IP Library › Granted Patent US 12,242,636
Granted Patent B2
US 12,242,636 · App. 17/844,601 · Granted Mar 4, 2025

Implementing secure user-defined functions in a multi-tenant database system

Inventors: Allison Waingold Lee (San Mateo, CA); Peter Povinec (Redwood City, CA); Martin Hentschel (Seattle, WA); Robert Muglia (Mercer Island, WA)
Assignee: Snowflake Inc.
G06F21/6227G06F16/2282G06F16/245G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,242,636
App. No.
17/844,601
Granted
Mar 4, 2025
Kind
B2
Abstract

Systems, methods, and devices for implementing secure user-defined function (UDF) in a multi-tenant database system are disclosed. A method includes receiving a grant to access a share object comprising usage functionality associated with a secure UDF to underlying data. The method includes accessing the share object using the grant. The method includes causing a share component to implement the secure view and the usage functionality associated with the secure UDF.

Claims (63)

1. A multi-tenant database system comprising:

a memory; and

one or more processors operatively coupled to the memory, the one or more processors to:

receive a grant to access a share object comprising a plurality of functions associated with a secure user-defined function (UDF) to underlying data;

access the share object using the grant;

send a request to a share component to cause the share component to:

determine that a first function of the plurality of functions produces errors;

annotate the first function of the plurality of functions with a safety property indicating that the first function produces errors;

implement a second function of the plurality of functions by pushing the second function through a secure view boundary;

prevent, based on the safety property, an implementation of the second function by ensuring that the second function is not pushed through the secure view boundary;

hide the secure UDF from a second account having access to a view associated with a first account by modifying an output of commands to prevent the second account from receiving the secure UDF; and

receive, by the first account from the secure UDF, the functionality to the underlying data, wherein the functionality prevents the first account from using the functionality to access unauthorized data by preventing the first account from receiving metadata associated with the underlying data.

2. The multi-tenant database system of claim 1 , wherein the share object further comprises one or more of:

a data field of an underlying table of the share object;

a structural element of an underlying table of the share object; or

a quantity of data in an underlying table of the share object.

3. The multi-tenant database system of claim 1 , wherein the grant to access the share object is without access rights to a view of a procedural logic associated with the secure UDF, and wherein the procedural logic associated with the secure UDF comprises one or more of:

a table access according to the secure UDF; or

a quantity of data processed according to the secure UDF.

4. The multi-tenant database system of claim 1 , wherein the secure UDF is a scalar UDF comprising parameters such that the scalar UDF returns at least one of a single row or a single column, and further comprising:

receiving one or more of a simple SQL expression or a subquery.

5. The multi-tenant database system of claim 1 , wherein the secure UDF is a table-valued UDF comprising a correlated table.

6. The multi-tenant database system of claim 1 , wherein the grant to access the share object is without access rights to a view of a procedural logic associated with the secure UDF.

7. A method, comprising:

receiving a grant to access a share object comprising a plurality of functions associated with a secure user-defined function (UDF) to underlying data;

accessing the share object using the grant;

sending a request to a share component to cause the share component to:

determine that a first function of the plurality of functions produces errors;

annotate the first function of the plurality of functions with a safety property indicating that the first function produces errors;

implement a second function of the plurality of functions by pushing the second function through a secure view boundary;

prevent, based on the safety property, an implementation of the second function by ensuring that the second function is not pushed through the secure view boundary;

hide the secure UDF from a second account having access to a view associated with a first account by modifying an output of commands to prevent the second account from receiving the secure UDF; and

receiving, from the secure UDF, the functionality to the underlying data, wherein the functionality prevents the first account from using the functionality to access unauthorized data by preventing the first account from receiving metadata associated with the underlying data.

8. The method of claim 7 , wherein the share object further comprises one or more of:

a data field of an underlying table of the share object;

a structural element of an underlying table of the share object; or

a quantity of data in an underlying table of the share object.

9. The method of claim 7 , wherein the grant to access the share object is without access rights to a view of a procedural logic associated with the secure UDF, and wherein the procedural logic associated with the secure UDF comprises one or more of:

a table accessed according to the secure UDF; or

a quantity of data processed according to the secure UDF.

10. The method of claim 7 , wherein the secure UDF is a scalar UDF comprising parameters such that the scalar UDF returns at least one of a single row or a single column, and further comprising:

receiving one or more of a simple SQL expression or a subquery.

11. The method of claim 9 , wherein the share object is accessible in a query profile as a single node.

12. The method of claim 11 , wherein the procedural logic is not exposed in the query profile.

13. The method of claim 7 , wherein the grant to access the share object is without access rights to a view of a procedural logic associated with the secure UDF.

14. A non-transitory computer readable storage media storing instructions that, when executed by one or more processors of a multi-tenant database, cause the one or more processors to:

receive, by the one or more processors, a grant to access a share object comprising functionality associated with a secure user-defined function (UDF) to underlying data;

access, by the one or more processors, the share object using the grant;

send a request to a share component to cause the share component to:

determine that a first function of the plurality of functions produces errors;

annotate the first function of the plurality of functions with a safety property indicating that the first function produces errors;

implement a second function of the plurality of functions by pushing the second function through a secure view boundary;

prevent, based on the safety property, an implementation of the second function by ensuring that the second function is not pushed through the secure view boundary;

hide the secure UDF from a second account having access to a view associated with a first account by modifying an output of commands to prevent the second account from receiving the secure UDF; and

receive, by the first account from the secure UDF, the functionality to the underlying data, wherein the functionality prevents the first account from using the functionality to access unauthorized data by preventing the first account from receiving metadata associated with the underlying data.

15. The non-transitory computer readable storage media of claim 14 , wherein the share object further comprises one or more of:

a data field of an underlying table of the share object;

a structural element of an underlying table of the share object; or

a quantity of data in an underlying table of the share object.

16. The non-transitory computer readable storage media of claim 14 , wherein the grant to access the share object is without access rights to a view of a procedural logic associated with the secure UDF, and wherein the procedural logic associated with the secure UDF comprises one or more of:

a table access according to the secure UDF; or

a quantity of data processed according to the secure UDF.

17. The non-transitory computer readable storage media of claim 14 , wherein the grant to access the share object is without access rights to a view of a procedural logic associated with the secure UDF.

Continuity (5)
Continuation 17559226 · Dec 22, 2021
Continuation 17333343 · May 28, 2021
Continuation 16241463 · Jan 7, 2019
Continuation In Part 16055824 · Aug 6, 2018
Related Publication 20220318419A1 · Oct 6, 2022
References Cited (78)
US 6301575B1 · Chadha · 2001 [cited by examiner]
US 6757680B1 · Choy · 2004 [cited by examiner]
US 7921299B1 · Anantha et al. · 2011 [cited by applicant]
US 9715513B2 · Sharma · 2017 [cited by examiner]
US 10289611B2 · Stegelmann · 2019 [cited by examiner]
US 10528596B2 · Shivarudraiah et al. · 2020 [cited by applicant]
US 11138340B1 · Blum et al. · 2021 [cited by applicant]
US 20060041544A1 · Santosuosso · 2006 [cited by examiner]
US 20060265699A1 · Ali et al. · 2006 [cited by applicant]
US 20070220004A1 · Fifield · 2007 [cited by examiner]
US 20080071785A1 · Kabra · 2008 [cited by examiner]
US 20080082540A1 · Weissman et al. · 2008 [cited by applicant]
US 20080162483A1 · Becker et al. · 2008 [cited by applicant]
US 20080209428A1 · Baryshnikov · 2008 [cited by examiner]
US 20110191751A1 · Munday et al. · 2011 [cited by applicant]
US 20110196892A1 · Xia · 2011 [cited by applicant]
US 20110225232A1 · Casalaina et al. · 2011 [cited by applicant]
US 20110246772A1 · O'Connor et al. · 2011 [cited by applicant]
US 20110307695A1 · Slater · 2011 [cited by applicant]
US 20110307947A1 · Kariv et al. · 2011 [cited by applicant]
US 20120191642A1 · George · 2012 [cited by applicant]
US 20120209884A1 · Mattsson · 2012 [cited by examiner]
US 20140095470A1 · Chen · 2014 [cited by examiner]
US 20150120758A1 · Cichosz · 2015 [cited by examiner]
US 20160034710A1 · McReynolds et al. · 2016 [cited by applicant]
US 20160188617A1 · Gaikwad · 2016 [cited by applicant]
US 20160203157A1 · Kuruganti et al. · 2016 [cited by applicant]
US 20170099360A1 · Levi et al. · 2017 [cited by applicant]
US 20180046659A1 · Chen · 2018 [cited by examiner]
US 20180091306A1 · Antonopoulos · 2018 [cited by examiner]
US 20180114190A1 · Borrel · 2018 [cited by applicant]
US 20180121426A1 · Barsness · 2018 [cited by examiner]
US 20180121667A1 · Karpel et al. · 2018 [cited by applicant]
US 20180196955A1 · Dageville et al. · 2018 [cited by applicant]
US 20180336364A1 · Haila et al. · 2018 [cited by applicant]
US 20190340284A1 · Kandukuri et al. · 2019 [cited by applicant]
US 20190384929A1 · Noe et al. · 2019 [cited by applicant]
US 20200042734A1 · Lee et al. · 2020 [cited by applicant]
US 20210286893A1 · Lee · 2021 [cited by examiner]
US 20210303371A1 · Wang · 2021 [cited by examiner]
Data integration through database federation. Haas. (Year: 2012). [cited by examiner]
Selectivity Estimation in Extensible Databases—A Neural Network Approach. Lakshmi. (Year: 1998). [cited by examiner]
A Data Mining System Based on SQL Queries and UDFs for Relational Databases. Ordonez. ACM. (Year: 2011). [cited by examiner]
Data-Intensive Cloud Computing: Requirements, Expectations, Challenges, and Solutions. Shamsi. Springer. (Year: 2013). [cited by examiner]
Crypt-EHRServer: Protecting Confidentiality with Attribute-Based Encryption and Encrypted Query Processing. Zhang. IEEE. (Year: 2017). [cited by examiner]
Bring Precision and Access Control to Business Document Search. Chatvichienchai. IEEE. (Year: 2008). [cited by examiner]
Easy Domain Processing over Heterogeneous Databases: A Unified Programming Paradigm. Wang. (Year: 2010). [cited by examiner]
TICC: Transparent Inter-Column Compression for Column-Oriented Database Systems. Liu. ACM. (Year: 2017). [cited by examiner]
Declarative Error Management for Robust Data-Intensive Applications. Kanne. ACM. (Year: 2012). [cited by examiner]
Dynamic Approach for Data Scrubbing Process. Ahmed. IJCSE. (Year: 2010). [cited by examiner]
International Search Report and Written Opinion mailed on Oct. 18, 2019 for International Patent Application No. PCT/US2019/045358. [cited by applicant]
Role and Attribute Based Collaborative Administration of Intra-Tenant Cloud IaaS. Jin et al. IEEE. (Year: 2014). [cited by applicant]
Multi-tenancy authorization models for collaborative cloud services. Tang. John Wiley & Sons. (Year: 2014). [cited by applicant]
Role-Centric Circle-of-Trust in Multi-tenant Cloud IaaS. Pustchi et al. LNCS. (Year: 2016). [cited by applicant]
CQSTR: Securing Cross-Tenant Applications with Cloud COntianers. Zhai et al. So CC. (Year: 2016). [cited by applicant]
Identity Access Management for Multi-tier Cloud Infrastructures. Faraji et al. IEEE. (Year: 2014). [cited by applicant]
Comparative Analysis of Access Control Systems on Cloud. Ghazia-e-Um et al. IEEE. (Year: 2012). [cited by applicant]
Multi-tenant Database Access Control. Yaish et al. IEEE. (Year: 2013). [cited by applicant]
Design Role-Based Multi-Tenancy Access Control Scheme for Cloud Services. Yang et al. IEEE. (Year: 2013). [cited by applicant]
A Cross Tenant Access Control (CTAC) Model for Cloud Computing: Formal Specification and Verification. Alam. IEEE. (Year: 2017). [cited by applicant]
A Trust Model for Security and Privacy in Cloud Services. Himanshu. IEEE. (Year: 2017). [cited by applicant]
Authorization Management in Multi-Cloud Collaboration using Attribute-based Access Control. John. IEEE. (Year: 2016). [cited by applicant]
Migration of Web Application SIMA into Multi-tenant Saas. Nugraheni (Year: 2013). [cited by applicant]
Analysis of Cloud Computing Information Security Strategy in Biznet Networks. Sutrisno . (Year: 2013). [cited by applicant]
Identifying and Analyzing Security Threats to Virtualized Cloud Computing Infrastructures. Brohi. IEEE. (Year: 2012). [cited by applicant]
Cloud Computing: Security Threats & Control Strategy using Tri-Mechanism. Gupta. ICCICCT. (Year: 2014). [cited by applicant]
MTBase: Optimizing Cross-Tenant Database Queries. Braun. EDBT. (Year: 2018). [cited by applicant]
A Service Framework for Multi-tenant Enterprise Application in Saas Environments. Liao. (Year: 2014). [cited by applicant]
The Snowflake Elastic Data Warehouse. Dageville. ACM. (Year: 2016). [cited by applicant]
ADON: Application-Driven Overlay Network-as-a-Service for Data-Intensive Science. Antequera. IEEE. (Year: 2018). [cited by applicant]
Implementing a Storage Pattern in the OR Mapping Framework. Khan. IJGDC. (Year: 2013). [cited by applicant]
Security Aspects of Database-as-a-Service (DBaaS) in Cloud Computing. Mehak. (Year: 2014). [cited by applicant]
Big Data: A Survey. Chen. Springer. (Year: 2014). [cited by applicant]
A Comprehensive Taxonomy for the Infrastructure as a Service in Cloud Computing. Firdhous. IEEE. (Year: 2014). [cited by applicant]
Toward Lightweight Transparent Data Middleware in Support of Document Stores. Ma. IEEE. (Year: 2013). [cited by applicant]
Parallel NoSQL Entity Resolution Approach with MapReduce. Ma. IEEE. (Year: 2015). [cited by applicant]
European Patent Office Action of Application No. 19848393.5, mailed Nov. 24, 2023, 6 pages. [cited by applicant]
Ringer, Craig, “How security barriers work in PostgreSQL security_barrier views work?”, 2ndQuadrant PostgreSQL, Nov. 7, 2013, 2ndQuadrant Ltd. URL:https://www.2ndquadrant.com/en/blog/how-do-postgresql-security_barrier-v… [cited by applicant]