Machine room access management method and system
By combining biometric identification and work card communication keys, the shortcomings of existing access management systems in terms of security and convenience are solved, achieving efficient identity verification and access control in the computer room, and improving the security and convenience of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- INFORMATION & COMM CO OF STATE GRID XINJIANG ELECTRIC POWER CO LTD
- Filing Date
- 2023-02-15
- Publication Date
- 2026-04-24
AI Technical Summary
The existing access control system is inadequate in terms of security and convenience. It cannot ensure the validity period of the access control password, which may allow non-office personnel to enter, and the multiple verification methods affect convenience.
The system uses a biometric identification module to collect personnel information and communicates with the access control module via a communication key on the work card to enable automatic opening of the computer room or cabinet. It also combines Bluetooth and radio frequency modules for identity verification and access control, simplifying the verification process.
It improves the security and convenience of the computer room, prevents tailgating, enables seamless entry, simplifies verification methods, and enhances the system's usability and security.
Smart Images

Figure CN116259123B_ABST
Abstract
Description
Technical Field
[0001] This application generally relates to the field of intelligent management technology, and specifically to a method and system for managing access to a computer room. Background Technology
[0002] Access management systems, as an advanced high-tech means of prevention and management, have been widely used in scientific research, industry, museums, hotels, shopping malls, medical monitoring, and other fields. In particular, due to the system's inherent security and convenience, its application in many fields is becoming increasingly widespread.
[0003] However, some existing access control systems are relatively simple in their management methods and cannot implement the requirement that access control passwords be used only once within a specific time period. This allows non-office personnel to sneak in unnoticed. In addition, some existing access control systems require multiple verification methods to improve security, which affects convenience. Summary of the Invention
[0004] In view of the above-mentioned defects or deficiencies in the existing technology, it is desirable to provide a data center access management method and system that can improve the security and convenience of access management system and facilitate management.
[0005] Firstly, this application provides a data center access management method, applied to an access management system. The system includes multiple access control modules and work cards. The access control modules are used to control the opening of the data center or server racks. The work cards correspond one-to-one with biometric information. The method includes:
[0006] The biometric identification module collects the biometric information of personnel.
[0007] Based on the biometric information, a communication key is issued to the work card;
[0008] The work card communicates with the access control module based on the communication key to control the opening of the computer room or cabinet.
[0009] Optionally, the access control module includes a computer room access control and a cabinet access control located downstream of the computer room access control. The computer room access control is used to control the opening of the computer room, and the cabinet access control is used to control the opening of the cabinet. The communication key includes an area identifier corresponding to the computer room access control and a sub-area identifier corresponding to the cabinet door.
[0010] Optionally, the communication key is the key for this communication, wherein issuing the communication key to the work card based on the biometric information includes:
[0011] Based on the biometrics, obtain the permission information corresponding to the biometrics;
[0012] The communication key for that session is issued to the work card based on the permission information.
[0013] Optionally, the work card includes a Bluetooth module and an RF module, and the system further includes a Bluetooth node communication module and an RF node communication module disposed on the access control module, wherein,
[0014] The work card communicates with the access control module based on the communication key, including:
[0015] The Bluetooth module establishes a Bluetooth communication connection with the Bluetooth node communication module.
[0016] The work card obtains a communication key based on the Bluetooth communication connection;
[0017] The radio frequency module establishes the radio frequency communication connection with the radio frequency node communication module based on the communication key.
[0018] Optionally, the method further includes:
[0019] The identity verification information of the person is generated based on the biometric information; the identity verification information includes check-in information and check-out information.
[0020] Optionally, the Bluetooth module establishes a Bluetooth communication connection with the Bluetooth node communication module, including:
[0021] The Bluetooth module listens to the Bluetooth wake-up broadcast signal sent by the Bluetooth node communication module, and sends a first request message to the Bluetooth node communication module based on the Bluetooth wake-up broadcast signal;
[0022] Based on the received first request information, the Bluetooth node communication module establishes a Bluetooth communication connection with the Bluetooth module after confirming that the work card device identifier in the first request information corresponds to the check-in information. The work card device identifier corresponds one-to-one with the biometric information.
[0023] Optionally, the method further includes:
[0024] After the Bluetooth module completes the currently executing Bluetooth event, the work card controls the Bluetooth module to enter the corresponding sleep mode; wherein,
[0025] The sleep mode includes a deep sleep mode and a shallow sleep mode. In the deep sleep mode, the Bluetooth module only listens to the Bluetooth wake-up broadcast signal, while in the shallow sleep mode, the Bluetooth module listens to all Bluetooth broadcast signals.
[0026] Optionally, the work card controls the Bluetooth module to enter a deep sleep mode, specifically including:
[0027] The Bluetooth module listens to the Bluetooth sleep broadcast signal sent by the Bluetooth node communication module; and sends a second request message to the Bluetooth node communication module based on the Bluetooth sleep broadcast signal;
[0028] Based on the received second request information, the Bluetooth node communication module establishes a Bluetooth communication connection with the Bluetooth module after confirming that the work card device identifier in the second request information corresponds to the sign-out information.
[0029] The Bluetooth module obtains a deep sleep command sent by the Bluetooth node communication connection based on the Bluetooth communication connection. The deep sleep command is used to control the Bluetooth module to execute a deep sleep event and enter deep sleep mode.
[0030] Optionally, the work card controls the Bluetooth module to enter a shallow sleep mode, specifically including:
[0031] After the Bluetooth module performs an event other than a deep sleep event, the work card controls the Bluetooth module to enter a shallow sleep mode;
[0032] The Bluetooth module periodically determines whether it receives a Bluetooth broadcast signal in the shallow sleep mode; if it does not receive one, it maintains the shallow sleep mode; if it receives one, it enters the working mode.
[0033] Secondly, this application provides a data center access management system, applied to any of the data center access management methods described above, the system comprising:
[0034] Multiple access control modules, which are used to control the opening of the computer room or server rack;
[0035] A biometric identification module, which is used to collect biometric information of personnel;
[0036] The management module is used to issue a communication key to the work card based on the biometric information;
[0037] The work card corresponds one-to-one with the biometric information and is used to communicate with the access control module based on the communication key in order to control the opening of the computer room or cabinet.
[0038] The technical solutions provided by the embodiments of this application may include the following beneficial effects:
[0039] The data center access management method provided in this application embodiment can authenticate identity information through a biometric recognition module, ensuring that the person clocking in is the one who actually clocked in. Only when the clocking in is successful can the employee card obtain a communication key. The employee card communicates with the access control module through the communication key to open the access control. Multiple matching verifications can be automatically completed through the clocking-in operation alone. Through biometric recognition alone, the opening of the server rack can be controlled through permission management, simplifying the verification process and achieving contactless entry. Through the linkage of the data center access management system, tailgating can be effectively prevented, improving the security of the data center. Attached Figure Description
[0040] Other features, objects, and advantages of this application will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:
[0041] Figure 1 A flowchart illustrating a data center access management method provided for embodiments of this application;
[0042] Figure 2 A schematic diagram of a computer room access management system provided for an embodiment of this application;
[0043] Figure 3 A schematic diagram of the structure of a work card provided for an embodiment of this application;
[0044] Figure 4 A schematic diagram of the layout of a computer room access management system provided for an embodiment of this application;
[0045] Figure 5 A flowchart illustrating a data center access management method provided for embodiments of this application;
[0046] Figure 6 A flowchart illustrating a data center access management method provided for embodiments of this application;
[0047] Figure 7 A flowchart illustrating another data center access management method provided for embodiments of this application;
[0048] Figure 8-10 A flowchart illustrating another data center access management method provided for embodiments of this application;
[0049] Figure 11 This is a schematic diagram of the structure of a computer device provided for an embodiment of this application. Detailed Implementation
[0050] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.
[0051] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.
[0052] Please see details. Figure 1-2 This application provides a data center access management method applied to an access management system 1000. The system 1000 includes multiple access control modules 110 and work cards 100. The access control modules 110 are used to control the opening of the data center or server racks. The work cards 100 are associated with biometric information. The method includes:
[0053] S10. Collect the biometric information of personnel through the biometric identification module 200;
[0054] S20. A communication key is sent to the work card 100 based on the biometric information;
[0055] S30. The work card 100 communicates with the access control module 110 based on the communication key to control the opening of the computer room or cabinet.
[0056] The data center access management method provided in this application embodiment can authenticate identity information through the biometric recognition module 200, ensuring that the person clocking in is the one who actually clocked in. Only when the clocking in is successful can the employee card 100 obtain the communication key. The employee card 100 communicates with the access control module 110 through the communication key to open the access control. Multiple matching verifications can be automatically completed through the clocking-in operation alone. Through biometric recognition alone, the opening of the server rack can be controlled through permission management, simplifying the verification process and achieving contactless entry. Through the linkage of the data center access management system 1000, tailgating can be effectively prevented, improving the security of the data center.
[0057] The biometric identification module 200 can be implemented using a time clock or personal terminal. It compares the received biometric data of a person with pre-stored biometric data. If the comparison matches, a verification result indicating valid identity verification is generated; otherwise, a verification result indicating invalid identity verification is generated. The biometric data can include features such as face, iris, and fingerprint, but this invention is not limited to these. Furthermore, existing identification algorithms can be used to collect or compare personnel biometric data, which will not be listed here.
[0058] The access management system 1000 in this application, based on facial recognition technology, integrates several data center management workflows, including automatic permission issuance, data center access control 111, rack access control 112, and alarm information push. It enables real-time monitoring of personnel entry and exit, presence, and rack door locks, meeting comprehensive management needs and improving the level of data center safety and operational management. It achieves integrated monitoring, centralized management, and intelligent linkage of multiple systems 1000, enhancing the system's practicality and reducing production management costs. It also enables automatic authorization, monitoring, and recording of data center maintenance personnel throughout the entire process, and provides data information for post-incident analysis of cause and handling procedures.
[0059] The system assigns permissions to personnel based on work order information received by the system 1000. Permissions are verified separately in the computer room or on the server rack. The facial recognition module 200 installed in the computer room ensures that personnel entering the computer room have computer room permissions. When opening a server rack using a work card 100, it ensures that the personnel opening the server rack have server rack permissions. This enables effective monitoring and management of server racks and effectively manages situations such as one person having multiple cards, multiple people having multiple cards, and multiple people having one card, thereby improving the security of the monitoring and management system 1000.
[0060] like Figure 3 As shown, this application also provides a work card 100 that matches the access management system, wherein the work card 100 includes a Bluetooth module 10 and a radio frequency module 20.
[0061] Bluetooth is a wireless technology that supports short-range communication (generally within 10 meters). In this embodiment, the Bluetooth module 10 may have a transmitter and a receiver respectively for transmitting and receiving Bluetooth signals. In this embodiment, the Bluetooth module 10 can receive Bluetooth broadcast signals sent by external devices and can also communicate with external devices (Bluetooth node communication module 300) by establishing a Bluetooth link. The transmitter of the Bluetooth module 10 can send uplink signals to external devices, and the receiver is used to receive downlink signals sent by external devices and then send them to the control module 30 of the work card 100 for processing.
[0062] In this application, the Bluetooth module 10 can adopt Bluetooth Low Energy (BLE). BLE reduces the power consumption of the Bluetooth module on the work card 100. Of course, in other embodiments, the work card 100 can use various power supply methods such as solar power to improve its operating time. It is important to note that the physical layer modulation and demodulation methods of classic Bluetooth and Bluetooth Low Energy are different. Therefore, Bluetooth Low Energy devices and classic Bluetooth devices cannot communicate with each other. Do not confuse them during selection. If the Bluetooth node communication module 300 is a Bluetooth Low Energy device, the work card 100 must also be a Bluetooth Low Energy device; similarly, the classic Bluetooth work card 100 can only communicate with the classic Bluetooth node communication module 300.
[0063] The radio frequency module 20 can be a 13.56MHz radio frequency identification (RFID) module. It enables contactless two-way data communication via radio frequency, and uses radio frequency to read and write recording media (electronic tags or RFID cards), thereby achieving the purpose of target identification and data exchange.
[0064] In this embodiment of the application, the work card 100 includes a control module 30. The Bluetooth module 10 and the radio frequency module 20 are communicatively connected to the control module 30. The Bluetooth module 10 sends the received Bluetooth information to the control module 30 for further processing, and the radio frequency module 20 can also send the received radio frequency information to the control module 30 for further processing.
[0065] The control module 30 uses an intelligent, high-precision control chip microcontroller as its core to coordinate the normal operation of other modules. The control module 30 can be a microcontroller, embedded chip, FPGA, or other device capable of receiving, processing, and generating signals for information encryption and decryption; alternatively, the control module 30 can also be a memory. Encryption and decryption can be implemented using hardware encryption modules or circuits, or as an encryption program stored in memory. This application does not limit the implementation method of the control module 30.
[0066] In some possible embodiments, the hardware device of the work card 100 stores various types of personnel information in the control module 30 when it leaves the factory. It is understood that, in this embodiment, when the work card 100 is issued, the personal information in the work card 100 can be bound to the control module 30, Bluetooth module 10, and radio frequency module 20 to prevent individuals from arbitrarily replacing any of these components. The binding method can employ any binding method in the prior art.
[0067] The system 1000 also includes a Bluetooth node communication module 300 and a radio frequency node communication module 400 disposed on the access control module 110. In this embodiment, when the radio frequency module 20 and the radio frequency node communication module 400 perform verification, the radio frequency node communication module 400 (reader / writer device) sends an inquiry request to the radio frequency module 20 (electronic tag). The electronic tag generates authentication information based on the received inquiry request information and the communication key of the work card 100, and returns the authentication information to the reader / writer device. The reader / writer device verifies the authentication information to obtain a verification result. If the verification is successful, it controls the opening of the control room door, allowing entry, and returns the verification result.
[0068] This application does not limit the location of the access control module 110. For example, the access control module 110 includes a computer room access control 111 and a cabinet access control 112 located downstream of the computer room access control 111. The computer room access control 111 controls the opening of the computer room, and the cabinet access control 112 controls the opening of the cabinet. The communication key includes an area identifier corresponding to the computer room access control 111 and a sub-area identifier corresponding to the cabinet door.
[0069] It is understood that the number of computer rooms in this region and the number of server racks in the computer rooms are not limited in this embodiment of the application. In this embodiment of the application, the region where the computer room is located is defined as the first node 1, the biometric identification module is set on the first node 1, the computer room is the second node 2, the computer room access control 111 is set on the second node 2, the server rack is the third node 3, and the server rack access control 112 is set on the third node 3.
[0070] It is understood that, in this embodiment of the application, the geographical locations of the first node 1, the second node 2, and the third node 3 are not limited. The first node 1 is set before the entry management time of the second node 2 to generate check-in information, and the first node 1 is set after the entry management time of the third node 3 to generate check-out information. The second node 2 is set before the entry management time of the third node 3 to obtain the key used for radio frequency verification at the third node 3, thereby realizing entry management.
[0071] In step S20, the step of issuing a communication key to the work card based on the biometric information includes:
[0072] Based on the biometrics, obtain the permission information corresponding to the biometrics; based on the permission information, issue the current communication key to the work card.
[0073] It should be further explained that, in this application, the communication key is used for verification between the radio frequency module 20 and the radio frequency node communication module 400. This communication key can be used for a fixed period of time or a fixed number of times, for example, for daily radio frequency verification or for each radio frequency verification. This application does not limit the application method of the communication key. This application also does not limit the key generation method; various different key generation methods from the prior art can be used.
[0074] The communication key carries a region identifier corresponding to the second node 2 and a sub-region identifier corresponding to the third node 3. Different second nodes 2 correspond to different region identifiers, and different third nodes 3 correspond to different region identifiers.
[0075] In S30 of this application, the work card 100 communicates with the access control module 110 based on the communication key, including:
[0076] The Bluetooth module 10 establishes a Bluetooth communication connection with the Bluetooth node communication module 300, and the work card 100 obtains a communication key based on the Bluetooth communication connection; the radio frequency module 20 establishes a radio frequency communication connection with the radio frequency node communication module 400 based on the communication key.
[0077] In this application, the communication key can be a shared key corresponding to multiple work cards 100. After obtaining the communication key, the work card 100 further encrypts the key based on its own stored encryption method to generate an independent communication key for the work card 100. Multiple security verification methods are used in Bluetooth communication management and application to improve system security and prevent tampering and forgery during data exchange. Of course, in other embodiments, the work card 100 can also generate an independent key related to the work card device identifier based on the work card device identifier, and this application does not limit this.
[0078] It is understood that this application does not limit the location of the Bluetooth communication module 300. It can be set on the first node 1 or on the second node 2. There can be multiple Bluetooth communication modules 300. In the embodiments of this application, multiple current communication keys of different second nodes 2 can be obtained by Bluetooth communication modules 300 set on different second nodes 2, or they can be obtained all at once by Bluetooth communication modules 300 set on the first node 1.
[0079] In this embodiment, each third node 3 corresponds to a second node 2, enabling the Bluetooth module 10 of each second node 2 to obtain the current communication key corresponding to each third node 3. Of course, in other possible embodiments, the Bluetooth node communication module 300 of the second node 2 can obtain different current communication keys corresponding to different third nodes 3, and this application does not limit this. It is understood that the current communication keys corresponding to the first node 1, second node 2, and third node 3 in this application can also be implemented in other ways to achieve universality or updates, and this application does not limit this.
[0080] For example, such as Figure 4 As shown, the first node 1 can be set at the building entrance, the second node 2 can be set on the way to the third node 3, such as the elevator entrance on each floor, and the third node 3 can be multiple computer rooms corresponding to each floor. By setting the second node 2 on the necessary route to the third node 3, it can be realized that the current communication key has been received each time the area where the third node 3 is located is entered. Each floor corresponds to a different area identifier, which is used for entering multiple computer rooms on that floor. In this application, multiple computer rooms on each floor can correspond to the same current communication key. The control module 30 on the work card 100 automatically updates the current communication key according to a preset encryption method, generating different current communication keys for the work card 100, so that the current communication key for each computer room is different.
[0081] like Figure 5 As shown, in order to effectively manage work cards, the method further includes:
[0082] S110. Generate the person's identity verification information based on the biometric information; the identity verification information includes check-in information and check-out information;
[0083] S120. Based on the check-in information, the communication key is sent to the work card via the Bluetooth node communication module;
[0084] S130. Based on the sign-out information, a key deletion command is sent to the work card via the Bluetooth node communication module.
[0085] The generated sign-in information can be used to enable the system to issue the communication key to the work card based on the sign-in information. The system can also issue a key deletion command to the work card based on the sign-out information. This key deletion command can invalidate the key on the work card; it can also be used to put the work card into a deep sleep mode, but this application is not limited in this regard. A detailed description follows.
[0086] In this application, the power consumption of the Bluetooth device is reduced by controlling the Bluetooth module 10 to enter a sleep mode. For example, when the Bluetooth device is not actively communicating with other Bluetooth devices, the Bluetooth module 10 is controlled to enter a sleep mode to reduce the power consumption of the Bluetooth device.
[0087] In this embodiment, the Bluetooth module 10 includes a working mode and a sleep mode. In the sleep mode, the Bluetooth module 10 only listens to the corresponding broadcast signal. When a Bluetooth request needs to be sent, the work card 100 first activates the Bluetooth mode to enter the working mode, and performs Bluetooth events such as sending and receiving Bluetooth requests in the working mode.
[0088] The Bluetooth module, in the stated operating mode, can listen to various Bluetooth broadcast signals and send Bluetooth broadcast signals and specific Bluetooth signals. This application does not limit the Bluetooth operating mode in this regard. Exemplarily, a Bluetooth device primarily operates in three states: broadcast, scan, and connect. In broadcast mode, it broadcasts according to a pre-set frequency to be discovered by other Bluetooth devices. In scan mode, it scans according to a pre-set scanning frequency and scanning window to discover other Bluetooth devices. In connect mode, the two Bluetooth devices communicate and exchange data according to a pre-set time interval. That is, multiple broadcast events, scan events, and connect events can occur, each with its own set interval, and they may alternate between each other.
[0089] To save power consumption of the work card, the method further includes:
[0090] After the Bluetooth module completes the currently executing Bluetooth event, the work card controls the Bluetooth module to enter the corresponding sleep mode; wherein,
[0091] The sleep mode includes a deep sleep mode and a shallow sleep mode. In the deep sleep mode, the Bluetooth module only listens to the Bluetooth wake-up broadcast signal, while in the shallow sleep mode, the Bluetooth module listens to all Bluetooth broadcast signals.
[0092] In this embodiment, the wake-up method for the deep sleep mode can be automatic or passive. Automatic wake-up can be achieved by controlling the Bluetooth module 10 to enter working mode via the control module 30 under the control of the clock module on the work card 100. Automatic wake-up can be implemented at fixed time intervals or fixed cycles. Passive wake-up, on the other hand, is achieved by automatically monitoring the Bluetooth wake-up broadcast signal in deep sleep mode, as described in S201-S204 of this application.
[0093] like Figure 6As shown, the passive wake-up method in the deep sleep mode includes:
[0094] S201, The Bluetooth module listens to the Bluetooth wake-up broadcast signal sent by the Bluetooth node communication module;
[0095] S202. Send a first request message to the Bluetooth node communication module based on the Bluetooth wake-up broadcast signal;
[0096] S203. Based on the received first request information, the Bluetooth node communication module establishes a Bluetooth communication connection with the Bluetooth module after confirming that the work card device identifier in the first request information corresponds to the check-in information, and the work card device identifier corresponds one-to-one with the biometric information.
[0097] S204. The Bluetooth module obtains the communication key sent by the Bluetooth node communication connection based on the Bluetooth communication connection.
[0098] The work card device identifier can carry information representing the work card 100, which can be a serial number or other identifier that is uniquely linked to the biometric information of the person carrying the work card 100. The work card device identifier can also uniquely identify the person associated with it.
[0099] In this application, the Bluetooth module 10 on the work card 100 sends a first request message to the Bluetooth node communication module 300. The Bluetooth node communication module 300 determines whether the person has signed in based on the person's identity in the first request message. If the person has signed in, the Bluetooth node communication module 300 establishes a Bluetooth communication connection with the Bluetooth module 10 on the work card 100 and sends the communication key for this communication to the work card 100.
[0100] In this embodiment, the Bluetooth node communication module 300 has two types of broadcasts: a Bluetooth sleep broadcast signal and a Bluetooth wake-up signal broadcast. The two broadcasts are broadcast alternately, with only one broadcast transmitting a signal at a time. When a person holding a work card 100 approaches the Bluetooth node communication module 300, the work card 100 scans the broadcast information transmitted by the Bluetooth node communication module 300. The control module 30 on the work card 100 parses the fields corresponding to the broadcast to determine whether to wake up the Bluetooth module 10 on the work card 100 and put it into working mode.
[0101] In this embodiment, the Bluetooth Low Energy broadcast channels (divided to prevent network interference) are only three, used to receive Bluetooth sleep broadcast signals, Bluetooth wake-up broadcast signals, and transmit incoming and outgoing data broadcast signals during operation. In the Bluetooth wake-up method provided in this embodiment, the received Bluetooth broadcast signals are bandpass filtered to block signals outside a preset frequency band, retaining signals within the preset frequency band. After verifying the retained signals within the preset frequency band (e.g., the geographic identifier in the Bluetooth broadcast signal in this application),...
[0102] In this embodiment, the Bluetooth module 10 enters deep sleep mode via both automatic and passive methods. Automatic entry into deep sleep mode can be achieved by controlling the Bluetooth module 10 to enter deep sleep mode via the control module 30 of the work card 100 after a predetermined period of time outside the signal range of the Bluetooth node communication module 300. Once the work card 100 leaves the Bluetooth signal coverage area, it can no longer wirelessly connect to the gateway. Therefore, when it is determined that the work card 100 is not in the preset work area, the functions of the Bluetooth module 10, except for scanning broadcast signals on fixed channels, are turned off, thus entering a low-power non-working state, i.e., deep sleep mode.
[0103] Please continue to refer to this. Figure 6 In this application, the work card controls the Bluetooth module 10 to passively enter a deep sleep mode, specifically including:
[0104] S211. The Bluetooth module listens to the Bluetooth sleep broadcast signal sent by the Bluetooth node communication module;
[0105] S212. Send a second request message to the Bluetooth node communication module based on the Bluetooth sleep broadcast signal;
[0106] S213. Based on the received second request information, the Bluetooth node communication module establishes a Bluetooth communication connection with the Bluetooth module after confirming that the work card device identifier in the second request information corresponds to the sign-out information.
[0107] S214. The Bluetooth module obtains a deep sleep instruction (key elimination instruction) sent by the Bluetooth node communication connection based on the Bluetooth communication connection. The deep sleep instruction is used to control the Bluetooth module to execute a deep sleep event and enter deep sleep mode, or the deep sleep instruction can also be used to eliminate the current communication key.
[0108] It is understood that in this embodiment, if the work card 100 enters deep sleep mode after generating sign-out information, the communication key becomes invalid. If sign-out information is obtained, the entry verification of the radio frequency module 20 is performed, i.e., a verification result indicating invalid identity verification information is generated. Of course, sign-in information can also be obtained by signing in again.
[0109] In this embodiment, the Bluetooth module 10 enters shallow sleep mode automatically. When the employee ID card indicates entry into the workplace, the control module 30 can switch between working and non-working states at certain intervals. To distinguish between automatically entering deep sleep mode and automatically entering shallow sleep mode, this application uses different time periods. For example, after obtaining the communication key through Bluetooth communication connection, i.e., after completing this Bluetooth event, the Bluetooth module 10 enters shallow sleep mode. Alternatively, a time-segmented approach can be used; for example, during working hours, Bluetooth automatically enters shallow sleep mode after completing a Bluetooth event, while during non-working hours, Bluetooth automatically enters deep sleep mode. This application can also combine other set conditions to control the switching between deep sleep mode and shallow sleep mode during working hours.
[0110] In this application, the work card 100 controls the Bluetooth module 10 to enter a shallow sleep mode, specifically including:
[0111] S301. After the Bluetooth module executes an event other than a deep sleep event, the work card controls the Bluetooth module to enter a shallow sleep mode.
[0112] S302, the Bluetooth module periodically determines whether it receives a Bluetooth broadcast signal in the shallow sleep mode;
[0113] S303. If no signal is received, maintain the shallow sleep mode.
[0114] S304. If received, enter working mode.
[0115] In this embodiment, the wake-up method for the shallow sleep mode can be automatic or passive. Automatic wake-up can be achieved by controlling the Bluetooth module 10 to enter working mode via the control module 30 under the control of the clock module on the work card 100. Automatic wake-up can be implemented at fixed time intervals or fixed cycles. Passive wake-up, on the other hand, is achieved by automatically monitoring the Bluetooth broadcast signal in the shallow sleep mode, as described in S301-S304 of this application.
[0116] In this embodiment, by setting two different Bluetooth sleep modes, Bluetooth power consumption can be effectively reduced. Different sleep and wake-up methods correspond to different sleep modes. By enabling the lower power consumption deep sleep mode to sleep for an extended period, the power consumption of the work card 100 can be reduced. In the low power consumption shallow sleep mode, the Bluetooth wake-up signal can be monitored. If it is determined that the communication key corresponding to the geographical information of the Bluetooth wake-up signal has been received, the shallow sleep mode is maintained, and the time interval for receiving the Bluetooth wake-up signal is increased, thereby reducing power consumption. If it is determined that the communication key corresponding to the geographical information of the Bluetooth wake-up signal has not been received, the Bluetooth module 10 is woken up and enters the working mode to send a request to obtain the key.
[0117] To enable effective management of the computer room, the method further includes:
[0118] When the work card opens the cabinet and closes the cabinet, record information is generated. The record information includes the work room information, work cabinet information, work time information, and work personnel information.
[0119] In this embodiment of the application, the system can also be a video surveillance device 600 installed in the computer room 111, enabling it to automatically capture the facial information of personnel entering the monitored area and provide the recognition results to the computer room dynamic face system for analysis, comparison, recognition, and storage. Figure 7 As shown, by combining the video surveillance equipment installed in the computer room 111 as a dynamic face recognition module 600, dynamic human image capture can also be used for mutual verification with the work card 100, computer room access control 111, and cabinet access control 112, thereby improving system security.
[0120] The dynamic facial recognition module 600 can monitor staff in the computer room and determine if unauthorized personnel have entered. For important computer rooms, it can issue an alert or automatically close the rack access control 112 when unauthorized personnel are detected, preventing tailgating. Furthermore, the dynamic facial recognition module can also be used to determine permissions, such as whether unauthorized personnel have followed others into the vicinity of the open rack access control 112.
[0121] In the embodiments of this application, such as Figure 8 As shown, to prevent multiple people from entering the server room with the same card, a dynamic face recognition module 600 can be used to determine whether each person entering the server room has the necessary permissions. Optionally, the method further includes:
[0122] S401. When multiple facial information is collected simultaneously by the facial recognition module installed in the computer room, it is determined based on the personnel information whether all multiple facial information have passed the computer room access verification.
[0123] S402. If some facial information fails the data center access verification, anomaly handling information is generated based on the facial information that fails the data center access verification.
[0124] S403. If all facial information passes the data center access verification, then the record information is generated based on all facial information.
[0125] To prevent card-swapping, dynamic facial recognition and employee card verification can be used, verifying identity via Bluetooth connection. Alternatively, as... Figure 9 As shown, the Bluetooth module receives the communication key sent by the Bluetooth node communication module, and the method includes:
[0126] S411, The Bluetooth module sends a Bluetooth connection request to the Bluetooth node communication module;
[0127] S412. Based on the Bluetooth connection request, determine whether the personnel corresponding to the work card have computer room access.
[0128] S413. If present, the Bluetooth module establishes a Bluetooth communication connection with the Bluetooth node communication module.
[0129] S414. If not, report the work card information to generate exception handling information.
[0130] To prevent multiple people from opening the server rack with the same SIM card, a mutual verification method using employee cards can be adopted. Alternatively, such as... Figure 10 As shown, the method further includes:
[0131] S421. After the radio frequency node communication module passes the cabinet verification of the radio frequency module, the work card becomes the local card, and the local card Bluetooth module on the local card enters the working mode.
[0132] S422. The Bluetooth module of this card sends an entry / exit data broadcast signal to all surrounding Bluetooth modules within the network coverage area. The entry / exit data broadcast signal includes a timestamp and work rack information.
[0133] S423. The surrounding Bluetooth module determines whether the work card corresponding to the surrounding Bluetooth module has undergone radio frequency entry verification within a preset time based on the monitored entry and exit data broadcast signal.
[0134] S424. If the radio frequency verification fails, the surrounding Bluetooth modules generate entry / exit reporting data based on the entry / exit data broadcast signal.
[0135] If the surrounding Bluetooth modules have the corresponding server room access, the method includes:
[0136] The surrounding Bluetooth module communicates with the Bluetooth node communication module in the computer room via Bluetooth and reports the entry and exit data, so that the management system can generate record information corresponding to the work cabinet based on the reported data.
[0137] If the surrounding Bluetooth modules do not have the corresponding server room access, the method includes:
[0138] The surrounding Bluetooth module communicates with the Bluetooth node communication module of this card via Bluetooth and reports the entry and exit data, so that the management system can generate abnormal handling information corresponding to the work cabinet based on the reported information data.
[0139] Based on the same inventive concept, please continue to refer to Figure 2 This application provides a data center access management system 1000, applied to any of the data center access management methods described above, wherein the system 1000 includes:
[0140] Multiple access control modules 110 are used to control the opening of the computer room or server rack;
[0141] A biometric identification module 200 is used to collect biometric information of personnel.
[0142] Management module 500, the management module 500 is used to send a communication key to the work card 100 based on the biometric information;
[0143] The work card 100 corresponds one-to-one with the biometric information and is used to communicate with the access control module 110 based on the communication key in order to control the opening of the computer room or cabinet.
[0144] It should be understood that the units or modules described in System 1000 are related to the reference. Figure 1 The steps in the described method correspond to each other. Therefore, the operations and features described above for the method also apply to system 1000 and the units contained therein, and will not be repeated here. System 1000 can be pre-implemented in the browser or other security applications of an electronic device, or it can be loaded into the browser or other security applications of an electronic device by means of downloading. The corresponding units in system 1000 can cooperate with the units in the electronic device to implement the solution of the embodiments of this application.
[0145] The division of modules or units mentioned in the detailed description above is not mandatory. In fact, according to the embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0146] In this embodiment, the processor is a processing device capable of performing logical operations, such as a central processing unit (CPU), field-programmable array (FPGA), digital signal processor (DSP), microcontroller (MCU), application-specific logic circuit (ASIC), graphics processing unit (GPU), or other devices with data processing and / or program execution capabilities. It is readily understood that the processor is typically communicatively connected to memory, where any combination of one or more computer program products is stored. The memory can include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, erasable programmable read-only memory (EPROM), USB memory, flash memory, etc. One or more computer instructions can be stored in the memory, and the processor can execute these computer instructions to implement related analysis functions. Various applications and various data, such as various data used and / or generated by applications, can also be stored in the computer-readable storage medium.
[0147] In the embodiments of this application, each module can be implemented by the processor executing relevant computer instructions. For example, the image processing module can be implemented by the processor executing instructions for image transformation algorithms, the machine learning module can be implemented by the processor executing instructions for machine learning algorithms, and the neural network can be implemented by the processor executing instructions for neural network algorithms.
[0148] In the embodiments of this application, each module can run on the same processor or on multiple processors; each module can run on a processor of the same architecture, such as all running on x86 architecture processors, or it can run on processors of different architectures, such as the image processing module running on an x86 architecture CPU and the machine learning module running on a GPU. Each module can be packaged in a computer product, such as each module being packaged in a computer software and running on a computer (server), or each module or part of it can be packaged in different computer products, such as the image processing module being packaged in a computer software and running on a computer (server), and the machine learning modules being packaged in separate computer software and running on another or more computers (servers); the computing platform when each module executes can be local computing, cloud computing, or a hybrid computing consisting of local computing and cloud computing.
[0149] like Figure 11 As shown, the computer device is used to run the methods described above, specifically including a central processing unit (CPU) 601, which can perform various appropriate actions and processes based on a program stored in read-only memory (ROM) 602 or a program loaded from storage portion 608 into random access memory (RAM) 603. RAM 603 also stores various programs and data required for the system's operating instructions. CPU 601, ROM 602, and RAM 603 are interconnected via bus 604. Input / output (I / O) interface 605 is also connected to bus 604.
[0150] The following components are connected to I / O interface 605: an input section 606 including a keyboard, mouse, etc.; an output section 607 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to I / O interface 605 as needed. A removable medium 611, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 610 as needed so that computer programs read from it can be installed into storage section 608 as needed.
[0151] Specifically, according to embodiments of this application, the flowchart above refers to... Figure 2The described process can be implemented as a computer software program. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowchart. In such an embodiment, the computer program contains program code for performing the methods shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via communication section 609, and / or installed from removable medium 611. When the computer program is executed by central processing unit (CPU) 601, it performs the functions defined in the system of this application.
[0152] This application also provides a computer-readable storage medium storing a computer program that is executed by a processor to implement the methods described in any of the above claims.
[0153] It should be noted that the computer-readable medium shown in this application may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof.
[0154] In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wireline, optical fiber, RF, etc., or any suitable combination thereof.
[0155] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operational instructions of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two connected blocks may actually be executed substantially in parallel, or they may sometimes be executed in reverse order, depending on the functions involved.
[0156] It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified functions or operational instructions, or using a combination of dedicated hardware and computer instructions. The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed.
[0157] Those skilled in the art should understand that the scope of disclosure in this application is not limited to technical solutions formed by specific combinations of the above-mentioned technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-mentioned technical features or their equivalent features without departing from the aforementioned disclosed concept. For example, technical solutions formed by substituting the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this application.
Claims
1. A method for managing access to a computer room, characterized in that, This system is used in an access management system, which includes multiple access control modules and work cards. The access control modules are used to control the opening of computer rooms or server racks, and the work cards correspond one-to-one with biometric information. The area where the computer room is located is the first node, and the biometric identification module is set on the first node. The computer room is the second node, and the computer room access control is set on the second node. The server rack is the third node, and the server rack access control is set on the third node. The first node is set before the entry management time of the second node to generate check-in information, and the first node is set after the entry management time of the third node to generate check-out information. The second node is set before the entry management time of the third node to obtain the key used for radio frequency verification at the third node. By setting the second node on the necessary route to the third node, it is possible to determine whether the current communication key has been received each time the area where the third node is located is entered. The method includes: The biometric identification module collects the biometric information of personnel. Based on the biometric information, a communication key is issued to the work card; The work card communicates with the access control module based on the communication key to control the opening of the computer room or cabinet; The work card includes a Bluetooth module and an RF module. The system also includes a Bluetooth node communication module and an RF node communication module mounted on the access control module. The work card communicates with the access control module based on the communication key, including: The Bluetooth module establishes a Bluetooth communication connection with the Bluetooth node communication module. The work card obtains a communication key based on the Bluetooth communication connection; The radio frequency module establishes the radio frequency communication connection with the radio frequency node communication module based on the communication key; The method further includes: After the Bluetooth module completes the currently executing Bluetooth event, the work card controls the Bluetooth module to enter the corresponding sleep mode; wherein, The sleep mode includes a deep sleep mode and a shallow sleep mode. In the deep sleep mode, the Bluetooth module only listens to the Bluetooth wake-up broadcast signal, while in the shallow sleep mode, the Bluetooth module listens to all Bluetooth broadcast signals. If the work card enters deep sleep mode after the check-out information is generated, the communication key for that session will become invalid.
2. The computer room access management method according to claim 1, characterized in that, The access control module includes a computer room access control and a cabinet access control located downstream of the computer room access control. The computer room access control is used to control the opening of the computer room, and the cabinet access control is used to control the opening of the cabinet. The communication key includes an area identifier corresponding to the computer room access control and a sub-area identifier corresponding to the cabinet door.
3. The computer room access management method according to claim 1, characterized in that, The communication key is the key for this communication, wherein the step of issuing the communication key to the work card based on the biometric information includes: Based on the biometrics, obtain the permission information corresponding to the biometrics; The communication key for that session is issued to the work card based on the permission information.
4. The computer room access management method according to claim 1, characterized in that, The method further includes: The identity verification information of the person is generated based on the biometric information; the identity verification information includes check-in information and check-out information.
5. The computer room access management method according to claim 4, characterized in that, The Bluetooth module establishes a Bluetooth communication connection with the Bluetooth node communication module, including: The Bluetooth module listens to the Bluetooth wake-up broadcast signal sent by the Bluetooth node communication module, and sends a first request message to the Bluetooth node communication module based on the Bluetooth wake-up broadcast signal; Based on the received first request information, the Bluetooth node communication module establishes a Bluetooth communication connection with the Bluetooth module after confirming that the work card device identifier in the first request information corresponds to the check-in information. The work card device identifier corresponds one-to-one with the biometric information.
6. The computer room access management method according to claim 1, characterized in that, The work card controls the Bluetooth module to enter deep sleep mode, specifically including: The Bluetooth module listens to the Bluetooth sleep broadcast signal sent by the Bluetooth node communication module; and sends a second request message to the Bluetooth node communication module based on the Bluetooth sleep broadcast signal; Based on the received second request information, the Bluetooth node communication module establishes a Bluetooth communication connection with the Bluetooth module after confirming that the work card device identifier in the second request information corresponds to the sign-out information. The Bluetooth module obtains a deep sleep command sent by the Bluetooth node communication connection based on the Bluetooth communication connection. The deep sleep command is used to control the Bluetooth module to execute a deep sleep event and enter deep sleep mode.
7. The computer room access management method according to claim 1, characterized in that, The work card controls the Bluetooth module to enter a shallow sleep mode, specifically including: After the Bluetooth module performs an event other than a deep sleep event, the work card controls the Bluetooth module to enter a shallow sleep mode; The Bluetooth module periodically determines whether it receives a Bluetooth broadcast signal in the shallow sleep mode; if it does not receive one, it maintains the shallow sleep mode; if it receives one, it enters the working mode.
8. A computer room access management system, characterized in that, The system, applied to the data center access management method according to any one of claims 1-7, comprises: Multiple access control modules, which are used to control the opening of the computer room or server rack; A biometric identification module, which is used to collect biometric information of personnel; The management module is used to issue a communication key to the work card based on the biometric information; The work card, which corresponds one-to-one with the biometric information, is used to communicate with the access control module based on the communication key to control the opening of the computer room or cabinet; The work card includes a Bluetooth module and an RF module. The system also includes a Bluetooth node communication module and an RF node communication module mounted on the access control module. The work card communicates with the access control module based on the communication key, including: The Bluetooth module establishes a Bluetooth communication connection with the Bluetooth node communication module. The work card obtains a communication key based on the Bluetooth communication connection; The radio frequency module establishes the radio frequency communication connection with the radio frequency node communication module based on the communication key; The work card is also used for: After the Bluetooth module completes the currently executing Bluetooth event, the work card controls the Bluetooth module to enter the corresponding sleep mode; wherein, The sleep mode includes a deep sleep mode and a shallow sleep mode. In the deep sleep mode, the Bluetooth module only listens to the Bluetooth wake-up broadcast signal, while in the shallow sleep mode, the Bluetooth module listens to all Bluetooth broadcast signals.
Citation Information
Patent Citations
Access control management method based on identity recognition
CN110648435A
Access control system, method and device and biological key card
CN113436376A