Dynamic Shared Data Object Masking for Scalable Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud database services face challenges in securely and scalably managing access to specific data as the amount of data increases, making it difficult to create secure access for individuals while maintaining scalability.

Innovation Solution

A shared database platform implements dynamic masking of data based on preconfigured functions associated with user roles, allowing masking to be applied at runtime in response to user access requests, with a network-based data warehouse system that separates computing resources from data storage, enabling dynamic scaling and secure data sharing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access control methods are used in cloud database services, then data security can be maintained, but scalability deteriorates as the amount of data increases

Engineering Contradiction:
Improvedata securityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic data masking where the masking rules and visibility of data are determined at runtime based on user roles, attributes, and contextual factors. This allows the access control system to adapt dynamically to different users and data scenarios without requiring manual configuration changes, thereby maintaining security while scaling efficiently as data grows.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes access control parameters dynamically based on user attributes, data sensitivity levels, and contextual conditions. By modifying masking parameters at runtime rather than using static access control lists, the system achieves both security (through parameter-based control) and scalability (through automated parameter adjustment without manual intervention).

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If data is shared across multiple user accounts, then data accessibility is improved, but data security and access control complexity increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidaccess control complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent creates a universal masking framework that applies across all user accounts and data types through a consistent set of rules and policies. This single multi-functional system handles access control for diverse users and data scenarios, eliminating the need for separate access control configurations for each user or data set, thereby reducing overall system complexity while improving accessibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically applies appropriate masking rules based on user attributes and data characteristics without requiring manual access control configuration for each user. The automated rule application and role-based access control enable the system to self-manage access complexity, making data sharing easier while keeping access control mechanisms transparent and manageable.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3956797B1Dynamic shared data object masking
Publication Date: 2025.09.03 SNOWFLAKE INC
  • EP3956797B1 patent drawingFigure 1
  • EP3956797B1 patent drawingFigure 2
  • EP3956797B1 patent drawingFigure 3

AI summary

A shared database platform implements dynamic masking on data shared between users where specific data is masked, transformed, or otherwise modified based on preconfigured functions that are associated with user roles. The shared database platform can implement the masking at runtime dynamically in response to users requesting access to a database object that is associated with one or more masking policies.