IP Library Granted Patent US 12,277,237
Granted Patent B2
US 12,277,237 · App. 17/514,982 · Granted Apr 15, 2025

Managed metastorage

Inventors: Matei Zaharia (Palo Alto, CA); David Lewis (Salt Lake City, UT); Cheng Lian (Alameda, CA); Yuchen Huo (San Bruno, CA); Ali Ghodsi (Berkeley, CA)
Assignee: Databricks, Inc.
G06F21/62G06F3/0604G06F3/0655G06F3/0673
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,277,237
App. No.
17/514,982
Granted
Apr 15, 2025
Kind
B2
Abstract

The present application discloses a method, system, and computer system for providing access to information stored on system for data storage. The method includes receiving a data request from a user, determining data corresponding to the data request, determining whether the user has requisite permissions to access the data, and in response to determining that the user has requisite permissions to access the data: determining a manner by which to provide access to the data, wherein the data comprises a filtered subset of stored data, and generating a token based at least in part on the user and the manner by which access to the data is to be provided.

Claims (52)

1. A system, comprising:

one or more processors; and

a memory, coupled with the one or more processors, the memory comprising stored instructions executable by the one or more processors, the instructions when executed causes the one or more processors to:

receive a data request from a user;

determine data corresponding to the data request;

determine whether the user has requisite permissions to access the data; and

in response to a determination that the user has requisite permissions to access the data:

determine, based on an identity of the user, a manner by which to provide access to the data, wherein the data comprises a filtered subset of stored data, wherein the determination of the manner by which to provide access to the data further comprises instructions to determine whether to provide the data via a secure cluster or to provide data by providing access to a location at which the data is stored, wherein the secure cluster is a set of connected nodes;

in response to a determination to provide data via a secure cluster, instantiating a secure cluster;

copying the filtered subset of stored data from the location at which the data is stored to the instantiated secure cluster, wherein the filtered subset of stored data copied to the instantiated secure cluster may only be accessible to the user; and

generate a token based at least in part on the user and the instantiated secure cluster.

2. The system of claim 1 , wherein the filtered subset of the stored data is stored in a new structure, a file, or table.

3. The system of claim 2 , wherein the token enables access to an entity stored on the secure cluster.

4. The system of claim 3 , wherein the filtered subset of the stored data is transferred from a storage system without selective access control.

5. The system of claim 1 , further comprising:

in response to determining to provide data by providing access to a location at which the data is stored, providing a path to the location at which the data is stored.

6. The system of claim 1 , wherein:

a storage system storing the stored data allows only access to the filtered subset of the stored data based on the token;

the storage system constitutes certain data responsive to the data request; and

in response to receiving a request in connection with the token, the storage system permits access associated with the request to only a table that has been constituted.

7. The system of claim 6 , wherein the certain data is constituted based on permissions associated with the user.

8. The system of claim 1 , wherein:

the stored data is stored on a system for data storage; and

user requests to access data comprised in the system for data storage are mediated by a metastore layer.

9. The system of claim 8 , wherein the metastore layer stores an index of information comprised in the stored data.

10. The system of claim 8 , wherein the metastore layer stores metadata associated with information comprised in the stored data.

11. The system of claim 8 , wherein the metastore layer stores permissions for one or more users with respect to information comprised in the stored data.

12. The system of claim 1 , wherein an extent of a permission that the token provides with respect to the stored data is defined based on the data request.

13. The system of claim 1 , wherein the token expires after a preset period of time, at a preset time, or in response to an action.

14. The system of claim 1 , wherein the one or more processors are further configured to provide to the user the token with which the user is to access data responsive to the data request.

15. A method, comprising:

receiving, by one or more processors, a data request from a user;

determining data corresponding to the data request;

determining whether the user has requisite permissions to access the data; and

in response to determining that the user has requisite permissions to access the data:

determining, based on an identity of the user, a manner by which to provide access to the data, wherein the data comprises a filtered subset of stored data, wherein determining the manner by which to provide access to the data further comprises determining whether to provide the data via a secure cluster or to provide data by providing access to a location at which the data is stored, wherein the secure cluster is a set of connected nodes;

in response to determining to provide data via a secure cluster, instantiating a secure cluster;

copying the filtered subset of stored data from the location at which the data is stored to the instantiated secure cluster, wherein the filtered subset of stored data copied to the instantiated secure cluster may only be accessible to the user; and

a token based at least in part on the user and the instantiated secure cluster.

16. The method of claim 15 , the filtered subset of the stored data is stored in a new structure, a file, or table.

17. The method of claim 15 , wherein the token enables access to an entity stored on the secure cluster.

18. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving, by one or more processors, a data request from a user;

determining data corresponding to the data request;

determining whether the user has requisite permissions to access the data; and

in response to determining that the user has requisite permissions to access the data:

determining, based on an identity of the user, a manner by which to provide access to the data, wherein the data comprises a filtered subset of stored data, wherein determining the manner by which to provide access to the data further comprises determining whether to provide the data via a secure cluster or to provide data by providing access to a location at which the data is stored, wherein the secure cluster is a set of connected nodes;

in response to determining to provide data via a secure cluster, instantiating a secure cluster;

copying the filtered subset of stored data from the location at which the data is stored to the instantiated secure cluster, wherein the filtered subset of stored data copied to the instantiated secure cluster may only be accessible to the user; and

generating a token based at least in part on the user and the instantiated secure cluster.

19. The computer program product embodied in the non-transitory computer readable medium of claim 18 , the filtered subset of the stored data is stored in a new structure, a file, or table.

20. The computer program product embodied in the non-transitory computer readable medium of claim 18 , wherein the token enables access to an entity stored on the secure cluster.

Assignments (3)
SECURITY INTEREST Recorded Jan 6, 2025
From: DATABRICKS, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 069825/0419 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S NAME PREVIOUSLY RECORDED AT REEL: 058609 FRAME: 0936. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jul 13, 2023
From: ZAHARIA, MATEI; LEWIS, DAVID; LIAN, CHENG; HUO, YUCHEN; GHODSI, ALI
To: DATABRICKS, INC.
Reel/Frame 064273/0634 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2022
From: ZAHARIA, MATEI; LEWIS, DAVID; LIAN, CHENG; HUO, YUCHEN; GHODSI, ALI
To: DATABRICKS INC.
Reel/Frame 058609/0936 →
Continuity (2)
Provisional Application 63190591 · May 19, 2021
Related Publication 20220374532A1 · Nov 24, 2022
References Cited (7)
US 9594922B1 · McGuire · 2017 [cited by examiner]
US 11200331B1 · Bouaichi · 2021 [cited by examiner]
US 20140172808A1 · Burge · 2014 [cited by examiner]
US 20140282192A1 · Grossman · 2014 [cited by examiner]
US 20150149441A1 · Nica · 2015 [cited by examiner]
US 20160034547A1 · Lerios · 2016 [cited by examiner]
US 20210279365A1 · Apsingekar · 2021 [cited by examiner]