arXiv ScienceSearch

arXiv · 2606.02235

Optimized Point Addition Circuits for Elliptic Curve Discrete Logarithms

Abstract

Shor's algorithm represents the main threat of quantum computers to cryptography. In order to precisely understand its feasibility, many authors have worked towards reducing its costs, either at the logical level (assuming a fault-tolerant architecture), or at the physical level (taking into account the constraints of envisioned hardware). In particular, recent works by Chevignard et al. (CRYPTO 2024) and Gidney (arXiv 2025) used improved arithmetic to significantly reduce the qubit cost of factoring RSA public keys. Even more recently, Babbush et al. (arXiv 2026) improved the cost of computing elliptic curve discrete logarithms, with a reduction of a factor 2 to 3 in gate count and qubit count compared to a previous work by Litinski (arXiv 2023). Their result relies on optimized point addition circuits on elliptic curves over prime fields. However they did not reveal their logical quantum circuits, relying instead on a zero-knowledge proof. In this paper, we detail a quantum logical circuit architecture which gives similar results as Babbush et al., with a slightly higher number of qubits (around 1.5% increase) and a slightly smaller Toffoli gate count (between 6.5% and 10% reduction) for the curve secp256k1. We also give gate counts for a generic variant of the circuit, which is valid for any prime field.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

André Schrottenloher. 2026-06-01. Optimized Point Addition Circuits for Elliptic Curve Discrete Logarithms. https://arxiv.org/abs/2606.02235

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Designing a Hybrid Digital / Analog Quantum Physics Emulator as Open Hardware

Existing approaches to emulating quantum computing algorithms using classical electronic hardware are limited by exponential scaling limitations in space, such as circuit size, or time, such as runtime or bandwidth. We introduce a scheme for representing quantum information using analog signals that lessens the bandwidth limitation problem (in certain regimes) seen in existing approaches [1, 2] by taking full advantage of the ability of analog signals to encode information using RMS voltage as well as frequency and phase. We introduce the mathematical framework for this representation, which separates the information relevant for measurement in the computational basis from information that is not relevant to it. We introduce circuits that take advantage of this separation of concerns to achieve simplifications, for working with quantum information in this representation. We argue that it is comparatively very inexpensive (as low as ~$5.00 / qubit) to outmatch the computing capabilities of existing FPGA based emulators [3], though scaling beyond tens of qubits is still impractical due to constraints of analog hardware module precision. However, our approach opens the door to a new avenue by which classical emulators can hope to improve: by improving on analog electronic circuit performance.

quant-ph

Measuring a Quantum Measure Exceeding Unity

The history based formalism known as Quantum Measure Theory (QMT) generalizes the concept of probability-measure so as to incorporate quantum interference. The resulting quantum measure $μ$ is defined for arbitrary events (sets of histories), not just for observables at a fixed moment of time. Thanks to interference effects, $μ$ can exceed unity, exhibiting its non-classical nature in a particularly striking manner. Here, in an optical experiment, we illustrate an ancilla based filtering scheme that gives operational meaning to the quantum measure. For a specific photonic event $E$, we report a measured value of $μ(E)=1.172^{+0.013}_{-0.019}$, which within errors agrees with the theoretical value of $5/4$, while exceeding the maximum value permissible for a classical probability (namely $1$) by $13.32$ upper or $8.89$ lower percentile widths. The directly observed quantity is an ordinary detector probability $p_D\le 1$ (or, with laser light, an equivalent power ratio); the value $μ(E)>1$ is inferred via the calibrated relation $μ(E)=2p_D$ for our filter. If an unconventional theoretical concept is to play a role in meeting the foundational challenges of quantum theory, it seems important to bring it into contact with experiment as much as possible. Our experiment does this for the quantum measure.

quant-ph

Complexity Theory for Quantum Promise Problems

We begin by establishing structural results for several fundamental quantum complexity classes: p/mBQP, p/mQ(C)MA, $\text{p/mQSZK}_{\text{hv}}$, p/mQIP, p/mBQP/qpoly, p/mBQP/poly, and p/mPSPACE. This includes identifying complete problems, as well as proving containment and separation results among these classes. Here, p/mC denotes the corresponding quantum promise complexity class with pure (p) or mixed (m) quantum input states for any classical complexity class C. Surprisingly, our findings uncover relationships that diverge from their classical analogues -- specifically, we show unconditionally that p/mQIP$\neq$p/mPSPACE and p/mBQP/qpoly$\neq$p/mBQP/poly. This starkly contrasts the classical setting, where QIP$=$PSPACE and separations such as BQP/qpoly$\neq$BQP/poly are only known relative to oracles. More interestingly, these separation results further connected to the topic of for both quantum property testing and unitary synthesis. This new framework has numerous applications in quantum cryptography, particularly in the contexts of Microcrypt. We provide a better characterization of its primitives; for example, we show that OWSG and PRS can be broken by a p/mQCMA oracle, leading to a natural quantum analogue of Impagliazzo's five worlds by substituting the classical complexity classes in Pessiland, Heuristica, and Algorithmica with mBQP and mQCMA. Moreover, we establish the relativization barrier for proving the existence of EFI, noting that no such barrier currently exists within traditional complexity theory.

quant-ph