IP Library Granted Patent US 12701113
Granted Patent B2
US 12701113 · App. 18/503,753 · Granted Aug 4, 2026

Packet watermark with dynamic token validation

Inventor: Yutun (Tony) Tseng (San Jose, CA)
Assignee: A10 Networks, Inc.
H04L63/083H04L63/0245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12701113
App. No.
18/503,753
Granted
Aug 4, 2026
Kind
B2
Abstract

A method and system for mitigating a threat associated with network data packets are provided. The method commences with receiving, by an authentication server, a request for access to a server from a client. The method further includes authenticating the client by the authentication server. The authentication includes providing an authentication token to the client. The method continues with receiving, by a mitigation device, from the client, at least one network packet directed to the server. The at least one network packet embeds the authentication token. The method further includes validating, by the mitigation device, authenticity of the authentication token and selectively forwarding, based on the validation, the at least one network packet to the server. The authentication token is independently generated by the authentication server and the mitigation device, and is unique for each packet.

Claims (42)

1 . A system for mitigating a threat associated with network data packets, the system comprising:

an authentication server comprising at least one memory and at least one hardware processor, that:

receives, from a client, a request for access to a first server; and

authenticates the client, the authentication including providing an authentication token to the client; and

a mitigation device that:

receives, from the client, at least one network packet directed to the first server, the at least one network packet embedding the authentication token in a payload of the at least one network packet;

validates authenticity of the authentication token; and

based on the validation, selectively forwards the at least one network packet to the first server, wherein the authentication token is unique for each network packet;

the system further comprising an administrative module resident in at least one memory and executed by at least one processor, the administrative module configured to provide a shared token generation algorithm and a salt-prefix value to the authentication server and the mitigation device.

2 . A system for mitigating a threat associated with network data packets, the system comprising:

an authentication server comprising at least one memory and at least one hardware processor, that:

receives, from a client, a request for access to a first server; and

authenticates the client, the authentication including providing an authentication token to the client; and

a mitigation device that:

receives, from the client, at least one network packet directed to the first server, the at least one network packet embedding the authentication token in a payload of the at least one network packet;

validates authenticity of the authentication token; and

based on the validation, selectively forwards the at least one network packet to the first server, wherein the authentication token is unique for each network packet; wherein the at least one network packet is a User Datagram Protocol (UDP) packet, and the authentication token is located within a first four bytes of a payload of the UDP packet.

3 . A method for mitigating a threat associated with network data packets, the method comprising:

receiving, from a client, by an authentication server, a request for access to a first server;

authenticating the client by the authentication server, the authentication including providing an authentication token to the client;

receiving, by a mitigation device, from the client, at least one network packet directed to the first server with an authentication token embedded into a payload of the at least one network packet;

validating, by the mitigation device, authenticity of the authentication token; and

based on the validation, selectively forwarding, by the mitigation device, the at least one network packet to the first server, wherein the authentication token is unique for each network packet; wherein

a shared token generation algorithm and a salt-prefix value are provided by an administrative module to the authentication server and mitigation device.

4 . A method for mitigating a threat associated with network data packets, the method comprising:

receiving, from a client, by an authentication server, a request for access to a first server;

authenticating the client by the authentication server, the authentication including providing an authentication token to the client;

receiving, by a mitigation device, from the client, at least one network packet directed to the first server with an authentication token embedded into a payload of the at least one network packet;

validating, by the mitigation device, authenticity of the authentication token; and

based on the validation, selectively forwarding, by the mitigation device, the at least one network packet to the first server, wherein the authentication token is unique for each network packet; wherein

the at least one network packet is a User Datagram Protocol (UDP) packet, and the authentication token is located within a first four bytes of a payload of the UDP packet.

5 . A system for mitigating a threat associated with network data packets, the system comprising:

an authentication server comprising at least one memory and at least one hardware processor, the authentication server configured to:

receive, from a client, a request for access to a first server; and

authenticate the client, the authentication including providing an authentication token to the client;

a mitigation device resident in at least one memory and executed by at least one processor, the mitigation device configured to:

receive, from the client, at least one network packet directed to the first server, the at least one network packet embedding the authentication token in a payload of the at least one network packet;

validate authenticity of the authentication token;

based on the validation, selectively forward the at least one network packet to the first server, wherein the authentication token is unique for each network packet; and

mitigate a threat associated with the at least one network packet if the authentication token fails the validation; and

an administrative module resident in at least one memory and executed by at least one processor, the administrative module configured to:

provide a shared token generation algorithm and a salt-prefix value to the authentication server, mitigation device, and the client.