IP Library Granted Patent US 12,563,025
Granted Patent B2
US 12,563,025 · App. 18/616,891 · Granted Feb 24, 2026

Token-based secure database query result sharing

Inventors: Damien Carru (New York, NY); Thierry Cruanes (San Mateo, CA); Jiaqi Yan (Menlo Park, CA)
Assignee: Snowflake Inc.
H04L63/0807
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,563,025
App. No.
18/616,891
Granted
Feb 24, 2026
Kind
B2
Abstract

Techniques for sharing query results in a multi-tenant database system are described. The query results can be shared between users of the same account or organization in the multi-tenant network-based database system using security tokens. A first user executes a query, and the results are stored in the network-based database system. The first user can invoke a function to create a security token to provide access to the stored query results to other users in the same account. The first user can share the security token with the other users, who can directly access the stored results in the network-based database system instead of having to download local copies of the query results.

Claims (53)

1 . A method comprising:

receiving, from a first user associated with an account in a multi-tenant database system, a query;

executing, by at least one hardware processor in the multi-tenant database system, the query to generate query results;

storing the query results in at least one storage device in the multi-tenant database system;

generating a security token associated with the stored query results, the security token including a unique string value;

managing lifecycle of the security token separately from lifecycle of the stored query results;

sharing the security token with a second user; and

providing access to the stored query results in the at least one storage device to the second user based on the security token.

2 . The method of claim 1 , further comprising:

receiving, from the second user, a request to access the stored query results, the request including the security token; and

authenticating the second user as belonging to the account in the multi-tenant database system.

3 . The method of claim 1 , wherein metadata associated with the security token is stored in a metadata database separate from the stored query results.

4 . The method of claim 3 , wherein the metadata includes a data persistent object including properties and slices.

5 . The method of claim 1 , further comprising:

tracking access to the stored query results based on usage of the security token to generate tracking information.

6 . The method of claim 5 , further comprising:

generating audit information of access to the stored query results based on the tracking information, wherein the audit information is generated based on slice information stored in metadata associated with the security token.

7 . A non-transitory machine-storage medium embodying instructions that, when executed by a machine, cause the machine to perform actions comprising:

receiving, from a first user associated with an account in a multi-tenant database system, a query;

executing the query to generate query results;

storing the query results in at least one storage device in the multi-tenant database system;

generating a security token associated with the stored query results, the security token including a unique string value;

managing lifecycle of the security token separately from lifecycle of the stored query results;

sharing the security token with a second user; and

providing access to the stored query results in the at least one storage device to the second user based on the security token.

8 . The non-transitory machine-storage medium of claim 7 , further comprising:

receiving, from the second user, a request to access the stored query results, the request including the security token; and

authenticating the second user as belonging to the account in the multi-tenant database system.

9 . The non-transitory machine-storage medium of claim 7 , wherein metadata associated with the security token is stored in a metadata database separate from the stored query results.

10 . The non-transitory machine-storage medium of claim 9 , wherein the metadata includes a data persistent object including properties and slices.

11 . The non-transitory machine-storage medium of claim 7 , further comprising:

tracking access to the stored query results based on usage of the security token to generate tracking information.

12 . The non-transitory machine-storage medium of claim 11 , further comprising:

generating audit information of access to the stored query results based on the tracking information, wherein the audit information is generated based on slice information stored in metadata associated with the security token.

13 . A system comprising:

at least one hardware processor; and

at least one memory storing instructions that, when executed by the at least one hardware processor, cause the at least one hardware processor to perform operations comprising:

receiving, from a first user associated with an account in a multi-tenant database system, a query;

executing the query to generate query results;

storing the query results in at least one storage device in the multi-tenant database system;

generating a security token associated with the stored query results, the security token including a unique string value;

managing lifecycle of the security token separately from lifecycle of the stored query results;

sharing the security token with a second user; and

providing access to the stored query results in the at least one storage device to the second user based on the security token.

14 . The system of claim 13 , the operations further comprising:

receiving, from the second user, a request to access the stored query results, the request including the security token; and

authenticating the second user as belonging to the account in the multi-tenant database system.

15 . The system of claim 13 , wherein metadata associated with the security token is stored in a metadata database separate from the stored query results.

16 . The system of claim 15 , wherein the metadata includes a data persistent object including properties and slices.

17 . The system of claim 13 , the operations further comprising:

tracking access to the stored query results based on usage of the security token to generate tracking information.

18 . The system of claim 17 , the operations further comprising:

generating audit information of access to the stored query results based on the tracking information, wherein the audit information is generated based on slice information stored in metadata associated with the security token.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2024
From: CARRU, DAMIEN; CRUANES, THIERRY; YAN, JIAQI
To: SNOWFLAKE INC.
Reel/Frame 066903/0560 →
Continuity (2)
Continuation 18497232 · Oct 30, 2023
Related Publication 20250141860A1 · May 1, 2025
References Cited (21)
US 8321460B2 · Munday · 2012 [cited by applicant]
US 10235417B1 · Sterin · 2019 [cited by examiner]
US 10664319B1 · Kaplan et al. · 2020 [cited by applicant]
US 10986117B1 · Agbabian et al. · 2021 [cited by applicant]
US 10999355B1 · Chu et al. · 2021 [cited by applicant]
US 11010392B1 · Hirsch et al. · 2021 [cited by applicant]
US 11062042B1 · Mckervey et al. · 2021 [cited by applicant]
US 11194815B1 · Kumar · 2021 [cited by examiner]
US 11270020B1 · Carru et al. · 2022 [cited by applicant]
US 11392578B1 · James et al. · 2022 [cited by applicant]
US 11507685B1 · Carru · 2022 [cited by examiner]
US 11831521B1 · Dhake · 2023 [cited by examiner]
US 20040162786A1 · Cross · 2004 [cited by examiner]
US 20060294192A1 · Mao · 2006 [cited by examiner]
US 20170061012A1 · Bortnikov · 2017 [cited by examiner]
US 20180196955A1 · Dageville et al. · 2018 [cited by applicant]
US 20190122209A1 · Shah · 2019 [cited by examiner]
US 20190294726A1 · Santoso · 2019 [cited by examiner]
US 20200274712A1 · Gray · 2020 [cited by examiner]
US 20200396077A1 · Wojcik · 2020 [cited by examiner]
“U.S. Appl. No. 18/497,232, Notice of Allowance mailed Dec. 27, 2023”, 12 pgs. [cited by applicant]