Pith. sign in

REVIEW 11 cited by

How to compute a 256-bit elliptic curve private key with only 50 million Toffoli gates

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2306.08585 v1 pith:WSOA3HXU submitted 2023-06-14 quant-ph

How to compute a 256-bit elliptic curve private key with only 50 million Toffoli gates

classification quant-ph
keywords connectionscostnon-localalgorithmalgorithmiccurved-localelliptic
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved
0 comments
Share X Bluesky LinkedIn Reddit HN
abstract

We use Shor's algorithm for the computation of elliptic curve private keys as a case study for resource estimates in the silicon-photonics-inspired active-volume architecture. Here, a fault-tolerant surface-code quantum computer consists of modules with a logarithmic number of non-local inter-module connections, modifying the algorithmic cost function compared to 2D-local architectures. We find that the non-local connections reduce the cost per key by a factor of 300-700 depending on the operating regime. At 10% threshold, assuming a 10-$\mu$s code cycle and non-local connections, one key can be generated every 10 minutes using 6000 modules with 1152 physical qubits each. By contrast, a device with strict 2D-local connectivity requires more qubits and produces one key every 38 hours. We also find simple architecture-independent algorithmic modifications that reduce the Toffoli count per key by up to a factor of 5. These modifications involve reusing the stored state for multiple keys and spreading the cost of the modular division operation over multiple parallel instances of the algorithm.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 11 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Exploring the landscape of compact magic-state distillation factories

    quant-ph 2026-06 unverdicted novelty 8.0

    Classical codes plus SAT search yield no-go theorems limiting error detection in sub-8-qubit distillation and new minimal-qubit protocols for T-to-T (distances 4-5 on 10-11 qubits) and T-to-CCZ (distances 3-4 on 9-10 qubits).

  2. Exploring the landscape of compact magic-state distillation factories

    quant-ph 2026-06 accept novelty 7.0

    Classical repetition-code framing plus SAT search yields no-go theorems (no d>3 T-to-T on <8 qubits) and the smallest known unitary factories for d=4,5 T-states (10–11 qubits) and d=3,4 CCZ-states (9–10 qubits).

  3. The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes

    quant-ph 2026-02 unverdicted novelty 7.0

    Pinnacle Architecture using QLDPC codes reduces physical qubits needed to factor RSA-2048 to under 100,000 at 10^{-3} error rate.

  4. Fast and Parallel High-Rate STAR Architecture for Megaquop Quantum Simulation

    quant-ph 2026-06 unverdicted novelty 6.0

    A symmetry-co-designed high-rate QEC architecture with parallel STAR injection on bivariate bicycle codes achieves ~5.5x space savings for TFIM and Fermi-Hubbard simulations versus surface-code STAR.

  5. Optimized Point Addition Circuits for Elliptic Curve Discrete Logarithms

    quant-ph 2026-06 unverdicted novelty 6.0

    Explicit quantum circuits for elliptic-curve point addition achieve 6.5-10% fewer Toffoli gates and 1.5% more qubits than Babbush et al. for secp256k1, plus a generic prime-field version.

  6. Towards Deploying Optimistic Quantum Fourier Transforms: An Architecture-Algorithm Co-Design Study

    quant-ph 2026-05 unverdicted novelty 6.0

    A hot-zone architecture for OQFT on reconfigurable neutral-atom hardware yields tunable latency via 2-4 zones, converging to roughly 500 extra logical ancillae and 128-qubit peak parallelism for half-time performance ...

  7. Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations

    quant-ph 2026-03 conditional novelty 6.0

    Resource estimates show Shor's algorithm can break 256-bit ECDLP with fewer than 1450 logical qubits and 90 million Toffoli gates on fast-clock quantum hardware, enabling on-spend attacks on cryptocurrency mempools.

  8. Shor's algorithm is possible with as few as 10,000 reconfigurable atomic qubits

    quant-ph 2026-03 unverdicted novelty 6.0

    Shor's algorithm for cryptographically relevant problems becomes feasible on neutral-atom systems with as few as 10,000 reconfigurable physical qubits via high-rate quantum error correction.

  9. On the practicality of quantum sieving algorithms for the shortest vector problem

    quant-ph 2024-10 unverdicted novelty 6.0

    Quantum sieving for SVP in dimension 400 needs ~10^13 physical qubits and ~10^31 years under optimistic assumptions, offering no practical speedup over classical methods.

  10. Hardware-Tailored Resource Estimation for Magic-State Distillation on Silicon Spin Qubits

    quant-ph 2026-05 unverdicted novelty 5.0

    Resource estimation for magic-state distillation on silicon spin qubits finds 42% overhead reduction via optimized pulses and ~3x physical footprint reduction with biased codes versus surface code.

  11. Strategic Plan for Neutral Atom Quantum Computation

    quant-ph 2026-07 conditional novelty 3.0

    If qubit-count growth (~1.8x/yr) and gate-error reduction (~0.62x/yr) continue, neutral-atom quantum computers could reach practical quantum advantage within a decade, this roadmap projects.