Shared Object Discovery for Secure Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data sharing methods are inefficient and costly, particularly for smaller entities, as they require cumbersome data transfer processes, lack control over data access, and introduce latency, making it difficult for smaller businesses to access valuable large datasets.
Innovation Solution
A data exchange platform that allows data providers to share data without copying it, using cloud computing services like SNOWFLAKE, where data providers control access and permissions, enabling secure and scalable data sharing through role-based access control and secure joins, while utilizing share authorization to correctly identify authorized access to shared objects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional data sharing methods are used to transfer large datasets, then data access is enabled, but the process becomes cumbersome, costly, and introduces latency
Solution Approach 1:
Instead of physically copying and transferring large datasets through traditional methods, the patent creates a shared database object that references the original data. This allows multiple users to access the same data without actual data movement, eliminating transfer time and costs while maintaining data availability.
Solution Approach 2:
The patent introduces a shared database object as an intermediary between the original data source and users. This object acts as a reference layer that enables data access without direct data transfer, resolving the contradiction between enabling data access and avoiding transfer latency.
2Ease of operation
If data is shared through traditional transfer methods, then data access is provided, but control over data access and usage is lost
Solution Approach 1:
The patent implements dynamic access control through the shared database object, which can be configured with specific privileges and permissions. The data provider can dynamically grant, revoke, or modify access rights without affecting the underlying data, enabling both easy access and maintained control simultaneously.
3Reliability
If data is encrypted for secure storage, then unauthorized access is prevented, but data sharing and querying become more complex
Solution Approach 1:
The patent extracts the security management function from the data sharing process itself. By implementing access control at the shared object level rather than requiring decryption and re-encryption during sharing, the system maintains security while simplifying the data sharing and querying operations.
Data Source
AI summary
A consumer account may invoke an operation referencing a set of shared objects stored within a database of a provider account using an imported database that makes the set of shared objects available within the consumer account. A call context of the operation may be updated to cache the imported database, which references a share created from the provider account database, the share having grants to the set of shared objects. One or more database level objects may be discovered in a context of the share and each role granted to the share may be obtained based on the one or more database level objects. Whether any role granted to the share has access to any of the set of shared objects may be determined and the operation may be executed for each of the set of shared objects to which any role granted to the share has access.


