Cloud Database Data Certification for Limited Consumer Views

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud database platforms like Snowflake struggle to efficiently manage data sharing among consumers with varying access permissions, leading to cumbersome and resource-intensive processes due to the need for data duplication and processing to enforce access restrictions.

Innovation Solution

Implementing a data certification process that generates a limited consumer view definition, allowing consumers to access only permitted data portions without modifying the underlying data, using cloud database platforms with virtual warehouses to enforce access rules through shared view definitions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is shared among multiple consumers with different access permissions, then data accessibility and collaboration are improved, but data security and access control complexity increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidaccess control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments data access control into two independent layers: (1) data certification layer that validates data quality and compliance independently of consumers, and (2) access permission layer that handles consumer-specific authorization. This segmentation allows different consumers to access the same certified data with different permission levels without increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary data certification before data sharing occurs. Data producers must certify their data against predefined rules and standards before it becomes available to consumers. This preliminary action ensures data quality and compliance upfront, eliminating the need for complex runtime validation for each consumer and simplifying access control.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If data is duplicated and processed to enforce access restrictions, then data security is improved, but storage and processing overheads increase

Engineering Contradiction:
Improvedata securityVSAvoidstorage overhead
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent introduces data certification as an intermediary mechanism between data producers and consumers. Instead of duplicating data for different consumers, the system uses certification metadata and virtual views to enforce access restrictions. This intermediary approach maintains data security while avoiding the storage overhead of physical data duplication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses virtual copying through view definitions rather than physical data duplication. Certified data remains stored once, but multiple consumers can access it through virtual views that enforce their specific access permissions. This virtual copying approach maintains security while minimizing storage overhead.

Inventive Principle:
Principle #26Copying

3Reliability

If data is duplicated and processed to enforce access restrictions, then data security is improved, but processing time and resources increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs data certification and validation in advance, before data is shared with consumers. This preliminary processing ensures data security requirements are met upfront, so that during actual data access, no additional processing time is required to enforce restrictions. Consumers can query certified data immediately with minimal overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes continuous data certification processes where data producers maintain ongoing compliance with certification rules. Once data is certified, this valid certification state continues to be recognized across all consumer accesses, eliminating the need for repeated validation processing for each query and maintaining continuous security enforcement with minimal time overhead.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12361156B2Data certification process for cloud database platform
Publication Date: 2025.07.15 CAPITAL ONE SERVICES LLC
  • US12361156B2 patent drawing
  • US12361156B2 patent drawing
  • US12361156B2 patent drawing

AI summary

Methods, systems, and apparatuses for providing access to records of a database stored on a database server in a cloud database platform are described herein. A data sharing platform may determine a shared view definition for access to the database. The data sharing platform may determine rules that specify criteria that limit access to the records stored by the database. The one or more first rules may be received via a user interface. The data sharing platform may perform, based on the rules, a data access certification process on the records stored by the database to generate a table of certification results. The data sharing platform may generate, based on the table of certification results, and without modifying the records stored by the database, a limited consumer view definition. Based on updates to the records, a new limited consumer view definition may be generated.