Service Oriented Architecture For Encryption In Small And Medium-Sized Health Centers

Gesairo, Japhet Ngwono (2026) Service Oriented Architecture For Encryption In Small And Medium-Sized Health Centers. Masters thesis, Institut Teknologi Sepuluh Nopember.

[thumbnail of 6026241026-Master_Thesis.pdf] Text
6026241026-Master_Thesis.pdf
Restricted to Repository staff only

Download (6MB) | Request a copy

Abstract

The rapid digitization of healthcare systems has significantly improved service delivery through the adoption of Electronic Health Records (EHRs). However, this transformation has also exposed small and medium-sized health centers (SMHCs) to increasing cybersecurity risks, particularly due to limited technical infrastructure and financial constraints. Many SMHCs lack robust data protection mechanisms, making sensitive patient information vulnerable to unauthorized access, data breaches, and regulatory non-compliance.
This research proposes and evaluates a Service-Oriented Encryption Framework (SOEF) designed to provide scalable and efficient data protection tailored to SMHC environments. Guided by the Design Science Research (DSR) methodology, the study identified key security challenges, defined functional and non-functional requirements, and developed a working prototype based on a Service-Oriented Architecture (SOA). The framework implements a two-stage encryption model, combining client-side AES-128 encryption to eliminate plaintext data exposure during transmission with server-side AES-256 encryption within an independent SOA microservice for enhanced data-at-rest protection. The system also integrates Role-Based Access Control (RBAC), secure RESTful APIs over HTTPS/TLS, structured key management, and comprehensive audit logging to support regulatory compliance with standards such as HIPAA and GDPR.
The prototype was implemented using Node.js, Express.js, and MySQL, and evaluated through structured testing scenarios including success, failure, authentication, performance, and concurrent workload simulations. Key evaluation metrics included Encryption Success Rate, Decryption Accuracy, Average Response Time, and Error Rate. Results demonstrated high encryption reliability, accurate decryption recovery, sub-second API response times under simulated SMHC conditions, and stable behavior during concurrent access scenarios. An empirical comparison of encryption standards further validated AES-256 as an optimal balance between cryptographic strength and computational efficiency in resource-constrained healthcare settings.
The findings confirm that a modular, service-oriented encryption architecture can effectively strengthen healthcare data security without imposing excessive computational overhead. By bridging the gap between cryptographic robustness and operational feasibility, this research contributes a practical, scalable, and compliance-aligned solution for improving cybersecurity resilience in small and medium-sized health centers.

Item Type: Thesis (Masters)
Uncontrolled Keywords: Service-Oriented Architecture, Electronic Health Records, Healthcare Cybersecurity, Data Encryption, Small and Medium-Sized Health Centers.
Subjects: Q Science
Q Science > QA Mathematics > QA76.9.A25 Computer security. Digital forensic. Data encryption (Computer science)
Divisions: Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Information System > 59101-(S2) Master Thesis
Depositing User: Japhet Ngwono Gesairo
Date Deposited: 30 Jul 2026 07:06
Last Modified: 30 Jul 2026 07:06
URI: http://repository.its.ac.id/id/eprint/140503

Actions (login required)

View Item View Item