Submitted:
10 July 2026
Posted:
14 July 2026
You are already at the latest version
Abstract
Keywords:
MSC: 68Q12; 81P68; 94A60; 11T71; 11Y16
1. Introduction
1.1. Motivation: Resource Estimates as Security Claims
1.2. Two Disclosure Models in Recent Quantum-ECDLP Work
1.3. Our Contribution
- (i)
- We define a resource certificate object for public reversible arithmetic blocks. The certificate records a circuit commitment, gate basis, arithmetic parameters, resource counts, input-output specification, deterministic tests, transcript data, and optional proof artifact.
- (ii)
- We give a deterministic hash-derived test-generation method for arithmetic circuits. This prevents test vectors from being handpicked and makes correctness transcripts reproducible.
- (iii)
- We prove a basic soundness bound for randomized testing certificates: if a deterministic circuit is incorrect on an -fraction of its domain, then the probability that it passes N independently sampled tests is at most , under the stated random-oracle model for hash-derived tests.
- (iv)
- We specialize the framework to modular inversion over prime fields. For this case, correctness is checked by verifying for claimed input-output pairs .
- (v)
- We outline a prototype verifier and certificate schema suitable for an open repository. The prototype is intended to support small exhaustive tests, larger deterministic randomized tests, and resource-count metadata checks.
- (vi)
- We compare three disclosure models: full circuit disclosure, withheld circuit with zero-knowledge attestation, and public circuit with a reusable certificate. The proposed certificate model is complementary to both existing models.
1.4. Scope and Non-Goals
1.4.0.1. Code availability.
2. Background on Quantum ECDLP Arithmetic
2.1. ECDLP and Coherent Group Arithmetic
2.2. Affine Point Addition and Modular Inversion
2.3. Resource Metrics
- Logical qubits.
- The number of logical qubits required by the reversible arithmetic block, including input, output, control, and work registers.
- Ancilla or work qubits.
- The subset of logical qubits used as temporary storage. A certificate should specify whether these qubits are clean, dirty, borrowed, or required to be returned to .
- Toffoli count.
- The number of Toffoli-type non-Clifford gates, or the specified equivalent count in the chosen gate basis. Since Toffoli or T-type resources often dominate fault-tolerant runtime, this is one of the central resource metrics in ECDLP estimates.
- CNOT count.
- The number of CNOT gates or controlled-X operations after compilation to the stated reversible gate basis.
- Depth.
- The circuit depth under a specified scheduling convention. When relevant, this may be refined to Toffoli depth, active depth, or architecture-aware depth.
- Architecture-aware metrics.
- Some estimates also depend on routing, connectivity, surface-code layout, reaction time, active volume, or physical-qubit assumptions. These metrics are not part of the minimal certificate in this paper, but the format is designed to allow such fields.
2.4. Disclosure Models and Verification Pressure
3. Certificate Objects for Reversible Arithmetic Blocks
3.1. Reversible Arithmetic Blocks
3.2. Resource Certificate Schema
3.3. Certificate Levels
- Level 0.
- Hash, arithmetic parameters, gate basis, and resource counts. This level records what is being claimed but does not by itself test arithmetic correctness.
- Level 1.
- Level 0 plus deterministic randomized tests. Test inputs are generated from a hash-derived seed, and the certificate records a correctness transcript. For modular inversion, each transcript row is checked by verifying .
- Level 2.
- Level 1 plus exhaustive correctness over toy-size domains. This is feasible for small primes and is useful for debugging the verifier and circuit representation.
- Level 3.
- Level 2 plus formal verification of arithmetic correctness. At this level, the certificate is supported by a machine-checkable proof that the circuit realizes the specified arithmetic function.
- Level 4.
- Level 3, or a Level 1-style claim, embedded into a succinct or zero-knowledge proof system. This level is appropriate when one wants an independently checkable proof artifact, possibly without revealing all circuit details.
3.4. Relationship to Withheld-Circuit Attestation
4. Deterministic Test Generation and Soundness
4.1. Hash-Derived Tests
4.2. Randomized Testing Soundness
4.3. What Testing Does and Does Not Prove
5. Certificate Specialization: Modular Inversion over Prime Fields
5.1. Arithmetic Specification
5.2. Correctness Checks
5.3. Resource Fields for Modular Inversion Certificates
5.4. Relation to Luo-Style EEA Inversion
6. Prototype Verifier
6.1. Circuit Representation
6.2. Gate and Qubit Counting
- Logical qubits.
- The declared circuit qubit count.
- Total gates.
- The length of the gate list.
- NOT count.
- The number of gates.
- CNOT count.
- The number of gates.
- Toffoli count.
- The number of gates.
- SWAP count.
- The number of gates.
- Serial depth.
- The number of gates under the prototype serial scheduling convention.
6.3. Test Generator
6.4. Verifier
6.5. Certificate Artifact
- certificate_id.
- A stable identifier for the certificate.
- circuit_hash.
- A hash commitment to the circuit or circuit family.
- gate_basis.
- The reversible gate basis used for counting.
- arithmetic_function.
- The arithmetic function being certified, for example modular inversion.
- arithmetic_parameters.
- The modulus, bit length, and field convention.
- resource_counts.
- Qubits, gate counts, and serial depth.
- io_spec.
- The input-output convention and correctness relation.
- test_generation.
- The hash-derived or exhaustive test specification.
- correctness_transcript.
- The test inputs, outputs, and pass flags.
- transcript_hash.
- A hash of the canonical transcript.
- proof_artifact.
- Optional proof metadata.
7. Experiments and Case Studies
7.1. Toy Exhaustive Tests
| Certificate | Function | Tests | Circuit check | Status |
|---|---|---|---|---|
| CNOT-copy | toy_cnot_copy | exhaustive | hash and resource counts verified | pass |
| Toffoli-AND | toy_toffoli_and | exhaustive | hash and resource counts verified | pass |
| SWAP | toy_swap | exhaustive | hash and resource counts verified | pass |
| Addition mod | toy_add_mod_2n | exhaustive | hash and resource counts verified | pass |
7.2. Deterministic Randomized Tests
| Certificate | p | Tests | Transcript | Public circuit | Status |
|---|---|---|---|---|---|
| inv_8bit | 251 | 32 | hash verified | not attached | pass |
| inv_16bit | 65521 | 64 | hash verified | not attached | pass |
| inv_8bit_with_circuit | 251 | 32 | hash verified | hash/counts verified | pass |
7.3. Resource-Count Reproduction
7.4. Certificate-Size and Verifier-Runtime Measurements
8. Comparison with Existing Disclosure Models
8.1. Open Circuits and Recomputation
8.2. Withheld Circuits and Zero-Knowledge Attestation
8.3. Public Arithmetic Blocks with Proof-Carrying Certificates
8.4. Summary Table
9. Limitations
10. Future Work
11. Conclusions
References
- Babbush, R.; Zalcman, A.; Gidney, C.; Broughton, M.; Khattar, T.; Neven, H.; Bergamaschi, T.; Drake, J.; Boneh, D. Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations, 2026, [arXiv:quant-ph/2603.28846]. Version 2, April 2026.
- Luo, H.; Yang, Z.; Wang, Z.; Su, Y.; Li, T. Space-Efficient Quantum Algorithm for Elliptic Curve Discrete Logarithms with Resource Estimation, 2026, [arXiv:quant-ph/2604.02311]. Version 2, April 2026.
- Shor, P.W. Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer. SIAM Journal on Computing 1997, 26, 1484–1509. [CrossRef]
- Proos, J.; Zalka, C. Shor’s Discrete Logarithm Quantum Algorithm for Elliptic Curves. In Proceedings of the Quantum Information and Computation, 2003, Vol. 3, pp. 317–344. Often cited for the register-sharing approach to quantum ECDLP.
- Roetteler, M.; Naehrig, M.; Svore, K.M.; Lauter, K. Quantum Resource Estimates for Computing Elliptic Curve Discrete Logarithms. In Proceedings of the Advances in Cryptology – ASIACRYPT 2017. Springer, 2017, Vol. 10625, Lecture Notes in Computer Science, pp. 241–270. [CrossRef]
- Häner, T.; Jaques, S.; Naehrig, M.; Roetteler, M.; Soeken, M. Improved Quantum Circuits for Elliptic Curve Discrete Logarithms, 2020, [arXiv:quant-ph/2001.09580]. Metadata to be verified against final publication if used.
- Fiat, A.; Shamir, A. How to Prove Yourself: Practical Solutions to Identification and Signature Problems. Advances in Cryptology – CRYPTO ’86 1987, 263, 186–194. [CrossRef]
- National Institute of Standards and Technology. SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions. FIPS PUB 202, National Institute of Standards and Technology, 2015. [CrossRef]
- Nielsen, M.A.; Chuang, I.L. Quantum Computation and Quantum Information, 10th anniversary edition ed.; Cambridge University Press, 2010. [CrossRef]
- Amy, M.; Maslov, D.; Mosca, M.; Roetteler, M. A Meet-in-the-Middle Algorithm for Fast Synthesis of Depth-Optimal Quantum Circuits. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems 2013, 32, 818–830. [CrossRef]
- National Institute of Standards and Technology. SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions. Federal Information Processing Standards Publication 202, National Institute of Standards and Technology, Gaithersburg, MD, 2015. [CrossRef]
- Groth, J. On the Size of Pairing-Based Non-interactive Arguments. In Proceedings of the Advances in Cryptology – EUROCRYPT 2016. Springer, 2016, Vol. 9666, Lecture Notes in Computer Science, pp. 305–326. [CrossRef]
- Creutz, B. Second p-Descents on Elliptic Curves. Mathematics of Computation 2014, 83, 365–409. [CrossRef]
- Dogra, N. 2-Descent for Bloch–Kato Selmer Groups and Rational Points on Hyperelliptic Curves II, 2024, [arXiv:math.NT/2403.09790]. Verify final publication data before journal submission.
| 1 | outputs/certificatereport.md and outputs/certificatereport.csv. |
| 2 | outputs/toycircuitreport.md and outputs/toycircuitreport.csv. |
| Field | Meaning |
|---|---|
| Input width | Number of bits used to represent x. |
| Output width | Number of bits used to represent . |
| Work width | Number and type of work registers. |
| Gate basis | For example, , , , and in the prototype. |
| Toffoli count | Number of Toffoli-type gates under the stated gate basis. |
| CNOT count | Number of CNOT gates under the stated gate basis. |
| Serial depth | Depth under the prototype’s serial scheduling convention. This is not a parallel or architecture-aware depth metric. |
| Test status | Whether correctness was checked exhaustively or by hash-derived randomized tests. |
| Field | Prototype verification rule |
|---|---|
| logical_qubits | Compare against the declared qubit count in the public gate-list circuit. |
| toffoli_count | Recompute the number of TOFFOLI gates in the public gate list. |
| cnot_count | Recompute the number of CNOT gates in the public gate list. |
| serial_depth | Compare against the prototype serial-schedule convention. In the current verifier, this equals the total number of gates. |
| circuit_hash | Recompute the hash of the canonical circuit representation and compare it to the certificate commitment. |
| Certificate | Bits | Tests | Certificate size | Verify time | Status |
|---|---|---|---|---|---|
| inv_8bit | 8 | 32 | to be reported | to be reported | pass |
| inv_16bit | 16 | 64 | to be reported | to be reported | pass |
| Addition mod | 2 | exhaustive | to be reported | to be reported | pass |
| Model | Representative use | Verification mechanism | Best suited for |
|---|---|---|---|
| Full disclosure | Public circuit construction, as in Luo et al. [2] | Independent recomputation from a public circuit or generator | Open arithmetic designs where full technical disclosure is intended. |
| Withheld circuit with proof | Sensitive resource claims, as in Babbush et al. [1] | Circuit commitment, randomized tests, and proof artifact | Full attack circuits or sensitive implementations where disclosure may be undesirable. |
| Public circuit with certificate | This paper | Circuit hash, resource-count checks, deterministic tests, and transcript hash | Public reversible arithmetic blocks, such as modular inversion, multiplication, and point addition. |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).