Token-based networking data plane protocol and token processing engine
A method of providing token security implemented by a network device in a network. The method includes encoding, into a signature mask, an identity of one or more token cells that have been signed; encoding, into the signature mask, an indication of which of the one or more token cells have been partially signed; and encoding, into the signature mask, an indication of which portion of the one or more partially signed token cells have been signed. A method of utilizing a scratchpad and a method of decomposing a contract clause are also disclosed.
1 . A method of providing token security implemented by a network device in a network, comprising:
encoding, into a signature mask, an identity of one or more token cells that have been signed;
encoding, into the signature mask, an indication of which of the one or more token cells have been partially signed; and
encoding, into the signature mask, an indication of which portion of the one or more partially signed token cells have been signed, wherein the indication of which portion identifies one or more octets of the one or more token cells being partially signed;
storing an identity of the network device generating the signature mask, the signature mask, and signature mask material in a security token cell, the signature mask material comprising a security type, a key identifier (ID), and a hash result; and
adding the security token cell to a packet, and transmitting the packet toward another network device.
2 . The method of claim 1 , further comprising encoding a position indicator into the signature mask, the position indicator indicating whether a position of the one or more token cells is absolute or relative to a position of the security token cell.
3 . The method of claim 1 , further comprising encoding the identity of the one or more token cells being signed into a first portion of the signature mask, and encoding a next indicator into the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells being signed.
4 . The method of claim 1 , further comprising encoding the indication of which of the one or more token cells is being partially signed into a first portion of the signature mask, and encoding a next indicator into the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells being partially signed.
5 . The method of claim 1 , wherein the security token cell is configured to secure a scratchpad token cell.
6 . An apparatus in a network and configured to implement token-based networking, comprising:
a memory storing instructions; and
at least one processor in communication with the memory, the at least one processor configured, upon execution of the instructions, to perform the following steps:
encode, into a signature mask, an identity of one or more token cells that have been signed;
encode, into the signature mask, an indication of which of the one or more token cells have been partially signed; and
encode, into the signature mask, an indication of which portion of the one or more token cells have been partially signed, wherein the indication of which portion identifies one or more octets of the one or more token cells being partially signed;
storing an identity of the apparatus generating the signature mask, the signature mask, and signature mask material in a security token cell, the signature mask material comprising a security type, a key identifier (ID), and a hash result; and
adding the security token cell to a packet, and transmitting the packet toward another network device.
7 . The apparatus of claim 6 , wherein the at least one processor is further configured to encode a position indicator into the signature mask, the position indicator indicating whether a position of the one or more token cells is absolute or relative to a position of the security token cell.
8 . The apparatus of claim 6 , wherein the at least one processor is further configured to encode the identity of the one or more token cells being signed into a portion of the signature mask, and encode a next indicator into the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells being signed.
9 . The apparatus of claim 6 , wherein the at least one processor is further configured to encode the indication of which of the one or more token cells is being partially signed into a first portion of the signature mask, and encode a next indicator into the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells being partially signed.
10 . The apparatus of claim 6 , wherein the security token cell is configured to secure a scratchpad token cell.
11 . The apparatus of claim 6 , the at least one processor further configured, upon execution of the instructions, to perform the following steps:
receive a packet comprising the one or more token cells and the signature mask;
decode a first segment of the signature mask to determine an identity of the one or more token cells in the packet that are signed;
decode a second segment of the signature mask to determine which of the one or more token cells in the packet are partially signed; and
decode a third segment of the signature mask to determine which portion of the one or more token cells in the packet are partially signed.
12 . A method of providing token security implemented by a network device in a network, comprising:
receiving a packet comprising one or more token cells and a signature mask;
decoding a first segment of the signature mask to determine an identity of the one or more token cells in the packet that are signed;
decoding a second segment of the signature mask to determine which of the one or more token cells in the packet are partially signed;
decoding a third segment of the signature mask to determine which portion of the one or more token cells in the packet are partially signed; and
verifying a signature of the one or more token cells according to the first segment, the second segment, and the third segment as decoded.
13 . The method of claim 12 , wherein the packet further comprises a security token cell including an identity of the network device that generated the signature mask, the signature mask, and signature mask material, the signature mask material comprising a security type, a key identifier (ID), and a hash result.
14 . The method of claim 13 , wherein the signature mask comprises a position indicator indicating whether a position of the one or more token cells is absolute or relative to a position of the security token cell.
15 . The method of claim 12 , further comprising decoding the identity of the one or more token cells that are signed from a first portion of the signature mask, and decoding a next indicator from the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells that are signed.
16 . The method of claim 12 , further comprising decoding an indication of which of the one or more token cells that are partially signed from a first portion of the signature mask, and decoding a next indicator from the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells that are partially signed.