🤖 AI Summary
This work investigates the quantum acceleration potential and practical feasibility of Grover’s algorithm for preimage attacks against 3-round Keccak-256. Method: Leveraging hardware-aware, end-to-end quantum resource modeling—including surface-code error correction—we quantify physical implementation overheads for the first time: ~3.2 million physical qubits, ultra-deep circuits, and severe error accumulation. Contribution/Results: While theoretical speedup reduces search complexity from $2^{57.8}$ to $2^{28.9}$, it is fully offset by prohibitive hardware costs; estimated attack runtime spans 43 days to 2,365 years—highly sensitive to device assumptions yet fundamentally bottlenecked by qubit count and circuit depth. The study confirms SHA-3’s resilience against practical quantum preimage attacks in the foreseeable future. Its key innovations include the first complete quantum circuit synthesis for Keccak-256, Toffoli gate optimization, and a unified logical–physical qubit complexity analysis framework.
📝 Abstract
This paper presents a hardware-conscious analysis of the quantum acceleration of the classical 3-round Keccak-256 preimage attack using Grover's Algorithm. While the theoretical quantum speed-up from T_cl=2^{57.8} (classical) to T_qu = 2^{28.9} (quantum) is mathematically sound, the practical implementation overhead is so extreme that attacks remain wholly infeasible in both resource and runtime dimensions. Using Qiskit-based circuit synthesis, we derive that a 3-round Keccak quantum oracle requires: 9,600 Toffoli gates (with uncomputation for reversibility); 3,200 logical qubits (1,600 state + 1,600 auxiliary); 7.47 * 10^{13} total 2-qubit gates (full Grover search); 3.2 million physical qubits (with quantum error correction)PROHIBITIVE; 0.12 years (43 days) to 2,365+ years execution time, depending on machine assumptions. These barriers -- particularly the physical qubit requirements, circuit depth, and error accumulation -- render the quantum attack infeasible for any foreseeable quantum computer. Consequently, SHA-3 security is not threatened by quantum computers for preimage attacks. We emphasize the critical importance of hardware-aware complexity analysis in quantum cryptanalysis: the elegant asymptotic theory of Grover's Algorithm hides an engineering overhead so prohibitive that the quantum approach becomes infeasible from both resource and implementation perspectives.