What you need to know about securing data centres

March 2011 Access Control & Identity Management, Information Security

In the mass data storage and communications industries, security and dependability are at the forefront of customers’ minds. But, firewalls and encryptions are only part of the solution. If somebody breaks into the facility and steals the server, everybody is in big trouble.

A data centre is a centralised repository, either physical or virtual, used for the storage, management, processing and dissemination of data and information organised around a particular body of knowledge or pertaining to a particular business, usually treated as a mission-critical operation or facility. Just about every company has its own data centre. A small local insurance agency calls it a computer system. The insurance conglomerate might call it the computer room. In many instances, the data centre is part of a company that provides data services to its customers.

The data centres market is an important prospect base for building contractors with growth estimated at 11% through 2014. When building their infrastructures, the design needs to provide the ability to scale and adapt to support future needs with near-zero downtime. It involves integrating IT, HVAC, lighting, fire and safety, and communications monitoring and control systems and algorithms to process and monitor data. Lastly, data centres require real-time access to local vendor technical expertise with strong reputations.

The layout of most large data centres is similar (Figure 1). There is a security/reception area that the user enters to gain access to their system. Upon check-in, they go to the lobby. From there, they go through a sally port to get into the secure common area. What this means is that, at the end of the lobby, they must be identified as authorised to enter the sally port room. Upon entering it, the door is closed. At the end of the sally port room, there is another identification authorisation performed before they can go through that door to the secure common area. At this point, they can go to their own cage or vault, where they will again be identified as authorised before going through.

Figure 1
Figure 1

Most data centres also have similar customer needs. First of all, because of their mission-critical nature, they need a high level of security. They typically have a large number of infrequent users. This is especially true of independent data centres which have large numbers of customer users who only occasionally visit the site. Therefore, the system has to be easy to use but cannot rely on cards which can be easily transferred from person to person.

For offsite storage facilities, the challenges are even greater. They require remote enrolment and multifacility management in which customers need immediate access but the security level must remain quite high.

What is meant by a security level? They range from high to low with the lowest being something you have, such as a card. Perhaps, it is an employee card that can be swiped through a magnetic stripe or proximity reader, just as at the entrance to many companies. Can another use this card? Of course, as at this level, you are only checked for what you have.

The second level of security is something you know, like a PIN number or password. It could be your mother’s maiden name or where you were born. The theory is that only you would know this. But, if you wanted to, you could tell another what your PIN or password is and they could use it. And, they would get entry, because, at this level, you are only checked for what you know.

The third level becomes trickier to fool. It checks for what you do. The most common application at this stage is to write your name and have it verified that it indeed matches the signature on file. Can your signature be forged by someone who really wants to share your access credentials? Of course!

That is why the highest level checks for things you are…in others words, a biometric. Biometrics identify people by unique human characteristics, the size and shape of the hand, a fingerprint, the voice and several aspects of the eye are some of the unique attributes that make you you and me me. A biometric access control reader compares a person’s unique characteristics against a previously enrolled image for the purpose of verification.

Since the challenge in such offsite storage and information handling facilities has been to provide employees and customers with immediate access while at the same time producing a level of security commensurate with the value of assets being protected, clearly a simple card-based system, where cards can be lost or stolen is not the answer. PINs, passwords and signatures do not help either.

Therefore, it is no surprise that, for data industry leaders, when addressing the questions of physical access control, the overwhelming answer has been biometric technology, which provides a level of security beyond that of conventional card systems by verifying the identity of the person. Hand readers and fingerprint scanners provide a level of security beyond that of conventional card system by verifying the identity of the person.

At the same time, they eliminate the burden and expense of a card-based system. Cards generally cost several dollars each and reissuing them takes time. In addition, forgotten and misplaced cards degrade the effectiveness of a security system. Today, Internet data, telecommunications and co-location facilities around the world are using biometrics for their physical access control because they offer high security and convenience.

How do biometric devices work?

For instance, the hand geometry reader simultaneously analyses more than 31 000 points and instantaneously records more than 90 separate measurements of an individual's hand, including length, width, thickness and surface area, to verify the person’s identification. In conjunction with a PIN number or swipe of a card, the registered individual can gain access to the facility.

However, the authentication process involves a one-to-one search. A live biometric presented by the user is compared to a stored sample, previously given by that individual during enrolment, and the match is confirmed. The hand geometry or fingerprint of the user is not stored in a database or on an ID card. Instead, a mathematical equation, or algorithm, is performed with points measured on the finger or hand. The template that results from this equation is all that is stored.

When the user presents an ID card or enters an assigned PIN, only that template is transmitted. When the employee presents his/her hand or finger, the reader runs the authentication process to determine if the template that is stored matches the biometric being presented. If there is a match, the person is authenticated.

Hand geometry is selected for many reasons, including:

* Easy to install and maintain.

* Field-proven in high volume applications, such as San Francisco International Airport with its up to 250 000 transactions in a day.

* Easy to enrol people and easy to use.

* Best combination of high speed and accuracy.

* Good for all population sizes and high volume applications.

* Eliminates privacy concerns.

* Integrates into existing card and access systems.

The most common way to integrate biometrics is through ‘card reader emulation’. This method is especially effective when integrating into existing card-based systems. The wiring is identical to the card reader’s wiring.

In this mode, the biometric device essentially works with the access control panel in the exact same way that a card reader does. The ‘card reader output port’ of the biometric is connected to the panel’s card reader port. When a person uses the biometric, it outputs the ID number of the individual if, and only if, they are verified.

The format of the output is consistent with the card technology used by the access control panel. Once an ID number reaches the panel, it is handled as if it came from a card reader. The determination of granting access is made by the panel. The access control panel, not the biometric, handles door control and monitoring.

Which biometric fits your application?

Hand readers and fingerprint readers cover 80% of biometric access control applications. They are complementary, as each meets specific needs in the market. When using these two technologies under a single platform, dealers, integrators and users can create technology alternatives, fitting the appropriate biometric technology to each access point.

Fingerprint readers bring biometric security to low volume applications. Fingerprint readers complement hand readers by being a low-cost biometric that is best used on doors accessed by less than 100 people. Such small user populations are where most fingerprint readers are being used successfully.

In these applications, the total number of transactions tends to be fairly low. Therefore, issues generated by the higher error rates exhibited in fingerprint technology ends up being a minor inconvenience rather than a major hassle. Yet, adding the biometric technology provides a huge increase in security over a ‘card only’ system.

For these low volume openings, cost is a key consideration and fingerprint products meet that need. For instance, a fingerprint reader is ideal for sensitive document and high value storage locations accessed by 10, 20 or 30 people. This has been a major growth area for fingerprint products. They will also squeeze into small areas, like at the door to a medical cabinet. They are best when used indoors.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
AI agents become ‘First Class Identities’
Access Control & Identity Management
AI agents are now approving transactions, accessing systems, triggering workflows, and making decisions autonomously. But uncontrolled AI agents are becoming one of the largest security gaps in modern enterprises.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Securing water infrastructure for industry and community
Access Control & Identity Management Fire & Safety Government and Parastatal (Industry)
The Badirammogo Water User Association needed a solution that could secure remote sites, reduce reliance on physical guards, and ensure uninterrupted service delivery while remaining aligned with its values and long-term strategy.

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Disconnect between confidence in identity security and operational reality
Access Control & Identity Management News & Events
New FIDO Alliance and HID study reveals gap between identity security confidence and reality; 94% of enterprises claim they can revoke employee access within 24 hours, yet 35% experienced delays or failures in the past two years.

Read more...
Paxton Solo training available to security installers
Paxton Access Control & Identity Management News & Events
Following the launch of Solo, Paxton’s brand-new access control system, the security manufacturer is rolling out dedicated Solo training sessions across South Africa to support security installers working with the system.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.