IP Library Granted Patent US 11,487,893
Granted Patent B1
US 11,487,893 · App. 17/841,996 · Granted Nov 1, 2022

Fine-grained access control via database roles

Inventors: Damien Carru (New York, NY); Pui Kei Johnston Chu (Unionville, CA); Benoit Dageville (San Carlos, CA); Shreyas Narendra Desai (Bellevue, WA); Subramanian Muralidhar (Mercer Island, WA); Bowen Zhang (Newark, CA)
Assignee: Snowflake Inc.
G06F21/6218G06F16/21G06F16/256G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,487,893
App. No.
17/841,996
Granted
Nov 1, 2022
Kind
B1
Abstract

Embodiments of the present disclosure provide techniques for defining database roles to allow sharing of the objects within a database in a more granular fashion. A set of database roles is created within a database container of a provider account, each database role comprising a separate object from any of a plurality of objects within the database container. A set of grants to a particular subset of the plurality of data objects of the database container is assigned to each of the set of database roles. A share object to which each of the set of database roles has been granted is mounted within a consumer account, thereby generating an imported database container having an imported copy of each of the set of database roles within the consumer account. Certain imported copies of the set of database roles are granted to account level roles of the consumer account.

Claims (56)

1. A method comprising:

generating, within a database container of a provider account, a set of database roles, each of the set of database roles comprising an object that is separate from any of a plurality of objects the database container is comprised of;

assigning to each of the set of database roles, a set of grants to a particular subset of the plurality of data objects of the database container;

mounting within a consumer account, a share object to which each of the set of database roles has been granted, to generate an imported database container within the consumer account, the imported database container including an imported copy of each of the set of database roles; and

granting, to each of one or more account level roles of the consumer account, a subset of the imported copies of the set of database roles.

2. The method of claim 1 , further comprising:

updating the database container with an additional object; and

assigning to a first database role of the set of database roles, a grant to the additional object, wherein the additional object is immediately available to an account level role of the consumer account to which an imported copy of the first database role is granted.

3. The method of claim 2 , wherein no new objects are created by the consumer account in response to the additional object being added to the database container.

4. The method of claim 1 , wherein the imported database may access the particular subset of the plurality of data objects assigned to each of the set of database roles and each of the one or more account level roles may access the particular subset of the plurality of data objects assigned to each of the subset of imported database roles granted to that account level role.

5. The method of claim 1 , wherein each of the set of database roles does not include grants to objects outside of the database container.

6. The method of claim 1 , further comprising:

granting each of the set of database roles to the share object.

7. The method of claim 6 , wherein granting a database role to the share object comprises:

creating a hidden role;

granting the database role to the hidden role; and

granting the hidden role to the share object.

8. The method of claim 7 , wherein the hidden role comprises a database role or an account level role.

9. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, the processing device to:

generate, within a database container of a provider account, a set of database roles, each of the set of database roles comprising an object that is separate from any of a plurality of objects the database container is comprised of;

assign to each of the set of database roles, a set of grants to a particular subset of the plurality of data objects of the database container;

mount within a consumer account, a share object to which each of the set of database roles has been granted, to generate an imported database container within the consumer account, the imported database container including an imported copy of each of the set of database roles; and

grant, to each of one or more account level roles of the consumer account, a subset of the imported copies of the set of database roles.

10. The system of claim 9 , wherein the processing device is further to:

update the database container with an additional object; and

assign to a first database role of the set of database roles, a grant to the additional object, wherein the additional object is immediately available to an account level role of the consumer account to which an imported copy of the first database role is granted.

11. The system of claim 10 , wherein no new objects are created by the consumer account in response to the additional object being added to the database container.

12. The system of claim 9 , wherein the imported database may access the particular subset of the plurality of data objects assigned to each of the set of database roles and each of the one or more account level roles may access the particular subset of the plurality of data objects assigned to each of the subset of imported database roles granted to that account level role.

13. The system of claim 9 , wherein each of the set of database roles does not include grants to objects outside of the database container.

14. The system of claim 9 , wherein the processing device is further to:

grant each of the set of database roles to the share object.

15. The system of claim 14 , wherein to grant a database role to the share object, the processing device is to:

create a hidden role;

grant the database role to the hidden role; and

grant the hidden role to the share object.

16. The system of claim 15 , wherein the hidden role comprises a database role or an account level role.

17. A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processing device, cause the processing device to:

generate, within a database container of a provider account, a set of database roles, each of the set of database roles comprising an object that is separate from any of a plurality of objects the database container is comprised of;

assign to each of the set of database roles, a set of grants to a particular subset of the plurality of data objects of the database container;

mount within a consumer account, a share object to which each of the set of database roles has been granted, to generate an imported database container within the consumer account, the imported database container including an imported copy of each of the set of database roles; and

grant, to each of one or more account level roles of the consumer account, a subset of the imported copies of the set of database roles.

18. The non-transitory computer-readable medium of claim 17 , wherein the processing device is further to:

update the database container with an additional object; and

assign to a first database role of the set of database roles, a grant to the additional object, wherein the additional object is immediately available to an account level role of the consumer account to which an imported copy of the first database role is granted.

19. The non-transitory computer-readable medium of claim 18 , wherein no new objects are created by the consumer account in response to the additional object being added to the database container.

20. The non-transitory computer-readable medium of claim 17 , wherein the imported database may access the particular subset of the plurality of data objects assigned to each of the set of database roles and each of the one or more account level roles may access the particular subset of the plurality of data objects assigned to each of the subset of imported database roles granted to that account level role.

21. The non-transitory computer-readable medium of claim 17 , wherein each of the set of database roles does not include grants to objects outside of the database container.

22. The non-transitory computer-readable medium of claim 17 , wherein the processing device is further to:

grant each of the set of database roles to the share object.

23. The non-transitory computer-readable medium of claim 22 , wherein to grant a database role to the share object, the processing device is to:

create a hidden role;

grant the database role to the hidden role; and

grant the hidden role to the share object.

24. The non-transitory computer-readable medium of claim 23 , wherein the hidden role comprises a database role or an account level role.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2022
From: CARRU, DAMIEN; CHU, PUI KEI JOHNSTON; DAGEVILLE, BENOIT; DESAI, SHREYAS NARENDRA; MURALIDHAR, SUBRAMANIAN; ZHANG, BOWEN
To: SNOWFLAKE INC.
Reel/Frame 060249/0613 →
Continuity (2)
Continuation 17464538 · Sep 1, 2021
Provisional Application 63237490 · Aug 26, 2021
Cited By (1)
US 12,568,090