REVIEW 11 cited by
How to compute a 256-bit elliptic curve private key with only 50 million Toffoli gates
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
How to compute a 256-bit elliptic curve private key with only 50 million Toffoli gates
abstract
We use Shor's algorithm for the computation of elliptic curve private keys as a case study for resource estimates in the silicon-photonics-inspired active-volume architecture. Here, a fault-tolerant surface-code quantum computer consists of modules with a logarithmic number of non-local inter-module connections, modifying the algorithmic cost function compared to 2D-local architectures. We find that the non-local connections reduce the cost per key by a factor of 300-700 depending on the operating regime. At 10% threshold, assuming a 10-$\mu$s code cycle and non-local connections, one key can be generated every 10 minutes using 6000 modules with 1152 physical qubits each. By contrast, a device with strict 2D-local connectivity requires more qubits and produces one key every 38 hours. We also find simple architecture-independent algorithmic modifications that reduce the Toffoli count per key by up to a factor of 5. These modifications involve reusing the stored state for multiple keys and spreading the cost of the modular division operation over multiple parallel instances of the algorithm.
Forward citations
Cited by 11 Pith papers
-
Exploring the landscape of compact magic-state distillation factories
Classical codes plus SAT search yield no-go theorems limiting error detection in sub-8-qubit distillation and new minimal-qubit protocols for T-to-T (distances 4-5 on 10-11 qubits) and T-to-CCZ (distances 3-4 on 9-10 qubits).
-
Exploring the landscape of compact magic-state distillation factories
Classical repetition-code framing plus SAT search yields no-go theorems (no d>3 T-to-T on <8 qubits) and the smallest known unitary factories for d=4,5 T-states (10–11 qubits) and d=3,4 CCZ-states (9–10 qubits).
-
The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes
Pinnacle Architecture using QLDPC codes reduces physical qubits needed to factor RSA-2048 to under 100,000 at 10^{-3} error rate.
-
Fast and Parallel High-Rate STAR Architecture for Megaquop Quantum Simulation
A symmetry-co-designed high-rate QEC architecture with parallel STAR injection on bivariate bicycle codes achieves ~5.5x space savings for TFIM and Fermi-Hubbard simulations versus surface-code STAR.
-
Optimized Point Addition Circuits for Elliptic Curve Discrete Logarithms
Explicit quantum circuits for elliptic-curve point addition achieve 6.5-10% fewer Toffoli gates and 1.5% more qubits than Babbush et al. for secp256k1, plus a generic prime-field version.
-
Towards Deploying Optimistic Quantum Fourier Transforms: An Architecture-Algorithm Co-Design Study
A hot-zone architecture for OQFT on reconfigurable neutral-atom hardware yields tunable latency via 2-4 zones, converging to roughly 500 extra logical ancillae and 128-qubit peak parallelism for half-time performance ...
-
Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations
Resource estimates show Shor's algorithm can break 256-bit ECDLP with fewer than 1450 logical qubits and 90 million Toffoli gates on fast-clock quantum hardware, enabling on-spend attacks on cryptocurrency mempools.
-
Shor's algorithm is possible with as few as 10,000 reconfigurable atomic qubits
Shor's algorithm for cryptographically relevant problems becomes feasible on neutral-atom systems with as few as 10,000 reconfigurable physical qubits via high-rate quantum error correction.
-
On the practicality of quantum sieving algorithms for the shortest vector problem
Quantum sieving for SVP in dimension 400 needs ~10^13 physical qubits and ~10^31 years under optimistic assumptions, offering no practical speedup over classical methods.
-
Hardware-Tailored Resource Estimation for Magic-State Distillation on Silicon Spin Qubits
Resource estimation for magic-state distillation on silicon spin qubits finds 42% overhead reduction via optimized pulses and ~3x physical footprint reduction with biased codes versus surface code.
-
Strategic Plan for Neutral Atom Quantum Computation
If qubit-count growth (~1.8x/yr) and gate-error reduction (~0.62x/yr) continue, neutral-atom quantum computers could reach practical quantum advantage within a decade, this roadmap projects.
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.