Workshop paper

Clean and Resource-Efficient Quantum Circuits for SHA-3

Abstract

Efficient quantum implementations of SHA-3 are critical for estimating the security of hash-based and post-quantum cryptographic systems against quantum adversaries. We present a resource-efficient reversible realization of the θ\theta transformation of SHA-3 together with a novel inverse-θ\theta ancilla-cleaning procedure. Our construction is, to the best of our knowledge, the first clean implementation of θ\theta requiring only five reusable ancilla qubits while restoring all temporary workspace to 0\ket{0}. By exploiting the polynomial representation of θ1\theta^{-1} and organizing cleanup operations into parallel parity networks, we reduce ancilla-uncomputation depth and obtain complete clean θ\theta circuits with depths between 137 and 225 using 5, 10, or 20 ancillas. Combined with existing χ\chi implementations, this enables complete SHA-3 round with depths ranging from 147 to 235. In addition, we study the impact of hardware-aware transpilation on SHA-3 and show that circuit structure and hardware connectivity can significantly influence practical implementation costs.