Salesforce multi-tenant data access control with cloud token security
Summary
USPTO granted Salesforce patent US12598193B2 covering fine granularity control of data access and usage across multi-tenant systems. The system validates user access requests against data source permissions and creates cloud-specific tokens converted from cloud-neutral tokens, establishing temporary IAM roles and policies with automatic expiration.
What changed
USPTO granted patent US12598193B2 to Salesforce, Inc. for a system enabling fine granularity data access control across multi-tenant cloud environments. The invention covers authorizing user requests by validating qualifications and checking data source permissions, creating cloud-neutral tokens converted to cloud-specific tokens at remote data sources, and generating temporary IAM roles and policies with time-to-live expiration for automatic credential cleanup.
Technology companies utilizing multi-tenant cloud architectures and IAM-based access controls should monitor this patent for potential licensing implications or freedom-to-operate concerns. The patent's claims around token conversion, temporary credential generation, and automated policy expiration establish intellectual property protections that may affect how organizations implement similar cloud security mechanisms.
What to do next
- Monitor for potential licensing needs
- Review intellectual property portfolio for overlapping patents
Source document (simplified)
Fine granularity control of data access and usage across multi-tenant systems
Grant US12598193B2 Kind: B2 Apr 07, 2026
Assignee
Salesforce, Inc.
Inventors
Chi Wang, Eugene Wayne Becker, Nidhi Chaudhary, Kishore Chaganti, Prasad Nimmakayala, Qingbo Cai, Linwei Zhu, Hsiang-Yun Lee, Amit Zohar, Raghu Setty, Bhavesh Doshi
Abstract
System and method for fine granularity control of data access and usage for across multi-tenant systems. A user makes a request to access a particular set of data from a particular remote data source for a specific purpose. The system authorizes the user to validate whether the user is qualified to make the request. The data source is checked to see if the particular data has been granted access for that particular purpose. A cloud neutral token is created and converted into a cloud specific token upon reaching the remote data source. The cloud specific token is used to create a temporary IAM role and IAM policy with a predetermined time to live. After the time to live expires, the IAM role and IAM policy are deleted.
CPC Classifications
H04L 63/108 H04L 63/083 H04L 63/102 H04L 63/105 H04L 63/0807 H04L 9/3213 H04L 9/3226 G06F 21/6218 G06F 21/6245 H04W 12/069
Filing Date
2024-01-31
Application No.
18429187
Claims
20
Related changes
Get daily alerts for ChangeBridge: Patent Grants - Networking (H04L)
Daily digest delivered to your inbox.
Free. Unsubscribe anytime.
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get alerts for this source
We'll email you when ChangeBridge: Patent Grants - Networking (H04L) publishes new changes.