0% found this document useful (0 votes)
4 views54 pages

Project

The Capstone Project Document outlines the development of the System for Retinal Vascular Health Screening, a web application aimed at early detection of systemic diseases through retinal imaging. The project includes detailed management plans, software requirements, design specifications, and testing documentation, emphasizing the use of AI for clinical decision support. The team consists of six members under the supervision of Nguyen Van Chien, with a completion target set for April 2025.

Uploaded by

anhboom45
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views54 pages

Project

The Capstone Project Document outlines the development of the System for Retinal Vascular Health Screening, a web application aimed at early detection of systemic diseases through retinal imaging. The project includes detailed management plans, software requirements, design specifications, and testing documentation, emphasizing the use of AI for clinical decision support. The team consists of six members under the supervision of Nguyen Van Chien, with a completion target set for April 2025.

Uploaded by

anhboom45
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Capstone Project Document

Group Members Vo Thi Tu Nhi


Bui Thanh Tung
Nguyen Hoang Thanh Hieu
Tran Nhat Huy
Nguyen Ngoc Anh Thu
Le Thi Ngoc Tram
Supervisor Nguyen Van Chien
Capstone Project code SP26SE025

- Ho Chi Minh, January 2026 -

1
Table of Contents
I. Project Introduction ..............................................................................................................5
1. Overview ....................................................................................................................... 5
II. Project Management Plan ................................................................................................... 9
1. Overview ....................................................................................................................... 9
2. Management Approach ..............................................................................................14
3. Project Communications .............................................................................................16
III. Software Requirement Specification ................................................................................ 18
1. Product Overview ....................................................................................................... 18
2. User Requirements ..................................................................................................... 18
3. Requirement Appendix ...............................................................................................39
IV. Software Design Description ............................................................................................ 40
1. System Design ............................................................................................................. 40
V. Software Testing Documentation ...................................................................................... 52
1. Scope of Testing ..........................................................................................................52
2. Test Strategy ................................................................................................................53
3. Test Plan...................................................................................................................... 54

2
Acknowledgement
We would like to take this opportunity to express our deepest appreciation to all those who have
supported and contributed to the completion of this graduation project.

First and foremost, we would like to sincerely thank the lecturers of the Faculty of Information
Technology, with special appreciation to Mr. Nguyen Van Chien for his dedicated guidance,
insightful advice, and continuous encouragement throughout the development of this project. The
lecturers’ professional knowledge and constructive feedback were invaluable and played a significant
role in the successful development of the CollabSphere product.

We are also deeply grateful to our families and friends for their constant encouragement,
understanding, and emotional support during our academic journey and throughout the project
implementation process.

In addition, we would like to thank the students who participated in testing the system and provided
meaningful feedback, which greatly contributed to improving the quality and practicality of the
product.

Although we have devoted our best efforts to this project, due to limitations in time and experience, the
system still has certain shortcomings. We sincerely hope to receive understanding as well as valuable
comments and suggestions from the lecturers to help us further enhance and improve the project in the
future.

Once again, we would like to express our sincere thanks.

Definition and Acronyms

Acronym Definition

SRVHS System for Retinal Vascular Health Screening

BR Business Rule

ERD Entity Relationship Diagram

GUI Graphical User Interface

PM Project Manager

SDD Software Design Description

SRS Software Requirement Specification

UC Use Case

3
API Application Programming Interface

CDS Clinical Decision Support

ORM Object-Relational Mapping

4
I. Project Introduction
1. Overview
1.1 Project Information
• Project name: System for Retinal Vascular Health Screening
• Project code: SP26SE025
• Group name:
• Software Type: Web application

1.2 Project Team


Full Name Role ID
Bui Thanh Tung Member 079206018521

Vo Thi Tu Nhi Member 089306000846

Nguyen Hoang Thanh Hieu Member 079206016084

Tran Nhat Huy Member 052206017361

Nguyen Ngoc Anh Thu Member 083306009541

Le Thi Ngoc Tram Member 082306016385

2. Product Background
With the increasing focus on preventive healthcare, early detection of systemic diseases
has become a critical factor in improving treatment outcomes and reducing healthcare costs.
Many serious conditions, such as cardiovascular diseases, diabetes-related complications, and
neurological disorders, often develop silently and are only diagnosed at advanced stages,
when treatment becomes more difficult and less effective.
Retinal imaging provides a non-invasive and reliable method to assess vascular health, as
the retina reflects the condition of the body’s microvascular system. Changes in retinal blood
vessels have been shown to correlate strongly with risks of hypertension, diabetes, and stroke.
Therefore, retinal images can serve as an effective indicator for early disease risk screening.
However, access to advanced retinal analysis remains limited in many healthcare facilities
in Vietnam due to high costs, complex diagnostic procedures, and a shortage of specialized
personnel. To address these limitations, the System for Retinal Vascular Health Screening
(SP26SE025) is proposed. The system utilizes AURA (AI Understanding Retinal Analysis) as a
Clinical Decision Support tool to assist doctors in analyzing retinal images and identifying
potential vascular abnormalities.

5
3. Business Opportunity
The growing demand for preventive healthcare and early disease screening, together with the
increasing burden of cardiovascular and metabolic diseases in Vietnam, creates a significant
business opportunity for AI-based retinal screening solutions. By utilizing existing retinal
imaging devices and cloud-based analysis, the proposed system offers a cost-effective and
scalable service for clinics and hospitals, enabling subscription or pay-per-use business models
and supporting long-term adoption in the digital healthcare market.

4. Software Product Vision


Vision Statement AURA aims to become a scalable, ethical, and AI-powered Clinical Decision
Support System that leverages retinal imaging to enable early detection of systemic vascular-
related diseases. By transforming retinal images into actionable health insights, AURA helps
healthcare providers improve preventive care, reduce diagnostic barriers, and enhance
patient outcomes—especially in resource-limited settings.
Target Users:
 Patients / General Users seeking non-invasive and early health risk screening
 Doctors requiring AI-assisted analysis and decision support
 Clinics and Hospitals conducting large-scale screening and preventive programs System
 Administrators managing operations, AI performance, and compliance
Core Value Proposition:
 Early Disease Risk Detection: Utilize retinal vasculature as a non-invasive indicator for
cardiovascular, diabetic, and neurological risks.
 Clinical Decision Support, Not Replacement: Provide explainable AI insights that assist
doctors in faster and more confident diagnoses.
 Expanded Access to Preventive Healthcare: Enable community clinics and mid-tier
hospitals to perform advanced screenings without costly infrastructure.
 Ethical and Transparent AI: Ensure interpretability, data privacy, and compliance with
medical regulations.
 Scalable and Sustainable Platform: Support multi-clinic deployment, bulk image analysis,
and continuous AI model improvement.
5. Project Scope & Limitations
5.1 Major Features
5.1.1 User Functional Requirements
[FR-1] Register and log in using email, Google account, or social authentication.
[FR-2] Upload single or multiple retinal (Fundus or OCT) images for analysis.
[FR-3] View AI-generated diagnostic results and risk levels.
[FR-4] Visualize annotated images showing affected vascular areas.
[FR-5] Receive automated health recommendations or warnings.
[FR-6] Access personal analysis history and previous reports.
[FR-7] Download or export diagnostic reports (PDF/CSV).
[FR-8] Manage and update personal profile and medical information.
[FR-9] Receive notifications when AI results are ready.
[FR-10] Communicate with the assigned doctor via in-app messaging.
6
[FR-11] Purchase or renew analysis service packages.
[FR-12] View payment history and remaining analysis credits.
5.1.2 Doctor Functional Requirements
[FR-13] Log in and manage assigned patient profiles.
[FR-14] Review AI analysis results and annotations.
[FR-15] Validate or correct AI-generated findings.
[FR-16] Add medical notes, diagnoses, or recommendations.
[FR-17] Access patient history, previous analyses, and trend data.
[FR-18] Filter or search patients by ID, name, or risk level.
[FR-19] Provide feedback to improve AI accuracy and model retraining.
[FR-20] Communicate with users (patients) through consultation chat.
[FR-21] View performance summaries or analysis statistics.

5.1.3 Clinic Functional Requirements


[FR-22] Register clinic accounts and verify organization identity.
[FR-23] Manage multiple doctor and user (patient) accounts.
[FR-24] Upload and submit bulk retinal images for AI analysis.
[FR-25] Monitor all patient analysis reports and aggregated risk data.
[FR-26] Generate clinic-wide reports for screening campaigns.
[FR-27] Track number of images analyzed and package usage.
[FR-28] Purchase or renew clinic-level service packages.
[FR-29] Receive alerts for high-risk patients or abnormal trends.
[FR30]4.3. Export summarized statistics for clinical research or management.

5.1.4 Admin Functional Requirements


[FR-31] Manage user, doctor, and clinic accounts (enable, disable, edit).
[FR-32] Define and update user roles and access permissions.
[FR-33] Configure AI parameters, thresholds, and retraining policies.
[FR-34] Manage service packages, pricing, and billing models.
[FR-35] Access global dashboard showing usage, revenue, and AI performance.
[FR-36] View system analytics (image count, risk distribution, error rates).
[FR-37] Handle data compliance, audit logs, and privacy settings.
[FR-38] Approve or suspend clinic registrations.
[FR-39] Manage notification templates and communication policies.

7
5.2 Limitations & Exclusions
LI- No FPT email verification No integration with the
01
university SSO due to API access restrictions

LI- Supports Vietnamese only Additional languages will be


02
developed in future versions

LI- No native mobile app Only a responsive web app;


03
iOS/Android apps planned later

LI- File upload limit of 100MB per file To reduce storage costs and
04
prevent abuse

LI- AI chatbot supports English only AWS Bedrock models are


05
primarily trained on English data

LI- No offline mode Continuous internet connection required for real-time


06 features

Maximum 20 image per account Limited by WebRTC peer connections and bandwidth
LI-
07

LI- Whiteboard does not Only drawing and shapes


08 support image import
supported; image upload planned later

LI- No external calendar integration No synchronization with Google or Outlook Calendar


09

LI- No plagiarism detection Submissions are not checked for plagiarism


10

LI- Manual backup only No automatic backup; admins must export data
11 periodically

LI- SQLlite only No support for MySQL, MongoDB, or other databases


12

LI- Real-time sync delay Instant synchronization not guaranteed for collaborative
13 editor
< 2 seconds

LI- No document version control No history or restore feature for collaborative documents
14

LI- Non-customizable email notifications Fixed email templates; users cannot customize them
15

8
II. Project Management Plan
1. Overview
1.1 Scope & Estimation

Est. Effort
# WBS Item Complexity (man-
days)
1 Initiating 20

1.1 Define project scope Medium 12

1.2 Collect requirements Medium 8

2 Planning 14

2.1 Create kick-off meeting Medium 7

2.2 Create plan document Medium 7

3 Executing

3.1 Analysis 18

3.1.1 Analysis requirements Medium 8


3.1.2 Feasibility Analysis Complex 10

3.2 Design 12

3.2.1 Design conceptual ERD Medium 4

3.2.2 Design code architecture Medium 4

3.2.3 Design web application Medium 4

3.3 Implementation

3.3.1 Authentication 4

[Link] Signing with Email Medium 2

[Link] Get refresh token Medium 1

[Link] Verify token Medium 1

3.3.2 User management 17

[Link] User registration & login Simple 2

[Link] User roles & permissions Medium 4

[Link] User Profile Simple 2

9
[Link] Scan Retinal Image by AI Complex 7

[Link] Manager assign account Simple 2

3.3.3 Timeline Management 2

[Link] Manager image for each upload Simple 2

3.3.4 Criteria Form Management 4

[Link] Admin config features of AI Medium 4

3.3.5 Project Registration & Approval 14

[Link] User and Clinic submit thesis proposal Medium 4

[Link] Doctor reviews and response diagnosis Medium 4

[Link] Consulation reviews and response the thesis report Medium 6

3.3.6 Team Formation & Matching 20

[Link] Create teams Simple 2

[Link] AI-powered member suggestions Complex 7

[Link] AI-powered team suggestions Complex 7

[Link] Leader sends invitations for member Medium 2

[Link] Team members and mentor response the invitations Simple 2

3.3.7 Team Recruitment Posts 5

[Link] Create recruitment blog Simple 1

[Link] Accept & comment on report Simple 1

[Link] Admin view list of accounts Simple 1

3.3.8 Project Progress Management 7

[Link] Manager import review schedules Medium 2

[Link] Admin review user profile Simple 1

[Link] User can update profile Simple 1

[Link] Doctor review and respond updating topic Simple 1


Manager report and respond updating topic after
[Link] Simple 1
mentor
[Link] Doctor provide feedback after review 3 Simple 1

3.3.10 Team Rate Contribution 4

10
[Link] Admin rate contribution Simple 4

3.3.11 Capstone Management 4

[Link] Manager import capstone schedules Medium 2

[Link] Manager update capstone results Simple 1

[Link] User view report results Simple 1

3.3.12 Messaging System 10

[Link] Initiating a Chat Complex 7

[Link] Sending & Receiving Messages Complex 3

3.3.13 Notification System 9

[Link] Send notification Complex 5

[Link] View notification Medium 2

[Link] Manager create notification for system Medium 2

3.4 Testing 24

3.4.1 Unit test Complex 8

3.4.2 Integration Test Complex 8

3.4.3 System Test Complex 8

3.5 Monitoring and Controlling 24

3.5.1 Control the process Complex 12

3.5.2 Track performance a quality Complex 12

3.6 Closing 20

3.6.1 Report Simple 20

Total Estimated Effort (man-days) 232

11
1.2 Project Objectives
● Timelines: The project must be finished before 30 April, 2025
● Allocated Effort (Man-days): 232
● Defect Distributions:

No. of % of
# Testing Stage Test Coverage
Defects Defect
Notes

Backend: Code
review (python,
Authentication)
Frontend: Code Focus on security,
1 Reviewing review (HTML, <30 5% performance, and
CSS, JS) maintainability
Backend:
Business logic
Ensure correctness of auth,
Frontend:
2 Unit Test <20 3% UI interactions, and state
Component management
testing, Form
validation
Backend: API
integration
Verify API interactions,
Frontend: API
3 Integration Test <5 1% state consistency, and UI
calls, Data behavior
binding, UI
responsiveness
Backend: Full
system testing
with database
(SQLite) Ensure smooth UI-Backend
4 System Test Frontend: End- <5 1% communication and DB
to-end consistency
navigation, user
experience

Ensure system meets


5 Acceptance Test Full workflow <5 1%
business requirements

12
1.3 Project Risks
# Risk Description Impact Possibility Response Plans
Incorrect risk assessment Use high-quality training datasets, perform
Inaccurate or biased
1 may mislead doctors and Medium continuous model validation, and require
AI analysis results
affect clinical decisions. doctor verification before final diagnosis.
Exposure of sensitive patient Apply strong encryption, role-based access
Data security
2 medical data leads to legal Medium control (RBAC), regular security audits, and
breaches
issues and loss of trust. compliance with medical data regulations.
Poor system Delayed AI analysis and Optimize AI processing, enable horizontal
3 performance during report generation reduce High scaling of microservices, and implement
peak usage user satisfaction. load balancing.
Integration issues Clinics may fail to upload or Support standardized image formats,
4 with retinal imaging process retinal images Medium provide clear upload guidelines, and
devices correctly. perform extensive integration testing.
Doctors may distrust AI Provide visual explanations such as
Lack of explainability
5 results and hesitate to use Medium heatmaps and annotated images, along with
in AI outputs
the system. transparent risk scoring logic.
Delayed doctor Users may not receive timely
Implement automated alerts and priority
6 feedback or medical guidance for high-risk Low
notifications for high-risk analysis results.
validation cases.

13
2. Management Approach
2.1 Project Process
After carefully evaluating different software development models, the project will adopt an
Iterative and Incremental Software Development Process. In this model, an initial partial
version of the system is developed and delivered early, ensuring that there is always
something functional at every stage. The Iterative and Incremental approach is especially
beneficial when the project scope is large, major requirements are already well-defined,
but further details will emerge during the development process. This method breaks the
system development into smaller, manageable tasks, with each task completed in phases. This
allows us to build upon knowledge gained in earlier phases. The reasons for choosing this
model include:

● Developing core features based on priority requirements first.


● The flexibility to easily accommodate changes in requirements.
● Continuous testing and debugging during each iteration.
● The ease of managing risks, as risks are identified and addressed during each iteration.
● Clients can provide feedback after each product increment, helping to avoid surprises
at the end of the project.
● Important functionality is delivered early, ensuring early value for the clients.

2.2 Quality Management


2.2.1 Defect Prevention: In the event that a defect is identified, the responsible person must
be notified immediately. Each defect must be carefully assessed by answering questions such
as: "How critical is the defect, and can it potentially damage the system?" and "How long will it
take to resolve the defect?" A clear deadline for defect resolution must be established.
Additionally, a proactive plan should always be in place to anticipate any possible issues that
could arise during development.

2.2.2 Reviewing: The review process must be conducted impartially and without bias towards
any project team member. If an error is discovered, the responsible party must be promptly
informed. Defects should be recorded in the Bug Tracking software with detailed information,
including the defect's priority. The person responsible for addressing the defect must provide a
solution and resolve the issue as quickly as possible.

2.2.3 Unit Testing: Test cases must be prepared thoroughly and accurately, ensuring that no
possible test scenario is overlooked. The test cases should align with the system's
functionalities. Any defects found during testing must be logged in the Bug Tracking software,

14
including relevant details such as priority. The person responsible for the defect must offer a
solution to fix it promptly.
Integration Testing: Test cases for integration testing should be prepared carefully and
accurately, without omitting any possible scenarios. These test cases should align with the
system's functionality. All defects identified during integration testing should be documented
in the Bug Tracking software, with specific details such as priority level. The person
responsible for addressing the defect must implement a solution quickly. It's essential that
internal modules of the system work seamlessly together.

2.2.4 System Testing: System testing requires that test cases be designed carefully and in full
alignment with the system's requirements and architectural design. Any defects encountered
during system testing must be logged in the Bug Tracking software, along with important
details like priority. The individual responsible for resolving the defect must devise a solution
and resolve the issue swiftly. System testing must ensure that all system functionalities are
thoroughly covered, including interactions with any external systems still under developme

15
3. Project Communications

Communication When, Type, Tool,


Who/ Target Purpose
Item Frequency Method(s)
Review plan, schedule,
members work
Team weekly All team 17:30 pm
achievements during the
meeting members every Friday
week and report the
project progress and status
- Review work progress,
including code and
documentation.
Supervisors - Answer requirements and Online
Weekly Report 2 day / week
Team members technical questions. Google Meet
- Control project deadlines
and ensure projects run on
schedule.
Report the progress that
Daily Meeting Team members Daily Google Meet
members achieved each
When there’s a critical
When
problem that needs to be
Unscheduled All team members find
resolved immediately, Google Meet
meeting members important
discuss then resolve that
problems
problem

4. Configuration Management
4.1 Document Management
Document tools: Confluence, Jira,Excel File

management

4.2 Source Code Management


Source code is managed by Git on [Link]

16
4.3 Tools & Infrastructures

Category Tools / Infrastructure


Technology HTML+CSS+JS (FrontEnd), Python/FastAPI (BackEnd)
Database SQLite
IDEs/Editors Visual Studio Code
Diagramming DrawIO
Documentation Ms Office, Google Docs/Sheets/Slides, Confluence
Version Control GitLab (Source Codes)
Project management Jira

17
III. Software Requirement Specification
1. Product Overview
The System for Retinal Vascular Health Screening (SP26SE025) is an AI-powered Clinical
Decision Support platform designed to assist healthcare providers in early detection of
systemic disease risks through retinal image analysis. By integrating cloud-based AI services
with existing retinal imaging devices, the system automatically analyzes fundus or OCT images,
highlights vascular abnormalities, and generates interpretable risk assessments for clinicians.
The platform supports users, doctors, clinics, and administrators through a unified web
application, enabling scalable, secure, and efficient retinal screening while maintaining clinical
transparency and data privacy.

2. User Requirements
2.1 Actors
# Actor Description
The User represents patients seeking retinal vascular health
1 User screening, with the ability to securely register, upload retinal images,
and receive AI-generated results with risk levels and annotations. The
system allows users to view historical reports, receive
recommendations and notifications, communicate with doctors,
manage personal data, and purchase or renew service packages.
The Doctor reviews and validates AI-assisted retinal analysis by
accessing assigned patients, annotated images, and risk assessments,
2 Clinic
and by confirming or correcting AI findings with medical notes. The
system supports patient search, historical trend analysis, secure
patient communication, and feedback to improve AI model
performance.
The Clinic represents a healthcare organization that manages
doctors and patients, including account registration and
3 Doctor verification, user and doctor management, and bulk retinal image
uploads. The system supports aggregated reporting, screening
campaign management, service package tracking, and alerts for
high-risk cases or abnormal trends.
The Administrator oversees system governance and operations,
including account management, role-based access control, AI
configuration, and service packages with billing. The system provides
4 Admin
dashboards, analytics, audit logs, and compliance tools to manage
clinic approvals while ensuring data security and regulatory
compliance.

18
2.2 Use Cases Diagram

19
Descriptions
ID Use Case Actors Use Case Descriptions

1 Register User/Patient, Doctor, Clinic Register to AURA system

2 Login User/Patient, Doctor, Login to AURA system


Clinic, Admin

3 Manage Personal User/Patient, Doctor Update personal information


Profile

4 Upload Retinal User/Patient Upload retinal images


Images

5 View Diagnostic User/Patient Patients view the diagnostic report generated by


Report the AI system and the doctor confirms it

6 View Annotated User/Patient View annotated images


Images

7 Purchase Service User/Patient Users purchase service packages


Package

8 Exchange Messages User/Patient, Doctor Patients and doctors exchange text messages
directly

9 Export Report to PDF User/Patient User exports report to PDF file

10 View Assigned Doctor The doctor reviews the list of patients assigned by
Patients the system or clinic

11 View Patient History Doctor The doctor reviews the patient's medical history
and previous reports

12 View & Update Doctor View medical records and update medical
Medical Information information

13 Validate & Diagnosis Doctor The doctor reviews the AI results, makes a
professional assessment, and confirms the
diagnosis

14 Review AI Analysis Doctor See detailed AI analysis

15 Send AI Feedback Doctor Submit feedback on the AI analysis review

16 Bulk Image Upload Clinic Upload images

20
17 Purchase Clinic Clinic Purchase a dedicated analysis package for your
Package clinic

18 Manage Staff & Clinic Manage the clinic's list of staff, doctors and
Patients patient

19 View Clinic Reports Clinic View summary analysis reports of all patients in
the clinic

20 View Health Risk Clinic Monitoring and statistically analyzing the health
Statistics risk levels of patients in the clinic

21 Manage Users, Admin Manage and grant permissions to all users on the
Doctors & Clinics system

22 Approve Clinic Admin Approve new clinic account registration request


Registration

23 Configure AI Admin Edit AI parameters, configure models, or set


Parameters analysis thresholds

24 View System Admin View system operating parameters, number of


Dashboard analyzed images, number of users, error report

25 <<External System>> Payment Gateway Process online payments between users/clinics


Payment Gateway (External), User/Patient, and the system through an intermediary payment
Clinic gateway

21
2.3. Data Flow Diagram (Level 0)

1. Phân tích Actor Bệnh nhân (User / Patient)

Actor:
Bệnh nhân (User/Patient) : là đối tượng sử dụng dịch vụ của hệ thống.

Actor I/O :
a) Gửi vào hệ thống (Input) :
a.1) Retinal images (Upload): Tải lên hình ảnh chụp võng mạc để phân tích.
a.2) Service package selection: Lựa chọn các gói dịch vụ khám bệnh.
a.3) Report view requests & PDF export commands: Yêu cầu xem báo cáo chẩn đoán và xuất file PDF.
a.4) Chat messages: Gửi tin nhắn trao đổi hoặc tư vấn khám bệnh.

b) Nhận từ hệ thống (Output):


b.1) Diagnostic reports & Annotated images: Kết quả chẩn đoán và hình ảnh các vùng bệnh lý được chẩn đoán
bằng AI.
b.2) PDF Report files: Nhận tệp báo cáo PDF để tải về máy.
b.3) Payment status notifications: Thông báo về tình trạng thanh toán.
b.4) Image format error alerts: Cảnh báo nếu hình ảnh tải lên sai định dạng hoặc chất lượng kém.

22
2. Phân tích Actor Bác sĩ (Doctor)

Actor :
Bác sĩ (Doctor) : Bác sĩ đóng vai trò thẩm định chuyên môn cho kết quả của AI.
Actor I/O :
a) Gửi vào hệ thống (Input):
a.1) Diagnosis validation & feedback: Đánh giá tính khả thi của kết quả chẩn đoán bằng AI và đưa ra phản hồi.
a.2) AI accuracy feedback:Đưa ra phản hồi về độ chính xác của thuật toán AI.
a.3) Patient search requests: Thực hiện các yêu cầu tìm kiếm hồ sơ bệnh nhân.

b) Nhận từ hệ thống (Output):


b.1) Initial AI analysis results: Nhận kết quả phân tích sơ bộ do AI thực hiện trước.
b.2) Patient profiles & lists: Tiếp nhận danh sách và hồ sơ bệnh án của bệnh nhân.

3. Phân tích Actor Phòng khám (Clinic)

Actor :
Phòng khám (Clinic) : Đây là các đơn vị tổ chức hoặc đối tác y tế.
Actor I/O :
a) Gửi vào hệ thống (Input):
a.1) Bulk image uploads: Tải lên cùng lúc nhiều hình ảnh võng mạc .
a.2) New staff/patient info: Cập nhật thông tin nhân viên mới hoặc bệnh nhân mới.
a.3) AI analysis review requests: Yêu cầu duyệt,kiểm tra lại những phân tích từ AI.
b) Nhận từ hệ thống (Output):
b.1) Clinic-wide reports: Nhận báo cáo tổng hợp tình hình sức khỏe của toàn bộ bệnh nhân trong phòng khám.
b.2) Storage & AI processing status: Theo dõi tình trạng lưu trữ của dữ liệu và tiến độ xử lý của AI.

4. Phân tích Actor Quản trị viên (Admin)

Actor :
Quản trị viên (Admin): Người vận hành và cấu hình hệ thống.
Actor I/O:
a) Gửi vào hệ thống (Input):
a.1) Medical package updates: Cập nhật thông tin và giá các gói dịch vụ y tế.
a.2) Account verify/lock commands: Thực hiện lệnh xác minh hoặc khóa tài khoản người dùng.
a.3) AI parameter configurations: Thiết lập các thông số kỹ thuật cho thuật toán AI.
b) Nhận từ hệ thống (Output):

23
b.1)User account data: Quản lý dữ liệu tài khoản của các thành viên.
b.2)System Dashboard & Management reports: Theo dõi biểu đồ hệ thống và các báo cáo quản trị tổng quát.

5. Phân tích Actor Cổng thanh toán (Payment Gateway)

Actor:
Cổng thanh toán (Payment Gateway): Actor trung gian xử lý các giao dịch tài chính.
Actor I/O:
a) Gửi vào hệ thống (Input):
a.1) Payment processing requests :Yêu cầu xử lý thanh toán khi người dùng chọn gói dịch vụ.
b) Nhận từ hệ thống (Output):
b.1) Transaction results (Success/Failed) :Kết quả giao dịch thành công hoặc thất bại để hệ thống quyết định
trả kết quả cho bệnh nhân.

24
2.4. Activity Diagram

Description: This diagram illustrates the steps for uploading a user's retinal image data:
 User: Select the function and choose an image file from the device.
 System: Receives the file and performs a check for image format and size (Validate image format & size).
 Handling: > * If the file is invalid, the system displays an error message (Display error).
 If the file is valid, the system will store the image in the database.

The diagram describes the interaction flow when the user wants to view results from the system:

Request: The user selects **View Diagnostic Report** (Select view diagnostic report).

Check: The system checks whether the report is available (Check report availability).

If not available (Not available):


The system notifies the user (Notify user) and ends the process.

25
If available (Available):
The system displays the report content (Display diagnostic report).

Action selection: On the report screen, the user can select an action (Select action):

- View annotated images (View annotated images):


The system displays the processed images (Display annotated images).

- Export PDF (Export PDF):


The system generates a PDF file (Generate PDF) and allows the user to download it (Download).

- Non-action:
The process ends.

This diagram describes the workflow between the Clinic side and the System to check the status and content of
AI analysis results.

Start: A Clinic member selects a specific AI analysis result (Select AI analysis result).

System Processing: The system receives the request and checks the status of the analysis (Check status).

Decision Point (Branch by Status):

Processing status (Processing):


If the AI is still processing, the system displays a processing notification (Display processing) and ends the
process.

Completed status (Accomplished):


If the AI analysis is completed, the system displays the AI analysis content (Display AI analysis).

Final Action: After the system displays the result, the Clinic reviews and evaluates the AI analysis (Review AI
analysis) before the process ends.

26
This diagram is dedicated to the Clinic role when handling large data:

Clinic: Selects multiple images at the same time (Select images) and uploads them (Upload images).

System: Receives the images and stores all of them in the database (Store images).

Post-upload Processing: After successful storage, the system automatically sends the images to the AI
processing component (Send images to AI processing) to start the analysis.

This process helps the Clinic search for and add a member to the system:

Clinic: Types the username of the user to be added (Type username).

System: Checks whether the user exists (Check available).

If not available (Not available):


The system displays nothing (Display nothing) and ends the process.
27
If available (Available):
The system displays the user information (Display user information).

Clinic: Reviews the information (Check user information) and confirms adding the user (Add user).

This process is designed for the Administrator (Admin) to control user accounts:

Admin: Reviews user accounts (Review user account).

System: Displays the list and detailed information (Display information).

Admin: Selects a specific user account (Select user account) and chooses an action to perform (Select action).

Action: The Admin can choose to verify the account (Verify account) or lock the account (Lock account).

System: Updates the new status of the user account in the system (Update user account status).

28
This process manages medical service packages:

Administrator (Admin): Selects the function to update a medical package (Update medical package).

Action: The administrator fills in the required medical package information (Fill medical package information).

System: Saves the new information into the system (Save medical package).

This diagram describes the interaction flow between the User, the System, and the Payment Gateway to
perform a transaction:

User Actions:

The user starts by selecting the desired service package (Select service package).

Then, the user confirms the purchase of the service package (Confirm purchase).

System Processing:

The system receives the request and sends a payment request to a third party (Send payment request).

Payment Gateway Processing:

29
The payment gateway processes the transaction (Process payment).

Result Branching:

If the payment fails (Failed):


The system receives the signal and notifies the user of the payment failure (Notify payment failure).

If the payment is successful (Success):


The system activates the service package for the user account (Activate service package).

End: The process stops after the user receives the result notification or the service package is successfully
activated.

30
2.5. Entity Raltionship Diagram (ERD)

Các nhóm đối tượng chính:

Người dùng (Users)


Phòng khám (Clinics)
Bác sĩ (Doctors)
Bệnh nhân (Patients)
Tư vấn y tế (Consultations)
Tin nhắn (Messages)
Tải lên dữ liệu & báo cáo AI (Uploads, Reports)
Chẩn đoán (Diagnoses)
Gói dịch vụ & đăng ký (Packages, Subscriptions)

31
Đặc tả các thực thể (Entities)

1.1. Users (Người dùng):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

full_name varchar (50) Họ và tên

username varchar (50) Tên đăng nhập

password varchar (50) Mật khẩu đã mã hóa

role enum Vai trò (admin / clinic / doctor / patient)

is_active boolean Trạng thái hoạt động

verified boolean Đã xác thực hay chưa

blocked boolean Bị khóa hay không

block_reason varchar (100) Lý do bị khóa

email varchar (50) Email

phone varchar (10) Số điện thoại

created_at datetime Ngày tạo

updated_at datetime Ngày cập nhật

1.2. Clinics (Phòng khám):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

user_id int (FK) Liên kết Users

business_certificate varchar (50) Giấy phép kinh doanh

clinic_name varchar (50) Tên phòng khám

address text Địa chỉ

phone varchar (10) SĐT

website varchar (50) Website

verified boolean Đã xác thực

created_at datetime Ngày tạo

updated_at datetime Ngày cập nhật

32
1.3. Doctors (Bác sĩ):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

user_id int (FK) Liên kết Users

practice_certificate varchar (50) Chứng chỉ hành nghề

specialization varchar (50) Chuyên khoa

phone varchar (10) SĐT

years_experience int Số năm kinh nghiệm

clinic_name varchar (50) Tên nơi làm việc

clinic_address text Địa chỉ làm việc

verified boolean Đã xác thực

created_at datetime Ngày tạo

updated_at datetime Ngày cập nhật

1.4. Patients (Bệnh nhân):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

user_id int (FK) Liên kết Users

clinic_id int (FK) Phòng khám quản lý

date_of_birth datetime Ngày sinh

gender varchar (10) Giới tính

phone varchar (10) SĐT

address text Địa chỉ

created_at datetime Ngày tạo

updated_at datetime Ngày cập nhật

1.5. Clinic_Doctors (Bác sĩ – Phòng khám):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

clinic_id int (FK) Phòng khám

doctor_id int (FK) Bác sĩ

joined_date datetime Ngày tham gia

is_active boolean Trạng thái

33
1.6. Consultations (Tư vấn):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

doctor_id int (FK) Bác sĩ

patient_id int (FK) Bệnh nhân

topic varchar (50) Chủ đề tư vấn

status varchar (50) Trạng thái

scheduled_date datetime Thời gian hẹn

completed_at datetime Thời gian hoàn thành

created_at datetime Ngày tạo

updated_at datetime Ngày cập nhật

1.7. Messages (Tin nhắn):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

consultation_id int (FK) Phiên tư vấn

user_id int (FK) Người gửi

message_text text Nội dung

created_at datetime Ngày gửi

updated_at datetime Ngày cập nhật

1.8. Uploads (Dữ liệu tải lên):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

user_id int (FK) Người tải

patient_id int (FK) Bệnh nhân

file_name varchar (50) Tên file

file_path varchar (255) Đường dẫn

file_size int Kích thước

file_type varchar (50) Loại file

description text Mô tả

analyzed boolean Đã phân tích AI

created_at datetime Ngày tạo

34
updated_at datetime Ngày cập nhật

1.9. Reports (Báo cáo AI):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

upload_id int (FK, UNIQUE) Dữ liệu nguồn

status varchar (50) Trạng thái

ai_analysis text Phân tích AI

confidence_score float Độ tin cậy

risk_level varchar (50) Mức độ rủi ro

annotations text Ghi chú

created_at datetime Ngày tạo

updated_at datetime Ngày cập nhật

1.10. Diagnoses (Chẩn đoán):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

report_id int (FK) Báo cáo

doctor_id int (FK) Bác sĩ

diagnosis_text text Nội dung chẩn đoán

recommendations text Khuyến nghị

severity varchar (50) Mức độ

follow_up_required boolean Cần tái khám

follow_up_date datetime Ngày tái khám

created_at datetime Ngày tạo

updated_at datetime Ngày cập nhật

1.11. Packages (Gói dịch vụ):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

name varchar Tên gói

description text Mô tả

price float Giá

35
duration_days int Thời hạn

max_uploads int Giới hạn upload

features text Tính năng

created_at datetime Ngày tạo

updated_at datetime Ngày cập nhật

1.12. Subscriptions (Đăng ký gói):

Thuộc tính Kiểu Mô tả

id int (PK) Khóa chính

user_id int (FK) Người dùng

package_id int (FK) Gói

start_date datetime Ngày bắt đầu

end_date datetime Ngày kết thúc

is_active boolean Trạng thái

created_at datetime Ngày tạo

Đặc tả quan hệ:

Quan hệ Kiểu

Quan hệ Kiểu

User – Clinic 1–1

User – Doctor 1–1

User – Patient 1–1

Clinic – Doctor N–N

Clinic – Patient 1–N

Doctor – Consultation 1–N

Patient – Consultation 1–N

Consultation – Message 1–N

Upload – Report 1–1

Report – Diagnosis 1–N

User – Subscription 1–N

Package – Subscription 1–N

36
2.6. Class Diagram

1. User Management Subsystem


Parent Class User:
Acts as the base class containing common information such as userId, fullName, email, passwordHash, and
medicalHistory (medical history).
Main methods: register(), login(), logout(), updateProfile().
Inheritance Relationship:
Admin: Inherits from User. Has the right to manage users (manageUsers), configure AI (configureAI), and view
system statistics (viewSystemAnalytics).
Doctor: Inherits from User. Has additional professional attributes such as licenseNumber (license number) and
specialization (specialty). Doctors can perform actions such as viewing AI results (reviewAIResult) and adding
medical notes (addMedicalNote).

37
2. Diagnosis & AI Core
RetinalImage: Stores image information uploaded by the user. Contains the attributes imageURL, imageType,
and a method for validating image quality (validateQuality).
AIAnalysis: Performs analysis on retinal images.
Has a dependency relationship with RetinalImage.
Provides metrics such as riskScore and heatmapImage.
DiagnosisResult: Generated from the analysis process. Contains the final conclusion (riskLevel, description).
Recommendation: Links to the diagnosis results to provide treatment or healthcare advice (content, severity).
Report: Summarizes the diagnosis results and exports them to a file (PDF/Excel) using the exportReport()
method.
3. Clinic & Services Management Subsystem
Clinic: Manages medical facility information (clinicName, address, verifiedStatus).
Has a relationship with Doctors (doctors working at the clinic).
Methods: Clinic registration (registerClinic), doctor management (manageDoctors).
ServicePackage: Manages user-purchased service packages (e.g., examination packages, AI analysis packages).
Attributes include price, numberOfCredits, and activation/renewal methods (activate, renew).
Payment: Processes financial transactions related to service packages, recording amount, paymentDate, and
status.
4. System Utilities Subsystem
Notification: Sends notifications to users about system status or examination results (sendNotification).
Message: Supports communication (potentially between doctor and patient or through a messaging system),
including content and sent time.
AuditLog: Records important actions for security and review (recordAction), saves action and timestamp.

38
3. Requirement Appendix
3.1 Business Rules

ID Rule Definition
BR-01 A user can be upload a retinal image at a time.

BR-02 A clinic can send image to AI at a time.

BR-03 Each report must have been underatked at least one doctor

BR-04 Email address must be unique across the entire system

BR-05 Password must contain at least 6 characters

BR-06 Once admin accepts an account, they are officially added to the system.

BR-07 Each review stage will have two assigned doctors to provide comments.

BR-08 Students and lecturers can submit project proposals only during the designated
proposal submission periods.
BR-09 When request mentor’s topic, team size of team must be equal to team size of topic

BR-10 Doctor has to give feedback for report after review 3 and 1 week before the defense
1 start
BR-11 Manager has to import defense 1 schedule after review 3 and 1 week before the
defense 1 start
BR-12 Manager has to import defense 2 schedule after review 3 and 1 week before the
defense 2 start
BR-13 When the image size of retinal image to the team size of topic, image will be rejected

39
IV. Software Design Description
1. System Design
1.1 Presentation Layer (Client Layer)

Thành phần:

- Web Client: HTML + CSS + JS, Framework (tailwind/bootstrap)

Chức năng:

- Giao diện cho Người dùng / Bác sĩ / Phòng khám / Admin

- Upload hình ảnh võng mạc

- Hiển thị kết quả AI, chú thích, báo cáo

1.2 API Gateway Layer

Chức năng:

- Xác thực & phân quyền (JWT / OAuth2)

- Điều phối request tới các microservices

- Logging & Monitoring

1.3 Backend Application Layer (Microservices)


1.3.1User Management Service

Quản lý tài khoản

Phân quyền RBAC

Hồ sơ người dùng, bác sĩ, phòng khám

1.3.2Clinic Management Service

Quản lý phòng khám

Quản lý bác sĩ & bệnh nhân

1.3.3Image & Report Service

40
Nhận hình ảnh từ client

Gửi hình ảnh sang AI Core

Lưu kết quả phân tích

1.3.4Notification & Messaging Service

Thông báo khi có kết quả AI

1.3.5Payment & Subscription Service

Quản lý gói dịch vụ

Thanh toán

1.4 AI Core Microservice Layer

Thành phần:

- Model segmentation mạch máu võng mạc

- Model risk prediction (hypertension, diabetes, stroke)

- Explainability module (heatmap, vessel map)

Đặc điểm

Viết bằng Python

Giao tiếp qua REST API

AI Core KHÔNG truy cập trực tiếp database bệnh nhân

1.5 Data Layer (Data & Storage)

Thành phần
Loại dữ liệu Công nghệ

User, Clinic, Payment SQLite


AI metadata, logs SQLite

41
1.6 System Architecture
Layer Components Technologies Port

Client Web Browser TailwindCSS, [Link] Client 8000

Web Server Nginx Reverse Proxy, Load Balancer, SSL/TLS Nginx, Let's Encrypt SSL 443

Application FastAPI Core (60+ endpoints), [Link] (Real- Python 3.9+, FastAPI 0.104+, 8000
time), Background Tasks SQLite, [Link]

Data SQLite (11 tables, 6 modules), Redis Cache SQLite 5432

External AWS Bedrock (AI), Cloudinary (CDN), SMTP AWS SDK, Cloudinary SDK, N/A
(Email) Gmail/SendGrid

1.2. TECHNOLOGY STACK


Frontend Technology Stack
Category Technology Version Purpose

Language JavaScript ES6+ Programming language

Styling Tailwind CSS 4.0+ Utility-first CSS framework

Routing React Router 6.16+ Client-side routing

HTTP Client Axios 1.5+ Making API requests

Real-time [Link] Client 4.5+ WebSocket communication

Form Handling React Hook Form 7.47+ Form validation

Date/Time date-fns 2.30+ Date manipulation

Notifications Notistack 3.0+ Snackbar notifications

File Upload React Dropzone 14.2+ Drag-and-drop file upload

Rich Text Editor Quill / Slate Latest Collaborative editing

Whiteboard Excalidraw / [Link] Latest Drawing canvas

Backend Technology Stack


Category Technology Version Purpose

Language Python 3.9+ Programming language

Web Framework FastAPI 0.104+ Async web framework

ORM SQLite 0.0.12+ Database ORM (based on SQLAlchemy)

Validation Pydantic 2.4+ Data validation

Authentication python-jose 3.3+ JWT token generation

Password Hashing passlib 4.1+ Secure password hashing

Database Driver psycopg2 2.9+ SQLite driver

Migration Alembic 1.12+ Database schema migrations

42
WebSocket [Link] 3.0+ Real-time communication

Email email-validator 2.1+ Email validation

SMTP smtplib Built-in Sending emails

AI Integration gemini-2.5-flash-lite 2.5 AWS SDK for Bedrock

Environment python-dotenv 1.0+ Environment variable management

COMPONENT ARCHITECTURE:

### Backend Components

#### API Router Modules (Endpoints)

- **auth_api_extended.py**: Authentication endpoints

- POST `/api/auth/register` - User registration

- POST `/api/auth/login` - User login

- POST `/api/auth/logout` - User logout

- POST `/api/auth/forgot-password` - Password reset request

- **admin_api.py**: Admin management endpoints

- User management, system administration, monitoring

- **doctor_api.py**: Doctor management endpoints

- Doctor profile, case management, diagnosis operations

- **patient_api.py**: Patient management endpoints

- Patient profiles, medical history, appointment booking

- **clinic_api.py**: Clinic management endpoints

- Clinic information, doctor management, patient records

- **report_api.py**: Report generation endpoints

- Generate, retrieve, export medical reports

- **analysis_api.py**: Medical image analysis endpoints

- Image upload, AI analysis, annotation results


43
#### Core Components

- **[Link]**: FastAPI application entry point

- Router registration, middleware setup, CORS configuration

- Static/template file serving

- **[Link]**: SQLAlchemy ORM models

- `User` - User accounts and authentication

- `Upload` - File upload records

- `Report` - Medical reports

- Additional domain models for clinic, doctor, patient entities

- **[Link]**: Pydantic validation schemas

- `UserRegister` - Registration data validation

- `UserLogin` - Login credentials validation

- DTO (Data Transfer Objects) for API requests/responses

- **[Link]**: Database configuration

- SQLAlchemy engine and session setup

- Database initialization (`init_db()`)

- Session dependency injection (`get_db()`)

- **[Link]**: Application configuration

- Environment variables management

- Database URLs, API keys, JWT settings

- Debug/production settings

#### Authentication & Security

- **[Link]**: Core authentication utilities

- Password hashing (`get_password_hash()`)

44
- Token generation (`create_access_token()`)

- Token verification (`verify_token()`)

- **auth_middleware.py**: Request authentication middleware

- `AuthMiddleware` - Token validation for all requests

- `get_current_user()` - Extract authenticated user from request

- `RoleBasedAccessControl` - RBAC enforcement

#### Utility Modules

- **email_utils.py**: Email service

- Send reset password emails

- Email templates and SMTP configuration

- **file_utils.py**: File handling utilities

- `save_upload_file()` - Save uploaded files to disk

- `delete_upload_file()` - Remove files

- `validate_file_type()` - Check file extensions

- `validate_file_size()` - Enforce size limits

- **gemini_api.py**: Google Gemini AI integration

- AI-powered medical image analysis

- Natural language annotation

#### Database Migrations

- **alembic/** - Database schema versioning

- `[Link]` - Alembic environment configuration

- `versions/` - Migration scripts

- `91c4c52760d6_initial_setup.py` - Initial schema

- `add_block_functionality.py` - Block feature schema

45
- `add_password_reset_model.py` - Password reset schema

### Frontend Components

#### HTML Templates

- **[Link]**: User login interface

- Email/password form, registration link, forgot password link

- **[Link]**: User registration interface

- Role selection (User/Doctor/Clinic), certificate validation

- **user_dashboard.html**: Patient dashboard

- Image upload, analysis history, medical records view

- **doctor_dashboard.html**: Doctor dashboard

- Case list, diagnosis tools, patient communication

- **clinic_dashboard.html**: Clinic management dashboard

- Doctor management, patient records, analytics

- **admin_dashboard.html**: System administration dashboard

- User management, system statistics, monitoring

#### Static Assets

- **static/**: CSS, JavaScript, images

- Tailwind CSS styling

- Frontend JavaScript logic

- Images and icons

### Data Flow Architecture

```

Frontend (HTML/JS)

↓ HTTP Requests

46
Middleware (AuthMiddleware)

↓ Token Validation

FastAPI Main App ([Link])

↓ Route Dispatch

API Routers (auth, doctor, patient, clinic, admin, analysis, report)

↓ Business Logic

Core Utilities (auth, email, file, gemini)

↓ Data Access

SQLAlchemy Models

Database (SQLite/PostgreSQL)

```

### Module Dependencies

```

[Link]

├── imports all routers

├── imports AuthMiddleware

├── imports database utilities

└── imports config

API Routers (e.g., doctor_api.py)

├── depends on [Link]

├── depends on [Link]

├── depends on [Link]

└── may use utilities (auth, email, file, gemini)

47
auth_middleware.py

├── imports [Link]

└── imports [Link]

Other Utilities

├── email_utils.py - uses [Link]

├── file_utils.py - standalone

└── gemini_api.py - uses [Link], [Link]

```

## Features

1. Authentication

- **Register**: Support for 3 user types

- Regular User (Patient)

- Doctor (with practice certificate)

- Clinic (with business registration)

- **Login**: Email and password authentication

- **Token-based**: JWT for secure API calls

- **Forgot Password**: Password reset via email

- **Session Management**: Secure token storage

2. User Dashboards

- **User Dashboard**: Upload retinal images, view analysis results

- **Doctor Dashboard**: Review cases, provide diagnoses, chat with patients

- **Clinic Dashboard**: Manage doctors, patients, reports, and analytics

- **Admin Dashboard**: System administration and monitoring

3. Core Features

48
- Role-based access control (RBAC)

- Image upload and analysis

- AI-powered medical image annotation

- Doctor-patient communication

- Report generation and export

- Analytics and statistics

## API Endpoints

### Authentication Routes

```

POST /api/auth/register - Register new user

POST /api/auth/login - User login

POST /api/auth/logout - User logout

POST /api/auth/forgot-password - Request password reset

```

### Frontend Routes

```

GET / - Home (redirects to login)

GET /login - Login page

GET /register - Registration page

GET /user_dashboard - User dashboard

GET /doctor_dashboard - Doctor dashboard

GET /clinic_dashboard - Clinic dashboard

GET /admin_dashboard - Admin dashboard

```

49
## Configuration

### Password Security

- Passwords are hashed using bcrypt

- Minimum length: 6 characters (customizable)

- Should enforce more strict requirements in production

### JWT Token

- Default expiration: 30 minutes

- Change `SECRET_KEY` in [Link] for production

- Use environment variables for sensitive data

### Database

- Currently uses SQLite for development

- Ready for PostgreSQL/MySQL in production

- Use SQLAlchemy ORM for database operations

### CORS

- Enabled for development (localhost)

- Restrict to specific origins in production

## Development Next Steps

1. **Database Integration**

- Implement SQLAlchemy models for users, patients, doctors, reports

- Create database migrations

2. **Authentication**

- Implement JWT token verification in protected endpoints

- Add role-based access control middleware

3. **User Registration**

50
- Validate business certificates

- Verify practice certificates

- Store user data in database

4. **File Upload**

- Implement image upload and storage

- Add image validation and processing

5. **Email Service**

- Implement password reset email sending

- Add email verification during registration

6. **Medical Image Analysis**

- Integrate AI/ML model for retinal image analysis

- Implement annotation system

- Store analysis results

7. **Reporting**

- Generate PDF reports

- Export data to CSV

- Create analytics dashboards

51
V. Software Testing Documentation
1. Scope of Testing
- Scope:

● Features to be tested:
○ Upload retinal images (Fundus / OCT) and submit them to the AI analysis engine.
○ AI-based retinal vascular analysis and disease risk assessment.
○ Generation of annotated retinal images (heatmaps, highlighted vessels).
○ Display of diagnostic results, risk levels, and explanations.
○ User account management (User, Doctor, Clinic, Admin).
○ Doctor validation and feedback on AI-generated results.
○ In-app communication between users and doctors.
○ Report generation and export (PDF, CSV).
○ Service package management, billing, and usage tracking.
○ Notification system for completed analyses and high-risk alerts.
○ Admin dashboards for system usage, performance, and analytics.
● Features not to be tested:
○ Hardware-level accuracy of retinal fundus or OCT cameras.
○ Clinical outcome validation beyond decision-support purposes.
○ Integration with national EHR systems not included in the project scope.
○ Large-scale stress testing beyond predefined limits.
- Testing Levels:

● Unit Testing:
○ Responsible: Developers.
○ Inputs: Individual components such as image upload module, AI inference service, report
generation service, authentication module.
○ Focus: Correct handling of inputs and outputs. Validation of data processing logic and error
handling.
○ Acceptance Criteria: Each module functions correctly in isolation according to design
specifications.
● Integration Testing:
○ Responsible: Development and QA teams.
○ Inputs: Interactions between system components (e.g., Web Application ↔ AI Core API ↔
Database).
○ Focus: Data flow between image upload, AI analysis, result storage, and visualization. Role-
based access control across User, Doctor, Clinic, and Admin modules.
52
○ Acceptance Criteria: All integrated components communicate correctly. Data consistency and
integrity are preserved across services.
● System Testing:
○ Responsible: QA team.
○ Inputs: Fully deployed system with all modules integrated.
○ Focus: End-to-end workflows (from image upload to report generation). Verification of
functional and non-functional requirements.
○ Acceptance Criteria: The system meets all defined functional requirements (FRs). Performance,
security, usability, and reliability requirements are satisfied.
● Non-Functional Testing:
○ Performance Testing: Validate AI analysis time (10–20 seconds per image) and dashboard
response time (<3 seconds).
○ Security Testing: Verify data encryption, authentication, authorization, and role-based access
control.
○ Usability Testing: Ensure clinicians can complete key tasks (upload, review, validation) within
minimal steps.
○ Reliability Testing: Confirm system stability under continuous operation and proper recovery
from failures.

- Constraints and Assumptions:

● Testing is conducted in a controlled environment with simulated clinical data.


● Maximum testing load includes: Up to 1,000 concurrent users. Up to 100 retinal images per bulk
upload. Assumes stable network connectivity and cloud infrastructure during testing.
● AI diagnostic outputs are evaluated for technical correctness and consistency, not for real-world
clinical diagnosis.

2. Test Strategy
2.1 Testing Types
- Unit Testing:
● Objective: Verify the correctness of individual system modules.
● Technique: White-box testing using automated testing frameworks.
● Scope: Image upload and validation module AI inference logic Risk scoring and report generation
Authentication and authorization services
● Completion Criteria: At least 95% unit test pass rate with no critical defects.

- Integration Testing:
● Objective: Validate interactions between system components.
● Technique: API and interface testing. Scope: Web Client ↔ AI Core Microservice AI Core ↔ Database
Notification service ↔ User/Doctor modules
53
● Completion Criteria: All integration test cases pass with no major functional defects.

- System Testing:
● Objective: Confirm the complete AURA system operates according to specifications.
● Technique: Black-box testing.
● Scope: End-to-end workflow from retinal image upload to report generation Role-based access control
(User, Doctor, Clinic, Admin)
● Completion Criteria: All functional and non-functional requirements are fully satisfied.

- Performance Testing:
● Objective: Assess system behavior under different workloads.
● Technique: Load and stress testing.
● Scope: AI image analysis performance Dashboard responsiveness Bulk image upload processing
● Completion Criteria: AI analysis time ≤ 20 seconds per image System response time < 3 seconds with
up to 1,000 concurrent users

2.2 Test Levels


● Unit Testing: Focuses on isolated components such as image processing, AI prediction, and report
formatting.
● Integration Testing: Covers interactions between the database, AI Core services, and frontend
interfaces.
● System Testing: Validates the complete deployed system against business, functional, and non-
functional requirements.
3. Test Plan
3.1 Human Resources

● Test Lead: Responsible for planning, coordinating, and monitoring all testing activities.
● Test Engineers: Execute manual and automated test cases, log defects, and verify fixes.
● Developers: Perform unit testing, fix detected bugs, and support integration testing.

3.2 Test Environment

● Software: Docker, Jest, SonarQube, Selenium, Postman.


● Hardware: Servers with minimum 16 GB RAM, multi-core processors.
● Infrastructure: Staging environment replicating production setup.

54

You might also like