A TEE-based approach for preserving data secrecy in process mining with decentralized sources

Publication date

2026-05

Authors

Basile, Davide
Goretti, Valerio
Barbaro, Luca
Reijers, Hajo A.ORCID 0000-0001-9634-5852ISNI 0000000037238136
Di Ciccio, ClaudioORCID 0000-0001-5570-0475ISNI 000000051813627X

Editors

Advisors

Supervisors

Document Type

Article

License

taverne

Abstract

Process mining techniques enable organizations to gain insights into their business processes through the analysis of execution records (event logs) stored by information systems. While most process mining efforts focus on intra-organizational scenarios, many real-world business processes span multiple independent organizations. Inter-organizational process mining, though, faces significant challenges, particularly regarding confidentiality guarantees: The analysis of data can reveal information that the participating organizations may not consent to disclose to one another, or to a third party hosting process mining services. To overcome this issue, this paper presents CONFINE, an approach for secrecy-preserving inter-organizational process mining. CONFINE leverages Trusted Execution Environments (TEEs) to deploy trusted applications that are capable of securely mining multi-party event logs while preserving data secrecy. We propose an architecture supporting a four-stage protocol to secure data exchange and processing, allowing for protected transfer and aggregation of unaltered process data across organizational boundaries. To avoid out-of-memory errors due to the limited capacity of TEEs, our protocol employs a segmentation-based strategy, whereby event logs are transmitted to TEEs in smaller batches. We conduct a formal verification of our approach’s correctness alongside a security analysis on the guarantees provided by the TEE core. We test our implementation using real-world and synthetic data to assess memory usage. Our experiments show that an incremental approach to segment processing in discovery and conformance checking is preferable over non-incremental strategies as the former maintains memory usage trends within a narrow range at runtime, whereas the latter exhibit high peaks towards the end of the execution. Furthermore, our results confirm that our prototype can handle real-world workloads without out-of-memory failures. The scalability tests reveal that memory usage grows logarithmically as the event log size increases. Memory consumption grows linearly with the number of provisioning organizations, indicating potential scalability limitations and opportunities for further optimizations.

Keywords

Business Process Management, Confidential computing, Process mining, Secrecy, Taverne

Citation

Basile, D, Goretti, V, Barbaro, L, Reijers, H A & Ciccio, C D 2026, 'A TEE-based approach for preserving data secrecy in process mining with decentralized sources', Journal of Information Security and Applications, vol. 98, 104381. https://doi.org/10.1016/j.jisa.2026.104381