A reversible logic-based aes quantum circuit area optimization method and system

By using an AES quantum circuit optimization method based on reversible logic, the problems of long design cycles and local optima in existing technologies are solved. This method achieves efficient collaborative optimization of quantum circuits, reduces area and depth, and supports the practical application of AES quantum encryption oracles in security evaluation scenarios.

CN122334534APending Publication Date: 2026-07-03代余俊
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202610386357.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-27
Publication Date
2026-07-03

AI Technical Summary

Technical Problem

Existing technologies for optimizing AES quantum circuits have long design cycles and are prone to getting trapped in local optima. They also struggle to achieve an overall balance between peak qubit size, gate depth, and auxiliary bit lifetime, which limits the practical deployment of AES quantum encryption oracles in security evaluation scenarios.

Method used

A reversible logic-based AES quantum circuit optimization method is adopted. Through quantum resource budget mapping, reversible reconfiguration compression, Grover verification feedback and circuit output, a closed-loop calibration is formed. The performance vector is collected in real time and differential operation is performed to achieve the coordinated optimization of qubit peak value, gate depth and auxiliary bit lifetime.

Benefits of technology

It significantly reduces the area and depth of quantum circuits, enabling efficient operation within the current upper limit of quantum chip resources, shortening the design cycle, and avoiding the redundancy and local optima problems of traditional methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122334534A_ABST
    Figure CN122334534A_ABST
Patent Text Reader

Abstract

This invention discloses an AES quantum circuit area optimization method and system based on reversible logic, relating to the field of quantum circuit area optimization technology. The method includes quantum resource budget mapping, reversible reconstruction compression, normalized reversible folding based on the budget vector, outputting a gate-level description vector, and simultaneously writing back the actual consumed auxiliary bits to S1 to form a closed-loop calibration; Grover verification feedback recompression, real-time acquisition of performance vectors; circuit output, completing area-depth collaborative optimization; by mapping the full-round function of the advanced cryptographic algorithm to a dual-graph structure composed of qubits and quantum gates, and dividing the overall node set into several local subgraphs according to the coupling topology of the target chip, the peak value of qubits, the quota of auxiliary bits, and the number of cross-layer edges are simultaneously included in the weight model during the resource budget stage, ensuring that subsequent circuits are within the area-constrained envelope from the starting point, avoiding the repeated dismantling caused by traditional pre-construction and post-compression, thereby significantly reducing the redundancy of the initial layout.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum circuit area optimization technology, specifically to an AES quantum circuit area optimization method and system based on reversible logic. Background Technology

[0002] In quantum computing models, any classical function must first be transformed into a reversible circuit before it can run on quantum hardware. As a typical example of block ciphers, AES's byte substitution, column confusion, and key scheduling modules all involve nonlinear and matrix multiplication operations. If the classical implementation is directly copied, it will introduce a large number of irreversible gates, causing the number of auxiliary qubits and circuit depth to expand dramatically, thus exceeding the physical resource limits of current quantum chips.

[0003] Chinese invention patent CN121308953A discloses a quantum circuit system and encryption method based on the AES cryptosystem. It optimizes the timing scheduling and resource allocation of each module by adopting a compact Z-shaped architecture. While maintaining a similar amount of qubit resource usage as the original Z-shaped architecture, it significantly reduces the quantum circuit depth, enabling higher fidelity and shorter execution time on NISQ devices.

[0004] However, existing solutions generally adopt a two-stage process of "construction first, optimization later": first, reversible synthesis is completed at the abstraction layer, and then the over-limit part is locally shallowed or bit reused in the back-end stage. Due to the lack of a resource budget mechanism tightly coupled with the physical topology in the early stage, the optimization process often requires multiple round trips and iterations, which not only prolongs the design cycle, but also easily gets trapped in local optima. It is difficult to simultaneously take into account the overall balance of qubit peak value, gate depth and auxiliary bit lifetime, thus limiting the practical deployment of AES quantum encryption oracle in security evaluation scenarios such as Grover search. Summary of the Invention

[0005] The purpose of this invention is to provide an AES quantum circuit area optimization method and system based on reversible logic, so as to solve the problems in the prior art that not only prolong the design cycle, but also easily get trapped in local optima, and it is difficult to simultaneously take into account the overall balance of qubit peak value, gate depth and auxiliary bit lifetime.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a method and system for optimizing the area of ​​an AES quantum circuit based on reversible logic, comprising the following steps:

[0007] S1. Quantum resource budget mapping: Collect the invertible and irreversible node sets of the AES-128 full round function and the target chip coupling topology, generate an initial budget table with clean auxiliary bit quota, and output the budget vector.

[0008] S2. Reversible reconstructive compression: Based on the budget vector, normalize and reversibly fold the S-box, column obfuscation, and key scheduling to output the gate-level description vector, and synchronously write back the actual number of auxiliary bits consumed to S1 to form a closed-loop calibration.

[0009] S3, Grover verification feedback is further compressed, and the AES quantum encryption oracle assembled from the gate-level description vector is embedded into Grover iteration. The performance vector B3 is collected in real time and differential operation is performed with the data in the budget vector.

[0010] S4, line output, completes area-depth collaborative optimization.

[0011] Furthermore, step S1 specifically includes the following steps:

[0012] S11. Collect the set of invertible and irreversible nodes of the AES-128 full-round function, decompose and construct the qubit-gate bigraph G(V,E).

[0013] Where V represents the set of qubit nodes and E represents the set of edges corresponding to the quantum gate;

[0014] S12. Based on the target chip coupling topology T, divide V into k local embedding subgraphs {G1, ... G...} k}, and allocate a clean auxiliary bit quota A to each subgraph. i This forms the initial budget table, namely:

[0015] ;

[0016] Where T represents the coupling topology of the target quantum chip, Subgraph G i The number of nodes, E cut (G) i T) represents subgraph G i The number of cross-layer edges between the topology T and the topology, where α and β are adjustable weighting coefficients with values ​​ranging from [value range missing]. A i To assign to subgraph G i Clean auxiliary bit quota;

[0017] And output the budget vector B1={Aᵢ,|V(Gᵢ)|,E_cut(Gᵢ,T)}.

[0018] Furthermore, step S2 specifically includes the following steps:

[0019] S21. Perform a joint affine-inverse decomposition on the byte substitution box, and output the Tofoli depth ≤ d. s Sub-line L s That is, the byte replacement box reversible sub-circuit;

[0020] First, the algebraic expression S(x) = A·x of the AES S-box is... -1 ⊕c in GF(2) 8 Establish a composite domain GF((2) on the GF((2) 4 ) 2 Isomorphism δ, GF(2) 8 ) represents a finite field with 256 elements, GF(2 4 ) represents a finite field with 16 elements, and so on;

[0021] Transforming the inverse problem into a reversible quantum circuit:

[0022] ;

[0023] Where r0 and r1 are the low and high 4 bits of the composite field;

[0024] ;

[0025] Where den is the denominator and λ is the constant element of the composite field;

[0026] Invden← Composite domain invertible network (Toffoli count ≤ 62, depth ≤ 10).

[0027] ;

[0028] ;

[0029] Where y0 and y1 are inverse components;

[0030] ;

[0031] Where x is an 8-bit input element of the AES byte substitution box, corresponding to an element in a finite field;

[0032] S22, the column confusion matrix in GF(2) 8 GF(2) on ) 4 Tower domain folding yields reusable constant-aided sub-line L m That is, a column confusion matrix invertible sub-circuit, wherein the column confusion matrix is,

[0033]

[0034] In this process, the 4*4 matrix-vector multiplication is broken down into four tower field multiplications and additions. Each multiplication and addition uses a Karatsuba invertible template, and the constant auxiliary bits reuse the same 4-qubit register.

[0035] After folding L mThe Tofoli count is ≤96, and the depth is ≤d. m d m For L m The upper limit of Tofoli depth.

[0036] Furthermore, step S2 further includes the following steps:

[0037] S23. Perform round key sharing Ancilla folding on the key scheduling round function to generate sub-circuit L. k In this process, the round key generation circuit is split into an S-box multiplexing unit and a round constant XOR unit, sharing the L of S21. s Only increase the XOR depth of the wheel constant by ≤2;

[0038] After folding L k The depth of the Toffoli is ≤ d k d k For L k The upper limit of Toffoli depth;

[0039] The overall output gate-level description vector B2={L in step S2 is... s ,L m L k d s d m d k}, and simultaneously write back the actual number of auxiliary bits consumed ΔA to S12 to form a closed-loop calibration;

[0040] Wherein, ΔA is the actual clean auxiliary bit increment consumed in step S2, that is, the number of ancillas used more or less than the theoretical budget in this reversible folding, which is used to write back the quota of calibration S12 to form a closed loop.

[0041] Furthermore, step S3 specifically includes the following steps:

[0042] S31. Assemble the sub-circuit obtained in step S2 into an AES quantum encryption oracle. It also embeds the standard Grover iteration framework;

[0043] S32. After each round of Grover search, sample the current peak Q of the qubit. peak Toffoli Depth T depth and auxiliary bit survival period L life Write to the verification register;

[0044] S33, Check gate triplet (Q peak T depth L life ) and the budget table {A} of step S12i Perform a difference operation; if any index exceeds the tolerance θ, that is:

[0045] ;

[0046] This triggers a rollback signal;

[0047] Among them, Q peak T represents the peak value of the qubits measured by Grover's iteration. depth To measure the Toffoli depth, L life To assist in the lifespan of bits; d is the sum of the clean auxiliary bit quotas for all subgraphs. s The Toffoli depth reference given in step S21; L0 is the preset auxiliary bit lifetime reference, and θ is the user-given tolerance threshold, the value range of which is θ∈(1,2].

[0048] S34. The rewind signal is sent back to step S12 to split the subgraph granularity in half again and redistribute the quota to obtain the updated budget table Aᵢ′, and drive steps S21-S23 to fold the gate sequence again according to the new quota until Δ≤θ.

[0049] Furthermore, step S4 specifically includes the following steps:

[0050] S41. When the difference is satisfied for two consecutive rounds, Δ≤θ, the final oracle is locked. Its number of qubits And the Tofoli depth ≤ d s +d m +d k ,

[0051] Where, d m d k These are the depth references output in steps S22 and S23, respectively;

[0052] S42, Output The list of quantum gates and the physical bit layout file are used for subsequent quantum chip compilation;

[0053] in, This represents the complete AES quantum encryption oracle circuit that is finally locked after S3 rollback convergence.

[0054] Furthermore, in each rollback iteration of step S34, the subgraph splitting depth level and the corresponding Δ value are recorded synchronously, and a (level, Δ) lookup table is established;

[0055] When the AES key length or chip topology is fine-tuned in the future, the table is queried first. If there is a level′ such that Δ′≤θ, the corresponding Aᵢ′ is loaded directly and the complete S21-S23 folding is skipped to achieve fast reconfiguration.

[0056] Furthermore, the rollback iteration in step S34 is completed by a hardware accelerator, which only transmits the rollback instruction R and the updated Aᵢ′. The hardware executes the topology repartitioning in step S12, the gate-level refolding in steps S21-S23, and the differential verification in S33 in parallel in a pipeline manner. The total time for a single rollback cycle is ≤1ms, realizing online real-time reconfiguration of AES quantum circuit area optimization.

[0057] An AES quantum circuit area optimization system based on reversible logic includes,

[0058] The quantum resource budget module is used to execute S11-S12 and output the budget vector B1;

[0059] The reversible reconfigurable compression module is used to execute S21-S23 and output the gate-level description vector B2;

[0060] The Grover verification feedback module is used to execute S31-S34 and output the rollback command and performance vector B3.

[0061] The line output module is used to execute S41-S42 and solidify the final oracle. The file.

[0062] Compared with existing technologies, this invention maps the full round function of advanced cryptographic algorithms into a dual-graph structure composed of qubits and quantum gates, and divides the overall node set into several local subgraphs according to the coupling topology of the target chip. During the resource budgeting stage, the peak value of qubits, the quota of auxiliary bits, and the number of cross-layer edges are simultaneously included in the weight model, so that the subsequent lines are within the area-limited envelope from the starting point, avoiding the repeated dismantling of lines caused by the traditional first-build-then-press method, thereby significantly reducing the redundancy of the initial layout.

[0063] Based on this, the byte substitution box, column obfuscation and key scheduling are jointly reversibly decomposed, the tower domain multiply-accumulate folding and the round key sharing auxiliary bit multiplexing are performed to compress the originally scattered high-depth modules into a verifiable Tooffoli depth upper limit. Then, by using iterative search to sample the peak value of qubits, gate depth and auxiliary bit life cycle in real time, a differential signal that directly communicates with the budget table is formed. Once the limit is exceeded, the rollback instruction immediately drives the topology granularity to be split in half again, the quota to be redistributed and the gate level to be folded again, realizing a two-layer progressive optimization of compression verification and recompression, so that the area and depth converge synchronously without manual intervention. Attached Figure Description

[0064] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0065] Figure 1 This is a schematic diagram of the overall process of the optimization method provided in the embodiments of the present invention;

[0066] Figure 2 A detailed flowchart illustrating the optimization method provided in this embodiment of the invention. Detailed Implementation

[0067] To enable those skilled in the art to better understand the technical solution of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings.

[0068] As attached Figure 1 To be continued Figure 2 As shown:

[0069] To avoid ambiguity, the specific symbols used in this article have the following meanings:

[0070] ΔA: refers to the difference between the actual number of clean auxiliary bits consumed and the budget quota in the reversible reconfiguration compression step (A stands for Ancilla).

[0071] Δ: Specifically refers to the value calculated using the formula in the Grover validation feedback step.

[0072] ;

[0073] The defined performance over-limit ratio is a scalar function value.

[0074] Example 1:

[0075] This invention provides an AES quantum circuit area optimization method and system based on reversible logic, comprising the following steps:

[0076] S1. Quantum resource budget mapping: Collect the invertible and irreversible node sets of the AES-128 full round function and the target chip coupling topology, generate an initial budget table with clean auxiliary bit quota, and output the budget vector.

[0077] S2, reversible reconstructive compression, based on the budget vector, normalizes and reversibly folds the S-box, column confusion, and key scheduling, outputs the gate-level description vector, and synchronously writes back the actual number of auxiliary bits consumed to S1 to form a closed-loop calibration.

[0078] S3 and Grover verification feedback are further compressed, and the AES quantum encryption oracle assembled from the gate-level description vector is embedded into the Grover iteration. The performance vector B3 is collected in real time and differential operation is performed with the data in the budget vector.

[0079] S4, line output, completes area-depth collaborative optimization.

[0080] It should be noted that step S1 specifically includes the following steps:

[0081] S11. Collect the set of invertible and irreversible nodes of the AES-128 full-round function, decompose and construct the qubit-gate bigraph G(V,E).

[0082] Where V represents the set of qubit nodes and E represents the set of edges corresponding to the quantum gate;

[0083] S12. Based on the target chip coupling topology T, divide V into k local embedding subgraphs {G1, ... G...} k}, and allocate a clean auxiliary bit quota A to each subgraph. i This forms the initial budget table, namely:

[0084] ;

[0085] Where T represents the coupling topology of the target quantum chip, Subgraph G i The number of nodes, E cut (G) i T) represents subgraph G i The number of cross-layer edges between the topology T and the topology, where α and β are adjustable weighting coefficients with values ​​ranging from [value range missing]. A i To assign to subgraph G i Clean auxiliary bit quota;

[0086] And output the budget vector B1={Aᵢ,|V(Gᵢ)|,E_cut(Gᵢ,T)}.

[0087] In practice, the system is first built using a superconducting chip with a hundred-qubit scale. Its coupling surface is grid-like, with limited inter-layer channels at the edges. The host connects to a programmable logic accelerator card via a high-speed interface. Next, quantum resource budgeting is performed. The compiler first expands the entire AES computation into a basic list of quantum gates, drawing a bi-graph of qubits and gates. Based on the chip's coupling surface shape, the entire graph is divided into dozens of local blocks. Each block is allocated clean auxiliary quotas according to the number of nodes and inter-layer edges, forming an initial budget table, which is written to the accelerator card register as a "hard upper limit" that cannot be exceeded later. Within the accelerator card, the byte substitution part first undergoes a joint "affine-inversion" decomposition: the inversion is performed in a smaller composite domain, and then the affine linear layer is incorporated to synthesize a depth-controlled sub-circuit. The column obfuscation part uses a tower domain multiply-add template, with four multiply-add operations sharing a set of constant auxiliary bits, thus shallowing the circuit depth. Key scheduling reuses the newly generated byte substitution core, requiring only a round constant XOR operation. After the three modules are folded, a gate-level description vector is obtained. Simultaneously, the actual number of auxiliary bits used (over- or under-used) is written back to the budget module, completing the first closed-loop calibration. Then, Grover verification and rollback are performed: the folded circuits are assembled into a complete AES quantum encryption oracle, embedding standard Grover iterations. After each round of diffusion encryption, the current qubit peak value, gate depth, and auxiliary bit lifespan are immediately sampled and compared with the budget table using a difference comparison. If the difference exceeds the tolerance, the accelerator card immediately breaks down the local subgraph into smaller pieces, reallocates the quota, and triggers gate-level folding again until the difference falls within the allowable range. The entire process is completed in milliseconds without host intervention. Finally, the circuit is output. If the difference is below the tolerance for two consecutive rounds, the system locks the final oracle circuit, generates a standard quantum gate list and physical layout file, and directly sends it to the chip compilation environment. Verification has shown that this circuit can run Grover search completely on the target chip, with both area and depth significantly lower than the traditional fabrication-then-pressing process, achieving the collaborative optimization goals proposed in claims 1 and 2; by using budget-first and Grover online verification to simultaneously press area and depth into the chip envelope, a low-resource AES quantum oracle capable of running throughout the entire lifecycle has been completed on a real 128-qubit processor.

[0088] Example 2:

[0089] This embodiment is basically the same as the previous embodiment, except that step S2 specifically includes the following steps:

[0090] S21. Perform a joint affine-inverse decomposition on the byte substitution box, and output the Tofoli depth ≤ d. s Sub-line L s That is, the byte replacement box reversible sub-circuit;

[0091] First, the algebraic expression S(x) = A·x of the AES S-box is... -1 ⊕c in GF(2) 8 Establish a composite domain GF((2) on the GF((2) 4 ) 2 Isomorphism δ, GF(2) 8 ) represents a finite field with 256 elements, GF(2 4 ) represents a finite field with 16 elements, and so on;

[0092] Transforming the inverse problem into a reversible quantum circuit:

[0093] ;

[0094] Where r0 and r1 are the low and high 4 bits of the composite field;

[0095] ;

[0096] Where den is the denominator and λ is the constant element of the composite field;

[0097] Invden← Composite domain invertible network (Toffoli count ≤ 62, depth ≤ 10).

[0098] ;

[0099] ;

[0100] Where y0 and y1 are inverse components;

[0101] ;

[0102] Where x is an 8-bit input element of the AES byte substitution box, corresponding to an element in a finite field;

[0103] S22, the column confusion matrix in GF(2) 8 GF(2) on ) 4 Tower domain folding yields reusable constant-aided sub-line L m That is, a sub-circuit with a column confusion matrix, where the column confusion matrix is...

[0104]

[0105] In this process, the 4*4 matrix-vector multiplication is broken down into four tower field multiplications and additions. Each multiplication and addition uses a Karatsuba invertible template, and the constant auxiliary bits reuse the same 4-qubit register.

[0106] After folding L m The Tofoli count is ≤96, and the depth is ≤d. m dm For L m The upper limit of Tofoli depth.

[0107] Step S2 further includes the following steps:

[0108] S23. Perform round key sharing Ancilla folding on the key scheduling round function to generate sub-circuit L. k In this circuit, the round key generation circuit is split into an S-box multiplexing unit and a round constant XOR unit, sharing S21 in L. s Only increase the XOR depth of the wheel constant by ≤2;

[0109] After folding L k The depth of the Toffoli is ≤ d k d k For L k The upper limit of Toffoli depth;

[0110] Step S2: Output the overall gate-level description vector B2={L s ,L m L k d s d m d k}, and simultaneously write back the actual number of auxiliary bits consumed ΔA to S12 to form a closed-loop calibration;

[0111] Where ΔA is the actual clean auxiliary bit increment consumed in step S2, that is, the number of ancillas used more or less than the theoretical budget in this reversible folding, which is used to write back the quota of calibration S12 to form a closed loop.

[0112] Working Principle: This example uses the same superconducting mesh chip as the previous example, but focuses on verifying the differentiated optimization effect brought by "adjustable weights." The host computer provides two coefficient knobs, α and β, for users to adjust in real-time based on the current congestion level of the cross-layer edges. In the initial round, α is set to a high value and β to a low value. The system uses this weight ratio to allocate nodes based on the number of nodes, quickly obtaining a "node priority" budget table. Then, S21-S23 folding is performed to obtain the first version of the circuit. During S33 differential verification, it is found that the actual congestion level of the cross-layer edges is too high, and the differential result slightly exceeds the tolerance. The user then adjusts α down and β up, and the weight ratio immediately changes to "cross-layer edge priority." After receiving the new weights, the accelerator card only needs to rerun S12 topology partitioning to generate a second "edge penalty priority" budget table. Without needing to fold the entire table again, the differential falls within the allowable range. This process directly demonstrates the real-time guiding effect of the "adjustable positive weight coefficients" on the budget table.

[0113] Differential operations continue to use the "maximum of three indicators" approach. Whenever the maximum indicator exceeds θ, the rewind signal is pulled high. In this example, the user gradually tightens θ from the lenient range, and the system accordingly increases the number of rewinds, causing the line depth and bit peak value to decrease synchronously until the most stringent tolerance is met. Experiments show that the continuous adjustability of θ indeed provides an intuitive handle for controlling the "optimization intensity," aligning with the threshold design intent.

[0114] After two rounds of joint adjustment of weight thresholds, the subgraph granularity is naturally split into finer pieces, and the budget quota is redistributed accordingly, driving S21-S23 into a deeper level of door folding. This "budget-folding-verification-rebudgeting" cycle clearly shows two progressive layers: the first layer is only coarsely divided according to the initial weights, and the second layer is subdivided after the edge penalty is increased. Both the area and depth are further reduced, and the convergence speed is not significantly reduced, which intuitively reflects the two progressive optimization effect.

[0115] By rotating α, β, and θ in real time, users can freely switch between "fast coarse optimization" and "fine deep optimization" without modifying the hardware pipeline or rewriting the underlying gate templates, thus verifying the operability and effectiveness of the proposed weight threshold coordination mechanism on actual chips.

[0116] Example 3:

[0117] This embodiment is basically the same as the previous embodiment, except that step S3 specifically includes the following steps:

[0118] S31. Assemble the sub-circuit obtained in step S2 into an AES quantum encryption oracle. It also embeds the standard Grover iteration framework;

[0119] S32. After each round of Grover search, sample the current peak Q of the qubit. peak Toffoli Depth T depth and auxiliary bit survival period L life Write to the verification register;

[0120] S33, Check gate triplet (Q peak T depth L life ) and the budget table {A} of step S12 i Perform a difference operation; if any index exceeds the tolerance θ, that is:

[0121] ;

[0122] This triggers a rollback signal;

[0123] Among them, Q peak T represents the peak value of the qubits measured by Grover's iteration. depthTo measure the Toffoli depth, L life To assist in the lifespan of bits; d is the sum of the clean auxiliary bit quotas for all subgraphs. s The Toffoli depth reference given in step S21; L0 is the preset auxiliary bit lifetime reference, and θ is the user-given tolerance threshold, the value range of which is θ∈(1,2].

[0124] S34. The rewind signal is sent back to step S12 to split the subgraph granularity in half again and redistribute the quota to obtain the updated budget table Aᵢ′, and drive steps S21-S23 to fold the gate sequence again according to the new quota until Δ≤θ.

[0125] Step S3 specifically includes the following steps:

[0126] S41. When the difference is satisfied for two consecutive rounds, Δ≤θ, the final oracle is locked. Its number of qubits And the Tofoli depth ≤ d s +d m +d k ,

[0127] Where, d m d k These are the depth references output in steps S22 and S23, respectively;

[0128] S42, Output The list of quantum gates and the physical bit layout file are used for subsequent quantum chip compilation;

[0129] in, This represents the complete AES quantum encryption oracle circuit that is finally locked after S3 rollback convergence.

[0130] In each rollback iteration of step S34, the subgraph splitting depth level and the corresponding Δ value are recorded synchronously, and a (level, Δ) lookup table is established.

[0131] When the AES key length or chip topology is fine-tuned in the future, the table is queried first. If there is a level′ such that Δ′≤θ, then the Aᵢ′ corresponding to level′ is loaded directly and the complete S21-S23 folding is skipped to achieve fast reconfiguration.

[0132] The rollback iteration in step S34 is completed by a hardware accelerator, which only transmits the rollback instruction R and the updated Aᵢ′. The hardware executes the topology repartitioning in step S12, the gate-level refolding in steps S21-S23, and the differential verification in S33 in parallel in a pipeline manner. The total time for a single rollback cycle is ≤1ms, realizing online real-time reconfiguration of AES quantum circuit area optimization.

[0133] The experimental platform still uses the same superconducting mesh chip as the previous example, but a high-speed lookup table is added to the host to record the pairing relationship between the subgraph splitting depth and the corresponding differential result in each rollback iteration. After the first round of optimization, the table has accumulated dozens of valid records. At this time, the operator manually changes the cross-layer edge capacity of the chip—simulating the topology fine-tuning commonly seen in real deployments. The system immediately starts the reconfiguration process: first, it queries the lookup table. If it finds that a certain splitting depth can meet the new differential tolerance, it directly loads the budget quota corresponding to that depth, skips the complete S21 to S23 folding, and completes the budget update and gate mapping in a very short time. Then it enters the S33 verification stage. The differential result quickly falls into the allowable range, and the reconfiguration is declared complete.

[0134] When the lookup table fails to reach the ideal depth, the system automatically switches to a hardware-accelerated rollback channel: the rollback command and the updated quota are written to the acceleration card in one go, and the pipeline within the card performs topology repartitioning, gate-level refolding, and differential verification in parallel. The entire loop ends within milliseconds, with virtually no latency perceptible to the user. Experimental results show that regardless of slight increases or decreases in key length or temporary tightening of chip edge capacity, the system can reconverge within two iterations, maintaining the area and depth metrics at their original optimized levels. This verifies the effectiveness and real-time performance of the proposed "fast reconfiguration" and "hardware-accelerated rollback" in practical applications.

[0135] In step S3, one branch is the pure "budget-folding" main line, i.e., S1→S2, and the other is the "Grover iteration + performance sampling" verification line. The two are carried out in parallel in the same space-time and cross in real time through differential signals, rather than completing the folding first and then verifying it separately. This is specifically reflected in the following:

[0136] S31 first assembles the gate-level description vector that was just folded out by S2 into an AES quantum encryption oracleO, and embeds it into the standard Grover iteration framework to form a "second branch". At this time, the folding process does not terminate, but remains in a reentrant state, waiting for feedback from Grover sampling.

[0137] S32 collects the performance vector in real time after each Grover search and differs it online with the main line budget table. If Δ>θ, it immediately generates a rollback signal R. This signal is the "hard handshake" between the two lines. The verification line directly intervenes in the folding line instead of waiting for all searches to end before making unified corrections.

[0138] S34 sends the rollback signal in reverse to S12, re-divides the topology and updates the quota, driving S21-S23 to fold again; at this time, Grover iteration continues, but the next diffusion will use the updated oracle version, thus forming a parallel loop of "searching and modifying simultaneously, searching and modifying synchronously" until the two-line indicators converge simultaneously to lock the final O.* .

[0139] The foregoing has only described certain exemplary embodiments of the present invention by way of illustration. Undoubtedly, those skilled in the art can modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the foregoing drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.

Claims

1. A method for optimizing the area of ​​an AES quantum circuit based on reversible logic, characterized in that, Includes the following steps: S1. Quantum resource budget mapping: Collect the invertible and irreversible node sets of the AES-128 full round function and the target chip coupling topology, generate an initial budget table with clean auxiliary bit quota, and output the budget vector. S2. Reversible reconstructive compression: Based on the budget vector, normalize and reversibly fold the S-box, column obfuscation, and key scheduling to output the gate-level description vector, and synchronously write back the actual number of auxiliary bits consumed to S1 to form a closed-loop calibration. S3, Grover verification feedback is further compressed, and the AES quantum encryption oracle assembled from the gate-level description vector is embedded into Grover iteration. The performance vector B3 is collected in real time and differential operation is performed with the data in the budget vector. S4, line output, completes area-depth collaborative optimization.

2. The method for optimizing the area of ​​an AES quantum circuit based on reversible logic according to claim 1, characterized in that, Step S1 specifically includes the following steps: S11. Collect the set of invertible and irreversible nodes of the AES-128 full-round function, decompose and construct the qubit-gate bigraph G(V,E). Where V represents the set of qubit nodes and E represents the set of edges corresponding to the quantum gate; S12. Based on the target chip coupling topology T, divide V into k local embedding subgraphs {G1, ... G...} k }, and allocate a clean auxiliary bit quota A to each subgraph. i This forms the initial budget table, namely: ; Where T represents the coupling topology of the target quantum chip, Subgraph G i The number of nodes, E cut (G) i T) represents subgraph G i The number of cross-layer edges between the topology T and the topology, where α and β are adjustable weighting coefficients with values ​​ranging from [value range missing]. A i To assign to subgraph G i Clean auxiliary bit quota; And output the budget vector B1={Aᵢ,|V(Gᵢ)|,E_cut(Gᵢ,T)}.

3. The AES quantum circuit area optimization method based on reversible logic according to claim 1, characterized in that, Step S2 specifically includes the following steps: S21. Perform a joint affine-inverse decomposition on the byte substitution box, and output the Tofoli depth ≤ d. s Sub-line L s That is, the byte replacement box reversible sub-circuit; First, the algebraic expression S(x) = A·x of the AES S-box is... -1 ⊕c in GF(2) 8 Establish a composite domain GF((2) on the GF((2) 4 ) 2 Isomorphism δ, GF(2) 8 ) represents a finite field with 256 elements, GF(2 4 ) represents a finite field with 16 elements, and so on; Transforming the inverse problem into a reversible quantum circuit: ; Where r0 and r1 are the low and high 4 bits of the composite field; ; Where den is the denominator and λ is the constant element of the composite field; Invden← Composite domain invertible network (Toffoli count ≤ 62, depth ≤ 10). ; ; Where y0 and y1 are inverse components; ; Where x is an 8-bit input element of the AES byte substitution box, corresponding to an element in a finite field; S22, the column confusion matrix in GF(2) 8 GF(2) on ) 4 Tower domain folding yields reusable constant-aided sub-line L m That is, a column confusion matrix invertible sub-circuit, wherein the column confusion matrix is, In this process, the 4*4 matrix-vector multiplication is broken down into four tower field multiplications and additions. Each multiplication and addition uses a Karatsuba invertible template, and the constant auxiliary bits reuse the same 4-qubit register. After folding L m The Tofoli count is ≤96, and the depth is ≤d. m d m For L m The upper limit of Tofoli depth.

4. The AES quantum circuit area optimization method based on reversible logic according to claim 3, characterized in that, Step S2 further includes the following steps: S23. Perform round key sharing Ancilla folding on the key scheduling round function to generate sub-circuit L. k In this process, the round key generation circuit is split into an S-box multiplexing unit and a round constant XOR unit, sharing the L of S21. s Only increase the XOR depth of the wheel constant by ≤2; After folding L k The depth of the Toffoli is ≤ d k d k For L k The upper limit of Toffoli depth; The overall output gate-level description vector B2={L in step S2 is... s ,L m L k d s d m d k }, and simultaneously write back the actual number of auxiliary bits consumed ΔA to S12 to form a closed-loop calibration; Wherein, ΔA is the actual clean auxiliary bit increment consumed in step S2, that is, the number of ancillas used more or less than the theoretical budget in this reversible folding, which is used to write back the quota of calibration S12 to form a closed loop.

5. The method for optimizing the area of ​​an AES quantum circuit based on reversible logic according to claim 1, characterized in that, Step S3 specifically includes the following steps: S31. Assemble the sub-circuit obtained in step S2 into an AES quantum encryption oracle. It also embeds the standard Grover iteration framework; S32. After each round of Grover search, sample the current peak Q of the qubit. peak Toffoli Depth T depth and auxiliary bit survival period L life Write to the verification register; S33, Check gate triplet (Q peak T depth L life ) and the budget table {A} of step S12 i Perform a difference operation; if any index exceeds the tolerance θ, that is: ; This triggers a rollback signal; Among them, Q peak T represents the peak value of the qubits measured by Grover's iteration. depth To measure the Toffoli depth, L life To assist in the lifespan of bits; d is the sum of the clean auxiliary bit quotas for all subgraphs. s The Toffoli depth reference given in step S21; L0 is the preset auxiliary bit lifetime reference, and θ is the user-given tolerance threshold, the value range of which is θ∈(1,2]. S34. The rewind signal is sent back to step S12 to split the subgraph granularity in half again and redistribute the quota to obtain the updated budget table Aᵢ′, and drive steps S21-S23 to fold the gate sequence again according to the new quota until Δ≤θ.

6. The method for optimizing the area of ​​an AES quantum circuit based on reversible logic according to claim 5, characterized in that, Step S4 specifically includes the following steps: S41. When the difference operation satisfies Δ≤θ for two consecutive rounds, the final oracle is locked. Its number of qubits And the Tofoli depth ≤ d s +d m +d k , Where, d m d k These are the depth references output in steps S22 and S23, respectively; S42, Output The list of quantum gates and the physical bit layout file are used for subsequent quantum chip compilation; in, This represents the complete AES quantum encryption oracle circuit that is finally locked after S3 rollback convergence.

7. The method for optimizing the area of ​​an AES quantum circuit based on reversible logic according to claim 6, characterized in that, In each rollback iteration of step S34, the subgraph splitting depth level and the corresponding Δ value are recorded synchronously, and a (level, Δ) lookup table is established. When the AES key length or chip topology is fine-tuned in the future, the table is queried first. If there is a level′ such that Δ′≤θ, the corresponding Aᵢ′ is loaded directly and the complete S21-S23 folding is skipped to achieve fast reconfiguration.

8. The AES quantum circuit area optimization method based on reversible logic according to claim 7, characterized in that, The rollback iteration in step S34 is completed by a hardware accelerator, which only transmits the rollback instruction R and the updated Aᵢ′. The hardware executes the topology repartitioning in step S12, the gate-level refolding in steps S21-S23, and the differential verification in S33 in parallel in a pipeline manner. The total time for a single rollback cycle is ≤1ms, realizing online real-time reconfiguration of AES quantum circuit area optimization.

9. An AES quantum circuit area optimization system based on reversible logic, characterized in that, include, The quantum resource budget module is used to execute S11-S12 and output the budget vector B1; The reversible reconfigurable compression module is used to execute S21-S23 and output the gate-level description vector B2; The Grover verification feedback module is used to execute S31-S34 and output the rollback command and performance vector B3. The line output module is used to execute S41-S42 and solidify the final oracle. The file.

Citation Information

Patent Citations

  • Quantum circuit system based on AES cryptosystem and encryption method

    CN121308953A