Figure 1.
![Toffoli decomposition with measurement-based uncomputation, using four T gates, (a) without using any ancilla qubit [20], (b) with a single reusable ancilla qubit [13].](https://sciendo-parsed.s3.eu-central-1.amazonaws.com/69b03f3073f0b3637a28372d/j_qic-2025-0032_fig_001.jpg?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=ASIA6AP2G7AKHWVIK4OR%2F20260313%2Feu-central-1%2Fs3%2Faws4_request&X-Amz-Date=20260313T065145Z&X-Amz-Expires=3600&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEL7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaDGV1LWNlbnRyYWwtMSJIMEYCIQCmpjodvcCGbuMCOlFqerCkMsrZbsnjMscu9CMOrVrYOwIhAPHL5z41emb9UqZlvRMMiIXUVJyTQAvomRcIy4Ci%2BsrBKsYFCIf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQAhoMOTYzMTM0Mjg5OTQwIgwvWVM5Y8f9dKcB0xcqmgW3o8zkc7TKIC%2FMqpnqj%2BgUa5VpAnsPxq2reHqfDqiWTph3fGHwZbiGxLZ%2Foxvi4j9rGkY94F94979YKnwhb30Em8AS1IotiAhMEFlo8feWmJkGnKDM%2FDcJCc9udpsWWHtx%2BxbRSzOxNnfOOwNOI6lBxRap69FckjQV6fH7royLVWV0oq1PuEACnhqNvQRWLciLNDXsKfBXGPpVkrxEcsUIiab7mxnF8xDEH%2BpUQGjo%2Bj59OsqakgAbq1rmYW%2FjE%2F5yZUipEDlCOJpU4zJNI4G7%2Bh2bI9JcFyfkMUs4kt8oxjKDCaUET45aSRgkyoZ1koLrzGHEs0UfVAdJmVrYyPyxyGLnR%2Fs8YEIa9iCRcEIaynDomInBMTvdUSbu5v8XgEL24FqeWtXmPYRsgAoa1iBYJOMGlXSjOs2W1PE4xAjE3CiL6nvizd52w7GjxBZnVmU3s2Z4XOJBZs8TkfARZVQ%2FAhSS5OzZhl2rAVY44gLESQfFFkrD38Eg54y8lbzO6el4M5IBoF78jH1%2Fw%2F086d07gc1tptUXkr%2Bl71jKKaRt5or3nL%2FAi83PC6g8Te9N0cI7Xu5WDS3eDSEIDOlAqaEY%2FJgaJOUA%2Bb40XcE2tTtXDY43NP%2BHueabNCVaiPHlKdrLvP3FoIy9G8BxdqrSTd27YAMfvCWC35rcVi%2BOrU%2F9KCgRn0MCBkrOJq5w3%2B2h7DQHPGlf%2BBu2YAp0E%2BT2gKs2tLdesxJh4qZL%2FxR5KsP79Sr1vC6h0EqTOpRdZQt%2FiDJuW8w9Fl3D2U54TLy5Jlzne8azK%2BxUimtw9emjyIv%2BoqFjxnRyoU92c0A%2B6eDR9NP1oHIYwpldXbMfhyHjnmaQkcTQq%2BdlZSm4QO6rmNdH3bL6sL1U0S4HGBsw4MjOzQY6sAF2WXET%2F37Yd%2BxNy%2BAtlD3IkSxvu2DaGiQ4h%2BoLr%2Br%2B02b%2FyzFa5d9JIVA08PxCq5VwjCBQ56zlNUvpExqSWojrll9x74j%2FaEYN29DYX5Erspyd3VfrR4yJu64pbyPG6pyh14Qfsf6c8jnGYl9SomrAgEh1%2Fs39KMfHJrhPZ9h3tzSZR6a0%2FPTdlcBn6XbQ5%2FUGC7BtSsaxzJXPpy2WeocVjQtZ6I0EDyn616Zpa%2FI2Og%3D%3D&X-Amz-Signature=bb1e00c49f4d0ef381b3bdea2dd84febc739e3b209f8ff6a057042778907899f&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)
Figure 2.

Figure 3.

Optimal T-depth quantum implementation of full round AES with corresponding resources_
| Key size | No. of round | Ancilla count | CNOT count | CNOT depth | T-count | T-depth |
|---|---|---|---|---|---|---|
| 128 | 10 | 10688 | 588328 | 1967 | 157440 | 30 |
| 192 | 12 | 10944 | 706072 | 2363 | 188928 | 36 |
| 256 | 14 | 11200 | 823816 | 2759 | 220416 | 42 |
Optimal T-depth quantum circuit synthesis for various standard S-boxes with corresponding resource estimates using Theorem 2_ *A detailed analysis for the AES S-box is provided in Section 4_
| S-box | #Variables | Ancilla count | CNOT count | CNOT depth | T-count | T-depth |
|---|---|---|---|---|---|---|
| LowMC [22] | 3 | 9 | 39 | 13 | 12 | 1 |
| DEFAULT [23] | 4 | 17 | 79 | 27 | 24 | 2 |
| GIFT [24] | 4 | 14 | 76 | 27 | 24 | 2 |
| PRESENT [25] | 4 | 19 | 105 | 30 | 32 | 2 |
| PRINCE [26] | 4 | 24 | 128 | 28 | 40 | 2 |
| ASCON [27] | 5 | 27 | 120 | 22 | 32 | 1 |
| AES [28]* | 8 | 596 | 3647 | 184 | 984 | 3 |
Quantum implementation of a single round of AES with corresponding resource estimates_
| Toffoli-to-T | Ancilla count | CNOT count | CNOT depth | T-count | T-depth |
|---|---|---|---|---|---|
| Using Figure 1a | 7520 | 47064 | 189 | 15744 | 4 |
| Using Figure 1b | 9536 | 58872 | 198 | 15744 | 3 |
Quantum circuits for AES S-box with corresponding resource estimates_
| Toffoli-to-T | Ancilla count | CNOT count | CNOT depth | T-count | T-depth |
|---|---|---|---|---|---|
| Using Figure 1a | 470 | 2909 | 175 | 984 | 4 |
| Using Figure 1b | 596 | 3647 | 184 | 984 | 3 |
Optimal T-depth quantum implementation of full round AES: A comparison with prior results_
| Key size | References | Ancilla count | CNOT count | CNOT depth | T-count | T-depth |
|---|---|---|---|---|---|---|
| 128 | [13, Table 4] | 4244 | 284420 | NA | 54400 | 120 |
| 128 | [30, Table 2] | 9384 | NA | NA | 33600 | 50 |
| 128 | [15, Table 13] | 3689 | 132376 | NA | 27200 | 40 |
| 128 | [14, Table 7] | 5576 | 285393 | NA | 62400 | 30 |
| 128 | [16, Table VI] | NA | 228020 | NA | 52800 | 30 |
| 128 | [18, Table 8] | NA | 176580 | NA | 33600 | 30 |
| 128 | [19, Table 5] | 6128 | 120812 | NA | 117984 | 30 |
| 128 | [This paper] | 10688 | 588328 | 1967 | 157440 | 30 |
| 192 | [13, Table 4] | 4564 | 321021 | NA | 60928 | 144 |
| 192 | [30, Table 2] | 10456 | NA | NA | 37632 | 60 |
| 192 | [15, Table 13] | 3945 | 149256 | NA | 30464 | 48 |
| 192 | [19, Table 5] | 6448 | 136812 | NA | 132960 | 36 |
| 192 | [This paper] | 10944 | 706072 | 2363 | 188928 | 36 |
| 256 | [13, Table 4] | 4884 | 393534 | NA | 75072 | 168 |
| 256 | [30, Table 2] | 46368 | NA | NA | 12704 | 70 |
| 256 | [15, Table 13] | 4457 | 187128 | NA | 38080 | 56 |
| 256 | [19, Table 5] | 6768 | 168548 | NA | 165264 | 42 |
| 256 | [This paper] | 11200 | 823816 | 2759 | 220416 | 42 |