IP Library Granted Patent US 12,235,992
Granted Patent B2
US 12,235,992 · App. 18/060,504 · Granted Feb 25, 2025

Data clean rooms using defined access in trusted execution environment

Inventors: Artin Avanes (Palo Alto, CA); Thierry Cruanes (San Mateo, CA); Monica J. Holboke (Toronto, CA); Allison Waingold Lee (Pebble Beach, CA); Subramanian Muralidhar (Mercer Island, WA); David Schultz (Piedmont, CA)
Assignee: Snowflake Inc.
G06F21/6245G06F9/541G06F9/547G06F16/2456G06F21/53G06F21/6254G06F2221/032
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,235,992
App. No.
18/060,504
Granted
Feb 25, 2025
Kind
B2
Abstract

In an embodiment, an application is created on a data-provider platform. The application includes one or more application programming interfaces (APIs) corresponding to one or more underlying code blocks. Provider data is shared with the application on the data-provider platform. An application instance of the application is installed in a trusted execution environment (TEE). The application instance includes one or more APIs corresponding to the one or more APIs in the application on the data-provider platform. Consumer data is shared with the application instance from a data-consumer platform. One or more of the APIs of the application instance are invoked to execute, on the TEE, respective associated underlying code blocks that are not visible on the TEE. The output of the one or more respective associated underlying code blocks is saved to the data-consumer platform.

Claims (41)

1. A method performed by executing instructions on at least one hardware processor, the method comprising:

creating an application on a data-provider platform, the application comprising one or more application programming interfaces (APIs) corresponding to one or more underlying code blocks;

sharing provider data with the application on the data-provider platform;

installing, in a trusted execution environment (TEE), an application instance of the application, the application instance comprising one or more APIs corresponding to the one or more APIs in the application on the data-provider platform;

sharing consumer data with the application instance from a data-consumer platform;

invoking one or more of the APIs of the application instance to execute respective associated underlying code blocks on the TEE, the respective associated underlying code blocks not being visible on the TEE; and

saving output of the one or more respective associated underlying code blocks to the data-consumer platform.

2. The method of claim 1 , wherein the application instance is, by default, not authorized to exfiltrate consumer data from the data-consumer platform.

3. The method of claim 1 , wherein the respective associated underlying code blocks not being visible on the TEE comprises a source code of the respective associated underlying code blocks not being visible on the TEE.

4. The method of claim 1 , wherein the saved output comprises aggregated output data.

5. The method of claim 4 , wherein the saved output does not include any of the shared provider data.

6. The method of claim 1 , wherein the saved output comprises a relation.

7. The method of claim 6 , wherein the relation includes only a subset of the consumer data that was shared with the application instance.

8. A computer system comprising:

at least one hardware processor; and

one or more non-transitory computer readable storage media containing instructions that, when executed by the at least one hardware processor, cause the computer system to perform operations comprising:

creating an application on a data-provider platform, the application comprising one or more application programming interfaces (APIs) corresponding to one or more underlying code blocks;

sharing provider data with the application on the data-provider platform;

installing, in a trusted execution environment (TEE), an application instance of the application, the application instance comprising one or more APIs corresponding to the one or more APIs in the application on the data-provider platform;

sharing consumer data with the application instance from a data-consumer platform;

invoking one or more of the APIs of the application instance to execute respective associated underlying code blocks on the TEE, the respective associated underlying code blocks not being visible on the TEE; and

saving output of the one or more respective associated underlying code blocks to the data-consumer platform.

9. The computer system of claim 8 , wherein the application instance is, by default, not authorized to exfiltrate consumer data from the data-consumer platform.

10. The computer system of claim 8 , wherein the respective associated underlying code blocks not being visible on the TEE comprises a source code of the respective associated underlying code blocks not being visible on the TEE.

11. The computer system of claim 8 , wherein the saved output comprises aggregated output data.

12. The computer system of claim 11 , wherein the saved output does not include any of the shared provider data.

13. The computer system of claim 8 , wherein the saved output comprises a relation.

14. The computer system of claim 13 , wherein the relation includes only a subset of the consumer data that was shared with the application instance.

15. One or more non-transitory computer readable storage media containing instructions that, when executed by at least one hardware processor of a computer system, cause the computer system to perform operations comprising:

creating an application on a data-provider platform, the application comprising one or more application programming interfaces (APIs) corresponding to one or more underlying code blocks;

sharing provider data with the application on the data-provider platform;

installing, in a trusted execution environment (TEE), an application instance of the application, the application instance comprising one or more APIs corresponding to the one or more APIs in the application on the data-provider platform;

sharing consumer data with the application instance from a data-consumer platform;

invoking one or more of the APIs of the application instance to execute respective associated underlying code blocks on the TEE, the respective associated underlying code blocks not being visible on the TEE; and

saving output of the one or more respective associated underlying code blocks to the data-consumer platform.

16. The one or more non-transitory computer readable storage media of claim 15 , wherein the application instance is, by default, not authorized to exfiltrate consumer data from the data-consumer platform.

17. The one or more non-transitory computer readable storage media of claim 15 , wherein the respective associated underlying code blocks not being visible on the TEE comprises a source code of the respective associated underlying code blocks not being visible on the TEE.

18. The one or more non-transitory computer readable storage media of claim 15 , wherein the saved output comprises aggregated output data.

19. The one or more non-transitory computer readable storage media of claim 18 , wherein the saved output does not include any of the shared provider data.

20. The one or more non-transitory computer readable storage media of claim 15 , wherein the saved output comprises a relation.

21. The one or more non-transitory computer readable storage media of claim 20 , wherein the relation includes only a subset of the consumer data that was shared with the application instance.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2023
From: AVANES, ARTIN; CRUANES, THIERRY; HOLBOKE, MONICA J.; LEE, ALLISON WAINGOLD; MURALIDHAR, SUBRAMANIAN; SCHULTZ, DAVID
To: SNOWFLAKE INC.
Reel/Frame 062807/0300 →
Continuity (3)
Continuation In Part 18051457 · Oct 31, 2022
Provisional Application 63366316 · Jun 13, 2022
Related Publication 20230401333A1 · Dec 14, 2023
References Cited (42)
US 10831460B2 · Cooper · 2020 [cited by examiner]
US 11601402B1 · Delaney · 2023 [cited by examiner]
US 11645413B2 · Arikapudi · 2023 [cited by examiner]
US 11763029B2 · Avanes et al. · 2023 [cited by applicant]
US 11803432B1 · Avanes et al. · 2023 [cited by applicant]
US 20040039924A1 · Baldwin · 2004 [cited by examiner]
US 20120222084A1 · Beaty · 2012 [cited by examiner]
US 20130097417A1 · Lauter et al. · 2013 [cited by applicant]
US 20130318160A1 · Beraka · 2013 [cited by examiner]
US 20130339980A1 · Meshar · 2013 [cited by examiner]
US 20140032759A1 · Barton · 2014 [cited by examiner]
US 20140040638A1 · Barton · 2014 [cited by examiner]
US 20160006724A1 · Vlot · 2016 [cited by examiner]
US 20170180386A1 · Dewan · 2017 [cited by examiner]
US 20170195458A1 · Parekh · 2017 [cited by examiner]
US 20180198839A1 · Demulder · 2018 [cited by examiner]
US 20190079782A1 · Goldberg · 2019 [cited by examiner]
US 20200160388A1 · Sabeg et al. · 2020 [cited by applicant]
US 20200202262A1 · Merritt et al. · 2020 [cited by applicant]
US 20200294056A1 · Patel et al. · 2020 [cited by applicant]
US 20200394318A1 · Bahrami · 2020 [cited by examiner]
US 20210119794A1 · Shpurov et al. · 2021 [cited by applicant]
US 20210288973A1 · Dimble · 2021 [cited by examiner]
US 20220075878A1 · Begg et al. · 2022 [cited by applicant]
US 20220126210A1 · Kumar et al. · 2022 [cited by applicant]
US 20220131685A1 · Lim · 2022 [cited by examiner]
US 20220140997A1 · Lam et al. · 2022 [cited by applicant]
US 20230053566A1 · Horne et al. · 2023 [cited by applicant]
US 20230081545A1 · Bull · 2023 [cited by examiner]
US 20230130637A1 · Hosudurg · 2023 [cited by examiner]
US 20230177210A1 · Avanes et al. · 2023 [cited by applicant]
U.S. Appl. No. 18/051,457, filed Oct. 31, 2022, Data Clean Rooms Using Defined Access. [cited by applicant]
U.S. Appl. No. 18/162,506, filed Jan. 31, 2023, Data Clean Rooms Using Defined Access With Homomorphic Encryption. [cited by applicant]
U.S. Appl. No. 18/217,163, filed Jun. 30, 2023, Data Clean Rooms Using Defined Access With Homomorphic Encryption. [cited by applicant]
“U.S. Appl. No. 18/051,457, Notice of Allowance mailed Jun. 22, 2023”, 12 pages. [cited by applicant]
“International Application Serial No. PCT US2023 023407, International Search Report mailed Jul. 10, 2023”, 3 pages. [cited by applicant]
“International Application Serial No. PCT US2023 023407, Written Opinion mailed Jul. 10, 2023”, 3 pages. [cited by applicant]
“U.S. Appl. No. 18/051,457, Supplemental Notice of Allowability mailed Jul. 14, 2023”, 2 pages. [cited by applicant]
“U.S. Appl. No. 18/051,457, Corrected Notice of Allowability mailed Sep. 1, 2023”, 4 pages. [cited by applicant]
“U.S. Appl. No. 18/051,457, 312 Amendment filed Sep. 19, 2023”, 3 pages. [cited by applicant]
“U.S. Appl. No. 18/051,457, PTO Response to Rule 312 Communication mailed Sep. 28, 2023”, 2 pages. [cited by applicant]
“U.S. Appl. No. 18/162,506, Notice of Allowance mailed May 25, 2023”, 16 pgs. [cited by applicant]