Searcharxiv⌕ Search

arXiv · 2609.34996

Cyclotomic Cosets: Hidden Subgroup and Quantum Sieving Algorithm for Prime-Power Moduli

Abstract

The Learning With Errors (LWE) problem is a fundamental assumption in post-quantum cryptography. Regev established a quantum reduction from LWE to the Dihedral Coset Problem (DCP). Later, Brakerski et al. introduced the Extrapolated Dihedral Coset Problem (EDCP), proving its equivalence to LWE. However, unlike DCP, EDCP no longer admits a coset structure. This limits the direct application of techniques for hidden subgroup problems. In this work, we introduce the Cyclotomic Coset Problem (CCP), a cyclotomic generalization of DCP that preserves an exact hidden-subgroup structure. Let $ζ_p$ be a primitive $p$-th root of unity, let $π=ζ_p-1$, and write $q=p^t$ and $L=t(p-1)$. We work over $R_q=\mathbb Z_q[ζ_p] \cong \mathbb Z[ζ_p]/(π^L)$, where the isomorphism follows from the total ramification identity $(p)=(π)^{p-1}$. We exploit the resulting $π$-adic ideal chain to construct a quantum sieve that successively reduces phase states modulo $π^{L},π^{L-1},\ldots,π$. For every fixed prime $p$ and modulus $q=p^t$, our algorithm solves the CCP in time and sample complexity $2^{O_p(\log n\log q)}$, using polynomial quantum space. The sieve also applies to uniform EDCP and Gaussian S|LWE>, yielding quasi-polynomial time algorithms for all the above problems when $q=\text{poly}(n)$. This extends the power-of-two EDCP sieve of Bai et al. (CRYPTO 2025) to a cyclotomic setting. However, we emphasize that our result does not, by itself, yield a quasi-polynomial-time algorithm for standard LWE, because the currently known reduction produces only a limited number of approximate CCP states.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Mathias Boucher, Pierre-Alain Fouque, Yixin Shen. 2026-09-28. Cyclotomic Cosets: Hidden Subgroup and Quantum Sieving Algorithm for Prime-Power Moduli. https://arxiv.org/abs/2609.34996

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Preparation of Hamming-Weight-Preserving Quantum States with Log-Depth Quantum Circuits

Hamming-Weight-Preserving (HWP) states, $\vertψ_{\mathrm{H}}\rangle=\sum_{\mathrm{HW}(x)=k}α_x\vert x\rangle$, represent a fundamental class of quantum states on $n$ qubits with fixed excitation number $k$, playing a pivotal role in quantum simulation, machine learning, and optimization, with prominent examples including the Bethe eigenstates of integrable models and Configuration Interaction states. However, existing preparation methodologies typically rely on sequential architectures whose depth scales linearly with the subspace dimension, whereas practical deployment on realistic quantum hardware demands shallow circuits to mitigate decoherence. In this work, we present quantum circuits that achieve the information theoretic limit of depth logarithmic in the number of populated computational basis states while maintaining asymptotically optimal size. Specifically, for general HWP states, we provide a construction that matches the lower bounds of $Θ(\log \binom{n}{k})$ depth and $Θ(\binom{n}{k})$ size. Furthermore, we propose a resource efficient scheme utilizing only $O(\log k)$ ancillary qubits. For the $k=2$ case, where HWP states naturally admit a graph representation, we show that states whose support graphs are trees or grids admit ancilla free preparation with $Θ(\log n)$ depth and $Θ(m)$ size. Overall, our work provides logarithmic depth state preparation algorithms across various regimes while establishing a connection between quantum state synthesis and Krawtchouk polynomials.

quant-ph↗

Matrix-product-state-assisted variational Gibbs-state preparation

Evaluating the von Neumann entropy is a central challenge in variational Gibbs-state preparation. We introduce and benchmark matrix-product-state (MPS) assistance for classically evaluating and optimizing the purification circuits without full-statevector storage, examining how circuit architecture affects both thermal-state accuracy and the computational resources required. Comparisons on four- and six-spin transverse-field Ising and XXZ chains reveal complementary strengths: a thermofield-double ansatz performs better at high temperature, whereas a contiguous hardware-efficient ansatz (HEA) performs better on cooling. We identify a layer-dependent entropy ceiling in the contiguous HEA and compare it with an interleaved architecture whose entropy capacity is set solely by the ancilla qubit count. MPS-based benchmarks on 10 x 1, 20 x 1, 3 x 3, and 4 x 4 transverse-field Ising systems show that the tested interleaved circuits generally lower the free-energy errors and improve thermal observables. However, greater entropy capacity and lower free energy do not guarantee improvement in every observable. The architectures also differ in classical cost: contiguous registers permit entropy evaluation at a single MPS bond, whereas the interleaved arrangement requires a dense entropy calculation that scales exponentially with the number of ancillas. These benchmarks connect the accuracy of MPS-assisted Gibbs-state preparation to circuit capacity, optimization, and the tractability of energy and entropy evaluation.

quant-ph↗

A Unified Error Correction Code for Universal Quantum Computing with Identical Particles

We present a universal fault-tolerant quantum computing architecture based on identical particle qubits (IPQs), where we find that the first-order IPQ - bath interaction fundamentally differs from the conventional first-order qubit-bath interaction. This key distinction necessitates a redesign of existing strategies to fight decoherence. We propose that the simplest quantum error correction code can be realized directly within the physical qubit, provided that conventional correction and restoration are generalized beyond unitary operations to employ physically implementable reversal operations -- naturally placing logical and physical qubits on equal footing. We further demonstrate that dynamical decoupling (DD) remains effective within this unified framework, and that a decoherence-free subspace (DFS) -- like structure emerges. Unlike previous approximate treatments, our analytically solvable IPQ-Bath model enables rigorous testing of these strategies, with numerical simulations validating their effectiveness.

quant-ph↗