ConceptioArchiveNCBI PubMed Central
NCBI PubMed Centralopen access

Reversible data hiding for electronic patient information security for telemedicine applications.

Muhudin A et al. · ncbi_pmc
NCBI PubMed Central · Papers · License: Open Access
Open Source ↗Direct PDF ↓
cryptographysecurity
cryptography security

Skip to main content An official website of the United States government Here's how you know Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Log in Dashboard Publications Account settings Log out Search… Search NCBI Primary site navigation Search Logged in as: Dashboard Publications Account settings Log in Search PMC Full-Text Archive Search in PMC Journal List User Guide PERMALINK Copy As a library, NLM provides access to scientific literature. Inclusion in an NLM database does not imply endorsement of, or agreement with, the contents by NLM or the National Institutes of Health. Learn more: PMC Disclaimer | PMC Copyright Notice Sci Rep . 2026 Feb 25;16:8381. doi: 10.1038/s41598-026-39512-5 Search in PMC Search in PubMed View in NLM Catalog Add to search Reversible data hiding for electronic patient information security for telemedicine applications Adam Muhudin Adam Muhudin 1 Department of Computer Science, Faculty of Computing, SIMAD University, Mogadishu, Somalia Find articles by Adam Muhudin 1, ✉ , Osman Diriye Hussein Osman Diriye Hussein 2 Department of Telecommunications, Faculty of Engineering, SIMAD University, Mogadishu, Somalia Find articles by Osman Diriye Hussein 2 , Abdullahi Mohamud Osoble Abdullahi Mohamud Osoble 1 Department of Computer Science, Faculty of Computing, SIMAD University, Mogadishu, Somalia Find articles by Abdullahi Mohamud Osoble 1 , Jayanta Mondal Jayanta Mondal 3 School of Computer Engineering, KIIT University, Bhubaneswar, India Find articles by Jayanta Mondal 3 Author information Article notes Copyright and License information 1 Department of Computer Science, Faculty of Computing, SIMAD University, Mogadishu, Somalia 2 Department of Telecommunications, Faculty of Engineering, SIMAD University, Mogadishu, Somalia 3 School of Computer Engineering, KIIT University, Bhubaneswar, India ✉ Corresponding author. Received 2025 Dec 26; Accepted 2026 Feb 5; Collection date 2026. © The Author(s) 2026 Open Access This article is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License, which permits any non-commercial use, sharing, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if you modified the licensed material. You do not have permission under this licence to share adapted material derived from this article or parts of it. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons.org/licenses/by-nc-nd/4.0/ . PMC Copyright notice PMCID: PMC12972314  PMID: 41741530 Abstract Telemedicine workflows require the secure transmission of medical images while preserving diagnostic integrity. We propose a Reversible Data Hiding in Encrypted Images (RDH‑EI) scheme tailored for telemedicine that couples (i) a Generation of Encryption Parameters (GEP) mechanism to derive per‑block embedding controls from a data‑hiding key and (ii) a two‑level Least Significant Bit (LSB) strategy that provides separable payload extraction and exact image recovery. Images are first encrypted using AES‑CTR with a unique nonce; GEP then produces block‑wise traversal orders, offsets, and parity masks used by Phase‑1 (odd blocks, parity‑of‑triples) and Phase‑2 (even blocks, serialized side‑information). The method supports three operating modes: payload‑only extraction, decrypt‑only viewing, and full, bit‑exact recovery when both keys are available. On a 90‑image test set (30 X‑rays, 30 MRIs, 30 CTs, all 512 × 512), the proposed approach achieves higher quality on directly decrypted images than representative baselines at Z = 16: PSNR 39.92 ± 0.41 dB (X‑ray), 37.78 ± 0.38 dB (MRI), and 38.27 ± 0.36 dB (CT), with SSIM 0.9784 ± 0.0021, 0.9694 ± 0.0023, and 0.9835 ± 0.0018, respectively. The recovered images are bit‑exact (PSNR = ∞). Encryption robustness is supported by near‑maximal entropy, high NPCR (> 99%), and UACI near 33%. These results indicate that the proposed GEP‑driven, two‑level embedding improves the payload–distortion trade‑off while retaining strict reversibility, making it suitable for secure medical‑image sharing in telemedicine. Keywords: Reversible data hiding, Encrypted images, Telemedicine security, Medical imaging, LSB embedding, AES‑CTR Subject terms: Computational biology and bioinformatics, Engineering, Health care, Mathematics and computing, Medical research Introduction Rapid improvements in the field of health informatics have transformed face-to-face medical care in remote consultation, popularly known as telemedicine 1 . Consequently, a very serious necessity with respect to keeping such patients’ information is placing great demands on privacy with no parallels earlier 2 . Telemedicine, the subject perhaps forced into acceleration by the recently heightened world health needs which holds out tremendous promise to advance greater accessibility and efficiency within limited resource systems in the delivery of care 3 . It has also been proven to reduce the burden on patients attending health facilities, remote monitoring, and enhancing the continuity of care for chronic conditions 4 . This development does not come without a number of significant challenges 5 ; the most important among these is data security and privacy 6 . Personal information regarding patients is to be protected for confidentiality and integrity at all costs 7 , since the consequences of medical data breaches might come as far as unauthorized access to health records 8 , identity theft 9 , and even threats to the lives of the patients 10 . In this context, reversible data hiding (RDH) has emerged as a promising method for enhancing the security of telemedicine applications 11 . RDH techniques will allow healthcare providers and associated systems to reversibly embed critical information, such as authentication codes or diagnostic data, within patient files 12 . This implies that the host data can be completely restored after extraction 13 . This property is vital in medical images and records, where minor changes may alter the clinical interpretation 14 . RDH provides a different concept than other data hiding techniques in preserving data integrity and allowing the hiding of confidential data 15 . Unlike existing encryption methods 16 , which, if applied, might raise some suspicions toward hidden information, RDH offers unobtrusive and safe embedding; hence, RDH has become an optimum choice for medical applications that call for both security and imperceptibility 17 . The importance of RDH in telemedicine is that it includes a large set of digital medical data such as images, text, and other records that are necessary for diagnosis, treatment, and follow-up 18 . In telemedicine applications, medical images are generally transmitted across different platforms, often among various health facilities, specialists, and even across international borders 19 . Because of the importance of real data in medical applications, RDH provides a secure method to hide auxiliary information into images without destroying diagnostic utility related to the original data, especially for fulfilling medical healthcare regulations that require the data to be protected, including laws by Health Insurance Portability and Accountability Act (HIPAA) in the USA, General Data Protection Regulation (GDPR) in Europe, and elsewhere 20 . These regulations not only provide the responsibility of protecting the information of patients but also impose accountability on healthcare providers to ensure that patients’ data are not misused and not made accessible to unauthorized persons 21 . In this context, this type of data can be protected from tampering by applying RDH whereas medical practitioners can still view and exploit the original data in its initial form at any point if needed 22 . It allows for the consideration of both protective sensitive patient information and medical utilization of data into account 23 . In addition to the integrity of data, RDH introduces a certain degree of flexibility that allows the application of watermarking techniques, thereby increasing traceability and accountability within the domain of telemedicine 24 . Practical applications of RDH in the telemedicine domain are endless and involve authentication and validation of data, protection of patient privacy, and secure sharing of data 25 . However, the integration of RDH into telemedicine systems presents some challenges, which are fundamentally related to computational overhead and incompatibility with existing medical imaging formats and infrastructure 5 . In real time health care applications, such as remote monitoring or emergency teleconsultation, the reversible data-hiding approach should be adequately efficient to guarantee minimum latency without compromising data security 9 . Therefore, there is an increasing interest in optimized RDH algorithms that can balance computational requirements with effectiveness in security, so that telemedicine services can retain both security and responsiveness 19 . In addition, RDH systems must be designed to support a wide range of digital medical record formats and imaging technologies to allow seamless integration with various telemedicine platforms 4 . If not well addressed, compatibility issues could be a major hindrance to the widespread adoption of RDH-based security solutions in the healthcare sector 2 . Literature review Reversible Data Hiding (RDH) has been widely studied as a solution to hide additional information in digital images with the goal of perfectly recovering the original image. In medical imaging, RDH plays a critical role in ensuring the integrity, authenticity, and confidentiality of unaltered medical images. The literature on RDH in medical images and RDH in Encrypted Images (RDH-EI) will be briefly reviewed, with the latest research focusing on the capacity-distortion- complexity trade-off and integrity-oriented applications. Reversible data hiding for medical images (plaintext domain) Early methods of RDH in medical images mainly worked in the plaintext domain. Gomathi et al. 4 described the use of authenticated medical image transmission based on an enhanced RDH with rhombus prediction and the NNP2 algorithm. This study provides good visual quality and the ability to check for tampering. These methods demonstrate that embedding authentication information is possible. Because embedding occurs in the plaintext domain, confidentiality is not guaranteed. Recent studies in the watermarking domain further emphasize the importance of reversible embedding in the context of image integrity and recovery. Sahu and Sahu 26 proposed a hybrid fragile image watermarking method that supports tamper evidence, localization, and simultaneous self-recovery with excellent perceptual quality using transform domain embedding. Similarly, Sahu et al. 27 proposed a dual-image reversible fragile watermarking method that supports the embedding of multiple bits per pixel with accurate tamper evidence. In summary, these approaches efficiently address the challenges in image authentication and recovery; however, they target plaintext images, which do not consider the importance of encrypted domain embedding or separable data extraction in secure telemedicine applications. Reversible data hiding in encrypted images (RDH-EI) To address the issue of confidentiality, reversible data hiding in encrypted images (RDH-EI) has attracted considerable attention. Shiu et al. 1 presented an RDH-EI method using difference expansion and public-key cryptography, which makes it possible to embed data into encrypted images with reversibility. This study provides a theoretical foundation for separable RDH-EI systems, in which data retrieval and image decryption are independent. Motomura et al. 5 furtherd researched on Reversible Data Hiding in Encrypted Images by introducing a technique to address the trade-off between hiding capacity and compression ratio. While their finding offers flexibility to control the trade-off between the payload and bitrate, it also increases the computational complexity introduced by compression processing. Recently, to address the low hiding capacity of RDH-EI for encrypted medical images, Chai et al. 28 suggested an efficient high-capacity RDH-EI scheme based on adaptive pixel modulation and HBP-RMC. Recently, a reversible data hiding scheme in encrypted images with secure multi-party computation was introduced for telemedicine applications, focusing on collaborative data embedding and extraction without exposing image content in untrusted environments 29 . The method demonstrates the feasibility of integrating RDH-EI with multi-party security mechanisms for protecting electronic patient information during transmission and storage. Although their approaches are effective, they generally incur higher computational costs. Histogram shifting and difference expansion-based RDH-EI methods Difference expansion (DE) and histogram shifting (HS) are the two most popular methods in RDH-EI due to their good rate-distortion performance. Wang et al. 2 introduced an optimal method based on multiple histogram shifts, which significantly improved embedding efficiency with acceptable image quality. However, the use of multiple histogram shifts increases the complexity and has to be handled very carefully. Shetty et al. 3 attempted to integrate difference expansion and histogram shifting in to an encrypted image to enhance the embedding capability and quality of the decrypted image. This hybrid solution not only improves the efficiency of the process, but also suffers from the disadvantages of multi-pass processing, which are not present in the individual techniques of difference expansion and histogram shifting. Surveys and foundational studies Apart from algorithmic developments, survey and review works also provide important insights into reversible embedding and watermarking methods. Sahu et al. in their work 30 presented a comprehensive survey on image watermarking methods using traditional and machine learning techniques, and presented methods in the spatial and transform domains based on tradeoffs among robustness, imperceptibility, and computational complexity. Although survey and review work provide important insights into reversible embedding methods, they neither provide information on encrypted domain embedding nor the reversibility constraints that are necessary in the secure transmission of medical images. Recent studies have explored secure signal and image processing methods in the context of medicine and telemedicine applications. Hybrid fragile and robust watermarking methods have been proposed to enable tampering identification, location, and recovery in medical images, emphasizing integrity protection in the encrypted domain and reversible data hiding 31 , 32 . Other researchers have also ventured into more sophisticated image encryption methods based on chaotic maps and bio-inspired coding to further improve confidentiality 33 . Although these works are beneficial for securing medical image processing in a different and complementary manner, they do not provide solutions to the problem of reversible data hiding in encrypted images in terms of strict separability and exact recovery or target RDH-EI in medical images. Overall, the existing RDH and RDH-EI methods have achieved notable progress in improving the embedding capacity, decrypted-image quality, and integrity verification. Nevertheless, several challenges remain, including balancing the high payload capacity with low distortion, reducing computational overhead, and ensuring clear separability between encryption and data-hiding operations. In particular, many RDH-EI schemes rely on prediction, histogram construction, or adaptive optimization, which increases the complexity and complicates side-information management. These limitations motivated the proposed GEP-driven two-level RDH-EI scheme, which aims to provide a balanced solution with high payload efficiency, low computational overhead, strict reversibility, and suitability for secure telemedicine applications. Recently, Sahu and Sahu 26 proposed a hybrid fragile watermarking method for medical images that allows for the detection, localization, and dual self-recovery of tampered images in the plaintext domain. This method shows promising imperceptibility and recovery capabilities for integrity verification of images; However, it only works with images in the plaintext domain and does not support reversible data hiding with separable access, as discussed in the proposed method, which focuses on reversible data hiding with separable access in the encrypted domain for secure transmission of images without exposing the content of images during the process of data hiding or transmission. Despite advances made in the field of reversible data hiding (RDH) and reversible data hiding in encrypted images (RDH-EI), several drawbacks exist, particularly for telemedicine applications. In many existing RDH-EI schemes, the capacity of an image is often prioritized at the expense of the decrypted image quality. In many cases, the schemes are computationally expensive due to the complex prediction and histogram operations. In recent years, many image security schemes in the medical domain have focused on fragile or robust watermarking of plaintext images, which do not provide confidentiality during transmission. In addition, it is observed that the existing RDH-EI methods are challenged by difficulties in achieving a high payload capacity, high-quality decrypted images, and low computational complexity simultaneously under a unified platform. This inspired the proposed GEP-driven two-level embedding method, which aims to overcoming these challenges by achieving high-capacity embedding in the encrypted domain with exact recovery and high computational efficiency. Proposed method Image encryption and data hiding have emerged as two important strategies that help avoid unauthorized access to digital images. The approach in this paper aims at improving data security by optimizing the embedding capacity of additional data while simultaneously encrypting images, thus providing robust protection with efficient usage of storage space. Beyond encryption, data hiding has been an added important layer of security in embedding the data within images covertly. Unlike prior RDH-in-encrypted-image (RDH EI) methods that either (i) reserve room before encryption (RRBE) or (ii) rely solely on histogram shifting/difference expansion within the encrypted domain, our method introduces a two-part contribution that improves payload accounting, guarantees exact reversibility, and clarifies the security interface between encryption and data-hiding. GEP-Driven Per Block Parameterization. We define a Generation of Encryption Parameters (GEP) mechanism that derives per-block parameters from a master key and public nonce. GEP produces a deterministic but pseudo-random parameter set that is used for block partitioning, embedding order, and parity masks. This yields (a) block-wise key diversity (hardening against structured attacks on encrypted content) and (b) reproducible control signals for embedding/extraction without leaking the encryption key to the data hider. Two Level Leas Significant bit (LSB) Embedding with Explicit Side Information Accounting. We formalize a two-phase embedding scheme on the encrypted image IE: Phase 1 (odd blocks): Embed payload using 3 LSB parity coding that changes at most one bit per three LSB tuples, maximizing payload-to-distortion. Phase 2 (even blocks): Store all side information needed to reverse Phase 1 (modification flags and original three LSB tuples for modified groups), along with a compact header. This makes the reversibility conditions explicit and verifiable. Together, the phases maintain separability: a holder of the data hiding key can extract payload from I E without decrypting; a holder of the encryption key can decrypt to a visually meaningful image; a holder of both can restore the original image bit exactly. Empirically, this design supports higher payloads at comparable or lower distortion while meeting strict reversibility and auditability requirements. It also standardizes the crypto interface by recommending a stream cipher (e.g., AES CTR) with clear key/nonce handling, replacing ad hoc XOR. Preliminaries Let: I: Original 8-bit grayscale image of size H × W. Z: Block size (Z × Zpixels per block). B: ⌊H/Z⌋⋅⌊W/Z⌋ Number of blocks indexed b = 0,…,B − 1. K E : Encryption key (stream cipher). K H : Data-hiding key (GEP seed). N: Public nonce per image. I E : Encrypted image. P: Payload bitstream. R b is a pseudo-random permutation of pixel indices inside block b. Only K h and N are needed for GEP reproduction; KE remains secret for decryption. Cover image encryption The proposed technique involves three steps, starting with the Cover Image Encryption phase. In this initial phase, a secure encryption algorithm is applied to the cover image such that its content remains confidential and inaccessible to unauthorized users. This encryption procedure converts an image into an unreadable format for the main purpose of security and protecting it from interception and tampering. After encryption, the embedding phase involves embedding additional confidential data into an encrypted cover image. Using this encrypted image as a container, the hidden data are protected from direct access, thereby offering an extra layer of protection. This RDH scheme introduces a proposed architecture for secure encryption, efficient embedding, and recovery of sensitive electronic patient information in telemedicine applications. It comprises both the encryption and decryption phases as illustrated in Fig. 1 . The encryption phase first encrypts the original image with a robust encryption algorithm using an encryption key to ensure the confidentiality of medical data. Fig. 1. Open in a new tab The proposed architecture. Additional data are subsequently embedded in the encrypted image using the GEP algorithm, which is followed by an LSB embedding technique for a grayscale layer to achieve high capacity and imperceptibility. It also enables the extraction of three flexible cases during the decryption phase: embedded data extraction without decryption, decryption without embedded data access, and full data extraction with image recovery. It was developed considering the tough requirements for protecting sensitive medical data transmission under strong privacy regulations such as HIPAA and GDPR: highly secure, completely reversible, and minimal distortion. The novelty of this approach lies in the data-embedding process, in which two different embedding strategies are applied to different image blocks. The overall interaction among the content owner, data hider, and receiver, along with the encryption, embedding, extraction, and recovery stages, is illustrated in Fig. 2 . Fig. 2. Open in a new tab Flowchart of the proposed scheme. Proposed RDH architecture: step-by-step process Actors I. Content Owner/Doctor: Holds the encryption key K E and is responsible for image encryption and/or decryption. II. Data Hider/Telemedicine Service: Hold the data-hiding key K H and performs payload embedding or extraction without accessing the plaintext image. III. Receiver: May hold K E , K H , or both, enabling decryption, payload extraction, or full recovery. Communication steps I. Image Encryption The content owner encrypts the original image I using AES-CTR with K E ​ and nonce N to produce I E and then nonce N is stored with the image metadata for subsequent decryption. II. Data Embedding The data hider derives per-block embedding parameters (s b , r b ,m b , and q b ) using GEP with K H ​ and N and then Two-level LSB embedding is applied to I E to produce the embedded-encrypted image I EMB ​. III. Transmission I EMB ​and the nonce N are transmitted over the network to the receiver. IV. Reception and Processing Data-only receiver (K H only): This uses GEP to extract the payload P without decryption. Decrypt-only receiver (K E only): This uses AES-CTR to recover a visually usable image without payload access. Full-access receiver (K E and K H ): Recovers both P and the original image I bit accurately. Generation of encryption parameters (GEP)-algorithm R b is a pseudo-random permutation of pixel indices inside block b. Only K h and N are needed for GEP reproduction; KE remains secret for decryption. The steps of generation of encryption parameters (GEP)-algorithm are as follows: Encrypted image is divided into non-overlapping blocks of size Z x Z. A pseudo-random permutation of the pixel locations is produced for every block with the key K N . Block specific embedding parameters (s b , m b , b b ) are calculated and retained. These parameters are later used for embedding and extraction processes without requiring image decryption. Two-level LSB embedding-algorithm The proposed two-level LSB method works in two steps : Phase 1 The secret data are embedded into odd-indexed blocks using GEP-controlled LSB substitution. Phase 2 The side information necessary for exact recovery is incorporated into the even-indexed blocks. This two-step procedure ensures strict reversibility and enables high embedding capacity and separable data extraction. To ensure perfect reversibility, we first embed the original least significant bits (LSBs) of the even-numbered blocks before embedding any information. In other words, before embedding the message into these blocks, we extracted their original LSB values and embedded them into odd-numbered blocks in the first embedding round using the two-level LSB method controlled by GEP. During the extraction process, we first extracted side information from the odd-numbered blocks and used it to recover the original LSBs of the even-numbered blocks. Thus, both the message and the original image can be extracted perfectly. The reversibility process can be summarized as follows: The original LSBs of the even-numbered blocks are saved as side information prior to embedding. Side information is embedded into odd-numbered blocks together with the payload. During extraction, the side information is recovered first and used to restore the original LSBs of the even-numbered blocks. The proposed method does not claim originality in terms of the individual cryptographic and data hiding techniques that it uses, such as AES-based encryption and LSB substitution, as these have been well-established techniques in the literature. Rather, the originality of this work lies in its ability to integrate a parameter control mechanism based on GEP with a two-level embedding strategy to address the issues of reversible data hiding in encrypted images. This is because it provides a framework for handling issues such as embedding parameters, side information, and separable access associated with images that are encrypted. This is where the real contribution of this study lies. Capacity condition where C even ​ is the total number of even-block pixels available for 1-LSB embedding. Encryption and security model Encryption phase We used AES-CTR for image encryption because of its proven security and reversibility. Encryption key K E : 256-bit, unique to the content owner. Nonce N: 96-bit, unique per image, stored with metadata. Keystream : KS=AES_CTR(K E ,N) Cipher image : I E =I⊕KS (bytewise XOR). In the proposed scheme, AES-CTR is employed for image encryption due to its efficiency and reversibility. A public nonce N is generated uniquely for each image and combined with the encryption key K E to produce the keystream. The nonce N is not required to be secret and can be safely stored or transmitted as image metadata. It is well known, reuse of the same nonce key pair in CTR mode can lead to keystream reuse and compromise confidentiality; therefore, nonce uniqueness per encrypted image is strictly enforced. In practical telemedicine systems, this requirement can be satisfied by deriving N from unique image identifiers, timestamps, or secure counters managed by the content owner or imaging system, thereby preventing nonce reuse across transmissions. The key management analysis in this study assumed the best practices for key management in telemedicine applications. In particular, it is assumed that the encryption key KE is generated and distributed only to authorized medical staff, whereas the other key KN associated with GEP is distributed to data hiders and extractors based on established access control policies. The public parameters of the AES-CTR mode do not need to be kept confidential. The attack scenarios involve unauthorized tapping of encrypted image channels, any form of payload tampering, and replay attacks. These are addressed by encrypted domain embedding, reversibility, and separable access control in the new scheme. Compromise attacks on keys or endpoint security are assumed not to be within the purview of this research. Generation of encryption parameters (GEP) A separate data-hiding key K H drives GEP to produce per-block parameters (s b ,r b ,m b , and q b ) controlling the embedding order, offsets, and parity masks. K E and K H are independent, and enable separable encryption and embedding. Threat model Adversary: Full access to I EMB , knows algorithms, may hold zero, one, or both keys. Goals: Image confidentiality without K E . Payload confidentiality without K H . Perfect reversibility with both keys. Separability for single-key holders. The embedded payload is extracted in a lossless manner prior to image decryption, ensuring that both the secret data and the original medical image are recovered exactly. The proposed scheme is secure against the most common types of attacks that can be launched against images in telemedicine systems. Unauthorized access to the image data was prevented using the AES-CTR mode of operation. The data are encrypted, thus keeping them secure during transmission. Data embedding is performed in the encrypted domain. Thus, an unauthorized party cannot extract any information about the image or data embedded in the image. An unauthorized party cannot modify the data because the data are extracted in the reversible domain. The separable access control ensures that the data are not extracted and the image is not decrypted by an unauthorized party. An unauthorized party cannot gain access to data or images using the proposed scheme. The proposed scheme is secure against the following types of attacks: unauthorized access of the image data, data tampering, and data replay. The proposed scheme is not secure against the following types of attacks: unauthorized access of image data using the decryption key, unauthorized access of image data using the data extraction key, and unauthorized access of image data using the separable access control system. Experimental analysis The proposed method was evaluated on 90 test images (30 X-ray, 30 MRI, and 30 CT images) drawn from publicly available medical imaging datasets. All results reported in this section were computed over the entire 90-image set and are expressed as mean ± standard deviation unless stated otherwise. For a visual illustration, we present the results for three representative images as shown in Fig. 3 , and the corresponding original, encrypted, embedded-encrypted, decrypted, and fully recovered images are presented in Figs. 4 , 5 and 6 . These examples are intended to demonstrate visual quality; however, statistical conclusions were drawn from the full dataset. The tables report the aggregate performance for all images, whereas the payload–distortion plots summarize the trade-off between embedding capacity and image quality across the complete test set. Fig. 3. Open in a new tab Test images: (1) X-ray, (2) MRI, (3) CT. Fig. 4. Open in a new tab The experimental phase of the X-ray image. Fig. 5. Open in a new tab The experimental phase of the MRI scan image. Fig. 6. Open in a new tab The experimental phase of the CT scan image. Evaluation matrices The following section presents the mathematical equations for the fundamental evaluation indicators used in RDH-based approaches for measuring image quality. Peak signal-to-noise ratio (PSNR) Determines the ratio of the noise caused by encryption to the maximum possible pixel value, which is typically 255 for 8-bit images. Good quality images (less noise) is indicated by a higher PSNR. Structural similarity index (SSIM) Examines the structural parallels between the encrypted and real images. It looks at the structure, contrast, and brightness. Better perceptual quality is indicated by a higher SSIM (photos appear more identical). In terms of data hiding capacity, the proposed method enhances the data hiding capacity by embedding additional data into the least significant bits (LSBs) of the encrypted image using a two-level approach. The odd-numbered blocks are first modified, followed by the even-numbered blocks, thereby increasing the data payload without significantly distorting the image. This ensures both high capacity and image quality, while encryption protects hidden data from unauthorized access, making it ideal for secure telemedicine applications. Number of pixel change rate (NPCR) The percentage of pixels that differ between two encrypted images when a single bit in the original image or encryption key is changed is evaluated. Our method consistently produced NPCR values above 99%, indicating that even the smallest change in the input causes widespread pixel alterations in the cipher image. This high sensitivity directly supports our finding that encryption is robust against differential attacks and ensures data confidentiality in telemedicine. Unified average changing intensity Quantifies the average change in pixel intensity between two encrypted images. The proposed scheme achieved UACI values near the ideal of 33%, confirming that the changes are uniformly distributed across the cipher image. This complements the high NPCR and entropy results, reinforcing our finding that the encryption output is highly unpredictable and resistant to statistical and differential analyses. Entropy Measures the statistical randomness of the pixel values in an image. In the proposed method, the encrypted images achieve entropy values close to 8 bits/pixel, which is the theoretical maximum for an 8-bit image. This confirms that the cipher images have a uniform pixel intensity distribution, leaving no exploitable statistical patterns, which aligns with our finding that the encryption stage effectively conceals both the cover image and embedded data from unauthorized analysis. Computational overhead analysis Let N = H × W denote the total number of pixels in the image. In the proposed scheme, AES-CTR encryption operates in linear time O(N) through a single byte wise XOR per pixel. The Generation of Encryption Parameters (GEP) mechanism generates block-wise parameters once per block, resulting in a complexity of O(B), where B = N/Z 2 ; for a fixed block size Z, this term is linear with respect to N. The two-phase LSB embedding process performs a single traversal of the encrypted image, thereby yielding an additional O(N) cost. Consequently, the overall computational complexity of the proposed method is O(N). In contrast, many RDH-EI schemes based on difference expansion and histogram shifting require multiple predictions, histogram construction, and shifting passes, leading to a higher effective complexity commonly expressed as O(kN), where k > 1 denotes the number of processing passes. The analysis shows that the computational overhead imposed by the two-level embedding scheme driven by GEP is minimal and that scalability in practical telemedicine applications can be maintained. Table 1 reports the PSNR values for the directly decrypted and fully recovered images across different medical imaging modalities. Table 1. PSNR (dB) for directly decrypted and recovered images. (Mean ± SD over 30 images per modality; three representative examples are shown the in Figs. 4 , 5 , 6 ). Images Directly decrypted image Recovered image X-ray 39.92 ± 0.41 ∞ (lossless) MRI 37.78 ± 0.38 ∞ (lossless) CT 38.27 ± 0.36 ∞ (lossless) All 38.66 ± 0.87 ∞ Open in a new tab Table 2 reports the Structural Similarity Index (SSIM) values for directly decrypted and fully recovered images across different medical image modalities. Table 2. SSIM for Directly Decrypted and Recovered Images (Mean ± SD over 30 images per modality; three representative examples are shown in the Figs. 4 , 5 , 6 ). Images Directly decrypted image Recovered image X-ray 0.9784 ± 0.0021 0.9993 MRI 0.9694 ± 0.0023 0.9989 CT 0.9835 ± 0.0018 0.9948 All 0.9771 ± 0.0060 0.9984 Open in a new tab Table 3 compares the PSNR and SSIM performance of the proposed method with those of representative RDH-EI approaches for decrypted images at block size Z = 16 across different medical image modalities. Table 3. PSNR (dB) and SSIM for Decrypted Images (Block Size Z = 16). Block Size Method X-ray MRI CT All Modalities PSNR 1 33.98 ± 0.42 34.83 ± 0.39 35.68 ± 0.37 35.56 ± 0.71 2 37.08 ± 0.39 35.88 ± 0.36 36.58 ± 0.34 36.51 ± 0.64 3 38.18 ± 0.35 36.78 ± 0.33 37.68 ± 0.31 37.55 ± 0.60 Proposed 39.92 ± 0.41 37.78 ± 0.38 38.27 ± 0.36 38.66 ± 0.87 SSIM 1 0.9620 ± 0.0024 0.9507 ± 0.0027 0.9584 ± 0.0020 0.9570 ± 0.0052 2 0.9682 ± 0.0021 0.9568 ± 0.0025 0.9641 ± 0.0018 0.9630 ± 0.0044 3 0.9726 ± 0.0019 0.9609 ± 0.0022 0.9690 ± 0.0016 0.9675 ± 0.0039 Proposed 0.9784 ± 0.0021 0.9694 ± 0.0023 0.9835 ± 0.0018 0.9771 ± 0.0060 Open in a new tab The block size Z = 16 was selected empirically, as it provides a practical trade-off between embedding capacity, decrypted-image quality, and computational efficiency, which is consistent with common design choices in RDH-EI schemes. Table 4 presents a detailed comparison between the proposed RDH-EI scheme and some baseline schemes in terms of payload capacity, quality of decrypted images (mean ± standard deviation over all test images), and computational complexity for a block size of Z = 16. It can be seen from this table that the proposed RDH-EI scheme achieves the maximum PSNR and SSIM values along with a high payload capacity and less computational complexity compared to some existing RDH-EI schemes. Table 4. Comparison of RDH-EI methods for medical images (Z = 16). Method Payload capacity PSNR (db) SSIM Computational complexity 1 Low (≤ 0.5 bpp) 35.56 ± 0.71 0.9570 ± 0.0052 Moderate 2 Moderate (≈ 0.6–0.8 bpp) 36.51 ± 0.64 0.9630 ± 0.0044 Moderate–High 3 High (≈ 0.8–1.0 bpp) 37.55 ± 0.60 0.9675 ± 0.0039 High Proposed Method High (≥ 1.0 bpp) 38.66 ± 0.87 0.9771 ± 0.0060 Low–Moderate Open in a new tab The experimental results confirm that the proposed method guarantees strict reversibility, and achieves lossless recovery of both the embedded data and original image across all test cases. To quantitatively assess the statistical significance of the observed quality improvements, a paired two-tailed t-test was performed on the PSNR and SSIM metrics of the images in the test set, where the images were decrypted directly. The proposed method was compared with the RDH-EI baseline methods using the same testing protocols. In all cases, the p -values were found to be well below the 0.05 significance threshold ( p < 0.01 in most cases), which suggests that the quality improvements observed in the decrypted images were statistically significant. Statistical testing was not performed on the recovered images, because the reconstruction process was lossless. The ablation study on the proposed method in Table 5 compares the individual contributions of the GEP process and two-level embedding strategy under the same experimental conditions (Z = 16). When two-level LSB embedding is employed without GEP, reversibility can be maintained at moderate payloads. However, the absence of adaptive coordination among the embedding parameters results in noticeable quality degradation in the recovered image. When GEP is used alone with single-level embedding, the exact recovery is preserved only at reduced payloads, and the limited embedding flexibility leads to pronounced quality loss. In contrast, the proposed method which jointly employs GEP and two-level embedding achieves a high payload capacity with high decrypted-image quality and exact recovery. These ablation results confirm that combining both components is necessary to achieve a favorable rate–distortion–capacity trade-off for secure medical image transmission. Table 5. Analytical ablation of GEP and two-level embedding at (Z = 16). Variant GEP Two-Level Embedding Decrypted-Image Quality (PSNR / SSIM—relative) Payload Capacity Exact Recovery Computational Overhead Proposed method Y Y High visual fidelity (38.66 ± 0.87 db/0.9771 ± 0.0060) High (≥ 1.0 bpp) Yes (high payload) Low–moderate Two-level LSB only N Y Noticeable quality degradation due to non-adaptive parameter selection Moderate (≈0.7–0.9 bpp) Yes (moderate payload) Low GEB only Y N Pronounced quality loss caused by reduced embedding flexibility Moderate (≤ 0.7 bpp) Yes (reduced payload) Low Open in a new tab Figure 7 compares the PSNR performance of the proposed method with that of representative RDH-EI approaches across different medical image modalities for block size Z = 16. Fig. 7. Open in a new tab Comparison of PSNR values across modalities for block Z = 16. “Modality” refers to the type of medical image: X-ray, MRI, or CT. “All” denotes the mean ± standard deviation computed over the complete set of 90 test images (30 from each modality). Figure 8 compares the SSIM performance of the proposed method with representative RDH-EI approaches across different medical image modalities for a block size of Z = 16. Fig. 8. Open in a new tab Comparison of SSIM values across modalities for block Z = 16. Figure 9 shows the security performance of the encrypted images in terms of entropy, NPCR, and UACI across different medical imaging modalities. Fig. 9. Open in a new tab Security metrics for encrypted images across modalities (mean ± SD over 30 images per modality). In clinical practice, the quality of the decrypted image is sufficient for preserving the required information. The values above 38 dB and close to 0.98 SSIM index values reveal that there is excellent structural similarity between the original and decrypted images, and this proves that the essential anatomical information is well preserved. Because this scheme provides perfect recovery after data extraction, no distortion is added to the medical images. This is essential in telemedicine applications, where the integrity of the diagnosis should be preserved while allowing secure embedding and transmission. Although clinical validation is not covered in this work, the experimental results prove that the proposed scheme is suitable for secure medical image communication. Conclusion We presented a GEP‑driven RDH in Encrypted Image scheme that enables separable payload extraction and exact image recovery for telemedicine images. Using AES‑CTR encryption and a two‑phase LSB embedding (parity‑of‑triples plus serialized side‑information), the method improves quality on directly decrypted images versus established baselines while guaranteeing lossless restoration (PSNR = ∞). Across 90 images spanning X‑ray, MRI, and CT, we observed consistent gains in PSNR/SSIM at Z = 16, with security metrics (entropy, NPCR, and UACI) indicating strong resistance to statistical and differential analysis. Limitations and future work Although the proposed method, shows promising results, it also has several of limitations. First, the proposed scheme was used for reversible data hiding in the encrypted images. It does not specifically handle lossy compression or geometric attacks, which are sometimes problematic in image transmission. Second, the proposed scheme used a fixed block size. Although this results in a good balance between the data capacity and quality of the image, using an adaptive block size could lead to further performance improvements. Third, the proposed scheme focuses on image quality metrics. It does not involve clinical validation of the proposed scheme by a medical practitioner. Future research could be carried out on the proposed scheme to further improve its robustness, selection of the block size, and clinical validation of the proposed scheme. Acknowledgements The authors would like to thank and extend their heartfelt gratitude to SIMAD University for their continuous support throughout this research project. Their provision of resources and encouragement has been instrumental in the successful completion of this work Author contributions Adam Muhudin: Conceptualization, methodology, software, validation, investigation, data curation, formal analysis, visualization, writingoriginal draft, writing—review & editing. Osman Diriye Hussein: Investigation, data curation, validation, writing, review & editing. Abdullahi Mohamud Osoble: Investigation, data curation, validation, writing, review & editing. Jayanta Mondal: Supervision, conceptualization, methodology guidance, resources, writing, review & editing, project administration. Funding This research did not receive any specific grant from funding agencies in the public, commercial, or not-for-profit sectors. Data availability The data supporting the findings of this study are publicly available from the Radiopaedia.org repository and can be accessed via “[ https://radiopaedia.org ] (https:/radiopaedia.org)”. All data are de-identified and subject to Radiopaedia’s terms of use and attribution guidelines. Code availability The proposed algorithms are fully described in the methods section and are sufficient to enable independent reproduction of the reported results. The implementation code, developed within research-specific medical imaging pipelines and subject to institutional data-handling policies, is available from the corresponding author upon reasonable request for academic and non-commercial use. Declarations Competing interests The authors declare no competing interests. Footnotes Publisher’s note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations. References 1. Shiu, C. W., Chen, Y. C. & Hong, W. Encrypted image-based reversible data hiding with public key cryptography from difference expansion. Signal Process. Image Commun. 39 , 226–233 (2015). [ Google Scholar ] 2. Wang, J., Ni, J., Zhang, X. & Shi, Y. Q. Rate and distortion optimization for reversible data hiding using multiple histogram shifting. IEEE Trans. Cybern. 47 (2), 315–326 (2016). [ DOI ] [ PubMed ] [ Google Scholar ] 3. Shetty, N. R., Naik, G. R. & Vidyasagar, K. B. Reversible data hiding in encrypted images using difference expansion and histogram shifting. J. Electr. Syst. 20 (10s), 4732–4743 (2024). [ Google Scholar ] 4. Gomathi, R. Authenticated medical image transmission using enhanced reversible data hiding (RDH) with NNP2 algorithm and rhombus prediction. Int. J. Recent Technol. Eng. 8 (4), 12188–12192 (2019). [ Google Scholar ] 5. Motomura, R., Imaizumi, S. & Kiya, H. A reversible data hiding method in encrypted images for controlling trade-off between hiding capacity and compression efficiency. J. Imaging 7 (12), 268 (2021). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 6. Liu, Y., Qu, X. & Xin, G. A ROI-based reversible data hiding scheme in encrypted medical images. J. Vis. Commun. Image Represent. 39 , 51–57 (2016). [ Google Scholar ] 7. Hong, W., Chen, T.-S. & Wu, H.-Y. An improved reversible data hiding in encrypted images using side match. IEEE Signal Process. Lett. 19 (4), 199–202 (2012). [ Google Scholar ] 8. Zhang, X. Separable reversible data hiding in encrypted image. IEEE Trans. Inf. Forensics Secur. 7 (2), 826–832 (2012). [ Google Scholar ] 9. Ma, K., Zhang, W., Zhao, X., Yu, N. & Li, F. Reversible data hiding in encrypted images by reserving room before encryption. IEEE Trans. Inf. Forensics Secur. 8 (3), 553–562 (2013). [ Google Scholar ] 10. Fallahpour, M. Megias, D. & Ghanbari, M. High capacity, reversible data hiding in medical images. In Proc. 16th IEEE Int. Conf. Image Process . (ICIP), 4241–4244. (2009) 11. Huang, L.-C., Tseng, L.-Y. & Hwang, M.-S. A reversible data hiding method by histogram shifting in high quality medical images. J. Syst. Softw. 86 (3), 716–727 (2013). [ Google Scholar ] 12. Wu, H.-T., Huang, J. & Shi, Y.-Q. A reversible data hiding method with contrast enhancement for medical images. J. Vis. Commun. Image Represent. 31 , 146–153 (2015). [ Google Scholar ] 13. Hussein, O. D., Abdullahi, H. O. & Hassan, A. A. Blockchain-driven enhancement of SDN security in IoT-related scenarios. Ingénierie des systèmes d Inf. 29 (6), 2265 (2024). [ Google Scholar ] 14. Yang, Y., Zhang, W., Liang, D. & Yu, N. Reversible data hiding in medical images with enhanced contrast in texture area. Digit. Signal Process. 52 , 13–24 (2016). [ Google Scholar ] 15. Parah, S. A., Ahad, F., Sheikh, J. A. & Bhat, G. M. Hiding clinical information in medical images: A new high capacity and reversible data hiding technique. J. Biomed. Inform. 66 , 214–230 (2017). [ DOI ] [ PubMed ] [ Google Scholar ] 16. Gao, G. et al. Reversible data hiding with automatic contrast enhancement for medical images. Signal Process. 178 , 107817 (2021). [ Google Scholar ] 17. Govind, P. V. S. & Judy, M. V. A secure framework for remote diagnosis in health care: A high capacity reversible data hiding technique for medical images. Comput. Electr. Eng. 89 , 106933 (2021). [ Google Scholar ] 18. Huang, H.-C. Fang, W.-C. & Lai, W.-H. Secure medical information exchange with reversible data hiding. In 2012 IEEE International Symposium on Circuits and Systems (ISCAS, 1424–1427 ), (2012). 19. Parah, S. A., Ahad, F., Sheikh, J. A., Loan, N. A. & Bhat, G. M. A new reversible and high capacity data hiding technique for E-healthcare applications. Multimed. Tools Appl. 76 , 3943–3975 (2017). [ Google Scholar ] 20. Gao, G. et al. Reversible data hiding with contrast enhancement and tamper localization for medical images. Inf. Sci. 385 , 250–265 (2017). [ Google Scholar ] 21. Ayyappan, S., Lakshmi, C. & Menon, V. A secure reversible data hiding and encryption system for embedding EPR in medical images. Curr. Signal Transduct. Ther. 15 (2), 124–135 (2020). [ Google Scholar ] 22. Li, J. et al. A partial encryption algorithm for medical images based on quick response code and reversible data hiding technology. BMC Med. Inform. Decis. Mak. 20 , 177 (2020). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 23. Bhardwaj, R. Hiding patient information in medical images: An enhanced dual image separable reversible data hiding algorithm for E-healthcare. J. Ambient Intell. Humanized Comput. 14 (1), 321–337 (2023). [ Google Scholar ] 24. Geetha, R. & Geetha, S. Embedding electronic patient information in clinical images: An improved and efficient reversible data hiding technique. Multimed. Tools Appl. 79 (19), 12869–12890 (2020). [ Google Scholar ] 25. Bhardwaj, R. An improved reversible and secure patient data hiding algorithm for telemedicine applications. J. Ambient Intell. Humanized Comput. 12 (2), 2915–2929 (2021). [ Google Scholar ] 26. Sahu, A. K. & Sahu, M. Hybrid fragile image watermarking for tamper detection, localization and dual self-recovery. Eng. Sci. Technol., Int. J. 73 , 102266 (2026). 27. Sahu, A. K., Sahu, M., Patro, P., Sahu, G. & Nayak, S. R. Dual image-based reversible fragile watermarking scheme for tamper detection and localization. Pattern Anal. Appl. 26 (2), 571–590 (2023). [ Google Scholar ] 28. Chai, X. et al. High-capacity reversible data hiding in encrypted medical images using adaptive pixel-modulation and HBP-RMC. Biomed. Signal Process. Control. 95 , 106424 (2024). [ Google Scholar ] 29. Qu, L., Li, M. & Chen, P. Reversible data hiding in encrypted image with secure multi-party for telemedicine applications. Biomed. Signal Process. Control. 93 , 106209 (2024). [ Google Scholar ] 30. Sahu, A. K. Pradhan, A. Sahu, M. & Swain, G. A Comprehensive Review of Traditional and Machine Learning Based Approaches in Digital Image Watermarking. In Proc. Int. Conf. Recent Innov. Comput . 2 , (ICRIC 2024), 267, (Springer Nature, 2025). 31. Vaidya, S. P. et al. A robust fragile watermarking approach for image tampering detection and restoration utilizing hybrid transforms. Sci. Rep. 15 (1), 17645 (2025). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 32. Beggari, A. S., Wali, A., Khaldi, A., Kafi, M. R., and Sahu, A. K. Robust medical image watermarking based on ridgelet transform and ant colony optimization for telemedicine security. Syst. Soft Comput . 200390 (2025). 33. Chen, L. P. et al. A novel color image encryption algorithm based on a fractional-order discrete chaotic neural network and DNA sequence operations. Front. Inf. Technol. Electron. Eng. 21 (6), 866–879 (2020). [ Google Scholar ] Associated Data This section collects any data citations, data availability statements, or supplementary materials included in this article. Data Availability Statement The data supporting the findings of this study are publicly available from the Radiopaedia.org repository and can be accessed via “[ https://radiopaedia.org ] (https:/radiopaedia.org)”. All data are de-identified and subject to Radiopaedia’s terms of use and attribution guidelines. The proposed algorithms are fully described in the methods section and are sufficient to enable independent reproduction of the reported results. The implementation code, developed within research-specific medical imaging pipelines and subject to institutional data-handling policies, is available from the corresponding author upon reasonable request for academic and non-commercial use. Articles from Scientific Reports are provided here courtesy of Nature Publishing Group ACTIONS View on publisher site PDF (2.2 MB) Cite Collections Permalink PERMALINK Copy RESOURCES Similar articles Cited by other articles Links to NCBI Databases Cite Copy Download .nbib .nbib Format: AMA APA MLA NLM Add to Collections Create a new collection Add to an existing collection Name your collection * Choose a collection Unable to load your collection due to an error Please try again Add Cancel Follow NCBI NCBI on X (formerly known as Twitter) NCBI on Facebook NCBI on LinkedIn NCBI on GitHub NCBI RSS feed Connect with NLM NLM on X (formerly known as Twitter) NLM on Facebook NLM on YouTube National Library of Medicine 8600 Rockville Pike Bethesda, MD 20894 Web Policies FOIA HHS Vulnerability Disclosure Help Accessibility Careers NLM NIH HHS USA.gov Back to Top

Record · ID 1217 · SHA-256 e2bba78d7e7f9220
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.