Shor's discrete logarithm quantum algorithm for elliptic curves
John Proos, Christof Zalka
Abstract
We show in some detail how to implement Shor's efficient quantum algorithm for discrete logarithms for the particular case of elliptic curve groups. It turns out that for this problem a smaller quantum computer can solve problems further beyond current computing than for integer factorisation. A 160 bit elliptic curve cryptographic key could be broken on a quantum computer using around 1000 qubits while factoring the security-wise equivalent 1024 bit RSA modulus would require about 2000 qubits. In this paper we only consider elliptic curves over GF(p) and not yet the equally important ones over GF(2n) or other finite fields. The main technical difficulty is to implement Euclid's gcd algorithm to compute multiplicative inverses modulo p. As the runtime of Euclid's algorithm depends on the input, one difficulty encountered is the ``quantum halting problem''.
Create a lesson
Related papers
Parallel quantum channel discrimination and numerical ranges in tensor product subspaces
Adam Bílek, Paulina Lewandowska, Ryszard Kukulski
Asymptotically Good Quantum Locally Testable Codes
William Gay, Fernando Granha Jeronimo
All causally separable quantum processes are quantum circuits with classical control of causal order
Julian Wechs, Alastair A. Abbott, Cyril Branciard
Analytic leakage suppression with a single control field: fast two-qubit gates with tunable couplers
Lukas Heunisch, Michael J. Hartmann, Aashish A. Clerk
Procrastinating einselection in non-Markovian quantum dynamics
Michael J. Moody, Tara Kalsi, Agung Budiyono et al.
Quantum Entropy Contraction and Factorization from Hypercontractivity
Li Gao, Lijun Wang