IP Library Granted Patent US 12,562,898
Granted Patent B2
US 12,562,898 · App. 18/508,865 · Granted Feb 24, 2026

Native application integration in data system

Inventors: Maynard Daniels Bryant, Jr. (Roswell, GA); James Pan (Oakville, CA)
Assignee: Snowflake Inc.
H04L9/088G06F8/61H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,562,898
App. No.
18/508,865
Granted
Feb 24, 2026
Kind
B2
Abstract

Techniques for sharing application packages in a multi-tenant database system are described. A provider account can create and share an application package with provider key information. A consumer application can be installed in a consumer account based on the application package and consumer account can be registered using an onboard service user and the provider key information. A unique consumer service user can be registered in the provider account corresponding to the consumer account.

Claims (53)

1 . A method comprising:

providing, from a provider account in a multi-tenant database system, an application package to a consumer account, the application package including provider key information;

installing, by at least one hardware processor, a consumer application in the consumer account based on the application package;

registering the consumer account in the provider account using an onboard service user and the provider key information;

registering a unique consumer service user corresponding to the consumer account in the application package stored in the provider account;

generating, by the consumer application, a consumer-specific private key and a consumer-specific public key:

encrypting, by the consumer application, the execution request using the consumer-specific private key and a username for the unique consumer service user;

transmitting, from the consumer application, to the provider account an the execution request using a direct application programming interface (API); and

executing the execution request in the provider account using the unique consumer service user.

2 . The method of claim 1 , further comprising:

transmitting, by the consumer application, to the provider account the consumer-specific public key; and

registering the unique consumer service user with the consumer-specific public key.

3 . The method of claim 1 , further comprising:

authenticating, by the provider account, the unique consumer service user based on the consumer-specific public key.

4 . The method of claim 3 , wherein the consumer-specific private key is inaccessible to the consumer account outside of the consumer application.

5 . The method of claim 4 , wherein the consumer-specific private key is inaccessible to the provider account.

6 . The method of claim 4 , wherein the consumer-specific private key is stored in a local storage associated with the consumer account.

7 . A machine-storage medium embodying instructions that, when executed by a machine, cause the machine to perform operations comprising:

providing, from a provider account in a multi-tenant database system, an application package to a consumer account, the application package including provider key information;

installing a consumer application in the consumer account based on the application package;

registering the consumer account in the provider account using an onboard service user and the provider key information;

registering a unique consumer service user corresponding to the consumer account in the application package stored in the provider account;

generating, by the consumer application, a consumer-specific private key and a consumer-specific public key;

encrypting, by the consumer application, the execution request using the consumer-specific private key and a username for the unique consumer service user;

transmitting, from the consumer application, to the provider account an the execution request using a direct application programming interface (API); and

executing the execution request in the provider account using the unique consumer service user.

8 . The machine-storage medium of claim 7 , further comprising:

transmitting, by the consumer application, to the provider account the consumer-specific public key; and

registering the unique consumer service user with the consumer-specific public key.

9 . The machine-storage medium of claim 7 , further comprising:

authenticating, by the provider account, the unique consumer service user based on the consumer-specific public key.

10 . The machine-storage medium of claim 9 , wherein the consumer-specific private key is inaccessible to the consumer account outside of the consumer application.

11 . The machine-storage medium of claim 10 , wherein the consumer-specific private key is inaccessible to the provider account.

12 . The machine-storage medium of claim 10 , wherein the consumer-specific private key is stored in a local storage associated with the consumer account.

13 . A system comprising:

at least one hardware processor; and

at least one memory storing instructions that, when executed by the at least one hardware processor, cause the at least one hardware processor to perform operations comprising:

providing, from a provider account in a multi-tenant database system, an application package to a consumer account, the application package including provider key information;

installing a consumer application in the consumer account based on the application package;

registering the consumer account in the provider account using an onboard service user and the provider key information;

registering a unique consumer service user corresponding to the consumer account in the application package stored in the provider account;

generating, by the consumer application, a consumer-specific private key and a consumer-specific public key;

encrypting, by the consumer application, the execution request using the consumer-specific private key and a username for the unique consumer service user;

transmitting, from the consumer application, to the provider account an the execution request using a direct application programming interface (API); and

executing the execution request in the provider account using the unique consumer service user.

14 . The system of claim 13 , the operations further comprising:

transmitting, by the consumer application, to the provider account the consumer-specific public key; and

registering the unique consumer service user with the consumer-specific public key.

15 . The system of claim 13 , the operations further comprising:

authenticating, by the provider account, the unique consumer service user based on the consumer-specific public key.

16 . The system of claim 15 , wherein the consumer-specific private key is inaccessible to the consumer account outside of the consumer application.

17 . The system of claim 16 , wherein the consumer-specific private key is inaccessible to the provider account.

18 . The system of claim 16 , wherein the consumer-specific private key is stored in a local storage associated with the consumer account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2024
From: BRYANT, MAYNARD DANIELS, JR.; PAN, JAMES
To: SNOWFLAKE INC.
Reel/Frame 066165/0785 →
Continuity (1)
Related Publication 20250158814A1 · May 15, 2025
References Cited (27)
US 10129229B1 · Leavy · 2018 [cited by examiner]
US 10999252B1 · Gernhardt · 2021 [cited by examiner]
US 11330067B1 · Deen · 2022 [cited by examiner]
US 20120072716A1 · Hu · 2012 [cited by examiner]
US 20120166818A1 · Orsini · 2012 [cited by examiner]
US 20140095874A1 · Desai · 2014 [cited by examiner]
US 20160099927A1 · Oz · 2016 [cited by examiner]
US 20170300708A1 · Gopshtein · 2017 [cited by examiner]
US 20190149342A1 · Fynaardt · 2019 [cited by examiner]
US 20190230090A1 · Kathiara · 2019 [cited by examiner]
US 20190280860A1 · Peddada · 2019 [cited by examiner]
US 20190306138A1 · Carru · 2019 [cited by examiner]
US 20190384624A1 · Jamkhedkar · 2019 [cited by examiner]
US 20190387072A1 · Jamkhedkar · 2019 [cited by examiner]
US 20200007529A1 · Bahrenburg · 2020 [cited by examiner]
US 20200028848A1 · Gupta · 2020 [cited by examiner]
US 20210248205A1 · Tank · 2021 [cited by examiner]
US 20210409409A1 · Palanisamy · 2021 [cited by examiner]
US 20220038296A1 · Fynaardt · 2022 [cited by examiner]
US 20220386124A1 · Kb · 2022 [cited by examiner]
US 20230061123A1 · Low · 2023 [cited by examiner]
US 20230185823A1 · Chu · 2023 [cited by examiner]
US 20230185952A1 · Carru · 2023 [cited by examiner]
US 20230409731A1 · Voelker · 2023 [cited by examiner]
US 20240211237A1 · R · 2024 [cited by examiner]
US 20250047473A1 · Nachbaur · 2025 [cited by examiner]
US 20250141696A1 · Elemenshawy · 2025 [cited by examiner]