H.E.EZ Layer: Nanophotonics & IoT Security
- H.E.EZ Layer is a dual-usage term referring to both a broadband epsilon-near-zero metamaterial design in nanophotonics and a multi-stage cryptographic substrate in IoT-cloud security.
- In the metamaterials context, it uses the Bergman spectral representation to synthesize effective permittivity with specific layer parameters for broadband ENZ behavior.
- In IoT-Cloud security, it integrates improved Hyperledger-Fabric, a lightweight Enc-Block cipher, and a hybrid ECDSA-ZSS scheme to secure data exchange.
Searching arXiv for the cited papers and closely related context. arxiv_search: query="(Farshadinia et al., 1 Sep 2025)" max_results=5 H.E.EZ Layer denotes two unrelated constructs in the arXiv literature. In nanophotonics, it refers to a broadband “High-Efficiency Epsilon-Near-Zero” layer realized by a step-like metal-dielectric multilayer whose effective permittivity is synthesized through the Bergman spectral representation (Sun et al., 2013). In IoT-Cloud security, the closely related label H.E.E.Z identifies the bottom “Cryptography” layer of a three-layer framework that combines an improved Hyperledger-Fabric module, an improved Enc-Block lightweight cipher, and a hybrid ECDSA-ZSS cryptosystem (Farshadinia et al., 1 Sep 2025). The shared label is therefore terminological rather than methodological: one usage concerns effective-medium design in the optical regime, and the other concerns layered cryptographic processing for secure data exchange.
1. Terminological scope and disambiguation
The term has acquired a dual usage, and disambiguation is essential because the underlying formalisms, objectives, and evaluation criteria are entirely different.
| Usage | Domain | Core definition |
|---|---|---|
| H.E.EZ layer | Optical metamaterials | Broadband epsilon-near-zero layer built from step-like metal-dielectric multilayers |
| H.E.E.Z layer | IoT-Cloud security | Bottom cryptography layer combining improved HF, Enc-Block, and hybrid ECDSA-ZSS |
In the metamaterials usage, the relevant problem is broadband control of the effective permittivity tensor, specifically maintaining over a target optical band (Sun et al., 2013). In the IoT-Cloud usage, the relevant problem is multi-stage lightweight cryptography with layered protection, communication efficiency, and scalable auditing (Farshadinia et al., 1 Sep 2025).
A common misconception is to treat the label as naming a single established technique. The available literature instead supports a polysemous reading: the same or nearly the same label is used for two distinct research objects, one electromagnetic and one cryptographic.
2. Spectral-space construction of the broadband epsilon-near-zero layer
In the quasi-static limit, Sun et al. describe a layered composite of metal inclusions with permittivity in a dielectric host through the Bergman spectral formula. Defining the dimensionless spectral variable
the effective -direction permittivity of the three-layer stack is
with
and
An equivalent geometric expression for three homogeneous “effective” layers of thickness with total thickness and metal filling fraction 0 is
1
Matching the spectral form to the geometric form yields a one-to-one mapping between 2 in spectral space and 3 in physical space (Sun et al., 2013).
The design procedure begins by choosing a target optical band 4 over which 5. Three ENZ frequencies 6 are then selected within that band so that 7. For equally spaced points, the construction may use
8
with 9, 0, and 1. The residues are obtained from the linear conditions
2
after which one inverts the geometric expression at a generic 3 such as 4 to retrieve 5 and 6 (Sun et al., 2013).
For the band 7–8, using gold-in-SiO9 parameters, the reported design yields
0
and
1
This construction is significant because it converts a multi-frequency ENZ specification into a physically realizable three-layer stack rather than treating broadband ENZ behavior as an ad hoc numerical search problem.
3. Dispersion, realization, and optical functions of the metamaterial H.E.EZ layer
Substituting 2 into the spectral or geometric representation gives the full complex dispersion curve,
3
For Au, the metal permittivity is taken as
4
with 5, 6, and 7 to model thin-film damping. The host dielectric is SiO8 with 9, nearly constant in the band. The reported dispersion shows that 0 crosses zero at five points across 1, while 2 remains moderate (Sun et al., 2013). A frequent misunderstanding is to equate ENZ with vanishing loss; the reported result is instead broadband near-zero real permittivity with moderate imaginary part.
The meta-atom has a transverse footprint of 3 and total stack thickness 4. For practical fabrication, each “homogeneous” layer is replaced by a sub-stack of Au/SiO5 with gold height 6, patterned by standard e-beam evaporation or sputtering and lithography. The reported tolerance analysis indicates that rounding 7 and 8 to two significant digits broadens but does not destroy the ENZ band (Sun et al., 2013). This suggests that the design is not restricted to an exactly idealized parameter set.
Two device demonstrations organize the optical significance of the layer. In the first, a prism built from these meta-atoms in air has a 9-tilted top face. Under vertical illumination across 0–1, the outgoing beam refracts almost normal to the slanted face, with average refraction angle 2 over the full band, corresponding to an effective group index 3. The explanation given is the flat, nearly zero-4 elliptical iso-frequency contour. In the second, an S-shaped lens of radius 5 produces a conformal phase front, with mean phase delay across the band of 6, nearly constant over 7–8, enabling broadband phase control (Sun et al., 2013).
4. Architecture of the H.E.E.Z cryptography layer
In the IoT-Cloud framework, H.E.E.Z is the first and bottom layer of a three-layer stack. It consists of three subcomponents: an Improved Hyperledger-Fabric module, an Improved Enc-Block Lightweight Cipher, and a Hybrid ECDSA-ZSS Cryptosystem, denoted “EZ” (Farshadinia et al., 1 Sep 2025).
The reported data flow is block-oriented. A user submits a file 9, which is split into blocks 0. Each 1 is first processed by the improved HF module, producing blockchain-ready ciphertexts 2. The first 3 bits of each 4 are then re-encrypted by Enc-Block, while the last 5 bits are encrypted under EZ. The resulting triple-encrypted segments are passed to the higher layers, namely the Credential Management layer and the C-Audit layer (Farshadinia et al., 1 Sep 2025).
This architecture matters because the layer is not presented as a single cipher or signature scheme. It is a composition of blockchain-oriented block processing, lightweight fixed-width re-encryption, and credential-oriented asymmetric cryptography. Another common misconception is therefore to identify H.E.E.Z with the ECDSA-ZSS hybrid alone; the paper’s architecture defines it as the joint operation of all three modules on distinct parts of the HF output.
5. Formal primitives and data flow in the cryptographic H.E.E.Z layer
For the improved Hyperledger-Fabric module, the system-wide public parameters are
6
where 7 and 8 are cyclic groups of prime order 9, 0 is the target group, 1 is a bilinear map, 2, and 3. User key generation is
4
with secret key 5 and public key 6. For a file block 7, the module samples 8}G_19%%%%888%%%%2d_i$3-bit half-block $d_i$4 using an internal $d_i$5-word state $d_i$6 with each $d_i$7 and a $d_i$8-bit LFSR register. For $d_i$9, the round structure is specified by chained subcipher calls
$d=\sum d_i$0
$d=\sum d_i$1
$d=\sum d_i$2
and
$d=\sum d_i$3
After four rounds, the ciphertext is
$d=\sum d_i$4
The paper characterizes this as a lightweight cipher specialized to the fixed $d=\sum d_i$5-bit segment selected from the HF output (Farshadinia et al., 1 Sep 2025).
The hybrid ECDSA-ZSS component combines elliptic-curve commitments, ECDSA signatures, ZSS credential issuance, pairing-based verification, and a Schnorr proof of knowledge. Setup uses an elliptic curve
$d=\sum d_i$6
points $d=\sum d_i$7, and a Type-3 pairing
$d=\sum d_i$8
User key generation is
$d=\sum d_i$9
For an attribute vector $\varepsilon_m(\omega)$00, commitment is
$\varepsilon_m(\omega)$01
The Identity Verifier runs ECDSA on $\varepsilon_m(\omega)$02, the Credential Provider issues
$\varepsilon_m(\omega)$03
and the ZSS credential is verified through
$\varepsilon_m(\omega)$04
For unlinkable presentation, the paper introduces a blinding scalar $\varepsilon_m(\omega)$05}\mathbb{Z}<em>q<sup>*$\varepsilon_m(\omega)$06$ \tilde\sk_u=b\sk_u,\quad \tilde\pk_u=b\pk_u,\quad \tilde\sigma\CP=b\sigma_\CP,\quad \tilde P=bP,
07
R=r\cdot\tilde P,\qquad s=H(R),\qquad t=s\cdot\tilde\sk_u+r,
08
t\tilde P=R+s\tilde\pk_u \quad\wedge\quad e\bigl(H(C)\tilde P+\tilde\pk_\CP,\tilde\sigma_\CP\bigr)=e(\tilde P,\tilde\pk_u).
09
T_{\HF}(n)=n\,(T_H+T_{\exp_{G_1}})+O(n) =O\bigl(n\,(T_H+T_{\exp_{G_1}})\bigr).
10
T_{\EncBlk}=4\times 8\times[\text{1 subcipher call}]=O(1) \quad\text{(constant per half-block)}.
11
T_{\EZ}=T_{\mathit{commit}}+T_{ECDSA}+T_{\mathit{ZSS_sign}}+T_{\mathit{pair_verify}} =O\bigl(n\bigl(T_{ECDSA}+T_{\rm pair}\bigr)\bigr) \quad\text{(amortized over }n\text{)}.
12
T_{\H.E.EZ}(n)\approx T_{\HF}(n)+n\,T_{\EncBlk}+n\,T_{\EZ} =O\bigl(n\,(T_H+T_{\exp_{G_1}}+T_{\EncBlk}+T_{ECDSA}+T_{\rm pair})\bigr).
13
\mathrm{Comm}(n)=n\bigl(|G_1|+16+O(\log q)\bigr) =O\bigl(n\,(|G_1|+\log q)\bigr).
14
T(#\mathrm{TPA})\approx 0.0202\;#\mathrm{TPA}+308.5\quad(\mathrm{ms}),
15
T(#\mathrm{blocks})\approx 0.0202\,#\mathrm{blocks}+308.5\quad(\mathrm{ms}), 16 lower compute times (Farshadinia et al., 1 Sep 2025).
The comparative security and systems results are also explicit.
| Scheme | Total time (ms) | Communication per block |
|---|---|---|
| Vahi [31] | 1800 | ~720 bits |
| Lu [30] | 1600 | ~650 bits |
| Proposed | 1100 | ~500 bits |
The paper states that H.E.E.Z satisfies all 17 listed security criteria, including integrity, multi-replica consistency, TPA-verifiable, accountability, conspiracy resistance, layered protection, non-frameability, physical-attack resilience, formal proofs, mutual authentication, anonymity, and key-extraction resistance, whereas HF-Audit [30] and SEPAR [31] satisfy only 18–19 features each. It further states that stand-alone ECDSA lacks multi-replica consistency and layered protection, and that ZSS alone depends on a TTP and fails user-anonymity in many settings (Farshadinia et al., 1 Sep 2025).
Taken together, the two meanings of H.E.EZ layer illustrate how an identical label can refer either to a broadband ENZ effective-medium design or to a multi-stage cryptographic substrate. In the first case, the defining idea is a one-to-one mapping between spectral singularities and physical layer parameters; in the second, it is a staged composition of HF processing, lightweight half-block encryption, and unlinkable credential mechanisms. The typographic overlap should therefore not obscure the substantive separation between electromagnetic material synthesis and IoT-Cloud security engineering.