IP Library › Granted Patent US 11,929,986
Granted Patent B1
US 11,929,986 · App. 18/325,388 · Granted Mar 12, 2024

Two-way data sharing between private and public clouds

Inventors: Khondokar Sami Igram (Burlingame, CA); Laxman Mamidi (Redwood City, CA); Sanjay Srivastava (Mountain View, CA); Chieh-Sheng Wang (San Mateo, CA); Di Wu (Newark, CA)
Assignee: Snowflake Inc.
H04L63/0263G06F21/6218H04L63/0272H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,929,986
App. No.
18/325,388
Granted
Mar 12, 2024
Kind
B1
Abstract

Methods, systems, and computer programs are presented for enabling automated secure data sharing from a private cloud region to a public cloud region and vice versa. A cloud data platform confirms a relationship establishment procedure between a provider and a consumer is recorded with a cloud data platform, the provider being associated with a private cloud deployment and the consumer being associated with a public cloud deployment in a public region. The cloud data platform enables disabling of a firewall policy that is preventing data traffic between the private cloud deployment and the public cloud deployment and enables data sharing between the private cloud deployment and the public cloud deployment. The cloud data platform enables data sharing in a database of the cloud data platform.

Claims (74)

1. A method comprising:

determining, by one or more hardware processors, that a relationship establishment procedure between a provider and a consumer is recorded with a cloud data platform, the provider being associated with a private cloud deployment and the consumer being associated with a public cloud deployment in a public region, the private cloud deployment comprising a virtualized environment running on dedicated hardware instances of the cloud data platform; and

in response to determining that the relationship establishment procedure is recorded with the cloud data platform:

providing, in the private cloud deployment, a parameter to enable or disable a region where a listing is visible;

disabling a firewall policy that is preventing data traffic between the private cloud deployment and the public cloud deployment, the firewall policy blocking the listing from being visible in the region;

enabling data sharing associated with the listing between the private cloud deployment in a private region and the public cloud deployment in a public multi-tenant region; and

enabling the data sharing in a database of the cloud data platform, the data sharing including database replication to the virtualized environment based on the listing.

2. The method of claim 1 , wherein the private cloud deployment is a virtual private cloud deployment in a first region designated as the private region and the public cloud deployment is the public multi-tenant cloud deployment in a second region designated as a public multi-tenant region.

3. The method of claim 2 , wherein the disabling of the firewall policy is performed only once to enable the provider to share data with any consumer in the public multi-tenant region.

4. The method of claim 3 , comprising:

enabling the provider to grant permission to users of the cloud data platform to share the data in the public multi-tenant region.

5. The method of claim 1 , wherein the disabling of the firewall policy comprises:

generating, in a state cache of the database, a cross-region group sharing token; and

validating the cross-region group sharing token.

6. The method of claim 1 , wherein the disabling of the firewall policy comprises:

receiving, by the cloud data platform, a message from the provider to disable the firewall policy; and

enabling the data sharing from the private cloud deployment to the public cloud deployment.

7. The method of claim 1 , wherein the relationship establishment procedure is initiated by the provider of the private cloud deployment.

8. The method of claim 1 , comprising:

enabling, the provider, a privilege to disable the firewall policy to allow inbound listings to and outbound listings from a private cloud deployment region.

9. The method of claim 1 , comprising:

enabling the provider in the private cloud deployment to target any consumer in a consumer organization.

10. The method of claim 1 , comprising:

blocking a public listing, for the provider in the private cloud deployment, when the public region is set as a visible region.

11. A system comprising:

one or more hardware processors of a machine; and

at least one memory storing instructions that, when executed by the one or more hardware processors, cause the system to perform operations comprising:

determining, by one or more hardware processors, that a relationship establishment procedure between a provider and a consumer is recorded with a cloud data platform, the provider being associated with a private cloud deployment and the consumer being associated with a public cloud deployment in a public region, the private cloud deployment comprising a virtualized environment running on dedicated hardware instances of the cloud data platform; and

in response to determining that the relationship establishment procedure is recorded with the cloud data platform:

providing, in the private cloud deployment, a parameter to enable or disable a region where a listing is visible;

disabling a firewall policy that is preventing data traffic between the private cloud deployment and the public cloud deployment, the firewall policy blocking the listing from being visible in the region;

enabling data sharing associated with the listing between the private cloud deployment in a private region and the public cloud deployment in a public multi-tenant region; and

enabling the data sharing in a database of the cloud data platform, the data sharing including database replication to the virtualized environment based on the listing.

12. The system of claim 11 , wherein the private cloud deployment is a virtual private cloud deployment in a first region designated as the private region and the public cloud deployment is a public multi-tenant cloud deployment in a second region designated as the public multi-tenant region.

13. The system of claim 12 , wherein the disabling of the firewall policy is performed only once to enable the provider to share data with any consumer in the public multi-tenant region.

14. The system of claim 13 , wherein the operations comprise:

enabling the provider to grant permission to users of the cloud data platform to share the data in the public multi-tenant region.

15. The system of claim 11 , wherein the disabling of the firewall policy comprises:

generating, in a state cache of the database, a cross-region group sharing token; and

validating the cross-region group sharing token.

16. The system of claim 11 , wherein the disabling of the firewall policy comprises:

receiving, by the cloud data platform, a message from the provider to disable the firewall policy; and

enabling the data sharing from the private cloud deployment to the public cloud deployment.

17. The system of claim 11 , wherein the relationship establishment procedure is initiated by the provider of the private cloud deployment.

18. The system of claim 11 , wherein the operations comprise:

enabling, the provider, a privilege to disable the firewall policy to allow inbound listings to and outbound listings from a private cloud deployment region.

19. The system of claim 11 , wherein the operations comprise:

enabling the provider in the private cloud deployment to target any consumer in a consumer organization.

20. The system of claim 11 , wherein the operations comprise:

blocking a public listing, for the provider in the private cloud deployment, when the public region is set as a visible region.

21. A machine-readable storage device embodying instructions that, when executed by a machine, cause the machine to perform operations comprising:

determining, by one or more hardware processors, that a relationship establishment procedure between a provider and a consumer is recorded with a cloud data platform, the provider being associated with a private cloud deployment and the consumer being associated with a public cloud deployment in a public region, the private cloud deployment comprising a virtualized environment running on dedicated hardware instances of the cloud data platform; and

in response to determining that the relationship establishment procedure is recorded with the cloud data platform:

providing, in the private cloud deployment, a parameter to enable or disable a region where a listing is visible;

disabling a firewall policy that is preventing data traffic between the private cloud deployment and the public cloud deployment, the firewall policy blocking the listing from being visible in the region;

enabling data sharing associated with the listing between the private cloud deployment in a private region and the public cloud deployment in a public multi-tenant region; and

enabling the data sharing in a database of the cloud data platform, the data sharing including database replication to the virtualized environment based on the listing.

22. The machine-readable storage device of claim 21 , wherein the private cloud deployment is a virtual private cloud deployment in a first region designated as the private region and the public cloud deployment is a public multi-tenant cloud deployment in a second region designated as the public multi-tenant region.

23. The machine-readable storage device of claim 22 , wherein the disabling of the firewall policy is performed only once to enable the provider to share data with any consumer in the public multi-tenant region.

24. The machine-readable storage device of claim 23 , wherein the operations comprise:

enabling the provider to grant permission to users of the cloud data platform to share the data in the public multi-tenant region.

25. The machine-readable storage device of claim 21 , wherein the disabling of the firewall policy comprises:

generating, in a state cache of the database, a cross-region group sharing token; and

validating the cross-region group sharing token.

26. The machine-readable storage device of claim 21 , wherein the disabling of the firewall policy comprises:

receiving, by the cloud data platform, a message from the provider to disable the firewall policy; and

enabling the data sharing from the private cloud deployment to the public cloud deployment.

27. The machine-readable storage device of claim 21 , wherein the relationship establishment procedure is initiated by the provider of the private cloud deployment.

28. The machine-readable storage device of claim 21 , wherein the operations comprise:

enabling, the provider, a privilege to disable the firewall policy to allow inbound listings to and outbound listings from a private cloud deployment region.

29. The machine-readable storage device of claim 21 , wherein the operations comprise:

enabling the provider in the private cloud deployment to target any consumer in a consumer organization.

30. The machine-readable storage device of claim 21 , wherein the operations comprise:

blocking a public listing, for the provider in the private cloud deployment, when the public region is set as a visible region.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2023
From: IQRAM, KHONDOKAR SAMI
To: SNOWFLAKE INC.
Reel/Frame 065402/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2023
From: MAMIDI, LAXMAN; SRIVASTAVA, SANJAY; WANG, CHIEH-SHENG; WU, DI
To: SNOWFLAKE INC.
Reel/Frame 064983/0193 →
Continuity (1)
Provisional Application 63381673 · Oct 31, 2022
Cited By (3)
US 12,699,789 US 12,712,850 US 12,724,761