IP Library Granted Patent US 12665935
Granted Patent B2
US 12665935 · App. 18/904,287 · Granted Jun 23, 2026

Execution node security using multiple gateway endpoints

Inventors: Derek Denny-Brown (Seattle, WA); Ajay Shridhar Joshi (Kirkland, WA); Xuguang Yang (Bellevue, WA); Haowei Yu (Newark, CA)
Assignee: Snowflake Inc.
H04L63/20H04L63/0245H04L67/1097H04L67/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12665935
App. No.
18/904,287
Granted
Jun 23, 2026
Kind
B2
Abstract

A system and method for enhancing data storage security in cloud environments using multiple gateway endpoints. The system includes a cloud data platform with a plurality of networks, each associated with a different gateway endpoint. Each gateway endpoint has a respective gateway endpoint tag. The method involves creating networks and corresponding gateway endpoints, configuring each gateway endpoint to enable traffic for sessions associated with the gateway endpoint tag, and assigning execution nodes to networks with session tokens that include the gateway endpoint tag. This setup ensures that only sessions with the correct tag can access data storage, reducing the risk of unauthorized data exfiltration.

Claims (47)

1 . A system comprising:

a memory comprising instructions; and

one or more computer processors, the instructions, when executed by the one or more computer processors, causing the system to perform operations comprising:

creating a plurality of networks in a cloud data platform;

creating a gateway endpoint for each network from the plurality of networks, each network being associated with a different gateway endpoint, each gateway endpoint having a respective gateway endpoint tag;

configuring each gateway endpoint to enable traffic for sessions that are associated with the gateway endpoint tag;

placing each execution node created in the cloud data platform in one of the networks from the plurality of networks; and

assigning, to each execution node, a session token associated with the gateway endpoint tag of the network where the execution node is placed.

2 . The system as recited in claim 1 , wherein each gateway endpoint provides access to a different data storage in the cloud data platform.

3 . The system as recited in claim 1 , wherein the instructions further cause the one or more computer processors to perform operations comprising:

receiving, by a first gateway endpoint, a network packet associated with a first session;

checking that the first session is associated with the gateway endpoint tag of the first gateway endpoint; and

dropping the network packet in response to detecting that the first session is not associated with the gateway endpoint tag of the first gateway endpoint.

4 . The system as recited in claim 1 , wherein each execution node is placed randomly in one of the networks from the plurality of networks.

5 . The system as recited in claim 1 , wherein each network corresponds to a subnet, wherein each subnet utilizes a different routing table for routing packets to the corresponding gateway endpoint associated with the subnet.

6 . The system as recited in claim 1 , wherein each gateway endpoint is provided by a cloud service to access data storage in the cloud service.

7 . The system as recited in claim 1 , wherein traffic in the gateway endpoint is not routed for sessions that use gateway endpoint tags for other gateway endpoints.

8 . The system as recited in claim 1 , wherein one gateway endpoint tag is used per customer and network, and the execution nodes of the customer in the same subnet share the gateway endpoint tag.

9 . The system as recited in claim 1 , wherein a security manager in the cloud data platform configures the execution nodes with an internet protocol (IP) address in the network where the execution node is placed.

10 . The system as recited in claim 1 , further comprising:

dividing the execution nodes into producer execution nodes and consumer execution nodes, wherein producer execution nodes and consumer execution nodes are not placed in the same network.

11 . A computer-implemented method comprising:

creating a plurality of networks in a cloud data platform;

creating a gateway endpoint for each network from the plurality of networks, each network being associated with a different gateway endpoint, each gateway endpoint having a respective gateway endpoint tag;

configuring each gateway endpoint to enable traffic for sessions that are associated with the gateway endpoint tag;

placing each execution node created in the cloud data platform in one of the networks from the plurality of networks; and

assigning, to each execution node, a session token associated with the gateway endpoint tag of the network where the execution node is placed.

12 . The method as recited in claim 11 , wherein each gateway endpoint provides access to a different data storage in the cloud data platform.

13 . The method as recited in claim 11 , further comprising:

receiving, by a first gateway endpoint, a network packet associated with a first session;

checking that the first session is associated with the gateway endpoint tag of the first gateway endpoint; and

dropping the network packet in response to detecting that the first session is not associated with the gateway endpoint tag of the first gateway endpoint.

14 . The method as recited in claim 11 , wherein each execution node is placed randomly in one of the networks from the plurality of networks.

15 . The method as recited in claim 11 , wherein each network corresponds to a subnet, wherein each subnet utilizes a different routing table for routing packets to the corresponding gateway endpoint associated with the subnet.

16 . A non-transitory machine-storage medium including instructions that, when executed by a machine, cause the machine to perform operations comprising:

creating a plurality of networks in a cloud data platform;

creating a gateway endpoint for each network from the plurality of networks, each network being associated with a different gateway endpoint, each gateway endpoint having a respective gateway endpoint tag;

configuring each gateway endpoint to enable traffic for sessions that are associated with the gateway endpoint tag;

placing each execution node created in the cloud data platform in one of the networks from the plurality of networks; and

assigning, to each execution node, a session token associated with the gateway endpoint tag of the network where the execution node is placed.

17 . The machine-storage medium as recited in claim 16 , wherein each gateway endpoint provides access to a different data storage in the cloud data platform.

18 . The machine-storage medium as recited in claim 16 , wherein the machine further performs operations comprising:

receiving, by a first gateway endpoint, a network packet associated with a first session;

checking that the first session is associated with the gateway endpoint tag of the first gateway endpoint; and

dropping the network packet in response to detecting that the first session is not associated with the gateway endpoint tag of the first gateway endpoint.

19 . The machine-storage medium as recited in claim 16 , wherein each execution node is placed randomly in one of the networks from the plurality of networks.

20 . The machine-storage medium as recited in claim 16 , wherein each network corresponds to a subnet, wherein each subnet utilizes a different routing table for routing packets to the corresponding gateway endpoint associated with the subnet.