Search arXivSearch

arXiv · 2408.16458

Quantum Sieving for Code-Based Cryptanalysis and Its Limitations for ISD

Abstract

Sieving using near-neighbor search techniques is a well-known method in lattice-based cryptanalysis, yielding the current best runtime for the shortest vector problem in both the classical [BDGL16] and quantum [BCSS23] setting. Recently, sieving has also become an important tool in code-based cryptanalysis. Specifically, using a sieving subroutine, [GJN23, DEEK24] presented a variant of the information-set decoding (ISD) framework, which is commonly used for attacking cryptographically relevant instances of the decoding problem. The resulting sieving-based ISD framework yields complexities close to the best-performing classical algorithms for the decoding problem such as [BJMM12, BM18]. It is therefore natural to ask how well quantum versions perform. In this work, we introduce the first quantum algorithms for code sieving by designing quantum variants of the aforementioned sieving subroutine. In particular, using quantum-walk techniques, we provide a speed-up over the best known classical algorithm from [DEEK24] and over a variant using Grover's algorithm [Gro96]. Our quantum-walk algorithm exploits the structure of the underlying search problem by adding a layer of locality-sensitive filtering, inspired by the quantum-walk algorithm for lattice sieving from [CL21]. We complement our asymptotic analysis of the quantum algorithms with numerical results, and observe that our quantum speed-ups for code sieving behave similarly as those observed in lattice sieving. In addition, we show that a natural quantum analog of the sieving-based ISD framework does not provide any speed-up over the first presented quantum ISD algorithm [Ber10]. Our analysis highlights that the framework should be adapted in order to outperform the state-of-the-art of quantum ISD algorithms [KT17, Kir18].

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Lynn Engelberts, Simona Etinski, Johanna Loyer. 2024-12-24. Quantum Sieving for Code-Based Cryptanalysis and Its Limitations for ISD. https://arxiv.org/abs/2408.16458

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Iteratively decoded magic state distillation

We present numerical simulation results for the 7-to-1 and 15-to-1 state distillation circuits, constructed using transversal CNOTs acting on multiple surface code patches. The distillation circuits are decoded iteratively using the method outlined in [arXiv:2407.20976]. We show that, with a re-configurable qubit architecture, we can perform fast magic state distillation in $\sim\mathcal{O}(1)$ code cycles. We confirm that both circuits suppress an injected input logical error rate $p$ to $\mathcal{O}(p^3)$ in the presence of additional circuit-level noise. This is done with two types of stabiliser proxies, distilling logical $|-\rangle$ and $|Y\rangle$ states, the latter is the intended state of the 7-to-1 circuit while a stabiliser-proxy for the 15-to-1 circuit. We then also provide numerical evidences for actual $|T\rangle$ state distillation using the 15-to-1 circuit with a faulty-$T$ measurement, leveraging recent near-Clifford simulation tools. Finally, we outline how ZX-calculus and Pauli webs can be used to benchmark stabiliser proxies for these distillation circuits.

quant-ph

Enhanced measurements on quantum computers via the simultaneous probing of non-commuting Pauli operators

Measuring the state of quantum computers is a highly non-trivial task, with implications for virtually all quantum algorithms. A promising avenue is multi-copy schemes, where identical copies of a quantum state are measured jointly so that all Pauli operators within the considered observable can be simultaneously assessed. Here, we present a first implementation of such a two-copy scheme in a measurement protocol. Based on Bayesian statistics, it accurately estimates not only the average of the desired observable but also the error en route. This enables an adaptive shot-allocation algorithm that preferentially samples the most uncertain Pauli terms. In regimes with many non-commuting Pauli operators, this ``double'' scheme can outperform the state-of-the-art measurement protocol in minimizing total shots for a given precision. We also numerically confirm the finding in previous theoretical works that the two-copy scheme incurs an overhead due to the square-root relationship between the variance of measured quantities and the number of measurement shots.

quant-ph

Thermodynamics of a phaseonium-driven optomechanical Otto engine

We study an optomechanical Otto engine whose working medium is a single-mode cavity driven by beams of coherently prepared three-level phaseonium atoms. The atoms are not thermal reservoirs in the Gibbs sense; rather, their populations and ground-state coherence set the detailed-balance ratio of the cavity collision map, so that the field relaxes to a Gibbs state at an operational apparent temperature. We combine the finite-time collision-model dynamics with radiation-pressure work extraction and compare three reservoir preparations: a thermal reference at the same apparent temperatures, an incoherent atomic beam with the same populations, and the coherent phaseonium beam. We show that the phaseonium isochore charges the cavity passively: the cavity ergotropy and energy-basis coherence remain zero up to numerical precision, while the state converges to the Gibbs fixed point selected by the apparent detailed balance. We further estimate lower bounds on the cost of preparing the atomic populations and coherence, showing that the relevant advantage of phaseonium is a resource-preparation tradeoff rather than a cost-free enhancement over a thermal bath at the same temperature. Finally, we assess the finite-time performance of a two-cavity cascade with additive mechanical work accounting. Over the investigated coherence-phase range, the cascade produces approximately $47\%$--$52\%$ more power than the single-cavity engine while requiring only $65\%$--$68\%$ of the hot and cold phaseonium atoms needed by two independent engines, resulting in a $9\%$--$15\%$ enhancement of power per injected atom over a complete cycle.

quant-ph