We provide a high-level cost comparison between Regev's quantum algorithm with Eker{\aa}-G\"artner's extensions on the one hand, and existing state-of-the-art quantum algorithms for factoring and computing discrete logarithms on the other. This when targeting cryptographically relevant problem instances, and when accounting for the space-saving optimizations of Ragavan and Vaikuntanathan that apply to Regev's algorithm, and optimizations such as windowing that apply to the existing algorithms. Our conclusion is that Regev's algorithm without the space-saving optimizations may achieve a per-run advantage, but not an overall advantage, if non-computational quantum memory is cheap. Regev's algorithm with the space-saving optimizations does not achieve an advantage, since it uses more computational memory, whilst also performing more work, per run and overall, compared to the existing state-of-the-art algorithms. As such, further optimizations are required for it to achieve an advantage for cryptographically relevant problem instances.
翻译:本文对Regev量子算法(结合Ekerå-Gärtner扩展)与现有最先进的因式分解及离散对数计算量子算法进行了高层成本比较。比较针对密码学相关的问题实例,并考虑了适用于Regev算法的Ragavan-Vaikuntanathan节内存优化,以及适用于现有算法的窗口化等优化技术。我们的结论表明:在非计算量子内存成本较低的前提下,未采用节内存优化的Regev算法可能实现单次运行优势,但无法获得整体优势;而采用节内存优化的Regev算法则不具备优势,因为与现有最先进算法相比,该算法不仅需要更多计算内存,同时在单次运行和整体层面都需执行更多计算工作。因此,要实现密码学相关问题实例的破解优势,该算法仍需进一步优化。