Secure Data Application Access via Privileged Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data platforms face challenges in securely sharing data applications across multiple accounts without exposing sensitive data, as current solutions often require copying data from the provider's account to the consumer's account, compromising data security.

Innovation Solution

The data platform implements a solution where data applications are granted privileges to access data in both the provider's and consumer's accounts, while maintaining secure user contexts. This is achieved by creating the data application as a first-class database entity, allowing users and roles to be granted access, and packaging it within a data platform native application framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is copied from provider's account to consumer's account to enable application access, then application accessibility is improved, but data security is worsened

Engineering Contradiction:
Improveapplication accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a data platform as an intermediary that enables the data application to access data in both provider and consumer accounts without requiring data copying. The platform acts as a mediator that manages access privileges and maintains secure user contexts, allowing the application to query and process data from multiple accounts simultaneously while preserving security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The data application is designed with universal access capabilities, allowing it to operate in multiple account contexts (both provider and consumer accounts) simultaneously. This multi-functionality enables the application to leverage data from diverse sources without requiring separate instances or data copies, thereby improving accessibility while maintaining security through controlled privilege management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If data application is shared across multiple accounts, then application versatility is improved, but data exposure risk is worsened

Engineering Contradiction:
Improveapplication sharing capabilityVSAvoiddata exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by maintaining distinct user contexts for each account (provider and consumer), ensuring that data access privileges are scoped and localized to appropriate accounts. The data application operates with different access rights in different contexts, allowing versatile multi-account functionality while preventing unauthorized data exposure through context-aware privilege control.

Inventive Principle:
Principle #3Local quality

3Productivity

If data is transferred between accounts to enable application functionality, then application operational capability is improved, but data loss is worsened

Engineering Contradiction:
Improveapplication operational capabilityVSAvoiddata transfer
Core Design Contradiction:
ProductivityVSLoss of substance

Solution Approach 1:

The data platform serves as an intermediary that enables application operational capability across multiple accounts without requiring physical data transfer. The platform provides virtual data access mechanisms that allow the application to query, process, and analyze data from both provider and consumer accounts in real-time, eliminating the need for data copying while maintaining full operational capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250045444A1Secure shared data application access
Publication Date: 2025.02.06 SNOWFLAKE INC
  • US20250045444A1 patent drawing
  • US20250045444A1 patent drawing
  • US20250045444A1 patent drawing

AI summary

A data platform for developing and deploying a data application. The data platform receives from a first user the data application and provider granted privileges including a consumer usage privilege and a consumer access to data privilege. The data platform authorizes the second user to access the data platform based on one or more consumer account privileges included in a set of account privileges. The data platform authorizes the second user to execute the data application based on the consumer usage privilege. During execution, the data platform authorizes the data application to access the provider database object based on the consumer access to data privilege, and authorizes the data application to access the consumer database object based on a provider access to data privilege provided by the second user.