Information processing program, information processing method, and information processing system

By optimizing the number of control qubits and operation times in quantum circuits, the execution time for prime factorization is reduced, addressing the inefficiencies in conventional Shor algorithms.

JP2025161499APending Publication Date: 2025-10-24FUJITSU LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024064732
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-12
Publication Date
2025-10-24

AI Technical Summary

Technical Problem

Conventional Shor algorithms for quantum computers require a large number of control qubits, leading to increased circuit depth and prolonged execution time for prime factorization operations, with little consideration given to reducing circuit depth through intermediate values.

Method used

Determine the number of control quantum bits based on the relationship between modular exponentiation calculation and measurement-classical conditional operation times, and generate a quantum circuit that optimizes these processes to minimize execution time.

Benefits of technology

Reduces the execution time of prime factorization operations by optimizing the quantum circuit configuration to balance the number of control qubits and operation times, thereby decreasing circuit depth.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025161499000001_ABST
    Figure 2025161499000001_ABST
Patent Text Reader

Abstract

To provide an information processing program, information processing method, and information processing system that shorten the execution time of prime factorization operations.SOLUTION: A computer is made to execute the following processes for: determining the number of control qubits based on the relationship between the first computation time required for each of the multiple power residue calculation processes in a prime factorization operation and the second computation time needed for each of the numerous measurement and classical conditional operations included in the inverse quantum Fourier transform process for the results of the numerous power residue calculation processes in the prime factorization operation; based on the determined number of control qubits, determining a circuit pattern for performing the prime factorization calculation by executing the multiple power residue calculation processes and the inverse quantum Fourier transform process; generating a quantum circuit for performing the prime factorization calculation based on the determined circuit pattern; and performing the prime factorization calculation using the quantum circuit.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing program, an information processing method, and an information processing system. [Background technology]

[0002] Data encryption is an effective technical approach to ensure the security of data distribution. There are various data encryption methods, but encryption that takes advantage of the difficulty of prime factorization is widely used. The Shor algorithm, which uses a quantum computer, is a fast quantum algorithm for solving prime factorization.

[0003] The Shor algorithm uses a quantum circuit, a quantum algorithm that performs quantum computation using quantum bits to prime factorize a target integer. A quantum bit is an information unit in quantum computation. In the following, the quantum circuit that realizes the Shor algorithm will be simply referred to as a "quantum circuit". A quantum circuit is composed of wires and quantum gates. A quantum gate is an arithmetic element that performs operations to rewrite the state of quantum bits. A quantum circuit consists of a part that performs modular exponentiation computation and a part that performs the inverse quantum Fourier transform (QFT). -1 It is roughly divided into a part that performs the Inverse Quantum Fourier Transform (Inverse Quantum Fourier Transform) and a part that performs the Inverse Quantum Fourier Transform (Inverse Quantum Fourier Transform).

[0004] Quantum circuits perform operations using inputs of qubits that represent the number of targets for prime factorization and control qubits that control the prime factorization, so a large number of qubits are used for the operation. For example, if the number of targets is L bits, there will be 2L+1 control qubits. Therefore, a technology has been proposed that reduces the number of control qubits used to one by using measurement and classical conditional operations in the inverse quantum Fourier transform operation. This inverse quantum Fourier transform using measurement and classical conditional operations is called semi-classical QFT. -1 This semiclassical QFT -1 The method of calculating the Shor algorithm using this is called the 1-controlling qubit trick.

[0005] Here, for quantum circuits, the number of operations that can be executed simultaneously in parallel is called the "circuit depth." The deeper the circuit depth, the longer it takes to execute prime factorization, so the circuit depth is closely related to execution time. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] International Publication No. 2022 / 249963 Summary of the Invention [Problem to be solved by the invention]

[0007] However, the number of controlling qubits used in conventional Shor algorithms is a maximum of 2L+1 or a minimum of 1, and there has been little consideration of using intermediate values ​​to reduce the circuit depth. In this regard, the time required for each unit, which is a collection of quantum gates that perform modular exponentiation calculations, as well as measurements and classical conditional operations, varies depending on the architecture. Therefore, if there are excess qubits overall, it may be possible to reduce the circuit depth by not using the 1 controlling qubit trick. However, it has been difficult to reduce the execution time of prime factorization operations with conventional quantum circuits.

[0008] The disclosed technology has been made in view of the above, and aims to provide an information processing program, an information processing method, and an information processing system that reduce the execution time of prime factorization operations. [Means for solving the problem]

[0009] In one aspect of the information processing program, information processing method, and information processing system disclosed in the present application, the number of control quantum bits is determined based on the relationship between a first calculation time required for each of a plurality of modular exponentiation calculation processes in a prime factorization calculation, and a second calculation time required for each of a plurality of measurement-classical conditional operations included in an inverse quantum Fourier transform process on the results of the plurality of modular exponentiation calculation processes in the prime factorization calculation, and a circuit pattern for performing the plurality of modular exponentiation calculation processes and the inverse quantum Fourier transform process to calculate the prime factorization is determined based on the determined number of control quantum bits, a quantum circuit that performs the prime factorization calculation is generated using the determined circuit pattern, and a computer is caused to execute a process of performing the prime factorization calculation using the quantum circuit. [Effects of the Invention]

[0010] In one aspect, the present invention can reduce the execution time of a prime factorization operation. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is a block diagram of an information processing system that performs prime factorization using the Shor algorithm. [Figure 2] FIG. 2 is a diagram showing a quantum circuit of the Shor algorithm before reducing the quantization bits. [Figure 3] FIG. 3 is a diagram of an example of a quantum circuit using the 1-controlling qubit trick. [Figure 4] FIG. 4 is a diagram showing the first circuit pattern. [Figure 5] FIG. 5 shows an example of a quantum circuit that uses semiclassical QFT-1 when the time required for a modular exponentiation unit is less than the time required for measurement-classical conditional operations. [Figure 6] FIG. 6 is a diagram showing the circuit configuration of the t-th half-classical QFT-1. [Figure 7] FIG. 7 is a diagram showing a second circuit pattern. [Figure 8]FIG. 8 is a flowchart of a process for generating a quantum circuit by a classical computer according to the embodiment. [Figure 9] FIG. 9 is a diagram showing the hardware configuration of a classical computer. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, an information processing program, an information processing method, and an information processing system disclosed in the present application will be described in detail with reference to the accompanying drawings. Note that the information processing program, the information processing method, and the information processing system disclosed in the present application are not limited to the following embodiments. [Example]

[0013] 1 is a block diagram of an information processing system that performs prime factorization using the Shor algorithm. The information processing system 1 includes a classical computer 10 and a quantum computer 20. The classical computer 10 is connected to the quantum computer 20.

[0014] The classical computer 10 generates a circuit pattern of a quantum circuit that performs prime factorization using the Shor algorithm. Then, the classical computer 10 transmits the generated circuit pattern to the quantum computer 20 to generate a quantum circuit.

[0015] Here, we will explain about quantum bits. The state of one quantum bit is expressed as a two-dimensional complex vector. To clarify that it is a quantum bit, we use the ket vector notation "|〉". For example, a quantum bit is expressed by the following mathematical formula (1). In the following, n quantum bits will be called n quantum bits. Also, multiple quantum bits will be called multiple quantum bits. Also, for example, if all of the L-bit quantum bits are 0, then |0,...,0〉=|0 L 〉.

[0016]

number

[0017] In particular, the pair of one quantum bit shown in the following formula (2) is called the canonical basis. For the state |ψ〉 of one quantum bit, there exist complex coefficients α and β, which can be expressed as |ψ〉 = α|0〉 + β|1〉.

[0018]

number

[0019] The state of multiple qubits can be expressed as the tensor product of the states of one qubit. For example, the state of multiple qubits can be expressed as the following equation (3).

[0020]

number

[0021] Next, we will explain quantum gates. There are the following types of quantum gates. An X gate is a quantum gate that operates on X, as shown in formula (4). When |0> is input to an X gate, |1> is output. Also, when |1> is input to an X gate, |0> is output.

[0022]

number

[0023] The CX gate is a quantum gate that operates on the CX shown in the following formula (5). The CX gate operates on the state of two quantum bits. The CX gate is a gate that executes a NOT gate on the second quantum bit when the first quantum bit is 1.

[0024]

number

[0025] The Hadamard gate is a quantum gate that operates on H, as shown in formula (6). When |0〉 is input, the Hadamard gate operates on (1 / 2 1 / 2 )|0〉+(1 / 21 / 2 )|1〉. This output is also expressed as |+〉. Also, when |1〉 is input, the Hadamard gate outputs (1 / 2 1 / 2 )|0〉-(1 / 2 1 / 2 )|1〉.

[0026]

number

[0027] Next, we will explain measurement. In quantum computing, the calculation result is obtained by an operation called measurement. As a result of the measurement, one of the basis sets of the quantum bit is probabilistically obtained, and the state of that quantum bit becomes that basis. For example, (1 / 3 1 / 2 )|0〉+(2 1 / 2 / 3 1 / 2 )|1〉, upon measurement, there is a 1 / 3 probability that a 0 will be obtained and the quantum bit will become |0〉, and there is a 2 / 3 probability that a 1 will be obtained and the quantum bit will become |1〉.

[0028] Furthermore, the operation that determines the quantum gate to be activated based on the measurement result is called a classical conditional operation. For example, if the measurement result is 1, the X gate is activated, and if the measurement result is 0, the X gate is not activated and the data is passed through.

[0029] Next, the Shor algorithm will be described. Fig. 2 is a diagram showing a quantum circuit of the Shor algorithm before the quantization bits are reduced. This quantum circuit of the Shor algorithm before the quantization bits are reduced is called a "basic quantum circuit." The basic quantum circuit has a modular exponentiation calculation unit 121 and an inverse quantum Fourier transform unit 122 shown in Fig. 2.

[0030] Quantum gate 101, with "H" written in a square frame, is a Hadamard gate. Quantum gate 102, with "Rj (j=2, 2L, 2L+1)" written in a square frame, is a rotation gate. The rotation gate is expressed by the matrix shown in the following formula (7).

[0031]

number

[0032] Also, quantum gate 103 is an example of a controlled rotary gate. In Figure 2, the calculation proceeds to the right as you face the page. Each flow of calculation is called a system, and controlled rotary gates, like quantum gate 103, receive input from other systems. The quantum bit input from other systems corresponds to the first quantum bit in the controlled rotary gate, and the quantum bit input from one's own system corresponds to the second quantum bit in the controlled rotary gate. Also, there is a "U" in the square frame. i Unit 104, which contains (i=g^(2^0),g^(2^1),···,g^(2^2L)) (where "^" indicates modular exponentiation), is an arithmetic circuit that performs modular exponentiation calculations and includes multiple quantum gates. Unit 105 is a circuit that measures the input calculation results to confirm the calculation results and then stores the confirmed calculation results.

[0033] The basic quantum circuit has a modular exponentiation calculation unit 121 and an inverse quantum Fourier transform unit 122. The basic quantum circuit receives as input L qubits 131 representing an L-digit target number to be prime factorized, and a control qubit group 132 including 2L+1 control qubits 111 for controlling the operation. L qubits 131 are qubits 112. The quantum states of control qubits 111 and qubits 112 are held in respective registers.

[0034] The modular exponentiation calculation unit 121 performs modular exponentiation calculation by applying each unit 104 that has input the control quantum bit 111 to the input quantum bit 112. Ui applied by the unit 104 is a quantum circuit that multiplies by g^(2^k) and modN the multiplication result.

[0035] Here, we will explain modular exponentiation. Specifically, modular exponentiation is performed as follows: w 〉 is set to 1 by the X gate acting on the lowest digit, and becomes |0,···,0,1〉. Next, for |0,···,0,1〉, the control bit x for U^(2^(ν-1)) isν-1 If is 1, it acts on the input, and |g^(x ν-1 2^(ν-1))modN〉. A superposition of all modular exponentiation calculations is created to produce the result shown in the following equation (8).

[0036]

number

[0037] Inverse quantum Fourier transform unit 122 performs an inverse quantum Fourier transform by applying quantum gate 101, which is a Hadamard gate, and quantum gate 103, which is a control rotation gate, to each control quantum bit 111.

[0038] In the inverse quantum Fourier transform, the phase can be extracted. For example, the quantum states in each system of the inverse quantum Fourier transform unit 122 are expressed as |0〉+e 2πi0.jν |1〉,|0〉+e 2πi0.jν-1jν |1〉,···,|0〉+e 2πi0.j2···jν-1jν |1〉,|0〉+e 2πi0.j1j2···jν-1jν Then, the quantum state of the top system is |0〉+e 2πi0.jν Applying the Hadamard gate to |1〉 gives |jν〉. Also, |0〉+e 2πi0.jν-1jν Applying R2 to |1〉 gives |0〉 + e 2πi0.jν-1 |1〉, and when a Hadamard gate is applied, it becomes |jν-1〉. In this way, the inverse quantum Fourier transform eliminates the lower digits one by one. As a result, the respective outputs become |jν〉, |jν-1〉, ,|j2〉, |j1〉.

[0039] Thereafter, in the basic quantum circuit, the unit 105 performs measurements on each output to determine the calculation result, and the determined calculation result is stored in the unit 105.

[0040] Here, the final process of factorization using modular exponentiation and inverse quantum Fourier transform will be explained. The case where the superposition of all modular exponentiations is shown in the following equation (9) will be explained.

[0041]

number

[0042] By substituting the following formula (10) into formula (9), formula (11) is obtained.

[0043]

number

number

[0044] By performing an inverse quantum Fourier transform on this equation (11), we obtain equation (12).

[0045]

number

[0046] In equation (12), |s / q〉 is a ν-bit approximation of a multiple of 1 / q. In this way, a multiple of 1 / q can be obtained from the phase.

[0047] ν-bit approximation of a multiple of 1 / q (s / q) ~ Then, by performing continued fraction expansion as shown in the following equation (13) and searching for q that satisfies gq=1modN, gcd(gq / 2±1,N) can be obtained as the solution to prime factorization.

[0048]

number

[0049] Next, a quantum circuit using the 1-controlling qubit trick will be described. FIG. 3 is a diagram of an example of a quantum circuit using the 1-controlling qubit trick. In a quantum circuit using the 1-controlling qubit trick, a quantum circuit 110 that performs measurement and classical conditional operations is sandwiched between the inputs to each unit 104 of the system that calculates the control qubit 111. Between the first unit 104 and the next unit 104, a quantum circuit 110a in which a Hadamard gate, a classical conditional operation, and a Hadamard gate are arranged in this order is placed. Furthermore, from the next unit 104 onwards, a quantum circuit R' is placed between the units 104. j A quantum gate 106 that operates on (j=2, 3, . . . , 2L), a Hadamard gate, a classical conditional operation, and a quantum circuit 110b that is arranged in this order are arranged. j is expressed by the following equation (14).

[0050]

number

[0051] Furthermore, after the last unit 104, R' 2L The quantum circuit 110c is arranged in which a quantum gate that operates on the quantum state, a Hadamard gate, and a measurement unit are arranged in this order. The inverse quantum Fourier transform shown in FIG. 3 is -1 is.

[0052] The time required for each modular exponentiation calculation unit U104 and the time required for measurement and classical conditional calculations vary depending on the architecture. If there are excess quantum bits overall, it may be possible to reduce the circuit depth by not using the 1 controlling qubit trick. Therefore, the classical computer 10 according to this embodiment determines the configuration of the quantum circuit as follows:

[0053] The following describes the process of generating a circuit pattern for a quantum circuit by a classical computer 10, with reference to Fig. 1. As shown in Fig. 1, the classical computer 10 includes an information acquisition unit 11, a circuit pattern selection unit 12, a first circuit pattern generation unit 13, and a second circuit pattern generation unit 14.

[0054] The information acquiring unit 11 receives input of information on the algorithm used for the modular exponentiation calculation and the algorithm used for the inverse quantum Fourier transform. For example, the information acquiring unit 11 acquires information on the algorithm used for the modular exponentiation calculation and the algorithm used for the inverse quantum Fourier transform input by an operator using an input device (not shown).

[0055] Next, the information acquiring unit 11 acquires the time required for each of the units 104 used in the modular exponentiation calculation according to the algorithm used for the modular exponentiation calculation. The information acquiring unit 11 also acquires the time required for each of the measurement and classically conditional operations shown in the quantum circuit 110 according to the algorithm used for the inverse quantum Fourier transform. Thereafter, the information acquiring unit 11 outputs the time required for each of the units 104 and the time required for each of the measurement and classically conditional operations to the circuit pattern selecting unit 12.

[0056] Here, the time required for each operation by unit 104 and the time required for each measurement and classical conditional operation can be calculated as follows. The circuit depth of the modular exponentiation calculation can be estimated using previous research (see, for example, J. Yamaguchi et al., 2023). In addition, since the time required for each gate varies depending on the quantum computer 20 used, the time required for each quantum gate can be actually measured and then estimated using the above previous research.

[0057] Furthermore, the time required for each of the measurement and classically conditional operations also differs depending on the quantum computer 20. Therefore, the time required for each of the measurement and classically conditional operations can be calculated by performing a measurement on the quantum computer 20 and using the measurement result to actually measure the time required to perform the gate operation.

[0058] The time required for each calculation by unit 104 and the time required for each measurement / classical conditional calculation may be calculated by the operator and input to information acquisition unit 11, or may be calculated by information acquisition unit 11.

[0059] The circuit pattern selection unit 12 receives input of the time required for each calculation by the unit 104 and the time required for each measurement- and classically-conditioned calculation. Next, the circuit pattern selection unit 12 determines whether the shortest time required for each calculation by the unit 104 is equal to or greater than the longest time required for each measurement- and classically-conditioned calculation. Hereinafter, the time required for each calculation by the unit 104 will be simply referred to as the "modular exponentiation calculation time," and the time required for each measurement- and classically-conditioned calculation will be simply referred to as the "measurement- and classically-conditioned calculation time." This modular exponentiation calculation time is an example of a "first calculation time required for each of the multiple modular exponentiation calculations included in the modular exponentiation calculation process in the prime factorization calculation." Furthermore, the measurement- and classically-conditioned calculation time is an example of a "second calculation time required for each of the multiple measurement- and classically-conditioned calculations included in the inverse quantum Fourier transform process for the modular exponentiation result in the prime factorization calculation."

[0060] If the modular exponentiation calculation time is equal to or greater than the measurement-classical-conditional operation time, the circuit pattern selection unit 12 determines the number of control qubits to be 2. Hereinafter, the number of control qubits to be used will be represented as k.

[0061] Figure 4 is a diagram showing the first circuit pattern. In considering the operation time, the dominant times in a quantum circuit are the modular exponentiation calculation time and the measurement- and classical-conditional operation time, so in Figure 4, the quantum circuit is displayed using each of these times. In Figure 4, U represents the modular exponentiation calculation time, and M represents the measurement- and classical-conditional operation time.

[0062] If the modular exponentiation calculation time is equal to or longer than the measurement-classical-conditional operation time, the time can be minimized if all but the last measurement-classical-conditional operation is completed before the modular exponentiation calculations by all units 104 are completed, as in the first circuit pattern shown in Figure 4. Here, if the modular exponentiation calculation time is equal to or longer than the measurement-classical-conditional operation time, the time required will be the same regardless of the value of k, the number of control qubits, as long as it is 2 or greater. Since fewer control qubits are better, it is preferable to set k = 2. Therefore, the circuit pattern selection unit 12 sets the number of control qubits k = 2. This is an example of "processing with the number of control qubits set to 2."

[0063] Here, we explain why k is not set to 3 or greater in this case. When k = 1, the circuit depth of a quantum circuit using the 1 controlling qubit trick is (2L + 1)(M + U) when expressed in terms of the time required, because none of U and M can be performed simultaneously. In contrast, when k = 2, all M except the last can be completed during the calculation of U, so the circuit depth is (2L + 1)U + M. Furthermore, when k is set to 3 or greater, all Us are executed using L qubits, so the circuit depth is at least (2L + 1)U or greater. Furthermore, since the final M is added, the circuit depth ultimately becomes (2L + 1)U + M. Thus, when k is set to 3 or greater, the circuit depth is the same as when k = 2, so k = 2, which uses the fewest qubits, is selected. The circuit pattern selection unit 12 then selects a first circuit pattern, which is a quantum circuit pattern using two control qubits. The process of selecting this first circuit pattern is an example of a process of "determining a circuit pattern to a first circuit pattern that uses two control qubits to perform measurement and classical conditional operations in parallel with the sequential execution of multiple modular exponentiation calculations."

[0064] Thereafter, circuit pattern selection unit 12 notifies first circuit pattern generation unit 13 of k=2, which is the number of control quantum bits, and instructs first circuit pattern generation unit 13 to generate a first circuit pattern. The circuit depth of the first circuit pattern is (2L+1)U+M, as described above.

[0065] Furthermore, if the time required for unit 104 is less than the time required for measurement and classical conditional operations, circuit pattern selection unit 12 sets the number of control quantum bits as k>(2L+1) / ((1-α)2L+1).

[0066] Figure 5 shows the semiclassical QFT when the time required for the modular exponentiation unit is less than the time required for the measurement-classical conditional operation. -1 If the time taken by unit 104 is less than the time taken for measurement and classical conditional operations, the quantum circuit is classified as semi-classical QFT. -1 When using this method, a lot of waiting time occurs for measurement and classical conditional operations. For example, in Figure 4, times T1 and T2 are waiting times. In this case, the circuit depth is U+(2L+1)M.

[0067] Therefore, the circuit pattern selection unit 12 uses a newly defined inverse quantum Fourier transform, which will be explained next, to select a quantum circuit. -1 The figure shows the circuit configuration of the quantum Fourier transform shown in Figure 6. t is a subscript indicating the number from the beginning in the quantum circuit of the Shor algorithm, and is 0, 1, .... In the following, we will consider the newly defined inverse quantum Fourier transform shown in the circuit of Figure 6 as a half-classical QFT. -1 It is called.

[0068] Half classical QFT -1 has a system of numbers from 0 to k-1 as shown in Fig. 6. Each system corresponds to an integer k of 1 or more, and R' tk+k ,R' tk+(k-1) ,···,R' tk+1 The quantum gate and the Hadamard gate operate on the

[0069] QFT in the usual Shor algorithm -1 The circuit depth is O(L 2 ), but the semi-classical QFT shown in Figure 6 -1 is the circuit depth O(L 2 ) + M. The two are the same when k = 2L + 1.

[0070] 7 is a diagram showing a second circuit pattern. As shown in FIG. 7, the second circuit pattern uses three or more control qubits, and performs a half-classical QFT illustrated by units 201 and 202 each time a unit 104 corresponding to each control qubit is operated. -1 Unit 201 performs the semi-classical QFT at t=0. -1 Also, unit 202 is a semi-classical QFT with t=1. -1 is.

[0071] Here, we assume that k is sufficiently smaller than L. This is a condition that holds in many cases, since L is generally a very large number. In this case, we can use the half-classical QFT -1 The circuit depth of the second circuit pattern using is (2L+1)(U+(1 / k)M).

[0072] In this case, if U = αM (0 < α < 1), the semiclassical QFT shown in Figure 5 -1 The circuit depth when using the half-classical QFT shown in Figure 7 is (α+2L+1)M. -1 The circuit depth of the second circuit pattern using is (2L+1)(α+(1 / k))M. Comparing the two, we see that the half classical QFT -1 The circuit depth of the second circuit pattern using the semiclassical QFT is given by k>(2L+1) / ((1-α)2L+1). -1 The circuit depth is smaller than that when using

[0073] Therefore, circuit pattern selection unit 12 sets the number of control quantum bits as k>(2L+1) / ((1-α)2L+1), and sets the value when k is as large as the quantum bits allow as the number of control quantum bits. Then, circuit pattern selection unit 12 selects the second circuit pattern as a quantum circuit pattern that uses the set number of control quantum bits.

[0074] Setting the number of control qubits is an example of "a process of setting the number of control qubits to a number greater than a predetermined number based on a constant calculated from the number of bits used to represent the number to be factorized and the relationship between the first operation time and the second operation time." α is an example of "a constant representing the ratio between the first operation time and the second operation time." (2L+1) / ((1-α)2L+1) is an example of "a predetermined number based on a constant calculated from the relationship between the first operation time and the second operation time." Selecting the second circuit pattern is an example of "a process of determining a second circuit pattern in which a predetermined quantum circuit having a Hadamard gate, a rotation gate, and a measurement unit is arranged during modular exponentiation of the number of control qubits."

[0075] Thereafter, the circuit pattern selection unit 12 notifies the second circuit pattern generation unit 14 of the number of control quantum bits as the largest k that satisfies k>(2L+1) / ((1-α)2L+1), and instructs the second circuit pattern generation unit 14 to generate a second circuit pattern.

[0076] Thereafter, when circuit pattern selection unit 12 receives notification from second circuit pattern generation unit 14 that it is difficult to generate the second circuit pattern, it cancels the second circuit pattern and the number of control quantum bits to be used. Then, circuit pattern selection unit 12 sets the number of control quantum bits to k=2. Then, circuit pattern selection unit 12 notifies first circuit pattern generation unit 13 that the number of control quantum bits is k=2, and instructs first circuit pattern generation unit 13 to generate a first circuit pattern.

[0077] As described above, the circuit pattern selection unit 12 determines the number of control quantum bits that minimizes the execution time of the prime factorization operation, based on the relationship between the first operation time and the second operation time. Then, based on the determined number of control quantum bits, the circuit pattern selection unit 12 determines a circuit pattern for performing the modular exponentiation operation and the inverse quantum Fourier transform operation to perform the prime factorization operation.

[0078] The first circuit pattern generation unit 13 receives an instruction from the circuit pattern selection unit 12 to generate a first circuit pattern with the number of control quantum bits set to k=2. Then, the first circuit pattern generation unit 13 transmits information on the first circuit pattern shown in FIG. 4 to the quantum computer 20. Specifically, the first circuit pattern generation unit 13 transmits the number of quantum bits and a list of quantum gates to be used in the quantum circuit to be executed by the quantum computer 20. In this way, a quantum circuit having the first circuit pattern is generated in the quantum computer 20.

[0079] For example, the first circuit pattern generation unit 13 transmits the number of quantum bits as k+L+the number of auxiliary bits used in the modular exponentiation calculation. In the case of the first circuit pattern, k=2. In contrast, the number of auxiliary bits used in the modular exponentiation calculation varies depending on the algorithm. For example, if Q-ADD is used as the addition method within the modular exponentiation calculation, the number of auxiliary bits used in the modular exponentiation calculation will be L+2 bits.

[0080] The first circuit pattern generation unit 13 also generates a list of quantum gates, for example, as shown below, and transmits it to the quantum computer 20. The first circuit pattern generation unit 13 arranges a Hadamard gate for the first control quantum bit, an H gate for the second control quantum bit, and an X gate used in modular exponentiation calculation for the last bit of the register at the beginning of the list. Furthermore, for example, when Q-ADD is employed, the first circuit pattern generation unit 13 sequentially adds to the list a list of gates for executing Q-ADD using the first control quantum bit as the control bit. Next, the first circuit pattern generation unit 13 measures the first control quantum bit and executes an X^m gate for the measurement result m. ​​Next, the first circuit pattern generation unit 13 adds to the list a list of gates for operating a Hadamard gate and executing Q-ADD using the second control quantum bit as the control bit, arranging them in parallel. As described above, the first circuit pattern generation unit 13 generates a list of quantum gates by sequentially adding specific gates to the list.

[0081] As specific circuit contents, the first circuit pattern generation unit 13 generates the following quantum circuit for the quantum computer 20. First, the first circuit pattern generation unit 13 prepares two control quantum bits, |+> and |+>, which are numbered 0 and 1, respectively. In addition, the first circuit pattern generation unit 13 prepares |0 as a target register for prime factorization. L 〉.

[0082] Then, the first circuit pattern generation unit 13 creates a quantum circuit by applying an X gate to the last bit of the target register to set the target register to |0···01〉. Next, the first circuit pattern generation unit 13 creates a quantum circuit by repeating the next first process for the first pattern and the second process for the first pattern up to h=0,1,···,L-1 for the target register |0···01〉.

[0083] The first process for the first pattern is as follows: First, U is written to the target register as the control quantum bit. g^(2^(2L-2h)) Here, if h is greater than 0, U by No. 1 g^(2L―(2h-1)+1) After this is completed, number 0 is used as the control qubit and U is written to the target register. g^(2^(2L-2h)) Next, apply the Hadamard gate H to number 0. Here, if h is greater than 0, R 2h+1 After applying ' to number 0, we apply the Hadamard gate H to number 0. Then, we perform a measurement and store the measurement result in the measurement unit m 2h Then store it in X m2h and H, which is a Hadamard gate, are applied to number 0.

[0084] The second process for the first pattern is as follows: First, U is sent to the target register as the control quantum bit. g^(2^(2L-2h)) After the operation is finished, number 1 is used as the control qubit and U is written to the target register. g^(2^(2L-(2h+1)) Then, R 2h+2 After applying ' to No. 1, the Hadamard gate H is applied to No. 1. Then, a measurement is performed and the measurement result is stored in the measurement unit m 2h+1Then store it in X m2h+1 and H, which is a Hadamard gate, are applied to the first.

[0085] Finally, the first circuit pattern generation unit 13 creates a quantum circuit so as to execute the first process for the first pattern with h=L. However, the first circuit pattern generation unit 13 does not generate the last X m2h The action of H, the Hadamard gate, on number 0 is omitted.

[0086] The second circuit pattern generation unit 14 receives an instruction to generate a second circuit pattern from the circuit pattern selection unit 12, with the number of control qubits set to the largest k that satisfies k>(2L+1) / ((1-α)2L+1). The second circuit pattern generation unit 14 then selects the half-classical QFT shown in FIG. -1 7 using the above-mentioned method to the quantum computer 20. Specifically, the second circuit pattern generation unit 14 transmits the number of quantum bits and a list of quantum gates to be used in the quantum circuit to be executed by the quantum computer 20. As a result, the second circuit pattern generation unit 14 generates a quantum circuit having the second circuit pattern in the quantum computer 20.

[0087] As a specific circuit content, the second circuit pattern generation unit 14 generates the following half-classical QFT in the quantum computer 20: -1 Generate a quantum circuit for the semi-classical QFT explained below. -1 In the quantum circuit of the above, the initial value of t is 0, and t is incremented by one in the second circuit pattern from the front.

[0088] The second circuit pattern generation unit 14 prepares k quantum bits, numbered 0, 1, . . . , k-1, in order. When t is greater than 0, the second circuit pattern generation unit 14 assigns R' to all of the quantum bits numbered 0, 1, . . . , k-1. tk+1 A quantum circuit is generated to operate on

[0089] Furthermore, the second circuit pattern generation unit 14 creates a quantum circuit so as to repeat the next first process for the second pattern and the second process for the second pattern up to h=0, 1, . . . , k.

[0090] The first process for the second pattern operates H, which is a Hadamard gate, on the h-th quantum bit. In addition, the second process for the second pattern repeats the following process for g=1, 2, . . . , kh-1 when h is smaller than k. That is, with the h-th quantum bit as the control quantum bit, the h+g-th quantum bit is targeted, and R tk+g+1 A quantum circuit is created to apply the

[0091] Thereafter, the second circuit pattern generation unit 14 measures all of the qubits 0, 1, . . . , k-1, and outputs the respective results as m tk ,m tk+1 ,···,m tk+(k-1) Create a quantum circuit to store the

[0092] Here, when generating the second circuit pattern, the second circuit pattern generation unit 14 determines whether the specified second circuit pattern has a sufficient number of quantum bits in the quantum computer 20. If the number of quantum bits is insufficient, the second circuit pattern generation unit 14 notifies the circuit pattern selection unit 12 that it is difficult to generate the second circuit pattern. On the other hand, if the specified second circuit pattern has a sufficient number of quantum bits in the quantum computer 20, the second circuit pattern generation unit 14 generates a quantum circuit of the second circuit pattern in the quantum computer 20 and ends the generation of the quantum circuit.

[0093] Here, we will summarize the quantum circuit created by the information processing system 1 according to this embodiment. For example, when U=2M, U is greater than or equal to M, so the information processing system 1 generates a quantum circuit using the first circuit pattern with the number of control qubits set to k=2. In this case, the circuit depth is reduced to U+(2L+1)M=(2L+3)M, compared to the circuit depth (2L+1)(M+U)=3(2L+1)M of a quantum circuit using one controlling qubit trick when k=1.

[0094] Furthermore, when U=(1 / 2)M, U is less than M, so information processing system 1 generates a quantum circuit using the second circuit pattern with the largest k that satisfies k>(2L+1) / (L+1)=2 as the number of controlling qubits. In this case, the circuit depth is reduced to (2L+1)(U+(1 / k)M)=(5 / 6)(2L+1)M when k=3, compared to the circuit depth (2L+1)(M+U)=(3 / 2)(2L+1)M of a quantum circuit using one controlling qubit trick when k=1.

[0095] Furthermore, when U=(2 / 3)M, U is less than M, so information processing system 1 generates a quantum circuit using the second circuit pattern with the largest k that satisfies k>(6L+3) / (2L+3)=3 as the number of controlling qubits. In this case, the circuit depth is reduced to (2L+1)(U+(1 / k)M)=(11 / 12)(2L+1)M when k=4, compared to the circuit depth (2L+1)(M+U)=(5 / 3)(2L+1)M of a quantum circuit using one controlling qubit trick when k=1.

[0096] 8 is a flowchart of a process for generating a quantum circuit by a classical computer according to an embodiment. Next, the flow of a process for generating a quantum circuit by a classical computer 10 according to an embodiment will be described with reference to FIG.

[0097] The information acquiring unit 11 receives information on an algorithm used for modular exponentiation calculation as an input. Next, the information acquiring unit 11 acquires a modular exponentiation calculation time, which is the time required for each of the units 104 used for the modular exponentiation calculation according to the algorithm used for the modular exponentiation calculation (step S1).

[0098] The information acquiring unit 11 also receives input of information on the algorithm used for the inverse quantum Fourier transform. Next, the information acquiring unit 11 acquires the measurement and classically conditioned operation time according to the algorithm used for the inverse quantum Fourier transform (step S2). Thereafter, the information acquiring unit 11 outputs the modular exponentiation calculation time and the measurement and classically conditioned operation time to the circuit pattern selecting unit 12.

[0099] The circuit pattern selection unit 12 determines whether the modular exponentiation calculation time is equal to or greater than the measurement-classical conditional calculation time (step S3).

[0100] If the modular exponentiation calculation time is equal to or greater than the measurement-classical-conditional operation time (step S3: Yes), the circuit pattern selection unit 12 determines the number of control quantum bits to be k=2 (step S4). Then, the circuit pattern selection unit 12 instructs the first circuit pattern generation unit 13 to generate a quantum circuit using a first circuit pattern in which the number of control quantum bits is k=2.

[0101] Upon receiving an instruction from the circuit pattern selection unit 12, the first circuit pattern generation unit 13 transmits information on a first circuit pattern in which the number of control quantum bits is k=2 to the quantum computer 20 to generate the first circuit pattern (step S5).

[0102] On the other hand, if the modular exponentiation calculation time is less than the measurement-classical-conditional operation time (step S3: No), the circuit pattern selection unit 12 determines the number of control quantum bits, k, to be the maximum value greater than (2L+1) / ((1-α)2L+1) (step S6).Then, the circuit pattern selection unit 12 instructs the second circuit pattern generation unit 14 to generate a quantum circuit using a second circuit pattern in which the number of control quantum bits is the maximum value greater than (2L+1) / ((1-α)2L+1).

[0103] In response to the instruction from the circuit pattern selection unit 12, the second circuit pattern generation unit 14 transmits information about a second circuit pattern in which the number of control quantum bits is set to the maximum value greater than (2L+1) / ((1-α)2L+1) to the quantum computer 20. As a result, the second circuit pattern generation unit 14 causes the quantum computer 20 to generate a second circuit pattern (step S7).

[0104] Here, the second circuit pattern generation unit 14 determines whether the number of quantum bits of the quantum computer 20 is sufficient to generate a quantum circuit of the second circuit pattern in which the number of control quantum bits is the maximum value greater than (2L+1) / ((1-α)2L+1) (step S8).

[0105] If there are not enough quantum bits (step S8: No), the second circuit pattern generation unit 14 notifies the circuit pattern selection unit 12 that it is difficult to generate a quantum circuit of the second circuit pattern. The circuit pattern selection unit 12 cancels the second circuit pattern (step S9). Thereafter, the quantum circuit generation process returns to step S4.

[0106] On the other hand, if there are enough quantum bits (step S8: Yes), the second circuit pattern generation unit 14 ends the quantum circuit generation process with the quantum computer 20 generating a quantum circuit of the second circuit pattern.

[0107] As explained above, the classical computer according to this embodiment determines the number of control qubits and the circuit pattern that minimizes the execution time of the prime factorization operation based on the relationship between the time required for the modular exponentiation calculation and the time required for the measurement-classical conditional operation. A quantum circuit that performs prime factorization operations is generated in a quantum computer using the determined circuit pattern. This reduces the execution time of the prime factorization operations. By reducing the execution time of the prime factorization operations, it becomes possible to easily and reliably perform security checks of encrypted communications and cipher evaluations, thereby improving the security of the system.

[0108] (Hardware configuration) 9 is a diagram showing the hardware configuration of the classical computer 10. Next, an example of the hardware configuration for realizing each function of the classical computer 10 will be described with reference to FIG.

[0109] 9, the classical computer 10 includes, for example, a CPU (Central Processing Unit) 91, a memory 92, a hard disk 93, and a network interface 94. The CPU 91 is connected to the memory 92, the hard disk 93, and the network interface 94 via a bus.

[0110] The network interface 94 is an interface for communication between the classical computer 10 and an external device. The network interface 94 relays communication between the quantum computer 20 and the CPU 91, for example.

[0111] The hard disk 93 is an auxiliary storage device that stores various programs, including programs for realizing the functions of the information acquisition unit 11, the circuit pattern selection unit 12, the first circuit pattern generation unit 13, and the second circuit pattern generation unit 14 illustrated in FIG.

[0112] The memory 92 is a main storage device and may be, for example, a dynamic random access memory (DRAM).

[0113] The CPU 91 reads various programs from the hard disk 93, expands them into the memory 92, and executes them. As a result, the CPU 91 realizes the functions of the information acquisition unit 11, the circuit pattern selection unit 12, the first circuit pattern generation unit 13, and the second circuit pattern generation unit 14 illustrated in FIG. [Explanation of symbols]

[0114] 1. Information Processing Systems 10 Classical Calculator 11 Information acquisition department 12 Circuit pattern selection section 13 First circuit pattern generation unit 14 Second circuit pattern generation unit 20 Quantum Computer

Claims

1. determining the number of control qubits based on a relationship between a first operation time required for each of a plurality of modular exponentiation calculation processes in the prime factorization operation and a second operation time required for each of a plurality of measurement / classical conditional operations included in an inverse quantum Fourier transform process on the results of the plurality of modular exponentiation calculation processes in the prime factorization operation; determining a circuit pattern for performing the modular exponentiation calculation processes and the inverse quantum Fourier transform process to calculate the prime factorization based on the determined number of control quantum bits; generating a quantum circuit that executes the prime factorization operation using the determined circuit pattern; The quantum circuit is used to perform the prime factorization operation. An information processing program that causes a computer to execute a process.

2. In the process of determining the number of control qubits, the number is determined so as to minimize the execution time of the prime factorization operation.

2. The information processing program according to claim 1, wherein:

3. When the first calculation time is equal to or longer than the second calculation time, determining the number of control qubits includes setting the number of control qubits to 2; The process of determining the circuit pattern includes a process of determining the circuit pattern as a first circuit pattern that executes the measurement and classical conditional operations in parallel with sequential execution of the plurality of modular exponentiation calculation processes using the two control qubits.

2. The information processing program according to claim 1, wherein:

4. If the first calculation time is less than the second calculation time, the process of determining the number of control quantum bits sets the number of control quantum bits to a number greater than a predetermined number based on a constant calculated from the relationship between the number of bits used to represent a number to be factorized and the first processing time and the second processing time; The process of determining the circuit pattern includes a process of determining the circuit pattern as a second circuit pattern in which a predetermined quantum circuit having a Hadamard gate, a rotation gate, and a measurement unit is arranged during the modular exponentiation calculation process of the number of control quantum bits.

2. The information processing program according to claim 1, wherein:

5. The process of determining the number of control qubits includes: calculating a first number by doubling the number of bits used to represent the number to be factorized and adding 1 to the result; a constant representing a ratio between the first calculation time and the second calculation time is set as the constant, the constant is subtracted from 1, the result is multiplied by twice the number of bits, and 1 is added to the multiplication result to calculate a second number; Dividing the first number by the second number to calculate the predetermined number.

5. The information processing program according to claim 4, further comprising a process for:

6. The computer determining the number of control qubits based on a relationship between a first operation time required for each of a plurality of modular exponentiation calculation processes in the prime factorization operation and a second operation time required for each of a plurality of measurement / classical conditional operations included in an inverse quantum Fourier transform process on the results of the plurality of modular exponentiation calculation processes in the prime factorization operation; determining a circuit pattern for performing the modular exponentiation calculation processes and the inverse quantum Fourier transform process to calculate the prime factorization based on the determined number of control quantum bits; generating a quantum circuit that performs the prime factorization operation using the circuit pattern determined using the determined number of control quantum bits; The quantum circuit is used to perform the prime factorization operation. An information processing method characterized by executing processing.

7. An information processing system including a classical computer and a quantum computer, The classical computer is a circuit pattern selection unit that determines the number of control quantum bits based on a relationship between a first operation time required for each of a plurality of modular exponentiation operations in a prime factorization operation and a second operation time required for each of a plurality of measurement / classical-conditional operations included in an inverse quantum Fourier transform operation on a result of the plurality of modular exponentiation operations in the prime factorization operation, and that determines a circuit pattern for performing the plurality of modular exponentiation operations and the inverse quantum Fourier transform operation to perform the prime factorization operation based on the determined number of control quantum bits; a quantum circuit generation unit that generates, in the quantum computer, a quantum circuit that executes the prime factorization operation using the circuit pattern determined using the number of control quantum bits determined by the circuit pattern selection unit, The quantum computer executes the prime factorization operation using the quantum circuit. An information processing system comprising:

Citation Information

Patent Citations

  • Quantum circuit

    WO2022249963A1