IP Library Granted Patent US 12,481,735
Granted Patent B2
US 12,481,735 · App. 18/491,500 · Granted Nov 25, 2025

Data asset sharing between accounts at a data processing service using cloud tokens

Inventors: Xiaotong Sun (Mountain View, CA); Abhijit Chakankar (San Jose, CA); Ramesh Chandra (Sunnyvale, CA)
Assignee: Databricks, Inc.
G06F21/31
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,481,735
App. No.
18/491,500
Granted
Nov 25, 2025
Kind
B2
Abstract

A data processing service receives indication that a recipient will request access to data assets of a provider and provides a request for credentials from a recipient governance module. The recipient governance module stores a recipient metastore including an object for a provider metastore. In response to determining that the assets are associated with the provider metastore, the service provides a request for credentials to a provider governance module. The provider governance module stores the provider metastore describing data assets of the provider and permissions for accessing data assets. The provider metastore includes a recipient object attached to the data assets with an identifier for the recipient metastore. In response to verifying that the recipient was provided access to the data assets, the service provides a token to the recipient governance module. The service then provides the token to a computing resource to provide access to the data assets.

Claims (49)

1 . A method, comprising:

receiving an indication that a recipient user of a data processing service will request access to one or more shared data assets of a provider user of the data processing service by a computing resource of a cloud infrastructure;

providing, to a first data governance module for the recipient user, a request to generate temporary credentials, the first data governance module storing a recipient metastore, wherein the recipient metastore includes a provider object for the provider user indicating an identifier for a provider metastore associated with the provider user;

responsive to determining that the one or more shared assets are associated with the provider metastore, providing, to a second data governance module for the provider user, a request to generate the temporary credentials, the second data governance module storing a provider metastore, the provider metastore describing data assets of the provider user, wherein the provider metastore includes a recipient object attached to the one or more shared data assets of the provider user indicating an identifier for the recipient metastore;

responsive to verifying that the user has access to the one or more shared data assets, providing, by the second data governance module, an access token to the first data governance module; and

providing, by the first data governance module, the access token to the computing resource such that the computing resource accesses the one or more shared data assets using the access token.

2 . The method of claim 1 , further comprising:

receiving, from the provider user, a share request to share the one or more shared data assets with the recipient user; and

responsive to receiving the share request, creating the recipient object in the provider metastore.

3 . The method of claim 2 , wherein the indication that the recipient user will request access to the one or more shared data assets of the provider user is received by the data processing service in response to receiving the share request.

4 . The method of claim 1 , wherein the access token is a short-lived temporary token.

5 . The method of claim 1 , wherein the second data governance module for the provider:

identifies a storage location associated with the one or more shared data assets; and

requests the access token from a corresponding cloud identity and access management (IAM) service of a cloud provider based on the storage location.

6 . The method of claim 1 , wherein the access token provides the recipient user access to the one or more data assets stored in cloud object storage.

7 . The method of claim 1 , wherein the recipient user is a first entity with a first account at the data processing service and the provider user is a second entity with a second account at the data processing service.

8 . A non-transitory computer readable storage medium storing instructions that, when executed by one or more computer processors, causes the one or more computer processors to:

receive an indication that a recipient user of a data processing service will request access to one or more shared data assets of a provider user of the data processing service by a computing resource of a cloud infrastructure;

provide, to a first data governance module for the recipient user, a request to generate temporary credentials, the first data governance module storing a recipient metastore, wherein the recipient metastore includes a provider object for the provider user indicating an identifier for a provider metastore associated with the provider user;

responsive to determining that the one or more shared assets are associated with the provider metastore, provide, to a second data governance module for the provider user, a request to generate the temporary credentials, the second data governance module storing a provider metastore, the provider metastore describing data assets of the provider user, wherein the provider metastore includes a recipient object attached to the one or more shared data assets of the provider user indicating an identifier for the recipient metastore;

responsive to verifying that the user has access to the one or more shared data assets, provide, by the second data governance module, an access token to the first data governance module; and

provide, by the first data governance module, the access token to the computing resource such that the computing resource accesses the one or more shared data assets using the access token.

9 . The non-transitory computer readable storage medium of claim 8 , wherein the instructions that, when executed by the one or more computer processors, further causes the one or more computer processors to:

receive, from the provider user, a share request to share the one or more shared data assets with the recipient user; and

responsive to receiving the share request, create the recipient object in the provider metastore.

10 . The non-transitory computer readable storage medium of claim 9 , wherein the indication that the recipient user will request access to the one or more shared data assets of the provider user is received by the data processing service in response to receiving the share request.

11 . The non-transitory computer readable storage medium of claim 8 , wherein the access token is a short-lived temporary token.

12 . The non-transitory computer readable storage medium of claim 8 , wherein the second data governance module for the provider:

identifies a storage location associated with the one or more shared data assets; and

requests the access token from a corresponding cloud identity and access management (IAM) service of a cloud provider based on the storage location.

13 . The non-transitory computer readable storage medium of claim 8 , wherein the access token provides the recipient user access to the one or more data assets stored in cloud object storage.

14 . The non-transitory computer readable storage medium of claim 8 , wherein the recipient user is a first entity with a first account at the data processing service and the provider user is a second entity with a second account at the data processing service.

15 . A computer system comprising:

a computer processor; and

a non-transitory computer readable storage medium storing instructions that, when executed by one or more computer processors, causes the one or more computer processors to:

receive an indication that a recipient user of a data processing service will request access to one or more shared data assets of a provider user of the data processing service by a computing resource of a cloud infrastructure;

provide, to a first data governance module for the recipient user, a request to generate temporary credentials, the first data governance module storing a recipient metastore, wherein the recipient metastore includes a provider object for the provider user indicating an identifier for a provider metastore associated with the provider user;

responsive to determining that the one or more shared assets are associated with the provider metastore, provide, to a second data governance module for the provider user, a request to generate the temporary credentials, the second data governance module storing a provider metastore, the provider metastore describing data assets of the provider user, wherein the provider metastore includes a recipient object attached to the one or more shared data assets of the provider user indicating an identifier for the recipient metastore;

responsive to verifying that the user has access to the one or more shared data assets, provide, by the second data governance module, an access token to the first data governance module; and

provide, by the first data governance module, the access token to the computing resource such that the computing resource accesses the one or more shared data assets using the access token.

16 . The computing system of claim 15 , wherein the instructions that, when executed by the one or more computer processors, further causes the one or more computer processors to:

receive, from the provider user, a share request to share the one or more shared data assets with the recipient user; and

responsive to receiving the share request, create the recipient object in the provider metastore.

17 . The computing system of claim 16 , wherein the indication that the recipient user will request access to the one or more shared data assets of the provider user is received by the data processing service in response to receiving the share request.

18 . The computing system of claim 15 , wherein the access token is a short-lived temporary token.

19 . The computing system of claim 15 , wherein the second data governance module for the provider:

identifies a storage location associated with the one or more shared data assets; and

requests the access token from a corresponding cloud identity and access management (IAM) service of a cloud provider based on the storage location.

20 . The computing system of claim 15 , wherein the access token provides the recipient user access to the one or more data assets stored in cloud object storage.

Assignments (2)
SECURITY INTEREST Recorded Jan 6, 2025
From: DATABRICKS, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 069825/0419 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2024
From: SUN, XIAOTONG; CHAKANKAR, ABHIJIT; CHANDRA, RAMESH
To: DATABRICKS, INC.
Reel/Frame 066008/0167 →
Continuity (1)
Related Publication 20250131070A1 · Apr 24, 2025
References Cited (62)
US 8725963B1 · Emelianov · 2014 [cited by examiner]
US 8892677B1 · Grove · 2014 [cited by examiner]
US 9032081B1 · North · 2015 [cited by examiner]
US 9588977B1 · Wang · 2017 [cited by examiner]
US 9727470B1 · Cande · 2017 [cited by examiner]
US 9898477B1 · Panghal · 2018 [cited by examiner]
US 10079842B1 · Brandwine · 2018 [cited by examiner]
US 10109003B1 · Jenkins · 2018 [cited by examiner]
US 10515212B1 · McClintock · 2019 [cited by examiner]
US 10817280B1 · Masrani · 2020 [cited by examiner]
US 10915497B1 · Bono · 2021 [cited by examiner]
US 10936494B1 · Panghal · 2021 [cited by examiner]
US 11093442B1 · Bhutani · 2021 [cited by examiner]
US 11204715B1 · Fawcett · 2021 [cited by examiner]
US 11431497B1 · Liguori · 2022 [cited by examiner]
US 11640410B1 · Zulak · 2023 [cited by examiner]
US 11785280B1 · Dakss · 2023 [cited by examiner]
US 12182014B2 · Monteith · 2024 [cited by examiner]
US 20050044148A1 · Son · 2005 [cited by examiner]
US 20110023018A1 · Park · 2011 [cited by examiner]
US 20140019753A1 · Lowry · 2014 [cited by examiner]
US 20140344327A1 · Lovric · 2014 [cited by examiner]
US 20170286698A1 · Shetty · 2017 [cited by examiner]
US 20180146037A1 · Figueroa · 2018 [cited by examiner]
US 20180336079A1 · Soman · 2018 [cited by examiner]
US 20190132120A1 · Zhang · 2019 [cited by examiner]
US 20200134215A1 · Natanzon · 2020 [cited by examiner]
US 20200234375A1 · Natanzon · 2020 [cited by examiner]
US 20200287718A1 · Hildebrand · 2020 [cited by examiner]
US 20200410018A1 · Gao · 2020 [cited by examiner]
US 20210109818A1 · Perneti · 2021 [cited by examiner]
US 20210109862A1 · Yang · 2021 [cited by examiner]
US 20210132811A1 · Puvvada · 2021 [cited by examiner]
US 20210258329A1 · Clayton · 2021 [cited by examiner]
US 20210294679A1 · Thakur · 2021 [cited by examiner]
US 20210314402A1 · Seshadri · 2021 [cited by examiner]
US 20210360401A1 · Marinho · 2021 [cited by examiner]
US 20220028193A1 · Ehlert · 2022 [cited by examiner]
US 20220058164A1 · Thakur · 2022 [cited by examiner]
US 20220100715A1 · Lee · 2022 [cited by examiner]
US 20220198070A1 · Hunt · 2022 [cited by examiner]
US 20220283724A1 · Malamut · 2022 [cited by examiner]
US 20220287089A1 · Singh · 2022 [cited by examiner]
US 20220391748A1 · Nikitin · 2022 [cited by examiner]
US 20220400103A1 · Jafri · 2022 [cited by examiner]
US 20230121460A1 · Banerjee · 2023 [cited by examiner]
US 20230185774A1 · Brand · 2023 [cited by examiner]
US 20230237177A1 · Kwatra · 2023 [cited by examiner]
US 20230239348A1 · Padmanabhan · 2023 [cited by examiner]
US 20230353568A1 · Denny-Brown · 2023 [cited by examiner]
US 20230401332A1 · Vahidnia · 2023 [cited by examiner]
US 20230403279A1 · Gnanaprakasam · 2023 [cited by examiner]
US 20240020206A1 · Arai · 2024 [cited by examiner]
US 20240378118A1 · Chis · 2024 [cited by examiner]
US 20240385598A1 · Nookala · 2024 [cited by examiner]
US 20240403093A1 · Yang · 2024 [cited by examiner]
US 20240420180A1 · Qu · 2024 [cited by examiner]
US 20240422192A1 · Patrick, II · 2024 [cited by examiner]
US 20250004665A1 · Busick · 2025 [cited by examiner]
US 20250021437A1 · Juneja · 2025 [cited by examiner]
US 20250061090A1 · Khobragade · 2025 [cited by examiner]
US 20250086017A1 · Schworer · 2025 [cited by examiner]