IP Library Granted Patent US 12,568,090
Granted Patent B2
US 12,568,090 · App. 18/160,801 · Granted Mar 3, 2026

Systems and methods for managing database-level roles for data sharing

Inventors: Damien Carru (Rhinebeck, NY); Jeremy Yujui Chen (Newark, CA); Laxman Mamidi (Redwood City, CA); Bowen Zhang (Newark, CA)
Assignee: Snowflake Inc.
H04L63/105G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,090
App. No.
18/160,801
Granted
Mar 3, 2026
Kind
B2
Abstract

Disclosed herein are systems and methods for managing database-level roles for data sharing. In an embodiment, a database system shares a database that resides in a data-provider account with a data-consumer account. The provider-side database includes a provider-side database-level role. The database system receives a request to grant the provider-side database-level role to a consumer-side account-level role in the data-consumer account. The database system responsively grants a hidden provider-side database-level role in the data-provider account to a hidden consumer-side database-level role in the data-consumer account, where the hidden provider-side database-level role had been granted to the provider-side database-level role, and grants the hidden consumer-side database-level role to the consumer-side account-level role in the data-consumer account.

Claims (98)

1 . A method performed by a database system executing instructions on at

least one hardware processor, the method comprising:

receiving a first database-mounting request from a data-consumer account;

establishing, in the data-consumer account in response to receiving the first database mounting request, a first mounted database that resides in the data-consumer account of the database system, the first mounted database being a shadow database comprising references to table data stored in a provider-side database in a data-provider account;

receiving a database-role-grant request to grant a provider-side database-level role to a consumer-side account-level role in the data-consumer account for the first mounted database, the provider-side database-level role having one or more database-level-role privileges, the database level-role privileges comprising at least one of: read access, write access, visibility access, usage access, or administrative access;

performing, responsive to receiving the database-role-grant request, a set of database-role granting operations comprising granting a first hidden provider-side database-level role to a hidden consumer-side account-level role in the data-consumer account for the first mounted database without granting the first hidden provider-side database-level role to the consumer-side account level role, the hidden consumer-side database-level role enabling the data-consumer account to perform one or more functions on a particular set of data with the role being hidden from the data consumer account, the hidden provider-side database-level role being hidden from the data-provider account;

receiving a second database-mounting request from the data-consumer account;

establishing, in the data-consumer account in response to receiving the second database mounting request, a second mounted database, the first and second mounted databases being shadow databases storing reference pointers to data stored in a provider-side database;

receiving a database-role-grant request to grant a provider-side database-level role to a consumer-side account-level role in the data-consumer account for the second mounted database;

granting a second hidden consumer-side database-level role to the consumer-side account level role in the data-consumer account for the second mounted database;

receiving a request to demount the first mounted database; and

in response to receiving the request to demount the first mounted database, revoking a first hidden consumer-side database-level role without revoking the second hidden consumer-side database-level role leaving the second mounted database mounted on the data-consumer account.

2 . The method of claim 1 , wherein:

the provider-side database comprises a table; and

the one or more database-level-role privileges comprise access to the table.

3 . The method of claim 1 , wherein the set of database-role-granting operations further comprises:

creating a hidden provider-side database-level role in a data-provider account;

granting the provider-side database-level role to the hidden provider-side database-level role; and

creating the first hidden consumer-side database-level role in the data-consumer account.

4 . The method of claim 3 , further comprising:

receiving a database-mounting request from the data-consumer account; and

establishing, in the data-consumer account in response to receiving the database-mounting request, a mounted database corresponding to the provider-side database,

wherein the first hidden consumer-side database-level role is created in the mounted database in the data-consumer account.

5 . The method of claim 4 , wherein the mounted database in the data-consumer account corresponding to the provider-side database comprises the mounted database being a shadow database of references to table data stored in the provider-side database in the data-provider account.

6 . The method of claim 4 , further comprising:

establishing, in the data-consumer account, a second mounted database corresponding to the provider-side database;

receiving a second database-role-grant request to grant the provider-side database-level role to the consumer-side account-level role in the data-consumer account in connection with the second mounted database;

performing, responsive to receiving the second database-role-grant request, a second set of database-role-granting operations comprising:

creating, in the second mounted database, a second hidden consumer-side database-level role;

granting the hidden provider-side database-level role to the second hidden consumer-side database-level role; and

granting the second hidden consumer-side database-level role to the consumer-side account-level role in the data-consumer account in connection with the second mounted database.

7 . The method of claim 1 , wherein receiving the database-role-grant request comprises receiving the database-role-grant request from the data-consumer account.

8 . The method of claim 1 , further comprising receiving a second database-role-grant request to grant the provider-side database-level role to a second consumer-side account-level role in the data-consumer account, and responsively granting the first hidden consumer-side database-level role to the second consumer-side account-level role in the data-consumer account.

9 . The method of claim 3 , further comprising:

receiving a database-role-revoke request to revoke the provider-side database-level role from the consumer-side account-level role; and

revoking, responsive to receiving the database-role-revoke request, the hidden provider-side database-level role from the first hidden consumer-side database-level role.

10 . The method of claim 1 , wherein granting the first hidden provider-side database-level role to the hidden consumer-side account-level role in the data-consumer account for the first mounted database without granting the first hidden provider-side database-level role to the consumer-side account-level role comprises granting privileges of the first hidden provider-side database-level role to the hidden consumer-side account-level role while the consumer-side account-level role itself being hidden from the data-consumer account.

11 . The method of claim 1 , wherein granting the first hidden provider-side database-level role to the hidden consumer-side account-level role in the data-consumer account for the first mounted database without granting the first hidden provider-side database-level role to the consumer-side account-level role comprises granting privileges of the first hidden provider-side database-level role to the hidden consumer-side account-level role without granting at least some privileges of an unhidden provider-side database-level role to the consumer-side account-level role while the consumer-side account-level role itself being hidden from the data-consumer account.

12 . The method of claim 1 , wherein the hidden consumer-side database- level role enabling visibility of the particular set of data to the data-consumer account while the role being hidden from the data-consumer account.

13 . A database system comprising:

at least one hardware processor; and

one or more non-transitory computer readable storage media containing instructions that, when executed by the at least one hardware processor, cause the at least one hardware processor to perform operations comprising:

receiving a first database-mounting request from a data-consumer account;

establishing, in the data-consumer account in response to receiving the first database mounting request, a first mounted database that resides in the data-consumer account of the database system, the first mounted database being a shadow database comprising references to table data stored in a provider-side database in a data-provider account;

receiving a database-role-grant request to grant a provider-side database-level role to a consumer-side account-level role in the data-consumer account for the first mounted database, the provider-side database-level role having one or more database-level-role privileges, the database level-role privileges comprising at least one of: read access, write access, visibility access, usage access, or administrative access;

performing, responsive to receiving the database-role-grant request, a set of database-role granting

operations comprising granting a first hidden provider-side database-level role to a hidden consumer-side account-level role in the data-consumer account for the first mounted database without granting the first hidden provider-side database-level role to the consumer-side account level role, the hidden consumer-side database-level role enabling the data-consumer account to perform one or more functions on a particular set of data with the role being hidden from the data consumer account, the hidden provider-side database-level role being hidden from the data-provider account;

receiving a second database-mounting request from the data-consumer account;

establishing, in the data-consumer account in response to receiving the second database mounting request, a second mounted database, the first and second mounted databases being shadow databases storing reference pointers to data stored in a provider-side database;

receiving a database-role-grant request to grant a provider-side database-level role to a consumer-side account-level role in the data-consumer account for the second mounted database;

granting a second hidden consumer-side database-level role to the consumer-side account level role in the data-consumer account for the second mounted database;

receiving a request to demount the first mounted database; and

in response to receiving the request to demount the first mounted database, revoking a first hidden consumer-side database-level role without revoking the second hidden consumer-side database-level role leaving the second mounted database mounted on the data-consumer account.

14 . The database system of claim 13 , wherein:

the provider-side database comprises a table; and

the one or more database-level-role privileges comprise access to the table.

15 . The database system of claim 13 , wherein the set of database-role- granting operations further comprises:

creating a hidden provider-side database-level role in a data-provider account;

granting the provider-side database-level role to the hidden provider-side database-level role; and

creating the first hidden consumer-side database-level role in the data-consumer account.

16 . The database system of claim 15 , the operations further comprising:

receiving a database-mounting request from the data-consumer account; and

establishing, in the data-consumer account in response to receiving the database-mounting request, a mounted database corresponding to the provider-side database,

wherein the first hidden consumer-side database-level role is created in the mounted database in the data-consumer account.

17 . The database system of claim 16 , wherein the mounted database in the data-consumer account corresponding to the provider-side database comprises the mounted database being a shadow database of references to table data stored in the provider-side database in the data-provider account.

18 . The database system of claim 16 , the operations further comprising:

establishing, in the data-consumer account, a second mounted database corresponding to the provider-side database;

receiving a second database-role-grant request to grant the provider-side database-level role to the consumer-side account-level role in the data-consumer account in connection with the second mounted database;

performing, responsive to receiving the second database-role-grant request, a second set of database-role-granting operations comprising:

creating, in the second mounted database, a second hidden consumer-side database-level role;

granting the hidden provider-side database-level role to the second hidden consumer-side database-level role; and

granting the second hidden consumer-side database-level role to the consumer-side account-level role in the data-consumer account in connection with the second mounted database.

19 . The database system of claim 13 , wherein receiving the database-role-grant request comprises receiving the database-role-grant request from the data-consumer account.

20 . The database system of claim 13 , the operations further comprising receiving a second database-role-grant request to grant the provider-side database-level role to a second consumer-side account-level role in the data-consumer account, and responsively granting the first hidden consumer-side database-level role to the second consumer-side account-level role in the data-consumer account.

21 . The database system of claim 15 , the operations further comprising:

receiving a database-role-revoke request to revoke the provider-side database-level role from the consumer-side account-level role; and

revoking, responsive to receiving the database-role-revoke request, the hidden provider-side database-level role from the first hidden consumer-side database-level role.

22 . One or more non-transitory computer readable storage media containing instructions that, when executed by at least one hardware processor of a database system, cause the database system to perform operations comprising:

receiving a first database-mounting request from a data-consumer account;

establishing, in the data-consumer account in response to receiving the first database mounting request, a first mounted database that resides in the data-consumer account of the database system, the first mounted database being a shadow database comprising references to table data stored in a provider-side database in a data-provider account;

receiving a database-role-grant request to grant a provider-side database-level role to a consumer-side account-level role in the data-consumer account for the first mounted database, the provider-side database-level role having one or more database-level-role privileges, the database level-role privileges comprising at least one of: read access, write access, visibility access, usage access, or administrative access;

performing, responsive to receiving the database-role-grant request, a set of database-role granting operations comprising granting a first hidden provider-side database-level role to a hidden consumer-side account-level role in the data-consumer account for the first mounted database without granting the first hidden provider-side database-level role to the consumer-side account level role, the hidden consumer-side database-level role enabling the data-consumer account to perform one or more functions on a particular set of data with the role being hidden from the data consumer account, the hidden provider-side database-level role being hidden from a data-provider account;

receiving a second database-mounting request from the data-consumer account;

establishing, in the data-consumer account in response to receiving the second database mounting request, a second mounted database, the first and second mounted databases being shadow databases storing reference pointers to data stored in a provider-side database;

receiving a database-role-grant request to grant a provider-side database-level role to a consumer-side account-level role in the data-consumer account for the second mounted database;

granting a second hidden consumer-side database-level role to the consumer-side account level role in the data-consumer account for the second mounted database;

receiving a request to demount the first mounted database; and

in response to receiving the request to demount the first mounted database, revoking a first hidden consumer-side database-level role without revoking the second hidden consumer-side database-level role leaving the second mounted database mounted on the data-consumer account.

23 . The one or more non-transitory computer readable storage media of claim 22 , wherein:

the provider-side database comprises a table; and

the one or more database-level-role privileges comprise access to the table.

24 . The one or more non-transitory computer readable storage media of claim 22 , wherein the set of database-role-granting operations further comprises:

creating a hidden provider-side database-level role in a data-provider account;

granting the provider-side database-level role to the hidden provider-side database-level role; and

creating the first hidden consumer-side database-level role in the data-consumer account.

25 . The one or more non-transitory computer readable storage media of claim 24 , the operations further comprising:

receiving a database-mounting request from the data-consumer account; and

establishing, in the data-consumer account in response to receiving the database-mounting request, a mounted database corresponding to the provider-side database, wherein the first hidden consumer-side database-level role is created in the mounted database in the data-consumer account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2023
From: CARRU, DAMIEN; CHEN, JEREMY YUJUI; MAMIDI, LAXMAN; ZHANG, BOWEN
To: SNOWFLAKE INC.
Reel/Frame 062806/0834 →
Continuity (1)
Related Publication 20240259387A1 · Aug 1, 2024
References Cited (61)
US 5946399A · Kitaj · 1999 [cited by examiner]
US 6993657B1 · Renner · 2006 [cited by examiner]
US 8473880B1 · Bennett · 2013 [cited by examiner]
US 8595064B1 · Hagy · 2013 [cited by examiner]
US 9111114B1 · Choi · 2015 [cited by examiner]
US 9244976B1 · Zhang · 2016 [cited by examiner]
US 9659040B1 · Bellingan · 2017 [cited by examiner]
US 9824095B1 · Taylor · 2017 [cited by examiner]
US 10044723B1 · Fischer · 2018 [cited by examiner]
US 10824751B1 · Kurian · 2020 [cited by examiner]
US 11366920B1 · Carru · 2022 [cited by examiner]
US 11487893B1 · Carru · 2022 [cited by examiner]
US 11580245B1 · Carru · 2023 [cited by examiner]
US 11704338B1 · Chu · 2023 [cited by examiner]
US 20020116385A1 · Kagalwala · 2002 [cited by examiner]
US 20060248083A1 · Sack · 2006 [cited by examiner]
US 20080086482A1 · Weissman · 2008 [cited by examiner]
US 20080221964A1 · Berkovitz · 2008 [cited by examiner]
US 20090190584A1 · Gemmer · 2009 [cited by examiner]
US 20100100461A1 · Laing · 2010 [cited by examiner]
US 20110087646A1 · Dalvi · 2011 [cited by examiner]
US 20110238553A1 · Raj · 2011 [cited by examiner]
US 20110265188A1 · Ramaswamy · 2011 [cited by examiner]
US 20110321159A1 · Nestler · 2011 [cited by examiner]
US 20120254258A1 · Gao · 2012 [cited by examiner]
US 20130031136A1 · Shah · 2013 [cited by examiner]
US 20130262685A1 · Shelton · 2013 [cited by examiner]
US 20140108794A1 · Barton · 2014 [cited by examiner]
US 20150074747A1 · Philip · 2015 [cited by examiner]
US 20150326580A1 · McMillan · 2015 [cited by examiner]
US 20160057151A1 · Brock · 2016 [cited by examiner]
US 20160072817A1 · Makhervaks · 2016 [cited by examiner]
US 20160098572A1 · Povalyayev · 2016 [cited by examiner]
US 20160134929A1 · Robii · 2016 [cited by examiner]
US 20170169059A1 · Horowitz · 2017 [cited by examiner]
US 20180196955A1 · Dageville · 2018 [cited by examiner]
US 20180315053A1 · Schukai · 2018 [cited by examiner]
US 20200042737A1 · Lee · 2020 [cited by examiner]
US 20210043284A1 · Liphardt · 2021 [cited by examiner]
US 20210157948A1 · Avanes · 2021 [cited by examiner]
US 20220035556A1 · Cashman · 2022 [cited by examiner]
US 20220150256A1 · Kapoor · 2022 [cited by examiner]
US 20220335263A1 · Balgañón Canela · 2022 [cited by examiner]
US 20220358141A1 · Chu · 2022 [cited by examiner]
US 20230063911A1 · Carru · 2023 [cited by examiner]
CN 109525570A · 2019 [cited by examiner]
CN 110348202A · 2019 [cited by examiner]
CN 111311425A · 2020 [cited by examiner]
CN 114722408A · 2022 [cited by examiner]
JP 2006048423A · 2006 [cited by examiner]
WO WO0017824A1 · 2000 [cited by examiner]
WO WO2019046204A1 · 2019 [cited by examiner]
WO WO2023027879A1 · 2023 [cited by examiner]
Li, Wei, Haishan Wan, Xunyi Ren, and Sheng Li. “A refined RBAC model for cloud computing.” In 2012 IEEE/ACIS 11th International Conference on Computer and Information Science, pp. 43-48. IEEE, 2012. (Year: 2012). [cited by examiner]
Sharing Data Securely Across Regions and Cloud Platforms, Sep. 2, 2019, 7 pages. (Year: 2019). [cited by examiner]
Steele, Robert, and Kyongho Min. “Role-based access to portable personal health records.” In 2009 International Conference on Management and Service Science, pp. 1-4. IEEE, 2009. (Year: 2009). [cited by examiner]
Faynberg, Igor, Hui-Lan Lu, and Herbert Ristock. “On dynamic access control in Web 2.0 and beyond: Trends and technologies.” Bell Labs Technical Journal 16, No. 2 (2011): 199-218. (Year: 2011). [cited by examiner]
Pereira. “Role-based access control for grid database services using the community authorization service.” IEEE Transactions on Dependable and Secure Computing 3, No. 2 (2006): 156-166. (Year: 2006). [cited by examiner]
Kormpakis. “Energy Sector Digitilisation: A Security Framework Application for Role-Based Access Management.” In 2023 14th International Conference on Information, Intelligence, Systems & Applications (IISA), pp. 1-10. … [cited by examiner]
Hu, Xiaorong. “Role-based concurrent control and its realization in CSCL.” In 2013 IEEE Third International Conference on Information Science and Technology (ICIST), pp. 377-379. IEEE, 2013. (Year: 2013). [cited by examiner]
Tsai, Wei-Tek, and Qihong Shao. “Role-based access-control using reference ontology in clouds.” In 2011 Tenth International Symposium on Autonomous Decentralized Systems, pp. 121-128. IEEE, 2011. (Year: 2011). [cited by examiner]