Paper 2025/1832

Can Quantum Break ZUC? Only with a Million Qubits and a Billion Years to Spare

Anik Basu Bhaumik, Nanyang Technological University
Suman Dutta, Indian Statistical Institute
Siyi Wang, Nanyang Technological University
Anubhab Baksi, Lund University
Kyungbae Jang, Hansung University
Amit Saha, Inria Paris, École Normale Supérieure - PSL
Hwajeong Seo, Hansung University
Anupam Chattopadhyay, Nanyang Technological University
Abstract

The ZUC stream cipher is integral to modern mobile communication standards, including 4G and 5G, providing secure data transmission across global networks. Recently, Dutta et al. (Indocrypt, 2024) presented the first quantum resource estimation of ZUC under Grover's search, Although preliminary, this work marks the beginning of quantum security analysis for ZUC. In this paper, we present an improved quantum resource estimation for ZUC, offering tighter bounds for Grover-based exhaustive key search. Beyond traditional quantum resource estimations, we also provide a concrete timescale required to execute such attacks using the specified quantum resources. Our findings show that a full-round, low depth implementation of ZUC-128 can be realized with a maximum of $375$ ancilla qubits, a T-count of $106536$, and a T-depth of $15816$. Furthermore, the Grover-based key search can be performed most efficiently using $1201$ logical qubits, $170681$ T gates, and a T-depth of $78189$, resulting in a runtime of $1.78\times10^{11}$ years, an improvement of 93.43% over the estimated $2.71 \times 10^{12}$ years by the implementation given by Dutta et al., we also provide akin analysis for ZUC-256 with an 99.23% decrease in time. These estimations are done assuming state-of-the-art superconducting qubit error-correcting technology.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Fault-tolerant quantum computingGrover's algorithmQuantum circuit optimisationSpace-depth trade-offs
Contact author(s)
anikbasu001 @ e ntu edu sg
sumand iiserb @ gmail com
siyi002 @ e ntu edu sg
anubhab baksi @ eit lth se
starj1023 @ gmail com
abamitsaha @ gmail com
hwajeong84 @ gmail com
anupam @ ntu edu sg
History
2025-10-10: revised
2025-10-04: received
See all versions
Short URL
https://ia.cr/2025/1832
License
Creative Commons Attribution-NonCommercial-NoDerivs
CC BY-NC-ND

BibTeX

@misc{cryptoeprint:2025/1832,
      author = {Anik Basu Bhaumik and Suman Dutta and Siyi Wang and Anubhab Baksi and Kyungbae Jang and Amit Saha and Hwajeong Seo and Anupam Chattopadhyay},
      title = {Can Quantum Break {ZUC}? Only with a Million Qubits and a Billion Years to Spare},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1832},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1832}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.