IP Library › Granted Patent US 12,393,657
Granted Patent B2
US 12,393,657 · App. 18/159,731 · Granted Aug 19, 2025

Systems and methods for faster behavioral retraining

Inventors: Per Burström (Luleå, SE); Matthias Baumhof (Berg, DE); Ingo Deutschmann (Frankleben, DE); Philip Lindblad (Lidingö, SE); Tony Libell (Luleå, SE)
Assignee: LEXISNEXIS RISK SOLUTIONS FL INC.
G06F21/32G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,393,657
App. No.
18/159,731
Granted
Aug 19, 2025
Kind
B2
Abstract

Systems and methods are provided for behavioral biometrics retraining on credential input provided by a user for authentication. A method includes receiving a successful login indication that a user has been authenticated for access on the enterprise server based on the credential input. The method includes receiving metadata and user behaviometric data corresponding to the credential input. The method includes computing, with a behavioral scoring module, a metadata similarity score by comparing the received metadata to metadata previously stored in a user profile, resetting at least a portion of previously stored user profile data based on receiving the successful login indication and the metadata similarity score being less than a threshold value, and training user profile data using the received user behaviometric data based on receiving the successful login indication and the metadata similarity score being less than a threshold value.

Claims (51)

1. A computer-implemented method for behavioral biometrics retraining on credential input provided by a user for authentication, the method comprising:

receiving, at a behavioral biometrics server, and from an enterprise server based on the credential input:

a successful login indication that a user has been authenticated for access on the enterprise server;

metadata corresponding to the credential input; and

user behaviometric data corresponding to the credential input;

computing, with a behavioral scoring module, a metadata similarity score by comparing the received metadata to metadata previously stored in a user profile;

computing a behaviometric similarity score by comparing the received user behaviometric data to behaviometric data previously stored in the user profile;

generating and sending a request to the enterprise server to re-authenticate a user when user credentials have not changed and responsive to receiving the successful login indication and the behaviometric similarity score is less than a threshold value;

resetting at least a portion of previously stored user profile data based on receiving the successful login indication and the metadata similarity score or the behaviometric similarity score being less than a threshold value; and

training user profile data using the received behaviometric data based on receiving the successful login indication and the metadata similarity score being less than a threshold value.

2. The method of claim 1 , wherein the metadata comprises a generated hash based on the credential input, wherein the credential input includes at least one field having field content comprising one or more of a username, a password, and a company login name.

3. The method of claim 2 , wherein the generated hash is based on one or more of a length of the field content corresponding to the credential input and all or part-of the field content corresponding to the credential input.

4. The method of claim 2 , wherein the generated hash is based on behaviometric data corresponding to the credential input.

5. The method of claim 4 , wherein the behaviometric data comprises one or more of keypress count, keypress timings, timings between keypresses, bigram timings, number of pauses during keypress entry, and length of pauses during keypress entry.

6. The method of claim 2 , further comprising receiving, at the behavioral biometrics server, user device information, and wherein resetting at least a portion of the previously stored user profile data is further based on the user device corresponding to a trusted device.

7. The method of claim 6 , wherein training the user profile data is allowed only when a digital signature is utilized by the trusted device to sign the metadata or hash.

8. The method of claim 1 , wherein the successful login indication comprises at least a portion of one or more of the credential input and user behaviometric data related to the credential input.

9. A system configured for behavioral biometrics retraining on credential input provided by a user for authentication, the system comprising:

a processor; and

a memory having programming instructions stored thereon, which, when executed by the processor, cause the processor to:

receive, from an enterprise server:

a successful login indication that a user has been authenticated for access on the enterprise server based on credential input;

metadata corresponding to the credential input; and

user behaviometric data corresponding to the credential input;

compute a metadata similarity score by comparing the received metadata to metadata previously stored in a user profile;

compute a behaviometric similarity score by comparing the received user behaviometric data to behaviometric data previously stored in the user profile;

generate and send a request to the enterprise server to re-authenticate a user when user credentials have not changed and responsive to receiving the successful login indication and the behaviometric similarity score is less than a threshold value;

reset at least a portion of previously stored user profile data based on receiving the successful login indication and the metadata similarity score or the behaviometric similarity score being less than a threshold value; and

train user profile data using the received user behaviometric data based on receiving the successful login indication and the metadata similarity score being less than a threshold value.

10. The system of claim 9 , wherein the metadata comprises a generated hash based on the credential input, wherein the credential input includes at least one field having field content comprising one or more of a username, a password, and a company login name.

11. The system of claim 10 , wherein the generated hash is based on a length of the field content corresponding to the credential input.

12. The system of claim 10 , wherein the generated hash is based on all or part of the field content corresponding to the credential input.

13. The system of claim 10 , wherein the generated hash is based on the user behaviometric data corresponding to the credential input.

14. The system of claim 13 , wherein the user behaviometric data comprises one or more of keypress count, keypress timings, timings between keypresses, bigram timings, number of pauses during keypress entry, and length of pauses during keypress entry.

15. The system of claim 10 , further comprising receiving user device information, and wherein resetting at least a portion of the previously stored user profile data is further based on the user device corresponding to a trusted device.

16. The system of claim 15 , wherein training the user profile data is allowed only when a digital signature is utilized by the trusted device to sign the metadata or hash.

17. A non-transitory computer-readable medium having stored thereon software instructions that, when executed by a processor, cause the processor to perform a method of:

receiving, at a behavioral biometrics server, and from an enterprise server based on the credential input:

a successful login indication that a user has been authenticated for access on the enterprise server;

metadata corresponding to the credential input; and

user behaviometric data corresponding to the credential input;

computing, with a behavioral scoring module, a metadata similarity score by comparing the received metadata to metadata previously stored in a user profile;

computing a behaviometric similarity score by comparing the received user behaviometric data to behaviometric data previously stored in the user profile;

generating and sending a request to the enterprise server to re-authenticate a user when user credentials have not changed and responsive to receiving the successful login indication and the behaviometric similarity score is less than a threshold value;

resetting at least a portion of previously stored user profile data based on receiving the successful login indication and the metadata similarity score or the behaviometric similarity score being less than a threshold value; and

training user profile data using the received behaviometric data based on receiving the successful login indication and the metadata similarity score being less than a threshold value.

18. The non-transitory computer-readable medium of claim 17 , wherein the metadata comprises a generated hash based on the credential input, wherein the credential input includes at least one field having field content comprising one or more of a username, a password, and a company login name.

19. The non-transitory computer-readable medium of claim 18 , wherein the generated hash is based on one or more of:

a length of the field content corresponding to the credential input;

all or part of the field content corresponding to the credential input; and

the user behaviometric data corresponding to the credential input, wherein the user behaviometric data comprises one or more of keypress count, keypress timings, timings between keypresses, bigram timings, number of pauses during keypress entry, and length of pauses during keypress entry.

Assignments (2)
MERGER Recorded Jun 25, 2025
From: BEHAVIOSEC INC.
To: LEXISNEXIS RISK SOLUTIONS FL INC.
Reel/Frame 071521/0926 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2023
From: BURSTRÖM, PER; BAUMHOF, MATTHIAS; DEUTSCHMANN, INGO; LINDBLAD, PHILIP; LIBELL, TONY
To: BEHAVIOSEC INC.
Reel/Frame 062494/0267 →
Continuity (1)
Related Publication 20240256643A1 · Aug 1, 2024
References Cited (9)
US 9301140B1 · Costigan · 2016 [cited by examiner]
US 12231889B2 · Dymek · 2025 [cited by examiner]
US 20130259330A1 · Russo · 2013 [cited by examiner]
US 20150358317A1 · Deutschmann · 2015 [cited by examiner]
US 20160350761A1 · Raziel · 2016 [cited by examiner]
US 20220124498A1 · Dymek · 2022 [cited by examiner]
US 20220224683A1 · Solano Gomez · 2022 [cited by examiner]
US 20250112925A1 · Norton, Jr. · 2025 [cited by examiner]
Lee, Hyoung-joo, and Sungzoon Cho. “Retraining a keystroke dynamics-based authenticator with impostor patterns.” Computers & Security 26.4 (2007): 300-310. (Year: 2007). [cited by examiner]