Unit group computations are a cryptographic primitive for which one has a fast quantum algorithm, but the required number of qubits is $\tilde O(m^5)$. In this work we propose a modification of the algorithm for which the number of qubits is $\tilde O(m^2)$ in the case of cyclotomic fields. Moreover, under a recent conjecture on the size of the class group of $\mathbb{Q}(\zeta_m + \zeta_m^{-1})$, the quantum algorithms is much simpler because it is a hidden subgroup problem (HSP) algorithm rather than its error estimation counterpart: continuous hidden subgroup problem (CHSP). We also discuss the (minor) speed-up obtained when exploiting Galois automorphisms thanks to the Buchmann-Pohst algorithm over $\mathcal{O}_K$-lattices.
翻译:单位群计算是一种密码学原语,其快速量子算法所需量子比特数为$\tilde O(m^5)$。本文提出对该算法的改进方案,使分圆域情形下的量子比特数降至$\tilde O(m^2)$。此外,根据关于$\mathbb{Q}(\zeta_m + \zeta_m^{-1})$类群大小的最新猜想,该量子算法可简化为隐藏子群问题(HSP)算法而非其误差估计版本——连续隐藏子群问题(CHSP),从而显著降低复杂度。我们还讨论了在$\mathcal{O}_K$格上利用Buchmann-Pohst算法执行伽罗瓦自同构时获得的(微小)加速收益。