Remote execution using a global identity

US11570259B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11570259-B2
Application numberUS-202217661096-A
CountryUS
Kind codeB2
Filing dateApr 28, 2022
Priority dateJul 17, 2020
Publication dateJan 31, 2023
Grant dateJan 31, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Embodiments of the present disclosure may provide a streamlined process for performing operations, such as data sharing and data replication, using multiple accounts. A global identity (also referred to as an organization user) may be employed, where the global identity may have access to multiple accounts across the same or different deployments. The global identity may switch between accounts from its login session and perform various tasks in the context of different accounts without undergoing further authentication.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: establishing a login session for a global identity providing access to a plurality of accounts associated with an organization; from the login session: transmitting a first request to establish a first remote session with a first deployment, the first deployment being associated with a first account from the plurality of accounts; receiving a first confirmation message from the first deployment regarding establishing the first remote session including a first remote session identification; transmitting a first execution request to the first deployment to execute a first task, the first execution request including the first remote session identification; receiving a first result in response to the first execution request, the first result being generated in the first deployment using a first proxy user associated with the global identity; transmitting a second request to establish a second remote session with a second deployment, the second deployment being associated with a second account from the plurality of accounts; receiving a second confirmation message from the second deployment regarding establishing the second remote session including a second remote session identification; transmitting a second execution request to the second deployment to execute a second task, the second execution request including the second remote session identification; and receiving a second result in response to the second execution request, the second result being generated in the second deployment using a second proxy user associated with the global identity. 2. The method of claim 1 , further comprising: combining the first and second results to generate a final result. 3. The method of claim 1 , further comprising: authenticating a one-way trust relationship associated with the global identity, wherein the single login session provides access to the plurality of accounts without further authentication. 4. The method of claim 3 , wherein the authenticating is performed using a single sign-on token. 5. The method of claim 1 , further comprising: providing a session pool of active remote sessions in parallel allowing switching by the global identity between the active remote sessions. 6. The method of claim 1 , wherein at least one property value of the first proxy user indicates that that the first proxy user is standing in for the global identity. 7. The method of claim 1 , wherein receiving the first result includes retrieving the first result from a cloud storage location. 8. A system comprising: one or more processors of a machine; and at least one memory storing instructions that, when executed by the one or more processors, cause the machine to perform operations comprising: establishing a login session for a global identity providing access to a plurality of accounts associated with an organization; from the login session: transmitting a first request to establish a first remote session with a first deployment, the first deployment being associated with a first account from the plurality of accounts; receiving a first confirmation message from the first deployment regarding establishing the first remote session including a first remote session identification; transmitting a first execution request to the first deployment to execute a first task, the first execution request including the first remote session identification; receiving a first result in response to the first execution request, the first result being generated in the first deployment using a first proxy user associated with the global identity; transmitting a second request to establish a second remote session with a second deployment, the second deployment being associated with a second account from the plurality of accounts; receiving a second confirmation message from the second deployment regarding establishing the second remote session including a second remote session identification; transmitting a second execution request to the second deployment to execute a second task, the second execution request including the second remote session identification; and receiving a second result in response to the second execution request, the second result being generated in the second deployment using a second proxy user associated with the global identity. 9. The system of claim 8 , the operations further comprising: combining the first and second results to generate a final result. 10. The system of claim 8 , the operations further comprising: authenticating a one-way trust relationship associated with the global identity, wherein the single login session provides access to the plurality of accounts without further authentication. 11. The system of claim 10 , wherein the authenticating is performed using a single sign-on token. 12. The system of claim 8 , the operations further comprising: providing a session pool of active remote sessions in parallel allowing switching by the global identity between the active remote sessions. 13. The system of claim 8 , wherein at least one property value of the first proxy user indicates that that the first proxy user is standing in for the global identity. 14. The system of claim 8 , wherein receiving the first result includes retrieving the first result from a cloud storage location. 15. A non-transitory computer readable storage media storing instructions that, when executed by one or more processors, cause the one or more processors to: establishing a login session for a global identity providing access to a plurality of accounts associated with an organization; from the login session: transmitting a first request to establish a first remote session with a first deployment, the first deployment being associated with a first account from the plurality of accounts; receiving a first confirmation message from the first deployment regarding establishing the first remote session including a first remote session identification; transmitting a first execution request to the first deployment to execute a first task, the first execution request including the first remote session identification; receiving a first result in response to the first execution request, the first result being generated in the first deployment using a first proxy user associated with the global identity; transmitting a second request to establish a second remote session with a second deployment, the second deployment being associated with a second account from the plurality of accounts; receiving a second confirmation message from the second deployment regarding establishing the second remote session including a second remote session identification; transmitting a second execution request to the second deployment to execute a second task, the second execution request including the second remote session identification; and receiving a second result in response to the second execution request, the second result being generated in the second deployment using a second proxy user associated with the global identity. 16. The non-transitory computer readable storage media of claim 15 , further comprising: combining the first and second results to generate a final result. 17. The non-transitory computer readable storage media of claim 15 , further comprising: authenticating a one-way trust relationship associated with the global identity, wherein the single login session provides access to the plurality of accounts without further authentication. 18. The non-transitory computer readable storage media

Assignees

Inventors

Classifications

  • providing single-sign-on or federations · CPC title

  • for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS] · CPC title

  • based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title

  • Network service management, e.g. ensuring proper service fulfilment according to agreements · CPC title

  • G06F21/31Primary

    User authentication · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11570259B2 cover?
Embodiments of the present disclosure may provide a streamlined process for performing operations, such as data sharing and data replication, using multiple accounts. A global identity (also referred to as an organization user) may be employed, where the global identity may have access to multiple accounts across the same or different deployments. The global identity may switch between accounts…
Who is the assignee on this patent?
Snowflake Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/31. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jan 31 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).