{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:38:28Z","timestamp":1780634308878,"version":"3.54.1"},"reference-count":0,"publisher":"Universitatsbibliothek der Ruhr-Universitat Bochum","issue":"2","license":[{"start":{"date-parts":[[2025,3,4]],"date-time":"2025-03-04T00:00:00Z","timestamp":1741046400000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["TCHES"],"abstract":"<jats:p>This paper improves upon the quantum circuits required for the Shor\u2019s attack on binary elliptic curves. We present two types of quantum point addition, taking both qubit count and circuit depth into consideration.In summary, we propose an in-place point addition that improves upon the work of Banegas et al. from CHES\u201921, reducing the qubit count \u2013 depth product by more than 73% \u2013 81% depending on the variant. Furthermore, we develop an out-of-place point addition by using additional qubits. This method achieves the lowest circuit depth and offers an improvement of over 92% in the qubit count \u2013 quantum depth product (for a single step).To the best of our knowledge, our work improves from all previous works (including the CHES\u201921 paper by Banegas et al., the IEEE Access\u201922 paper by Putranto et al., and the CT-RSA\u201923 paper by Taguchi and Takayasu) in terms of circuit depth and qubit count \u2013 depth product.Equipped with the implementations, we discuss the post-quantum security of the binary elliptic curve cryptography. Under the MAXDEPTH metric (proposed by the US government\u2019s NIST), the quantum circuit with the highest depth in our work is 224, which is significantly lower than the MAXDEPTH limit of 240. For the gate count \u2013 full depth product, a metric for estimating quantum attack cost (proposed by NIST), the highest complexity in our work is 260 for the curve having degree 571 (which is comparable to AES-256 in terms of classical security), considerably below the post-quantum security level 1 threshold (of the order of 2156).<\/jats:p>","DOI":"10.46586\/tches.v2025.i2.781-804","type":"journal-article","created":{"date-parts":[[2025,3,5]],"date-time":"2025-03-05T10:28:50Z","timestamp":1741170530000},"page":"781-804","source":"Crossref","is-referenced-by-count":4,"title":["New Quantum Cryptanalysis of Binary Elliptic Curves"],"prefix":"10.46586","volume":"2025","author":[{"given":"Kyungbae","family":"Jang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vikas","family":"Srivastava","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anubhab","family":"Baksi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Santanu","family":"Sarkar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hwajeong","family":"Seo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"25480","published-online":{"date-parts":[[2025,3,4]]},"container-title":["IACR Transactions on Cryptographic Hardware and Embedded Systems"],"original-title":[],"link":[{"URL":"https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/download\/12065\/11909","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/download\/12065\/11909","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,7]],"date-time":"2025-03-07T12:47:28Z","timestamp":1741351648000},"score":1,"resource":{"primary":{"URL":"https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/view\/12065"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,4]]},"references-count":0,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025,3,4]]}},"URL":"https:\/\/doi.org\/10.46586\/tches.v2025.i2.781-804","relation":{},"ISSN":["2569-2925"],"issn-type":[{"value":"2569-2925","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3,4]]}}}