Cloud Database Data Certification for Limited Consumer Views
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud database platforms like Snowflake struggle to efficiently manage data sharing among consumers with varying access permissions, leading to cumbersome and resource-intensive processes due to the need for data duplication and processing to enforce access restrictions.
Innovation Solution
Implementing a data certification process that generates a limited consumer view definition, allowing consumers to access only permitted data portions without modifying the underlying data, using cloud database platforms with virtual warehouses to enforce access rules through shared view definitions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is shared among multiple consumers with different access permissions, then data accessibility and collaboration are improved, but data security and access control complexity increase
Solution Approach 1:
The patent segments data access control into two independent layers: (1) data certification layer that validates data quality and compliance independently of consumers, and (2) access permission layer that handles consumer-specific authorization. This segmentation allows different consumers to access the same certified data with different permission levels without increasing overall system complexity.
Solution Approach 2:
The patent implements preliminary data certification before data sharing occurs. Data producers must certify their data against predefined rules and standards before it becomes available to consumers. This preliminary action ensures data quality and compliance upfront, eliminating the need for complex runtime validation for each consumer and simplifying access control.
2Reliability
If data is duplicated and processed to enforce access restrictions, then data security is improved, but storage and processing overheads increase
Solution Approach 1:
The patent introduces data certification as an intermediary mechanism between data producers and consumers. Instead of duplicating data for different consumers, the system uses certification metadata and virtual views to enforce access restrictions. This intermediary approach maintains data security while avoiding the storage overhead of physical data duplication.
Solution Approach 2:
The patent uses virtual copying through view definitions rather than physical data duplication. Certified data remains stored once, but multiple consumers can access it through virtual views that enforce their specific access permissions. This virtual copying approach maintains security while minimizing storage overhead.
3Reliability
If data is duplicated and processed to enforce access restrictions, then data security is improved, but processing time and resources increase
Solution Approach 1:
The patent performs data certification and validation in advance, before data is shared with consumers. This preliminary processing ensures data security requirements are met upfront, so that during actual data access, no additional processing time is required to enforce restrictions. Consumers can query certified data immediately with minimal overhead.
Solution Approach 2:
The patent establishes continuous data certification processes where data producers maintain ongoing compliance with certification rules. Once data is certified, this valid certification state continues to be recognized across all consumer accesses, eliminating the need for repeated validation processing for each query and maintaining continuous security enforcement with minimal time overhead.
Data Source
AI summary
Methods, systems, and apparatuses for providing access to records of a database stored on a database server in a cloud database platform are described herein. A data sharing platform may determine a shared view definition for access to the database. The data sharing platform may determine rules that specify criteria that limit access to the records stored by the database. The one or more first rules may be received via a user interface. The data sharing platform may perform, based on the rules, a data access certification process on the records stored by the database to generate a table of certification results. The data sharing platform may generate, based on the table of certification results, and without modifying the records stored by the database, a limited consumer view definition. Based on updates to the records, a new limited consumer view definition may be generated.


