Method and system for delivering runtime business intelligence (BI) and ensuring data protection
The method and system ensure secure delivery of BI services by generating encrypted queries and placeholders within the customer's network, addressing data security and compliance challenges, and maintaining data sovereignty and service provider IP protection.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-10
- Publication Date
- 2026-03-26
AI Technical Summary
Conventional methods for delivering business intelligence (BI) services face challenges in ensuring data security and compliance with privacy regulations, leading to risks of data breaches and exposure of proprietary algorithms when deployed externally.
A method and system that generates encrypted queries and placeholders using AI/ML models within a customer's secure network, ensuring data protection by executing these queries and placeholders within the customer's environment, utilizing a Zero Trust Orchestration framework to maintain data sovereignty and compliance.
Enables secure delivery of BI services with real-time analytics and AI-driven insights while keeping sensitive data within the customer's secure boundary, aligning with regulatory frameworks like GDPR and HIPAA, and protecting service provider intellectual property.
Smart Images

Figure IN2025051477_26032026_PF_FP_ABST
Abstract
Description
METHOD AND SYSTEM FOR DELIVERING RUNTIME BUSINESS INTELLIGENCE (BI) AND ENSURING DATA PROTECTIONCROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims the benefit of Indian Provisional Patent Application No. 202441071043 filed September 19, 2024, which is incorporated herein by reference for all purposes in its entirety.FIELD
[0002] This disclosure relates generally to Business Intelligence (BI), and more particularly to systems and methods for delivering business intelligence (BI) services, SaaS, and other Artificial Intelligence based services for data privacy protection. The disclosure further relates to a Zero Trust Orchestration (ZTO) framework for secure intelligence delivery, implemented in a model-agnostic manner across AI / ML technologies.BACKGROUND
[0003] In today's data-driven environment, businesses and organizations generate and manage vast amounts of data across various departments. The data is critical for decision-making, operational efficiency, and long-term strategy. Business Intelligence (BI) solutions have emerged to analyze and extract actionable insights from the data. Further, BI services offer advanced analytics, real-time dashboards, and data visualization to help businesses harness the power of the data.
[0004] However, the adoption of third-party BI services faces significant challenges due to data security concerns. Contemporary enterprises are obligated to adhere to data privacy laws like the General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), Service Organization Controls 2 (SOC2), and Information Security Management System (ISMS). These regulations impose constraints on the sharing of sensitive information with external organizations. The data privacy issues have forced companies to either invest in in-house analytics teams or require service providers to deploy their entire analytics infrastructure on-site, within the organization’s secure network. The conventional approach, while safeguarding data, introduces additional risks related to the protection of the service provider’s intellectual property (IP), especially when proprietary algorithms and tools are deployed within a customer's environment.
[0005] Conventional methods to address these challenges include data anonymization, federated learning, homomorphic encryption, and zero-knowledge proofs. These approaches aim to protect sensitive data while enabling external providers to deliver BI services. However, such techniques have inherent limitations, such as the risk of re-identification in pseudonymized data, the performance overhead associated with homomorphic encryption, and the complexity of implementation.
[0006] The conventional techniques fail to provide fully secure BI services. Accordingly, there is a need for improved methods and systems to deliver BI services that address the aforementioned limitations.
[0007] Further limitations and disadvantages of conventional and traditional approaches will become apparent to one of skill in the art through comparison of such systems with some aspects of the present disclosure as set forth in the remainder of the present application with reference to the drawings.SUMMARY OF THE INVENTION
[0008] In one aspect of the invention, a method for delivering runtime business intelligence (BI) services ensuring data protection is disclosed. In one example, the method includes receiving metadata associated with a plurality of data. The plurality of data is stored in a data warehouse(s) on a user device accessible only at customer’s secured network. The method further includes generating placeholders for visualizations based on the metadata. Further, the method includes generating encrypted queries based on the metadata via AI / ML (artificial intelligence / Machine Learning) models such as a Large Language Model (LLM). The encrypted queries are generated based on a request from the user device. The method further includes executing the encrypted queries and the placeholders on the data warehouse using a fetcher to deliver the BI services.
[0009] In an embodiment, the metadata received by the computing device is encrypted to ensure data safety.
[0010] In another embodiment, the encrypted queries and the placeholders includes a set of instructions to deliver the BI services.
[0011] In yet another embodiment, the method for generating placeholders for visualizations based on the metadata includes receiving a request from the user device. Further, the method includes preparing the placeholders for visualizations based on the metadata and the user request. The method further includes encrypting the placeholders using a key stored in the computing device.
[0012] In an embodiment, the method for generating the encrypted queries based on the metadata via the AI / ML model includes receiving a natural language query from the user device. The natural language query includes the set of instructions to visualize the BI services. The method further includes generating Structured Query Language (SQL) queries based on the metadata and the natural language query using the AI / ML model. Further, the method includes encrypting the SQL queries using a key stored in the computing device.
[0013] In another embodiment, the method for executing the encrypted queries and the placeholders on the data warehouse using the fetcher to deliver the BI services includes receiving the encrypted queries and the placeholders by the fetcher. Further, the method includes decrypting and executing, the encrypted queries and the placeholders on the data warehouse to fetch the relevant data based on the metadata. The method further includes rendering the visualization of the BI services on a User Interface (UI).
[0014] In a further embodiment, the method includes logging requests, instructions, and statuses for auditing to ensure compliances.
[0015] In another aspect of the invention, a system for delivering runtime business intelligence (BI) services ensuring data protection is disclosed. In one example, the system includes a processor and a computer-readable medium communicatively coupled to the processor. The computer-readable medium having stored thereon processor-executable instructions, which, when executed by a processor, cause the processor to receive metadata associated with a plurality of data, wherein the plurality of data is stored in a data warehouse on a user device. The processor-executable instructions, on execution, further cause the processor to generate placeholders for visualizations based on the metadata. The processor-executable instructions, on execution, further cause the processor to generate encrypted queries based on the metadata using an AI / ML model. The encrypted queries are generated based on a request from the user device. The processor-executable instructions, on execution, further cause the processor to execute the encrypted queries and the placeholders on the data warehouse using a fetcher to deliver the BI services.
[0016] In an embodiment, the processor instructions to generate placeholders for visualizations based on the metadata, on execution, further cause the processor to receive a request from the user. The processor-executable instructions, on execution, further cause the processor to prepare the placeholders for visualizations based on the metadata and the user request. The processor-executable instructions, on execution, further cause the processor to encrypt the placeholders using a key stored in the computing device.
[0017] In another embodiment, the processor instructions to generate the encrypted queries based on the metadata via the AI / ML model, on execution, cause the processor to receive a natural language query from the user device. The natural language query includes a user instruction to visualize the BI services. The processor-executable instructions, on execution, further cause the processor to generate Structured Query Language (SQL) queries based on the metadata and the natural language query using the AI / ML model. The processor-executable instructions, on execution, further cause the processor to encrypt the SQL queries using a key stored in the computing device.
[0018] In another embodiment, the processor instructions to execute the encrypted queries and the placeholders on the data warehouse using a fetcher to deliver the BI services, on execution, cause the processor to receive the encrypted queries and the placeholders. The processor-executable instructions, on execution, further cause the processor to decrypt and execute the encrypted queries and the placeholders on the data warehouse to fetch the relevant data. The processor-executable instructions, on execution, further cause the processor to render the visualization of the BI services on a User Interface (UI).
[0019] In some embodiments, the invention further implements a Zero Trust Orchestration (ZTO) framework in which orchestration instructions (including, for example, SQL queries, placeholders, and automation directives) are generated and cryptographically sealed in a control plane external to the customer environment, and executed exclusively within a secure execution plane inside the customer environment. This separation ensures data sovereignty and compliance by design, while still enabling secure intelligence delivery through model-agnostic AI / ML orchestration.
[0020] The disclosed method and system provide secure intelligence delivery by enabling real-time analytics, AI-driven insights, and automation to be executed entirely within the customer environment. The framework is model-agnostic, supporting diverse AI / ML paradigms including, without limitation, LLMs, SLMs, hybrid symbolic-neural models, reinforcement learning, federated and continual learning, multimodal architectures, autonomous or agentic AI systems capable of reasoning, planning, and execution with minimal human intervention, and self-improving AI frameworks.
[0021] In certain embodiments, domain-specific SLMs may be securely shipped into the customer environment under zero-trust conditions to enable low-latency, privacy-preserving analytics, ensuring that sensitive data never leaves the secure boundary and that customers are not required to trust external providers.
[0022] It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the invention, as claimed.
[0023] The method of the present invention includes further features and advantages which will be apparent from, or are set forth in more detail in, the accompanying drawings and the following detailed description, which together serve to explain certain principles of the invention.BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The foregoing summary, as well as the following detailed description of the invention, will be better understood when read in conjunction with the appended drawings. For the purpose of assisting in the explanation of the invention, there are shown in the drawings, embodiments that are presently preferred and considered illustrative. The use of the same reference numerals may indicate similar or identical items. Various embodiments may utilize elements and / or components other than those illustrated in the drawings, and some elements and / or components may not be present in different embodiments. It should be understood, however, that the invention is not limited to the precise arrangements and instrumentalities shown therein the drawings:
[0025] is a block diagram of an exemplary system for delivering runtime business intelligence (BI) services ensuring data protection, in accordance with some embodiments
[0026] illustrates a functional block diagram of an exemplary system for managing a data warehouse to deliver runtime BI services ensuring data protection, in accordance with some embodiments
[0027] illustrates a functional block diagram of an exemplary system for generating queries for delivering runtime BI services ensuring data protection, in accordance with some embodiments
[0028] illustrates a functional block diagram of an exemplary system for generating placeholders and delivering runtime BI services ensuring data protection, in accordance with some embodiments
[0029] illustrates a flow diagram of an exemplary process for delivering runtime BI services ensuring data protection, in accordance with some embodiments
[0030] illustrates a flow diagram of an exemplary process for generating placeholders for delivering runtime BI services ensuring data protection, in accordance with some embodiments
[0031] illustrates a flow diagram of an exemplary process for generating Structured Query Language (SQL) queries for delivering runtime BI services ensuring data protection, in accordance with some embodiments
[0032] illustrates a flow diagram of an exemplary process for executing the encrypted queries and the placeholders to deliver the runtime BI services ensuring data protection, in accordance with some embodiments
[0033] is a block diagram of an exemplary computer system for implementing embodiments consistent with the present disclosureREFERENCE NUMERALS:
[0034] 100 – System for delivering runtime BI services102 – Computing device104 – Processor106 – Computer-readable medium / memory108 – Display110 – User Interface (UI)112 – User device114 – Communication network200 – System for managing data warehouse202 – Browser204 – User206 – Application208 – Metadata discoverer210 – Data warehouse212 – Application Programming Interface (API)214 – Metadata warehouse / metadata database216 – Vault (decentralized, blockchain-based)218 – Fetcher220 – Agent300 – System for generating queries302 – AI / ML model (LLM, SLM, etc.)400 – System for generating placeholders402 – Reports engine500 – Method for delivering runtime BI services502 – Step: receiving metadata504 – Step: generating placeholders506 – Step: generating encrypted queries508 – Step: executing queries / placeholders600 – Process for generating placeholders602 – Step: receiving user request604 – Step: preparing placeholders606 – Step: encrypting placeholders700 – Process for generating SQL queries702 – Step: receiving natural language query704 – Step: generating SQL queries706 – Step: encrypting SQL queries800 – Process for executing encrypted queries / placeholders802 – Step: receiving encrypted queries / placeholders804 – Step: decrypting and executing queries / placeholders806 – Step: rendering visualization900 – Computing system (general-purpose)902 – Processor (computing system)904 – Bus906 – Memory (RAM / volatile)908 – Storage devices910 – Media drive912 – Storage media914 – Removable storage unit916 – Interface for removable storage918 – Communications interface920 – Communication channel922 – Input / Output devicesDETAILED DESCRIPTION
[0035] Exemplary embodiments are illustrated with reference to the accompanying drawings. For consistency, identical reference numerals are used throughout the drawings to denote the same or similar components. Although specific examples and features of the disclosed principles are described, it should be understood that modifications, adaptations, and alternative implementations are possible without deviating from the spirit and scope of the disclosed embodiments. The following detailed description is intended to be exemplary in nature, with the true scope and spirit of the invention being defined by the appended claims.
[0036] As used herein, the term AI / ML model refers broadly to machine learning and artificial intelligence models, including but not limited to Large Language Models (LLMs), Small Language Models (SLMs), and other evolving architectures.
[0037] Referring now to, an exemplary system 100 for delivering runtime business intelligence (BI) services ensuring data protection is illustrated, in accordance with some embodiments. The system 100 may implement a computing device 102 (for example, server, desktop, laptop, notebook, netbook, tablet, smartphone, mobile phone, or any other computing device), in accordance with some embodiments of the present disclosure. The computing device 102 may deliver runtime BI services ensuring data protection to a user without accessing any sensitive data.
[0038] As will be described in greater detail in conjunction with FIGS. 2-8, the computing device 102 receives metadata associated with a plurality of data. The plurality of data is stored in a data warehouse on a user device 112 accessible at customer’s secured network. The computing device 102 further generates placeholders for visualizations based on the metadata. To generate placeholders for visualizations based on the metadata, the computing device 102 receives a request from the user device. Further, the computing device 102 prepares the placeholders for visualizations based on the metadata and the user request. The computing device 102 further encrypts the placeholders using a key. The computing device 102 further generates encrypted queries based on the metadata via an AI / ML model such as an LLM. The encrypted queries are generated based on a request from the user device 112. To generate the encrypted queries based on the metadata via the AI / ML model, the computing device 102 receives a natural language query from the user device 112. The natural language query includes a set of instructions to visualize BI services. The computing device 102 further generates Structured Query Language (SQL) queries based on the metadata and the natural language query using the AI / ML model. Further, the computing device 102 encrypts the SQL queries using the key. The computing device 102 further executes the encrypted queries and the placeholders on the data warehouse using a fetcher to deliver the BI services. To execute the encrypted queries and the placeholders on the data warehouse using the fetcher to deliver the BI services, the computing device 102 receives the encrypted queries and the placeholders by the fetcher. Further, the computing device 102 decrypts and executes the encrypted queries and the placeholders on the data warehouse to fetch the relevant data based on the metadata. The computing device 102 further renders the visualization of the BI services on a User Interface (UI).
[0039] In some embodiments, the computing device 102 may include one or more processors 104 and a computer-readable medium 106 (for example, a memory). The computer-readable medium 106 may include the database. Further, the computer-readable storage medium 106 may store instructions that, when executed by the one or more processors 104, cause the one or more processors 104 to deliver runtime BI services ensuring data protection, in accordance with aspects of the present disclosure. The computer-readable storage medium 106 may also store various data (for example, user instructions, user requests, the plurality of metadata, source code, encryption key, a decryption key, and the like) that may be captured, processed, and / or required by the system 100.
[0040] The system 100 may further include a display 108. The system 100 may interact with a user via a user interface 110 accessible via the display 108. The system 100 may also include one or more user devices 112. In some embodiments, the computing device 102 may interact with the one or more user devices 112 over a communication network 114 for sending or receiving various data. The user devices 112 may include, but may not be limited to, a remote server, a digital device, or another computing system.
[0041] Referring now to, a functional block diagram of an exemplary system 200 for managing data warehouse to deliver runtime BI services ensuring data protection is illustrated, in accordance with some embodiments. In an embodiment, the system 200 is analogous to the system 100. The system 200 includes a computing device analogous to the computing device 102, a user device analogous to the user device 112, and a browser 202. Further, the computing device 102 may include an application 206, an Application Programming Interface (API) 212, a metadata warehouse 214, and a vault 216. The user device 112 may include a Metadata discoverer 208, a data warehouse 210, a fetcher 218, and an agent 220.
[0042] In an embodiment, the browser 202 may be configured to access the computing system 102 by a user 204. The browser 202 may require login details associated with the user 204 to access the computing device 102. Further, the browser 202 may transmit configuration information to an application 206 installed on the computing device 102. The application 206 may be an interface to interact with the browser 202 and the user device 112. In another embodiment, if the user 204 is logged in to the user device 112, the application 206 may receive the configuration information via the metadata discoverer 208. The configuration information may include metadata of a plurality of data stored in a data warehouse 210, an encryption and decryption key, login credentials, etc. The metadata discoverer 208 may Identify and pre-process the metadata within the user device 112 and transfer it to the computing device 102, upon verification by the user 204.
[0043] Further, the data warehouse 210 may be a centralized repository that stores structured or unstructured plurality of data from various sources within an organization. In an exemplary embodiment, the data warehouse may be a single database or a complex federated environment involving multiple databases spanning different technologies like MySQL, Postgres, Casandra, Big Query, File Stores, HDFS, Amazon S3, etc. The plurality of data may be sensitive data of the customers of a business or organization such as date of birth, names, location, demographics, marital status etc.
[0044] Upon receiving the configuration information, the application 206 stores the metadata into the metadata database 214 and the encryption and decryption keys, and login credentials into the vault 216, via the API 212. The vault 216 may be a de-centralized blockchain-based vault to ensure the safety of the sensitive information. The API 212 may be, but is not limited to, a Metadata Management API, a BI Services Interaction API, Security and Encryption API, etc. Further, the vault 216 may encrypt the metadata using the encryption key and transmit the encrypted metadata and the decryption key to the application 206 via the API 212. Further, the application 206 may generate provisioning, maintenance, and ETL instructions based on the encrypted metadata.
[0045] Upon generating a set of instructions and receiving a user request from the user device 112, the application 206 transmits the encrypted metadata, the decryption key, and the set of instructions to the agent 220 of the user device 112 via the API 212. In an embodiment, the agent 220 is configured to collect transmitted configuration information and run-time instructions from the computing device 102 through the one-way communication link and execute them on the user device 112. The agent 220 may be implemented in various ways such as, a Queueing method, a Publisher Subscriber model, a real-time listener, and a Proxy service, etc.
[0046] Upon receiving the configuration information and run-time instructions, the agent 220 may transmit feedback to the computing device 102 corresponding to a completion status or an error code respecting data privacy rule. In an embodiment, the agent 220 may cause the fetcher 218 to execute the runtime instructions based on the encrypted metadata on the data warehouse 210 to deliver BI services as explained in detail in FIGs. 3 and 4.
[0047] By way of an example, Gus is working as a business analyst for an organisation. He is assigned a task to analyse the demographics of the existing customers in order to prepare for expansion of the organization. Gus configures metadata corresponding to the demographics of the customers of the data warehouse into the computing device along with the needed credentials and secrets for the fetcher access. Alternatively, Gus may use the metadata discoverer service to automatically read and preprocess metadata from the data warehouse. The metadata is then verified and transferred to the computing device along with the needed credentials and secrets for the fetcher access.
[0048] Further, the application stores the metadata on the metadata database using the API, and the credentials and secrets on the vault using a crypto service. The application further generates provisioning, maintenance, and ETL instructions using the metadata from the data warehouse and encodes them using the keys from the vault and the crypto services. The encrypted instructions are transmitted to the agent for processing. The only feedback that is received by Gus is the completion status or an error code, if any, thereby respecting data privacy rules.
[0049] Referring now to, an exemplary system 300 for generating queries and placeholders for delivering runtime BI services ensuring data protection is illustrated, in accordance with an embodiment. In an embodiment, the system 300 is analogous to the system 100. In addition to the system 200, the system 300 may include an AI / ML model 302 to generate queries based on the metadata and the user request. Upon receiving the encrypted metadata, configuration information and run-time instructions, the user 204 may send a natural language query to the application 206 via the browser 202. The natural language query may be a readable query, such as in English, Hindi, French, etc., corresponding to the BI service.
[0050] In an embodiment, the AI / ML model 302 may fetch the required metadata associated with the natural language query via the API 212. The AI / ML model 302 may be configured to generate a Structured Query language (SQL) queries based on the natural language query. The AI / ML model 302 may serve as an advanced query processing component within the system 100. The AI / ML model 302 allows users to input natural language queries (e.g., plain English questions) and converts the queries into structured SQL queries. The AI / ML model 302 uses the schema metadata from the data warehouse to understand the structure of the data and generate accurate queries. In an exemplary embodiment, the AI / ML model 302 may be a locally installed AI / ML model, or external services such as OpenAI, webserver, etc.
[0051] In some embodiments, the AI / ML model 302 may generate the placeholders such as types of charts, color-combination, etc. The placeholders may be used as templates to fill the required data from the data warehouse for delivering BI services. Further, the AI / ML model 302 encodes the queries and placeholders using the encryption key from the vault 216. It should be noted that the encryption is essential to transmit sensitive information to protect the information from data breaches and to enhance the security of the information.
[0052] Further, the encrypted response is transmitted to the browser 202 of the user device 112 via the API 212. The browser 202 is an Interface used by end-users 204 to interact with BI services. The encrypted response may include the visualization placeholders and the SQL queries with required access controls of the user device 112. Further, the Browser 202 may transmit the encrypted response to the fetcher 218 for execution and delivering BI services as explained in detail in.
[0053] By way of an example, Gus sends a natural language query in English through the Browser in the computing device. Upon receiving the natural language query, the computing device fetches the metadata associated with the natural language query and provides it to the AI / ML model. Further, the AI / ML model generates SQL queries with placeholders based on the metadata. The generated SQL queries with placeholders are then encrypted using the key in the vault and the crypto service. Further, the encrypted response is transmitted to the browser via the API. Further, the fetcher may be called to decrypt the response received on the browser. The fetcher executes the SQL query on the Data Warehouse and retrieves the data. Further, the rendering instructions with the data are transmitted back to the browser. Finally, the browser formats the final response or graph for Gus and renders the BI services via the UI.
[0054] Referring now to, an exemplary system 400 for generating placeholders and delivering runtime BI services ensuring data protection is illustrated, in accordance with an embodiment. In an embodiment, the system 400 is analogous to the system 100. In addition to the system 200 and 300, the system 400 may include a reports engine 402 to generate visual placeholders based on the metadata and the user request. The reports engine 402 may be responsible for generating, managing, and delivering reports metadata and queries based on metadata stored in a metadata database or other data repositories. Further, the reports engine 402 serves as the backend process that takes user requests and produces structured, formatted report placeholders that are be rendered on the browser 202 after the data is retrieved from the user device 112.
[0055] In an embodiment, the user 204 may send a user request to the computing device 102 via the browser 202. The user request may correspond to an instruction to deliver a BI service such as, to generate a demographics report of the customers, or to generate a report of the customers who recently bought from the organization, etc. Further, the reports engine 402 fetches the metadata corresponding to the user request from the metadata database 214. By way of an example, if the user request corresponds to generating a demographics report, then the reports engine 402 only fetches the metadata of the demographics of the customers from the metadata database 214. Further, the reports engine 402 generate visual placeholders in conjunction with the AI / ML model 302 based on the queries and the metadata, and the user request. In some embodiments, the reports engine 402 may work complementary with the AI / ML model 302 to generate SQL Queries and the placeholders based on the user request.
[0056] In an embodiment, the reports engine 402 may encrypt the visual placeholders using the key from the vault 216. Further, the computing device 102 transmits the encrypted visual placeholders along with the decryption key to the browser 202 via the application 206. The browser 202 further sends the encrypted visual placeholder to the fetcher 218. The fetcher 218 may decrypt the visual placeholders using the decryption key. In an embodiment, the fetcher may also decrypt the Queries from the AI / ML model 302 along with the visual placeholders. The encrypted queries and the placeholders include a set of instructions to deliver the BI services. Further, the fetcher 218 executes the Queries and the placeholders on the data warehouse 210. The fetcher 218 may fetch the data corresponding to the metadata from the data warehouse 210 and fill the visual placeholders according to the queries to generate the interactive BI services. The executed placeholders are then transmitted to the browser 202 to render the BI service to the user 204 via the UI 110. It should be noted that the user device 112 logs all the user requests, instructions, and statuses for auditing to ensure compliance.
[0057] By way of an example, Gus requests a demographic report through the browser on the user device. Gus’s requests include a demographic report in a bar chart format. In response to Gus’s request, the reports engine fetches the metadata associated with the demographics of the customers from the metadata database. Further, the reports engine processes Gus’s request and prepares the bar chart placeholders for the demographics report. Further, the placeholder and SQL queries with required access controls is encrypted and transmitted to the browser of the user device. Further, the fetcher decrypts the visual placeholders received on the browser and executes the SQL query on the Data Warehouse. The fetcher fetches the demographics data from the data warehouse and fills the visual placeholder with the relevant data. Further, the fetcher returns the visual placeholder along with the relevant data to the browser. The browser then formats the visual placeholder to generate the BI service, according to the user device specifications and renders the BI service to the UI.
[0058] It is to be understood that the aforementioned modules 202–210, 302, and 402 may be represented as a single module or as a combination of multiple modules. Furthermore, as will be recognized by those skilled in the art, each of the modules 202–210, 302, and 402 may be located entirely on a single device or distributed across multiple devices in communication with one another. In certain embodiments, the modules 202–210, 302, and 402 may be implemented as dedicated hardware circuits, such as custom application-specific integrated circuits (ASICs), gate arrays, or other discrete components, including off-the-shelf semiconductors like logic chips or transistors. Alternatively, the modules 202–210, 302, and 402 may be implemented in programmable hardware devices, such as field-programmable gate arrays (FPGAs), programmable array logic, or programmable logic devices. In other embodiments, these modules may be implemented in software executable by various types of processors (e.g., processor 104). A given module of executable code may consist of one or more physical or logical blocks of computer instructions, which may be structured as an object, procedure, function, or other software construct. However, the executable instructions for a particular module do not need to be physically co-located; they may comprise separate instructions stored in different locations that, when logically connected, constitute the module and fulfil its intended function. Indeed, a module may consist of a single instruction or multiple instructions, potentially distributed across various code segments, applications, and memory devices.
[0059] As will be understood by those skilled in the art, various methods may be employed to provide runtime Business Intelligence (BI) services ensuring data protection. For instance, the exemplary system 100 and its associated computing device 102 may facilitate the delivery of runtime BI services ensuring data protection using the processes described herein. Specifically, control logic and / or automated routines for executing the techniques and steps outlined may be implemented in system 100 and computing device 102 through hardware, software, or a combination of both. For example, appropriate code may be accessed and executed by one or more processors of system 100 to carry out some or all of the described techniques. Additionally, application-specific integrated circuits (ASICs) designed to execute some or all of the processes described herein may be incorporated within the one or more processors of system 100.
[0060] Referring now to, an exemplary process 500 for delivering runtime BI services ensuring data protection is depicted via a flowchart, in accordance with some embodiments. In an embodiment, the process 500 may be implemented by the computing device 102 of the system 100. The process 500 includes receiving metadata associated with a plurality of data, at step 502. The plurality of data is stored in a data warehouse 210 on the user device 112. The plurality of data may include but is not limited to, customer data, customer demographics, previous orders of the customer, age of the customers, marital status of the customer, and other sensitive data of the customers. The user device 112 may transmit the metadata to the computing device 102, instead of the plurality of data in order to protect the integrity of the data.
[0061] Further, the process 500 includes generating placeholders for visualizations based on the metadata, at step 504. The placeholders may include format, style, colour combinations, etc., for generating BI services reports. In simple words, the placeholders are skeletons or templates of the BI services, which may be filled with appropriate data to generate interactive reports for the user 204.
[0062] Further, the process 500 includes generating encrypted queries based on the metadata via an AI / ML model 302, at step 506. The encrypted queries are generated based on a request from the user device 112. In an embodiment, the encrypted queries may be Structured Query Language (SQL) queries generated by the AI / ML model 302 based on the user request. It should be noted that the queries are encrypted to ensure the security of the data. The user request may be a natural language request that is interpreted by the AI / ML model 302. The AI / ML model 302 may be, but not limited to, a translation model, a classification model, a GPT model, a generative AI model, a BERT model, a PaLM model, a federated learning model, etc.
[0063] Further, the process 500 includes executing the encrypted queries and the placeholders on the data warehouse 210 using the fetcher 218 to deliver the BI services, at step 508. The encrypted queries are decrypted using a key stored in the vault engine 216 of the computing device 102. It should be noted that the execution process is implemented on the user device 112 to ensure data safety. Further, the fetcher 218 may be an async function that accepts a key and returns data. For example, a stale-while-revalidate (SWR) fetcher may be used with libraries like Unfetch, Axios, or GraphQL-request. Further, the encrypted queries and the placeholders fetch data from the data warehouse 210 and fill the placeholders with relevant data based on the queries to generate interactive reports of the BI services. Further, the BI service may be rendered on the UI 110 of the user device 112.
[0064] In some embodiments, the invention implements a Zero Trust Orchestration (ZTO) framework that enforces a clear separation between a control plane and an execution plane. The control plane is positioned external to the customer’s secure environment, typically operating in a trusted orchestration service or provider-managed domain. Its sole responsibility is to generate orchestration instructions—such as structured database queries, parameterized placeholders, workflow automation directives, or AI / ML model invocation steps—and then encrypt those instructions before transmission. By design, the control plane does not access, process, or store any raw data from the customer environment, thereby maintaining a strict zero-trust boundary.
[0065] The execution plane, on the other hand, is deployed entirely within the customer’s secure perimeter, whether on-premises, within a private cloud, or inside a sovereign data center. This execution plane is equipped to receive the encrypted orchestration instructions, decrypt them locally using customer-controlled keys, and execute the operations against internal datasets, compute resources, or model runtimes. All raw data, intermediate processing states, and model artifacts remain confined within the execution environment, ensuring that no sensitive information leaves the customer’s domain at any stage of orchestration.
[0066] By decoupling orchestration from execution, the ZTO framework achieves several critical technical benefits. It guarantees data sovereignty and compliance by design, since the data is never transmitted outside the trusted boundary, and ensures compliance with regulatory frameworks such as GDPR, HIPAA, or jurisdiction-specific data governance laws. It enforces confidentiality by preventing orchestration providers from gaining visibility into customer datasets, thereby reducing insider and third-party risk. Moreover, because orchestration instructions are expressed as abstract, encrypted directives, the framework remains model-agnostic, capable of driving diverse AI / ML systems and analytics pipelines without exposing their internal mechanics.
[0067] The ZTO framework further aligns with the principles of Zero Trust security, wherein no external system is implicitly trusted. All communications between planes are cryptographically secured, and only the customer-controlled execution plane possesses the keys required for decryption and execution. This architecture allows customers to benefit from external orchestration intelligence such as optimization strategies, adaptive scheduling, or federated learning coordination without compromising on compliance, governance, or security posture.
[0068] Referring now to, an exemplary process 600 for generating placeholders for delivering runtime BI services ensuring data protection is depicted via a flow chart, in accordance with some embodiments. In an embodiment, the process 600 may be implemented by the computing device 102 of the system 100. The process 600 includes receiving a request from the user device 112, at step 602. The user request may include a set of instructions to generate the placeholders for the BI services. It should be noted that the user may choose from a plurality of templates, colours, and other settings for the placeholders via the user device 112.
[0069] Further, the process 600 includes preparing the placeholders for visualizations based on the metadata and the user request, at step 604. The placeholders may be chosen by either the user 204 or prepared automatically by the report engine 302 in conjunction with the AI / ML model 402 based on the metadata and the user request.
[0070] Further, the process 600 includes encrypting the placeholders using a key stored in the computing device 102, at step 606. The placeholders may be encrypted to safeguard the data from potential third-party transmission leaks. The encrypted placeholders are then transmitted to the user device 112 for decryption and execution.
[0071] Referring now to, an exemplary process 700 for generating Structured Query Language (SQL) queries for delivering runtime BI services ensuring data protection is depicted via a flow chart, in accordance with some embodiments. In an embodiment, the process 700 may be implemented by the AI / ML model 402 of the computing device 102. The process 700 includes receiving a natural language query from the user device 112, at step 702. The natural language query includes the set of instructions to visualize the BI services. The natural language query may include the set of instructions in English or any other language that the user 204 may understand.
[0072] Further, the process 700 includes generating Structured Query Language (SQL) queries based on the metadata and the natural language query using the AI / ML model 402, at step 704. The AI / ML model 402 may interpret the natural language query to generate the corresponding SQL queries. Further, the natural language query may include instructions to generate the BI services, such as type of data used, amount of data used, type of reports such as, bar graph, chart, etc.
[0073] Further, the process 700 includes encrypting the SQL queries using a key stored in the computing device 102, at step 706. The computing device 102 may transmit the encrypted queries and the key to the fetcher 218 of the user device 112. The fetcher 218 may decrypt the SQL queries using the key and the metadata on the data warehouse 210 as explained in detail in.
[0074] Referring now to, an exemplary process 800 for executing the encrypted queries and the placeholders to deliver the runtime BI services ensuring data protection is depicted via a flow chart, in accordance with some embodiments. In an embodiment, the process 800 may be implemented by the user device 112 of the system 100. The process 800 may include receiving the encrypted queries and the placeholders by the fetcher 218, at step 802.
[0075] Further, the process 800 includes decrypting and executing, the encrypted queries and the placeholders on the data warehouse 210 to fetch the relevant data based on the metadata, at step 804. The fetcher 218 may decrypt the encrypted queries into a readable format based on the key and the metadata. Further, the fetcher 210 may fetch the data relevant to the metadata from the data warehouse 210 to fill the placeholder based on the SQL queries.
[0076] Further, the process 800 includes rendering the visualization of the BI services on a User Interface (UI) 110, at step 806. The UI 110 may be an analogue UI or digital UI configured to display the reports of the BI services to the user 204. In some embodiments, the UI 110 may be embedded in the user device 112 to render the BI services and input user requests and instructions.
[0077] The disclosed framework is adaptable to a wide range of AI / ML technologies and is not limited to Large Language Models. Without limitation, the AI / ML model may comprise an LLM, an SLM, an agent-based system, a hybrid symbolic-neural system, a reinforcement learning system, a federated learning system, a continual learning system, or a multimodal system integrating text, vision, audio, or other sensory data, an autonomous or agentic AI system capable of reasoning, planning, and execution with minimal human intervention, or a self-improving AI framework. In some embodiments, domain-specific SLMs may be shipped and deployed inside the customer environment to support secure, low-latency analytics under zero-trust conditions. This architecture enables secure intelligence delivery by ensuring that real-time analytics, AI-driven insights, and automation are executed entirely within the customer environment, so that sensitive data never leaves the secure boundary and customers are not required to trust external providers.
[0078] It will be appreciated by those skilled in the art that the techniques described above may be implemented as computer- or controller-executed processes and corresponding apparatuses. The disclosure can also be embodied in the form of computer program code comprising instructions stored on tangible media, such as floppy diskettes, solid-state drives, CD-ROMs, hard drives, or any other computer-readable storage medium. When this computer program code is loaded into and executed by a computer or controller, the device becomes an apparatus for practicing the invention. The disclosure may also be embodied as computer program code in the form of signals, which may be stored in a storage medium, executed by a computer or controller, or transmitted over a transmission medium such as electrical wiring, fiber optics, or electromagnetic radiation. Once the computer program code is loaded and executed, the computer functions as an apparatus for practicing the invention. When implemented on a general-purpose microprocessor, the computer program code segments configure the processor to create specific logic circuits.
[0079] The disclosed methods and systems may be executed on a conventional or general-purpose computing system, such as a personal computer (PC) or server. Referring to, an exemplary computing system 900 is illustrated, which may implement processing functionality for various embodiments (e.g., as a SIMD device, client device, server device, or one or more processors). Those skilled in the art will recognize that other computing systems or architectures may also be used to implement the invention. The computing system 900 may represent a user device, such as a desktop, laptop, mobile phone, personal entertainment device, DVR, or any other special or general-purpose computing device appropriate for a given application or environment. The computing system 900 may include one or more processors, such as processor 902, implemented using a general-purpose or specialized processing engine, such as a microprocessor, microcontroller, or other control logic. In some embodiments, processor 902 may be an AI processor, implemented as a Tensor Processing Unit (TPU), graphical processing unit (GPU), or custom-programmable solution, such as a Field-Programmable Gate Array (FPGA).
[0080] The computing system 900 may further include memory 906 (e.g., Random Access Memory (RAM) or other dynamic memory) for storing instructions and information to be executed by processor 902. Memory 906 may also store temporary variables or intermediate information during execution. Additionally, the computing system 900 may include a read-only memory (ROM) or other static storage device connected to bus 904 for storing static information and instructions for processor 902.
[0081] Storage devices 908 may also be included in computing system 900, consisting of, for example, a media drive 910 and a removable storage interface. Media drive 910 may support fixed or removable storage media, such as hard disk drives, floppy drives, magnetic tape drives, SD card ports, USB ports, optical disk drives (e.g., CD or DVD drives), or other media. Storage media 912 may include hard disks, magnetic tapes, flash drives, or other media that can be read and written to by media drive 910. Storage media 912 may store computer-readable software or data.
[0082] Alternatively, storage devices 908 may include other means for loading computer programs or data into computing system 900, such as removable storage unit 914 and interface 916, program cartridges, removable memory (e.g., flash memory), memory slots, and similar storage units and interfaces.
[0083] Computing system 900 may also include a communications interface 918 to transfer software and data between user devices 112 and system 900. Examples include network interfaces (e.g., Ethernet), communication ports (e.g., USB, micro-USB), Near Field Communication (NFC), and other protocols. The signals transferred via communications interface 918 may include electronic, electromagnetic, optical, or other forms of transmission through channel 920, which may utilize wireless mediums, fibre optics, wires, or cables.
[0084] Computing system 900 may also include Input / Output (I / O) devices 922, such as a display, keypad, microphone, speakers, vibration motors, LED indicators, etc., allowing user interaction and feedback. The term "computer-readable medium" may refer to any storage medium used, such as memory 906, storage devices 908, removable storage unit 914, or signal(s) on channel 920. Such media may store sequences of instructions, or "computer program code," which, when executed, enable computing system 900 to perform the methods and functions described in embodiments of the invention.
[0085] In embodiments where elements are implemented in software, the software may be stored on a computer-readable medium and loaded into computing system 900 via removable storage unit 914, media drive 910, or communications interface 918. When executed by processor 902, this control logic (e.g., software instructions or computer program code) causes processor 902 to perform the invention's functions as described.
[0086] Thus, the disclosed method and system try to overcome the technical problem of delivering runtime Business Intelligence (BI) services ensuring data protection. The method and system provide means to provide robust data security by ensuring that sensitive business data remains within the customer's secure environment, never being exposed to third-party service providers. Further, the method and system provide intellectual property (IP) protection for service providers by allowing them to deliver advanced analytics services without deploying their proprietary tools or algorithms on the customer’s network, thereby safeguarding their IP. The method and system further provide the capability of delivering runtime Business Intelligence services as a Software as a Service (SaaS), ensuring data privacy as the data processing happen on the customer’s device / servers. Further, the method and system provide comprehensive analytics capabilities, supporting advanced BI functionalities such as interactive dashboards, real-time analytics, and natural language querying through AI / ML models, all while maintaining data security. The method and system further provide scalability, allowing organizations of different sizes and across various industries to leverage the benefits of advanced analytics without significant investments in additional infrastructure. The method and system provide user-friendly interaction, enabling non-technical users to generate meaningful insights from data through intuitive natural language queries, lowering the barrier to data-driven decision-making. Additionally, the method and system provide enhanced control and transparency for customers and ensures that data privacy and compliance requirements are adhered to. The method and system further provide flexibility in supporting various data storage architectures, including federated environments involving multiple databases and cloud-based data storage solutions, without compromising data security or performance.
[0087] As will be appreciated by those skilled in the art, the techniques described in the various embodiments discussed above are not routine, conventional, or well-understood in the art. The techniques discussed above provide for delivering runtime business intelligence (BI) services ensuring data protection. The techniques first receive metadata associated with a plurality of data. The plurality of data is stored in a data warehouse on a user device. The techniques then generate encrypted queries based on the metadata via an AI / ML model. The encrypted queries are generated based on a request from the user device. The techniques then execute the encrypted queries and the placeholders on the data warehouse using a fetcher to deliver the BI services.
[0088] In light of the above-mentioned advantages and the technical advancements provided by the disclosed method and system, the claimed steps as discussed above are not routine, conventional, or well understood in the art, as the claimed steps enable the following solutions to the existing problems in conventional technologies. Further, the claimed steps clearly bring an improvement in the functioning of the device itself as the claimed steps provide a technical solution to a technical problem.
[0089] The specification has described the method and system for delivering runtime BI services ensuring data protection. The illustrated steps are set out to explain the exemplary embodiments shown, and it should be anticipated that ongoing technological development will change the manner in which particular functions are performed. These examples are presented herein for purposes of illustration, and not limitation. Further, the boundaries of the functional building blocks have been arbitrarily defined herein for the convenience of the description. Alternative boundaries can be defined so long as the specified functions and relationships thereof are appropriately performed. Alternatives (including equivalents, extensions, variations, deviations, etc., of those described herein) will be apparent to persons skilled in the relevant art(s) based on the teachings contained herein. Such alternatives fall within the scope and spirit of the disclosed embodiments.
[0090] Furthermore, one or more computer-readable storage media may be utilized in implementing embodiments consistent with the present disclosure. A computer-readable storage medium refers to any type of physical memory on which information or data readable by a processor may be stored. Thus, a computer-readable storage medium may store instructions for execution by one or more processors, including instructions for causing the processor(s) to perform steps or stages consistent with the embodiments described herein. The term “computer-readable medium” should be understood to include tangible items and exclude carrier waves and transient signals, i.e., be non-transitory. Examples include random access memory (RAM), read-only memory (ROM), volatile memory, nonvolatile memory, hard drives, CD ROMs, DVDs, flash drives, disks, and any other known physical storage media.
[0091] The foregoing description of the specific embodiments so fully reveals the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the spirit and scope of the embodiments as described herein.
[0092] Throughout this specification the word “comprise”, or variations such as “comprises” or “comprising”, will be understood to imply the inclusion of a stated element, integer or step, or group of elements, integers or steps, but not the exclusion of any other element, integer or step, or group of elements, integers or steps.
[0093] The use of the expression “at least” or “at least one” suggests the use of one or more elements or ingredients or quantities, as the use may be in the embodiment of the disclosure to achieve one or more of the desired objects or results.
[0094] Any discussion of documents, acts, materials, devices, articles or the like that has been included in this specification is solely for the purpose of providing a context for the disclosure. It is not to be taken as an admission that any or all of these matters form a part of the prior art base or were common general knowledge in the field relevant to the disclosure as it existed anywhere before the priority date of this application.
[0095] The numerical values mentioned for the various physical parameters, dimensions or quantities are only approximations and it is envisaged that the values higher / lower than the numerical values assigned to the parameters, dimensions or quantities fall within the scope of the disclosure, unless there is a statement in the specification specific to the contrary.
[0096] While considerable emphasis has been placed herein on the components and component parts of the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiment as well as other embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be interpreted merely as illustrative of the disclosure and not as a limitation.
Claims
A method (500) for delivering runtime business intelligence (BI) services, the method (500) comprising:receiving (502), by a computing device (102), metadata associated with a plurality of data, wherein the plurality of data is stored in a data warehouse (210) on a user device (112);generating (504), by the computing device (102), placeholders for visualizations based on the metadata;generating (506), by the computing device (102), encrypted queries based on the metadata via an AI / ML model (302), wherein the encrypted queries are generated based on a request from the user device (112); andexecuting (508), by the computing device (102), the encrypted queries and the placeholders on the data warehouse (210) using a fetcher (218) to deliver the BI services, wherein the execution occurs under a Zero Trust Orchestration (ZTO) framework configured to enforce separation of a control plane and an execution plane, the control plane being adapted to generate and encrypt orchestration instructions including queries, placeholders, and automation directives, and the execution plane being adapted to decrypt and execute the orchestration instructions exclusively within a customer secure environment, thereby preventing exposure of raw data and intermediate results outside the customer secure environment.The method (500) as claimed in claim 1, wherein the metadata received by the computing device (102) is encrypted to ensure data safety.The method (500) as claimed in claim 1, wherein the encrypted queries and the placeholders comprises a set of instructions to deliver the BI services.The method of claim 1, wherein sensitive data never leaves the customer secure environment, thereby ensuring compliance with data protection and sovereignty requirements.The method (500) as claimed in claim 1, wherein generating placeholders for visualizations based on the metadata comprises:receiving a request from the user device (112);preparing the placeholders for visualizations based on the metadata and the user request; andencrypting the placeholders using a key stored in the computing device (102).The method (500) as claimed in claim 1, wherein generating the encrypted queries based on the metadata via the AI / ML model (302) comprises:receiving a natural language query from the user device (112), wherein the natural language query comprises the set of instructions to visualize the BI services;generating Structured Query Language (SQL) queries based on the metadata and the natural language query using the AI / ML (302); andencrypting the SQL queries using the key stored in the computing device (102).The method of claim 6, wherein the AI / ML model is model-agnostic and comprises at least one of a Large Language Model (LLM), a Small Language Model (SLM) deployed inside the customer environment, an agent-based model, a hybrid symbolic-neural model, a reinforcement learning model, a federated learning model, a continual learning model, a multimodal model integrating text, vision, audio, and other sensory data.The method (500) as claimed in claim 1, wherein executing the encrypted queries and the placeholders on the data warehouse (210) using the fetcher (218) to deliver the BI services comprises:receiving, by the fetcher (218), the encrypted queries and the placeholders;decrypting and executing, the encrypted queries and the placeholders on the data warehouse (210) to fetch the relevant data based on the metadata; andrendering the visualization of the BI services on a User Interface (UI) (110).The method (500) as claimed in claim 1, further comprising logging requests, instructions, and statuses for auditing to ensure compliances.A system (100) for delivering runtime business intelligence (BI) service, the system (100) comprising:a processor (104); anda memory communicatively coupled to the processor (104), wherein the memory stores processor instructions, which when executed by the processor (104), cause the processor (104) to:receive metadata associated with a plurality of data, wherein the plurality of data is stored in a data warehouse (210) on a user device (112);generate placeholders for visualizations based on the metadata;generate encrypted queries based on the metadata via an AI / ML model (302), wherein the encrypted queries are generated based on a request from the user device (112); andexecute the encrypted queries and the placeholders on the data warehouse (210) using a fetcher (218) to deliver the BI services, wherein the system implements a Zero Trust Orchestration (ZTO) framework comprising a control plane and an execution plane, the control plane being configured to generate and encrypt orchestration instructions including queries, placeholders, and automation directives, and the execution plane being configured to decrypt and execute the orchestration instructions exclusively within a customer secure environment, thereby preventing exposure of raw data and intermediate results outside the customer secure environment and enabling secure intelligence delivery with inherent data sovereignty and compliance by design.The system (100) as claimed in claim 10, wherein to generate placeholders for visualizations based on the metadata, the processor instructions, on execution, cause the processor (104) to:receive a request from the user device (112);prepare the placeholders for visualizations based on the metadata and the user request; andencrypt the placeholders using a key stored in the computing device (102).The system (100) as claimed in claim 10, wherein to generate the encrypted queries based on the metadata via the AI / ML (302), the processor instructions, on execution, cause the processor (104) to:receive a natural language query from the user device (112), wherein the natural language query comprises a user instruction to visualize the BI services;generate Structured Query Language (SQL) queries based on the metadata and the natural language query using the AI / ML; andencrypt the SQL queries using the key stored in the computing device (102).The system of claim 12, wherein the orchestration supports shipping of domain-specific Small Language Models (SLMs) into the customer environment for secure, low-latency analytics under zero-trust conditions.The system (100) as claimed in claim 10, wherein to execute the encrypted queries and the placeholders on the data warehouse (210) using a fetcher (218) to deliver the BI services, the processor instructions, on execution, cause the processor (104) to:receive the encrypted queries and the placeholders;decrypt and execute the encrypted queries and the placeholders on the data warehouse (210) to fetch the relevant data; andrender the visualization of the BI services on a User Interface (UI) (104).The system of claim 10, wherein sensitive data never leaves the customer secure environment, thereby ensuring compliance with data protection and sovereignty requirements.