Personnel evaluation full life cycle log auditing and security control method

CN122779718APending Publication Date: 2026-09-18国投人力资源服务有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611272567.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-21
Publication Date
2026-09-18

AI Technical Summary

Technical Problem

[0004]上述前置修正使配置变更产生的评分变化提前转移至共用测评值集合形成阶段,现有双评分配置版本比较难以识别前置修正对配置变更影响的缩减或掩盖

Benefits of technology

[0011] In summary, due to the adoption of the above-mentioned method for auditing and security control of the entire lifecycle log of personnel assessment, the beneficial effects of this invention are as follows: This invention reads the current shared assessment set and correction records based on the personnel assessment task identifier, the assessed personnel identifier, the assessment item identifier, and the execution time. After verifying the continuity of the correction records, it restores the candidate benchmark set in the isolated copy and generates a set version identifier and a result version identifier, which can maintain the traceability relationship between the correction records, the two assessment sets, the two scoring configuration versions, and the corresponding calculation results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122779718A_ABST
    Figure CN122779718A_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of security audit, and relates to a personnel evaluation full life cycle log audit and security control method. A personnel evaluation server reads a current common evaluation set and a correction record according to a personnel evaluation task identifier, a person to be evaluated identifier, an evaluation item identifier and an execution time, checks continuity, forms a candidate reference set and a set version identifier in an isolated copy; a first and a second score configuration version are used to calculate a comprehensive score and generate a result version identifier, a configuration change influence masking risk is identified according to a reference configuration influence amplitude, a current configuration influence amplitude and a configuration influence reduction amount; a security control state field of an affected content is set to be prohibited from being published and referenced, a publishing interface and a reference interface are blocked from outputting and are recalculated; an audit record chain is formed according to a processing order, and a terminal check code is stored in an independent read-only storage area. If a check and review are passed, a result is replaced, otherwise a state is maintained, version tracing and abnormal result output blocking are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of security auditing technology and relates to a method for auditing and controlling the entire lifecycle logs of personnel assessment. Background Technology

[0002] In personnel assessment scenarios such as annual performance reviews, job competitions, and talent selection, organizational personnel information, business performance information, and evaluation information are typically collected and used to form a common set of assessment values ​​according to a preset scoring configuration. When the indicator weights, scoring ranges, methods for handling missing assessment values, or methods for excluding invalid assessment values ​​change, the same common set of assessment values ​​is calculated using both a first and a second scoring configuration version. By comparing changes in the overall score, personnel ranking, and the selected list, it is determined whether the configuration change has a targeted impact on specific assessed personnel.

[0003] However, the shared evaluation value set may undergo negative evaluation value exclusion, missing evaluation value filling, business performance modification, late evaluation value supplementation, duplicate performance re-identification, and old and new evaluation value overlay before its formation. Existing technologies typically only ensure that the first and second scoring configuration versions use the same version of the shared evaluation value set, without further determining whether this shared evaluation value set has been abnormally modified during its formation. When unfavorable evaluation values ​​for a specific evaluated person are excluded in advance, or favorable evaluation values ​​are added in a concentrated manner, both scoring configuration versions are calculated based on the already offset shared evaluation value set, resulting in a narrowing of the score difference between the two calculations. This leads the system to incorrectly judge that the configuration change has not had a targeted impact.

[0004] The aforementioned pre-emptive correction shifts the scoring changes resulting from configuration changes to the shared evaluation value set formation stage in advance. Existing dual-scoring configuration versions struggle to identify whether the pre-emptive correction reduces or masks the impact of configuration changes. Furthermore, correction records, the current shared evaluation set, candidate benchmark set, scoring configuration version, and result content typically lack version identifiers and corresponding audit records throughout the processing. Even when audit records are deleted, inserted, or altered, the system may still erroneously deactivate security controls, allowing abnormal results that failed integrity checks to continue being output through the release or reference interfaces. Summary of the Invention

[0005] The purpose of this invention is to address the problem that pre-processing in personnel assessment servers reduces or masks the impact of configuration changes, and that the correspondence between correction records, assessment sets, scoring configuration versions, result versions, and audit records is easily lost, resulting in abnormal results still being output by the publishing or referencing interface after the audit records are deleted, inserted, or changed. Therefore, this invention proposes a method for auditing and controlling the entire lifecycle logs of personnel assessment.

[0006] A method for auditing and security control of the entire lifecycle logs of personnel assessment, executed by the personnel assessment server, includes the following steps: reading the current shared assessment set and correction records, verifying the continuity of correction records, and forming a candidate benchmark set in an isolated copy;

[0007] The comprehensive score of the two sets is calculated using the first and second scoring configuration versions, and the result version identifier is generated to obtain the impact range of the baseline configuration, the impact range of the current configuration, and the reduction in configuration impact.

[0008] When the impact of the baseline configuration reaches the second configuration impact threshold, the impact of the current configuration is lower than the first configuration impact threshold, and the reduction in configuration impact reaches the masking threshold, the directly affected personnel are identified.

[0009] Set its comprehensive score, personnel ranking and selection list to a security control state that prohibits publication and citation, block the output of the publication interface and citation interface, and recalculate using the candidate benchmark set and the second score configuration version;

[0010] The audit records are connected according to the operation time to form an audit record chain, and the end verification code is stored in an independent read-only storage area; when the integrity verification and review of the audit record chain pass, the result is replaced and the security control status is released; otherwise, the security control status is maintained.

[0011] In summary, due to the adoption of the above-mentioned method for auditing and security control of the entire lifecycle log of personnel assessment, the beneficial effects of this invention are as follows: This invention reads the current shared assessment set and correction records based on the personnel assessment task identifier, the assessed personnel identifier, the assessment item identifier, and the execution time. After verifying the continuity of the correction records, it restores the candidate benchmark set in the isolated copy and generates a set version identifier and a result version identifier, which can maintain the traceability relationship between the correction records, the two assessment sets, the two scoring configuration versions, and the corresponding calculation results.

[0012] This invention identifies directly affected test subjects by jointly judging the impact of baseline configuration, the impact of current configuration, and the reduction in configuration impact. It also identifies associated affected test subjects based on changes in personnel rankings and the selected list, enabling the tracking of the propagation range of configuration change impacts within ranking groups and selection boundaries.

[0013] This invention sets the affected comprehensive score, personnel ranking, and selection list to a security control state that prohibits publication and citation. It uses a candidate benchmark set to generate a recalculated result with a result version identifier. At the same time, it forms an audit record chain for each process and saves the end verification code in an independent read-only storage area. Only after the integrity verification is passed can the execution result be replaced and the security control state be lifted according to the review conclusion, preventing the results that fail the integrity verification from continuing to be output through the publication interface or citation interface. Attached Figure Description

[0014] Figure 1 This is a flowchart illustrating a method for auditing and controlling the entire lifecycle logs of personnel assessment in this invention.

[0015] Figure 2 This is a flowchart illustrating the process of setting up the candidate benchmark set in this invention;

[0016] Figure 3 This is a schematic diagram of the process for determining the reduction amount affected by the configuration in this invention;

[0017] Figure 4 This is a schematic diagram illustrating the determination of the risk of configuration change affecting the masking of risks in this invention. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. The described embodiments are only some embodiments of the present invention, and not all embodiments. Other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are all within the protection scope of the present invention.

[0019] Example 1:

[0020] See Figure 1 - Figure 4 A method for auditing and controlling the entire lifecycle logs of personnel assessment, comprising S1 to S6.

[0021] The entire lifecycle of personnel assessment in this embodiment includes personnel assessment task creation, import of assessed personnel, configuration of assessment items, establishment of the first scoring configuration version, collection and correction of assessment values, release of the second scoring configuration version, calculation of comprehensive scores, generation of personnel rankings, generation of the selected list, security control review, release of results, and task archiving. The personnel assessment server generates corresponding audit records at each lifecycle stage and establishes a correlation between them using the personnel assessment task identifier, the assessed personnel identifier, the assessment item identifier, and the execution time. The assessment set, scoring configuration, and calculation results are established with a one-to-one correspondence using the set version identifier, configuration version identifier, and result version identifier, respectively. Sections S1 to S6 focus on the log auditing and security control process from the correction of assessment values ​​to the re-release of assessment content. Audit records generated in other stages are included in the audit record chain using the same personnel assessment task identifier. The first scoring configuration version is the version used before the scoring configuration change, and the second scoring configuration version is the version released after the scoring configuration change. A ranking group refers to a set of assessed personnel who are ranked uniformly in the same personnel assessment task using the same assessment items, scoring range, sorting method, and number of selected personnel.

[0022] S1. Based on the personnel assessment task identifier, the assessed personnel identifier, the assessment item identifier, and the execution time, read the current shared assessment set and correction record, verify the continuity of the correction record, form a candidate benchmark set in the isolated copy, and generate a set version identifier.

[0023] Considering that the current shared evaluation set may have undergone multiple additions, replacements, exclusions, or overwrites, simply reading the pre-correction evaluation values ​​from the last correction record might result in evaluation values ​​inconsistent with the historical formation process due to missing intermediate records or discontinuities in values. Furthermore, directly performing reverse replacement within the current shared evaluation set could alter the data currently in use. Therefore, this step first verifies the continuity of correction records, then restores the pre-correction evaluation values ​​in a copy isolated from the current shared evaluation set. When records are not continuous, verification is performed using the source system's historical records, original imported files, and database backups, thereby forming a candidate benchmark set that does not overwrite the current content and is independently traceable.

[0024] In one specific embodiment, such as Figure 2 As shown, the formation of the candidate benchmark set includes the following steps: S101, the personnel assessment server reads the current shared assessment set from the assessment value database and the corresponding correction record from the correction record database based on the personnel assessment task identifier. Specifically, each assessment value and correction record is associated with at least the personnel assessment task identifier, the assessed personnel identifier, the assessment item identifier, the assessment period, and the execution time; the correction record also includes the assessment value before correction, the assessment value after correction, and the correction time, so that the correction record can be accurately associated with the corresponding assessment value in the current shared assessment set.

[0025] S102. Group the correction records according to the person being evaluated and the evaluation item, and arrange the correction records in each group in chronological order of correction time to form a correction sequence for the corresponding evaluation item. If there are correction records for different evaluation items for the same person being evaluated, then form a correction sequence for each evaluation item separately to avoid cross-substitution between different evaluation items.

[0026] S103. First, compare the evaluation value of the corresponding evaluation item in the current shared evaluation set with the corrected evaluation value of the last corrected record in the correction sequence. Then, compare the corrected evaluation value of the previous corrected record with the uncorrected evaluation value of the next corrected record in adjacent corrected records one by one. When the current evaluation value is equal to the corrected evaluation value of the last corrected record, and all adjacent corrected records satisfy the condition that the corrected evaluation value of the previous record is equal to the uncorrected evaluation value of the next record, the correction sequence is determined to be continuous.

[0027] S104. For a continuous correction sequence, replace the corresponding post-correction evaluation value with the pre-correction evaluation value in each correction record in order from the end to the beginning of the correction time, until all reverse replacements of the correction sequence are completed, and use the final evaluation value as the pre-correction evaluation value of the corresponding evaluation item for the person being evaluated.

[0028] S105. For discontinuous correction sequences, verification is performed separately for each evaluated person and evaluation item. First, the corresponding evaluation value in the current shared evaluation set is replaced with the pre-correction evaluation value from each correction record, forming multiple candidate evaluation sets for that evaluation item. Then, the evaluation values ​​corresponding to the same evaluated person, the same evaluation item, and the same evaluation period are sequentially searched in the source system's historical records, original imported files, and database backups. When multiple corresponding evaluation values ​​exist from the same source, the evaluation value whose generation time is earlier than the first correction time of that evaluation item and closest to the first correction time is selected as the verification evaluation value.

[0029] Furthermore, the set of candidate assessments whose pre-correction assessment values ​​equal the verification assessment values ​​is used as the candidate content corresponding to that assessment item. The source system history records contain the business formation time and business source identifier. The original import file retains the original content of the assessment values ​​before they entered the personnel assessment server. The database backup retains the assessment values ​​of the personnel assessment server at historical points in time. The above search order is used to prioritize the records that are closer to the original formation stage of the assessment values.

[0030] When a single test subject has multiple discontinuously modified assessment items, all candidate items will only be jointly written into the candidate benchmark set if each assessment item yields a unique candidate item. If any assessment item fails to yield a unique candidate item, the test subject will be marked as unable to form a candidate benchmark set. The test subject's overall score, ranking in their ranking group, and corresponding selection list will be set to a security control status that prohibits publication and citation, and subsequent recalculation for that test subject will be stopped; other ranking groups will continue to execute subsequent steps.

[0031] S106. Write the pre-correction assessment values ​​(after recovery or verification) to a copy isolated from the current shared assessment set, while keeping the uncorrected assessment values ​​unchanged, forming a candidate benchmark set. The personnel assessment server concatenates the personnel assessment task identifier, assessed personnel identifier, assessment item identifier, assessment period, set type, and set generation time in a fixed order to generate the current set version identifier and the candidate set version identifier, respectively. The two sets have the same assessed personnel, assessment items, and assessment period, differing only in the assessment values ​​corresponding to the correction records.

[0032] S2. Using the first and second scoring configuration versions, calculate the comprehensive score of each person being evaluated based on the current shared evaluation set and candidate benchmark set, and generate a result version identifier.

[0033] Considering that the differences in the overall scores are affected not only by the set of evaluation values ​​and the scoring configuration, but also by changes in the personnel involved in the calculation, the range of evaluation items, the number of digits retained in the overall score, and the ranking group, if the four calculations use different calculation bases, it is impossible to accurately determine whether the score differences stem from prior adjustments or configuration changes. Therefore, this step fixes the personnel being evaluated, the evaluation items, the number of digits retained in the overall score, and the ranking group, only changing the set version and the scoring configuration version to generate four overall scores and their result version identifiers.

[0034] In one specific embodiment, the calculation of the comprehensive score includes the following steps: S201, for the same person being evaluated, read each evaluation item in the current shared evaluation set and the corresponding evaluation item in the candidate benchmark set, and verify that the person being evaluated, the evaluation item and the evaluation period in the two sets are consistent; if there is an inconsistency, stop the cross calculation of the person being evaluated, and set the comprehensive score of the person being evaluated, the ranking of the person in the ranking group and the corresponding list of selected persons to a security control state of prohibiting publication and prohibiting citation.

[0035] The first and second scoring configuration versions each include a configuration version identifier, and at least one of the following: indicator weights, scoring ranges, methods for handling missing assessment values, and methods for excluding invalid assessment values. Except for configuration changes between the two scoring configuration versions, the four calculations use the same scoring program version, assessment item range, normalization benchmark, parallel scoring method, number of digits retained in the comprehensive score, and rounding position. Before each calculation, the scoring program reads the corresponding set version identifier and configuration version identifier and writes them to the audit log. Specifically, the personnel assessment server converts assessment values ​​into score values ​​according to the scoring range recorded in the scoring configuration version and performs weighted calculations according to the indicator weights. When assessment values ​​are missing, the missing assessment value handling method recorded in the corresponding scoring configuration version is executed, invalid assessment values ​​are removed from the calculation range according to the corresponding exclusion method, and the remaining indicator weights are normalized.

[0036] S202. Fix the evaluation items, the number of digits retained in the comprehensive score, and the ranking group of the evaluated person. Use the first scoring configuration version to calculate the candidate benchmark set to obtain the candidate first comprehensive score; use the second scoring configuration version to calculate the candidate benchmark set to obtain the candidate second comprehensive score.

[0037] S203. Keeping the above calculation conditions unchanged, the first scoring configuration version is used to calculate the current shared assessment set to obtain the current first comprehensive score; the second scoring configuration version is used to calculate the current shared assessment set to obtain the current second comprehensive score. The personnel assessment server concatenates the personnel assessment task identifier, the assessed personnel identifier, the set version identifier, the configuration version identifier, the comprehensive score, and the calculation time in a fixed order to generate the result version identifier corresponding to each comprehensive score, enabling each result to be able to look up its assessment set and scoring configuration.

[0038] For example, a personnel assessment task includes three assessment items: business performance, organizational evaluation, and job performance capability. The candidate benchmark assessment values ​​are 90, 60, and 80 points, respectively, while the current shared assessment values ​​are 65, 60, and 80 points. Only allowing the business performance assessment value to change between the two sets, while keeping the organizational evaluation and job performance capability assessment values ​​constant, ensures that subsequent changes in the overall score correspond to adjustments in the business performance assessment value, avoiding the difficulty in identifying the source of score changes when multiple assessment items change simultaneously. There is a significant difference between the candidate benchmark assessment value of 90 points for business performance and the organizational evaluation assessment value of 60 points, while the current shared assessment value of 65 points for business performance is close to the organizational evaluation value of 60 points. This allows the same configuration change to result in different score changes across the two sets.

[0039] In the first scoring configuration, the weights for business performance, organizational evaluation, and job performance capability are 0.5, 0.3, and 0.2, respectively. In the second scoring configuration, the corresponding weights are 0.3, 0.5, and 0.2, respectively. Keeping the weight of job performance capability unchanged and only adjusting the weights of business performance and organizational evaluation is to ensure that the configuration change primarily affects the difference in evaluation values ​​between business performance and organizational evaluation, avoiding the weakening of the comparability between the two sets due to simultaneous changes in multiple weights.

[0040] Based on the same evaluation items, the same weight order, and the same number of digits retained in the comprehensive score, the first candidate's comprehensive score is 79 points, the second candidate's comprehensive score is 73 points, the current first comprehensive score is 66.5 points, and the current second comprehensive score is 65.5 points.

[0041] Therefore, the candidate benchmark set shows a score change of 6 points under the two scoring configuration versions, while the current shared evaluation set shows a score change of only 1 point under the two scoring configuration versions. This clearly illustrates that prior adjustments may reduce the score changes that configuration changes can still generate. The above evaluation values, weights, and comprehensive scores are used to illustrate the calculation process corresponding to the two sets and the two scoring configuration versions, and are not intended to limit fixed values ​​in actual personnel evaluation tasks.

[0042] S3. Based on the comprehensive scores corresponding to the candidate benchmark set and the current shared evaluation set, determine the impact range of the benchmark configuration, the impact range of the current configuration, and the reduction in configuration impact, and determine whether the pre-correction masks the impact of the configuration change.

[0043] Comparing only the absolute difference in the overall score between two configuration versions can reflect the magnitude of the configuration change, but it cannot determine whether the preceding correction has an effect in the same direction as the configuration change. If the correction's effect is opposite to the direction of the configuration change, the reduction in the current configuration's impact may come from the cancellation of different effects, rather than the preceding correction prematurely implementing the configuration change's effect. Therefore, this step simultaneously determines the correction change, the baseline configuration change, and the current configuration change, and calculates the reduction in configuration impact using the combined conditions of consistent direction and reduced change magnitude.

[0044] In one specific embodiment, such as Figure 3 As shown, determining the reduction in configuration impact includes the following steps: S301, the absolute difference between the candidate first comprehensive score and the candidate second comprehensive score is taken as the baseline configuration impact magnitude, and the absolute difference between the current first comprehensive score and the current second comprehensive score is taken as the current configuration impact magnitude. The baseline configuration impact magnitude represents the magnitude of score change caused by configuration change after restoring the pre-correction evaluation value, and the current configuration impact magnitude represents the magnitude of configuration change score change that can be observed under the current shared evaluation set.

[0045] S302. Subtract the candidate first comprehensive score from the current first comprehensive score to obtain the correction change; subtract the candidate first comprehensive score from the candidate second comprehensive score to obtain the baseline configuration change; subtract the current first comprehensive score from the current second comprehensive score to obtain the current configuration change. The correction change retains the score rise / fall direction caused by the previous correction, while the baseline configuration change and the current configuration change retain the score rise / fall direction caused by the configuration change.

[0046] S303. When the product of the corrected change and the baseline configuration change is greater than zero, it is determined that the preceding correction and the configuration change have the same direction of action. When the absolute value of the current configuration change is less than the absolute value of the baseline configuration change, it is determined that the configuration change magnitude under the current shared evaluation set is less than the configuration change magnitude under the candidate baseline set. When both conditions are met simultaneously, the absolute value of the baseline configuration change is subtracted from the absolute value of the current configuration change to obtain the configuration impact reduction.

[0047] For ease of explanation, the difference between the candidate second comprehensive score and the candidate first comprehensive score is recorded as the baseline configuration change; the difference between the current second comprehensive score and the current first comprehensive score is recorded as the current configuration change; and the difference between the current first comprehensive score and the candidate first comprehensive score is recorded as the correction change. The reduction in configuration impact is calculated using the following formula: .

[0048] in, This indicates the amount of reduction due to configuration changes; This represents the change in baseline configuration obtained by subtracting the candidate's first comprehensive score from the candidate's second comprehensive score. This represents the change in configuration obtained by subtracting the current first comprehensive score from the current second comprehensive score; This indicates that the absolute value of the value within the absolute value symbol is taken.

[0049] In the aforementioned example, subtracting the candidate first comprehensive score of 79 from the current first comprehensive score of 66.5 results in a correction change of -12.5 points; subtracting the candidate first comprehensive score of 79 from the candidate second comprehensive score of 73 results in a baseline configuration change of -6 points; and subtracting the current first comprehensive score of 66.5 from the current second comprehensive score of 65.5 results in a current configuration change of -1 point. These three values ​​are all calculated from the same set of four comprehensive scores to ensure that the score changes caused by the preceding correction correspond to the configuration changes under the two sets.

[0050] Both the revised change and the baseline configuration change are negative, indicating that both the business performance evaluation value revision and the configuration change lowered the overall score, and their effects are in the same direction. The absolute value of the current configuration change (1 point) is less than the absolute value of the baseline configuration change (6 points), indicating that the observable configuration change after the business performance evaluation value revision has decreased. Therefore, subtracting 1 point from 6 points yields a configuration impact reduction of 5 points.

[0051] Using the same set of four comprehensive scores to continuously determine the correction change, the baseline configuration change, the current configuration change, and the reduction in configuration impact can avoid the lack of correspondence between calculation results caused by selecting different comprehensive scores separately, and avoid misjudging the situation where the opposite direction of action is due to a reduction in score differences as a risk of configuration change impact being masked.

[0052] S304. To avoid the situation where the effects of the same direction and the opposite direction cancel each other out in multiple corrections, and the judgment is made solely based on the amount of change in correction, the correction records corresponding to the evaluated personnel are arranged according to the correction time. The candidate first comprehensive score is used as the initial comprehensive score. The corrected evaluation value in each correction record is used to replace the corresponding pre-correction evaluation value in turn. The comprehensive score after each replacement is calculated using the first score configuration version.

[0053] Subsequently, the overall score after each replacement is subtracted from the overall score before that replacement to obtain the correction contribution for the corresponding correction record. Correction contributions with the same sign as the baseline configuration change are designated as unidirectional correction contributions, while those with opposite signs are designated as inverse correction contributions. When the sum of the absolute values ​​of unidirectional correction contributions is greater than the sum of the absolute values ​​of inverse correction contributions, it is determined that the unidirectional correction contribution dominates all corrections, and it is confirmed that the correction change and the baseline configuration change act in the same direction.

[0054] S305. Determine the first configuration influence threshold, the second configuration influence threshold, and the masking threshold. Specifically, read historical personnel assessment tasks that have the same assessment items, scoring ranges, and ranking group division methods as the current personnel assessment task, and for which no correction records have been made. Calculate the two comprehensive scores of the assessed personnel in each historical personnel assessment task using the first scoring configuration version and the second scoring configuration version, respectively, and arrange them in ascending order of the absolute difference between the two comprehensive scores to form a historical configuration influence sequence.

[0055] The 50th percentile of the historical configuration impact sequence is used as the first configuration impact threshold, and the 90th percentile of the historical configuration impact sequence is used as the second configuration impact threshold. The first configuration impact threshold is used to characterize the magnitude of common configuration changes in historical personnel assessment tasks, and the second configuration impact threshold is used to characterize the magnitude of more significant configuration changes in historical personnel assessment tasks.

[0056] Furthermore, historical personnel assessment tasks that have been verified and confirmed to have the risk of configuration change impact masking are retrieved. The reduction amount of configuration impact for each historical personnel assessment task is calculated, and the 50th percentile of each reduction amount is used as the masking threshold. Historical personnel assessment tasks can be retrieved from the assessment result database and audit record database according to the task identifier. "Verified and confirmed" means that the corresponding task has been manually reviewed and the review conclusion is stored in the audit record database.

[0057] S306. When the baseline configuration impact of the evaluated personnel reaches the second configuration impact threshold, the current configuration impact is lower than the first configuration impact threshold, and the reduction in configuration impact reaches the masking threshold, the evaluated personnel are determined to meet the judgment conditions for the risk of configuration change impact masking.

[0058] like Figure 4As shown, with the current configuration's impact magnitude on the horizontal axis and the baseline configuration's impact magnitude on the vertical axis, the coordinate region is divided into zones A, B, C, and D by the first and second configuration impact thresholds. Zone A represents a situation where the current configuration's impact magnitude is below the first configuration impact threshold and the baseline configuration's impact magnitude reaches the second configuration impact threshold. Zones B, C, and D represent situations where one or both of the aforementioned two configuration impact magnitude conditions are not met. The star-shaped markers in the figure represent example test subjects; those located in Zone A and whose configuration impact reduction reaches the masking threshold are identified as directly affected test subjects. Different colors are used to distinguish the zones; the numerical values ​​and colors in the figure do not limit the actual values ​​of the configuration impact magnitudes and thresholds.

[0059] S4. Based on the ranking and selection list changes of directly affected test subjects in the current shared assessment set and candidate benchmark set, determine the related affected test subjects.

[0060] Personnel rankings and selection lists constitute relative evaluation content within the ranking group. When a candidate's overall score changes, it not only alters their own ranking but may also affect the order of other candidates ranked between their previous and current rankings, and potentially change the inclusion or exclusion of individuals near the selection boundary. If only the overall scores of directly affected candidates are subject to safety controls, the rankings and selection lists of other candidates may still retain the impact of the previous correction propagation. Therefore, this step tracks the propagation range of overall score changes within the ranking group based on the ranking interval.

[0061] In one specific embodiment, determining the affected test subjects includes the following steps: determining the test subjects who meet the criteria of the baseline configuration impact reaching the second configuration impact threshold, the current configuration impact being lower than the first configuration impact threshold, and the configuration impact reduction reaching the masking threshold, as directly affected test subjects.

[0062] Using the second scoring configuration, the current ranking and selection list of directly affected test subjects in their respective ranking groups are calculated based on the current shared assessment set. Using the same second scoring configuration, the ranking and selection list of subjects in the same ranking group are recalculated based on the candidate benchmark set. Both rankings use the same parallel sorting method and the same number of selected subjects to ensure comparability of ranking positions and selection boundaries.

[0063] A ranking interval is formed based on the position of each directly affected participant in the current ranking and the recalculated ranking. The starting point of the ranking interval is the smaller of the two ranking positions, and the ending point is the larger of the two ranking positions. Participants who are within the ranking interval but whose rankings differ in the two rankings are identified as ranking-related participants.

[0064] When there are multiple directly affected test subjects, multiple corresponding ranking intervals are formed. If two ranking intervals overlap or are adjacent, they are merged into a single merged ranking interval. The ranking-related personnel are then identified within the merged ranking interval to avoid the same test subject being identified repeatedly and to cover the continuous ranking propagation range caused by multiple changes in comprehensive scores.

[0065] By comparing the current list of selected participants with the recalculated list of selected participants, those who were changed from not included to included or from included to not included will be identified as participants associated with the list; those who are associated with the ranking and those who are associated with the list will be jointly identified as participants affected by the list; and those who are directly affected and those who are associated with the list will be jointly identified as participants affected by the list.

[0066] For example, a ranking group has 8 participants, with 3 selected. Using 8 participants ensures that the ranking of directly affected participants can include other participants between the two rankings. Setting the number of selected participants to 3 ensures that the boundary of the selected list lies within the ranking interval formed by the two rankings, thus using the same group of participants to simultaneously illustrate changes in both the ranking and the selected list.

[0067] The directly affected person being evaluated is ranked 2nd in the current ranking and 5th in the recalculated ranking. Therefore, the ranking range from 2nd to 5th is formed by taking the smaller ranking position between 2nd and 5th as the starting point and the larger ranking position as the ending point.

[0068] Besides the directly affected participants, other participants within the same ranking range whose rankings differed between the two assessments were also affected by the change in the overall score of the directly affected participants, and were thus identified as ranking-related participants. Since the number of participants was three, the directly affected participant changed from second place in the current list to fifth place in the recalculated ranking. The participant currently ranked fourth was added to the recalculated list, and therefore, this participant was identified as a list-related participant.

[0069] By identifying both those associated with the ranking and those associated with the list as affected participants, we can avoid overlooking the impact of changes in their overall scores on other participants and the final list within the same ranking group when only the directly affected participants are subject to safety controls. The number of participants, the number of finalists, and their rankings mentioned above are for illustrative purposes only and are not intended to limit the actual number of participants in the ranking group or the final list.

[0070] S5. Set the security control status field corresponding to the affected content to prohibit publishing and prohibit referencing, block the output of the publishing interface and the referencing interface, and recalculate using the candidate benchmark set.

[0071] After confirming the risk of configuration changes masking the impact, allowing the current comprehensive score, personnel ranking, and selection list to continue to be published or referenced in subsequent personnel management processes would further spread the effects of the previous corrections. Conversely, directly replacing the original results after recalculation could bypass the audit log chain integrity check. Therefore, this step first sets up security controls prohibiting publication and citation, then generates a recalculated result with a version identifier, and reserves the replacement of the result and the removal of security controls for execution only after integrity verification and review have both passed.

[0072] In one specific embodiment, security control and recalculation include the following steps: The evaluation result database sets security control status fields for the overall score, personnel ranking, and selection list. The security control status fields corresponding to the overall scores of directly affected evaluated personnel and associated affected evaluated personnel are set to "prohibited from publishing" and "prohibited from referencing." Simultaneously, the security control status fields corresponding to the personnel rankings of the ranking groups to which directly affected evaluated personnel belong and the corresponding selection lists are set to "prohibited from publishing" and "prohibited from referencing." The publishing and referencing interfaces read the security control status fields and refuse to output the corresponding content. During the security control period, the original overall score, personnel ranking, selection list, and their result version identifiers are retained without deletion or replacement for subsequent audit comparison.

[0073] Using the candidate benchmark set and the second scoring configuration version, the comprehensive score of each person being evaluated in the ranking group is recalculated, and the personnel ranking is generated in the same sorting method as the original personnel ranking. The selection list is generated with the same number of selections as the original selection list. The candidate set version identifier, the configuration version identifier of the second scoring configuration version, the recalculated content and the calculation time are associated to generate the result version identifier corresponding to the recalculation result.

[0074] The content before recalculation is determined by the current set version identifier, the configuration version identifier of the second scoring configuration version, and the corresponding result version identifier. The content after recalculation is determined by the candidate set version identifier, the configuration version identifier of the second scoring configuration version, and the new result version identifier. The comprehensive score, personnel ranking, and selection list are compared item by item. If any item changes, the security control status of the relevant content of the corresponding evaluated personnel is maintained; if none changes, the relevant content is marked as pending deactivation.

[0075] Keep the overall score and personnel rankings that have changed before and after recalculation under safe control; if there are additions or removals to the selected list before and after recalculation, keep the corresponding selected list as a whole under safe control; do not immediately remove content marked as pending removal, but remove the safe control status after the integrity verification and review of the audit record chain have passed, in order to prevent unverified content from being reused.

[0076] Once the candidate benchmark set completes the continuity verification of the correction records, or, if the records are discontinuous, completes the verification of the source system's historical records, original imported files, or database backups, and after recalculating the results and generating their version identifiers, a personnel assessment review task is generated. Personnel with review permissions read the candidate benchmark set, correction records, recalculated results, and corresponding version identifiers, and submit a review record including the personnel assessment task identifier, reviewer identifier, evaluated personnel identifier, review content, review conclusion, and review time.

[0077] Review records are added to the audit record chain according to the review time. When the audit record chain integrity check passes and the review conclusion is passed, the comprehensive score, personnel ranking, selected list and its result version identifier are recalculated and written to the evaluation result database, replacing the corresponding results and removing the security control status. When the integrity check fails, or the review conclusion is failed or needs to be supplemented, the security control status of the corresponding content is maintained, and the result replacement is not performed. When a review record is added to the audit record chain, the review time is used as the operation time, the reviewer identifier is used as the operator identifier, the review content is used as the input content, and the review conclusion is used as the output content. A checksum is generated according to the same field order and hash operation as other audit records.

[0078] S6. Perform audit record chain integrity verification on collection reading, correction record continuity verification, version identifier generation, configuration impact reduction calculation, affected personnel identification, security control status setting and recalculation.

[0079] Since the basis for replacing and deregulating security control status is derived from correction records, candidate benchmark sets, scoring configuration versions, result versions, and configuration impact reduction, if the corresponding audit record is deleted, inserted, or changed after the security control status is set, the personnel assessment server may improperly deregulate the security control status based on the changed content. Therefore, this step connects the processing steps in execution order and re-verifies before deregulating the security control status, ensuring that the integrity of the audit record chain is directly linked to the control over the publication, citation, and replacement of assessment results.

[0080] In one specific embodiment, the audit record chain integrity verification includes the following steps: for the stages of personnel assessment task creation, personnel import, assessment item configuration, establishment of the first scoring configuration version, assessment value collection, release of the second scoring configuration version, result release and task archiving, the personnel assessment server generates audit records respectively, and uses the verification code of the last audit record of the previous life cycle stage as the verification code of the first audit record of the next stage, so that each stage is continuously connected.

[0081] Audit logs are generated upon completion of the following steps: reading the assessment set and correction records, continuity verification, version identifier generation, calculation of configuration impact reduction, identification of affected assessed personnel, setting of security control status, and recalculation. Each log includes the personnel assessment task identifier, operation time, operator identifier, input content, and output content. The input and output content records the assessed personnel identifier, assessment item identifier, set version identifier, configuration version identifier, result version identifier, and processed data. The operation time is the time when the corresponding processing step is completed and the audit log is generated, and is distinct from the execution time associated with the assessment value or correction record.

[0082] Audit records are sorted in ascending order of operation time; if operation times are the same, they are sorted in ascending order of their sequential audit record numbers. The personnel assessment task identifier, operation time, operator identifier, input content, and output content are encoded in UTF-8 and concatenated sequentially according to their length and content. Empty fields are represented by a length of zero, forming the content to be verified. The personnel assessment task identifier is concatenated with a preset initial checksum, and a 256-bit hash operation is used to generate a first-order pre-checksum. The preset initial checksum is generated and permanently saved when the personnel assessment task is created; the same preset initial checksum is used for the same personnel assessment task.

[0083] For the For each audit record, the checksum of the previous audit record is concatenated with the content to be checked in the current audit record to calculate the checksum of the current audit record. This checksum is then used for the next audit record. The calculation relationship is as follows: .

[0084] in, Indicates the first Verification code for the audit record; This indicates the verification code for the previous audit record; Indicates the first The personnel assessment task identifier corresponding to the audit record; when hour, This indicates that the first pre-check code is obtained by concatenating the personnel assessment task identifier and the preset initial check code in a fixed order and then performing a hash operation with an output length of 256 bits. This indicates a hash operation with an output length of 256 bits; Indicates the first The operation time of the audit record; Indicates the first The operator identification for each audit record; Indicates the first Input content for each audit record; Indicates the first The output content of the audit record; This indicates that the fields are joined according to a fixed field order, field length, and field content. Indicates the sequential number of the audit record, and .

[0085] Specifically, the verification algorithm uses a hash algorithm with an output length of 256 bits. After all audit records are completed, the terminal verification code, along with the corresponding personnel assessment task identifier, the number of audit records, and the generation time, are simultaneously stored in the audit record database and a separate read-only storage area. The separate read-only storage area only provides interfaces for appending and reading terminal verification codes; it does not provide interfaces for modification or deletion. When a review record is added to the audit record chain, a new terminal verification code is generated and appended in the same manner, while retaining both the previous and updated terminal verification codes.

[0086] Before deactivating the security control status of the comprehensive score, personnel ranking, or selection list, or before replacing the corresponding result with a recalculated result, recalculate each checksum according to the same field order, data format, connection method, and verification algorithm. Then, compare the recalculated end checksum value with the saved values ​​in the audit record database and the independent read-only storage area that contain the same personnel assessment task identifier and the number of audit records. If any comparison is inconsistent or the review conclusion is not passed, maintain the security control status and do not perform a replacement; if all comparisons are consistent and the review conclusion is passed, perform result replacement and deactivate the security control status.

[0087] Through the above steps S1 to S6, the personnel assessment server reads the corresponding content based on the personnel assessment task identifier, the assessed personnel identifier, the assessment item identifier, and the execution time. It verifies and corrects the continuity of the records and restores the candidate benchmark set in the isolated copy, maintaining a one-to-one correspondence through the set version identifier, configuration version identifier, and result version identifier. Subsequently, it identifies the risk of configuration change impact masking, determines the scope of propagation, and sets the security control status. Finally, it uses the audit record chain and the end checksum in the independent read-only storage area to control the result replacement and the release of the security control status.

[0088] The above embodiments can be implemented by software, hardware, or a combination of software and hardware. When implemented in software, the processor in the personnel assessment server executes the program stored in the memory to complete tasks such as identifier association reading, isolated copy recovery, version identifier generation, calculation of four comprehensive scores, calculation of configuration impact reduction, ranking propagation tracking, security control status setting, recalculation, and audit record chain verification.

[0089] Those skilled in the art will understand that each step can be integrated into the same personnel assessment server, or it can be deployed separately on the assessment calculation server, log audit server, and assessment result management server, and a corresponding relationship can be established through personnel assessment task identifier, assessed personnel identifier, assessment item identifier, set version identifier, configuration version identifier, and result version identifier. The specific deployment method does not affect the substance of the technical solution of this invention.

[0090] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for auditing and controlling the entire lifecycle logs of personnel assessment, characterized in that, Performed by the personnel assessment server, the process includes the following steps: Read the current shared evaluation set and correction records, verify the continuity of the correction records, and form a candidate benchmark set in the isolated copy; The comprehensive score of the two sets is calculated using the first and second scoring configuration versions, and the result version identifier is generated to obtain the impact range of the baseline configuration, the impact range of the current configuration, and the reduction in configuration impact. When the impact of the baseline configuration reaches the second configuration impact threshold, the impact of the current configuration is lower than the first configuration impact threshold, and the reduction in configuration impact reaches the masking threshold, the directly affected personnel are identified. Set its comprehensive score, personnel ranking and selection list to a security control state that prohibits publication and citation, block the output of the publication interface and citation interface, and recalculate using the candidate benchmark set and the second score configuration version; The audit records are connected according to the operation time to form an audit record chain, and the end verification code is stored in an independent read-only storage area; when the integrity verification and review of the audit record chain pass, the result is replaced and the security control status is released; otherwise, the security control status is maintained.

2. The method for auditing and controlling the entire lifecycle logs of personnel assessment according to claim 1, characterized in that, The reduction in the impact of the configuration includes: The first and second scoring configuration versions are used to calculate the comprehensive scores of the two sets respectively, and the candidate first comprehensive score, candidate second comprehensive score, current first comprehensive score and current second comprehensive score are obtained. The absolute value of the difference between the candidate second comprehensive score and the candidate first comprehensive score, and the absolute value of the difference between the current second comprehensive score and the current first comprehensive score are respectively used as the influence range of the baseline configuration and the influence range of the current configuration; the difference between the current first comprehensive score and the candidate first comprehensive score, the difference between the candidate second comprehensive score and the candidate first comprehensive score, and the difference between the current second comprehensive score and the current first comprehensive score are respectively used as the correction change, the baseline configuration change, and the current configuration change. When the change amount has the same sign as the baseline change amount and the absolute value of the current change amount is less than the absolute value of the baseline change amount, the difference between the two absolute values ​​is used as the reduction amount of the configuration impact.

3. The method for auditing and controlling the entire lifecycle logs of personnel assessment according to claim 2, characterized in that, Determining the direction of the correction change includes: The revised evaluation values ​​are replaced with the original evaluation values ​​in sequence according to the revision time. The first scoring configuration version is used to calculate the comprehensive score before the first replacement and after each replacement. The difference between two adjacent comprehensive scores is used as the revision contribution. The sum of all correction contributions is taken as the correction change. When the sum of the absolute values ​​of the correction contributions with the same sign as the baseline configuration change is greater than the sum of the absolute values ​​of the correction contributions with the opposite sign to the baseline configuration change, the correction change is determined to be in the same direction as the baseline configuration change.

4. The method for auditing and controlling the entire lifecycle logs of personnel assessment according to claim 1, characterized in that, The candidate benchmark set includes: Grouped by the person being evaluated and the evaluation item, and arranged by the revision time; When the current evaluation value is equal to the last corrected evaluation value, and the previous corrected evaluation value of the adjacent correction record is equal to the previous evaluation value before the correction, the evaluation value before the correction is restored in reverse order of correction time. The restored pre-correction evaluation values ​​and uncorrected evaluation values ​​are written into an isolated copy to form a candidate benchmark set, and a current set version identifier and a candidate set version identifier are generated.

5. The method for auditing and controlling the entire lifecycle logs of personnel assessment according to claim 1, characterized in that, The calculation of the overall score includes: Both the first and second scoring configuration versions include a configuration version identifier, indicator weights, and scoring ranges, as well as methods for handling missing evaluation values ​​or excluding invalid evaluation values; the two versions are used to calculate the comprehensive score of the two sets; Connect the personnel assessment task identifier, the assessed personnel identifier, the set version identifier, the configuration version identifier, the comprehensive score and the calculation time, and generate the result version identifier; the four calculations use the same assessment items, the same number of digits retained in the comprehensive score and the same ranking group.

6. The method for auditing and security control of the entire lifecycle logs of personnel assessment according to claim 1, characterized in that, The affected test takers include: The second scoring configuration version was used to calculate the ranking of the directly affected test subjects in the two sets and the list of selected personnel. Ranking intervals are formed based on the two rankings of each directly affected person being evaluated, and overlapping or adjacent intervals are merged. Those whose ranking changes within the interval or who are added to or removed from the two selected lists are identified as the affected participants. The affected test subjects and directly affected test subjects will be merged into the affected test subjects.

7. The method for auditing and security control of the entire lifecycle log of personnel assessment according to claim 6, characterized in that, Recalculation includes: The overall scores of the affected test subjects, their rankings in their respective ranking groups, and the list of selected individuals will be set to a security control status that prohibits publication and citation. The result version identifier is recalculated using the candidate benchmark set and the second scoring configuration version; After the changes before and after recalculation are verified and approved by the audit record chain integrity check, the changes are replaced and the security control status is lifted. The unchanged items are lifted after the same verification and review.

8. The method for auditing and security control of personnel assessment lifecycle logs according to claim 1, characterized in that, The determination of the first and second configuration impact thresholds and masking thresholds includes: Read historical personnel assessment tasks with the same assessment items, scoring ranges, and ranking groups that have no correction records, and form a historical configuration impact sequence based on the absolute difference of the comprehensive scores of the same person under two scoring configuration versions. The median and the 90th percentile of the sequence are used as the first and second configuration influence thresholds, respectively. The median reduction in the configuration impact of historical personnel assessment tasks, based on the review conclusions, was used as the coverage threshold.

9. A method for auditing and controlling the entire lifecycle logs of personnel assessment according to claim 4, characterized in that, When correcting discontinuous sequences: Each of the previous evaluation values ​​was replaced with the current evaluation value to form a set of candidate evaluations; The system sequentially searches through the source system's historical records, original imported files, and database backups for the same person being evaluated, the same evaluation item, and the same verification evaluation value during the evaluation period. The set of candidate benchmarks whose pre-correction evaluation values ​​are equal to the verification evaluation values ​​is used as the candidate benchmark set. If no verification evaluation value is found or no matching set of candidate evaluations is available, maintain the security control status of the corresponding comprehensive score, personnel ranking and selection list.

10. A method for auditing and controlling the entire lifecycle logs of personnel assessment according to claim 7, characterized in that, Also includes: Audit records are generated for each of the following: reading of the assessment set and correction records, continuity verification, generation of version identifiers, calculation of configuration impact reduction, identification of affected assessment personnel, setting and recalculation of security control status. The audit records are arranged according to the operation time. The personnel assessment task identifier is connected with the preset initial verification code fixed when the task is created to generate the first pre-verification code. Then, the previous verification code is connected with the current audit record to generate the current verification code. The end check code and the number of audit records are stored in the audit record database and a separate read-only storage area. The end check code is recalculated before the security control status is lifted. If the recalculated value of the end checksum matches the two saved values ​​with the same number of audit records and passes the review, the recalculated value replaces the original value and the security control status is lifted; otherwise, the security control status is maintained.