在具有20,000量子比特的容错离子阱量子计算机上26天内计算256位椭圆曲线离散对数
Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer with 20,000 qubits
浏览论文内容
中文总结 AI 辅助
本文针对离子阱量子计算机,优化行走猫架构,使用Shor算法解决secp256k1上256位ECDLP,通过改进CCZ工厂、并行测量和损失校正,在约26天内用约2万物理量子比特达到63%成功率。
中文摘要 AI 辅助
我们最近提出的用于离子阱量子计算机的行走猫架构的优势之一是,它易于针对特定应用进行扩展和优化。作为概念验证,我们在此展示了针对使用Shor算法在secp256k1上求解256位椭圆曲线离散对数问题(ECDLP)的此类优化,secp256k1是比特币等区块链技术所使用的椭圆曲线。我们优化了Schrottenloher近期工作中的电路,得到了一个用于求解ECDLP的逻辑量子电路,该电路使用约1450个量子比特和40×10^6个Toffoli门,并具有逻辑级成功概率的严格下界,该下界以至少1-2^{-128}的置信度成立。使用我们的编译工具链,通过手动优化逻辑布局和集成路由,我们将所有组件编译为符合架构约束的测量调度,从而产生逻辑测量深度和所需物理量子比特数量的估计。一个关键要素是快速的CCZ魔法态工厂和深度为一的CCZ态注入,将CCZ门的执行时间减少了31倍。我们利用非重叠的基于猫的并行测量来增加逻辑测量并行性,并利用最近提出的逻辑CliNR协议来加速Clifford操作。为了减少量子比特开销,我们引入了一种更高效的损失校正协议,设计了一种允许我们回收CliNR辅助量子比特的布局,并根据电路的峰值测量并行性提供可重用的猫态资源。综合所有结果和优化,我们得出结论,基于我们架构的离子阱量子计算机可以在约25.7天内使用19,397个物理量子比特解决secp256k1上的ECDLP,估计成功概率为63%。
英文摘要
One of the strengths of our recently proposed Walking Cat Architecture for a trapped-ion quantum computer is that it is straightforward to extend and optimize for a specific application. As a proof-of-concept, here we present such optimizations for solving the $256$-bit elliptic curve discrete logarithm problem (ECDLP) on $\mathtt{secp256k1}$, which is the elliptic curve used by blockchain technologies such as Bitcoin, using Shor's algorithm. We optimize the circuits from Schrottenloher's recent work and arrive at a logical quantum circuit for solving the ECDLP using about $1450$ qubits and $40\cdot 10^6$ Toffoli gates, with a rigorous lower bound on the logical-level success probability that holds with confidence at least $1-2^{-128}$. Using our compilation toolchain with manual optimization of the logical layout and integrated routing, we produce estimates for the logical measurement depth and the required number of physical qubits by compiling all components to measurement schedules that obey the architectural constraints. A key ingredient is a fast CCZ magic-state factory and a depth-one CCZ state injection, reducing the execution time of CCZ gates by a factor of $31$. We increase the logical-measurement parallelism using non-overlapping cat-based measurements in parallel, and we leverage the recently proposed logical CliNR protocol to speed up Clifford operations. To reduce the qubit overhead, we introduce a more efficient loss correction protocol, design a layout that allows us to recycle the CliNR ancilla qubits, and provision reusable cat-state resources according to the circuit's peak measurement parallelism. All results and optimizations combined, we conclude that a trapped-ion quantum computer based on our architecture can solve the ECDLP on $\mathtt{secp256k1}$ in approximately 25.7 days using 19,397 physical qubits with an estimated success probability of $63\%$.
发表机构
- IonQ Inc.(IonQ公司)
机构由 AI 辅助整理,请以论文原文为准。