IP Library Granted Patent US 11,750,602
Granted Patent B2
US 11,750,602 · App. 17/202,715 · Granted Sep 5, 2023

Orchestrating security operations using bifurcated biometric data

Inventors: Jared Frankston (Newton, MA); Barry Curran (Belfast, GB); Luke Milby (Bloomington, IL); Ashwin Anand (Acton, MA)
Assignee: Rapid7, Inc.
H04L63/0861H04L41/28H04L63/0853H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,750,602
App. No.
17/202,715
Granted
Sep 5, 2023
Kind
B2
Abstract

Disclosed herein are methods, systems, and processes for facilitating security orchestration, automation, and response (SOAR) in cybersecurity computing environments that use biometric data or implement biometric data gathering. An instruction is periodically transmitted to a protected computing device to perform a security scanning operation that captures biometric data generated from a biometric device associated with the protected computing device. The biometric data received from the protected computing device includes a biometric identity of a trusted user or an untrusted user. A security database is accessed to determine whether the biometric identity matches a stored biometric identity of the trusted user. A security workflow that includes orchestrated security operations configured to identify the untrusted user and to prevent the untrusted user from accessing the protected computing device if the biometric identity does not match the stored biometric identity is generated and transmitted to the protected computing device. A confirmation is received from the protected computing device that the orchestrated security operations have been performed.

Claims (56)

1. A computer-implemented method, comprising:

transmitting, from a security server, a periodic instruction to a protected computing device to perform a security scanning operation that captures biometric data generated, at least in part, from a facial recognition device associated with the protected computing device;

receiving an indication from the protected computing device that the biometric data comprises bifurcated biometric data with a plurality of parts of a biometric facial identity captured from the facial recognition device and that only a part of plurality of parts of the biometric facial identity comprised in the bifurcated biometric data is stored locally by the protected computing device;

sending a request to the protected computing device to only transmit, to the security server, one or more other parts of the biometric facial identity other than the part of the plurality of parts of the biometric facial identity;

accessing a security database to determine whether at least one part of the one or more others parts of the biometric facial identity matches at least a portion of the bifurcated biometric data that is not stored locally by the protected computing device and is stored remotely;

generating a security workflow comprising a plurality of orchestrated security operations configured to prevent access to the protected computing device if the at least one part of the one or more other parts of the biometric facial identity does not match at least the portion of the bifurcated biometric data that is stored remotely;

transmitting the security workflow to the protected computing device; and

receiving confirmation from the protected computing device that the plurality of orchestrated security operations have been performed.

2. The computer-implemented method of claim 1 , further comprising:

determining that the at least one part of the one or more parts of the biometric facial identity does not match at least the portion of the bifurcated biometric data that is stored remotely is part of a malicious biometric identity.

3. The computer-implemented method of claim 1 , wherein

each of the plurality of parts of the biometric facial identity comprise at least a partial facial identity or a partial retinal identity.

4. The computer-implemented method of claim 3 , wherein

the security workflow is generated based on a vulnerability level assigned to each partial facial identity and each partial retinal identity of the plurality of parts of the biometric facial identity either individually, or to one or more combinations of partial facial identities or partial retinal identities.

5. The computer-implemented method of claim 1 , further comprising:

upon receiving confirmation from the protected computing device that the plurality of orchestrated security operations have been performed, transmitting, to the protected computing device, the at least one part of the one or more parts of the biometric facial identity that does not match at least the portion of the bifurcated biometric data that is stored remotely.

6. The computer-implemented method of claim 5 , wherein

the transmitting causes denial of access to the protected computing device if a subsequent security scanning operation performed by the facial recognition device captures new biometric data that comprises the at least one part of the one or more parts of the biometric facial identity transmitted to the protected computing device after the plurality of orchestrated security operations have been performed.

7. A non-transitory computer readable storage medium comprising program instructions executable to:

transmit, from a security server, a periodic instruction to a protected computing device to perform a security scanning operation that captures biometric data generated, at least in part, from a facial recognition device associated with the protected computing device;

receive an indication from the protected computing device that the biometric data comprises bifurcated biometric data with a plurality of parts of a biometric facial identity captured from the facial recognition device and that only a part of plurality of parts of the biometric facial identity comprised in the bifurcated biometric data is stored locally by the protected computing device;

send a request to the protected computing device to only transmit, to the security server, one or more other parts of the biometric facial identity other than the part of the plurality of parts of the biometric facial identity;

access a security database to determine whether at least one part of the one or more others parts of the biometric facial identity matches at least a portion of the bifurcated biometric data that is not stored locally by the protected computing device and is stored remotely;

generate a security workflow comprising a plurality of orchestrated security operations configured to prevent access to the protected computing device if the at least one part of the one or more other parts of the biometric facial identity does not match at least the portion of the bifurcated biometric data that is stored remotely;

transmit the security workflow to the protected computing device; and

receive confirmation from the protected computing device that the plurality of orchestrated security operations have been performed.

8. The non-transitory computer readable storage medium of claim 7 , further comprising:

determining that the at least one part of the one or more parts of the biometric facial identity does not match at least the portion of the bifurcated biometric data that is stored remotely is part of a malicious biometric identity.

9. The non-transitory computer readable storage medium of claim 7 , wherein

each of the plurality of parts of the biometric facial identity comprise at least a partial facial identity or a partial retinal identity.

10. The non-transitory computer readable storage medium of claim 9 , wherein

the security workflow is generated based on a vulnerability level assigned to each partial facial identity and each partial retinal identity of the plurality of parts of the biometric facial identity either individually, or to one or more combinations of partial facial identities or partial retinal identities.

11. The non-transitory computer readable storage medium of claim 7 , further comprising:

upon receiving confirmation from the protected computing device that the plurality of orchestrated security operations have been performed, transmitting, to the protected computing device, the at least one part of the one or more parts of the biometric facial identity that does not match at least the portion of the bifurcated biometric data that is stored remotely.

12. The non-transitory computer readable storage medium of claim 11 , wherein

the transmitting causes denial of access to the protected computing device if a subsequent security scanning operation performed by the facial recognition device captures new biometric data that comprises the at least one part of the one or more parts of the biometric facial identity transmitted to the protected computing device after the plurality of orchestrated security operations have been performed.

13. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

transmit, from a security server, a periodic instruction to a protected computing device to perform a security scanning operation that captures biometric data generated, at least in part, from a facial recognition device associated with the protected computing device;

receive an indication from the protected computing device that the biometric data comprises bifurcated biometric data with a plurality of parts of a biometric facial identity captured from the facial recognition device and that only a part of plurality of parts of the biometric facial identity comprised in the bifurcated biometric data is stored locally by the protected computing device;

send a request to the protected computing device to only transmit, to the security server, one or more other parts of the biometric facial identity other than the part of the plurality of parts of the biometric facial identity;

access a security database to determine whether at least one part of the one or more others parts of the biometric facial identity matches at least a portion of the bifurcated biometric data that is not stored locally by the protected computing device and is stored remotely;

generate a security workflow comprising a plurality of orchestrated security operations configured to prevent access to the protected computing device if the at least one part of the one or more other parts of the biometric facial identity does not match at least the portion of the bifurcated biometric data that is stored remotely;

transmit the security workflow to the protected computing device; and

receive confirmation from the protected computing device that the plurality of orchestrated security operations have been performed.

14. The system of claim 13 , further comprising:

determining that the at least one part of the one or more parts of the biometric facial identity does not match at least the portion of the bifurcated biometric data that is stored remotely is part of a malicious biometric identity.

15. The system of claim 13 , wherein

each of the plurality of parts of the biometric facial identity comprise at least a partial facial identity or a partial retinal identity.

16. The system of claim 15 , wherein

the security workflow is generated based on a vulnerability level assigned to each partial facial identity and each partial retinal identity of the plurality of parts of the biometric facial identity either individually, or to one or more combinations of partial facial identities or partial retinal identities.

17. The system of claim 13 , further comprising:

upon receiving confirmation from the protected computing device that the plurality of orchestrated security operations have been performed, transmitting, to the protected computing device, the at least one part of the one or more parts of the biometric facial identity that does not match at least the portion of the bifurcated biometric data that is stored remotely.

18. The system of claim 17 , wherein

the transmitting causes denial of access to the protected computing device if a subsequent security scanning operation performed by the facial recognition device captures new biometric data that comprises the at least one part of the one or more parts of the biometric facial identity transmitted to the protected computing device after the plurality of orchestrated security operations have been performed.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2021
From: ANAND, ASHWIN; CURRAN, BARRY; FRANKSTON, JARED; MILBY, LUKE
To: RAPID7, INC.
Reel/Frame 055912/0208 →
Continuity (2)
Continuation 16416426 · May 20, 2019
Related Publication 20210226947A1 · Jul 22, 2021
Cited By (1)
US 12,563,088