Balancing Confidentiality and Transparency for Blockchain-Based Process-Aware Information Systems

  • Alessandro Marcelletti*
  • , Edoardo Marangone
  • , Michele Kryston
  • , Claudio Di Ciccio
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

Abstract

Blockchain enables novel, trustworthy Process-Aware Information Systems (PAISs) by enforcing the security, robustness, and traceability of operations. In particular, transparency ensures that all information exchanges are openly accessible, fostering trust within the system. Although this is a desirable property to enable notarization and auditing activities, it also represents a limitation for such cases where confidentiality is a requirement since interactions involve sensitive data. Current solutions rely on obfuscation techniques or private infrastructures, hindering the enforcement capabilities of smart contracts and the public verifiability of transactions. Against this background, we propose CONFETTY, an architecture for blockchain-based PAISs to preserve confidentiality and transparency. Smart contracts enact, enforce and store public interactions, while attribute-based encryption techniques are adopted to specify access grants to confidential information. We assess the security of our solution through a systematic threat model analysis and evaluate its practical feasibility by gauging the performance of our implemented prototype in different scenarios from the literature.

Original languageEnglish
Title of host publicationBusiness Process Management Forum - BPM 2025 Forum, Proceedings
EditorsArik Senderovich, Cristina Cabanillas, Irene Vanderfeesten, Hajo A. Reijers
PublisherSpringer Science and Business Media Deutschland GmbH
Pages238-255
Number of pages18
ISBN (Print)9783032029287
DOIs
Publication statusPublished - 2026
EventBPM Forum held at the 23rd International Conference on Business Process Management, BPM 2025 - Seville, Spain
Duration: 31 Aug 20255 Sept 2025

Publication series

NameLecture Notes in Business Information Processing
Volume564 LNBIP
ISSN (Print)1865-1348
ISSN (Electronic)1865-1356

Conference

ConferenceBPM Forum held at the 23rd International Conference on Business Process Management, BPM 2025
Country/TerritorySpain
CitySeville
Period31/08/255/09/25

Bibliographical note

Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.

Keywords

  • Attribute-based encryption
  • Blockchain
  • Business process management
  • Distributed ledger technologies
  • Privacy
  • Security

Fingerprint

Dive into the research topics of 'Balancing Confidentiality and Transparency for Blockchain-Based Process-Aware Information Systems'. Together they form a unique fingerprint.

Cite this