Paper 2026/1128

Optimized Point Addition Circuits for Elliptic Curve Discrete Logarithms

André Schrottenloher, Univ Rennes, Inria, CNRS, IRISA
Abstract

Shor's algorithm represents the main threat of quantum computers to cryptography. In order to precisely understand its feasibility, many authors have worked towards reducing its costs, either at the logical level (assuming a fault-tolerant architecture), or at the physical level (taking into account the constraints of envisioned hardware). In particular, recent works by Chevignard et al. (CRYPTO 2024) and Gidney (arXiv 2025) used improved arithmetic to significantly reduce the qubit cost of factoring RSA public keys. Even more recently, Babbush et al. (arXiv 2026) improved the cost of computing elliptic curve discrete logarithms, with a reduction of a factor 2 to 3 in gate count and qubit count compared to a previous work by Litinski (arXiv 2023). Their result relies on optimized point addition circuits on elliptic curves over prime fields. However they did not reveal their logical quantum circuits, relying instead on a zero-knowledge proof. In this paper, we detail a quantum logical circuit architecture which gives similar results as Babbush et al., with a slightly higher number of qubits (around 1.5% increase) and a slightly smaller Toffoli gate count (between 6.5% and 10% reduction) for the curve secp256k1. We also give gate counts for a generic variant of the circuit, which is valid for any prime field.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Quantum cryptanalysisShor's algorithmDiscrete logarithmsElliptic curvesQuantum resource estimates
Contact author(s)
andre schrottenloher @ inria fr
History
2026-06-04: approved
2026-06-01: received
See all versions
Short URL
https://ia.cr/2026/1128
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1128,
      author = {André Schrottenloher},
      title = {Optimized Point Addition Circuits for Elliptic Curve Discrete Logarithms},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1128},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1128}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.