楕円曲線の量子点加算を省資源化する可逆演算
Efficient Record-and-Replay Arithmetic for Quantum Elliptic-Curve Point Addition
この論文をやさしく読む
ひとことで言うと
量子計算で使う楕円曲線の点加算回路を改良し、必要な量子ビット数とゲート数を評価した研究です。
何に役立つ?
楕円曲線離散対数に向けた量子回路の資源見積もりや、点加算の設計比較に役立ちます。完全なShor計算の実行規模を直接示したものではありません。
この研究の面白いところ
異なる二つの可逆演算構成を比較し、修復版では10万件の追加試験で失敗を検出しなかった一方、構造化された反例も明記しています。
どこまで分かった?
全入力での正しさは未確立です。資源比較も指定条件下での個々の点加算についてで、数え方の違いから既存方式への形式的優位性は示せません。
v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。
アブストラクトの日本語訳
Shorの楕円曲線離散対数アルゴリズムに向け、ECDSA.Failを通じて開発された可逆なsecp256k1点加算回路を研究する。記録・再生型の最大公約数演算を改善する、相補的な二つの構成を示す。Jump-2は二進最大公約数のステップをまとめ、判断結果を5進符号化で圧縮する。ping-pongはレジスタを固定的に交互使用し、1ビットの判断で全ビット幅の比較とデータ依存の交換を避ける。融合した再生処理では、倍算と符号付き加算を一つの剰余補正にまとめる。いずれの構成も、測定によるルックアップの後片付けを伴う量子アドレス指定のウィンドウ選択に対応する。 9種類のルックアップ表設定について、新しい入力10万件を使い、3種類の回路を比較した。別途試験した修復版は1,419量子ビットを使い、実行されたToffoliゲートの平均は135万6千回で、さらに別の10万入力では失敗が検出されなかった。ただし、対応する入力に対する構造化された反例が残るため、これらの試験は全入力についての正しさを確立しない。条件付きのコヒーレント誤差解析と、可逆safegcdとの比較も提示する。指定されたウィンドウ数の許容範囲では、修復版回路の資源量はGoogleの低ゲート数上限およびSchrottenloherの低ゲート数推定を下回る。しかし、資源の数え方と正しさに関する証拠が異なるため、形式的な優位性は主張できない。結果はウィンドウ選択を伴う個々の点加算に関するもので、Shorアルゴリズム全体の計算には関するものではない。
v1の要旨から自動生成。本文の精読・人による確認は未実施。
- 初稿
- 2026-09-24(UTC)
- 最新改訂
- 2026-09-24 · v1
- 査読・掲載
- 査読状況未確認
更新履歴
- v1 2026-09-24 この版を読む
取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。
原文の要旨
We study reversible secp256k1 point-addition circuits developed through ECDSA.Fail for Shor's elliptic-curve discrete-logarithm algorithm. Two complementary constructions improve record-and-replay GCD arithmetic: Jump-2 groups binary-GCD steps and compresses their decisions using base-5 encoding, while ping-pong uses fixed register alternation and one-bit decisions to avoid full-width comparisons and data-dependent swaps. Fused replay combines doubling and signed addition into one modular correction. Both constructions support quantum-addressed window selection with measurement-based lookup cleanup. We compare three circuits on 100,000 fresh inputs across nine lookup-table configurations. A separately tested repair uses 1,419 qubits and 1.356 million mean executed Toffolis, with no detected failures on another 100,000 inputs. Structured supported-input counterexamples remain, so these tests do not establish all-input correctness. We also provide conditional coherent-error analysis and reversible safegcd comparisons. Under the stated window allowance, repaired-circuit resources lie below Google's low-gate caps and Schrottenloher's low-gate estimates, but differing accounting and correctness evidence preclude formal dominance. The results concern individual window-selected additions, not complete Shor computations.
著者のコメント
35 pages, 2 figures. Technical companion to arXiv:2609.09582. Reproducibility artifacts: https://github.com/jieyilong/ecdsafail-circuit-evidence/releases/tag/v1.4.0
arXiv ID: 2609.28882 / 要約の誤りについて