Skip to main content
Quantum Computation
Simplified
Kathiresan S
Part - 6 Shor’s algorithm, QPE & QFT
Introduction
What is Shor’s algorithm?
 This is to find prime factors of an integer and invented by an American
mathematician Peter Shor in 1994
 Could be used to break RSA cryptography schemes (used in online transactions).
 This is much faster than the most efficient known classical factoring algorithm.
(eg. To break RSA 2048 which will use a 617-digit number, it will take many
years in classical computer and a few seconds in a perfect Quantum Computer)
Prerequisite for this video
Essential
 Basic knowledge of Quantum Computing – my previous videos (Part 1 to 5) or
equivalent from other videos/ textbooks
Desirable
 Fourier transform
 Prime factorization
 Euclidean algorithm for finding GCD
 Continued fraction
 Root of unity
Factoring Algorithm
 N = P.Q where N is an odd composite number and P & Q are odd prime numbers (of roughly
equal in length/ value)
 𝑋2
= 1(mod N): 𝑋 ≠ ±1 (mod N)
 𝑋2
− 1 = 0(mod N)
 N divides (𝑋2
− 1) or (X - 1)(X + 1) but not X - 1 and X + 1
 GCD (N, X -1) and GCD(N, X + 1) will give factors of N
 Pick x a random number and find its period r such that 𝑥𝑟 = 1 mod N , Finding Greatest
Common Divisor (GCD) (𝑥𝑟/2
+ 1, 𝑁) 𝑎𝑛𝑑/𝑜𝑟 GCD (𝑥𝑟/2
− 1, 𝑁) will give factors of N
 Attempt fails when r is odd or 𝑥𝑟/2
= −1 (𝑚𝑜𝑑 𝑁). Repeat above step till these two conditions
are not met.
 Probability of guessing the right x is 1 −
1
2𝑘−1 where k is the number of distinct odd prime
factors of N
How to get period ‘r’
 What is period r? The period or order (r), is the smallest (non-zero) integer such that
xr mod N = 1
 Let us assume N = 15, x = 2 , 21(mod 15) = 2, 22(mod 15) = 4, 23(mod 15) =8,
24(mod 15) = 1, 25(mod 15) = 2, 26(mod 15) = 4, 27(mod 15) = 8,..
 r can be found out using Quantum Phase Estimation algorithm
 𝑈 𝜑 = 𝑒2𝜋𝑖𝜃 𝜑 where U is a unitary matrix and 𝑒2𝜋𝑖𝜃 is its eigen value and | 𝜑 is its
eigen vector
 In order to measure 𝜃, we need to know about Quantum Fourier Transform (& its
inverse) and Continued Fraction
Quantum Fourier Transform (QFT)
 Similar to FFT/ DFT, transforms between two bases, the computational (Z) basis, and
the Fourier basis
8 (decimal) in Computational Basis
8 (decimal) in Fourier Basis
Rotation of qubits – Multiples of
8
2𝑛 x 2𝜋 𝑟𝑎𝑑𝑖𝑎𝑛𝑠 =
8
16
x 360 𝑑𝑒𝑔𝑟𝑒𝑒𝑠
15 (decimal) in Computational Basis
15 (decimal) in Fourier Basis
Quantum Fourier Transform
 Discrete Fourier Transform
DFT of a vector of complex numbers, x0,….,xN-1 is given by the following equation wherein yk = y0,…...yN-1
𝑦𝑘 ≡
1
𝑁 𝑗=0
𝑁−1
𝑥𝑗𝑒2𝜋𝑖𝑗𝑘/𝑁
 Quantum Fourier Transform
QFT on an orthonormal basis states |0 , … … , |𝑁 − 1 is given by the following equation
|𝑗 →
1
𝑁 𝑘=0
𝑁−1
𝑒2𝜋𝑖𝑗𝑘/𝑁|𝑘
Assuming N = 2n where n is an integer,
|𝑗 →
1
2𝑛/2
𝑘=0
2𝑛−1
𝑒2𝜋𝑖𝑗𝑘/2𝑛
|𝑘
Quantum Fourier Transform
From previous slide,
|𝑗 →
1
2𝑛/2
𝑘=0
2𝑛−1
𝑒2𝜋𝑖𝑗𝑘/2𝑛
|𝑘
Normally, we need to have a Unitary matrix to do this operation. It is given by,
We will simplify the matrix with known small gates (unitary matrices)
|𝑗1 … … … … . . 𝑗𝑛 →
|0 + 𝑒2𝜋𝑖0.𝑗𝑛|1 |0 + 𝑒2𝜋𝑖0.𝑗𝑛−1𝑗𝑛|1 … … |0 + 𝑒2𝜋𝑖0.𝑗1𝑗2……𝑗𝑛|1
2𝑛/2
Quantum Fourier Transform
From previous slide,
|𝑗1,……….𝑗𝑛
→
|0 + 𝑒2𝜋𝑖0.𝑗𝑛|1 |0 + 𝑒2𝜋𝑖0.𝑗𝑛−1𝑗𝑛|1 … … |0 + 𝑒2𝜋𝑖0.𝑗1𝑗2……𝑗𝑛|1
2𝑛/2
𝑤ℎ𝑒𝑟𝑒𝑖𝑛 0. 𝑗1𝑗2 ….. 𝑗𝑛 =
𝑗1
21 +
𝑗2
22 + ⋯ … … +
𝑗𝑛
2𝑛
This can be achieved using three types of gates - Hadamard gate
1
2
1 1
1 −1
and a
Rotational gate 𝑅𝑘 =
1 0
0 𝑒
2𝜋𝑖
2𝑘
𝑤ℎ𝑒𝑟𝑒 𝑒
2𝜋𝑖
2𝑘
is 2k th root of unity and the circuit will look like this
(we need to have swap gates to maintain the order)
Quantum Fourier Transform
Let us try QFT on Binary 1000 (Decimal 8) in IBM QISKIT Quantum simulator
https://qiskit.org/
Quantum Phase Estimation (QPE)
No of bits to
meet accuracy
• Quantum phase estimation algorithm (also referred to as quantum eigenvalue estimation algorithm), is
a quantum algorithm to estimate the phase (or eigenvalue) of an eigenvector of a unitary operator. 𝑈 𝜑 = 𝑒2𝜋𝑖𝜃 𝜑
where U is a unitary operator and 𝑒2𝜋𝑖𝜃
is its eigen value and | 𝜑 is its eigen vector
After applying Hadamard gates on counting qubits, 𝜓1 =
1
2
𝑛
2
(|0 + |1 )⊗𝑛|𝜓
After applying Controlled Unitary Operator U for n times, 𝜓2 =
1
2
𝑛
2
|0 + 𝑒2𝜋𝑖𝜃20
|1 ⊗ |0 + 𝑒2𝜋𝑖𝜃21
|1 … … . .⊗
|0 + 𝑒2𝜋𝑖𝜃2𝑛−1
|1 ⊗ |𝜓
𝜓1 𝜓2
Quantum Phase Estimation
After applying Controlled Unitary Operator U n times,
𝜓2 =
1
2
𝑛
2
|0 + 𝑒2𝜋𝑖𝜃20
|1 ⊗ |0 + 𝑒2𝜋𝑖𝜃21
|1 … … . .⊗ |0 + 𝑒2𝜋𝑖𝜃2𝑛−1
|1 ⊗ |𝜓 =
1
2
𝑛
2
𝑘=0
2𝑛−1
𝑒2𝜋𝑖𝜃𝑘|𝑘 ⊗ |𝜓
This looks similar to QFT equation seen earlier. After applying inverse QFT and making measurement,
we will get the output as 2𝑛𝜃 with high probability
We will run QPE with T gate given by
1 0
0 𝑒
𝑖𝜋
4
operating a qubit with state |1 getting T |1 = 𝑒2𝜋𝑖𝜃|𝜓 ,
resulting in 𝜃 = 1/8.
We will use 3 counting Qbits and divide the number that we get after measurement by 23, we will get 𝜃.
https://qiskit.org/
Factoring Problem
 Let us try to factor 15 (N) using Shor’s algorithm
 We will assume ‘a’ as 7 and find out period ‘r’ (74 = 1 mod(15))
 We will find the factors from GCD(𝑥𝑟/2
+ 1, 𝑁) 𝑎𝑛𝑑 GCD(𝑥𝑟/2
− 1, 𝑁)
https://qiskit.org/
Factoring in QC – Current Status
 Till 2012, the largest number that was factored by Shor’s algorithm was 21 with 10
qubits. Now different algorithms are being tried with more qubits.
 A start-up company Zapata has worked with IBM to develop a new way and factored
1,099,551,473,989 to get prime factors 1,048,589 and 1,048,601 (quote from “New
Scientist”)
 To break RSA 2048, we would need thousands of logical qubits, but millions of
physical qubits (quote from “The Quantum Daily”)
 IBM is building a quantum processor with more than 1,000 physical qubits — and
somewhere between 10 and 50 logical qubits — by the end of 2023 (quote from
“Techcrunch”)
References
 Basics & Shor algorithm explained
https://arxiv.org/abs/quant-ph/9508027
https://www.youtube.com/playlist?list=PL74Rel4IAsETUwZS_Se_P-fSEyEVQwni7
https://en.wikipedia.org/wiki/Shor%27s_algorithm
 Different codes
https://qiskit.org/textbook/ch-algorithms/shor.html
https://github.com/quantumlib/Cirq/blob/master/examples/shor.py
 Text Book
Quantum Computation and Quantum Information by Michael A Nielsen and Isaax L. Chuang
What Next?
YOU
• You can start getting into the depth of quantum computing.
• You can go through the references and other videos/ documents and let
me know if I need to bring out a video on any specific topic
I
• I will continue to learn and come out with videos which will be useful for
your learning
THANK YOU