IP Library Granted Patent US 12,013,960
Granted Patent B2
US 12,013,960 · App. 18/343,361 · Granted Jun 18, 2024

Granting access to resources of a database

Inventors: Benoit Dageville (Foster City, CA); Thierry Cruanes (San Mateo, CA); Martin Hentschel (San Mateo, CA); Peter Povinec (Redwood City, CA)
Assignee: Snowflake Inc.
G06F21/6218G06F16/256G06F2221/2145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,013,960
App. No.
18/343,361
Granted
Jun 18, 2024
Kind
B2
Abstract

A method of sharing data in a multi-tenant database includes inspecting, by a processing device of a multiple tenant database, a sharer account to determine an existence of a link between an alias object in a target account and a database, wherein the database is linked to a first role object included in a share object in the sharer account. The method includes granting a second role object, in the target account, access rights to the alias object, wherein the first role object having one or more grants to one or more resources of the sharer account, and wherein the target account accesses the one or more resources using the one or more grants of the share object and using the alias object without at least one of copying the one or more resources or transmitting the one or more resources.

Claims (47)

1. A method comprising:

inspecting, by a processing device of a multiple tenant database, a sharer account to determine an existence of a link between an alias object in a target account and a database, wherein the database is linked to a first role object included in a share object in the sharer account; and

granting a second role object, in the target account, access rights to the alias object, wherein the first role object having one or more grants to one or more resources of the sharer account, and wherein the target account accesses the one or more resources using the one or more grants of the share object and using the alias object without at least one of copying the one or more resources or transmitting the one or more resources.

2. The method of claim 1 , wherein each grant of the one or more grants comprises at least one of a usage grant, a modification grant, or a select grant.

3. The method of claim 1 , wherein when the alias object is used, the alias object is internally replaced by an object associated with the one or more resources of the sharer account.

4. The method of claim 1 , wherein the sharer account and the target account are accounts within the multiple tenant database.

5. The method of claim 1 , wherein the alias object references a dataset associated with the one or more resources of the sharer account and the sharer account shares the one or more grants with one or more other target accounts such that the one or more other target accounts can read the dataset without copying or transmitting the dataset using one or more virtual warehouses corresponding to the one or more other target accounts.

6. The method of claim 1 , wherein the alias object references database data associated with the one or more resources of the sharer account.

7. The method of claim 1 , further comprising:

receiving a request for access to the one or more resources; and

processing the request using a virtual warehouse, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the sharer account to generate a response to the request.

8. The method of claim 1 , wherein the alias object serves as a proxy for an object associated with the one or more resources of the sharer account.

9. The method of claim 1 , further comprising:

creating a link between the alias object and an object associated with the one or more resources of the sharer account.

10. The method of claim 1 , wherein the alias object references an object associated with the one or more resources of the sharer account, the one or more resources of the sharer account are organized in an object hierarchy, and the object is at the top of the object hierarchy.

11. A system comprising:

a memory; and

one or more processors operatively coupled to the memory, the one or more processors to:

inspect a sharer account to determine an existence of a link between an alias object in a target account and a database, wherein the database is linked to a first role object included in a share object in the sharer account; and

grant a second role object, in the target account, access rights to the alias object, wherein the first role object having one or more grants to one or more resources of the sharer account, and wherein the target account accesses the one or more resources using the one or more grants of the share object and using the alias object without at least one of copying the one or more resources or transmitting the one or more resources.

12. The system of claim 11 , wherein each grant of the one or more grants comprises at least one of a usage grant, a modification grant, or a select grant.

13. The system of claim 11 , wherein when the alias object is used, the alias object is internally replaced by an object associated with the one or more resources of the sharer account.

14. The system of claim 11 , wherein the sharer account and the target account are accounts within a multiple tenant database.

15. The system of claim 11 , wherein the alias object references a dataset associated with the one or more resources of the sharer account and the sharer account shares the one or more grants with one or more other target accounts such that the one or more other target accounts can read the dataset without copying or transmitting the dataset using one or more virtual warehouses corresponding to the one or more other target accounts.

16. The system of claim 11 , wherein the alias object references database data associated with the one or more resources of the sharer account.

17. The system of claim 11 , wherein the one or more processors further to:

receive a request for access to the one or more resources; and

process the request using a virtual warehouse, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the sharer account to generate a response to the request.

18. The system of claim 11 , wherein the alias object serves as a proxy for an object associated with the one or more resources of the sharer account.

19. The system of claim 11 , wherein the one or more processors further to:

create a link between the alias object and an object associated with the one or more resources of the sharer account.

20. The system of claim 11 , wherein the alias object references an object associated with the one or more resources of the sharer account, the one or more resources of the sharer account are organized in an object hierarchy, and the object is at the top of the object hierarchy.

21. A non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more processors, causes the one or more processors to:

inspect a sharer account to determine an existence of a link between an alias object in a target account and a database, wherein the database is linked to a first role object included in a share object in the sharer account; and

grant a second role object, in the target account, access rights to the alias object, wherein the first role object having one or more grants to one or more resources of the sharer account, and wherein the target account accesses the one or more resources using the one or more grants of the share object and using the alias object without at least one of copying the one or more resources or transmitting the one or more resources.

22. The non-transitory computer-readable medium of claim 21 , wherein each grant of the one or more grants comprises at least one of a usage grant, a modification grant, or a select grant.

23. The non-transitory computer-readable medium of claim 21 , wherein when the alias object is used, the alias object is internally replaced by an object associated with the one or more resources of the sharer account.

24. The non-transitory computer-readable medium of claim 21 , wherein the sharer account and the target account are accounts within a multiple tenant database.

25. The non-transitory computer-readable medium of claim 21 , wherein the alias object references a dataset associated with the one or more resources of the sharer account and the sharer account shares the one or more grants with one or more other target accounts such that the one or more other target accounts can read the dataset without copying or transmitting the dataset using one or more virtual warehouses corresponding to the one or more other target accounts.

26. The non-transitory computer-readable medium of claim 21 , wherein the alias object references database data associated with the one or more resources of the sharer account.

27. The non-transitory computer-readable medium of claim 21 , wherein the one or more processors further to:

receive a request for access to the one or more resources; and

process the request using a virtual warehouse, wherein the virtual warehouse comprises a set of one or more compute nodes configured to access data in a storage layer corresponding to the sharer account to generate a response to the request.

28. The non-transitory computer-readable medium of claim 21 , wherein the alias object serves as a proxy for an object associated with the one or more resources of the sharer account.

29. The non-transitory computer-readable medium of claim 21 , wherein the one or more processors further to:

create a link between the alias object and an object associated with the one or more resources of the sharer account.

30. The non-transitory computer-readable medium of claim 21 , wherein the alias object references an object associated with the one or more resources of the sharer account, the one or more resources of the sharer account are organized in an object hierarchy, and the object is at the top of the object hierarchy.

Assignments (2)
CHANGE OF NAME Recorded Apr 16, 2024
From: SNOWFLAKE COMPUTING INC.
To: SNOWFLAKE INC.
Reel/Frame 067127/0013 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2024
From: DAGEVILLE, BENOIT; CRUANES, THIERRY; HENTSCHEL, MARTIN; POVINEC, PETER
To: SNOWFLAKE COMPUTING INC.
Reel/Frame 067073/0274 →
Continuity (8)
Continuation 17697744 · Mar 17, 2022
Continuation 17354972 · Jun 22, 2021
Continuation 17103786 · Nov 24, 2020
Continuation 17004458 · Aug 27, 2020
Continuation 16833482 · Mar 27, 2020
Continuation 16779103 · Jan 31, 2020
Continuation 15402906 · Jan 10, 2017
Related Publication 20230334166A1 · Oct 19, 2023