A multi-role hierarchical permission teacher achievement intelligent management system and method

CN122550115APending Publication Date: 2026-08-11山西工学院
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-01
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0010]本发明提供一种多角色分级权限的师生成果智能管理系统,是一种角色权限分级、成果分类标准化、审核流程可配置、文档安全可控、查询统计智能化的师生科研成果管理系统,可以解决背景技术架构固化、功能扩展性不足、存在权限划分粗放、审核流程固定不可配置、成果类型覆盖不全、多角色差异化管控缺失等技术缺陷

Benefits of technology

1.权限严格隔离,数据高度安全采用五类角色+三级权限+数据范围的三层控制,学生、教师、教学管理员、科研管理员和超级管理员的权限边界清晰,从源头防止越权查看、误修改和数据泄露,满足校园数据安全与隐私保护要求。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122550115A_ABST
    Figure CN122550115A_ABST
Patent Text Reader

Abstract

This invention relates to the field of information technology, specifically to an intelligent management system and method for faculty and student research projects with multi-role hierarchical access control. The intelligent management system includes a unified identity authentication and access control module, a faculty and student information management module, a research project classification management module, a hierarchical review process module, a document security management module, a combined query and statistical report module, and a system operation and maintenance and message center module. This invention provides a system with hierarchical access control, standardized research project classification, configurable review processes, controllable document security, and intelligent query and statistics capabilities. It achieves digital, automated, and secure management of the entire lifecycle of research projects, from input, submission, review, archiving, querying, statistics, to export, comprehensively improving the efficiency, data quality, and security level of research project management in universities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information technology, specifically to an intelligent management system and method for teacher and student achievements with multi-role hierarchical permissions. Background Technology

[0002] With the continuous high-quality development of higher education in my country, the vitality of scientific research and innovation in universities has been constantly improving. The quantity of research achievements, teaching achievements, competition results, and intellectual property achievements produced by teachers and students has shown explosive growth, and the types of achievements have become increasingly diverse. At present, universities widely adopt two types of achievement management models: one is a semi-manual offline management model that combines Excel summarization with manual review, and the other is a single-function online scientific research management system.

[0003] Currently, most universities use a semi-manual approach to manage research results, which involves offline submission, paper-based processing, Excel summarization, and manual review. Although some universities have introduced online research management systems, these systems suffer from limitations such as limited functionality, poor scalability, ambiguous permissions, and rigid review processes. These deficiencies fail to meet the requirements for standardized, refined, and intelligent management of university research results, and are manifested in the following five aspects.

[0004] Inconsistent data entry practices make it difficult to guarantee data quality. Under the traditional model, the lack of standardized fields and format constraints across different types of deliverables leads to issues such as missing information, incorrect fields, inconsistent formatting, and non-standard attachment naming when students and faculty submit their data. Reviewers must spend significant time verifying information, correcting formats, and supplementing materials, severely reducing management efficiency. Furthermore, the lack of standardized rules for attachment uploading results in frequent issues such as disorganized file formats, exceeding size limits, duplicate uploads, and loss or damage, failing to meet the requirements for long-term archiving and verification.

[0005] The blurred boundaries of access permissions and the lack of precise control result in significant data security and privacy risks. Traditional systems or spreadsheet-based management models cannot achieve fine-grained access control, and the data boundaries between students, regular teachers, research administrators, teaching administrators, and super administrators are unclear. Students may unauthorizedly view others' work, teachers may accidentally modify data that is not their own, and administrators have excessive privileges with a lack of operational traceability, which can easily lead to data leaks, accidental deletions, tampering, and other security problems, failing to meet campus data security management standards.

[0006] The review process lacks flexibility, transparency, and efficiency. Current review processes largely rely on fixed offline procedures, with review milestones that are neither configurable nor adjustable. This fails to adapt to the differentiated review rules applicable to different types of outputs, departments, and management requirements. The review process depends on manual notifications and offline delivery, with no real-time progress tracking and no traceability of review comments. This easily leads to backlogs, unprocessed deadlines, and lost materials, severely impacting core functions such as faculty and student title evaluation, awards and honors, and academic credit recognition.

[0007] The system suffers from weak query and statistical capabilities, hindering its ability to support management decisions. Traditional methods rely on manual data aggregation, resulting in limited statistical dimensions, error-prone calculations, and slow report generation. They also fail to quickly achieve multi-dimensional statistical combinations by department, year, achievement level, and achievement type. Research and teaching management departments require significant manpower for data processing when conducting discipline evaluations, performance assessments, and data reporting, and the accuracy and timeliness of the data cannot be guaranteed, making it difficult to support scientific management decisions.

[0008] Document management lacks standards, making long-term archiving and traceability difficult. Documents such as attachments, supporting materials, and review records are stored in a scattered manner without unified naming rules, unique identifiers, or access control, making them prone to problems such as file overwriting, loss, and leakage. At the same time, there is a lack of operation logs and change records, making it impossible to identify the responsible party and trace the operation process when problems occur, which does not meet the requirements of record management and auditing.

[0009] Existing online research management systems in some universities only support the management of a limited number of output types, such as papers and projects, and cannot cover all categories of output from faculty and students; they cannot implement hierarchical management of teaching and research outputs; they cannot support dynamic review process configuration and intelligent message reminders; and they cannot provide visual statistical analysis and flexible filtering and export functions. Therefore, they fail to meet the needs of universities for "one-stop, full-cycle, refined, and intelligent" output management. Summary of the Invention

[0010] This invention provides an intelligent management system for faculty and student research achievements with multi-role hierarchical permissions. It is a management system for faculty and student research achievements that features hierarchical role permissions, standardized achievement classification, configurable review processes, controllable document security, and intelligent query and statistics. It addresses technical shortcomings such as a rigid technical architecture, insufficient functional scalability, coarse permission division, fixed and unconfigurable review processes, incomplete coverage of achievement types, and lack of differentiated management across multiple roles. Existing systems only support management of a limited number of achievement types, such as papers and projects, failing to cover all categories of faculty and student achievements; they lack differentiated input templates for both faculty and students, resulting in poor separation of permissions between teaching and research achievements; they cannot support dynamic review process configuration and intelligent message reminders; and they cannot provide visual statistical analysis and flexible filtering and export. This invention enables digital, automated, and secure management of the entire lifecycle of achievements, from input, submission, review, archiving, querying, statistics to export, comprehensively improving the efficiency, data quality, and data security level of university achievement management. This invention provides the following technical solution: A multi-role, hierarchical access control system for teacher and student achievements includes: The unified identity authentication and permission hierarchy module is used to set up five roles: student, teacher, teaching administrator, research administrator, and super administrator. It employs a three-tiered permission system to achieve access isolation and operation control, specifically using a "role-permission group-functional permission" three-tiered permission system to build a fine-grained access control mechanism. The teacher and student information management module enables unified maintenance, self-service modification, and batch maintenance by administrators of basic teacher and student information, ensuring the accuracy and consistency of basic data. The output classification management module configures standardized output templates for four categories of student outputs and nine categories of teacher outputs. Each standardized output template has preset standardized field validation, format regular expression validation, attachment format constraints, word limits, and standardized drop-down options, enabling standardized entry of all types of outputs. It supports automatic saving, editing, submission, and deletion of drafts throughout the entire process, preventing data loss. The hierarchical review process module enables configurable, traceable, and reminder-enabled multi-level automated review, solving the problems of inefficiency and opaque progress in offline reviews. The document security management module ensures unified, secure, and standardized storage of output attachments, addressing issues of disorganized, easily lost, and easily leaked files. The combined query and statistical report module provides field querying, visual statistical analysis, and custom export capabilities to meet the needs of assessment, evaluation, and reporting. The system operation and maintenance and message center module ensures system stability and supports custom filtering and configuration, auditing, and notification of visual reports. The unified identity authentication and permission hierarchy module categorizes roles into five types: 1. Student Users: Can only manage their own four types of outputs; cannot view others' data or review it. 2. Teacher Users: Can manage their own nine types of outputs and review the outputs of students they supervise; cannot view irrelevant data. 3. Teaching Administrators: Responsible for reviewing and statistically analyzing teaching-related outputs; cannot manage research data. 4. Research Administrators: Responsible for reviewing, grading, and statistically analyzing research outputs across the university; cannot manage teaching data. 5. Super Administrators: Responsible for system configuration, user management, permission allocation, data monitoring, and operation and maintenance; possesses the highest configuration permissions. The core functions of the unified identity authentication and access control module are as follows: 1. Account / Password Login: Supports login using unique student ID / employee ID identifiers; passwords are stored using asymmetric RSA encryption. 2. Security Policy: Locks the account after consecutive incorrect password attempts to prevent brute-force attacks. 3. Account Status Management: Supports enabling and disabling automatic notifications and logging of status changes. 4. Permission Assignment: Supports permission assignment, adjustment, and revocation for individual and batch users, with full traceability. 5. Data Permission Isolation: Students can only view their own data; teachers can view their own data and the data of the students they supervise; administrators view data according to their assigned areas; super administrators can view all data.The functions of the student and faculty information management module are as follows: 1. Student Information Management: Maintains fields including student ID, name, gender, grade, department, major, email, avatar, academic year, and contact information. Students can independently modify non-core information, while administrators can modify core information (major, class, student status, etc.). After modification, a notification is automatically sent and a change log is recorded. 2. Faculty Information Management: Maintains fields including employee ID, name, gender, title, department, email, avatar, and contact information. Faculty can independently modify information. 3. Data Synchronization Mechanism: Supports integration with the campus unified identity data, enabling automatic synchronization of basic information, reducing duplicate entry, and ensuring data consistency. The review process rules of the tiered review process module are as follows: 1. Default process for student achievements: Submission - Instructor review. 2. Default process for faculty achievements: Submission to the Research Office - Review by the Research Office or Academic Affairs Office. 3. Super administrators can manually adjust the review status. The review operations of the tiered review process module are as follows: 1. Supports both approval and rejection operations. 2. Review comments must be filled out and automatically saved. 3. Automatic status progression: Pending submission - Under review - Approved / Rejected. 4. After rejection, modifications and resubmission are possible, and the review process will restart. The tiered review process module's message reminders are as follows: 1. An "pending review" message is automatically pushed to the reviewer after submission. 2. The result is automatically pushed to the submitter after review completion. 3. Automatic reminders for unreviewed items exceeding the time limit improve processing efficiency. The tiered review process module's review traceability is as follows: All review records are permanently saved, including reviewer's review time, review nodes, review comments, and review results, thus supporting audit traceability. The core rules of the document security management module are as follows: 1. Main attachments are in file format to ensure compliance and long-term archiving. 2. Ordinary attachments have size requirements; exceeding these limits results in automatic blocking. 3. Unified storage paths and automatic categorization and archiving in the backend. The functions of the document security management module are as follows: 1. Controlled download permissions: Only the user, instructor, and corresponding administrator can download, preventing unauthorized access. 2. Operation log: Records every preview, download, deletion, and upload action, allowing for traceability. 3. Supports batch uploading, deletion, and replacement of attachments. The combined query and statistical report module offers the following combined queries: 1. Supports combined searches by achievement type, time range, level, department, major, review status, and keywords. 2. Linked conditions: Selecting a patent automatically displays the patent type and authorization status; selecting a paper automatically displays the journal category and search type. 3. Allows for free combination of fuzzy search, precise search, and range search. 4. Returns data according to permissions, ensuring no overstepping of authority or data disclosure. The combined query and statistical report module provides the following statistical report information: 1. Statistical dimensions: Statistics by achievement type, year, department, individual, level, and review status. 2. Chart types: Pie chart (percentage), bar chart (quantity comparison), and line chart (trend). 3. Automatically generates individual reports, research statistical reports, and teaching summary reports. The combined query and statistical report module's export function includes: 1. Supports exporting to Excel format.2. Customizable export fields allow users to select desired columns for export. 3. Exported files are automatically named and timestamped for easy archiving. The System Operation and Message Center module supports dynamic configuration of competition levels, paper categories, journal directories, project levels, review time limits, etc., adapting to policy updates without code modification. The System Operation and Message Center module's system monitoring and log auditing are as follows: 1. Monitoring CPU, memory, disk, online users, and the number of pending reviews. 2. Operation logs: including login, data entry, modification, deletion, review, export, and permission changes. 3. Data change logs: recording content before and after modifications, auditable and traceable. 4. Logs are permanently stored, meeting compliance requirements. The System Operation and Message Center module's message task center includes the following functions: 1. Task reminders: including pending review and rejected tasks. 2. System notifications: including announcements, policy updates, and account status changes. 3. Support for system homepage notifications, ensuring important messages are not missed.

[0011] As a further aspect of this invention: students' four types of achievements include competitions, patents, papers, and software copyrights; teachers' nine types of achievements include academic papers, monographs, software copyrights, textbooks, research projects, patents, award-winning achievements, student competition guidance, and achievement transformation.

[0012] A method for intelligent management of teacher and student work with multi-role hierarchical access control, employing the aforementioned intelligent management system for teacher and student work with multi-role hierarchical access control, includes the following steps: 1. User Login and Permission Loading: Users log in using their student ID / employee ID. The system verifies the user's identity, password, and verification code. After successful authentication, menu permissions, data permissions, and button permissions are loaded according to the user's role, and the corresponding role's interface is displayed.

[0013] 2. Standardized Input of Results: Students / teachers enter the corresponding results input page and fill in the information according to the standardized template provided by the system; format verification, mandatory field verification, and word count verification are performed in real time; the results can be saved as a draft for further editing; after confirming that there are no errors, the results are submitted for review, and attachments are uploaded at the same time.

[0014] 3. Tiered review and automatic workflow: After submission, the application enters the preset review process, and the corresponding reviewer is automatically pushed a task assignment message; the reviewer can view the results and attachments online, perform the pass / reject operation, and fill in the comments; the review results are synchronized in real time and automatically notified to the submitter.

[0015] 4. Archive and Query Statistics of Results: Approved results are automatically entered into the official archive, supporting full-text search and field filtering. Administrators can generate statistical charts by department, year and type to view the distribution, growth trend and level composition of results; one-click export of reports is supported for assessment and reporting.

[0016] 5. System Operation and Security Management: The super administrator configures the data dictionary, approval process, file size limit, and notification template; automatically records all operation logs, login logs, and data change logs; automatically locks accounts and alerts the administrator upon detecting abnormal behavior; and regularly backs up data automatically to ensure security.

[0017] Compared with the prior art, the beneficial effects of the present invention are: 1. Strictly isolated permissions and highly secure data: A three-tiered control system of five roles, three levels of permissions, and data scope is adopted. The permission boundaries of students, teachers, teaching administrators, research administrators, and super administrators are clearly defined, preventing unauthorized viewing, accidental modification, and data leakage from the source, thus meeting the requirements for campus data security and privacy protection.

[0018] 2. The results are fully standardized, and the data quality is greatly improved. The results cover 13 categories, including 4 categories of students and 9 categories of teachers. Each category of results provides standardized fields, format regular expressions, attachment format constraints, word limits, and drop-down options for standardization checks. This ensures that the information is standardized, complete, and accurate from the data entry stage, and greatly reduces the cost of review and correction.

[0019] 3. Automated review process significantly improves management efficiency. Supports multi-level configurable review processes with automatic workflow, reminders, notifications, and record keeping, and the review progress is visible in real time. This solves the problems of slow, backlogged, lost, and opaque offline reviews, and greatly improves overall review efficiency.

[0020] 4. Intelligent query and statistics support management decision-making through combined queries, visualization charts, and custom export, meeting the needs of all scenarios such as professional title evaluation, performance appraisal, discipline assessment, and data reporting. The statistical results are accurate, real-time, and intuitive, providing data support for scientific research management and teaching management.

[0021] 5. Unified and secure document management, long-term archiving, unified storage, unique ID naming, controlled access and traceable operations, solving the problems of file clutter, loss and leakage, meeting the requirements of university archives management and auditing, and supporting long-term preservation and verification.

[0022] 6. Full-process log traceability, meeting the compliance audit requirements for login, operation, data change, review, export and permission adjustment. The logs are searchable, exportable and traceable, meeting the security compliance and audit requirements of information systems in the education industry. Attached Figure Description

[0023] Figure 1 This is a schematic diagram of the structure of the intelligent management system for teacher and student achievements with multi-role hierarchical permissions in an embodiment of the present invention.

[0024] Figure 2 This is a schematic diagram illustrating the steps of the intelligent management method for teacher and student achievements with multi-role hierarchical permissions in an embodiment of the present invention. Detailed Implementation

[0025] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0026] Existing results management systems generally suffer from common problems such as insufficient access control, poor process flexibility, and significant data security risks. Furthermore, existing solutions have not yet formed an integrated management system that adapts to the entire process and multiple roles. Therefore, developing an intelligent management system for faculty and student research results—one that enables multi-role hierarchical access control, standardized entry of all types of results, configurable multi-level review processes, controllable document security, and full log traceability—is crucial for addressing existing technologies and has become an urgent technical problem to be solved in the informatization construction of universities.

[0027] The innovative aspects of this invention are as follows: 1. Five types of roles (student, teacher, teaching administrator, research administrator and super administrator) and a three-level permission system of "role-permission group-functional permission" are adopted to realize a fine-grained permission isolation mechanism and data access control based on roles. Students can only view their own data, teachers can view their own data and the data of the students they guide, administrators manage data according to their scope of responsibility, and super administrators have global control over data.

[0028] 2. Four standardized templates for student outputs are provided. These templates include built-in mandatory field validation, regular expression format validation, attachment size constraints, attachment format constraints, and automatic saving of drafts, thus achieving full standardization of output entry.

[0029] 3. Supports multi-level configurable review processes. Student work is reviewed by the supervising teacher, and teacher work is reviewed by the teaching / research management department. The process is automatically streamlined, pending tasks are automatically pushed, and results are automatically notified. Review comments are permanently recorded and traceable.

[0030] 4. Attachments to the deliverables are stored securely and uniformly, with download and viewing controlled by permissions. Uploading, previewing, deleting, and modifying are all logged, ensuring manageability and controllability throughout the entire document lifecycle.

[0031] 5. Supports multi-dimensional combined queries, generation of visual statistical tables, and export of custom fields to Excel, which can quickly meet management needs such as professional title evaluation, performance appraisal, discipline assessment, and data reporting.

[0032] 6. The system supports dynamic configuration of the data dictionary, which can adapt to policy changes such as output categories, levels, and review rules without modifying the code. It also has complete operation logs, data change logs, and anomaly locking mechanisms to meet the security and auditing requirements of university information systems.

[0033] The specific implementation of the present invention will be described in detail below with reference to specific embodiments.

[0034] Example 1, see Figures 1-2This is an intelligent management system for student and faculty research output with multi-role hierarchical permissions. The unified identity authentication and permission hierarchy module allows for setting five roles: student, teacher, teaching administrator, research administrator, and super administrator. A three-tiered permission system is used to achieve access isolation and operational control, employing a "role-permission group-functional permission" system to construct a fine-grained access control mechanism. The student and faculty information management module enables unified maintenance, self-service modification, and batch maintenance by administrators of basic student and faculty information, ensuring accurate and consistent basic data. The output classification management module configures standardized output templates for four categories of student outputs and nine categories of teacher outputs. Each standardized output template has preset standardized field validation, format regular expression validation, attachment format constraints, word limits, and standardized drop-down options, enabling standardized entry of all types of outputs. It supports automatic saving, editing, submission, and deletion of drafts throughout the entire process, preventing data loss. The hierarchical review process module enables configurable, traceable, and reminder-based multi-level automated review, solving the problems of inefficiency and opaque progress in offline reviews. The document security management module ensures unified, secure, and standardized storage of output attachments, addressing issues of disorganized, easily lost, and easily leaked files. The combined query and statistical report module provides field querying, visual statistical analysis, and custom export capabilities to meet the needs of assessment, evaluation, and reporting. The system operation and maintenance and message center module ensures system stability and supports custom filtering and configuration, auditing, and notification of visual reports. The unified identity authentication and permission hierarchy module categorizes roles into five types: 1. Student Users: Can only manage their own four types of outputs; cannot view others' data or review it. 2. Teacher Users: Can manage their own nine types of outputs and review the outputs of students they supervise; cannot view irrelevant data. 3. Teaching Administrators: Responsible for reviewing and statistically analyzing teaching-related outputs; cannot manage research data. 4. Research Administrators: Responsible for reviewing, grading, and statistically analyzing research outputs across the university; cannot manage teaching data. 5. Super Administrators: Responsible for system configuration, user management, permission allocation, data monitoring, and operation and maintenance; possesses the highest configuration permissions. The core functions of the unified identity authentication and access control module are as follows: 1. Account / Password Login: Supports login using unique student ID / employee ID identifiers; passwords are stored using asymmetric RSA encryption. 2. Security Policy: Locks the account after consecutive incorrect password attempts to prevent brute-force attacks. 3. Account Status Management: Supports enabling and disabling automatic notifications and logging of status changes. 4. Permission Assignment: Supports permission assignment, adjustment, and revocation for individual and batch users, with full traceability. 5. Data Permission Isolation: Students can only view their own data; teachers can view their own data and the data of the students they supervise; administrators view data according to their assigned areas; super administrators can view all data.The functions of the student and faculty information management module are as follows: 1. Student Information Management: Maintains fields including student ID, name, gender, grade, department, major, email, avatar, academic year, and contact information. Students can independently modify non-core information, while administrators can modify core information (major, class, student status, etc.). After modification, a notification is automatically sent and a change log is recorded. 2. Faculty Information Management: Maintains fields including employee ID, name, gender, title, department, email, avatar, and contact information. Faculty can independently modify information. 3. Data Synchronization Mechanism: Supports integration with the campus unified identity data, enabling automatic synchronization of basic information, reducing duplicate entry, and ensuring data consistency. The review process rules of the tiered review process module are as follows: 1. Default process for student achievements: Submission - Instructor review. 2. Default process for faculty achievements: Submission to the Research Office - Review by the Research Office or Academic Affairs Office. 3. Super administrators can manually adjust the review status. The review operations of the tiered review process module are as follows: 1. Supports both approval and rejection operations. 2. Review comments must be filled out and automatically saved. 3. Automatic status progression: Pending submission - Under review - Approved / Rejected. 4. After rejection, modifications and resubmission are possible, and the review process will restart. The tiered review process module's message reminders are as follows: 1. An "pending review" message is automatically pushed to the reviewer after submission. 2. The result is automatically pushed to the submitter after review completion. 3. Automatic reminders for unreviewed items exceeding the time limit improve processing efficiency. The tiered review process module's review traceability is as follows: All review records are permanently saved, including reviewer's review time, review nodes, review comments, and review results, thus supporting audit traceability. The core rules of the document security management module are as follows: 1. Main attachments are in file format to ensure compliance and long-term archiving. 2. Ordinary attachments have size requirements; exceeding these limits results in automatic blocking. 3. Unified storage paths and automatic categorization and archiving in the backend. The functions of the document security management module are as follows: 1. Controlled download permissions: Only the user, instructor, and corresponding administrator can download, preventing unauthorized access. 2. Operation log: Records every preview, download, deletion, and upload action, allowing for traceability. 3. Supports batch uploading, deletion, and replacement of attachments. The combined query and statistical report module offers the following combined queries: 1. Supports combined searches by achievement type, time range, level, department, major, review status, and keywords. 2. Linked conditions: Selecting a patent automatically displays the patent type and authorization status; selecting a paper automatically displays the journal category and search type. 3. Allows for free combination of fuzzy search, precise search, and range search. 4. Returns data according to permissions, ensuring no overstepping of authority or data disclosure. The combined query and statistical report module provides the following statistical report information: 1. Statistical dimensions: Statistics by achievement type, year, department, individual, level, and review status. 2. Chart types: Pie chart (percentage), bar chart (quantity comparison), and line chart (trend). 3. Automatically generates individual reports, research statistical reports, and teaching summary reports. The combined query and statistical report module's export function includes: 1. Supports exporting to Excel format.2. Customizable export fields allow users to select desired columns for export. 3. Exported files are automatically named and timestamped for easy archiving. The System Operation and Message Center module supports dynamic configuration of competition levels, paper categories, journal directories, project levels, review time limits, etc., adapting to policy updates without code modification. The System Operation and Message Center module's system monitoring and log auditing are as follows: 1. Monitoring CPU, memory, disk, online users, and the number of pending reviews. 2. Operation logs: including login, data entry, modification, deletion, review, export, and permission changes. 3. Data change logs: recording content before and after modifications, auditable and traceable. 4. Logs are permanently stored, meeting compliance requirements. The System Operation and Message Center module's message task center includes the following functions: 1. Task reminders: including pending review and rejected tasks. 2. System notifications: including announcements, policy updates, and account status changes. 3. Support for system homepage notifications, ensuring important messages are not missed. Example

[0035] A multi-role, hierarchical access control system for teacher and student achievements. The operating environment is as follows: 1. Frontend: Vue, JAVA.

[0036] 2. Backend: C++, JAVA. 3. Database: MySQL 8.0 or later relational database. 4. Deployment: JAR package deployment, supports Windows servers. 5. Browser: Latest versions of Chrome, Edge, and Firefox.

[0037] The management method of this multi-role, hierarchical, and intelligent management system for teacher and student achievements is as follows: I. Implementation of Identity Authentication and Access Control Users open the system login page, select their role (student / teacher), and enter their student ID / employee ID, password, and verification code.

[0038] • Verification failed: An error message will be displayed, and consecutive errors will trigger a lockout.

[0039] • Verification successful: The system loads roles, permissions, data scope, and menu list from the database.

[0040] • Student side: Only four modules are displayed: competitions, patents, papers, and software copyrights. Students can only view their own data.

[0041] • Teacher's side: Displays 9 types of achievement modules, allowing teachers to view their own achievements and those of the students they have mentored.

[0042] • Administrator side: Displays the approval, statistics, query and configuration modules.

[0043] Super Administrator: Shows all functions.

[0044] Access control employs triple verification: menu permissions, button permissions, and data permissions. • Menu permissions: Control the visibility of the left-side menu.

[0045] • Button permissions: Control the visibility of the Add, Modify, Delete, Export, and Approve buttons.

[0046] • Data permissions: Control the range of data that can be viewed, and automatically inject filter conditions through SQL aspects.

[0047] II. Implementation of Results Entry and Submission Taking students entering their thesis results as an example: 1. Upon entering the paper entry page, the system loads a standardized form.

[0048] 2. Fill in the paper title, journal name, DOI, publication date, paper category, etc.

[0049] 3. Real-time system verification: Title not empty, DOI format, valid date, and paper category are mandatory.

[0050] 4. Upload the paper attachments; the system will verify the format and size.

[0051] 5. Click "Save Draft" to restore the current data when you exit and re-enter.

[0052] 6. Once you confirm that everything is correct, click "Submit for Review". The data will then enter the review process and the status will change to "Under Review".

[0053] Similarly, when teachers enter their results, the system automatically loads the corresponding 9 types of templates, supporting extended fields such as associated topics, guided students, and conversion amounts.

[0054] Audit Implementation Taking student thesis review as an example: 1. After the student submits the application, the supervising teacher receives a notification that it is pending review.

[0055] 2. Teachers log in to the system and view the paper information, attachments, and author information in the task center.

[0056] 3. Teachers can choose to approve or reject the application and fill in their comments.

[0057] 4. If approved, the process will be automatically pushed to the teaching and research administrator.

[0058] 5. Once the teaching and research administrator approves the application, the status changes to "Approved and Archived".

[0059] 6. If rejected, the status will change to "Rejected," and the student will receive a notification. They can then modify and resubmit all review records, which will be permanently saved in the log.

[0060] IV. Implementation of Query, Statistics and Export 1. The query function allows users to select the type of output, publication date, level, and A1 grade. Clicking the search system will return a list of data that meets the criteria and is within the user's permissions.

[0061] The statistics administrator selects the department and year, and the system automatically generates a bar chart to display the number of papers published by each department.

[0062] Export the fields selected by the user, click export to generate an Excel file, and then download the file.

[0063] V. Operation and Maintenance Implementation 1. Data dictionary configuration: The super administrator can enter the dictionary management, modify the paper category, competition level and journal directory and save. The changes will take effect automatically throughout the system.

[0064] 2. Log Query: Enter the operator's time type to query logs such as login, data entry, approval, and export.

[0065] 3. Push notifications: The system automatically sends reminders for pending review, review results, account notifications, and status notifications.

[0066] VI. Data Security Implementation Passwords are stored encrypted and cannot be decrypted. All permissions for the interface must be verified to prevent unauthorized access.

[0067] Uploaded files are scanned and their formats are verified to prevent malicious files.

[0068] Data is logically deleted but not physically deleted, and can be recovered.

[0069] Regular automatic backups are supported, with one-click recovery.

[0070] This system can be directly deployed in various undergraduate colleges, vocational colleges, and independent colleges. It is suitable for academic affairs offices, research offices, secondary colleges, student affairs departments, and information technology departments to manage the research, teaching, competition, and intellectual property achievements of teachers and students. The system is standardized, modular, configurable, and scalable. It can be quickly launched and used without customized development. It can significantly reduce the manual cost of university achievement management, improve data quality, increase review efficiency, and enhance data security. It has strong practicality and promotional value.

[0071] It should be noted that, in this invention, unless otherwise explicitly specified and limited, the terms "fixed," "set," etc., should be interpreted broadly. For example, they can refer to welded connections, bolted connections, or integral connections; they can refer to mechanical connections or electrical connections; they can refer to direct connections or indirect connections through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components, unless otherwise explicitly limited. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0072] Furthermore, it should be understood that although this specification describes embodiments, not every embodiment contains only one independent technical solution. This narrative style is merely for clarity. Those skilled in the art should consider the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.

Claims

1. A multi-role hierarchical access control system for teacher and student achievements, characterized in that, include: The unified identity authentication and permission hierarchy module is used to set up five roles: student, teacher, teaching administrator, research administrator and super administrator. It adopts a three-level permission system to realize access isolation and operation control. The teacher and student information management module is used to enable unified maintenance, self-service modification, and batch maintenance by administrators of basic teacher and student information. The outcome classification management module is used to configure standardized outcome templates for four categories of student outcomes and nine categories of teacher outcomes. The tiered review process module is used to achieve configurable, traceable, and alert-enabled multi-level automated review. The document security management module is used to ensure the unified, secure, and standardized storage of output attachments; The combined query and statistical report module provides field query, visual statistical analysis, and custom export capabilities; The system operation and maintenance and message center module is used to ensure system stability and support the configuration, auditing and notification of custom filtering and visual reports.

2. The intelligent management system for teacher and student achievements with multi-role hierarchical permissions according to claim 1, characterized in that, Students' achievements fall into four categories: competitions, patents, papers, and software copyrights.

3. The intelligent management system for teacher and student achievements with multi-role hierarchical permissions according to claim 1 or 2, characterized in that, Teachers' nine types of achievements include academic papers, monographs, software copyrights, textbooks, research projects, patents, award-winning achievements, guidance for student competitions, and the commercialization of research results.

4. The intelligent management system for teacher and student achievements with multi-role hierarchical permissions as described in claim 1, characterized in that, The standardized deliverables template includes preset standardized field validation, format regular expression validation, attachment format constraints, word count limits, and drop-down option standardization.

5. A method for intelligent management of teacher and student achievements with multi-role hierarchical permissions, characterized in that, The intelligent management system for teacher and student achievements with multi-role hierarchical permissions as described in any one of claims 1-4 includes the following steps:

1. User login and permission loading; 2. Standardized data entry of results; 3. Automated workflow for tiered review; 4. Results archiving, retrieval, and statistics; 5. System operation and security management.

6. The intelligent management method for teacher and student achievements with multi-role hierarchical permissions according to claim 5, characterized in that, User login and permission loading include the following steps: Users log in using their student ID / employee ID. The system verifies the user's identity, password, and verification code. After successful authentication, menu permissions, data permissions, and button permissions are loaded according to the user's role, and the corresponding role's interface is displayed.

7. The intelligent management method for teacher and student achievements with multi-role hierarchical permissions according to claim 5, characterized in that, The standardized entry of research results includes the following steps: Students / teachers enter the corresponding research result entry page and fill in the information according to the standardized template provided by the system; format verification, mandatory field verification, and word count verification are performed in real time; after confirming that there are no errors, the results are submitted for review, and attachments are uploaded at the same time.

8. The intelligent management method for teacher and student achievements with multi-role hierarchical permissions according to claim 5, characterized in that, The tiered review and automatic workflow includes the following steps: After submission, the system enters the preset review process and automatically pushes the task assignment message to the corresponding reviewer; the reviewer views the deliverables and attachments online, performs the pass / reject operation, and fills in comments; the review results are synchronized in real time and automatically notified to the submitter.

9. The intelligent management method for teacher and student achievements with multi-role hierarchical permissions according to claim 5, characterized in that, The archiving and query statistics of research results include the following steps: approved research results are automatically entered into the official archive. Administrators generate statistical charts by department, year, and type to view the distribution, growth trend, and level composition of research results.

10. The intelligent management method for teacher and student achievements with multi-role hierarchical permissions according to claim 5, characterized in that, System operation and security management includes the following steps: super administrator configures data dictionary, approval process, file size limit and notification template; automatically records all operation logs, login logs and data change logs; automatically locks accounts and alerts administrators when abnormal behavior is detected; and automatically backs up data regularly.