IP Library Granted Patent US 10,878,120
Granted Patent B1
US 10,878,120 · App. 17/004,458 · Granted Dec 29, 2020

Granting access rights to objects

Inventors: Benoit Dageville (Foster City, CA); Thierry Cruanes (San Mateo, CA); Martin Hentschel (San Mateo, CA); Peter Povinec (Redwood City, CA)
Assignee: Snowflake Inc.
G06F21/6218G06F16/256G06F2221/2145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,878,120
App. No.
17/004,458
Granted
Dec 29, 2020
Kind
B1
Abstract

A method for sharing data in a multi-tenant database includes granting, by one or more processors, a second role object in a target account access rights to an alias object, wherein the alias object references an object at a top of an object hierarchy. The method also includes granting the second role object in the target account access rights to a first role object included in a share object in a sharer account, wherein the share object includes a first role object having a set of grants to one or more resources of the sharer account, and wherein the target account accesses the one or more resources using the set of grants of the share object and using the alias object without copying the one or more resources.

Claims (26)

1. A method comprising:

granting, by one or more processors, a second role object in a target account access rights to an alias object, wherein the alias object references an object at a top of an object hierarchy, wherein the alias object serves as a proxy for the object at the top of the object hierarchy; and

granting the second role object in the target account access rights to a first role object included in a share object in a sharer account, wherein the share object includes the first role object having a set of grants to one or more resources of the sharer account, and wherein the target account accesses the one or more resources using the set of grants of the share object and using the alias object without copying the one or more resources.

2. The method of claim 1 , wherein each grant of the set grants comprises a usage grant, a modification grant, or a select grant.

3. The method of claim 1 , wherein when the alias object is used, the alias object is internally replaced by the object at the top of the object hierarchy in the sharer account for which the alias object serves as a proxy.

4. The method of claim 1 , wherein the sharer account and the target account are accounts within a multiple tenant database.

5. The method of claim 1 , wherein the object at the top of the object hierarchy is a dataset and the sharer account shares the set of grants with multiple other target such that the multiple other target accounts can read the dataset without ingesting or copying the dataset using one or more virtual warehouses corresponding to the multiple other target accounts.

6. The method of claim 1 , wherein the object at the top of the object hierarchy comprises database data associated with the sharer account.

7. A system comprising:

a memory; and

one or more processors operatively coupled to the memory, the one or more processors to:

grant a second role object in a target account access rights to an alias object, wherein the alias object references an object at a top of an object hierarchy, wherein the alias object serves as a proxy for the object at the top of the object hierarchy; and

grant the second role object in the target account access rights to a first role object included in a share object in a sharer account, wherein the share object includes the first role object having a set of grants to one or more resources of the sharer account, and wherein the target account accesses the one or more resources using the set of grants of the share object and using the alias object without copying the one or more resources.

8. The system of claim 7 , wherein each grant of the set grants comprises a usage grant, a modification grant, or a select grant.

9. The system of claim 7 , wherein when the alias object is used, the alias object is internally replaced by the object at the top of the object hierarchy in the sharer account for which the alias object serves as a proxy.

10. The system of claim 7 , wherein the sharer account and the target account are accounts within a multiple tenant database.

11. The system of claim 7 , wherein the object at the top of the object hierarchy is a dataset and the sharer account shares the set of grants with multiple other target such that the multiple other target accounts can read the dataset without ingesting or copying the dataset using one or more virtual warehouses corresponding to the multiple other target accounts.

12. The system of claim 7 , wherein the object at the top of the object hierarchy comprises database data associated with the sharer account.

13. A non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more processors, causes the one or more processors to:

grant, by the more or more processors, a second role object in a target account access rights to an alias object, wherein the alias object references an object at a top of an object hierarchy, wherein the alias object serves as a proxy for the object at the top of the object hierarchy; and

grant the second role object in the target account access rights to a first role object included in a share object in a sharer account, wherein the share object includes the first role object having a set of grants to one or more resources of the sharer account, and wherein the target account accesses the one or more resources using the set of grants of the share object and using the alias object without copying the one or more resources.

14. The non-transitory computer-readable medium of claim 13 , wherein each grant of the set grants comprises a usage grant, a modification grant, or a select grant.

15. The non-transitory computer-readable medium of claim 13 , wherein when the alias object is used, the alias object is internally replaced by the object at the top of the object hierarchy in the sharer account for which the alias object serves as a proxy.

16. The non-transitory computer-readable medium of claim 13 , wherein the sharer account and the target account are accounts within a multiple tenant database.

17. The non-transitory computer-readable medium of claim 13 , wherein the object at the top of the object hierarchy is a dataset and the sharer account shares the set of grants with multiple other target such that the multiple other target accounts can read the dataset without ingesting or copying the dataset using one or more virtual warehouses corresponding to the multiple other target accounts.

18. The non-transitory computer-readable medium of claim 13 , wherein the object at the top of the object hierarchy comprises database data associated with the sharer account.

Assignments (2)
CHANGE OF NAME Recorded Nov 20, 2020
From: SNOWFLAKE COMPUTING INC.
To: SNOWFLAKE INC.
Reel/Frame 054492/0966 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2020
From: DAGEVILLE, BENOIT; CRUANES, THIERRY; HENTSCHEL, MARTIN; POVINEC, PETER
To: SNOWFLAKE COMPUTING INC.
Reel/Frame 053618/0244 →
Continuity (3)
Continuation 16833482 · Mar 27, 2020
Continuation 16779103 · Jan 31, 2020
Continuation 15402906 · Jan 10, 2017