Skip to main content
QUICK REVIEW

[Paper Review] Benchmarking the quantum cryptanalysis of symmetric, public-key and hash-based cryptographic schemes

Vlad Gheorghiu, Michele Mosca|arXiv (Cornell University)|Feb 6, 2019
Cryptography and Data Security22 citations
TL;DR

This paper provides state-of-the-art resource estimates for quantum cryptanalytic attacks on symmetric ciphers, hash functions, and public-key schemes (like RSA and ECC) using fault-tolerant quantum computing models. It leverages surface code error correction and optimized quantum circuits to quantify the physical qubits, T-gates, and time required to break these schemes under realistic hardware constraints, offering a benchmark for quantum risk assessment across cryptographic primitives with varying security levels.

ABSTRACT

Quantum algorithms can break factoring and discrete logarithm based cryptography and weaken symmetric cryptography and hash functions. In order to estimate the real-world impact of these attacks, apart from tracking the development of fault-tolerant quantum computers it is important to have an estimate of the resources needed to implement these quantum attacks. For attacking symmetric cryptography and hash functions, generic quantum attacks are substantially less powerful than they are for today's public-key cryptography. So security will degrade gradually as quantum computing resources increase. At present, there is a substantial resource overhead due to the cost of fault-tolerant quantum error correction. We provide estimates of this overhead using state-of-the-art methods in quantum fault-tolerance. We use state-of-the-art optimized circuits, though further improvements in their implementation would also reduce the resources needed to implement these attacks. To bound the potential impact of further circuit optimizations we provide cost estimates assuming trivial-cost implementations of these functions. These figures indicate the effective bit-strength of the various symmetric schemes and hash functions based on what we know today (and with various assumptions on the quantum hardware), and frame the various potential improvements that should continue to be tracked. As an example, we also look at the implications for Bitcoin's proof-of-work system. For many of the currently used asymmetric (public-key) cryptographic schemes based on RSA and elliptic curve discrete logarithms, we again provide cost estimates based on the latest advances in cryptanalysis, circuit compilation and quantum fault-tolerance theory. These allow, for example, a direct comparison of the quantum vulnerability of RSA and elliptic curve cryptography for a fixed classical bit strength.

Motivation & Objective

  • To assess the realistic resource costs of quantum attacks on widely deployed cryptographic schemes under fault-tolerant quantum computing assumptions.
  • To quantify the impact of quantum algorithms—especially Grover’s and Shor’s—on the security of symmetric, hash-based, and public-key cryptography.
  • To provide updated, hardware-grounded cost estimates using state-of-the-art quantum fault-tolerance techniques, such as lattice surgery and surface code error correction.
  • To enable direct comparison of quantum vulnerability across different cryptographic schemes (e.g., RSA vs. ECC) for equivalent classical security levels.
  • To serve as a benchmark for tracking future advances in quantum algorithms, circuit optimization, and error correction efficiency.

Proposed method

  • The authors model quantum attacks using surface code-based fault-tolerant quantum computing, estimating logical and physical resource costs under realistic error rates.
  • They use optimized quantum circuits for cryptographic functions (e.g., AES, SHA-256, RSA modular exponentiation) and apply T-count and T-depth metrics as proxies for quantum resource overhead.
  • The analysis incorporates lattice surgery techniques to reduce logical qubit and surface code cycle requirements by roughly a factor of 5 compared to earlier methods.
  • Resource estimates are computed across a range of physical error rates (10⁻⁵ to 10⁻³), with trade-offs between space (qubits) and time (surface code cycles) visualized in logarithmic plots.
  • The study includes two cost models: one with optimized circuits and another assuming trivial-cost implementations to bound potential future improvements.
  • For public-key schemes, the analysis uses the latest advances in Shor’s algorithm compilation and modular exponentiation circuit optimization.

Experimental results

Research questions

  • RQ1What is the minimum number of physical qubits and surface code cycles required to break AES-128 using Grover’s algorithm under fault-tolerant surface code error correction?
  • RQ2How do resource estimates for breaking RSA-2048 vary with physical error rate and time constraints, and how do they compare to those for ECC of equivalent classical security?
  • RQ3What is the effective bit-strength of symmetric and hash-based schemes when subjected to quantum attacks under realistic quantum hardware assumptions?
  • RQ4How do recent advances in fault-tolerant quantum computing, such as lattice surgery, reduce the resource overhead for quantum cryptanalysis?
  • RQ5What is the impact of circuit optimization on the feasibility of quantum attacks, and how do trivial-cost implementations frame the upper bounds of potential future improvements?

Key findings

  • Breaking AES-128 with Grover’s algorithm requires approximately 2.14 million physical qubits and 2.93×10¹³ surface code cycles at a physical error rate of 10⁻⁵, assuming one-day execution time.
  • For RSA-2048, the attack requires about 9.78 million physical qubits and 2.35×10¹⁴ surface code cycles at 10⁻⁵ error rate, with 2.41×10¹² T gates and 4,098 logical qubits.
  • RSA-3072 requires roughly 25.5 million physical qubits and 7.91×10¹⁴ cycles at 10⁻⁵ error rate, reflecting a 128-bit classical security level.
  • RSA-4096 demands approximately 57 million physical qubits and 1.88×10¹⁵ cycles at 10⁻⁵ error rate, with 1.92×10¹³ T gates and 8,194 logical qubits.
  • RSA-7680 requires up to 7.41 billion physical qubits and 2.47×10¹⁶ cycles at 10⁻⁵ error rate, corresponding to a 192-bit classical security level.
  • The study shows that lattice surgery reduces memory costs by ~5× compared to earlier surface code methods, significantly improving the practicality of large-scale quantum cryptanalysis.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.