Pith. sign in

REVIEW 8 cited by

How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1905.09749 v3 pith:QY7KEQYY submitted 2019-05-23 quant-ph

How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits

classification quant-ph
keywords integersconstructionekerqubitscosterrorfactorfactoring
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved
0 comments
Share X Bluesky LinkedIn Reddit HN
abstract

We significantly reduce the cost of factoring integers and computing discrete logarithms in finite fields on a quantum computer by combining techniques from Shor 1994, Griffiths-Niu 1996, Zalka 2006, Fowler 2012, Eker{\aa}-H{\aa}stad 2017, Eker{\aa} 2017, Eker{\aa} 2018, Gidney-Fowler 2019, Gidney 2019. We estimate the approximate cost of our construction using plausible physical assumptions for large-scale superconducting qubit platforms: a planar grid of qubits with nearest-neighbor connectivity, a characteristic physical gate error rate of $10^{-3}$, a surface code cycle time of 1 microsecond, and a reaction time of 10 microseconds. We account for factors that are normally ignored such as noise, the need to make repeated attempts, and the spacetime layout of the computation. When factoring 2048 bit RSA integers, our construction's spacetime volume is a hundredfold less than comparable estimates from earlier works (Van Meter et al. 2009, Jones et al. 2010, Fowler et al. 2012, Gheorghiu et al. 2019). In the abstract circuit model (which ignores overheads from distillation, routing, and error correction) our construction uses $3 n + 0.002 n \lg n$ logical qubits, $0.3 n^3 + 0.0005 n^3 \lg n$ Toffolis, and $500 n^2 + n^2 \lg n$ measurement depth to factor $n$-bit RSA integers. We quantify the cryptographic implications of our work, both for RSA and for schemes based on the DLP in finite fields.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 8 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Borrowed Identities: Malleable Distillation Factories and a Unified Numerical Search

    quant-ph 2026-06 accept novelty 7.5

    A borrowed-identity condition unifies magic-state distillation across Clifford levels and output types, recovering all known distance-2 factories in one search and enabling malleable parent circuits.

  2. Borrowed Identities: Malleable Distillation Factories and a Unified Numerical Search

    quant-ph 2026-06 unverdicted novelty 7.0

    Borrowed-identity condition unifies numerical searches for magic-state distillation factories across Clifford hierarchy levels and code families.

  3. Zeno-Enhanced Probabilistic Error Cancellation with Quantum Error Detection Codes

    quant-ph 2026-05 unverdicted novelty 7.0

    Using post-selection to map physical noise to a weaker accepted logical channel and then applying order-K perturbative PEC reduces sampling overhead by 3-4 orders of magnitude for logical GHZ preparation on up to 200 ...

  4. The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes

    quant-ph 2026-02 unverdicted novelty 7.0

    Pinnacle Architecture using QLDPC codes reduces physical qubits needed to factor RSA-2048 to under 100,000 at 10^{-3} error rate.

  5. Magic states are rarely the best resource to optimize: An analytical tool for qubit resource estimation in concatenated codes

    quant-ph 2024-11 conditional novelty 7.0

    A closed-form resource estimation tool for concatenated quantum error correction reveals that magic-state operations rarely dominate qubit costs, with general optimizations providing orders-of-magnitude larger reducti...

  6. Fast and Parallel High-Rate STAR Architecture for Megaquop Quantum Simulation

    quant-ph 2026-06 unverdicted novelty 6.0

    A symmetry-co-designed high-rate QEC architecture with parallel STAR injection on bivariate bicycle codes achieves ~5.5x space savings for TFIM and Fermi-Hubbard simulations versus surface-code STAR.

  7. Resource-efficient equivariant quantum convolutional neural networks

    quant-ph 2024-10 unverdicted novelty 6.0

    Equivariant sp-QCNN encodes general symmetries with group theory, splits circuits at pooling layers to preserve symmetry while enabling parallel measurements, and shows improved efficiency and trainability over standa...

  8. Cybersecurity in the Quantum Era: Assessing the Impact of Quantum Computing on Infrastructure

    cs.CR 2024-04 unverdicted novelty 2.0

    The paper assesses quantum computing threats to cybersecurity across infrastructure layers and proposes a nine-component blueprint for quantum-resistant defenses.