IP Library › Granted Patent US 12,437,100
Granted Patent B1
US 12,437,100 · App. 18/058,816 · Granted Oct 7, 2025

Priority-based masking policy selection in a database environment

Inventors: Dmytro Bogatov (Boston, MA); Kiran Kumar Chinta (Fremont, CA); Todd Jeffrey Green (Davis, CA); Yanzhu Ji (Sunnyvale, CA); James Claiborne Moore (Boston, MA); Gaurav Saxena (Cupertino, CA); Abhishek Rai Sharma (Sunnyvale, CA)
Assignee: Amazon Technologies, Inc.
G06F21/6227G06F16/221G06F16/245G06F21/6254
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,100
App. No.
18/058,816
Filed
Nov 25, 2022
Granted
Oct 7, 2025
Kind
B1
Art Unit
2493
USPC
726/1
Abstract

Techniques for priority-based masking policy selection in a database environment are described. Masking policies are defined and attached to columns of relational data for particular users or roles. The attachment of a masking policy to a column includes a user-specified priority value. When multiple policies could apply to a particular query, the conflict can be easily resolved and understood by use of the priority values, for example, by selecting a candidate policy having a highest priority value.

Claims (59)

1. A computer-implemented method comprising:

receiving, at a database service, a request to execute a query involving at least a column of a table of a database, wherein the request was issued on behalf of a user through a user account;

identifying, based on a data structure, one or more roles associated with the user account;

identifying multiple masking policies that are attached to the table, are associated with the column, and are applicable for all users or are applicable for the user account or are applicable for users associated with any of the one or more roles;

selecting a masking policy from among the multiple masking policies based on the one or more roles associated with the user account, and based on an analysis of user-configured priority values associated with the multiple masking policies, whereby the masking policy is selected due to it having a highest or lowest priority value from among the user-configured priority values; and

executing the query to generate a result, the executing comprising modifying values of the column based on the masking policy.

2. The computer-implemented method of claim 1 , wherein executing the query comprises:

rewriting the query to yield a rewritten query based on the masking policy;

providing the rewritten query to one or more compute nodes of the database service for use in generating one or more intermediate query results, wherein the one or more compute nodes apply a masking function, selected based on the rewritten query, to values of the column; and

generating the result based on the one or more intermediate query results.

3. The computer-implemented method of claim 1 , further comprising:

receiving, at the database service, a request to define the masking policy originated on behalf of a second user via a second user account; and

receiving, at the database service, a request to attach the masking policy to the column, wherein the request includes a priority value specified by the second user.

4. A computer-implemented method comprising:

receiving a request to execute a query involving at least a column of a relation of a database, wherein the request was issued through a user account;

identifying, based on a data structure, one or more roles associated with the user account;

identifying multiple masking policies that are attached to the relation, are associated with the column, and are applicable for all users or are applicable for the user account or are applicable for users associated with any of the one or more roles;

selecting a masking policy from among the multiple masking policies based on the one or more roles associated with the user account, and based on an analysis of priority values associated with the multiple masking policies, whereby the masking policy is selected due to it having a highest or lowest priority value from among the priority values; and

executing the query to generate a result, the executing comprising modifying values of the column based on the masking policy.

5. The computer-implemented method of claim 4 , wherein the priority values are user-configured priority values associated with attachments of the multiple masking policies to the relation.

6. The computer-implemented method of claim 4 , wherein executing the query comprises:

rewriting the query to yield a rewritten query based on the masking policy;

providing the rewritten query to one or more compute nodes of the database service for use in generating one or more intermediate query results, wherein the one or more compute nodes apply a masking function, selected based on the rewritten query, to values of the column; and

generating the result based on the one or more intermediate query results.

7. The computer-implemented method of claim 4 , wherein the query further involves a second column of the relation, and wherein the method further comprises:

selecting a second masking policy from a second set of multiple masking policies that are associated with the second column based on the one or more roles of the user account,

wherein executing the query further comprises modifying values of the second column based on the selected second masking policy.

8. The computer-implemented method of claim 4 , wherein selecting the masking policy from multiple masking policies comprises:

identifying, via a first data structure, a plurality of masking policies that have been attached to the relation and that output values for the column, and

selecting, for inclusion in the multiple masking policies, those of the plurality of masking policies that apply to any of the one or more roles or the user account.

9. The computer-implemented method of claim 8 , wherein selecting the masking policy from multiple masking policies further comprises selecting, for inclusion in the multiple masking policies, those of the plurality of masking policies that apply to all users or user roles.

10. The computer-implemented method of claim 4 , further comprising receiving a request to define the masking policy originated on behalf of a second user via a second user account.

11. The computer-implemented method of claim 10 , further comprising receiving a request to attach the masking policy to the relation.

12. The computer-implemented method of claim 11 , wherein the request to attach the masking policy to the column includes a priority value specified by the second user.

13. The computer-implemented method of claim 10 , wherein the masking policy indicates that values are to be modified based at least in part on a cryptographic function.

14. The computer-implemented method of claim 13 , wherein the masking policy indicates that the values are to be modified via:

an email address masking function;

a date masking function;

a national identification number masking function; or

a financial account number masking function.

15. A system comprising:

one or more electronic devices to implement a database service in a multi-tenant service provider network, the database service including one or more processors and memory storing instructions that upon execution by the one or more processors cause the database service to:

receive a request to execute a query involving at least a column of a relation of a database, wherein the request was issued through a user account;

identify, based on a data structure, one or more roles associated with the user account;

identify multiple masking policies that are attached to the relation, are associated with the column, and are applicable for all users or are applicable for the user account or are applicable for users associated with any of the one or more roles;

select a masking policy from among the multiple masking policies based on the one or more roles associated with the user account, and based on an analysis of priority values associated with the multiple masking policies, whereby the masking policy is selected due to it having a highest or lowest priority value from among the priority values; and

execute the query to generate a result, the executing comprising modifying values of the column based on the selected masking policy, wherein the values of the column were obtained previously or concurrently from data objects of a storage service in the multi-tenant service provider network.

16. The system of claim 15 , wherein the priority values are user-configured priority values associated with attachments of the multiple masking policies to the relation.

17. The system of claim 15 , wherein executing the query comprises:

rewriting the query to yield a rewritten query based on the masking policy;

providing the rewritten query to one or more compute nodes of the database service for use in generating one or more intermediate query results, wherein the one or more compute nodes apply a masking function, selected based on the rewritten query, to values of the column; and

generating the result based on the one or more intermediate query results.

18. The system of claim 15 , wherein the query further involves a second column of the relation, and wherein the database service further includes instructions that upon execution cause the database service to:

select a second masking policy from a second set of multiple masking policies that are associated with the second column and with the one or more roles or the user account,

wherein to execute the query the database service is further to modify values of the second column based on the selected second masking policy.

19. The system of claim 15 , wherein as part of the selection of the masking policy from multiple masking policies, the database service is to:

identify, via a first data structure, a plurality of masking policies that have been attached to the relation; and

select, for inclusion in the multiple masking policies, those of the plurality of masking policies that apply to any of the one or more roles or the user account.

20. The system of claim 19 , wherein as part of the selection of the masking policy from multiple masking policies, the database service is further to select, for inclusion in the multiple masking policies those of the plurality of masking policies that apply to all users or user roles.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2025
From: BOGATOV, DMYTRO; CHINTA, KIRAN KUMAR; JI, YANZHU; MOORE, JAMES CLAIBORNE; SAXENA, GAURAV; SHARMA, ABHISHEK RAI; GREEN, TODD JEFFREY
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 071241/0943 →
References Cited (62)
US 4825391A · Merz · 1989 [cited by examiner]
US 5751967A · Raab · 1998 [cited by examiner]
US 8473410B1 · Haggerty · 2013 [cited by examiner]
US 10867063B1 · Avanes · 2020 [cited by examiner]
US 11341270B2 · Reeve · 2022 [cited by applicant]
US 11567943B1 · Blum · 2023 [cited by examiner]
US 11593521B1 · Balakrishnan · 2023 [cited by examiner]
US 11783078B1 · Li · 2023 [cited by examiner]
US 20030014394A1 · Fujiwara · 2003 [cited by examiner]
US 20060238799A1 · Kidokoro · 2006 [cited by examiner]
US 20110029473A1 · van Lunteren · 2011 [cited by examiner]
US 20120054095A1 · Lesandro · 2012 [cited by examiner]
US 20120197919A1 · Chen · 2012 [cited by examiner]
US 20130019276A1 · Biazetti et al. · 2013 [cited by applicant]
US 20130060820A1 · Bulusu · 2013 [cited by examiner]
US 20130117313A1 · Miao · 2013 [cited by examiner]
US 20140032928A1 · Taskaya et al. · 2014 [cited by applicant]
US 20140096184A1 · Zaitsev · 2014 [cited by examiner]
US 20150095647A1 · Lachterman · 2015 [cited by applicant]
US 20150150075A1 · Vahlis · 2015 [cited by examiner]
US 20150358433A1 · Parthasarathy · 2015 [cited by examiner]
US 20150358434A1 · Parthasarathy · 2015 [cited by examiner]
US 20160164679A1 · Song et al. · 2016 [cited by applicant]
US 20160232159A1 · Parikh · 2016 [cited by applicant]
US 20170005788A1 · Irvine · 2017 [cited by applicant]
US 20170039387A1 · Leonardi · 2017 [cited by examiner]
US 20170272472A1 · Adhar · 2017 [cited by applicant]
US 20180060365A1 · Mujumdar · 2018 [cited by examiner]
US 20180232520A1 · Frandzel et al. · 2018 [cited by applicant]
US 20180307859A1 · LaFever · 2018 [cited by examiner]
US 20190229905A1 · Fan et al. · 2019 [cited by applicant]
US 20190319925A1 · Chalvadi · 2019 [cited by examiner]
US 20200301917A1 · Niu · 2020 [cited by examiner]
US 20200311304A1 · Parthasarathy · 2020 [cited by applicant]
US 20200327252A1 · Mcfall · 2020 [cited by examiner]
US 20200396210A1 · Taylor et al. · 2020 [cited by applicant]
US 20210157948A1 · Avanes · 2021 [cited by examiner]
US 20210286894A1 · Avanes · 2021 [cited by examiner]
US 20220092213A1 · Hou · 2022 [cited by examiner]
US 20220100900A1 · Baldwin et al. · 2022 [cited by applicant]
US 20220164477A1 · Patodia · 2022 [cited by examiner]
US 20220215107A1 · Wong · 2022 [cited by examiner]
US 20220405420A1 · Tommasi et al. · 2022 [cited by applicant]
US 20220407861A1 · Beecham · 2022 [cited by examiner]
US 20220414601A1 · Shek · 2022 [cited by examiner]
US 20230005391A1 · Sharma · 2023 [cited by examiner]
US 20230130637A1 · Hosudurg · 2023 [cited by examiner]
US 20230135186A1 · Hen · 2023 [cited by examiner]
US 20230169198A1 · Blum et al. · 2023 [cited by applicant]
US 20230281326A1 · Magalsky · 2023 [cited by examiner]
US 20240111896A1 · Mcgrath et al. · 2024 [cited by applicant]
US 20240134660A1 · Eberlein · 2024 [cited by examiner]
WO WO2021107994A1 · 2021 [cited by examiner]
Lu et al., “Auditing a Database under Retention Restrictions,” 2009 IEEE 25th International Conference on Data Engineering, Shanghai, China, 2009, pp. 42-53, doi: 10.1109/ICDE.2009.125. (Year: 2009). [cited by examiner]
Colombo et al., “Efficient Enforcement of Action-Aware Purpose-Based Access Control within Relational Database Management Systems,” in IEEE Transactions on Knowledge and Data Engineering, vol. 27, No. 8, pp. 2134-2147, … [cited by examiner]
Naguib et al., “Database Security: Current Challenges and Effective Protection Strategies,” 2024 6th International Conference on Computing and Informatics (ICCI), New Cairo—Cairo, Egypt, 2024, pp. 120-130, doi: 10.1109/… [cited by examiner]
Non-Final Office Action, U.S. Appl. No. 18/058,820, filed Sep. 24, 2024, 43 pages. [cited by applicant]
Peter et al. “Query-Driven Enforcement of Rule-Based Policies for Data-Privacy Compliance”—Published—2019 (Peter hereinafter) (Year: 2019). [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/058,819, filed Dec. 18, 2024, 16 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/058,821, filed Nov. 27, 2024, 13 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 18/058,820, Apr. 9, 2025, 27 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 18/058,821, Mar. 27, 2025, 12 pages. [cited by applicant]
Cited By (2)
US 12,657,344 US 12,743,530