Design method for realizing S-box circuit for quantum optimization
By analyzing and dividing the classic implementation structure of S-box, combining quantum logic gate set design quantum optimization implementation, the Toffoli depth and T depth of quantum circuits are optimized, and the problem of resource occupation and speed limitation in large-scale S-boxes in quantum computing is solved, and efficient quantum implementation is achieved.
Patent Information
- Application Number
- CN202510701441.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-07-08
Smart Images

Figure CN120281467A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of quantum computing, and more specifically, to a design method for implementing an S-box circuit for quantum optimization. Background Art
[0002] The parallel processing ability of quantum computers poses a significant threat to modern cryptography. In particular, through the Grover algorithm, the key search process can be accelerated within square root time, which directly reduces the security of symmetric cryptography algorithms. Taking AES-128 as an example, the time complexity of a brute-force key attack on it under the classical computing model is 2 128 , while with the help of the quantum Grover algorithm, the time complexity of a brute-force key attack on AES-128 under the quantum computing model is only 2 64 . Studying the quantum implementation of symmetric cryptography is of great significance. It can verify the impact boundary of the quantum computing model on the traditional cryptographic system and provide a key basis for the adaptability of the basic theory of cryptography in the quantum environment. For example, the quantum implementation of a cryptographic algorithm is a core part of the G iteration of the Grover algorithm. By constructing a quantum circuit to implement a symmetric cryptography algorithm, the actual threat level of a quantum attack based on the Grover algorithm can be accurately quantified, and this is related to the definition of the quantum security level of cryptographic algorithms given by the National Institute of Standards and Technology of the United States.
[0003] When designing the quantum circuit of a symmetric cryptography algorithm, two commonly used logic gate sets are the NCT logic gate set and the Clifford+T logic gate set. The former consists of the Pauli-X gate, the CNOT gate, and the Toffoli gate, and the latter consists of the Clifford logic gate set and the T gate, where the Clifford logic gate set includes the Pauli-X gate, the S gate, the H gate, the CNOT gate, etc. Currently, the state of qubits in a quantum computer is vulnerable to decoherence due to the external environment, which directly affects the advantage of quantum computing compared to classical computing. Completing the function of the quantum circuit before the occurrence of decoherence poses higher requirements for the depth of the quantum circuit (i.e., the total depth). Note that in the NCT logic gate set, the implementation cost of the Toffoli gate is much greater than that of the Pauli-X gate and the CNOT gate, and in the Clifford+T logic gate set, the implementation cost of the T gate is much greater than that of the Clifford logic gate. Therefore, the important reference value of the Toffoli depth or T depth of the circuit cannot be ignored either.
[0004] In the NCT logic gate set, the Pauli-X gate is a single-qubit gate that changes the state |0> to |1> and the state |1> to |0>, and its function can be described as The CNOT gate is a two-qubit gate that flips the target bit state only when the control bit state is |1). Its function can be described as The Toffoli gate is a 3-input quantum logic gate that can flip the target bit state only when both control bit states are |1>. Its function can be described as Note that the NOT gate in the classical implementation can be simulated by the Pauli-X gate, the XOR gate can be simulated by the CNOT gate, and the AND gate can be simulated by the Toffoli gate. Therefore, given a classical implementation based on the AND gate, XOR gate, and NOT gate design, the corresponding quantum NCT circuit can be designed. In the Clifford+T logic gate set, the Pauli-X gate and CNOT gate can simulate the NOT gate and XOR gate in the classical circuit. For the simulation of the AND gate, the quantum logic gate QAND gate uses a quantum auxiliary bit with a state of |0> to store the result of the multiplication of the two operands in another quantum bit with a state of |0). Its function can be described as (|a>,|b>,|0>)→|a>,|b>,|a·b>,|0>). It can be seen that a classical AND gate can be simulated by a QAND gate with the help of 2 quantum auxiliary bits. For example Figure 1 As shown, the QAND gate is composed of Clifford+T logic gates. Therefore, given a classical implementation based on AND gates, XOR gates, and NOT gates, the corresponding quantum Cliffford+T circuit can be designed. At the same time, it can also be used with The gate resets the state of the quantum auxiliary bit that stores the product of the two operands in the QAND gate to |0> for subsequent use, thereby achieving the purpose of saving quantum bits. The circuit diagram of the gate is as follows Figure 1 shown.
[0005] Confusion and diffusion are the two basic principles that must be followed in the design of symmetric cryptography. S-boxes are often used as the only nonlinear subcomponent in symmetric cryptography to provide confusion. With the development of science and technology, the application scenarios of cryptographic algorithms are complex and varied. In order to meet different application requirements, the design methods of various subcomponents of cryptographic algorithms will also change, including S-boxes. In addition, the in-depth research on cryptographic theory has further enriched the design methods of symmetric cryptographic S-boxes. The implementation efficiency of the S-box is closely related to its design scheme, and this correlation is reflected in multiple dimensions such as computing resource occupancy and computing speed. However, whether in classical application scenarios or in quantum application scenarios, there is currently no universal method for designing optimized implementation circuits for large-scale S-boxes (such as 8-bit S-boxes) in a short period of time. Summary of the invention
[0006] The purpose of the present invention is to provide a design method for quantum optimization-oriented S-box circuit to overcome the defects of the prior art.
[0007] In order to achieve the above object, the technical solution adopted by the present invention is as follows:
[0008] A design method for quantum optimization-oriented S-box circuit, comprising the following steps:
[0009] S1. Analyze the linear and nonlinear operations in the classic implementation of S-box and divide the classic implementation structure of S-box;
[0010] S2, designing the quantum implementation of different modules in the classical implementation structure of the S-box step by step;
[0011] S3. Analyze the associativity of the linear module implementation circuit in the quantum implementation of the S-box to optimize the quantum implementation of the S-box.
[0012] Furthermore, in step S1, the depth of the AND gate of the given classical implementation is d, and the nonlinear module composed of the AND gates of the i-th layer (i=1, 2, ..., d) is N i , and N i The linear module composed of the linear operations related to the calculation of the logic gate input variables is L i , the steps of dividing the classic implementation structure of the S-box include:
[0013] S11. For i=1,2,…,d, initialize initialization To save the linear operations that the output variables of the last layer and gate depth have to go through;
[0014] S12, let the current AND operation be t = a·b, if or And t = a·b can be implemented in parallel with the AND operation in N1, then update N1 = N1∪{t = a·b}; otherwise, if the AND operation cannot be implemented in parallel with the AND operation in N1, then determine whether N2 is an empty set. If or If t=a·b can be implemented in parallel with the AND operation in N2, then N2=N2∪{t=a·b} is updated; and so on until the AND operation in the classic implementation is divided;
[0015] S13, record the current linear operation as If it is relevant to the computation of the operand of the AND operation in N1, update Determine whether it is related to the calculation of the operand of the AND operation in N2. If so, update And so on, until the judgment is completed Is it consistent with N1, N2, ..., N d The ones in are related to the calculation of the operands of the operation;
[0016] S14, according to L1, L2, ..., Ld+1 In the linear operation, expand the calculation expressions of the operands of the operation to eliminate the redundant intermediate variables L1, L2, …, L d+1 in
[0017] S15. After modularly processing all operations in the classical implementation, return the partitioning result {L1, N1, L2, N2, …, L d , N d , L d+1}}.
[0018] Furthermore, if the current linear operation in step S13 is not relevant to the calculations of the operands of the AND operations in N1, N2, …, N d , then this linear operation is used to linearly calculate the output of the S-box, and then update
[0019] Furthermore, step S2 specifically includes:
[0020] S21. According to the different designed circuits, select quantum logic gates to simulate the AND operations in each non-linear module;
[0021] S22. Represent the linear operations in the linear module using matrix multiplication to restore the binary matrix, construct the quantum implementation of the linear module through the quantum optimization of the designed binary matrix, and after using the output of a specific linear module, reverse the order of using the quantum circuit of this module to reset the state of the quantum auxiliary qubits.
[0022] Furthermore, step S3 is specifically as follows: Starting from the inverse circuit of the circuit implementing the linear module L1, sequentially determine the associativity of the operations it contains with the operations of the subsequent circuit. If they can be combined, then combine the relevant operations and redesign and optimize the implementation scheme to replace the original operations.
[0023] Compared with the prior art, the advantages of the present invention are as follows: The design of the quantum circuit in the present invention is based on the classical implementation of the S-box, and combines the underlying quantum logic gate set to design the quantum optimization implementation of the S-box. The circuit design method proposed by the present invention provides a general framework for the quantum implementation of the S-box. Whether designing the NCT implementation or the Clifford+T implementation, the classical circuit can be divided into non-linear modules and linear modules for separate processing based on this framework. The classical optimized implementation circuit ensures that the Toffoli depth and T depth of the quantum circuit are optimized. The optimization of the linear module further ensures that the quantum logic gate consumption and the total circuit depth of the quantum implementation circuit of the S-box are optimized. Therefore, the S-box circuit design method for quantum optimization implementation of the present invention effectively speeds up the quantum implementation efficiency of the S-box in the cryptographic algorithm and reduces the cost of the related quantum circuit implementation. Description of the Drawings
[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0025] Figure 1 is the quantum QAND gate and quantum gate circuit diagram in the present invention;
[0026] Figure 2 is the quantum circuit framework diagram designed based on the classical implementation with a depth of 2 of the AND gate in the present invention;
[0027] Figure 3 is the combined schematic diagram of the inverse circuit of the linear module L1 and a part of the circuit of the linear module L2 in the present invention;
[0028] Figure 4 is the framework diagram of the design method for the quantum-optimized implementation of the S-box circuit in the present invention. Specific Embodiments
[0029] The following will elaborate on the preferred embodiments of the present invention in conjunction with the drawings, so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby making a clearer and more definite definition of the protection scope of the present invention.
[0030] Refer to Figure 4 As shown, this embodiment discloses a design method for the quantum-optimized implementation of the S-box circuit, including the following steps:
[0031] Step S1: Analyze the linear operations and non-linear operations in the classical implementation of the S-box, and divide the classical implementation structure of the S-box.
[0032] Compared with the quantum implementation of the S-box, after years of in-depth exploration by scholars, the research on the classical optimized implementation of the S-box has produced more abundant results. Therefore, designing the corresponding quantum circuit based on the optimized classical implementation of the S-box is a common method for designing the quantum implementation of large-scale S-boxes currently. In a classical circuit, the function of an AND gate can be described as calculating t = a·b, the function of an XOR gate can be described as calculating The function of a NOT gate can be described as calculating In this embodiment, the NOT gate is regarded as a special form of the XOR gate, and the XOR gate and the NOT gate are collectively referred to as linear operations, and are uniformly described by to uniformly describe linear operations.
[0033] An exclusive-OR gate and a NOT gate can be simulated by a CNOT gate and a Pauli-X gate respectively. The CNOT gate and the Pauli-X gate belong to both the NCT logic gate set and the Clifford+T logic gate set. Therefore, when designing an NCT circuit and a Clifford+T circuit based on a classical circuit, there are only differences in the way of simulating a classical AND gate. When designing an NCT circuit or a Clifford+T circuit based on a classical circuit, the classical circuit can be divided into a non-linear module composed of AND gates and a linear module composed of exclusive-OR gates and NOT gates. Since a Toffoli gate and a QAND gate are used respectively in quantum circuit design to simulate the AND gate in a classical circuit, the AND gate depth of the classical circuit determines the Toffoli depth of the NCT circuit and also determines the T depth of the Clifford+T circuit. Note that the operands of the AND gate in the circuit (i.e., the inputs of the AND gate) are generated in two ways: directly as the outputs of the AND gates in the previous AND gate depth or calculated based on linear operations. Accordingly, after a preliminary division of the operations in the classical implementation based on whether the AND gates can be parallelized, the linear operations related to the calculation of the operands of the AND gates within the same AND gate depth can be further divided. At the same time, in the quantum scenario, a variable is equivalent to a qubit. Considering saving qubits, the variables generated by multiple exclusive-OR operations are directly exclusive-ORed together to reduce the number of intermediate variables. For example, and are directly represented as
[0034] In this embodiment, the AND gate depth of the given classical implementation is denoted as d, and the non-linear module composed of AND gates in the i-th layer (i = 1, 2,..., d) is denoted as N i , and the linear module composed of linear operations related to the calculation of the input variables of the logic gates in N i is denoted as L i . The specific steps of step S1 include:
[0035] Step S11: For i = 1, 2,..., d, initialize At the same time, initialize to save the linear operations that the output variables of the last AND gate depth need to go through. Go to step S12 and process each AND operation in the classical implementation in sequence.
[0036] Step S12: Denote the current AND operation as t = a·b. If or and t = a·b can be implemented in parallel with the AND operations in N1, then update N1 = N1 ∪ {t = a·b}; otherwise, if this AND operation cannot be implemented in parallel with the AND operations in N1, then judge whether N2 is an empty set. If or And if \(t = a\cdot b\) can be implemented in parallel with the AND operation in \(N_2\), then update \(N_2=N_2\cup\{t = a\cdot b\}\); and so on, until the AND operations in the classical implementation are all partitioned. At this time, go to step S13 to process each linear operation.
[0037] Step S13: Denote the current linear operation as If it is computationally related to the operands of the AND operation in \(N_1\), then update Then determine whether it is computationally related to the operands of the AND operation in \(N_2\). If so, then update And so on, until it is determined whether it is computationally related to the operands of the AND operation in \(N_1,N_2,\cdots,N\) Whether it is computationally related to the operands of the AND operation in \(N_1,N_2,\cdots,N\) d In particular, if the current linear operation is not computationally related to the operands of the AND operations in \(N_1,N_2,\cdots,N\), it means that this linear operation is used to linearly calculate the output of the S-box. At this time, update d In particular, if the current linear operation is not computationally related to the operands of the AND operations in \(N_1,N_2,\cdots,N\), it means that this linear operation is used to linearly calculate the output of the S-box. At this time, update Repeat the above process until all linear operations are partitioned, and then go to step S14.
[0038] Step S14: According to the linear operations in \(L_1,L_2,\cdots,L\) d+1 in turn, directly expand the computational expressions of the operands of the AND operation, so as to eliminate the redundant intermediate variables in \(L_1,L_2,\cdots,L\) d+1 Go to step S15.
[0039] Step S15: After all the operations in the classical implementation are modularly processed, return the partitioning result \(\{L_1,N_1,L_2,N_2,\cdots,L\) d ,N d ,L d+1 \}.
[0040] Note that after the above partitioning steps, the AND operations in the non-linear module \(N\) i still have the form \(t = a\cdot b\), while the linear operations in the linear module \(L\) i after the expansion step to eliminate redundant intermediate variables, have the form That is, they are not necessarily 2-input operations.
[0041] To more intuitively describe the specific process of the circuit design in this embodiment, taking the 8-bit S-box of the AES algorithm as an example below, the S-box circuit design process for quantum optimization implementation is elaborated. Denote the input of the S-box as \((x_0,x_1,\cdots,x_7)\) and the output as \((s_0,s_1,\cdots,s_7)\). Using the tower field decomposition technique, the AES algorithm S-box is decomposed into a Top function, a Middle function, and a Bottom function. The classical optimized implementation of the AES algorithm S-box designed through the above decomposition is shown in Table 1 below, where the variable \(y\)i , t j , z k are all intermediate variables, represents the negation operation, i.e., a NOT gate.
[0042] Table 1 Classical implementation of the S-box of the AES algorithm
[0043]
[0044]
[0045] Since the AND gate depth of the classical implementation determines the Toffoli depth and T depth of the quantum circuit, in order to further optimize the classical implementation of the S-box of the AES algorithm, in this embodiment, the 24th to 39th operations in the classical implementation of the Middle function shown in Table 1 are regarded as a whole, and the above whole is optimized again on the premise of optimizing the AND gate depth, and an equivalent implementation with an AND gate depth of 2 for this whole is designed. After combining the new equivalent implementation with other operations shown in Table 1, the S-box of the AES algorithm can be implemented within 4 AND gate depths. After partitioning through this step, the L1, N1, L2, N2, L3, N3, L4, N4, L5 modules of this circuit are as follows respectively:
[0046] (1) The operations included in the linear module L1 are: y0 = x7;
[0047] (2) The operations included in the non-linear module N1 are: t2 = y 12 · y 15 ; t3 = y3 · y6; t5 = y4 · y0; t7 = y 13 · y 16 ; t8 = y5 · y1; t 10 = y2 · y7; t 12 = y9 · y 11 ; t 13 = y 14 · y 17 ; t 15 = y8 · y 10 ;
[0048] (3) The operations included in the linear module L2 are:
[0049] (4) The operations included in the non-linear module N2 are: g0 = t 24 · t 22 ; g2 = t 23 · g6;
[0050] (5) The operations included in the linear module L3 are:
[0051] (6) The operations included in the non - linear module N3 are: g1 = t 21 ·g7; g3 = t 21 ·g8; g4 = t 24 ·g2; g5 = t 23 ·g0;
[0052] (7) The operations included in the linear module L4 are: the operations in L1, and
[0053] (8) The operations included in the non - linear module N4 are: z0 = t 44 ·y 15 ; z1 = t 37 ·y6; z2 = t 33 ·y0; z3 = t 43 ·y 16 ; z4 = t 40 ·y1; x5 = t 29 ·y7; z6 = t 42 ·y 11 ; z7 = t 45 ·y 17 ; z8 = t 41 ·y 10 ; z9 = t 44 ·y 12 ; z 10 = t 37 ·y3; x 11 = t 33 ·y4; z 12 = t 43 ·y 13 ; z 13 = t 40 ·y5; z 14 = t 29 ·y2; z 15 = t 42 ·y9; z 16 = t 45 ·y 14 ; z 17 = t 41 ·y8;
[0054] (9) The operations included in the linear module L5 are:
[0055] Step S2: Design the quantum implementation of different modules in the classical implementation structure of the S - box step by step.
[0056] Step S2 specifically includes the following steps:
[0057] Step S21: According to different designed circuits, this embodiment selects quantum logic gates to simulate the AND operations in each non-linear module. Specifically, when designing an NCT circuit, the Toffoli gate is used to simulate the AND operation. When designing a Clifford+T circuit, the QAND gate is used to simulate the AND operation.
[0058] Through the above simulation operations in this embodiment, the functions corresponding to the classical AND operation can be realized in the quantum application scenario, which also means that the quantum implementation circuits of each non-linear module obtained from the classical implementation division are constructed.
[0059] Step S22: Represent the linear operations in the linear module by matrix multiplication to restore the binary matrix, and construct the quantum implementation of the linear module through the quantum optimization design of the binary matrix. After using the output of a specific linear module, the quantum circuit of this module is used in reverse order to reset the states of the quantum auxiliary bits.
[0060] In this embodiment, it is assumed that the depth of the AND gate in the classical circuit is d, and the output of the logic gates in the linear module L i , that is, the output variables of L i , are the operands (input variables of the AND gate) of the AND gates in the non-linear module N i , where i = 1, 2,..., d. It should be noted that a linear transformation can be represented by matrix multiplication. For example, in the classical implementation of each module of the AES algorithm S-box with an AND gate depth of 4 designed in the previous step, the output variables y0, y1,..., y 17 of module L1 can be expressed as follows:
[0061]
[0062] Therefore, the quantum circuit implementation of module L1 can be constructed by designing the quantum implementation of the 18×8 binary matrix in the above formula.
[0063] Quantum auxiliary bits may be used when designing the quantum implementation of the matrix. For example, for the classical implementation module division of the AES algorithm S-box with an AND gate depth of 4 designed in the previous step, when implementing the linear module L1, in order to ensure that y0, y1,..., y 17 can be input into the non-linear module N1 simultaneously, quantum auxiliary bits are needed to save the values of y0, y1,..., y 17 . And in order to save quantum bits, after module N1 uses y0, y1,..., y 17 , the circuit of module L1 can be used in reverse order (that is, the inverse of the implementation circuit of L1) to reset the quantum auxiliary bits that save the values of y0, y1,..., y 17 , and these reset quantum auxiliary bits can be used as the quantum auxiliary bits of other modules subsequently.Figure 2 Taking the classical implementation with an AND - gate depth of 2 as an example, the process of designing the corresponding quantum circuit based on the above steps is described.
[0064] Similarly processing the operations in all linear modules can achieve the goal of designing a quantum circuit from a given classical circuit.
[0065] Step S3: Analyze the associativity of the implementation circuit of the linear module in the quantum implementation of the S - box to optimize the quantum implementation of the S - box.
[0066] In this embodiment, when implementing the linear module, in order to save qubits, after using the output of the linear module in the previous step, the quantum auxiliary qubits are reset by using the implementation circuit of the linear module in reverse order. However, the output of the previous linear module may also be the output of the subsequent linear module. For example, in each module of the classical implementation of the AES algorithm S - box with an AND - gate depth of 4 designed in the previous step, the output of the linear module L1 is also part of the output of the linear module L4. After using the implementation circuit of the previous linear module in reverse order, when implementing the subsequent module, it is necessary to calculate the same output as the previous module again. Repeated calculation will undoubtedly increase the implementation cost. In addition, even if the output of the previous module and the output of the subsequent module are different, they may still be calculated using the same variables. For example, in each module of the classical implementation of the AES algorithm S - box with an AND - gate depth of 4 designed in the previous step, the output of the linear module L1 and part of the output of the linear module L2 are both calculated based on the input (x0, x1, …, x7) of the S - box. The logical gates acting on the same variables may affect the circuit depth. Therefore, first using the reverse of the implementation circuit of module L1 to reset the quantum auxiliary qubits and then calculating the variables related to (x0, x1, …, x7) in the output of module L2 may increase the overall quantum implementation depth of the S - box.
[0067] Among them, the implementation of the current S - box is successively composed of the implementation of module L1, the implementation of module N1, the reverse of the implementation of module L1, the implementation of module L2, the implementation of module N2, the reverse of the implementation of module L2, …, the implementation of module N d of the implementation, the implementation of module L d+1 where d is the AND - gate depth of the given classical implementation. From the above analysis, by studying the associativity of the implementation of each linear module in the circuit and its inverse circuit, the quantum implementation cost of the S - box can be improved. Specifically, for the implementation of module L1, the reverse of the implementation of module L1, the implementation of module L2, the reverse of the implementation of module L2, …, the implementation of module L d+1The implementation starts from the inverse circuit of the circuit of the linear module L1, and sequentially determines the combinability of the operations it contains with the operations of the subsequent circuit. If they can be combined, the relevant operations are combined and the implementation scheme is redesigned and optimized to replace the original operations. Taking the classical implementation of each module of the AES algorithm S-box with a depth of 4 for AND gates as an example, the circuit of module L1 calculates y0, y1, …, y based on x0, x1, …, x7 17 , and the inverse circuit of the circuit of L1 restores y0, y1, …, y 17 to x0, x1, …, x7, and then calculates y in the output of L2 based on x0, x1, …, x7 through the circuit of L2 18 , y 19 , y 20 , y 21 . In fact, the operations related to the calculation of y 18 , y 19 , y 20 , y 21 in the inverse circuit of the circuit of L1 and the circuit of L2 can be combined, and directly calculate y 17 from the output y0, y1, …, y of the circuit of L1 18 , y 19 , y 20 , y 21 . The specific process is as shown by the dotted line in Figure 3 .
[0068] Using the above steps in this embodiment, the quantum-optimized implementation of the S-box can be designed. Taking the AES algorithm S-box as an example, using the S-box circuit design method for quantum-optimized implementation designed in this embodiment, based on the classical implementation of the AES algorithm with a depth of 4 for AND gates designed in this embodiment, a Clifford+T implementation with a T-depth of 4 for the AES algorithm S-box can be obtained. Specifically, in the designed C1 circuit (the initial values of the output bits of the S-box are not all 0), the number of T-gate consumptions is 132, the total circuit depth is 74, and the number of quantum auxiliary bits is 75; in the designed C0 circuit (the initial values of the output bits of the S-box are all 0), the number of T-gate consumptions is 132, the total circuit depth is 74, and the number of quantum auxiliary bits is 67. The number of quantum bits, the number of T-gates, and the total circuit depth required for the implementation of the currently designed C0 circuit and C1 circuit for the AES algorithm S-box with a T-depth of 4 are shown in Table 2, and the results obtained by using the S-box circuit design method for quantum-optimized implementation proposed in this embodiment based on the classical implementation with a depth of 4 for AND gates designed in this embodiment are in parentheses.
[0069] Table 2 Clifford+T Implementation of the AES Algorithm with a T-Depth of 4
[0070] Circuit type Number of quantum auxiliary bits Number of T gates Total depth <![CDATA[C0]]> 68(67) 136(132) 77(74) <![CDATA[C1]]> 76(75) 136(132) 77(74)
[0071] As can be seen from the results in Table 2, from the perspectives of the total circuit depth, the consumption of T gates, or the consumption of quantum auxiliary qubits, the quantum implementation circuit of the AES algorithm with a T depth of 4 obtained by the S-box circuit design method for quantum optimization implementation of the present invention saves the implementation cost of the AES algorithm S-box. Further, the implementation scheme designed by using the method proposed by the present invention can effectively reduce the quantum implementation cost of the AES algorithm.
[0072] Based on the optimized classical implementation, the present invention constructs a quantum NCT implementation by using Toffoli gates, CNOT gates, and Pauli-X gates to simulate AND gates, XOR gates, and NOT gates in the classical implementation respectively, and can also construct a quantum Clifford+T implementation by using QAND gates, CNOT gates, and Pauli-X gates to simulate AND gates, XOR gates, and NOT gates in the classical implementation respectively. The AND gate depth of the optimized classical implementation determines the Toffoli depth of the NCT circuit and also determines the T depth of the Clifford+T circuit. Therefore, the S-box circuit design method for quantum optimization implementation designed by the present invention gives a general framework for designing the quantum implementation of the S-box, that is, given any classical implementation, the quantum optimization implementation of the S-box can be obtained by using the method designed by the present invention, and further optimize the quantum implementation of the algorithm.
[0073] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, the patent owner can make various deformations or modifications within the scope of the appended claims, and as long as it does not exceed the protection scope described in the claims of the present invention, it should be within the protection scope of the present invention.
Claims
1. A design method for an S-box circuit oriented to quantum optimization, characterized in that, Including the following steps: S1. Analyze the linear and non - linear operations in the classical implementation of the S - box, and divide the classical implementation structure of the S - box; S2. Design the quantum implementation of different modules in the classical implementation structure of the S - box step by step; S3. Analyze the associativity of the linear module implementation circuit in the quantum implementation of the S - box to optimize the quantum implementation of the S - box.
2. The design method for an S-box circuit oriented towards quantum optimization according to claim 1, characterized in that In the step S1, the depth of the AND gate in the given classical implementation is denoted as d, and the non-linear module composed of AND gates in the i-th layer (i = 1, 2,..., d) is N i , and the linear module composed of linear operations related to the calculation of the input variables of the logic gates in N i is L i , and the steps of partitioning the classical implementation structure of the S-box include: S11. For i = 1, 2, …, d, initialize Initialize for the linear operations that the output variables for storing the AND gate depth of the last layer will go through; S12. Denote the current AND operation as t = a·b. If or and t = a·b can be implemented in parallel with the AND operations in N1, then update N1 = N1 ∪ {t = a·b}; otherwise, if this AND operation cannot be implemented in parallel with the AND operations in N1, then determine whether N2 is an empty set. If or and t = a·b can be implemented in parallel with the AND operations in N2, then update N2 = N2 ∪ {t = a·b}; and so on until the AND operations in the classical implementation are all partitioned. S13. Record the current linear operation as If it is related to the calculation of the operands of the AND operation in N1, update Determine whether it is related to the calculation of the operands of the AND operation in N2. If so, update And so on until it is determined Whether it is related to the calculation of the operands of the AND operation in N1, N2,..., N d ; S14, according to L1, L2, ..., L d+1 The linear operation in the operation expands the calculation expression of the operand and eliminates L1, L2, ..., L d+1 Redundant intermediate variables in S15. After modularizing all operations in the classical implementation, return the partitioning result {L1, N1, L2, N2, …, L d , N d , L d+1}.
3. The design method of the S-box circuit for quantum optimization implementation according to claim 1, characterized in that If the current linear operation in step S13 is not related to the calculation of the operands of the AND operations in N1, N2, …, N d , then this linear operation is used to linearly calculate the output of the S-box, and then update 4. The design method of the S-box circuit for quantum optimization implementation according to claim 1, characterized in that The specific content of step S2 includes: S21. According to different designed circuits, select quantum logic gates to simulate the AND operation in each non - linear module; S22. Represent the linear operation in the linear module by matrix multiplication to restore the binary matrix, construct the quantum implementation of the linear module through the quantum optimization implementation of the designed binary matrix, and after using the output of the specific linear module, reverse - order use the quantum circuit of the module to reset the state of the quantum auxiliary qubits.
5. The design method of the S-box circuit for quantum optimization implementation according to claim 1, characterized in that, The specific content of step S3 is: starting from the inverse circuit of the implementation circuit of the linear module L1, successively judge the associativity of the operations it contains with the operations of the subsequent circuit. If they can be combined, combine the relevant operations and redesign and optimize the implementation scheme to replace the original operations.
Citation Information
Cited By
Implementation method for enabling linear subcomponent of ZUC algorithm to be suitable for multiple scenes
CN121750375A
A method for implementing a ZUC algorithm linear sub-component suitable for multiple scenarios
CN121750375B