IP Library Granted Patent US 11,210,415
Granted Patent B2
US 11,210,415 · App. 17/347,143 · Granted Dec 28, 2021

Data sharing in a multi-tenant database system

Inventors: Benoit Dageville (Foster City, CA); Thierry Cruanes (San Mateo, CA); Martin Hentschel (San Mateo, CA); Peter Povinec (Redwood City, CA)
Assignee: Snowflake Inc.
G06F21/6218G06F16/256G06F2221/2145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,210,415
App. No.
17/347,143
Granted
Dec 28, 2021
Kind
B2
Abstract

A method for sharing data in a multi-tenant database includes receiving, by a target account of a multiple tenant database, access rights of a share object in a first account of the multiple tenant database, wherein the share object having access rights to a database object of the first account and wherein access to the database object of the first account by the target account is based on the access rights of the share object. The method also includes receiving, by one or more processors of the target account, access rights to an alias object, wherein the alias object references the database object of the first account.

Claims (38)

1. A method comprising:

sending, by a processing device to a multiple tenant database, a request for data associated with a sharer account, the request causes the multiple tenant database to: generate a share object in the sharer account, the share object including a first role object having a set of grants to one or more resources of the sharer account to be shared with a target account associated with the processing device; and generate, within the target account, an alias object that references an object associated with the one or more resources, wherein the target account accesses a set of data associated with the one or more resources of the sharer account using the set of grants of the share object and the alias object; and

receiving, by the processing device from the multiple tenant database, the set of data.

2. The method of claim 1 , wherein each grant of the set of grants comprises at least one of a usage grant, a modification grant, or a select grant.

3. The method of claim 1 , wherein the request further causes the multiple tenant database to: grant a second role object in the target account access rights to the alias object, and grant the second role object in the target account access rights to the first role object included in the share object such that the target account accesses the set of data associated with the one or more resources using the set of grants of the share object and by way of the alias object without copying the set of data.

4. The method of claim 1 , wherein the alias object serves as a proxy for the object associated with the one or more resources.

5. The method of claim 4 , wherein when the alias object is used, the alias object is internally replaced by the object associated with the one or more resources in the sharer account for which the alias object serves as a proxy.

6. The method of claim 1 , wherein the request further causes the multiple tenant database to receive a second request from the target account to access the set of data, wherein the second request from the target account is directed to the alias object.

7. The method of claim 6 , wherein the request further causes the multiple tenant database to process the second request from the target account using a virtual warehouse corresponding to the target account, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the sharer account to generate a response to the second request.

8. The method of claim 1 , wherein the sharer account and each of the one or more target accounts are accounts within the multiple tenant database.

9. The method of claim 8 , wherein the object associated with the one or more resources is a dataset and the sharer account shares the set of grants with multiple other target accounts of the multiple tenant database such that the multiple other target accounts can read the dataset without ingesting or copying the dataset using one or more virtual warehouses corresponding to the multiple other target accounts.

10. The method of claim 1 , wherein the object associated with the one or more resources comprises database data associated with the sharer account.

11. A system comprising:

a memory; and

one or more processors operatively coupled to the memory, the one or more processors to:

send, to a multiple tenant database, a request for data associated with a sharer account, the request causes the multiple tenant database to: generate a share object in a sharer account, the share object including a first role object having a set of grants to one or more resources of the sharer account to be shared with a target account associated with the one or more processors, and generate, within the target account, an alias object that references an object associated with the one or more resources of the sharer account using the set of grants of the share object and the alias object; and

receive, from the multiple tenant database, the set of data.

12. The system of claim 11 , wherein each grant of the set grants comprises at least one of a usage grant, a modification grant, or a select grant.

13. The system of claim 11 , wherein the request further causes the multiple tenant database to: grant a second role object in the target account access rights to the alias object and grant the second role object in the target account access rights to the first role object included in the share object such that the target account accesses the set of data associated with the one or more resources using the set of grants of the share object and by way of the alias object without copying the set of data.

14. The system of claim 11 , wherein the alias object serves as a proxy for the object associated with the one or more resources.

15. The system of claim 14 , wherein when the alias object is used, the alias object is internally replaced by the object associated with the one or more resources in the sharer account for which the alias object serves as a proxy.

16. The system of claim 11 , wherein the request further causes the multiple tenant database to receive a second request from the target account to access the set of data, wherein the second request from the target account is directed to the alias object.

17. The system of claim 16 , wherein the request further causes the multiple tenant database to process the second request from the target account using a virtual warehouse corresponding to the target account, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the sharer account to generate a response to the second request.

18. The system of claim 11 , wherein the sharer account and each of the one or more target accounts are accounts within the multiple tenant database.

19. The system of claim 18 , wherein the object associated with the one or more resources is a dataset and the sharer account shares the set of grants with multiple other target accounts of the multiple tenant database such that the multiple other target accounts can read the dataset without ingesting or copying the dataset using one or more virtual warehouses corresponding to the multiple other target accounts.

20. The system of claim 11 , wherein the object associated with the one or more resources comprises database data associated with the sharer account.

21. A non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more processors, causes the one or more processors to:

send, by the one or more processors to a multiple tenant database, a request for data associated with a sharer account, the request causes the multiple tenant database to: generate a share object in a sharer account, the share object including a first role object having a set of grants to one or more resources of the sharer account to be shared with a target account associated with the processing device, and generate, within the target account, an alias object that references an object associated with the one or more resources of the sharer account using the set of grants of the share object and the alias object; and

receive, from the multiple tenant database, the set of data.

22. The non-transitory computer-readable medium of claim 21 , wherein each grant of the set grants comprises at least one of a usage grant, a modification grant, or a select grant.

23. The non-transitory computer-readable medium of claim 21 , wherein the request further causes the multiple tenant database to: grant a second role object in the target account access rights to the alias object, and grant the second role object in the target account access rights to the first role object included in the share object such that the target account accesses the set of data, associated with the one or more resources using the set of grants of the share object and by way of the alias object without copying the set of data.

24. The non-transitory computer-readable medium of claim 21 , wherein the alias object serves as a proxy for the object associated with the one or more resource.

25. The non-transitory computer-readable medium of claim 24 , wherein when the alias object is used, the alias object is internally replaced by the object associated with the one or more resources in the sharer account for which the alias object serves as a proxy.

26. The non-transitory computer-readable medium of claim 21 , wherein the request further causes the multiple tenant database to receive a second request from the target account to access the set of data, wherein the second request from the target account is directed to the alias object.

27. The non-transitory computer-readable medium of claim 26 , wherein the request further causes the multiple tenant database to process the second request from the target account using a virtual warehouse corresponding to the target account, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the sharer account to generate a response to the second request.

28. The non-transitory computer-readable medium of claim 21 , wherein the sharer account and each of the one or more target accounts are accounts within the multiple tenant database.

29. The non-transitory computer-readable medium of claim 28 , wherein the object associated with the one or more resources is a dataset and the sharer account shares the set of grants with multiple other target accounts of the multiple tenant database such that the multiple other target accounts can read the dataset without ingesting or copying the dataset using one or more virtual warehouses corresponding to the multiple other target accounts.

30. The non-transitory computer-readable medium of claim 21 , wherein the object associated with the one or more resources comprises database data associated with the sharer account.

Assignments (2)
CHANGE OF NAME Recorded Jun 22, 2021
From: SNOWFLAKE COMPUTING INC.
To: SNOWFLAKE INC.
Reel/Frame 056646/0686 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2021
From: DAGEVILLE, BENOIT; CRUANES, THIERRY; HENTSCHEL, MARTIN; POVINEC, PETER
To: SNOWFLAKE COMPUTING INC.
Reel/Frame 056543/0258 →
Continuity (5)
Continuation 17005163 · Aug 27, 2020
Continuation 16833482 · Mar 27, 2020
Continuation 16779103 · Jan 31, 2020
Continuation 15402906 · Jan 10, 2017
Related Publication 20210303719A1 · Sep 30, 2021