Applying Grover's algorithm to AES: quantum resource estimates
From MaRDI portal
Abstract: We present quantum circuits to implement an exhaustive key search for the Advanced Encryption Standard (AES) and analyze the quantum resources required to carry out such an attack. We consider the overall circuit size, the number of qubits, and the circuit depth as measures for the cost of the presented quantum algorithms. Throughout, we focus on Clifford gates as the underlying fault-tolerant logical quantum gate set. In particular, for all three variants of AES (key size 128, 192, and 256 bit) that are standardized in FIPS-PUB 197, we establish precise bounds for the number of qubits and the number of elementary logical quantum gates that are needed to implement Grover's quantum algorithm to extract the key from a small number of AES plaintext-ciphertext pairs.
Recommendations
- Implementing Grover oracles for quantum key search on AES and LowMC
- Quantum resource estimates of Grover's key search on ARIA
- Improvements to quantum search techniques for block-ciphers, with applications to AES
- Quantum resource estimation for FSR based symmetric ciphers and related Grover's attacks
- Quantum circuit implementations of AES with fewer qubits
Cited in
(67)- Quantum reversible circuit of AES-128
- Estimating the cost of generic quantum pre-image attacks on SHA-2 and SHA-3
- Quantum algorithm design: techniques and applications
- Low-communication parallel quantum multi-target preimage search
- Quantum key search with side channel advice
- Time-space complexity of quantum search algorithms in symmetric cryptanalysis: applying to AES and SHA-2
- A trade-off between classical and quantum circuit size for an attack against CSIDH
- A framework for reducing the overhead of the quantum oracle for use with Grover's algorithm with applications to cryptanalysis of SIKE
- Breaking LWC candidates: sESTATE and Elephant in quantum setting
- Quantum resource estimates of Grover's key search on ARIA
- Evaluation of Grover's algorithm toward quantum cryptanalysis on ChaCha
- Quantum implementation and resource estimates for rectangle and knot
- Parallel quantum addition for Korean block ciphers
- Grover on SM3
- Some efficient quantum circuit implementations of Camellia
- New quantum circuit implementations of SM4 and SM3
- Quantum Demiric-Selcuk meet-in-the-middle attacks on reduced-round AES
- Implementing Grover oracles for quantum key search on AES and LowMC
- Quantum security analysis of CSIDH
- Quantum algorithm for Boolean equation solving and quantum algebraic attack on cryptosystems
- A note on quantum collision resistance of double-block-length compression functions
- Evaluation of quantum cryptanalysis on SPECK
- Efficient quantum algorithms related to autocorrelation spectrum
- Concrete resource analysis of the quantum linear-system algorithm used to compute the electromagnetic scattering cross section of a 2D target
- Using frequency analysis and Grover's algorithm to implement known ciphertext attack on symmetric ciphers
- Grover on \(SIMON\)
- Optimized reversible quantum circuits for \(\mathbb{F}_{2^8}\) multiplication
- Quantum reversible circuits for \(\mathrm{GF}(2^8)\) multiplication based on composite field arithmetic operations
- Quantum search for scaled hash function preimages
- Implementation of efficient quantum search algorithms on NISQ computers
- Estimating quantum speedups for lattice sieves
- Quantum circuit implementations of AES with fewer qubits
- Optimization of \(S\)-boxes GOST R 34.12-2015 ``Magma quantum circuits without ancilla qubits
- Towards large-scale functional verification of universal quantum circuits
- Quantum security analysis of Rocca
- Quantum circuit implementation and resource analysis of LBlock and LiCi
- Optimized quantum implementation of AES
- Implementing Grover oracle for lightweight block ciphers under depth constraints
- Optimizing the depth of quantum implementations of linear layers
- Synthesizing quantum circuits of AES with lower \(T\)-depth and less qubits
- Quantum resource estimation for FSR based symmetric ciphers and related Grover's attacks
- Improved quantum analysis of SPECK and LowMC
- Quantum circuit implementations of SM4 block cipher based on different gate sets
- Further insights on constructing quantum circuits for Camellia block cipher
- Characterizing the qIND-qCPA (In)security of the CBC, CFB, OFB and CTR Modes of Operation
- Depth-measurement trade-off for quantum search on block ciphers
- Improved quantum circuits for AES: reducing the depth and the number of qubits
- Concrete analysis of quantum lattice enumeration
- Leveraging Grover's algorithm for quantum searchable encryption in cloud infrastructure and its application in AES resource estimation
- Grover on chosen IV related key attack against GRAIN-128a
- Estimates of implementation complexity for quantum cryptanalysis of post-quantum lattice-based cryptosystems
- New results in quantum analysis of LED: featuring one and two oracle attacks
- On the construction of quantum circuits for S-boxes with different criteria based on the SAT solver
- Quantum secure multiparty secret sharing using quantum non-locality
- Quantum computing and fuzzy logic
- Constructing quantum implementations with the minimal T-depth or minimal width and their applications
- Post-quantum block cipher-based symmetric cryptography: existing results and topical research directions
- Quantum cryptanalysis of ZUC and related resource estimation
- Quantum circuits of AES with a low-depth linear layer and a new structure
- Quantum circuit implementation and security analysis of IVLBC
- Quantum implementation and analysis of Default
- A practical-quantum differential attack on block ciphers
- On recovering block cipher secret keys in the cold boot attack setting
- A new quantum oracle model for a hybrid quantum-classical attack on post-quantum lattice-based cryptosystems
- Asymptotic optimality of Grover-Radhakrishnan-Korepin algorithm
- Low-gate quantum golden collision finding
- Improvements to quantum search techniques for block-ciphers, with applications to AES
This page was built for publication: Applying Grover's algorithm to AES: quantum resource estimates
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q2802601)