发表机构
Institute for Interdisciplinary Information Sciences, Tsinghua University; Center on Frontiers of Computing Studies, Peking University; School of Computer Science, Peking University; Institute of Quantum Computing and Software, School of Computer Science and Engineering, Sun Yat-Sen University; State Key Lab of Processors, Institute of Computing Technology, Chinese Academy of Sciences; School of Computer Science and Technology, University of Chinese Academy of Sciences(清华大学交叉信息研究院; 北京大学前沿计算研究中心; 北京大学计算机学院; 中山大学计算机科学与工程学院量子计算与软件研究所; 中国科学院计算技术研究所处理器重点实验室; 中国科学院大学计算机科学与技术学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究针对椭圆曲线离散对数问题的量子算法,提出空间高效方法,通过新的可逆模逆电路及优化技术,减少逻辑量子比特和托佛利门数量,实现更高效求解,改进了之前算法在特定素域曲线下的资源需求。
AI 中文摘要
椭圆曲线离散对数问题(ECDLP)是密码学中的一个基本问题,降低求解ECDLP的量子算法的资源需求是一个重要目标。在这项工作中,我们提出了一种用于在素域上求解ECDLP的空间高效量子算法,仅用$3n + 6\lfloor \log_2 n \rfloor + O(1)$个逻辑量子比特和$919n^3 / \log_2 n + O(n^2)$个托佛利门就能实现,其中$n$是素数的比特长度。对于256位素域曲线,我们的构造仅需835个逻辑量子比特,分别低于Chevignard等人[EUROCRYPT 2026]和Babbush等人[ArXiv预印本2026]之前的最佳估计值1098和1175个逻辑量子比特。我们改进的关键是一种新的空间高效可逆模逆电路,它解决了仿射坐标点加法中的主要空间瓶颈。从扩展欧几里得算法(EEA)出发,我们通过引入长度寄存器和位置控制算法来优化Proos和Zalka的寄存器共享技术,以紧凑地存储和更新中间变量。我们进一步优化可逆更新过程并构建相应的受控算法电路,得到一个仅由$2n + 6\lfloor \log_2 n \rfloor + O(1)$个逻辑量子比特和$195n^2 + O(n\log_2 n)$个托佛利门实现的模逆电路。这个模逆电路与电路中间测量和经典前馈操作一起提供了一个空间高效的受控仿射点加法电路以及用于ECDLP的Shor算法的完整实现。
英文摘要
The Elliptic Curve Discrete Logarithm Problem (ECDLP) is a fundamental problem in cryptography, and reducing the resource requirements of quantum algorithms for solving ECDLP is an important goal. In this work, we present a space-efficient quantum algorithm for solving the ECDLP over prime fields, achieving an implementation with only $3n+6\lfloor \log_2 n \rfloor+O(1)$ logical qubits and $1056n^3/\log_2 n+O(n^2)$ Toffoli gates, where $n$ is the bit-length of the prime. For a 256-bit prime-field curve, our construction requires only 835 logical qubits, reducing the previous best estimates of 1098 and 1175 logical qubits by Chevignard et al. [EUROCRYPT 2026] and Babbush et al. [ArXiv Preprint 2026], respectively. The key to our improvement is a new space-efficient reversible modular inversion circuit, which addresses the dominant space bottleneck in affine-coordinate point addition. Starting from the extended Euclidean algorithm (EEA), we refine the register-sharing technique of Proos and Zalka by introducing length registers and location-controlled arithmetic to compactly store and update intermediate variables. We further optimize the reversible update procedures and construct the corresponding controlled arithmetic circuits, resulting in a modular inversion circuit implemented by only $2n+6\lfloor \log_2 n \rfloor+O(1)$ logical qubits and $229n^2+O(n\log_2 n)$ Toffoli gates. This modular inversion circuit together with mid-circuit measurements and classical feed-forward operations provides a space-efficient controlled affine point-addition circuit and a complete implementation of Shor's algorithm for ECDLP.
Comments46 pages, 15 figures, 6 tables. This paper supersedes our earlier preprint arXiv:2604.02311. Compared with the earlier version, the present paper reduces the space complexity from $5n+O(\log_2 n)$ to $3n+O(\log_2 n)$ for affine point addition and from $3n+O(\log_2 n)$ to $2n+O(\log_2 n)$ for modular inversion