Figure 1.

Figure 2.

Figure 3.

Optimal T-depth quantum implementation of full round AES with corresponding resources_
| Key size | No. of round | Ancilla count | CNOT count | CNOT depth | T-count | T-depth |
|---|---|---|---|---|---|---|
| 128 | 10 | 10688 | 588328 | 1967 | 157440 | 30 |
| 192 | 12 | 10944 | 706072 | 2363 | 188928 | 36 |
| 256 | 14 | 11200 | 823816 | 2759 | 220416 | 42 |
Optimal T-depth quantum circuit synthesis for various standard S-boxes with corresponding resource estimates using Theorem 2_ *A detailed analysis for the AES S-box is provided in Section 4_
| S-box | #Variables | Ancilla count | CNOT count | CNOT depth | T-count | T-depth |
|---|---|---|---|---|---|---|
| LowMC [22] | 3 | 9 | 39 | 13 | 12 | 1 |
| DEFAULT [23] | 4 | 17 | 79 | 27 | 24 | 2 |
| GIFT [24] | 4 | 14 | 76 | 27 | 24 | 2 |
| PRESENT [25] | 4 | 19 | 105 | 30 | 32 | 2 |
| PRINCE [26] | 4 | 24 | 128 | 28 | 40 | 2 |
| ASCON [27] | 5 | 27 | 120 | 22 | 32 | 1 |
| AES [28]* | 8 | 596 | 3647 | 184 | 984 | 3 |
Quantum implementation of a single round of AES with corresponding resource estimates_
| Toffoli-to-T | Ancilla count | CNOT count | CNOT depth | T-count | T-depth |
|---|---|---|---|---|---|
| Using Figure 1a | 7520 | 47064 | 189 | 15744 | 4 |
| Using Figure 1b | 9536 | 58872 | 198 | 15744 | 3 |
Quantum circuits for AES S-box with corresponding resource estimates_
| Toffoli-to-T | Ancilla count | CNOT count | CNOT depth | T-count | T-depth |
|---|---|---|---|---|---|
| Using Figure 1a | 470 | 2909 | 175 | 984 | 4 |
| Using Figure 1b | 596 | 3647 | 184 | 984 | 3 |
Optimal T-depth quantum implementation of full round AES: A comparison with prior results_
| Key size | References | Ancilla count | CNOT count | CNOT depth | T-count | T-depth |
|---|---|---|---|---|---|---|
| 128 | [13, Table 4] | 4244 | 284420 | NA | 54400 | 120 |
| 128 | [30, Table 2] | 9384 | NA | NA | 33600 | 50 |
| 128 | [15, Table 13] | 3689 | 132376 | NA | 27200 | 40 |
| 128 | [14, Table 7] | 5576 | 285393 | NA | 62400 | 30 |
| 128 | [16, Table VI] | NA | 228020 | NA | 52800 | 30 |
| 128 | [18, Table 8] | NA | 176580 | NA | 33600 | 30 |
| 128 | [19, Table 5] | 6128 | 120812 | NA | 117984 | 30 |
| 128 | [This paper] | 10688 | 588328 | 1967 | 157440 | 30 |
| 192 | [13, Table 4] | 4564 | 321021 | NA | 60928 | 144 |
| 192 | [30, Table 2] | 10456 | NA | NA | 37632 | 60 |
| 192 | [15, Table 13] | 3945 | 149256 | NA | 30464 | 48 |
| 192 | [19, Table 5] | 6448 | 136812 | NA | 132960 | 36 |
| 192 | [This paper] | 10944 | 706072 | 2363 | 188928 | 36 |
| 256 | [13, Table 4] | 4884 | 393534 | NA | 75072 | 168 |
| 256 | [30, Table 2] | 46368 | NA | NA | 12704 | 70 |
| 256 | [15, Table 13] | 4457 | 187128 | NA | 38080 | 56 |
| 256 | [19, Table 5] | 6768 | 168548 | NA | 165264 | 42 |
| 256 | [This paper] | 11200 | 823816 | 2759 | 220416 | 42 |