How htp Secured an Unmanned Data Centre, From Car Park to the Server Cabinet

htp GmbH is one of Germany’s highest-performing regional carriers, serving the Hannover, Braunschweig and Hildesheim economic triangle with telephone and DSL connections, value-added services and network services for private and business customers. Its internet and data traffic services run from three of its own specially secured data centres. The largest covers 4,000 square metres, operates without staff on site, and places 1,200 square metres of usable floor space deep below ground. Access control, server cabinet release, intrusion alarm control, key management and biometric identification all run on Primion technology, through prime WebAccess and highly integrated IDT 32 controllers.

htp building

A Banking Data Centre, Built Underground

The facility was originally built by GAD, an IT service provider and software house serving around 450 banks. That purpose required a highly available, specially secured environment for the banking applications of the Volksbanken and Raiffeisenbanken, and it left behind infrastructure htp could build on. Several high-bitrate data lines connect the site to htp’s high-speed fibre network, and its redundant structure delivers very high availability.

The defining feature of the security concept is its underground construction, almost unique in the region. The 1,200 square metres of usable floor space sit deep below the surface, which protects the facility above all against external force. htp invested more than two million euros in extending and modernising the high-security concept, with the goal of achieving TÜV-IT certification at one of the highest security levels. The site already holds a certificate for the recognition of components and systems from VdS Schadenverhütung GmbH.

Three Groups of People, Nobody on Site

The requirements placed on the access management system were high. A single concept had to govern three different populations moving through the same building: htp’s customers, htp’s own personnel, and external personnel.

It also had to do that without staff on site. Because this is an unmanned data centre operated for customers, convenience and ease of use could not be sacrificed to security.

One Passive Credential for Every Barrier

htp set out a single list of requirements for the system:

  • One passive identification medium covering access control, the server rooms and server cabinets, control of the intrusion alarm system and key management
  • Unique identification of individuals by a biometric characteristic
  • An interface to the building management system
  • Constant controllability and communication with htp’s own network management centre

What the Architecture Had to Handle

prime WebAccess integrated into the existing network and database structure and met the requirements for video surveillance, remote control, logging and message forwarding.
Turnstiles, airlocks and doors are controlled by highly integrated IDT 32 access management controllers. The operating and display units for the intrusion alarm system are connected to those same controllers.

Inside the Security Area

Entry to the inner security area runs through a personnel and material airlock, where a fingerprint reader uniquely identifies the person on both entry and exit.

All turnstiles and airlocks use anti-passback, which prevents a badge being passed back or used twice and assigns each person unambiguously to one area. That makes it possible to establish at any moment who is in which security area, and it allows the intrusion alarm system to arm automatically once a sector is clear. The same area accounting feeds the building management interface, releasing lighting control and switching lighting off automatically in areas that are not in use.

Keys, Cabinets and the Audit Trail

Keys could not be eliminated entirely, so they were brought into the same system. htp personnel and external personnel take the keys they need for maintenance work from a key safe and return them there. The badge identifies the person, their profile determines what they may take and return, and the software logs it.

Individual server cabinets are handled the same way. A central reader releases rented server cabinets for the customer according to their access authorisation profile and locks them again automatically after an adjustable interval. Those events are logged in prime WebAccess too.

From the Car Park to the Server Cabinet

The result is a continuous access management system covering every stage from the car park to the server cabinet, used by htp customers and meeting the security requirements set for the site.

quote

The System, By the Numbers

4,000 m²

total data centre area under one access management system

1,200 m²

of usable floor space built deep underground

3

IDT 32 controllers running turnstiles, airlocks and doors

A Partnership That Continued Beyond the Data Centre

The result is a continuous access management system covering every stage from the car park to the server cabinet. One credential carries a person through the turnstile, the airlock, the server room and the server cabinet, with every movement logged and every key accounted for. The trust built working side by side on the data centre carried into a follow-up project for Primion at htp GmbH’s head office. For htp’s customers, the facility does what an unmanned data centre has to do: it lets them reach their own equipment, at any hour, without a single member of staff on site, and it meets the security requirements the site was built to.

Implemented Products

prime WebAccess

Protect buildings and assets from unauthorised access with flexible, reliable systems.
Type: Software
Solution: Access Control

prime SecurityManagement

A modular security management platform that integrates and controls various security systems for a scalable and automated hazard management.
Type: Software

IDT 32

Control panel for alarm monitoring, fire detection and video surveillance.
Type: Hardware
Solution: Access Control

More References