IP Library Granted Patent US 11,188,670
Granted Patent B2
US 11,188,670 · App. 16/368,339 · Granted Nov 30, 2021

Secure data joins in a multiple tenant database system

Inventors: Justin Langseth (Kailua, HI); Matthew J. Glickman (Larchmont, NY); Christian Kleinerman (Burlingame, CA); Robert Muglia (Mercer Island, WA); Daniel Freundel (San Francisco, CA); Thierry Cruanes (San Mateo, CA); Allison Waingold Lee (San Carlos, CA)
Assignee: Snowflake Inc.
G06F21/6227G06F16/2456H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,188,670
App. No.
16/368,339
Granted
Nov 30, 2021
Kind
B2
Abstract

Systems, methods, and devices for generating a secure join of database data are disclosed. A method includes determining data stored in a first account to be compared with data stored in a second account. The method includes determining a function for generating a secure join key, wherein the secure join key includes a hashed string that hashes one or more of a data entry of the first account and a data entry of the second account. The method includes providing the secure join key to the first account and/or the second account.

Claims (35)

1. A system, comprising:

a memory; and

one or more processors operatively coupled to the memory, the one or more processors to:

determine a function for generating a secure join key, wherein the secure join key comprises a hash string that hashes first data from a first account and second data from a second account;

provide the function to one of the first account or the second account to generate the secure join key, so that the first account cannot access the second data of the second account and the second account cannot access the first data of the first account; and

execute a second function to compare the first data with the second data based on the secure join key, wherein the secure join key is received by the second function as an input.

2. The system of claim 1 , wherein the first data is a first salted value and the second data is a second salted value.

3. The system of claim 2 , wherein the first salted value from the first account comprises a data entry of the first account.

4. The system of claim 2 , wherein the first salted value from the first account comprises a first salt string associated with the first account.

5. The system of claim 2 , wherein the first salted value from the first account comprises a first account identification number associated with the first account.

6. The system of claim 1 , wherein to determine the function, the one or more processors are to determine the function such that the secure join key is further based on a salted data entry received from the second account that does not refer to any real data entry in the second account and is included to insert noise into the secure join key.

7. The system of claim 1 , wherein to determine the function, the one or more processors further to determine the function such that the secure join key is defined by the first account and is executed on an execution platform associated with the second account.

8. The system of claim 7 , wherein the first account does not have visibility into when or if the function to generate the secure join key was executed by the second account.

9. A method, comprising:

determining a function to generate a secure join key, wherein the secure join key comprises a hash string that hashes first data from a first account and second data from a second account;

providing the function to one of the first account or the second account to generate the secure join key, so that the first account cannot access the second data of the second account and the second account cannot access the first data of the first account; and

executing a second function to compare the first data with the second data based on the secure join key, wherein the secure join key is received by the second function as an input.

10. The method of claim 9 , wherein the first data is a first salted value and the second data is a second salted value.

11. The method of claim 10 , wherein the first salted value from the first account comprises a data entry of the first account.

12. The method of claim 10 , wherein the first salted value from the first account comprises a first salt string associated with the first account.

13. The method of claim 10 , wherein the first salted value from the first account comprises a first account identification number associated with the first account.

14. The method of claim 10 , wherein determining the function comprises determining the function such that the secure join key is further based on a salted data entry received from the second account that does not refer to any real data entry in the second account and is included to insert noise into the secure join key.

15. The method of claim 10 , determining the function comprises determining the function such that the secure join key is defined by the first account and is executed on an execution platform associated with the second account.

16. The method of claim 15 , wherein the first account does not have visibility into when or if the function to generate the secure join key was executed by the second account.

17. A non-transitory computer readable storage media storing instructions that, when executed by one or more processors, cause the one or more processor to execute the instructions to:

determine, by the one or more processors, a function to generate a secure join key, wherein the secure join key comprises a hash string that hashes first data from a first account and second data from a second account;

provide the secure join key to one of the first account or the second account to generate the secure join key, so that the first account cannot access the second data of the second account and the second account cannot access the first data of the first account; and

executing a second function to compare the first data with the second data based on the secure join key, wherein the secure join key is received by the second function as an input.

18. The non-transitory computer readable storage media of claim 17 , wherein the first data is a first salted value and the second data is a second salted value.

19. The non-transitory computer readable storage media of claim 18 , wherein the first salted value from the first account comprises a data entry of the first account.

20. The non-transitory computer readable storage media of claim 18 , wherein the first salted value from the first account comprises a first salt string associated with the first account.

21. The non-transitory computer readable storage media of claim 18 , wherein the first salted value from the first account comprises a first account identification number associated with the first account.

22. The non-transitory computer readable storage media of claim 17 , wherein to determine the function, the one or more processors to determine the function such that the secure join key is further based on a salted data entry received from the second account that does not refer to any real data entry in the second account and is included to insert noise into the secure join key.

23. The non-transitory computer readable storage media of claim 17 , wherein to determine the function, the one or more processors further to determine the function such that the secure join key is defined by the first account and is executed on an execution platform associated with the second account.

24. The non-transitory computer readable storage media of claim 23 , wherein the first account does not have visibility into when or if the function to generate the secure join key was executed by the second account.

Assignments (2)
CHANGE OF NAME Recorded Apr 11, 2019
From: SNOWFLAKE COMPUTING, INC.
To: SNOWFLAKE INC.
Reel/Frame 049127/0027 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2019
From: LANGSETH, JUSTIN; GLICKMAN, MATTHEW J.; KLEINERMAN, CHRISTIAN; MUGLIA, ROBERT; FREUNDEL, DANIEL; CRUANES, THIERRY; LEE, ALLISON WAINGOLD
To: SNOWFLAKE COMPUTING INC.
Reel/Frame 048731/0522 →
Continuity (1)
Related Publication 20200311297A1 · Oct 1, 2020
Cited By (2)
US 12,223,082 US 12,717,958