arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.11563quant-ph

高效量子模约简:Crandall约简及其容错资源分析

Efficient Quantum Modular Reduction: Crandall reduction and its Fault-tolerant resource analysis

Changyeol Lee, Sungyeon Kook, Wooyeong Song, Kwangil Bae, Wonhyuk Lee, IlKwon Sohn

首次发表
浏览论文内容

中文总结 AI 辅助

该研究针对密码学量子算法的模约简需求,提出Crandall约简的可逆量子电路形式,开发两个变体,经实验验证其在量子资源和运行时间上均优于优化后的折叠Barrett约简。

中文摘要 AI 辅助

模运算在密码学问题的量子算法中处于核心地位,包括Shor算法和基于Grover的密码分析,其中模约简对电路成本贡献显著。伪梅森模数q=2^n−c可让经典Crandall约简用折叠和常数运算替代除法,为实现比Barrett约简更高效的量子模约简提供了结构机会。我们通过推导2n位输入的显式折叠与归一化条件,将这一优势转化为可逆量子场景。据我们所知,这是Crandall约简的首个精确可逆量子电路形式。基于该形式,我们开发了两个变体:Crandall约简-1通过单步归一化设计以最小化执行成本,而Crandall约简-2采用两步归一化,以有限开销支持更广泛的c取值范围。逻辑资源估计显示,两个变体所需量子比特数、T门数量及T门深度均少于优化后的折叠Barrett约简。当n=10时,Crandall约简-1的T门数量和T门深度较优化后的折叠Barrett约简降低约46.9%。表面码分析进一步表明,在稀疏Blossom解码器下,当n=20时,两个变体的估计运行时间分别为30.05 ms和35.39 ms,而优化后的折叠Barrett约简为53.77 ms。这些结果证明了在容错量子电路设计中利用模数特定算术结构的实用价值。

英文摘要

Modular arithmetic is central to quantum algorithms for cryptographic problems, including Shor's algorithm and Grover-based cryptanalysis, with modular reduction contributing substantially to circuit cost. Pseudo-Mersenne moduli $q=2^n-c$ allow classical Crandall reduction to replace division with folding and constant arithmetic, providing a structural opportunity for more efficient quantum modular reduction than Barrett reduction. We translate this advantage into a reversible quantum setting by deriving explicit folding and normalization conditions for $2n$-bit inputs. To the best of our knowledge, this constitutes the first exact reversible quantum circuit formulation of Crandall reduction. Based on this formulation, we develop two variants: Crandall reduction-1 is designed to minimize execution cost through one-step normalization, whereas Crandall reduction-2 uses two-step normalization to support a wider range of $c$ with limited overhead. Logical resource estimates show that both variants require fewer qubits and lower T-count and T-depth than optimized folding Barrett reduction. At $n=10$, Crandall reduction-1 reduces both T-count and T-depth by approximately 46.9% relative to optimized folding Barrett reduction. Surface-code analysis further shows that, at $n=20$ under the Sparse Blossom decoder, the estimated runtimes of the two variants are 30.05 ms and 35.39 ms, respectively, compared with 53.77 ms for optimized folding Barrett reduction. These results demonstrate the practical value of exploiting modulus-specific arithmetic structure in fault-tolerant quantum circuit design.

补充信息

↑