IP Library Granted Patent US 12,316,681
Granted Patent B2
US 12,316,681 · App. 18/423,012 · Granted May 27, 2025

Data platform with unified privileges

Inventors: Jeremy Yujui Chen (Newark, CA); Unmesh Jagtap (San Mateo, CA); William A. Pugh (Seattle, WA); Brian Smith (Hillsborough, CA); Xu Xu (Campbell, CA)
Assignee: Snowflake Inc.
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,681
App. No.
18/423,012
Granted
May 27, 2025
Kind
B2
Abstract

A data platform for developing and deploying a user application within a unified security context. The data platform authorizes a first user to use an editor to access source code of a user application based on security policies of a security context and authorizes the first user to use an application and data manager to set usage privileges for a second user to use the user application based on the security policies of the security context. To provide the user application to the second user, the data platform deploys the user application by instantiating a User Defined Function (UDF) server and an application engine of the UDF server within the security context, instantiating the user application as an application of the application engine within the security context, and authorizing access by the user application to databased on the security policies of the security context.

Claims (43)

1. A computer-implemented method for managing security of a user application in a data platform, comprising:

receiving, by the data platform, user application source code of the user application from a first user based on first security policies, the first security policies allowing the first user to create, edit, store, and execute the user application source code on the data platform;

receiving, by the data platform, from the first user, second security policies comprising sharing and usage privileges for a second user to use the user application when the user application is deployed on the data platform;

deploying, by the data platform, the user application within a security context based on sandbox policies including permissions for accessing system resources by performing operations comprising:

instantiating components that execute the user application; and

authorizing interactions of the instantiated components with resources of the data platform based on the sandbox policies;

receiving a request from the second user to utilize the user application; and

authorizing the request from the second user based on the second security policies.

2. The method of claim 1 , wherein the resources of the data platform include database objects stored in a database storage.

3. The method of claim 1 , wherein the instantiated components include a User Defined Function (UDF) server and an application engine.

4. The method of claim 1 , wherein deploying the user application further comprises instantiating the user application as an application of an application engine.

5. The method of claim 1 , wherein the interactions include accessing data of database objects of the data platform.

6. The method of claim 1 , wherein authorizing the interactions is performed in part by a security manager based on security manager policies included in the first security policies.

7. The method of claim 6 , wherein the sandbox policies are included in the second security policies.

8. The method of claim 1 , wherein the request from the second user is received via a browser runtime component.

9. The method of claim 1 , further comprising providing, by the user application, data of database objects to the second user in response to authorizing the request.

10. A machine comprising:

at least one processor; and

at least one memory storing instructions that, when executed by the at least one processor, cause the machine to perform operations comprising:

receiving user application source code of a user application from a first user based on first security policies, the first security policies allowing the first user to create, edit, store, and execute the user application source code;

receiving, from the first user, second security policies comprising sharing and usage privileges for a second user to use the user application when the user application is deployed on a data platform;

deploying, by the data platform, the user application within a security context based on sandbox policies including permissions for accessing system resources by performing operations comprising:

instantiating components that execute the user application; and

authorizing interactions of the instantiated components with resources of a data platform based on the sandbox policies;

receiving a request from the second user to utilize the user application; and

authorizing the request from the second user based on the second security policies.

11. The machine of claim 10 , wherein the resources of the data platform include database objects stored in a database storage.

12. The machine of claim 10 , wherein the instantiated components include a User Defined Function (UDF) server and an application engine.

13. The machine of claim 10 , wherein deploying the user application further comprises instantiating the user application as an application of an application engine.

14. The machine of claim 10 , wherein the interactions include accessing data of database objects of the data platform.

15. The machine of claim 10 , wherein authorizing the interactions is performed in part by a security manager based on security manager policies included in the first security policies.

16. The machine of claim 15 , wherein the sandbox policies are included in the second security policies.

17. The machine of claim 10 , wherein the request from the second user is received via a browser runtime component.

18. The machine of claim 10 , wherein the operations further comprise providing, by the user application, data of database objects to the second user in response to authorizing the request.

19. The machine of claim 18 , wherein providing the data to the second user is authorized based on the first security policies and the second security policies.

20. A machine-storage medium storing instructions that, when executed by a machine, cause the machine to perform operations comprising:

receiving user application source code of a user application from a first user based on first security policies, the first security policies allowing the first user to create, edit, store, and execute the user application source code;

receiving from the first user, second security policies comprising sharing and usage privileges for a second user to use the user application when the user application is deployed on a data platform;

deploying, by the data platform, the user application within a security context based on sandbox policies including permissions for accessing system resources by performing operations comprising:

instantiating components that execute the user application; and

authorizing interactions of the instantiated components with resources of the data platform based on the sandbox policies;

receiving a request from the second user to utilize the user application; and

authorizing the request from the second user based on the second security policies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2024
From: CHEN, JEREMY YUJUI; JAGTAP, UNMESH; PUGH, WILLIAM A.; SMITH, BRIAN; XU, XU
To: SNOWFLAKE INC.
Reel/Frame 066293/0410 →
Continuity (3)
Continuation 18053956 · Nov 9, 2022
Provisional Application 63366266 · Jun 13, 2022
Related Publication 20240163316A1 · May 16, 2024
References Cited (104)
US 7555497B2 · Thompson · 2009 [cited by examiner]
US 7698398B1 · Lai · 2010 [cited by applicant]
US 7921299B1 · Anantha et al. · 2011 [cited by applicant]
US 9460474B2 · Grignon · 2016 [cited by applicant]
US 9712542B1 · Brandwine · 2017 [cited by applicant]
US 9774586B1 · Roche et al. · 2017 [cited by applicant]
US 11055390B1 · Kragh · 2021 [cited by applicant]
US 11093634B1 · Szuflita et al. · 2021 [cited by applicant]
US 11093912B1 · Fakhraie et al. · 2021 [cited by applicant]
US 11146564B1 · Ankam et al. · 2021 [cited by applicant]
US 11216581B1 · Arikapudi · 2022 [cited by examiner]
US 11256606B2 · Wunderlich et al. · 2022 [cited by applicant]
US 11461080B1 · Brossard · 2022 [cited by examiner]
US 11461322B1 · Plenderleith · 2022 [cited by applicant]
US 11494493B1 · Baird · 2022 [cited by applicant]
US 11520920B1 · Carru et al. · 2022 [cited by applicant]
US 11552948B1 · Peterson et al. · 2023 [cited by applicant]
US 11750661B1 · Carru et al. · 2023 [cited by applicant]
US 11775669B1 · Carru et al. · 2023 [cited by applicant]
US 11823164B1 · Goetz et al. · 2023 [cited by applicant]
US 12010147B2 · Chen et al. · 2024 [cited by applicant]
US 12153698B2 · Carru et al. · 2024 [cited by applicant]
US 20040054630A1 · Ginter et al. · 2004 [cited by applicant]
US 20060080257A1 · Vaughan et al. · 2006 [cited by applicant]
US 20070157203A1 · Lim · 2007 [cited by examiner]
US 20080184330A1 · Lal · 2008 [cited by examiner]
US 20100299738A1 · Wahl · 2010 [cited by applicant]
US 20110265010A1 · Ferguson et al. · 2011 [cited by applicant]
US 20120096521A1 · Peddada · 2012 [cited by applicant]
US 20140143830A1 · Lim · 2014 [cited by applicant]
US 20140173702A1 · Wong et al. · 2014 [cited by applicant]
US 20160070449A1 · Christiansen et al. · 2016 [cited by applicant]
US 20160104005A1 · Toussaint et al. · 2016 [cited by applicant]
US 20160255089A1 · Diestler et al. · 2016 [cited by applicant]
US 20160321412A1 · Basri · 2016 [cited by applicant]
US 20170249475A1 · Schneider et al. · 2017 [cited by applicant]
US 20170308377A1 · Tucker et al. · 2017 [cited by applicant]
US 20170322992A1 · Joseph et al. · 2017 [cited by applicant]
US 20180007155A1 · Saito · 2018 [cited by applicant]
US 20190238467A1 · Guan et al. · 2019 [cited by applicant]
US 20190318100A1 · Bhatia et al. · 2019 [cited by applicant]
US 20190372783A1 · Martinez et al. · 2019 [cited by applicant]
US 20210166573A1 · Douglas et al. · 2021 [cited by applicant]
US 20210173701A1 · Cheng et al. · 2021 [cited by applicant]
US 20210342196A1 · Natarajan et al. · 2021 [cited by applicant]
US 20220272117A1 · Maheve et al. · 2022 [cited by applicant]
US 20220345483A1 · Shua · 2022 [cited by applicant]
US 20220358233A1 · Thakur et al. · 2022 [cited by applicant]
US 20220407889A1 · Narigapalli et al. · 2022 [cited by applicant]
US 20230164189A1 · Danilchenko et al. · 2023 [cited by applicant]
US 20230401326A1 · Carru et al. · 2023 [cited by applicant]
US 20230403306A1 · Chen et al. · 2023 [cited by applicant]
US 20230409724A1 · Carru et al. · 2023 [cited by applicant]
US 20230412647A1 · Carru et al. · 2023 [cited by applicant]
CN 117235338 · 2023 [cited by applicant]
CN 117235339 · 2023 [cited by applicant]
DE 202023103214 · 2023 [cited by applicant]
DE 202023103216 · 2023 [cited by applicant]
JP 2005284353 · 2005 [cited by applicant]
WO 2023244989 · 2023 [cited by applicant]
U.S. Appl. No. 17/934,899 U.S. Pat. No. 11,750,661, filed Sep. 23, 2022, First Class Database Object Web Application. [cited by applicant]
U.S. Appl. No. 18/353,445, filed Jul. 17, 2023, First Class Database Object Server Application. [cited by applicant]
U.S. Appl. No. 18/053,956 U.S. Pat. No. 12,010,147, filed Nov. 9, 2022, Data Platform With Unified Privileges. [cited by applicant]
U.S. Appl. No. 18/060,476 U.S. Pat. No. 11,775,669, filed Nov. 30, 2022, Secure Shared Data Application Access. [cited by applicant]
U.S. Appl. No. 18/187,031, filed Mar. 21, 2023, User Interface Framework for Web Application. [cited by applicant]
U.S. Appl. No. 18/104,275, filed Jan. 31, 2023, Secure Shared Data Application Access. [cited by applicant]
“U.S. Appl. No. 18/187,031, Response filed Nov. 11, 2024 to Final Office Action mailed Sep. 10, 2024”, 11 pgs. [cited by applicant]
“International Application Serial No. PCT/US2023/068326, International Preliminary Report on Patentability mailed Dec. 26, 2024”, 6 pgs. [cited by applicant]
“U.S. Appl. No. 18/104,275, Preliminary Amendment filed Feb. 2, 2023”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 18/060,476, Non Final Office Action mailed Feb. 28, 2023”, 21 pgs. [cited by applicant]
“U.S. Appl. No. 18/053,956, Notice of Allowance mailed Mar. 3, 2023”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 18/053,956, Supplemental Notice of Allowability mailed Mar. 29, 2023”, 2 pgs. [cited by applicant]
“U.S. Appl. No. 17/934,899, Notice of Allowance mailed Apr. 17, 2023”, 11 pgs. [cited by applicant]
“U.S. Appl. No. 18/104,275, Non Final Office Action mailed May 10, 2023”, 23 pgs. [cited by applicant]
“U.S. Appl. No. 18/060,476, Response filed May 30, 2023 to Non Final Office Action mailed Feb. 28, 2023”, 15 pgs. [cited by applicant]
“U.S. Appl. No. 18/053,956, Notice of Allowance mailed Jul. 6, 2023”, 10 pgs. [cited by applicant]
“U.S. Appl. No. 18/060,476, Notice of Allowance mailed Jul. 7, 2023”, 19 pgs. [cited by applicant]
“U.S. Appl. No. 17/934,899, 312 Amendment filed Jul. 17, 2023”, 8 pgs. [cited by applicant]
“U.S. Appl. No. 18/060,476, Corrected Notice of Allowability mailed Jul. 27, 2023”, 2 pgs. [cited by applicant]
“U.S. Appl. No. 18/187,031, Non Final Office Action mailed Jul. 31, 2023”, 15 pgs. [cited by applicant]
“U.S. Appl. No. 17/934,899, PTO Response to Rule 312 Communication mailed Aug. 7, 2023”, 2 pgs. [cited by applicant]
“International Application Serial No. PCT US2023 068326, International Search Report mailed Aug. 9, 2023”, 2 pgs. [cited by applicant]
“International Application Serial No. PCT US2023 068326, Written Opinion mailed Aug. 9, 2023”, 4 pgs. [cited by applicant]
“U.S. Appl. No. 18/104,275, Response filed Aug. 10, 2023 to Non Final Office Action mailed May 10, 2023”, 12 pgs. [cited by applicant]
“U.S. Appl. No. 18/104,275, Final Office Action mailed Sep. 11, 2023”, 24 pgs. [cited by applicant]
“U.S. Appl. No. 18/053,956, Notice of Allowance mailed Sep. 14, 2023”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 18/187,031, Response filed Oct. 31, 2023 to Non Final Office Action mailed Jul. 31, 2023”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 18/187,031, Final Office Action mailed Nov. 16, 2023”, 15 pgs. [cited by applicant]
“European Application Serial No. 23178771.4, Extended European Search Report mailed Oct. 26, 2023”, 10 pgs. [cited by applicant]
“European Application Serial No. 23178797.9, Extended European Search Report mailed Oct. 31, 2023”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 18/053,956, Notice of Allowance mailed Nov. 29, 2023”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 18/104,275, Response filed Dec. 11, 2023 to Final Office Action mailed Sep. 11, 2023”, 13 pgs. [cited by applicant]
“U.S. Appl. No. 18/104,275, Non Final Office Action mailed Jan. 30, 2024”, 25 pgs. [cited by applicant]
“U.S. Appl. No. 18/187,031, Response filed Jan. 30, 2024 to Final Office Action mailed Nov. 16, 2023”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 18/187,031, Non Final Office Action mailed Feb. 29, 2024”, 16 pgs. [cited by applicant]
“U.S. Appl. No. 18/104,275, Response filed Apr. 30, 2024 to Non Final Office Action mailed Jan. 30, 2024”, 13 pgs. [cited by applicant]
“U.S. Appl. No. 18/053,956, Supplemental Notice of Allowability mailed May 2, 2024”, 2 pgs. [cited by applicant]
“U.S. Appl. No. 18/187,031, Response filed May 29, 2024 to Non Final Office Action mailed Feb. 29, 2024”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 18/104,275, Notice of Allowance mailed Jun. 5, 2024”, 9 pgs. [cited by applicant]
“European Application Serial No. 23178797.9, Response filed Jun. 20, 24 to Extended European Search Report mailed Oct. 31, 23”, 10 pgs. [cited by applicant]
“European Application Serial No. 23178771.4, Response filed Jun. 20, 24 to Extended European Search Report mailed Oct. 26, 23”, 11 pgs. [cited by applicant]
“U.S. Appl. No. 18/104,275, Notice of Allowance mailed Jul. 23, 2024”, 9 pgs. [cited by applicant]
“U.S. Appl. No. 18/187,031, Final Office Action mailed Sep. 10, 2024”, 12 pgs. [cited by applicant]
Saiz-Laudo, “EGEON: Software-Defined Data Protection for Object Storage”, IEEE 22nd International Symposium on Cluster, Cloud and Internet Computing (CCGrid), 99-108. [cited by applicant]