Quantum circuit for implementing Camellia S-box with low costs
ZhenQiang Li, Gao Fei, Qin Su-Juan, Wen Qiao-yan · Zhongguo kexue. Wulixue Lixue Tianwenxue · 2023
Camellia, after AES, is one of the most competitive block cipher algorithms. It has been widely used in many fields of information security. Camellia's distinctive nonlinear component is the S-box. This paper studies how to build the quantum circuit of the Camellia S-box at lower costs. First, the multiplicative inversion in F_2^8can be obtained by the multiplicative inversion (and multiplication) in F_2^4via a mapping matrix, and the latter can be implemented by the automation tool LIGHTER-R. The affine transformation of the S-box is then implemented with CNOT and NOT gates using the PLU decomposition and elimination approach. Finally, the Camellia S-box quantum circuit is built with 20 qubits, 54 Toffoli gates, 196 CNOT gates, 13 NOT gates, and a Toffoli depth of 42. In comparison with the previous study, which required 23 qubits, 67 Toffoli, and 38 CNOT gates, and a Toffoli depth of 53, the S-box quantum circuit in this paper requires fewer resources. Furthermore, the S-box quantum circuit used in the study can reduce the quantum resources in implementing Camellia, reducing the quantum circuit scale required to attack Camellia by the Grover algorithm.