IP Library › Granted Patent US 12,671,656
Granted Patent B2
US 12,671,656 · App. 18/450,677 · Granted Jun 30, 2026

Token-based networking data plane protocol and token processing engine

Inventors: Alexander Clemm (Los Gatos, CA); Stewart Bryant (Plano, TX)
Assignee: Huawei Technologies Co., Ltd.
H04L45/7453H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,671,656
App. No.
18/450,677
Granted
Jun 30, 2026
Kind
B2
Abstract

A method of providing token security implemented by a network device in a network. The method includes encoding, into a signature mask, an identity of one or more token cells that have been signed; encoding, into the signature mask, an indication of which of the one or more token cells have been partially signed; and encoding, into the signature mask, an indication of which portion of the one or more partially signed token cells have been signed. A method of utilizing a scratchpad and a method of decomposing a contract clause are also disclosed.

Claims (37)

1 . A method of providing token security implemented by a network device in a network, comprising:

encoding, into a signature mask, an identity of one or more token cells that have been signed;

encoding, into the signature mask, an indication of which of the one or more token cells have been partially signed; and

encoding, into the signature mask, an indication of which portion of the one or more partially signed token cells have been signed, wherein the indication of which portion identifies one or more octets of the one or more token cells being partially signed;

storing an identity of the network device generating the signature mask, the signature mask, and signature mask material in a security token cell, the signature mask material comprising a security type, a key identifier (ID), and a hash result; and

adding the security token cell to a packet, and transmitting the packet toward another network device.

2 . The method of claim 1 , further comprising encoding a position indicator into the signature mask, the position indicator indicating whether a position of the one or more token cells is absolute or relative to a position of the security token cell.

3 . The method of claim 1 , further comprising encoding the identity of the one or more token cells being signed into a first portion of the signature mask, and encoding a next indicator into the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells being signed.

4 . The method of claim 1 , further comprising encoding the indication of which of the one or more token cells is being partially signed into a first portion of the signature mask, and encoding a next indicator into the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells being partially signed.

5 . The method of claim 1 , wherein the security token cell is configured to secure a scratchpad token cell.

6 . An apparatus in a network and configured to implement token-based networking, comprising:

a memory storing instructions; and

at least one processor in communication with the memory, the at least one processor configured, upon execution of the instructions, to perform the following steps:

encode, into a signature mask, an identity of one or more token cells that have been signed;

encode, into the signature mask, an indication of which of the one or more token cells have been partially signed; and

encode, into the signature mask, an indication of which portion of the one or more token cells have been partially signed, wherein the indication of which portion identifies one or more octets of the one or more token cells being partially signed;

storing an identity of the apparatus generating the signature mask, the signature mask, and signature mask material in a security token cell, the signature mask material comprising a security type, a key identifier (ID), and a hash result; and

adding the security token cell to a packet, and transmitting the packet toward another network device.

7 . The apparatus of claim 6 , wherein the at least one processor is further configured to encode a position indicator into the signature mask, the position indicator indicating whether a position of the one or more token cells is absolute or relative to a position of the security token cell.

8 . The apparatus of claim 6 , wherein the at least one processor is further configured to encode the identity of the one or more token cells being signed into a portion of the signature mask, and encode a next indicator into the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells being signed.

9 . The apparatus of claim 6 , wherein the at least one processor is further configured to encode the indication of which of the one or more token cells is being partially signed into a first portion of the signature mask, and encode a next indicator into the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells being partially signed.

10 . The apparatus of claim 6 , wherein the security token cell is configured to secure a scratchpad token cell.

11 . The apparatus of claim 6 , the at least one processor further configured, upon execution of the instructions, to perform the following steps:

receive a packet comprising the one or more token cells and the signature mask;

decode a first segment of the signature mask to determine an identity of the one or more token cells in the packet that are signed;

decode a second segment of the signature mask to determine which of the one or more token cells in the packet are partially signed; and

decode a third segment of the signature mask to determine which portion of the one or more token cells in the packet are partially signed.

12 . A method of providing token security implemented by a network device in a network, comprising:

receiving a packet comprising one or more token cells and a signature mask;

decoding a first segment of the signature mask to determine an identity of the one or more token cells in the packet that are signed;

decoding a second segment of the signature mask to determine which of the one or more token cells in the packet are partially signed;

decoding a third segment of the signature mask to determine which portion of the one or more token cells in the packet are partially signed; and

verifying a signature of the one or more token cells according to the first segment, the second segment, and the third segment as decoded.

13 . The method of claim 12 , wherein the packet further comprises a security token cell including an identity of the network device that generated the signature mask, the signature mask, and signature mask material, the signature mask material comprising a security type, a key identifier (ID), and a hash result.

14 . The method of claim 13 , wherein the signature mask comprises a position indicator indicating whether a position of the one or more token cells is absolute or relative to a position of the security token cell.

15 . The method of claim 12 , further comprising decoding the identity of the one or more token cells that are signed from a first portion of the signature mask, and decoding a next indicator from the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells that are signed.

16 . The method of claim 12 , further comprising decoding an indication of which of the one or more token cells that are partially signed from a first portion of the signature mask, and decoding a next indicator from the signature mask to indicate whether the signature mask contains a second portion containing one or more additional token cells that are partially signed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2023
From: FUTUREWEI TECHNOLOGIES, INC.
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 065347/0354 →
Continuity (4)
Continuation PCTUS2021041870 · Jul 15, 2021
Provisional Application 63169591 · Apr 1, 2021
Provisional Application 63156587 · Mar 4, 2021
Related Publication 20230396545A1 · Dec 7, 2023
References Cited (19)
US 20140280717A1 · Frost et al. · 2014 [cited by applicant]
US 20160105414A1 · Bringer · 2016 [cited by examiner]
US 20200322266A1 · Clad · 2020 [cited by examiner]
US 20200322325A1 · Filsfils · 2020 [cited by examiner]
Bryant, S., et al., “Token Cell Routing: A New Sub-IP Layer Protocol,” 2021 17th International Conference on Network and Service Management (CNSM), Izmir, Turkey, 2021, pp. 153-159. [cited by applicant]
Rosen, et al., “Multiprotocol Label Switching Architecture,” RFC 3031, Jan. 2001, 61 pages. [cited by applicant]
Deering, et al, “Internet Protocol, Version 6 (IPv6) Specification,” STD 86, RFC 8200, Jul. 2017, 42 pages. [cited by applicant]
Bryant, et al, “Pseudowire Emulation Edge-to-Edge (PWE3) Control Word for Use over an MPLS PSN,” RFC 4385, Feb. 2006, 12 pages. [cited by applicant]
Finn, et al., “Deterministic Network Architecture,” RFC 8655, Oct. 2019, 38 pages. [cited by applicant]
Varga, et al., “Deterministic Networking (DetNet) Data Plane: MPLS,” RFC 8964, Jan. 2021, 27 pages. [cited by applicant]
Filsfils, et al., “Segment Routing Architecture,” RFC 8402, Jul. 2018, 32 pages. [cited by applicant]
Li, et al., “A New Framework and Protocol for Future Networking Applications,” ACM SIGCOMM Workshop on Networking for Emerging Applications and Technologies (NEAT), Budapest, Hungary, Aug. 2018, pp. 21-26. [cited by applicant]
Francois, et al., “BPP over P4: Exploring Frontiers and Limits in Programmable Packet Processing”, IEEE Global Communications Conference, Dec. 2020, 7 pages. [cited by applicant]
Bosshart, et al., “P4: Programming protocol-independent packet processors,” SIGCOMM Comput. Commun. Rev., vol. 44, No. 3, p. 87-95, Jul. 2014. [cited by applicant]
Brockners, et al., “Data Fields for In-situ OAM.” Internet Draft draft-ietf-ippm-ioam-data-12, IETF, Feb. 2021, 89 pages. [cited by applicant]
Bryant, Ed., et al., “Pseudo Wire Emulation Edge-to-Edge (PWE3) Architecture”, RFC 3985, Mar. 2005, 42 pages. [cited by applicant]
Clemm, A., T. Eckert: High-Precision Latency Forwarding over Packet-Programmable Networks. IEEE/IFIP Network Operations and Management Symposium (NOMS 2020), Budapest, Hungary / virtual, Apr. 2020, 8 pages. [cited by applicant]
Shand, et al., “IP Fast Reroute Framework”, RFC 5714, Jan. 2010, 15 pages. [cited by applicant]
ITU-T FG-Net 2030: New services and capabilities for network 2030: description, technical gap and performance target analysis. FG-NET2030 document NET2030-O-027, 2019, 45 pages. [cited by applicant]