{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T19:35:24Z","timestamp":1782156924930,"version":"3.54.5"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319694528","type":"print"},{"value":"9783319694535","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-69453-5_18","type":"book-chapter","created":{"date-parts":[[2017,10,19]],"date-time":"2017-10-19T08:39:11Z","timestamp":1508402351000},"page":"317-337","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":75,"title":["Estimating the Cost of Generic Quantum Pre-image Attacks on SHA-2 and SHA-3"],"prefix":"10.1007","author":[{"given":"Matthew","family":"Amy","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Olivia","family":"Di Matteo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vlad","family":"Gheorghiu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michele","family":"Mosca","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alex","family":"Parent","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"John","family":"Schanck","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,10,20]]},"reference":[{"issue":"5","key":"18_CR1","doi-asserted-by":"publisher","first-page":"1484","DOI":"10.1137\/S0097539795293172","volume":"26","author":"PW Shor","year":"1997","unstructured":"Shor, P.W.: Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput. 26(5), 1484\u20131509 (1997). http:\/\/link.aip.org\/link\/?SMJ\/26\/1484\/1","journal-title":"SIAM J. Comput."},{"key":"18_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"424","DOI":"10.1007\/3-540-44750-4_34","volume-title":"Advances in Cryptology \u2014 CRYPT0\u2019 95","author":"D Boneh","year":"1995","unstructured":"Boneh, D., Lipton, R.J.: Quantum cryptanalysis of hidden linear functions. In: Coppersmith, D. (ed.) CRYPTO 1995. LNCS, vol. 963, pp. 424\u2013437. Springer, Heidelberg (1995). doi:10.1007\/3-540-44750-4_34"},{"key":"18_CR3","doi-asserted-by":"publisher","first-page":"325","DOI":"10.1103\/PhysRevLett.79.325","volume":"79","author":"LK Grover","year":"1997","unstructured":"Grover, L.K.: Quantum mechanics helps in searching for a needle in a haystack. Phys. Rev. Lett. 79, 325\u2013328 (1997). http:\/\/link.aps.org\/doi\/10.1103\/PhysRevLett.79.325","journal-title":"Phys. Rev. Lett."},{"key":"18_CR4","doi-asserted-by":"crossref","unstructured":"Boyer, M., Brassard, G., H\u00f8yer, P., Tapp, A.: Tight bounds on quantum searching. Fortschritte der Physik 46(4\u20135), 493\u2013505 (1998). http:\/\/dx.doi.org\/10.1002\/(SICI)1521--3978(199806)46:4\/5<493::AID-PROP493>3.0.CO;2-P","DOI":"10.1002\/(SICI)1521-3978(199806)46:4\/5<493::AID-PROP493>3.0.CO;2-P"},{"key":"18_CR5","doi-asserted-by":"crossref","unstructured":"Gilles, B., Peter, H., Michele, M., Alain, T.: Quantum amplitude amplification and estimation. Quantum Comput. Quantum Inf. 305, 53\u201374 (2002). e-print arXiv:quant-ph\/0005055. Lomonaco Jr., S.J. (ed.) AMS Contemporary Mathematics","DOI":"10.1090\/conm\/305\/05215"},{"key":"18_CR6","unstructured":"U.S. National Security Agency: NSA Suite B Cryptography - NSA\/CSS. NSA. https:\/\/www.nsa.gov\/ia\/programs\/suiteb_cryptography\/"},{"key":"18_CR7","doi-asserted-by":"crossref","unstructured":"Chen, L., Jordan, S., Liu, Y.K., Moody, D., Peralta, R., Perlner, R., Smith-Tone, D.: Report on post-quantum cryptography. National Institute of Standards and Technology Internal Report 8105, February 2016","DOI":"10.6028\/NIST.IR.8105"},{"key":"18_CR8","unstructured":"Lenstra, A.K.: Key lengths. In: Handbook of Information Security. Wiley (2004)"},{"issue":"4","key":"18_CR9","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1007\/s00145-001-0009-4","volume":"14","author":"AK Lenstra","year":"2001","unstructured":"Lenstra, A.K., Verheul, E.R.: Selecting cryptographic key sizes. J. Cryptol. 14(4), 255\u2013293 (2001)","journal-title":"J. Cryptol."},{"key":"18_CR10","doi-asserted-by":"crossref","unstructured":"Blaze, M., Diffie, W., Rivest, R., Schneier, B., Shimomura, T., Thompson, E., Weiner, M.: Minimal key lengths for symmetric ciphers to provide adequate commercial security. Technical report, An ad hoc group of cryptographers and computer scientists (1996)","DOI":"10.21236\/ADA385264"},{"issue":"10","key":"18_CR11","doi-asserted-by":"publisher","first-page":"1476","DOI":"10.1109\/TCAD.2014.2341953","volume":"33","author":"M Amy","year":"2014","unstructured":"Amy, M., Maslov, D., Mosca, M.: Polynomial-time t-depth optimization of Clifford+T circuits via matroid partitioning. IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst. 33(10), 1476\u20131489 (2014)","journal-title":"IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst."},{"key":"18_CR12","unstructured":"Grassl, M., Langenberg, B., Roetteler, M., Steinwandt, R.: Applying Grover\u2019s algorithm to AES: quantum resource estimates, e-print arXiv:1512.04965 [quant-ph]"},{"key":"18_CR13","doi-asserted-by":"publisher","first-page":"032324","DOI":"10.1103\/PhysRevA.86.032324","volume":"86","author":"AG Fowler","year":"2012","unstructured":"Fowler, A.G., Mariantoni, M., Martinis, J.M., Cleland, A.N.: Surface codes: towards practical large-scale quantum computation. Phys. Rev. A 86, 032324 (2012). http:\/\/link.aps.org\/doi\/10.1103\/PhysRevA.86.032324","journal-title":"Phys. Rev. A"},{"issue":"4","key":"18_CR14","doi-asserted-by":"publisher","first-page":"042313","DOI":"10.1103\/PhysRevA.86.042313","volume":"86","author":"AG Fowler","year":"2012","unstructured":"Fowler, A.G., Whiteside, A.C., Hollenberg, L.C.L.: Towards practical classical processing for the surface code: timing analysis. Phys. Rev. A 86(4), 042313 (2012). http:\/\/link.aps.org\/doi\/10.1103\/PhysRevA.86.042313","journal-title":"Phys. Rev. A"},{"issue":"3","key":"18_CR15","doi-asserted-by":"publisher","first-page":"032324","DOI":"10.1103\/PhysRevA.86.032324","volume":"86","author":"AG Fowler","year":"2012","unstructured":"Fowler, A.G., Mariantoni, M., Martinis, J.M., Cleland, A.N.: Surface codes: towards practical large-scale quantum computation. Phys. Rev. A 86(3), 032324 (2012). http:\/\/link.aps.org\/doi\/10.1103\/PhysRevA.86.032324","journal-title":"Phys. Rev. A"},{"issue":"18","key":"18_CR16","doi-asserted-by":"publisher","first-page":"180501","DOI":"10.1103\/PhysRevLett.108.180501","volume":"108","author":"AG Fowler","year":"2012","unstructured":"Fowler, A.G., Whiteside, A.C., Hollenberg, L.C.L.: Towards practical classical processing for the surface code. Phys. Rev. Lett. 108(18), 180501 (2012). http:\/\/link.aps.org\/doi\/10.1103\/PhysRevLett.108.180501","journal-title":"Phys. Rev. Lett."},{"key":"18_CR17","unstructured":"Fowler, A.G.: Minimum weight perfect matching of fault-tolerant topological quantum error correction in average $O(1)$ parallel time. arXiv:1307.1740 [quant-ph], July 2013"},{"key":"18_CR18","unstructured":"Mining hardware comparison. Bitcoin Wiki, September 2015. https:\/\/en.bitcoin.it\/wiki\/Mining_hardware_comparison. Accessed 30 Mar 2016"},{"key":"18_CR19","unstructured":"Bernstein, D.J., Lange, T. (eds.): eBACS: ECRYPT Benchmarking of Cryptographic Systems. http:\/\/bench.cr.yp.to. Accessed 30 Mar 2016"},{"key":"18_CR20","doi-asserted-by":"crossref","unstructured":"Selinger, P.: Quantum circuits of $$T$$-depth one. Phys. Rev. A, 87, 042302 (2013). http:\/\/link.aps.org\/doi\/10.1103\/PhysRevA.87.042302","DOI":"10.1103\/PhysRevA.87.042302"},{"key":"18_CR21","unstructured":"NIST: Federal information processing standards publication 180\u20132 (2002). See also the Wikipedia entry http:\/\/en.wikipedia.org\/wiki\/SHA-2"},{"key":"18_CR22","unstructured":"Parent, A., Roetteler, M., Svore, K.M.: Reversible circuit compilation with space constraints. arXiv preprint arXiv:1510.00377 (2015)"},{"key":"18_CR23","unstructured":"Cuccaro, S.A., Draper, T.G., Kutin, S.A., Moulton, D.P.: A new quantum ripple-carry addition circuit. arXiv preprint arXiv:quant-ph\/0410184 (2004)"},{"issue":"6","key":"18_CR24","doi-asserted-by":"publisher","first-page":"818","DOI":"10.1109\/TCAD.2013.2244643","volume":"32","author":"M Amy","year":"2013","unstructured":"Amy, M., Maslov, D., Mosca, M., Roetteler, M.: A meet-in-the-middle algorithm for fast synthesis of depth-optimal quantum circuits. IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst. 32(6), 818\u2013830 (2013)","journal-title":"IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst."},{"key":"18_CR25","unstructured":"NIST: Federal information processing standards publication 202 (2015). See also the Wikipedia entry http:\/\/en.wikipedia.org\/wiki\/SHA-3"},{"key":"18_CR26","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Assche, G.V.: Sponge functions. In: Ecrypt Hash Workshop 2007, May 2007"},{"key":"18_CR27","doi-asserted-by":"publisher","first-page":"525","DOI":"10.1147\/rd.176.0525","volume":"17","author":"CH Bennett","year":"1973","unstructured":"Bennett, C.H.: Logical reversibility of computation. IBM J. Res. Dev. 17, 525\u2013532 (1973)","journal-title":"IBM J. Res. Dev."},{"key":"18_CR28","doi-asserted-by":"publisher","first-page":"766","DOI":"10.1137\/0218053","volume":"18","author":"CH Bennett","year":"1989","unstructured":"Bennett, C.H.: Time\/space trade-offs for reversible computation. SIAM J. Comput. 18, 766\u2013776 (1989)","journal-title":"SIAM J. Comput."},{"key":"18_CR29","doi-asserted-by":"crossref","unstructured":"Bertoni, G., Daemen, J., Peeters, M., Assche, G.V.: KeccakTools software, April 2012. http:\/\/keccak.noekeon.org\/","DOI":"10.1007\/978-3-642-38348-9_19"},{"key":"18_CR30","unstructured":"Amy, M., Parent, A., Roetteler, M.: ReVerC software, September 2016. https:\/\/github.com\/msr-quarc\/ReVerC"},{"key":"18_CR31","doi-asserted-by":"crossref","unstructured":"Amy, M., Roetteler, M., Svore, K.M.: Verified compilation of space-efficient reversible circuits. arXiv preprint arXiv:1603.01635 (2016)","DOI":"10.1007\/978-3-319-63390-9_1"},{"key":"18_CR32","doi-asserted-by":"publisher","first-page":"022316","DOI":"10.1103\/PhysRevA.71.022316","volume":"71","author":"S Bravyi","year":"2005","unstructured":"Bravyi, S., Kitaev, A.: Universal quantum computation with ideal Clifford gates and noisy Ancillas. Phys. Rev. A 71, 022316 (2005). http:\/\/link.aps.org\/doi\/10.1103\/PhysRevA.71.022316","journal-title":"Phys. Rev. A"},{"key":"18_CR33","doi-asserted-by":"crossref","unstructured":"Fowler, A.G., Devitt, S.J., Jones, C.: Surface code implementation of block code state distillation. Scientific Reports 3, 1939 EP - (2013). http:\/\/dx.doi.org\/10.1038\/srep.01939","DOI":"10.1038\/srep01939"}],"container-title":["Lecture Notes in Computer Science","Selected Areas in Cryptography \u2013 SAC 2016"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-69453-5_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,18]],"date-time":"2021-10-18T02:04:05Z","timestamp":1634522645000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-69453-5_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319694528","9783319694535"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-69453-5_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]},"assertion":[{"value":"20 October 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SAC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Selected Areas in Cryptography","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"St. John's","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Canada","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2016","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 August 2016","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 August 2016","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"sacrypt2016","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.engr.mun.ca\/~sac2016\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}