Rack Access Control via Dual-Task Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems for physically secured racks in data centers often rely on permanently defined codes or keys that can be compromised or stolen, allowing unauthorized access due to lack of multi-factor authentication.

Innovation Solution

A method that requires both a personal access identification and an order identification, generated by an independent key computer system, to authorize access to a rack, ensuring that access is restricted to specific individuals and documented for traceability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If permanently defined codes or keys are used for access control, then access authorization is simple to implement, but security is compromised as codes can be stolen or passed to unauthorized persons

Engineering Contradiction:
Improveaccess authorizationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access control system segments the authorization process into multiple independent factors: personal identification (e.g., biometric data), job identification (temporary code), and rack identification. Each factor serves a distinct security function, and all must be presented together for access. This segmentation prevents any single factor from being sufficient for unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary access control unit that verifies all identification factors before granting access. This intermediary validates the personal ID, job ID, and rack ID independently, preventing direct access even if some factors are compromised. The intermediary ensures that stolen or passed codes cannot alone enable unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple access factors are required for authorization, then security is enhanced, but access control system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control unit is designed as a universal device that handles multiple identification types (biometric, card, PIN) and multiple verification factors (personal ID, job ID, rack ID) through a single integrated interface. This multi-functionality reduces the need for separate systems for each factor, managing complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary verification of all identification factors before access is granted. The access control unit pre-validates the personal ID, job ID, and rack ID combination, and only then activates the access mechanism. This preliminary action streamlines the access process by consolidating verification steps before the actual access decision.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If job-specific temporary access codes are used, then access traceability is improved, but the access process becomes more time-consuming

Engineering Contradiction:
Improveaccess traceabilityVSAvoidaccess process
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system uses temporary job identification codes that are digital copies or representations of authorized access rights. These codes can be electronically generated, distributed, and verified instantly without physical media exchange. The digital nature of these copies enables rapid verification while maintaining complete traceability through electronic logging of each code's issuance and use.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3103057B1Method for accessing a physically secured rack and computer network infrastructure
Publication Date: 2019.11.06 FUJITSU SIEMENS COMP GMBH
  • EP3103057B1 patent drawingFigure 1

AI summary

The invention relates to a method for accessing a physically secured rack (1). A task identification (task-PIN) is assigned by means of a key computer system (2) and specifies a task for access to the rack (1) to an administrator (A, B, C, D). The task identification (task-PIN) is subsequently transmitted to the administrator (A, B, C, D) and to an access control unit (4) for the rack (1). In addition, a query and verification of the task identification (task-PIN) is carried out and a query and verification of a personal access identification (ID) of the administrator (A, B, C, D) is carried out by the access control unit (4). A physical security access system for the rack (1) is released in the case where both previously mentioned verification steps were successful. The method has the advantage that access to the rack (1) is not exclusively possible through an entity (Administrator) outside of the rack (1), but instead must be additionally authorized by an entity at or in the rack (1) (access control unit) on the basis of identification assigned specifically for the task.