Quantum Complexity for Discrete Logarithms and Related Problems

07/06/2023
by   Minki Hhan, et al.
0

This paper studies the quantum computational complexity of the discrete logarithm (DL) and related group-theoretic problems in the context of generic algorithms – that is, algorithms that do not exploit any properties of the group encoding. We establish a generic model of quantum computation for group-theoretic problems, which we call the quantum generic group model. Shor's algorithm for the DL problem and related algorithms can be described in this model. We show the quantum complexity lower bounds and almost matching algorithms of the DL and related problems in this model. More precisely, we prove the following results for a cyclic group G of prime order. - Any generic quantum DL algorithm must make Ω(log |G|) depth of group operations. This shows that Shor's algorithm is asymptotically optimal among the generic quantum algorithms, even considering parallel algorithms. - We observe that variations of Shor's algorithm can take advantage of classical computations to reduce the number of quantum group operations. We introduce a model for generic hybrid quantum-classical algorithms and show that these algorithms are almost optimal in this model. Any generic hybrid algorithm for the DL problem with a total number of group operations Q must make Ω(log |G|/log Q) quantum group operations of depth Ω(loglog |G| - loglog Q). - When the quantum memory can only store t group elements and use quantum random access memory of r group elements, any generic hybrid algorithm must make either Ω(√(|G|)) group operations in total or Ω(log |G|/log (tr)) quantum group operations. As a side contribution, we show a multiple DL problem admits a better algorithm than solving each instance one by one, refuting a strong form of the quantum annoying property suggested in the context of password-authenticated key exchange protocol.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/23/2021

Quantum algorithms for group convolution, cross-correlation, and equivariant transformations

Group convolutions and cross-correlations, which are equivariant to the ...
research
09/06/2022

A Subexponential Quantum Algorithm for the Semidirect Discrete Logarithm Problem

Group-based cryptography is a relatively young family in post-quantum cr...
research
06/17/2021

Quantum algorithm for Dyck Language with Multiple Types of Brackets

We consider the recognition problem of the Dyck Language generalized for...
research
12/22/2018

Quantum query complexity of symmetric oracle problems

We study the query complexity of quantum learning problems in which the ...
research
12/03/2020

Quantum learning algorithms imply circuit lower bounds

We establish the first general connection between the design of quantum ...
research
10/10/2019

A New Cryptosystem Based on Positive Braids

The braid group is an important non commutative group, at the same time,...
research
05/22/2019

Revisiting Shor's quantum algorithm for computing general discrete logarithms

We heuristically demonstrate that Shor's algorithm for computing general...

Please sign up or login with your details

Forgot password? Click here to reset