IP Library › Granted Patent US 12,462,056
Granted Patent B2
US 12,462,056 · App. 18/787,930 · Granted Nov 4, 2025

Fine-grained access control via database roles

Inventors: Damien Carru (New York, NY); Pui Kei Johnston Chu (Unionville, CA); Benoit Dageville (San Carlos, CA); Shreyas Narendra Desai (Bellevue, WA); Subramanian Muralidhar (Mercer Island, WA); Bowen Zhang (Newark, CA)
Assignee: Snowflake Inc.
G06F21/6218G06F16/21G06F16/256G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,056
App. No.
18/787,930
Granted
Nov 4, 2025
Kind
B2
Abstract

Embodiments of the present disclosure relate to sharing data using database roles. Database roles are generated within a database container of a provider account. Grants to a particular subset of the plurality of data objects of the database container may be assigned to each of the database roles, and each of the database roles are granted to a share object. The share object is mounted within a consumer account to generate an imported copy of each of the database roles. The imported copy of one or more of the database roles is granted to each of one or more account level roles of the consumer account. When a new object is added to a particular database role, it is immediately available for consumption by any account level roles to which the imported copy of the particular database role has been granted.

Claims (68)

1 . A method comprising:

generating, within a database container of a provider account, a set of database roles, wherein the database container comprises a plurality of objects;

assigning, by a processing device, to each of the set of database roles, a set of grants to a particular subset of the plurality of objects of the database container;

generating an imported database container within a consumer account, the imported database container including an imported copy of each of the set of database roles;

granting, to each of one or more account level roles of the consumer account, the imported copy of one or more of the set of database roles; and

adding a new object to a particular database role of the set of database roles, wherein the new object is immediately available for consumption by any of the one or more account level roles to which the imported copy of the particular database role has been granted.

2 . The method of claim 1 , further comprising:

granting each of the set of database roles to a share object; and

mounting in the consumer account, the share object, wherein granting a database role of the set of database roles to the share object comprises:

creating a hidden role having no identifier;

granting the database role to the hidden role; and

granting the hidden role to the share object.

3 . The method of claim 2 , wherein the hidden role comprises a database role or an account level role.

4 . The method of claim 2 , wherein any objects granted by the provider account to the share object will not result in objects being automatically created in the consumer account.

5 . The method of claim 1 , further comprising:

granting a first database role of the set of database roles to each of a set of share objects.

6 . The method of claim 5 , wherein granting the first database role to each of the set of share objects comprises:

creating a hidden role having no identifier for each of the set of share objects, thereby creating a set of hidden roles;

granting the first database role to each of the set of hidden roles; and

granting each of the set of hidden roles to the corresponding share object of the set of share objects.

7 . The method of claim 1 , wherein adding the new object to the particular database role of the set of database roles database roles does not involve creation in the consumer account of a proxy object that represents the new object and on which the consumer account can grant local privileges.

8 . The method of claim 1 , wherein each of the set of database roles does not include grants to objects outside of the database container.

9 . A system comprising:

a memory; and

a processing device operatively coupled to the memory, the processing device to:

generate, within a database container of a provider account, a set of database roles, wherein the database container comprises a plurality of objects;

assign to each of the set of database roles, a set of grants to a particular subset of the plurality of objects of the database container;

generate an imported database container within a consumer account, the imported database container including an imported copy of each of the set of database roles;

grant, to each of one or more account level roles of the consumer account, the imported copy of one or more of the set of database roles; and

add a new object to a particular database role of the set of database roles, wherein the new object is immediately available for consumption by any of the one or more account level roles to which the imported copy of the particular database role has been granted.

10 . The system of claim 9 , wherein the processing device is further to:

grant each of the set of database roles to a share object; and

mount in the consumer account, the share object, wherein to grant a database role of the set of database roles to the share object, the processing device is to:

create a hidden role having no identifier;

grant the database role to the hidden role; and

grant the hidden role to the share object.

11 . The system of claim 10 , wherein the hidden role comprises a database role or an account level role.

12 . The system of claim 10 , wherein any objects granted by the provider account to the share object will not result in objects being automatically created in the consumer account.

13 . The system of claim 9 , wherein the processing device is further to:

grant a first database role of the set of database roles to each of a set of share objects.

14 . The system of claim 13 , wherein to grant the first database role to each of the set of share objects, the processing device is to:

create a hidden role having no identifier for each of the set of share objects, thereby creating a set of hidden roles;

grant the first database role to each of the set of hidden roles; and

grant each of the set of hidden roles to the corresponding share object of the set of share objects.

15 . The system of claim 9 , wherein when adding the new object to the particular database role of the set of database roles database roles, the processing device does not create in the consumer account, a proxy object that represents the new object and on which the consumer account can grant local privileges.

16 . The system of claim 9 , wherein each of the set of database roles does not include grants to objects outside of the database container.

17 . A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processing device, cause the processing device to:

generate, within a database container of a provider account, a set of database roles, wherein the database container comprises a plurality of objects;

assign, by the processing device, to each of the set of database roles, a set of grants to a particular subset of the plurality of objects of the database container;

generate an imported database container within a consumer account, the imported database container including an imported copy of each of the set of database roles;

grant, to each of one or more account level roles of the consumer account, the imported copy of one or more of the set of database roles; and

add a new object to a particular database role of the set of database roles, wherein the new object is immediately available for consumption by any of the one or more account level roles to which the imported copy of the particular database role has been granted.

18 . The non-transitory computer-readable medium of claim 17 , wherein the processing device is further to:

grant each of the set of database roles to a share object; and

mount in the consumer account, the share object, wherein to grant a database role of the set of database roles to the share object, the processing device is to:

create a hidden role having no identifier;

grant the database role to the hidden role; and

grant the hidden role to the share object.

19 . The non-transitory computer-readable medium of claim 18 , wherein the hidden role comprises a database role or an account level role.

20 . The non-transitory computer-readable medium of claim 18 , wherein any objects granted by the provider account to the share object will not result in objects being automatically created in the consumer account.

21 . The non-transitory computer-readable medium of claim 17 , wherein the processing device is further to:

grant a first database role of the set of database roles to each of a set of share objects.

22 . The non-transitory computer-readable medium of claim 21 , wherein to grant the first database role to each of the set of share objects, the processing device is to:

create a hidden role having no identifier for each of the set of share objects, thereby creating a set of hidden roles;

grant the first database role to each of the set of hidden roles; and

grant each of the set of hidden roles to the corresponding share object of the set of share objects.

23 . The non-transitory computer-readable medium of claim 17 , wherein when adding the new object to the particular database role of the set of database roles database roles, the processing device does not create in the consumer account, a proxy object that represents the new object and on which the consumer account can grant local privileges.

24 . The non-transitory computer-readable medium of claim 17 , wherein each of the set of database roles does not include grants to objects outside of the database container.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2025
From: CARRU, DAMIEN; CHU, PUI KEI JOHNSTON; DAGEVILLE, BENOIT; DESAI, SHREYAS NARENDRA; MURALIDHAR, SUBRAMANIAN; ZHANG, BOWEN
To: SNOWFLAKE INC.
Reel/Frame 071651/0772 →
Continuity (7)
Continuation 18378575 · Oct 10, 2023
Continuation 18109191 · Feb 13, 2023
Continuation 17957794 · Sep 30, 2022
Continuation 17841996 · Jun 16, 2022
Continuation 17464538 · Sep 1, 2021
Provisional Application 63237490 · Aug 26, 2021
Related Publication 20240394395A1 · Nov 28, 2024
References Cited (35)
US 7870188B2 · Mazzitelli et al. · 2011 [cited by applicant]
US 8688736B2 · Mehta · 2014 [cited by examiner]
US 9256761B1 · Sahu et al. · 2016 [cited by applicant]
US 10613737B1 · Morris · 2020 [cited by applicant]
US 10628415B1 · Rajaperumal · 2020 [cited by examiner]
US 10642856B1 · Chu et al. · 2020 [cited by applicant]
US 10671628B2 · Sullivan et al. · 2020 [cited by applicant]
US 10713380B1 · Langseth et al. · 2020 [cited by applicant]
US 11068492B2 · Trudeau et al. · 2021 [cited by applicant]
US 20020184401A1 · Kadel, Jr. et al. · 2002 [cited by applicant]
US 20090070744A1 · Taylor et al. · 2009 [cited by applicant]
US 20130054648A1 · Mehta et al. · 2013 [cited by applicant]
US 20140095546A1 · Kruglikov · 2014 [cited by examiner]
US 20150310188A1 · Ford et al. · 2015 [cited by applicant]
US 20170041296A1 · Ford et al. · 2017 [cited by applicant]
US 20170323112A1 · Tran · 2017 [cited by examiner]
US 20180196955A1 · Dageville et al. · 2018 [cited by applicant]
US 20180373887A1 · Smith · 2018 [cited by applicant]
US 20190222560A1 · Ford et al. · 2019 [cited by applicant]
US 20200042734A1 · Lee et al. · 2020 [cited by applicant]
US 20200042737A1 · Lee et al. · 2020 [cited by applicant]
US 20200159514A1 · Brooks et al. · 2020 [cited by applicant]
US 20200226281A1 · Hentschel et al. · 2020 [cited by applicant]
US 20200257817A1 · Dageville et al. · 2020 [cited by applicant]
US 20210084104A1 · Glickman · 2021 [cited by examiner]
US 20220245032A1 · Singh · 2022 [cited by examiner]
Shah, Vivek, et al., “Actor-Relational Database Systems: A Manifesto”, arXiv, dated: Sep. 10, 2018, downloaded from: https://arxiv.org/abs/1707.06507v2, document: arViv:1707.06507v2 [cs.DB], Cornell University, pp. 1-16. [cited by examiner]
Raghuram, S., et al., “Taming the Downtime: High Availability in Sybase ASE 12”, ICDE 2000, San Diego, CA, Feb. 29-Mar. 3, 2000, 10 pages. [cited by examiner]
Wong, Raymond K., “RBAC Support in Object-Oriented Role Databases”, RBAC '97, Fairfax, VA, © 1997 ACM, pp. 109-120. [cited by examiner]
Anoshin, Dmitry, et al., “Chapter 10: Secure Data Sharing”, Jump Start Snowflake, Apress, Berkeley, CA, Dec. 21, 2019 (first online), pp. 177-193. [cited by applicant]
Moyer, Matthew J. et al. “Generalized Role-Based Access Control”, ICDSC 2001, Mesa, AZ, Apr. 16-19, 2001, pp. 391-398. [cited by applicant]
Zeng, Wenrong, et al., “Content-Based Access Control: Use Data Content to Assist Access Control for Large-Scale Content-Centric Databases”, BigData 2014, Washington DC, Oct. 27-30, 2014, pp. 701-710. [cited by applicant]
International Search Report and Written Opinion for related PCT Application No. PCT/US2022/039493, mailed on Nov. 30, 2022, 12 pages. [cited by applicant]
International Preliminary Report on Patentability for related PCT Application No. PCT/US2022/039493, mailed on Mar. 7, 2024, 9 pages. [cited by applicant]
Anonymous: “Sharing Data Securely in Snowflake—Snowflake Documentation”, Mar. 27, 2021, 119 pages, XP055983128, https://web.archive.org/web/20210120193756/https://docs.snowflake.com/en/user-guide-data-share.html. [cited by applicant]