AG-2026.04-1769·quant-ph
Simon's Algorithm for the Even-Mansour Cipher on Quantum Hardware
Authors
- Anina Köhler
- Jakob Murauer
- Tim Heine
- Stefan Rosemann
- Tobias Hemmert
Abstract
Simon's algorithm is a polynomial period-finding algorithm that has been used to exploit the algebraic structure of specific symmetric ciphers, showing that exponential speedups in their cryptanalysis are theoretically possible. While the theoretical framework for an attack using Simon's algorithm on the Even-Mansour cipher is well-established, practical implementations on noisy intermediate-scale quantum (NISQ) hardware remain limited. This paper presents a proof of concept quantum cryptanalysis of the Even-Mansour cipher using Simon's period-finding algorithm on NISQ hardware. For N = 3 and N = 4, we successfully demonstrate secret key recovery for N-bit constructions on the ibm_miami processor. Our experiments also identify a scaling limitation in the classical pre-processing stage: The DORCIS circuit optimization tool encountered a memory bottleneck at N = 5, preventing the generation of optimized circuits for larger key lengths. Our results suggest firstly that Simon's algorithm is effective for the Even-Mansour cipher for short bit lengths on current quantum hardware. Secondly, while DORCIS is effective for the small-scale S-boxes for which it was designed, there remains a need for the investigation of more scalable and efficient synthesis tools capable of handling larger and more general permutations in the context of Even-Mansour ciphers.
Submitted
28 April 20262 weeks ago
Version
v1
License
CC-BY-4.0
DOI
10.48550/arXiv.2604.25509
Summary
Researchers demonstrated Simon's algorithm breaking Even-Mansour encryption on real quantum hardware for small key sizes (3-4 bits), but hit practical limits scaling beyond that due to circuit optimization challenges.
- Simon's algorithm—a quantum speedup for finding hidden periodicities—can theoretically crack certain symmetric ciphers; this work shows it actually works on today's noisy quantum processors, not just in theory.
- The attack succeeded for tiny keys (3-4 bits) on IBM's quantum computer, recovering secret keys faster than classical methods could for those sizes.
- The real bottleneck wasn't quantum hardware but classical software: tools for converting cryptographic components into quantum circuits ran out of memory at 5 bits, highlighting a practical engineering gap between theory and implementation.
curious · generated by claude-haiku-4-5
Chat with this PDF
Ask questions, probe assumptions, request a plain-English summary. Answers cite sections from the preprint itself.
Community
Questions and answers about this paper from other readers. No formal peer review — just a place to think out loud.