IP Library › Granted Patent US 12,537,799
Granted Patent B2
US 12,537,799 · App. 18/582,313 · Granted Jan 27, 2026

Data stream replication using staggered encryption

Inventors: Robert Bengt Benedikt Gernhardt (Seattle, WA); Mikhail Kazhamiaka (Bellevue, WA); Eric Robinson (Sammamish, WA); Rodney Weaver (Kenmore, WA)
Assignee: Snowflake Inc.
H04L63/0272G06F16/27H04L63/0281H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,537,799
App. No.
18/582,313
Filed
Feb 20, 2024
Granted
Jan 27, 2026
Kind
B2
Art Unit
2493
USPC
726/12
Abstract

A method includes encoding, by at least one hardware processor, database data in a first portion of a first data file of a plurality of data files. The encoding of the database data is based on a first encryption key. The method further includes encoding the first encryption key in a second portion of the first data file. The encoding of the first encryption key is based on a second encryption key associated with a second data file of the plurality of data files. The method further includes causing transmission of the plurality of data files from a first database deployment to a second database deployment.

Claims (77)

1 . A method comprising:

encoding, by at least one hardware processor, database data in a first portion of a first data file of a plurality of data files, the encoding of the database data based on a first encryption key;

encoding the first encryption key in a second portion of the first data file, the encoding of the first encryption key based on a second encryption key associated with a second data file of the plurality of data files; and

causing transmission of the plurality of data files from a first database deployment to a second database deployment.

2 . The method of claim 1 , further comprising:

receiving the plurality of data files as a data stream at the first database deployment, wherein the second data file precedes the first data file in the data stream.

3 . The method of claim 2 , further comprising:

decoding the second encryption key using the second data file and a public encryption key, the public encryption key associated with the second database deployment.

4 . The method of claim 3 , further comprising:

causing transmission of the second data file prior to the first data file during the transmission of the plurality of data files from the first database deployment to the second database deployment.

5 . The method of claim 1 , further comprising:

encoding a third encryption key in a third portion of the first data file, the third encryption key associated with a third data file of the plurality of data files.

6 . The method of claim 5 , further comprising:

encoding the third encryption key in the third portion of the first data file using a public encryption key, wherein the public encryption key is common to the first database deployment and the second database deployment.

7 . The method of claim 5 , further comprising:

encoding second database data in the third data file, the encoding of the database data based on a fourth encryption key; and

encoding the fourth encryption key in the third data file, the encoding of the fourth encryption key based on the third encryption key.

8 . The method of claim 1 , wherein the first encryption key is a data encryption key (DEK), the second encryption key is a wrapping replication key (WRK), and the method further comprises:

encoding the DEK using the WRK to generate an encrypted DEK; and

encoding a second WRK associated with a third data file to generate an encoded second WRK, and the encoding of the second WRK using a public key of the second database deployment.

9 . The method of claim 8 , further comprising:

encoding the first data file to include the encrypted DEK, the encoded second WRK, and the public key of the second database deployment before the transmission of the plurality of data files.

10 . The method of claim 1 , further comprising:

periodically regenerating the first encryption key and the second encryption key to generate an updated first encryption key and an updated second encryption key;

encoding a configuration message for transmission to the second database deployment, the configuration message including the updated first encryption key and the updated second encryption key for decoding a subsequent transmission of the data stream.

11 . A system comprising:

one or more processors of a machine; and

at least one memory storing instructions that, when executed by the one or more processors of a first database deployment, cause the machine to perform operations comprising:

encoding database data in a first portion of a first data file of a plurality of data files, the encoding of the database data based on a first encryption key;

encoding the first encryption key in a second portion of the first data file, the encoding of the first encryption key based on a second encryption key associated with a second data file of the plurality of data files; and

causing transmission of the plurality of data files from the first database deployment to a second database deployment.

12 . The system of claim 11 , the operations further comprising:

receiving the plurality of data files as a data stream at the first database deployment, wherein the second data file precedes the first data file in the data stream.

13 . The system of claim 12 , the operations further comprising:

decoding the second encryption key using the second data file and a public encryption key, the public encryption key associated with the second database deployment.

14 . The system of claim 13 , the operations further comprising:

causing transmission of the second data file prior to the first data file during the transmission of the plurality of data files from the first database deployment to the second database deployment.

15 . The system of claim 11 , the operations further comprising:

encoding a third encryption key in a third portion of the first data file, the third encryption key associated with a third data file of the plurality of data files.

16 . The system of claim 15 , the operations further comprising:

encoding the third encryption key in the third portion of the first data file using a public encryption key, wherein the public encryption key is common to the first database deployment and the second database deployment.

17 . The system of claim 15 , the operations further comprising:

encoding second database data in the third data file, the encoding of the database data based on a fourth encryption key; and

encoding the fourth encryption key in the third data file, the encoding of the fourth encryption key based on the third encryption key.

18 . The system of claim 11 , wherein the first encryption key is a data encryption key (DEK), the second encryption key is a wrapping replication key (WRK), and the operations further comprising:

encoding the DEK using the WRK to generate an encrypted DEK; and

encoding a second WRK associated with a third data file to generate an encoded second WRK, and the encoding of the second WRK using a public key of the second database deployment.

19 . The system of claim 18 , the operations further comprising:

encoding the first data file to include the encrypted DEK, the encoded second WRK, and the public key of the second database deployment before the transmission of the plurality of data files.

20 . The system of claim 11 , the operations further comprising:

periodically regenerating the first encryption key and the second encryption key to generate an updated first encryption key and an updated second encryption key;

encoding a configuration message for transmission to the second database deployment, the configuration message including the updated first encryption key and the updated second encryption key for decoding a subsequent transmission of the data stream.

21 . A computer-storage medium embodying instructions that, when executed by a machine of a first database deployment, cause the machine to perform operations comprising:

encoding database data in a first portion of a first data file of a plurality of data files, the encoding of the database data based on a first encryption key;

encoding the first encryption key in a second portion of the first data file, the encoding of the first encryption key based on a second encryption key associated with a second data file of the plurality of data files; and

causing transmission of the plurality of data files from the first database deployment to a second database deployment.

22 . The computer-storage medium of claim 21 , the operations further comprising:

receiving the plurality of data files as a data stream at the first database deployment, wherein the second data file precedes the first data file in the data stream.

23 . The computer-storage medium of claim 22 , the operations further comprising:

decoding the second encryption key using the second data file and a public encryption key, the public encryption key associated with the second database deployment.

24 . The computer-storage medium of claim 23 , the operations further comprising:

causing transmission of the second data file prior to the first data file during the transmission of the plurality of data files from the first database deployment to the second database deployment.

25 . The computer-storage medium of claim 21 , the operations further comprising:

encoding a third encryption key in a third portion of the first data file, the third encryption key associated with a third data file of the plurality of data files.

26 . The computer-storage medium of claim 25 , the operations further comprising:

encoding the third encryption key in the third portion of the first data file using a public encryption key, wherein the public encryption key is common to the first database deployment and the second database deployment.

27 . The computer-storage medium of claim 25 , the operations further comprising:

encoding second database data in the third data file, the encoding of the database data based on a fourth encryption key; and

encoding the fourth encryption key in the third data file, the encoding of the fourth encryption key based on the third encryption key.

28 . The computer-storage medium of claim 21 , wherein the first encryption key is a data encryption key (DEK), the second encryption key is a wrapping replication key (WRK), and the operations further comprising:

encoding the DEK using the WRK to generate an encrypted DEK; and

encoding a second WRK associated with a third data file to generate an encoded second WRK, and the encoding of the second WRK using a public key of the second database deployment.

29 . The computer-storage medium of claim 28 , the operations further comprising:

encoding the first data file to include the encrypted DEK, the encoded second WRK, and the public key of the second database deployment before the transmission of the plurality of data files.

30 . The computer-storage medium of claim 21 , the operations further comprising:

periodically regenerating the first encryption key and the second encryption key to generate an updated first encryption key and an updated second encryption key;

encoding a configuration message for transmission to the second database deployment, the configuration message including the updated first encryption key and the updated second encryption key for decoding a subsequent transmission of the data stream.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2024
From: GERNHARDT, ROBERT BENGT BENEDIKT; KAZHAMIAKA, MIKHAIL; ROBINSON, ERIC; WEAVER, RODNEY
To: SNOWFLAKE INC.
Reel/Frame 066556/0358 →
Continuity (9)
Continuation 18055493 · Nov 15, 2022
Continuation 17808429 · Jun 23, 2022
Continuation 17644854 · Dec 17, 2021
Continuation 17463338 · Aug 31, 2021
Continuation 17219716 · Mar 31, 2021
Continuation 17162919 · Jan 29, 2021
Continuation 17086258 · Oct 30, 2020
Continuation 16862996 · Apr 30, 2020
Related Publication 20240195785A1 · Jun 13, 2024
References Cited (109)
US 6963971B1 · Bush · 2005 [cited by examiner]
US 7433359B2 · Havala et al. · 2008 [cited by applicant]
US 7502796B2 · Parkkinen et al. · 2009 [cited by applicant]
US 9230114B1 · Juels · 2016 [cited by examiner]
US 9514164B1 · Matic et al. · 2016 [cited by applicant]
US 9736047B2 · Chan et al. · 2017 [cited by applicant]
US 10063429B2 · Caison et al. · 2018 [cited by applicant]
US 10153943B2 · Mulligan et al. · 2018 [cited by applicant]
US 10230697B2 · Shin · 2019 [cited by examiner]
US 10268704B1 · Sanderson et al. · 2019 [cited by applicant]
US 10346374B1 · Johnson et al. · 2019 [cited by applicant]
US 10447498B2 · De Luca · 2019 [cited by applicant]
US 10547679B1 · Burnett et al. · 2020 [cited by applicant]
US 10855660B1 · Gernhardt et al. · 2020 [cited by applicant]
US 10909120B1 · Mohamad et al. · 2021 [cited by applicant]
US 10977383B2 · Dageville · 2021 [cited by examiner]
US 10999252B1 · Gernhardt et al. · 2021 [cited by applicant]
US 10999282B2 · Owen et al. · 2021 [cited by applicant]
US 11032352B2 · Lew · 2021 [cited by examiner]
US 11063011B1 · Tsai et al. · 2021 [cited by applicant]
US 11063911B1 · Gernhardt et al. · 2021 [cited by applicant]
US 11134061B1 · Gernhardt et al. · 2021 [cited by applicant]
US 11157664B2 · Higginson et al. · 2021 [cited by applicant]
US 11223603B2 · Gernhardt et al. · 2022 [cited by applicant]
US 11238174B2 · Chong · 2022 [cited by examiner]
US 11374908B2 · Gernhardt et al. · 2022 [cited by applicant]
US 11539672B2 · Gernhardt et al. · 2022 [cited by applicant]
US 11943203B2 · Gernhardt et al. · 2024 [cited by applicant]
US 12222828B2 · Bui · 2025 [cited by examiner]
US 20020174139A1 · Midgley · 2002 [cited by examiner]
US 20030014523A1 · Teloh et al. · 2003 [cited by applicant]
US 20030024523A1 · Ching-Hui · 2003 [cited by applicant]
US 20030200168A1 · Andrew, III et al. · 2003 [cited by applicant]
US 20040174887A1 · Lee · 2004 [cited by applicant]
US 20070078937A1 · Delgaudio et al. · 2007 [cited by applicant]
US 20090037607A1 · Farinacci et al. · 2009 [cited by applicant]
US 20100122320A1 · Merati · 2010 [cited by examiner]
US 20110106759A1 · Brown, III · 2011 [cited by applicant]
US 20120047107A1 · Doddavula et al. · 2012 [cited by applicant]
US 20120059839A1 · Andrade et al. · 2012 [cited by applicant]
US 20120131093A1 · Hamano et al. · 2012 [cited by applicant]
US 20130204849A1 · Chacko · 2013 [cited by applicant]
US 20130262864A1 · Hamid · 2013 [cited by examiner]
US 20130346619A1 · Panuganty et al. · 2013 [cited by applicant]
US 20140230044A1 · Liu et al. · 2014 [cited by applicant]
US 20150039557A1 · Howard et al. · 2015 [cited by applicant]
US 20150052523A1 · Raghu · 2015 [cited by applicant]
US 20150295751A1 · Caison et al. · 2015 [cited by applicant]
US 20150310219A1 · Haager · 2015 [cited by examiner]
US 20160048408A1 · Madhu et al. · 2016 [cited by applicant]
US 20160321460A1 · Suter · 2016 [cited by examiner]
US 20160329965A1 · Cook et al. · 2016 [cited by applicant]
US 20160357971A1 · Sinha · 2016 [cited by examiner]
US 20170262204A1 · Dornemann et al. · 2017 [cited by applicant]
US 20170262350A1 · Dornemann · 2017 [cited by applicant]
US 20170359370A1 · Humphries · 2017 [cited by examiner]
US 20170371968A1 · Horowitz · 2017 [cited by examiner]
US 20180062880A1 · Yu et al. · 2018 [cited by applicant]
US 20180062917A1 · Chandrashekhar et al. · 2018 [cited by applicant]
US 20180123800A1 · Kim · 2018 [cited by examiner]
US 20180146068A1 · Johnston et al. · 2018 [cited by applicant]
US 20180260466A1 · Jacoby et al. · 2018 [cited by applicant]
US 20180284999A1 · Aslam et al. · 2018 [cited by applicant]
US 20190020474A1 · Kurian · 2019 [cited by examiner]
US 20190141015A1 · Nellen · 2019 [cited by applicant]
US 20190227998A1 · Wang et al. · 2019 [cited by applicant]
US 20190251180A1 · Lachambre et al. · 2019 [cited by applicant]
US 20190347404A1 · Bengtson · 2019 [cited by applicant]
US 20200036707A1 · Callahan et al. · 2020 [cited by applicant]
US 20200067734A1 · Hira et al. · 2020 [cited by applicant]
US 20200092259A1 · Bjäre et al. · 2020 [cited by applicant]
US 20200104310A1 · Dageville · 2020 [cited by examiner]
US 20200134080A1 · Freund et al. · 2020 [cited by applicant]
US 20200301942A1 · Robinson et al. · 2020 [cited by applicant]
US 20210029195A1 · Kolbe et al. · 2021 [cited by applicant]
US 20210056121A1 · Jayanthi · 2021 [cited by applicant]
US 20210081379A1 · Buehne et al. · 2021 [cited by applicant]
US 20210182115A1 · Gera et al. · 2021 [cited by applicant]
US 20210303404A1 · Shah et al. · 2021 [cited by applicant]
US 20210392114A1 · Gernhardt et al. · 2021 [cited by applicant]
US 20220116360A1 · Gernhardt et al. · 2022 [cited by applicant]
US 20220321538A1 · Gernhardt et al. · 2022 [cited by applicant]
US 20230073653A1 · Gernhardt et al. · 2023 [cited by applicant]
CN 107483390 · 2017 [cited by applicant]
CN 111052106 · 2020 [cited by applicant]
CN 111066300 · 2020 [cited by applicant]
CN 113875206 · 2021 [cited by applicant]
WO 2021222543 · 2021 [cited by applicant]
“U.S. Appl. No. 16/862,996, Notice of Allowance mailed Sep. 2, 2020”, 15 pgs. [cited by applicant]
“U.S. Appl. No. 17/086,258, Notice of Allowance mailed Jan. 12, 2021”, 10 pgs. [cited by applicant]
“U.S. Appl. No. 17/162,919, Notice of Allowance mailed Mar. 31, 2021”, 15 pgs. [cited by applicant]
“U.S. Appl. No. 17/219,716, Preliminary Amendment filed Apr. 15, 2021”, 6 pgs. [cited by applicant]
“International Application Serial No. PCT US2021 029864, International Search Report mailed May 18, 2021”, 2 pgs. [cited by applicant]
“International Application Serial No. PCT US2021 029864, Written Opinion mailed May 18, 2021”, 3 pgs. [cited by applicant]
“U.S. Appl. No. 17/162,919, Corrected Notice of Allowability mailed Jun. 17, 2021”, 2 pgs. [cited by applicant]
“U.S. Appl. No. 17/219,716, Notice of Allowance mailed Jul. 2, 2021”, 14 pgs. [cited by applicant]
“U.S. Appl. No. 17/463,338, Notice of Allowance mailed Nov. 18, 2021”, 10 pgs. [cited by applicant]
“U.S. Appl. No. 17/644,854, Notice of Allowance mailed Apr. 8, 2022”, 15 pgs. [cited by applicant]
“U.S. Appl. No. 17/808,429, Notice of Allowance mailed Sep. 1, 2022”, 10 pgs. [cited by applicant]
“International Application Serial No. PCT US2021 029864, International Preliminary Report on Patentability mailed Nov. 10, 2022”, 5 pgs. [cited by applicant]
“Chinese Application Serial No. 202180001744.3, Office Action mailed Feb. 24, 2023”, with machine English translation, 13 pages. [cited by applicant]
“Chinese Application Serial No. 202180001744.3, Response filed Jun. 25, 2023 to Office Action mailed Feb. 24, 2023”, with English claims, 19 pages. [cited by applicant]
“U.S. Appl. No. 18/055,493, Notice of Allowance mailed Nov. 29, 2023”, 10 pgs. [cited by applicant]
“European Application Serial No. 21796690.2, Extended European Search Report mailed Feb. 9, 2024”, 6 pgs. [cited by applicant]
Bhattarai, Krishna Prasad, “Monitoring of E-Learning System Servers Using the MariaDB Galera Cluster”, IEEE, 2019 International Conference On Networking and Network Applications (NANA), (Oct. 10, 2019), 296-301. [cited by applicant]
V V Singh, Kuldeep Kuwar, “A New Approach for the Security of VP”, Information and Communication Technology for Competitive Strategies, ACM, 2 Penn Plaza, Suite 701 New York NY 10121-0701 USA, (Mar. 4, 2016), 1-5. [cited by applicant]
“European Application Serial No. 21796690.2, Response filed Aug. 16, 2024 to Extended European Search Report mailed Feb. 9, 2024”, 18 pgs. [cited by applicant]
“Indian Application Serial No. 202247066847, Voluntary Amendment Filed Oct. 9, 2024”, with English claims, 13 pages. [cited by applicant]
“Indian Application Serial No. 202247066847, First Examination Report mailed Jun. 25, 2025”, 7 pgs. [cited by applicant]