Secure Data Application Access via Privileged Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data platforms face challenges in securely sharing data applications across multiple accounts without exposing sensitive data, as current solutions often require copying data from the provider's account to the consumer's account, compromising data security.
Innovation Solution
The data platform implements a solution where data applications are granted privileges to access data in both the provider's and consumer's accounts, while maintaining secure user contexts. This is achieved by creating the data application as a first-class database entity, allowing users and roles to be granted access, and packaging it within a data platform native application framework.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is copied from provider's account to consumer's account to enable application access, then application accessibility is improved, but data security is worsened
Solution Approach 1:
The patent introduces a data platform as an intermediary that enables the data application to access data in both provider and consumer accounts without requiring data copying. The platform acts as a mediator that manages access privileges and maintains secure user contexts, allowing the application to query and process data from multiple accounts simultaneously while preserving security boundaries.
Solution Approach 2:
The data application is designed with universal access capabilities, allowing it to operate in multiple account contexts (both provider and consumer accounts) simultaneously. This multi-functionality enables the application to leverage data from diverse sources without requiring separate instances or data copies, thereby improving accessibility while maintaining security through controlled privilege management.
2Adaptability or versatility
If data application is shared across multiple accounts, then application versatility is improved, but data exposure risk is worsened
Solution Approach 1:
The patent implements local quality by maintaining distinct user contexts for each account (provider and consumer), ensuring that data access privileges are scoped and localized to appropriate accounts. The data application operates with different access rights in different contexts, allowing versatile multi-account functionality while preventing unauthorized data exposure through context-aware privilege control.
3Productivity
If data is transferred between accounts to enable application functionality, then application operational capability is improved, but data loss is worsened
Solution Approach 1:
The data platform serves as an intermediary that enables application operational capability across multiple accounts without requiring physical data transfer. The platform provides virtual data access mechanisms that allow the application to query, process, and analyze data from both provider and consumer accounts in real-time, eliminating the need for data copying while maintaining full operational capability.
Data Source
AI summary
A data platform for developing and deploying a data application. The data platform receives from a first user the data application and provider granted privileges including a consumer usage privilege and a consumer access to data privilege. The data platform authorizes the second user to access the data platform based on one or more consumer account privileges included in a set of account privileges. The data platform authorizes the second user to execute the data application based on the consumer usage privilege. During execution, the data platform authorizes the data application to access the provider database object based on the consumer access to data privilege, and authorizes the data application to access the consumer database object based on a provider access to data privilege provided by the second user.


