Applying Grover's algorithm to AES: quantum resource estimates
From MaRDI portal
(Redirected from Publication:2802601)
Abstract: We present quantum circuits to implement an exhaustive key search for the Advanced Encryption Standard (AES) and analyze the quantum resources required to carry out such an attack. We consider the overall circuit size, the number of qubits, and the circuit depth as measures for the cost of the presented quantum algorithms. Throughout, we focus on Clifford gates as the underlying fault-tolerant logical quantum gate set. In particular, for all three variants of AES (key size 128, 192, and 256 bit) that are standardized in FIPS-PUB 197, we establish precise bounds for the number of qubits and the number of elementary logical quantum gates that are needed to implement Grover's quantum algorithm to extract the key from a small number of AES plaintext-ciphertext pairs.
Recommendations
- Implementing Grover oracles for quantum key search on AES and LowMC
- Quantum resource estimates of Grover's key search on ARIA
- Improvements to quantum search techniques for block-ciphers, with applications to AES
- Quantum resource estimation for FSR based symmetric ciphers and related Grover's attacks
- Quantum circuit implementations of AES with fewer qubits
Cited in
(66)- Quantum implementation and resource estimates for rectangle and knot
- Quantum cryptanalysis of ZUC and related resource estimation
- Evaluation of quantum cryptanalysis on SPECK
- Parallel quantum addition for Korean block ciphers
- Grover on SM3
- Some efficient quantum circuit implementations of Camellia
- Improvements to quantum search techniques for block-ciphers, with applications to AES
- Low-gate quantum golden collision finding
- Concrete resource analysis of the quantum linear-system algorithm used to compute the electromagnetic scattering cross section of a 2D target
- Efficient quantum algorithms related to autocorrelation spectrum
- Towards large-scale functional verification of universal quantum circuits
- Quantum circuits of AES with a low-depth linear layer and a new structure
- Using frequency analysis and Grover's algorithm to implement known ciphertext attack on symmetric ciphers
- Quantum algorithm design: techniques and applications
- Optimized quantum implementation of AES
- New quantum circuit implementations of SM4 and SM3
- Implementation of efficient quantum search algorithms on NISQ computers
- Quantum Demiric-Selcuk meet-in-the-middle attacks on reduced-round AES
- Quantum circuit implementation and security analysis of IVLBC
- Grover on \(SIMON\)
- Quantum search for scaled hash function preimages
- Implementing Grover oracle for lightweight block ciphers under depth constraints
- Quantum algorithm for Boolean equation solving and quantum algebraic attack on cryptosystems
- Quantum resource estimation for FSR based symmetric ciphers and related Grover's attacks
- Quantum reversible circuit of AES-128
- Quantum implementation and analysis of Default
- A practical-quantum differential attack on block ciphers
- On recovering block cipher secret keys in the cold boot attack setting
- Estimating the cost of generic quantum pre-image attacks on SHA-2 and SHA-3
- Quantum key search with side channel advice
- Low-communication parallel quantum multi-target preimage search
- Improved quantum analysis of SPECK and LowMC
- A new quantum oracle model for a hybrid quantum-classical attack on post-quantum lattice-based cryptosystems
- Quantum security analysis of Rocca
- Implementing Grover oracles for quantum key search on AES and LowMC
- Quantum security analysis of CSIDH
- Time-space complexity of quantum search algorithms in symmetric cryptanalysis: applying to AES and SHA-2
- A framework for reducing the overhead of the quantum oracle for use with Grover's algorithm with applications to cryptanalysis of SIKE
- Concrete analysis of quantum lattice enumeration
- Improved quantum circuits for AES: reducing the depth and the number of qubits
- Synthesizing quantum circuits of AES with lower \(T\)-depth and less qubits
- Quantum circuit implementations of SM4 block cipher based on different gate sets
- Leveraging Grover's algorithm for quantum searchable encryption in cloud infrastructure and its application in AES resource estimation
- Optimization of \(S\)-boxes GOST R 34.12-2015 ``Magma quantum circuits without ancilla qubits
- Optimized reversible quantum circuits for \(\mathbb{F}_{2^8}\) multiplication
- A trade-off between classical and quantum circuit size for an attack against CSIDH
- Evaluation of Grover's algorithm toward quantum cryptanalysis on ChaCha
- A note on quantum collision resistance of double-block-length compression functions
- Breaking LWC candidates: sESTATE and Elephant in quantum setting
- Further insights on constructing quantum circuits for Camellia block cipher
- Optimizing the depth of quantum implementations of linear layers
- Quantum circuit implementations of AES with fewer qubits
- New results in quantum analysis of LED: featuring one and two oracle attacks
- Quantum circuit implementation and resource analysis of LBlock and LiCi
- Grover on chosen IV related key attack against GRAIN-128a
- On the construction of quantum circuits for S-boxes with different criteria based on the SAT solver
- Quantum secure multiparty secret sharing using quantum non-locality
- Estimates of implementation complexity for quantum cryptanalysis of post-quantum lattice-based cryptosystems
- Quantum computing and fuzzy logic
- Characterizing the qIND-qCPA (In)security of the CBC, CFB, OFB and CTR Modes of Operation
- Constructing quantum implementations with the minimal T-depth or minimal width and their applications
- Quantum reversible circuits for \(\mathrm{GF}(2^8)\) multiplication based on composite field arithmetic operations
- Estimating quantum speedups for lattice sieves
- Post-quantum block cipher-based symmetric cryptography: existing results and topical research directions
- Quantum resource estimates of Grover's key search on ARIA
- Depth-measurement trade-off for quantum search on block ciphers
This page was built for publication: Applying Grover's algorithm to AES: quantum resource estimates
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q2802601)