A high-level comparison of state-of-the-art quantum algorithms for breaking asymmetric cryptography

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ekerå, Martin, Gärtner, Joel
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908307584712704
author Ekerå, Martin
Gärtner, Joel
author_facet Ekerå, Martin
Gärtner, Joel
contents We provide a high-level cost comparison between Regev's quantum algorithm with Ekerå-Gärtner's extensions on the one hand, and existing state-of-the-art quantum algorithms for factoring and computing discrete logarithms on the other. This when targeting cryptographically relevant problem instances, and when accounting for the space-saving optimizations of Ragavan and Vaikuntanathan that apply to Regev's algorithm, and optimizations such as windowing that apply to the existing algorithms. Our conclusion is that Regev's algorithm without the space-saving optimizations may achieve a per-run advantage, but not an overall advantage, if non-computational quantum memory is cheap. Regev's algorithm with the space-saving optimizations does not achieve an advantage, since it uses more computational memory, whilst also performing more work, per run and overall, compared to the existing state-of-the-art algorithms. As such, further optimizations are required for it to achieve an advantage for cryptographically relevant problem instances.
format Preprint
id arxiv_https___arxiv_org_abs_2405_14381
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle A high-level comparison of state-of-the-art quantum algorithms for breaking asymmetric cryptography
Ekerå, Martin
Gärtner, Joel
Cryptography and Security
Quantum Physics
We provide a high-level cost comparison between Regev's quantum algorithm with Ekerå-Gärtner's extensions on the one hand, and existing state-of-the-art quantum algorithms for factoring and computing discrete logarithms on the other. This when targeting cryptographically relevant problem instances, and when accounting for the space-saving optimizations of Ragavan and Vaikuntanathan that apply to Regev's algorithm, and optimizations such as windowing that apply to the existing algorithms. Our conclusion is that Regev's algorithm without the space-saving optimizations may achieve a per-run advantage, but not an overall advantage, if non-computational quantum memory is cheap. Regev's algorithm with the space-saving optimizations does not achieve an advantage, since it uses more computational memory, whilst also performing more work, per run and overall, compared to the existing state-of-the-art algorithms. As such, further optimizations are required for it to achieve an advantage for cryptographically relevant problem instances.
title A high-level comparison of state-of-the-art quantum algorithms for breaking asymmetric cryptography
topic Cryptography and Security
Quantum Physics
url https://arxiv.org/abs/2405.14381