IP Library › Granted Patent US 12,598,193
Granted Patent B2
US 12,598,193 · App. 18/429,187 · Granted Apr 7, 2026

Fine granularity control of data access and usage across multi-tenant systems

Inventors: Chi Wang (San Francisco, CA); Eugene Wayne Becker (San Francisco, CA); Nidhi Chaudhary (San Francisco, CA); Kishore Chaganti (San Francisco, CA); Prasad Nimmakayala (San Francisco, CA); Qingbo Cai (San Francisco, CA); Linwei Zhu (San Francisco, CA); Hsiang-Yun Lee (San Francisco, CA); Amit Zohar (San Francisco, CA); Raghu Setty (San Francisco, CA); Bhavesh Doshi (San Francisco, CA)
Assignee: Salesforce, Inc.
H04L63/108G06F21/6218H04L63/083H04L63/102H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,193
App. No.
18/429,187
Granted
Apr 7, 2026
Kind
B2
Abstract

System and method for fine granularity control of data access and usage for across multi-tenant systems. A user makes a request to access a particular set of data from a particular remote data source for a specific purpose. The system authorizes the user to validate whether the user is qualified to make the request. The data source is checked to see if the particular data has been granted access for that particular purpose. A cloud neutral token is created and converted into a cloud specific token upon reaching the remote data source. The cloud specific token is used to create a temporary IAM role and IAM policy with a predetermined time to live. After the time to live expires, the IAM role and IAM policy are deleted.

Claims (49)

1 . A system comprising:

a processor;

memory, the memory storing instructions for executing a method, the method comprising:

receiving a request from a user to access a set of data from an associated data consent record at a remote data base for a specific purpose of developing or improving a machine learning (ML) feature;

as a first phase of a three-phase authorization process validating, based on a role of the user, that the user has permission to request data access for an application associated with the request;

verifying that the associated data consent record has granted the user access to the set of data for the specific purpose wherein the data consent record specifies the application, representing the machine learning feature, for which consent is granted and a list of consented data entities;

as a second phase of the three-phase authorization process and responsive to successful validation and verification, generating a context-based token that defines a data scope and an operation scope for the request;

generating a cloud neutral token from the context-based token and the associated data consent record

as a third phase of the three-phase authorization process, converting the cloud neutral token into a cloud specific token and verifying the cloud specific token with backend services of a remote cloud system to apply security scope for data and operations; and

in response to the user being authorized and verified via the three-phase authorization process:

creating a temporary Identity and Access Management (IAM) role and a temporary IAM policy that allows restricted access to the set of data by the user according to the cloud specific token the temporary IAM role and policy being associated with a time to live value, and

automatically deleting the temporary IAM role and temporary IAM policy after the time to live value expires.

2 . The system of claim 1 , wherein the remote cloud system grants access via a data consent process.

3 . The system of claim 1 , wherein validating the user includes validating that the user is part of a team and project that has been granted access from the remote cloud system for that specific purpose.

4 . The system of claim 1 , wherein validating the user does not immediately grant access to the set of data.

5 . The system of claim 1 , wherein after the user is authorized and has access to the set of data, the user can only access the data for the specific purpose and not any other purpose.

6 . The system of claim 1 , wherein the specific purpose is enforced via tagging resources with tags corresponding to an application context field specified in the cloud neutral token.

7 . The system of claim 6 , wherein after the time to live expires the tags are also deleted.

8 . A method comprising:

receiving a request from a user to access a set of data from an associated data consent record at a remote data base for a specific purpose of developing or improving a machine learning (ML) feature;

as a first phase of a three-phase authorization process validating, based on a role of the user, that the user has permission to request data access for an application associated with the request;

verifying that the associated data consent record has granted the user access to the set of data for the specific purpose wherein the data consent record specifies the application, representing the machine learning feature, for which consent is granted and a list of consented data entities;

as a second phase of the three-phase authorization process and responsive to successful validation and verification, generating a context-based token that defines a data scope and an operation scope for the request;

generating a cloud neutral token from the context-based token and the associated data consent record

as a third phase of the three-phase authorization process, converting the cloud neutral token into a cloud specific token and verifying the cloud specific token with backend services of a remote cloud system to apply security scope for data and operations; and

in response to the user being authorized and verified via the three-phase authorization process:

creating a temporary Identity and Access Management (IAM) role and a temporary IAM policy that allows restricted access to the set of data by the user according to the cloud specific token the temporary IAM role and policy being associated with a time to live value, and

automatically deleting the temporary IAM role and temporary IAM policy after the time to live value expires.

9 . The method of claim 8 , wherein the remote cloud system grants access via a data consent process.

10 . The method of claim 8 , wherein validating the user includes validating that the user is part of a team and project that has been granted access from the remote cloud system for that specific purpose.

11 . The method of claim 8 , wherein validating the user does not immediately grant access to the set of data.

12 . The method of claim 8 , wherein after the user is authorized and has access to the set of data, the user can only access the data for the specific purpose and not any other purpose.

13 . The method of claim 8 , wherein the specific purpose is enforced via tagging resources with tags corresponding to an application context field specified in the cloud neutral token.

14 . The method of claim 13 , wherein after the time to live expires the tags are also deleted.

15 . A non-transitory computer readable medium storing instructions to cause a processor to execute a method, the method comprising:

receiving a request from a user to access a set of data from an associated data consent record at a remote data base for a specific purpose of developing or improving a machine learning (ML) feature;

as a first phase of a three-phase authorization process validating, based on a role of the user, that the user has permission to request data access for an application associated with the request;

verifying that the associated data consent record has granted the user access to the set of data for the specific purpose wherein the data consent record specifies the application, representing the machine learning feature, for which consent is granted and a list of consented data entities;

as a second phase of the three-phase authorization process and responsive to successful validation and verification, generating a context-based token that defines a data scope and an operation scope for the request;

generating a cloud neutral token from the context-based token and the associated data consent record

as a third phase of the three-phase authorization process, converting the cloud neutral token into a cloud specific token and verifying the cloud specific token with backend services of a remote cloud system to apply security scope for data and operations; and

in response to the user being authorized and verified via the three-phase authorization process:

creating a temporary Identity and Access Management (IAM) role and a temporary IAM policy that allows restricted access to the set of data by the user according to the cloud specific token the temporary IAM role and policy being associated with a time to live value, and

automatically deleting the temporary IAM role and temporary IAM policy after the time to live value expires.

16 . The method of claim 8 , wherein the time to live value is defined within the cloud neutral token.

17 . The method of claim 8 , wherein the method further comprises attaching a resource tag, encoding the specific purpose and a project identifier, to the temporary IAM role, and wherein access to a data resource is denied unless the resource tag matches a corresponding tag on the data resource.

18 . The method of claim 17 , wherein the temporary IAM policy is further configured to restrict the temporary IAM role to access only specific cloud services and data storage locations based on the operation scope defined in the cloud neutral token.

19 . The method of claim 8 , wherein verifying the cloud specific token with the backend services comprises transmitting the token to a cloud provider's IAM endpoint and receiving a validation response that confirms the permissions encoded in the token are authorized and within the applied security scope.

20 . The method of claim 8 , wherein the cloud neutral token includes a field specifying one or more consented data entities from the data consent record, and wherein the temporary IAM policy is configured to permit access only to those specified data entities.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2026
From: WANG, CHI; BECKER, EUGENE WAYNE; CHAUDHARY, NIDHI; CHAGANTI, KISHORE; NIMMAKAYALA, PRASAD; CAI, QINGBO; ZHU, LINWEI; LEE, HSIANG-YUN; ZOHAR, AMIT; SETTY, RAGHU; DOSHI, BHAVESH
To: SALESFORCE, INC.
Reel/Frame 074246/0464 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 29, 2024
From: WANG, CHI; BECKER, EUGENE WAYNE; CHAUNDHARY, NIDHI; CHAGANTI, KISHORE; NIMMAKAYALA, PRASAD; CAI, QINGBO; ZHU, LINWEI; LEE, HSIANG-YUN; ZOHAR, AMIT; SETTY, RAGHU; DOSHI, BHAVESH
To: SALESFORCE, INC.
Reel/Frame 066608/0732 →
Continuity (2)
Provisional Application 63584833 · Sep 22, 2023
Related Publication 20250106200A1 · Mar 27, 2025
References Cited (30)
US 10757015B2 · Wang et al. · 2020 [cited by applicant]
US 11163722B2 · Wang et al. · 2021 [cited by applicant]
US 11194961B2 · Wang et al. · 2021 [cited by applicant]
US 11582091B2 · Wang et al. · 2023 [cited by applicant]
US 20180077143A1 · Sridharan et al. · 2018 [cited by applicant]
US 20190286832A1 · Szeto et al. · 2019 [cited by applicant]
US 20200007529A1 · Bahrenburg · 2020 [cited by examiner]
US 20200084098A1 · Wang et al. · 2020 [cited by applicant]
US 20210202103A1 · Bostic · 2021 [cited by examiner]
US 20210234864A1 · Dube · 2021 [cited by examiner]
US 20220038449A1 · Tripp et al. · 2022 [cited by applicant]
US 20220043797A1 · Wang et al. · 2022 [cited by applicant]
US 20220046110A1 · Wang et al. · 2022 [cited by applicant]
US 20230224304A1 · Lukanov · 2023 [cited by examiner]
US 20230239301A1 · Ivanov et al. · 2023 [cited by applicant]
US 20230244505A1 · Hernandez Serrano et al. · 2023 [cited by applicant]
US 20230362172A1 · Mandagere et al. · 2023 [cited by applicant]
US 20230418651A1 · Prabhu · 2023 [cited by examiner]
US 20240283784A1 · McCormick · 2024 [cited by applicant]
US 20250106221A1 · Wang et al. · 2025 [cited by applicant]
AWS Security Token Service API Reference API Version Jun. 15, 2011, 2022, pp. 1-58 (Year: 2022). [cited by examiner]
Hong Jiang et al., “Design and Implementation of an Improved Cloud Storage System,” Feb. 2016, pp. 1-8 (Year: 2016). [cited by examiner]
Mohammad Faraji, “Identity Access Management for Multi-tier Cloud Infrastructures,” Jun. 19, 2014, pp. 1-9. (Year: 2014). [cited by examiner]
U.S. Appl. No. 18/429,275, USPTO e-Office Action: NOA—Notice of Allowance, Nov. 21, 2025, 9 pages. [cited by applicant]
U.S. Appl. No. 18/429,331, USPTO e-Office Action: NOA—Notice of Allowance, Jan. 13, 2026, 11 pages. [cited by applicant]
U.S. Appl. No. 18/429,356, USPTO e-Office Action: NOA—Notice of Allowance, Dec. 15, 2025, 9 pages. [cited by applicant]
U.S. Appl. No. 18/429,275, USPTO e-Office Action: CTNF—Non-Final Rejection, Sep. 10, 2025, 15 pages. [cited by applicant]
U.S. Appl. No. 18/429,331, USPTO e-Office Action: CTNF—Non-Final Rejection, Oct. 2, 2025, 25 pages. [cited by applicant]
U.S. Appl. No. 18/429,356, USPTO e-Office Action: CTFR—Final Rejection, Nov. 5, 2025, 9 pages. [cited by applicant]
U.S. Appl. No. 18/429,356, USPTO e-Office Action: CTNF—Non-Final Rejection, Sep. 10, 2025, 16 pages. [cited by applicant]