Cloud Database Data Certification for Copy-Free Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud database platforms like Snowflake struggle with efficiently sharing data among consumers while ensuring compliance with access restrictions, leading to cumbersome and resource-intensive data processing and duplication.

Innovation Solution

Implementing limited consumer view definitions that allow data producers to share data without copying or modifying it, using cloud database platforms with virtual warehouses to enforce access rules, ensuring consumers access only permitted data portions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is copied and modified for different consumers, then access restrictions can be enforced, but storage needs increase and resource waste occurs

Engineering Contradiction:
Improveaccess restriction enforcementVSAvoiddata storage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent uses virtual copies (views) of data rather than physical copies. Multiple consumer-specific views can be created from a single data source, allowing access restrictions to be enforced through virtual duplication without duplicating the actual data storage. This resolves the contradiction by enabling restriction enforcement while maintaining single-source storage.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a data certification layer as an intermediary between the data source and consumers. This certification mechanism validates data against access rules without requiring data modification or copying, enabling restriction enforcement while preserving the original data intact.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is copied and modified for different consumers, then access restrictions can be enforced, but processing resources increase

Engineering Contradiction:
Improveaccess restriction enforcementVSAvoidprocessing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

By using virtual views instead of physical copies, the system avoids the computational overhead of duplicating and synchronizing data across multiple copies. The certification process operates on metadata and access rules rather than actual data transformations, significantly reducing processing resource consumption.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The data certification layer acts as an intermediary that enforces access restrictions through validation logic rather than data modification. This approach requires minimal processing resources compared to traditional methods that would need to physically filter, copy, or transform data for each consumer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If traditional data sharing methods are used, then access control can be implemented, but data duplication and storage overhead occur

Engineering Contradiction:
Improveaccess controlVSAvoiddata storage
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent implements access control through virtual copying via views rather than physical data duplication. Multiple consumer-specific views can be defined over the same underlying data, providing ease of access control while eliminating the storage overhead associated with traditional data copying methods.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent creates a universal data sharing mechanism where a single data source can serve multiple consumers with different access requirements simultaneously. The certification layer provides multi-functional access control that can handle different consumer needs without requiring separate data copies for each consumer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250307248A1Data Certification Process for Updates to Data in Cloud Database Platform
Publication Date: 2025.10.02 CAPITAL ONE SERVICES LLC
  • US20250307248A1 patent drawing
  • US20250307248A1 patent drawing
  • US20250307248A1 patent drawing

AI summary

Methods, systems, and apparatuses for providing access to records of a database stored on a database server in a cloud database platform are described herein. A data sharing platform may determine a shared view definition for access to the database. The data sharing platform may determine rules that specify criteria that limit access to the records stored by the database. The one or more first rules may be received via a user interface. The data sharing platform may perform, based on the rules, a data access certification process on the records stored by the database to generate a table of certification results. The data sharing platform may generate, based on the table of certification results, and without modifying the records stored by the database, a limited consumer view definition. Based on updates to the records, a new limited consumer view definition may be generated.