A data center security management system

By introducing two-factor access control module and work ticket management module in the data center security system, and using multiple identity authentication and time period matching, the problem of insufficient security in data center access control management is solved and higher security and reliability are achieved.

CN116311609BActive Publication Date: 2025-08-29SHENZHEN SHENPENGDA POWER GRID TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310156523.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-17
Publication Date
2025-08-29
Estimated Expiration
2043-02-17

AI Technical Summary

Technical Problem

The existing data center security system is insufficient in access control management and poses security risks.

Method used

The two-factor access control module is used for identity verification, combined with the work ticket management module, the first and second identification units are respectively authenticated, and matched with the work ticket time period to improve security.

Benefits of technology

It effectively improves the security of access control management, prevents operators from passing access control during non-working hours, and enhances the overall security of the data center.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116311609B_ABST
    Figure CN116311609B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of security and discloses a data center security management system, comprising a dual-factor access control module and a work ticket management module; the work ticket management module is used to issue electronic work tickets, which include the start time and end time of the work; the dual-factor access control module comprises a first identification unit, a second identification unit, and an unlocking unit; the first identification unit is used to authenticate an operator using a first authentication method; the second identification unit is used to authenticate the operator using a second authentication method after the operator passes the authentication of the first identification unit; the unlocking unit is used to determine whether the operator's entry time falls between the start time and the end time of the work after the operator passes the authentication of the second identification unit, and if so, to open the corresponding door. The present invention improves the security of access control management in data centers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security, and in particular to a data center security management system. Background Art

[0002] Data centers typically occupy a single room, one or more floors, or even the entire building. They house a wide variety of computer equipment, necessitating stringent security management. Data center security encompasses both personnel and equipment security. Existing data center security systems typically rely solely on a single authentication method for access control, resulting in inadequate security and potential safety risks. Summary of the Invention

[0003] The purpose of the present invention is to disclose a data center security management system to solve the problem of how to improve the security of the access control of the data center.

[0004] In order to achieve the above object, the present invention adopts the following technical solutions:

[0005] A data center security management system, including a dual-factor access control module and a work ticket management module;

[0006] The work ticket management module is used to issue electronic work tickets, which include the start time and end time of the work, the name of the operator, the specific content of the work and the location of the work;

[0007] The dual-factor access control module includes a first identification unit, a second identification unit, and an unlocking unit;

[0008] The first identification unit is used to authenticate the operator using a first identity authentication method;

[0009] The second identification unit is used to authenticate the operator using a second identity authentication method after the operator passes the identity authentication of the first identification unit;

[0010] The unlocking unit is used to communicate with the work ticket management module after the operator passes the identity authentication of the second identification unit, and determine whether the operator's entry time is between the start time and the end time of the work. If so, the corresponding door is opened.

[0011] Preferably, the first identity authentication method includes: reading information from the access card carried by the operator, and determining whether the password stored in the access card is consistent with the password stored in the first identification unit. If they are consistent, it means that the operator has passed the identity authentication of the first identification unit.

[0012] Preferably, it also includes a storage module, which is used to store the biometric information of the operator.

[0013] Preferably, the biometric information includes fingerprint images and face images.

[0014] Preferably, the second identity verification method includes:

[0015] Acquire the operator's fingerprint image;

[0016] A first similarity between the acquired fingerprint image and the fingerprint image stored in the storage module is calculated. If the first similarity is greater than a set first similarity threshold, it indicates that the operator has passed the identity authentication of the second recognition unit.

[0017] Preferably, the second identity verification method includes:

[0018] Acquire the operator's facial image;

[0019] A second similarity between the acquired facial image and the facial image stored in the storage module is calculated. If the second similarity is greater than a set second similarity threshold, it indicates that the operator has passed the identity authentication of the second recognition unit.

[0020] Preferably, it also includes a cabinet remote unlocking module;

[0021] The cabinet remote unlocking module is used to remotely open the cabinet door when authorized operators are performing cabinet maintenance.

[0022] Preferably, it also includes an intelligent monitoring module;

[0023] The intelligent monitoring module is used to detect intrusion by people walking in the data center.

[0024] Preferably, it also includes an alarm module, which is used to issue a warning notification when the intelligent monitoring module detects an intrusion event.

[0025] Preferably, it also includes a report management module;

[0026] The report management module is used to collect statistics on intrusion events and generate intrusion reports.

[0027] Compared to existing technologies, this invention uses two different identity recognition methods for access control management, effectively improving access control security. Furthermore, access control management is linked to work tickets, preventing operators from passing through the access control during non-working hours, further improving data center security. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] The drawings described herein are used to provide further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute improper limitations on the present application.

[0029] Figure 1 This is a schematic diagram of a data center security management system according to the present invention.

[0030] Figure 2 A schematic diagram of the dual-factor access control module of the present invention. DETAILED DESCRIPTION

[0031] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative work are within the scope of protection of the present application. In addition, unless otherwise specified (for example, "or in addition" or "or in an alternative"), the term "or" as used herein refers to a non-exclusive "or" (that is, "and / or"). Furthermore, the various embodiments described herein are not necessarily mutually exclusive, because some embodiments can be combined with one or more other embodiments to form new embodiments.

[0032] like Figure 1 In one embodiment shown, the present invention provides a data center security management system, including a dual-factor access control module and a work ticket management module;

[0033] The work ticket management module is used to issue electronic work tickets, which include the start time and end time of the work, the name of the operator, the specific content of the work and the location of the work;

[0034] like Figure 2 As shown, the dual-factor access control module includes a first identification unit, a second identification unit and an unlocking unit;

[0035] The first identification unit is used to authenticate the operator using a first identity authentication method;

[0036] The second identification unit is used to authenticate the operator using a second identity authentication method after the operator passes the identity authentication of the first identification unit;

[0037] The unlocking unit is used to communicate with the work ticket management module after the operator passes the identity authentication of the second identification unit, and determine whether the operator's entry time is between the start time and the end time of the work. If so, the corresponding door is opened.

[0038] Compared to existing technologies, this invention uses two different identity recognition methods for access control management, effectively improving access control security. Furthermore, access control management is linked to work tickets, preventing operators from passing through the access control during non-working hours, further improving data center security.

[0039] Preferably, the first identity authentication method includes: reading information from the access card carried by the operator, and determining whether the password stored in the access card is consistent with the password stored in the first identification unit. If they are consistent, it means that the operator has passed the identity authentication of the first identification unit.

[0040] Preferably, it also includes a storage module, which is used to store the biometric information of the operator.

[0041] Preferably, the biometric information includes fingerprint images and face images.

[0042] Preferably, the second identity verification method includes:

[0043] Acquire the operator's fingerprint image;

[0044] A first similarity between the acquired fingerprint image and the fingerprint image stored in the storage module is calculated. If the first similarity is greater than a set first similarity threshold, it indicates that the operator has passed the identity authentication of the second recognition unit.

[0045] Preferably, calculating the first similarity between the acquired fingerprint image and the fingerprint image stored in the storage module includes:

[0046] Performing enhancement processing on the acquired fingerprint image to obtain an enhanced image;

[0047] Calculate the similarity between the enhanced image and each fingerprint image stored in the storage module respectively;

[0048] The similarity with the largest value is taken as the first similarity.

[0049] Preferably, performing enhancement processing on the acquired fingerprint image to obtain an enhanced image includes:

[0050] Convert the acquired fingerprint image into Lab color space;

[0051] Use the following function to filter the pixels in the image of the L component in the Lab color space:

[0052]

[0053] Wherein, L(x,y) is the pixel value of the pixel at (x,y) in the image of the L component, thrs1 and thrs2 represent the set first comparison threshold and second comparison threshold respectively; L w (x, y) is the mean value of the pixel values ​​within the range of Q×Q centered at the pixel at (x, y); ma means obtaining the larger value in the brackets.

[0054] Save the pixel points that meet the above function to the set shet;

[0055] Use the following function to perform the promotion process:

[0056]

[0057] Among them, fL p is the pixel value after the pixel p in the set shet is lifted, λ is the scale parameter, L p is the pixel value of the pixel point p in shet before the lifting process, nsi is the set of pixels within the range of Q×Q centered on the pixel point p, and L q is the pixel value of pixel q, wgt q is the lifting coefficient of pixel q, dist p,q is the Euclidean distance between pixel p and pixel q,

[0058] The lifted image fL is converted to RGB color space to obtain a lifted image.

[0059] During the lifting process, the present invention first uses a function to filter out a set of pixels that need to be lifted, and then lifts the pixels in the set, avoiding lifting all pixels and improving the efficiency of the lifting process. In the lifting function, the weighted result of the pixel values ​​of the pixels surrounding the pixel point p is used as a reference, and the weighted result is combined with the result before the process using a scale parameter to obtain the lifted result. Because the information of the surrounding pixels is referenced, the pixel values ​​of the pixels after the lifting are more evenly distributed, thereby improving the quality of the image and thus improving the accuracy of the similarity calculation result.

[0060] Preferably, the second identity verification method includes:

[0061] Acquire the operator's facial image;

[0062] A second similarity between the acquired facial image and the facial image stored in the storage module is calculated. If the second similarity is greater than a set second similarity threshold, it indicates that the operator has passed the identity authentication of the second recognition unit.

[0063] Preferably, it also includes a cabinet remote unlocking module;

[0064] The cabinet remote unlocking module is used to remotely open the cabinet door when authorized operators are performing cabinet maintenance.

[0065] Preferably, it also includes an intelligent monitoring module;

[0066] The intelligent monitoring module is used to detect intrusion by people walking in the data center.

[0067] Preferably, the storage module is also used to store facial images of daily staff members of the data center.

[0068] Daily staff are different from operators. Daily staff are people who work in the data center for a long time, while operators are generally people who are allowed to enter the data center only when installation, maintenance and other operations are required.

[0069] Preferably, intrusion detection is performed on people walking around the data center, including:

[0070] Acquire facial images of people walking around the data center;

[0071] The acquired facial image is compared with the facial images of the operator and routine staff stored in the storage module. If the acquired facial image is neither the facial image of the operator nor the facial image of the routine staff, it means that an intrusion event is detected.

[0072] Preferably, it also includes an alarm module, which is used to issue a warning notification when the intelligent monitoring module detects an intrusion event.

[0073] Preferably, it also includes a report management module;

[0074] The report management module is used to collect statistics on intrusion events and generate intrusion reports. The intrusion report includes the location, time, name of the person who handled the intrusion, and the handling record.

[0075] In addition, the report management module is also used to collect statistics on the opening of access control doors and generate access control reports.

[0076] The above is only an implementation method of the present application and does not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the description and drawings of this application, or directly or indirectly used in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A data center security management system, characterized in that: Including dual-factor access control module and work ticket management module; The work ticket management module is used to issue electronic work tickets, which include the start time and end time of the work, the name of the operator, the specific content of the work and the location of the work; The dual-factor access control module includes a first identification unit, a second identification unit, and an unlocking unit; The first identification unit is used to authenticate the operator using a first identity authentication method; The second identification unit is used to authenticate the operator using a second identity authentication method after the operator passes the identity authentication of the first identification unit; The unlocking unit is used to communicate with the work ticket management module after the operator passes the identity authentication of the second identification unit, and determine whether the operator's entry time is between the start time and the end time of the work. If so, the corresponding door is opened; It also includes a storage module, the storage module is used to store the biometric information of the operator; Biometric information includes fingerprint images and facial images; Secondary identity verification methods include: Obtaining the operator's fingerprint image; Calculating a first similarity between the acquired fingerprint image and the fingerprint image stored in the storage module, and if the first similarity is greater than a set first similarity threshold, it indicates that the operator has passed the identity authentication of the second recognition unit; Calculating a first similarity between the acquired fingerprint image and the fingerprint image stored in the storage module includes: Performing enhancement processing on the acquired fingerprint image to obtain an enhanced image; Calculate the similarity between the enhanced image and each fingerprint image stored in the storage module respectively; The similarity with the largest value is taken as the first similarity; Performing enhancement processing on the acquired fingerprint image to obtain an enhanced image, including: Convert the acquired fingerprint image into Lab color space; Use functions to filter pixels in the image of the L component in the Lab color space, including: Use the following function to filter the pixels in the image of the L component in the Lab color space: in, In the image with L component The pixel value of the pixel at and Respectively represent the set first comparison threshold and the second comparison threshold; For The pixel at the center is The mean pixel value of the pixel points within the range of ; Indicates getting the larger value in the brackets. Save the pixels that meet the function to the collection ; right The pixels in the image are enhanced, including: in, For collection Pixels in The pixel value after the lifting process, is the scale parameter, for Pixels in Pixel value before lifting, Pixels centered, The set of pixels within the range of Pixel The pixel value of Pixel The improvement factor, , Pixel and pixels The Euclidean distance between ; The processed image will be enhanced Convert to RGB color space to get the enhanced image.

2. A data center security management system according to claim 1, characterized in that: The first identity authentication method includes: reading information from the access card carried by the operator, and determining whether the password stored in the access card is consistent with the password stored in the first identification unit. If they are consistent, it means that the operator has passed the identity authentication of the first identification unit.

3. A data center security management system according to claim 1, characterized in that: Secondary identity verification methods include: Acquire the operator's facial image; A second similarity between the acquired facial image and the facial image stored in the storage module is calculated. If the second similarity is greater than a set second similarity threshold, it indicates that the operator has passed the identity authentication of the second recognition unit.

4. A data center security management system according to claim 1, characterized in that: Also includes a cabinet remote unlock module; The cabinet remote unlocking module is used to remotely open the cabinet door when authorized operators are performing cabinet maintenance.

5. A data center security management system according to claim 1, characterized in that: It also includes an intelligent monitoring module; The intelligent monitoring module is used to detect intrusion by people walking in the data center.

6. A data center security management system according to claim 5, characterized in that: It also includes an alarm module, which is used to issue a warning notification when the intelligent monitoring module detects an intrusion event.

7. A data center security management system according to any one of claim 6, characterized in that: Also includes report management module; The report management module is used to collect statistics on intrusion events and generate intrusion reports.

Citation Information

Patent Citations

  • Transformer substation service self-service handling method and device

    CN110246249A

  • Power cabinet monitoring and control system and method based on Internet of Things

    CN110855776A

  • Access control dynamic authorization system and method

    CN114022990A