Systems and methods for generating and implementing reversible hash circuits

The conversion of irreversible hash functions into reversible circuits using specific operations and tools allows for efficient hash reversal, addressing the challenge of reversing cryptographic hash functions and enhancing cybersecurity and quantum computing applications.

JP2025535766APending Publication Date: 2025-10-28ANAMETRIC INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025521081
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-10-12
Filing Date
2023-10-09
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

Existing cryptographic hash functions are difficult to reverse, which poses challenges for cybersecurity and quantum computing applications, as efficient techniques for hash reversal are not readily available.

Method used

A method to generate reversible hash circuits by converting irreversible hash functions into reversible circuits using a limited set of operations or gates, such as AND and XOR, and applying circuit synthesis tools to create a reversible hash circuit that can be operated in reverse to obtain input values from output values.

Benefits of technology

Enables efficient generation of reversible hash functions suitable for cybersecurity tasks like blockchain operations and cryptographic decryption, bypassing the need for brute-force searches and optimizing hash reversal processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025535766000001_ABST
    Figure 2025535766000001_ABST
Patent Text Reader

Abstract

Systems and methods for generating reversible hash circuits from irreversible hash functions are disclosed, along with reversible hash circuits generated using such systems and methods. Generally, embodiments generate a reversible hash circuit by taking a hash function and mapping the irreversible hash function to a reversible hash circuit that includes a reversible element, whereby the reversible hash circuit may be utilized to obtain a corresponding input from an output value of the hash function.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (Related Applications) This application claims the benefit of priority under 35 U.S.C. § 119 to U.S. Provisional Patent Application No. 63 / 415,508, entitled "Systems and Methods For Computing An Inverse Hash Function," filed October 12, 2022 by Mitchell A. Thornton et al., which is hereby fully incorporated by reference in its entirety.

[0002] (Technical field) The present disclosure relates generally to computer security, and more particularly to embodiments of systems and methods for implementing hash functions, including the generation, implementation, or use of such hash functions. [Background technology]

[0003] (background) A hash function transforms inputs in one form into outputs in another form, ideally via a mathematical function that transforms every unique input into a unique output. A hash function can therefore be thought of as a data structure that stores information through such a transformation. Robust hash functions, i.e., hash functions that minimize collisions (different inputs that map to the same output) and do not allow easy retrieval of inputs from their outputs, are useful cryptographic tools for encrypting data.

[0004] More specifically, cryptographic hash functions are traditionally designed to be "one-way." For such one-way functions, it is easy to go from an input I to an output O. Conversely, for these one-way functions, it is very difficult to recover I when only O and the hash function are known. As a result, such one-way hash functions are useful tools in cryptography because they can be used to encrypt data. When information to be encrypted is sent through a hash function (e.g., as an input I), the resulting output (O) cannot be easily transformed back into the input. This process of going from the output to the input is called hash reversal, and efficient techniques for reversing cryptographically strong hash functions have been widely studied.

[0005] Some of these techniques involve the use of quantum computers. Quantum computers differ from these classical computers in several important ways. One such difference is that some quantum circuit synthesis methods require reversible function specifications. A logically reversible circuit is one in which each output has a unique input. In other words, it is possible to obtain an input that produced a known output, provided we know the output and the function applied to produce it.

[0006] Therefore, the process of hash reversal is of great interest at least due to its unanticipated implications for cybersecurity and its potential usefulness in developing algorithms for quantum computing. Therefore, simple and efficient methods for generating and implementing reversible hash functions are desirable. Summary of the Invention [Means for solving the problem]

[0007] (overview) With the above context in mind, some additional context regarding hash functions, their reversibility and uses may be useful. As discussed, it is desirable to be able to determine and generate logically reversible circuits for hash functions, and to be able to use those reversible hash circuits to generate input values ​​from output values ​​for the hash functions.

[0008] To those ends, attention is directed herein to disclosed embodiments of systems and methods for generating reversible hash circuits from (e.g., irreversible) hash functions, in particular, along with reversible hash circuits generated using embodiments of such systems and methods. Generally, embodiments may generate a reversible hash circuit by taking a hash function (e.g., formed from irreversible elements) and mapping the irreversible hash function to a reversible hash circuit that includes reversible elements. This reversible hash circuit may be utilized to obtain a corresponding input value from an output value of the hash function.

[0009] First, a representation of the hash function may be obtained. The representation of the hash function may be converted to a second representation of the hash function, which may utilize a limited set of operations or gates (e.g., AND and exclusive OR (XOR)) to represent the hash function. The second representation of the hash function may then be mapped to a set of reversible gates to generate a reversible hash circuit. To generate the original input value for the hash function from the output value, an output value from which it is desired to determine the input value may be selected, and the reversible hash circuit may be run in reverse based on the output with the selected output value to generate the corresponding input value.

[0010] Thus, in one embodiment, a first representation of a hash function can be obtained, the first representation of the hash function can be transformed into a second representation of the hash function, and a reversible hash circuit for the hash function can then be generated by mapping the second representation of the hash function to a set of reversible gates comprising the reversible hash function.

[0011] In some embodiments, the first representation is a programmable logic array (PLA), a netlist, or a decision tree. The second representation may be, for example, an exclusive-or-sum-of-products (ESOP) representation. The hash circuit can therefore be minimized before the reversible hash circuit is generated.

[0012] Once a reversible hash circuit is generated, it can be utilized by providing a given output value of the hash function as an input to the reversible hash circuit and operating the reversible hash circuit in the reverse direction to obtain an input value corresponding to the given output value. This operation can be in the classical domain or the quantum domain. When the reversible hash circuit is operated in the quantum domain, the output value can include a set of output values, and the obtained input value can include multiple input values, each corresponding to one of the set of output values.

[0013] Thus, embodiments may provide systems and methods for efficiently generating reversible hash functions, and such hash functions may have several applications that may be important (e.g., to the cybersecurity community). For example, participating in the blockchain ecosystem (including cryptocurrency mining), decrypting website credentials, and forging cryptographic signatures all involve hashes. Embodiments as described herein may generate circuits that directly compute reverse hashes, thereby bypassing the vast set of forward hash calculations involved in brute-force searches. Furthermore, embodiments may be particularly well-suited for tasks involving fixed-size hashes, such as those used in blockchains, because hash reversal circuits do not need to be resynthesized in real time.

[0014] These and other aspects of the present disclosure will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following description, while indicating various embodiments of the present disclosure and numerous specific details thereof, is given by way of illustration and not by way of limitation. Many substitutions, modifications, additions, and / or rearrangements may be made within the scope of the present disclosure without departing from the spirit thereof, and the present disclosure includes all such substitutions, modifications, additions, and / or rearrangements. [Brief explanation of the drawings]

[0015] The drawings accompanying and forming a part of this specification are drawn to illustrate certain aspects of the present disclosure. It should be noted that the features illustrated in the drawings are not necessarily drawn to scale. A more complete understanding of the present disclosure and its advantages may be obtained by referring to the following description in conjunction with the drawings in which like reference numerals refer to like features.

[0016] [Figure 1] FIG. 1 is a block diagram of an example of a non-reciprocal circuit.

[0017] [Figure 2] FIG. 2 is a block diagram of an example of a reversible circuit.

[0018] [Figure 3] FIG. 3 is a block diagram of one embodiment for generating and utilizing a reversible hash circuit.

[0019] [Figure 4A] 4A, 4B and 4C depict a representation of the function. [Figure 4B] 4A, 4B and 4C depict a representation of the function. [Figure 4C] 4A, 4B and 4C depict a representation of the function.

[0020] [Figure 5A] 5A, 5B, 5C and 5D depict a representation of the circuit. [Figure 5B] 5A, 5B, 5C and 5D depict a representation of the circuit. [Figure 5C] 5A, 5B, 5C and 5D depict a representation of the circuit. [Figure 5D] 5A, 5B, 5C and 5D depict a representation of the circuit.

[0021] [Figure 6] FIG. 6 depicts a representation of the circuit.

[0022] [Figure 7] FIG. 7 depicts a representation of the circuit.

[0023] [Figure 8] FIG. 8 depicts an example circuit according to some embodiments.

[0024] [Figure 9A] 9A and 9B depict exemplary circuit representations according to an embodiment. [Figure 9B] 9A and 9B depict exemplary circuit representations according to an embodiment.

[0025] [Figure 10] FIG. 10 depicts an exemplary circuit representation according to an embodiment.

[0026] [Figure 11] FIG. 11 depicts an exemplary circuit representation according to an embodiment.

[0027] [Figure 12] 1 depicts an exemplary minimized hash function representation.

[0028] [Figure 13A]13A-13E depict the generation and use of an exemplary inverse hash function, according to an embodiment. [Figure 13B] 13A-13E depict the generation and use of an exemplary inverse hash function, according to an embodiment. [Figure 13C] 13A-13E depict the generation and use of an exemplary inverse hash function, according to an embodiment. [Figure 13D] 13A-13E depict the generation and use of an exemplary inverse hash function, according to an embodiment. [Figure 13E] 13A-13E depict the generation and use of an exemplary inverse hash function, according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0029] (Detailed explanation) The present invention and its various features and advantages will be more fully explained with reference to the non-limiting embodiments illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known starting materials, processing techniques, components and equipment have been omitted so as not to unnecessarily obscure the invention in detail. It should be understood, however, that the detailed description and specific examples, while indicating preferred embodiments of the invention, are given by way of illustration only and not by way of limitation. Various substitutions, modifications, additions and / or rearrangements within the spirit and / or scope of the underlying inventive concept will become apparent to those skilled in the art from this disclosure.

[0030] Before discussing the embodiments in detail, it may be useful to provide a general overview of certain aspects related to the embodiments. As can be recalled from the above discussion, a hash function transforms an input of one form into an output of another form via a mathematical function that ideally transforms every unique input into a unique output. A hash function may therefore be thought of as a data structure that stores information through such a transformation. Some hash functions are designed to be one-way and are therefore useful tools in cryptography for encrypting data or other tasks. The process of inverting such a hash function is called hash inversion, and efficient techniques for such hash inversion are of interest in various fields, including cryptography and quantum computing.

[0031] In particular, it is desirable to be able to determine and generate logically reversible circuits for hash functions. Because it will be clear to those skilled in the art how a physical circuit can be created from a description of a function in either the classical or quantum domain, and how a circuit (e.g., either reversible or irreversible) can implement and be described by a function, the terms circuit and function will be used substantially interchangeably for purposes of this disclosure. It will further be noted that such circuits and functions can similarly be implemented in computer-executable instructions without loss of generality. Thus, for example, embodiments may include a set of computer-executable instructions that can be applied to a stored hash function (e.g., described or expressed in a file or as a set of instructions for that hash function) to generate and store an inverse function of that hash function (e.g., described or expressed in a file or as a set of instructions for that reversible hash function).

[0032] In any case, a logically reversible circuit is one in which each output has a unique input; in other words, it is possible to obtain the input that produced the output by knowing only the output and the function applied to generate it. This reversibility can be illustrated by comparing two functions. Consider a two-input AND operation with a truth table and circuit diagram as depicted in the circuit of Figure 1. Given an output r=0 and the information that an AND operation was applied, it is impossible to know what the inputs are, since there are three possible input pairs for an output of r=0: 1) p=0 and q=0, 2) p=0 and q=1, and 3) p=1 and q=0. Therefore, the AND operation is not reversible.

[0033] Contrast this with Figure 2, which depicts a reversible three-input Toffoli circuit and associated truth table. The Toffoli operation is a controlled operation: NOT is applied if and only if both p and q are 1. (In other words, if p and q are both 1, then u = ~r.) p and q are called the controls, and r is called the target of the operation. The value of the controls does not change (i.e., s = p and t = q), but both values ​​are included as outputs so that the operation is reversible. So, for example, if the outputs are s = 1, t = 1, and u = 0, then the set of possible inputs is only p = 1, q = 1, and r = 1.

[0034] Certain techniques for adding inputs and outputs can be used to generate irreversible functions from invertible functions, as illustrated by comparing the AND operation to the Toffoli operation in Figures 1 and 2. And because developing algorithms for quantum computers often involves designing reversible algorithms, techniques have been developed for converting irreversible functions into invertible functions.

[0035] In particular, synthesis, compilation, or optimization tools have been developed that convert functions from representations suitable for synthesizing classically specified circuits to circuit descriptions suitable for quantum computers. As discussed, quantum computers typically require invertible functions. Thus, circuit synthesizers for use with quantum computers may include functionality to convert non-invertible functions to invertible form.

[0036] Such tools may be understood by reference to the following: A. Sinha, E.R. Henderson, J.M. Henderson, and M.A. Thornton, "Automated Quantum Memory Compilation with Improved Dynamic Range," Proceedings of the IEEE / ACM 3rd International Workshop on Quantum Computing Software (QCS), Dallas, TX, 2022; K.N. Smith and M.A. Thornton, "A quantum computational compiler and design tool for technology-specific targets," 2022 IEEE International Symposium on Computer Architecture (ISCA), 2019; Smith, Kaitlin, "Technology-dependent Quantum Logic Synthesis and Compilation," 2019; K. Fazel, M.A. Thornton, and J.E. Rice, "ESOP-based Toffoli gate cascade generation," 2007 IEEE Pacific Coast Conference on Communications, Computers, and Signal Processing, IEEE, 2007; Nielsen, Michael A., and Isaac Chuang, "Quantum computation and quantum Information," 10th Edition (2010), all of which are hereby incorporated by reference in their entirety and for all purposes.

[0037] In one embodiment, therefore, a circuit synthesis tool may be applied to a hash function to generate an equivalent invertible hash function. In particular, a circuit synthesis tool that creates an invertible function by adding additional inputs (known as unsigned integers) and outputs (known as garbage) and using gates (e.g., operations) that utilize those additional inputs and outputs may be applied to a hash function to generate an equivalent invertible hash function.

[0038] 3 depicts one embodiment of a method for generating a reversible hash function using a circuit synthesis tool. First, a representation of the hash function may be obtained (step 310). The representation of the forward hash function may be converted to a second representation of the hash function, which may utilize a limited set of operations or gates (e.g., AND and exclusive OR (XOR)) to represent the hash function (step 320). The second representation of the hash function may then be mapped as a set of reversible gates (e.g., gates that can be used to implement the reversible function) to generate a reversible hash circuit (step 330).

[0039] To generate an output value from the original input value, the output value(s) for which it is desired to determine the input value(s) can be selected (step 340). It will be noted that if it is desired to operate in the classical domain, a single (e.g., output) value may be selected, but if operating in the quantum domain, multiple (e.g., output) values ​​may be inverted (e.g., simultaneously) during a single operation of the reversible hash circuit. Once the output value is selected, the reversible hash circuit may be run in reverse based on the selected output value to generate the corresponding input value (step 350).

[0040] Then, according to one embodiment, a (first) representation of the hash function can be obtained, the first representation of the hash function being desired for generating a reversible hash circuit for such hash function. This representation can be formatted as, for example, an electronic design file, such as a file in the .pla file format (hence the .pla extension) used for physical descriptions of programmable logic arrays (PLAs), or a hardware description language (HDL), such as a structural-level Verilog HDL format (e.g., a Verilog netlist). Other embodiments may utilize decision diagrams to represent forward hash functions, including binary decision diagrams, etc. While tables are used herein for ease of representation, those skilled in the art will understand that there are more compact ways to represent switching functions other than tables, such as the aforementioned representations (e.g., binary decision diagrams, textual netlists of conventional electrical gates, or others), and that such representations are fully contemplated herein.

[0041] The .pla format was originally conceived as a compact textual representation for specifying digital PLA for physical implementation in electronic circuits, specifically as a file format that allows specifications to be programmatically minimized.

number

number

[0042] Examples of .pla files representing trivial functions are presented in Figures 4A, 4B, and 4C. Figure 4A depicts a simple function converted to the .pla format in Figure 4B. Each line represents an input / output pair, and multiple input / output pairs can be represented if the function has cube covering overlap. For example, the .pla in Figure 4C can be simplified to the .pla in Figure 4C with the introduction of a hyphen (-). The hyphen in line 1 indicates that when the first input is zero, the output is also zero, regardless of the value of the second input. Similarly, the hyphen in line 2 indicates that whenever the second input is zero, the output is also zero. While this trivial example has minimal simplifications, .pla files representing larger functions with a significant amount of cube covering overlap can be significantly reduced in size through such simplifications.

[0043] The use of .pla files in some embodiments is advantageous because they are intuitively understandable and can efficiently represent even very large functions if the functions have sufficient cube covering overlap between their inputs and outputs. In fact, such cube covering overlap allows .pla to efficiently represent some functions with over 100 inputs and outputs.

[0044] However, in some cases, .pla files may be inherently limited because, even without cube cover overlap, the size of a .pla specification grows exponentially with the number of inputs and outputs. Some hashes can be represented as .pla files because robust hash functions may or may not have overlaps in input / output pairs. Therefore, while .pla files are useful for some hash functions, representing larger hash functions may be specified using a different format for specific implementations.

[0045] For example, a structural Verilog HDL netlist may allow for the representation of functions that are much larger than a .pla file can accommodate, because a Verilog netlist allows for multiple levels of specification. Structural Verilog represents functions as an interconnection of gates that act on inputs to create desired outputs. Thus, Verilog HDL may be a more versatile way of representing functions, given that it does not require explicitly listing every input / output pair, or in most cases, most of them. Therefore, some embodiments may utilize Verilog HDL to represent a hash function to be inverted.

[0046] Once a representation of the hash circuit to be inverted is obtained, the hash function (e.g., representation of the hash function) can be transformed into a representation of the hash function that utilizes a limited number of functions (e.g., AND and XOR functions). The transformed representation of the forward hash function can then be utilized to generate a reversible hash circuit by mapping the operations of the transformed representation to reversible gates.

[0047] In one embodiment, such conversions and mappings may be accomplished by a circuit synthesis tool that converts a function from a representation suitable for synthesizing classically specified circuits to a circuit description suitable for a quantum computer, such as a tool that implements an exclusive-or-multiply-sum (ESOP) synthesizer as described in "ESOP-based Toffoli gate cascade generation" by Fazel, MAT Hornton, and JE Rice, and "ESOP-based Toffoli gate cascade generation" by K. Fazel, MAT Hornton, and JE Rice. The ESOP representation of a function can therefore combine the input variables of the function with AND operators to create product terms that can be summed together using XOR operators.

[0048] Thus, transformations and mappings of the presented hash functions may be achieved, in one embodiment, by adding additional inputs (known as unsigned integers) and outputs (known as garbage) and by applying gates that utilize these additional inputs and outputs. In particular embodiments, the representation of the hash function may therefore be transformed and mapped to generate circuits that use reversible gates (e.g., only reversible gates), including NOT or Pauli-X gates, Controlled-Not (C-NOT) gates, and Toffoli gates. These Toffoli gates may be either "true" Toffoli gates with only two controls or generalized Toffoli gates with three or more controls.

[0049] Figure 5A depicts a truth table for a NOT (or Pauli-X) gate (or operation), Figure 5B depicts a commonly used representation for a NOT gate in the classical domain, and Figures 5C and 5D are representations of the NOT operation as used in quantum circuits. Figure 2, as mentioned above, depicts a Controlled-Not or C-NOT gate. Figure 6 depicts a truth table and gate representation for a reversible Toffoli operation. A Toffoli operation is a controlled operation in which NOT is applied to r if and only if both p and q are 1. (In other words, if p and q are both 1, then u = r). p and q are called the controls, and r is called the target of the operation. The values ​​of the controls do not change (i.e., s = p and t = q), but both values ​​are included as outputs so that the operation is reversible. Figure 7 depicts a truth table and circuit representation for a generated Toffoli with three controls. p, q, and r are controls for target s, t, u, and v maintain the values ​​of p, q, and r, and w = s when p, q, and r are all 1.

[0050] The ESOP synthesis method therefore creates an invertible function, with the originally specified irreversible function embedded within the resulting invertible specification. The resulting circuit may have the original number of inputs, the original number of outputs, and may also have additional unscrambler or garbage bits. Upon completion of the calculation using the generated invertible hash function, the output bits contain output values ​​corresponding to the specified input values, and any garbage output values ​​are ignored. This is illustrated in FIG. 8, where an exemplary circuit with two inputs, two outputs, and two unscramblers is illustrated according to an embodiment. The inputs remain unchanged throughout the process. The unscrambler and output may be initialized to zero, resulting in "garbage" values ​​and the final desired output, respectively.

[0051] A hash function in ESOP format can be expressed as an exclusive-or-sum-of-products. Function variables are combined into products via the logical AND operator, and these products are summed together using the disjunctive exclusive-or operator. When the resulting expression is evaluated at the variable values, it produces the corresponding function value.

[0052] Specifically, in an embodiment, a hash function may first be converted to ESOP form, i.e., the hash function comprises a list of products that, when combined via an exclusive-or operator, create an ESOP representation of the function. Each row of the table's input variable values ​​represents a product: a value of 1 or 0 corresponds to the positive or negative pole of the product, respectively. For each product, the ESOP method creates a Toffoli gate, thereby mapping the list of products to a reversible logic circuit.

[0053] The ESOP composition algorithm therefore creates a cascade of gates comprising the function through this mapping. In one embodiment, the steps for this mapping are as follows: For each input variable and each output variable of the ESOP-style hash function, a bit (which may be a qubit) is added as an input or output to the generated circuit. For each product comprising the function, each output value of 1 maps to a Toffoli gate with its target on the corresponding output qubit. The remaining aspects of that Toffoli gate (its control) are determined by the input corresponding to the output variable: an input value of 1 means that a control is placed on the corresponding input bit, while an input value of 0 means that a control is placed on the corresponding input bit with two NOT gates on either side of the control. These NOT gates invert the bit (e.g., the polarity of the bit) and then restore it for the subsequent Toffoli gate.

[0054] Stated another way, each input-output pair of a circuit can be considered to generate a cascade of gates that comprise the circuit. For each input-output pair, for each output variable value that is 1, a Toffoli gate is added to the output side of the cascade of gates being generated, with the Toffoli gate target for that added gate being on the corresponding output bit. The control for the resulting Toffoli gate is determined by the input variable values, with each value 1 in the input variable values ​​mapping to a control on the corresponding input bit and each value 0 mapping to a control tied between two Pauli-X gates on the corresponding input bit.

[0055] As can be seen, such an ESOP synthesizer may result in a large number of gates. Therefore, in one embodiment, before such a circuit synthesizer is executed, a minimization process may be applied to the hash function (e.g., the ESOP representation of the hash function) to reduce the circuit size of the hash function. For example, ESOP minimization may involve application of a circuit minimizer such as EXORCISM-4 EXMIN2, MINT, EXORCISM-3, EXORCISM-2, or another minimizer.

[0056] Once the circuit specification is generated through the mapping, the circuit can be simply inverted to generate a reversible hash circuit. This inversion can simply mean swapping the gate order of the circuit. For example, if the gates are numbered 1, 2, 3, ... n-1, n, the inverted circuit would have gate order n, n-1, ... 3, 2, 1.

[0057] To describe in more detail, the operation of a reversible hash circuit to obtain an input for a particular original output may, in one embodiment, be accomplished by first selecting the output from which it is desired to obtain an input. Next, those outputs may be placed on the output lines, and currently undetermined variables are placed on the input lines (e.g., on the left side of the diagram). Next, zeros are placed on the output lines (e.g., on the right side) because the outputs may always be set to start in a zero state. However, it should be noted that these output lines may start in any state, as long as the state is known when the circuit is synthesized. For simplicity and to conform to conventions in the art, zeros are utilized for the purposes of this example. Currently undetermined input values ​​may be placed on the input lines (e.g., on the right side) (this is possible because embodiments may preserve the values ​​of the inputs). The reversible nature of the circuit may then be utilized to determine what input corresponds to a specified output (e.g., the circuit may be run in a "reverse" direction). This process can be performed classically or using quantum computing, although in some cases performing the inversion in the quantum domain may allow for greater parallelization.

[0058] It may be useful here to provide an understanding of the embodiments to explain an example of hash inversion for a 4-bit hash function. Given the utility in describing .pla files, the example function is presented as a .pla, but it could also be expressed as a Verilog HDL netlist, a decision diagram, or another type of representation, as previously discussed.

[0059] Thus, consider the 4-bit hash function presented in Figures 9A and 9B. For purposes of considering an illustrative example, the exemplary hash function is not particularly "strong," but it should be noted that the process described with respect to this example can be equally applied to other (e.g., stronger) hash functions. From the hash function represented in Figure 9A, an embodiment as disclosed herein can generate the circuit presented in Figure 9B. Zero values ​​for all unsigned integers and outputs, as well as associated inputs, are sent to the circuit, as described for the single input / output value pair in Figure 10. Specifically, generating an output of 1001 from an input of 0110 is described. Note that the inputs remain unchanged, and the unsigned integers are used as operating values ​​to produce a "garbage" output, but the final output contains the desired computation. It is also noted that for this trivial function, the garbage value always equals the value of the output, but for more complex function compositions, this may not necessarily be the case.

[0060] Reversing the order of gates in a circuit specification allows working backward from the output to obtain the input, as illustrated in circuit 1100 of FIG. 11. Specifically, what is illustrated in FIG. 11 is working backward from output 1001 to obtain input 0110 for circuit 1100. As depicted, the numerals closest to the right on lines 0, 1, 2, and 3 are the inferred input values ​​w=0, x=1, y=1, and z=0. The numbers indicating the intermediate values ​​of each line are as follows: values ​​1102a and 1102b are associated with the inversion of w, values ​​1102c and 1102d are associated with the inversion of x, values ​​1102e and 1102f are associated with the inversion of y, and 1102g and 1102h are associated with the inversion of z. Gate 1104 is a gate whose output value was flipped between "0" and "1", while gate 1106 is a gate whose output was unchanged.

[0061] The steps for determining the inputs from the outputs can now be described. Note that larger functions require more complex circuitry, but the same process applies. Referring to the left side of Figure 11, the variables w, x, y, and z represent unknown inputs, the variables a, b, c, and d represent unknown garbage values, and the numeric values ​​represent known outputs for which the corresponding inputs are desired.

[0062] On the right side of Figure 11, the variables w, x, y, and z again represent unknown inputs, but the unsigned integers and output values ​​are all set to zero. It should be noted that while the inputs w, x, y, and z are identical on both sides in the illustrated example, this is not a requirement for the inversion process, but may instead be a feature of a circuit synthesis tool that may be utilized in embodiments. Instead, it is a feature that is useful in mapping functions more generally. Note: Circuit synthesis tools may be designed to restore inputs to their original values ​​after each intermediate circuit change. Similarly, the initialization of all unsigned integers and outputs to zero is not a requirement for function inversion, but may be a design choice for the function synthesis tool. Thus, for example, it would be possible to use the same inversion procedure with unsigned integers or outputs initialized to non-zero values. Note: What is important is that the initialization values ​​are known. It will also be noted that NOT gate 1108, which occurs to the left of C-NOT gates 1104a, 1104b, 1106a, and 1106b in circuit 1100, is an input restoration gate that may not be necessary in some embodiments.

[0063] The inputs can be determined from the outputs because circuits created by circuit synthesis tools by mapping a circuit function to a circuit (e.g., circuit 1100) are reversible. As a result, by working backward, we can ascertain what happens to each part of the circuit and obtain a known output. Consider the first gate 1104, specifically gate 1104d. Line 11 has a final output value of 1, but it started out as 0. That means gate 1104d inverts the value of line 11, and therefore the gate's input must have been 1. (This is indicated by the value 1102g of 1 to the right of gate 1104d's control on line 7.) Tracing line 7 to the right of the control for gate 1104d is gate 1104a. The value 1102g output from gate 1104a, which is 1, indicates that the original value (0) of line 7 has been inverted. As a result, the control on line 3 for gate 1104a must have had an input value 1102g of 1. Finally, following line 3 to the right of the control for gate 1104a is NOT gate 1110d. Because the output of that gate 1110d must be value 1102g, which is 1, it can be determined that the input to the NOT was value 1102h, which is 0, and therefore it can be determined that input z had a starting value of 0.

[0064] The same process can be used for each of the outputs, and the results are illustrated in FIG. 11. Now, as will remain understood by those skilled in the art, one more example will be described, specifically that of gate 1106c. Gate 1106c has a target on line 10, which has both a final and starting value of 0. This means that the control for gate 1106c, located on line 6, must have had an input value 1102e of 0. Tracing back from that control to the beginning of line 6, the target of gate 1106b is encountered. Note again that the output of that target must be identical to the initial 0 value 1102e on line 6, so the control for gate 1106b, located on line 2, must also have had an input value of 0. Moving to the right from there, we arrive at NOT gate 1110c. Since the result of NOT 1110c is value 1102e, which is 0, input value 1102f must be 1, i.e., y=1.

[0065] The depiction and description of verification as discussed above is only possible for fairly small functions. Even for moderately larger functions, verification can be achieved by combining a circuit specification in the "forward" direction (i.e., input to output) with a circuit specification for the "inverted" direction (i.e., output to input). Verilog HDL simulation can then be used to verify that all of the values ​​input on the left side match the values ​​output on the right side. Inversion is proven successful when the combined forward and inverted circuits behave identically for output pairs uniquely for all possible input / output pairs.

[0066] Another example may also prove useful. Turning now to Figure 12, an exemplary hash function .pla table representation identical to that of Figure 9A is depicted along with a corresponding .pla table representation of a minimized ESOP form of that same function. An example of ESOP synthesis of a reversible hash circuit from that hash function is depicted in Figures 13A-13D.

[0067] Recall that each input / output pair of the circuit can be considered to generate the cascade of gates that comprise the ESOP version of the circuit. For each input / output pair considered, for each output variable that is 1 for that pair, a Toffoli gate is added to the output side of the cascade of gates being generated, with the Toffoli gate target for that added Toffoli gate being on the corresponding output bit. The control for the resulting Toffoli gate is determined by the input variable values ​​of that input-output pair, such that each 1 in the input variable values ​​maps to a control on the corresponding input bit, and each 0 maps to a control tied between two Pauli-X gates on the corresponding input bit.

[0068] Thus, referring first to FIG. 13A, a reversible circuit 1300a generated for a hash function such as that depicted in FIG. 12 may include four input lines 1302 (1302a, 1302b, 1302c, 1302d) and four output lines 1310 (1310a, 1310b, 1310c, 1310d). This generation may involve processing each input-output value pair of the representation and including a corresponding gate in circuit 1300a based on that input-value pair. In FIG. 13B, the determination and inclusion of a gate in circuit 1300a for a first input-output pair 1320a of a function representation for hashing is depicted. Here, input value pair 1320a is 0 (e.g., corresponding to input lines 1302a, 1302b, 1302c, and 1302d, respectively), while output value pair is 0001 (e.g., corresponding to output lines 1310a, 1310b, 1310c, and 1310d, respectively). It will be understood that each hyphen or dash in the input value pair representation can be effectively ignored for purposes of inclusion of gates in circuit 1300a, because either input value (0 or 1) on the input lines corresponding to those dashes will map to the corresponding output value of that output pair.

[0069] Therefore, for each bit in the pair of output values ​​that is a 1, a controlled gate is included in circuit 1300a, with that gate's target on output line 1310 in circuit 1300a corresponding to that bit. For this first input-output pair 1320a, a 1 is in the last place of the output value, and therefore corresponds to last output line 1302d. Therefore, a (e.g., CNOT or Toffoli) gate 1330d is included in circuit 1300a on output line 1302d based on the value 1 in the last place of the output value.

[0070] The value of the corresponding input value of the input-output value pair (here, 0) can then be evaluated to determine where control lines for any added control gates should be added. Specifically, dashes in the input values ​​may be ignored, and whenever the input value has a 1, a control line from input line 1302 corresponding to that 1 value to the added gate may be added to circuit 1300a; if the input value has a 0, a control line between two NOT gates may be added to circuit 1300a to control the added controlled gate. Thus, for the input-output pair illustrated in FIG. 13B, there is a 0 in the input value location corresponding to input line 1302d. Therefore, control line 1332d for gate 1330d may be added (coupled) between the two NOT gates 1334 on input line 1302d.

[0071] 13C, the determination and inclusion in circuit 1300a of a second input-output pair 1320b of a functional expression for hashing is depicted, where input value pair 1320b is --0- (e.g., corresponding to input lines 1302a, 1302b, 1302c, and 1302d, respectively), while output value pair is 0010 (e.g., corresponding to output lines 1310a, 1310b, 1310c, and 1310d, respectively).

[0072] Therefore, for each bit in that output value of an input-output pair that is a 1, a controlled gate is included in circuit 1300a, with that gate's target on the output line in circuit 1300 corresponding to that bit. For this second input-output pair 1320b, that corresponds to output line 1302c because the 1 is in the penultimate output location of the output value. Therefore, a (e.g., CNOT or Toffoli) gate 1330c is included in circuit 1300a on output line 1302c based on the value of 1 in the penultimate location of the output value.

[0073] The value of the corresponding input value of the input-output value pair (here, 0) can then be evaluated to determine where the control line for the added control gate 1330c should be added (coupled). For the input-output pair illustrated in Figure 13C, 0 is in the input value location corresponding to input line 1302c. Therefore, control line 1332c for gate 1330c can be added (coupled) between the two NOT gates 1334 on input line 1302c.

[0074] The input-output pairs of the remaining expressions can then be evaluated, and gates can be added to circuit 1300a in a similar manner to yield a reversible hash circuit 1300a for the hash function of the expression. This reversible hash circuit is depicted in FIG. 13D.

[0075] An example of the operation of the reversible hash circuit generated in Figures 13A-13D in a reverse or inverted manner to generate input values ​​for selected output values ​​is depicted in Figure 13E. Here, output 1310 of circuit 1300b is depicted on the left of each figure, and input 1302 of circuit 1300b is on the right of each figure. In other words, an input value (e.g., a set of bit values ​​on input lines 1302) to reversible hash circuit 1300 that produces an output value (e.g., a set of bit values ​​on output lines 1310) when operating the hash function in the forward direction will result in providing the output value of that input-output value pair to circuit 1300b on output lines 1310 when circuit 1300b is operated in the reverse direction.

[0076] Thus, when it is desired to operate hash circuit 1300b in an inverted manner to obtain an input value for a given input-output pair, the output value of the input-output value pair can be selected and provided as an input to circuit 1300b on output line 1310. For illustrative purposes of this example, output value 1001 of input-output value pair 1320c has been selected. It should be noted that all input-output pair values ​​of the hash function corresponding to circuit 1300b are illustrated in FIG. 13E for ease of understanding (rather than a minimized representation of the function). Additionally, while the input values ​​of each of the input-output pair values ​​are depicted here for illustrative purposes, it will be apparent that such input values ​​would not normally be available when it is desired to invert such a function based on the output value, as they are the input values ​​desired to generate.

[0077] Thus, once an output value is selected (e.g., 1001 here), that output value of the input-output value pair can be provided as an input to circuit 1300b on output line 1310, causing circuit 1300b to operate and generate the corresponding input value of input-output value pair 1320c for the hash function on input line 1302 of circuit 1300b. Again, as is standard in the art, the output of circuit 1300b will be held at zero for purposes of explanation.

[0078] Thus, describing the operation of circuit 1300b in an inverting operation, looking first at output line 1310a, a 1 is provided as an input on this output line 1310a, and the resulting output on output line 1310a is a 0. This means that gate 1330a must have been controlled to flip the value on output line 1310a from 1 to 0. Therefore, the value on control line 1332a for gate 1330a must have been 1. Therefore, NOT gate 1340a will flip such a 1 value to a 0, and the output value (w) on input line 1302a will also be 0.

[0079] Similarly, if a 0 is provided as an input on output line 1310b, the resulting output on output line 1310b is 0. This means that gate 1330b must not have inverted the value on output line 1310b. Therefore, the value on control line 1332b for gate 1330b must have been 0. Therefore, NOT gate 1340b will invert such a 0 value to 1, and the output value (x) on input line 1302b will be 1.

[0080] Similarly, if a 0 is provided as an input on output line 1310c, the resulting output on output line 1310b will be 0. This means that gate 1330c must not have inverted the value on output line 1310b. Therefore, the value on control line 1332c for gate 1330c must have been 0. Therefore, NOT gate 1340c will invert such a 0 value to 1, and the output value (y) on input line 1302b will be 1.

[0081] On output line 1310d, a 1 is provided as input, and the resulting output on output line 1310d is a 0. This means that gate 1330d must have been controlled to flip the value on output line 1310d from 1 to 0. Therefore, the value on control line 1332d for gate 1330d must have been 1. Therefore, NOT gate 1340d will flip such a 1 value to 0, and the output value (z) on input line 1302d will also be 0.

[0082] Then, as can be seen, by executing circuit 1300b in an inverted manner and providing output value 1001 as an input to circuit 1300b on output line 1310, the result corresponds to input value 0110 produced as output on input line 1302, and input value 1110 corresponds to output value 1001 in input-output pair 1320c.

[0083] Thus, embodiments may provide systems and methods for efficiently generating inverse hash functions. Efficiently reversing hashes in accordance with embodiments may have several applications that may be important (e.g., to the cybersecurity community). For example, participating in the blockchain ecosystem (including cryptocurrency mining), decrypting website credentials, and forging cryptographic signatures all involve hashes. Embodiments as described herein may generate circuits that directly compute inverse hashes, thereby bypassing the vast set of forward hash calculations involved in brute-force searches. Furthermore, because hash-reversible circuits do not need to be resynthesized in real time, embodiments may be particularly well-suited for tasks involving fixed-size hashes, such as those used in blockchains for fixed-size messages (such as single bank transactions) or in cryptographic signatures.

[0084] Therefore, it may be useful to describe some of these applications. In just one example, embodiments may be applied to blockchain applications, such as cryptocurrency mining. Such mining involves attempting to reverse a hash function that is being calculated on a particular blockchain database. Once the hash function is reversed, it is used to create a "Proof-of-Work" (PoW) that verifies the integrity of a given blockchain input. This mining process typically requires significant computational resources, given that a classical computer is often required to perform a brute-force search (which requires calculating all possible forward hash results for a given blockchain input) to obtain the reverse of the blockchain signature. As mentioned above, applying embodiments as described herein will avoid such an exhaustive search.

[0085] Almost any desired quantum or classical data processing system can be utilized to implement the disclosed embodiments. Such a data processing system may include one or more central processing units (CPUs) or processors coupled to one or more user input / output (I / O) devices or memory devices. Examples of I / O devices may include, but are not limited to, keyboards, displays, monitors, touchscreens, printers, or pointing devices such as mice, trackballs, styluses, touchpads, etc. Examples of memory devices may include, but are not limited to, hard disks (HDs), magnetic disk drives, optical disk drives, magnetic cassettes, tape drives, flash memory cards, random access memory (RAM), read-only memory (ROM), smart cards, etc.

[0086] Those skilled in the art will appreciate that the present invention can be implemented or performed using other computer system configurations, including, but not limited to, multiprocessor systems, network devices, minicomputers, mainframe computers, data processors, etc. The present invention can be embodied in a computer or data processor that is specifically programmed, configured, or constructed to perform the functions described in detail herein. The present invention can also be used in distributed computing environments, where tasks or modules are performed by remote processing devices linked through a communications network such as a LAN, a WAN, and / or the Internet. In a distributed computing environment, program modules or subroutines can be located in both local and remote memory storage devices. These program modules or subroutines can be stored or distributed on computer-readable media, including, for example, magnetic and optically readable and removable computer disks, or stored as firmware in chips, as well as electronically distributed across the Internet or other networks (including wireless networks). An exemplary chip can include an Electrically Erasable Programmable Read-Only Memory (EEPROM) chip. The embodiments discussed herein can be implemented in suitable instructions that can reside in non-transitory computer-readable media, hardware circuits, etc., or any combination, and that can be translated by one or more server machines. Examples of non-transitory computer-readable media are provided below in this disclosure.

[0087] ROM, RAM, and HD are computer memories for storing computer-executable instructions that can be executed by a CPU or compiled or interpreted to be executable by a CPU. Suitable computer-executable instructions may reside in a computer-readable medium (e.g., ROM, RAM, and / or HD), hardware circuitry, etc., or any combination thereof. Within this disclosure, the term "computer-readable medium" is not limited to ROM, RAM, and HD, but can include any type of data storage medium that can be read by a processor. Examples of computer-readable storage media include, but are not limited to, volatile and non-volatile computer memory and storage devices, such as random access memory, read-only memory, hard drives, data cartridges, direct access storage device arrays, magnetic tape, floppy diskettes, flash memory drives, optical data storage devices, compact disc read-only memory, and other suitable computer memory and data storage devices. Thus, computer-readable media may refer to data cartridges, data backup magnetic tapes, floppy diskettes, flash memory drives, optical data storage drives, CD-ROMs, ROMs, RAMs, HDs, etc.

[0088] The processes described herein may be implemented in suitable computer-executable instructions that may reside on a computer-readable medium (e.g., disk, CD-ROM, memory, etc.) Alternatively, or in addition, the computer-executable instructions may be stored as software code components on a direct access storage device array, magnetic tape, floppy diskette, optical storage device, or other suitable computer-readable medium or storage device.

[0089] Any suitable programming language, including Python, can be used to implement the routines, methods, or programs of the invention embodiments described herein. Other software / hardware / network architectures can be used. For example, the functionality of the disclosed embodiments can be implemented on a single computer or shared / distributed among two or more computers in or across a network. Communication between computers implementing embodiments can be achieved using any electronic, optical, radio frequency signal, or other suitable communication methods and tools, in accordance with known network protocols.

[0090] Different programming techniques, such as procedural or object-oriented, may be used. Any particular routine may execute on a single computing device or multiple computing devices, a single computing processor, or multiple computing processors. Data may be stored in a single storage medium or distributed across multiple storages, and may reside in a single database or multiple databases (or other data storage technologies). While steps, operations, or computations may be presented in a particular order, this order may be changed in different embodiments. In some embodiments, to the extent that multiple steps are shown sequentially herein, some combinations of such steps in alternative embodiments may be performed simultaneously. The sequence of operations described herein may be interrupted, paused, or otherwise controlled by another process, such as an operating system, kernel, etc. Routines may operate in an operating system environment or as stand-alone routines. The functions, routines, methods, steps, and operations described herein may be implemented in hardware, software, firmware, or any combination thereof.

[0091] The embodiments described herein can be implemented in the form of control logic in software or hardware, or a combination of both. The control logic can be stored in an information storage medium, such as a computer-readable medium, as a plurality of instructions adapted to instruct an information processing device to perform a set of steps disclosed in various embodiments. Based on the disclosure and teachings provided herein, one skilled in the art will appreciate other ways or methods for implementing the present invention.

[0092] It is also within the spirit and scope of the present invention to implement any of the steps, operations, methods, routines, or portions thereof described herein with software programming or code, which can be stored on a computer-readable medium and executed by a processor to enable a computer to perform any of the steps, operations, methods, routines, or portions thereof described herein. The functionality of the present invention can be achieved in many ways. The present invention can be implemented by using software programming or code in one or more computers, by using application-specific integrated circuits, programmable logic devices, field-programmable gate arrays, optical, chemical, biological, quantum, or nanoengineered systems, or by a combination of many such other computational mechanisms or methods listed above. The present invention can also be implemented using distributed or networked systems, components, and circuits. In distributed system embodiments, communication or transportation of data (or otherwise moving it from one location to another) can be achieved by wired, wireless, offline storage of partial results, or any other similar method.

[0093] As used herein, the terms "comprise," "comprising," "includes," "including," "has," "having," or any other variation thereof, are intended to cover non-exclusive inclusion. For example, a process, product, article, or apparatus comprising a list of elements is not necessarily limited to only those elements, but may include other elements not expressly listed or inherent in such process, product, article, or apparatus.

[0094] Furthermore, as used herein, the term "or" is generally intended to mean "and / or" unless otherwise indicated. For example, condition A or B is satisfied by any one of the following: A is true (or present) and B is false (or absent), A is false (or absent) and B is true (or present), and A and B are both true (or present). As used herein, terms preceded by "a" or "an" (or "the" when the antecedent is "a" or "an") include both the singular and plural forms of such terms (i.e., reference to "a" or "an" clearly indicates only the singular or only the plural). Also, as used in the description herein, the meaning of "in" includes "in" and "on" unless the context clearly dictates otherwise. The scope of the present disclosure is to be determined by the following claims and their legal equivalents.

[0095] Although the present invention has been described with reference to specific embodiments thereof, these embodiments are merely illustrative of the present invention and are not limiting. Throughout the present invention, references throughout this specification to “one embodiment,” “an embodiment,” or “a specific embodiment,” “a specific implementation,” or similar terms mean that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment and may not necessarily be present in all embodiments. Thus, each appearance of the phrase “in one embodiment,” “in an embodiment,” or “in a specific embodiment,” or similar terms in various places throughout this specification does not necessarily refer to the same embodiment. Furthermore, the particular features, structures, or characteristics of any particular embodiment may be combined in any suitable manner with one or more other embodiments. Other variations and modifications of the embodiments described and illustrated herein are possible in light of the teachings herein and should be considered as part of the spirit and scope of the present invention.

[0096] Benefits, other advantages, and solutions to problems have been described above with respect to particular embodiments. However, the benefits, advantages, solutions to problems, and any component(s) that may cause or make more pronounced any benefit, advantage, or solution should not be construed as a critical, required, or essential feature or component.

Claims

1. 1. A system for generating a reversible hash circuit, the system comprising: a processor; Non-transitory computer-readable medium Equipped with The non-transitory computer-readable medium comprises: Obtaining a first representation of a hash function; converting the first representation of a hash function to a second representation of the hash function; generating a reversible hash circuit for the hash function by mapping the second representation of the hash function to a set of reversible gates comprising the reversible hash function; The system includes instructions for:

2. The system of claim 1 , wherein the first representation is a programmable logic array (PLA), a netlist, or a decision tree.

3. The system of claim 1 , wherein the second representation is an exclusive-or-sum-of-products (ESOP) representation.

4. The system of claim 3 , wherein the instructions are further for minimizing the second representation before generating the reversible hash circuit.

5. 2. The system of claim 1, wherein the instructions are further for operating the reversible hash circuit by providing an output value of the hash function to the reversible hash circuit as an input, and operating the reversible hash circuit in a reverse direction to obtain an input value corresponding to the output value.

6. The system of claim 5 , wherein the reversible hash circuit is operated in the classical domain or the quantum domain.

7. 7. The system of claim 6, wherein the reversible circuit is operated in the quantum domain, the output value comprises a set of output values, and the obtained input values ​​comprise a plurality of input values, each input value corresponding to one of the set of output values.

8. 1. A method for generating a reversible hash circuit, the method comprising: Obtaining a first representation of a hash function; converting the first representation of a hash function to a second representation of the hash function; generating a reversible hash circuit for the hash function by mapping the second representation of the hash function to a set of reversible gates comprising the reversible hash function; A method comprising:

9. The method of claim 8 , wherein the first representation is a programmable logic array (PLA), a netlist, or a decision tree.

10. The method of claim 8 , wherein the second representation is an exclusive-or-sum-of-products (ESOP) representation.

11. 11. The method of claim 10, wherein the instructions are further for minimizing the second representation before generating the reversible hash circuit.

12. 9. The method of claim 8, further comprising: operating the reversible hash circuit by providing the output value of the hash function as input to the reversible hash circuit; and operating the reversible hash circuit in a reverse direction to obtain an input value corresponding to the output value.

13. The method of claim 12 , wherein the reversible hash circuit is operated in the classical domain or the quantum domain.

14. 14. The method of claim 13, wherein the reversible circuit is operated in the quantum domain, the output value comprises a set of output values, and the obtained input values ​​comprise a plurality of input values, each input value corresponding to one of the set of output values.

15. 1. A non-transitory computer-readable medium comprising instructions for generating a reversible hash circuit, the generating the reversible hash circuit comprising: Obtaining a first representation of a hash function; converting the first representation of a hash function to a second representation of the hash function; generating a reversible hash circuit for the hash function by mapping the second representation of the hash function to a set of reversible gates comprising the reversible hash function; 1. A non-transitory computer-readable medium, comprising:

16. 16. The non-transitory computer-readable medium of claim 15, wherein the first representation is a programmable logic array (PLA), a netlist, or a decision tree.

17. 16. The non-transitory computer-readable medium of claim 15, wherein the second representation is an exclusive-or-sum-of-products (ESOP) representation.

18. 20. The non-transitory computer-readable medium of claim 17, wherein the instructions are further for minimizing the second representation before generating the reversible hash circuit.

19. 16. The non-transitory computer-readable medium of claim 15, wherein the instructions are further for operating the reversible hash circuit by providing an output value of the hash function to the reversible hash circuit as input, and operating the reversible hash circuit in a reverse direction to obtain an input value corresponding to the output value.

20. 20. The non-transitory computer-readable medium of claim 19, wherein the reversible hash circuit is operated in the classical domain or the quantum domain.

21. 21. The non-transitory computer-readable medium of claim 20, wherein the reversible circuit is operated in the quantum domain, the output value comprises a set of output values, and the obtained input values ​​comprise a plurality of input values, each input value corresponding to one of the set of output values.