Quantum multiplication circuit

WO2026054793A3PCT designated stage expired Publication Date: 2026-04-16PSIQUANTUM CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-11-27
Publication Date
2026-04-16

AI Technical Summary

Technical Problem

Quantum computing operations, particularly multiplication and addition, incur significant overhead due to their frequent performance, necessitating improvements in efficiency and complexity reduction.

Method used

Implementing a bidirectional controlled adder circuit in quantum multiplication operations, combined with correction operators, to optimize qubit operations and reduce computational cost.

Benefits of technology

The proposed method significantly reduces the number of Toffoli gates required for quantum multiplication, achieving up to a 50% cost reduction for large computations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2024057735_16042026_PF_FP_ABST
    Figure US2024057735_16042026_PF_FP_ABST
Patent Text Reader

Abstract

Quantum computing devices, circuits, and methods for performing a quantum multiplication of two numbers. A first quantum register is prepared in a first state indicative of a first number, and a second quantum register is prepared in a second state indicative of a second number. A third quantum register is prepared in an initial state. Each of a plurality of controlled bidirectional addition circuits performs controlled bidirectional addition of the second number into the third quantum register, controlled on a respective qubit of the first plurality of qubits. A plurality of correction operator circuits operates on the first, second and third quantum registers to remove discrepancies between performing controlled bidirectional addition and performing controlled addition. Qubits in the third quantum register are output in a prepared state indicative of a product of the first and second numbers.
Need to check novelty before this filing date? Find Prior Art

Description

Attorney Docket No. 7246-02001Quantum Multiplication CircuitTechnical Field

[0001] Embodiments herein relate generally to quantum computational methods, systems and devices, for performing multiplication operations.Background

[0002] Quantum computing can be distinguished from “classical” computing by its reliance on structures referred to as “qubits.” At the most general level, a qubit is a quantum system that may exist in one of two orthogonal states (denoted as 10) and 11) in the conventional bra / ket notation) or in a superposition of the two states (e.g., -7= (| 0) + |1)). By operating on a system (or ensemble) of qubits, a quantum computer may quickly perform certain categories of computations that would require impractical amounts of time in a classical computer.

[0003] Quantum computational methods almost ubiquitously compute the addition and / or multiplication of numbers during the computation of a desired quantity. Because these addition and / or multiplication operations may be performed many times in a quantum computation, they may add a significant amount of overhead to the overall computation. Accordingly, improvements in the field of quantum computational systems and methods to increase the efficiency and reduce the complexity of quantum multiplication and addition operations are desired.Summary

[0004] Some embodiments described herein include quantum computing devices, quantum circuits, systems, and methods for performing a quantum multiplication of two numbers.

[0005] In some embodiments, a first quantum register is prepared in a first state indicative of a first number, and a second quantum register is prepared in a second state indicative of a second number. A third quantum register may be prepared in an initial state, which may be the null state. Each of the first, second and third quantum registers may include respective pluralities of qubits.

[0006] In some embodiments, a plurality of controlled bidirectional addition circuits is configured to perform controlled bidirectional addition of the second number into the third- i .Attorney Docket No. 7246-02001 quantum register. Each controlled bidirectional addition circuit may be controlled on a respective qubit of the first plurality of qubits.

[0007] In some embodiments, a plurality of correction operator circuits is configured to operate on the first, second and third quantum registers to remove discrepancies between performing controlled bidirectional addition and performing controlled addition.

[0008] In some embodiments, the qubits of the third quantum register may be output in a prepared state indicative of a product of the first and second numbers. In some embodiments, the qubits of the third quantum register are then measured to produce classical measurement results, and the classical measurement results are stored in a non-transitory computer- readable memory medium.

[0009] Ute techniques described herein may be implemented in and / or used with a number of different types of devices, including but not limited to photonic quantum computing devices and / or systems, hybrid quantum / classical computing systems, and any of various other quantum computing systems.

[0010] This Summary is intended to provide a brief overview of some of the subject matter described in this document. Accordingly, it will be appreciated that the above-described features are merely examples and should not be construed to narrow the scope or spirit of the subject matter described herein in any way. Other features, aspects, and advantages of the subject matter described herein will become apparent from the following Detailed Description, Figures, and Claims.Brief Description of the Drawings[Oil] For a better understanding of the various described embodiments, reference should be made to the Detailed Description below, in conjunction with the following drawings in which like reference numerals refer to corresponding parts throughout the Figures.

[0012] Figure 1A is a system diagram illustrating a quantum computing system, according to some embodiments;

[0013] Figures 1B-G illustrate the utilization of surface codes to constructed an error-corrected fault-tol erant logical qubit, according to some embodiments;

[0014] Figure 2A illustrates a quantum circuit for implementing a Gidney Adder without carry-out, according to some embodiments;Attorney Docket No. 7246-02001

[0015] Figure 2B illustrates a quantum circuit for implementing addition without cany -out in a simplified notation, according to some embodiments;

[0016] Figure 2C illustrates a quantum circuit for implementing a Gidney Adder with cany- out, according to some embodiments;

[0017] Figure 2D illustrates a quantum circuit for implementing addition with carry-out in a simplified notation, according to some embodiments;

[0018] Figure 3 illustrates a quantum circuit for implementing subtraction without carry-out, according to some embodiments;

[0019] Figures 4A and 4B illustrated controlled adder circuits, with and without cany-out, respectively, according to some embodiments;

[0020] Figure 5A illustrates a quantum circuit to implement controlled bi-directional addition without carry-out, according to some embodiments;

[0021] Figure 5B illustrates a quantum circuit to implement controlled bi-directional addition with carry-out, according to some embodiments;

[0022] Figure 6A illustrates a quantum circuit to implement multiplication of two .' / -digit numbers, according to some embodiments;

[0023] Figure 6B illustrates a quantum circuit to implement multiplication of an n-digit number and an m-digit number, according to some embodiments;

[0024] Figure 7 A illustrates a quantum circuit to implement multiplication of two w-digit numbers using bidirectional controlled addition, according to some embodiments;

[0025] Figure 7B illustrates a quantum circuit to implement multiplication of an n-digit number and an iw-digit number using bi-directional controlled addition, according to some embodiments;

[0026] Figure 8 illustrates a quantum circuit to implement modular multiplication of two n~ digit numbers, according to some embodiments;

[0027] Figure 9 illustrates a quantum circuit to implement modular multiplication of two n- digit numbers mod 2", according to some embodiments;

[0028] Figure 10 illustrates a quantum circuit to implement modular multiplication mod y. where p is a prime number, according to some embodiments;

[0029] Figure 11 illustrates quantum circuit subroutines of the ModMultStep operation, according to some embodiments;Attorney Docket No. 7246-02001[030 [ Figure 12 illustrates a quantum circuit for a modified ModMultStep operation that incorporates bi-directional controlled addition, according to some embodiments;

[0031] Figure 13 is a flowchart diagram illustrates a method for utilizing bi-directional controlled addition to multiply two numbers, according to some embodiments.

[0032] While the features described herein may be susceptible to various modifications and alternative forms, specific embodiments thereof are shown by way of example in the drawings and are herein described in detail. It should be understood, however, that the drawings and detailed description thereto are not intended to be limiting to the particular form disclosed, but on the contrary', the intention is to cover all modifications, equivalents and alternatives falling within the spirit and scope of the subject matter as defined by tire appended claims.DETAILED DESCRIPTION

[0033] Disclosed herein are examples (also referred to as “embodiments”) of quantum computing systems and methods for implementing a quantum multiplication circuit.[034 [ Although embodiments are described with specific detail to facilitate understanding, those skilled in the art with access to this disclosure will appreciate that the claimed invention may be practiced without these details. Reference will now be made in detail to embodiments, examples of which are illustrated in the accompanying drawings. In other instances, well-known methods, procedures, components, circuits, and networks have not been described in detail so as not to unnecessarily obscure aspects of the embodiments.Overview of Quantum Computing[035 [ To facilitate understanding of the disclosure, an overview of relevant concepts and terminology is provided in the following paragraphs.

[0036] Quantum computing relies on the dynamics of quan tum objects, e.g., photons, electrons, atoms, ions, molecules, nanostructures, and the like, which follow' the rules of quantum theory. In quantum theory, the quantum state of a quantum object is described by a set of physical properties, the complete set of which is referred to as a mode. In some embodiments, a mode is defined by specifying the value (or distribution of values) of one or more properties of the quantum object. For example, in the case where the quantum object is a photon, modes may be defined by the frequency of the photon, the position m space of the photon (e.g., which waveguide or superposition of waveguides the photon is propagatingAttorney Docket No. 7246-02001 within), the associated direction of propagation (e.g., the ^-vector for a photon in free space), the polarization state of the photon (e.g., the direction (horizontal or vertical) of the photon’s electric and / or magnetic fields), a time window in which the photon is propagating, the orbital angular momentum state of the photon, and the like.

[0037] Persons of ordinary skill in the art will be able to implement examples using any of a variety of types of quantum systems, including but not limited to photonic systems, solid state system, topological quantum computing systems, hybrid quantum computing systems, and superconducting systems, among other possibilities.[038J As used herein, a “qubit” (or quantum bit) is a quantum sy stem with an associated quantum state that may be used to encode information, A quantum state may be used to encode one bit of information if the quantum state space can be modeled as a (complex) two- dimensional vector space, with one dimension in the vector space being mapped to logical value 0 and the other to logical value 1. In contrast to classical bits, a qubit may have a state that is a superposition of logical values 0 and 1. More generally, a “qudit” describes any quantum system having a quantum state space that may be modeled as a (complex) n- dimensional vector space (for any integer «), which may be used to encode log2(n) bits of information . For the sake of clarity of description, the term “qubit” is used herein, although in some embodiments the system may also employ quantum information carriers that encode information in a manner that is not necessarily associated with a binary bit, such as a qudit or a plurality of qubits encoded to form an error-corrected logical q ubit. For example, embodiments herein for quantum computational methods and circuits that utilize fault- tolerant quantum computing schemes use the term “qubit” to refer to an error-corrected logical qubit that contains a plurality' of physical qubits entangled together in an errorcorrecting code. Embodiments herein use the term “quantum register” to refer to a set of one or more qubits used in a quantum computational method. Typically, distinct quantum registers are separated at the logical layer, i.e., different quantum registers serve distinct logical purposes in a quantum computing method or circuit.

[0039] Qubits (or qudits) may be implemented m a variety of quantum systems. Examples of qubits include: polarization states of photons; presence of photons in waveguides; or energy states of molecules, atoms, ions, nuclei, or photons. Other examples include other engineered quantum systems such as flux qubits, phase qubits, or charge qubits (e.g., formed from aAttorney Docket No. 7246-02001 superconducting Josephson junction); topological qubits (e.g., Majorana fermions); or spin qubits formed from vacancy centers (e.g., nitrogen vacancies in diamond).Figure 1 A - Quantum Computing System

[0040] Figure 1A is a system diagram of a quantum computing system 101 that may be utilized to implement method steps of embodiments described herein. As illustrated, the system includes a classical computing system 103 coupled to a quantum processing unit (QPU) 105 over a classical channel 112. The classical channel may relay classical information between the classical computing system and the QPU.

[0041] In some embodiments, the classical computing system 103 includes one or more non- transitory computer-readable memory' media 104, one or more central processing units (CPUs) or processor(s) 102, a power supply, an input / output (I / O) subsystem, and a communication bus interconnecting these components. The processor(s) 102 may execute modules, programs, and / or instructions stored in memory 104 and thereby perform processing operations. The processor(s) may additionally or alternatively perform operations based on information and / or instructions received from tire QPU 105 over the channel 112. The processor may comprise a dedicated processor, or it may be a field programmable gate arrays (FPGA), an application specific integrated circuit (ASIC), or a “system on a chip” that includes classical processors and memory, among other possibilities. In some embodiments, memory 104 stores one or more programs (e.g., sets of instructions) and / or data structures and is coupled to the processor(s).

[0042] The classical computing system may be classical in the sense that it operates computer code represented as a plurality of classical bits that may take a value of 1 or 0. Programs may' be writen in the form of ordered lists of instructions and stored within the classical (e.g., digital) memory' 104 and executed by the classical (e.g., digital) processor 102 of the classical computer. The memory 104 is classical in the sense that it stores data and / or program instructions in a storage medium in the form of bits, which have a single definite binary state at any' point in time. The processor may' read instructions from the computer program in the memory' 104 and / or write data, into memory', and may optionally receive input data from a source external to the computer 103, such as from a user input device such as a mouse, keyboard, or any other input device. The processor 102 may execute program instructions that have been read from the memory 104 to perform computations on data readAttorney Docket No. 7246-02001 from the memory 104 and / or input from the QPU, and generate output from those instructions. The processor 102 may store that output back into tire memory 104 and / or provide the output to the QPU over the channel 112.

[0043] Tire QPU 105 may include a plurality of qubits and a controller 106 configured to interface with a plurality of qubits 110. In some embodiments, the qubits are divided into one or more independent qubit modules, where each qubit module includes a self-contained plurality of fault-tolerant qubits, and different qubit modules may be interchangeably used for various steps within a quantum computation. The controller 106 may include physical hardware to interact with and / or perform operations on the qubits, e.g., to apply quantum gates or perform other operations. In some embodiments, the controller further includes a classical processor, potentially coupled to its own dedicated non-transitory (classical) memory, that is configured to direct the physical hardware to interact with the qubits and communicate with the processor of the classical computing system 103 over the channel 112. Alternatively, the classical processor of the classical computing system 103 may directly communicate with the hardware of the controller to provide instructions for interacting with and manipulating the qubits. The qubits may be configured to evolve in time under the directed influence of the controller, and a measurement system 108 may at times perform quantum measurements on all or a subset of the qubits to obtain quantum measurement results in the form of classical data bits (e.g., ones and zeros). The classical data from the measurement results may be intermediate results that inform behavior of the classical computing system and / or the quantum controller 106 during a quantum computation, and they may additionally include classical results of the quantum computation. In some embodiments, the QPU further includes one or more decoders configured to receive and decode the classical measurement results, and the decoded measurement results may be provided to the classical computing system tor processing. The measurement results may be communicated to the classical computing system and / or the controller 106, and further the classical computing system may provide directions and / or instructions to the controller 106 and the measurement system 108 to guide the behavior of the QPU while performing a quantum computation. For example, the classical computing system 103 may provide classical data signals used for performing a multiplication operation within the QPU 105, in response to which the controller may manipulate the qubits 110 to perfonn the multiplication operation.Attorney Docket No. 7246-02001Figures 1B-G - Surface Codes and Physical implementations

[0044] Qubits (and operations on qubits) may be implemented using a variety of physical systems. In some embodiments, qubits are provided in an integrated photonic system employing waveguides, beam splitters, photonic switches, and single photon detectors, and the modes that may be occupied by photons are spatiotemporal modes that correspond to presence of a photon in a waveguide. Modes may be coupled using mode couplers, e.g., optical beam splitters, to implement transformation operations, and measurement operations may be implemented by coupling single-photon detectors to specific waveguides. One of ordinary' skill m the art with access to this disclosure will appreciate that modes defined by any appropriate set of degrees of freedom, e.g., polarization modes, temporal modes, and the like, may be used without departing from the scope of the present disclosure. For instance, for modes that only differ in polarization (e.g., horizontal (H) and vertical (V)), a mode coupler may be any optical element that coherently rotates polarization, e.g., a birefringent material such as a waveplate. For other systems such as ion trap systems or neutral atom systems, a mode coupler may be any physical mechanism that couples two modes, e.g., a pulsed electromagnetic field that is tuned to couple two internal states of the atom / ion.

[0045] In some embodiments of a photonic quantum computing system using dual-rail encoding, a qubit may be implemented using a pair of waveguides. In some embodiments, a photon in a first waveguide of the pair and no photon in a second w aveguide of the pair (also referred to as a vacuum mode) may correspond to the i 0) state of a photonic qubit. Alternatively, a state with a photon in the second waveguide and no photon in the first waveguide may correspond to the 11) state of the photonic qubit. To prepare a photonic qubit in a known state, a photon source may be coupled to one end of one of the waveguides. Hie photon source may be operated to emit a single photon into the waveguide to which it is coupled, thereby preparing a photonic qubit in a known state. Photons travel through tire waveguides, and by periodically operating the photon source, a quantum system having qubits whose logical states map to different temporal modes of the photonic system may be created in the same pair of waveguides. In addition, by providing multiple pairs of waveguides, a quantum system having qubits whose logical states correspond to different spatiotemporal modes may be created. It should be understood that the waveguides in such aAttorney Docket No. 7246-02001 system need not have any particular spatial relationship to each other. For instance, they may be but need not be arranged in parallel.

[0046] Some embodiments described below relate to physical implementations of unitary operations that couple modes of a quantum system, which may be understood as transforming the quantum state of the system. For instance, if the initial state of the quantum system (prior to mode coupling) is one in which one mode is occupied with probability 1 and another mode is unoccupied with probability 1 (e.g., a state 110) in Fock notation), mode coupling mayresult in a state in which both modes have a nonzero probability of being occupied, e.g., a state aJ 10) + a2|01), where |aT|2+ |a2|2= 1. In some embodiments, operations of this kind may be implemented by using beam splitters to couple modes together and variable phase shifters to apply phase shifts to one or more modes. The amplitudes ai and ci?, depend on the reflectivity (or transmissivity) of tire beam splitters and on any phase shifts that are introduced.

[0047] A single physical qubit (e.g., such as the 2-level physical qubit illustrated in Figure IB with a quantum state |i / ») = a:J0) +a2 |1?) may be used for quantum computation in principle. However, individual physical qubits are generally highly susceptible to noise and decoherence. Fault-tolerant quantum computing utilizes a plurality of entangled physical qubits to encode a single logical qubit to mitigate the frailty and / or short coherence times of individual physical qubits. In fault-tolerant quantum computing schemes, a plurality of physical qubits is entangled together according to a specific error-correcting code (e.g., using fusion measurements on resource states) to produce a single logical qubit that is less susceptible to noise and decoherence, such as is shown in Figure 1C,

[0048] Figure 1 C illustrates one example for constructing a fault-tol erant logical qubit using a circuit-based approach. In the illustrated example, the light shaded circles are data qubits (e.g., qubits 125-131) that encode quantum information. The data qubits are entangled with adjacent measure qubits, illustrated as dark shaded circles (such as measure qubit 123). Tire measure qubits may be measured to determine aspects of the quantum information encoded in the data qubits. The example illustrated in Figure 1C has a code length of d — 12. Fusionbased approaches to encoding fault-tolerant logical qubits may also be used for embodiments described herein. Encoding qubits in this manner causes the resultant logical qubit to be less sensitive to error and noise, and resultant errors may be fixed via quantum error correction.Attorney Docket No. 7246-02001Encoding a logical qubit may itself be vulnerable to errors, which may likewise be corrected and / or tolerated.

[0049] In some quantum computing methodologies, such as fusion-based quantum computing, a logical qubit is encoded from a plurality of physical qubits using a sequence of specific measurements (e.g., stabilizer measurements). The measurement sequence may be constructed where a subset of the physical qubits is measured (e.g., collapsing the quantum state and producing classical information, i.e., the measurement result) in such a way that the remaining unmeasured / un-collapsed degrees of freedom (e.g., a 2-dimensional subspace which has support over all the physical qubits) form tire desired encoded logical qubit. Accordingly, the processes of performing stabilizer measurements and / or encoding a fault- tolerant logical qubit may receive a plurality of physical qubits as input and as output may produce both the encoded logical qubit and classical information (e.g., syndrome graph data) resulting from the measurement sequence.[0501 In some embodiments, a logical qubit may be a component of a quantum error- correcting code where an operation (for example, a quantum gate acting on the logical qubit) may be performed on encoded logical information. For example, a logical qubit may include multiple resources states that are entangled with one another in a specific way. Resource states are defined as a plurality of physical qubits prepared in a specific entangled manner. In some embodiments, 6-qubit resource states may be used, or other types of resource states may be used.[0511 If the above-described surface code measurement schedule is applied for numerous time steps, the system effectively acts as a fault-tolerant quantum memory for the logical qubit encoded by the underlying surface code or, viewed another way, as a fault-tolerant logical identity gate on the logical qubit that is encoded by the underlying surface code. Viewed yet another way, this process operates as a fault-tolerant logical channel.

[0052] Figure ID illustrates a 3-dimensional graphical depiction of such a fault-tolerant logical identity gate. The surface labeled 114 is the input to the gate and includes an arbitrary logical state encoded in a surface code, represented as the input checkerboard surface. Likewise, the surface labeled 118 identifies the output qubits after the identity gate Zhas been applied to it. As one example, in a circuit-based implementation the fault-tolerant logical qubit shown in Figure 1C may be utilized as the input surface 114, which may be operated on within the illustrated volume and output as the surface 1 18. Tire input and output surfaces.Attorney Docket No. 7246-02001 which may be associated with either the physical or relational arrangement of qubits, are connected to each other via an intervening volume that represents the unique set of measurements to be applied overtime. Accordingly, in Figure ID, time flows from left to right and the lighter shaded (front and back) and darker shaded (top and bottom) sides of the boundaries of the volume depict whether the primal or dual plaquettes are disposed on that boundary. Figure IE represents the same concept but written in a more familiar quantum circuit notation illustrating the analogy between the more familiar quantum circuit. While Figure ID shows the logical identity gate, any gate can be depicted in this manner and such a depiction is one example of a logical block that specifies a set of instructions to be performed on the underlying surface code qubits to perform a logical operation (the identity gate in this example) on the logical qubit that is encoded by surface code. Other examples of such gates are the S gate, the Hadamard gate, and the CX gate, among other possibilities. This combination of gates may be used, for example, to implement the quantum circuits described in various embodiments.

[0053] The protocol for preparing an encoded logical state may contain two parameters, L and Ld. Here L is referred to as the “distance” of the scheme, which corresponds to the length and width of the cross section shown in Figure I D - it determines the code distance of the surface code state being prepared. In some embodiments, L may be separated into two parameters, Lx and Ly, i.e., the code distance may be different in the two spatial directions. This may be desirable, for example, when there is an asymmetery in the noise model or logical error rates in the X and Z directions, and the code distance may be separately tuned in the two spatial directions. Ldis referred to as the “depth” of the scheme - it can be thought of as simulated time, i.e. the number of rounds of stabilizer measurements in CBQC, or the number of layers of resource states in FBQC. LAmay determine the number of stabilizer checks in the protocol from which information may be gathered for post-selection. A minimal depth of Ld= 2 may be chosen, however, longer depths may also be used (using more overhead) to allow for more information to be collected m order to better predict logical errors on the output state.

[0054] Figures IF and 1G illustrate a specific example in fusion-based quantum computing (FBQC) of an arrangement of phy sical qubits that may be used to perform a (Z2, Z3) measurement on four logical qubits qi-q4. The individual circles shown in the rectangular sheet 120 in the top half of Figure 1G represent individual physical qubits, and the linesAttorney Docket No. 7246-02001 connecting adjacent qubits indicate entanglement (e.g., via fusion measurements). In the stack of d = 9 layers shown at 122. of Figure 1G, the vertical direction represents the depth of the logical qubit (i.e., time), which is a sequence of nine entangling measurements performed on the 9x9 grid of physical qubits representing each of the qubits qi-tp as well as a portion of the auxiliary qubits 121. While Figures IF and 1G illustrate an arrangement of physical qubits that may be used to perform a simple dual -qubit measurement, it is understood by those of ordinary' skill in the art how more complex arrangements of qubits may be utilized to perform the operations shown in the quantum circuit diagrams shown in Figures 2-12.Quantum Multiplication Circuit with Reduced Toffoli Gates

[0055] Quantum circuits for multiplying integers may consist of controlled adders. Usually, a controlled adder is twice as computationally expensive as an uncontrolled adder. Embodiments herein utilize a modified version of a controlled adder, referred to herein as a “bidirectional controlled adder” or “bidirectional controlled addition”, which is advantageously not significantly more expensive than an uncontrolled adder, to reduce the computational cost of a quantum multiplication circuit. In a controlled adder, when the control qubit is “0”, instead of performing an addition, the controlled adder performs no operation. For the bidirectional controlled adder disclosed herein, instead of performing no operation when the control qubit is “0”, it performs a subtraction. Using a bidirectional controlled adder together with corrections to remove or reduce discrepancies between the bidirectional controlled adder and a normal controlled adder, computationally cheaper operations may enable a reduction of the cost of multiplication by up to a factor of 2. The full factor of 2 is approached tor sufficiently large quantum computations (e.g., for the multiplication of two sufficiently large numbers), so for smaller numbers a smaller reduction in computational cost may result (e.g., '-35% reduction in some cases). Multiplication can be the dominant cost in arithmetic-based simulation algorithms, for example, in calculating a kinetic energy or a Coulomb potential energy using Newton’s method. For example, in some applications this may result in a ~30% cost reduction by reducing the number of Toffoli gates.Figures 2-5 - Quantum Addition Circuits

[0056] Figures 2-5 and the following paragraphs provide a summary of different versions of addition circuits. One example, shown in Figure 2A, is an adder that takes two n-qubitAttorney Docket No. 7246-02001 numbers a and b and maps|a)|h + amod2n), i.e., the adder outputs another n- qubit number. Ulis adder circuit is described in Halving the Cost of Quantum Addition, Gidney, Quantum 2, 74 (2018). It uses n — 1 Toffoli gates. Figure 2A illustrates an adder for n = 5. Figure 2B illustrates in a simplified notation the quantum addition circuit shown in Figure 2A.

[0057] Figure 2C illustrates a slightly modified circuit that takes two n-qubit numbers and outputs an (n + 1) -qubit number which is tire actual sum of the two integers (that is, not the sum mod 2n). It utilizes one more Toffoli gate than the circuit shown in Figure 2A, and maintains the final carry bit. Figure 2D illustrates in a simplified notation the quantum addition circuit shown in Figure 2C.

[0058] Both of the circuits in Figures 2A and 2C also have an input carry bi t cinthat may be set to 0 in a standard addition circuit. This input carry may be useful for performing a subtraction instead of an addition. For example, in a two's-complement encoding of integers, if all bits of an integer a are flipped, a number a ~ —a — 1 is obtained. By setting the input carry to 1 and flipping all bits of a, a subtraction may be performed with n — 1 Toffolis using the standard addition circuit, by modifying the circuit of Figure 2B as shown in Figure 3.

[0059] Figures 4A and 4B illustrated controlled adder circuits, with and without cany-out, respectively. The circuits shown in Figures 4A-B are described by Gidney in[arXiv: 1709.06648] and use approximately twice as many Toffoli gates as the uncontrolled adder circuits show n in Figures 2A-B.

[0060] Embodiments herein improve on previous quantum addition and multiplication circuits by implementing a bidirectional controlled adder, as shown for the case without carry-out in the circuit diagram illustrated in Figure 5A. If the control qubit is used to selectively flip |a) and the input cany using a bunch of CNOTs (i.e., no Toffoli gates), a standard uncontrolled adder may be used to do a controlled plus / minus addition where the control qubit determines if an addition or subtraction mod 2nis performed. Figure 5 B illustrates a similar bidirectional adder circuit to Figure 5A that keeps the output carry qubit, costing one more Toffoli gate. In this case, if f a and b are positive integers, the operation either outputs b + a (if Ctrl = 1) or b + 2n— a (if Ctrl = 0).Attorney Docket No. 7246-02001Figures 6A-B and 7A-B - Quantum Multiplication Circuits

[0061] Figures 6A-B and 7A-B illustrate various examples of utilizing quantum addition circuits to construct quantum multiplication circuits, according to various embodiments. Figure 6A illustrates a standard multiplication circuit which takes two n-qubit numbers and computes their 2n-qubit product. The circuit illustrated in Figure 6A computes xy ~ xk ’ 2fey. An addition of xfe2ky may be performed with a controlled addition controlled on xfe(the k-th bit of x where x0is the least significant bit), adding y shifted by k bits. Accordingly, the circuit in Figure 6A includes n controlled n-qubit additions with cany-out.Figure 6B illustrates a generalization of the circuit shown in Figure 6A, which takes an n-qubit number and an m-qubit number and computes their nm-qubit product.

[0063] In some embodiments, an improved quantum multiplication circuit is implemented that utilizes controlled bidirectional addition, which takes two n-qubit numbers and computes their 2n-qubit product, as shown in Figure 7A. As illustrated, by replacing each controlled addition with a bidirectional controlled addition, each step will add (1 — xk)2n+k+ (2xfe— 1) • 2,c• y. Accordingly, tor xfe= 1, 2ky is added (as in a standard controlled adder), but for x,. = 0, 2n+k— 2ky is added. After n controlled plus-minus additions, the following result is obtained (e.g., after performing the operations 708a-d in Figure 7 A):

[0064] Yk.-o (1 ~ xfe)2n+k+ (2xfe— 1) ■ 2Ky — 2xy + 22n— 2n(x + 1 + y) + y (1)

[0065] Equation (1) may be corrected to obtain the desired product, xy. For example, 2n(x + 1) may be added using an n-qubit adder with the input cany set to 1. A 2n-qubit subtraction of 22n+ y may be performed, as well as a n-qubit addition of 2"y . The resulting number may be divided by two by simply relabeling the qubits. These corrections may be performed by the correction circuits 710a-d shown in Figure 7A. In total, the circuit shown in Figure 7 A performs multiplication of two n-digit qubits with only n2+ 4n + 3 Toffoli gates.

[0066] Figure 7B illustrates a generalization of the circuit shown in Figure 7 A, which takes an n-qubit number and an m-qubit number and computes their nm-qubit product using controlled bidirectional addition, utilizing nm + 2n + 2m + 3 Toffoli gates.Attorney Docket No. 7246-02001Modular Quantum Multiplication Circuits

[0067] Figure 8 illustrates a quantum circuit configured to perform modular multiplication mod 2nfor some positive integer n. The circuit shown in Figure 8 is computationally cheaper than the multiplication circuit illustrated in Figure 6A, since the bits after the n~th most significant bit are not kept.

[0068] An addition of 2ky mod 2ncorresponds to an n ■■■■ / c-qubit addition using only the n ■■■■ k least significant bits. The circuit shown in Figure 8 is improved upon in the circuit illustrated in Figure 9, which utilizes controlled bidirectional addition. For the circuit shown in Figure 9, a factor of 2 is saved in computational load compared to the Figure 8 circuit by replacing controlled adders with bidirectional controlled adders.

[0069] For the Figure 9 circuit, the result may be treated as an n + 1 -qubit number as it is expected to generate 2xy as an output (up to corrections), so all addition operations are mod 2n+1. Similar to the circuits shown in Figures 7A-B, the output may be corrected and divided by two by relabeling qubits. The corrections for Figure 9 are somewhat simpler than for Figure 7 A, since the resulting number after the controlled bidirectional additions is:

[0070] 2xy + 22n— 2n(x + 1 + y) + ymod2n+1= 2xy — 2n(x + 1 + y) + ymod2n+1(2)

[0071] The total number of Toffoli gates isk + n — 0.5n2+ 1.5n, since the modular addition of x0+ 1 + yGis performed using CNOT gates. Note that multiplication mod 2" may be useful when multiplying two floating-point numbers,

[0072] Figure 10 illustrates an example quantum circuit configured to perform modular multiplication mod p, where p is a prime number. As illustrated, multiplication may be performed using n / w "ModMultStep" operations, shown here tor w = 4, where w is the "window size".

[0073] Figure 1 1 is a quantum circuit illustrating the subroutines involved in each ModMultStep operation, for w = 4. As illustrated, Figure 11 contains w controlled adders, a quantum read-only memory (QROM) load of 2Welements, an n + w-qubit addition and an uncomputation of the QROM. The Toffoli count of this circuit is (2n + l)w + 2W+ (n + w ■■■■ 1) + 3 • 2W / 2. Since this is repeated n / w times, and there are 2n additional Toffoli gates at the end of the circuit, and the total Toffoli count of this multiplication operation isAttorney Docket No. 7246-02001

[0074] 2n2+ 4n + ( 2W+ 3 ■ 2W''2+ n - 1) (3)

[0075] For a window size of w = log2n, the Toffoli count is

[0077] or approximately 2n2for large n.

[0078] In some embodiments, the first half of each ModMultStep in the Figure 10 circuit is replaced with controlled bidirectional adders, as shown in Figure 12. As illustrated, the first half of each ModMultStep consists of tv controlled additions that are controlled on the w bits of x starting with the wk -th least significant bit. This number is referred to herein as x =• The input to the circuit is an n-qubit number an n + w-qubit number, tire result shown in Equation (5):

[0079] result

[0080] For the circuit in Figure 12 with controlled bidirectional adders, the input number Zfc-! may be initially doubled by adding a 0 as the least significant bit. This may be performed initially to anticipate that the result will be divided by two at the end of the computation. The integer y may be treated as an n + 1 -qubit number (with the most significant bit set to 0) and controlled bidirectional additions may be performed to obtain:

[0082] - 2 - result ■■■■ 2n(x + 1) + 2n+w+ y ■■■■ 2wy (6)

[0083] Corrections may be applied by performing a w-qubit addition to add 2n(x + 1), an n + w + 1 -qubit subtraction to subtract 2n+w+ y, and an n-qubit addition to add 2wy. The resulting quantity 2 • result may be divided by two by relabeling qubits to obtain the final result. The total Toffoli count of the ModMultStep operation is then (n + 3)w + 2W+ (3n + w) + 3 • 2K' / 2. Accordingly, the total Toffoli count of the multiplication is

[0085] For a window size of w = log2n, the Toffoli count isAttorney Docket No. 7246-02001

[0087] or approximately n2for large n.

[0088] To summarize the Toffoli count improvements provided by embodiments described herein, the quantum circuit for addition of two w-digit integers shown tn Figure 7 A (which uses bidirectional controlled adders) utilizes n2+ 4n + 3 Toffoli gates, compared to the 2n2+ n Toffoli gates utilized by the circuit shown in Figure 6A that uses traditional controlled adders. For large values of n, the described embodiments may result in a significant reduction in Toffoli gate count.

[0089] The quantum circuit for addition of an M-digit integer and an zn-digit integer shown in Figure 7B (which uses bidirectional controlled adders) utilizes nm + 2n + 2m + 3 Toffoli gates, compared to the 2nm + n Toffoli gates utilized by the circuit shown in Figure 6B that uses traditional controlled adders. For large values of either n or m, the described embodiments may result in a significant reduction in Toffoli gate count.

[0090] The quantum circuit for modular multiplication mod 2nof two n-qubit integers shown in Figure 9 (which uses bidirectional controlled adders) utilizes 0.5n2+ 1.5n Toffoli gates, compared to the n2Toffoli gates utilized by the circuit shown in Figure 6 that uses traditional controlled adders. For large values of M, the described embodiments may result in a significant reduction in Toffoli gate count.

[0091] The quantum circuit for modular multiplication mod p of two n-qubit integers for a prime number p shown in Figure 12 (which uses bidirectional controlled adders) utilizes n2+ 6n + — W ( ■2W+ 3 • 2W / '2+ 3n) Toffoli gates, compared to the 2n2+ 4n + — w (2W+ 3 • 2W / 2+ n — 1) Toffoli gates utilized by the circuit shown in Figure 10 that uses traditional controlled adders. For large values of m tire described embodiments may result in a significant reduction in Toffoli gate count.

[0092] Mote that the optimal window size w for modular multiplication may depend on w'hether optimization is performed for Toffoli counts or active volume.Figure 13 - Flowchart for Quantum Multiplication Circuit

[0093] Figure 13 is a flowchart diagram illustrating a quantum computational method for utilizing a quantum circuit to multiply two numbers encoded using physical qubits. The method shown in Figure 13 may be used in conjunction with any of the computer systems orAttorney Docket No. 7246-02001 devices shown in the above Figures, among other devices. For example, the method shown in Figure 13 may be performed by a quantum computing device or system 101 as illustrated in Figure 1A. A quantum computing system 101 may be configured to direct the described method steps, and may include (or be coupled to) a classical computing system 103 for processing classic information and directing operations of a QPU 105. In some embodiments, classical information is passed back and forth between the classical processor and the QPU during the process of a quantum computational method. For example, classical measurement results and other classical information may be provided to the classical processor by the QPU over the channel 112, and the classical processor may use this information to determine instructions to provide back to the QPU for manipulating and / or measuring qubits. The QPU may then provide results of these operations back to the classical processor.

[0094] In some embodiments, the described quantum circuits may be implemented in any of a variety of types of quan tum computing systems, including bu t not limi ted to photonic, semiconductor, superconducting and / or topological quantum computing systems. It is to be understood this method may be used by any of a variety of types of quantum computing architectures, and these other types of systems should be considered within the scope of the embodiments described herein. As illustrated, the method shown in Figure 13 may proceed as follows.

[0095] At 1302, first, second and third quantum registers are prepared in respective states. Each of the first, second and third quantum registers include respective pluralities of qubits. The quantum registers may be included within a QPU, and the QPU may additionally include a controller configured to manipulate and otherwise interact with the quantum registers (e.g., to apply quantum gates). The first quantum register is prepared in a first state indicative of a first number, the second quantum register is prepared in a second state indicative of a second number, and the third quantum register is prepared in an initial state. The initial state may be a null state, or another initial state (e.g., the ‘T’ state). The first and second quantum registers may each contain a number of logical qubits (e.g., error-corrected qubits capable of storing a single logical qubit of quantum information) equal to the number of bits in a binary representation of the first and second number, respectively. The third quantum register may contain a number of qubits eq ual to the sum of the number of qubits in tire first and second quantum registers (for modular multiplication), or one plus the sum of the number of qubits in the first and second quantum registers (for non-modular multiplication, where theAttorney Docket No. 7246-02001 additional qubit provides space of the carry-over bit of the product). For example, the quantum circuit diagram shown in Figure 7 A illustrates an example of the three quantum registers as n qubits prepared in the state |x) 702 (first quantum register), where x is the first number, n qubits prepared in the state |y) 704 (second quantum register), where y is the second number, and 2n + 1 qubits prepared in the null state |0) 706 (third quantum register).

[0096] At 1304-1306, for each respective qubit of the first quantum register, controlled bidirectional addition is performed of the second number into the third quantum register controlled on the respective qubit of the first plurality of qubits. A classical processor may provide instructions to the controller of the QPU to perform the controlled bidirectional addition, in some embodiments. Performing controlled bidirectional addition of the second number into the third quantum register may be performed into a respective subset of qubits of the third quantum register that is selected based on a respective significant digit of the respective qubit of the first quantum register. The qubits controlling the controlled bidirectional addition circuit may represent significant digits of the first number that correspond to respective significant digits of the third quantum register into which the controlled bidirectional addition of the second number is performed. A quantum circuit illustrating controlled bidirectional additional is shown in Figure 7A, e.g., circuit elements 708a~d.

[0097] At 1308, the first, second and third quantum registers are operated on to remove discrepancies between performing controlled bidirectional addition and performing controlled addition. A classical processor may provide instructions to the controller of the QPU to apply operations to remove the discrepancies, in some embodiments. Operating on the first, second and third quantum registers to remove discrepancies between performing controlled bidirectional addition and performing controlled addition may implement correction circuits to perform one or more of: a) performing an addition operation of 2n times the first number plus 2n on the third quantum register, where n is the number of qubits in the first quan tum register, b) performing a subtraction operation of the second number and of 22non the third quantum register, c) performing an addition operation of 2n times the second number on the third quantum register, and d) shifting each qubit in the third quantum register to a next-lower significant digit. A quantum circuit illustrating the four correction circuits a)-d) is shown in Figure 7 A, as circuit elements 710a-d, respectively.Attorney Docket No. 7246-02001[098[ In some embodiments, the instructions provided by the classical processor at steps 1304-1308 may be determined by the classical processor based on the size (in binary representation) of the first and second numbers. For example, the classical processor may receive information indicating a size of the first number a size of the second number, and the instructions for performing steps 1304-1308 may be detennined based on the sizes of the first and second numbers. In some embodiments, the classical processor may have a priori knowledge of the sizes of the two numbers (e.g., from knowledge of the overall quantum computational procedure) such that the classical processor does not need to explicitly receive this information from a separate source, e.g., it may access it directly from memory.

[0099] At 1310, the qubits of the third quantum register are utilized in a third state indicative of a product of the first and second numbers (e.g., the state |xy) shown at element 712 in Figure 7A. The third quantum register qubits may be utilized in a variety' of applications while prepared in the state |xy). In some embodiments, the third quantum register may be measured with measurement circuitry of the QPU to produce classical measurement results that specify the product xy. The classical measurement results may be provided to a classical processor, which may store them in a non-transitory memory medium. In some embodiments, the third quantum register prepared in the state |xy) is utilized in a subsequent quantum circuit of a quantum computational method. For example, the third quantum register may be further acted on and / or operated on by the controller as indicated by' the quantum computational method being performed. In some embodiments, the third quantum register prepared in the state |xy) is output to a separate QPU or another device. In some embodiments, the third quantum register is utilized by storing the qubits in the state |xy). As used herein, “storing” qubits refers to maintaining the qubits in a particular quantum state, e.g., by repeated application of an identity operator.

[0100] In some embodiments, the product of the first and second numbers is a mod 2n modular multiplication product, where n is a number of qubits in the first quantum register. An example quantum circuit configured to implement mod 2n multiplication is shown in Figure 8.

[0101] In some embodiments, the product of the first and second numbers is a mod / ? modular multiplication product, where p is a prime number. An example quantum circuit configured to implement mod / ? multiplication is shown in Figure 9.Attorney Docket No. 7246-02001

[0102] In some embodiments, the method multiplies two / ?-digit numbers (in binary representation, such that n is the number of qubits in each of the first and second quantum registers), and the method overall includes performing n2+ 4n + 3 Toffoli gates.Advantageously, the quantum multiplication may be performed with fewer than the 2n2+ n Toffoli gates utilized in a traditional quantum multiplication circuit. An example of this type of quantum circuit is illustrated in Figure 7A, according to some embodiments.

[0103] In some embodiments, the method may multiply an w-digit number by an / w-digit number (e.g., where n and m may be different), in which case the overall method includes performing nm + 2n + 2m + 3 Toffoli gates. An example of this type of quantum circuit is shown in Figure 7B, according to some embodiments.

[0104] In some embodiments, the qubits in the third quantum register prepared in the state indicative of the product of the first and second numbers are measured by measurement circuitry to produce classical measurement results. The classical measurement results may be stored in a non-transitory computer-readable memory medium, in some embodiments.Alternatively, m some embodiments the qubits in the third quantum register prepared in the state indicative of the product of the first and second numbers are provided to a subsequent step in a quantum computational method (i.e., without being measured at that time).Additional Technical Detail

[0105] The following numbered paragraphs provide additional technical detail and description regarding embodiments herein.

[0106] In some embodiments, other types of multiplication circuits may utilize bidirectional controlled adders to reduce computational cost. For example, the previous examples of multiplication circuits multiply two numbers stored in quantum registers. An alternative multiplication circuit may multiply a number stored in a quantum register by a constant (e.g., a "classical number"). In this case, multiplying an integer by a constant may utilize O(n2 / logn) Toffoli gates without using controlled bidirectional addition, as described in [arXiv: 1905.07682],

[0107] For 256-bit numbers, the optimized construction reduces the Toffoli count of modular multiplication with a prime modulus from approximately 2,25n2+ 9n Toffolis to around 1.5n2+ 12n Toffolis. For 256-bit elliptic curve keys using 3000k logical qubits of memory,Attorney Docket No. 7246-02001 this reduces the Toffoli count from 44 + 65 / fc million Toffoli gates to 30 + 73 / , k million Toffoli gates.

[0108] Note that while the active volume benefits just as much as the Toffoli count in the case of traditional multiplication and modular multiplication mod 2n, the same may not be true for modular multiplication mod p without further optimizations. This is due to the presence of the QROM which features a much higher active volume per Toffoli gate than the adders. Using a window size of w = 6 for multiplication and a window size of 15 (instead of 16) for elliptic curve point addition, the active volume is reduced from 2.8 + 3.8 / k billion blocks to 2.4 + 4.2 / k billion blocks, which is an asymptotic reduction of around 15%.

[0109] It should be understood that all numerical values used herein are for purposes of illustration and may be varied. In some instances, ranges are specified to provide a sense of scale, but numerical values outside a disclosed range are not precluded.

[0110] It should also be understood that all diagrams herein are intended as schematic. Unless specifically indicated otherwise, the drawings are not intended to imply any particular physical arrangement of the elements shown therein, or that all elements shown are necessary. Those skilled in the art with access to tins disclosure will understand that elements shown m drawings or otherwise described in this disclosure may be modified or omitted and that other elements not shown or described may be added.

[0111] Uiis disclosure provides a description of the claimed invention with reference to specific embodiments. Those skilled in the art with access to this disclosure wili appreciate that the embodiments are not exhaustive of the scope of the claimed invention, which extends to all variations, modifications, and equivalents.

[0112] The terminology used in the description of the various described embodiments herein is for the purpose of describing particular embodiments only and is not intended to be limiting. As used in the description of the various described embodiments and the appended claims, the singular forms “a”, ‘"an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It wili also be understood that the term “and / or” as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. It will be further understood that the terms “includes,” “including,” “comprises,” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but doAttorney Docket No. 7246-02001 not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0113] It will also be understood that, although the terms first, second, etc., are, in some instances, used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first switch could be termed a second switch, and, similarly, a second switch could be termed a first switch, without departing from the scope of the various described embodiments. The first switch and the second switch are both switches, but they are not the same switch unless explicitly stated as such.

[0114] As used herein, the term “if’ is, optionally, construed to mean “when” or “upon” or “in response to determining” or “in response to detecting” or “in accordance wi th a determination that,” depending on the context.

[0115] 'Hie foregoing description, for purpose of explanation, has been described with reference to specific embodiments. However, the illustrative discussions above are not intended to be exhaustive or to limit the scope of the claims to the precise forms disclosed. Many modifications and variations are possible in view of the above teachings. The embodiments were chosen in order to best explain the principles underlying the claims and their practical applications, to thereby enable others skilled in the art to best use the embodiments with various modifications as are suited to the particular uses contemplated.

Claims

Attorney Docket No. 7246-02001ClaimsWhat is claimed is:

1. A quantum multiplication circuit (700), comprising: a first quantum register (702) prepared in a first state indicative of a first number, wherein the first quantum register comprises a first plurality of qubits; a second quantum register (704) prepared in a second s tate indicative of a second number; a third quantum register (706) prepared in an initial state; a plurality of controlled bidirectional addition circuits (708a-d) configured to perform controlled bidirectional addition of the second number into the third quantum register, wherein each of the plurality of controlled bidirectional addition circuits is controlled on a respective qubit of the first plurality of qubits; a plurality of correction operator circuits (710a-d) configured to operate on the first, second and third quantum registers to remove discrepancies between performing controlled bidirectional addition and performing controlled addition.

2. Tire quantum multiplication circuit of claim 1 , wherein the quantum multiplication circuit is configured to output qubits of the third quantum register prepared in a third state indicative of a product of the first and second numbers (712).

3. lire q uantum multiplication circuit of claim 2, wherein the quantum multiplication circuit further comprises: measurement circuitry' configured to measure the qubits of the third quantum register prepared in the third state to produce classical measurement results; and a non-transitory computer-readable memory medium configured to store the classical measurement results.

4. The quantum multiplication circuit of claim 1, wherein each of the plurality of controlled bidirectional addition circ uits is configured to perform controlled bidirectional addition of the second number into a respective subset ofAttorney Docket No. 7246-02001 qubits of the third quantum register that is selected based on a respective significant digit of the respective qubit of the first plurality of qubits.

5. Tire quantum multiplication circuit of claim 1 , wherein the plurality of correction operator circuits comprises one or more of a first correction operator circuit (710a) configured to perform an addition operation of 2” times the first number plus 2” on the third quantum register, wherein n comprises a number of qubits in the first plurality of qubits; a second correction operator circuit (710b) configured perform a subtraction operation of the second number and of 22” on the third quantum register; a third correction operator circui t (710c) configured to perform an addition operation of 2” times the second number on the third quantum register; and a fourth configured operator circuit (7 lOd) configured to shift each qubit m the third quantum register to a next-lower significant digit,6. lire quantum multiplication circuit of claim 1, wherein the qubits controlling the controlled bidirectional addition circuit comprise significant digits that correspond to respective significant digits of the third quantum register into which the controlled bidirectional addition of the second number is performed.

7. The quantum multiplication circuit of claim 1, wherein the quantum multiplication circuit comprises one of: a mod 2n modular multiplication circuit, wherein n comprises a number of qubits in the first plurality of qubits; or a mod p modular multiplication circuit, wherein p comprises a prime number.

8. The quantum multiplication circuit of claim 1, wherein the quantum multiplication circuit comprises n2+ 4n + 3 Toffoli gates, wherein n comprises a number of qubits in tire first plurality of qubits.

9. The quantum multiplication circuit of claim 1,Attorney Docket No. 7246-02001 wherein the quantum multiplication circuit comprises nm + 2n + 2m + 3 Toffoli wheretn comprises a number of qubits in the first quantum register, and wherein m comprises a number of qubits in the second quantum register.

10. The quantum multiplication circuit of claim 1, wherein the quantum multiplication circuit comprises fewer than 2n2+ n Toffoli gates, and wherein n comprises a number of qubits in the first quantum register.

11. The quantum multiplication circuit of claim 1, wherein the initial state comprises a null state.

12. A method, comprising: preparing a first quantum register in a first state indicative of a first number, wherein the first quantum register comprises a first plurality of qubits; preparing a second quantum register in a second state indicative of a second number; preparing a third quantum register in an initial state; for each respective qubit of the first plurality of qubits: performing controlled bidirectional addition of the second number into the third quantum register controlled on the respective qubit of the first plurality of qubits; operating on the first, second and third quantum registers to remove discrepancies between performing controlled bidirectional addition and performing controlled addition; and outputting qubits of the third quantum register prepared in a third state indicative of a product of the first and second numbers.

13. The method of claim 12, wherein, for each respective qubit of the first plurality of qubits, performing controlled bidirectional addition of the second number into the third quantum register is perfonned into a respective subset of the third q uantum register q ubits that is selected based on a respective significant digit of the respective qubit of the first plurality of qubits.Attorney Docket No. 7246-0200114. The method of claim 12, wherein operating on the first, second and third quantum registers to remove discrepancies between performing controlled bidirectional addition and performing controlled addition comprises one or more of: performing an addition operation of 2ntimes the first number plus 2non the third quantum register, wherein n comprises a number of qubits in the first quantum register; performing a subtraction operation of the second number and of 22non the third quantum register; performing an addition operation of 2ntimes the second number on the third quantum register; and shifting each qubit in the third quantum register to a next-lower significant digit.

15. The method of claim 12, wherein the qubits controlling the controlled bidirectional addition circuit encode significant digits of the first number that correspond to respective significant digits of the third quantum register into which the controlled bidirectional addition of the second number is performed.

16. The method of claim 12, wherein the product of the first and second numbers comprises one of: a mod 2n modular multiplication product, wherein n comprises a number of qubits in the first quantum register; or a mod p modular multiplication product, wherein p comprises a prime number.

17. The method of claim 12, wherein the method performs n2+ 4n + 3 Toffoli gates, wherein n comprises a number of qubits in the first quantum register.

18. The method of claim 12, wherein the method performs nrn + 2n + 2m + 3 Toffoli gates, wherein n comprises a number of qubits in the first quantum register, andAttorney Docket No. 7246-02001 wherein m comprises a number of qubits in the second quantum register.19, The method of claim 12, wherein the method performs fewer than 2n2+ n Toffoli gates, and wherein n comprises a number of qubits in the first quantum register.

20. The method of claim 12, wherein the initial state comprises a null state.

21. The method of claim 12, further comprising: measuring the qubits of the third quantum register prepared in the third state to produce classical measurement results; and storing the classical measurement results in a non-transitory computer-readable memory medium.

22. A quantum computing system, comprising: a classical processor; a quantum processing unit (QPU) coupled to the classical processor, wherein the QPU comprises: a first quantum register (702) prepared in a first state indicative of a first number, wherein the first quantum register comprises a first plurality of qubits; a second quantum register (704) prepared in a second state indicative of a second number; and a third quantum register (706) prepared in an initial state; and a controller configured to interact with the first, second and third quantum registers; and a non-transitory' computer-readable memory' medium coupled to the classical processor, wherein the memory medium stores program instructions that are executable to cause the classical processor to: provide, to the QPU, first instructions to apply a plurality' of controlled bidirectional additions of the second number into the third quantum register, wherein each ofAttorney Docket No. 7246-02001 the plurality of controlled bidirectional additions is controlled on a respective qubit of tin first plurality of qubits: and provide, to the QPU, second instructions to apply a plurality of correction operators (710a-d) on the first, second and third quantum registers to remove discrepancies between performing controlled bidirectional addition and performing controlled addition.

23. The quantum computing system of claim 22, wherein the program instructions are further executable to cause the classical processor to: determine the first instructions and second instructions based at least in part on a size of the first number and a size of the second number.

24. The quantum computing system of claim 22, wherein the QPU is configured to operate on qubits of the third quantum register prepared in a third state indicative of a product of the first and second numbers (712).25, The quantum computing system of claim 22, wherein the QPU is configured to store qubits of the third quantum register prepared in a third state indicative of a product of the first and second numbers (712).

26. The quantum computing system of claim 22, wherein the QPU further comprises: measurement circuitry configured to measure the qubits of the third quantum register prepared in the third state to produce classical measurement results, wherein the QPU is further configured to provide the classical measurement results to the classical processor to store in the non-transitory computer-readable memory medium.