Skip to main content

Table 6 The cost of quantum exhaustive search on SIMON32/64

From: Quantum key recovery attack on SIMON32/64

Round

#NOT

# CNOTsum

# Hsum

#Cliff

#T

T-depth

Full depth

#qubit

Refer.

  

#CNOT

#Toff-C

#H

#Toff-H

      

32

243

1.62·245

0

0

0

1.35·245.5

1.27·246

1.18·245

1.05·246.3

161

(Anand et al. 2020c)

32

1.41·241

1.87·244

1.15·246

1.62·238

1.32·244

247

1.15·246

1.87·241

244

255

This paper

19

1.52·240

1.07·244

1.41·245

1.62·238

1.62·243

1.23·246

1.41·245

1.74·241

1.74·243

255

This paper