Quantum computing method and apparatus for performing prime factorization of an integer, quantum computing method and apparatus for inverting a logic gate circuit

The quantum computing method addresses the challenges of integer factorization by employing short-range quantum interactions and gate-encoded Hamiltonians, facilitating efficient prime factorization with reduced qubit requirements and complexity.

JP7684514B2Active Publication Date: 2025-05-27PARITY QUANTUM COMPUTING GMBH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024508403
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-12
Publication Date
2025-05-27
Estimated Expiration
2041-08-12

AI Technical Summary

Technical Problem

Current quantum algorithms for integer factorization require large numbers of qubits and long-range quantum interactions, which are difficult to implement effectively.

Method used

A quantum computing method that determines a logic gate circuit and uses gate-encoded Hamiltonians to perform short-range quantum interactions, allowing for prime factorization of an integer with a reduced number of qubits and localized interactions.

Benefits of technology

This method enables efficient prime factorization using only short-range quantum interactions, reducing the complexity and scalability issues associated with long-range interactions, and maintaining a manageable number of qubits.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007684514000040
    Figure 0007684514000040
  • Figure 0007684514000041
    Figure 0007684514000041
  • Figure 0007684514000042
    Figure 0007684514000042
Patent Text Reader

Abstract

A quantum computing method for performing prime factorization of an integer includes determining a logic gate circuit (1000) including logic gates (1010-1013, 1020-1023, 1030-1033, 1040-1043), the logic gate circuit configured to compute a multiplication function having an integer as an output. The quantum computing method determines a gate-encoded Hamiltonian (H G ), where each gate-coded Hamiltonian encodes an input / output relationship for one of the plurality of logic gates and is a sum of summand Hamiltonians. The quantum computing method includes providing a quantum system (1100) including components (401-404, 901-904, 911-914), where each summand Hamiltonian of each of the plurality of gate-coded Hamiltonians is associated with a respective component of the quantum system. The quantum computing method includes determining a first set of short-range quantum interactions of the components based on logic gates of the logic gate circuit. The quantum computing method includes determining a second set of short-range quantum interactions of the components based on an integer. The quantum computing method includes performing the first set of short-range quantum interactions and the second set of short-range quantum interactions to evolve the quantum system. The quantum computing method includes measuring at least a portion of the quantum system to obtain a readout. The quantum computing method includes determining prime factors of the integer based on the readout.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments described herein relate to a quantum computing method. The quantum computing method uses a quantum system including components such as qubits. For example, a quantum processing unit acts on the components of the quantum system to process the information carried by the components. Some of the components of the quantum system are measured to reveal the information contained in the components. Based on the readings obtained from the measurements, computational problems are solved. Further embodiments described herein relate to the basic subroutines of quantum computing that operate on a quantum system. Further embodiments described herein relate to an apparatus for executing the disclosed method.

Background Art

[0002] It is a basic mathematical fact that every integer can be decomposed as a product of prime factors. However, the problem of calculating the prime factors of a given integer is known to be computationally difficult. In fact, there is no known algorithm for conventional (classical) computers that can factor an integer during execution and scale as a polynomial of the number of digits of the problem integer. The computational difficulty of this factorization problem forms the basis of encryption protocols such as RSA (Rivest-Shamir-Adleman) widely used in information encryption.

[0003] A quantum computer is a new type of computing device in which information is stored in a quantum system. The quantum system can be composed of a plurality of components such as qubits used for information storage and processing. At the end of quantum computing, information can be read out by performing measurements on at least a part of the quantum system. The quantum system exhibits quantum effects by following the laws of quantum physics. By utilizing such quantum effects, certain computational tasks can be executed faster than known classical algorithms.

[0004] Quantum algorithms for performing integer factorization have been proposed. However, although some of such algorithms may theoretically be capable of performing the task of factoring integers of any size, the actual implementation of such quantum algorithms is empirically very difficult. In particular, the number of qubits required to factor medium-sized integers can be quite large. Furthermore, the quantum interactions required for the implementation of the problem quantum algorithms may be long-range interactions, which are empirically difficult to realize, if not impossible.

[0005] For example, one approach is to formulate the factorization problem as an optimization problem such as a quadratic unconstrained binary optimization (QUBO) problem and use existing quantum algorithms to solve such general QUBO problems. However, such QUBO approaches to integer factorization typically involve long-range quantum algorithms. In some implementations, these long-range interactions can then be removed by mapping the quantum system to another quantum system that can realize integer factorization using only short-range quantum interactions. For example, the first QUBO-related quantum algorithm can be mapped to the quantum hardware graph used in the DWAVE system. The DWAVE system includes only short-range interactions. However, in such additional mapping, the number of qubits required for the resulting quantum system is sacrificed. In particular, the number of qubits required to ensure that only short-range interactions are included can scale as (logN) 4 where N is the size (number of digits) of the integer to be factored. Such quartic scaling can become difficult to handle as the number of digits increases.

[0006] From the above perspectives, an improved quantum algorithm for integer factorization is needed. SUMMARY OF THE INVENTION

[0007] According to one embodiment, a quantum computing method for performing prime factorization of an integer is provided. The quantum computing method includes determining a logic gate circuit including a plurality of logic gates, the logic gate circuit being configured to calculate a multiplication function having an integer as an output. The quantum computing method includes determining, one by one for each of the plurality of logic gates, a gate-encoded Hamiltonian, each gate-encoded Hamiltonian encoding an input-output relationship of one of the plurality of logic gates and being a sum of addend Hamiltonians. The quantum computing method includes providing a quantum system including components, each addend Hamiltonian of each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians being associated with each component of the quantum system. The quantum computing method includes determining a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit. The quantum computing method includes determining a second set of short-range quantum interactions of the components based on the integer. The quantum computing method includes performing the first set of short-range quantum interactions and the second set of short-range quantum interactions, including evolving the quantum system. The quantum computing method includes measuring at least a part of the quantum system to obtain a readout. The quantum computing method includes determining a prime factor of the integer based on the readout.

[0008] According to a further embodiment, a quantum computing method for performing prime factorization of an integer is provided. The quantum computing method includes determining a logic gate circuit including a plurality of logic gates, the logic gate circuit being configured to calculate a multiplication function having an integer as an output. The quantum computing method includes providing a quantum system including components. The quantum computing method includes determining a first set of short-range quantum interactions of the components based on the logic gates. Determining the first set includes, for each logic gate of the plurality of logic gates, determining a subset of the components associated with the logic gate and encoding the logic gate with the short-range quantum interactions of the subset of the components. The quantum computing method includes determining a second set of short-range quantum interactions of the components based on the integer. The quantum computing method includes performing the first set of short-range quantum interactions and the second set of short-range quantum interactions, including evolving the quantum system. The quantum computing method includes measuring at least a part of the quantum system to obtain a readout. The quantum computing method includes determining prime factors of the integer based on the readout.

[0009] According to a further embodiment, a quantum computing or basic subroutine therefor operating on a quantum system including components is provided. The basic subroutine includes determining a basic subsystem of the quantum system including at least four components. Each summand Hamiltonian of a gate-encoding Hamiltonian HAND defined by the following formula is associated with each component of the basic subsystem.

Number

[0010] According to a further embodiment, a basic subroutine for or of quantum computing operating on a quantum system including components is provided. The basic subroutine includes determining a basic subsystem of a quantum system including at least eight components. Each summand Hamiltonian of the gate-encoded Hamiltonian H AND.FA is associated with each component of the basic subsystem.

Number

[0011] According to a further embodiment, a method of performing quantum computing is provided. The method includes providing a quantum system including components. The method includes performing one or more basic subroutines described herein, such as one or more basic subroutines related to AND gates and / or one or more basic subroutines related to AND.FA gates. The method includes measuring at least a portion of the quantum system to obtain a readout.

[0012] According to a further embodiment, a quantum computing method for inverting a logic gate circuit including a plurality of logic gates is provided. The quantum computing method includes providing an output of the logic gate circuit corresponding to an unknown input of the logic gate circuit. The quantum computing method includes determining, one by one for each logic gate of the plurality of logic gates, a gate-encoded Hamiltonian, each gate-encoded Hamiltonian encoding the input-output relationship of one of the plurality of logic gates and being a sum of addend Hamiltonians. The quantum computing method includes providing a quantum system including components, each addend Hamiltonian of each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians being associated with each component of the quantum system. The quantum computing method includes determining a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit. The quantum computing method includes determining a second set of short-range quantum interactions of the components based on the output of the logic gate circuit. The quantum computing method includes performing the first set of short-range quantum interactions and the second set of short-range quantum interactions, including evolving the quantum system. The quantum computing method includes measuring at least a portion of the quantum system to obtain a readout. The quantum computing method includes determining the unknown input of the logic gate circuit based on the readout.

[0013] According to a further embodiment, an apparatus for performing prime factorization of an integer is provided. The apparatus includes a classical computing system. The apparatus includes a quantum system including components. The apparatus includes a quantum processing unit. The apparatus includes a measurement unit. The classical computing system is configured to determine a logic gate circuit including a plurality of logic gates, and the logic gate circuit is configured to calculate a multiplication function having an integer as an output. The classical computing system is configured to determine a gate-encoded Hamiltonian one by one for each logic gate of the plurality of logic gates, and each gate-encoded Hamiltonian encodes the input-output relationship of one logic gate of the plurality of logic gates and is the sum of the addend Hamiltonians. Each addend Hamiltonian of each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians is associated with each component of the quantum system. The classical computing system is configured to determine a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit. The classical computing system is configured to determine a second set of short-range quantum interactions of the components based on the integer. The quantum processing unit is configured to execute the first set of short-range quantum interactions and the second set of short-range quantum interactions and to evolve the quantum system. The measurement unit is configured to measure at least a part of the quantum system to obtain a readout. The classical computing system is further configured to determine prime factors of the integer based on the readout.

[0014] According to a further embodiment, an apparatus for performing integer prime factorization is provided. The apparatus includes a classical computing system. The apparatus includes a quantum system including components. The apparatus includes a quantum processing unit. The apparatus includes a measurement unit. The classical computing system is configured to determine a logic gate circuit including a plurality of logic gates, and the logic gate circuit is configured to calculate a multiplication function having an integer as an output. The classical computing system is configured to determine a first set of short-range quantum interactions of the components based on the logic gates. This determination includes, for each logic gate of the plurality of logic gates, determining a subset of the components associated with the logic gate and encoding the logic gate with the short-range quantum interactions of the subset of the components. The classical computing system is configured to determine a second set of short-range quantum interactions of the components based on the integer. The quantum processing unit is configured to perform the first set of short-range quantum interactions and the second set of short-range quantum interactions and to evolve the quantum system. The measurement unit is configured to measure at least a part of the quantum system to obtain a readout. The classical computing system is further configured to determine the prime factors of the integer based on the readout.

[0015] According to a further embodiment, an apparatus for inverting a logic gate circuit including a plurality of logic gates is provided. The apparatus includes a classical computing system. The apparatus includes a quantum system including components. The apparatus includes a quantum processing unit. The apparatus includes a measurement unit. The classical computing system is configured to provide an output of the logic gate circuit corresponding to an unknown input of the logic gate circuit. The classical computing system is configured to determine, for each of the logic gates of the plurality of logic gates, one by one, a gate-encoded Hamiltonian, each gate-encoded Hamiltonian encoding an input-output relationship of one of the plurality of logic gates and being a sum of addend Hamiltonians. Each addend Hamiltonian of each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians is associated with each component of the quantum system. The classical computing system is configured to determine a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit. The classical computing system is configured to determine a second set of short-range quantum interactions of the components based on the output of the logic gate circuit. The quantum processing unit is configured to develop the quantum system by performing the first set of short-range quantum interactions and the second set of short-range quantum interactions. The measurement unit is configured to measure at least a part of the quantum system to obtain a readout. The classical computing system is further configured to determine the unknown input of the logic gate circuit based on the readout.

[0016] Embodiments also relate to a method of operating the systems described herein and to the use of a system for performing the methods according to the embodiments described herein.

[0017] Further advantages, features, aspects and details that can be combined with the embodiments described herein will be apparent from the dependent claims, the description and the drawings.

Brief Description of the Drawings

[0018] A complete and enabling disclosure to those skilled in the art is described in more detail in the remainder of the specification, including reference to the accompanying drawings.

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15i

Figure 15ii

Figure 15iii

Figure 15iv

Figure 15v

Figure 15vi

Figure 15vii

Figure 15viii

Figure 15ix

Figure 16a)

Figure 16b)

Figure 17

Figure 18

Figure 19

Figure 20A

Figure 20B

DETAILED DESCRIPTION OF THE INVENTION

[0019] Here, various exemplary embodiments are referred to in detail, and one or more examples of each are shown in the respective figures. Each example is provided for illustrative purposes and is not meant to be limiting. For example, features illustrated or described as part of one embodiment can be used in other embodiments or in combination with other embodiments to create yet another embodiment. The present disclosure is intended to include such modifications and variations.

[0020] In the following description of the drawings, the same reference numbers refer to the same components. Generally, only differences regarding individual embodiments are described. The structures shown in the drawings are not necessarily drawn to scale and may include details drawn in an exaggerated manner to enable a better understanding of the embodiments.

[0021] The embodiments described in this specification relate to a quantum computing method for performing prime factorization of an integer. The quantum computing method includes determining a logic gate circuit including a plurality of logic gates, the logic gate circuit being configured to calculate a multiplication function having an integer as an output. The quantum computing method includes determining, one by one for each logic gate of the plurality of logic gates, a gate-encoding Hamiltonian, each gate-encoding Hamiltonian encoding an input-output relationship of one of the plurality of logic gates and being a sum of addend Hamiltonians. The quantum computing method includes providing a quantum system including components, each addend Hamiltonian of each gate-encoding Hamiltonian of the plurality of gate-encoding Hamiltonians being associated with a respective component of the quantum system. The quantum computing method includes determining a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit. The quantum computing method includes determining a second set of short-range quantum interactions of the components based on the integer. The quantum computing method includes developing the quantum system, including performing the first set of short-range quantum interactions and the second set of short-range quantum interactions. The quantum computing method includes measuring at least a part of the quantum system to obtain a readout. The quantum computing method includes determining prime factors of the integer based on the readout.

[0022] The embodiments provide the advantage that the quantum computing method includes only short-range quantum interactions. This is an improvement over other approaches to factorization that require long-range interactions, as long-range interactions may be empirically impossible to realize. In particular, according to some embodiments, the components of the quantum system are arranged on the vertices of a part of a three-dimensional body-centered lattice, specifically, a part of which may include a pair of two-dimensional lattices stacked on top of each other, and the interactions exist only between pairs of adjacent unit cells of the lattice.

[0023] Another advantage is that the number of components of the quantum system is (logN) 2to be scaled. N is the size (number of digits) of the integer to be factored. Thus, for example, (logN) 4 When compared to the QUBO approach to factoring with scaling, the exponent is improved only by a factor of 2.

[0024] Another advantage is that the method provides a scalable approach composed of basic building blocks that can be combined together in a flexible way. This means that as the size of the integer to be factored increases, the corresponding quantum system can be expanded in a modular way by adding further basic groups of components (referred to herein as local subsystems) with little change to the initial quantum system. Similarly, the required short-range quantum interactions are also modular. That is, an increase in the size of the integer can be accounted for by adding new quantum interactions between the additional local subsystems, while the initial short-range interactions can be maintained as they are.

[0025] Another advantage is that the magnitude (strength) of the short-range quantum interactions is limited by a constant expressed mathematically as O(1). That is, the magnitude of the interactions does not increase as the integer to be factored increases, but is independent of the size of the integer. This is in contrast to other approaches that require interactions of magnitude O(N) or more, i.e., interactions of a magnitude that depends on the number of digits of the integer. Such magnitudes are empirically very difficult because, for example, the application of a very strong electromagnetic field is required.

[0026] Quantum system

[0027] The quantum system described in this specification is a physical system that exhibits quantum effects. That is, the quantum system is a real-world object. The quantum system includes components. The components of the quantum system are physical quantum entities themselves and can be regarded as smaller d-level quantum systems that jointly form the quantum system. Specifically, the components of the quantum system can be qubits. A qubit needs to be understood as a physical entity that realizes a two-level quantum system. The components may be d-level quantum systems ( "qudits") with d>2, and only two of the d levels may be used.

[0028] The quantum system can be in different quantum states, such as an initial quantum state (prepared at the start of quantum computing) and a final quantum state (the quantum state that finally ends by quantum computing). The final quantum state can be the ground state of the final quantum Hamiltonian of the quantum system. The quantum Hamiltonian is an observable quantity (that is, a measurable quantity) of the quantum system whose eigenvalues represent the possible energies of the quantum system. The quantum system can evolve from the initial quantum state to the ground state of the final quantum Hamiltonian of the quantum system. Such an evolution is a real-world process, and in particular, it is a controlled technical process (quantum computing) that leads the quantum system from the initial quantum state to an a priori unknown final quantum state containing information about the solution to the computational problem. The said information can be revealed by measuring the quantum system or a part thereof, that is, at least a part of its components. The act of measurement is a physical / technical process. By measurement, the readout of the quantum system can be obtained. The readout of the quantum system is a set of measured values obtained by measuring the components of the quantum system, which involves physical interaction with the components of the quantum system.

[0029] The quantum system can include K qubits, where K can be at least 100, at least 1000, or at least 10000. K can range from 100 to 10000, or from 100 to 100000, although K can be greater than 100000. It should be understood that the quantum systems shown and illustrated in the figures are, for purposes of illustration and explanation, much smaller and are not intended to impose any limitations.

[0030] As described in European Patent No. 3113084, the coupled quantum interaction between groups of components of a quantum system is only achievable when the components of that group are close to each other. A short-range quantum Hamiltonian refers to a Hamiltonian that represents the coupling interaction within a group of components, and the interaction cutoff distance D SR is such that no interaction occurs between components that are separated from each other by a distance greater than the interaction cutoff distance D SR may be a constant distance. The interaction cutoff distance D SR may be much smaller compared to the maximum component distance between components in a particular arrangement of the components of the quantum system. For example, the interaction cutoff distance may be 30% or less, specifically 20% or less, more specifically 10% or less of the maximum component distance. When the components are arranged within a lattice having a basic distance (lattice constant), the short-range quantum Hamiltonian can be such that no interaction occurs between components that are separated from each other by a distance exceeding r times the basic distance (lattice constant) of the lattice. Here, r can be between 1 and 5. For example, r = √2, 2, 3, 4, or 5.

[0031] The quantum interaction represented by the short-range quantum Hamiltonian is referred to as a short-range quantum interaction. The quantum interaction between groups of components of a quantum system is a short-range quantum interaction when the maximum distance between the components within that group is less than or equal to the interaction cutoff distance D SR or less.

[0032] In this specification, the term "classical" is used to distinguish from "quantum". The term "classical" can be understood as "not quantum".

[0033] For example, classical information carriers such as classical bits are distinguished from quantum information carriers such as qubits. A classical bit is an information carrier that can assume two possible values, 0 and 1. A quantum bit (i.e., qubit) is a quantum system having two levels (quantum states) |0> and |1>, and the state space of a qubit includes a continuum of quantum states of the form a|0> + b|1> (using complex coefficients a and b). The components of the quantum systems described in this specification function as quantum information carriers.

[0034] As another example, classical computing systems are distinguished from quantum computing systems. A classical computing system can be understood as a computing system that stores and processes information using only classical information carriers such as classical bits. A classical computing system can include a personal computer or a network of personal computers. In a classical computing system, it may not be possible to use quantum information carriers for information processing. A quantum computing system uses the components of a quantum system as quantum information carriers for storing and processing information. Information can be stored in the components and processed by performing operations on the components (e.g., by providing interactions between the components, by performing measurements on one or more components, etc.). A quantum computing system can be a hybrid system that uses both classical and quantum information carriers. For example, a quantum computing system can include components of a quantum system (e.g., qubits) that function as quantum information carriers, a quantum processing unit (e.g., a system including a laser) for processing the information stored in the components, and a classical computing system connected to the quantum processing unit to instruct the quantum processing unit on which operations to perform.

[0035] As yet another example, a classical Hamiltonian is distinguished from a quantum Hamiltonian. A classical Hamiltonian is a function that describes the interactions between classical entities such as classical spins. A classical spin can be understood as a variable or quantity having a finite, i.e., at least countable, set as its state space. For example, a classical spin can be a variable z that can take two possible states such as +1 and -1. The classical Hamiltonian of a system of classical spins z1, z2, ··· can be a function H(z1, z2, ···) that represents the interactions in the system of classical spins. A quantum Hamiltonian is an observable quantity (mathematically represented by a Hermitian operator acting on a Hilbert space) that represents the quantum interactions between the components of a quantum system. Examples of classical and quantum Hamiltonians are shown below.

[0036] Logic gate circuit

[0037] Logic gates are the basic components of logic gate circuits. Examples of logic gates include AND, OR, NOT, NAND, FA, AND.FA gates, etc. A logic gate has logical variables that include one or more input variables and one or more output variables. The logical variables can be variables that can take two possible values such as 0 or 1 (or equivalently 1 and -1, etc.), i.e., binary variables.

[0038] The truth table of a logic gate is a table, matrix, list, sequence, set, etc. that enumerates all possible configurations of the values of the input variables of the logic gate and gives the corresponding values of the output variables of the logic gate for each such configuration. The truth table of a logic gate may include rows. If a logic gate has k input variables and m output variables (where k and m can be any natural numbers other than zero, including the case where k and / or m equals 1), the rows of the truth table can be understood as sequences of the form a 1 ···a k b 1 ···b m and can be understood as sequences of the form a 1 ,···,a kis a possible configuration of the values of k input variables, and b 1 , ···, b m are the corresponding values of m output variables based on the operation of the logic gates of the problem. If each input variable of the logic gate can take two possible values 0 and 1, the truth table contains a total of 2 k rows. The truth table of a logic gate may have k + m columns. Each of the first k columns can be associated with one of the k input variables. Each of the last m columns can be associated with one of the m output variables.

[0039] For example, an AND gate is a logic gate having two input variables u and v and one output variable s. u, v, and s can each take the value 0 or 1, and s = u · v (thus, s is equal to 1 only when both u and v are equal to 1). The truth table of the AND gate is given by the following table.

Number

[0040] A logic gate can be schematically represented by a box or other shape having one leg for each logic variable of the logic gate. For example, FIG. 1 shows a schematic diagram of an AND gate as a shape having three legs. FIG. 1 shows an AND gate having a first leg 12 representing the input variable u of the AND gate, a second leg 14 representing the input variable v of the AND gate, and a third leg 16 representing the output variable s of the AND gate.

[0041] A logic gate circuit includes a set of logic gates that act on an input x to generate an output y. The input x is x = (x 1 , x 2 , ···, xK ) can be a string in the form of. For example, each component x of the input i is a bit. Similarly, the output y is y = (y 1 , y 2 , ···, y M ) can be a string in the form of. Each component y j is a bit. The length K of the input x (the number of components x i ) may be the same as or different from the length L of the output y (the number of components y j ). A part of the logic gates of the logic gate circuit can be applied concatenated in the sense that the output variable of a logic gate can be used as the input variable of another logic gate (such logic gates are said to be (mutually) connected). The logic gate circuit can be schematically represented by a set of boxes, one for each logic gate of the logic gate circuit, and the legs connecting some of the boxes indicate that the output variables of some gates function as the input variables of other gates.

[0042] Figure 2 shows an example of a logic gate circuit 200 including logic gates 21 to 28. The logic gate circuit maps an input x = (x 1 , x 2 , x 3 , x 4 , x 5 , x 6 , x 7 ) to an output y = (y 1 , y 2 , y 3 , y 4 , y 5 ). Each x i and each y jcan be bits. In the exemplary logic circuit 200 shown in FIG. 2, the calculation proceeds from left to right as indicated by the arrows, with logic gates 21, 22, 23 being applied first and logic gate 28 being applied last. Each logic gate has one or more legs representing the input variables of the logic gate on the left side of the gate and one or more legs representing the output variable on the right side of the logic gate. The left-right division of the legs corresponding to the input and output variables shown in FIG. 2 is merely an example and the present invention is not limited thereto. Some of the legs connect different gates to each other. For example, logic gate 23 and logic gate 25 are connected to each other by leg 15, indicating that the output variable of logic gate 23 functions as the input variable of logic gate 25. Some of the logic gates have common input variables. For example, x 2 is an input variable of logic gate 21 and also an input variable of logic gate 24.

[0043] A logic gate circuit maps each input x of the logic gate circuit to an output y. The function f given by y = f(x) is the function computed by the logic gate circuit. When the input x is given, applying the logic gate circuit to the input x can determine the corresponding output y = f(x). The embodiments described in this specification relate to the inverse problem of inverting a logic gate circuit, that is, the problem where the task is to determine the input x when the output y corresponding to the unknown input x is given. Inverting a logic gate circuit is considered a computationally difficult task even for relatively simple logic gate circuits. For example, considering a logic gate circuit that computes the multiplication of two integers (multiplication is a computationally easy task), inverting such a logic gate circuit corresponds to the task of prime factorization, which is known to be a difficult problem as described above. The difficulty of inverting a logic gate circuit is related to the fact that the logic gates of the logic gate circuit may be irreversible gates. When multiple inputs of a logic gate are mapped to the same output, the logic gate is irreversible, and it is impossible to obtain the input based only on the output. For example, the output 0 of an AND gate can correspond to three possible configurations of the input variables, namely (0, 0), (0, 1), and (1, 0). Based only on the output 0, it is not possible to determine whether the input is (0, 0), (0, 1), or (1, 0).

[0044] The embodiments described in this specification relate to a quantum computing method for inverting a logic gate circuit. Some of the embodiments described in this specification relate to a quantum computing method for performing prime factorization of an integer, that is, a method by considering a logic gate circuit (multiplication circuit) configured to compute a multiplication function.

[0045] The quantum computing method described in this specification includes the step of providing an output y of a logic gate circuit corresponding to an unknown input x of the logic gate circuit. The task performed by this method is to determine the unknown input x from the output y. For example, the output can be an integer n that is the multiplication of two unknown prime numbers p and q (i.e., n = p·q), and the goal is to calculate at least one of the unknown prime factors. The fact that the output y is "provided" will be understood to mean that the output becomes available to the user or device so that subsequent operations of the quantum computing method can be performed. Providing the output can include, for example, obtaining the output from a memory where the output may be stored, receiving the output when the output is transmitted to the user or device from another location, or determining the output (e.g., performing specific preprocessing operations to determine the output).

[0046] Gate-encoded Hamiltonian H G

[0047] The logic gate circuit to be inverted includes logic gates. According to an embodiment, for each logic gate G of a plurality of logic gates, a gate-encoded Hamiltonian H G is determined from the logic gate. The concept of the gate-encoded Hamiltonian includes several aspects described below.

[0048] The gate-encoded Hamiltonian can be a quantum Hamiltonian or a classical Hamiltonian. The gate-encoded Hamiltonian can be a quantum Hamiltonian that represents interactions that may occur in a quantum system, for example, a quantum system including a large number of qubits. Alternatively, the gate-encoded Hamiltonian may be a classical Hamiltonian that represents interactions that may occur in a classical system including a large number of classical spins.

[0049] Furthermore, the gate-encoded Hamiltonian (whether it is a quantum Hamiltonian or a classical Hamiltonian) encodes the input-output relationship of the logic gate. Next, the case where the gate-encoded Hamiltonian is a quantum Hamiltonian will be described. The classical gate-encoded Hamiltonian will be described later.

[0050] When the logic gate G has k input variables and m output variables (k and m can be any non-zero natural numbers, including the case where k and / or m is equal to 1), the corresponding gate-encoded Hamiltonian H G may be a quantum Hamiltonian of k + m qubits having a basis space that encodes the truth table of the logic gate. The basis space may have a basis composed of all 2 1 , ···, a k , b 1 , ···, b m > of the form of quantum states (basis states). Each such quantum state is a state of k + m qubits. Here, a k , ···, a 1 , ···, a k ranges over all possible configurations of the values of the k input variables (for example, since each value is 0 or 1, there are a total of 2k configurations), and b 1 , ···, b m are the corresponding values of the m output variables under the action of the logic gate G. In other words, each quantum state |a 1 , ···, a k , b 1 , ···, b m > may correspond to a row of the truth table of the logic gate G.

[0051] Therefore, the gate-encoded Hamiltonian H of the logic gate G having k input variables and m output variables GIt can be a quantum Hamiltonian representing the quantum interaction in a system of k + m qubits. Briefly, k + m is said to be "the number of qubits of the gate-encoded Hamiltonian", or the gate-encoded Hamiltonian is said to be "the Hamiltonian of k + m qubits". As described above, the first k qubits each correspond to the input variables of G, and the last m qubits each correspond to the output variables of G.

[0052] The gate-encoded Hamiltonian H G 's base space provides a reversible encoding of the action of the logical gate G, even when the logical gate itself is an irreversible gate. The reversible encoding can be understood as an encoding that "remembers" which values of the input variables of G are mapped to which values of the output variables. Therefore, H G 's base space contains information that enables determining, for a given configuration (output configuration) of the values of the output variables of G, which configuration of the values of the input variables is mapped to the said output configuration under the action of the logical gate G. In other words, the information contained in the base space of H G enables the logical gate G to be inverted.

[0053] For example, the gate-encoded Hamiltonian of an AND gate can be a three-qubit quantum Hamiltonian having a base space with a base composed of four quantum states: |0 0 0>, |0 1 0>, |1 0 0>, and |1 1 1>. Each of the above quantum states corresponds to one row of the truth table of the aforementioned AND gate. Representing the input variables of the AND gate as u and v and the output variable as s, the first two qubits of each of the above four quantum states correspond to the input variables u and v, and the third qubit corresponds to the output variable s.

[0054] The gate-encoded Hamiltonian H G considers the truth table of the logical gate G and then the base space corresponding to the truth table in the aforementioned sense, that is, |a 1 , ···, a k , b 1 , ···, bm can be constructed by determining a quantum Hamiltonian having a basis space with a basis of >. Given such a basis space encoding a truth table, there may be several Hamiltonians having the same basis space, so the corresponding gate-encoded Hamiltonian may not be unique. Possible forms of the gate-encoded Hamiltonian are described below.

[0055] The gate-encoded Hamiltonian H associated with the logic gate G G is the sum of the addend Hamiltonians H 1 , H 2 , ···, that is, H G = H 1 + H 2 + ···. According to some embodiments, the gate-encoded Hamiltonian is a quantum Hamiltonian H having the following form G q (the superscript q indicates that this is a quantum Hamiltonian).

Number

[0056] The above form of the gate-encoded Hamiltonian containing only Pauli σ Z operators and their products is illustrative and the present disclosure is not limited thereto. For example, by applying a unitary transformation (change of basis) to some or all of the qubits, the above gate-encoded Hamiltonian H G q can be converted into a gate-encoded Hamiltonian having another form containing, for example, Pauli σ X and / or σ Y operators (represented by X and Z respectively). Such a converted gate-encoded Hamiltonian can also be used for the purposes of the present method as it encodes the same information as the original gate-encoded Hamiltonian, namely the input-output relationship of the logical gates. Further, although the above example refers to the Hamiltonian of a qubit system, other quantum systems can also be used, such as a d-level system in which only two levels are occupied.

[0057] Returning to the example of the AND gate, the corresponding gate-encoded Hamiltonian is the following quantum Hamiltonian which is the quantum Hamiltonian of three qubits (also denoted with the superscript q).

Number

[0058] As described above, the gate-encoded Hamiltonian can be a quantum Hamiltonian or a classical Hamiltonian. Next, the case of a classical gate-encoded Hamiltonian will be described. In this regard, it should be noted that the aforementioned example of a quantum gate-encoded Hamiltonian contains only Pauli σ Z operators. Since such operators commute with each other (i.e., they are diagonal in a common basis), they can be specified by the corresponding classical Hamiltonian. The classical Hamiltonian in question can be obtained by replacing each Pauli operator Z i with a classical spin z i ∈ {1, -1} assuming two possible states such as. For example, the classical gate-encoded Hamiltonian H i corresponding to the quantum Hamiltonian H AND q is given by the following equation, which is the classical Hamiltonian (denoted by the superscript c) of three classical spins. AND c is given by the following equation for the classical Hamiltonian (denoted by the superscript c) of three classical spins.

Number

[0059] More generally, similar to the quantum case, the classical gate - encoding Hamiltonian H of a logic gate G having k input variables and m output variables G c can be a classical Hamiltonian representing interactions within a system of k + m classical spins. k + m is said to be "the number of classical spins of the gate - encoding Hamiltonian", or the gate - encoding Hamiltonian is said to be "a Hamiltonian of k + m classical spins". The classical gate - encoding Hamiltonian can have the following form. [Number] The above form is similar to the aforementioned quantum Hamiltonian H G q but each Pauli operator Z i is replaced by a classical spin z i ∈ {1, - 1}. The product of up to n classical spins may be included in the above formula. Here, n = k + m is the number of classical spins of the gate - encoding Hamiltonian H c . Furthermore, c i , c ij , c ijk ··· are zero or non - zero coefficients, and the non - zero coefficients c i , c ij , c ijk are called the interaction coefficients of the gate - encoding Hamiltonian H G c in this specification, similar to the quantum case. Each term of the above sum where the coefficient in question is non - zero is an addend Hamiltonian of the gate - encoding Hamiltonian H G c . In other words, the classical gate - encoding Hamiltonian H G c is the sum of addend Hamiltonians, and each addend Hamiltonian is a product of a plurality of classical spins (or a single classical spin) given their respective interaction coefficients.

[0060] In the present disclosure, the following notations are used. The gate-encoded Hamiltonian H can be expressed by an equation of the following form.

Number

Number

[0061] According to the embodiments described in this specification, the gate-encoded Hamiltonian (regardless of whether it is a classical Hamiltonian or a quantum Hamiltonian) is determined from each logic gate of the logic gate circuit. The operation of determining the gate-encoded Hamiltonian can be understood, for example, as a classical procedure executed by the classical computing system described in this specification. Determining the gate-encoded Hamiltonian can be understood as determining a description (i.e., a classical description) of the gate-encoded Hamiltonian. Determining the gate-encoded Hamiltonian can be understood as determining classical information that enables the gate-encoded Hamiltonian to be specified, particularly enabling each addend Hamiltonian of the gate-encoded Hamiltonian to be specified. For example, determining the gate-encoded Hamiltonian can include determining the mathematical formula of the gate-encoded Hamiltonian, individually determining the mathematical formula of each addend Hamiltonian, determining which Pauli operators (in the case of quantum) or which classical spins (in the classical case) are included in the gate-encoded Hamiltonian and / or each addend Hamiltonian, determining for which qubits (in the case of quantum) or which classical spins (in the classical case) each addend Hamiltonian is configured to act, determining the interaction coefficients of each addend Hamiltonian, and so on. The term "determine" can also be understood as "calculate" (e.g., by a classical computing system), but can also be understood as "read" (e.g., read from a memory in which the description of the gate-encoded Hamiltonian and / or each addend Hamiltonian is stored), or "receive" (e.g., when the description of the gate-encoded Hamiltonian is calculated elsewhere and then communicated for performing this method, receiving that description).

[0062] Further aspects regarding the gate-encoded Hamiltonian relate to the question of whether the interactions represented by the gate-encoded Hamiltonian are physically implemented. According to some approaches to quantum computing, the gate-encoded Hamiltonian is a quantum Hamiltonian, and these quantum Hamiltonians are physically implemented as part of a quantum computing method for inverting a logical gate circuit. That is, a quantum system (e.g., a system of qubits) can be provided, and the quantum interactions represented by the quantum gate-encoded Hamiltonian can be physically realized within the quantum system to encode a logical gate circuit in the quantum system. However, such an approach to physically implementing the gate-encoded Hamiltonian has the drawback that it may involve long-range interactions between qubits. Long-range interactions typically occur, for example, when logical gates have input variables that are far apart within a logical gate circuit. Actually realizing such long-range interactions can be difficult, if not impossible.

[0063] According to embodiments described herein, the gate-encoded Hamiltonian H G (regardless of whether it is a classical Hamiltonian or a quantum Hamiltonian) need not be physically implemented in an actual physical system. That is, not only the qubits (in the case of quantum) or classical spins (in the classical case) of the gate-encoded Hamiltonian, but also the interactions represented by the gate-encoded Hamiltonian need not be physically implemented. The gate-encoded Hamiltonian H G is determined as an intermediate classical operation. The classical description of each gate-encoded Hamiltonian H G is used to determine a short-range quantum Hamiltonian H G SR , and the latter Hamiltonian H G SR is physically implemented as part of a quantum computing method for inverting a logical gate circuit. The short-range quantum Hamiltonian H G SRrepresents short - range quantum interactions between components of a quantum system. These short - range quantum interactions are different from the interactions represented by the corresponding gate - encoded Hamiltonian H G In fact, the quantum system itself may be completely different from the system related to the gate - encoded Hamiltonian, as will be clarified below. After the short - range quantum Hamiltonian H G SR is determined, the corresponding short - range quantum interactions are physically executed in the quantum system as part of the quantum computing method described herein.

[0064] Local subsystem

[0065] According to the embodiments described herein, a quantum system including components is provided. The quantum system can include local subsystems, each of which can be composed of a subset of the components of the quantum system. The local subsystems can be mutually prime (each component of the quantum system can belong to at most one local subsystem).

[0066] The local subsystem can be a small subsystem of the quantum system. The number of components in the local subsystem may be 30% or less, specifically 20% or less, more specifically 10% or less of the total number of components of the quantum system. The local subsystem may include 20 or fewer components, more specifically 10 or fewer components.

[0067] The local subsystem can be a subset of components. The distance between any two components within the subset is less than or equal to the locality diameter D local of the quantum system. The locality diameter D local may be much smaller than the maximum component distance between components in a specific arrangement of the components of the quantum system. The locality diameter D local can be a constant distance. For example, the locality diameter D localmay be 30% or less, specifically 20% or less, more specifically 10% or less of the maximum component distance. When the components are arranged within a lattice having a basic distance (lattice constant), the local diameter D local may be r times the basic distance of the lattice. Here, r can be from 1 to 5. For example, r = √2, 2, 3, 4, or 5 may be used. The local diameter D local may depend on the spatial arrangement of the components (e.g., whether the components are arranged along a 2D lattice, a 3D lattice, whether the lattice is a square, triangular, or hexagonal lattice, or another geometric structure that is not a lattice, etc.). Further, or alternatively, the local diameter D local may be a function of the maximum range of available physical interactions between the components. In other words, depending on the type of available interactions, components that are at most a predetermined distance apart from each other may be physically coupled. The local diameter D local may be a function of the latter distance.

[0068] For example, when a quantum system is formed by components arranged along a 2D square lattice, a subset of 4 components that form a plaquette (basic square) of the lattice can be considered a local subsystem of the quantum system. Similarly, when the components are arranged along a 3D square lattice, a subsystem composed of the basic cube of the lattice (having 8 components) can be understood as a local subsystem of the quantum system in question. These examples are merely illustrative and the present disclosure is not limited thereto. For example, in the case of a 2D square lattice, a subsystem composed of two adjacent plaquettes, or a subsystem composed of one plaquette and one additional component adjacent to that plaquette, etc., may also be a local subsystem of the quantum system in question depending on the specific local diameter D local of the quantum system.

[0069] Figure 3 shows a quantum system 300 having local subsystems 350. Each local subsystem 350 includes components 320 of the quantum system 300. The number of components of each local subsystem 350 is small compared to the total number of components of the quantum system 300 (in Figure 3, each local subsystem includes 5 or fewer components). The local diameter D local is indicated at 302. The maximum distance between components within each local subsystem 350 is less than the local diameter D local .

[0070] Short-range quantum Hamiltonian H G SR

[0071] According to the embodiments described herein, each gate-encoded Hamiltonian H G (where G is a logic gate of a logic gate circuit) is mapped to a short-range quantum Hamiltonian H G that represents quantum interactions occurring within a local subsystem S G SR of the quantum system. The local subsystem S G is associated with the logic gate G. Possible mappings are described below.

[0072] According to the mapping of the problem, each summand Hamiltonian H G =Σ i H i of the gate-encoded Hamiltonian H i is associated with (or assigned to) each component of the local subsystem S G . In other words, for each summand Hamiltonian H G of the gate-encoded Hamiltonian H i , a corresponding component within the subsystem S G is provided.

[0073] For example, the gate-encoded Hamiltonian H AND of an AND gate = -σ s -σ u σ s -σ v σs +σ u σ v σ s Regarding σ, as described above, this Hamiltonian has four addend Hamiltonians. Therefore, the related local subsystem S AND contains a total of four components, one for each addend Hamiltonian. The four components can be labeled as (s), (u, s), (v, s), and (u, v, s) respectively, corresponding to the exponents that appear in each addend Hamiltonian. Figure 4 shows the local subsystem S AND associated with the AND gate (see Figure 1), and the four components (s), (u, s), (v, s), and (u, v, s) of S AND denoted as 401, 402, 403, and 404 respectively. The components in question are arranged along the basic squares (plaquettes).

[0074] Therefore, note that the number of components associated with the gate - encoded Hamiltonian H G depends on the number of addend Hamiltonians of H G . It should be noted that the number of said addend Hamiltonians is different from, and specifically may be larger than, the number of qubits (in the case of quantum) or classical spins (in the classical case) of H G . For example, as described above, since the gate - encoded Hamiltonian H AND has four addend Hamiltonians, H AND is mapped to a set of four components. In contrast, the Hamiltonian H AND itself is a three - qubit / classical - spin Hamiltonian.

[0075] Figure 5 shows the mapping from the gate - encoded Hamiltonian H G to the components of the local subsystem S G . For the sake of concreteness (but not to limit the scope), the gate - encoded Hamiltonian H G shown in Figure 5 has four addend Hamiltonians H i , and H G = H1 +H 2 +H 3 +H 4 results. For example, the gate-encoded Hamiltonian H G can be the Hamiltonian H AND associated with an AND gate. The quantum system includes a local subsystem S G associated with the gate-encoded Hamiltonian H G . The local subsystem S G includes four components 501, 502, 503, and 504, and each of these four components is associated with one of the addend Hamiltonians H i . The short-range quantum Hamiltonian H G SR (not shown) acts within the local subsystem S G . The above four components are the primary components of the local subsystem S G . As shown in the figure, the local subsystem S G can include additional components (secondary components located at the center of the subsystem S G ) that are not associated with the addend Hamiltonian of H G .

[0076] H G The components associated with the addend Hamiltonian H i can encode the parity of the addend Hamiltonian H i . When the addend Hamiltonian H i is a Pauli operator or a (tensor) product of Pauli operators (such as the Z i Z j Z k ···-form operators that may occur in the gate-encoded Hamiltonian), the correspondence with the components associated with the addend Hamiltonian H i can be defined. Here, the eigenspace of H i with eigenvalue +1 is mapped to the basis state |0> of the component, and the eigenspace of H iThe eigen - space is mapped to the basis state |1> of the component. According to this correspondence, the components of the problem are the addend Hamiltonians H i It is said to encode the parity of. By applying this mapping to each addend Hamiltonian, the gate - encoded Hamiltonian H G is associated with a subset of components that encode the parity of each addend Hamiltonian of H G .

[0077] The local subsystem S G In addition to the aforementioned components related to the addend Hamiltonians of H G , may include additional components. This will be described later.

[0078] The mapping further includes determining the short - range quantum Hamiltonian H G from the gate - encoded Hamiltonian H G SR . The short - range quantum Hamiltonian H G SR represents the short - range quantum interactions within the local subsystem S G . The mapping from H G to H G SR can be configured such that there is a correspondence between the basis spaces of both Hamiltonians. When H G is a quantum Hamiltonian, the basis spaces of H G and H G SR each have a basis of quantum states, and the quantum basis states of the basis space of H G correspond to the quantum basis states of the basis space of H G SR . The correspondence may be a one - to - one correspondence. Similarly, when H G is a classical Hamiltonian, H G SR has a basis of quantum states corresponding to the basis states (classical spin configurations) of H G . Thus, H G and H G SRThe base spaces of both, despite using different encodings, encode the input-output relationships of the corresponding logic gate G. As described above, H G 's base space directly encodes the rows of the truth table of G, while H G SR 's base space encodes the same truth table in an indirect way by encoding it into components related to the parity of the summand Hamiltonians. Nevertheless, based on the information contained in the base space of the short-range quantum Hamiltonian HGSR, the base space of the gate-encoding Hamiltonian H G , and thus the input-output relationship of G, can be derived by inverting the mapping of the problem. Therefore, if the base space of H G SR is known (for example, at the end of a quantum calculation), the truth table of G can be determined based on it.

[0079] The possible forms of the short-range quantum Hamiltonian H G SR will be described below. The short-range quantum Hamiltonian H G SR can be the sum of two Hamiltonians, namely the monomer Hamiltonian H 1-body and the constraint Hamiltonian H cons , so H G SR = H 1-body + H cons .

[0080] The monomer Hamiltonian can be understood as a Hamiltonian that is the sum of monomer summand Hamiltonians, and each monomer summand Hamiltonian acts on a single component of the quantum system. The monomer Hamiltonian can have the form H 1-body = A 1 + A 2 + A 3 + ···. Here, each monomer summand Hamiltonian A i acts only on the α i -th component of the quantum system. For example, H = a 1 Z 1 + a 2 Z 2 + a3 Z 3 + ···, where each a i is a coefficient, and each Z i acts on the i-th component as the Pauli σ Z operator. A Hamiltonian in this form is a monomer Hamiltonian. The monomer Hamiltonian is a d-body Hamiltonian with d = 1.

[0081] The monomer Hamiltonian H G SR forms part of the short-range quantum Hamiltonian H 1-body The function of H G is to encode the information contained in the gate-encoded Hamiltonian H 1-body Specifically, it encodes the information contained in its interaction coefficients. The monomer Hamiltonian H G may be the sum of monomer addend Hamiltonians, and each monomer addend Hamiltonian acts on the S G components associated with each addend Hamiltonian of H G The monomer addend Hamiltonian is a function of the addend Hamiltonian of the problem. For example, if the gate-encoded Hamiltonian H i is expressed as the sum H G = Σ i H i then by replacing each addend Hamiltonian H i with a term of the form a i Z i the monomer Hamiltonian H 1-body can be obtained. Here, a i is a coefficient, and Z i is the Pauli σ i operator acting on the components of the local subsystem S G associated with the addend Hamiltonian H Z Therefore, when H G has the form H G = Σ i H i then H 1-body is H 1-body = Σ i a i Z imay have the form. According to some embodiments, H 1-body each coefficient a i is equal to the interaction coefficient of the corresponding addend Hamiltonian H i or, more generally, can be a function thereof. H in the form of a monomer Hamiltonian containing only Pauli σ Z operators is H 1-body =Σ i a i Z i is merely an example, and it should be understood that the present disclosure is not limited thereto. For example, by applying a change of basis to at least a part of the components, the monomer Hamiltonian can include operators other than Pauli σ Z operators such as X operators and Y operators, and even other (non-Pauli) operators.

[0082] In connection with the example shown in FIG. 5, the gate-encoded Hamiltonian HG is mapped to the short-range quantum Hamiltonian H G SR =H 1-body +H cons The monomer Hamiltonian H 1-body is of the form H 1-body =A 1 +A 2 +A 3 +A 4 Here, the monomer addend Hamiltonians A 1 A 2 A 3 and A 4 act on components 501, 502, 503, and 504, respectively.

[0083] H G For each basis state of H 1-body there may exist a corresponding basis state within the basis space of the monomer Hamiltonian H G However, as described above, since the number of components associated with H G depends on the number of addend Hamiltonians of H G it may be larger than the number of qubits / classical spins of H GAssociating with a set of components of a quantum system may involve an increase in the number of degrees of freedom. Further, there may be dependencies between the addend Hamiltonians of H G (for example, as will be described in detail below, since the product of all the addend Hamiltonians of H G is equal to 1, one of the addend Hamiltonians may be described as the product of the remaining addend Hamiltonians). This may not be reflected in the ground state of H 1-body . Thus, the ground space of the single Hamiltonian H 1-body may include ground states that do not have ground states corresponding to the ground space of H G . The function of the constraint Hamiltonian H cons is to remove this contradiction. The constraint Hamiltonian reduces the dimension of the ground space and ensures the consistency of the mapping by imposing one or more additional constraints on the ground space of H 1-body . That is, it guarantees a correspondence between the ground space of the gate-encoded Hamiltonian H G and the ground space of the short-range Hamiltonian H G SR = H 1-body + H cons .

[0084] For example, according to some embodiments, the product of all the addend Hamiltonians of the gate-encoded Hamiltonian H G may be proportional to the identity. In the case of a quantum gate-encoded Hamiltonian, this means that the product of all the addend Hamiltonians is equal to cI. Here, I is the identity operator and c is a coefficient. In the case of a classical gate-encoded Hamiltonian, this means that the product of all the addend Hamiltonians is a constant c, i.e., a coefficient independent of the classical spin z i ,z j ···. For example, if H G is a classical Hamiltonian or a quantum Hamiltonian given in the following form as described above,

Number

[0085] More generally, according to some embodiments, the product of a subset of the summand Hamiltonians of the gate-encoded Hamiltonian H G can be proportional to the identity. The subset can consist of some or all of the summand Hamiltonians of H G . This property can be enforced on the local subsystem S cons by adding an appropriate constraint Hamiltonian H G . An appropriate constraint Hamiltonian is, for example, a constraint Hamiltonian that is a (tensor) product of Pauli σ Z operators acting on all the components associated with the summand Hamiltonians within a subset of the problem.

[0086] The d-body Hamiltonian (where d is a natural number) can be understood as a Hamiltonian representing the interactions within a group of components of the quantum system that are d or less. The Hamiltonian, which is the sum of the addend Hamiltonians, can be a d-body Hamiltonian if each addend Hamiltonian represents a binding interaction within a group of components that are d or less. The d-body interaction of the components is an interaction that can be expressed by a d-body Hamiltonian.

[0087] The constraint Hamiltonian may be a d-body Hamiltonian. Here, d is a natural number, and d can be 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, or 12. The number d may be 4 or less. The number d may be 3 or more. The number d may be a constant. The constraint Hamiltonian H cons is the sum of the addend Hamiltonians B i , that is, H cons =Σ i B i and may be so. Each addend Hamiltonian of the constraint Hamiltonian can be a Pauli operator (possibly with coefficients). Each addend Hamiltonian may include a Z operator acting on a maximum of d components. Each addend Hamiltonian can have the form C Z···Z and acts on a maximum of d components with a constraint strength C. Alternatively, the constraint Hamiltonian may be a single term, for example, not the sum of multiple addend Hamiltonians but a single Pauli operator. For example, referring to FIG. 5, the constraint Hamiltonian may be a 4-body Hamiltonian of the form H cons =C ZZZZ (single term). It should be understood that the constraint Hamiltonian does not necessarily have to include only Pauli σ Z operators (denoted here as Z). For example, by applying a unitary transformation (change of basis) to some or all of the components, constraint Hamiltonians with different forms can be obtained, including, for example, Pauli σ X operators and / or Pauli σ Y operators, and even other (non-Pauli) operators.

[0088] As described in this specification, the single-body Hamiltonian and the short-range quantum Hamiltonian H G SR The constraint Hamiltonian of can contain only Pauli σ Z operators. The single-body Hamiltonian and the constraint Hamiltonian can be commuting Hamiltonians. All short-range quantum Hamiltonians H G SR associated with the logical gate circuit can be pairwise commuting with each other.

[0089] In the example of the AND gate and the corresponding gate-encoding Hamiltonian below,

Number

Number

[0090] Thus, according to this method, each logical gate G can be associated with a gate - encoded Hamiltonian H G that has a basis space encoding the truth - value table of the logical gate. Next, each gate - encoded Hamiltonian H G is mapped to a short - range quantum Hamiltonian H G SR G =H 1-body +H cons representing short - range quantum interactions between components within a local subsystem S. For this reason, the information contained in the basis space of H G SR enables H GThe ground state, that is, the input-output relationship of the logic gate G can be determined. The gate-encoded Hamiltonian H G is mapped to the short-range quantum Hamiltonian H G SR has the advantage that since H G SR contains only short-range interactions, the long-range interactions that may exist in the gate-encoded Hamiltonian H G are removed.

[0091] FIG. 6 shows the aforementioned mapping. The logic gate G is mapped to the gate-encoded Hamiltonian H G (610). The gate-encoded Hamiltonian H G is mapped to the local subsystem S G of the quantum system (620). The short-range quantum Hamiltonian H G SR = H 1-body +H cons acts within the local subsystem S G and has a basis space corresponding to the basis space of H G .

[0092] Gate-interconnection Hamiltonian, common-variable Hamiltonian

[0093] As described above, according to the embodiments described in this specification, a plurality of mutually prime local subsystems S G are provided, and each local subsystem is associated with the logic gate G of the logic gate circuit. The logic gates of the logic gate circuit are not independent of each other. There may be an interconnection between the logic gates and / or different logic gates may have a common input variable. According to the embodiments described in this specification, such dependencies between the logic gates can be reflected in the quantum system by coupling the corresponding local subsystems to each other.

[0094] The first logic gate G 1 and the second logic gate G 2being connected to each other (that is, in other words, there is an interconnection between two logic gates) means that the output variable of the first logic gate G 1 is input to the second logic gate G 2 , so the output variable of G 1 can be understood as also being the input variable of G 2 . The first logic gate G 1 can be associated with the first local subsystem S G1 and the first short - range quantum Hamiltonian H G1 SR through the aforementioned mapping. The basis space of the first short - range quantum Hamiltonian H G1 SR may have a basis composed of states that (indirectly as described above) encode the input - output relationship of the first logic gate G 1 . Similarly, the second logic gate G 2 can be associated with the second local subsystem S G2 and the second short - range quantum Hamiltonian H G2 SR . The basis space of the second short - range quantum Hamiltonian H G2 SR may have a basis that (also indirectly) encodes the truth - table of the second logic gate G 2 . Deductively, the basis spaces of H G1 SR and H G2 SR are independent of each other. The fact that the output variable of G 1 is also the input variable of G 2 can be regarded as a secondary condition or constraint imposed on the logical variables of the two logic gates in question (that is, a constraint of the form a i =b j . Here, a i is the input variable of G 1 , and b j is the output variable of G 2 ). This secondary condition is the gate - interconnection Hamiltonian H that couples the first local subsystem S G1 to the second local subsystem S G2 ​12 conn This can be enforced in quantum systems as well by introducing the gate interconnection Hamiltonian H 12 conn is the quantum Hamiltonian that describes the quantum interaction between these two local subsystems (herein referred to as the gate interconnection interaction). More specifically, the gate interconnection Hamiltonian is the Hamiltonian H G1 SR +H G2 SR +H 12 conn We can couple the two local subsystems in such a way that the basis space of contains only ground states that obey this side condition. G1 SR +H G2 SR +H 12 conn Each ground state of (Gate-encoded Hamiltonian H G1 and H G2 from the short-range quantum Hamiltonian H G1 SR and H G2 SR ) to find a "valid" configuration of the logic variables of the two logic gates, i.e. the first logic gate G 1 The output variable of the second logic gate G 2 , which may correspond to configurations that are also input variables of . Thus, the gate interconnect Hamiltonian energetically favors (i.e., assigns lower energy to) quantum states that correspond to valid configurations of the logic variables. Further examples and technical details regarding the construction of the gate interconnect Hamiltonian are provided in the "Further Aspects" section below.

[0095] Additionally or alternatively, two logic gates may have a common input variable, i.e. the same logic variable is input to both the first and second logic gates G 1 and a second logic gate G 2may also be an input variable. Similar to what has been described above for gate interconnections, the fact that two logical gates have a common input variable can be regarded as a subsidiary condition that can be enforced within the quantum system by the corresponding Hamiltonian (referred to herein as the common variable Hamiltonian H 12 com-var . The common variable Hamiltonian is a quantum Hamiltonian that can couple the first and second local subsystems in such a way that the basis space of H G1 SR +H G2 SR +H 12 com-var contains only basis states that comply with this subsidiary condition. Each basis state of H G1 SR +H G2 SR +H 12 com-var corresponds to a "valid" configuration of the logical variables of the two logical gates (by reversing the mapping from the gate-encoded Hamiltonian to the first / second short-range quantum Hamiltonian), i.e., a configuration in which the input variable of the problem is a common input variable of the first logical gate G 1 and the second logical gate G 2 . Further examples and technical details regarding the construction of the common variable Hamiltonian will be described in the section "Further Aspects" below.

[0096] When two gates are interconnected and have a common input variable, combinations of gate interconnection Hamiltonians and common variable Hamiltonians can be provided, such as a Hamiltonian of the form H G1 SR +H G2 SR +H 12 conn +H 12 com-var .

[0097] FIG. 7 shows a quantum system 700 associated with the logic gate circuit 200 shown in FIG. 2. The quantum system includes components 750 shown as circles (for ease of representation, only two components are explicitly referred to by reference numeral 750, but it should be understood that each circle in FIG. 7 represents a component of the quantum system). The quantum system includes local subsystems 721-728 respectively associated with the logic gates 21-28 of the logic gate circuit 200 shown in FIG. 2. Each local subsystem includes a set of components (for clarity, each local subsystem is shown as including four components, but the present disclosure is not limited thereto). Each short-range quantum Hamiltonian H G SR acts on each local subsystem as shown by boxes 731-738. Some of the local subsystems are connected by solid lines, representing a gate interconnect Hamiltonian that couples the local subsystems in question. For example, the gate interconnect Hamiltonian couples local subsystem 721 and local subsystem 724, and since the logic gate circuit 200 in FIG. 2 includes a connection between logic gate 21 and logic gate 24, it is shown by the solid line connecting these two subsystems. Some of the local subsystems are connected by dashed lines, representing a common variable Hamiltonian that couples the local subsystems in question. For example, since logic gates 23 and 25 shown in FIG. 2 have a common input variable (i.e., variable x 6 ), the common variable Hamiltonian couples local subsystem 723 and local subsystem 725, and is shown by the dashed line connecting these two subsystems.

[0098] Hereinafter, the term "gate coupling Hamiltonian" shall be used to refer to either a gate interconnect Hamiltonian or a common variable Hamiltonian.

[0099] As described above, the local subsystem S G is an addend Hamiltonian H G of the gate-encoded Hamiltonian H ican include components associated therewith. Such components are referred to herein as the primary components of the local subsystem S G In addition to the primary components, the local subsystem can include one or more secondary components. The secondary components of the local subsystem are not associated with the addend Hamiltonians of the gate-coded Hamiltonian and may be the "additional" components of the local subsystem. The first logical gate G 1 associated with the first local subsystem S G1 is coupled to the second local subsystem S 2 associated with the second logical gate G G2 with respect to the gate coupling Hamiltonian (regardless of whether the gate coupling Hamiltonian is a gate interconnecting Hamiltonian or a common variable Hamiltonian), the gate coupling Hamiltonian can act jointly on one or more components of the first local subsystem and one or more components of the second local subsystem. One or more components of the first local subsystem can include one or more primary components and / or one or more secondary components of the first local subsystem. One or more components of the second local subsystem can include one or more primary components and / or one or more secondary components of the second local subsystem.

[0100] The gate coupling Hamiltonian may be a k-body Hamiltonian. Here, k is a natural number, and k may be 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, or 12. The number k may be 4 or less. The number k may be 3 or more. The number k may be a constant. The gate coupling Hamiltonian may be the sum of addend Hamiltonians. Each addend Hamiltonian of the gate coupling Hamiltonian can be a Pauli operator (possibly with coefficients). Each addend Hamiltonian may include a Z operator acting on up to k components. Each addend Hamiltonian can have the form K Z···Z and can act on up to k components with a coupling strength K. Alternatively, the gate coupling Hamiltonian may be a single term, e.g., a single Pauli operator rather than the sum of multiple addend Hamiltonians. The gate coupling Hamiltonian need not contain only Pauli σ Z operators. It will be understood, for example, that by applying a unitary transformation (change of basis) to some or all of the components, a gate coupling Hamiltonian having a different form can be obtained, which includes, for example, Pauli σ X operators and / or σ Y operators, and further other (non-Pauli) operators.

[0101] Output-encoded Hamiltonian, total Hamiltonian, inversion of the logic gate circuit

[0102] Given a logic gate circuit having logic gates (e.g., a multiplication circuit), a first Hamiltonian H G SR can be considered, which is the sum of all short-range quantum Hamiltonians H 1 over all logic gates G of the logic gate circuit and all gate coupling Hamiltonians (i.e., all gate interconnect Hamiltonians and all common variable Hamiltonians). The first Hamiltonian H 1 is a quantum Hamiltonian acting on the primary and secondary components of the quantum system. The first Hamiltonian H 1has a basis space with a ground state that encodes a valid input-output configuration of a logic gate circuit, i.e., a configuration of logic variables that follows the interconnection of the gates and the secondary conditions resulting from the common variables (if any) according to the respective operations of each logic gate.

[0103] As described above, the object of the method described in this specification is to invert a logic gate circuit. That is, when the output y of a logic gate circuit is given, the problem is to determine the input x corresponding to that output y. The fact that the output of the logic gate circuit is equal to y can be regarded as another secondary condition imposed on the logic gate circuit. Similar to the case of the gate-coupling Hamiltonian, this secondary condition can also be enforced in the quantum system by introducing a second quantum Hamiltonian H 2 in this specification called the output-encoding Hamiltonian. The second quantum Hamiltonian is added to the first Hamiltonian H 1 and energetically prioritizes only the ground state(s) (if there are multiple, then multiple ground states) corresponding to the output y of the problem. The output-encoding Hamiltonian may include one or more primary components and / or one or more secondary components.

[0104] The output-encoding Hamiltonian may be an r-body Hamiltonian. Here, r is a natural number, and r may be 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, or 12. The number r may be 4 or less. For example, the number r may be 2 or more. The number r may be a constant. The output-encoding Hamiltonian can be the sum of addend Hamiltonians. Each addend Hamiltonian of the output-encoding Hamiltonian can be a Pauli operator (possibly with coefficients). Each addend Hamiltonian acts on at most r components with the Pauli σ ZThere may be cases where an operator (denoted as Z in this specification) is included. Each addend Hamiltonian can have the form R Z···Z, and each addend Hamiltonian acts with a coupling strength R on up to r components. Alternatively, the output-encoded Hamiltonian may be a single term, e.g., a single Pauli operator rather than the sum of multiple addend Hamiltonians. The output-encoded Hamiltonian does not necessarily have to contain only Pauli Z operators. It should be understood that, for example, by applying a unitary transformation (change of basis) to some or all of the components, e.g., Pauli X and / or Pauli Y operators, and even other (non-Pauli) operators, output-encoded Hamiltonians with different forms can be obtained. Further examples and technical details regarding the construction of the output-encoded Hamiltonian will be described in the section "Further Aspects" below.

[0105] Taking the above into account, the total Hamiltonian H 1 given by the sum of the first Hamiltonian H 2 and the output-encoded Hamiltonian H TOTAL (the second Hamiltonian) can be considered. Thus, H TOTAL = H 1 + H 2 where H 1 = Σ (all short-range quantum Hamiltonians H G SR ) + Σ (all gate coupling Hamiltonians). H 1 The first sum and the second sum in the above formula for H G SR roughly represent the sum of all short-range quantum Hamiltonians H 2 associated with the logical gate circuit and the sum of all gate coupling Hamiltonians, respectively. Thanks to the output-encoded Hamiltonian H TOTALThe base space has a basis of quantum states that includes only the configuration(s) of logical variables corresponding to the output y, or in other words, the configuration that encodes the unknown input x. Thus, the unknown input x can be determined by evolving the quantum system into a quantum state equal to (or close to) the ground state of the total Hamiltonian H TOTAL and then measuring at least a part of the quantum system.

[0106] For example, when the logic gate circuit is such that a single input x corresponds to the output y, the total Hamiltonian H TOTAL can have a single ground state. This ground state encodes the unknown input x through the mapping from the gate-encoding Hamiltonian to the short-range quantum Hamiltonian H G SR . That is, the ground state contains information that can determine the unknown input x. Thus, when the quantum system is in or close to the ground state of H TOTAL , measuring at least a part of the components and then inverting the aforementioned mapping can determine the unknown input x of the logic gate circuit. Similarly, when the total Hamiltonian H TOTAL has a degenerate base space (multiple ground states), there may be multiple inputs x corresponding to the same output y (i.e., the logic gate circuit may compute a many-to-one function). In such a case, the same procedure can be applied to determine at least one of the unknown inputs x. Also in this case, a measurement is performed and then the mapping is inverted.

[0107] Regarding the measurement, all components associated with one of the summand Hamiltonians of the gate-encoding Hamiltonian H G associated with the logic gate circuit (i.e., all primary components of the quantum system) can be measured, for example, in the standard basis {|0>, |1>}. Based on the readings obtained from these measurements, the mapping described herein can be inverted to determine the unknown input x (e.g., the prime factors of the integer to be factored). Specifically, each local subsystem S GUsing the measurement results obtained from the measurement of the primary components, for each logic gate G of the logic gate circuit, it is possible to determine the configuration (or configurations) of the values of the input variables of G that is consistent with the fact that the output of the logic gate circuit is y. Specifically, this is performed for a subset of all the logic gates G that act directly on the input of the logic gate circuit (for example, in FIG. 2, these are logic gates 21, 22, 23, 24, and 25, and in FIG. 10, all the logic gates act directly on the input of the logic gate circuit), and by inverting the mapping of this specific subset of the logic gates, the input x corresponding to the output y can be determined.

[0108] Alternatively, to determine the unknown input x, it may be sufficient to measure only a subset of the primary components. For example, a local subsystem S corresponding to the aforementioned subset of local gates that act directly on the input of the logic gate circuit G It may be sufficient to measure only the primary components. Furthermore, even within this subset of the local subsystem, it may not be necessary to measure all the primary components. For example, within the same local subsystem S G within, S G There may be a dependency relationship between its primary components in the sense that the quantum state of one or more primary components within S G is determined by the quantum states of the remaining primary components within S. In such a case, it may be sufficient to measure only a subset of the components of S G .

[0109] According to some embodiments, at least a part of the secondary components can be measured, for example, to perform a consistency check.

[0110] As described herein, all the Hamiltonians that appear in the total Hamiltonian (that is, the short-range quantum Hamiltonian H G SR, (gate interconnect Hamiltonian, common variable Hamiltonian, output encoding Hamiltonian) may only include Z operators. Therefore, the total Hamiltonian may be a sum composed of mutually commuting Hamiltonians.

[0111] Furthermore, the interactions represented by the total Hamiltonian may each have a magnitude (represented by the coefficients appearing in the total Hamiltonian) that is bounded by a constant independent of the size of the quantum system (the number of components). This means that even considering a larger logical gate circuit, i.e., a larger quantum system, the magnitude of the interactions (interaction strength) required to implement the quantum computing method may not increase accordingly and may remain within a small constant range.

[0112] AND.FA gate

[0113] The logical gate circuit can include one or more AND.FA gates (where "FA" represents "full adder"). The AND.FA gate has four input variables u, v, s, c and two output variables s’, c’, each of which can take values of 0 and 1. The operation of the AND.FA gate for the input variables is defined by the following relationships. 2c’+s’=s+c+u·v The above equation uniquely defines the values of the output variables as a function of the input variables (for example, when u = v = s = c = 1, the above equation means c’ = s’ = 1).

[0114] The possible gate encoding Hamiltonian of the AND.FA gate is given as follows.

Equation

Number

[0115] The Hamiltonian H AND.FA SR has a basis composed of the quantum states of eight qubits, and each of the basis states corresponds to the basis state of the gate-encoded Hamiltonian H AND.FA . In the gate-encoded Hamiltonian H AND.FA , note that the product of the first four summand Hamiltonians (-σ s σ c σ s’ )(-σ u σ s σ c σ s’ )(-σ v σ s σ c σ s’ )(σ u σ v σ s σ c σ s’ ) is proportional to the identity (each index appears an even number of times). This is reflected in the presence of the first term -k AND.FA SR of the constraint Hamiltonian H cons that ensures that the basis space of H 1 Z (s,c,s’) Z (u,s,c,s’) Z (v,s,c,s’) Z (u,v,s,c,s’) matches this condition. Similarly, in the gate-encoded Hamiltonian H AND.FA , the product of the second set of four summand Hamiltonians (-σ s σ c σ s’ σ c’ )(-σ s σ c’ )(-σ cσ c’ )(σ s’ σ c’ ) is identically proportional. This is the constraint Hamiltonian H AND.FA SR that guarantees that the base space of H cons 's second term -k 2 Z (s,c,s’,c’) Z (s,c’) Z (c,c’) Z (s’,c’) is also consistent with this condition.

[0116] The eight (primary) components can be arranged along the vertices of a cube, and (s, c, s'), (u, s, c, s'), (v, s, c, s') and (u, v, s, c, s') are located at the four lower vertices of the cube (forming the first plaquette of the cube, called the "sum plaquette" herein), and (s, c, s', c'), (s, c'), (c, c') and (s', c') are arranged at the four upper vertices of the cube (forming the second plaquette of the cube, called the "carry plaquette" herein). Thus, the first term of H AND.FA cons acts on the first plaquette formed by the four lower vertices of the cube, and the second term acts on the second plaquette formed by the four upper vertices. Apart from these eight primary components, the local subsystem S AND.FA may contain secondary components. When an AND.FA gate is connected to another logic gate of a logic gate circuit and / or shares a common variable with another logic gate of the logic gate circuit, the secondary components can be acted upon by the gate interconnect Hamiltonian and / or the common variable Hamiltonian. The secondary components can be arranged, for example, at the center of a cube (body-centered cube) composed of eight primary components.

[0117] The Hamiltonian H AND.FA and H AND.FA SR For further technical details regarding and possible forms of the associated gate coupling Hamiltonian, see the "Further Aspects" section.

[0118] FIG. 8 shows a schematic diagram of an AND.FA gate. Input variables u, v, s, c and output variables s’, c’ correspond to respective legs (solid lines) of the AND.FA gate.

[0119] FIG. 9 shows the local subsystem S AND.FA associated with the AND.FA gate shown in FIG. 8. AND.FA The local subsystem S AND.FA includes eight primary components (s, c, s’), (u, s, c, s’), (v, s, c, s’), (u, v, s, c, s’), (s, c, s’, c’), (s, c’), (c, c’) and (s’, c’) arranged at the corners of a cube. Components (s, c, s’), (u, s, c, s’), (v, s, c, s’) and (u, v, s, c, s’), denoted by 901, 902, 903 and 904 respectively, are located at four lower vertices of the cube forming the first placket (“sum placket”). Components (s, c, s’, c’), (s, c’), (c, c’) and (s’, c’), denoted by 911, 912, 913 and 914 respectively, are arranged at four upper vertices forming the second placket (“carry placket”). The local subsystem S AND.FA includes a secondary component 950 arranged at the center of the cube.

[0120] According to some embodiments, the logic gates of the logic gate circuits described herein include and specifically consist of one or more AND gates and one or more AND.FA gates. Each logic gate of the plurality of logic gates can be an AND gate or an AND.FA gate. Such a circuit can be of interest, for example, from the perspective of a quantum computing method for factoring integers as described below.

[0121] Integer factorization

[0122] According to an embodiment, the logic gate circuit can calculate a multiplication function (multiplication circuit). Specifically, the logic gate circuit can calculate the product of two integers p and q. The input x of the circuit may include the binary representations of two integers p and q, and the output y may include the binary representation of the product n = p·q. Therefore, the task of inverting the logic gate circuit is to give an integer n and determine the integers p and q such that n = p·q. When p and q are prime numbers, the numerical value n is called a semi-prime number. Therefore, the task of inverting the logic gate circuit (multiplication circuit) includes the problem of determining the prime factors of the integer n. Therefore, the embodiments described herein include a quantum computing method for prime factorization.

[0123] According to an embodiment, the multiplication circuit may be such that each logic gate is an AND gate or an AND.FA gate. FIG. 10 shows a logic gate circuit 1000 that calculates a multiplication function, that is, a multiplication circuit. Each logic gate of the logic gate circuit is either an AND gate or an AND.FA gate. The AND gates are indicated by 1010, 1011, 1012, and 1013. The AND.FA gates are indicated by 1020, 1021, 1022, and 1023 (the first row of the AND.FA gate), 1030, 1031, 1032, and 1033 (the second row of the AND.FA gate), and 1040, 1041, 1042, and 1043 (the third row of the AND.FA gate). The inputs of the logic gate circuit 1000 are the binary representations p = p 0 2 0 + p 1 2 1 + p 2 2 2 + ··· and q = q 0 2 0 + q 1 2 1 + q 2 2 2 + ··· provided by two integers p and q, where p i and q i are bits. In the simple example shown in FIG. 10, p and q are 4-bit integers, but it is possible to generalize the multiplication circuit to any integer immediately. The output of the multiplication circuit is the integer n = n 02 0 +n 1 2 1 +n 2 2 2 + ··· (n = p·q). In FIG. 10, the calculation proceeds from top to bottom.

[0124] FIG. 11 shows a quantum system 1100 associated with the logic gate circuit 100 of FIG. 10. The quantum system 1100 includes local subsystems 1110, 1111, 1112, and 1113 associated with the AND gates of the multiplication circuit shown in FIG. 10, local subsystems 1120, 1121, 1122, and 1123, local subsystems 1130, 1131, 1132, and 1133, and local subsystems 1140, 1141, 1142, and 1143 associated with the AND.FA gates of the multiplication circuit of FIG. 10. The local subsystems in FIG. 11 may each be local subsystems S AND and S AND.FA and may be constructed according to the mapping described herein. Specifically, each of the local subsystems 1110, 1111, 1112, and 1113 associated with the AND gates may be composed of four components arranged along a plaquette, as shown in FIG. 4 for example. Each of the local subsystems 1120, 1121, 1122, 1123, 1130, 1131, 1132, 1133, 1140, 1141, 1142, and 1143 associated with the AND.FA gates may be composed of eight primary components arranged along a cube and a secondary component arranged at the center of the cube, as shown in FIG. 9 for example. Thus, the quantum system may include two layers of components (primary components) stacked vertically. Each layer is a two-dimensional square lattice, and the secondary component is arranged between the two layers. This form of the quantum system is further shown in FIG. 14.

[0125] For each connection between two logic gates represented by a solid line between the logic gates in FIG. 10, a corresponding gate interconnect Hamiltonian can be provided to couple the corresponding local subsystems, shown by the corresponding solid line in FIG. 11. An exemplary connection between logic gates is shown at 1050 in FIG. 10, and the corresponding gate interconnect Hamiltonian is shown at 1150 in FIG. 11. In the multiplication circuit of FIG. 10, since the connections only exist between adjacent logic gates (in other words, there are no long-distance connections between non-adjacent gates in the multiplication circuit), all gate interconnect Hamiltonians are short-distance Hamiltonians.

[0126] Furthermore, a common variable Hamiltonian, shown by a dashed line connecting the local subsystems in FIG. 11, can be provided to couple local subsystems whose corresponding logic gates have a common input variable. For example, in FIG. 10, the variable q 0 is common to all AND gates of the logic gate circuit, and it can be seen that the AND gates form the top row of gates 1010, 1011, 1012, and 1013 of the multiplication circuit. As described above, the fact that a logic variable is common to a pair of logic gates can be understood as an additional condition imposed on the logic gate circuit. Thus, for each pair of AND gates within the multiplication circuit of FIG. 10, a corresponding secondary condition can be provided to enforce that the variable q 0 is a common input variable for the pair of AND gates in question. However, the resulting secondary conditions are not all independent of each other. In other words, there is redundancy in such a set of all secondary conditions. For example, requiring that q 0 is a common variable for the first AND gate 1010 and the second AND gate 1011, and further requiring that q 0 is a common variable for the second AND gate 1011 and the third AND gate 1012 means that q 0also means that it is a common variable of the first AND gate 1010 and the third AND gate 1012. Therefore, the latter secondary condition for the first AND gate 1010 and the third AND gate 1012 does not need to be explicitly enforced within the quantum system by the corresponding common variable Hamiltonian. Thus, as shown in FIG. 11, it is sufficient to provide a set of common variable Hamiltonians 1151, 1152, and 1153 arranged along a chain corresponding to the rows of the local subsystems 1110, 1111, 1112, and 1113 corresponding to the rows of AND gates for imposing all secondary conditions related to the common variable q 0 In particular, the chain of common variable Hamiltonians 1151, 1152, and 1153 contains only short-range Hamiltonians because each of these common variable Hamiltonians couples adjacent local subsystems. Similar considerations apply to the remaining common variables. For example, q 1 is the common variable of the top row of the AND.FA gates (gates 1020, 1021, 1022, and 1023) of the multiplication circuit, which is enforced by a set of common variable Hamiltonians 1161, 1162, and 1163 arranged in a chain along the corresponding rows of the local subsystems 1120, 1121, 1122, and 1123. Again, the resulting chain of common variable Hamiltonians contains only short-range Hamiltonians because only pairs of adjacent local subsystems are coupled. As yet another exemplary example, p 0 is the common variable of a set of diagonally arranged gates (i.e., gates 1010, 1020, 1030, and 1040) on the right side of the multiplication circuit, which is enforced by common variable Hamiltonians 1171, 1172, and 1173 arranged in a chain along the corresponding diagonally arranged local subsystems 1110, 1120, 1130, and 1140. Again, the resulting chain of common variable Hamiltonians contains only short-range Hamiltonians because only pairs of adjacent local subsystems are coupled.

[0127] Considering the above, when the mapping described in this specification is applied to the multiplication circuit shown in FIG. 10, the resulting gate-coupled Hamiltonian can all be short-range Hamiltonians.

[0128] Short-range quantum Hamiltonian H AND SR and H AND.FA SR The mapping described in this specification for constructing and, the construction of the gate-coupled Hamiltonian reflecting the gate interconnectivity and common variables of the logic gates can be applied to the aforementioned multiplication circuit. Similarly, the integer n to be factored can be encoded into the quantum system by the output-encoded Hamiltonian. In this case, the output-encoded Hamiltonian becomes a two-body Hamiltonian. The quantum system can be evolved to (or at least towards) the ground state of the total Hamiltonian H AND SR and H AND.FA SR , which is the sum of all short-range quantum Hamiltonians H TOTAL , all gate-coupled Hamiltonians, and the output-encoded Hamiltonian. Then, a measurement is performed to give a readout, based on which the unknown input, i.e., the unknown prime factors of n, can be determined. Thereby, a quantum computing method for calculating the prime factors p and q (unknown inputs) based on the integer n (the output of the multiplication circuit) is obtained.

[0129] FIG. 12 shows an apparatus 1200 for performing integer prime factorization. The apparatus 1200 includes a classical computing system 1210, a quantum processing unit 1220, a measurement unit 1230, and a quantum system 1250 including components that can be grouped into a local subsystem shown by the dashed line. The quantum system 1250 can be any quantum system described in this specification, for example, the quantum system 300 (see FIG. 3), the quantum system 700 (see FIG. 7), or the quantum system 1100 (see FIG. 11).

[0130] The classical computing system 1210 is connected to the quantum processing unit 1220 and the measurement unit 1230. The classical computing system 1210 can be configured to send instructions to the quantum processing unit 1220 and / or the measurement unit 1230. The classical computing system 1210 can be configured to receive information from the quantum processing unit 1220 and / or the measurement unit 1230. For example, the measurement results obtained by the measurement unit 1230 can be sent to the classical computing system 1210. The classical computing system 1210 can be configured to determine a logic gate circuit including logic gates. The logic gate circuit can be configured to calculate a multiplication function having an integer as an output. The classical computing system 1210 can be configured to determine a gate-encoded Hamiltonian from the logic gates as described herein, and each addend Hamiltonian of each gate-encoded Hamiltonian of the gate-encoded Hamiltonian is associated with each component of the quantum system. The classical computing system 1210 can be configured to determine a first set of short-range quantum interactions (e.g., interactions represented by the total Hamiltonian) of the components based on the logic gates of the logic gate circuit. The classical computing system 1210 can be configured to determine a second set of short-range quantum interactions (e.g., interactions represented by the output-encoded Hamiltonian) of the components based on the integer.

[0131] The quantum processing unit 1220 and the measurement unit 1230 can be configured to act on the quantum system 1250. The quantum processing unit 1220 can be configured to evolve the quantum system 1250, including executing a first set of short-range quantum interactions and a second set of short-range quantum interactions. The measurement unit 1230 can be configured to measure at least a part of the quantum system 1250 to obtain a readout. The classical computing system 1210 can be configured to determine the prime factors of an integer based on the readout.

[0132] Device 1200 may more generally be a device for inverting a logic gate circuit. Device 1200 may be configured to execute a quantum computing method for inverting a logic gate circuit according to the embodiments described herein.

[0133] Spatial arrangement of components

[0134] The local subsystems of a quantum system can be spatially arranged in a way that reflects the spatial arrangement of the logic gates within a logic gate circuit. This is shown in FIGS. 7 and 11. Referring to FIGS. 7 and 11, it can be seen that the geometric structure in which the local subsystems are arranged corresponds to the spatial arrangement of the logic gates within the associated logic gate circuit (see, for example, FIGS. 2 and 10). Thus, within a logic gate circuit, if logic gate G 2 is located near logic gate G 1 , the associated local subsystems may also be located near each other within the quantum system. A connection between two logic gates of a logic gate circuit (as described herein, meaning that the output variable of the first logic gate functions as the input variable of the second logic gate) is referred to as a short-distance connection if the two logic gates are separated from each other by a distance of less than or equal to the cut-off distance D circuit . The cut-off distance D circuit may be a constant distance. The cut-off distance D circuit can be much smaller compared to the maximum gate distance between logic gates in a particular arrangement of the logic gates of a logic gate circuit. For example, the cut-off distance D circuitIt may be 30% or less, specifically 20% or less, and more specifically 10% or less of the maximum gate distance. When all connections between logic gates in a logic gate circuit are short-distance connections, the logic gate circuit is said to include only short-distance gate interconnections. The gate interconnection Hamiltonian corresponding to the short-distance connections between gates in a logic gate circuit may be a short-distance Hamiltonian. In the case of a logic gate circuit including only short-distance gate interconnections, all corresponding gate interconnection Hamiltonians acting on the associated quantum system can be short-distance Hamiltonians. For example, since the multiplication circuit described in this specification includes only short-distance connections, all associated gate interconnection Hamiltonians are short-distance Hamiltonians.

[0135] Furthermore, the structure of the logic gate circuit may be such that all common variable Hamiltonians acting on the associated quantum system are likewise short-distance Hamiltonians. Consider the set of all logic gates of a logic gate circuit that have a logical variable v as an input variable. Each pair of logic gates taken from this set gives rise to a subcondition of the form "v is a common variable of logic gate X and logic gate Y", which is referred to herein as the common variable subcondition. The set Comm-Var(v) composed of all such common variable subconditions related to the variable v contains redundancy. That is, not all common variable subconditions in the set are independent of each other. For example, the first subcondition "v is a common variable of logic gate G 1 and logic gate G 2 " and the second subcondition "v is a common variable of logic gate G 2 and logic gate G 3 " imply the third subcondition "v is a common variable of logic gate G 1 and logic gate G 3 ". The minimum subset of the common variable subconditions of the variable v is a subset of the common variable subconditions that implies all the remaining common variable subconditions of the variable v. The logic gate circuit is such that for each logical variable that is a common variable of the logic gates in the logic gate circuit, all subconditions within the minimum subset of the common variable subconditions of that logical variable are within the cut-off distance D of the logic gate circuit.circuit When including logic gates separated from each other by the following distance, it is said to include only short - distance common - variable sub - conditions. When a logic - gate circuit includes only short - distance common - variable sub - conditions, all corresponding common - variable Hamiltonians may be short - distance Hamiltonians. For example, as described above, the multiplication circuit described in this specification includes only short - distance common - variable sub - conditions, so all related common - variable Hamiltonians are short - distance Hamiltonians.

[0136] According to an embodiment, a logic - gate circuit may include only short - distance gate interconnections and / or may include only short - distance common - variable sub - conditions. Specifically, a multiplication circuit may include only short - distance gate interconnections and / or may include only short - distance common - variable sub - conditions.

[0137] Development of the quantum system

[0138] A quantum - computing method can include initializing components of a quantum system to an initial state, evolving the quantum system, and measuring at least a part of the components of the quantum system to obtain a readout. The evolution of the quantum system may continue from the initial state to a final state. The final state may be at least approximately equal to the ground state of the total Hamiltonian H TOTAL . When the quantum system is in the final state, measurements can be made on at least a part of the components. An apparatus for performing quantum computing can include a quantum processing unit for initializing the quantum system to the initial state and / or for controlling the evolution of the quantum system. This apparatus may include a measurement unit for performing measurements of the quantum system.

[0139] According to the embodiments described in this specification, a quantum - computing method is the total Hamiltonian H TOTALIncluding developing a quantum system towards its ground state. Developing the quantum system can include performing quantum interactions represented by a total Hamiltonian (specifically, a first set of short-range quantum interactions and a second set of short-range quantum interactions described herein). The act of performing quantum interactions can be understood as performing one or more operations to physically realize or manipulate quantum interactions within the quantum system. The one or more operations can be performed by a quantum processing unit (e.g., including a laser) coupled to the quantum system.

[0140] The development of the quantum system during quantum computing can be controlled by analog driving, particularly adiabatic sweeping (quantum annealing). The background of adiabatic driving (quantum annealing) is described in European Patent No. 3113084. Alternatively, the analog driving can be anti-adiabatic driving using a Hamiltonian having an additional anti-adiabatic part, the background of this technique being described in International Publication No. 2020 / 259813. European Patent No. 3113084 and International Publication No. 2020 / 259813 are incorporated by reference.

[0141] Developing the quantum system may include initializing the quantum system to an initial quantum state. The initial quantum state may be the ground state of an initial Hamiltonian H of the quantum system (or at least close to such a ground state). The initial Hamiltonian H, also called the driving Hamiltonian, may be, for example (but not limited to), a Hamiltonian having a known ground state, such as the Hamiltonian Σ init X init X is a Pauli σ i operator acting on the i-th component of the quantum system. i The initial Hamiltonian and the total Hamiltonian may not commute with each other. For example, the initial Hamiltonian may only include σ i operators, and the total Hamiltonian may only include σ X operators. X operators, and the total Hamiltonian may only include σ Z operators.

[0142] Developing a quantum system can involve gradually transitioning from an initial Hamiltonian through an intermediate Hamiltonian to a total Hamiltonian H TOTAL A family of quantum Hamiltonians H(t) can be considered. Here, t is a time parameter ranging from an initial time t init to a final time t fin and, when t = t init , H(t) equals H init , and when t = t fin , H(t) equals H TOTAL . For a time t between t init and t fin , the Hamiltonian H(t) is an intermediate Hamiltonian. The Hamiltonian H(t) can be a linear combination of the initial Hamiltonian H init and the total Hamiltonian H TOTAL . More generally, the Hamiltonian H(t) can be a linear combination of the initial Hamiltonian H init , a short - range quantum Hamiltonian H G SR associated with a logic gate circuit, a gate - interconnect Hamiltonian associated with the logic gate circuit, a common - variable Hamiltonian associated with the logic gate circuit, and an output - encoding Hamiltonian. Coefficients may be given to each Hamiltonian within the linear combination. The coefficients of the Hamiltonians in the linear combination can be time - dependent functions. Each time - dependent function can represent the strength of each Hamiltonian. The time - dependent functions can describe the relative strength of the Hamiltonians as time progresses. In an exemplary example (but not limiting), t init = 0 and t fin = 1, and the Hamiltonian H(t) can have the following form. H(t)=(1 - t)H init +tH TOTAL In the above equation, when t = 0, H(t) equals H init , and when t = 1, H(t) equals H TOTALbe equal to.

[0143] The transition from the initial Hamiltonian to the total Hamiltonian can include the fade - out of the initial Hamiltonian and the fade - in of the total Hamiltonian. The fade - out may include an adjustment of the intensity of the corresponding Hamiltonian down, represented by a time - dependent function that decreases over time. Conversely, the fade - in may include an adjustment of the intensity of the corresponding Hamiltonian, described by a time - dependent function that increases over time.

[0144] Developing a quantum system can include performing adiabatic evolution (quantum annealing) of the quantum system. The gradual transition from the initial Hamiltonian to the total Hamiltonian may be performed adiabatically. For example, without intending to be bound by a particular theory, considering the adiabatic theorem of quantum mechanics, the quantum state of the quantum system will be in the ground state or, if the transition from the initial Hamiltonian to the total Hamiltonian is performed sufficiently slowly, for all values of the time parameter t from the initial time to the final time, it is well approximated by the ground state of at least all the Hamiltonians H(t). Thus, adiabatic evolution (quantum annealing) develops the initial quantum state at the initial time to the final quantum state at the final time. The final quantum state is the ground state of the total Hamiltonian or is at least well approximated by the ground - state formula of the total Hamiltonian.

[0145] According to some embodiments, the intermediate Hamiltonian H(t) can be a linear combination of the initial Hamiltonian H init , the total Hamiltonian H TOTAL and an additional Hamiltonian H count (the anti - adiabatic Hamiltonian). The Hamiltonian H(t) can be the initial Hamiltonian H init and the short - range quantum Hamiltonian H G SRand a gate interconnectivity Hamiltonian associated with the logic gate circuit, a common variable Hamiltonian associated with the logic gate circuit, an output coding Hamiltonian, and an adiabatic counterdiabatic Hamiltonian H count can be a linear combination including them. Coefficients can be given to each Hamiltonian in the linear combination. As described above, the coefficients of the Hamiltonians in the linear combination can be time-dependent functions. In an exemplary example (however, not limiting the scope), the Hamiltonian H(t) can have the following form. H(t)=A(t)H init +B(t)H TOTAL +C(t)H count Here, A(t), B(t), and C(t) are time-dependent coefficients such that A(t init ) = 1 = B(t fin ) and A(t fin ) = C(t fin ) = B(t init ) = C(t init ) = 0. The adiabatic counterdiabatic Hamiltonian H count may not commute with the initial Hamiltonian H init , and / or may not commute with the total Hamiltonian H TOTAL . For example, the initial Hamiltonian may contain only σ X operators, the total Hamiltonian may contain only σ Z operators, and the adiabatic counterdiabatic Hamiltonian H count may contain only σ Y operators. For example, the adiabatic counterdiabatic Hamiltonian H count may have the form of Σ i b i Y i . Here, Y i is the Pauli σ Y operator acting on the i-th component of the quantum system, and each b i is a coefficient. The adiabatic counterdiabatic Hamiltonian H countBy having an intermediate Hamiltonian that includes [description], a broader space of possible "paths" for evolving the initial Hamiltonian into the total Hamiltonian becomes available. Using this larger space, the time required to evolve the initial Hamiltonian into the total Hamiltonian can be shortened. Therefore, a faster execution time for solving computational problems can be provided. Specifically, by passing through an intermediate Hamiltonian that includes an anti-adiabatic Hamiltonian, the initial Hamiltonian can be evolved into the total Hamiltonian according to an adiabatic process (or non-adiabatic process, anti-adiabatic process) while remaining sufficiently close to the ground state of the quantum system throughout the evolution. By passing through an intermediate Hamiltonian that includes an anti-adiabatic Hamiltonian, the evolution from the initial Hamiltonian to the total Hamiltonian is carried out adiabatically, that is, faster than the rate allowed by the adiabatic theorem, and at the same time, a ground state close to the ground state of the total Hamiltonian can be reached.

[0146] The evolution of a quantum system during quantum computing can be controlled by digital driving, particularly gate-based quantum computing. In gate-based quantum computing, quantum computing is driven by applying a sequence of unitary operators to the initial state of the quantum system. The sequence of unitary operators and their parameters can be optimized in N operations by reading out (measuring) the quantum system at least one previous time and applying an optimized sequence at a later time using classical feedforward. The background of gate-based quantum computing technology is described in International Publication No. WO 2020 / 156680. International Publication No. WO 2020 / 156680 is incorporated by reference.

[0147] The goal of gate-based quantum computing is first to minimize the energy E min = min <Ψ|H TOTAL |Ψ>. Once the minimum (or an acceptable low level) of energy is determined, the components are read out by measurement when they are in the quantum state having the minimum (acceptable low level) of energy. The quantum state of the problem is the total Hamiltonian H TOTALSince the readout contains information about the prime factors of the integer y being factored, (more generally, if the logic gate circuit is not a multiplier circuit, the readout contains information about the unknown input that corresponds to the output y). Now,

number

[0148] The minimization can be performed by a variational method that individually changes variational parameters such as α 1 ···α m , β 1 ···β m at different numbers of operations. Comparing the energies obtained at different numbers of operations, a sequence of unitary operators that yields a smaller energy is selected, and the parameters can be further changed by a small perturbation using the selected sequence. In this way, the next round of optimization may depend on the classical information of the previous round before being fed forward, and the energy always decreases or at least does not increase. Details of such a variational method are described in International Publication No. WO 2020 / 156680.

[0149] The unitary operator U Hinit is local and can be realized by single-qubit rotations and phase rotations. The unitary operator U H TOTAL , more specifically, the propagation function of each constraint Hamiltonian can be realized by CNOT gates and single-qubit rotations (R z ) as described in International Publication No. WO 2020 / 156680.

[0150] The quantum computing method described herein may include determining a sequence of unitary operators. The unitary operators within the sequence can be obtained from the following set of unitary operators. That is, a unitary operator that is a function of the initial Hamiltonian, a short-range quantum Hamiltonian H G SRThey are unitary operators that are functions of, unitary operators that are functions of the gate connection Hamiltonian, unitary operators that are functions of the common variable Hamiltonian, and unitary operators that are functions of the output encoding Hamiltonian. The function may be an exponential function. The unitary operator can be the propagation function of the aforementioned Hamiltonian. The function may contain variational parameters. Each unitary operator in the sequence of unitary operators may be attached with its own variational parameter.

[0151] Developing a quantum system can include applying a sequence of unitary operators to the quantum system, specifically to the initial state of the quantum system. The initial state may be the ground state of the initial Hamiltonian. When applying the sequence of unitary operators, the parameters of the unitary operator may be in a first configuration. The method may include measuring at least a part of the components of the quantum system after applying the sequence of unitary operators to obtain a first readout. The method may also include deriving a first energy from the first readout, and the first energy may be the energy of the total Hamiltonian of the quantum state obtained as a result of applying the sequence of unitary operators to the initial state.

[0152] The method may include applying a second sequence of unitary operators to a quantum system, specifically to an initial state of the quantum system. When applying the second sequence of unitary operators, the parameters of the unitary operators may be a second configuration different from the first configuration. The method may include measuring at least a part of the components of the quantum system after applying the second sequence of unitary operators to obtain a second readout. The method may include deriving a second energy from the second readout, and the second energy may be the energy of the total Hamiltonian of the quantum state obtained as a result of applying the second sequence of unitary operators to the initial state. The method may include selecting the first or second sequence according to the first and second readouts, specifically selecting the first sequence when the first energy is lower than the second energy, and selecting the second sequence when the second energy is smaller than the first energy.

[0153] The method may include applying a third sequence of unitary operators to a quantum system, specifically to an initial state of the quantum system. When applying the third sequence of unitary operators, the parameters of the unitary operators may be a third configuration. When the first sequence is selected, the third configuration is a variation of the first configuration, and when the second sequence is selected, the third configuration is a variation of the second sequence. The method may be able to include N operations, where N≥2, and each of the N operations may include applying the i-th sequence of unitary operators with the parameters in the i-th configuration, and may include measuring at least a part of the components of the quantum system to obtain the i-th readout. The method may include deriving the i-th energy from the i-th readout, and the i-th energy may be the energy of the total Hamiltonian of the quantum state obtained as a result of applying the i-th sequence of unitary operators to the initial state. The i-th configuration of the parameters may be determined based on one or more readouts (or one or more energies) of the previous operation. The i-th configuration may be determined such that the energy of the quantum state corresponding to the selected configuration decreases (or at least does not increase).

[0154] The method may include applying a final sequence of unitary operators to the quantum system, specifically to the initial state, after the N-th operation, to evolve the quantum system to a final state. The final sequence may be selected such that the configuration of its parameters provides the minimum value of N energies determined by the N operations. The method may include measuring the quantum system or at least a part thereof when the quantum system is in the final state. The method may include determining, from the reading of this measurement value, the prime factors of the integer to be factored (or, more generally, the unknown input x corresponding to the known output y of a logic gate circuit).

[0155] Evolving the quantum system may include cooling the quantum system towards the ground state of the total Hamiltonian, which can be performed by a cooling unit. The ground state of the quantum Hamiltonian is a quantum state with zero temperature. Thus, by cooling the quantum system to a sufficiently low temperature, it is possible to prepare at least approximately the ground state of the total Hamiltonian. Such a cooling process can bring the quantum system to the ground state (or a state close thereto) of the total Hamiltonian, for example, without the need to further perform adiabatic, anti-adiabatic or gate-based evolution.

[0156] Exemplary execution of the quantum system

[0157] As described herein, the quantum system and its components (such as qubits) are physical entities. Hereinafter, the specific implementation of the interactions included in the quantum system / components and the quantum computing method will be described. However, the method can be performed for other specific implementations of the physical entities and their interactions, and the exemplary implementations are not considered to be limiting.

[0158] The component can be a superconducting qubit, such as a transmon or a flux qubit. The superconducting qubit can include a primary and a secondary superconducting loop. Superconducting currents propagating clockwise and counterclockwise respectively within the primary superconducting loop can form the quantum ground states |1> and |0> of the superconducting qubit. Further, a magnetic flux bias through the secondary superconducting loop can couple the quantum ground states |0> and |1>.

[0159] The single-body Hamiltonian can be realized by a plurality of magnetic fluxes that interact with the superconducting qubit. The magnetic flux or magnetic flux bias may extend through the primary and secondary superconducting loops of the superconducting qubit. The parameters of the single-body Hamiltonian can be adjusted by adjusting a plurality of magnetic fluxes or magnetic flux biases. Alternatively, the single-body Hamiltonian can be realized by a plurality of charges that interact with a plurality of superconducting qubits. The parameters of the problem Hamiltonian can be adjusted by adjusting a plurality of charge bias fields. To realize the single-body drive Hamiltonian (e.g., from the perspective of adiabatic evolution), the magnetic flux bias through the primary superconducting loop of the superconducting qubit can be set such that the ground states |0> and |1> have the same energy, i.e., the energy difference between these ground states is zero. Further, the magnetic flux bias through the secondary superconducting loop can couple the ground states |0> and |1>. As a result, the addend Hamiltonian of the drive Hamiltonian in the form of hσ x (k) and thus the drive Hamiltonian in the form of H drive =hΣ k σ x (k) can also be realized for a plurality of superconducting qubits.

[0160] The d-body Hamiltonian (gate-interconnection Hamiltonian, common-variable Hamiltonian, output-encoding Hamiltonian) acting on a group of d qubits (e.g., a plaquette) can be realized using an auxiliary qubit. The auxiliary qubit can be placed within the group of d qubits (e.g., at the center of the plaquette). ckm σ z (k) σ z (m) The interaction between qubits in the form of can be realized by a coupling unit, for example, an inductive coupling unit. The coupling unit includes a superconducting quantum interference device. When an adjustable magnetic flux bias is applied to the superconducting quantum interference device, the coefficient c km can be adjusted. The d-body Hamiltonian can be realized by C(σ z (1) +σ z (2) +···σ z (d) -2σ z (p) -1) 2 This includes only the form σ z (k) σ z (m) corresponding to the energy difference imposed between the quantum ground states of |0> and |1> and the pair interaction of the single-body σ z (l) terms. Here, σ z (p) represents an auxiliary qubit. Alternatively, a d-body Hamiltonian such as a plaquette Hamiltonian can also be realized without an auxiliary qubit, for example, by using a three-island superconducting device as a transmon qubit. By integrating two additional superconducting quantum interference devices into the coupling unit and capacitively coupling the four qubits of the plaquette to a coplanar resonator, a constraint Hamiltonian in the form of -Cσ z (1) σ z (2) σ z (3) σ z (4) can be realized. The coupling coefficient C can be adjusted by a time-dependent magnetic flux bias through two additional superconducting quantum interference devices.

[0161] The qubit states |0> and |1> of a superconducting qubit can be measured with high fidelity using a measurement device that includes a plurality of superconducting quantum interference devices, specifically N hysteresis DC superconducting quantum interference devices, and latches of N RF superconducting quantum interference devices controlled by bias lines (the number of bias lines varies according to √N).

[0162] Alternatively, the quantum system may be realized using a system of ions trapped as qubits. In this case, the quantum ground states |0> and |1> of the qubits are formed by two energy levels of a Zeeman manifold or hyperfine manifold, or by crossing forbidden optical transitions of positively charged ions such as Ca40+ that are alkaline earth or like alkaline earth. Individual ions can be addressed by spatial separation or energy separation. In the case of spatial separation, it includes the use of a laser beam that has passed through and / or been reflected by an acousto-optic deflector, acousto-optic modulator, micromirror device, etc. In the case of energy separation, it includes the use of a magnetic field gradient that changes the internal transition frequency, which enables selection by energy difference, i.e., detuning of the applied magnetic field. The single-body Hamiltonian can be realized by a laser field or microwave that resonates or non-resonates with the internal transition, or by a difference in spatial magnetic fields. The interaction between ions can be transmitted via a phonon bath. For this purpose, a laser or microwave detuned with respect to the blue side and / or red side band transitions of phonons can be used. The intensity and detuning of the laser can adjust the strength of the interaction. Direct interaction by Rydberg excitation can also be used. The ions can be initialized (prepared in the initial state) by optical pumping using a laser that deterministically transfers the ion to one of the two quantum ground states. Since this process reduces entropy, it can be regarded as cooling the internal state of the ion. The single-body unitary operator exp(itσ x ) or exp(itσ z) can be realized by controlled magnetic dipole transitions or controlled Raman transitions. Measurements of ion-based quantum systems can be performed by fluorescence spectroscopy. There, when an ion is in one of two spin states, the ion undergoes a transition with a short lifetime. As a result, the ions in the driven state emit many photons, while the other ions remain dark. The emitted photons can be recorded with a commercially available CCD camera. Measurements in any direction on the Bloch sphere are performed by appropriate single-qubit pulses prior to fluorescence spectroscopy.

[0163] As yet another alternative, the quantum system may be realized using ultracold atoms trapped in an optical lattice or a lattice with a large spacing from a laser field, such as ultracold neutral alkali atoms. The atoms can be evolved towards the ground state using laser cooling. The quantum ground state of the qubit can be formed by the ground state of the atom and the higher Rydberg state. The qubit can be addressed by laser light. The single-body Hamiltonian can be realized by a change in the detuning of the electronic transition frequency with respect to the laser frequency. The interaction between qubits can be controlled by the detuning of the laser that excites d atoms. In this case, the Hamiltonian is a d-body Hamiltonian. The d-body Hamiltonian can be executed from d-body interactions or from ancillary qubits having two-body interactions. The initial state can be prepared by exciting an atom in the ground state to the Rydberg state with a large detuning. The single-body unitary operator exp(itσ x ) or exp(itσ z ) can be realized by detuned laser driving of the Rydberg transition. The qubit can be measured by performing a selective sweep of the ground state atoms and fluorescence imaging with single-site resolution.

[0164] As yet another alternative, the quantum system may be realized using quantum dots. Quantum dot qubits can be fabricated from GaAs / AlGaAs heterostructures. The qubits are encoded in spin states, which can be prepared by adiabatically tuning the potential from a single well to a double well potential. The single qubit Hamiltonian can be realized using an electric field. In the initial state, each qubit is prepared in the state |0> or |1>. This is carried out by adiabatically switching from a single well to a double well using a strong additional magnetic field. The interaction between two qubits can be adjusted by an electric field gradient and a magnetic field. The d - qubit Hamiltonian can be realized by using additional auxiliary qubits and interactions realized with pulse sequences and magnetic fields. The single qubit unitary operator exp(itσ x ) or exp(itσ z ) can be realized using an electrical pulse sequence and a magnetic field. Quantum dot qubits can be read out from the pulse sequence by rapid adiabatic passage.

[0165] As yet another alternative, the quantum system can be realized using impurities in a solid crystal, such as an NV center which is a point defect in a diamond crystal. Other impurities, such as color centers associated with chromium impurities, rare earth ions within a solid crystal, or defect centers in silicon carbide, may be used. The NV center has two unpaired electrons and provides a ground state of spin 1. This enables the identification of two sharp defect levels with long lifetimes that can be used, perhaps in combination with the surrounding nuclear spins, to realize qubits. By using magnetic resonance by applying microwave pulses, the qubit state can be coherently manipulated on a nanosecond timescale. Selective single qubit operations can also be achieved conditional on the state of nearby nuclear spins. The interaction between NV centers to realize a short-range Hamiltonian can be mediated by coupling the NV centers to an optical field. In the case of a quantum system realized using NV centers, the NV centers can be individually addressed by using standard optical confocal microscopy techniques. Initialization (preparation of the initial state) and measurement can be performed by non-resonant or resonant optical excitation. Single qubit operations are performed by coupling the nuclear spins to the electron spin and driving the electron spin with microwaves.

[0166] Embodiment

[0167] According to one embodiment, a quantum computing method for performing prime factorization of an integer is provided. The quantum computing method includes determining a logic gate circuit including logic gates, the logic gate circuit being configured to calculate a multiplication function having an integer as an output. The quantum computing method includes determining, one by one for each of the plurality of logic gates, a gate-encoded Hamiltonian, each gate-encoded Hamiltonian encoding the input-output relationship of one of the plurality of logic gates and being a sum of addend Hamiltonians. The quantum computing method includes providing a quantum system including components, each addend Hamiltonian of each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians being associated with each component of the quantum system. The quantum computing method includes determining a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit. The quantum computing method includes determining a second set of short-range quantum interactions of the components based on the integer. The quantum computing method includes evolving the quantum system, including executing the first set of short-range quantum interactions and the second set of short-range quantum interactions. The quantum computing method includes measuring at least a part of the quantum system to obtain a readout. The quantum computing method includes determining prime factors of the integer based on the readout.

[0168] The statement that the logic gate circuit is "determined" can be understood to mean that the description of the logic gate circuit becomes available to the user or device so that subsequent operations of the quantum computing method can be performed. Determining the logic gate circuit can include, for example, retrieving the description of the logic gate circuit from the memory in which it is stored, receiving the description of the logic gate circuit, for example, receiving the description when the description of the logic gate circuit is transmitted to the user or device from another location, or calculating the description, for example, by performing a specific preprocessing operation to determine what the description of the logic gate circuit is.

[0169] The term "one" in the expression "determine a gate-encoded Hamiltonian for each of a plurality of logic gates, one by one" should be understood to mean that for each of the plurality of logic gates, "one" gate-encoded Hamiltonian is determined. The expression in question does not exclude the determination of a plurality of, i.e., one or more, gate-encoded Hamiltonians for a given logic gate. That is, the term "one" in the foregoing expression should be understood not in the limited sense of "only one", but rather in the sense of "at least one", or in other words, "one, and in some cases more than one".

[0170] Each of the plurality of gate-encoded Hamiltonians may be a classical Hamiltonian or a quantum Hamiltonian. Each of the plurality of gate-encoded Hamiltonians can have a basis space that encodes the input-output relationship of one of the plurality of logic gates. The basis space can encode the truth table of the logic gate. Each of the plurality of gate-encoded Hamiltonians can encode the input-output relationship of a logic gate having logical variables, and the logical variables include one or more input variables (e.g., u, v, ···) and one or more outputs (e.g., s', c', ···) of the logic gate. The gate-encoded Hamiltonian may include, for each logical variable of the logic gate, one by one, spin observables (e.g., σ u , σ v , σ s’ , σ c’ ···). Each spin observable can be a classical spin or a quantum observable.

[0171] Each of the plurality of gate-encoded Hamiltonians may be a classical Hamiltonian or a quantum Hamiltonian. Each of the plurality of gate-encoded Hamiltonians can have a basis space that encodes the input-output relationship of one of the plurality of logical gates. The basis space can encode the truth table of the logical gate. Each of the plurality of gate-encoded Hamiltonians can encode the input-output relationship of a logical gate having logical variables, and the logical variables include one or more input variables (e.g., u, v, ···) and one or more outputs (e.g., s’, c’, ···) of the logical gate. The gate-encoded Hamiltonian may include one spin observable (e.g., σ u , σ v , σ s’ , σ c’ ···) for each logical variable of the logical gate. Each spin observable can be a classical spin or a quantum observable.

[0172] Determining the first set of short-range quantum interactions can include, for each of the plurality of gate-encoded Hamiltonians, determining short-range quantum interactions from the gate-encoded Hamiltonian. The short-range quantum interactions can be the interactions represented by the short-range quantum Hamiltonian H G SR described herein. The determined short-range quantum interactions may be included in the first set of short-range quantum interactions. The determined short-range quantum interactions may act within the local subsystem associated with the gate-encoded Hamiltonian. Executing the first set of short-range quantum interactions described herein can include executing the determined short-range quantum interactions. The short-range quantum interactions and / or the short-range quantum Hamiltonian H G associated with the gate-encoded Hamiltonian H G SR is the gate-encoded Hamiltonian H GIt can be configured to encode the input-output relationship of the logic gate G in the local subsystem associated therewith. A single-body interaction can be understood as an interaction that can be represented by the single-body Hamiltonian of a quantum system. A single-body interaction can be realized, for example, by interacting a single component of a quantum system with an external field.

[0173] Determining the first set of short-range quantum interactions described herein may include, for each gate-encoded Hamiltonian of a plurality of gate-encoded Hamiltonians, determining a single-body interaction from the gate-encoded Hamiltonian. The determined single-body interaction may be included in the first set of short-range quantum interactions. Executing the first set of short-range quantum interactions may include executing the determined single-body interaction. The determined single-body interaction may be represented by a single-body Hamiltonian H operating within the local subsystem associated with the gate-encoded Hamiltonian. 1-body Each addend Hamiltonian of each gate-encoded Hamiltonian of a plurality of gate-encoded Hamiltonians may have an interaction coefficient. The interaction coefficient may be mapped to one of the plurality of single-body interactions. A single-body interaction may be a function of the interaction coefficient.

[0174] Determining the first set of short-range quantum interactions described herein may include, for each gate-encoded Hamiltonian of a plurality of gate-encoded Hamiltonians, determining one or more constraint interactions from the gate-encoded Hamiltonian. The one or more constraint interactions may be included in the first set of short-range quantum interactions. Executing the first set of short-range quantum interactions may include executing the determined one or more constraint interactions. The one or more constraint interactions are constraint Hamiltonians H acting within the local subsystem associated with the gate-encoded Hamiltonian. consIt may be representable by. The constraint interaction and / or constraint Hamiltonian determined from the gate-encoded Hamiltonian can be configured to provide consistency between the qubits or classical spins of the gate Hamiltonian and the components associated with the summand Hamiltonians of the gate-encoded Hamiltonian. The constraint interaction and / or constraint Hamiltonian can be configured to match the ground space of the short-range quantum Hamiltonian H G SR to one or more properties of the gate-encoded Hamiltonian H G Each of the one or more properties can be defined such that the product of a subset of the summand Hamiltonians of the gate-encoded Hamiltonian H G is proportional to the identity, or the product of all summand Hamiltonians of H G is proportional to the identity.

[0175] The logic gate circuit described in this specification can include gate interconnections between pairs of logic gates. When the same logic variable is both the output variable of a first logic gate and the input variable of a second logic gate, there is a gate interconnection between the first logic gate and the second logic gate. Determining a first set of short-range quantum interactions can include, for each gate interconnection of a plurality of gate interconnections, determining a gate interconnection interaction or a set of gate interconnections from the gate interconnection. Each gate interconnection or set of gate interconnection interactions determined from the gate interconnection can be represented by a gate interconnection Hamiltonian that couples at least two local subsystems of the quantum system. The gate interconnection Hamiltonian can act jointly on a first local subsystem and a second local subsystem. The first local subsystem can be associated with a first gate-encoding Hamiltonian. The second local subsystem can be associated with a second gate-encoding Hamiltonian. The first gate-encoding Hamiltonian and the second gate-encoding Hamiltonian can each be associated with a first logic gate and a second logic gate of the logic gates, respectively. The first logic gate and the second logic gate may be connected to each other by one of the plurality of gate interconnections. The gate interconnection and / or the gate interconnection Hamiltonian can be configured to encode the gate interconnections of the logic gate circuit in the quantum system.

[0176] The determined gate interconnection interactions may be included in the first set of short-range quantum interactions. Executing the first set of short-range quantum interactions includes executing the determined gate interconnection interactions.

[0177] The logic gate circuits described in this specification can include common variables. The common variables are the same logical variables that are input variables of each logic gate within a group of two or more logic gates. Determining a first set of short-range quantum interactions can include determining common variable interactions or a set of common variable interactions from each of the common variables of the set of common variables. The common variable interactions or set of common variable interactions determined from the common variables can be representable by a common variable Hamiltonian that couples at least two local subsystems of a quantum system. The common variable Hamiltonian can act jointly on a first local subsystem and a second local subsystem. The first local subsystem can be associated with a first gate-encoded Hamiltonian. The second local subsystem can be associated with a second gate-encoded Hamiltonian. The first gate-encoded Hamiltonian and the second gate-encoded Hamiltonian can be associated with a first logic gate and a second logic gate of the logic gates, respectively.

[0178] The common variable in question can be an input variable of both the first logic gate and the second logic gate. The common variable interactions and / or the common variable Hamiltonian can be configured to encode the occurrence of the common variable in the logic gate circuit into the quantum system.

[0179] The determined common variable interactions can be included in a first set of short-range quantum interactions. Executing the first set of short-range quantum interactions includes executing the determined common variable interactions.

[0180] Determining a second set of short-range quantum interactions may include determining a set of output-encoded interactions from an integer to be factored or, more generally, from the output of a logic gate circuit (when the logic gate circuit is not a multiplication circuit). The set of output-encoded interactions may be represented by an output-encoded Hamiltonian. The output-encoded Hamiltonian may be a two-body Hamiltonian. The determined output-encoded interactions may be included in the second set of short-range quantum interactions. Executing the second set of short-range quantum interactions includes executing the determined output-encoded interactions. The output-encoded interactions and / or the output-encoded Hamiltonian may be configured to encode an integer to be factored, more generally, the output of a logic gate circuit, into a quantum system.

[0181] Developing the quantum system described herein involves a total Hamiltonian, e.g., the total Hamiltonian H described herein TOTALIt may include developing a quantum system towards its ground state. The total Hamiltonian may be a sum including a first Hamiltonian and a second Hamiltonian. The first Hamiltonian can represent a first set of short-range quantum interactions as described herein. The first Hamiltonian can be a sum including a monomer Hamiltonian corresponding to determined monomer interactions, a constraint Hamiltonian corresponding to determined constraint interactions, a gate interconnect Hamiltonian corresponding to determined gate interconnect interactions, a common variable Hamiltonian corresponding to determined common variable interactions, or any combination thereof. The second quantum Hamiltonian can represent a second set of short-range quantum interactions as described herein. The second Hamiltonian may be the gate-encoded Hamiltonian described herein. The ground state of the total Hamiltonian can encode at least one prime factor of an integer to be factored, or more generally, an unknown input of the logical gate circuit of the problem (when the logical gate circuit is not a multiplication circuit), or can encode information that enables at least the prime factor / unknown input to be determined. As described herein, measuring at least a part of the quantum system to obtain a readout may include performing the measurement when the quantum system is in a quantum state equal to or approximately equal to the ground state of the total Hamiltonian.

[0182] Developing the quantum system described herein may include cooling the quantum system, performing adiabatic evolution of the quantum system, performing anti-adiabatic evolution of the quantum system, performing gate-based evolution of the quantum system, or any combination thereof.

[0183] The logical gates of the logical gate circuit described herein can include AND gates and / or AND.FA gates. Specifically, each of the plurality of logical gates can be one of an AND gate and an AND.FA gate.

[0184] For each logic gate of a plurality of logic gates that are AND gates, the gate-encoded Hamiltonian associated with the logic gate may have the following form.

Number

[0185] For each logic gate of a plurality of logic gates that are AND.FA gates, the gate-encoded Hamiltonian associated with the logic gate may have the following form.

Number

[0186] According to a further embodiment, a quantum computing method for performing integer prime factorization is provided. The quantum computing method includes determining a logic gate circuit including logic gates, the logic gate circuit being configured to calculate a multiplication function having an integer as an output. The quantum computing method includes providing a quantum system including components. The quantum computing method includes determining a first set of short-range quantum interactions of the components based on the logic gates. Determining includes, for each logic gate of a plurality of logic gates, determining a subset of the components associated with the logic gate and encoding the logic gate in the short-range quantum interactions of the subset of the components. The quantum computing method includes determining a second set of short-range quantum interactions of the components based on the integer. The quantum computing method includes evolving the quantum system, including performing the first set of short-range quantum interactions and the second set of short-range quantum interactions. The quantum computing method includes measuring at least a portion of the quantum system to obtain a readout. The quantum computing method includes determining prime factors of the integer based on the readout. A quantum computing method for performing integer prime factorization can include any of the features or aspects described in relation to the quantum computing method described herein.

[0187] The quantum computing method may include, for each logic gate of a plurality of logic gates, determining a gate-encoding Hamiltonian from the logic gate. The gate-encoding Hamiltonian can encode the input-output relationship of the logic gate and can be a sum of addend Hamiltonians. Each addend Hamiltonian can be associated with each component of a subset of the components associated with the logic gate.

[0188] The quantum system can include local subsystems, each including a subset of the components, as described herein. For each logic gate of a plurality of logic gates, a gate-encoding Hamiltonian determined from the logic gate can be associated with a local subsystem. The local subsystem may include a subset of the components associated with the logic gate.

[0189] For each logic gate of a plurality of logic gates, encoding the logic gate with short-range quantum interactions of a subset of components can include determining single-body interactions from a gate-encoding Hamiltonian determined from the logic gate, as described herein. The determined single-body interactions can be represented by a single-body quantum Hamiltonian acting within a subset of components associated with the logic gate.

[0190] For each logic gate of a plurality of logic gates, encoding the logic gate with short-range quantum interactions of a subset of components can include determining one or more constraint interactions from a gate-encoding Hamiltonian determined from the logic gate, as described herein. The determined constraint interactions can be represented by a constraint Hamiltonian acting within a subset of components associated with the logic gate.

[0191] According to a further embodiment, a quantum computation or a basic subroutine for quantum computation operating on a quantum system including components is provided. The basic subroutine includes determining a basic subsystem of the quantum system including at least four components. Each summand Hamiltonian of the gate-encoding Hamiltonian H AND is associated with each component of the basic subsystem.

Number

[0192] The basic subsystem may be the local subsystem described herein. Determining the short-range quantum interactions of the basic subsystem may include determining single-body interactions from the gate-encoded Hamiltonian H AND In some cases. The determined single-body interactions can be represented by single-body Hamiltonians acting within the local subsystem. Each summand Hamiltonian of the gate-encoded Hamiltonian H AND may have an interaction coefficient. The interaction coefficient can be mapped to a single-body interaction. The single-body interaction can be a function of the interaction coefficient. Executing the determined short-range quantum interactions in the basic subsystem may include executing the determined single-body interactions. Determining the short-range quantum interactions of the basic subsystem may include determining one or more constraint interactions from the gate-encoded Hamiltonian H AND In some cases. The determined one or more constraint interactions can be represented by constraint Hamiltonians acting within the local subsystem. Executing the determined short-range quantum interactions in the basic subsystem may include executing the determined one or more constraint interactions.

[0193] According to a further embodiment, a basic subroutine for quantum computing or for quantum computing operating on a quantum system including components is provided. The basic subroutine includes determining a basic subsystem of the quantum system including at least eight components. Each summand Hamiltonian of the gate-encoded Hamiltonian H AND.FA is associated with each component of the basic subsystem.

Number

[0194] The basic subsystem may be the local subsystem described herein. Determining the short-range quantum interactions of the basic subsystem may include determining the one-body interactions from the gate-encoded Hamiltonian H AND.FA . The determined one-body interactions can be represented by one-body Hamiltonians acting within the local subsystem. Each summand Hamiltonian of the gate-encoded Hamiltonian H AND.FA may have an interaction coefficient. The interaction coefficient can be mapped to the one-body interaction. The one-body interaction can be a function of the interaction coefficient. Executing the determined short-range quantum interactions in the basic subsystem can include executing the determined one-body interactions. Determining the short-range quantum interactions of the basic subsystem is the gate-encoded Hamiltonian H AND.FAmay include determining one or more constraint interactions. The determined one or more constraint interactions may be represented by a constraint Hamiltonian acting within a local subsystem. Executing the determined short-range quantum interactions in a basic subsystem may include executing the determined one or more constraint interactions.

[0195] According to a further embodiment, a method of performing quantum computing is provided. The method includes providing a quantum system including components. The method includes performing one or more basic subroutines described herein, for example, one or more basic subroutines related to an AND gate and / or one or more basic subroutines related to an AND.FA gate. The method includes measuring at least a portion of the quantum system to obtain a readout.

[0196] According to one embodiment, a quantum computing method for inverting a logic gate circuit including logic gates is provided. The quantum computing method includes providing an output of the logic gate circuit corresponding to an unknown input of the logic gate circuit. The quantum computing method includes determining, one by one, for each of a plurality of logic gates, a gate-encoded Hamiltonian, each gate-encoded Hamiltonian encoding the input-output relationship of one of the plurality of logic gates and being a sum of addend Hamiltonians. The quantum computing method includes providing a quantum system including components, each addend Hamiltonian of each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians being associated with each component of the quantum system. The quantum computing method includes determining a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit. The quantum computing method includes determining a second set of short-range quantum interactions of the components based on the output of the logic gate circuit. The quantum computing method includes performing the first set of short-range quantum interactions and the second set of short-range quantum interactions, including evolving the quantum system. The quantum computing method includes measuring at least a part of the quantum system to obtain a readout. The quantum computing method includes determining an unknown input of the logic gate circuit based on the readout. The quantum computing method can include any of the features or aspects described in relation to the foregoing quantum computing method. The quantum computing method may be a method for performing integer prime factorization. The logic gate circuit may be configured to calculate a multiplication function having an integer as an output. As described herein, determining an unknown input based on a readout can include determining prime factors of an integer.

[0197] According to a further embodiment, an apparatus for performing integer prime factorization is provided. The apparatus includes a classical computing system. The apparatus includes a quantum system having components. The apparatus includes a quantum processing unit. The apparatus includes a measurement unit. The classical computing system is configured to determine a logic gate circuit including logic gates, and the logic gate circuit is configured to compute a multiplication function having an integer as an output. The classical computing system is configured to determine, for each of the plurality of logic gates, one by one, a gate-encoded Hamiltonian, and each gate-encoded Hamiltonian encodes the input-output relationship of one of the plurality of logic gates and is the sum of the addend Hamiltonians. Here, each addend Hamiltonian of each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians is associated with each component of the quantum system. The classical computing system is configured to determine a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit. The classical computing system is configured to determine a second set of short-range quantum interactions of the components based on the integer. The quantum processing unit is configured to execute the first set of short-range quantum interactions and the second set of short-range quantum interactions and to evolve the quantum system. The measurement unit is configured to measure at least a part of the quantum system to obtain a readout. The classical computing system is further configured to determine the prime factors of the integer based on the readout. The apparatus may be configured to execute a quantum computing method or a part thereof according to any of the embodiments described herein. The features and aspects described above in relation to the quantum computing method are also applicable to embodiments of the apparatus.

[0198] The quantum processing unit described in this specification can include a cooling system for cooling the quantum system. The quantum processing unit can be configured to perform adiabatic evolution of the quantum system. The quantum processing unit can be configured to perform reverse adiabatic evolution of the quantum system. The quantum processing unit can be configured to perform unitary evolution of the quantum system. The quantum processing unit can be configured by arbitrarily combining the foregoing aspects.

[0199] According to a further embodiment, an apparatus for performing integer prime factorization is provided. The apparatus includes a classical computing system. The apparatus includes a quantum system with components. The apparatus includes a quantum processing unit. The apparatus includes a measurement unit. The classical computing system is configured to determine a logic gate circuit including logic gates, and the logic gate circuit is configured to calculate a multiplication function having an integer as an output. The classical computing system is configured to determine a first set of short-range quantum interactions of the components based on the logic gates. Determining the first set includes determining, for each logic gate of the plurality of logic gates, a subset of the components associated with the logic gate, and encoding the logic gate in the short-range quantum interactions of the subset of the components. The classical computing system is configured to determine a second set of short-range quantum interactions of the components based on the integer. The quantum processing unit includes performing the first set of short-range quantum interactions and the second set of short-range quantum interactions, and is configured to evolve the quantum system. The measurement unit is configured to measure at least a part of the quantum system to obtain a readout. The classical computing system is further configured to determine the prime factors of the integer based on the readout. The apparatus can be configured to perform a quantum computing method or a part thereof according to any of the embodiments described in this specification. The features and aspects described above in relation to the quantum computing method are also applicable to embodiments of the apparatus.

[0200] According to a further embodiment, a component is provided for performing a basic subroutine of quantum computing that operates on a quantum system including components. The component includes a classical computing system. The component includes a basic subsystem of a quantum system including at least four components. H AND =-σ s -σ u σ s -σ v σ s +σ u σ v σ s The gate-encoded Hamiltonian H AND defined by each summand Hamiltonian is associated with each component of the basic subsystem. The gate-encoded Hamiltonian H AND has the logical variables u and v as input variables and encodes the input-output relationship of an AND gate having the logical variable s as an output variable. Here, σ u σ v and σ s are spin observables associated with the logical variables u, v, and s, respectively. The component includes a quantum processing unit. The classical computing system is configured to determine short-range quantum interactions of the basic subsystem from the gate-encoded Hamiltonian H AND . The quantum processing unit is configured to execute the short-range quantum interactions determined in the basic subsystem and to develop the quantum system. The component may be configured to execute a basic subroutine according to the embodiments described herein.

[0201] According to a further embodiment, a component is provided for performing a basic subroutine of quantum computing that operates on a quantum system including components. The component includes a classical computing system. The component includes a basic subsystem of a quantum system including at least eight components. The gate-encoded Hamiltonian H AND.FA defined by the following equation, each summand Hamiltonian is associated with each component of the basic subsystem.

Number

[0202] According to a further embodiment, an apparatus for inverting a logic gate circuit including logic gates is provided. The apparatus includes a classical computing system. The apparatus includes a quantum system including components. The apparatus includes a quantum processing unit. The apparatus includes a measurement unit. The classical computing system is configured to provide the output of the logic gate circuit corresponding to the unknown input of the logic gate circuit. The classical computing system is configured to determine, for each of the logic gates of the plurality of logic gates, one by one, a gate-encoded Hamiltonian, each gate-encoded Hamiltonian encoding the input-output relationship of one of the plurality of logic gates and being the sum of the addend Hamiltonians. Each addend Hamiltonian of each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians is associated with each component of the quantum system. The classical computing system is configured to determine a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit. The classical computing system is configured to determine a second set of short-range quantum interactions of the components based on the output of the logic gate circuit. The quantum processing unit is configured to develop the quantum system by performing the first set of short-range quantum interactions and the second set of short-range quantum interactions. The measurement unit is configured to measure at least a part of the quantum system to obtain a readout. The classical computing system is further configured to determine the unknown input of the logic gate circuit based on the readout. The apparatus may be configured to execute a quantum computing method or a part thereof according to any of the embodiments described herein. The features and aspects described above in relation to the quantum computing method are also applicable to embodiments of the apparatus.

[0203] Further aspects

[0204] A further aspect is described below in relation to FIGS. 13 to 20.

[0205] Figure 13 shows the multiplication circuit described in this specification. Factorization (prime factorization) can be considered as running the multiplication circuit in reverse. The arrow from left to right indicates multiplication, and the reverse arrow indicates factorization. The logic gates (AND gate, AND.FA gate) of the multiplication circuit, which are irreversible gates, are mapped to the corresponding gate-encoded Hamiltonian. The latter Hamiltonian provides a reversible encoding of the logic gate because the input-output relationship (truth table) of each logic gate is encoded in the basis space of the corresponding gate-encoded Hamiltonian. Due to the reversible encoding, the multiplication circuit can be inverted.

[0206] Figure 14 shows the method according to the embodiment described in this specification. At the bottom of Figure 14, a multiplication circuit composed of AND gates and AND.FA gates is shown. The multiplication circuit is mapped to the quantum system shown at the top of the figure. Each AND gate is mapped to a local subsystem composed of 4 qubits forming a plaquette. Each AND.FA gate is mapped to a local subsystem composed of 9 qubits forming a body-centered cube. The short-range quantum Hamiltonian H AND SR or H AND.FA SR acts on each local subsystem. The local subsystems are coupled using a gate interconnectivity Hamiltonian and a common variable Hamiltonian, a part of which is shown by triangles and squares in Figure 14 respectively.

[0207] Figure 15(i) shows the AND gate (left) of the quantum system and the related local subsystem (right). The local subsystem is composed of 4 qubits arranged at the corners of the plaquette. The short-range quantum Hamiltonian H AND SR can act on the local subsystem. The Hamiltonian H AND SR is the sum of the monomer Hamiltonian and the constraint Hamiltonian. The monomer Hamiltonian has Pauli σ with a coefficient of +1 or -1 (interaction coefficient) ZIt is the sum of the operators. The coefficients +1 and -1 are indicated by white circles and dashed circles, respectively. The constraint Hamiltonian is the Pauli σ acting on the four qubits of the plaquette with coefficients (-k, etc., where k is a positive number) Z It is a four-body Hamiltonian given by the tensor product of the operators. The constraint Hamiltonian is shown by the shape formed by the four solid lines connecting the four qubits.

[0208] Figure 15(ii) shows the AND.FA gate (left) of the quantum system and the related local subsystem (right). The local subsystem contains eight qubits (primary qubits). Figure 15(ii) shows two groups of four qubits, and each qubit in one group is arranged at the corner of each plaquette. The left plaquette is the "sum plaquette" and the right plaquette is the "carry plaquette". The two plaquettes can be stacked on top of each other to form a cube, with the sum plaquette being the bottom plaquette of the cube. The short-range quantum Hamiltonian H AND.FA SR can act on the local subsystem. The Hamiltonian H AND.FA SR is the sum of the single-body Hamiltonian and the constraint Hamiltonian. The single-body Hamiltonian is the sum of the Pauli σ Z operators with coefficients +1 or -1 (interaction coefficients). The coefficients +1 and -1 are indicated by white circles and dashed circles, respectively. The constraint Hamiltonian is a four-body Hamiltonian given by the sum of two terms. That is, the first term is the tensor product of the Pauli σ Z operators acting on the sum plaquette (with coefficients given), and the second term is the tensor product of the Pauli σ Z operators acting on the carry plaquette (also with coefficients given). The first term of the constraint Hamiltonian is shown by the line connecting the four qubits of the sum plaquette. The second term is shown by the line connecting the four qubits of the carry plaquette.

[0209] Figure 15(iii) shows two AND gates (left) and two associated local subsystems (right), each local subsystem being shown as a group of four qubits arranged on a plaquette. The two AND gates have a common variable q 0 which is reflected in the quantum system by the presence of a common variable Hamiltonian that couples the two local subsystems. The common variable Hamiltonian is shown in the shaded area. The common variable Hamiltonian is a four-body tensor product of Pauli σ Z operators (possibly with coefficients) acting on two qubits of the local subsystem associated with the first AND gate (left-hand plaquette) and two qubits of the local subsystem associated with the second AND gate (right-hand plaquette).

[0210] Figure 15(iv) shows two AND.FA gates having a common variable q 0 . Further, there is an interconnection between the two gates. That is, the variable c 1 is the output variable of one AND.FA gate and also the input variable of the other AND.FA gate. Figure 15(iv) further shows two associated local subsystems. Each local subsystem is composed of eight qubits (primary qubits) arranged at the corners of a cube and an additional qubit (secondary qubit, carry qubit) at the center of the cube. That is, each local subsystem has the shape of a body-centered cube. The common variable q 0 is reflected by the presence of a common variable Hamiltonian that couples the two local subsystems. The common variable Hamiltonian is shown by the hatched quadrilateral. The common variable Hamiltonian is a four-body tensor product of Pauli σ Z operators (possibly with coefficients) acting on two qubits of the sum plaquette of the local subsystem associated with the first AND.FA gate and two qubits of the sum plaquette of the local subsystem associated with the second AND gate. The variable c 1The interconnection related to [[ID=]] is reflected by the gate interconnection Hamiltonian that couples two local subsystems. The gate interconnection Hamiltonian is a three-body Hamiltonian that is the sum of three terms, namely the first term, the second term, and the third term. The first term is the tensor product of three Pauli σ Z operators (possibly with coefficients) acting on two secondary qubits (carry qubits) and the primary qubit of the first local subsystem among the two local subsystems. The second term is the tensor product of three Pauli σ Z operators (possibly with coefficients) acting on two additional primary qubits and the secondary qubit of the first local system. The third term is similar to the second term but is applied to the second local subsystem. The first term, the second term, and the third term are each shown as a triangle.

[0211] Figure 15(v) shows two AND.FA gates where there is an interconnection, and the variable s 1 is the output variable of one AND.FA gate and the input variable of the other AND.FA gate. Figure 15(v) further shows two related local subsystems, and each local subsystem is a body-centered cube as described above. The gate interconnection related to the variable s 1 is reflected by the gate interconnection Hamiltonian that couples two local subsystems. The gate interconnection Hamiltonian is a four-body Hamiltonian that is the sum of three terms, namely the first term, the second term, and the third term. The first term is the tensor product of four Pauli σ Z operators (possibly with coefficients) acting on each secondary qubit (carry qubit) and each one primary qubit of the two local subsystems respectively. The second term is the tensor product of three Pauli σ Z operators (possibly with coefficients) acting on two additional primary qubits and the secondary qubit of the first local system. The third term is similar to the second term but is applied to the second local subsystem. The first term is shown as a quadrilateral, and the second term and the third term are shown as triangles.

[0212] Figure 15(vi) shows an AND gate connected to an AND.FA gate, where the variable s 1 is the output variable of the AND gate and also an input variable of the AND.FA gate. Figure 15(vi) further shows two related local subsystems, namely the plaquette associated with the AND gate and the body-centered cube associated with the AND.FA gate. The gate interconnectivity related to the variable s 1 is reflected by the gate-interconnectivity Hamiltonian that couples the two local subsystems. The gate-interconnectivity Hamiltonian is a three-body Hamiltonian that is the sum of the first and second terms. The first term is the tensor product of three Pauli σ Z operators (possibly with coefficients) acting on the qubits of the local subsystem associated with the AND gate and the first and second qubits (carry qubits) of the local subsystem associated with the AND.FA gate. The second term is the tensor product of three Pauli σ Z operators (possibly with coefficients) acting on the second qubit of the body-centered cube and two additional first qubits. The first and second terms are each shown by a triangle.

[0213] Figure 15(vii) shows two AND.FA gates with a gate interconnectivity in between, where the variable cs is the output variable of one AND.FA gate and also an input variable of the other AND.FA gate. Further, p k is a common input variable for both AND.FA gates. Figure 15(vii) further shows two related local subsystems, each of which is a body-centered cube as described above. The gate interconnectivity is reflected by the gate-interconnectivity Hamiltonian that couples the two local subsystems. The gate-interconnectivity Hamiltonian is a three-body Hamiltonian that is the sum of three terms, namely the first, second, and third terms. The first term is the tensor product of three Pauli σ ZIt is a tensor product of operators (possibly with coefficients). The second term is three Pauli σ acting on two primary qubits and one secondary qubit of the first local system Z It is a tensor product of operators (possibly with coefficients). The third term is similar to the second term but applied to the second local subsystem. The first, second, and third terms are each shown as a triangle. The common variable is reflected by the common variable Hamiltonian that couples the two local subsystems. The common variable Hamiltonian is a single term, namely four Pauli σ acting on two primary qubits of each of the two local subsystems Z It is a four-body Hamiltonian composed of a tensor product of operators (possibly with coefficients). The common variable Hamiltonian is shown as a quadrilateral.

[0214] Figure 15 (viii) shows an AND gate and an AND.FA gate having a common variable p k Figure 15 (viii) further shows two related local subsystems, namely the first local subsystem forming a plaquette and the second local subsystem forming a body-centered cube. The common variable is reflected by the common variable Hamiltonian that couples the two local subsystems. The common variable Hamiltonian is a four-body Hamiltonian, namely four Pauli σ acting on two primary qubits of each of the two local subsystems Z It is a tensor product of operators (possibly with coefficients). The common variable Hamiltonian is shown as a hatched quadrilateral.

[0215] Figure 15 (ix) shows two AND.FA gates having a common variable p k Figure 15 (ix) further shows two related local subsystems, namely the first local subsystem and the second local subsystem each forming a body-centered cube. The common variable is reflected by the common variable Hamiltonian that couples the two local subsystems. The common variable Hamiltonian is a four-body Hamiltonian, namely four Pauli σ acting on two primary qubits of each of the two local subsystems ZIt is a tensor product of operators (possibly with coefficients). The common variable Hamiltonian is shown by the hatched square.

[0216] Figure 16(a) shows a multiplication circuit composed of the AND gate and the AND.FA gate described in this specification. The lines between the gates represent the gate interconnections described in this specification. Specifically, the lines extending horizontally from the AND.FA gate represent the carry operation of multiplication. The vertical lines represent the sum operation. p i q j =p i ∧q j Therefore, the partial product p i q j can be formed by applying an AND gate. One way to sum these is to use full adders arranged on a 2D array. Since the variables p i and q j are repeated vertically or horizontally respectively, the gates share common input variables.

[0217] Figure 16(b) schematically shows the internal structure of the AND.FA gate with increasing detail level from left to right. The first circuit diagram in Figure 16(b) represents the AND.FA gate. The second circuit diagram shows that the AND.FA gate can be formed as a basic logic gate circuit including an AND gate and a full adder (FA) gate. The third circuit diagram shows that the FA gate can be formed as a basic logic gate circuit including an OR gate and two half adder (HA) gates. The fourth circuit diagram shows that the HA gate can be formed as a basic logic gate circuit including an AND gate and an XOR gate.

[0218] Figures 17 and 18 show the gate-coded Hamiltonian and its spectrum associated with the AND gate and the AND.FA gate respectively.

[0219] Figure 19 shows a comparison of the number of components (qubits) required to perform prime factorization of an integer n by different quantum computing methods. The horizontal axis is the size of the integer (number of bits) l = |log 2(n) | is shown. The vertical axis shows the number of qubits required for each method. Embodiments of the methods described herein (graph 1910) use a large number of qubits that scale quadratically with l. In contrast, an approach based on mapping the factoring problem to a QUBO problem and then mapping the latter problem to annealing hardware scales as O(l 4 ) (graph 1920).

[0220] Figure 20 shows the method based on an example of 3-bit × 3-bit multiplication.

[0221] The fundamental asymmetry between the difficulty of integer multiplication and integer factorization underlies encryption and forms the basis of well-known protocols such as RSA. From the perspective of complexity theory, it is unlikely that the factoring problem is either NP-complete or in P (NP stands for "nondeterministic polynomial time" and P stands for "polynomial time"). However, the factoring problem has been proven to be in the complexity classes NP and BQP ("bounded-error quantum polynomial time"). Using Shor's quantum algorithm, it has been shown that integer factorization can be performed in polynomial time on a quantum computer, achieving a (quasi-)exponential speedup compared to all known classical factoring algorithms. Nevertheless, due to extensive requirements regarding the number of qubits and the quality of quantum gates, Shor's algorithm remains limited to proof-of-concept demonstrations and is far from factoring of the sizes used in real-world cryptographic systems.

[0222] In the present disclosure, a quantum algorithm for integer factorization is provided based on a reduction of the factoring problem to a parity-based spin model. The quantum algorithm has O(log 2(n) qubits and an interaction strength of O(1) are used, where n is the integer to be factored. This represents a significant improvement in terms of the number of qubits required compared to previous quantum algorithms. In this quantum algorithm, reversible versions of AND gates and AND.FA gates are constructed using parity-based encoding. In this encoding, the truth table of each logical gate is encoded in the ground state of a Hamiltonian (the short-range quantum Hamiltonian H described herein) G SR ). This makes the gates reversible, and for example, the multiplication circuit can be quantum mechanically inverted by an adiabatic quantum computing protocol. Using the eigen-symmetry of the Hamiltonian H G SR , a quantum factorization device composed of basic building blocks that can be repeatedly combined is provided, resulting in a scalable quantum architecture.

[0223] Previous approaches to performing integer factorization on a quantum computer are based on a quadratic unconstrained binary optimization (QUBO) problem involving O(log 2 (n)) qubits. To solve the optimization problem using adiabatic quantum computing technology, the structure of the 2-local Hamiltonian, which is a long-range Hamiltonian obtained from the QUBO approach, needs to be mapped to a short-range connection graph on available hardware such as a D-WAVE system, for example, via minor embeddings. In the latter mapping, an additional overhead that is quadratic in the number of qubits is added. Therefore, in such an approach based on QUBO, O(log 4 (n)) qubits are required to perform factorization in a quantum system containing only short-range interactions.

[0224] In contrast, according to the embodiments described herein, since the logic of the binary multiplication circuit is executed directly, i.e., without mapping to a QUBO problem, factorization can be performed with short-range quantum interactions using only O(log 2 (n)) qubits, thereby providing a quadratic improvement in the number of qubits required.

[0225] A Boolean circuit (multiplication circuit) can be provided that takes as input the binary representations of two integers p and q and outputs the binary representation of their product n. As shown in FIG. 16, this circuit can be constructed from AND gates and AND.FA gates. As described herein, a short-range quantum Hamiltonian H having a basis space that encodes the valid input-output relationships of these logic gates G SR can be constructed. Thereby, the Hamiltonian of the following equation (1) (the first Hamiltonian described herein) has a basis space in which the quantum state following the correct multiplication logic spreads. H 1 =Σ (all short-range quantum Hamiltonians H G SR ) + Σ (all gate coupling Hamiltonians) ··· (1) To select one particular multiplication, an additional term H in (p,q) can be added that gives an energy penalty to all quantum states that do not have p and q as corresponding inputs. Thus, finding the basis space of the Hamiltonian H product =H 1 +H in (p,q) solves the (simple) task of multiplying the numerical values p and q. The same approach can be applied to factorization. The output n can be fixed by adding an additional term H 1 to the Hamiltonian H out-enc (n) (output encoding Hamiltonian / the second Hamiltonian described herein). Thereby, a total Hamiltonian H TOTAL =H 1 +H out-enc (n) is obtained that has a basis space that encodes the prime factors p and q of the integer n. These prime factors can be determined by evolving the quantum system to the ground state of H TOTAL and then measuring the quantum system.

[0226] The Hamiltonian H G SRThe construction is motivated by aspects related to the number of required resources, namely the number of qubits and the number of interactions, and by considering scalability. The construction of the Hamiltonian HGSR is based on parity encoding that reduces the degree and amount of required interactions. The resulting total Hamiltonian H TOTAL is a short-range Hamiltonian. The quantum system on which the total Hamiltonian acts is composed of unit cells (local subsystems), and by adding more of these unit cells, factorization of larger integers can be realized. Each Hamiltonian H G SR is composed of two parts. A single-body Hamiltonian (one-body field) that encodes the gate G, and three-body and four-body terms (forming the constraint Hamiltonian described herein) that add parity constraints to truncate the Hilbert space by imposing a penalty on the subspace. Finally, H out-enc (n) can be defined as a two-body nearest-neighbor Hamiltonian to identify the desired integer n. The resulting architecture provides a scalable and short-range programmable total Hamiltonian that encodes the prime factors p and q such that the ground state is n = p·q.

[0227] Some notations are introduced. Below, the diagonal quantum Hamiltonian in the form of the following equation (2) is repeatedly used.

Equation

[0228] The idea behind the ground state spin logic involves embedding a set of bit strings S⊆{0,1} m into the ground space of the Hamiltonian H S . For example, consider an AND gate that defines four valid bit configurations (u, v, s = u ∧ v). Here, u and v are the input variables of the AND gate, and s is the output variable of the AND gate. u, v, s ∈ {0,1}. The corresponding Hamiltonian H AND (gate - encoding Hamiltonian) that encodes the input - output relationship of the AND gate requires the ground space of Equation (3) below.

Number

Number

[0229] Using the above approach, a logic gate circuit constructed from logic gates can be encoded into the basis space of a Hamiltonian. This is particularly applicable to a logic gate circuit (multiplication circuit) that performs a multiplication relationship between two integers. FIG. 16 shows the possibility of creating a binary multiplication circuit based on an AND gate and an AND.FA gate. The AND.FA gate is composed of a concatenation of an AND gate and a full adder (FA) gate, as shown in FIG. 16b. The AND gate performs a binary multiplication of two bits u and v based on the relationship u∧v = u·v, and the FA gate maps the sum variable s and the carry variable c (or carry overflow variable) to a new sum variable s’ and a new carry variable c’ such that the relationship shown in the following equation (5) is satisfied. [Number] The AND.FA gate is defined by equation (5). This gate operates on six bits u, v, c, s, c’, s’, and since four of them are input variables (i.e., u, v, c, s), there are a total of 16 valid input-output configurations. These input-output configurations can be encoded into the basis space of a gate-coded Hamiltonian H AND.FA [Number] FIG. 18 shows the spectrum of this Hamiltonian. The ground state manifold of H AND.FA has energy -4, and the other states (excited states) have energy 0 or +4. Notably, the gate-coded Hamiltonian H AND.FA ​The first four terms (the addend Hamiltonian) are, from Equation (4), the gate-encoded Hamiltonian H of the AND gate AND and very similar. Instead of the term Z s , there is the product Z s Z c Z s’ (abbreviated as Z scs’ according to the notation introduced above). Similar to the AND gate that specifies the output variable "s", this part of the Hamiltonian H AND.FA matches the parity of "(s, c, s')" according to the inputs of the variables "u" and "v" following the logic of the AND gate. Therefore, the first four terms of H AND.FA do not interact with the carry output "c'" and are thus called the sum terms. Without the carry terms (the other four terms of H AND.FA ), the basis space is 32-fold degenerate and all possible states are permitted without fixing c'. Adding these carry terms removes this degeneracy and divides the basis space by preferring the states that execute the correct logic of the AND.FA gate.

[0230] Again, there is a family of Hamiltonians that can encode the AND.FA logic, but in particular (after expansion), the above Hamiltonian H AND.FA is desirable because all indices u, v, s, c, c' and s' are included an even number of times.

[0231] The gate-encoded Hamiltonians such as the Hamiltonian H AND and H AND.FA of Equation (4) and Equation (6) respectively are Hamiltonians defined in a system of qubits labeled by the logical variables of the logical gates of the problem. For example, H AND is defined in a system of three qubits (since the AND gate has three logical variables), and H AND.FAIt is defined in a six - qubit system (since the AND.FA gate has six logical variables). The qubits in which the gate - encoded Hamiltonian is defined are called "auxiliary qubits", and the quantum system formed by the auxiliary qubits is called the "auxiliary quantum system". As described herein, the determination of the gate - encoded Hamiltonian is an intermediate classical step. In other words, neither the auxiliary qubits nor the interactions represented by the gate - encoded Hamiltonian need to be physically executed. Rather, the gate - encoded Hamiltonian is mapped to the components of another quantum system (excluding the auxiliary qubits), and it is the latter quantum system that is physically realized. Hereinafter, this quantum system is called the "main quantum system" to distinguish it from the "auxiliary quantum system". The main quantum system refers to the quantum system described in the claims and explained in the corresponding embodiments above.

[0232] Specifically, for each term (addend Hamiltonian) of the gate - encoded Hamiltonian, qubits of the main quantum system (referred to herein as primary components or primary qubits) are introduced. In the form cZ i Z j Z k ··· (c is a coefficient) acting on the auxiliary qubits i, j, k, ···, the relevant qubits of the main quantum system can be labeled with (i, j, k, ···). The following conditions are imposed.

Number

[0233] In the case of the AND gate, the Hamiltonian of Equation (4) has four terms. Therefore, the terms Z s Z u Z s Z v Z s Z u Z v Z s introduce four (primary) qubits (s), (u, s), (v, s), and (u, v, s) of the main quantum system that encode the expected values. Under the action of this mapping, the gate-encoded Hamiltonian H AND reduces to a single-body Hamiltonian (the sum of local fields). The subspace of all quantum states obtained by applying the mapping defined in Equation (7) above within the set of four qubits associated with the gate-encoded Hamiltonian H AND that forms the local subsystem of the main quantum system is shown as the effective subspace of the local subsystem of the problem. All quantum states within the effective subspace follow the same parity condition. That is, the following Equation (8) holds. [Number] This is due to a specific choice of AND gate encoding in the form of Equation (4). Here, each logical variable of H AND appears an even number of times, and generally (Z i ) 2 = 1 holds. Therefore, only every second basis state belongs to the effective subspace. This can be understood as there are eight possible bit configurations (u, v, s), that is, the Hilbert space of the three auxiliary qubits is 2 3 = 8 - dimensional, and these are mapped to a system with four qubits of the main quantum system (the four qubits have a 16 - dimensional Hilbert space). Adding a penalty term (constraint Hamiltonian) of the form -kZ(s)Z(u,s)Z(v,s)Z(u,v,s) causes the set of states of the local subsystem of the four qubits to be partitioned according to their parity, and the effective subspace is energetically preferred. In summary, the gate - encoding Hamiltonian acts on a set of four qubits that form the local subsystem of the main quantum system and is mapped to a short - range quantum Hamiltonian H AND SR in the following form. [Number] Here, k > 0. The four qubits of the problem are arranged on a plaquette so that the four - body penalty term -kZ (s) Z (u,s) Z (v,s) Z (u,v,s) becomes local in the geometric sense.

[0234] The multiplication circuit further includes AND.FA gates. Next, it shows how the H AND.FA gate - encoding Hamiltonian of Equation (6) can be mapped to the short - range quantum Hamiltonian H AND.FA SR . The short - range quantum Hamiltonian H AND.FA SRhas a single-body field acting on eight qubits (of the primary quantum system) arranged in two four-body plaquettes, each plaquette having a four-body parity constraint (see Figure 15ii). H AND.FA The first four terms (addend Hamiltonians) of AND.FA are conceptually similar to AND gate encoding, so these terms are the four qubits (s, c, s’), (u, s, c, s’), (v, s, c, s’) and (u, v, s, c, s’) of the (primary quantum system) arranged on a plaquette having single-body Hamiltonian -Z (s,c,s’) -Z (u,s,c,s’) -Z (v,s,c,s’) +Z (u,v,s,c,s’) and the corresponding four-body parity penalty term (constraint Hamiltonian) -kZ acting on the said plaquette (s,c,s’) Z (u,s,c,s’) Z (v,s,c,s’) Z (u,v,s,c,s’) and can be assigned to. This plaquette is called the sum plaquette. H AND.FA In the form of AND.FA , the other four terms of H AND.FA can each be identified with each qubit (s, c, s’, c’), (s, c’), (c, c’) and (s’, c’) of the (primary quantum system) only if the state of these qubits is in a "valid" state, and Z (s,c,s’,c’) Z (s,c’) Z (c,c’) Z (s’,c’) = 1. Therefore, it is possible to collect these terms in a second plaquette. This is called the carry plaquette. This consists of the single-body Hamiltonian -Z (s,c,s’,c’) -Z (s,c’) -Z (c,c’) +Z (s’,c’) and the four-body parity constraint -kZ (s,c,s’,c’) Z (s,c’) Z (c,c’) Z (s’,c’) acting on four qubits (see Figure 15ii). Therefore, the gate-encoding Hamiltonian H AND.FAacts on the set of eight qubits (s, c, s’), (u, s, c, s’), (v, s, c, s’), (u, v, s, c, s’), (s, c, s’, c’), (s, c’), (c, c’), (s’, c’) arranged at the vertices of a cube, the following short-range Hamiltonian H AND.FA SR is mapped to. [Number] where k > 0. H AND.FA In contrast to the direct execution of H AND.FA SR the execution of H AND.FA requires only one-body fields and two four-body terms, rather than three two-body, one three-body, three one-body four-body, and one five-body terms. Further, directly executing H i and q j functions as an input for the entire row or column of AND.FA gates (see Fig. 16a). In comparison, the method according to the embodiments described herein includes only short-range interactions.

[0235] The short-range Hamiltonians H AND SR and H AND.FA SR are the building blocks used to construct the total Hamiltonian encoding the multiplication circuit. To achieve this, the Hamiltonians H AND SR and H AND.FA SR need to be connected like bricks, reflecting that the output of the previous gate is input to the subsequent gate. Further, the total Hamiltonian encodes that multiple gates can share the same input. The short-range Hamiltonians H AND SR and H AND.FA SR show how to assemble them so that the desired logic is executed.

[0236] First, pay attention to the two adjacent AND gates that appear in the first row of the multiplication circuit (see Fig. 15iii). For the corresponding inputs, there are p 0 , q 0 and p 1 , q 0 labeled as such. Since q 0 appears twice (as the common input variable of the first and second AND gates), only 3 qubits instead of 4 qubits are required to encode the input information. When these inputs are specified, degrees of freedom are "lost". However, in the main quantum system, we still want to encode each AND gate in each 4 - qubit plaquette. The total number of qubits in the two plaquettes is 8, but since one of the variables is a common variable, the number of logical variables for both AND gates becomes 5 instead of 6. Since 8 - 5 = 3, specifying the two input variables needs to be compensated by adding constraints that penalize half of the quantum states. Let s 0 be the output of the first AND gate and s 1 be the output of the second AND gate. Then the labels of the qubits in the first plaquette are s 0 , (q 0 , s 0 ), (p 0 , s 0 ), (p 0 , q 0 , s 0 ), and the labels of the qubits in the second plaquette are s 1 , (q 0 , s 1 ), (p 1 , s 1 ), (p 1 , q 0 , s 1 ). The fact that the variable q 0 is a common input variable, that is, it appears in both plaquettes, means that the qubits (p 0 , s 0 ), (p 0 , q 0 , s 0 ) and (s 1 ), (q 0 , s 1)(See Fig. 15iii) By introducing an additional four-body Hamiltonian (common variable Hamiltonian) composed of four Z operators that act respectively, it can be enforced in a quantum system.

[0237] For the sake of concreteness, but without loss of generality, assume that both p and q are natural numbers that fit within a register of l / 2 bits. Thus, the product n = pq has at most l bits. To execute the corresponding multiplication circuit, l / 2 AND gates and l / 2(l / 2 - 1) AND.FA gates are required. Without considering the gate interconnections and common variables, and only counting the input and output nodes of the gates, 3l(l - 1) / 2 logical variables are needed to describe the system. However, by connecting these gates and enforcing that some of the input variables are common variables in order to execute the multiplication circuit, it is necessary to specify the following m id of them (see Fig. 16a). m id = l(l - 5 / 2) This means that in order to restrict the Hilbert space by imposing a penalty on the subspace where unwanted states spread, it is necessary to construct m id additional independent constraints (coupling Hamiltonian) in the main quantum system.

[0238] Below, possible arrangements of AND and AND.FA local subsystems are shown for designing a degenerate stabilizer space spanning all valid states corresponding to the multiplication of l / 2-bit and l / 2-bit numerical values. The gate-coded Hamiltonians H AND SR and H AND.FA SRThe qubit(s), (u, s), (v, s), and (u, v, s) of the principal quantum system associated with the term (addend Hamiltonian), and (s, c, s’), (u, s, c, s’), (v, s, c, s’), (u, v, s, c, s’), (s, c, s’, c’), (s, c’), (c, c’), (s, c’) are called the primary qubits of the principal quantum system. The primary qubits are arranged along two layers of the 3D grid, and secondary qubits are added at the center of the body-centered cubic grid. Using these secondary qubits, the missing m id constraints can be implemented as three-body or four-body parity constraints (coupling Hamiltonian) using only short-range interactions. Furthermore, by adding additional constraints that encode the target semi-prime number, it is shown how the degeneracy of the base space can be split. This separates a single base state that encodes the information of the prime factors n = p·q (apart from the exchange of p and q).

[0239] As described above, the first four terms (addend Hamiltonian) of H AND.FA are conceptually similar to the terms of H AND . This generates two separate plaquettes, the total plaquette and the carry plaquette. The total plaquette can be placed on a 2D grid that extends the rows of the plaquettes associated with the AND gates. In the layout of the multiplication circuit, the input variables p 0 , ···, p l / 2-1 are repeated vertically, and q 0 , ···, q l / 2-1 are repeated horizontally (see Figure 16a), so these plaquettes can be arranged such that the common variables are always shared by adjacent plaquettes. To account for the common variables, the plaquettes are connected via additional parity constraints (common variable Hamiltonian) (see Figures 14 and 15). The missing m id -l(l / 2 - 1) constraints arise from the identification of the output node of one gate and the input node of another gate (gate interconnection).

[0240] The entire multiplication circuit can be considered to be composed of individual AND gates and AND.FA gates interconnected using the following rules. a) Identify the sum output of the AND gates as the sum input of the AND.FA gates (sum-to-sum). Refer to Figure 15vi. b) Connect two AND.FA gates "horizontally". That is, connect the carry output of one AND.FA gate to the carry input of another AND.FA gate (carry-to-carry). Refer to Figure 15iv. c) Connect two AND.FA gates "vertically" by identifying the sum output of the first AND.FA gate as the sum input of the second AND.FA gate (sum-to-sum). Refer to Figure 15v. d) Obtain the carry output of the AND.FA gate and input it into the sum input of the second AND.FA gate (carry-to-sum). Refer to Figure 15vii.

[0241] First, explain case b), following the labels in Figure 15iv. The carry variable c 1 In addition to the gate interconnections given by, the input variable q 0 is a common input variable to both gates.

[0242] q 0 To construct the first constraint reflecting that is a common input variable, place the total plaquettes adjacent to each other, leaving space for an additional four-body plaquette (with a parity penalty term). This is the same as in the case of the two AND gates described in relation to Figure 15iii.

[0243] The carry variable c 1 To construct the second independent constraint reflecting the interconnection given by, place the carry plaquette in the second layer of the 3D grid (directly above the corresponding total plaquette). Add a secondary qubit, denoted as (c’), placed at the center of each cube formed by each eight qubits, and call this secondary qubit (c’) the carry qubit. To fix the value of the carry qubit, HAND.FA The term Z that appears in scs’ and Z scs’ Z c’ is Z c’ It should be noted that they only differ. Therefore, the three-body parity constraint (gate interconnectivity Hamiltonian) acting on two main qubits (s, c, s’) and (s, c, s’, c’) and the carry qubit (c’) of each cube can impose a preference for the state of the carry qubit of the cube to be in a state corresponding to the carry output value c’ of the corresponding AND.FA gate (see Fig. 15iv). Furthermore, this constraint modifies the size of the Hilbert space increased after the introduction of the carry qubit. After the introduction of the carry qubit, if there is a valid logical substitution, all indices appear exactly twice such that Z (c’) Z (s,c,s’) Z (s,c,s’,c’) = 1.

[0244] When two AND.FA gates are horizontally connected as shown in Fig. 15iv, the first carry variable c 1 is an iterative variable. That is, it also exists as (c 1 , c 2 ) in the pair of the second plaquettes. If c 2 is called the output carry variable of the second AND.FA gate (whose value is encoded in the corresponding carry qubit), three (c 1 ), (c 2 ) and (c 1 , c 2 ) enable the introduction of a further parity constraint, i.e., a three-body Hamiltonian acting on the carry qubits (c 1 ), (c 2 ) and one qubit of the cube (c 1 , c 2 ) (see Fig. 15iv).

[0245] Furthermore, by adding a carry qubit to each cube and adding the corresponding three-body parity constraint described above, cases a), c) and d) can also be solved.

[0246] For case c), according to the label in Fig. 15v, the variable s 1 represents the sum output of the first AND.FA gate, which also functions as the sum input of the second AND.FA gate. To enforce this gate interconnection, a four-body parity constraint (the product of Z operators) acts on two carry qubits (c 1 ) and (c 3 ), both of which are at the top layer, and the primary qubits labeled (c 1 , s 1 ) and (s 1 , c 3 ). This constraint is shown as a rectangle in Fig. 15v.

[0247] Cases a) and d) are boundary cases related to the first row of the AND gate or the diagonal at the left end of the AND.FA gate. Fig. 15vi shows case a). Since there is a qubit labeled (s 1 ) within the bracket of the four qubits associated with the AND gate, the sum output of the AND gate can be directly accessed (see Fig. 15i). As shown in Fig. 15vi, this sum output is connected to the sum input of the AND.FA gate. When the corresponding carry output variable is denoted as c 3 , a parity constraint (the product of Z operators) acting on the qubits (s 1 ), (s 1 , c 3 ) and (c 3 ) can be constructed. Case d) deals with the overflow carried to the next column when there is no partial sum yet and we want to add a carry (digit carry) to p k ·q l+1 using another AND.FA unit as shown in Fig. 15vii. Since the carry output of the first FA gate denoted as c s is specified as the sum input of the next gate, this variable appears in both relevant Hamiltonians. Therefore, for the local subsystem associated with the second AND.FA gate, the qubits (cs, c AND.FA ) corresponding to the combination (s, c’) according to the Hamiltonian H 3) includes this. As a result, there is another independent parity constraint (product of Z operators) acting on qubits (cs), (cs, c 3 ) and (c 3 ).

[0248] In addition to the gate interconnections described in items a) to d) above, variables p i and q j must also be forced to be common variables according to the multiplication circuit shown in FIG. 16a. The case of variable q i , which is the common variable of two AND gates, has been described above. See the description related to FIG. 15iii. The case of variable q i , which is the common variable of two AND.FA gates, has been described above in relation to FIG. 15iv. As shown in FIG. 15viii, the case of variable p j , which is the common variable of an AND gate and an AND.FA gate, is treated similarly. Furthermore, the fact that variable p j is the common variable of two AND.FA gates can be forced in the manner shown in FIG. 15ix. See also FIG. 15vii showing a further case of two AND.FA gates having a common variable p k .

[0249] The introduction of additional carry qubits (secondary qubits) also helps to encode the desired semi-prime number n = n 0 n 1 n 2 ···(n i is the bit of n) into the quantum system. To illustrate this, consider the 3-bit × 3-bit example (see FIG. 20). Inputs p and q are each 3-bit integers, i.e., integers in the range from 0 to 7. Therefore, the product n = p·q is not greater than 7×7 = 49, which is a 6-bit integer. Therefore, without loss of generality, n can be represented as a 6-bit integer, i.e., n = n 5 n 4 ···n 0 . The least significant bit n 0is the sum output variable of the AND gates at the right end of the multiplication circuit (see FIGS. 16a and 20a). Thus, bit n 0 exists as the primary qubit of the corresponding plaquette (n 0 ), so n 0 can be easily fixed (by the Z operator). Bit n 1 is the sum output variable of the AND.FA gates (see FIGS. 16a and 20a). Bit n 1 itself cannot be directly accessed as a corresponding qubit. Further, denoting the carry output variable of the relevant AND.FA gate as c 0 , the carry plaquette of the relevant local subsystem has qubits (n 1 , c 0 ), and (c 0 ) is the carry qubit of the local subsystem. The relative alignment between these qubits depends only on n 1 . Thus, adding two local terms ±k·σ c0 σ (n1,c0) fixes the value of n 1 depending on the sign of the interaction. Similarly, the parity between (c 2 , (n 2 , c 2 ), (c 3 , (n 3 , c 3 ) and (n 5 , (n 4 , n 5 ) fixes the values of n 2 , n 3 and n 4 . The value of n 5 is encoded in the auxiliary qubit n 5 and can be fixed by the sign of the local field ±k·σ c5 . To repeatedly use the full adder gates, even in the absence of previous sums or carries, it is necessary to fix some of the inputs of the AND.FA gates to zero. This is achieved by (cs, (a 0 , cs)), (c 0 , (a 1 , c 0 ) and (c 2 , (a 2,c 2 )(n is fixed in the same way as the output value by imposing antiferromagnetic / ferromagnetic interaction.) i )(This is done in the same way as the case where the output value of n is fixed.)

[0250] )(Generally, the bits n of an integer n) 0 ,···,n 1 )(appear as the output of the bottom row of the AND.FA gate at the right end of the AND.FA gate, as shown in Fig. 16a. All half adders and full adders are realized by AND.FA units. As shown in Fig. 16a, the least significant bit n) 0 )(is the sum output variable of the AND gate. Therefore, the bit n) 0 )(exists as the primary qubit (n) 0 ) of the corresponding plaquette. For this reason, the value of n) 0 )(can be encoded in the quantum system by a single qubit Z operator acting on the qubit (n) 0 ). Furthermore, as shown in Fig. 16a, the most significant bit n) l )(is the carry output variable of the AND.FA gate. Since a corresponding carry qubit (secondary qubit) has also been introduced for the latter carry output variable, it can be directly accessed. Therefore, the value of n) l )(can be encoded in the quantum system by a single qubit Z operator acting on the carry qubit of the problem. As further shown in Fig. 16a, the bits n) 1 ,···,n l-1 )(are the sum output variables of the AND.FA gate. Each of these bits can be encoded in the quantum system by a two-body operator (ZZ form) between the carry qubit c’ and the qubits (s’, c’) of each local subsystem, resulting in the value of the sum output s’ being fixed. In this way, an output encoding Hamiltonian that is the sum of the aforementioned single-body and two-body terms can be provided. Therefore, the output encoding Hamiltonian of the problem is a two-body Hamiltonian.)

[0251] Furthermore, as shown in Fig. 16a), the carry input c of the rightmost AND.FA gate can be set to zero (in order to realize the operation of a half adder using the AND.FA gate). This can also be implemented by imposing two constraints (in the ZZ form) between the qubit c’ (carry qubit) and (c,c’) (the primary qubit of the carry bracket).

[0252] A multiplication circuit that can multiply l / 2 times the number of l / 2 bits generates an output n of size l = |log2(n)| bits. Such a circuit is composed of l / 2 AND gates and l / 2(l / 2 - 1) AND.FA gates. When including the carry qubits that form the intermediate layer, l(9l - 10) / 4 qubits are required to construct the bracket. When using the multiplication circuit to find the factors of an odd semiprime number n = p·q, both p and q need to be odd, and p0 = q0 = 1. As a result, AND(u,1)=u holds, so the first row of the AND gate becomes unnecessary. Therefore, the -4l + 2 qubits associated with the AND gate can be removed from the following count. m phys =(9l 2 -26l + 8) / 4 The above shows the number of qubits required.

[0253] The aforementioned structure is optimized (with respect to the number of qubits) for the factors n = p·q such that both factors fit into a register of size l / 2. In general, for factoring any semiprime number n, the sufficient length of the factors is L p =l=|log 2 (n)| and L qIt becomes \(=|\frac{1}{2}(l + 1)|-1\). The fact that the length of the factors is not known in advance is part of the factorization problem. In extreme cases where one of the factors is very small or both are equal, it can be classically approached. For example, with simple trial division, factors up to a certain threshold size of \(r\) bits can be checked. On the other hand, the factorization algorithm as Fermat's method works well when the values of both factors are close. When using the RSA protocol, since there is an interest in making the attack as powerful as possible, it can be assumed that neither factor is small nor of the same size. To span this range of possible sizes, the circuit must encode the multiplication of \((L p -r)\) bits and \(L q bits to generate \(l\) bits. Without preprocessing, i.e., when \(r = 0\), the maximum resources required are approximately \(\frac{3}{2}m phys (l)\) qubits. This results in an estimated \(3.4l 2 qubits.

[0254] Table I shows the binary multiplication table. When expressing \(p\) and \(q\) in binary, the product \(n = p\cdot q\) can be rewritten in terms of the bits \(p i and \(q j as follows.

Number

Table I

[0255] According to the embodiments described in this specification, carry variables and sum variables can be introduced for all products p i q j appearing in the multiplication table. Since the carry variables connect different columns of the table while the sum variables connect different rows, the entire multiplication table is divided into cells. To perform the multiplication of p and q, the sum of all terms in each column is calculated while balancing the carry variables connected to the higher-order columns. The sum variables track the partial sum mod 2, and the carry variables connect only adjacent columns. Usually, the logic of these individual cells is described in the language of Boolean circuits. The corresponding cells are described by half adder (HA) gates and full adder (FA) gates respectively. Given the previous partial sum "s" from the upper row and the carry "c" from the previous column, the following relationship defines the new sum s' variable and the new carry c' variable. s + c + x = 2c' + s' In the multiplication circuit, each cell x is in the form of p i q j and can be regarded as the logical AND between the variables p i and q j

[0256] ​As described in this specification, after the quantum system has evolved to the ground state of the total Hamiltonian, at least a part of the quantum system (i.e., the main quantum system) can be measured. For example, all primary qubits (primary components) can be measured. Each measurement value of the qubits of the main quantum system may be a measurement value of the Pauli operator Z, and a readout δ (measurement result) of either 1 or -1 is obtained. Thanks to the parity mapping described in this specification (see, for example, Equation (7)), the Pauli operator Z acting on the primary qubits a=(i,j,k,···) of the main quantum system corresponds to an addend Hamiltonian of the gate-encoded Hamiltonian. The addend Hamiltonian is proportional to the product of the Pauli operators Z i Z j Z k ···. The operators Z i ,Z j ,Z k ,··· act on the qubits i,j,k,··· of the auxiliary quantum system respectively. The variable σ i ∈{-1,1} is assigned to the qubit i of the auxiliary quantum system, the variable σ j ∈{-1,1} is assigned to the qubit j of the auxiliary quantum system, the variable σ k ∈{-1,1} is assigned to the qubit k of the auxiliary quantum system, and so on. The variables σ i ,σ j ,σ k ··· represent the possible measurement results of the operators Z i ,Z j ,Z k ,··· acting on the qubits i,j,k,··· of the auxiliary quantum respectively. The fact that a readout δ is obtained by measuring the Pauli operator Z acting on the primary qubits (i,j,k,···) of the main quantum system means that δ = σ i σ j σ k ···, that is, the readout δ is the variable σ i ,σ j ,σ k··· means the product. Each measurement result of the primary qubits corresponds to the product of the variables assigned to the relevant qubits of the auxiliary quantum system under the parity mapping in this way. The task of inverting the parity mapping is to determine the set of variables σ i , σ j , σ k ··· associated with each qubit of the auxiliary quantum system based on the set of measurement results δ obtained by measuring the primary qubits of the primary quantum system. Therefore, it is necessary to solve a system of simultaneous equations in the following form. σ ω1 = δ 1 , σ ω2 = δ 2 , ···, σ ωr = δ r Here, each δ a ∈ {-1, 1} indicates the measurement result (readout) obtained by measuring the primary qubits a of the primary quantum system, and r is the number of primary qubits. Furthermore, σ ωa is a shorthand notation for the product σ ωa = σ ωa1 σ ωa2 σ ωa3 ···. σ ωai ∈ {-1, 1}, and a1, a2, a3, ··· are the qubits of the auxiliary system associated with the primary qubits a under the parity mapping as described above.

[0257] The multiplication of elements from {-1, 1} is isomorphic to performing an XOR operation (or modulo 2 addition) on the variables {0, 1}. Therefore, by changing the variables s k = (1 - σ k ) / 2 and d i = (1 - δ i ) / 2, the above system of simultaneous equations becomes equivalent to the following second system of simultaneous equations.

Number

Number

Number

[0258] Specific examples of a 3 - bit × 3 - bit multiplier are shown in FIGS. 20A and 20B. The input numerical values (prime factors) are given in binary expansion as p = p 2 p 1 p 0 and q = q 2 q 1 q 0 . Since both p and q are integers from 0 to 7, their product cannot exceed 49. Therefore, the output numerical value n fits into a 6 - bit register n = n 5 n 4 ···n 0 . To calculate the binary number of the integer product n = p·q, the multiplication circuit shown in FIG. 16a) takes into account the carry - over overflow to higher powers of 2 and calculates 3 2 = 9 binary products p i q jIt is necessary to sum them up. The corresponding circuit is constructed from three AND gates and six AND.FA units as shown in FIG. 20A. As described above, each relationship between gate nodes is compensated by independent constraints between the corresponding local subsystems. There are two types of such relationships. a) Common variables, that is, the type in which two input nodes are connected such that their corresponding states are equal, and b) Gate interconnections, that is, the type in which the output node of the previous gate is also the input node of the subsequent gate.

[0259] As shown in the left panel of FIG. 20A, each variable q j is a common variable for three gates. In this sense, q 0 functions as a common input for all three AND gates, and q 1 and q 2 function as common inputs for three AND.FA gates respectively. In the illustrated arrangement, the variable q j repeats "horizontally". Similarly, the input variable p i repeats "vertically". Each column of gates (consisting of one AND gate and two AND.FA gates) has a common input p i . In contrast to the case of three independent AND gates, the connection between the input nodes in the first row given by q 0 reduces the number of independent variables by two. Since the 3-bit circuit example is executed over three rows and three columns of gates, there are a total of 2·2·3 = 12 connections between the input nodes.

[0260] The right panel of FIG. 20A shows the gate interconnections. The rightmost AND gate directly outputs the least significant bit n 0 , while the other two AND gates output s 0 and s 1It is supplied to the subsequent two AND.FA gates. Further, the sum output of the AND.FA gate is connected twice to the sum input of the second AND.FA gate. In four cases, two AND.FA gates are connected from the carry output to the carry input, and finally in one case, the carry output is supplied to the sum input of the AND.FA gate. As a result, a total of nine gate interconnections are obtained.

[0261] In summary, to construct a 3-bit × 3-bit multiplier from basic AND gates and AND.FA gates, 12 + 9 = 21 constraints (12 common variable constraints and 9 gate interconnection constraints) are required. Figure 20A shows the labeling of the 24 relevant logical variables. Six of them store the inputs p, q, and six hold the output information n. Further, four sum variables s 0 、s 1 、s 2 、s 3 、four carry variables c 0 、c 1 、c 3 、c 4 、and a special variable cs for connecting the carry output at the left end to the sum input of the next row are required. Finally, three auxiliary variables a 0 、a 1 、a 2 are introduced to repeatedly use the AND.FA gates even when there is no previous carry or sum. Setting these inputs to zero enables the execution of the half adder required within the execution of the full adder.

[0262] The conversion to the parity model proceeds as described above. Each AND gate is executed as a 4-qubit plaquette, and the AND.FA gate is realized by a total of 9 qubits in a body-centered cube. Further, the connections of the gates and nodes are converted into parity constraints (gate interconnection Hamiltonian, common variable Hamiltonian) that connect the bare plaquettes. Figures 15i to 15ix show the basic conversion procedure.

[0263] Next, the common variable Hamiltonian will be described. FIGS. 15iii and 15iv show the case where the qj input variables are repeated "horizontally". As described above, the common input variable q that appears in adjacent gates j is converted into an additional four constraints (common variable Hamiltonian) in the parity model that connect both sum brackets. In addition to the horizontal connection of the input variables, there are variables p that are repeated vertically i as well. Similar to the horizontal case, these connections result in an additional four constraints that connect the sum brackets (see FIGS. 15vii to 15ix). To better understand, it is helpful to consider a simpler circuit. Consider a 2D grid of AND gates of size k×k. Connect the first input nodes of the gates in the column direction and the second input nodes in the row direction so that the circuit has 2k(k - 1) connections between the input nodes. k 2 plaquettes are used to convert the logic of the AND gates into a parity model. Enumerate the AND gates by [i,j]. Here, i indicates the column index and j indicates the row index (similar to the left panel of FIG. 20A). If s i,j is called the sum output of the [i,j]-AND gate, the corresponding plaquettes are labeled (s i,j ), (p i , s i,j ), (q j , s i,j ) and (p i , q j , s i、j ). These can be grouped into sets R := {(s i,j ), (q j , s i,j )} and L := {(p i , s i,j ), (p i , q j , s i,j ), or alternatively into sets D := {(s i,j ), (p i , s i,j )} and U := {(q j , s i,j ), (p i , q j , s i,j)} can also be grouped. Two tuples from the sets “right” R and “left” L formally differ only by q j from column i, while the elements “down” D and “up” U differ only by p i for all row indices j. Thus, adjacent AND parity plaquettes [i,j], [i + 1,j] are, for example, L 1 :={(p i ,s i,j ),(p i ,q j ,s i,j )} and R 2 :={(s i+1,j ),(q j ,s i+1,j ), that is, the qubits labeled on the left side of the first plaquette and the right side of the second plaquette can be connected to the parity constraint. Similarly, vertically adjacent AND parity plaquettes [i,j], [i,j + 1] are D 1 :={(s i,j ),(p i ,s i,j )} and U 2 :={(q j+1 ,s i,j+1 ),(p i ,q j+1 ,s i,j+1 )} of qubits with labels. In particular, by carefully arranging the labels between the plaquettes, horizontal and vertical parity constraints can be utilized simultaneously. A possible way is to arrange the labeling within each plaquette such that the upper qubit is labeled with a label from the set U, and the lower, right, and left qubits are labeled respectively. In that sense, the bottom-right qubit needs to obtain the label RD = R ∩ D = (s i,j ). Similarly, LD = (p i ,s i,j ), RU = (q j ,s i,j ), LU = (p i ,q j ,s i,j) is obtained. It is easy to confirm that 2k(k - 1) new 4 - body parity constraints are obtained by this arrangement.

[0264] With this analysis in mind, refocus on the arrangement of AND plaquettes and AND.FA plaquettes in the multiplication circuit. As already mentioned above, note that one of the two AND.FA plaquettes is conceptually similar to the AND parity plaquette. That is, the corresponding labeling is obtained by formally replacing the sum output label s with three s, c, s'. Except for this difference, the overall structure of the sum plaquettes related to the multiplication circuit is the same as that of the example of a 2D grid of AND gates. Here too, the input variable p i is repeated vertically, and the variable q j is repeated horizontally. From this, it can be easily understood that the sum plaquettes of the plaquettes and the corresponding AND.FA gates can be arranged in a 2D layer using 2k(k - 1) new four - body parity constraints acting on the plaquettes of adjacent qubits. When k = 3, as shown in the left panel of Figure 20B, there are 12 new constraints. These plaquettes are arranged in the first layer. The figure in the left panel of Figure 20B shows the labeling of the physical qubits. Since some indices repeatedly appear among the qubits belonging to the same plaquette, an abbreviated notation is introduced. The string of labels is formally divided into a common part and a unique part. In Figure 20B, the common part indicated by the expression of the form +(common label) is shown in the center of the plaquette, and the unique separate part is represented as the label associated with the qubit. When the reader finds an expression of the form +(common label) in the center of the plaquette, it should always be understood that the label of each of the four qubits of the said plaquette is extended by the common part (common label) to form the actual label string. For example, regarding the plaquette in the upper right corner of the left panel of Figure 20B, the three qubits of the said plaquette are (p 0 ,q 0 ),(q 0 ),(p 0) is labeled by, and one qubit of the said bracket has no label. Further, at the center of the bracket is +n 0 The expression of " is shown. Therefore, the qubit labels of the said bracket have a common part of n 0 which is (p 0 , q 0 , n 0 ), (q 0 , n 0 ), (p 0 , n 0 ) and (n 0 ) should be understood as.

[0265] Next to the nine brackets (i.e., the sum brackets) forming the first layer, there are six brackets still cut from the first layer (related to six AND.FA gates (carry brackets)). The gate interconnection is converted into a parity constraint (gate interconnection Hamiltonian) for coupling the carry brackets to the first layer. The basic construction steps have been described above and are shown in FIGS. 15iv to 15vii. As described above, for each pair of sum and carry brackets, three-body parity constraints (gate interconnection Hamiltonian) and carry qubits are introduced so that the values of the corresponding carry qubits are fixed by the constraints. The carry brackets can be arranged on the second layer above their sum counterparts (see the right panel of FIG. 20B), while the carry qubits can be arranged in the intermediate layer between these two layers (see the central panel of FIG. 20B). Using the six c 0 , c 1 , cs, c 2 , c 3 , n 5 auxiliary carry qubits, the nine missing constraints related to the gate interconnection can be constructed as shown in Table II.

Table II

[0266] In Table II, labels with two variables refer to the top - most qubits, and other labels with one variable are associated with either the middle - layer carry qubits or the output qubits in the first row of the bottom - most brackets (see FIG. 20B). The "comm.var." column indicates the common variables associated with each gate interconnect. Each such gate interconnect within the circuit enables the construction of parity constraints (gate - interconnect Hamiltonians) in the quantum system. Some of them, such as 4 - body constraints and 3 - body constraints, are highlighted in FIG. 20B. See also FIG. 14 for a 3D schematic of an example of a 3 - bit × 3 - bit multiplier. A total of 12 + 9 = 21 parity constraints compensate for 21 identifications made by the common input variables and gate interconnects when constructing the multiplication circuit from raw gates. Label n 0 and n 5 on the qubits associated with the single - body fields (single - body Hamiltonians), and the two - body Hamiltonians associated with the sets of labels \(\{(c 2 ),(n 2 ,c 2 )\}, \(\{(c 3 ),(n 3 ,c 3 )\}\) and \(\{(c 5 ),(n 4 ,c 5 )\}\), a 3 - bit × 3 - bit multiplication architecture can be programmed. That is, the integer n to be factored can be encoded in the quantum system. For illustration, FIG. 20B shows one of the two - body Hamiltonians necessary to program bit n 2 . Further, some carry inputs a1, a2 and sum input a0 are set to zero by adding additional Hamiltonians acting on \(\{(cs),(a 0 ,cs)\}, \(\{(c 0 ),(a 1 ,c 0 )\}\) and \(\{(c 2 ),(a 2 ,c 2 )\}\). This enables mimicking the logic of a half - adder within the execution of an AND.FA gate.

[0267] The foregoing 3-bit by 3-bit example can be generalized to any integer in a straightforward manner.

[0268] Although the above is directed to embodiments, other and further embodiments can be devised without departing from the scope determined by the claims.

Claims

1. A quantum computing method for performing prime factorization of an integer, comprising: a) determining a logic gate circuit (1000) including a plurality of logic gates (1010-1013, 1020-1023, 1030-1033, 1040-1043), the logic gate circuit being configured to calculate a multiplication function having the integer as an output, the determining step; b) For each of the plurality of logic gates, one by one, a gate-encoded Hamiltonian (H G ) determining step, wherein each gate-encoded Hamiltonian encodes the input-output relationship of one of the plurality of logic gates and is the sum of addend Hamiltonians, said determining step; c) providing a quantum system (1100) including components (401-404, 901-904, 911-914), each addend Hamiltonian of each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians being associated with each component of the quantum system, the providing step; d) determining a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit; e) determining a second set of short-range quantum interactions of the components based on the integer; f) developing the quantum system, including performing the first set of short-range quantum interactions and the second set of short-range quantum interactions; g) measuring at least a part of the quantum system to obtain a readout; h) determining prime factors of the integer based on the readout; A quantum computing method having the above steps.

2. The quantum system includes local subsystems (1110-1113, 1120-1123, 1130-1133, 1140-1143), each of which includes a subset of the components, and each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians is associated with a local subsystem. The quantum computing method according to Claim 1.

3. The step of determining the first set of short-range quantum interactions includes: for each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians, determining short-range quantum interactions from the gate-encoded Hamiltonian, the determined short-range quantum interactions acting within the local subsystem associated with the gate-encoded Hamiltonian, the determining step; performing the first set of short-range quantum interactions includes performing the determined short-range quantum interactions. The quantum computing method according to Claim 2.

4. The step of determining the first set of short-range quantum interactions comprises for each of the gate-encoded Hamiltonians of the plurality of gate-encoded Hamiltonians, a step of determining a monomer interaction from the gate-encoded Hamiltonian, wherein the determined monomer interaction is representable by a monomer Hamiltonian acting within the local subsystem associated with the gate-encoded Hamiltonian, the step of determining comprising executing the first set of short-range quantum interactions comprises executing the determined monomer interactions The quantum computing method according to claim 2 or 3.

5. Each addend Hamiltonian of each of the gate-encoded Hamiltonians of the plurality of gate-encoded Hamiltonians has an interaction coefficient, and the interaction coefficient is mapped to a monomer interaction The quantum computing method according to claim 4.

6. The step of determining the first set of short-range quantum interactions comprises for each of the gate-encoded Hamiltonians of the plurality of gate-encoded Hamiltonians, a step of determining one or more constraint interactions from the gate-encoded Hamiltonian, wherein the one or more constraint interactions are representable by a constraint Hamiltonian acting within the local subsystem associated with the gate-encoded Hamiltonian, the step of determining comprising executing the first set of short-range quantum interactions comprises executing the determined one or more constraint interactions The quantum computing method according to any one of claims 2 to 5.

7. (a) The logic gate circuit includes a plurality of gate interconnections (1050) between pairs of logic gates The step of determining the first set of short-range quantum interactions comprises for each of the gate interconnections (1050) of the plurality of gate interconnections, a step of determining one or more gate interconnection interactions from the gate interconnection, wherein the one or more gate interconnection interactions are representable by a gate interconnection Hamiltonian (1150) that couples at least two local subsystems of the quantum system, the step of determining comprising executing the first set of short-range quantum interactions comprises executing the determined gate interconnection interactions, and / or (b) The logic gate circuit includes a common variable of a group of logic gates, The step of determining the first set of the short-range quantum interactions is For each common variable of the set of common variables, a step of determining one or more common variable interactions from the common variables, wherein the one or more common variable interactions can be represented by a common variable Hamiltonian (1151-1153, 1161-1163, 1171-1173), and the determining step includes coupling at least two local subsystems of the quantum system, Executing the first set of the short-range quantum interactions includes executing the determined common variable interactions, The quantum computing method according to any one of claims 2 to 6.

8. The step of evolving the quantum system includes a step of evolving the quantum system towards the ground state of the total Hamiltonian, wherein the total Hamiltonian is a sum including a first Hamiltonian and a second Hamiltonian, the first Hamiltonian represents the first set of the short-range quantum interactions, and the second Hamiltonian represents the second set of the short-range quantum interactions, The quantum computing method according to any one of claims 1 to 7.

9. (a) The step of evolving the quantum system is The step of cooling the quantum system, or The step of performing adiabatic evolution of the quantum system, or The step of performing anti-adiabatic evolution of the quantum system, or The step of performing unitary evolution of the quantum system, or Includes any combination thereof, and / or (b) Each gate-encoded Hamiltonian of the plurality of gate-encoded Hamiltonians is a classical Hamiltonian or a quantum Hamiltonian, The quantum computing method according to any one of claims 1 to 8.

10. The logic gate includes an AND gate and / or an AND.FA gate, and each logic gate of the plurality of logic gates is one of an AND gate and an AND.FA gate, The quantum computing method according to any one of claims 1 to 9.

11. For each logic gate of the plurality of logic gates that is an AND gate, the gate-encoded Hamiltonian associated with the logic gate has the following form, The quantum computing method according to claim 10. 【Number 34】 Here, σ u , σ v and σ s are spin observables associated with the logical variables u, v, and s, respectively, where the logical variables u and v are input variables of the AND gate, and the logical variable s is an output variable of the AND gate.

12. For each of the plurality of logic gates that are AND.FA gates, the gate-coded Hamiltonian associated with the logic gate has the following form: The quantum computing method according to claim 10 or 11. 【Number 35】 Here, σu, σv, σs, σc, σs', and σc' are spin observables associated with the logical variables u, v, s, c, s', and c', respectively, and the logical variables u, v, s, and c are the AND. The input variables of the FA gate, and the logical variables s' and c' are the AND. The output variables of the FA gate.

13. A method for performing quantum computing, comprising: Providing a quantum system including components; Executing one or more first basic subroutines and / or one or more second basic subroutines; Measuring at least a part of the quantum system to obtain a reading; And having The first basic subroutine includes: Determining a first basic subsystem (S AND) of the quantum system including at least four components, Each addend Hamiltonian of the gate-coded Hamiltonian HAND defined by the following formula (A) is associated with each component of the first basic subsystem, 【Number 36】 The gate-coded Hamiltonian HAND encodes the input-output relationship of an AND gate having logical variables u and v as input variables and logical variable s as an output variable, σu, σv, and σs are spin observables associated with the logical variables u, v, and s, respectively, Determining the first basic subsystem; Determining short-range quantum interactions of the first basic subsystem from the gate-coded Hamiltonian HAND; Developing the quantum system by executing the determined short-range quantum interactions in the first basic subsystem; And having The second basic subroutine includes: Determining a second basic subsystem (S AND) of the quantum system including at least eight components, Each addend Hamiltonian of the gate-coded Hamiltonian HAND.FA defined by the following formula (B) is associated with each component of the second basic subsystem, 【Number 37】 The gate-coded Hamiltonian \(H_{AND.FA}\) has logical variables \(u\), \(v\), \(s\), and \(c\) as input variables and logical variables \(s'\) and \(c'\) as output variables, and codes the input-output relationship of the \(AND.FA\) gate. \(\sigma_{u}\), \(\sigma_{v}\), \(\sigma_{s}\), \(\sigma_{c}\), \(\sigma_{s'}\), and \(\sigma_{c'}\) are spin observables associated with the logical variables \(u\), \(v\), \(s\), \(c\), \(s'\), and \(c'\), respectively. The step of determining the second basic subsystem. The step of determining the short-range quantum interaction of the second basic subsystem from the gate-coded Hamiltonian \(H_{AND.FA}\). The step of developing the quantum system, including executing the determined short-range quantum interaction in the second basic subsystem. A quantum computing execution method having the above steps. [

14. ] A quantum computing method for inverting a logic gate circuit (200, 1000) including a plurality of logic gates (21 - 28, 1010 - 1013, 1020 - 1023, 1030 - 1033, 1040 - 1043). a) The step of providing the output of the logic gate circuit corresponding to the unknown input of the logic gate circuit. b) For each of the plurality of logic gates, one by one, a gate-encoded Hamiltonian (H G ) is determined, wherein each gate-encoded Hamiltonian encodes the input-output relationship of one of the plurality of logic gates and is the sum of the addend Hamiltonians, and the step of determining; c) The step of providing a quantum system (300, 700, 1100) including components (320, 401 - 404, 750, 901 - 904, 911 - 914), wherein each addend Hamiltonian of each gate-coded Hamiltonian of the plurality of gate-coded Hamiltonians is associated with each component of the quantum system. d) The step of determining a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit. e) The step of determining a second set of short-range quantum interactions of the components based on the output of the logic gate circuit. f) The step of developing the quantum system, including executing the first set of short-range quantum interactions and the second set of short-range quantum interactions. g) The step of measuring at least a part of the quantum system to obtain a readout. h) The step of determining the unknown input of the logic gate circuit based on the readout. A quantum computing method having the above steps. [

15. ] An apparatus (1200) for performing prime factorization of an integer. A classical computing system (1210). A quantum system (1250) including components. A quantum processing unit (1220). A measurement unit (1230), and The classical computing system Determining a logic gate circuit including a plurality of logic gates, the logic gate circuit being configured to calculate a multiplication function having the integer as an output; the determining step; Determining, for each of the plurality of logic gates, one gate-encoded Hamiltonian per logic gate, each gate-encoded Hamiltonian encoding the input-output relationship of one of the plurality of logic gates and being a sum of addend Hamiltonians, and each addend Hamiltonian of each of the plurality of gate-encoded Hamiltonians being associated with each component of the quantum system; the determining step; Determining a first set of short-range quantum interactions of the components based on the logic gates of the logic gate circuit; Determining a second set of short-range quantum interactions of the components based on the integer; and being configured to execute The quantum processing unit includes executing the first set of short-range quantum interactions and the second set of short-range quantum interactions, and is configured to evolve the quantum system; The measurement unit is configured to measure at least a part of the quantum system to obtain a readout; The classical computing system is further configured to determine prime factors of the integer based on the readout. Quantum computing device.

16. An apparatus (1200) for inverting a logic gate circuit including a plurality of logic gates, A classical computing system (1210), A quantum system (1250) including components, A quantum processing unit (1220), A measurement unit (1230), and comprising The classical computing system Providing an output of the logic gate circuit corresponding to an unknown input of the logic gate circuit; Determining, for each of the plurality of logic gates, one gate-encoded Hamiltonian per logic gate, each gate-encoded Hamiltonian encoding the input-output relationship of one of the plurality of logic gates and being a sum of addend Hamiltonians, and each addend Hamiltonian of each of the plurality of gate-encoded Hamiltonians being associated with each component of the quantum system; the determining step; Determining a first set of short-range quantum interactions of the component based on the logic gate of the logic gate circuit; Determining a second set of short-range quantum interactions of the component based on the output of the logic gate circuit; and The quantum processing unit is configured to execute the first set of the short-range quantum interactions and the second set of the short-range quantum interactions, and is configured to develop the quantum system. The measurement unit is configured to measure at least a part of the quantum system to obtain a readout. The classical computing system is further configured to determine the unknown input of the logic gate circuit based on the readout. Quantum computing device.

Citation Information

Patent Citations

  • Solving complex problems using self-organizing logic gates and circuits and self-organizing circuits

    JP2018530842A

  • Hybrid Quantum-Classical Computer System and Method for Performing Function Inversion

    US20200394547A1

  • Invertible logic circuit device

    WO2019208581A1