Server Room Management System and User Guidance Method in Server Rooms
Patent Information
- Application Number
- JP2025023204
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2026-08-27
AI Technical Summary
【0008】 本開示によれば、サーバルーム内における機密管理を強化できる。
Smart Images

Figure 2026137248000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a server room management system and a method for guiding users in a server room.
Background Art
[0002] Japanese Patent Application Laid-Open No. 2019-192123 (Patent Document 1) discloses an admission management system for managing admission to a data center.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0004] Generally, a large number of server racks are arranged in a server room installed in a large-scale data center or the like. The inventors of the present invention have focused on the fact that the following problems may occur in a server room. For each server rack, the group (typically a company) to which the user who uses the server rack belongs may be different. That is, a situation may occur in which a plurality of users belonging to different groups work in the same server room. Therefore, it is desirable to strengthen confidential management in the server room.
[0005] The present disclosure has been made to solve the above problems, and one of the objects of the present disclosure is to strengthen confidential management in a server room.
Means for Solving the Problems
[0006] A server room management system according to one aspect of this disclosure includes a management device that generates commands for controlling equipment installed in a server room based on entry information from an access control system for a server room in which multiple server racks are arranged. The server room includes a guidance device that guides users within the server room according to route commands generated by the management device. If the entry information indicates that a second user, who belongs to a different organization than the first user, enters the server room after the first user has entered the server room, the management device generates a route command that bypasses the first server rack assigned to the first user, allowing the second user to move to the second server rack assigned to the second user.
[0007] A user guidance method in a server room according to another aspect of the present disclosure is a user guidance method in a server room in which a plurality of server racks are arranged, comprising the steps of detecting by an access control system that a second user enters the server room after a first user has entered the server room, and guiding the second user by a guidance device if the organizations to which the first user and the second user belong are different. The guidance step includes guiding the second user such that the route for the second user to move to the second server rack assigned to the second user bypasses the first server rack assigned to the first user. [Effects of the Invention]
[0008] According to this disclosure, confidentiality management within the server room can be enhanced. [Brief explanation of the drawing]
[0009] [Figure 1] This figure shows an example of the overall configuration of a server room management system according to an embodiment of the present disclosure. [Figure 2] This figure shows an example of a server room configuration. [Figure 3] This figure shows an example of the hardware configuration of the management server. [Figure 4] This figure shows an example of rack information. [Figure 5] This figure shows an example of user information. [Figure 6] This figure shows an example of the hardware configuration of an access control system. [Figure 7] This figure shows an example of authentication information. [Figure 8] This is a diagram illustrating user guidance in this embodiment. [Figure 9] This diagram illustrates an example of user guidance using multiple projection devices. [Figure 10] This is a diagram illustrating the rotation of a server rack. [Figure 11] This flowchart shows an example of the processing procedure related to user guidance in this embodiment. [Modes for carrying out the invention]
[0010] This embodiment will be described in detail below with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals, and their descriptions will not be repeated.
[0011] [Embodiment] <System Configuration> Figure 1 shows an example of the overall configuration of a server room management system according to an embodiment of the present disclosure. The server room management system 100 includes a management server 1, an access control system 2, and an equipment control device 3. Two or more equipment control devices 3 and two or more server rooms 4 may be provided. The management server 1, the access control system 2, and each equipment control device 3 are connected to each other via a network NW so that they can communicate with one another.
[0012] The management server 1 generates a command for controlling various devices provided in the server room 4 based on the entry / exit information (entry information or exit information) from the entry / exit management system 2. The management server 1 corresponds to the "management device" according to the present disclosure. The entry / exit management system 2 manages the entry and exit of users to and from the server room 4. Each device control device 3 controls various devices (described later) in the server room 4 according to a command from the management server 1.
[0013] FIG. 2 is a diagram showing an example of the configuration of the server room 4. In the server room 4, a plurality of server racks 5, a plurality of projection devices 6, a plurality of floor modules 7, and a plurality of short-range wireless communication devices 8 are provided. In this example, the plurality of server racks 5 includes six server racks 51 to 56, but the number of server racks is not particularly limited. The device control device 3 includes a processor 31 and a memory 32 and controls each of these devices.
[0014] Each of the plurality of server racks 5 is assigned to any organization (in the following example, a company). When the server rack 52 is assigned to the company D1, the first user U1 (typically an employee of the company D1) belonging to the company D1 has the authority to use the server rack 52. For example, the first user U1 connects his / her own terminal (such as a personal computer) to the server rack 52 and performs various operations on the server rack 52 (maintenance operations, software update operations, etc.).
[0015] Each of the plurality of server racks 5 may include a lock mechanism (not shown) and be configured to unlock according to an unlocking command. Each of the plurality of server racks 5 may include a rotation mechanism (such as a rotating table, not shown) and be configured to rotate according to a rotation command from the device control device 3. In this case, the direction in which each server rack 5 faces is determined by the rotation command.
[0016] A plurality of projection devices 6 are installed, for example, on the ceiling of the server room 4. Each of the plurality of projection devices 6 projects one or more images for guiding (guiding) users in the server room onto the plurality of floor modules 7 according to a command from the device control device 3. The guidance of users will be described in detail later. Each projection device 6 corresponds to an example of the "guidance device" according to the present disclosure.
[0017] The plurality of floor modules 7 are installed on the floor surface of the server room 4. Each of the plurality of floor modules 7 includes a sensor (for example, a load sensor) for detecting a user on that module. Each floor module 7 transmits the detection result of the sensor to the device control device 3. Thereby, the device control device 3 can specify the current position of the user. The device control device 3 transmits the current position of the user to the management server 1.
[0018] The plurality of floor modules 7 may include a display or a light emitting element (not shown) and may be configured to guide a user according to a command from the device control device 3. In this case, each floor module 7 corresponds to another example of the "guidance device" according to the present disclosure.
[0019] Each of the plurality of short-range wireless communication devices 8 is configured to wirelessly communicate with a mobile terminal MT (typically a smartphone) held by a user (in this example, the second user U2) working inside the server room 4. The device control device 3 can specify the position of the mobile terminal MT (that is, the current position of the second user U2) according to which of the plurality of short-range wireless communication devices 8 has received the radio wave from the mobile terminal MT. The device control device 3 transmits the current position of the user to the management server 1.
[0020] FIG. 3 is a diagram showing an example of the hardware configuration of the management server 1. The management server 1 includes a processor 11, a memory 12, an input device 13, a display 14, a communication interface 15, and a database 16.
[0021] The processor 11 is, for example, a CPU (Central Processing Unit) and is configured to execute predetermined arithmetic operations according to a program. The memory 12 includes ROM (Read Only Memory), RAM (Random Access Memory), and HDD (Hard Disk Drive), and stores the program executed by the processor 11 and various data used by that program (maps, relational expressions, parameters, etc.). The input device 13 is a keyboard, mouse, etc., and accepts user input. The display 14 displays various information to the user. The communication interface 15 is configured to communicate with an external device (such as the device control unit 3).
[0022] In this specification, the term "processor" is not limited to processors that execute processing using stored-program methods, but may also include hardwired circuits such as ASICs (Application Specific Integrated Circuits) and FPGAs (Field-Programmable Gate Arrays). Therefore, the term "processor" can also be interpreted as processing circuitry in which processing is predefined by computer-readable code and / or hardwired circuits.
[0023] Database 16 stores rack information 161, user information 162, and registration information 163.
[0024] Figure 4 shows an example of rack information 161. In this example, rack information 161 includes, for each server rack, the rack ID (unique identification number) of the server rack, the installation location of the server rack (server room name), and the installation position of the server rack (coordinates within the server room).
[0025] Figure 5 shows an example of user information 162. In this example, user information 162 includes, for each user, the user's user ID (unique identification number) and the user's affiliation (company name, company identification number, etc.).
[0026] Returning to Figure 3, registration information 163 is information that links rack information 161 and user information 162 to each other. Registration information 163 defines which users have the authority to use which server racks.
[0027] Figure 6 shows an example of the hardware configuration of the access control system 2. The access control system 2 includes a processor 21, memory 22, input device 23, display 24, communication interface 25, and database 26. The database 26 stores authentication information 261 for authenticating users entering the server room 4. The other hardware configurations of the access control system 2 are basically the same as those of the management server 1 (see Figure 3).
[0028] Figure 7 shows an example of authentication information 261. Authentication information 261 includes, for example, a user ID, an authentication image, and a terminal ID. The authentication image is, for example, an image of the user for facial recognition. Authentication information 261 may also include other biometric information of the user (information about fingerprints, iris, vein, voiceprint, etc.) instead of the authentication image. The terminal ID is unique identification information relating to the mobile terminal MT (see Figure 2) possessed by the user.
[0029] <Secret management> The inventors focused on the following potential challenges that can arise within a server room. Generally, server rooms contain server racks used by various companies. As a result, situations can arise where multiple users from different companies work in the same server room. Therefore, it is desirable to strengthen confidentiality management within the server room. In this embodiment, when two or more users work in the server room, users who enter the server room later are guided to prevent the leakage of confidential information from users who entered the server room earlier.
[0030] Figure 8 is a diagram illustrating user guidance in this embodiment. In the example shown in Figure 8, it is assumed that a first user U1 has already entered the server room 4 and is working at server rack 52 when a second user U2 enters the server room 4. The second user U2 has just entered through door D, which is located at the entrance to the server room 4, and server rack 56, which is far from door D, is assigned to the second user U2. Server rack 52 corresponds to the "first server rack" in this disclosure, and server rack 56 corresponds to the "second server rack" in this disclosure.
[0031] When the second user U2 moves from door D to server rack 56, it is conceivable that the first user U1 could guide the second user U2 along route RA (shown as a dashed line in the figure), which passes near server rack 52 where the first user U1 is working. However, in that case, the second user U2 could see the status of server rack 52 where the first user U1 is working, as well as the information on the screen of the terminal used by the first user U1, and the possibility that corporate secrets of the company to which the first user U1 belongs (including the details of the first user U1's work) could be leaked to the second user U2 cannot be ruled out.
[0032] In this embodiment, the management server 1 generates a route command such that the route for the second user U2 to move from door D to server rack 56 bypasses server rack 52, which is assigned to the first user U1. More specifically, the management server 1 sets route RB (shown as a solid line in the figure) instead of route RA. When moving according to route RB, the second user U2 moves in the order of server rack 51 - server rack 54 - server rack 55 - server rack 56, and therefore does not pass near server rack 52. Thus, the leakage of the first user U1's corporate secrets to the second user U2 can be suppressed.
[0033] ≪Projection of the Root≫ When the management server 1 guides the second user U2 to take the route RB, it may project an image indicating the route RB onto the floor of the server room 4 using multiple projection devices 6.
[0034] Figure 9 is a diagram illustrating an example of user guidance using multiple projection devices 6. Figure 9 shows a top view of the server room 4 floor as seen from above. The image 61 for guiding the second user U2 may be an image of an arrow indicating the direction the second user U2 should go. Image 61 is not limited to an arrow shape and may be any shape (for example, a simple straight line). Image 61 may be illuminated sequentially to clearly indicate the direction the second user U2 should go. In Figure 9, illuminated arrows are shown with solid lines, and unlit arrows are shown with dashed lines.
[0035] Other devices besides the projection device 6 may be used to display the image 61. For example, displays or light-emitting elements (not shown) may be provided as guide lights on multiple floor modules 7 laid out on the floor.
[0036] Furthermore, it is possible to detect that the second user U2 has moved across multiple floor modules 7 using position detection sensors (e.g., load sensors) provided on each floor module 7. The management server 1 may generate an unlocking command to unlock the server rack 56 when the second user U2 moves across multiple floor modules 7 in accordance with the guidance. In other words, the management server 1 may leave the server rack 56 unlocked if the user moves without following the guidance.
[0037] ≪Rotation of server racks≫ As mentioned above, each of the server racks 5 is configured to be rotatable. The management server 1 may generate a rotation command so that the target server rack rotates by the required angle.
[0038] Figure 10 is a diagram illustrating the rotation of a server rack. In the example shown in Figure 10, the management server 1 generates a rotation command so that server rack 56, assigned to the second user U2, faces in a direction that is not visible from server rack 52. In other words, the management server 1 intentionally creates a blind spot by rotating server rack 56. This prevents the first user U1 from seeing the work of the second user U2 when looking from server rack 52 towards server rack 56.
[0039] Although not shown in the diagram, the management server 1 may rotate server rack 52 assigned to the first user U1 in place of or in addition to server rack 56. This prevents the second user U2 from seeing the work of the first user U1 when looking from server rack 56 towards server rack 52.
[0040] <User guidance process flow> Figure 11 is a flowchart showing an example of a user guidance process in this embodiment. In the figure, the processes executed by the management server 1 are shown on the left, and the processes executed by the access control system 2 are shown on the right. These processes are executed when predetermined conditions are met (usually when a user enters the server room). Each step is implemented by software processing by the management server 1 (processor 11) or the access control system 2 (processor 21), but may also be implemented by hardware (electrical circuits) located within the management server 1 or the access control system 2. Hereinafter, each step will be abbreviated as S.
[0041] Referring to Figures 1, 2, and 11, in S201, the access control system 2 authenticates the user who has requested entry into server room 4. Hereinafter, this user will be referred to as the "target user". The access control system 2 permits the target user to enter server room 4 only if both the target user's biometric authentication and the terminal authentication of the mobile device the target user possesses are obtained.
[0042] Biometric authentication may include, for example, facial recognition, but could also include fingerprint recognition, iris recognition, vein recognition, or voiceprint recognition. Terminal authentication may include, for example, 2D barcode authentication. Each user's mobile terminal is pre-registered in the access control system 2. The access control system 2 provides a 2D barcode to the mobile terminal based on the terminal's identification information (terminal ID). Each user authenticates their mobile terminal by holding the 2D barcode displayed on the mobile terminal towards the camera of the access control system 2. Terminal authentication is not limited to 2D barcode authentication; it may also use authentication using short-range wireless communication or authentication using RFID (Radio Frequency Identification). By having the access control system 2 perform both biometric and terminal authentication, the confidentiality of the server room 4 can be further enhanced. However, the access control system 2 may perform only one of biometric or terminal authentication.
[0043] When the access control system 2 grants permission for a target user to enter server room 4, it sends access information (such as a user ID) identifying the target user to the management server 1. The management server 1 retrieves the access information, including the target user's user ID, from the access control system 2 (S101).
[0044] In S102, the management server 1 determines whether any other users besides the target user are already working in the server room. If no other users are working (NO in S102), i.e., if the target user is the first user, the management server 1 skips the subsequent processing and returns to the main routine. If other users are working (YES in S102), the management server 1 proceeds to S103.
[0045] In S103, the management server 1 determines, based on user information 162 (see Figure 5), whether the target user and other users belong to different companies. If the target user and other users (more specifically, all other users in the server room) belong to the same company (NO in S103), the management server 1 skips the subsequent processing and returns to the main routine. If the target user and other users belong to different companies (YES in S103), that is, if at least one other user belonging to a different company than the target user is present, the management server 1 proceeds to S104.
[0046] In S104, the management server 1 identifies the location of the server rack 5 assigned to the target user (hereinafter referred to as "target rack") based on the rack information 161 (see Figure 4) and registration information 163. The management server 1 has already identified the locations of the server racks 5 assigned to other users working in the server room.
[0047] In S105, the management server 1 generates a route command to specify the target user's travel route. As explained in Figure 8, this route command is designed to bypass server rack 5 (server rack 52 in the example in Figure 8) where another user is working. The management server 1 transmits the route command to the equipment control device 3.
[0048] In S106, the management server 1 generates a rotation command so that the target rack faces in a direction that is not visible from other users' server racks (see Figure 10). The management server 1 transmits the rotation command to the equipment control device 3.
[0049] In S107, the management server 1 obtains the current location of the target user. The management server 1 may obtain the current location of the target user identified by the device control unit 3. The device control unit 3 may identify the current location of the target user based on the detection results of location detection sensors provided in each of the multiple floor modules 7. Alternatively, the device control unit 3 may identify the current location of the target user depending on which of the multiple short-range wireless communication devices 8 is receiving radio waves from the mobile terminal MT. The device control unit 3 may also identify the current location of the target user using a surveillance camera (not shown) installed in the server room. Instead of obtaining the current location of the target user from the device control unit 3, the management server 1 may identify the current location of the target user itself.
[0050] In S108, the management server 1 generates an image command to display an image (see Figure 9) on the floor that guides the target user from their current location to the target rack. The management server 1 transmits the image command to the equipment control device 3.
[0051] In S109, the management server 1 determines whether the target user has arrived at the target rack, that is, whether the guidance of the target user has been completed. If the guidance of the target user has not been completed (NO in S109), the management server 1 returns the process to S107. This allows the guidance of the target user to continue. Once the guidance of the target user is complete (YES in S109), the management server 1 terminates the series of processes.
[0052] As described above, in this embodiment, when a target user enters the server room, if another user is working there and that other user belongs to another company, the target user's movement route is generated to bypass the server rack assigned to that other user. This reduces the possibility of confidential information of that other user being leaked to the target user. Therefore, according to this embodiment, confidential information management within the server room can be strengthened.
[0053] In this embodiment, a configuration in which the management server 1, access control system 2, and equipment control device 3 are provided separately has been described (see Figures 1 and 2). However, the management server 1 may be integrated with the access control system 2, or the management server 1 may be integrated with the equipment control device 3, or the three devices may be integrated together.
[0054] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of this disclosure is indicated by the claims rather than by the description of the embodiments above, and all modifications within the meaning and scope equivalent to the claims are intended to be included. [Explanation of Symbols]
[0055] 100 Server room management system, 1 Management server, 2 Access control system, 3 Equipment control device, 4 Server room, 5, 51-56 Server racks, 6 Projection device, 7 Floor module, 8 Short-range wireless communication device, 11, 21, 31 Processor, 12, 22, 32 Memory, 13, 23 Input device, 14, 24 Display, 15, 25 Communication interface, 16, 26 Database, 161 Rack information, 162 User information, 163 Registration information, 261 Authentication information, 61 Image.
Claims
1. The system includes a management device that generates commands for controlling equipment installed in a server room based on access control information from an access control system for a server room where multiple server racks are located. The server room includes a guidance device that guides users within the server room according to route commands generated by the management device. A server room management system comprising: a management device that, when the entry information indicates that a second user belonging to a different organization than the first user enters the server room after the first user has entered the server room, generates a route command such that the route for the second user to move to the second server rack assigned to the second user bypasses the first server rack assigned to the first user.
2. Each of the aforementioned server racks is configured to rotate according to a rotation command generated by the management device. The server room management system according to claim 1, wherein the management device generates the rotation command such that the second server rack faces in a direction that is not visible from the first server rack.
3. The server room management system according to claim 2, wherein the management device generates the rotation command such that the first server rack faces in a direction that it cannot be seen from the second server rack.
4. The guidance device is configured to project images for guiding the second user onto the floor of the server room. The server room management system according to any one of claims 1 to 3, wherein the management device generates a command to the guidance device to generate an image of the second user navigating around the first server rack from their current location to the second server rack.
5. The aforementioned server room is A position detection sensor that detects the location of the floor to which the second user has moved, The system includes a short-range wireless communication device for detecting the location of a mobile device held by the second user, The server room management system according to claim 4, wherein the management device acquires the current location, which is determined based on the location of the floor and the location of the mobile terminal.
6. The server room management system according to any one of claims 1 to 3, wherein the management device generates an unlocking command to unlock the second server rack when the second user moves in accordance with the guidance, and de-unlocks the second server rack when the second user does not follow the guidance.
7. The server room management system further comprises the access control system, The access control system according to any one of claims 1 to 3, wherein the access control system permits the user to enter the server room when both the user's biometric authentication and the user's mobile device authentication are obtained.
8. The aforementioned biometric authentication is facial recognition. The server room management system according to claim 7, wherein the terminal authentication is two-dimensional barcode authentication.
9. A method for guiding users in a server room where multiple server racks are arranged, The access control system detects when a second user enters the server room after a first user has entered the server room. The procedure includes the step of guiding the second user by a guidance device if the organization to which the first user belongs and the organization to which the second user belongs are different. A method for guiding a user in a server room, wherein the guiding step includes guiding the second user such that the route for the second user to move to the second server rack assigned to the second user bypasses the first server rack assigned to the first user.
Citation Information
Patent Citations
Data center navigation system
JP2012256276A
Admission management system, data center, and admission management method
JP2019192123A