Skip to main content

Table 6 The cost of quantum exhaustive search on SIMON32/64

From: Quantum key recovery attack on SIMON32/64

Round #NOT # CNOTsum # Hsum #Cliff #T T-depth Full depth #qubit Refer.
   #CNOT #Toff-C #H #Toff-H       
32 243 1.62·245 0 0 0 1.35·245.5 1.27·246 1.18·245 1.05·246.3 161 (Anand et al. 2020c)
32 1.41·241 1.87·244 1.15·246 1.62·238 1.32·244 247 1.15·246 1.87·241 244 255 This paper
19 1.52·240 1.07·244 1.41·245 1.62·238 1.62·243 1.23·246 1.41·245 1.74·241 1.74·243 255 This paper