IP Library › Granted Patent US 12,699,797
Granted Patent B2
US 12,699,797 · App. 18/893,231 · Granted Aug 4, 2026

Catalog service configuration based on a privilege model and two-way synchronization

Inventors: Damien Carru (New York, NY); Xianyin Chen (Seattle, WA); Michael Collado (Seattle, WA); Benoit Dageville (San Mateo, CA); Dennis Huo (Newcastle, WA); Tyler Jones (Redwood City, CA); Dennis Edgar Lynch (San Carlos, CA); James Malone (Seattle, WA); Subramanian Muralidhar (Mercer Island, WA); Maninderjit Singh Parmar (Kirkland, WA); Saurin Shah (Kirkland, WA)
Assignee: Snowflake Inc.
G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,699,797
App. No.
18/893,231
Filed
Sep 23, 2024
Granted
Aug 4, 2026
Kind
B2
Art Unit
2498
USPC
726/28
Abstract

Provided herein are systems, methods, and computer-storage media for managing data object access in a catalog service account. The method includes detecting, at a catalog service account, by a catalog manager (CM), a user request to access a data object. The user request includes identification information of the user and a principal role associated with the user. The CM retrieves one or more catalog roles from a first catalog of the catalog service account. The one or more catalog roles correspond to the principal role. The CM determines a set of hierarchical data objects based on the user request. The set of hierarchical data objects comprise the data object. The CM performs a determination of whether access privileges of the set of hierarchical data objects and access privileges of the one or more catalog roles allow access to the data object. The CM grants access to the data object based on the determination.

Claims (92)

1 . A system comprising:

at least one hardware processor; and

at least one memory storing instructions that cause the at least one hardware processor to perform operations comprising:

detecting, at a catalog service account, a user request to access a data object, the user request including identification information of the user and a principal role associated with the user;

retrieving one or more catalog roles from a first catalog of the catalog service account, the one or more catalog roles corresponding to the principal role;

determining a set of hierarchical data objects based on the user request, the set of hierarchical data objects comprising the data object;

performing a determination of whether access privileges of the set of hierarchical data objects and access privileges of the one or more catalog roles allow access to the data object; and

granting access to the data object based on the determination.

2 . The system of claim 1 , the operations further comprising:

retrieving the access privileges of the set of hierarchical data objects and the access privileges of the one or more catalog roles from a role-based security model of the catalog service account.

3 . The system of claim 2 , the operations further comprising:

detecting the set of hierarchical data objects comprises a plurality of nested namespaces; and

determining the access privileges of the set of hierarchical data objects based on access privileges for each namespace of the plurality of nested namespaces.

4 . The system of claim 2 , the operations further comprising:

retrieving a first set of access privileges from the role-based security model, the first set of access privileges associated with the first catalog, and including the access privileges of the one or more catalog roles;

retrieving a second set of access privileges from the role-based security model, the second set of access privileges associated with a second catalog of the catalog service account; and

configuring access to the first catalog and the second catalog based on the first set of access privileges and the second set of access privileges.

5 . The system of claim 1 , the operations further comprising:

retrieving a plurality of principal identities associated with the catalog service account; and

selecting a principal identity of the plurality of principal identities based on the identification information of the user.

6 . The system of claim 5 , the operations further comprising:

retrieving a plurality of catalog roles configured in the first catalog; and

selecting the one or more catalog roles from the plurality of catalog roles based on the principal role.

7 . The system of claim 1 , the operations further comprising:

determining the set of hierarchical data objects based on the one or more catalog roles, the set of hierarchical data objects comprising at least one namespace, at least one table, and at least one table view.

8 . The system of claim 1 , the operations further comprising:

detecting a synchronization request received at the catalog service account, the synchronization request associated with a second catalog that is external to the catalog service account.

9 . The system of claim 8 , the operations further comprising:

generating responsive to the synchronization request, an external catalog representation of the second catalog, the external catalog representation configured as a read-only catalog in the catalog service account.

10 . The system of claim 9 , the operations further comprising:

receiving via an application programming interface (API), a notification of an update posted to the second catalog; and

updating the external catalog representation based on the update.

11 . A method comprising:

detecting, at a catalog service account, by at least one hardware processor, a user request to access a data object, the user request including identification information of the user and a principal role associated with the user;

retrieving one or more catalog roles from a first catalog of the catalog service account, the one or more catalog roles corresponding to the principal role;

determining a set of hierarchical data objects based on the user request, the set of hierarchical data objects comprising the data object;

performing a determination of whether access privileges of the set of hierarchical data objects and access privileges of the one or more catalog roles allow access to the data object; and

granting access to the data object based on the determination.

12 . The method of claim 11 , further comprising:

retrieving the access privileges of the set of hierarchical data objects and the access privileges of the one or more catalog roles from a role-based security model of the catalog service account.

13 . The method of claim 12 , further comprising:

detecting the set of hierarchical data objects comprises a plurality of nested namespaces; and

determining the access privileges of the set of hierarchical data objects based on access privileges for each namespace of the plurality of nested namespaces.

14 . The method of claim 12 , further comprising:

retrieving a first set of access privileges from the role-based security model, the first set of access privileges associated with the first catalog, and including the access privileges of the one or more catalog roles;

retrieving a second set of access privileges from the role-based security model, the second set of access privileges associated with a second catalog of the catalog service account; and

configuring access to the first catalog and the second catalog based on the first set of access privileges and the second set of access privileges.

15 . The method of claim 11 , further comprising:

retrieving a plurality of principal identities associated with the catalog service account; and

selecting a principal identity of the plurality of principal identities based on the identification information of the user.

16 . The method of claim 15 , further comprising:

retrieving a plurality of catalog roles configured in the first catalog; and

selecting the one or more catalog roles from the plurality of catalog roles based on the principal role.

17 . The method of claim 11 , further comprising:

determining the set of hierarchical data objects based on the one or more catalog roles, the set of hierarchical data objects comprising at least one namespace, at least one table, and at least one table view.

18 . The method of claim 11 , further comprising:

detecting a synchronization request received at the catalog service account, the synchronization request associated with a second catalog that is external to the catalog service account.

19 . The method of claim 18 , further comprising:

generating responsive to the synchronization request, an external catalog representation of the second catalog, the external catalog representation configured as a read-only catalog in the catalog service account.

20 . The method of claim 19 , further comprising:

receiving via an application programming interface (API), a notification of an update posted to the second catalog; and

updating the external catalog representation based on the update.

21 . A computer-storage medium comprising instructions that, when executed by one or more processors of a machine, configure the machine to perform operations comprising:

detecting at a catalog service account, a user request to access a data object, the user request including identification information of the user and a principal role associated with the user;

retrieving one or more catalog roles from a first catalog of the catalog service account, the one or more catalog roles corresponding to the principal role;

determining a set of hierarchical data objects based on the user request, the set of hierarchical data objects comprising the data object;

performing a determination of whether access privileges of the set of hierarchical data objects and access privileges of the one or more catalog roles allow access to the data object; and

granting access to the data object based on the determination.

22 . The computer-storage medium of claim 21 , the operations further comprising:

retrieving the access privileges of the set of hierarchical data objects and the access privileges of the one or more catalog roles from a role-based security model of the catalog service account.

23 . The computer-storage medium of claim 22 , the operations further comprising:

detecting the set of hierarchical data objects comprises a plurality of nested namespaces; and

determining the access privileges of the set of hierarchical data objects based on access privileges for each namespace of the plurality of nested namespaces.

24 . The computer-storage medium of claim 22 , the operations further comprising:

retrieving a first set of access privileges from the role-based security model, the first set of access privileges associated with the first catalog, and including the access privileges of the one or more catalog roles;

retrieving a second set of access privileges from the role-based security model, the second set of access privileges associated with a second catalog of the catalog service account; and

configuring access to the first catalog and the second catalog based on the first set of access privileges and the second set of access privileges.

25 . The computer-storage medium of claim 21 , the operations further comprising:

retrieving a plurality of principal identities associated with the catalog service account; and

selecting a principal identity of the plurality of principal identities based on the identification information of the user.

26 . The computer-storage medium of claim 25 , the operations further comprising:

retrieving a plurality of catalog roles configured in the first catalog; and

selecting the one or more catalog roles from the plurality of catalog roles based on the principal role.

27 . The computer-storage medium of claim 21 , the operations further comprising:

determining the set of hierarchical data objects based on the one or more catalog roles, the set of hierarchical data objects comprising at least one namespace, at least one table, and at least one table view.

28 . The computer-storage medium of claim 21 , the operations further comprising:

detecting a synchronization request received at the catalog service account, the synchronization request associated with a second catalog that is external to the catalog service account.

29 . The computer-storage medium of claim 28 , the operations further comprising:

generating responsive to the synchronization request, an external catalog representation of the second catalog, the external catalog representation configured as a read-only catalog in the catalog service account.

30 . The computer-storage medium of claim 29 , the operations further comprising:

receiving via an application programming interface (API), a notification of an update posted to the second catalog; and

updating the external catalog representation based on the update.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2025
From: CARRU, DAMIEN; CHEN, XIANYIN; COLLADO, MICHAEL; DAGEVILLE, BENOIT; HUO, DENNIS; JONES, TYLER; LYNCH, DENNIS EDGAR; MALONE, JAMES; MURALIDHAR, SUBRAMANIAN; PARMAR, MANINDERJIT SINGH; SHAH, SAURIN
To: SNOWFLAKE INC.
Reel/Frame 069817/0317 →
Continuity (1)
Related Publication 20260087160A1 · Mar 26, 2026
References Cited (22)
US 6076091A · Fohn · 2000 [cited by examiner]
US 11615062B1 · Waas et al. · 2023 [cited by applicant]
US 20130111583A1 · Hernandez · 2013 [cited by examiner]
US 20180004793A1 · Desai et al. · 2018 [cited by applicant]
US 20180150362A1 · Lee et al. · 2018 [cited by applicant]
US 20190045007A1 · Wyatt et al. · 2019 [cited by applicant]
US 20200089789A1 · Mace et al. · 2020 [cited by applicant]
US 20200311294A1 · Sim-Tang · 2020 [cited by examiner]
US 20240394293A1 · Lauber · 2024 [cited by applicant]
US 20250245206A1 · Fanghaenel et al. · 2025 [cited by applicant]
Apache Iceberg, “Spec Table Metadata Fields”, [Online]. Retrieved from the Internet: https: iceberg.apache.org spec #table-metadata-fields, (Accessed online Jan. 23, 2025), 131 pages. [cited by applicant]
Apache Iceberg, “Configuration Catalog Properties”, [Online]. Retrieved from the Internet: https: iceberg.apache.org docs 1.5.0 configuration #catalog-properties, (Accessed online Apr. 30, 2025), 16 pages. [cited by applicant]
Apache Polaris, “Access Control”, [Online]. Retrieved from the Internet: https: polaris.apache.org in-dev unreleased access-control, (Accessed online Apr. 23, 2025), 7 pages. [cited by applicant]
Github, “Rest Catalog Open-Api.yaml”, [Online]. Retrieved from the Internet: https: github.com apache iceberg blob 2886ef4bf6cf575f9780a5bfd351a4f4d51cce4b open-api rest-catalog-open-api.yaml#L959C3-L959C36, (Accessed o… [cited by applicant]
Github, “Rest Catalog Open api.yaml (ed2d041)”, [Online]. Retrieved from the Internet: https: github.com apache iceberg blob ed2d0410c861c6fcec825dff738d01559f2cd590 open-api rest-catalog-open-api.yaml#L2557C1-L2575C62,… [cited by applicant]
Github, “GlueTableOperations.java”, [Online]. Retrieved from the Internet: https: github.com apache iceberg blob e10098b9ab7cb532d2ca4876f00997102446e52d aws src main java org apache iceberg aws glue GlueTableOperations… [cited by applicant]
Github, “Rest Catalog Open api.yaml (ed0959257)”, [Online]. Retrieved from the Internet: https: github.com apache iceberg blob ed0959257cba02f378f7097d81cecaaaef9fa43f open-api rest-catalog-open-api.yaml#L132, (Accessed… [cited by applicant]
IBM, “Handle SQL identifiers”, [Online]. Retrieved from the Internet: https: www.ibm.com docs en netezza?topic=md- handle-sql-identifiers, (Accessed online Apr. 23, 2025), 2 pages. [cited by applicant]
Iceberg Apache, “Interface Supports Name spaces”, [Online]. Retrieved from the Internet: https: iceberg.apache. org javadoc latest org apache iceberg catalog SupportsNamespaces.html#setProperties(org.apache.iceberg.cata… [cited by applicant]
Kaul, Jan, “Rest-Catalog: Define Route to update MetadataLocation of a Table #7261”, apache iceberg, [Online]. Retrieved from the Internet: https: github.com apache iceberg issues 7261, (Apr. 1, 2023), 3 pages. [cited by applicant]
SPEC—Apache Iceberg, “Table Metadata Fields”, [Online]. Retrieved from the Internet: https: iceberg.apache.org spec #table-metadata-fields, (Accessed online Apr. 30, 2025), 132 pages. [cited by applicant]
Stack Overflow, “S3: How to grant access to multiple buckets?”, [Online]. Retrieved from the Internet: https: stackoverflow.com questions 33744753 s3-how-to-grant-access-to-multiple-buckets, (Accessed online Apr. 30, 20… [cited by applicant]