IP Library › Granted Patent US 12,712,850
Granted Patent B2
US 12,712,850 · App. 18/958,641 · Granted Aug 18, 2026

Two-way automated secure data sharing between cloud deployments

Inventors: Khondokar Sami Iqram (Burlingame, CA); Laxman Mamidi (Redwood City, CA); Sanjay Srivastava (Mountain View, CA); Chieh-Sheng Wang (San Mateo, CA); Di Wu (Newark, CA)
Assignee: Snowflake Inc.
H04L63/0263G06F21/6218H04L63/0272H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,712,850
App. No.
18/958,641
Filed
Nov 25, 2024
Granted
Aug 18, 2026
Kind
B2
Art Unit
2439
USPC
726/1
Abstract

A method for data sharing between cloud deployments is disclosed. A provider in a virtual private cloud (VPC) deployment generates a listing of data for sharing with a consumer in a public multi-tenant deployment. After creating a public account and transmitting a link associated with the listing to the consumer, the method responds to the consumer's selection of the link by automatically creating a secure shared area in the VPC deployment. The method includes replicating both a database and share object associated with the listing into the secure shared area as respective replicas. The replicated objects are then shared with the consumer account as data share objects, enabling the consumer to launch them in a consumer mounted database. The method concludes by enabling the consumer to perform database operations on the provider's data within the VPC deployment, ensuring secure and efficient data sharing between the cloud environments.

Claims (64)

1 . A method comprising:

generating, by a provider in a virtual private cloud (VPC) deployment, a listing of data for sharing with a consumer in a public multi-tenant deployment;

creating a public account in the public multi-tenant deployment;

transmitting, to the consumer in the public multi-tenant deployment, a link associated with the listing;

receiving, from the consumer, a selection of the link; and

in response to the selection of the link:

automatically creating, by at least one hardware processor, a secure shared area in the VPC deployment;

replicating, into the secure shared area, a database associated with the listing as a database replica;

replicating, into the secure shared area, a share object associated with the listing as a share object replica;

sharing, with the consumer in the public multi-tenant deployment, the database replica and the share object replica as data share objects;

enabling the consumer to launch the data share objects in a consumer mounted database; and

enabling the consumer to perform database operations on provider data within the VPC deployment.

2 . The method of claim 1 , wherein the VPC deployment is in a first region, the first region being designated as a private region and the public multi-tenant deployment is in a second region, the second region being designated as a public multi-tenant region.

3 . The method of claim 2 , wherein the first region and the second region are physically isolated regions.

4 . The method of claim 1 , further comprising:

disabling a firewall policy that restricts data traffic between the VPC deployment and the public multi-tenant deployment based on an established trust relationship, the disabling the firewall policy being contingent on a location of the consumer being within an approved geographic region, and wherein the disabling the firewall policy comprises:

employing rules for selectively restricting the data traffic based on the approved geographic region.

5 . The method of claim 1 , wherein the listing comprises metadata describing the share object.

6 . The method of claim 1 , further comprising:

synchronizing metadata associated with the provider into the VPC deployment.

7 . The method of claim 6 , wherein the metadata comprises at least one of organization data, account data, billing contacts, billing entities, connection data, data exchange profiles, listing VPC data platform targets, replication groups, global shares, or global databases.

8 . A system comprising:

one or more hardware processors of a machine; and

at least one memory storing instructions that, when executed by the one or more hardware processors, cause the system to perform operations comprising:

generating, by a provider in a virtual private cloud (VPC) deployment, a listing of data for sharing with a consumer in a public multi-tenant deployment;

creating a public account in the public multi-tenant deployment;

transmitting, to the consumer in the public multi-tenant deployment, a link associated with the listing;

receiving, from the consumer, a selection of the link; and

in response to the selection of the link:

automatically creating a secure shared area in the VPC deployment;

replicating, into the secure shared area, a database associated with the listing as a database replica;

replicating, into the secure shared area, a share object associated with the listing as a share object replica;

sharing, with the consumer in the public multi-tenant deployment, the database replica and the share object replica as data share objects;

enabling the consumer to launch the data share objects in a consumer mounted database; and

enabling the consumer to perform database operations on provider data within the VPC deployment.

9 . The system of claim 8 , wherein the VPC deployment is in a first region, the first region being designated as a private region and the public multi-tenant deployment is in a second region, the second region being designated as a public multi-tenant region.

10 . The system of claim 9 , wherein the first region and the second region are physically isolated regions.

11 . The system of claim 8 , wherein the operations further comprise:

disabling a firewall policy that restricts data traffic between the VPC deployment and the public multi-tenant deployment based on an established trust relationship, the disabling the firewall policy being contingent on a location of the consumer being within an approved geographic region, and wherein the disabling the firewall policy comprises:

employing rules for selectively restricting the data traffic based on the approved geographic region.

12 . The system of claim 8 , wherein the listing comprises metadata describing the share object.

13 . The system of claim 8 , wherein the operations further comprise:

synchronizing metadata associated with the provider into the VPC deployment.

14 . The system of claim 13 , wherein the metadata comprises at least one of organization data, account data, billing contacts, billing entities, connection data, data exchange profiles, listing VPC data platform targets, replication groups, global shares, or global databases.

15 . A machine-storage medium embodying instructions that, when executed by a machine, cause the machine to perform operations comprising:

generating, by a provider in a virtual private cloud (VPC) deployment, a listing of data for sharing with a consumer in a public multi-tenant deployment;

creating a public account in the public multi-tenant deployment;

transmitting, to the consumer in the public multi-tenant deployment, a link associated with the listing;

receiving, from the consumer, a selection of the link; and

in response to the selection of the link:

automatically creating a secure shared area in the VPC deployment;

replicating, into the secure shared area, a database associated with the listing as a database replica;

replicating, into the secure shared area, a share object associated with the listing as a share object replica;

sharing, with the consumer in the public multi-tenant deployment, the database replica and the share object replica as data share objects;

enabling the consumer to launch the data share objects in a consumer mounted database; and

enabling the consumer to perform database operations on provider data within the VPC deployment.

16 . The machine-storage medium of claim 15 , wherein the VPC deployment is in a first region, the first region being designated as a private region and the public multi-tenant deployment is in a second region, the second region being designated as a public multi-tenant region.

17 . The machine-storage medium of claim 16 , wherein the first region and the second region are physically isolated regions.

18 . The machine-storage medium of claim 15 , wherein the operations further comprise:

disabling a firewall policy that restricts data traffic between the VPC deployment and the public multi-tenant deployment based on an established trust relationship, the disabling the firewall policy being contingent on a location of the consumer being within an approved geographic region, and wherein the disabling the firewall policy comprises:

employing rules for selectively restricting the data traffic based on the approved geographic region.

19 . The machine-storage medium of claim 15 , wherein the listing comprises metadata describing the share object.

20 . The machine-storage medium of claim 15 , wherein the operations further comprise:

synchronizing metadata associated with the provider into the VPC deployment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2024
From: IQRAM, KHONDOKAR SAMI; MAMIDI, LAXMAN; SRIVASTAVA, SANJAY; WANG, CHIEH-SHENG; WU, DI
To: SNOWFLAKE INC.
Reel/Frame 069398/0232 →
Continuity (4)
Continuation 18429215 · Jan 31, 2024
Continuation 18325388 · May 30, 2023
Provisional Application 63381673 · Oct 31, 2022
Related Publication 20250088486A1 · Mar 13, 2025
References Cited (59)
US 8615528B2 · Shah · 2013 [cited by applicant]
US 9244951B2 · Mandelstein · 2016 [cited by examiner]
US 9251114B1 · Ancin · 2016 [cited by examiner]
US 9300633B2 · Acharya et al. · 2016 [cited by applicant]
US 9426155B2 · Chao et al. · 2016 [cited by applicant]
US 9755903B2 · Masurekar et al. · 2017 [cited by applicant]
US 10152384B1 · Amit · 2018 [cited by examiner]
US 11061929B2 · Xu · 2021 [cited by examiner]
US 11218421B1 · Khan et al. · 2022 [cited by applicant]
US 11929986B1 · Igram et al. · 2024 [cited by applicant]
US 12585666B2 · Gupta · 2026 [cited by examiner]
US 20140040999A1 · Zhang et al. · 2014 [cited by applicant]
US 20140075021A1 · Revanuru · 2014 [cited by applicant]
US 20140280961A1 · Martinez et al. · 2014 [cited by applicant]
US 20150052144A1 · Mari · 2015 [cited by examiner]
US 20150143501A1 · Cherukuri et al. · 2015 [cited by applicant]
US 20150156065A1 · Grandhe et al. · 2015 [cited by applicant]
US 20160241596A1 · Overby, Jr. et al. · 2016 [cited by applicant]
US 20160261639A1 · Xu · 2016 [cited by applicant]
US 20160352836A1 · Kamalakantha et al. · 2016 [cited by applicant]
US 20160359829A1 · Gulledge · 2016 [cited by applicant]
US 20170104755A1 · Arregoces et al. · 2017 [cited by applicant]
US 20170163644A1 · Horii et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20170302673A1 · Makhervaks et al. · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180034821A1 · Basetty et al. · 2018 [cited by applicant]
US 20180039494A1 · Lander et al. · 2018 [cited by applicant]
US 20180084052A1 · Trachy · 2018 [cited by examiner]
US 20180234459A1 · Kung et al. · 2018 [cited by applicant]
US 20190158499A1 · Pogrebinsky · 2019 [cited by applicant]
US 20190306237A1 · Srinivasan · 2019 [cited by examiner]
US 20190312909A1 · Kulkarni et al. · 2019 [cited by applicant]
US 20200137114A1 · Bender et al. · 2020 [cited by applicant]
US 20200177548A1 · Devarajan et al. · 2020 [cited by applicant]
US 20200257700A1 · Xu et al. · 2020 [cited by applicant]
US 20210034775A1 · Bender · 2021 [cited by examiner]
US 20210049035A1 · Beyer et al. · 2021 [cited by applicant]
US 20210176191A1 · Pargaonkar et al. · 2021 [cited by applicant]
US 20210385194A1 · Kulkarni et al. · 2021 [cited by applicant]
US 20220086189A1 · Nguyen et al. · 2022 [cited by applicant]
US 20220360602A1 · Rose · 2022 [cited by applicant]
US 20230133945A1 · Park · 2023 [cited by applicant]
US 20230367833A1 · Kol et al. · 2023 [cited by applicant]
US 20240171544A1 · Iqram et al. · 2024 [cited by applicant]
US 20240311208A1 · Kandasamy · 2024 [cited by examiner]
S. K. Abd, R. T. Salih, S. A. R. Al-Haddad, F. Hashim, A. B. H. Abdullah and S. Yussof, “Cloud computing security risks with authorization access for secure Multi-Tenancy based on AAAS protocol,” TENCON 2015—2015 IEEE R… [cited by examiner]
G. Kappes, A. Hatzieleftheriou and S. V. Anastasiadis, “Multitenant Access Control for Cloud-Aware Distributed Filesystems,” in IEEE Transactions on Dependable and Secure Computing, vol. 16, No. 6, pp. 1070-1085, 1 Nov.… [cited by examiner]
Deochake, Saurabh, and Vrushali Channapattan. “Identity and access management framework for multi-tenant resources in hybrid cloud computing.” Proceedings of the 17th International Conference on Availability, Reliabilit… [cited by examiner]
“U.S. Appl. No. 18/325,388, Examiner Interview Summary mailed Nov. 17, 2023”, 2 pgs. [cited by applicant]
“U.S. Appl. No. 18/325,388, Non Final Office Action mailed Aug. 14, 2023”, 29 pgs. [cited by applicant]
“U.S. Appl. No. 18/325,388, Notice of Allowance mailed Nov. 29, 2023”, 11 pgs. [cited by applicant]
“U.S. Appl. No. 18/325,388, Response filed Nov. 14, 2023 to Non Final Office Action mailed Aug. 14, 2023”, 14 pgs. [cited by applicant]
“U.S. Appl. No. 18/429,215, Notice of Allowance mailed Sep. 4, 2024”, 16 pgs. [cited by applicant]
D, Tayouri S, et al., “Cybersecurity in Agile Cloud Computing-Cybersecurity Guidelines for Cloud Access”, in Cybersecurity in Agile Cloud Computing-Cybersecurity Guidelines for Cloud Access, vol. no, (Sep. 28, 2022), 1-… [cited by applicant]
R, Mendes T., et al., “Charon: A Secure Cloud-of-Clouds System for Storing and Sharing Big Data”, IEEE Transactions on Cloud Computing, vol. 9, No. 4, (Oct. 1-Dec. 2021), 1349-1361. [cited by applicant]
Roy, Arpan, “Secure the cloud From the perspective of a service-oriented organization”, ACM Computing Surveys 47.3, 2015, 30 pages. [cited by applicant]
Shaikh, A, “Framework for security of shared data in cloud environment”, International Conference on Computing Communication Control and automation, 2016, 6 pages. [cited by applicant]
Zhang, Yun, “Secure Information and Resource Sharing in Cloud Infrastructure as a Service”, In Proceedings of the 2014 ACM Workshop on Information Sharing and Collaborative Security Association for Computing Machinery, … [cited by applicant]