A new cultivation protocol prepares reusable logical catalysts as eigenstates of high-period Clifford circuits to implement exact Z^{2^{-b}} phase gates with constant online depth in surface codes.
hub Canonical reference
How to factor 2048 bit RSA integers with less than a million noisy qubits
Canonical reference. 82% of citing Pith papers cite this work as background.
abstract
Planning the transition to quantum-safe cryptosystems requires understanding the cost of quantum attacks on vulnerable cryptosystems. In Gidney+Eker{\aa} 2019, I co-published an estimate stating that 2048 bit RSA integers could be factored in eight hours by a quantum computer with 20 million noisy qubits. In this paper, I substantially reduce the number of qubits required. I estimate that a 2048 bit RSA integer could be factored in less than a week by a quantum computer with less than a million noisy qubits. I make the same assumptions as in 2019: a square grid of qubits with nearest neighbor connections, a uniform gate error rate of $0.1\%$, a surface code cycle time of 1 microsecond, and a control system reaction time of $10$ microseconds. The qubit count reduction comes mainly from using approximate residue arithmetic (Chevignard+Fouque+Schrottenloher 2024), from storing idle logical qubits with yoked surface codes (Gidney+Newman+Brooks+Jones 2023), and from allocating less space to magic state distillation by using magic state cultivation (Gidney+Shutty+Jones 2024). The longer runtime is mainly due to performing more Toffoli gates and using fewer magic state factories compared to Gidney+Eker{\aa} 2019. That said, I reduce the Toffoli count by over 100x compared to Chevignard+Fouque+Schrottenloher 2024.
hub tools
citation-role summary
citation-polarity summary
representative citing papers
Classical repetition-code framing plus SAT search yields no-go theorems (no d>3 T-to-T on <8 qubits) and the smallest known unitary factories for d=4,5 T-states (10–11 qubits) and d=3,4 CCZ-states (9–10 qubits).
A new definition of quantum computer energy efficiency is introduced and applied to five major qubit platforms, yielding concrete consumption estimates for current systems and a benchmarking framework for future architectures.
LightStim automates DEM construction for QEC protocols via a record-augmented Pauli tableau tracker, validated across memory, logical operations, distillation, and a novel cross-code lattice surgery design.
A classical polynomial-time sampler exists for the output distribution of amplitude-damped IQP circuits with logarithmic depth and arbitrary l-local diagonal gates.
Pinnacle Architecture using QLDPC codes reduces physical qubits needed to factor RSA-2048 to under 100,000 at 10^{-3} error rate.
Tricycle codes generalize bicycle codes to three homological dimensions, enabling constant-depth CCZ circuits and single-shot magic state generation with circuit-level thresholds above 0.5% and low error rates at block lengths of 50-100 qubits.
Bivariate bicycle codes enable a modular architecture that supports an order of magnitude more logical circuit volume per physical qubit than surface-code designs under circuit noise.
Hardware experiment on IBM devices shows reset-free LUCI achieves logical X and Z error suppression ratios of 1.75(10) and 1.93(12), competitive with surface code despite halved syndrome density.
A calibration workflow using ELEA and CAFE circuits achieves CZ gate fidelity above 99.9% on an 84-qubit superconducting processor with 0.007% coherent error and median 99.25% across 72 gates.
A symmetry-co-designed high-rate QEC architecture with parallel STAR injection on bivariate bicycle codes achieves ~5.5x space savings for TFIM and Fermi-Hubbard simulations versus surface-code STAR.
Explicit quantum circuits for elliptic-curve point addition achieve 6.5-10% fewer Toffoli gates and 1.5% more qubits than Babbush et al. for secp256k1, plus a generic prime-field version.
Concatenating quantum Reed-Solomon codes over the gross code via Galois qudits reaches teraquop regime at uniform 10^{-3} noise with reduced overhead.
PIQC proposes a distributed FTQC architecture based on molecular quantum nodes with photonic integration, nuclear registers, loss-tolerant entanglement, and Floquetified qLDPC codes.
A forced-gap post-selection strategy using repeated Relay-BP decoder runs improves logical error rates by over 4x on 72- and 144-qubit bivariate bicycle codes at fixed post-selection rate.
A symmetry-leveraging framework for fault-tolerant ancilla preparation in quantum BCH codes yields lower spatial overhead and logical error rates than standard distillation in simulations up to 127 qubits.
Exact T-count minimization via precomputed optimal libraries up to 7 variables and Clifford canonicalization yields up to 14.3% T reduction on EPFL benchmarks and 40% on cryptographic modules.
A hot-zone architecture for OQFT on reconfigurable neutral-atom hardware yields tunable latency via 2-4 zones, converging to roughly 500 extra logical ancillae and 128-qubit peak parallelism for half-time performance on 256-2048 bit instances.
Proof-of-principle measurement-based blind quantum computation on a modular superconducting processor executing a 3-qubit Deutsch-Jozsa algorithm with verified information privacy.
Trapped-ion experiment generates all four Bell states of GKP qubits via beamsplitter interference of qunaught states and applies error correction to extend their lifetime.
Shor's algorithm generates and consumes magic resources in direct proportion to the difficulty of the underlying factoring problem.
The biplanar architecture maps Fermi-Hubbard spin sectors to two planes, eliminating swaps and cutting each Trotter step depth to 4t_synth + 90 logical timesteps versus 6t_synth + 354 in single-plane methods, yielding an estimated 2-hour runtime for L=8 with 1.35 million physical qubits under a 1% 1
FTPrimitiveBench is a new benchmark suite for testing surface-code logical primitives under Pauli-biased, measurement-biased, and spatially non-uniform noise models, revealing that noise structure interacts distinctly with each primitive and decoder.
A modular atomic processor with 500,000 qubits factors 2048-bit RSA numbers in roughly the same time as a single large module when inter-module Bell-pair communication runs at 10^5 per second.
citing papers explorer
-
Cultivating logical catalysts for fault-tolerant dyadic phase rotations
A new cultivation protocol prepares reusable logical catalysts as eigenstates of high-period Clifford circuits to implement exact Z^{2^{-b}} phase gates with constant online depth in surface codes.
-
Exploring the landscape of compact magic-state distillation factories
Classical repetition-code framing plus SAT search yields no-go theorems (no d>3 T-to-T on <8 qubits) and the smallest known unitary factories for d=4,5 T-states (10–11 qubits) and d=3,4 CCZ-states (9–10 qubits).
-
Energy efficiency of quantum computers
A new definition of quantum computer energy efficiency is introduced and applied to five major qubit platforms, yielding concrete consumption estimates for current systems and a benchmarking framework for future architectures.
-
Novelty-Based Generation of Continuous Landscapes with Diverse Local Optima Networks
LightStim automates DEM construction for QEC protocols via a record-augmented Pauli tableau tracker, validated across memory, logical operations, distillation, and a novel cross-code lattice surgery design.
-
Efficient simulation of noisy IQP circuits with amplitude-damping noise
A classical polynomial-time sampler exists for the output distribution of amplitude-damped IQP circuits with logarithmic depth and arbitrary l-local diagonal gates.
-
The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes
Pinnacle Architecture using QLDPC codes reduces physical qubits needed to factor RSA-2048 to under 100,000 at 10^{-3} error rate.
-
Magic tricycles: Efficient magic state generation with finite block-length quantum LDPC codes
Tricycle codes generalize bicycle codes to three homological dimensions, enabling constant-depth CCZ circuits and single-shot magic state generation with circuit-level thresholds above 0.5% and low error rates at block lengths of 50-100 qubits.
-
Tour de gross: A modular quantum computer based on bivariate bicycle codes
Bivariate bicycle codes enable a modular architecture that supports an order of magnitude more logical circuit volume per physical qubit than surface-code designs under circuit noise.
-
LUCI on IBM Hardware: Error Suppression with Almost Half Syndrome Density
Hardware experiment on IBM devices shows reset-free LUCI achieves logical X and Z error suppression ratios of 1.75(10) and 1.93(12), competitive with surface code despite halved syndrome density.
-
High-Precision Calibration Workflow Achieves Above $99.9\%$ CZ Gate Fidelity on a Scalable Superconducting Processor
A calibration workflow using ELEA and CAFE circuits achieves CZ gate fidelity above 99.9% on an 84-qubit superconducting processor with 0.007% coherent error and median 99.25% across 72 gates.
-
Fast and Parallel High-Rate STAR Architecture for Megaquop Quantum Simulation
A symmetry-co-designed high-rate QEC architecture with parallel STAR injection on bivariate bicycle codes achieves ~5.5x space savings for TFIM and Fermi-Hubbard simulations versus surface-code STAR.
-
Optimized Point Addition Circuits for Elliptic Curve Discrete Logarithms
Explicit quantum circuits for elliptic-curve point addition achieve 6.5-10% fewer Toffoli gates and 1.5% more qubits than Babbush et al. for secp256k1, plus a generic prime-field version.
-
Concatenating Algebraic Codes over High-Rate Quantum LDPC Codes
Concatenating quantum Reed-Solomon codes over the gross code via Galois qudits reaches teraquop regime at uniform 10^{-3} noise with reduced overhead.
-
PIQC: Scalable Distributed Quantum Computing via Photonic Integration of Designed Molecular Quantum Nodes
PIQC proposes a distributed FTQC architecture based on molecular quantum nodes with photonic integration, nuclear registers, loss-tolerant entanglement, and Floquetified qLDPC codes.
-
Forced Gap Post-Selection for Quantum LDPC Codes and their Operations
A forced-gap post-selection strategy using repeated Relay-BP decoder runs improves logical error rates by over 4x on 72- and 144-qubit bivariate bicycle codes at fixed post-selection rate.
-
Efficient Fault-Tolerant Ancilla Preparation for Quantum BCH codes via Cyclic Symmetry
A symmetry-leveraging framework for fault-tolerant ancilla preparation in quantum BCH codes yields lower spatial overhead and logical error rates than standard distillation in simulations up to 127 qubits.
-
Quantum Circuit Synthesis Using an Exact T Library
Exact T-count minimization via precomputed optimal libraries up to 7 variables and Clifford canonicalization yields up to 14.3% T reduction on EPFL benchmarks and 40% on cryptographic modules.
-
Towards Deploying Optimistic Quantum Fourier Transforms: An Architecture-Algorithm Co-Design Study
A hot-zone architecture for OQFT on reconfigurable neutral-atom hardware yields tunable latency via 2-4 zones, converging to roughly 500 extra logical ancillae and 128-qubit peak parallelism for half-time performance on 256-2048 bit instances.
-
Blind Quantum Computation on a Modular Superconducting Processor
Proof-of-principle measurement-based blind quantum computation on a modular superconducting processor executing a 3-qubit Deutsch-Jozsa algorithm with verified information privacy.
-
Error Correction of Beamsplitter-Generated Entangled GKP States
Trapped-ion experiment generates all four Bell states of GKP qubits via beamsplitter interference of qunaught states and applies error correction to extend their lifetime.
-
The true cost of factoring: Linking magic and number-theoretic complexity in Shor's algorithm
Shor's algorithm generates and consumes magic resources in direct proportion to the difficulty of the underlying factoring problem.
-
Two Layers, No Swaps: Biplanar SPOQC Architecture Improves Runtime of Fermi-Hubbard Simulation
The biplanar architecture maps Fermi-Hubbard spin sectors to two planes, eliminating swaps and cutting each Trotter step depth to 4t_synth + 90 logical timesteps versus 6t_synth + 354 in single-plane methods, yielding an estimated 2-hour runtime for L=8 with 1.35 million physical qubits under a 1% 1
-
FTPrimitiveBench: A Benchmark Suite For Logical Computation Under Hardware-Motivated and Biased Noise Models
FTPrimitiveBench is a new benchmark suite for testing surface-code logical primitives under Pauli-biased, measurement-biased, and spatially non-uniform noise models, revealing that noise structure interacts distinctly with each primitive and decoder.
-
Factoring $2048$ bit RSA integers with a half-million-qubit modular atomic processor
A modular atomic processor with 500,000 qubits factors 2048-bit RSA numbers in roughly the same time as a single large module when inter-module Bell-pair communication runs at 10^5 per second.
-
High-fidelity entangling gates and nonlocal circuits with neutral atoms
Neutral-atom system delivers state-of-the-art CZ gate fidelity of 99.854% (99.941% postselected) and demonstrates coherent rearrangement for nonlocal quantum circuits.
-
Millikelvin digital-to-analog converter for superconducting quantum processors
A millikelvin superconducting DAC integrated with fluxonium qubits generates persistent flux tuning signals via SFQ pulses without measurable coherence degradation.
-
LightStim: A Framework for QEC Protocol Evaluation and Prototyping with Automated DEM Construction
A tree-encoded fusion scheme and MemTree compiler suppress fusion erasure errors in photonic MBQC, achieving large execution-time reductions over prior compilers with real-hardware validation.
-
Assessing System Capabilities and Bottlenecks of an Early Fault-Tolerant Bicycle Architecture
Syn@fac optimization reduces estimated circuit failure probability by a factor of 9 on average across non-Clifford benchmarks for bivariate bicycle code modular FTQC architectures, with additional gains from transvection deferral and Clifford insertion.
-
Fault-Tolerant Quantum Computing with Trapped Ions: The Walking Cat Architecture
A trapped-ion architecture based on LDPC codes and cat-state factories achieves 110 logical qubits and one million T gates per day using 2514 physical qubits, with estimates for Heisenberg model simulation on 100 sites in one month using 10000 qubits.
-
QLLVM: A Scalable Quantum-Classical Co-Compilation Framework based on LLVM
QLLVM delivers an LLVM-based end-to-end co-compiler that unifies classical HPC and quantum programs into one executable, with a three-stage quantum path via MLIR and QIR that reduces circuit depth and gate counts on MQTBench versus prior compilers.
-
dqc_simulator: an easy-to-use distributed quantum computing simulator
dqc_simulator is a new Python toolkit for automating realistic simulations of both hardware and software in distributed quantum computing systems.
-
Fast measurement of neutral atoms with a multi-atom gate
A multi-atom Rydberg gate with N ancillae enables N-fold photon collection for fast neutral-atom measurement, achieving infidelity below 10^{-3} in 6 μs with N=5 in Cs-Rb simulations.
-
Long-range tunable coupler for modular fluxonium quantum processors
A tunable coupler design enables sub-100 ns two-qubit gates with errors below 10^{-4} between fluxonium qubits over 1 cm distances for modular architectures.
-
Heterogeneous architectures enable a 138x reduction in physical qubit requirements for fault-tolerant quantum computing under detailed accounting
Heterogeneous quantum architectures with task-specific hardware and QEC encodings deliver up to 138x lower physical-qubit overhead than monolithic baselines for fault-tolerant algorithms, including RSA-2048 factoring at 190k-381k qubits.
-
Space-Efficient Quantum Algorithm for Elliptic Curve Discrete Logarithms with Resource Estimation
A space-efficient quantum ECDLP algorithm uses 5n + 4⌊log₂n⌋ + O(1) logical qubits and O(n³) Toffoli gates, lowering the 256-bit estimate from 2124 to 1333 qubits.
-
Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations
Resource estimates show Shor's algorithm can break 256-bit ECDLP with fewer than 1450 logical qubits and 90 million Toffoli gates on fast-clock quantum hardware, enabling on-spend attacks on cryptocurrency mempools.
-
Low Latency GNN Accelerator for Quantum Error Correction
Hardware-guided pruning and quantization make a GNN surface-code decoder meet ~1 µs real-time latency on FPGA while cutting logical error rate 13–40% versus MWPM at d≤7, p=10⁻³.
-
Protection of Exponential Operation using Stabilizer Codes in the Early Fault Tolerance Era
A new encoding scheme for exp(-iθP) into stabilizer codes like [[n,n-2,2]] and [[5,1,3]] achieves 4-7x lower noise than unencoded versions with at most 3% runs discarded after postselection.
-
PureMagic: A Dynamic Scheduler for Lattice Surgery
Repurposing ancilla qubits for both magic-state cultivation and routing improves lattice-surgery schedule efficiency by 19-223% over dedicated-bus routing in simulations.
-
Entanglement boosting: Low-volume logical Bell pair preparation for distributed fault-tolerant quantum computation
Entanglement boosting protocol prepares logical Bell pairs in rotated surface codes with orders-of-magnitude lower link-limited volume, reaching 10^{-10} logical error from 86 physical pairs at 1% error using soft decoders and postselection within one patch.
-
Superconducting Qubit Readout Using Next-Generation Reservoir Computing
Reservoir computing using polynomial features from measurement signals achieves up to 50% error reduction on single-qubit and 11% on five-qubit datasets with 100x fewer multiplications than neural networks while reducing crosstalk.
-
Blueprint for a fault-tolerant compound photon-atom quantum architecture
Blueprint for a cavity-QED photon-atom platform that generates large-scale cluster states via atomic reuse and achieves a simulated 2.6% photon-loss threshold on the RHG lattice for fault-tolerant Clifford operations.
-
A Modular Benchmark of Variational Quantum Attack Algorithms for S-DES
A modular benchmarking framework is developed for variational quantum attacks on S-DES, with numerical simulations comparing design alternatives across four components and introducing standardized performance metrics.
-
Nanostructure modelling with early fault tolerant quantum computers
Quantum simulation framework for ground-state energies of 4- and 8-electron double quantum dots on surface-code fault-tolerant hardware, with resource estimates of 226k-314k physical qubits and 24 hours to 3.4 days runtime at 10^{-3} noise.
-
Hardware-Tailored Resource Estimation for Magic-State Distillation on Silicon Spin Qubits
Resource estimation for magic-state distillation on silicon spin qubits finds 42% overhead reduction via optimized pulses and ~3x physical footprint reduction with biased codes versus surface code.
-
Tolerating Device Failure in Distributed Quantum Computing
Distributed toric and hyperbolic Floquet codes maintain logical error suppression when entire nodes fail at low rates, with the toric code outperforming a monolithic device below 0.05% physical error rate for node failure probability p/100.
-
ADaPT: Adaptive-window Decoding for Practical fault-Tolerance
Adaptive-window decoding that shrinks or expands based on decoder confidence cuts reaction-time overhead in quantum error correction without raising logical error rates.
-
Demonstrating Record Fidelity for the Quantum Fourier Transform
A compilation scheme called Parity Twine achieved a 50-qubit unitary QFT with process fidelity ≈1e-2 on IBM Heron r3, and up to 52 qubits with plurality voting, surpassing prior unitary QFT demonstrations.
-
Operational criteria for quantum advantage in latency-constrained nonlocal games
A framework with operational criteria and a trapped-atom hardware proposal for achieving statistically significant quantum advantage in latency-constrained nonlocal games.
-
Integration and Resource Estimation of Cryoelectronics for Superconducting Fault-Tolerant Quantum Computers
This review surveys cryogenic electronics approaches for superconducting FTQCs and introduces a first-order resource estimation framework benchmarked on RSA-2048 scale.