Bibhas Chandra Das, Nilanjan Datta, et al.
PKC 2026
Efficient quantum implementations of SHA-3 are critical for estimating the security of hash-based and post-quantum cryptographic systems against quantum adversaries. We present a resource-efficient reversible realization of the transformation of SHA-3 together with a novel inverse- ancilla-cleaning procedure. Our construction is, to the best of our knowledge, the first clean implementation of requiring only five reusable ancilla qubits while restoring all temporary workspace to . By exploiting the polynomial representation of and organizing cleanup operations into parallel parity networks, we reduce ancilla-uncomputation depth and obtain complete clean circuits with depths between 137 and 225 using 5, 10, or 20 ancillas. Combined with existing implementations, this enables complete SHA-3 round with depths ranging from 147 to 235. In addition, we study the impact of hardware-aware transpilation on SHA-3 and show that circuit structure and hardware connectivity can significantly influence practical implementation costs.
Bibhas Chandra Das, Nilanjan Datta, et al.
PKC 2026
Pierrick Dartois, Luca De Feo
PKC 2022
Andrea Basso, Luciano Maino
Eurocrypt 2025
Jonathan Bootle, Vadim Lyubashevsky, et al.
PKC 2025