IP Library › Granted Patent US 12,067,019
Granted Patent B2
US 12,067,019 · App. 17/538,785 · Granted Aug 20, 2024

Dynamic data restriction in a database clean room

Inventors: Rachel Frances Blum (South Orange, NJ); Justin Langseth (Kailua, HI); Michael Earle Rainey (Pasco, WA)
Assignee: Snowflake Inc.
G06F16/24565G06F16/2443G06F16/27G06F21/6227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,067,019
App. No.
17/538,785
Granted
Aug 20, 2024
Kind
B2
Abstract

Embodiments of the present disclosure may provide a data clean room architecture that dynamically restricts data included in the clean room. The data clean room architecture can implement row access policy or dynamic data masking for row and column based restrictions of data provided through the clean room. The data clean room architecture can provide a limited set of data that does not require obfuscation of data for direction matching and correlation of data in the different datasets, such as matching user identifiers or emails.

Claims (37)

1. A method comprising:

accessing, by a first database account of a distributed database, a shared source dataset from a second database account of the distributed database, the first database account comprising a first local dataset stored locally by the first database account, the shared source dataset being synchronized between the first and second database accounts;

collectively generating, by the first and second database accounts, an approved-statements table comprising one or more database statements that are executable by the distributed database collectively against the first local dataset and the data that is synchronized between the first and second database accounts in the shared source dataset, the first local dataset being different than the shared source dataset;

generating, by the first database account, a database statement that includes a query operation configured to execute on the first local dataset and the shared source dataset;

based on determining, by the distributed database, that the database statement is in the approved-statements table, generating results data by executing the database statement against the first local dataset and the synchronized data in the shared source dataset;

dynamically restricting data of the distributed database by masking one or more columns of data corresponding to a database restriction object, masking the one or more columns of data corresponding to the database restriction object; and

storing, by the distributed database, the results data in the first database account.

2. The method of claim 1 , wherein the database restriction object of the distributed database further comprises a row-based database restriction object by showing or hiding one or more rows of data corresponding to the database restriction object.

3. The method of claim 1 , wherein the database restriction object of the distributed database comprises a column-based database restriction object, wherein masking the one or more columns of data corresponding to the database restriction object comprises replacing the original letters or numbers in the object with other letters or numbers.

4. The method of claim 1 , wherein the database restriction object is executed using execution nodes managed by the first database account.

5. The method of claim 4 , wherein the database statement is executed using one or more first storage units of the distributed database that store the first source dataset managed by the first database account, the one or more first storage units being managed by the first database account.

6. The method of claim 5 , wherein the database statement is executed using one or more second storage units of the distributed database that store the shared source dataset managed by the second database account, the one or more second storage units being managed by the second database account.

7. The method of claim 6 , wherein the database statement comprises a SELECT COUNT statement.

8. The method of claim 1 , wherein the shared source dataset comprises data stored in the shared source dataset that is accessible by both the first and second database accounts, wherein generating the approved-statements table comprises one or more database statements that are executable collectively against the first source dataset and the shared source dataset with data accessible by both the first and second database accounts.

9. The method of claim 1 , wherein the method further comprises: adding, by the first database account, only a subset of the first source dataset to the shared source dataset, wherein generating the approved-statements table comprises one or more database statements that are executable collectively against the first source dataset and the shared source dataset that includes only a subset of the first source dataset.

10. The method of claim 1 , wherein the data within the shared source dataset is synchronized between the first and second database accounts without obfuscating the underlying data.

11. The method of claim 1 , wherein the data within the shared source dataset is shared by the first and second database accounts without obfuscating the underlying data.

12. The method of claim 1 , wherein collectively generating the approved-statements table includes identifying matching statements in a first approved-statements table generated by the first database account and a second approved-statements table generated by the second database account.

13. The method of claim 1 , wherein the row-based database restriction object is further configured to show or hide one or more rows of data based on a type of database statement to be executed.

14. The method of claim 1 , wherein the row-based database restriction object is further configured to show or hide the one or more rows of data during execution of the database statement, the database statement executed on the shown and hidden rows of data.

15. The method of claim 1 , wherein the row-based database restriction object is further configured to mask the one or more columns of data during execution of the database statement, the database statement executed on the masked columns of data.

16. A system comprising:

one or more processors of a machine; and

at least one memory storing instructions that, when executed by the one or more processors, cause the machine to perform operations comprising:

accessing, by a first database account of a distributed database, a shared source dataset from a second database account of the distributed database, the first database account comprising a first local dataset stored locally by the first database account, the shared source dataset being synchronized between the first and second database accounts;

collectively generating, by the first and second database accounts, an approved-statements table comprising one or more database statements that are executable by the distributed database collectively against the first local dataset and the data that is synchronized between the first and second database accounts in the shared source dataset, the first local dataset being different than the shared source dataset;

generating, by the first database account, a database statement that includes a query operation configured to execute on the first local dataset and the shared source dataset;

based on determining, by the distributed database, that the database statement is in the approved-statements table, generating results data by executing the database statement against the first local dataset and the synchronized data in the shared source dataset;

dynamically restricting data of the distributed database by masking one or more columns of data corresponding to a database restriction object, masking the one or more columns of data corresponding to the database restriction object; and

storing, by the distributed database, the results data in the first database account.

17. A non-transitory machine-readable storage device embodying instructions that, when executed by a machine, cause the machine to perform operations comprising:

accessing, by a first database account of a distributed database, a shared source dataset from a second database account of the distributed database, the first database account comprising a first local dataset stored locally by the first database account, the shared source dataset being synchronized between the first and second database accounts;

collectively generating, by the first and second database accounts, an approved-statements table comprising one or more database statements that are executable by the distributed database collectively against the first local dataset and the data that is synchronized between the first and second database accounts in the shared source dataset, the first local dataset being different than the shared source dataset;

generating, by the first database account, a database statement that includes a query operation configured to execute on the first local dataset and the shared source dataset;

based on determining, by the distributed database, that the database statement is in the approved-statements table, generating results data by executing the database statement against the first local dataset and the synchronized data in the shared source dataset;

dynamically restricting data of the distributed database by masking one or more columns of data corresponding to a database restriction object, masking the one or more columns of data corresponding to the database restriction object, and

storing, by the distributed database, the results data in the first database account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2022
From: BLUM, RACHEL FRANCES; LANGSETH, JUSTIN; RAINEY, MICHAEL EARLE
To: SNOWFLAKE INC.
Reel/Frame 058910/0341 →
Continuity (1)
Related Publication 20230169198A1 · Jun 1, 2023