Skip to main content

Table 7 The cost of quantum partial key guessing using \(\mathcal {D}_{i}(i=1,2,3,4)\) in \(\mathcal {QRKR}\)

From: Quantum key recovery attack on SIMON32/64

#iter

#NOT

# CNOTsum

# Hsum

#Cliff

#T

T-depth

Full depth

#qubit

  

#CNOT

#Toff-C

#H

#Toff-H

     

1

0

464

2044

50

584

3142

2044

732

2560

209

\(\lfloor \frac {\pi }{4}\sqrt {2^{14}}\rfloor \)

0

1.41·215

1.52·217

1.23·212

1.74·215

1.23·218

1.52·217

1.15·216

218

209