发表机构
Theta Labs; Starknet Foundation; Brevis; MultiVM Labs; StarkWare; Adam Mickiewicz University Poznań; Warsaw University of Technology; Octav; Pauli Group; ScienceVR; Sei Labs; Stanford Free Systems Lab; Eigen Labs; Ethereum Foundation(Theta Labs; Starknet基金会; Brevis; MultiVM实验室; StarkWare; 波兹南亚当·密茨凯维奇大学; 华沙理工大学; Octav; Pauli集团; ScienceVR; Sei实验室; 斯坦福自由系统实验室; Eigen实验室; 以太坊基金会)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究提出两种改进的量子椭圆曲线点加法电路构造,通过Jump-2和ping-pong技术优化记录与重放GCD算术,在100,000输入测试中修复电路使用1,419量子比特和1.356百万Toffoli门,资源低于现有低门数估计。
AI 中文摘要
我们研究了通过此http URL为Shor椭圆曲线离散对数算法开发的可逆secp256k1点加法电路。两种互补的构造改进了记录与重放GCD算术:Jump-2对二进制GCD步骤进行分组,并使用基数为5的编码压缩其决策,而ping-pong使用固定寄存器交替和一位决策来避免全宽度比较和数据相关的交换。融合重放将加倍和带符号加法合并为一次模修正。两种构造都支持量子寻址窗口选择,并采用基于测量的查找清理。我们在九种查找表配置下,对100,000个新输入比较了三种电路。一个单独测试的修复电路使用1,419个量子比特和平均执行1.356百万个Toffoli门,在另外100,000个输入上未检测到失败。仍存在结构化的受支持输入反例,因此这些测试并未确立所有输入的正确性。我们还提供了条件相干误差分析和可逆safegcd比较。在所述的窗口允许条件下,修复后的电路资源低于Google的低门数上限和Schrottenloher的低门数估计,但不同的核算和正确性证据排除了形式上的优势。这些结果涉及单个窗口选择的加法,而非完整的Shor计算。
英文摘要
We study reversible secp256k1 point-addition circuits developed through ECDSA.Fail for Shor's elliptic-curve discrete-logarithm algorithm. Two complementary constructions improve record-and-replay GCD arithmetic: Jump-2 groups binary-GCD steps and compresses their decisions using base-5 encoding, while ping-pong uses fixed register alternation and one-bit decisions to avoid full-width comparisons and data-dependent swaps. Fused replay combines doubling and signed addition into one modular correction. Both constructions support quantum-addressed window selection with measurement-based lookup cleanup. We compare three circuits on 100,000 fresh inputs across nine lookup-table configurations. A separately tested repair uses 1,419 qubits and 1.356 million mean executed Toffolis, with no detected failures on another 100,000 inputs. Structured supported-input counterexamples remain, so these tests do not establish all-input correctness. We also provide conditional coherent-error analysis and reversible safegcd comparisons. Under the stated window allowance, repaired-circuit resources lie below Google's low-gate caps and Schrottenloher's low-gate estimates, but differing accounting and correctness evidence preclude formal dominance. The results concern individual window-selected additions, not complete Shor computations.
Comments35 pages, 2 figures. Technical companion to arXiv:2609.09582. Reproducibility artifacts: https://github.com/jieyilong/ecdsafail-circuit-evidence/releases/tag/v1.4.0