---
title: 'H.E.EZ Layer: Nanophotonics & IoT Security'
url: https://www.emergentmind.com/topics/h-e-ez-layer
type: topic
---

# H.E.EZ Layer: Nanophotonics & IoT Security

Searching arXiv for the cited papers and closely related context.
arxiv_search: query="2509.01717" max_results=5
H.E.EZ Layer denotes two unrelated constructs in the arXiv literature. In nanophotonics, it refers to a broadband “High-Efficiency Epsilon-Near-Zero” layer realized by a step-like metal-dielectric multilayer whose effective permittivity is synthesized through the Bergman spectral representation [1304.6634]. In IoT-Cloud security, the closely related label H.E.E.Z identifies the bottom “Cryptography” layer of a three-layer framework that combines an improved Hyperledger-Fabric module, an improved Enc-Block lightweight cipher, and a hybrid ECDSA-ZSS cryptosystem [2509.01717]. The shared label is therefore terminological rather than methodological: one usage concerns effective-medium design in the optical regime, and the other concerns layered cryptographic processing for secure data exchange.

## 1. Terminological scope and disambiguation

The term has acquired a dual usage, and disambiguation is essential because the underlying formalisms, objectives, and evaluation criteria are entirely different.

| Usage | Domain | Core definition |
|---|---|---|
| H.E.EZ layer | Optical metamaterials | Broadband epsilon-near-zero layer built from step-like metal-dielectric multilayers |
| H.E.E.Z layer | IoT-Cloud security | Bottom cryptography layer combining improved HF, Enc-Block, and hybrid ECDSA-ZSS |

In the metamaterials usage, the relevant problem is broadband control of the effective permittivity tensor, specifically maintaining $\operatorname{Re}\,\varepsilon_{\mathrm{eff}}(\omega)\approx 0$ over a target optical band [1304.6634]. In the IoT-Cloud usage, the relevant problem is multi-stage lightweight cryptography with layered protection, communication efficiency, and scalable auditing [2509.01717].

A common misconception is to treat the label as naming a single established technique. The available literature instead supports a polysemous reading: the same or nearly the same label is used for two distinct research objects, one electromagnetic and one cryptographic.

## 2. Spectral-space construction of the broadband epsilon-near-zero layer

In the quasi-static limit, Sun et al. describe a layered composite of metal inclusions with permittivity $\varepsilon_m(\omega)$ in a dielectric host $\varepsilon_h$ through the Bergman spectral formula. Defining the dimensionless spectral variable
$$
s(\omega)\equiv \frac{\varepsilon_h}{\varepsilon_h-\varepsilon_m(\omega)},
$$
the effective $x$-direction permittivity of the three-layer stack is
$$
\varepsilon_{\mathrm{eff}}(\omega)\equiv \varepsilon_x[s(\omega)],
$$
with
$$
\varepsilon_{\mathrm{eff}}(\omega)=\varepsilon_h\left[1-F(s(\omega))\right]^{-1},
$$
and
$$
F(s)=\sum_{i=1}^{3}\frac{F_i}{s-s_i},\qquad 0\le s_1<s_2<s_3<1,\qquad F_i>0.
$$
An equivalent geometric expression for three homogeneous “effective” layers of thickness $d_i$ with total thickness $d=\sum d_i$ and metal filling fraction $f_i$ is
$$
\varepsilon_x(s)=\varepsilon_h\left\{\sum_{i=1}^{3}\frac{d_i/d}{1-(f_i/s)}\right\}^{-1}.
$$
Matching the spectral form to the geometric form yields a one-to-one mapping between $\{s_i,F_i\}$ in spectral space and $\{f_i,d_i\}$ in physical space [1304.6634].

The design procedure begins by choosing a target optical band $[\omega_a,\omega_b]$ over which $\operatorname{Re}\,\varepsilon_{\mathrm{eff}}(\omega)\approx 0$. Three ENZ frequencies $\omega_{j=1,2,3}$ are then selected within that band so that $\operatorname{Re}\,\varepsilon_{\mathrm{eff}}(s(\omega_j))=0$. For equally spaced points, the construction may use
$$
\omega_1=\omega_a<\omega_2<\omega_3<\omega_4<\omega_5=\omega_b,
$$
with $s_1=0$, $s_2=\operatorname{Re}\,s(\omega_2)$, and $s_3=\operatorname{Re}\,s(\omega_3)$. The residues are obtained from the linear conditions
$$
\operatorname{Re}\left[1-\sum_{i=1}^{3}\frac{F_i}{s(\omega_j)-s_i}\right]=0,\qquad j=1,2,3,
$$
after which one inverts the geometric expression at a generic $s$ such as $s\to\infty$ to retrieve $f_i$ and $d_i/d$ [1304.6634].

For the band $537.42$–$589.62\ \mathrm{THz}$, using gold-in-SiO$_2$ parameters, the reported design yields
$$
f_1=0.21633,\qquad f_2=0.18852,\qquad f_3=0.163955,
$$
and
$$
d_1=43.6884\ \mathrm{nm},\qquad d_2=19.2691\ \mathrm{nm},\qquad d_3=37.0425\ \mathrm{nm}.
$$
This construction is significant because it converts a multi-frequency ENZ specification into a physically realizable three-layer stack rather than treating broadband ENZ behavior as an ad hoc numerical search problem.

## 3. Dispersion, realization, and optical functions of the metamaterial H.E.EZ layer

Substituting $s(\omega)=\varepsilon_h/[\varepsilon_h-\varepsilon_m(\omega)]$ into the spectral or geometric representation gives the full complex dispersion curve,
$$
\varepsilon_{\mathrm{eff}}(\omega)=\varepsilon_h\left\{1-\sum_{i=1}^{3}\frac{F_i}{s(\omega)-s_i}\right\}^{-1}.
$$
For Au, the metal permittivity is taken as
$$
\varepsilon_m(\omega)=\varepsilon_\infty-\frac{\omega_p^2}{\omega(\omega+i\gamma)},
$$
with $\varepsilon_\infty=5.7$, $\omega_p=1.3666\times 10^{16}\ \mathrm{rad/s}$, and $\gamma=3\times 4.0715\times 10^{13}\ \mathrm{rad/s}$ to model thin-film damping. The host dielectric is SiO$_2$ with $\varepsilon_h=2.1338$, nearly constant in the band. The reported dispersion shows that $\operatorname{Re}\,\varepsilon_{\mathrm{eff}}(\omega)$ crosses zero at five points across $\sim 52\ \mathrm{THz}$, while $\operatorname{Im}\,\varepsilon_{\mathrm{eff}}(\omega)$ remains moderate [1304.6634]. A frequent misunderstanding is to equate ENZ with vanishing loss; the reported result is instead broadband near-zero real permittivity with moderate imaginary part.

The meta-atom has a transverse footprint of $100\ \mathrm{nm}\times 25\ \mathrm{nm}$ and total stack thickness $\sum d_i=100\ \mathrm{nm}$. For practical fabrication, each “homogeneous” layer is replaced by a sub-stack of Au/SiO$_2$ with gold height $h_i=f_i\cdot h$, patterned by standard e-beam evaporation or sputtering and lithography. The reported tolerance analysis indicates that rounding $f_i$ and $d_i$ to two significant digits broadens but does not destroy the ENZ band [1304.6634]. This suggests that the design is not restricted to an exactly idealized parameter set.

Two device demonstrations organize the optical significance of the layer. In the first, a prism built from these meta-atoms in air has a $15^\circ$-tilted top face. Under vertical illumination across $537$–$590\ \mathrm{THz}$, the outgoing beam refracts almost normal to the slanted face, with average refraction angle $\approx 6.3^\circ$ over the full band, corresponding to an effective group index $n_g\approx 0.42$. The explanation given is the flat, nearly zero-$\varepsilon_x$ elliptical iso-frequency contour. In the second, an S-shaped lens of radius $3\ \mu\mathrm{m}$ produces a conformal phase front, with mean phase delay across the band of $\approx 0.7\ \mathrm{rad}$, nearly constant over $537$–$590\ \mathrm{THz}$, enabling broadband phase control [1304.6634].

## 4. Architecture of the H.E.E.Z cryptography layer

In the IoT-Cloud framework, H.E.E.Z is the first and bottom layer of a three-layer stack. It consists of three subcomponents: an Improved Hyperledger-Fabric module, an Improved Enc-Block Lightweight Cipher, and a Hybrid ECDSA-ZSS Cryptosystem, denoted “EZ” [2509.01717].

The reported data flow is block-oriented. A user submits a file $F$, which is split into blocks $F_1,\dots,F_n$. Each $F_i$ is first processed by the improved HF module, producing blockchain-ready ciphertexts $D_i$. The first $16$ bits of each $D_i$ are then re-encrypted by Enc-Block, while the last $16$ bits are encrypted under EZ. The resulting triple-encrypted segments are passed to the higher layers, namely the Credential Management layer and the C-Audit layer [2509.01717].

This architecture matters because the layer is not presented as a single cipher or signature scheme. It is a composition of blockchain-oriented block processing, lightweight fixed-width re-encryption, and credential-oriented asymmetric cryptography. Another common misconception is therefore to identify H.E.E.Z with the ECDSA-ZSS hybrid alone; the paper’s architecture defines it as the joint operation of all three modules on distinct parts of the HF output.

## 5. Formal primitives and data flow in the cryptographic H.E.E.Z layer

For the improved Hyperledger-Fabric module, the system-wide public parameters are
$$
\mathsf{PP}=\bigl(p,\,G_1,\,G_2,\,G_T,\,e,\,H,\,h\bigr),
$$
where $G_1$ and $G_2$ are cyclic groups of prime order $p$, $G_T$ is the target group, $e:G_1\times G_2\to G_T$ is a bilinear map, $H:\{0,1\}^*\to G_1$, and $h:G_1\to\mathbb{Z}_p^*$. User key generation is
$$
x\xleftarrow{\$}\mathbb{Z}_p^*,\qquad y=g^x\in G_2,
$$
with secret key $x$ and public key $y$. For a file block $F_i$, the module samples $u_m\xleftarrow{\$}G_1$ and computes
$$
C_i=\bigl(H(F_i)\cdot u_m\bigr)^x\in G_1.
$$
Verification by CSPT checks
$$
e(C_i,g)=e\bigl(H(F_i)u_m,y\bigr).
$$
This module therefore combines block hashing, group exponentiation, and pairing-based verification [2509.01717].

The improved Enc-Block cipher operates on exactly one $16$-bit half-block $P\in\{0,1\}^{16}$ using an internal $8$-word state $\mathbf{s}^0=(s_1^0,\dots,s_8^0)$ with each $s_j^0\in\{0,1\}^{16}$ and a $16$-bit LFSR register. For $t=0,1,2,3$, the round structure is specified by chained subcipher calls
$$
V_{12}^t=f_1(s_1^t\oplus s_3^t\oplus s_5^t),\qquad
V_{23}^t=f_2(V_{12}^t\oplus s_2^t),\ \dots,\ 
V_{78}^t=f_7(V_{67}^t\oplus s_7^t),
$$
$$
O^t=f_8(V_{78}^t\oplus s_8^t),
$$
$$
\mathbf{s}^{t+1}=
(s_1^t\oplus O^t,\;s_2^t\oplus V_{12}^t,\;s_3^t\oplus V_{23}^t,\dots,s_8^t\oplus V_{78}^t),
$$
and
$$
\mathrm{LFSR}^{t+1}=\mathrm{LFSR}^t\;\Vert\;O^t.
$$
After four rounds, the ciphertext is
$$
C=f_8(s_1^4\oplus O^3).
$$
The paper characterizes this as a lightweight cipher specialized to the fixed $16$-bit segment selected from the HF output [2509.01717].

The hybrid ECDSA-ZSS component combines elliptic-curve commitments, ECDSA signatures, ZSS credential issuance, pairing-based verification, and a Schnorr proof of knowledge. Setup uses an elliptic curve
$$
E: y^2=x^3+ax+b \pmod q,
$$
points $P,P_1,\dots,P_n\in E(\mathbb{F}_q)$, and a Type-3 pairing
$$
e:E(\mathbb{F}_q)\times E(\mathbb{F}_q)\to G_T.
$$
User key generation is
$$
\sk_u\xleftarrow{\$}\mathbb{Z}_q^*,\qquad \pk_u=\sk_u\cdot P\in E(\mathbb{F}_q).
$$
For an attribute vector $\mathbf{v}=(v_1,\dots,v_n)$, commitment is
$$
r\xleftarrow{\$}\mathbb{Z}_q^*,\qquad
C=r\cdot \pk_u+\sum_{i=1}^n v_iP_i\in E(\mathbb{F}_q).
$$
The Identity Verifier runs ECDSA on $C$, the Credential Provider issues
$$
\sigma_{\CP}=\bigl(H(C)+\sk_{\CP}\bigr)^{-1}\cdot \pk_u\in E(\mathbb{F}_q),
$$
and the ZSS credential is verified through
$$
e\bigl(H(C)P+\pk_\CP,\sigma_\CP\bigr)=e(P,\pk_u).
$$
For unlinkable presentation, the paper introduces a blinding scalar $b\xleftarrow{\$}\mathbb{Z}_q^*$ and defines
$$
\tilde\sk_u=b\sk_u,\quad
\tilde\pk_u=b\pk_u,\quad
\tilde\sigma_\CP=b\sigma_\CP,\quad
\tilde P=bP,
$$
with a non-interactive Schnorr proof
$$
R=r\cdot\tilde P,\qquad s=H(R),\qquad t=s\cdot\tilde\sk_u+r,
$$
and verification
$$
t\tilde P=R+s\tilde\pk_u
\quad\wedge\quad
e\bigl(H(C)\tilde P+\tilde\pk_\CP,\tilde\sigma_\CP\bigr)=e(\tilde P,\tilde\pk_u).
$$
The layer’s encryption pipeline is correspondingly staged: split $F$ into blocks, run HF encryption on each block, split the resulting bitstring so that bits $0..15$ become $P_{\text{head}}$ and bits $16..31$ become $P_{\text{tail}}$, apply Enc-Block to the head and EZ to the tail, then emit $(C_{\text{head}},C_{\text{tail}},\mathrm{metadata}_i)$ to the upper layers. Decryption reverses these operations and applies the pairing test before recovering $F_i$ [2509.01717].

## 6. Complexity, empirical evaluation, and comparative interpretation

The complexity analysis introduces the notation $n$ for the number of file blocks, $T_H$ for one $\hash\to G_1$, $T_{\exp_{G_1}}$ for one exponentiation in $G_1$, $T_{\mathit{EncBlk}}$ for one four-round Enc-Block operation, $T_{ECDSA}$ for one ECDSA sign or verify, and $T_{\rm pair}$ for one bilinear pairing. The HF module has
$$
T_{\HF}(n)=n\,(T_H+T_{\exp_{G_1}})+O(n)
=O\bigl(n\,(T_H+T_{\exp_{G_1}})\bigr).
$$
For Enc-Block,
$$
T_{\EncBlk}=4\times 8\times[\text{1 subcipher call}]=O(1)
\quad\text{(constant per half-block)}.
$$
For EZ,
$$
T_{\EZ}=T_{\mathit{commit}}+T_{ECDSA}+T_{\mathit{ZSS\_sign}}+T_{\mathit{pair\_verify}}
=O\bigl(n\bigl(T_{ECDSA}+T_{\rm pair}\bigr)\bigr)
\quad\text{(amortized over }n\text{)}.
$$
The total cost is summarized as
$$
T_{\H.E.EZ}(n)\approx
T_{\HF}(n)+n\,T_{\EncBlk}+n\,T_{\EZ}
=O\bigl(n\,(T_H+T_{\exp_{G_1}}+T_{\EncBlk}+T_{ECDSA}+T_{\rm pair})\bigr).
$$
Communication overhead is given as
$$
\mathrm{Comm}(n)=n\bigl(|G_1|+16+O(\log q)\bigr)
=O\bigl(n\,(|G_1|+\log q)\bigr).
$$
These expressions place the design in an explicitly layered cost model rather than treating its cryptographic stages as opaque black boxes [2509.01717].

The reported scalability fits are linear. For inter-chain pairing time versus $\#\mathrm{TPA}$,
$$
T(\#\mathrm{TPA})\approx 0.0202\;\#\mathrm{TPA}+308.5\quad(\mathrm{ms}),
$$
compared with slopes $0.0433$ and $0.0541$ for two reference schemes. For cross-chain cost versus $\#\mathrm{blocks}$,
$$
T(\#\mathrm{blocks})\approx 0.0202\,\#\mathrm{blocks}+308.5\quad(\mathrm{ms}),
$$
described as showing approximately $2\times$ lower slope than standard HF-Audit. In an incomplete-information scenario versus $\#\mathrm{neighbors}$, the proposed scheme is approximately $1.1$–$3.1\ \mathrm{s}$ over $30$–$120$ neighbors, compared to $1.6$–$3.9\ \mathrm{s}$ for [30] and $1.7$–$4.6\ \mathrm{s}$ for [31]. The paper summarizes these cases as approximately $30$–$50\%$ lower compute times [2509.01717].

The comparative security and systems results are also explicit.

| Scheme | Total time (ms) | Communication per block |
|---|---:|---:|
| Vahi [31] | 1800 | ~720 bits |
| Lu [30] | 1600 | ~650 bits |
| Proposed | 1100 | ~500 bits |

The paper states that H.E.E.Z satisfies all $18$ listed security criteria, including integrity, multi-replica consistency, TPA-verifiable, accountability, conspiracy resistance, layered protection, non-frameability, physical-attack resilience, formal proofs, mutual authentication, anonymity, and key-extraction resistance, whereas HF-Audit [30] and SEPAR [31] satisfy only $5$–$6$ features each. It further states that stand-alone ECDSA lacks multi-replica consistency and layered protection, and that ZSS alone depends on a TTP and fails user-anonymity in many settings [2509.01717].

Taken together, the two meanings of H.E.EZ layer illustrate how an identical label can refer either to a broadband ENZ effective-medium design or to a multi-stage cryptographic substrate. In the first case, the defining idea is a one-to-one mapping between spectral singularities and physical layer parameters; in the second, it is a staged composition of HF processing, lightweight half-block encryption, and unlinkable credential mechanisms. The typographic overlap should therefore not obscure the substantive separation between electromagnetic material synthesis and IoT-Cloud security engineering.

Source: https://www.emergentmind.com/topics/h-e-ez-layer