
A HYBRID ENCRYPTION ARCHITECTURE WITH DISTRIBUTED KEY MANAGEMENT FOR CLOUD-BASED DATA DIGITIZATION AT HAI PHONG UNIVERSITY | IJCT Volume 13 – Issue 5 | IJCT-V13I5P34
IJCT
International Journal of Computer Techniques
ISSN 2394-2231 · Peer-Reviewed · Open Access
📚 Volume 13, Issue 5
📅 September 5, 2026
📄 Pages 316–319
🔖 ID: IJCT-V13I5P34
Table of Contents
ToggleA HYBRID ENCRYPTION ARCHITECTURE WITH DISTRIBUTED KEY MANAGEMENT FOR CLOUD-BASED DATA DIGITIZATION AT HAI PHONG UNIVERSITY
Author(s)
Nguyen Van Quang, Hoang Van Lam, Tran Bien Thuy
Abstract
The authors’ earlier study compared the performance of AES, RSA, and a hybrid encryption scheme on digitized data, finding the hybrid model to be the best performance trade-off; however, real-world effectiveness depends heavily on how encryption keys are organized, distributed, and protected across multiple university units. This paper proposes a five-layer architecture — digitization application layer, hybrid encryption layer, Key Management Service (KMS), Role-Based Access Control (RBAC) layer, and cloud storage infrastructure — together with a key lifecycle process (generation, distribution, use/rotation, revocation, audit logging). The team built a simulation model of KMS workload as the number of managed users/records grows from 100 to 10,000, measuring key rotation time, distribution latency, access-control latency, revocation latency, and key-metadata storage size. All figures are simulated data, disclosed transparently to illustrate the scalability of the proposed architecture rather than measurements from a production system. Results show that key-rotation cost and revocation latency scale nearly linearly with system size, while access-control latency grows more slowly thanks to caching, indicating the architecture scales adequately for the university’s current and near-term (3–5 year) needs. The paper also provides a conceptual-level threat analysis and mitigation recommendations for insider key-leakage risk.
Keywords
encryption key management; cloud security architecture; hybrid encryption; role-based access control; data digitization.
Conclusion
This paper proposed a layered architecture combining hybrid encryption with a centralized key-management service for the cloud data-digitization system at Hai Phong University, and evaluated its scalability via a workload simulation model. Results indicate the architecture comfortably supports the university’s current scale and can extend to roughly 10,000 managed records without significant access-control latency.
References
[1] Le Dac Nhuong (2018), Data Security Textbook, Vietnam National University, Hanoi Press.
[2] Ngo Ba Hung, Thai Minh Tuan, Trieu Thanh Ngoan (2021), Cloud Computing Textbook, Can Tho University Publishing House, ISBN 978-604-965-542-5.
[3] Van, T. H., Vinh, N. P., Ngan, V. T. T., Phuong, L. H., & Le, D. N. (2026). A Course-Specific Agentic RAG Chatbot for IT Student Support: Architecture, Local Deployment, and Preliminary Evaluation at Hai Phong University. Next-Generation Computing Systems and Technologies, 2(2), 21-34.
[4] Ghonge M.M., Pramanik S., Mangrulkar R., Le D.-N. (2022), Cyber Security and Digital Forensics, Wiley, ISBN 9781119795636.
[5] Le D.-N., Bhatt C., Madhukar M. (2019), Security Designs for the Cloud, IoT, and Social Networking, Wiley, ISBN 9781119592266.
[6] Blessing M. (2024), "Cloud Encryption Strategies and Key Management".
[7] Dhinakaran D. et al. (2024), "Towards a Novel Privacy-Preserving Distributed Multiparty Data Outsourcing Scheme for Cloud Computing with Quantum Key Distribution".
[8] Mukhopadhyay D. et al. (2014), "Securing the Data in Clouds with Hyperelliptic Curve Cryptography".
[9] NIST SP 800-57 Part 1 Rev. 5 (2020), Recommendation for Key Management.
[10] NIST FIPS 197 (2001), Advanced Encryption Standard (AES).
[2] Ngo Ba Hung, Thai Minh Tuan, Trieu Thanh Ngoan (2021), Cloud Computing Textbook, Can Tho University Publishing House, ISBN 978-604-965-542-5.
[3] Van, T. H., Vinh, N. P., Ngan, V. T. T., Phuong, L. H., & Le, D. N. (2026). A Course-Specific Agentic RAG Chatbot for IT Student Support: Architecture, Local Deployment, and Preliminary Evaluation at Hai Phong University. Next-Generation Computing Systems and Technologies, 2(2), 21-34.
[4] Ghonge M.M., Pramanik S., Mangrulkar R., Le D.-N. (2022), Cyber Security and Digital Forensics, Wiley, ISBN 9781119795636.
[5] Le D.-N., Bhatt C., Madhukar M. (2019), Security Designs for the Cloud, IoT, and Social Networking, Wiley, ISBN 9781119592266.
[6] Blessing M. (2024), "Cloud Encryption Strategies and Key Management".
[7] Dhinakaran D. et al. (2024), "Towards a Novel Privacy-Preserving Distributed Multiparty Data Outsourcing Scheme for Cloud Computing with Quantum Key Distribution".
[8] Mukhopadhyay D. et al. (2014), "Securing the Data in Clouds with Hyperelliptic Curve Cryptography".
[9] NIST SP 800-57 Part 1 Rev. 5 (2020), Recommendation for Key Management.
[10] NIST FIPS 197 (2001), Advanced Encryption Standard (AES).
📋 How to Cite This Paper
Nguyen Van Quang, Hoang Van Lam, Tran Bien Thuy (2026). A HYBRID ENCRYPTION ARCHITECTURE WITH DISTRIBUTED KEY MANAGEMENT FOR CLOUD-BASED DATA DIGITIZATION AT HAI PHONG UNIVERSITY. International Journal of Computer Techniques, 13(5), 316–319. ISSN: 2394-2231. DOI: https://doi.org/10.5281/zenodo.22362432









