IP Library Granted Patent US 11,949,739
Granted Patent B2
US 11,949,739 · App. 17/018,165 · Granted Apr 2, 2024

Methods, apparatuses, and computer program products for management of data deletion requests based on geographically distributed data

Inventors: Raissa Largman (San Francisco, CA); Keith Adams (San Francisco, CA); James Scheinblum (San Francisco, CA); Richard Crowley (San Francisco, CA); Ratnadeep Bhattacharjee (San Francisco, CA); Milo Watanabe (San Francisco, CA); Leah Jones (San Francisco, CA); Henry Robinson (San Francisco, CA)
Assignee: Salesforce, Inc.
H04L67/1097G06F16/29H04L51/216H04L51/222H04L65/403
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,949,739
App. No.
17/018,165
Granted
Apr 2, 2024
Kind
B2
Abstract

Systems, apparatuses, methods, and computer program products are provided for managing geographically distributed data storage in a group-based communication system and for servicing deletion requests related thereto. In some embodiments, an apparatus physically located in a first geographic area defined by a first geographic boundary is provided. In embodiments, upon determining that an entity identifier associated with a message is associated with a geographic data storage policy, the apparatus is configured to transmit a geographic data residency message package comprising message data of the message to a geographic data residency server physically located within a second geographic area defined by a second geographic boundary. The second geographic area is associated with the geographic data storage policy. In some embodiments, the apparatus is configured to update the message data of the message with residency token data received from the geographic data residency server.

Claims (47)

1. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by a processor, perform a method for deletion of geographically distributed data within a group-based communication system, the method comprising the steps of:

receiving, from a client device, a message deletion request comprising a message identifier;

locating a first repository row comprising message metadata and residency token data associated with the message identifier within a local repository physically located in a first geographic area;

upon locating the first repository row, initiating a local repository row erasure operation by which contents of the first repository row are erased from the local repository; and

upon completion of the local repository row erasure operation, transmitting a data residency deletion request to a geographic data residency server associated with the residency token data, the data residency deletion request comprising the residency token data and indicating an expiration window of a data residency repository row associated with the residency token data, and

wherein, upon lapsing of the expiration window, the data residency deletion request is configured to initiate an erasure operation by which the contents of the data residency repository row are erased from a geographic data residency repository comprising the data residency repository row,

the geographic data residency repository being physically located within a second geographic area distinct from the first geographic area.

2. The one or more non-transitory computer-readable media of claim 1 , wherein the geographic data residency server is physically located within a third geographic area.

3. The one or more non-transitory computer-readable media of claim 1 , wherein the first geographic area is subject to a first data storage policy and the second geographic area is subject to a second data storage policy different from the first data storage policy.

4. The one or more non-transitory computer-readable media of claim 1 , wherein the residency token data comprises one or more of the message identifier, a storage location identifier, or a message encryption key.

5. The one or more non-transitory computer-readable media of claim 1 , wherein the message deletion request comprises a plurality of message identifiers.

6. The one or more non-transitory computer-readable media of claim 5 , wherein a first message identifier of the plurality of message identifiers is associated with a first data residency row stored in the geographic data residency repository in the second geographic area, and wherein a second message identifier of the plurality of message identifiers is associated with a second data residency row stored in another geographic data residency repository in a third geographic area distinct from the first geographic area and the second geographic area.

7. The one or more non-transitory computer-readable media of claim 1 , wherein the method further comprises the step of:

in an instance where a data residency deletion confirmation is not received within a deletion confirmation window, enqueuing a subsequent data residency deletion request comprising the residency token data to be transmitted to the geographic data residency server.

8. A method for deletion of geographically distributed data within a group-based communication system, the method comprising the steps of:

receiving, from a client device, a message deletion request comprising a message identifier;

locating a first repository row comprising message metadata and residency token data associated with the message identifier within a local repository physically located in a first geographic area;

upon locating the first repository row, initiating a local repository row erasure operation by which contents of the first repository row are erased from the local repository; and

upon completion of the local repository row erasure operation, transmitting a data residency deletion request to a geographic data residency server associated with the residency token data, the data residency deletion request comprising the residency token data and indicating an expiration window of a data residency repository row associated with the residency token data, and

wherein, upon lapsing of the expiration window, the data residency deletion request is configured to initiate an erasure operation by which the contents of the data residency repository row are erased from a geographic data residency repository comprising the data residency repository row,

the geographic data residency repository being physically located within a second geographic area distinct from the first geographic area.

9. The method of claim 8 , wherein the geographic data residency server is physically located within a third geographic area.

10. The method of claim 8 , wherein the first geographic area is subject to a first data storage policy and the second geographic area is subject to a second data storage policy different from the first data storage policy.

11. The method of claim 8 , wherein the residency token data comprises one or more of the message identifier, a storage location identifier, or a message encryption key.

12. The method of claim 8 , wherein the message deletion request comprises a plurality of message identifiers.

13. The method of claim 12 , wherein a first message identifier of the plurality of message identifiers is associated with a first data residency row stored in the geographic data residency repository in the second geographic area, and wherein a second message identifier of the plurality of message identifiers is associated with a second data residency row stored in another geographic data residency repository in a third geographic area distinct from the first geographic area and the second geographic area.

14. The method of claim 8 , further comprising the step of:

in an instance where a data residency deletion confirmation is not received within a deletion confirmation window, enqueuing a subsequent data residency deletion request comprising the residency token data to be transmitted to the geographic data residency server.

15. A system for performing deletion of geographically distributed data within a group-based communication system, the system comprising:

a client device;

a local repository physically located in a first geographic area;

a geographic data residency repository physically located in a second geographic area distinct from the first geographic area;

a processor programmed to perform a method for deletion of geographically distributed data, the method comprising the steps of:

receiving, from the client device, a message deletion request comprising a message identifier;

locating a first repository row comprising message metadata and residency token data associated with the message identifier within the local repository;

upon locating the first repository row, initiating a local repository row erasure operation by which contents of the first repository row are erased from the local repository; and

upon completion of the local repository row erasure operation, transmitting a data residency deletion request to a geographic data residency server associated with the residency token data, the data residency deletion request comprising the residency token data and indicating an expiration window of a data residency repository row associated with the residency token data, and

wherein, upon lapsing of the expiration window, the data residency deletion request is configured to initiate an erasure operation by which the contents of the data residency repository row are erased from the geographic data residency repository comprising the data residency repository row.

16. The system of claim 15 , wherein the geographic data residency server is physically located within a third geographic area.

17. The system of claim 15 , wherein the first geographic area is subject to a first data storage policy and the second geographic area is subject to a second data storage policy different from the first data storage policy.

18. The system of claim 15 , wherein the residency token data comprises one or more of the message identifier, a storage location identifier, or a message encryption key.

19. The system of claim 15 ,

wherein the message deletion request comprises a plurality of message identifiers,

wherein a first message identifier of the plurality of message identifiers is associated with a first data residency row stored in the geographic data residency repository in the second geographic area, and

wherein a second message identifier of the plurality of message identifiers is associated with a second data residency row stored in another geographic data residency repository in a third geographic area distinct from the first geographic area and the second geographic area.

20. The system of claim 15 , wherein the method further comprises the step of:

in an instance where a data residency deletion confirmation is not received within a deletion confirmation window, enqueuing a subsequent data residency deletion request comprising the residency token data to be transmitted to the geographic data residency server.

Assignments (5)
MERGER Recorded Nov 21, 2022
From: SLACK TECHNOLOGIES, LLC
To: SALESFORCE.COM, INC.
Reel/Frame 061972/0569 →
CHANGE OF NAME Recorded Nov 21, 2022
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 061972/0769 →
MERGER AND CHANGE OF NAME Recorded Oct 1, 2021
From: SLACK TECHNOLOGIES, INC.; SLACK TECHNOLOGIES, LLC
To: SLACK TECHNOLOGIES, LLC
Reel/Frame 057683/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2021
From: BHATTACHARJEE, RATNADEEP
To: SLACK TECHNOLOGIES, INC.
Reel/Frame 057056/0362 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2020
From: LARGMAN, RAISSA; ADAMS, KEITH; SCHEINBLUM, JAMES; CROWLEY, RICHARD; BHATTACHARJEE, DEEP; WATANABE, MILO; JONES, LEAH; ROBINSON, HENRY
To: SLACK TECHNOLOGIES, INC.
Reel/Frame 053746/0141 →
Continuity (5)
Continuation In Part 16702197 · Dec 3, 2019
Provisional Application 62900297 · Sep 13, 2019
Provisional Application 62895333 · Sep 3, 2019
Provisional Application 62780067 · Dec 14, 2018
Related Publication 20200412806A1 · Dec 31, 2020