Classical and Quantum Hybrid Integer Factorization Method Based on Quantum Smoothness Testing
Through the combination of quantum smoothness testing and classical computing, the problem of inefficient real relationship determination in traditional integer decomposition algorithms is solved, and the efficiency and security of integer decomposition are improved, which is suitable for large integer decomposition in public key cryptography.
Patent Information
- Application Number
- CN202311405211.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-27
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2043-10-27
AI Technical Summary
In traditional integer decomposition algorithms, determining the true relationship of candidate relationships is inefficient, resulting in inefficient integer decomposition, especially in public key cryptography, the difficulty of large integer decomposition affects the security of data transmission.
Using a method based on quantum smoothness testing, the candidate relationship of the target integer is obtained, and the smoothness judgment and decomposition are used to determine the true relationship, and batch decomposition is performed in combination with classical calculations to improve the determination efficiency of the true relationship.
The efficiency of determining the true relationship from a large number of candidate relationships is improved, thereby improving the efficiency of integer decomposition and reducing the computational complexity of integer decomposition.
Smart Images

Figure CN117313885B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of quantum computing technology, and particularly to a classical and quantum hybrid integer factorization method based on quantum smoothness testing. Background Art
[0002] Public-key cryptography is an encryption algorithm system based on number theory, used to ensure the security and privacy during data transmission, and the security of data transmission is closely related to the difficulty of large integer factorization.
[0003] In traditional technologies, first, a polynomial and a factor base are determined according to the target integer to be factorized, then candidate relations are determined using the sieve method and the threshold detection method, and then using the classical smoothness testing method, the norm corresponding to each candidate relation is continuously divided by each prime factor in the factor base until the division is complete to obtain a remainder, and then it is determined whether the candidate relation corresponding to the norm is a true relation according to the remainder. However, there are multiple norms corresponding to multiple candidate relations, and there are also multiple prime factors in the factor base. The efficiency of determining the true relations among the candidate relations through the above traditional technologies is low, resulting in low efficiency in subsequent completing the factorization of the target integer. Summary of the Invention
[0004] Based on this, it is necessary to provide a classical and quantum hybrid integer factorization method based on quantum smoothness testing for the above technical problems.
[0005] This application provides a classical and quantum hybrid integer factorization method based on quantum smoothness testing. The method includes:
[0006] Obtain the target integer to be factorized during information security computing, and determine multiple candidate relations corresponding to the target integer according to the requirements of the quadratic congruence class integer factorization algorithm, and the number of candidate relations exceeds a preset threshold;
[0007] Perform smoothness judgment on each candidate relation respectively. When the preset quantum cofactor integer factorization condition is satisfied, perform quantum integer factorization on the norm corresponding to the current candidate relation, and determine whether the current candidate relation is a true relation according to the decomposition result. When the current candidate relation is a true relation, determine the norm corresponding to the true relation as a smooth number that meets the smoothness requirement, and use the current candidate relation as the target relation;
[0008] Factorize the target integer according to the target relation.
[0009] In one embodiment, when the preset quantum cofactor integer factorization condition is satisfied, performing quantum integer factorization on the norm corresponding to the current candidate relation includes:
[0010] Determine the judgment parameters for smoothness testing according to the target integer, where the judgment parameters include the available amount of quantum resources, the cofactor binary bit length, and the batch decomposition smoothness bound;
[0011] Perform batch decomposition on the norm corresponding to the current candidate relationship according to the batch decomposition smoothness bound to obtain the target cofactor;
[0012] Determine the quantum resource demand for target cofactor decomposition according to the cofactor binary bit length;
[0013] When the quantum resource demand for cofactor decomposition is less than or equal to the available amount of quantum resources, perform quantum integer decomposition on the target cofactor.
[0014] In one embodiment, the method further includes:
[0015] When the quantum resource demand for cofactor decomposition is greater than the available amount of quantum resources, perform integer decomposition on the target cofactor according to a preset classical integer decomposition algorithm.
[0016] In one embodiment, performing batch decomposition on the norm corresponding to the current candidate relationship according to the batch decomposition smoothness bound to obtain the target cofactor includes:
[0017] Determine the number of norms to be decomposed in each batch and the number of decomposition rounds according to the maximum bit length of the absolute value of the target norm to be batch decomposed, a preset factor base, and a preset prime factor power scale upper limit parameter;
[0018] In each decomposition round, construct a product tree, an inverse tree, and a remainder tree for all the norms within the current round, and determine the smooth part of each norm according to the greatest common divisor between the leaf nodes of the remainder tree and the corresponding norms;
[0019] Divide the norm by the corresponding smooth part to obtain the target cofactor.
[0020] In one embodiment, the method further includes:
[0021] Judge whether the target cofactor needs to be decomposed according to a preset set of cofactor decomposition conditions. When the judgment result is that the target cofactor needs to be decomposed, determine the decomposition method of the target cofactor according to the comparison result between the quantum resource demand for cofactor decomposition and the available amount of quantum resources; when the judgment result is that the target cofactor does not need to be decomposed, determine whether the candidate relationship corresponding to the target cofactor is a true relationship according to the judgment results corresponding to each judgment condition in the set of cofactor decomposition conditions.
[0022] In one embodiment, the set of target cofactor decomposition determination conditions includes two sets of determination conditions executed in sequence. The first set of determination conditions includes whether the target cofactor is equal to a preset threshold and whether the target cofactor is not greater than the largest prime factor in the preset factor base. The second set of determination conditions includes whether the target cofactor is greater than the binary bit length of the cofactor, whether the target cofactor is less than the square value of the batch decomposition smooth bound, and whether the target cofactor is a prime number.
[0023] In one embodiment, there is no order relationship for execution among the determination conditions in each set of determination conditions.
[0024] In one embodiment, the method further includes:
[0025] When the target cofactor does not meet all the determination conditions in the first set of determination conditions and does not meet all the determination conditions in the second set of determination conditions, the determination result is that the target cofactor needs to be decomposed.
[0026] In one embodiment, the method further includes:
[0027] When the target cofactor meets any one of the determination conditions in the first set of determination conditions, the determination result is that the target cofactor does not need to be decomposed, the candidate relationship corresponding to the target cofactor is determined as a true relationship, and it is not necessary to execute the second set of determination conditions;
[0028] When the target cofactor does not meet any one of the determination conditions in the first set of determination conditions and meets any one of the determination conditions in the second set of determination conditions, the determination result is that the target cofactor does not need to be decomposed, the candidate relationship corresponding to the target cofactor is discarded, and the next candidate relationship is continued to be processed.
[0029] In one embodiment, the method further includes:
[0030] According to the binary bit length of the absolute value of the norm, determine the quantum resource requirement for norm decomposition. When the quantum resource requirement for norm decomposition is greater than the available quantum resources, perform batch decomposition on the norm corresponding to the current candidate relationship according to the batch decomposition smooth bound to obtain the target cofactor. According to the binary bit length of the cofactor, determine the quantum resource requirement for target cofactor decomposition, and according to the comparison result between the quantum resource requirement for cofactor decomposition and the available quantum resources, determine the decomposition method of the target cofactor; when the quantum resource requirement for norm decomposition is less than or equal to the available quantum resources, use the norm as the target cofactor for quantum integer decomposition.
[0031] The above classical and quantum hybrid integer factorization method based on quantum smoothness testing obtains the target integer to be factorized during information security computing, determines multiple candidate relationships corresponding to the target integer according to the requirements of the square congruence class integer factorization algorithm, and the number of candidate relationships exceeds a preset threshold; respectively perform smoothness judgment on each candidate relationship, and when the preset quantum cofactor integer factorization condition is satisfied, perform quantum integer factorization on the norm corresponding to the current candidate relationship, and determine whether the current candidate relationship is a true relationship according to the decomposition result. When the current candidate relationship is a true relationship, determine the norm corresponding to the true relationship as a smooth number that meets the smoothness requirement, and use the current candidate relationship as the target relationship; factorize the target integer according to the target relationship. By adopting the above method, when the current quantum resource environment meets the preset quantum cofactor integer factorization condition, perform quantum integer factorization on the norm corresponding to the current candidate relationship, and determine whether the current candidate relationship is a true relationship according to the decomposition result, so as to complete the smoothness test of the candidate relationship, and compared with the traditional integer factorization algorithm, it helps to improve the efficiency of determining the true relationship from a large number of candidate relationships, thereby improving the efficiency of subsequent target integer factorization. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 FIG. is an application environment diagram of a classical and quantum hybrid integer factorization method based on quantum smoothness testing in an embodiment;
[0033] Figure 2 FIG. is a flowchart of a classical and quantum hybrid integer factorization method based on quantum smoothness testing in an embodiment;
[0034] Figure 3 FIG. is a flowchart of factorizing a norm in an embodiment;
[0035] Figure 4 FIG. is a flowchart of obtaining the cofactor of a norm in an embodiment;
[0036] Figure 5 FIG. is a flowchart of determining whether a target cofactor needs to be factorized according to a preset set of cofactor factorization conditions in an embodiment;
[0037] Figure 6 FIG. is a flowchart of implementing integer factorization after mixing the classical MPQS algorithm and the quantum smoothness testing algorithm in an embodiment;
[0038] Figure 7 FIG. is a flowchart of implementing integer factorization after mixing the classical GNFS algorithm and the quantum smoothness testing algorithm in an embodiment;
[0039] Figure 8 FIG. is a structural block diagram of a classical and quantum hybrid integer factorization device based on quantum smoothness testing in an embodiment;
[0040] Figure 9 is the internal structure diagram of a computer device in an embodiment;
[0041] Figure 10 is the internal structure diagram of a computer device in another embodiment. Detailed implementation manners
[0042] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0043] The classical and quantum hybrid integer decomposition method based on quantum smoothness testing provided by the embodiments of the present application can be applied to an application environment as Figure 1 shown. Among them, the terminal 102 communicates with the server 104 through a network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or placed in the cloud or other network servers. Among them, the terminal 102 can be but is not limited to various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.
[0044] Integer factorization refers to the process of decomposing a large composite number, that is, a composite number with a long binary bit length, into its prime factors. To address the impact of quantum computing on integer factorization, this embodiment proposes a hybrid integer factorization method, namely a classical and quantum hybrid integer factorization method based on quantum smoothness testing, which combines the advantages of classical computing and quantum computing. This method uses batch factorization on a classical computer to reduce the complexity of the integer factorization problem, and then uses the capabilities of a quantum computer to further factorize the remaining non-smooth part. During the process of integer factorization, relation collection is the main time-consuming part of the integer factorization algorithm. For example, in the case of factoring a 190-bit (decimal) integer using the GNFS (General number field sieve) algorithm and the MPQS (Multiple Polynomial Quadratic Sieve) algorithm, the overhead of this part can reach more than 90% of the total overhead. Among them, the MPQS algorithm is the fastest large integer factorization algorithm for actual factorization within 110-bit decimal integers, and the GNFS algorithm is suitable for the factorization process of decimal integers above 110 bits. Specifically, relation collection includes two main steps: one is the sieving method, which is used to screen candidate relations that may meet the smoothness requirements, and this part is the main body of the time overhead of relation collection; the other is smoothness testing, which is used to finally determine whether the candidate relation is a true relation that meets the smooth relation requirements on the given factor base, and this part can account for 1 / 4 of the time overhead of relation collection.
[0045] In one embodiment, as Figure 2 shown, taking the application of this method to Figure 1 the terminal in
[0046] as an example for illustration, it can be understood that this method can also be applied to a server, and can also be applied to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. In this embodiment, the method includes the following steps:
[0047] Step 202, obtain the target integer to be factorized during information security computing, and determine multiple candidate relations corresponding to the target integer according to the requirements of the quadratic congruence class integer factorization algorithm, and the number of candidate relations exceeds a preset threshold.
[0047] Among them, the target integer can be a composite number with a relatively long number of binary bits. The target integer is usually equal to the product of two relatively large prime numbers. That is to say, the target integer can ultimately be decomposed into two relatively large prime factors, thereby forming the public key and private key in the encryption algorithm. The number of bits of the target integer is related to the security during data transmission. Generally speaking, the more bits the target integer to be factored has, the higher the computational complexity required for integer factorization, the greater the difficulty of breaking, and the higher the security during data transmission. The quadratic residue class integer algorithm is an integer factorization algorithm based on algebraic number theory. Such algorithms first determine a factor base, usually choosing a set of small prime numbers as the factor base. The factor base is a set of pre-selected prime numbers used in integer factorization, and these prime numbers are usually considered to be highly smooth; then, based on the selected factor base, find pairs of numbers that satisfy such a relationship, where r can be completely factored over the factor base; finally, determine a subset such that for the quadratic residue pairs in this subset, when multiplying the numbers on both sides of the equal sign, a perfect square number is obtained, that is, obtaining the congruence relation pair , and then by calculating the factors of the target integer N are obtained, where, is not equal to 1 and not equal to the target integer N. The differences between various quadratic residue algorithms lie in the different ways of finding the relationship.
[0048] The candidate relationship is a relationship in the quadratic residue class integer factorization algorithm that attempts to factor the target integer by constructing a series of quadratic residue pairs. According to the above content, the candidate relationship is usually a pair of numbers (x, r) that satisfy specific conditions. In order to gradually find the quadratic residue pairs of the target integer and achieve the factorization of the target integer in the follow-up, a sufficient number of candidate relationships are required. That is to say, the number of candidate relationships needs to exceed a preset threshold, and the preset threshold can be set according to the size of the target integer, the requirements of the algorithm itself, and the requirements for ensuring the success rate of the integer factorization algorithm.
[0049] Exemplarily, after obtaining the target integer to be factored, according to the classical integer factorization algorithm, such as the MPQS algorithm program, a polynomial about the target integer is selected, a factor base about the target integer is constructed, and the sieve region size is determined. Then, according to the requirements of the quadratic residue class integer factorization algorithm, a sufficient number of candidate relationships corresponding to the target integer and meeting the algorithm requirements are determined.
[0050] Step 204, perform smoothness judgment on each candidate relationship respectively. Under the condition of meeting the preset quantum cofactor integer factorization conditions, perform quantum integer factorization on the norm corresponding to the current candidate relationship, and judge whether the current candidate relationship is a true relationship according to the decomposition result. When the current candidate relationship is a true relationship, determine the norm corresponding to the true relationship as a smooth number that meets the smoothness requirements, and use the current candidate relationship as the target relationship.
[0051] Among them, the smoothness judgment of the candidate relationship, also known as the smoothness test of the candidate relationship, is to determine whether the candidate relationship meets the requirements of smoothness. Smoothness means that an integer can be divisible by a smaller factor base. The preset quantum cofactor integer factorization condition is the condition for judging whether the norm corresponding to the candidate relationship can perform quantum integer factorization. The preset quantum cofactor factorization condition can be that the current available quantum resources can meet the resource requirements for the cofactor factorization corresponding to the norm. The target relationship is the finally determined true relationship. The target relationship can provide information related to the factors of the target integer, which helps to further promote the factorization process of the target integer.
[0052] Exemplarily, when the current available quantum resources can meet the resource requirements for the cofactor factorization corresponding to the norm, perform quantum integer factorization on the norm corresponding to the current candidate relationship. And when it is judged that the current candidate relationship is a true relationship according to the decomposition result, determine the norm corresponding to the true relationship as a smooth number that meets the smoothness requirements, and use the current candidate relationship as the target relationship, that is, the true relationship.
[0053] Step 206, decompose the target integer according to the target relationship.
[0054] Exemplarily, after determining the true relationship, first output the true relationship, then perform deduplication and filtering on the output true relationship to exclude duplicate and invalid relationships; then construct a system of linear equations according to the deduplicated and filtered true relationships. Each true relationship corresponds to an equation, and the unknowns of the equation are usually the factor bases selected for decomposing the target integer; then solve the constructed system of linear equations, and use the solutions of the obtained system of equations to construct square congruence pairs; the roots of the square congruence pairs need to be further solved through the square root algorithm; then perform the greatest common divisor operation according to the obtained roots to obtain the complete factorization result of the target integer.
[0055] In the above classical and quantum hybrid integer factorization method based on quantum smoothness test, when the current quantum resource environment meets the preset quantum cofactor integer factorization condition, perform quantum integer factorization on the norm corresponding to the current candidate relationship, and judge whether the current candidate relationship is a true relationship according to the decomposition result, so as to complete the smoothness test of the candidate relationship. And compared with the traditional integer factorization algorithm, it helps to improve the efficiency of determining the true relationship from a large number of candidate relationships, thus improving the efficiency of subsequent completion of the target integer factorization.
[0056] In one embodiment, as Figure 3 shown, when meeting the preset quantum cofactor integer factorization condition, performing quantum integer factorization on the norm corresponding to the current candidate relationship includes:
[0057] Step 302: Determine the judgment parameters for smoothness testing according to the target integer. The judgment parameters include the available amount of quantum resources, the binary bit length of the cofactor, and the batch decomposition smooth bound.
[0058] Among them, the judgment parameters for smoothness testing are the parameters required for quantum integer factorization of the norm corresponding to each candidate relationship or quantum cofactor factorization of the cofactor corresponding to the norm. The available amount of quantum resources is the current available quantum resources of the system. The system can be a NISQ (Noisy Intermediate-Scale Quantum) quantum computer system, which can be used in a noisy and medium-scale quantum environment with noise interference. The available amount of quantum resources is related to the number of qubits currently owned by the system. A qubit is the basic unit of the quantum information unit. Quantum has characteristics such as quantum entanglement and quantum interference. The quantum characteristics of qubits make quantum computing more efficient than classical computing. That is to say, the more qubits, the stronger the ability of the quantum computer to handle complex computing tasks. The batch decomposition smooth bound is the batch decomposition threshold parameter for batch decomposition of the norm. It is agreed that the smooth bound can be replaced by its exponent, that is, the smooth bound B = For example, the smooth bound is 38. For a given batch decomposition smooth bound, multiply the prime factors of an integer that do not exceed the batch decomposition smooth bound to obtain the smooth part of the integer for the given batch decomposition smooth bound. After dividing the integer by the smooth part, the cofactor corresponding to the integer can be obtained. The binary bit length of the cofactor is the cofactor scale threshold, which is used to limit the number of bits of the cofactor. Based on this, the quantum integer factorization in this embodiment includes the processes of batch decomposition of the norm and quantum cofactor factorization of the cofactor corresponding to the norm.
[0059] Exemplarily, according to the target quantum system scale, the bit scale of the target integer, and the classical MPQS algorithm / GNFS algorithm, determine the available amount of quantum resources, the binary bit length R of the cofactor, and the batch decomposition smooth bound B for smoothness testing.
[0060] Step 304: Perform batch decomposition on the norm corresponding to the current candidate relationship according to the batch decomposition smooth bound to obtain the target cofactor.
[0061] Exemplarily, divide the norm corresponding to the current candidate relationship by the smooth part within the batch decomposition smooth bound to obtain the target cofactor corresponding to the current norm.
[0062] Step 306: Determine the quantum resource demand for target cofactor factorization according to the binary bit length of the cofactor.
[0063] Exemplarily, in quantum computing, cofactor decomposition is to perform integer decomposition on cofactors. The larger the cofactor size, the more qubits are required, that is, the more quantum resources are needed. Therefore, according to the binary bit length of the cofactor, that is, the size of the cofactor, the quantum resource requirement for the target cofactor decomposition is determined. The quantum resource requirement for the target cofactor decomposition in this embodiment is also the maximum amount of quantum resources required for the target cofactor decomposition.
[0064] Step 308, when the quantum resource requirement for cofactor decomposition is less than or equal to the available quantum resources, perform quantum integer decomposition on the target cofactor.
[0065] Exemplarily, when the quantum resource requirement for cofactor decomposition is less than or equal to the available quantum resources, it indicates that the current quantum resource environment of the system meets the decomposition requirements of the target cofactor. Quantum integer decomposition algorithms, such as Shor's algorithm and the Quantum Approximate Optimization Algorithm (QAOA), can be used to perform quantum integer decomposition on the target cofactor. Among them, Shor's algorithm is a quantum algorithm for the integer decomposition problem. Its core is to transform the integer decomposition problem into finding the minimum period. Using a quantum computer, the integer decomposition problem can be solved in polynomial time. The number of qubits required for Shor's algorithm to decompose the target integer N is O(logN). The number of qubits required for the currently optimal implementation circuit of Shor's algorithm is . The QAOA is a quantum approximate optimization algorithm. Many problems, including the integer decomposition problem, the Closest Vector Problem (CVP) (approximate or solve discrete quantization problems), and the maximum cut problem, can be transformed into optimization problems and solved by the QAOA. The QAOA itself is a classical-quantum hybrid algorithm. This algorithm can decompose the optimization problem into many sub-problems, use a quantum computer to solve the sub-problems, use a classical optimizer to perform optimization and control the task splitting and optimization direction, and the QAOA has a high tolerance for noise.
[0066] In this embodiment, when the current resource environment of the system meets the preset quantum cofactor integer factorization condition, the norm corresponding to the current candidate relationship is first batch factored, that is, the smooth part of the target integer is removed first to reduce the complexity of the target integer factorization. Then, when the quantum resource requirement during cofactor factorization is less than or equal to the available quantum resources, the Shor algorithm, the QAOA algorithm, or other quantum integer factorization algorithms are used to factorize the target cofactor, that is, the remaining non-smooth part is further factorized using the capabilities of a quantum computer, thereby completing the smoothness test of the candidate relationship, and the test result is the factorization result. Compared with the traditional classical integer factorization algorithm, the algorithm combining classical batch factorization and quantum integer factorization helps to reduce the complexity of the target integer factorization; moreover, through the combination of the algorithm of classical batch factorization and quantum integer factorization, it helps to improve the efficiency of the target integer factorization.
[0067] In one embodiment, the method further includes: when the quantum resource requirement during cofactor factorization is greater than the available quantum resources, the target cofactor is factorized into an integer according to a preset classical integer factorization algorithm.
[0068] Exemplarily, when the quantum resource requirement during cofactor factorization is greater than the available quantum resources, it indicates that the current quantum resource environment of the system does not meet the factorization requirements of the target cofactor. At this time, a classical integer factorization algorithm can be used, for example, classical cofactor factorization algorithms such as the sieve method and the trial division method, to factorize the target cofactor. The sieve method and the trial division method and other classical cofactor factorization algorithms are the preset classical integer factorization algorithms.
[0069] In this embodiment, when the quantum resource requirement during cofactor factorization is greater than the available quantum resources, the target cofactor is factorized into an integer according to classical cofactor factorization algorithms such as the sieve method or the trial division method, thereby realizing the flexible selection of a suitable integer factorization algorithm according to the magnitude relationship between the quantum resource requirement during cofactor factorization and the available quantum resources, which helps to improve the versatility and adaptability of the algorithm combining classical batch factorization and quantum integer factorization in this embodiment; moreover, since the target integer is first batch factored, even after batch factorization, when using a classical integer factorization algorithm to factorize the target cofactor, the calculation efficiency is greatly improved compared with the existing classical integer factorization algorithms.
[0070] In one embodiment, as Figure 4 shown, batch factoring the norm corresponding to the current candidate relationship according to the batch factorization smooth bound to obtain the target cofactor includes:
[0071] Step 402, determine the number of norms to be batch factored in each batch and the number of factorization rounds according to the maximum bit length of the absolute value of the target norm to be batch factored, a preset factor base, and a preset upper limit parameter of the prime factor power scale.
[0072] Among them, the batch factorization in this embodiment decomposes the norm corresponding to the current candidate relationship according to the Bernstein batch factorization algorithm. Specifically, the Bernstein batch factorization algorithm needs to calculate the product tree, inverse tree, and residual tree of a batch of integers in sequence in a binary tree form. By obtaining the greatest common divisor of each integer and the leaf node of the corresponding residual tree, the smooth part of the integer within the given smooth bound can be obtained. By removing the smooth part from the integer, the cofactor can be obtained, completing the decomposition of each integer in a batch of integers into the form of the product of the smooth part and the cofactor. The preset upper limit parameter of the prime factor power scale is used to limit the number and size of prime factors found in the candidate relationship during factorization. This parameter limits the maximum number of occurrences of each prime factor and controls the complexity and resource consumption during factorization.
[0073] Exemplarily, assume that the upper limit parameter of the prime factor power scale is x, and the largest prime factor in the factor base is FB max , and the total number of norms to be tested for smoothness is N total . The specific process of determining the number of norms decomposed each time and the number of decomposition rounds is as follows:
[0074] First, start traversing all prime factors p not exceeding the batch factorization smooth bound B from p = 2 i , continuously calculate its power for each prime factor , y is the maximum number of p that satisfies this inequality i ; then calculate the prime factor product , and count the product scale (the scale after converting the product to a binary number). For the power of 2 whose length is not 2, pad 0 to the high bit until it is a power of 2. The length after padding 0 is Length. The fewer 0s padded, the better the efficiency; then calculate the number of norms decomposed in each batch , and round down the calculation result. Among them, Leaf is the maximum bit length of the absolute value of the target norm to be batch factorized, N batch is also called the throughput rate of batch factorization, and N batch has the highest efficiency when it is a power of 2; then calculate the number of decomposition rounds , and round up the calculation result. In addition, in each round of batch smoothness test, first calculate the N norms that actually need to be processed in this round. When N < N batch , pad the norms with 1 to N batch norms, and then perform the batch factorization operation on N norms.
[0075] Step 404, in each round of decomposition, construct the product tree, inverse tree, and residual tree for all norms within the current round. According to the greatest common divisor between the leaf nodes of the residual tree and the corresponding norms, determine the smooth parts of each norm.
[0076] Among them, the product tree is a binary tree. The leaf nodes in the product tree represent each integer in a given batch of integers, while the non-leaf nodes represent the products of these numbers. The construction of the product tree is carried out recursively from the bottom up. The value of a non-leaf node in the product tree is equal to the product of the values of its left and right child nodes. The inverse tree is also a binary tree. The purpose of constructing the inverse tree is to obtain the reciprocal of the product tree. The inverse tree has the same structure as the product tree, and its construction is also carried out recursively from the bottom up. The value of its node is equal to the Montgomery inverse of the value of the product tree node. The residual tree is a tree structure calculated using the product tree and the inverse tree. Each leaf node of the residual tree represents each integer in a batch of integers, and its value is equal to the modulo result of the prime factor product PrimeProduct and this integer. During the process of calculating the residual tree, the greatest common divisor of each leaf node and the corresponding norm is obtained.
[0077] Exemplarily, for all norms in the current round, a product tree is constructed. The leaf nodes of the product tree represent each norm respectively, while the non-leaf nodes represent their products. By calculating recursively from the bottom up, we can obtain the values of each non-leaf node; then, an inverse tree is constructed. Each node of the inverse tree represents the reciprocal of the corresponding product tree node, that is, the Montgomery inverse of the value in the product tree, and by calculating recursively from the bottom up, the values of the nodes of the inverse tree can be obtained; finally, a residual tree is constructed. Each leaf node of the residual tree represents the modulo result of the prime factor product PrimeProduct and the corresponding norm, and the greatest common divisor of each norm and its corresponding residual tree leaf node is obtained. This greatest common divisor is the smooth part in the given smooth bound, that is, the norm can be divided evenly by the greatest common divisor.
[0078] Step 406, divide the norm by the corresponding smooth part to obtain the target cofactor.
[0079] Exemplarily, removing the smooth part from the target integer can obtain the cofactor. That is to say, dividing the norm by the corresponding smooth part can obtain the target cofactor.
[0080] In this embodiment, through the Bernstein batch decomposition algorithm, a batch of norms can be decomposed into the smooth part and the cofactor on the factor basis more quickly. After removing the smooth part, only by further judging the smoothness of the cofactor can the true relationship be determined, thereby improving the collection efficiency of the true relationship.
[0081] In one embodiment, the method further includes: judging whether a target cofactor needs to be decomposed according to a preset set of cofactor decomposition conditions; when the judgment result is that the target cofactor needs to be decomposed, determining a decomposition method for the target cofactor according to a comparison result between the quantum resource requirement and the available quantum resources during cofactor decomposition; when the judgment result is that the target cofactor does not need to be decomposed, determining whether the candidate relationship corresponding to the target cofactor is a true relationship according to the judgment results corresponding to the respective judgment conditions in the cofactor decomposition judgment condition set.
[0082] Wherein, the preset set of cofactor decomposition conditions is a set of multiple judgment conditions for judging whether a cofactor needs to be decomposed.
[0083] Exemplarily, when judging that the target cofactor needs to be decomposed according to the preset set of cofactor decomposition conditions, if the quantum resource requirement during cofactor decomposition is less than or equal to the available quantum resources, perform quantum cofactor decomposition on the target cofactor; if the quantum resource requirement during cofactor decomposition is greater than the available quantum resources, decompose the target cofactor according to the classical integer decomposition algorithm; when judging that the target cofactor does not need to be decomposed according to the preset set of cofactor decomposition conditions, it is necessary to further determine whether the candidate relationship corresponding to the target cofactor is a true relationship according to the specific results corresponding to the respective judgment conditions in the cofactor decomposition judgment condition set.
[0084] In this embodiment, by using the preset set of cofactor decomposition conditions to judge whether the target cofactor needs to be decomposed, when the target cofactor does not need to be decomposed, it indicates that the corresponding candidate relationship is either a true relationship or a relationship to be discarded. Then, only perform quantum cofactor decomposition on the target cofactors that need to be decomposed, thereby reducing the number of times the quantum cofactor decomposition algorithm is called, reducing system resource consumption, and improving the overall efficiency of the algorithm; and it helps to improve the collection efficiency of true relationships.
[0085] In one embodiment, the target cofactor decomposition judgment condition set includes two sets of judgment conditions executed in sequence, where the first set of judgment conditions includes whether the target cofactor is equal to a preset threshold and whether the target cofactor is not greater than the largest prime factor in the preset factor base, and the second set of judgment conditions includes whether the target cofactor is greater than the cofactor binary bit length, whether the target cofactor is less than the square value of the batch decomposition smooth bound, and whether the target cofactor is a prime number.
[0086] Exemplarily, in the first set of judgment conditions, the preset threshold is 1. When the first set of judgment conditions is executed, if the target cofactor is equal to 1, it indicates that all factors of the norm are less than the smooth bound, and the target cofactor does not need to be decomposed, and the candidate relationship corresponding to the norm can be directly determined as the true relationship. If the target cofactor is less than the largest prime factor in the preset factor base, it indicates that the target cofactor must also be a prime number and does not need to be decomposed, and the candidate corresponding to the norm can be directly determined as the true relationship. When the second set of judgment conditions is executed, it indicates that the target cofactor does not meet any of the judgment conditions in the first set of judgment conditions. At this time, if the target cofactor is greater than the binary bit length of the cofactor or the target cofactor is less than the square value of the batch decomposition smooth bound or the target cofactor is a prime number, the target cofactor does not need to be decomposed, and the corresponding candidate relationship is discarded. Therefore, when the target cofactor meets any of the judgment conditions in the first set of judgment conditions, there is no need to execute the remaining judgment conditions and the second set of judgment conditions, and the true relationship can be directly determined. When the target cofactor does not meet all of the judgment conditions in the first set of judgment conditions, the second set of judgment conditions is executed.
[0087] In this embodiment, by executing two sets of judgment conditions in sequence, it helps to ensure the sufficiency of the judgment process for whether the target cofactor needs to be decomposed, thereby improving the accuracy of determining the target cofactor that needs to be decomposed, and further helping to truly reduce the number of times the quantum cofactor decomposition algorithm is called and reduce system resource consumption.
[0088] In one embodiment, there is no sequential execution order relationship among the judgment conditions in each set of judgment conditions.
[0089] Exemplarily, according to the above content, there is a sequential execution order between the first set of judgment conditions and the second set of judgment conditions, but there is no strict sequential execution order among the judgment conditions in each group. The judgment result corresponding to any judgment condition in each group does not affect the judgment result of the next judgment condition, reflecting the diversity and flexibility of the execution order setting of the judgment conditions in the two sets of judgment conditions in this embodiment.
[0090] In one embodiment, the method further includes: when the target cofactor does not meet all of the judgment conditions in the first set of judgment conditions and the target cofactor does not meet all of the judgment conditions in the second set of judgment conditions, the judgment result is that the target cofactor needs to be decomposed.
[0091] Exemplarily, according to the above content, the second set of judgment conditions is only executed when the target cofactor does not meet all of the judgment conditions in the first set of judgment conditions, and the target cofactor needs to be decomposed only when the target cofactor also does not meet all of the judgment conditions in the second set of judgment conditions, thereby realizing a strict limitation on the target cofactor that needs to be decomposed, and further truly ensuring that system resources are not wasted.
[0092] In one embodiment, the method further includes:
[0093] When the target cofactor meets any one of the judgment conditions in the first set of judgment conditions, the judgment result is that the target cofactor does not need to be decomposed, the candidate relationship corresponding to the target cofactor is determined to be a true relationship, and the second set of judgment conditions does not need to be executed; when the target cofactor does not meet any one of the judgment conditions in the first set of judgment conditions and the target cofactor meets any one of the judgment conditions in the second set of judgment conditions, the judgment result is that the target cofactor does not need to be decomposed, the candidate relationship corresponding to the target cofactor is discarded, and the next candidate relationship is continued to be processed.
[0094] Exemplarily, as Figure 5 shown, Figure 5 gives one of the execution orders of each judgment condition in the two sets of judgment conditions. It can be seen from Figure 5 that when the target cofactor is equal to 1 or the target cofactor is greater than the largest prime factor in the preset factor base when it is not equal to 1, it is determined that the target cofactor does not need to be decomposed, and the candidate relationship corresponding to the target cofactor is determined to be a true relationship; when the target cofactor is not equal to 1 and the target cofactor is not greater than the largest prime factor in the preset factor base, that is, when the target cofactor does not meet all the judgment conditions in the first set of judgment conditions, the following second set of judgment conditions is executed. When the target cofactor is greater than the cofactor binary bit length, it is determined that the target cofactor does not need to be decomposed, and the candidate relationship corresponding to the target cofactor is discarded; when the target cofactor is not greater than the cofactor binary bit length, if the target cofactor is less than the square value of the batch decomposition smooth bound, exemplarily assuming the preset batch decomposition smooth bound B and the factor base largest prime factor FB max satisfies , it is determined that the target cofactor does not need to be decomposed, and the candidate relationship corresponding to the target cofactor is discarded; when the target cofactor is not greater than the cofactor binary bit length and the target cofactor is not less than the square value of the batch decomposition smooth bound, if the target cofactor is a prime number, it is determined that the target cofactor does not need to be decomposed, and the candidate relationship corresponding to the target cofactor is discarded; if the target cofactor is not a prime number, it is determined that the target cofactor needs to be decomposed. When decomposing, it is necessary to further determine the decomposition method of the target cofactor according to the comparison result of the quantum resource demand and the available quantum resources during cofactor decomposition. It can be seen from the flow chart shown in Figure 5 that when the quantum resource demand during cofactor decomposition is less than or equal to the available quantum resources, the target cofactor is decomposed according to the Shor algorithm, the QAOA algorithm or other quantum integer decomposition algorithms; when the quantum resource demand during cofactor decomposition is greater than the available quantum resources, the target cofactor is decomposed according to classical cofactor decomposition algorithms such as the sieve method and the trial division method.
[0095] In this embodiment, according to the execution results of the first set of judgment conditions and the second set of judgment conditions, it is determined whether the target cofactor really needs to be decomposed, and for the target cofactor that does not need to be decomposed, it is further determined whether the corresponding candidate relationship should be retained or discarded, so as to improve the determination efficiency of the true relationship while discarding useless candidate relationships and reducing resource consumption.
[0096] In one embodiment, the method further includes: determining the quantum resource demand during norm decomposition according to the binary bit length of the absolute value of the norm; in the case where the quantum resource demand during norm decomposition is greater than the available quantum resources, performing batch decomposition on the norm corresponding to the current candidate relationship according to the batch decomposition smooth bound to obtain the target cofactor, determining the quantum resource demand during the decomposition of the target cofactor according to the binary bit length of the cofactor, and determining the decomposition method of the target cofactor according to the comparison result between the quantum resource demand during the decomposition of the cofactor and the available quantum resources; in the case where the quantum resource demand during norm decomposition is less than or equal to the available quantum resources, performing quantum integer decomposition on the norm as the target cofactor.
[0097] Exemplarily, the quantum resource demand for completing norm decomposition using the Shor algorithm is calculated according to the following calculation formula:
[0098] ;
[0099] where Q1 is the quantum resource demand during norm decomposition; |F(x i )| is the absolute value of the norm corresponding to the target integer x i ; log|F(x i )| is the binary bit length of the absolute value of the norm corresponding to the target integer x i .
[0100] The quantum resource demand for cofactor decomposition is calculated according to the following calculation formula:
[0101] ;
[0102] where Q2 is the quantum resource demand during cofactor decomposition; R i is the value of the i-th cofactor; logR i is the binary bit length of the value of the i-th cofactor.
[0103] After obtaining the quantum resource requirements for norm decomposition, it is necessary to determine whether it is necessary to perform batch decomposition on the norm first based on the comparison result between the quantum resource requirements for norm decomposition and the available quantum resources. That is, at the beginning of judging the smoothness of each candidate relationship, that is, before judging whether the current quantum environment meets the preset quantum cofactor integer decomposition condition, it is necessary to first determine whether the norm needs to be batch decomposed. Specifically, when the quantum resource requirements for norm decomposition are greater than the available quantum resources, first perform batch decomposition on the norm to obtain the target cofactor, and then determine the decomposition method of the target cofactor according to the comparison result between the quantum resource requirements for cofactor decomposition and the available quantum resources. As Figure 5 can be seen, when the quantum resource requirements for cofactor decomposition are less than or equal to the available quantum resources, the target cofactor can be decomposed according to quantum integer decomposition algorithms such as Shor algorithm and QAOA algorithm; when the quantum resource requirements for cofactor decomposition are greater than the available quantum resources, the target cofactor can be decomposed according to classical cofactor decomposition algorithms such as sieve method and trial division method; and when the quantum resource requirements for norm decomposition are less than or equal to the available quantum resources, the norm can be directly used as the target cofactor and directly decomposed according to quantum integer decomposition algorithms such as Shor algorithm and QAOA algorithm.
[0104] In this embodiment, by comparing the quantum resource requirements for norm decomposition with the available quantum resources, it is determined whether the norm can be directly used as the target cofactor for quantum integer decomposition, which helps to further improve the efficiency of the smoothness test for candidate relationships, and thus improve the collection efficiency of true relationships.
[0105] As Figure 6 shown, taking the classical MPQS algorithm mixed with the quantum smoothness test algorithm as an example, the execution process of the classical and quantum hybrid integer decomposition method based on the quantum smoothness test in this embodiment is described. First, the small prime factors within the smooth bound in the candidate relationship are removed by using the Bernstein batch decomposition algorithm, and then the smoothness of the candidate relationship is determined by judging and decomposing the cofactor. Then, the prime factors of the smooth part of the true relationship are restored by using trial division, sieve method, etc. with negligible overhead, so as to accelerate the quantum batch smoothness test. The specific execution process is described as follows:
[0106] 1. Input the target integer to be factorized, and determine the judgment parameters for smoothness test according to the target integer. The judgment parameters include the available quantum resources, the binary bit length R of the cofactor, and the batch decomposition smooth bound B;
[0107] 2. Select a suitable screening polynomial and construct a factor base according to the classical MPQS algorithm;
[0108] 3. Perform the sieve method and threshold detection to determine the candidate relationship;
[0109] 4. Generate the norm F(x) corresponding to each candidate relationship, and determine the quantum resource requirement for performing the quantum smoothness test based on the binary bit length of the absolute value in the norm F(x), that is, the quantum resource requirement for norm decomposition, which is , and determine whether the quantum resource environment can meet the smoothness test requirements of the norm F(x), that is, determine whether the quantum resource requirement for norm decomposition is not greater than the available quantum resources. If the quantum resource requirement for norm decomposition is not greater than the available quantum resources, execute step 5; otherwise, execute step 6;
[0110] 5. Directly use the norm as the input for cofactor decomposition;
[0111] 6. First perform batch decomposition on the norm to remove a batch of factors within the norm smooth bound, and then perform threshold detection on each cofactor, that is, determine whether each cofactor needs to be decomposed according to the preset set of cofactor decomposition conditions. For the cofactor i that needs to be decomposed, according to its cofactor binary bit length R i , the quantum resource requirement for factorization can be determined, that is, the corresponding quantum bit requirement based on Shor's algorithm is , according to the comparison result of the quantum resource requirement for cofactor decomposition and the available quantum resources, determine the decomposition method of the cofactor. When the quantum resource requirement for cofactor decomposition is less than or equal to the available quantum resources, decompose the cofactor according to Shor's algorithm, the QAOA algorithm, or other quantum integer factorization algorithms to obtain the decomposition result; when the quantum resource requirement for cofactor decomposition is greater than the available quantum resources, decompose the cofactor according to classical cofactor decomposition algorithms such as the sieve method and the trial division method to obtain the decomposition result;
[0112] 7. Determine smoothness based on the decomposition result, that is, if all prime factors of the decomposed cofactor are in the factor base, then determine that the norm corresponding to this cofactor is a smooth number; otherwise, determine that the norm corresponding to this cofactor is not a smooth number;
[0113] 8. For the candidate relationships that meet the smoothness requirements, that is, the true relationships, perform deduplication, filtering, and construct a system of linear equations, solve the system of linear equations and square roots, and obtain the greatest common divisor of the target integer to be factorized to complete integer factorization.
[0114] As Figure 7 shown, in the embodiment of the present application, taking the classical GNFS algorithm hybrid quantum smoothness test algorithm as an example, combined with Figure 6 it can be seen that the process of the classical GNFS algorithm hybrid quantum smoothness test algorithm is basically the same as that of the classical MPQS algorithm hybrid quantum smoothness test algorithm, with only some differences in the quantum smoothness test part. Therefore Figure 7Only the corresponding quantum smoothness test part is shown, and the specific execution process is described as follows:
[0115] 1. Input the large integer to be factored, and determine the judgment parameters for smoothness test according to the target integer. The judgment parameters include the available quantum resources, the binary bit length R of the rational side cofactor, and the batch factoring smoothness bound B;
[0116] 2. Select a suitable sieving polynomial and construct a factor base according to the classical GNFS algorithm;
[0117] 3. Execute the bilateral sieve method and bilateral threshold detection to determine the candidate relations;
[0118] 4. The order of bilateral smoothness test can be chosen arbitrarily. Usually, the scale of the rational side norm is significantly smaller than that of the algebraic side norm. Therefore, in the process, the smoothness test of the rational side norm can be done first. After generating the rational side norm F(x) corresponding to each candidate relation, determine the quantum resource requirement for performing the quantum smoothness test according to the binary bit length of the absolute value of the rational side norm F(x), that is, the quantum resource requirement for rational side norm factorization, which is , and judge whether the quantum resource environment can meet the smoothness test requirement of the rational side norm F(x), that is, judge whether the quantum resource requirement for rational side norm factorization is not greater than the available quantum resources. If the quantum resource requirement for rational side norm factorization is not greater than the available quantum resources, execute step 5; otherwise, execute step 6;
[0119] 5. Directly use the rational side norm as the input for rational side cofactor factorization, and execute rational side quantum cofactor factorization according to the Shor algorithm, QAOA algorithm or other quantum integer factorization algorithms, and obtain the factorization result;
[0120] 6. First perform batch factorization on the rational side norm, remove the factors within the smoothness bound of a batch of rational side norms, and then perform threshold detection on each rational side cofactor, that is, judge whether each rational side cofactor needs to be factored according to the preset set of cofactor factorization conditions. For the rational side cofactor i that needs to be factored, according to the binary bit length R of the rational side cofactor i , the quantum resource requirement for rational side cofactor factorization can be determined, that is, the corresponding quantum bit requirement based on the Shor algorithm is , determine the decomposition method of the rational - edge cofactor according to the comparison result of the quantum resource demand and the available quantum resources during the rational - edge cofactor decomposition. When the quantum resource demand during the rational - edge cofactor decomposition is less than or equal to the available quantum resources, decompose the rational - edge cofactor according to Shor's algorithm, the QAOA algorithm, or other quantum integer factorization algorithms to obtain the decomposition result; when the quantum resource demand during the rational - edge cofactor decomposition is greater than the available quantum resources, decompose the rational - edge cofactor according to classical cofactor decomposition algorithms such as the sieve method and the trial division method to obtain the decomposition result;
[0121] 7. Determine the smoothness according to the decomposition result, that is, if all prime factors of the decomposed rational - edge cofactor are in the factor base, then determine that the rational - edge norm corresponding to this rational - edge cofactor is a smooth number; otherwise, determine that the rational - edge norm corresponding to this rational - edge cofactor is not a smooth number;
[0122] 8. The steps of the algebraic - edge quantum smoothness test refer to the above steps 4 - 7 and will not be elaborated here.
[0123] 9. For candidate relations that meet the bilateral smoothness requirements, that is, true relations, remove duplicates, filter them, and construct a system of linear equations. Solve the system of linear equations and square roots to obtain the greatest common divisor of the target integer to be factored, and complete the integer factorization.
[0124] Specifically, taking the classical MPQS algorithm combined with the quantum smoothness test algorithm for integer factorization as an example, assume that the number of available logical qubits in the quantum environment is 50 qbit, that is, the available quantum resources are 50 qbit, and the target integer to be factored is N = 19807040628652778691212872687. This target integer has 95 bits and 29 digits. The polynomial selection and factor - base construction both adopt the classical MPQS algorithm process and parameters. The MPQS algorithm program in the GGNFS open - source software package can be directly used. The MPQS algorithm without using some smooth relations is adopted. The running parameters of the MPQS classical algorithm are selected as follows: the sieve region size MPQS_SIEVELEN = 2 14 , select the 11th group of default parameters {180, 4, 4, 6, 23, 70} in the MPQS algorithm parameter table of the GGNFS open - source software package, mpqs_multiplier = 7; the Bernstein batch - decomposition parameter is that the smoothness bound B is taken as 2 11 , the large - prime number bound takes the largest prime factor in the factor base (2281 in this embodiment), and the binary bit length R of the cofactor takes the square of the large prime factor, that is, 2281 2 (an integer of 23 bits), the prime - factor exponentiation scale takes 53 bits, and the batch - processing data volume is 64.
[0125] Execute the hybrid MPQS algorithm. One of the 49 polynomials selected is . According to the MPQS polynomial construction rule, Qx must be an integer multiple of the quadratic coefficient mpqs_A = 64763759741. After removing the factor mpqs_A, the factor size of qx = Qx / mpqs_A may reach 61 bits. The number of qubits required for directly using quantum cofactor decomposition to perform quantum smoothness testing is 2*61 + 3 = 125 bits, which exceeds the upper limit of 50 bits. Therefore, it is impossible to directly perform quantum smoothness determination on qx. It is necessary to first perform Bernstein batch decomposition on it to remove small prime factors within the given smooth bound 2 11 . According to the cofactor threshold parameter, the upper limit of the cofactor size is 23 bits. Therefore, after filtering by the cofactor size threshold, a cofactor not exceeding 23 bits is obtained. The maximum number of qbits required for quantum cofactor decomposition is 2*23 + 3 = 49 bits, which meets the quantum environment constraints. Therefore, under this parameter setting, all cofactors to be decomposed can use the quantum algorithm for cofactor decomposition, and then use the quantum integer factorization algorithm to factorize the cofactors that meet the size threshold. Determine the smooth relationship based on the cofactor situation, and then continue with the classical MPQS algorithm process to de-duplicate and filter the relationships, list equations and solve equations, and finally complete the factorization of the integer N.
[0126] In this example, 49 polynomials need to be selected, 1830 candidate relationships are found, and a total of 193 smooth true relationships are screened out. Among them, the Shor algorithm is used to complete the factorization of 5 cofactors and find 4 true relationships. The remaining true relationships are those with a cofactor of 1 or a cofactor less than the largest prime factor in the factor base after Bernstein batch decomposition; the hybrid algorithm does not use relationships with large prime factors; the entire MPQS algorithm only lists equations and solves equations once to complete the factorization of the integer N. N contains two prime factors, Factor[0] = 140737488355939 and Factor[1] = 140737488355333 respectively.
[0127] This embodiment adopts the above method, that is, a classical and quantum hybrid integer factorization method based on quantum smoothness testing. It intends to directly optimize the relationship collection part in the currently asymptotically optimal classical GNFS integer factorization algorithm and the classical MPQS integer factorization algorithm with the fastest actual factorization speed within 110 bits by using the Shor algorithm with a determined complexity and a clearly estimable quantum resource requirement, and uses the quantum algorithm to accelerate the smoothness testing link. This technology can theoretically achieve acceleration compared with classical algorithms, and can obtain the upper bounds of the determined computational complexity and quantum resource requirements. In terms of resource complexity, when factoring the integer n, if the binary bit length of the selected cofactor is R and the maximum absolute value of the sieving polynomial function in the sieve region is Q, the qubit requirement of this method is O(logR), where the maximum value of R can be Q. In practice, the optimized MPQS and GNFS algorithms satisfy R << Q << n, so the qubit requirement is less than the O(logn) required for directly factoring the integer n using the Shor algorithm. In terms of time complexity, the computational process and complexity of the classical algorithm other than the quantum smoothness testing link remain unchanged. Assuming that the total scale of a batch of candidate relationships is m bits, when there are enough available qubits, the quantum smoothness testing does not need to perform the Bernstein batch factorization step, and directly uses the Shor algorithm to factor the function values of the sieving polynomial corresponding to the candidate relationships. At this time, the complexity of the quantum smoothness testing link is O(m); when the number of available qubits can only factor cofactors not exceeding R, the complexity of the quantum smoothness testing is approximately the complexity of the Bernstein batch factorization algorithm O(m * logm * loglogm * log(m / R)), and the complexity of the cofactor factorization part is O(m * R / Q), which can be ignored compared with the previous term; since the performance of the Bernstein batch factorization is better than that of the trial division method (O(m 2 )) or the trial division method combined with the sieve method to obtain the smooth part of the candidate relationship in the traditional smoothness testing, the Shor algorithm is faster than the classical cofactor factorization algorithm, so the complexity of the quantum smoothness testing algorithm is lower than that of the classical smoothness testing algorithm in integer factorization algorithms such as GNFS / MPQS. To sum up, the qubit requirement of the hybrid algorithm is lower than that of the Shor algorithm, and the time complexity is lower than that of the GNFS algorithm or the MPQS algorithm using the classical smoothness testing method.
[0128] The classical and quantum hybrid integer factorization method based on quantum smoothness testing proposed in this embodiment introduces the classical Bernstein batch factorization and the quantum Shor integer factorization algorithm in the relationship collection part of the classical GNFS or classical MPQS algorithm, and performs the cofactor factorization after batch factorization with the quantum algorithm.
[0129] The task division and connection method of the classical and quantum hybrid integer factorization method based on quantum smoothness testing proposed in this embodiment is in series and stock replacement. On the one hand, a better Bernstein batch factorization algorithm is used to accelerate the classical smoothness testing. On the other hand, the quantum Shor algorithm is used to replace the classical integer factorization algorithm in cofactor factorization. Therefore, the computational complexity will definitely be reduced compared with the classical algorithm. This application can adjust the batch factorization smoothness bound B and the cofactor threshold R according to the actual quantum resources, and then adjust the problem scale that the quantum algorithm needs to solve: for an environment with limited quantum resources, B can be increased and R can be decreased to reduce the problem scale of quantum integer factorization and make the hybrid algorithm more feasible on an actual quantum computer; for an environment with abundant quantum resources, B can be decreased and R can be increased to expand the problem scale of the quantum algorithm by adjusting the threshold; for an environment with rich quantum resources, the classical Bernstein batch factorization step can be skipped directly and the input data of Bernstein can be directly used as the input of the Shor algorithm, and the quantum algorithm can be directly used to complete the smoothness testing.
[0130] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the indications of the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless there is a clear indication in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily have to be executed at the same time, but can be executed at different times. The execution order of these steps or stages does not necessarily have to be sequential, but can be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.
[0131] Based on the same inventive concept, an embodiment of the present application also provides a classical and quantum hybrid integer factorization device based on quantum smoothness testing for implementing the above-mentioned classical and quantum hybrid integer factorization method based on quantum smoothness testing. The implementation solution provided by this device to solve the problem is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the classical and quantum hybrid integer factorization device based on quantum smoothness testing provided below can refer to the limitations on the classical and quantum hybrid integer factorization method based on quantum smoothness testing in the above text, and will not be repeated here.
[0132] In one embodiment, as Figure 8 shown, a classical and quantum hybrid integer factorization device based on quantum smoothness testing is provided, including: a candidate relationship determination module 802, a target relationship determination module 804, and an integer factorization module 806, where:
[0133] The candidate relationship determination module 802 is configured to obtain a target integer to be factorized during information security calculation, determine a plurality of candidate relationships corresponding to the target integer according to the requirements of the quadratic congruence class integer factorization algorithm, and the number of candidate relationships exceeds a preset threshold.
[0134] The target relationship determination module 804 is configured to perform a smoothness judgment on each candidate relationship respectively. When the preset quantum cofactor integer factorization condition is satisfied, perform quantum integer factorization on the norm corresponding to the current candidate relationship, and determine whether the current candidate relationship is a true relationship according to the decomposition result. When the current candidate relationship is a true relationship, determine the norm corresponding to the true relationship as a smooth number that meets the smoothness requirement, and use the current candidate relationship as the target relationship.
[0135] The integer factorization module 806 is configured to factorize the target integer according to the target relationship.
[0136] In one embodiment, the target relationship determination module 804 is further configured to: determine a judgment parameter for smoothness testing according to the target integer, where the judgment parameter includes the available quantum resources, the binary bit length of the cofactor, and the batch decomposition smoothness bound; perform batch decomposition on the norm corresponding to the current candidate relationship according to the batch decomposition smoothness bound to obtain a target cofactor; determine the quantum resource requirement for factorizing the target cofactor according to the binary bit length of the cofactor; and perform quantum integer factorization on the target cofactor when the quantum resource requirement for cofactor factorization is less than or equal to the available quantum resources.
[0137] In one embodiment, the integer factorization module 806 is further configured to: when the quantum resource requirement for cofactor factorization is greater than the available quantum resources, perform integer factorization on the target cofactor according to a preset classical integer factorization algorithm.
[0138] In one embodiment, the target relationship determination module 804 is further configured to: determine the number of norms to be decomposed in each batch and the number of decomposition rounds according to the maximum bit length of the absolute value of the target norm to be batch decomposed, a preset factor base, and a preset upper limit parameter of the prime factor power scale; in each round of decomposition, construct a product tree, an inverse tree, and a remainder tree for all the norms within the current round, and determine the smooth part of each norm according to the greatest common divisor between the leaf nodes of the remainder tree and the corresponding norms; and divide the norm by the corresponding smooth part to obtain a target cofactor.
[0139] In one embodiment, the target relationship determination module 804 is further configured to: determine whether a target cofactor needs to be decomposed according to a preset set of cofactor decomposition conditions; when the determination result is that the target cofactor needs to be decomposed and the quantum resource requirement during cofactor decomposition is less than or equal to the available quantum resources, perform quantum integer decomposition on the target cofactor; when the determination result is that the target cofactor does not need to be decomposed, determine whether the candidate relationship corresponding to the target cofactor is a true relationship according to the determination results corresponding to the determination conditions in the target cofactor decomposition determination condition set.
[0140] In one embodiment, the target relationship determination module 804 is further configured to: the target cofactor decomposition determination condition set includes two sets of determination conditions executed in sequence, where the first set of determination conditions includes whether the target cofactor is equal to a preset threshold and whether the target cofactor is not greater than the largest prime factor in the preset factor base, and the second set of determination conditions includes whether the target cofactor is greater than the cofactor binary bit length, whether the target cofactor is less than the square value of the batch decomposition smooth bound, and whether the target cofactor is a prime number.
[0141] In one embodiment, the target relationship determination module 804 is further configured to: there is no order relationship for the execution of the determination conditions in each set of determination conditions.
[0142] In one embodiment, the target relationship determination module 804 is further configured to: when the target cofactor does not meet all the determination conditions in the first set of determination conditions and the target cofactor does not meet all the determination conditions in the second set of determination conditions, the determination result is that the target cofactor needs to be decomposed.
[0143] In one embodiment, the target relationship determination module 804 is further configured to: when the target cofactor meets any one of the determination conditions in the first set of determination conditions, the determination result is that the target cofactor does not need to be decomposed, and the candidate relationship corresponding to the target cofactor is determined as a true relationship, and the second set of determination conditions does not need to be executed; when the target cofactor does not meet any one of the determination conditions in the first set of determination conditions and the target cofactor meets any one of the determination conditions in the second set of determination conditions, the determination result is that the target cofactor does not need to be decomposed, discard the candidate relationship corresponding to the target cofactor, and continue to process the next candidate relationship.
[0144] In one embodiment, the integer decomposition module 806 is further configured to: determine the quantum resource requirement during norm decomposition according to the binary bit length of the absolute value of the norm; in the case where the quantum resource requirement during norm decomposition is greater than the available quantum resources, perform batch decomposition on the norm corresponding to the current candidate relation according to the batch decomposition smooth bound to obtain a target cofactor, determine the quantum resource requirement during the decomposition of the target cofactor according to the binary bit length of the cofactor, and determine the decomposition method of the target cofactor according to the comparison result between the quantum resource requirement during the decomposition of the cofactor and the available quantum resources; in the case where the quantum resource requirement during norm decomposition is less than or equal to the available quantum resources, perform quantum integer decomposition on the norm as the target cofactor.
[0145] Each module in the above classical and quantum hybrid integer decomposition device based on quantum smoothness testing can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in hardware form or independent of the processor, or stored in the memory in the computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to the above modules.
[0146] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as Figure 9 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store relevant data such as candidate relations, factor bases, polynomials, batch decomposition smooth bounds, cofactor binary bit lengths, norms, decomposition results, etc. required for target integer decomposition. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a classical and quantum hybrid integer decomposition method based on quantum smoothness testing.
[0147] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as Figure 10As shown. The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a classical and quantum hybrid integer factorization method based on quantum smoothness testing. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covered on the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.
[0148] Those skilled in the art can understand that Figure 9 and Figure 10 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.
[0149] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.
[0150] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0151] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0152] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0153] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memories can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0154] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0155] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A classical and quantum hybrid integer factorization method based on quantum smoothness testing, characterized in that, The method includes: Obtaining a target integer to be factorized during information security calculation, and determining a plurality of candidate relationships corresponding to the target integer according to the requirements of the square congruence class integer factorization algorithm, where the number of the candidate relationships exceeds a preset threshold; Respectively performing smoothness judgment on each of the candidate relationships. When the preset quantum cofactor integer factorization condition is satisfied, performing quantum integer factorization on the norm corresponding to the current candidate relationship, and judging whether the current candidate relationship is a true relationship according to the decomposition result. When the current candidate relationship is the true relationship, determining the norm corresponding to the true relationship as a smooth number that meets the smoothness requirement, and taking the current candidate relationship as the target relationship; factorizing the target integer according to the target relationship; Wherein, the performing quantum integer factorization on the norm corresponding to the current candidate relationship when the preset quantum cofactor integer factorization condition is satisfied includes: Determining a judgment parameter for smoothness test according to the target integer, where the judgment parameter includes the available quantum resources, the binary bit length of the cofactor, and the batch decomposition smoothness bound; Performing batch decomposition on the norm corresponding to the current candidate relationship according to the batch decomposition smoothness bound to obtain a target cofactor; Determining the quantum resource requirement for factorizing the target cofactor according to the binary bit length of the cofactor; When the quantum resource requirement for factorizing the cofactor is less than or equal to the available quantum resources, performing quantum integer factorization on the target cofactor. When the quantum resource requirement for factorizing the cofactor is greater than the available quantum resources, performing integer factorization on the target cofactor according to a preset classical integer factorization algorithm.
2. The method according to claim 1, characterized in that, The performing batch decomposition on the norm corresponding to the current candidate relationship according to the batch decomposition smoothness bound to obtain a target cofactor includes: Determining the number of norms to be decomposed in each batch and the number of decomposition rounds according to the maximum bit length of the absolute value of the target norm to be batch decomposed, a preset factor base, and a preset upper limit parameter of the prime factor power scale; In each decomposition round, constructing a product tree, an inverse tree, and a remainder tree for the product of all the norms within the current round, and determining the smooth part of each norm according to the greatest common divisor between the leaf nodes of the remainder tree and the corresponding norms; Dividing the norm by the corresponding smooth part to obtain the target cofactor.
3. The method according to claim 1, wherein The method further includes: Judging whether the target cofactor needs to be factorized according to a preset set of cofactor factorization conditions. When the judgment result is that the target cofactor needs to be factorized, determining the factorization method of the target cofactor according to the comparison result between the quantum resource requirement for factorizing the cofactor and the available quantum resources; when the judgment result is that the target cofactor does not need to be factorized, determining whether the candidate relationship corresponding to the target cofactor is a true relationship according to the judgment results corresponding to the judgment conditions in the set of cofactor factorization conditions.
4. The method according to claim 3, characterized in that, The set of target cofactor decomposition judgment conditions includes two sets of judgment conditions executed in sequence, where the first set of judgment conditions includes whether the target cofactor is equal to a preset threshold and whether the target cofactor is not greater than the largest prime factor in the preset factor base, and the second set of judgment conditions includes whether the target cofactor is greater than the binary bit length of the cofactor, whether the target cofactor is less than the square value of the batch decomposition smooth bound, and whether the target cofactor is a prime number.
5. The method according to claim 4, wherein There is no order relationship for execution among the judgment conditions in each set of judgment conditions.
6. The method according to claim 4, wherein The method further includes: When the target cofactor does not meet all the judgment conditions in the first set of judgment conditions and the target cofactor does not meet all the judgment conditions in the second set of judgment conditions, the judgment result is that the target cofactor needs to be decomposed.
7. The method according to claim 4, wherein The method further includes: When the target cofactor meets any one of the judgment conditions in the first set of judgment conditions, the judgment result is that the target cofactor does not need to be decomposed, the candidate relationship corresponding to the target cofactor is determined as the true relationship, and the second set of judgment conditions does not need to be executed; When the target cofactor does not meet any one of the judgment conditions in the first set of judgment conditions and the target cofactor meets any one of the judgment conditions in the second set of judgment conditions, the judgment result is that the target cofactor does not need to be decomposed, the candidate relationship corresponding to the target cofactor is discarded, and the next candidate relationship is continued to be processed.
8. The method according to claim 1, wherein The method further includes: According to the binary bit length of the absolute value of the norm, determine the quantum resource requirement for norm decomposition. When the quantum resource requirement for norm decomposition is greater than the available quantum resources, perform batch decomposition on the norm corresponding to the current candidate relationship according to the batch decomposition smooth bound to obtain a target cofactor, determine the quantum resource requirement for the target cofactor decomposition according to the binary bit length of the cofactor, and determine the decomposition method of the target cofactor according to the comparison result between the quantum resource requirement for the cofactor decomposition and the available quantum resources; when the quantum resource requirement for norm decomposition is less than or equal to the available quantum resources, use the norm as the target cofactor for quantum integer decomposition.
Citation Information
Patent Citations
Quantum computer quantum processing unit, quantum circuit and quantum circuit quantum algorithm
CN110490327A
Integer decomposition optimization method and system based on Grover quantum computing search algorithm
CN112182494A