IP Library Granted Patent US 11,288,393
Granted Patent B2
US 11,288,393 · App. 17/354,972 · Granted Mar 29, 2022

Data sharing using alias objects

Inventors: Benoit Dageville (Foster City, CA); Thierry Cruanes (San Mateo, CA); Martin Hentschel (San Mateo, CA); Peter Povinec (Redwood City, CA)
Assignee: SNOWFLAKE INC.
G06F21/6218G06F16/256G06F2221/2145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,288,393
App. No.
17/354,972
Granted
Mar 29, 2022
Kind
B2
Abstract

A method of sharing data in a multi-tenant database includes generating a share object in a first account comprising a share role. The method includes associating one or more access rights with the share role, wherein the one or more access rights indicate which objects in the first account are accessible based on the share object. The method includes granting, to a second account, cross-account access rights to the share role or share object in the first account. The method includes receiving a request from the second account to access data or services of the first account. The method further includes providing a response to the second account based on the data or services of the first account.

Claims (38)

1. A method comprising:

sending, by a processing device to a multiple tenant database, a request for access to one or more resources of a sharer account, the request causes the multiple tenant database to: inspect the sharer account to determine a presence of a grant to a second role object, in a target account associated with the processing device, of access rights to a first role object included in a share object in the sharer account; and grant the second role object, in the target account, access rights to an alias object, wherein the share object includes the first role object having one or more grants to the one or more resources of the sharer account, and wherein the target account accesses the one or more resources using the one or more grants of the share object and using the alias object without at least one of copying the one or more resources or transmitting the one or more resources; and

receiving, by the processing device from the multiple tenant database, access to the one or more resources.

2. The method of claim 1 , wherein each grant of the one or more grants comprises at least one of a usage grant, a modification grant, or a select grant.

3. The method of claim 1 , wherein when the alias object is used, the alias object is internally replaced by an object associated with the one or more resources of the sharer account.

4. The method of claim 1 , wherein the sharer account and the target account are accounts within the multiple tenant database.

5. The method of claim 1 , wherein the alias object references a dataset associated with the one or more resources of the sharer account and the sharer account shares the one or more grants with one or more other target accounts such that the one or more other target accounts can read the dataset without copying or transmitting the dataset using one or more virtual warehouses corresponding to the one or more other target accounts.

6. The method of claim 1 , wherein the alias object references database data associated with the one or more resources of the sharer account.

7. The method of claim 1 , wherein the request for access further causes the multiple tenant database to process the request from the target account using a virtual warehouse corresponding to the target account, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the sharer account to generate a response to the request.

8. The method of claim 1 , wherein the alias object serves as a proxy for an object associated with the one or more resources of the sharer account.

9. The method of claim 1 , wherein the request for access further causes the multiple tenant database to create a link between the alias object and an object associated with the one or more resources of the sharer account.

10. The method of claim 1 , wherein the alias object references an object associated with the one or more resources of the sharer account, the one or more resources of the sharer account are organized in an object hierarchy, and the object is at the top of the object hierarchy.

11. A system comprising:

a memory; and

one or more processors operatively coupled to the memory, the one or more processors to:

send, to a multiple tenant database, a request for access to one or more resources of a sharer account, the request causes the multiple tenant database to: inspect the sharer account to determine a presence of a grant to a second role object, in a target account associated with the one or more processors, of access rights to a first role object included in a share object in a sharer account and grant the second role object, in the target account, access rights to an alias object, wherein the share object includes the first role object having one or more grants to one or more resources of the sharer account, and wherein the target account accesses the one or more resources using the one or more grants of the share object and using the alias object without at least one of copying the one or more resources or transmitting the one or more resources; and

receive, from the multiple tenant database, access to the one or more resources.

12. The system of claim 11 , wherein each grant of the one or more grants comprises at least one of a usage grant, a modification grant, or a select grant.

13. The system of claim 11 , wherein when the alias object is used, the alias object is internally replaced by an object associated with the one or more resources of the sharer account.

14. The system of claim 11 , wherein the sharer account and the target account are accounts within the multiple tenant database.

15. The system of claim 11 , wherein the alias object references a dataset associated with the one or more resources of the sharer account and the sharer account shares the one or more grants with one or more other target accounts such that the one or more other target accounts can read the dataset without copying or transmitting the dataset using one or more virtual warehouses corresponding to the one or more other target accounts.

16. The system of claim 11 , wherein the alias object references database data associated with the one or more resources of the sharer account.

17. The system of claim 11 , wherein the request for access further causes the multiple tenant database to process the request from the target account using a virtual warehouse corresponding to the target account, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the sharer account to generate a response to the request.

18. The system of claim 11 , wherein the alias object serves as a proxy for an object associated with the one or more resources of the sharer account.

19. The system of claim 11 , wherein the request for access further causes the multiple tenant database to create a link between the alias object and an object associated with the one or more resources of the sharer account.

20. The system of claim 11 , wherein the alias object references an object associated with the one or more resources of the sharer account, the one or more resources of the sharer account are organized in an object hierarchy, and the object is at the top of the object hierarchy.

21. A non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more processors, causes the one or more processors to:

send, by the more or more processors to a multiple tenant database, a request for access to one or more resources of a sharer account, the request causes the multiple tenant database to: inspect the sharer account to determine a presence of a grant to a second role object, in a target account associated with the one or more processors, of access rights to a first role object included in a share object in a sharer account and grant the second role object, in the target account, access rights to an alias object, wherein the share object includes the first role object having one or more grants to one or more resources of the sharer account, and wherein the target account accesses the one or more resources using the one or more grants of the share object and using the alias object without at least one of copying the one or more resources or transmitting the one or more resources; and

receive, from the multiple tenant database, access to the one or more resources.

22. The non-transitory computer-readable medium of claim 21 , wherein each grant of the one or more grants comprises at least one of a usage grant, a modification grant, or a select grant.

23. The non-transitory computer-readable medium of claim 21 , wherein when the alias object is used, the alias object is internally replaced by an object associated with the one or more resources of the sharer account.

24. The non-transitory computer-readable medium of claim 21 , wherein the sharer account and the target account are accounts within the multiple tenant database.

25. The non-transitory computer-readable medium of claim 21 , wherein the alias object references a dataset associated with the one or more resources of the sharer account and the sharer account shares the one or more grants with one or more other target accounts such that the one or more other target accounts can read the dataset without copying or transmitting the dataset using one or more virtual warehouses corresponding to the one or more other target accounts.

26. The non-transitory computer-readable medium of claim 21 , wherein the alias object references database data associated with the one or more resources of the sharer account.

27. The non-transitory computer-readable medium of claim 21 , wherein the request for access further causes the multiple tenant database to process the request from the target account using a virtual warehouse corresponding to the target account, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the sharer account to generate a response to the request.

28. The non-transitory computer-readable medium of claim 21 , wherein the alias object serves as a proxy for an object associated with the one or more resources of the sharer account.

29. The non-transitory computer-readable medium of claim 21 , wherein the request for access further causes the multiple tenant database to create a link between the alias object and an object associated with the one or more resources of the sharer account.

30. The non-transitory computer-readable medium of claim 21 , wherein the alias object references an object associated with the one or more resources of the sharer account, the one or more resources of the sharer account are organized in an object hierarchy, and the object is at the top of the object hierarchy.

Assignments (2)
CHANGE OF NAME Recorded Jun 29, 2021
From: SNOWFLAKE COMPUTING INC.
To: SNOWFLAKE INC.
Reel/Frame 056714/0527 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2021
From: DAGEVILLE, BENOIT; CRUANES, THIERRY; HENTSCHEL, MARTIN; POVINEC, PETER
To: SNOWFLAKE COMPUTING INC.
Reel/Frame 056635/0593 →
Continuity (6)
Continuation 17103786 · Nov 24, 2020
Continuation 17004458 · Aug 27, 2020
Continuation 16833482 · Mar 27, 2020
Continuation 16779103 · Jan 31, 2020
Continuation 15402906 · Jan 10, 2017
Related Publication 20210312070A1 · Oct 7, 2021