IP Library › Granted Patent US 12,277,093
Granted Patent B2
US 12,277,093 · App. 18/169,551 · Granted Apr 15, 2025

Method for managing a plurality of accounts in a multi-account database system

Inventors: Sandeep Shantharaj (Herndon, VA); Sunitha Kempnool Shambulingappa (Herndon, VA)
G06F16/185
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,277,093
App. No.
18/169,551
Granted
Apr 15, 2025
Kind
B2
Abstract

A system for cloud-based data-as-a-service setup and configuration across multiple accounts, multiple regions, and multiple cloud providers, wherein the system uses higher level constructs along with simplified integration of the data-as-a-service accounts with other software products and related analytics. Account group or similar grouping constructs allow for configuring multiple data-as-a-service accounts at once with repetitive and duplicate configuration for each account with the ability to allow for overrides to allow for extensibility or for exception purposes. Logical constructs called namespace allow for grouping resources to create logical boundaries within a shared data-as-a-service account. Namespace provides stored procedures as necessary controls to implement policies as code to keep the namespace behavior consistent. A user interface widget enables specification of privileges that users of a shared data-as-a-service account are allowed to grant and revoke.

Claims (22)

1. A system for managing a multiple account database the system comprising:

a control plane residing on a parent platform nonnative to the multiple account database, the control plane operatively associated with:

a memory; and

a processor coupled with the memory, wherein the memory stores instructions that, when executed by the processor, causes the control plane to perform operations comprising:

providing a producer account on the parent platform

integrating the producer account with a plurality of child accounts on the multiple account database so that data is shared between the producer account and each of the plurality of child accounts through application functionality native to the multiple account database;

defining, at the parent platform level, configuration data for one or more account objects for the plurality of child accounts;

publishing said configuration data to the producer account so that said configuration data is natively inherited or pushed on demand to the plurality of child accounts by way of the producer account; and

granting ownership of each account object, associated with the configuration data, to a namespace role that only administrators of a respective child account have access thereto so that for each child account a user thereof must create each account object via a stored procedure that is native to the multiple account database.

2. The system of claim 1 , wherein each account object comprises at least one of a tag, a parameter, a privilege, a resource, and a network policy.

3. The system of claim 2 , wherein at the parent platform, by way of the processor, an immutability of each account object is enabled or disabled for each of the plurality of child accounts,

whereby disabling immutability enables a user to augment the respective account object for each respective child account.

4. The system of claim 3 , wherein the control plane is configured for setting privileges for each account object.

5. The system of claim 4 , wherein the granting of ownership enables a high-level namespace construct facilitating access between a shared pool and a plurality of users, wherein the high-level namespace construct owns a one or more account objects in the shared pool of configurable resources so that each user manages the account objects only through a stored procedure obtaining a set of application programming interface calls for configuring each account object.

6. The system of claim 5 , wherein each child account has one or more user, wherein each user is an individual or application.

7. The system of claim 5 , wherein each resource comprises a role, a database, or a warehouse.

8. A method of configuring each account object for the multiple account database of claim 1 , the method comprises:

providing a user interface widget, by way of the processor, through the control plane, wherein the user interface widget enables changing each account object from default allow/deny to explicit allow to explicit deny and back.

9. The method of claim 8 , wherein the user interface widget provides a clickable interface for changing each account object privilege.

10. The method of claim 9 , wherein the configured account object is used by a stored procedure when users execute SQL commands indirectly via the stored procedure.

11. The system of claim 1 , wherein the multiple account database is a platform.

12. The system of claim 1 , wherein the multiple account database is a cloud-based platform.

Continuity (2)
Provisional Application 63310587 · Feb 16, 2022
Related Publication 20230259497A1 · Aug 17, 2023
References Cited (11)
US 8447829B1 · Geller · 2013 [cited by examiner]
US 10949402B1 · Chu · 2021 [cited by examiner]
US 11057491B1 · Bijon · 2021 [cited by examiner]
US 20020198806A1 · Blagg · 2002 [cited by examiner]
US 20060233313A1 · Adams · 2006 [cited by examiner]
US 20160019241A1 · Prabaker · 2016 [cited by examiner]
US 20190364051A1 · Ferrans · 2019 [cited by examiner]
US 20200120098A1 · Berg · 2020 [cited by examiner]
US 20220021746A1 · Bijon · 2022 [cited by examiner]
US 20220368593A1 · Shankar · 2022 [cited by examiner]
US 20230169090A1 · Gernhardt · 2023 [cited by examiner]