Polynomial modulo squarer, method of operation and related apparatus

By constructing alternating cascades of controlled adders and modular multiplication operators, the polynomial modular square operation in quantum computing is realized, which solves the problem of low efficiency in existing technologies, improves computing efficiency and supports more complex quantum computing tasks.

CN117196053BActive Publication Date: 2025-10-10ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311277423.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-28
Publication Date
2025-10-10
Estimated Expiration
2043-09-28

AI Technical Summary

Technical Problem

Existing technologies make it difficult to efficiently implement polynomial modular squaring operations in quantum computing, especially in modular multiplication operations, where there is a problem of low efficiency.

Method used

By adopting alternately cascaded n controlled adders and n-1 modular multiplication operators, a polynomial modular square operator is constructed through iterative controlled addition operations and variable modular multiplication operations, and the polynomial modular square operation is realized using quantum logic gates.

Benefits of technology

It realizes the polynomial modular square operation in quantum computing, improves the computing efficiency, and supports more complex quantum computing tasks such as elliptic curve point addition on binary fields and Shor's algorithm to solve ECDLP quantum circuits on binary extended fields.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117196053B_ABST
    Figure CN117196053B_ABST
Patent Text Reader

Abstract

The application discloses a polynomial modulus square operation device, an operation method and related devices, and is applied to the field of quantum computation. The polynomial modulus square operation device is used for determining the modulus square operation result of an input first polynomial. The modulus in the modulus square operation is a second polynomial. The polynomial modulus square operation device comprises n controlled adders and n-1 modulus multiplication operation devices which are alternately connected in cascade. The controlled adder is used for determining the sum of the a i times first polynomial and the numerical value of the initial state when the quantum state of the auxiliary bit is the target quantum state, or determining the sum of the a i times first polynomial and the output result of the previous modulus multiplication operation device. The auxiliary bit is used for storing the quantum state of the coefficient a i of each term in the first polynomial. The degree of the first polynomial is not greater than n-1. The modulus multiplication operation device is used for determining the modulus multiplication operation result of the output result of the previous controlled adder and the variable in the first polynomial. The modulus in the modulus multiplication operation is the second polynomial. Thus, the polynomial modulus square operation in quantum computation is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of quantum computing technology, and in particular to a polynomial modular square operator, an operation method and related devices. Background Art

[0002] A quantum computer is a physical device that follows the laws of quantum mechanics to perform high-speed mathematical and logical operations, and to store and process quantum information. When a device processes and calculates quantum information and runs quantum algorithms, it is considered a quantum computer. Quantum computers are a key technology under research because they can handle mathematical problems more efficiently than conventional computers. For example, they can reduce the time required to crack RSA keys from hundreds of years to just hours.

[0003] Modular arithmetic has a wide range of applications in number theory and cryptography, from determining parity and prime numbers, from Sun Tzu's theorem to the Caesar cipher, from finite fields to the implementation of block cipher field towers, and from elliptic curves over finite fields to elliptic curve-based public-key cryptography. Because modular arithmetic is the most commonly used function in computational components, it is also true for quantum computing. Implementing the modular squaring of polynomials is a pressing technical challenge in quantum computing. Summary of the Invention

[0004] The purpose of the present invention is to provide a polynomial modular square operator, an operation method and related devices, aiming to realize the polynomial modular square operation in quantum computing.

[0005] One embodiment of the present invention provides a polynomial modular square operator, which is used to determine a modular square operation result of a first polynomial input, where the modulus in the modular square operation is a second polynomial. The polynomial modular square operator includes n controlled adders and n-1 modular multiplication operators that are alternately cascaded, wherein:

[0006] The controlled adder is used to determine a when the quantum state of the auxiliary bit is the target quantum state. i times the sum of the first polynomial and the value of the initial state, or, determine a i The auxiliary bits are used to store the coefficients a of each degree term in the first polynomial. i The quantum state of the first polynomial is no more than n-1;

[0007] The modular multiplication operator is used to determine a modular multiplication result of an output result of the previous controlled adder and a variable in the first polynomial, where the module in the modular multiplication operation is the second polynomial.

[0008] Optionally, the number of the auxiliary bits is 1, and the quantum state of the auxiliary bit is obtained by acting on the storage a i The logic gates on the quantum bit and the auxiliary bit are obtained.

[0009] Optionally, the function is to store the a i The quantum bit and the logic gate on the auxiliary bit include two CNOT gates respectively located before and after the corresponding controlled adder, and the control bits of the CNOT gates before and after the corresponding controlled adder are both the storage a i The quantum bits, controlled bits are all the auxiliary bits.

[0010] Optionally, each of the controlled adders is controlled in sequence by the quantum states corresponding to the high-order coefficients to the low-order coefficients of the first polynomial; wherein, the first controlled adder is used to determine the sum of the numerical values ​​of the first polynomial times the highest-order coefficient and the initial state when the quantum state corresponding to the highest-order coefficient of the first polynomial is the target quantum state; the controlled adders other than the first one are used to determine the sum of the first polynomial times the corresponding coefficients and the output result of the previous modular multiplication operator when the quantum states corresponding to other coefficients of the first polynomial are the target quantum state.

[0011] Optionally, the degree of the first polynomial f(x) is n-1, and the degree of the second polynomial m(x) is n; the polynomial modular square operator includes a first quantum register and a second quantum register, and the number of quantum bits included in the first quantum register and the second quantum register are both n; the quantum bits in the first quantum register are used to store the quantum states of the coefficients of each degree term in the first polynomial f(x); each of the controlled adders is used to perform a CNOT gate operation on the quantum bits in the second quantum register when the quantum state of the auxiliary bit is |1>, so as to determine the sum of the quantum state of the coefficient of the first polynomial f(x) and the quantum state of the corresponding quantum bit in the second quantum register.

[0012] Optionally, the modular multiplication operator is used to perform a CNOT gate operation on the quantum bit corresponding to the i-1th coefficient in the second quantum register when the quantum state corresponding to the i-th coefficient of the second polynomial m(x) is |1>; and perform a SWAP gate operation on the quantum bits in the second quantum register in sequence based on the order of the corresponding coefficients in the second quantum register from high to low; wherein the i-th bit is the non-highest bit and non-lowest bit of the second polynomial m(x).

[0013] Yet another embodiment of the present invention provides a polynomial modular square operation method, the method comprising:

[0014] The polynomial modulus squaring operator, the first polynomial, and the second polynomial in the above embodiment are obtained.

[0015] The first polynomial and the second polynomial are input into the polynomial modulus squaring operator, and the polynomial modulus squaring operator is run to obtain a quantum state corresponding to a modulus squaring operation result of the first polynomial.

[0016] The modulus squaring operation result of the first polynomial is determined based on the quantum state corresponding to the modulus squaring operation result.

[0017] Another embodiment of the present application provides a polynomial modulus squaring operation device, and the device comprises:

[0018] An obtaining module is configured to obtain the polynomial modulus squaring operator, the first polynomial, and the second polynomial in the above embodiment.

[0019] A calculating module is configured to input the first polynomial and the second polynomial into the polynomial modulus squaring operator, and run the polynomial modulus squaring operator to obtain a quantum state corresponding to a modulus squaring operation result of the first polynomial.

[0020] A determining module is configured to determine the modulus squaring operation result of the first polynomial based on the quantum state corresponding to the modulus squaring operation result.

[0021] Another embodiment of the present application provides a storage medium, and the storage medium stores a computer program, wherein the computer program is configured to execute the method in the above embodiment when running.

[0022] Another embodiment of the present application provides an electronic device, which comprises a memory and a processor, the memory stores a computer program, and the processor is configured to execute the computer program to execute the method in the above embodiment.

[0023] Compared with the prior art, the polynomial modulus squaring operator, the operation method, and the related device provided by the present application are used to determine a modulus squaring operation result of an input first polynomial, and the modulus in the modulus squaring operation is a second polynomial. i The controlled adder is configured to determine a sum of the first polynomial multiplied by a i The controlled adder is configured to determine a sum of the first polynomial multiplied by a iThe quantum state of the first polynomial is not greater than n-1; the modular multiplication operator is used to determine the modular multiplication result of the output result of the previous controlled adder and the variable in the first polynomial, and the module in the modular multiplication operation is the second polynomial.

[0024] By decomposing the polynomial modular squaring operation into multiple iterative controlled addition operations and variable modular multiplication operations, and converting the above operation process into an executable quantum circuit form, a polynomial modular squaring operator was constructed, thus realizing the polynomial modular squaring operation in quantum computing. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 A network block diagram of a polynomial modular square operation system provided by an embodiment of the present invention;

[0026] Figure 2 A schematic diagram of a polynomial modular square operator provided by an embodiment of the present invention;

[0027] Figure 3 A schematic diagram of a modular multiplication operator provided in an embodiment of the present invention;

[0028] Figure 4 A schematic diagram of another polynomial modular square operator provided by an embodiment of the present invention;

[0029] Figure 5 A schematic diagram of a flow chart of a polynomial modular square operation method provided in an embodiment of the present invention;

[0030] Figure 6 A schematic structural diagram of a polynomial modular square operation device provided by an embodiment of the present invention;

[0031] Figure 7 A schematic structural diagram of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0032] The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and are not to be construed as limiting the present invention.

[0033] Figure 1 This is a network block diagram of a polynomial modular squaring operation system provided by an embodiment of the present invention. The polynomial modular squaring operation system may include a network 110, a server 120, a wireless device 130, a client 140, storage 150, a classical computing unit 160, a quantum computing unit 170, and may also include additional memory, classical processors, quantum processors, and other devices (not shown).

[0034] The network 110 is a medium for providing communication links between various devices and computers connected together in the polynomial modular square operation system, including but not limited to the Internet, corporate intranet, local area network, mobile communication network and their combinations. The connection method can be wired, wireless communication links or optical fiber cables, etc.

[0035] Server 120, wireless device 130, and client 140 are conventional data processing systems that may contain data and applications or software tools that perform conventional computing processes. Client 140 may be a personal computer or a network computer, so the data may also be provided by server 120. Wireless device 130 may be a smartphone, tablet, laptop, smart wearable device, etc. Storage unit 150 may include database 151, which may be configured to store data such as qubit parameters, quantum logic gate parameters, quantum circuits, and quantum programs.

[0036] The classical computing unit 160 (quantum computing unit 170) may include a classical processor 161 (quantum processor 171) for processing classical data (quantum data) and a memory 162 (memory 172) for storing classical data (quantum data). The classical data (quantum data) may be a boot file, an operating system image, and an application 163 (application 173). The application 163 (application 173) may be used to implement a quantum algorithm compiled according to the polynomial modular square operation method provided in an embodiment of the present invention.

[0037] Any data or information stored or generated in the classical computing unit 160 (quantum computing unit 170) can also be configured to be stored or generated in another classical (quantum) processing system in a similar manner, and similarly, any application program executed therein can also be configured to be executed in another classical (quantum) processing system in a similar manner.

[0038] It should be noted that a true quantum computer is a hybrid structure, which includes at least Figure 1 The system consists of two parts: the classical computing unit 160, which is responsible for performing classical calculations and control; and the quantum computing unit 170, which is responsible for running quantum programs and thus realizing quantum computing.

[0039] The classical computing unit 160 and quantum computing unit 170 can be integrated into a single device or distributed across two different devices. For example, a first device including the classical computing unit 160 runs a classical computer operating system, provides quantum application development tools and services, and also provides the storage and network services required for quantum applications. Users develop quantum programs using the quantum application development tools and services on the device, and send the quantum programs to a second device including the quantum computing unit 170 via the network services on the device. The second device runs a quantum computer operating system, which parses and compiles the code of the quantum program into instructions that can be recognized and executed by the quantum processor 170. The quantum processor 170 then implements the quantum algorithm corresponding to the quantum program based on the instructions.

[0040] The computing units of the classic processor 161 in the classic computing unit 160 are based on CMOS transistors on a silicon chip. These computing units are not constrained by time or coherence, meaning they are available at all times, regardless of the duration of their use. Furthermore, the number of these computing units on a silicon chip is plentiful. Currently, a classic processor 161 contains tens of thousands of computing units. This abundance of computing units and the selectable computational logic of the CMOS transistors are fixed, such as AND logic. When computing with CMOS transistors, a large number of CMOS transistors are combined with a limited number of logical functions to achieve the desired computational effect.

[0041] The basic computing unit of the quantum processor 171 in the quantum computing unit 170 is the qubit. The input of the qubit is limited by coherence and coherence time, that is, the qubit is limited by the length of use and is not available at any time. Making full use of the qubit within the available usage time of the qubit is a key problem in quantum computing. In addition, the number of qubits in a quantum computer is one of the representative indicators of the performance of the quantum computer. Each qubit realizes the computing function through the logical function configured on demand. Given the limited number of qubits, the logical functions in the field of quantum computing are diverse, such as: Hadamard gate (H gate), Pauli-X gate (X gate), Pauli-Y gate (Y gate), Pauli-Z gate (Z gate), X gate, RY gate, RZ gate, CNOT gate, CR gate, iSWAP gate, Toffoli gate, etc. During quantum computing, it is necessary to use limited qubits combined with a variety of logical functions to achieve the computing effect.

[0042] Based on these differences, the application of classical logic functions to the design of CMOS tubes and the application of quantum logic functions to the design of quantum bits are significantly and essentially different. The application of classical logic functions to the design of CMOS tubes does not require consideration of the individuality of the CMOS tubes. For example, the representation of CMOS tubes in silicon chips is the individual identification, position, and usable life of each CMOS tube. Therefore, the classical algorithms composed of classical logic functions only express the operational relationships of the algorithms, and do not express the algorithm's dependence on the individual CMOS tubes.

[0043] Quantum logic functions acting on qubits must consider their individuality, such as their position within the quantum chip, their individual identifier, their location, their relationship to surrounding qubits, and the usable lifespan of each qubit. Therefore, quantum algorithms composed of quantum logic functions not only express the algorithm's operational relationships but also its dependence on individual qubits.

[0044] Quantum chips can include qubits and channels that control them. Quantum logic gates are implemented using analog signals. Different combinations of analog signals are applied to qubits through the channels that control them, thereby realizing quantum circuits with different functions and completing data processing. Therefore, the design of quantum logic functions applied to qubits (including whether qubits are used and the efficiency of each qubit's use) is key to improving the computing performance of quantum computers and requires special design. This is also the uniqueness of quantum algorithms based on quantum logic functions, which are fundamentally and significantly different from classical algorithms based on classical logic functions. However, the above-mentioned qubit-specific design is a technical issue that ordinary computing devices do not need to consider or face.

[0045] The present invention proposes a polynomial modular square operator, an operation method and related devices, aiming to realize polynomial modular square operation in quantum computing.

[0046] An embodiment of the present invention provides a polynomial modular square operator for determining a modular square operation result of a first polynomial input, where the modulus in the modular square operation is a second polynomial. The polynomial modular square operator includes n controlled adders and n-1 modular multiplication operators that are alternately cascaded, wherein:

[0047] The controlled adder is used to determine a when the quantum state of the auxiliary bit is the target quantum state. i times the sum of the first polynomial and the value of the initial state, or, determine a i The auxiliary bits are used to store the coefficients a of each degree term in the first polynomial. i The quantum state of the first polynomial is no more than n-1;

[0048] The modular multiplication operator is used to determine a modular multiplication result of an output result of the previous controlled adder and a variable in the first polynomial, where the module in the modular multiplication operation is the second polynomial.

[0049] Specifically, the first polynomial input to the polynomial modular square operator may be f(x), and the modulus in the modular square operation may be the second polynomial m(x). Then, the polynomial modular square operation may be expressed as the polynomial operation: f(x) 2 modm(x).

[0050] In this embodiment, the degree of the first polynomial f(x) is no greater than n-1 and can be expressed as That is, f(x) = a n-1 x n-1 +a n-2 x n-2 +…+a1x+a0. First, for the above f(x) 2 The calculation process of mod m(x) is decomposed to obtain:

[0051]

[0052] From this we can determine that the polynomial modulo square operation f(x) 2 mod m(x) can be decomposed into n parts composed of a i Controlled addition operation and n-1 *x modular multiplication operations, accordingly, the polynomial modular square operator requires n controlled adders and n-1 modular multiplication operators.

[0053] Then we can first calculate the coefficients a of each degree term in the first polynomial f(x) i They are respectively encoded into the quantum state of a group of quantum bits. The encoding method can be commonly used basis encoding, angle encoding, amplitude encoding and the like, which are not specifically limited here.

[0054] For example, when the coefficient a i is an element on the binary field, that is, a i When it is equal to 1 or 0, the coefficient a can be encoded by basis coding. n-1 Encoded into the quantum state of a quantum bit, the quantum state of the encoded quantum bit is |1> or |0>. Correspondingly, when the coefficient a i When it is an element on a multivariate domain, we can first calculate the coefficient a of each term. i After normalization, the coefficients of the normalized terms are encoded into the amplitude of the quantum state through amplitude coding, which can be expressed as: cosθ|1>+sinθ|0>.

[0055] Through the above encoding method, the first group of n quantum bits can be used to encode the coefficients a of each order in the first polynomial f(x) respectively. n-1 、a n-2 , ..., a0, we get n quantum bits. i The quantum state is used to control the controlled adder and determine whether the corresponding controlled adder is running; it is also used to participate in quantum addition calculations when the controlled adder is running.

[0056] Therefore, on the one hand, the quantum state of the n qubits can be transferred or copied to the auxiliary bit through the quantum logic gate, so that the auxiliary bit control can also store the coefficients a of each order term in the first polynomial f(x) i In one embodiment, based on the quantum state of the n qubits, the quantum state of the auxiliary bit can be controlled by a quantum logic gate to evolve into other target quantum states. The other target quantum states can also be used to control the n controlled adders. For example, the other target quantum states can be |1>, Or a preset identifiable quantum state, which is not specifically limited here.

[0057] On the other hand, the coefficients a of the first polynomial f(x) are stored. n-1 、a n-2 The n quantum bits of the quantum state of a0 can also be used for quantum addition in each controlled adder, that is, the quantum state of the n quantum bits can be added to other quantum states respectively, thereby realizing the above-mentioned controlled addition process. The controlled adder is used to determine a when the quantum state of the auxiliary bit is the target quantum state. i The sum of the first polynomial times the value of the initial state, or, determine a i The sum of the first polynomial times the value and the output result of the previous modular multiplication operator.

[0058] Furthermore, the number of the auxiliary bits can be one or more. When there are multiple auxiliary bits, each auxiliary bit can store a coefficient a in the first polynomial f(x). i Considering the need to save computing resources and reduce the number of qubits required for polynomial modular square operations, it is usually also possible to choose to use only one auxiliary bit.

[0059] Correspondingly, when the number of auxiliary bits is 1, the quantum state of the auxiliary bit can be controlled by the quantum logic gate to evolve into different coefficients a according to the execution sequence of the controlled adder during the above quantum modular square operation. i The corresponding quantum state controls each controlled adder in turn.

[0060] As an implementation of the embodiment of the present application, the number of the auxiliary bits is 1, and the quantum state of the auxiliary bit is obtained by applying a logic gate on the quantum bit storing the a i and the auxiliary bit.

[0061] In an implementation, when the coefficients a i of each term in the first polynomial f(x) are elements on a binary field, i.e., a i is equal to 1 or 0; the logic gate applied on the quantum bit storing the a i and the auxiliary bit includes two CNOT gates respectively located before and after the corresponding controlled adder, the control bit of the CNOT gate located before the corresponding controlled adder and the CNOT gate located after the corresponding controlled adder are both the quantum bit storing the a i , and the controlled bits are both the auxiliary bit.

[0062] Specifically, the polynomial modulo squaring operator provided by the embodiment of the present application can be as shown in FIG. 1. Figure 2 The polynomial modulo squaring operator includes n controlled adders and n-1 modulo multiplication operators which are alternately connected in cascade, wherein the box marked with "*" represents a modulo multiplication operator, and the box marked with "+" represents a controlled adder. The solid dot on the top of the wire of the controlled adder represents the control bit of the controlled adder, i.e., the auxiliary bit in the above embodiment. The initial state of the auxiliary bit is |0>, and the target quantum state corresponding to the a i can be obtained by applying a logic gate on the quantum bit storing the a i and the auxiliary bit. After the quantum addition operation of the controlled adder, the target quantum state can be reset to |0> by a logic gate.

[0063] Further in the embodiment, the quantum state of the auxiliary bit can be evolved by a CNOT gate. For each controlled adder, a CNOT gate operation is performed before and after the running time sequence of the controlled adder, for example, Figure 2 The first controlled adder in the first polynomial f(x) is controlled by the quantum state |a n-1 > of the highest coefficient, and since the coefficients a i of each term in the first polynomial f(x) are elements on a binary field, i.e., a i is equal to 1 or 0, the quantum state |a n-1> is |1> or |0>. Then, the quantum bit storing the quantum state is used as the control bit, and the auxiliary bit is used as the controlled bit. By applying the CNOT gate, the quantum state of the auxiliary bit can be evolved into the quantum state of the quantum bit. After the auxiliary bit controls the first controlled adder to complete the addition operation, a CNOT gate operation is performed to reset the quantum state of the auxiliary bit to |0>. The above quantum state evolution process is iterated, and the auxiliary bit can control any controlled adder. Similarly, when the coefficients a of the first polynomial f(x) are i When it is an element on a multi-domain, the quantum state of the auxiliary bit can be evolved through other quantum logic gates, which will not be described here.

[0064] Thus, each of the controlled adders can be sequentially controlled by the qubits corresponding to the high-order coefficients to the low-order coefficients of the first polynomial. The first controlled adder is configured to, when the quantum state corresponding to the highest-order coefficient of the first polynomial is the target quantum state, determine the sum of the first polynomial times the highest-order coefficient and the initial state; and the controlled adders other than the first are configured to, when the quantum states corresponding to the other coefficients of the first polynomial are the target quantum state, determine the sum of the first polynomial times the corresponding coefficients and the output result of the previous modular multiplication operator.

[0065] Specifically, store the coefficient a of the first polynomial f(x) n-1 The control mode of the auxiliary bit of the controlled adder can be understood as follows: when the coefficient a n-1 When is an element on the binary domain, the corresponding target quantum state is |1>, which means that addition operation is required, and |0>, which means that addition operation is not required. It can be understood that when the coefficient a n-1 When it is an element on a multi-domain, the corresponding target quantum state indicates that an addition operation is required, and other quantum states indicate that no addition operation is required.

[0066] Since the coefficients of the first polynomial f(x) have been pre-encoded into the quantum state of the first group of quantum bits, the first controlled adder can be used to add the coefficients a of f(x) based on the quantum state of the auxiliary bits. n-1 Under the control of the corresponding quantum state, calculate a n-1 The coefficients of the first polynomial of the order a i The sum of the values ​​of the auxiliary bit and the initial state is stored in the second group of n quantum bits, where the initial state of the second group of n quantum bits is |0>. Then, the first controlled adder can output a when the quantum state of the auxiliary bit is the target quantum state. n-1 *The quantum state corresponding to f(x).

[0067] Furthermore, the first modular multiplication operator can calculate the modular multiplication result of the output result of the first controlled adder and the variable x in the first polynomial f(x), where the module in the modular multiplication operation is the second polynomial m(x), that is, calculate x(a n-1 *f(x)modm(x)), that is, calculate the remainder polynomial and output the quantum state corresponding to the calculation result.

[0068] Correspondingly, the second controlled adder can be n-2 Under the control of the corresponding quantum state, calculate a n-2 The coefficients of the first polynomial of the order a i The sum of the quantum state output by the first modular multiplication operator is the calculation of a n-2 *f(x)+x(a n-1 *f(x)modm(x)), thereby outputting the corresponding quantum state.

[0069] Then, through the iterative calculation of the above-mentioned alternating cascade of n controlled adders and n-1 modular multiplication operators, the n-th controlled adder can calculate the sum of the quantum state of a0*f(x) and the output result of the n-1 modular multiplication operator. Then, finally, the above-mentioned polynomial modular square operator can determine and output a0*f(x)+x(a1*f(x)+x(a2*f(x)+…+x(a n-2 *f(x)+x(a n-1 *f(x)mod m(x))mod m(x))mod m(x))…mod m(x) corresponds to the quantum state, thus obtaining f(x) 2 The result of the modular square operation of mod m(x) is expressed as Figure 2 The quantum state |f(x) output by the n qubits in the lower middle section 2 mod m(x)>.

[0070] In this embodiment, by decomposing the polynomial modular square operation into multiple iterative controlled addition operations and variable modular multiplication operations, and converting the above operation process into an executable quantum circuit, and controlling the controlled adder according to the execution sequence through an auxiliary bit, a polynomial modular square operator can be constructed using only 2n+1 quantum bits, realizing the polynomial modular square operation in quantum computing. Moreover, based on the polynomial modular multiplication operator and the polynomial modular square operator implemented in the embodiment of the present invention, it is possible to further realize the elliptic curve point addition quantum circuit on the binary field and the Shor algorithm to solve the binary extension field. More complex quantum computing tasks such as ECDLP quantum circuits.

[0071] The following describes the basic structure of the controlled adder and modular multiplication unit in the polynomial modular square operator in the embodiment of the present invention. Finite fields are an important foundation in cryptography, such as the Diffie-Hellman cryptographic algorithm on finite fields, the elliptic curve cryptography system on finite fields, and the application of binary field towers in block ciphers. Finite fields are generally divided into prime fields F in cryptographic applications. p and binary extension domain Binary extension domain It means constructing a new domain by adding two elements to a given domain F2, thereby expanding the original domain. p When the prime number p defined in is 2, F2 is a binary field. If a polynomial is a polynomial over a binary field, the coefficient of each term is an element over the binary field. Correspondingly, when a polynomial is a polynomial over a multivariate field, its coefficient has more possible values.

[0072] In one embodiment, if the coefficients of the first and second polynomials are elements on a multivariate field, the coefficients of the first polynomials can be encoded into the amplitudes of the first group of quantum bits using amplitude coding. If the amplitude of a quantum bit obtained by encoding is 0, that is, the quantum state is |0>, it means that the coefficient of a certain term in the first polynomial corresponding to the quantum bit is 0, and the remaining quantum states all indicate that the coefficients are not 0.

[0073] Then, a second group of quantum bits with an initial state of |0> is used to store the calculation results of the intermediate calculation process. Then, the controlled adder can determine a when the quantum state of the control bit corresponding to the coefficient is not |0>. i The sum of the first polynomial times the value of the initial state, or, determine a i The sum of the first polynomial times the value and the output result of the previous modular multiplication operator.

[0074] In one embodiment, the controlled adder may include a quantum multiplier and a quantum adder. First, a is calculated by the quantum multiplier. i The quantum state of the product of the coefficients of each order of the first polynomial is then added to the initial state |0> through a quantum adder, or added to the quantum state output by the previous modular multiplication operator, and the corresponding quantum state is input into the next modular multiplication operator.

[0075] Correspondingly, the modular multiplication operator may also include a quantum multiplier and a modular multiplication operation module. The quantum multiplier is used to calculate the product of the variable x and the input quantum state, and the modular multiplication operation module is used to calculate the modular multiplication of this product with the first polynomial and input the corresponding quantum state into the next controlled adder. The quantum states obtained by the above calculation process are all stored in the second group of quantum bits. Therefore, through iterative operations of the above controlled adder and modular multiplication operator, the nth controlled adder can ultimately output the quantum state |f(x)*g(x)mod m(x)>.

[0076] In this embodiment, when the coefficients of the first polynomial and the second polynomial are elements on a multivariate field, the polynomial modular square operator can calculate a through a quantum multiplier by means of amplitude coding and the like. i The product of the coefficients of each degree term of the first polynomial and the product of the calculated variable x and the input quantum state are used to solve the polynomial modular square operation problem on the multivariate field.

[0077] As an implementation method of an embodiment of the present invention, the coefficients of each order term in the above-mentioned first polynomial and second polynomial can be elements on a binary field, and the above-mentioned controlled adder is used to determine the sum of the numerical values ​​of the first polynomial and the initial state when the quantum state of its corresponding control bit is |1>, or to determine the sum of the first polynomial and the output result of the previous modular multiplication operator.

[0078] Specifically, in some application scenarios of modular operations, for example, when designing Shor's algorithm to solve discrete logarithms on a binary field or discrete logarithms on elliptic curves on a binary field, it is necessary to implement related components such as modular addition, modular multiplication, and modular squaring on the binary field.

[0079] In one embodiment, if the coefficients of the first and second polynomials are elements of a binary field, the coefficients of the first polynomial can be encoded onto the basis of the first set of qubits using basis encoding. The resulting quantum states of the encoded qubits are either |1> or |0>. When the quantum state of a qubit is |1>, the coefficient of a corresponding first-order term of the first polynomial is 1, requiring addition. Similarly, when the quantum state of the qubit is |0>, no addition is required.

[0080] As an implementation manner of an embodiment of the present invention, the degree of the first polynomial f(x) is n-1, and the degree of the second polynomial m(x) is n; the polynomial modular square operator includes a first quantum register and a second quantum register, and the number of quantum bits included in the first quantum register and the second quantum register is n; the quantum bits in the first quantum register are used to store the quantum states of the coefficients of each degree term in the first polynomial f(x).

[0081] Specifically, in the field theory, a binary extension field refers to a new field constructed by adding two elements to a given field, thereby extending the original field. Binary extension fields play an important role in algebra and mathematical applications, especially in the study of polynomial equations and algebraic structures. By constructing appropriate binary extension fields, some complex mathematical problems can be solved. For example, a commonly used representation method of binary extension field can be represented as:

[0082] Let F2[x] be a polynomial ring defined on a two-element field F2, and its elements are polynomials f(x)=a n x n +a n-1 x n -1 +…+a1x+a0. Further, a binary extension field can be realized by the above polynomial ring F2[x], where m(x) is an irreducible polynomial on the polynomial ring F2[x], the degree of m(x) is n (i.e. deg(m(x)=n), and the ideal <m(x)> can be regarded as a maximal ideal of F2[x]. Generally, the binary extension field can be represented as:

[0083] where a i =0 or 1, i=0,1,…,n-1.

[0084] In an embodiment, the binary extension field can be regarded as an n-dimensional vector space defined on the binary field F2, and {1,x,x 2 ,…,x n-1} can be selected as a set of bases on the binary extension field , which is also called a polynomial basis. Thus, the element f(x) on the binary extension field can be represented by a vector, i.e. the polynomial f(x)=a n-1 x n-1 +a n-2 x n-2 +…+a1x+a0 can be represented as a vector where a i =0 or 1, i=0,1,…,n-1. In a quantum circuit, since the polynomial has been represented by a {0,1} vector array, it can be easily represented as a quantum state, and then the information of the polynomial can be conveniently encoded on the quantum state |1> or |0> of the quantum bit.

[0085] If the modular square operation of the element on the binary extension field is to be calculated, i.e. f(x) 2 mod m(x) is to be implemented, where deg(f(x))≤n-1. Let Both have a i ,c i =0 or 1, i = 0, 1, ..., n-1. Since m(x) is an irreducible polynomial, its highest and lowest coefficients are 1, so c0 must be c n = 1. The modular polynomial m(x) can be represented by an n-dimensional array by default, and the highest bit is 1 by default.

[0086] Then, a first quantum register consisting of n qubits can be used to store the quantum states of the coefficients of each degree term in the first polynomial f(x). Since these coefficients are all elements of a binary field, the following calculation rules apply: 0+0=0, 0+1=1, 1+0=1, 1+1=0. The addition of the arrays corresponding to these polynomials can be achieved through CNOT gates between quantum states. The *x modular multiplication operation on the f(x) array is equivalent to a left shift of the array followed by a modulo operation m(x).

[0087] As an implementation manner of an embodiment of the present invention, each of the controlled adders is configured to perform a CNOT gate operation on the quantum bit in the second quantum register when the quantum state of the auxiliary bit is |1>, so as to determine the sum of the quantum state of the coefficient of the first polynomial f(x) and the quantum state of the corresponding quantum bit in the second quantum register.

[0088] Specifically, the second quantum register includes n qubits, all of which have an initial state of |0>. The number of qubits in the second quantum register is the same as that in the first quantum register. For each controlled adder, when the quantum state of the auxiliary bit is |1>, it indicates that the quantum state of the coefficient of the first polynomial needs to be added to the quantum state of the qubit in the second quantum register. This addition operation can be performed using the following CNOT gate:

[0089] In the first and second quantum registers, a CNOT gate is applied to the qubit corresponding to each coefficient. The controlling bit of this CNOT gate is the qubit in the first quantum register, and the controlled bit is the corresponding qubit in the second quantum register. Thus, through n such CNOT gates, the sum of the quantum state of the coefficient of the first polynomial f(x) and the quantum state of the corresponding qubit in the second quantum register can be calculated. This calculation result can be stored in the qubit in the second quantum register and used as the quantum state of the next modular multiplication operator.

[0090] In this embodiment, the first polynomial is a polynomial element over a binary extension field, and the second polynomial is an irreducible polynomial over the corresponding polynomial ring. By expressing the coefficients of each degree term of the polynomial as a binary array, they can be conveniently encoded into a quantum state. Furthermore, when performing a polynomial modular square operation, controlled addition between polynomials can be accurately and conveniently achieved through CNOT gate operations.

[0091] As an implementation manner of an embodiment of the present invention, the modular multiplication operator is used to perform a CNOT gate operation on the quantum bit corresponding to the i-1th coefficient in the second quantum register when the quantum state corresponding to the i-th coefficient of the second polynomial m(x) is |1>; and based on the order of the corresponding coefficients in the second quantum register from high to low, perform a SWAP gate operation on the quantum bits in the second quantum register in sequence; wherein the i-th bit is the non-highest bit and the non-lowest bit of the second polynomial m(x).

[0092] Specifically, the *x modular multiplication operation of the f(x) array is equivalent to the left shift of the array and then the modular multiplication of m(x). In the quantum circuit, it can be implemented by combining multiple CNOT gates and SWAP gates. First, the calculation process of x*f(x)mod m(x) is explained. Let Since m(x) is an irreducible polynomial, assume that there are coefficients c in t positions except the highest and lowest positions. i =1, the coefficient c will be 1 i Redefine as {c it}, obviously, t is an even number and less than n-1, and the calculation process of x*f(x)mod m(x) can be as follows:

[0093]

[0094] Then, we can use the non-zero i bits (the highest bit, excluding the lowest bit) of the modular polynomial (i.e., the second polynomial) to perform a controlled addition operation on the (i-1) bit of the first polynomial f(x), and then perform SWAP gate operations from left to right (i.e., from the high bit to the low bit of the calculation result of the addition operation).

[0095] For example, consider the polynomial f(x) = x^3 + x+1, and m(x) = x^4 + x^3 + x^2 + x+1. Since m(x) always has one more highest term than f(x) and the coefficient of the highest term is 1, when converted to a binary array, the polynomial can be represented using a binary array as f(x) = [1,0,1,1], m(x) = [1,1,1,1] (the highest bit is 1 by default and omitted). In this case, the coefficients of the arrays of f(x) and m(x) completely correspond. The process of x*f(x) mod m(x) can be as follows:

[0096] It is known that the coefficients of the x^3, x^2, and x^0 terms of m(x) (except the highest and lowest terms which have been omitted) are all 1. Then, controlled addition operations are performed on the x^2, x^3, and x^0 terms of f(x) with respect to the coefficient of the x^3 term of f(x) (since the highest term of g(x) is the x^3 term, the coefficient of this term must be 1 at this time), and the array [1,1,0,0] is obtained.

[0097] Then swap the array [1,1,0,0] from left to back and get the result [1,0,0,1], which means that the polynomial obtained by x*f(x)mod m(x) is x^3+1.

[0098] In one embodiment, the structure of the modular multiplication operator corresponding to the calculation process in the above example can be as follows: Figure 3 As shown, the modular multiplication operator acts on 4 quantum bits, which are used to store the highest bit to the lowest bit of the calculation result of x*f(x)mod m(x) from top to bottom.

[0099] The initial state of the quantum bit in this quantum circuit is |0>. First, three X gates are used to evolve the initial state into the quantum state |1011> corresponding to the polynomial f(x) array [1,0,1,1].

[0100] Since the polynomial m(x) array [1,1,1,1] still has coefficients of 1 in the x^3, x^2, and x^0 terms, except for the highest and lowest terms, controlled addition operations must be performed on the x^2, x^3, and x^0 terms of f(x) in sequence. Therefore, the quantum state |1> corresponding to the highest bit (x^3) coefficient of the polynomial f(x) array [1,0,1,1] can be used to perform a CNOT gate operation on the lower-order qubits below it, evolving the quantum state |1100>.

[0101] Finally, we perform SWAP gate operations on these four qubits in descending order of their corresponding coefficients, evolving the quantum state |1001>. This corresponds exactly to the array [1, 0, 0, 1] obtained from the classical calculation above.

[0102] In this embodiment, by combining multiple CNOT gates and SWAP gates, the modular multiplication operation of x*f(x)mod m(x) can be implemented through a quantum circuit with a low computational depth, thereby constructing a polynomial modular square operator for quantum computing.

[0103] In one embodiment, Figure 4 As shown, the polynomial modular square operator is also used to determine the modular addition and modular square operation result of the square of the first polynomial and the input third polynomial, the modulus in the modular addition and modular multiplication square operation is the second polynomial, and the polynomial modular square operator also includes n-1 modular division operators.

[0104] Wherein: the modular division operator is before the controlled adder and the modular multiplication operator, and is used to calculate the modular division result of the third polynomial and the second polynomial, and the modulus in the modular division operation is the second polynomial.

[0105] Specifically, the initial state of the quantum bits in the second quantum register is the quantum state of the coefficients of each degree term in the third polynomial, and the modular division operator is used to perform a SWAP gate operation on the quantum bits in the second quantum register in sequence based on the coefficients of the third polynomial from low to high; and when the quantum state corresponding to the i-th coefficient of the second polynomial is |1>, perform a CNOT gate operation on the quantum bit corresponding to the i-1-th coefficient of the third polynomial in the second quantum register; wherein the i-th bit is the non-highest bit and the non-lowest bit of the second polynomial.

[0106] Furthermore, in order to realize the polynomial modular addition and modular square operation in quantum computing, that is, h(x)+f(x) 2 mod m(x), we can set Then the specific implementation formula of the above polynomial module plus module square is:

[0107]

[0108] Then, if the initial state of the qubits in the second quantum register is set to the quantum state of the coefficients of each degree term in the third polynomial h(x), the above polynomial modular square operation f(x) can be performed. 2 Before mod m(x), divide h(x) by x n-1 The modular operation is performed by calculating the modular division result of the third polynomial h(x) and the second polynomial m(x) through the modular division operator, and then calculating the modular square operation result of the first polynomial f(x) through the polynomial modular square operator in the above embodiment, so as to obtain the quantum state of the polynomial modular addition modular square operation result |h(x)+f(x) 2 mod m(x)>.

[0109] The above modular division operator is set before the controlled adder and modular multiplication operator. n-1 The modular operation is the inverse of the *x operation, meaning that h(x) must be divided by x n-1 times, with the modulus being the second polynomial m(x). In contrast to the modular multiplication circuit described above, the modular division circuit performs SWAP gate operations on the qubits in the second quantum register, sequentially based on the coefficients of the third polynomial, ordered from lowest to highest. Furthermore, when the quantum state corresponding to the i-th bit (i-th bit is the non-highest bit or non-lowest bit of the second polynomial) of the second polynomial is |1>, a CNOT gate operation is performed on the qubit corresponding to the i-1th bit of the third polynomial in the second quantum register. The structure, principle, and specific construction of this quantum circuit are similar to those of the modular multiplication circuit described above and will not be further elaborated here.

[0110] In this embodiment, by combining multiple SWAP gates and CNOT gates, the construction of the modular division operator can be realized through a quantum circuit with a relatively low computational depth, thereby further expanding the scope of application of the polynomial modular square operator in the embodiment of the present invention. It can be used to determine the results of polynomial modular addition and modular square operations in quantum computing, and can better solve some problems of modular operations.

[0111] like Figure 5 As shown, an embodiment of the present invention further provides a polynomial modular square operation method, which may include the following steps:

[0112] Step 501: Obtain the polynomial modular square operator, the first polynomial, and the second polynomial described in the above embodiment;

[0113] Step 502: Inputting the first polynomial and the second polynomial into the polynomial modular square operator, and running the polynomial modular square operator to obtain a quantum state corresponding to a modular square operation result of the first polynomial;

[0114] Step 503: Determine the modular square operation result of the first polynomial based on the quantum state corresponding to the modular square operation result.

[0115] Specifically, in some embodiments, a third polynomial can also be obtained, and based on the polynomial modular addition and modular square operation method provided in the above embodiments, the modular addition and modular square operation result of the square of the first polynomial and the input third polynomial is determined. The modulus in the modular addition and modular square operation is the third polynomial, which will not be repeated here.

[0116] See also Figure 6 , Figure 6 An embodiment of the present invention provides a polynomial modular square operation device, the device comprising:

[0117] An acquisition module 601 is configured to acquire the polynomial modular square operator, the first polynomial, and the second polynomial described in the above embodiment;

[0118] A calculation module 602 is configured to input the first polynomial and the second polynomial into the polynomial modular square operator, and execute the polynomial modular square operator to obtain a quantum state corresponding to a modular square operation result of the first polynomial;

[0119] The determination module 603 is configured to determine a result of the modular square operation of the first polynomial based on the quantum state corresponding to the result of the modular square operation.

[0120] Regarding the specific functions and effects achieved by the polynomial modular square operation method and operation device, please refer to the other embodiments of this specification for reference and explanation, and will not be repeated here. The various modules in the polynomial modular square operation device can be implemented in whole or in part by software, hardware, or a combination thereof. The modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.

[0121] See also Figure 7 The present specification also provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the polynomial modular square operation method in the above embodiment. Figure 7 , the computer device may be a classical computer, or the computer device may be a quantum computer.

[0122] The embodiments of this specification also provide a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a computer, the computer executes the polynomial modular square operation method in the above embodiment.

[0123] The embodiments of this specification also provide a computer program product including instructions, which, when executed by a computer, enables the computer to perform the polynomial modular square operation method in the above embodiment.

[0124] It should be understood that the specific examples in this specification are only intended to help those skilled in the art better understand the implementation methods of this specification, rather than to limit the scope of the present invention.

[0125] It can be understood that in the various implementations of this specification, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the implementation methods of this specification.

[0126] It can be understood that the various embodiments described in this specification can be implemented individually or in combination, and the embodiments in this specification are not limited to this.

[0127] Unless otherwise indicated, all technical and scientific terms used in the embodiments of this specification have the same meaning as those commonly understood by those skilled in the art in the technical field of this specification. The terms used in this specification are only for the purpose of describing specific embodiments and are not intended to limit the scope of this specification. The term "and / or" used in this specification includes any and all combinations of one or more related listed items. The singular forms "a", "above", and "the" used in the embodiments of this specification and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise.

[0128] It is understood that the processor in the embodiments of this specification can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiment can be completed by hardware integrated logic circuits in the processor or software instructions. The above processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of this specification can be implemented or executed. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this specification can be directly implemented as being executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.

[0129] It is appreciated that the memory in the embodiments of the present specification can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM). It should be noted that the memory of the system and method described herein is intended to include, but not limited to, these and any other suitable types of memory.

[0130] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be realized in electronic hardware, or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present specification.

[0131] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.

[0132] In several embodiments provided in the present specification, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are merely schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0133] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, i.e. can be located in one place, or can be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment.

[0134] In addition, each functional unit in each embodiment of this specification may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0135] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this specification, or the part that contributes to the prior art, or the part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of this specification. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0136] The above description is merely a specific embodiment of this specification, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this specification should be included within the scope of protection of this specification. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A polynomial modular square operator, characterized in that: The polynomial modular square operator is used to determine the modular square operation result of the input first polynomial, where the modulus in the modular square operation is the second polynomial; it includes n controlled adders and n-1 modular multiplication operators that are alternately cascaded, wherein: The controlled adder is used to determine a when the quantum state of the auxiliary bit is the target quantum state. i times the sum of the first polynomial and the value of the initial state, or, determine a i The auxiliary bits are used to store the coefficients a of each degree term in the first polynomial. i The quantum state of the first polynomial is no more than n-1; The modular multiplication operator is used to determine a modular multiplication result of an output result of the previous controlled adder and a variable in the first polynomial, where the module in the modular multiplication operation is the second polynomial.

2. The polynomial modular square operator according to claim 1, wherein: The number of the auxiliary bit is 1, and the quantum state of the auxiliary bit is achieved by acting on the storage a i The logic gates on the quantum bit and the auxiliary bit are obtained.

3. The polynomial modular square operator according to claim 2, wherein: The function of storing the a i The quantum bit and the logic gate on the auxiliary bit include two CNOT gates respectively located before and after the corresponding controlled adder, and the control bits of the CNOT gates before and after the corresponding controlled adder are both the storage a i The quantum bits, controlled bits are all the auxiliary bits.

4. The polynomial modular square operator according to claim 1, wherein: Each of the controlled adders is controlled in sequence by the quantum states corresponding to the high-order coefficients to the low-order coefficients of the first polynomial; wherein the first controlled adder is used to determine the sum of the first polynomial times the highest-order coefficient and the value of the initial state when the quantum state corresponding to the highest-order coefficient of the first polynomial is the target quantum state; the controlled adders other than the first one are used to determine the sum of the first polynomial times the corresponding coefficients and the output result of the previous modular multiplication operator when the quantum states corresponding to other coefficients of the first polynomial are the target quantum state.

5. The polynomial modular square operator according to claim 3, wherein: The degree of the first polynomial f(x) is n-1, and the degree of the second polynomial m(x) is n; the polynomial modular square operator includes a first quantum register and a second quantum register, and the number of quantum bits included in the first quantum register and the second quantum register are both n; the quantum bits in the first quantum register are used to store the quantum state of the coefficient of each degree term in the first polynomial f(x); each of the controlled adders is used to perform a CNOT gate operation on the quantum bits in the second quantum register when the quantum state of the auxiliary bit is |1>, so as to determine the sum of the quantum state of the coefficient of the first polynomial f(x) and the quantum state of the corresponding quantum bit in the second quantum register.

6. The polynomial modular square operator according to claim 5, wherein: The modular multiplication operator is configured to perform a CNOT gate operation on the quantum bit corresponding to the i-1th coefficient in the second quantum register when the quantum state corresponding to the i-th coefficient of the second polynomial m(x) is |1>; and sequentially perform a SWAP gate operation on the quantum bits in the second quantum register based on the order of the corresponding coefficients in the second quantum register from high to low; wherein the i-th bit is a non-highest bit and a non-lowest bit of the second polynomial m(x).

7. A polynomial modular square operation method, characterized in that: The method comprises: Obtain the polynomial modular square operator, the first polynomial, and the second polynomial according to any one of claims 1 to 6; Inputting the first polynomial and the second polynomial into the polynomial modular square operator, and running the polynomial modular square operator to obtain a quantum state corresponding to a modular square operation result of the first polynomial; The modular square operation result of the first polynomial is determined based on the quantum state corresponding to the modular square operation result.

8. A polynomial modular square operation device, characterized in that: The device comprises: An acquisition module, configured to acquire the polynomial modular square operator, the first polynomial, and the second polynomial according to any one of claims 1 to 6; a calculation module, configured to input the first polynomial and the second polynomial into the polynomial modular square operator, and execute the polynomial modular square operator to obtain a quantum state corresponding to a modular square operation result of the first polynomial; A determination module is used to determine the modular square operation result of the first polynomial based on the quantum state corresponding to the modular square operation result.

9. A storage medium, characterized in that: The storage medium stores a computer program, wherein the computer program is configured to execute the method according to claim 7 when executed.

10. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method of claim 7 .

Citation Information

Patent Citations

  • Modular squaring circuit, modular squaring method, and modular squaring program

    EP1306748A2

  • Generic modular multiplier using partial reduction

    US20030206628A1