Polynomial modular arithmetic unit, polynomial modular arithmetic method and related device
By designing a polynomial mode operator on a quantum computer, using the modular inverse operation module and the modular multiplication operation module for modular operations based on Fermat's theorem and Karatsuba algorithm, the problem of low polynomial mode operation in the prior art is solved, and more efficient quantum computer modular operations are achieved.
Patent Information
- Application Number
- CN202311484703.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-07
- Publication Date
- 2025-05-09
AI Technical Summary
The prior art is inefficient when implementing polynomial mode operations on quantum computers, especially due to the need for complex quantum gates such as Toffoli gates, which may reach exponential orders and are difficult to achieve.
A polynomial modular calculator is designed, including a modular inverse operation module and a modular multiplication operation module. The modular inverse operation module performs modular inverse operation based on Fermat's theorem, and the modular multiplication operation module performs polynomial multiplication operation based on the Karatsuba algorithm, and combines modular operation to realize polynomial modular operation h(x)+f(x)/g(x)mod m(x).
By simplifying the construction of quantum circuits and reducing the use of Toffoli gates, the physical implementation requirements of quantum computers are reduced, and the efficiency of quantum computers to realize modular computing is improved.
Smart Images

Figure CN119962696A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of quantum computing technology, and in particular relates to a polynomial modular operator, a polynomial modular operation method and related devices. Background Art
[0002] Quantum computers are physical devices that follow the laws of quantum mechanics to perform high-speed mathematical and logical operations, store and process quantum information. When a device processes and calculates quantum information and runs quantum algorithms, it is a quantum computer. Quantum computers have become a key technology under research because they have the ability to process mathematical problems more efficiently than ordinary computers. For example, they can speed up the time to crack RSA keys from hundreds of years to a few hours.
[0003] The existing implementation of the polynomial modular operation h(x)+f(x) / g(x)mod m(x) requires complex quantum gates, such as Toffoli gates, and the depth of the gates may reach exponential levels, making its implementation on actual quantum computers difficult and inefficient. Summary of the invention
[0004] The purpose of the present invention is to provide a polynomial modular operator, a polynomial modular operation method and related devices, aiming to improve the efficiency of implementing polynomial modular operations on a quantum computer.
[0005] In order to achieve the above-mentioned object, a first aspect of an embodiment of the present invention provides a polynomial modular operator, the polynomial modular operator comprising a modular inverse operation module and a modular multiplication operation module;
[0006] The modular inverse operation module is used to perform a modular inverse operation on the first polynomial g(x) based on Fermat's little theorem;
[0007] The modular multiplication operation module is used to perform a polynomial multiplication operation on the second polynomial f(x), the third polynomial h(x) and the modular inverse operation result output by the modular inverse operation module based on the Karatsuba algorithm, and perform a modular operation based on the polynomial multiplication operation result to obtain a modular operation result h(x)+f(x) / g(x)mod m(x);
[0008] Among them, the module of the polynomial module operator is a fourth polynomial m(x), the first polynomial g(x), the second polynomial f(x) and the third polynomial h(x) are all ∈F2[x], F2[x] is a polynomial ring defined on the binary field F2, and the fourth polynomial m(x) is an irreducible polynomial defined on the binary field F2.
[0009] In a possible implementation, the modular inverse operation module acts on N quantum registers to implement a modular operation on each product term of the product form of the inverse of the first polynomial g(x) based on Fermat's little theorem, and the modular operation result of each product term is stored in the first N-1 quantum registers, wherein the first quantum register is used to load the coefficients of each order term of the first polynomial g(x), and the second quantum register stores the modular inverse operation result of the first polynomial g(x), and the first quantum register and the second quantum register are respectively the first quantum register and the last quantum register in the N quantum registers.
[0010] In a possible implementation, the modular inverse operation module includes K cascaded first operator modules, and the i-th first operator module acts on the i-th, i+1-th and N-th quantum registers to calculate the modular operation result stored in the i-th quantum register and the modular multiplication operation result of the modular square operation result stored in the N-th quantum register, and loads the calculated modular multiplication operation result into the i+1-th quantum register.
[0011] In a possible implementation, the modular inverse operation module further includes a second operator module, which is used to perform a modular operation on the modular operation results of the K first operator modules stored in the first N-1 quantum registers to obtain a modular inverse operation result, and store the modular inverse operation result in the second quantum register.
[0012] In one possible implementation, the modular multiplication operation module acts on the second quantum register, the third quantum register and the fourth quantum register to implement h(x)+f(x)*g(x) -1 mod m(x), the third quantum register is used to load the coefficients of each order of the second polynomial f(x), the fourth quantum register is used to load the coefficients of each order of the third polynomial h(x), and store the calculation result of h(x)+f(x) / g(x)mod m(x) output by the modular multiplication operation module;
[0013] Among them, the degrees of f(x) and g(x) are both less than n, the degree of h(x) is less than 2n-1, the polynomial coefficients in the coefficient array are arranged in descending order of degree, and n is a positive integer; the number of quantum bits of the second quantum register, the third quantum register and the fourth quantum register are n, n and 2n-1 respectively.
[0014] In one possible implementation, if k = n / 2, f(x) = f0(x) + f1(x)x k , g(x)=g0(x)+g1(x)x k ,h(x)=h0(x)+h1(x)x k +h2(x)x2k +h3(x)x 3k , then h(x)+f(x)*g(x) -1 =h0+α0+(h2+α1+β0+β1+γ0)x k +(h2+α1+β0+β1+γ1)x 2k +(h3+β1)x 3k , where α(x)=f0(x)g0(x)=α0(x)+α1(x)x k , β(x)=f1(x)g1(x)=β0(x)+β1(x)x k , γ(x)=(f0(x)+f1(x))(g0(x)+g1(x))=γ0(x)+γ1(x)x K .
[0015] In a possible implementation, the modular multiplication operation module includes a method for calculating h(x)+f(x)*g(x) -1 The third operator module and the one for calculating h(x)+(1+x k )f(x)g(x) is a fourth operator module, which performs a polynomial multiplication operation h(x)+f(x)*g(x) by the following steps: -1 :
[0016] Calling the fourth operator module to act on the second quantum register, the third quantum register and the fourth quantum register, so that the coefficients of the terms stored in the fourth quantum register evolve into h0+α0, h1+α0+α1+β0, h2+α1+β0+β1 and h3+β1;
[0017] A CNOT gate is applied to the second quantum register and the third quantum register, and the third operator module is called to act on the kth to 3k-2th quantum bits in the second quantum register, the third quantum register and the fourth quantum register, so that the coefficients of the orders stored in the fourth quantum register evolve into h0+α0, h2+α1+β0+β1+γ0, h2+α1+β0+β1+γ1 and h3+β1.
[0018] In a possible implementation, calling the fourth operator module to act on the second quantum register, the third quantum register, and the fourth quantum register so that the coefficients of the orders stored in the fourth quantum register evolve into h0+α0, h1+α0+α1+β0, h2+α1+β0+β1, and h3+β1, includes:
[0019] Calling the fourth operator module to act on the first k quantum bits of the second quantum register, the first k quantum bits of the third quantum register, and the first 3k-1 quantum bits of the fourth quantum register, so that the coefficients of the orders stored in the fourth quantum register evolve into h0+α0, h1+α0+α1, h2+α1, and h3;
[0020] The fourth operator module is called to act on the nk quantum bits after the second quantum register, the nk quantum bits after the third quantum register, and the 2n-1+k quantum bits after the fourth quantum register, so that the coefficients of the orders stored in the fourth quantum register evolve into h0+α0, h1+α0+α1+β0, h2+α1+β0+β1, and h3+β1.
[0021] In a second aspect, an embodiment of the present invention provides a polynomial modular operation method, the method comprising:
[0022] Constructing a polynomial modular operator as claimed in any one of claims 1 to 7 based on polynomials f(x), g(x) and h(x), wherein the module in the modular operation is the polynomial m(x);
[0023] Wherein, the polynomials f(x), g(x) and h(x) are all ∈F2[x], F2[x] is a polynomial ring defined on the binary field F2, and m(x) is an irreducible polynomial defined on the binary field F2;
[0024] Running the polynomial modular operator to obtain a quantum state corresponding to a result of a polynomial modular operation h(x)+f(x) / g(x)mod m(x);
[0025] The modular operation result is determined based on the quantum state corresponding to the operation result of the polynomial modular operation h(x)+f(x) / g(x)mod m(x).
[0026] In a third aspect, an embodiment of the present invention provides a polynomial modular operation device, the device comprising:
[0027] A construction module, used to construct a polynomial modular operator as described in any one of the first aspects based on polynomials f(x), g(x) and h(x), wherein the module in the modular operation is the polynomial m(x);
[0028] Wherein, the polynomials f(x), g(x) and h(x) are all ∈F2[x], F2[x] is a polynomial ring defined on the binary field F2, and m(x) is an irreducible polynomial defined on the binary field F2;
[0029] An operation module is used to operate the polynomial modular operator to obtain a quantum state corresponding to the operation result of the polynomial modular operation h(x)+f[x) / g(x)modm(x);
[0030] A determination module is used to determine the modular operation result based on the quantum state corresponding to the operation result of the polynomial modular operation h(x)+f(x) / g(x)mod m(x).
[0031] According to a fourth aspect of an embodiment of the present invention, a storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the steps of the method described in the second aspect when running.
[0032] According to a fifth aspect of an embodiment of the present invention, there is provided an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps of the method described in the second aspect.
[0033] Based on the above technical solution, the polynomial modular operator includes a modular inverse operation module and a modular multiplication operation module; the modular inverse operation module is used to perform modular inverse operation on the first polynomial g(x) based on Fermat's little theorem; the modular multiplication operation module is used to perform polynomial multiplication operation on the second polynomial f(x), the third polynomial h(x) and the modular inverse operation result output by the modular inverse operation module based on the Karatsuba algorithm, and perform modular operation based on the polynomial multiplication operation result to obtain the modular operation result h(x)+f(x) / g(x)mod m(x); wherein the module of the polynomial modular operator is a fourth polynomial m(x), the first polynomial g(x), the second polynomial f(x) and the third polynomial h(x) are all ∈F2[x], F2[x] is a polynomial ring defined on the binary field F2, and the fourth polynomial m(x) is an irreducible polynomial defined on the binary field F2.
[0034] The present invention realizes the polynomial modular operation h(x)+f[x) / g(x)modm(x) based on a modular inverse operation module and a modular multiplication operation module, wherein the modular inverse operation module is realized based on Fermat's little theorem, and the modular multiplication operation module is realized based on the Karatsuba algorithm, which only requires a simple single quantum logic gate to be realized, simplifies the construction of quantum circuits, reduces the use of Toffoli gates, thereby reducing the physical realization requirements of quantum computers and improving the efficiency of quantum computers in realizing modular operations. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 The present invention is a hardware structure block diagram of a computer terminal showing a polynomial modular operation method according to an exemplary embodiment.
[0036] Figure 2 is a schematic diagram of a polynomial modulus operator according to an exemplary embodiment.
[0037] Figure 3 is a schematic diagram of a modular inverse operation module according to an exemplary embodiment.
[0038] Figure 4 is a schematic diagram of a quantum circuit of a fifth operator module according to an exemplary embodiment.
[0039] Figure 5 is an example diagram of a quantum circuit corresponding to an L matrix according to an exemplary embodiment.
[0040] Figure 6 The figure is a flow chart of a polynomial modular operation method according to an exemplary embodiment.
[0041] Figure 7 The figure is a block diagram of a polynomial modular operation device according to an exemplary embodiment.
[0042] Figure 8 The invention is a block diagram of a computer device according to an exemplary embodiment. DETAILED DESCRIPTION
[0043] The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, but should not be construed as limiting the present invention.
[0044] Figure 1 1 is a network block diagram of a polynomial modular operation system provided by an embodiment of the present invention. The polynomial modular operation system may include a network 110, a server 120, a wireless device 130, a client 140, a storage 150, a classical computing unit 160, a quantum computing unit 170, and may also include additional memories, classical processors, quantum processors, and other devices not shown.
[0045] Network 110 is a medium for providing communication links between various devices and computers connected together in the polynomial modular operation system, including but not limited to the Internet, corporate intranets, local area networks, mobile communication networks and their combinations. The connection method can be wired, wireless communication links or optical fiber cables, etc.
[0046] The server 120, the wireless device 130 and the client 140 are conventional data processing systems, which may contain data and applications or software tools for performing conventional computing processes. The client 140 may be a personal computer or a network computer, so the data may also be provided by the server 120. The wireless device 130 may be a smart phone, a tablet, a laptop, a smart wearable device, etc. The storage unit 150 may include a database 151, which may be configured to store data such as quantum bit parameters, quantum logic gate parameters, quantum circuits, quantum programs, etc.
[0047] The classical computing unit 160 (quantum computing unit 170) may include a classical processor 161 (quantum processor 171) for processing classical data (quantum data) and a memory 162 (memory 172) for storing classical data (quantum data). The classical data (quantum data) may be a boot file, an operating system image, and an application 163 (application 173). The application 163 (application 173) may be used to implement a quantum algorithm compiled by the polynomial modular operation method provided in an embodiment of the present invention.
[0048] Any data or information stored or generated in the classical computing unit 160 (quantum computing unit 170) can also be configured to be stored or generated in another classical (quantum) processing system in a similar manner, and any application program executed by it can also be configured to be executed in another classical (quantum) processing system in a similar manner.
[0049] It should be noted that a true quantum computer is a hybrid structure, which includes at least Figure 1 There are two major parts in it: the classical computing unit 160, which is responsible for performing classical computing and control; the quantum computing unit 170, which is responsible for running quantum programs and thus realizing quantum computing.
[0050] The classical computing unit 160 and the quantum computing unit 170 may be integrated into one device or distributed in two different devices. For example, the first device including the classical computing unit 160 runs a classical computer operating system, on which quantum application development tools and services are provided, as well as storage and network services required for quantum applications. Users develop quantum programs through the quantum application development tools and services thereon, and send quantum programs to the second device including the quantum computing unit 170 through the network services thereon. The second device runs a quantum computer operating system, and the code of the quantum program is parsed and compiled into instructions that can be recognized and executed by the quantum processor 170 through the quantum computer operating system. The quantum processor 170 implements the quantum algorithm corresponding to the quantum program according to the instructions.
[0051] The computing unit of the classic processor 161 in the classic computing unit 160 is a CMOS tube based on a silicon chip. This computing unit is not limited by time and coherence, that is, this computing unit is not limited by the length of use and can be used at any time. In addition, in the silicon chip, the number of such computing units is also sufficient. At present, the number of computing units in a classic processor 161 is tens of thousands. The number of computing units is sufficient and the computing logic that can be selected by the CMOS tube is fixed, such as: AND logic. When calculating with the help of CMOS tubes, a large number of CMOS tubes are combined with limited logic functions to achieve the calculation effect.
[0052] The basic computing unit of the quantum processor 171 in the quantum computing unit 170 is a quantum bit. The input of the quantum bit is limited by coherence and coherence time, that is, the quantum bit is limited by the duration of use and is not available at any time. Making full use of the quantum bit within the available duration of use of the quantum bit is a key problem in quantum computing. In addition, the number of quantum bits in a quantum computer is one of the representative indicators of the performance of the quantum computer. Each quantum bit realizes the computing function through the logical function configured on demand. In view of the limited number of quantum bits, the logical functions in the field of quantum computing are diverse, such as: Hadamard gate (Hadamard gate, H gate), Pauli-X gate (X gate), Pauli-Y gate (Y gate) Pauli-Z gate (Z gate), X gate, RY gate, RZ gate, CNOT gate, CR gate, iSWAP gate, Toffoli gate, etc. In quantum computing, it is necessary to use limited quantum bits combined with a variety of logical function combinations to achieve the computing effect.
[0053] Based on these differences, the design of CMOS tubes by classical logic functions and the design of quantum bits by quantum logic functions are significantly and essentially different. The design of CMOS tubes by classical logic functions does not need to consider the individuality of CMOS tubes. For example, the representation of CMOS tubes in silicon chips is the individual identification, position, and usable life of each CMOS tube. Therefore, the classical algorithm composed of classical logic functions only expresses the operational relationship of the algorithm, but does not express the algorithm's dependence on individual CMOS tubes.
[0054] When quantum logic functions act on qubits, the individuality of qubits needs to be considered, such as the individual identification of the qubit in the quantum chip, its position, its relationship with surrounding qubits, and the usable time of each qubit. Therefore, the quantum algorithm composed of quantum logic functions not only expresses the computational relationship of the algorithm, but also expresses the algorithm's dependence on individual qubits.
[0055] Exemplary:
[0056] Quantum algorithm 1: H1, H2, CNOT(1,3), H3, CNOT(2,3);
[0057] Quantum algorithm 2: H1, H2, CNOT(1,2), H3, CNOT(2,3);
[0058] Among them, 1 / 2 / 3 represent three sequentially connected quantum bits Q1, Q2, Q3 or mutually connected quantum bits Q1, Q2, Q3;
[0059] An exemplary explanation of how quantum algorithms are affected by the coherence time of qubits is as follows:
[0060] Define the execution time of a single-qubit logic gate as t, and the execution time of a two-qubit logic gate acting on adjacent bits as 2t; then:
[0061] When Q1, Q2, and Q3 are interconnected, the calculation of quantum algorithm 1 takes 6t, which is divided into 4 time periods. The duration of each time period is t, 2t, t, and 2t respectively. The operations performed in each time period are: H1, H2; CNOT(1, 3); H3; CNOT(2, 3);
[0062] The calculation of quantum algorithm 1 takes 5t, which is divided into 3 time periods. The duration of each time period is t, 2t, and 2t respectively. The operations performed in each time period are: H1, H2, H3; CNOT(1, 2); CNOT(2, 3);
[0063] When Q1, Q2, and Q3 are connected in sequence, the quantum algorithm 1 needs to be equivalent to: H1, H2; swap(1, 2), CNOT(2, 3), swap(1, 2); H3; CNOT(2, 3); the calculation of the equivalent quantum algorithm 1 requires 10t, which is divided into 4 time periods, and the duration of each time period is t, 6t, t, and 2t respectively. The operations performed in each time period are: H1, H2; swap(1, 2), CNOT(2, 3), swap(1, 2); H3; CNOT(2, 3).
[0064] Therefore, the design of the quantum logic function acting on the quantum bit (including the design of whether the quantum bit is used or not and the design of the efficiency of each quantum bit) is the key to improving the computing performance of the quantum computer, and requires special design. This is also the uniqueness of the quantum algorithm based on the quantum logic function, which is essentially and significantly different from the classical algorithm based on the classical logic function. The above-mentioned design for quantum bits is a technical problem that ordinary computing devices do not need to consider or face. The present invention proposes a polynomial modular operator, a polynomial modular operation method and related devices, aiming to improve the efficiency of implementing polynomial modular operations on quantum computers.
[0065] An embodiment of the present invention provides a polynomial modular operator, the polynomial modular operator comprising a modular inverse operation module and a modular multiplication operation module;
[0066] The modular inverse operation module is used to perform a modular inverse operation on the first polynomial g(x) based on Fermat's little theorem;
[0067] The modular multiplication operation module is used to perform a polynomial multiplication operation on the second polynomial f(x), the third polynomial h(x) and the modular inverse operation result output by the modular inverse operation module based on the Karatsuba algorithm, and perform a modular operation based on the polynomial multiplication operation result to obtain a modular operation result h(x)+f(x) / g(x)mod m(x);
[0068] Among them, the module of the polynomial module operator is a fourth polynomial m(x), the first polynomial g(x), the second polynomial f(x) and the third polynomial h(x) are all ∈F2[x], F2[x] is a polynomial ring defined on the binary field F2, and the fourth polynomial m(x) is an irreducible polynomial defined on the binary field F2.
[0069] In the embodiments of the present invention, finite fields are important basic work in cryptography, such as the Diffie-Hellman cryptographic algorithm on finite fields, the elliptic curve cryptography system on finite fields, and the application of binary field towers in block ciphers. Finite fields are generally divided into prime fields and binary extension fields in cryptographic applications. The binary extension field refers to constructing a new field by adding two elements to a given field, thereby expanding the original field. Among them, when the prime number defined in the prime field is 2, it is a binary field. If a polynomial is a polynomial on a binary field, the coefficient of each term is one of the elements on the binary field; correspondingly, when the polynomial is a polynomial on a multivariate field, the coefficient of each term of the polynomial has more values.
[0070] The binary extension domain can be expressed as Where ai = 0 or 1, i = O, 1, ..., n-1}, polynomials f(x), g(x) and h(x) are all elements on F2[x], so polynomials f(x), g(x) and h(x) can be expressed as: That is a n-1 x n-1 +a n-2 x n-2 +…+a1x+a0, coefficient of each term a m Is 1 or 0.
[0071] Let F2[x] be a polynomial ring defined over the binary field F2, whose elements are polynomials f(x)=a n x n +a n-1 x n-1 +…+a1x+a0. Further, the binary extension domain is realized by the polynomial ring Where m(x) is an irreducible polynomial on F2[x], the degree of m(x) is n (i.e., deg(m(x)=n), and ideal<m(x)> It can be regarded as the great ideal of F2[x]. Since m(x) is an irreducible polynomial, c0=c n =1. The default modulus polynomial m(x) is represented by an n-dimensional array, and the default highest bit is 1, which is convenient for unified processing and representation on quantum circuits and saves one bit. The binary expansion domain is generally represented as:
[0072] where a i =0 or 1, i=0, 1,…, n-1}.
[0073] Here you can As an n-dimensional vector space defined on F2, choose {1, x, x 2 , …, x n-1 As A basis on , which is also called a polynomial basis. Thus, The element f(x) on can be represented by a vector, that is: f(x) = a n-1 x n-1 +a n-2 x n-2 +…+a1x+a o →Vector The above elements can be represented by n-dimensional vectors and stored using a quantum register The elements in require n qubits.
[0074] like Figure 2 As shown, Figure 2 A schematic diagram of a polynomial modulus operator provided by an embodiment of the present invention, Figure 2 The polynomial modular operator shown includes a modular inverse operation module and a modular multiplication operation module, wherein the modular inverse operation module acts on a total of N quantum registers from the first quantum register to the second quantum register, the first quantum register is the first quantum register among the N quantum registers, the second quantum register is the last quantum register among the N quantum registers, the first quantum register is used to load the coefficients of each order term of the first polynomial g(x), and the second quantum register is used to load the modular inverse operation result g(x) of the first polynomial g(x) output by the modular inverse operation module -1 mod m(x).
[0075] Figure 2The polynomial modular operator shown includes a modular multiplication operation module that acts on a second quantum register, a third quantum register, and a fourth quantum register, wherein the third quantum register is used to load coefficients of each order term of the second polynomial f(x), and the fourth quantum register is used to load coefficients of each order term of the third polynomial h(x). After the modular multiplication operation module acts, the fourth quantum register is used to store the polynomial modular operation result h(x)+f(x) / g(x)mod m(x) output by the modular multiplication operation module.
[0076] The present invention realizes the polynomial modular operation h(x)+f[x) / g(x)modm(x) based on a modular inverse operation module and a modular multiplication operation module, wherein the modular inverse operation module is realized based on Fermat's little theorem, and the modular multiplication operation module is realized based on the Karatsuba algorithm, which only requires a simple single quantum logic gate to be realized, simplifies the construction of quantum circuits, reduces the use of Toffoli gates, thereby reducing the physical realization requirements of quantum computers and improving the efficiency of quantum computers in realizing modular operations.
[0077] The modular inverse operation module in the embodiment of the present invention is introduced below. The modular inverse operation module in the above embodiment is implemented based on Fermat's little theorem.
[0078] Based on Fermat's little theorem, the modular inverse operation g(x) can be -1 mod m(x) converts to modular operation Right now
[0079] Then you can Further decomposition is performed. Binary expansion is performed on n-1 to obtain the exponent k of each term in the product form s ; where ks∈[k1,…,k t ], k1 is the highest order index K.
[0080] Then according to the iteration relationship: You can This breaks down into:
[0081]
[0082] Furthermore, the polynomial modular inverse operation g(x) -1 modm(x) can be decomposed into multiple constant modular squaring operations and constant modular multiplication operations on the polynomial g(x).
[0083] The highest-order terms are multiplied by constant modular multiplication and squared by constant modular multiplication. To perform the calculation, a total of k1 modular multiplication operations are required. Since k1>k2>…>k t≥0, that is, k1 is [k1,…,k t ], so when solving the highest order term The remaining terms can be obtained while taking the result of the modular operation of The result of the modular operation, that is, the present invention calculates the highest order term The modular operation results of the remaining items can be saved while the modular operation results of the remaining items can be saved, thereby saving the remaining items The modular operation process reduces the computational complexity.
[0084] The structure of the modular inverse operation module is further introduced. In another embodiment of the present invention, the modular inverse operation module acts on N quantum registers to realize the modular operation of each product term of the product form of the inverse of the first polynomial g(x) based on Fermat's little theorem, and the modular operation result of each product term is stored in the first N-1 quantum registers.
[0085] The first quantum register is used to load the coefficients of each order of the first polynomial g(x), and the second quantum register stores the modular inverse operation result of the first polynomial g(x). The first quantum register and the second quantum register are respectively the first quantum register and the last quantum register in the N quantum registers.
[0086] In the embodiment of the present invention, the coefficients of the polynomial g(x) can form an n-dimensional vector [a n-1 , a n-2 ,…a0],a i They are respectively encoded into the quantum states of the quantum bits in the first quantum register. The first register includes n quantum bits for encoding. The encoding method can be basis encoding, angle encoding, amplitude encoding, etc., which is not specifically limited in the embodiment of the present invention.
[0087] For example, the coefficients a of the polynomial g(x) i is 1 or 0, the coefficients a of the polynomial g(x) can be converted to i If they are encoded respectively into the basis of the quantum bits in the first quantum register, then the quantum states of the encoded quantum bits are all |1> or |0>.
[0088] In another implementation of the present invention, the first polynomial g(x) may also be a polynomial over a multivariate field, when the coefficient a i When it is an element on a multivariate domain, we can first calculate the coefficient a of each term. i After normalization, the coefficients of each order term obtained by normalization are encoded into the amplitude of the quantum state through amplitude coding, which can be expressed as: cosθ|1>+sinθ|0>.
[0089] The modular inverse operation module requires n*max(k1+t-1, k1+1) quantum bits, where And satisfy the relationship And k1>k2>…>k t ≥0. In addition to the first quantum register storing the information of the first polynomial g(x), it is necessary to apply for max(k1+t-1, k1+1)-1 quantum registers, each of which includes n quantum bits. Among them, the last quantum register (the second quantum register) stores the calculation result g(x) -1 mod m(x).
[0090] The modular inverse operation module comprises K cascaded first operation submodules and a second operation submodule connected to the last first operation submodule.
[0091] The i-th first operator module acts on the i-th, i+1-th and N-th quantum registers to calculate the modular multiplication result of the modular operation result stored in the i-th quantum register and the modular square operation result stored in the N-th quantum register, and loads the calculated modular multiplication result into the i+1-th quantum register.
[0092] The second operator module is used to perform a modular operation on the modular operation results of the K first operator modules stored in the first N-1 quantum registers to obtain a modular inverse operation result, and store the modular inverse operation result in the second quantum register.
[0093] For example, the above binary extension domain In the example, n = 10, then according to Fermat's little theorem, the binary field The modular inverse operation of the first polynomial g(x) and m(x) on can be expanded as:
[0094]
[0095] That is, n-1=9. By binary expansion of n-1=9, we can get n-1=2. 3 +2 0 , that is, k1 = 3, k2 = 0, and
[0096] So further, we can get:
[0097]
[0098] By constructing a quantum circuit for this expansion, we can obtain Figure 3 The modular inverse operation module shown, Figure 3The modular inverse operation module shown acts on five quantum registers, each of which includes n quantum bits. The first quantum register is used to load the coefficients of each order of the polynomial g(x). Figure 3 The modular inverse operation module shown also includes three cascaded first operation submodules and one second operation submodule. Figure 3 Each of the first operator modules includes a first CNOT gate, a constant modular square operator, a constant modular multiplication operator M, a modular square inverse operator and a second CNOT gate connected in sequence, wherein the constant modular square operator K 1 , K 2 and K 4 The exponent indicates how many times the modular square operation is performed, and the corresponding modular square inverse operator K -1 , K -2 and K -4 The exponent indicates how many times the modular square inverse operation is performed.
[0099] Figure 3 The controlled bit of the first CNOT gate of the first first operator module in the first quantum register is the first quantum register, and the controlled bit is the fifth quantum register. The first CNOT gate loads the coefficients of each order of the first polynomial f stored in the first quantum register to the fifth quantum register. The constant modulus square operator K acts on the fifth quantum register to perform a modulus square operation. The quantum state of the fifth quantum register at this time is |g 2 >, then the constant modular multiplication operator M acts on the first, second, and fifth quantum registers, based on the quantum state |g> of the first quantum register and the quantum state |g 2 >Perform modular multiplication operation to obtain the modular multiplication result |g 3 >, stored in the second quantum register, modular square inverse operator K -1 Acting on the fifth quantum register, the quantum state of the fifth quantum register |g 2 >Perform a modular square inverse operation to obtain the quantum state of the fifth quantum register as |g>. The second CNOT gate uses the first quantum register as the control bit and the controlled bit as the fifth quantum register to set the quantum state of the fifth quantum register to zero.
[0100] The controlled bit of the first CNOT gate of the second first operator module is the second quantum register, and the controlled bit is the fifth quantum register. The first CNOT gate converts the quantum state stored in the second quantum register |g 3 >Loaded into the fifth quantum register, constant modulus square operator K 2 Perform two modular square operations on the fifth quantum register. The quantum state of the fifth quantum register is |g 12>, then the constant modular multiplication operator M acts on the second, third, and fifth quantum registers, based on the quantum state of the second quantum register |g 3 > and the fifth quantum register quantum state |g 12 >Perform modular multiplication operation to obtain the modular multiplication result |g 15 >, stored in the third quantum register, modular square inverse operator K- 2 Acting on the fifth quantum register, the quantum state of the fifth quantum register |g 12 >Perform two modular square inverse operations to obtain the quantum state of the fifth quantum register as |g 3 >, the second CNOT gate uses the second quantum register as the control bit, and the controlled bit is the fifth quantum register, setting the quantum state of the fifth quantum register to the zero state.
[0101] The controlled bit of the first CNOT gate of the third first operator module is the third quantum register, and the controlled bit is the fifth quantum register. The first CNOT gate converts the quantum state stored in the third quantum register |g 15 >Loaded into the fifth quantum register, constant modulus square operator K 4 Perform four modular square operations on the fifth quantum register. The quantum state of the fifth quantum register is |g 240 >, then the constant modular multiplication operator M acts on the third, fourth, and fifth quantum registers, based on the quantum state of the third quantum register |g 15 > and the fifth quantum register quantum state |g 240 >Perform modular multiplication operation to obtain the modular multiplication result |g 255 >, stored in the fourth quantum register, modular square inverse operator K- 4 Acting on the fifth quantum register, the quantum state of the fifth quantum register |g 240 >Perform 4 modular square inverse operations, and the quantum state of the fifth quantum register is |g 15 >, the second CNOT gate uses the third quantum register as the control bit and the controlled bit as the fifth quantum register, setting the quantum state of the fifth quantum register to zero.
[0102] In summary, the modular operation performed by the three first operator modules is for the expansion The highest order term in After performing multiple modular operations, the modular operation result of the highest order term |g is obtained. 255 >.
[0103] In another embodiment of the present invention, based on the above embodiment, the above second operator module is used to perform modular operation on the modular operation results of the K first operator modules stored in the first N-1 quantum registers to obtain a modular inverse operation result, and store the modular inverse operation result in the Nth quantum register.
[0104] It can be seen from the above embodiment that the K first operator modules perform K modular operations on the highest-order terms in the product form, and store the modular operation results output by each modular operation module during the calculation process, so the modular operation results of other terms in the product form do not need to be repeatedly calculated. The second operator module performs modular operations based on the K modular operation results stored in the first N-1 quantum registers to obtain the modular inverse operation result.
[0105] Continuing with the above example Figure 3 For example, Figure 3 The modular inverse operation module shown also includes a second operator module, which sequentially includes a constant modular square operator K acting on the fourth quantum register, a constant modular multiplication operator M acting on the first, fourth and fifth quantum registers, and a constant modular square operator K acting on the fifth quantum register. After the first three first operator modules, the quantum state of the fourth quantum register is |g 255 >.
[0106] Combination It can be seen that:
[0107] The constant modulus square operator K acting on the fourth quantum register can operate on the quantum state |g stored in the fourth quantum register. 255 >Perform modular square operation to obtain |g 510 >.
[0108] The constant modular multiplication operator M acting on the first, fourth and fifth quantum registers can perform modular multiplication based on the quantum states of the first and fourth quantum registers to obtain |g 511 >, stored in the 5th quantum register.
[0109] The constant modulus square operator K acting on the fifth quantum register can affect the quantum state of the fifth quantum register |g 511 >Perform one modular square operation to obtain |g 1022 >, thus completing the Modulo operation, the obtained |g 1022 > is the result of the modular inverse operation of the first polynomial.
[0110] It should be noted that in the above embodiment, only n=10 is used as an example to illustrate the structure of the second operator module. The second modular inverse operation includes a constant modular square operator and a constant modular multiplication operator. The specific structure of the second operator module and the quantum registers that specifically act on the constant modular square operator and the constant modular multiplication operator need to be set according to the polynomial actually performing the modular inverse operation. The structure of the second operator module constructed for different polynomials is also different. The embodiment of the present invention does not specifically limit the specific structure of the second operator module.
[0111] In addition, the constant modular square operator and the constant modular multiplication operator in the embodiment of the present invention are both constructed according to the second polynomial m(x). The specific implementation method of the constant modular square operator can refer to the Chinese patent application document with application number 202311277423.3, and the specific implementation method of the constant modular multiplication operator can refer to the Chinese patent application document with application number 202311277400.2.
[0112] The modular multiplication operation module in the embodiment of the present invention is described below. The modular multiplication operation module in the embodiment of the present invention is implemented based on the Karatsuba algorithm. The Karatsuba algorithm is a classic algorithm for solving polynomial multiplication. Its basic idea is to divide the two polynomials to be multiplied into two segments for multiplication and addition, thereby reducing the complexity of multiplication. The present invention proposes a quantum circuit implementation based on the Karatsuba algorithm for solving h+f*g -1 Specifically, the quantum circuit designed based on Karatsuba polynomial multiplication has a number of Toffoli gates that is n less than the gate depth of the general polynomial multiplication quantum circuit. 1 / 3 Here, the Karatsuba algorithm is converted into a quantum circuit, and the required quantum gate depth is reduced by n compared to the previous polynomial multiplication. 1 / 3 Moreover, building this quantum circuit only requires a simple CNOT gate.
[0113] In another embodiment of the present invention, the modular multiplication operation module included in the polynomial modular operator in the above embodiment acts on the second quantum register, the third quantum register and the fourth quantum register to implement h(x)+f(x)*g(x) -1 modm(x), the third quantum register is used to load the coefficients of each order of the second polynomial f(x), the fourth quantum register is used to load the coefficients of each order of the third polynomial h(x), and store the calculation result of h(x)+f(x) / g(x)mod m(x) output by the modular multiplication operation module;
[0114] Among them, the degrees of f(x) and g(x) are both less than n, the degree of h(x) is less than 2n-1, the polynomial coefficients in the coefficient array are arranged in descending order of degree, and n is a positive integer; the number of quantum bits of the second quantum register, the third quantum register and the fourth quantum register are n, n and 2n-1 respectively.
[0115] For polynomials f(x), g(x) -1 And h(x), if k=n / 2, according to the Karatsuba algorithm we can get:
[0116] f(x)=f0(x)+f1(x)x k ,g(x) -1 =g0(x)+g1(x)x k ,h(x)=h0(x)+h1(x)x k +h2(x)x 2k +h3(x)x 3k , then h(x)+f(x)*g(x) -1 =h0+α0+(h2+α1+β0+β1+γ0)x k +(h2+α1+β0+β1+γ1)x 2k +(h3+β1)x 3k , where α(x)=f0(x)g0(x)=α0(x)+α1(x)x K , β(x)=f1(x)g1(x)=β0(x)+β1(x)x k , γ(x)=(f0(x)+f1(x))(g0(x)+g1(x))=γ0(x)+γ1(x)x K .
[0117] In another embodiment of the present invention, the modular multiplication operation module includes a module for calculating h(x)+f(x)*g(x) -1 The third operator module and the one for calculating h(x)+(1+x k )f(x)g(x) is a fourth operator module, which performs a polynomial multiplication operation h(x)+f(x)*g(x) by the following steps: -1 :
[0118] Step 1: Call the fourth operator module to act on the second quantum register, the third quantum register and the fourth quantum register, so that the coefficients of the orders stored in the fourth quantum register evolve into h0+α0, h1+α0+α1+β0, h2+α1+β0+β1 and h3+β1.
[0119] Specifically, step 1 can be implemented as follows: calling the fourth operator module to act on the first k quantum bits of the second quantum register, the first k quantum bits of the third quantum register, and the first 3k-1 quantum bits of the fourth quantum register, so that the coefficients of the orders stored in the fourth quantum register evolve into h0+α0, h1+α0+α1, h2+α1, and h3;
[0120] The fourth operator module is called to act on the nk quantum bits after the second quantum register, the nk quantum bits after the third quantum register, and the 2n-1+k quantum bits after the fourth quantum register, so that the coefficients of the orders stored in the fourth quantum register evolve into h0+α0, h1+α0+α1+β0, h2+α1+β0+β1, and h3+β1.
[0121] According to the above embodiment, h(x)=h0(x)+h1(x)x k +h2(x)x 2k +h3(x)x 3k , it can be seen that the coefficients of the first terms of h(x) stored in the fourth quantum register are h0, h1, h2 and h3.
[0122] Step 2: Apply CNOT gates to the second quantum register and the third quantum register, and call the third operator module to act on the kth to 3k-2th quantum bits in the second quantum register, the third quantum register, and the fourth quantum register, so that the coefficients of the orders stored in the fourth quantum register evolve into h0+α0, h2+α1+β0+β1+γ0, h2+α1+β0+β1+γ1, and h3+β1.
[0123] According to the above embodiment, h(x)+f(x)*g(x) -1 =h0+α0+(h2+α1+β0+β1+γ0)x k +(h2+α1+β0+β1+γ1)x 2k +(h3+β1)x 3k , it can be seen that after the above steps 1 and 2, the coefficients of each term stored in the fourth quantum register are the polynomial multiplication operation h(x)+f(x)*g(x) -1 The coefficients of the various terms of the result can be determined according to the quantum state of the fourth register to obtain the polynomial multiplication operation h(x)+f(x)*g(x) -1 result.
[0124] In another embodiment of the present invention, the fourth modulus operator module calculates h(x)+(1+x k )f(x)g(x) steps include:
[0125] Step 1: When m>1, split to get (fg)(x)=f(x)g(x)=(fg)0(x)+(fg)1(x)x k ,h(x)=h0(x)+h1(x)x K +h2(x)x 2k ;
[0126] Step 2: Use the CNOT gate to act on the fourth quantum register, so that the coefficients of the terms stored in the fourth quantum register evolve into h0+h1+h2, h0+h1+(fg)0 and h2;
[0127] Step 3: calling the third operator module to act on the second quantum register, the third quantum register and the fourth quantum register, so that the coefficients of the terms stored in the fourth quantum register evolve into h0+h1+h2, h0+h1+(fg)0 and h2+(fg)1;
[0128] Step 4: Use a CNOT gate to act on the fourth quantum register, so that the coefficients of the orders stored in the fourth quantum register evolve into h0+(fg)0, h1+(fg)0+(fg)1 and h2+(fg)1.
[0129] Define l = max{0, 2n-1-k}, then k+2n-2=2k+l-1, and the above steps 2 to 4 can be specifically implemented as follows:
[0130] 1. Use CNOT to act on the fourth quantum register, the control bits are the 2kth to 2k+l-1th quantum bits in the fourth quantum register, and the target bits are the kth to k+l-1th quantum bits.
[0131] 2. Use the CNOT gate to act on the fourth quantum bit, the control bits are the 2kth to 2k-1th quantum bits in the fourth quantum register, and the target bits are the 0th to k-1th quantum bits.
[0132] 3. Call the third operator module to act on the kth to 2k+l-1th quantum bits in the second quantum register, the third quantum register, and the fourth quantum register.
[0133] 4. Use CNOT to act on the fourth quantum register, the control bits are the kth to 2k-1th quantum bits in the fourth quantum register, and the target bits are the 0th to k-1th quantum bits.
[0134] 5. Use CNOT to act on the fourth quantum register, the control bits are the 2kth to 2k+l-1th quantum bits in the fourth quantum register, and the target bits are the kth to k+l-1th quantum bits.
[0135] As shown in Table 1 below, Table 1 is Algorithm 1: Implement the fourth operator module h(x)+(1+x k )f(x)g(x) is the pseudocode Multxk.
[0136]
[0137] Table 1
[0138] The following table 2 shows in detail the results of each step of the algorithm 1 shown in Table 1.
[0139] Table 2. Changes of the fourth quantum register C at each step in Algorithm 1
[0140] In Algorithm 1, C is divided into three parts, with corresponding bit sizes of k, k, and l, respectively, and the corresponding H(x) = h0+h1x k +h2x 2k According to Table 1, the final result is: h0+(fg)0+(h1+(fg)0+(fg)1)x k +(h2+(fg)1)x 2k =h0+h1x k +h2x 2k +fg+fgx k =h+(1+x k )fg.
[0141] Where (fg)0 is the first k items of fg, and (fg)1 is the last nk items of fg. Thus, according to Algorithm 1, h+(1+x k )fg. When m=1, only 2 CNOT gates and 1 Toffoli gate are needed
[0142] As shown in Table 3 below, Table 3 is Algorithm 2: Implement h(x)+f(x)g(x) -1 Pseudocode for KMult.
[0143]
[0144]
[0145] Table 3
[0146] The following table 4 shows the results of each step in Table 3 in detail:
[0147]
[0148] Table 4. Changes of C at each step of Algorithm 2 in Table 3
[0149] According to the change of C in Table 4 and the splitting formula of h(x), by continuously calling Algorithm 2 and Algorithm 1, h(x)+f(x)g(x) can be calculated. -1 .
[0150] The basic principle of Algorithm 2 is that when the algorithm KMult is continuously called, the change of n is continuously reduced from n to Finally, we reach n = 1. When n = 1, we can use the Toffoli gate to achieve h(x) + f(x) g(x) -1 .
[0151] In another embodiment of the present invention, the polynomial modulo operator further includes a fifth operator module for performing modulo operations based on LPU decomposition.
[0152] Since polynomial operations on the binary extension field F2[x] / (m(x)) can be represented by vectors, and any polynomial g(x) multiplied by a fixed polynomial f(x) is equivalent to a linear transformation, that is, g(x) -1 *f(x)mod m(x) can be expressed as A*g, where A is a matrix and g is the column vector representation of g(x). A is a set of polynomial bases {1, x, x}, which is a polynomial multiplied by F2[x] / (m(x)). 2 , …x n-1}. In order to correspond to the order from top to bottom in quantum circuits, the vector representation of the polynomial is also from top to bottom, from high to low. The specific steps of generating A are as follows:
[0153] 1. Calculate f(x)*x separately n-1 mod m(x), f(x)*x n-2 mod m(x),…,f(x)*1mod m(x);
[0154] 2. The calculated results are arranged in column vectors {v n-1 , v n-2 ,…,v0} are arranged from left to right to obtain an n*n square matrix.
[0155] The modular multiplication operation is equivalent to the function written in a matrix, and this matrix is a linear transformation matrix. The matrix can be decomposed by LUP, and the decomposed L / U / P matrix can be decomposed into quantum circuits. Only CNOT gates and SWAP gates are needed to implement the fifth operator module for modular multiplication operation. The specific quantum circuit implementation is as follows Figure 4 shown.
[0156] Figure 4 For s(x)q(x)mod m(x), m(x)=x 3 +x+1, q(x) represents A polynomial in , given the polynomial s(x) = 1 + x k , k = 2, calculate (1 + x 2 )q(x)mod m(x).
[0157] Step 1: Generate the matrix Z. First, calculate (1+x 2 )mod m(x),(1+x 2 )*x mod m(x), (1+x 2 )mod m(x). They are represented as vectors [0, 1, 0], [0, 0, 1], [1, 0, 1].
[0158] Step 2: Arrange the vectors from left to right as column vectors to obtain:
[0159]
[0160] Step 3: Decompose Z into LUP and get Z = LUP:
[0161]
[0162] Step 4: Decompose L, U, and P into quantum circuits, where L / U only requires CNOT gate operations and P only requires SWAP gate operations.
[0163] By performing quantum operations corresponding to the P / U / L matrices on the quantum state, we can obtain (1+x 2 )The result of q(x)mod m(x).
[0164] The process of decomposing L, U, and P onto quantum circuits can be, for example, as follows.
[0165] Since the elements of P-type, L-type, and U-type matrices are all taken from {0, 1}, the permutation matrix P can be implemented in the quantum circuit through the SWAP gate, and the lower triangular matrix L and the upper triangular matrix U can be implemented in the quantum circuit using the CNOT gate. And for the n*n triangular matrix, the conversion to the quantum circuit uses at most n*(n-1) / 2 CNOT gates.
[0166] See also Figure 5 , Figure 5 This is an example diagram of a quantum circuit corresponding to an L matrix provided in an embodiment of the present invention.
[0167] For example, the L matrix is:
[0168]
[0169] The corresponding quantum circuit can be transformed as follows, finding all non-zero elements except the diagonal, and listing these elements in the lexicographic order of the horizontal axis first:
[0170] a 20 =a 21 =a 30 =1.
[0171] where a 20 =1 means to establish a CNOT gate with the first quantum bit and the third quantum bit, a 21 =1 means that the second qubit and the third qubit will establish a CNOT gate, and the rest of the elements are similar. aij=1 means that the i+1th qubit and the j+1th qubit will establish a CNOT gate, and the control bit is always on the top and the target bit is always on the bottom. The above L matrix is fully implemented into a quantum circuit, such as Figure 5 shown.
[0172] The role of the above L-type matrix is:
[0173]
[0174] Correspondingly, the above quantum circuit can realize the conversion between quantum states as follows:
[0175]
[0176] Therefore, the quantum circuit above is consistent with the left multiplication of the L-type matrix.
[0177] Similarly, the U-type matrix can also be decomposed into the above quantum circuits. The difference from the L-type decomposition process is that the control bit is always at the bottom and the target bit is always at the top during the U-type decomposition into CNOT gates. In addition, the decomposition of the permutation matrix P is, for example, for non-zero a ij , which is equivalent to establishing a SWAP gate between the i+1th quantum bit and the j+1th quantum bit. By sequentially splicing the quantum circuits corresponding to the P matrix, the U matrix, and the L matrix, the decomposition of L, U, and P onto the quantum circuit can be realized.
[0178] Based on the algorithm in the above embodiment, it is used to calculate h(x)+f(x)g(x) -1 Modular multiplication quantum circuit of mod m(x) (labeled as ModMult). f(x), g(x) -1 The coefficient arrays of h(x) are stored in the third quantum register A, the second quantum register B, and the fourth quantum register C of n quantum bits respectively.
[0179] As shown in Table 5, Table 5 is Algorithm 3: pseudo code ModMult for implementing h(x)+f(x)g(x)mod m(x).
[0180]
[0181]
[0182] Table 5
[0183] Table 6 shows the results of each step in Algorithm 3 in detail. The correctness of the algorithm can be verified based on the results of each step in Algorithm 3.
[0184]
[0185] Table 6. Changes of C at each step in Algorithm 3
[0186] After finishing the last step of Algorithm 3, we can know that: (1+x k )*(α+((h / x k +γ)*(1+x k ) -1 +β)*x k )mod m=h+(1+x k )α+γx k +βx k (1+x k )mod m=h+f*g -1 mod m.
[0187] like Figure 6 As shown, Figure 6 A flowchart of a polynomial modular operation method provided by an embodiment of the present invention, the method comprising:
[0188] S601, constructing a polynomial modular operator as described in the above embodiment based on polynomials f(x), g(x) and h(x), where the module in the modular operation is the polynomial m(x);
[0189] Among them, the construction method of the polynomial modulus operator can refer to the relevant description in the above embodiment, which will not be repeated here.
[0190] Wherein, the polynomials f(x), g(x) and h(x) are all ∈F2[x], F2[x] is a polynomial ring defined on the binary field F2, and m(x) is an irreducible polynomial defined on the binary field F2;
[0191] S602, running the polynomial modular operator to obtain a quantum state corresponding to a result of a polynomial modular operation h(x)+f(x) / g(x)mod m(x);
[0192] S603. Determine a result of the modular operation based on the quantum state corresponding to the result of the polynomial modular operation h(x)+f(x) / g(x)mod m(x).
[0193] Based on the same inventive concept, the embodiment of the present invention also provides a polynomial modular operation device, such as Figure 7 As shown, the device comprises:
[0194] A construction module 701 is used to construct a polynomial modular operator as described in the above embodiment based on polynomials f(x), g(x) and h(x), where the module in the modular operation is the polynomial m(x);
[0195] Wherein, the polynomials f(x), g(x) and h(x) are all ∈F2[x], F2[x] is a polynomial ring defined on the binary field F2, and m(x) is an irreducible polynomial defined on the binary field F2;
[0196] An operation module 702 is used to operate the polynomial modular operator to obtain a quantum state corresponding to the result of the polynomial modular operation h(x)+f(x) / g(x)mod m(x);
[0197] The determination module 703 is used to determine the modular operation result based on the quantum state corresponding to the operation result of the polynomial modular operation h(x)+f(x) / g(x)mod m(x).
[0198] Regarding the specific functions and effects achieved by the polynomial modular operation device, reference can be made to other embodiments of this specification for comparative explanation, and no further description is given here. Each module in the polynomial modular operation device can be implemented in whole or in part by software, hardware, and a combination thereof. Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0199] See also Figure 8 The present specification also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the polynomial module operation method in any of the above embodiments when executing the computer program. Figure 8 , the computer device may be a classical computer. The computer device may also be a quantum computer.
[0200] The embodiments of this specification also provide a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a computer, the computer executes the polynomial modular operation method in any of the above embodiments.
[0201] The embodiments of this specification also provide a computer program product including instructions, which, when executed by a computer, enables the computer to perform the polynomial modular operation method in any of the above embodiments.
[0202] It should be understood that the specific examples in this specification are only intended to help those skilled in the art to better understand the implementation methods of this specification, rather than to limit the scope of the present invention.
[0203] It can be understood that in the various implementations of this specification, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the implementation methods of this specification.
[0204] It can be understood that the various embodiments described in this specification can be implemented individually or in combination, and the embodiments of this specification are not limited to this.
[0205] Unless otherwise specified, all technical and scientific terms used in the embodiments of this specification have the same meaning as those generally understood by those skilled in the art of the technical field of this specification. The terms used in this specification are only for the purpose of describing specific embodiments and are not intended to limit the scope of this specification. The term "and / or" used in this specification includes any and all combinations of one or more related listed items. The singular forms of "a", "above", and "the" used in the embodiments of this specification and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.
[0206] It can be understood that the processor of the embodiment of this specification can be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method implementation can be completed by the hardware integrated logic circuit or software instructions in the processor. The above processor can be a general processor, a digital signal processor (Digital Signal Processor, DSP), an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The disclosed methods, steps and logic block diagrams in the embodiment of this specification can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiment of this specification can be directly embodied as a hardware decoding processor to perform, or the hardware and software modules in the decoding processor are combined and executed. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
[0207] It is understood that the memory in the embodiments of this specification may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (programmable ROM, PROM), an erasable programmable read-only memory (erasablePROM, EPROM), an electrically erasable programmable read-only memory (EEPROM) or a flash memory. The volatile memory may be a random access memory (RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0208] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this specification.
[0209] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method implementation methods and will not be repeated here.
[0210] In the several embodiments provided in this specification, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device implementation described above is only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0211] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0212] In addition, each functional unit in each embodiment of the present specification may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0213] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this specification, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of this specification. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc., various media that can store program codes.
[0214] The above is only a specific implementation of this specification, but the protection scope of the present invention is not limited thereto. Any person skilled in the art who is familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in this specification, which should be included in the protection scope of this specification. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.
Claims
1. A polynomial modulo operator, characterized in that: The polynomial modular operator comprises a modular inverse operation module and a modular multiplication operation module; The modular inverse operation module is used to perform a modular inverse operation on the first polynomial g(x) based on Fermat's little theorem; The modular multiplication operation module is used to perform a polynomial multiplication operation on the second polynomial f(x), the third polynomial h(x) and the modular inverse operation result output by the modular inverse operation module based on the Karatsuba algorithm, and perform a modular operation based on the polynomial multiplication operation result to obtain a modular operation result h(x)+f(x) / g(x)mod m(x); Among them, the module of the polynomial module operator is a fourth polynomial m(x), the first polynomial g(x), the second polynomial f(x) and the third polynomial h(x) are all ∈F2[x], F2[x] is a polynomial ring defined on the binary field F2, and the fourth polynomial m(x) is an irreducible polynomial defined on the binary field F2.
2. The polynomial modulo operator according to claim 1, characterized in that: The modular inverse operation module acts on N quantum registers to realize modular operation on each product term of the product form of the inverse of the first polynomial g(x) based on Fermat's little theorem, and the modular operation result of each product term is stored in the first N-1 quantum registers, wherein the first quantum register is used to load the coefficients of each order term of the first polynomial g(x), and the second quantum register stores the modular inverse operation result of the first polynomial g(x), and the first quantum register and the second quantum register are respectively the first quantum register and the last quantum register in the N quantum registers.
3. The polynomial modulo operator according to claim 2, characterized in that: The modular inverse operation module includes K cascaded first operator modules, and the i-th first operator module acts on the i-th, i+1-th and N-th quantum registers to calculate the modular operation result stored in the i-th quantum register and the modular multiplication operation result of the modular square operation result stored in the N-th quantum register, and loads the calculated modular multiplication operation result into the i+1-th quantum register.
4. The polynomial modulo operator according to claim 3, characterized in that: The modular inverse operation module also includes a second operator module, which is used to perform modular operation on the modular operation results of the K first operator modules stored in the first N-1 quantum registers to obtain a modular inverse operation result, and store the modular inverse operation result in the second quantum register.
5. The polynomial modulo operator according to any one of claims 2 to 4, characterized in that: The modular multiplication operation module acts on the second quantum register, the third quantum register and the fourth quantum register to realize h(x)+f(x)*g(x) - 1 mod m(x), the third quantum register is used to load the coefficients of each order of the second polynomial f(x), the fourth quantum register is used to load the coefficients of each order of the third polynomial h(x), and store the calculation result of h(x)+f(x) / g(x)mod m(x) output by the modular multiplication operation module; Among them, the degrees of f(x) and g(x) are both less than n, the degree of h(x) is less than 2n-1, the polynomial coefficients in the coefficient array are arranged in descending order of degree, and n is a positive integer; the number of quantum bits of the second quantum register, the third quantum register and the fourth quantum register are n, n and 2n-1 respectively.
6. The polynomial modulo operator according to claim 5, characterized in that: If \(k = n / 2\), \(f(x)=f_0(x)+f_1(x)x\) k , \(g(x)=g_0(x)+g_1(x)x\) k , \(h(x)=h_0(x)+h_1(x)x\) k +h_2(x)x 2k +h_3(x)x 3k , then \(h(x)+f(x)\cdot g(x)\) -1 =h_0 + \alpha_0+(h_2+\alpha_1+\beta_0+\beta_1+\gamma_0)x k +(h_2+\alpha_1+\beta_0+\beta_1+\gamma_1)x 2k +(h_3+\beta_1)x 3k , where \(\alpha(x)=f_0(x)g_0(x)=\alpha_0(x)+\alpha_1(x)x\) k , \(\beta(x)=f_1(x)g_1(x)=\beta_0(x)+\beta_1(x)x\) k , \(\gamma(x)=(f_0(x)+f_1(x))(g_0(x)+g_1(x))=\gamma_0(x)+\gamma_1(x)x\) k .
7. The polynomial modulo operator according to claim 6, characterized in that: The modular multiplication operation module includes a module for calculating h(x)+f(x)*g(x) -1 The third operator module and the one for calculating h(x)+(1+x k )f(x)g(x) is a fourth operator module, which performs a polynomial multiplication operation h(x)+f(x)*g(x) by the following steps: -1 : Calling the fourth operator module to act on the second quantum register, the third quantum register and the fourth quantum register, so that the coefficients of the terms stored in the fourth quantum register evolve into h0+α0, h1+α0+α1+β0, h2+α1+β0+β1 and h3+β1; A CNOT gate is applied to the second quantum register and the third quantum register, and the third operator module is called to act on the kth to 3k-2th quantum bits in the second quantum register, the third quantum register and the fourth quantum register, so that the coefficients of the orders stored in the fourth quantum register evolve into h0+α0, h2+α1+β0+β1+γ0, h2+α1+β0+β1+γ1 and h3+β1.
8. The polynomial modulo operator according to claim 7, characterized in that: The calling of the fourth operator module acts on the second quantum register, the third quantum register, and the fourth quantum register so that the coefficients of the respective orders stored in the fourth quantum register evolve into h0+α0, h1+α0+α1+β0, h2+α1+β0+β1, and h3+β1, including: Calling the fourth operator module to act on the first k quantum bits of the second quantum register, the first k quantum bits of the third quantum register, and the first 3k-1 quantum bits of the fourth quantum register, so that the coefficients of the orders stored in the fourth quantum register evolve into h0+α0, h1+α0+α1, h2+α1, and h3; The fourth operator module is called to act on the nk quantum bits after the second quantum register, the nk quantum bits after the third quantum register, and the 2n-1+k quantum bits after the fourth quantum register, so that the coefficients of the orders stored in the fourth quantum register evolve into h0+α0, h1+α0+α1+β0, h2+α1+β0+β1, and h3+β1.
9. A polynomial modular operation method, characterized in that: The method comprises: Constructing a polynomial modular operator as claimed in any one of claims 1 to 8 based on polynomials f(x), g(x) and h(x), wherein the module in the modular operation is the polynomial m(x); Wherein, the polynomials f(x), g(x) and h(x) are all ∈F2[x], F2[x] is a polynomial ring defined on the binary field F2, and m(x) is an irreducible polynomial defined on the binary field F2; Running the polynomial modular operator to obtain a quantum state corresponding to a result of a polynomial modular operation h(x)+f(x) / g(x)mod m(x); The modular operation result is determined based on the quantum state corresponding to the operation result of the polynomial modular operation h(x)+f(x) / g(x)mod m(x).
10. A polynomial modular operation device, characterized in that: The device comprises: A construction module, used to construct a polynomial modular operator as described in any one of claims 1 to 8 based on polynomials f(x), g(x) and h(x), wherein the module in the modular operation is the polynomial m(x); Wherein, the polynomials f(x), g(x) and h(x) are all ∈F2[x], F2[x] is a polynomial ring defined on the binary field F2, and m(x) is an irreducible polynomial defined on the binary field F2; An operation module, used for operating the polynomial modular operator to obtain a quantum state corresponding to the operation result of the polynomial modular operation h(x)+f(x) / g(x)mod m(x); A determination module is used to determine the modular operation result based on the quantum state corresponding to the operation result of the polynomial modular operation h(x)+f(x) / g(x)mod m(x).
11. A storage medium, characterized in that: The storage medium stores a computer program, wherein the computer program is configured to execute the method according to claim 9 when executed.
12. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method of claim 9.
Citation Information
Patent Citations
Polynomial modular multiplication arithmetic unit, arithmetic method and related device
CN117196052A
Polynomial modular square arithmetic unit, arithmetic method and related device
CN117196053A