period compliance instruction and the user's unique index key and timestamp data.
[0083] The following formula is used to generate a temporary key: (18) In formula (18), This refers to a temporary key, which is a key used for temporary sessions or authorization verification. This represents a hash function, such as SHA-256, used to compress input data into a fixed-length key. This indicates a time-period compliance instruction, which includes the compliance rules or identifiers for the current time period. This represents a user's unique index key, used to uniquely identify the user. This represents timestamp data, ensuring that each generated temporary key has a valid time limit. This indicates a concatenation operation, which concatenates multiple input fields into a single string in sequence. The control logic of formula (18) is a hash-derived key generation model. The core of this model is to concatenate the time period compliance instruction, the user's unique index key, and the timestamp, and then generate a temporary key through a hash function for subsequent secure communication or authorization verification.
[0084] Based on the time-period compliance instructions, the system further combines the user's unique index key with the current timestamp data to generate a temporary key. This temporary key has an expiration date, typically linked to the remaining allowed time period. For example, if the remaining time period is 25 minutes, the key's validity period is set to 25 minutes plus a buffer time. A dynamic salt value for the timestamp is incorporated during the generation process to prevent key reuse or forgery. In one embodiment, if a user authenticates at 17:10 and the time period has 50 minutes remaining, the temporary key will carry an encrypted fragment of the user's index key and a timestamp offset, ensuring that the key can only be recognized and used by learning application modules within the specified time period. It should be noted that the temporary key generated through the above process is not only used for immediate access authorization but also serves as a trust anchor for subsequent device status monitoring. For example, when a learning application attempts to access restricted resources, it must present this key for verification, thereby preventing unauthorized use of entertainment functions. This mechanism, based on authentication, time period comparison, and temporary key link, enables control rules to be activated in real time with each user interaction. This ensures the strictness of the learning period while enhancing security and flexibility through dynamic key generation, ultimately effectively supporting the precise implementation of differentiated time period control.
[0085] Furthermore, in the student internet access time management method based on an encrypted network provided in this embodiment, step S500 includes: Step S510: Receive the temporary key output by the key generation mechanism, and use the temporary key to verify the protocol handshake data to build a secure communication link.
[0086] The key material for constructing a secure communication link is constructed using the following formula: (19) In formula (19), Key materials representing secure communication links, used to encrypt subsequent communication data. This represents a temporary key, generated from a time-compliant instruction, a user-unique index key, and a timestamp. This indicates that the shared key exchanged between the two parties through Diffie-Hellman is the result of negotiation during the protocol handshake phase. The formula (19) represents the XOR operation, which mixes two keys bit by bit to generate a new key material. This formula represents the process of combining the temporary key with the handshake negotiation result to generate the communication link key. The control logic of formula (19) is a two-factor key mixing model. The core is to perform an XOR operation on the temporary key and the shared key obtained by exchanging Diffie-Hellman (DH) to generate the final secure communication link key material, so as to ensure the security and timeliness of communication.
[0087] After the key generation mechanism generates the temporary key, the system immediately distributes it to the user's mobile learning application. The temporary key uses symmetric encryption, is typically 256 bits long, and embeds a fragment of the user's index key and a valid time stamp. Before initiating communication, the receiving application first uses this temporary key to encrypt and sign the protocol handshake packet. Upon receiving the handshake data, the server uses the same temporary key to decrypt and verify the signature. If the verification passes, the identities of both parties are confirmed, and an encrypted communication link is established. This encrypted communication link uses the TLS extension protocol to achieve end-to-end encrypted transmission, ensuring that subsequent data interactions are not intercepted or tampered with.
[0088] The key generation mechanism is the core encryption support mechanism in the multi-stage user adaptation system that ensures secure data interaction between users and the server. Its core function is to automatically generate a unique, time-sensitive, and secure temporary symmetric key after the user completes unified identity authentication. This key is then securely distributed to the user's mobile learning application and supports the establishment and maintenance of subsequent encrypted communication links. This ensures end-to-end encryption of protocol interactions and data transmission between the user and the server, preventing data interception, tampering, or forgery, and providing end-to-end security for system data interaction. The temporary key is designed using symmetric encryption. Considering system security requirements and adaptability to educational scenarios, the following core characteristics and generation rules are defined to ensure key security and traceability.
[0089] Step S520: Load the path mapping table based on the secure communication link, and unlock the compliant path according to the path mapping table.
[0090] The compliance path is derived using the following formula: (20) In formula (20), The compliant path represents the set of network resource paths that are currently allowed to be accessed. This function unlocks compliant paths based on a path mapping table, extracting compliant paths from the table according to the current compliance status and user identity. The path mapping table stores the correspondence between all network resource paths and compliance rules. The control logic of formula (20) is an access control model based on the path mapping table. The core is to extract the network paths that are allowed to be accessed during the current compliance period from the path mapping table through the unlock function.
[0091] Path mapping table This can be derived from the following formula: (twenty one) In formula (21), A secure communication link is a reliable communication channel that has been encrypted with key materials. The function represents loading the path mapping table based on the secure communication link, which obtains and parses the path mapping table through the secure communication link. The control logic of formula (21) is a secure link-driven data loading model. The core is to securely load the path mapping table from the backend through the established secure communication link to ensure that the data is not tampered with or stolen during transmission.
[0092] After a secure communication link is successfully established, the system retrieves the set of resource access paths bound to the current user from a pre-configured path mapping table. This path mapping table stores multiple path rules using the user's unique index key as the value; for example, it includes educational path prefixes such as " / math / exercise / primary6" and " / chinese / reading / comprehension" for sixth-grade users. The system filters out non-compliant paths based on the path mapping table, granting access only to these educational paths, thereby unlocking the set of compliant paths.
[0093] Step S530: Listen for resource access requests transmitted via compliant paths, and parse the resource access requests to obtain a list of target resources and access restrictions.
[0094] The target resource list is derived using the following formula: (twenty two) In formula (22), This represents the target resource list, which is a collection of all target resources in this request. Indicates the first The requested target resource, such as online resources like educational videos and courseware documents. This indicates the total number of target resources, i.e., the number of resources included in this request. It represents the set of all possible resources, which is the complete set of accessible resources in the system. The control logic of formula (22) is a structured resource request parsing model. Its core is to extract all requested target resources from the resource access requests transmitted through the compliant path and organize them into a clear list.
[0095] Access restrictions are derived using the following formula: (twenty three) In formula (23), These indicate access restrictions and are the core basis for subsequent resource access verification. This indicates the set of allowed operation types, such as "read-only", "download", "upload", etc. This indicates time constraints, such as "accessible only on weekends" or "open daily from 19:00 to 21:00". This indicates user access restrictions, such as "accessible only to junior high school students" or "exclusively for VIP users." This indicates other additional restrictions, such as "the number of daily accesses per IP address is ≤10" or "the device type is a tablet / computer". The control logic of formula (23) is a multi-dimensional access control condition encapsulation model. The core is to integrate the four key conditions of allowed operations, time constraints, user identity and additional restrictions into a structured set of access restriction conditions.
[0096] The system begins continuously listening for resource access requests received via compliant paths. Each request carries a list of target resource identifiers and additional access restrictions. For example, the request header may contain "resource_ids:[MTH-20260206-001, MTH-20260206-002]" and "max_duration:1800", indicating a maximum access time of 30 minutes. The parsing module unpacks the requests, extracting the list of target resources and the restrictions for each resource, such as the maximum dwell time per question or the daily limit for total attempts.
[0097] Step S540: Input the target resource list and access restriction conditions into the resource filtering matrix, extract specific resource entries with the educational resource tag, and allow access requests for only educational resources.
[0098] Access permission decisions are derived using the following formula: (twenty four) In formula (24), This indicates the access permission decision; a value of 1 indicates permission, and 0 indicates denial. Indicates a resource entry. This indicates a specific resource entry with an educational resource tag, which is a predefined, compliant educational resource library of the system. This indicates an indicator function that returns 1 if the condition is met, and 0 otherwise. For resource ownership determination, it indicates that the currently requested resource belongs to the educational resource set. The control logic of formula (24) is a filtering and determination model based on resource tags. The core is to determine whether the requested resource belongs to the educational resource set through an indicator function, thereby deciding whether to allow the access request.
[0099] Specific resource entries with educational resource tags This can be derived from the following formula: (25) In formula (25), This indicates that specific resource entries with the "educational resource" label are the final list of compliant resources that are approved. Indicates a resource entry. This represents the list of target resources derived from parsing the access request. For tag matching conditions, indicating resources The tag is "education". To satisfy access restrictions, it indicates that the resource All access restrictions are met. The logical AND operation requires that two conditions be met simultaneously. The control logic of formula (25) is a dual-condition resource filtering model. Its core is to filter out resource entries from the target resource list that simultaneously meet the conditions of "having an educational resource tag" and "meeting access restriction conditions".
[0100] The parsed resource list and access restrictions are uniformly fed into a resource filtering matrix for processing. The resource filtering matrix is a two-dimensional, structured, reproducible, and scalable multidimensional matching tool. Its core function is to filter the parsed resource list and access restrictions. Essentially, it combines an educational resource metadata tag library with access control rules to achieve an integrated filtering mechanism for resource tag matching and access permission verification. Through a pre-defined matrix structure, element assignment rules, and matching algorithms, it performs dual verification of the compliance of each resource's educational tags and the legality of its access permissions, outputting only the permission signal for resources that meet all requirements. This provides precise resource access control support for multi-stage user adaptation systems. The resource filtering matrix adopts a two-dimensional structured matrix design, consisting of three layers: row dimension, column dimension, and matrix elements. It combines a tag library to achieve multidimensional matching, and its structure is reproducible and scalable. This resource filtering matrix pre-loads the entire educational resource metadata tag library, with each resource labeled with tags such as "edu_subject:mathematics", "edu_grade:sixth grade", and "edu_type:word problem". The resource filtering matrix employs multi-dimensional matching logic, comparing each input resource identifier against its tag set. It only outputs a permission signal if a resource simultaneously meets the educational resource tag requirements and does not violate access restrictions. For example, if a user requests access to two types of resources—math word problems and entertainment games—the resource filtering matrix will match the math word problems, finding they have complete educational tags while the games lack the corresponding tags. Therefore, only the math word problem request is allowed, while the entertainment resource request is directly blocked.
[0101] Preferably, in the student internet access time management method based on an encrypted network provided in this embodiment, step S600 includes: Step S610: Collect real-time data streams transmitted via compliant paths and extract feature fingerprints from the real-time data streams.
[0102] The feature fingerprint is extracted using the following formula: (26) In formula (26), Indicates at time The extracted real-time data stream feature fingerprint is a hash value that uniquely identifies the current data stream. This represents a hash aggregation function, such as SHA-256, used to compress the merged features into a fixed-length fingerprint. This indicates a bit-level fusion operation, which mixes the outputs of multiple extractors bit by bit to generate a fused feature. Indicates the first A compliance extractor is used to extract key features from sub-data streams. Indicates the first A compliance path at all times The received sub-data stream. This represents the total number of compliant paths. The control logic of formula (26) is a hash aggregation model of multi-source data streams. The core is to extract features from the sub-data streams of different paths through multiple compliance extractors, and then generate unique feature fingerprints through bit-level fusion and hash operation, which are used for subsequent anomaly detection and data integrity verification.
[0103] In educational resource access control scenarios, monitoring and processing real-time data streams transmitted via compliant paths is particularly important. The system continuously collects data streams transmitted through compliant paths, such as operation records and resource request logs generated by students when using learning applications. These data streams typically contain information such as timestamps, resource identifiers, and user behavior patterns. The system extracts feature fingerprints from the data streams using specific algorithms, such as converting frequently occurring operation sequences or resource access patterns in the data streams into a set of feature values for subsequent matching and analysis.
[0104] In this embodiment, considering the educational resource access control scenario, for real-time data streams transmitted via compliant paths (such as student operation records, resource request logs, etc., including timestamps, resource identifiers, user behavior patterns, etc.), a combined algorithm of "data preprocessing + multi-dimensional feature extraction + hash normalization" is used to extract feature fingerprints. This ensures the uniqueness, stability, and matchability of the feature fingerprints, as well as their strong reproducibility. Hash normalization (generating feature fingerprints): The SHA-256 hash algorithm is called to perform a hash operation on the normalized feature vector, generating a 256-bit fixed-length hash value, which is the feature fingerprint of the data stream. Fingerprint post-processing: The 256-bit hash value is converted into a 64-bit hexadecimal string (for easy storage and matching) as the final feature fingerprint output, used for subsequent data stream matching and anomaly analysis (such as matching user historical behavior fingerprints and identifying abnormal data streams).
[0105] Step S620: Calculate the matching similarity value based on the feature fingerprint. If the matching similarity value exceeds the threshold, generate a link blocking command.
[0106] The similarity score is calculated using the following formula: (27) In formula (27), This represents the matching similarity score, with a value range of []. [1, 1], the closer the value is to 1, the higher the matching degree. This represents the first feature fingerprint, which is the feature fingerprint vector extracted in real time. The second feature fingerprint is the feature fingerprint vector in the violation behavior feature library. The control logic of formula (27) is a cosine similarity model based on vector dot product. The core is to quantify the matching degree between the real-time extracted feature fingerprint and the fingerprint in the violation behavior feature library by calculating the cosine similarity between the two, which serves as the basis for subsequent link blocking.
[0107] When calculating the similarity score, the system compares the extracted feature fingerprints with a known database of violation features to arrive at a similarity score. Assuming a threshold of 80%, if the feature fingerprint of a data stream matches 85% of the features in the violation database, the system will identify it as a potential violation and generate a link blocking command. This similarity calculation is typically based on a comprehensive evaluation of multi-dimensional features, such as access frequency, resource type, and time distribution, to ensure the accuracy of the judgment.
[0108] Step S630: Execute the link blocking command to disconnect the link and restore the restricted state, and capture the violation data and restricted state parameters to construct a structured behavior record.
[0109] Structured behavior records are derived using the following formula: (28) In formula (28), A structured behavior record is a complete record that includes details of the violation and the outcome of the action. This indicates a build operation used to integrate multi-source data into a structured record. This represents data on violations, including the time of the violation, characteristic fingerprints, and matching similarity. The restricted state parameters include information such as blocking time, restricted path, and recovery conditions. The control logic of formula (28) is an integrated model of violation behavior and state data. The core is to integrate violation behavior data and restricted state parameters into a structured behavior record for subsequent auditing, analysis, and strategy optimization.
[0110] After executing the link blocking command, the system immediately cuts off the current user's access link and restores their status to restricted mode. For example, when it detects a student attempting to access entertainment content during study hours, the system will cut off the link within 0.3 seconds and restrict the user to access only a preset standby page. This rapid response mechanism effectively prevents the continuation of violations while protecting the exclusivity of compliant paths. For example, when capturing violation data and restricted status parameters, the system records specific details of the violation, such as the identifier of the non-compliant resource accessed, the time of the violation, and the user's restricted status parameters at the time, such as 0 minutes of remaining access time. This information is integrated into a structured behavior log for easy subsequent analysis and feedback. For example, if the log shows that a user attempted to access non-educational resources 5 times within 10 minutes, the system will adjust their status to restricted mode and lock their access for 30 minutes.
[0111] Step S640: Store structured behavior records to enable real-time monitoring and blocking feedback of the current data stream.
[0112] The following formula is used to generate the feedback blocking decision: (29) In formula (29), This indicates a blocking feedback decision; 1 indicates triggering blocking, and 0 indicates allowing passage. This indicates the current data stream, which includes information such as real-time feature fingerprints. This represents structured behavior records, which are the stored baseline of violations. This indicates a consistency determination, comparing the current data stream with historical violation records; this formula is used to implement blocking feedback after monitoring. The control logic of formula (29) is a consistency determination model based on behavior records. The core is to determine whether to trigger blocking feedback by comparing the current data stream with the stored structured behavior records.
[0113] After storing structured behavioral records, the system can achieve real-time monitoring and feedback on data flow. For example, administrators can analyze students' behavioral patterns in learning applications through these records to identify potential violations and adjust control strategies accordingly. These records can also serve as data to optimize the feature fingerprint database and similarity threshold settings, thereby improving monitoring accuracy. Ultimately, this real-time monitoring and feedback mechanism effectively maintains a dedicated access environment for educational resources, ensuring focused learning.
[0114] Please see Figure 2This embodiment provides a student internet access time management system based on an encrypted network, used to execute the aforementioned student internet access time management method based on an encrypted network. It includes a multi-dimensional parameter set acquisition module 10, a time-segment management requirement description acquisition module 20, a differentiated management rule generation module 30, a temporary key generation module 40, a target resource list filtering module 50, and a feedback mechanism improvement module 60. The multi-dimensional parameter set acquisition module 10 acquires time schedule data and course planning information corresponding to the user's educational stage through a parameter acquisition module, while also acquiring user identity details, group attributes, and the type of current access device, resulting in a multi-dimensional parameter set containing stage characteristics, time details, and device attributes. The time-segment management requirement description acquisition module 20 inputs the multi-dimensional parameter set into a pre-built multi-stage user adaptation model. The multi-stage user adaptation model parses the time series data according to the learning requirement characteristics of different educational stages to obtain time-segment management requirements matching the current stage and schedule. Please describe the following: Access restriction specifications; a differentiated control rule generation module 30, used to generate differentiated control rules applicable to the current time by executing rule derivation based on the time-period control requirements description and the access control policy generation module; a temporary key generation module 40, used to verify user-initiated authentication requests through a unified identity authentication mechanism, and after successful authentication, to determine whether the current time falls within an allowed access period based on the differentiated control rules; if so, to trigger a key generation mechanism to generate a temporary key; a target resource list filtering module 50, used to establish a secure communication link and unlock compliant paths using the temporary key, while filtering the target resource list according to the access restrictions in the differentiated control rules, allowing only access requests for education-related resources; and a feedback mechanism improvement module 60, used to continuously monitor the data flow in real time according to the differentiated control rules during the communication link maintenance period, blocking the link and restoring the restricted state if rule violations are detected, and adding behavior records to improve the feedback mechanism.
[0115] This invention presents a student internet access time management method based on encrypted networks. It constructs a full-process encrypted network management system encompassing multi-dimensional parameter acquisition, phased adaptive modeling, differentiated rule generation, encrypted authentication access, and real-time monitoring and feedback. Addressing the technical pain points of traditional student internet access management methods, such as poor phase adaptability, simplistic management rules, low authentication security, inaccurate resource filtering, and delayed monitoring and feedback, this invention combines the characteristics of different educational stages with encrypted network technology to achieve intelligent, personalized, and secure management of student internet access time. It achieves multiple beneficial effects in terms of management accuracy, network security, and educational adaptability, as detailed below: 1. Based on multi-dimensional parameters and phased precise adaptation, this method solves the problem of homogeneity in traditional control rules and achieves personalized internet access control. It collects multi-dimensional parameters such as educational stage, time arrangement, course planning, user identity, and access device. Relying on a multi-stage user adaptation model, it analyzes the learning needs characteristics of different educational stages (primary / secondary / university) and generates time-based control requirements descriptions that highly match the student's current stage and learning schedule, breaking away from the rigid "one-size-fits-all" model of traditional control. Differentiated access restriction regulations are formulated for students at different educational stages. For example, primary school focuses on strict control of extracurricular entertainment access, while university focuses on open access to professional resources and guaranteed research time. This ensures that internet access control aligns with the teaching and development needs of each educational stage, achieving an upgrade from "unified control" to "personalized adaptation," and improving the scientific and rational nature of control.
[0116] 2. Dynamically generate differentiated real-time control rules to adapt to the dynamic changes in students' internet access scenarios, improving the flexibility and timeliness of control. This method derives differentiated control rules applicable to the current moment based on the description of time-based control requirements. It can dynamically adjust the allowed access time periods according to students' schedules, free time, holidays, and other time characteristics. At the same time, it distinguishes the control intensity based on the access device attributes (campus terminal / personal device), adapting to the dynamic changes in students' internet access scenarios. Compared with the traditional fixed time period and fixed rule control method, this method realizes dynamic updating of control rules, ensuring compliant access to network resources during students' study hours while also imposing targeted restrictions on non-study hours, thus balancing the dual needs of ensuring study and controlling internet access.
[0117] 3. Integrating unified identity authentication with temporary key encryption mechanisms strengthens network access security and prevents unauthorized access and control circumvention. This method rigorously verifies user authentication requests through a unified identity authentication mechanism, ensuring the uniqueness of internet access control targets and preventing impersonation, account sharing, and other control circumvention behaviors. After successful authentication, a temporary key is generated only during permitted periods. A secure communication link is established using this temporary key, enabling compliant access under an encrypted network. The one-time and time-limited nature of the temporary key effectively avoids the security risks caused by key leakage. Simultaneously, the encrypted communication link prevents control rules from being tampered with and data streams from being hijacked. Compared to traditional unencrypted or fixed-key control methods, this significantly improves the security and reliability of internet access control, ensuring the compliance and security of campus network access.
[0118] 4. Precise Filtering of Target Resources + Unlocking of Compliant Paths: Achieving Dual Constraints of "Time Control + Resource Control" to Enhance the Effectiveness of Control. This method, while unlocking compliant network access paths, precisely filters the list of target resources based on access restrictions in differentiated control rules. It only allows access requests to education-related resources (such as online course platforms, academic databases, and teaching resource websites), blocking access to non-educational resources such as games, entertainment, and inappropriate information at the source. Compared to traditional methods that only control time and ignore resource filtering, this method achieves dual verification of "whether internet access time is compliant" and "whether accessed resources are compliant," forming a comprehensive internet control system. This effectively prevents students from accessing irrelevant resources during permitted time periods, ensuring the educational and positive nature of their online behavior.
[0119] 5. Real-time monitoring of the entire communication link and immediate handling of violations establish a closed-loop management and feedback mechanism to enhance the enforcement of control. This method continuously monitors network data flow in real time while maintaining a secure communication link. Once a violation of control rules is detected (such as accessing non-educational resources or exceeding permitted internet access time), the communication link is immediately blocked and the restricted state is restored. Simultaneously, the violation is recorded in the feedback mechanism. This closed-loop design solves the problem of traditional control methods that prioritize authorization over monitoring, achieving full-process control from "pre-rule formulation - real-time monitoring during the process - post-violation handling." Immediate violation blocking effectively prevents inappropriate internet access behavior, while violation records provide data support for subsequent optimization of control rules and guidance of student internet behavior, creating a continuously optimizing closed loop for control.
[0120] 6. Lightweight control under an encrypted network architecture balances control effectiveness and network access experience, reducing campus network management costs. All control processes in this method are implemented based on an encrypted network. Operations such as temporary key generation, secure link establishment, and data flow monitoring are all automated by the algorithm module, without consuming large amounts of network bandwidth. This ensures smooth network access for compliant students while achieving strict control, without affecting their normal online learning, academic resource searches, and other operations. Furthermore, the fully automated control model replaces traditional manual review and intervention methods, significantly reducing the manpower costs of campus network management and improving the intelligence and efficiency of campus network control.
[0121] 7. Adapting to network access control across multiple devices and scenarios, enhancing the method's scenario coverage and practical applicability. This method incorporates the characteristics of the user's current access device during parameter collection, enabling the formulation of adaptive control policies for different access devices such as campus all-in-one machines, personal computers, and mobile terminals. Furthermore, the control rules can be adapted to different internet access scenarios, including on-campus and off-campus / home environments, overcoming the limitations of traditional control methods that only apply to the campus intranet and single devices. The method is built upon conventional network data collection, authentication, and encryption modules, requiring no large-scale modification of the existing campus network. It can seamlessly integrate with campus smart academic affairs systems and identity authentication systems, offering low modification costs, easy deployment, and strong practical applicability and promotional value.
[0122] 8. Balancing Internet Control and Educational Guidance to Help Students Develop Healthy Internet Habits: The control logic of this method always revolves around the learning needs of each educational stage. It is not simply about "banning internet access," but rather guiding students to access appropriate online resources at appropriate times through scientific time allocation and precise resource filtering. This allows students to gradually develop the understanding that "internet access serves learning" within the context of internet control, helping them develop healthy and self-disciplined internet habits. At the same time, it guarantees students' right to access high-quality educational online resources, achieving an organic combination of "control" and "guidance," which aligns with the needs of cultivating students' online literacy under the framework of quality education.
[0123] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention. Clearly, those skilled in the art can make various alterations and modifications to the invention without departing from its spirit and scope. Thus, if these modifications and modifications of the invention fall within the scope of the claims and their equivalents, the invention is also intended to include these modifications and modifications.
Claims
1. A method for managing student internet access time based on an encrypted network, characterized in that, Includes the following steps: S100: Obtain the time schedule data and course planning information corresponding to the user's current educational stage through the parameter acquisition module. At the same time, collect user identity details, group attributes and the type of currently connected device to obtain a multi-dimensional parameter set containing stage characteristics, time details and device attributes. S200. Input the multi-dimensional parameter set into a pre-built multi-stage user adaptation model. The multi-stage user adaptation model analyzes the time series data according to the learning needs characteristics of different education stages to obtain a time period control requirement description that matches the current stage and schedule, including access restriction specifications. S300. Based on the time period control requirements description, the access control policy generation module performs a rule derivation process to generate differentiated control rules applicable to the current time. S400. Verify the authentication request initiated by the user through the unified identity authentication mechanism. After successful authentication, determine whether the current time belongs to the allowed access period based on the differentiated control rules. If it does, trigger the key generation mechanism to generate a temporary key. S500: Establish a secure communication link and unlock the compliant path using the temporary key. At the same time, filter the target resource list according to the access restriction conditions in the differentiated control rules, and only allow access requests for education-related resources. S600: During the communication link maintenance period, continuously monitor the data flow in real time according to the differentiated control rules. If a violation of the rules is detected, block the link and restore the restricted state, and add behavior records to improve the feedback mechanism.
2. The method for managing student internet access time based on an encrypted network as described in claim 1, characterized in that, Step S100 includes: S110. Obtain the educational stage information corresponding to the user's identity identifier, and extract the course planning outline and semester teaching calendar data based on the educational stage information. S120. Analyze the course planning outline and semester teaching calendar data to generate a time arrangement sequence containing precise start and end times; S130. Combining the device resolution value of the access device with the historical interaction behavior patterns of similar user groups, the time arrangement sequence is adapted to generate stage feature description data. S140. The time schedule sequence, the hardware attribute parameters of the access device, and the stage feature description data are vectorized and aggregated to obtain a multi-dimensional parameter set containing stage features, time details, and device attributes.
3. The method for controlling student internet access time based on an encrypted network as described in claim 1, characterized in that, Step S200 includes: S210. Input the multi-dimensional parameter set into the multi-stage user adaptation model, and the multi-stage user adaptation model parses to obtain the education stage identifier vector; S220. Match the learning demand feature matrix according to the education stage identifier vector, and use the learning demand feature matrix to segment the time series to identify immersive learning periods; S230. Calculate the control intensity coefficient of the immersive learning period based on the device characteristics. If the control intensity coefficient exceeds the limit, generate an access blocking instruction. S240. Obtain the time period control requirement description and access restriction specifications based on the access blocking instruction.
4. The method for controlling student internet access time based on an encrypted network as described in claim 1, characterized in that, Step S300 includes: S310. Extract the set of basic constraints according to the time period control requirements description and access restriction specifications, and obtain a snapshot of the device status at the current moment containing the application running list; S320. The current device state snapshot is compared with the set of basic constraints to identify state violations; S330. Calculate a dynamic adjustment factor based on the status violation item, and use the dynamic adjustment factor to correct the preset permission mapping table; S340. Perform logical verification on the revised permission mapping table and generate differentiated control rules applicable to the current moment.
5. The method for controlling student internet access time based on an encrypted network as described in claim 1, characterized in that, Step S400 includes: S410. Receive an authentication request data packet containing user identity credentials, wherein the authentication request data packet is verified by a unified identity authentication mechanism to generate an authentication pass status identifier; S420. Extract the user's unique index key based on the authentication status identifier, and load the time period control logic entry from the differentiated control rules using the user's unique index key; S430. Obtain the timestamp data of the current system running time, compare the timestamp data with the time period control logic entry, and if the timestamp data is within the allowed access time period, output the time period compliance instruction. S440. Generate a temporary key based on the time period compliance instruction, the user's unique index key, and the timestamp data.
6. The method for controlling student internet access time based on an encrypted network as described in claim 1, characterized in that, Step S500 includes: S510. Receive a temporary key output by the key generation mechanism, and use the temporary key to verify the protocol handshake data to build a secure communication link; S520. Load the path mapping table based on the secure communication link, and unlock the compliant path according to the path mapping table; S530. Listen for resource access requests transmitted via the compliant path, and parse the resource access requests to obtain a list of target resources and access restriction conditions; S540. Input the target resource list and the access restriction conditions into the resource filtering matrix, extract specific resource entries with the education resource tag, so as to allow access requests for only education-related resources.
7. The method for controlling student internet access time based on an encrypted network as described in claim 1, characterized in that, Step S600 includes: S610. Collect real-time data streams transmitted via compliant paths and extract feature fingerprints from the real-time data streams; The feature fingerprint is extracted using the following formula: ; in, Indicates at time Extracted real-time data stream feature fingerprints, This represents a hash aggregation function. This indicates a bit-level fusion operation. Indicates the first A compliant extractor, Indicates the first A compliance path at all times Received sub-data stream, Indicates the total number of compliant paths; S620. Calculate the matching similarity value based on the feature fingerprint. If the matching similarity value exceeds the threshold, generate a link blocking command. S630. Execute the link blocking command to disconnect the link and restore the restricted state, and capture the violation data and restricted state parameters to construct a structured behavior record; S640. Store the structured behavior record to enable real-time monitoring and blocking feedback of the current data stream.
8. The student internet access time management method based on an encrypted network as described in claim 7, characterized in that, In step S630, the structured behavior record is obtained using the following formula: ; in, Represents structured behavior records. Indicates a build operation. Data indicating violations This represents the constrained state parameter.
9. The student internet access time management method based on an encrypted network as described in claim 8, characterized in that, In step S640, the blocking feedback decision is generated using the following formula: ; in, This indicates that feedback decision-making is blocked. Indicates the current data stream. This indicates a consistency determination; 1 indicates blocking, and 0 indicates passing.
10. A student internet access time management system based on an encrypted network, used to execute the student internet access time management method based on an encrypted network as described in any one of claims 1 to 9, characterized in that, include: The multidimensional parameter set acquisition module (10) is used to acquire the time arrangement data and course planning information corresponding to the user's educational stage through the parameter acquisition module, and at the same time collect user identity details, group attributes and current access device types to obtain a multidimensional parameter set containing stage characteristics, time details and device attributes. The time period control requirement description acquisition module (20) is used to input the multi-dimensional parameter set into the pre-built multi-stage user adaptation model. The multi-stage user adaptation model parses the time series data according to the learning requirement characteristics of different education stages to obtain a time period control requirement description that matches the current stage and arrangement, including access restriction specifications. The differentiated control rule generation module (30) is used to generate differentiated control rules applicable to the current time by performing the rule derivation process according to the time period control requirement description and the access control policy generation module. The temporary key generation module (40) is used to verify the authentication request initiated by the user through the unified identity authentication mechanism. After the authentication is successful, it determines whether the current time belongs to the allowed access period in combination with the differentiated control rules. If it does, the key generation mechanism is triggered to generate a temporary key. The target resource list filtering module (50) is used to establish a secure communication link and unlock the compliant path using the temporary key, and at the same time filter the target resource list according to the access restriction conditions in the differentiated control rules, allowing only access requests for education-related resources; The feedback mechanism enhancement module (60) is used to continuously monitor the data flow in real time according to the differentiated control rules during the communication link maintenance. If a violation of the rules is detected, the link is blocked and the restricted state is restored. Behavior records are added to enhance the feedback mechanism.