Estimating the cost of generic quantum pre-image attacks on SHA-2 and SHA-3 (original) (raw)
Abstract:We investigate the cost of Grover's quantum search algorithm when used in the context of pre-image attacks on the SHA-2 and SHA-3 families of hash functions. Our cost model assumes that the attack is run on a surface code based fault-tolerant quantum computer. Our estimates rely on a time-area metric that costs the number of logical qubits times the depth of the circuit in units of surface code cycles. As a surface code cycle involves a significant classical processing stage, our cost estimates allow for crude, but direct, comparisons of classical and quantum algorithms.
We exhibit a circuit for a pre-image attack on SHA-256 that is approximately 2153.82^{153.8}2153.8 surface code cycles deep and requires approximately 212.62^{12.6}212.6 logical qubits. This yields an overall cost of 2166.42^{166.4}2166.4 logical-qubit-cycles. Likewise we exhibit a SHA3-256 circuit that is approximately 2146.52^{146.5}2146.5 surface code cycles deep and requires approximately 2202^{20}220 logical qubits for a total cost of, again, 2166.52^{166.5}2166.5 logical-qubit-cycles. Both attacks require on the order of 21282^{128}2128 queries in a quantum black-box model, hence our results suggest that executing these attacks may be as much as 275275275 billion times more expensive than one would expect from the simple query analysis.
Submission history
From: Vlad Gheorghiu [view email]
[v1] Wed, 30 Mar 2016 21:01:14 UTC (504 KB)
[v2] Thu, 13 Oct 2016 16:24:02 UTC (532 KB)
[v3] Wed, 30 Nov 2016 14:23:49 UTC (532 KB)