IP Library Granted Patent US 10,642,993
Granted Patent B1
US 10,642,993 · App. 16/779,103 · Granted May 5, 2020

Data sharing in a multi-tenant database system

Inventors: Benoit Dageville (Foster City, CA); Thierry Cruanes (San Mateo, CA); Martin Hentschel (San Mateo, CA); Peter Povinec (Redwood City, CA)
Assignee: Snowflake Inc.
G06F21/6218G06F16/256G06F2221/2145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,642,993
App. No.
16/779,103
Granted
May 5, 2020
Kind
B1
Abstract

A method for sharing data in a multi-tenant database includes generating a share object in a first account comprising a share role. The method includes associating one or more access rights with the share role, wherein the one or more access rights indicate which objects in the first account are accessible based on the share object. The method includes granting, to a second account, cross-account access rights to the share role or share object in the first account. The method includes receiving a request from the second account to access data or services of the first account. The method further includes providing a response to the second account based on the data or services of the first account.

Claims (39)

1. A method comprising:

granting to a second account of a multiple tenant database, access rights of a share object in a first account of the multiple tenant database, the share object having access rights to a database object of the first account and wherein access to the database object by the second account is based on the access rights of the share object; and

generating, within the second account, an alias object that references the database object; and

linking, by one or more processors, the alias object to the database object, wherein the second account accesses the database object using the access rights of the share object and directs a request to access the database object to the alias object.

2. The method of claim 1 , further comprising:

granting the second account access rights to the alias object such that the second account accesses the database object using the access rights of the share object and by way of the alias object without copying the database object.

3. The method of claim 1 , wherein the alias object serves as a proxy for the database object.

4. The method of claim 1 , further comprising processing the request from the second account using a virtual warehouse corresponding to the second account, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the first account to generate a response to the request.

5. The method of claim 1 , further comprising storing an indication that the first account has granted access rights to the database object to the second account in a list of share objects, wherein the list of share objects indicates which accounts have access rights to which share objects associated with the first account.

6. The method of claim 1 , wherein the database object is a dataset and the first account grants access rights to the database object to multiple other accounts of the multiple tenant database such that the multiple other accounts can read the dataset without ingesting or copying the dataset using one or more virtual warehouses corresponding to the multiple other accounts.

7. The method of claim 1 , wherein the database object comprises database data associated with the first account of the multiple tenant database.

8. A system comprising:

a memory; and

one or more processors operatively coupled to the memory, the one or more processors to:

grant to a second account of a multiple tenant database, access rights of a share object in a first account of the multiple tenant database, the share object having access rights to a database object of the first account and wherein access to the database object by the second account is based on the access rights of the share object;

generate, within the second account, an alias object that references the database object; and

link the alias object to the database object, wherein the second account accesses the database object using the access rights of the share object and directs a request to access the database object to the alias object.

9. The system of claim 8 , wherein the one or more processors are further to:

grant the second account access rights to the alias object such that the second account accesses the database object using the access rights of the share object and by way of the alias object without copying the database object.

10. The system of claim 8 , wherein the alias object serves as a proxy for the database object.

11. The system of claim 8 , wherein the one or more processors are further to:

process the request from the second account using a virtual warehouse corresponding to the second account, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the first account to generate a response to the request.

12. The system of claim 8 , wherein the one or more processors are further to:

store an indication that the first account has granted access rights to the database object to the second account in a list of share objects, wherein the list of share objects indicates which accounts have access rights to which share objects associated with the first account.

13. The system of claim 8 , wherein the database object is a dataset and the one or more processors grant access rights to the database object to multiple other accounts of the multiple tenant database such that the multiple other accounts can read the dataset without ingesting or copying the dataset using one or more virtual warehouses corresponding to the multiple other accounts.

14. The system of claim 8 , wherein the database object comprises database data associated with the first account of the multiple tenant database.

15. A non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more processors, causes the one or more processors to:

grant to a second account of a multiple tenant database, access rights of a share object in a first account of the multiple tenant database, the share object having access rights to a database object of the first account and wherein access to the database object by the second account is based on the access rights of the share object;

generate, within the second account, an alias object that references the database object; and

link, by the one or more processors, the alias object to the database object, wherein the second account accesses the database object using the access rights of the share object and directs a request to access the database object to the alias object.

16. The non-transitory computer-readable medium of claim 15 , wherein the one or more processors are further to:

grant the second account access rights to the alias object such that the second account accesses the database object using the access rights of the share object and by way of the alias object without copying the database object.

17. The non-transitory computer-readable medium of claim 15 , wherein the alias object serves as a proxy for the database object.

18. The non-transitory computer-readable medium of claim 15 , wherein the one or more processors are further to:

process the request from the second account using a virtual warehouse corresponding to the second account, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the first account to generate a response to the request.

19. The non-transitory computer-readable medium of claim 15 , wherein the one or more processors are further to:

store an indication that the first account has granted access rights to the database object to the second account in a list of share objects, wherein the list of share objects indicates which accounts have access rights to which share objects associated with the first account.

20. The non-transitory computer-readable medium of claim 15 , wherein the database object is a dataset and the one or more processors grant access rights to the database object to multiple other accounts of the multiple tenant database such that the multiple other accounts can read the dataset without ingesting or copying the dataset using one or more virtual warehouses corresponding to the multiple other accounts.

21. The non-transitory computer-readable medium of claim 15 , wherein the database object comprises database data associated with the first account of the multiple tenant database.

Assignments (2)
CHANGE OF NAME Recorded Mar 26, 2020
From: SNOWFLAKE COMPUTING INC.
To: SNOWFLAKE INC.
Reel/Frame 052244/0569 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SERIAL NUMBER 16777120 SHOULD HAVE BEEN 16799103 PREVIOUSLY RECORDED ON REEL 051715 FRAME 0142. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGN, TRANSFER AND CONVEY TO ASSIGNEE ANY RIGHT, TITLE AND INTEREST. Recorded Feb 10, 2020
From: DAGEVILLE, BENOIT; CRUANES, THIERRY; HENTSCHEL, MARTIN; POVINEC, PETER
To: SNOWFLAKE COMPUTING INC.
Reel/Frame 051871/0189 →
Continuity (1)
Continuation 15402906 · Jan 10, 2017