IP Library Granted Patent US 11,580,245
Granted Patent B1
US 11,580,245 · App. 17/957,794 · Granted Feb 14, 2023

Fine-grained access control via database roles

Inventors: Damien Carru (New York, NY); Pui Kei Johnston Chu (Unionville, CA); Benoit Dageville (San Carlos, CA); Shreyas Narendra Desai (Bellevue, WA); Subramanian Muralidhar (Mercer Island, WA); Bowen Zhang (Newark, CA)
Assignee: Snowflake Inc.
G06F21/6218G06F16/21G06F16/256G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,580,245
App. No.
17/957,794
Granted
Feb 14, 2023
Kind
B1
Abstract

Embodiments of the present disclosure relate to sharing database roles using hidden roles. A database role may be generated within a database container having a plurality of data objects, wherein the database role exists exclusively within the database container. A set of grants to a particular subset of the plurality of data objects of the database container may be assigned to the database role. For each of a set of share objects to which the database role is to be granted: a hidden role having no identifier may be created, the database role may be granted to the hidden role, and the hidden role may be granted to a share object. Each of the set of share objects are mounted within a consumer account to generate a set of imported database containers within the consumer account, wherein each imported database container includes an individualized grant of the database roles.

Claims (53)

1. A method comprising:

generating, within a database container having a plurality of data objects, a database role, that exists exclusively within the database container;

assigning to the database role, a set of grants to a particular subset of the plurality of data objects of the database container; and

for each of a set of share objects to which the database role is to be granted:

creating a hidden role having no identifier;

granting the database role to the hidden role; and

granting the hidden role to share object; and

mounting within a consumer account, each of the set of share objects to generate a set of imported database containers within the consumer account, wherein each imported database container includes an individualized grant of the database roles.

2. The method of claim 1 , further comprising:

updating the database container with an additional object; and

assigning to a second database role, a grant to the additional object, wherein the additional object is immediately available to an account level role of the consumer account to which an imported copy of the second database role is granted.

3. The method of claim 2 , wherein no new objects are created by the consumer account in response to the additional object being added to the database container.

4. The method of claim 1 , wherein each of the set of imported database containers may access the particular subset of the plurality of data objects assigned to the database role and an account level role of the consumer account may access the particular subset of the plurality of data objects assigned to each of the subset of imported database roles granted to the account level role.

5. The method of claim 1 , wherein the database role does not include grants to objects outside of the database container.

6. The method of claim 1 , further comprising:

granting the database role to the share object.

7. The method of claim 1 , wherein the hidden role comprises a database role or an account level role.

8. A system comprising:

a memory; and

a processing device operatively coupled to the memory, the processing device to:

generate, within a database container having a plurality of data objects , a database role, that exists exclusively within the database container;

assign to the database role, a set of grants to a particular subset of the plurality of data objects of the database container; and

for each of a set of share objects to which the database role is to be granted:

create a hidden role having no identifier;

grant the database role to the hidden role; and

grant the hidden role to share object; and

mount within a consumer account, each of the set of share objects to generate a set of imported database containers within the consumer account, wherein each imported database container includes an individualized grant of the database roles.

9. The system of claim 8 , wherein the processing device is further to:

update the database container with an additional object; and

assign to a second database role, a grant to the additional object, wherein the additional object is immediately available to an account level role of the consumer account to which an imported copy of the second database role is granted.

10. The system of claim 9 , wherein no new objects are created by the consumer account in response to the additional object being added to the database container.

11. The system of claim 8 , wherein each of the set of imported database containers may access the particular subset of the plurality of data objects assigned to the database role and an account level role of the consumer account may access the particular subset of the plurality of data objects assigned to each of the subset of imported database roles granted to the account level role.

12. The system of claim 8 , wherein the database role does not include grants to objects outside of the database container.

13. The system of claim 8 , wherein the processing device is further to:

grant the database role to the share object.

14. The system of claim 8 , wherein the hidden role comprises a database role or an account level role.

15. A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processing device cause the processing device to:

generate, within a database container having a plurality of data objects, a database role, that exists exclusively within the database container;

assign to the database role, a set of grants to a particular subset of the plurality of data objects of the database container; and

for each of a set of share objects to which the database role is to be granted:

create a hidden role having no identifier;

grant the database role to the hidden role; and

grant the hidden role to the share object; and

mount within a consumer account, each of the set of share objects to generate a set of imported database containers within the consumer account, wherein each imported database container includes an individualized grant of the database roles.

16. The non-transitory computer-readable medium of claim 8 , wherein the processing device is further to:

update the database container with an additional object; and

assign to a second database role, a grant to the additional object, wherein the additional object is immediately available to an account level role of the consumer account to which an imported copy of the second database role is granted.

17. The non-transitory computer-readable medium of claim 9 , wherein no new objects are created by the consumer account in response to the additional object being added to the database container.

18. The non-transitory computer-readable medium of claim 8 , wherein each of the set of imported database containers may access the particular subset of the plurality of data objects assigned to the database role and an account level role of the consumer account may access the particular subset of the plurality of data objects assigned to each of the subset of imported database roles granted to the account level role.

19. The non-transitory computer-readable medium of claim 8 , wherein the database role does not include grants to objects outside of the database container.

20. The non-transitory computer-readable medium of claim 8 , wherein the processing device is further to:

grant the database role to the share object.

21. The non-transitory computer-readable medium of claim 8 , wherein the hidden role comprises a database role or an account level role.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2022
From: CARRU, DAMIEN; CHU, PUI KEI JOHNSTON; DAGEVILLE, BENOIT; DESAI, SHREYAS NARENDRA; MURALIDHAR, SUBRAMANIAN; ZHANG, BOWEN
To: SNOWFLAKE INC.
Reel/Frame 061292/0713 →
Continuity (3)
Continuation 17841996 · Jun 16, 2022
Continuation 17464538 · Sep 1, 2021
Provisional Application 63237490 · Aug 26, 2021
Cited By (1)
US 12,568,090