<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Quantum Computing on kenji.blog</title><link>http://kenji.blog/en/tags/quantum-computing/</link><description>Recent content in Quantum Computing on kenji.blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>kenjinote</copyright><lastBuildDate>Fri, 11 Sep 2026 20:00:00 +0900</lastBuildDate><atom:link href="http://kenji.blog/en/tags/quantum-computing/index.xml" rel="self" type="application/rss+xml"/><item><title>An Ultra-Beginner Guide to Quantum Programming with Qiskit</title><link>http://kenji.blog/en/p/qiskit-quantum-programming-intro/</link><pubDate>Fri, 11 Sep 2026 20:00:00 +0900</pubDate><guid>http://kenji.blog/en/p/qiskit-quantum-programming-intro/</guid><description>&lt;img src="http://kenji.blog/p/qiskit-quantum-programming-intro/img/eyecatch.jpg" alt="Featured image of post An Ultra-Beginner Guide to Quantum Programming with Qiskit" />&lt;h2 id="1-introduction">1. Introduction
&lt;/h2>&lt;p>Modern computers (classical computers) have dramatically changed our lives, supporting every aspect of society with their advanced computational power. However, it is known that for certain specific problems (such as factoring extremely large numbers, simulating complex molecular structures, and optimization problems), even the most cutting-edge supercomputers of today would require a time longer than the age of the universe.&lt;/p>
&lt;p>What holds the potential to break through these &amp;ldquo;limits of classical computers&amp;rdquo; is the &lt;strong>Quantum Computer&lt;/strong>. By utilizing the mysterious properties of quantum mechanics (superposition and quantum entanglement) as computational resources, it is believed that specific problems can be dramatically accelerated.&lt;/p>
&lt;p>In this article, we will take our first steps into the world of quantum programming using &lt;strong>Qiskit&lt;/strong>, an open-source quantum computing framework provided by IBM. This is an extremely detailed introductory guide that carefully explains everything from the basics of physics and mathematics, to actually writing code in Python and running quantum circuits on a simulator.&lt;/p>
&lt;hr>
&lt;h2 id="2-fundamentals-of-physics-and-mathematics-behind-quantum-computing">2. Fundamentals of Physics and Mathematics Behind Quantum Computing
&lt;/h2>&lt;p>To understand quantum programming, you first need to grasp the basic concepts of quantum mechanics. Here, we will explain the three important pillars: qubits, superposition, and quantum entanglement.&lt;/p>
&lt;h3 id="21-classical-bits-and-qubits-quantum-bits">2.1 Classical Bits and Qubits (Quantum Bits)
&lt;/h3>&lt;p>The unit of information in classical computers is the &amp;ldquo;Bit&amp;rdquo;. A bit always takes one of two states: &lt;code>0&lt;/code> or &lt;code>1&lt;/code>.&lt;/p>
&lt;p>On the other hand, the smallest unit of information in a quantum computer is called a &lt;strong>Qubit (Quantum bit)&lt;/strong>. A qubit can not only take the state of &lt;code>0&lt;/code> and &lt;code>1&lt;/code>, but it can also &lt;strong>hold both states simultaneously&lt;/strong>.&lt;/p>
&lt;p>Mathematically, the state of a qubit $|\psi\rangle$ is represented as a linear combination (superposition) of the basis states $|0\rangle$ and $|1\rangle$.&lt;/p>
$$
|\psi\rangle = \alpha|0\rangle + \beta|1\rangle
$$
&lt;p>Here, $\alpha$ and $\beta$ are complex numbers, representing the probability amplitudes of observing the states $|0\rangle$ and $|1\rangle$, respectively. Based on the fundamental principles of quantum mechanics, the sum of probabilities must equal 1, thus satisfying the following normalization condition:&lt;/p>
$$
|\alpha|^2 + |\beta|^2 = 1
$$
&lt;p>In other words, when this qubit is &amp;ldquo;measured (observed)&amp;rdquo;, the probability of getting $|0\rangle$ is $|\alpha|^2$, and the probability of getting $|1\rangle$ is $|\beta|^2$. The decisive difference from classical bits is that the state is only determined probabilistically before measurement.&lt;/p>
&lt;div class="mermaid">graph LR
A["Classical Bit"] --> B["Determined state: 0 or 1"]
C["Qubit"] --> D["Superposition: Both 0 and 1"]
D --> E["State is determined probabilistically by measurement"]&lt;/div>
&lt;h3 id="22-superposition">2.2 Superposition
&lt;/h3>&lt;p>As mentioned earlier, the state where $|0\rangle$ and $|1\rangle$ are mixed together is called &lt;strong>Superposition&lt;/strong>.&lt;/p>
&lt;p>For example, when a single qubit is in a perfectly equal superposition state, $\alpha = \frac{1}{\sqrt{2}}$ and $\beta = \frac{1}{\sqrt{2}}$.&lt;/p>
$$
|\psi\rangle = \frac{1}{\sqrt{2}}|0\rangle + \frac{1}{\sqrt{2}}|1\rangle
$$
&lt;p>When this state is measured, $|0\rangle$ and $|1\rangle$ are observed with a 50% probability each.
If you have 2 qubits, you can create a superposition of 4 states: $|00\rangle, |01\rangle, |10\rangle, |11\rangle$. With $n$ qubits, $2^n$ states can be represented simultaneously, which is one of the sources of the parallel processing power of quantum computers.&lt;/p>
&lt;h3 id="23-quantum-entanglement">2.3 Quantum Entanglement
&lt;/h3>&lt;p>The most powerful and mysterious property in quantum computing is &lt;strong>Quantum Entanglement&lt;/strong>. This phenomenon, which Einstein called &amp;ldquo;spooky action at a distance,&amp;rdquo; is a property where two or more qubits become strongly linked to each other. When the state of one qubit is determined, the state of the other qubit is instantaneously determined, no matter how far apart they are physically.&lt;/p>
&lt;p>One of the most famous quantum entangled states, the &amp;ldquo;Bell State&amp;rdquo;, specifically the $\Phi^+$ state, is expressed as follows:&lt;/p>
$$
|\Phi^+\rangle = \frac{|00\rangle + |11\rangle}{\sqrt{2}}
$$
&lt;p>In this state, the states $|01\rangle$ and $|10\rangle$ do not exist. Therefore, if the first qubit is measured and is $|0\rangle$, the second qubit is guaranteed to be $|0\rangle$ without even needing to be measured. Conversely, if the first is $|1\rangle$, the second will also necessarily be $|1\rangle$.&lt;/p>
&lt;hr>
&lt;h2 id="3-quantum-logic-gates">3. Quantum Logic Gates
&lt;/h2>&lt;p>Just as classical computers perform calculations using logic gates like AND, OR, and NOT, quantum computers also manipulate the state of qubits using &lt;strong>Quantum Gates&lt;/strong>. Since a quantum state is a vector, a quantum gate is represented as a &amp;ldquo;unitary matrix&amp;rdquo; acting on that vector.&lt;/p>
&lt;h3 id="31-pauli-gates-pauli-x-y-z">3.1 Pauli Gates (Pauli-X, Y, Z)
&lt;/h3>&lt;p>Pauli gates are fundamental operations on a single qubit.&lt;/p>
&lt;p>&lt;strong>・Pauli-X Gate (NOT Gate)&lt;/strong>
Equivalent to the classical NOT gate. It flips $|0\rangle$ to $|1\rangle$, and $|1\rangle$ to $|0\rangle$. (A 180-degree rotation around the X-axis on the Bloch sphere)&lt;/p>
$$
X = \begin{pmatrix} 0 &amp; 1 \\ 1 &amp; 0 \end{pmatrix}
$$
&lt;p>&lt;strong>・Pauli-Y Gate&lt;/strong>
Performs a 180-degree rotation around the Y-axis. It has the effect of flipping both the phase and the bit.&lt;/p>
$$
Y = \begin{pmatrix} 0 &amp; -i \\ i &amp; 0 \end{pmatrix}
$$
&lt;p>&lt;strong>・Pauli-Z Gate (Phase Flip Gate)&lt;/strong>
Leaves the state of $|0\rangle$ as is, but flips the phase of the $|1\rangle$ state (multiplies by $-1$). (A 180-degree rotation around the Z-axis)&lt;/p>
$$
Z = \begin{pmatrix} 1 &amp; 0 \\ 0 &amp; -1 \end{pmatrix}
$$
&lt;h3 id="32-hadamard-gate">3.2 Hadamard Gate
&lt;/h3>&lt;p>The Hadamard gate (H gate) is an extremely important gate that transforms a determined state ($|0\rangle$ or $|1\rangle$) into a superposition state.&lt;/p>
$$
H = \frac{1}{\sqrt{2}}
\begin{pmatrix}
1 &amp; 1 \\
1 &amp; -1
\end{pmatrix}
$$
&lt;p>Applying the H gate to $|0\rangle$ results in $|+\rangle$, which is an equal superposition state.&lt;/p>
$$
H|0\rangle = \frac{1}{\sqrt{2}}|0\rangle + \frac{1}{\sqrt{2}}|1\rangle = |+\rangle
$$
&lt;h3 id="33-phase-gates">3.3 Phase Gates
&lt;/h3>&lt;p>Phase gates are a generalization of the Z gate, rotating the phase of the $|1\rangle$ state by a specified angle $\theta$.&lt;/p>
$$
P(\theta) = \begin{pmatrix} 1 &amp; 0 \\ 0 &amp; e^{i\theta} \end{pmatrix}
$$
&lt;p>Typical examples include the S gate ($\theta = \pi/2$) and the T gate ($\theta = \pi/4$).&lt;/p>
&lt;h3 id="34-cnot-gate-controlled-not-gate">3.4 CNOT Gate (Controlled-NOT Gate)
&lt;/h3>&lt;p>The CNOT gate (CX gate) is a gate that performs an operation between two qubits and is essential for generating quantum entanglement. It consists of a &amp;ldquo;Control bit&amp;rdquo; and a &amp;ldquo;Target bit&amp;rdquo;.&lt;/p>
&lt;p>Only when the control bit is $|1\rangle$, an X gate (NOT operation) is applied to the target bit; if the control bit is $|0\rangle$, nothing happens.&lt;/p>
$$
CNOT = \begin{pmatrix}
1 &amp; 0 &amp; 0 &amp; 0 \\
0 &amp; 1 &amp; 0 &amp; 0 \\
0 &amp; 0 &amp; 0 &amp; 1 \\
0 &amp; 0 &amp; 1 &amp; 0
\end{pmatrix}
$$
&lt;hr>
&lt;h2 id="4-basics-of-qiskit-and-environment-setup">4. Basics of Qiskit and Environment Setup
&lt;/h2>&lt;p>From here on, we will actually write quantum programs using Python and Qiskit.&lt;/p>
&lt;h3 id="41-what-is-qiskit">4.1 What is Qiskit?
&lt;/h3>&lt;p>&lt;strong>Qiskit&lt;/strong> is an open-source software development kit (SDK) for quantum computing developed by IBM Quantum. Using Python, you can intuitively build quantum circuits and run them on a local simulator or on actual IBM quantum computers via the cloud.&lt;/p>
&lt;h3 id="42-installation-method">4.2 Installation Method
&lt;/h3>&lt;p>To use Qiskit, a Python environment is required. You can install Qiskit and related packages (simulator and drawing libraries) with the following command:&lt;/p>
&lt;div class="highlight">&lt;div class="chroma">
&lt;table class="lntable">&lt;tr>&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code>&lt;span class="lnt">1
&lt;/span>&lt;/code>&lt;/pre>&lt;/td>
&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code class="language-bash" data-lang="bash">&lt;span class="line">&lt;span class="cl">pip install qiskit qiskit-aer qiskit-ibm-runtime matplotlib pylatexenc
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/td>&lt;/tr>&lt;/table>
&lt;/div>
&lt;/div>&lt;h3 id="43-basic-flow-of-programming">4.3 Basic Flow of Programming
&lt;/h3>&lt;p>Quantum programming using Qiskit mainly progresses through the following steps:&lt;/p>
&lt;div class="mermaid">graph TD
A["1. Build (Construct the circuit)"] --> B["2. Compile (Transpile/Optimize)"]
B --> C["3. Execute (Run on backend)"]
C --> D["4. Analyze (Results analysis and visualization)"]&lt;/div>
&lt;ol>
&lt;li>&lt;strong>Build&lt;/strong>: Create a &lt;code>QuantumCircuit&lt;/code> object and add gates to it.&lt;/li>
&lt;li>&lt;strong>Compile&lt;/strong>: Optimize the circuit for the backend (actual hardware or simulator) to be executed on.&lt;/li>
&lt;li>&lt;strong>Execute&lt;/strong>: Send the job to the backend and retrieve the results.&lt;/li>
&lt;li>&lt;strong>Analyze&lt;/strong>: Plot histograms of the measurement results, etc.&lt;/li>
&lt;/ol>
&lt;hr>
&lt;h2 id="5-practice-building-a-circuit-to-create-a-bell-state-quantum-entanglement">5. Practice: Building a Circuit to Create a Bell State (Quantum Entanglement)
&lt;/h2>&lt;p>Let&amp;rsquo;s actually create the &amp;ldquo;Quantum Entanglement (Bell State)&amp;rdquo; we learned in theory using Qiskit. The target state is $|\Phi^+\rangle = \frac{|00\rangle + |11\rangle}{\sqrt{2}}$.&lt;/p>
&lt;h3 id="51-circuit-design">5.1 Circuit Design
&lt;/h3>&lt;p>To create a Bell state, we follow these steps:&lt;/p>
&lt;ol>
&lt;li>Prepare two qubits (both initially in the $|0\rangle$ state).&lt;/li>
&lt;li>Apply a Hadamard gate (H) to the first qubit to create a superposition state.&lt;/li>
&lt;li>Apply a CNOT gate with the first qubit as the &amp;ldquo;Control bit&amp;rdquo; and the second qubit as the &amp;ldquo;Target bit&amp;rdquo;.&lt;/li>
&lt;li>Perform a Measurement to read the result.&lt;/li>
&lt;/ol>
&lt;h3 id="52-pythonqiskit-code-implementation">5.2 Python/Qiskit Code Implementation
&lt;/h3>&lt;p>Now, let&amp;rsquo;s look at the actual code.&lt;/p>
&lt;div class="highlight">&lt;div class="chroma">
&lt;table class="lntable">&lt;tr>&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code>&lt;span class="lnt"> 1
&lt;/span>&lt;span class="lnt"> 2
&lt;/span>&lt;span class="lnt"> 3
&lt;/span>&lt;span class="lnt"> 4
&lt;/span>&lt;span class="lnt"> 5
&lt;/span>&lt;span class="lnt"> 6
&lt;/span>&lt;span class="lnt"> 7
&lt;/span>&lt;span class="lnt"> 8
&lt;/span>&lt;span class="lnt"> 9
&lt;/span>&lt;span class="lnt">10
&lt;/span>&lt;span class="lnt">11
&lt;/span>&lt;span class="lnt">12
&lt;/span>&lt;span class="lnt">13
&lt;/span>&lt;span class="lnt">14
&lt;/span>&lt;span class="lnt">15
&lt;/span>&lt;span class="lnt">16
&lt;/span>&lt;span class="lnt">17
&lt;/span>&lt;span class="lnt">18
&lt;/span>&lt;span class="lnt">19
&lt;/span>&lt;span class="lnt">20
&lt;/span>&lt;span class="lnt">21
&lt;/span>&lt;span class="lnt">22
&lt;/span>&lt;span class="lnt">23
&lt;/span>&lt;span class="lnt">24
&lt;/span>&lt;span class="lnt">25
&lt;/span>&lt;/code>&lt;/pre>&lt;/td>
&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code class="language-python" data-lang="python">&lt;span class="line">&lt;span class="cl">&lt;span class="kn">import&lt;/span> &lt;span class="nn">numpy&lt;/span> &lt;span class="k">as&lt;/span> &lt;span class="nn">np&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="kn">from&lt;/span> &lt;span class="nn">qiskit&lt;/span> &lt;span class="kn">import&lt;/span> &lt;span class="n">QuantumCircuit&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="n">transpile&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="kn">from&lt;/span> &lt;span class="nn">qiskit_aer&lt;/span> &lt;span class="kn">import&lt;/span> &lt;span class="n">Aer&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="kn">from&lt;/span> &lt;span class="nn">qiskit.visualization&lt;/span> &lt;span class="kn">import&lt;/span> &lt;span class="n">plot_histogram&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="kn">import&lt;/span> &lt;span class="nn">matplotlib.pyplot&lt;/span> &lt;span class="k">as&lt;/span> &lt;span class="nn">plt&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># 1. Circuit Initialization&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Create a quantum circuit with 2 qubits and 2 classical bits&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="n">qc&lt;/span> &lt;span class="o">=&lt;/span> &lt;span class="n">QuantumCircuit&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mi">2&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="mi">2&lt;/span>&lt;span class="p">)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># 2. Applying the H Gate&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Apply a Hadamard gate to qubit 0 (q0)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="n">qc&lt;/span>&lt;span class="o">.&lt;/span>&lt;span class="n">h&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mi">0&lt;/span>&lt;span class="p">)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># 3. Applying the CNOT Gate&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Apply CNOT using q0 as the control bit and q1 as the target bit&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="n">qc&lt;/span>&lt;span class="o">.&lt;/span>&lt;span class="n">cx&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mi">0&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="mi">1&lt;/span>&lt;span class="p">)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># 4. Measurement&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Measure qubits 0 and 1, and write the results to classical bits 0 and 1, respectively&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="n">qc&lt;/span>&lt;span class="o">.&lt;/span>&lt;span class="n">measure&lt;/span>&lt;span class="p">([&lt;/span>&lt;span class="mi">0&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="mi">1&lt;/span>&lt;span class="p">],&lt;/span> &lt;span class="p">[&lt;/span>&lt;span class="mi">0&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="mi">1&lt;/span>&lt;span class="p">])&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Draw the circuit diagram (using matplotlib)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># qc.draw(&amp;#39;mpl&amp;#39;)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="nb">print&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="n">qc&lt;/span>&lt;span class="o">.&lt;/span>&lt;span class="n">draw&lt;/span>&lt;span class="p">())&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/td>&lt;/tr>&lt;/table>
&lt;/div>
&lt;/div>&lt;p>When you execute this code, the following quantum circuit diagram will be displayed as ASCII art on the console.&lt;/p>
&lt;div class="highlight">&lt;div class="chroma">
&lt;table class="lntable">&lt;tr>&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code>&lt;span class="lnt">1
&lt;/span>&lt;span class="lnt">2
&lt;/span>&lt;span class="lnt">3
&lt;/span>&lt;span class="lnt">4
&lt;/span>&lt;span class="lnt">5
&lt;/span>&lt;span class="lnt">6
&lt;/span>&lt;span class="lnt">7
&lt;/span>&lt;/code>&lt;/pre>&lt;/td>
&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code class="language-text" data-lang="text">&lt;span class="line">&lt;span class="cl"> ┌───┐ ┌─┐
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">q_0: ┤ H ├──■──┤M├───
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> └───┘┌─┴─┐└╥┘┌─┐
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">q_1: ─────┤ X ├─╫─┤M├
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> └───┘ ║ └╥┘
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">c: 2/═══════════╩══╩═
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> 0 1
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/td>&lt;/tr>&lt;/table>
&lt;/div>
&lt;/div>&lt;p>&lt;code>H&lt;/code> represents the Hadamard gate, the combination of &lt;code>■&lt;/code> and &lt;code>X&lt;/code> is the CNOT gate, and &lt;code>M&lt;/code> represents measurement.&lt;/p>
&lt;h3 id="53-execution-on-simulator-and-interpretation-of-results">5.3 Execution on Simulator and Interpretation of Results
&lt;/h3>&lt;p>Next, we will run this circuit on IBM&amp;rsquo;s high-performance simulator &lt;code>Aer&lt;/code> and check the results.&lt;/p>
&lt;div class="highlight">&lt;div class="chroma">
&lt;table class="lntable">&lt;tr>&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code>&lt;span class="lnt"> 1
&lt;/span>&lt;span class="lnt"> 2
&lt;/span>&lt;span class="lnt"> 3
&lt;/span>&lt;span class="lnt"> 4
&lt;/span>&lt;span class="lnt"> 5
&lt;/span>&lt;span class="lnt"> 6
&lt;/span>&lt;span class="lnt"> 7
&lt;/span>&lt;span class="lnt"> 8
&lt;/span>&lt;span class="lnt"> 9
&lt;/span>&lt;span class="lnt">10
&lt;/span>&lt;span class="lnt">11
&lt;/span>&lt;span class="lnt">12
&lt;/span>&lt;span class="lnt">13
&lt;/span>&lt;span class="lnt">14
&lt;/span>&lt;span class="lnt">15
&lt;/span>&lt;span class="lnt">16
&lt;/span>&lt;span class="lnt">17
&lt;/span>&lt;span class="lnt">18
&lt;/span>&lt;span class="lnt">19
&lt;/span>&lt;/code>&lt;/pre>&lt;/td>
&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code class="language-python" data-lang="python">&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Get the Aer simulator backend&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="n">simulator&lt;/span> &lt;span class="o">=&lt;/span> &lt;span class="n">Aer&lt;/span>&lt;span class="o">.&lt;/span>&lt;span class="n">get_backend&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="s1">&amp;#39;qasm_simulator&amp;#39;&lt;/span>&lt;span class="p">)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Transpile (optimize) the circuit for the simulator&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="n">compiled_circuit&lt;/span> &lt;span class="o">=&lt;/span> &lt;span class="n">transpile&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="n">qc&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="n">simulator&lt;/span>&lt;span class="p">)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Execute the circuit (here, running 1000 shots)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="n">job&lt;/span> &lt;span class="o">=&lt;/span> &lt;span class="n">simulator&lt;/span>&lt;span class="o">.&lt;/span>&lt;span class="n">run&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="n">compiled_circuit&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="n">shots&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="mi">1000&lt;/span>&lt;span class="p">)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Retrieve the result&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="n">result&lt;/span> &lt;span class="o">=&lt;/span> &lt;span class="n">job&lt;/span>&lt;span class="o">.&lt;/span>&lt;span class="n">result&lt;/span>&lt;span class="p">()&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Get the observation counts for the states&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="n">counts&lt;/span> &lt;span class="o">=&lt;/span> &lt;span class="n">result&lt;/span>&lt;span class="o">.&lt;/span>&lt;span class="n">get_counts&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="n">compiled_circuit&lt;/span>&lt;span class="p">)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="nb">print&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="s2">&amp;#34;&lt;/span>&lt;span class="se">\n&lt;/span>&lt;span class="s2">Measurement results:&amp;#34;&lt;/span>&lt;span class="p">,&lt;/span> &lt;span class="n">counts&lt;/span>&lt;span class="p">)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># Plotting the histogram&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># plot_histogram(counts)&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="c1"># plt.show()&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/td>&lt;/tr>&lt;/table>
&lt;/div>
&lt;/div>&lt;p>&lt;strong>Interpretation of Results&lt;/strong>&lt;/p>
&lt;p>The console output should look something like this:
&lt;code>Measurement results: {'00': 495, '11': 505}&lt;/code>
(*Note: Because probabilities are random, the numbers will fluctuate slightly with each execution.)&lt;/p>
&lt;p>In an ideal simulation environment, the measurement results will show &lt;code>00&lt;/code> and &lt;code>11&lt;/code> observed roughly 50% of the time each, with &lt;code>01&lt;/code> and &lt;code>10&lt;/code> never being observed.
This completely matches the theoretical prediction of the Bell state $|\Phi^+\rangle = \frac{|00\rangle + |11\rangle}{\sqrt{2}}$ that we created. It accurately simulates &amp;ldquo;quantum entanglement&amp;rdquo; where if the first qubit is 0, the second is always 0, and if the first is 1, the second is always 1.&lt;/p>
&lt;p>Furthermore, when executed on an actual quantum computer (IBM Quantum Hardware), &lt;code>01&lt;/code> and &lt;code>10&lt;/code> might be observed slightly due to the influence of noise (quantum decoherence and gate errors). How to reduce this noise (quantum error correction) is one of the biggest challenges in current quantum computer development.&lt;/p>
&lt;hr>
&lt;h2 id="6-scaling-up-to-more-advanced-algorithms">6. Scaling Up to More Advanced Algorithms
&lt;/h2>&lt;p>Creating a Bell state can be considered the &amp;ldquo;Hello World&amp;rdquo; of quantum programming. By expanding upon this, we can construct powerful algorithms that surpass classical computers.&lt;/p>
&lt;h3 id="61-deutsch-jozsa-algorithm">6.1 Deutsch-Jozsa Algorithm
&lt;/h3>&lt;p>This is a problem to determine whether a given function $f(x)$ is a &amp;ldquo;constant function&amp;rdquo; (always outputs 0 or always outputs 1 regardless of input) or a &amp;ldquo;balanced function&amp;rdquo; (outputs 0 for half of the inputs and 1 for the other half).
While a classical computer requires at worst $2^{n-1} + 1$ evaluations of the function, the Deutsch-Jozsa algorithm can determine it with &lt;strong>just 1 evaluation&lt;/strong> by utilizing quantum parallelism. This demonstrates the basic pattern of quantum algorithms: inputting a superposition state, using interference to cancel out unnecessary states, and amplifying the desired answer.&lt;/p>
&lt;h3 id="62-grovers-algorithm">6.2 Grover&amp;rsquo;s Algorithm
&lt;/h3>&lt;p>In the search problem of finding specific data from $N$ unsorted database elements, a classical algorithm requires an average of $N/2$ computations, whereas Grover&amp;rsquo;s algorithm can find the target data in $\sqrt{N}$ computations.
This algorithm uses a black box called an &amp;ldquo;Oracle&amp;rdquo; to flip the phase of the target solution, and further applies &amp;ldquo;Amplitude Amplification&amp;rdquo; to dramatically increase the probability of observing the target solution.&lt;/p>
&lt;div class="mermaid">graph TD
A["Initialization (Superposition of all states)"] --> B["Oracle (Flip phase of the correct answer)"]
B --> C["Diffusion Operator (Amplitude amplification by inversion about the mean)"]
C --> D{"Reached sufficient probability?"}
D -- "No" --> B
D -- "Yes" --> E["Measurement"]&lt;/div>
&lt;hr>
&lt;h2 id="7-conclusion-and-future-learning">7. Conclusion and Future Learning
&lt;/h2>&lt;p>In this article, we started with fundamental concepts of quantum computing such as superposition and quantum entanglement, and explained in detail the manipulation of quantum logic gates using Qiskit, up to actually constructing and simulating a Bell state and interpreting the results.&lt;/p>
&lt;p>Because Qiskit allows you to write in a familiar language like Python, it is a powerful tool that helps you focus on algorithm construction by overcoming mathematical and physical barriers. Although quantum computers are currently in the era of Noisy Intermediate-Scale Quantum (NISQ) devices, applied research is rapidly advancing worldwide in numerous fields such as Quantum Machine Learning, Quantum Chemistry simulations, and cryptography.&lt;/p>
&lt;p>By all means, take this opportunity to create various quantum circuits using Qiskit and try running them on actual IBM Quantum processors. You should be able to experience the computing paradigm of the future firsthand.&lt;/p>
&lt;h3 id="references">References
&lt;/h3>&lt;ul>
&lt;li>&lt;a class="link" href="https://qiskit.org/documentation/" target="_blank" rel="noopener"
>Qiskit Official Documentation&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://qiskit.org/textbook/ja/preface.html" target="_blank" rel="noopener"
>Qiskit Textbook&lt;/a> - An official textbook recommended for those who want to learn deeper mathematical backgrounds and algorithms&lt;/li>
&lt;li>IBM Quantum Learning&lt;/li>
&lt;/ul>
&lt;p>Welcome to the quantum world!&lt;/p></description></item><item><title>What is Quantum Supremacy? Latest Trends from Google and IBM</title><link>http://kenji.blog/en/p/what-is-quantum-supremacy-google-ibm/</link><pubDate>Fri, 11 Sep 2026 18:00:00 +0900</pubDate><guid>http://kenji.blog/en/p/what-is-quantum-supremacy-google-ibm/</guid><description>&lt;img src="http://kenji.blog/p/what-is-quantum-supremacy-google-ibm/img/eyecatch.jpg" alt="Featured image of post What is Quantum Supremacy? Latest Trends from Google and IBM" />&lt;h2 id="1-introduction-the-dawn-of-quantum-computing-and-quantum-supremacy">1. Introduction: The Dawn of Quantum Computing and &amp;ldquo;Quantum Supremacy&amp;rdquo;
&lt;/h2>&lt;p>Quantum computing has the potential to solve complex problems that cannot be solved within a realistic timeframe by classical computers (the PCs and supercomputers we use daily) by applying quantum mechanics, the fundamental principle of physics, to information processing. For a long time, this field was primarily focused on theoretical research, but in recent years, rapid hardware advancements have intensified the race toward practical application.&lt;/p>
&lt;p>One of the most attention-grabbing keywords in this context is &amp;ldquo;Quantum Supremacy.&amp;rdquo; This refers to the moment when a quantum computer demonstrates overwhelming computational power over classical computers in a specific computational task. In this article, starting from the strict definition of quantum supremacy, we will provide a detailed technical and mathematical deep dive into the 2019 experiment by Google&amp;rsquo;s &amp;ldquo;Sycamore&amp;rdquo; processor—which was announced as the first in the world to reach this milestone—as well as IBM&amp;rsquo;s rebuttal and unique approach, and the latest roadmap towards &amp;ldquo;Quantum Error Correction (QEC)&amp;rdquo; and &amp;ldquo;Fault-Tolerant Quantum Computing (FTQC),&amp;rdquo; which represent the biggest barriers to true practical application.&lt;/p>
&lt;hr>
&lt;h2 id="2-theoretical-background-fundamentals-of-quantum-computing-and-complexity-classes">2. Theoretical Background: Fundamentals of Quantum Computing and Complexity Classes
&lt;/h2>&lt;p>To understand quantum supremacy, it is first necessary to understand the mathematical foundations of quantum computing and its position in computational complexity theory.&lt;/p>
&lt;h3 id="qubits-and-superposition">Qubits and Superposition
&lt;/h3>&lt;p>While the smallest unit of information in a classical computer is a bit (0 or 1), a quantum computer uses a qubit (Quantum bit). The state $|\psi\rangle$ of a single qubit is represented by a complex linear combination of the basis states $|0\rangle$ and $|1\rangle$.&lt;/p>
$$
|\psi\rangle = \alpha|0\rangle + \beta|1\rangle
$$
&lt;p>Here, $\alpha, \beta \in \mathbb{C}$, and they satisfy the normalization condition $|\alpha|^2 + |\beta|^2 = 1$. This property is called &amp;ldquo;Superposition.&amp;rdquo;&lt;/p>
&lt;h3 id="entanglement-and-tensor-product">Entanglement and Tensor Product
&lt;/h3>&lt;p>When there are multiple qubits, the state of the entire system is represented by the tensor product of the state spaces of the individual qubits. A system of $n$ qubits becomes a vector on a $2^n$-dimensional Hilbert space $\mathcal{H}^{\otimes n}$.&lt;/p>
$$
|\Psi\rangle = \sum_{x \in \{0, 1\}^n} c_x |x\rangle
$$
&lt;p>Here, $\sum |c_x|^2 = 1$. A state where qubits are not independent, and the state of one depends on the other, is called &amp;ldquo;Quantum Entanglement.&amp;rdquo; This gives quantum computers the potential to simultaneously process an exponentially vast state space.&lt;/p>
&lt;h3 id="computational-complexity-theory-definition-of-quantum-supremacy">Computational Complexity Theory Definition of Quantum Supremacy
&lt;/h3>&lt;p>In computational complexity theory, the class of problems that classical computers can solve efficiently (in polynomial time) is called &lt;strong>BPP&lt;/strong> (Bounded-error Probabilistic Polynomial time). On the other hand, the class of problems that quantum computers can solve efficiently is &lt;strong>BQP&lt;/strong> (Bounded-error Quantum Polynomial time).&lt;/p>
&lt;p>Demonstrating quantum supremacy means &amp;ldquo;executing a specific task on actual quantum hardware that is included in BQP but not in BPP (or is extremely likely not to be), and surpassing simulation by classical supercomputers in terms of time and resources.&amp;rdquo; It can be considered a historical attempt to falsify the extended Church-Turing thesis (&amp;ldquo;Any physically realizable computational model can be simulated by a probabilistic Turing machine in polynomial time&amp;rdquo;) through physical experiment.&lt;/p>
&lt;hr>
&lt;h2 id="3-2019-googles-demonstration-of-quantum-supremacy">3. 2019: Google&amp;rsquo;s Demonstration of Quantum Supremacy
&lt;/h2>&lt;p>In October 2019, the Google Quantum AI team announced in the scientific journal &lt;em>Nature&lt;/em> that they had achieved quantum supremacy using a 53-qubit superconducting processor called &amp;ldquo;Sycamore.&amp;rdquo;&lt;/p>
&lt;h3 id="architecture-of-the-sycamore-processor">Architecture of the Sycamore Processor
&lt;/h3>&lt;p>The Sycamore processor consists of 54 transmon superconducting qubits arranged in a 2D grid (53 were used in the experiment as one was malfunctioning). Tunable couplers are placed between adjacent qubits, realizing fast and highly accurate two-qubit gates (a hybrid of iSWAP and controlled-Z gates).&lt;/p>
&lt;div class="mermaid">graph TD
A["Quantum Algorithm Input"] --> B["Sycamore Processor (53 Qubits)"]
B --> C["Apply Random Quantum Gates"]
C --> D["Measure Quantum States (Bitstrings)"]
D --> E["Cross-Entropy Benchmarking (XEB)"]
E --> F["Verify Quantum Supremacy"]&lt;/div>
&lt;h3 id="random-circuit-sampling-rcs">Random Circuit Sampling (RCS)
&lt;/h3>&lt;p>The task Google chose was &amp;ldquo;Random Circuit Sampling.&amp;rdquo; This involves applying randomly chosen single-qubit gates and two-qubit gates over multiple cycles (depth $m$), and sampling from the probability distribution of bitstrings obtained by measuring the final state.&lt;/p>
&lt;p>The probability of a bitstring $x$ output from an ideal (noise-free) random quantum circuit is not a uniform distribution, but exhibits an interference fringe-like pattern called a Porter-Thomas distribution. To sample from this distribution on a classical computer requires simulating the entire state vector, and the computational complexity increases exponentially with respect to the number of qubits $n$ and the circuit depth $m$.&lt;/p>
&lt;h3 id="evaluating-fidelity-linear-cross-entropy-benchmarking-xeb">Evaluating Fidelity: Linear Cross-Entropy Benchmarking (XEB)
&lt;/h3>&lt;p>To prove that the experimental results were not just noise, but the results of actual quantum computation, Google used Linear Cross-Entropy Benchmarking (XEB). The ideal probability $P(x_i)$ of the circuit for the bitstring $x_i$ obtained in the experiment is calculated using a classical computer, and the fidelity $\mathcal{F}_{\text{XEB}}$ is obtained by the following formula:&lt;/p>
$$
\mathcal{F}_{\text{XEB}} = 2^n \langle P(x_i) \rangle_{i} - 1
$$
&lt;p>If $\mathcal{F}_{\text{XEB}}$ is 0, it means complete noise, and if it is 1, it means an ideal quantum processor without noise. The Sycamore processor achieved $\mathcal{F}_{\text{XEB}} \approx 0.002$ (0.2%) for a circuit with depth 20. At first glance, this seems low, but it is a statistically significant value above zero, representing an astonishing achievement of controlling a state space of $2^{53} \approx 9 \times 10^{15}$.&lt;/p>
&lt;p>The overall error rate was approximately modeled as the product of individual gate errors, measurement errors, etc.&lt;/p>
$$
\mathcal{F} \approx (1 - e_1)^{N_1}(1 - e_2)^{N_2} \cdots \approx \prod_{g \in 1Q} (1 - e_g) \prod_{g \in 2Q} (1 - e_g) \prod_{q} (1 - e_{RO})
$$
&lt;p>(* $e_g$ is the gate error, $e_{RO}$ is the measurement error)&lt;/p>
&lt;p>Google claimed that it would take a classical supercomputer (Summit) about 10,000 years to simulate this circuit. In contrast, Sycamore completed the sampling in just 200 seconds.&lt;/p>
&lt;hr>
&lt;h2 id="4-ibms-rebuttal-from-supremacy-to-utility">4. IBM&amp;rsquo;s Rebuttal: From &amp;ldquo;Supremacy&amp;rdquo; to &amp;ldquo;Utility&amp;rdquo;
&lt;/h2>&lt;p>Google&amp;rsquo;s announcement shocked the world, but IBM, which developed the world&amp;rsquo;s largest supercomputer &amp;ldquo;Summit&amp;rdquo; and is itself a leader in quantum computer development, immediately published a paper rebutting this claim.&lt;/p>
&lt;h3 id="improving-classical-simulation-via-tensor-network-contraction">Improving Classical Simulation via Tensor Network Contraction
&lt;/h3>&lt;p>The core of IBM&amp;rsquo;s rebuttal was that &amp;ldquo;the optimization of algorithms and resources on the classical computer side was insufficient.&amp;rdquo; Google assumed a state vector simulator that directly calculates the time evolution of the Schrödinger equation and came up with the 10,000-year estimate. However, IBM pointed out that the simulation time could be dramatically reduced by using a method called a &amp;ldquo;Tensor Network.&amp;rdquo;&lt;/p>
&lt;p>In a tensor network, the gate operations of a quantum circuit are represented as operations on multi-dimensional arrays (tensors), and the order of network &amp;ldquo;contraction&amp;rdquo; is optimized. Furthermore, they claimed that by fully utilizing Summit&amp;rsquo;s massive 250 PB of storage (hierarchical disk and memory), a higher-precision simulation would be possible in just &amp;ldquo;2.5 days&amp;rdquo; while maintaining the entire state vector.&lt;/p>
&lt;h3 id="quantum-advantage-and-quantum-utility">Quantum Advantage and Quantum Utility
&lt;/h3>&lt;p>Triggered by this debate, the trend in the entire industry shifted from merely adhering to &amp;ldquo;executing artificial tasks impossible for classical computers (Supremacy)&amp;rdquo; to a phase of &amp;ldquo;demonstrating a practical advantage over classical approaches in useful real-world problems (Quantum Advantage),&amp;rdquo; and further to &amp;ldquo;quantum computers functioning as new tools for scientific discovery (Quantum Utility).&amp;rdquo;&lt;/p>
&lt;p>IBM itself avoided the word &amp;ldquo;Supremacy&amp;rdquo; and advocated &amp;ldquo;Quantum Volume&amp;rdquo; and &amp;ldquo;CLOPS (Circuit Layer Operations Per Second)&amp;rdquo; as comprehensive performance metrics for quantum processors, promoting development that emphasizes a balance between hardware scale and quality.&lt;/p>
&lt;div class="mermaid">timeline
title "The Evolution of Quantum Milestones"
2019 : "Google Sycamore (53Q)" : "Quantum Supremacy announcement"
2019 : "IBM Rebuttal" : "Summit supercomputer simulation in 2.5 days"
2021 : "IBM Eagle (127Q)" : "Breaking the 100-qubit barrier"
2022 : "IBM Osprey (433Q)" : "Advancing processor scale"
2023 : "Google Surface Code" : "Scaling error correction (d=3 to d=5)"
2023 : "IBM Quantum Utility" : "Complex spin model simulation on 127Q"
2024 : "Beyond" : "Logical Qubits and Error Mitigation era"&lt;/div>
&lt;hr>
&lt;h2 id="5-the-next-frontier-error-mitigation-and-quantum-error-correction-qec">5. The Next Frontier: Error Mitigation and Quantum Error Correction (QEC)
&lt;/h2>&lt;p>Current quantum computers are called &amp;ldquo;NISQ (Noisy Intermediate-Scale Quantum),&amp;rdquo; and they are susceptible to noise (errors due to interactions with the external environment or imperfect control). When performing long computations, the results get buried in noise. There are broadly two approaches to overcoming this problem: &amp;ldquo;Error Mitigation&amp;rdquo; and &amp;ldquo;Quantum Error Correction.&amp;rdquo;&lt;/p>
&lt;h3 id="error-mitigation">Error Mitigation
&lt;/h3>&lt;p>Error mitigation is a method to remove the effects of noise from the expected values of calculation results through classical post-processing without changing the quantum hardware. In 2023, IBM achieved a precision that surpassed state-of-the-art approximate tensor network methods in a time evolution simulation of a complex Ising model by combining its 127-qubit &amp;ldquo;Eagle&amp;rdquo; processor with error mitigation techniques such as &amp;ldquo;Zero-Noise Extrapolation (ZNE),&amp;rdquo; thereby demonstrating &amp;ldquo;Quantum Utility.&amp;rdquo;&lt;/p>
&lt;h3 id="quantum-error-correction-qec-and-logical-qubits">Quantum Error Correction (QEC) and Logical Qubits
&lt;/h3>&lt;p>However, to ultimately run any arbitrary complex algorithm (e.g., Shor&amp;rsquo;s factoring algorithm or complex quantum chemistry calculations), error mitigation alone is insufficient, and &amp;ldquo;Quantum Error Correction (QEC),&amp;rdquo; which dynamically detects and corrects errors, is essential.&lt;/p>
&lt;p>The mainstream approach for QEC is the &amp;ldquo;Surface Code.&amp;rdquo; This is a method where multiple physical qubits (data qubits) are arranged in a 2D grid, and measurement qubits (ancilla qubits) are placed between them to continuously perform parity checks called &amp;ldquo;Stabilizers.&amp;rdquo;&lt;/p>
&lt;div class="mermaid">graph LR
Q1["Data Qubit (Data)"] --- M1["Measure X Stabilizer (Ancilla)"]
Q2["Data Qubit (Data)"] --- M1
Q3["Data Qubit (Data)"] --- M2["Measure Z Stabilizer (Ancilla)"]
Q4["Data Qubit (Data)"] --- M2
M1 --> EC["Error Syndrome Decoding (Classical)"]
M2 --> EC
EC --> LQ["Logical Qubit State Update"]&lt;/div>
&lt;h4 id="the-threshold-theorem-and-distance-d">The Threshold Theorem and Distance $d$
&lt;/h4>&lt;p>A &amp;ldquo;Threshold Theorem&amp;rdquo; exists in quantum error correction. When the error rate $p$ of physical qubits is below a certain threshold $p_{th}$ (around 1% for the surface code), increasing the code distance $d$ (allocating more physical qubits to a single logical qubit) can exponentially reduce the logical error rate $p_L$.&lt;/p>
&lt;p>The approximate formula for the logical error rate is expressed as follows:&lt;/p>
$$
p_L \approx \Lambda \left( \frac{p}{p_{th}} \right)^{\frac{d+1}{2}}
$$
&lt;p>Here, $\Lambda$ is a constant. If $p &lt; p_{th}$, increasing $d$ makes $p_L$ smaller. However, if $p > p_{th}$, increasing physical qubits conversely accumulates noise, worsening the logical error rate.&lt;/p>
&lt;h4 id="googles-2023-milestone-demonstrating-error-reduction-by-scaling-distance">Google&amp;rsquo;s 2023 Milestone: Demonstrating Error Reduction by Scaling Distance
&lt;/h4>&lt;p>In February 2023, Google published a monumental paper in &lt;em>Nature&lt;/em>. They became the first in the world to demonstrate that when expanding the distance of the surface code from $d=3$ (using 17 physical qubits) to $d=5$ (using 49 physical qubits) using their 3rd generation Sycamore processor, the logical error rate slightly decreased from 3.028% to 2.914%.&lt;/p>
&lt;p>This means they have stepped into the region where $p &lt; p_{th}$, showing that the most important Proof of Concept towards FTQC—where performance improves as more physical qubits are added—has been completed.&lt;/p>
&lt;hr>
&lt;h2 id="6-roadmap-and-prospects-for-ftqc-fault-tolerant-quantum-computing">6. Roadmap and Prospects for FTQC (Fault-Tolerant Quantum Computing)
&lt;/h2>&lt;p>While adopting different architectures and approaches, Google and IBM are engaged in fierce development competition towards the ultimate goal of FTQC (Fault-Tolerant Quantum Computing).&lt;/p>
&lt;h3 id="ibms-approach-modularization-and-heavy-hex-lattices">IBM&amp;rsquo;s Approach: Modularization and Heavy-Hex Lattices
&lt;/h3>&lt;p>IBM is focusing on scaling up processors in parallel with drastically reducing error rates. While challenging the limits of single chips with &amp;ldquo;Eagle (127Q),&amp;rdquo; &amp;ldquo;Osprey (433Q),&amp;rdquo; and &amp;ldquo;Condor (1121Q),&amp;rdquo; they announced a modular architecture called &amp;ldquo;Quantum System Two.&amp;rdquo; In addition, for the qubit coupling topology, they have adopted a &amp;ldquo;Heavy-Hex lattice&amp;rdquo; that reduces unnecessary crosstalk and increases stability. IBM&amp;rsquo;s strategy is a hybrid approach that gradually introduces QEC while pursuing utility through advanced error mitigation in the short term.&lt;/p>
&lt;h3 id="googles-approach-improving-logical-qubit-quality">Google&amp;rsquo;s Approach: Improving Logical Qubit Quality
&lt;/h3>&lt;p>Google&amp;rsquo;s strategy places greater emphasis on extremely lowering the error rate of a single logical qubit (e.g., down to $10^{-6}$) rather than rapidly increasing the number of physical qubits. Upon achieving this, they aim for a large-scale system that runs thousands to tens of thousands of physical qubits in parallel by establishing technologies for transferring quantum states between modules (Quantum Interconnects).&lt;/p>
&lt;p>Implementing protocols to fault-tolerantly execute non-Clifford gates, such as Magic State Distillation, will also be a major technical hurdle in the future. To run a practical Shor&amp;rsquo;s algorithm and crack a 2048-bit RSA cipher, it is said that thousands of logical qubits with an error rate of $10^{-8}$ or less are required, equating to millions to tens of millions of physical qubits, meaning the journey is still long.&lt;/p>
&lt;hr>
&lt;h2 id="7-conclusion">7. Conclusion
&lt;/h2>&lt;p>&amp;ldquo;Quantum Supremacy&amp;rdquo; was an important milestone in the history of quantum computers that physically proved the theoretical potential of computing machines. Google&amp;rsquo;s 2019 demonstration and IBM&amp;rsquo;s constructive rebuttal pushed the entire industry from mere theoretical proof into an era of genuine engineering towards the pursuit of actual Utility and, ultimately, Fault-Tolerant Quantum Computing (FTQC).&lt;/p>
&lt;p>Currently, we are witnessing a transitional phase from noisy NISQ devices to logical qubit devices equipped with error correction. In the next five to ten years, new discoveries in materials science, revolutions in the drug discovery process, and breakthroughs in optimization problems will likely become a reality alongside the evolution of this quantum hardware.&lt;/p>
&lt;p>We must keep a close eye on the movements of Google, IBM, and researchers worldwide who are shaping the future of computer science.&lt;/p></description></item><item><title>How Will Blockchain and Cryptocurrencies Change in the Post-Quantum Era?</title><link>http://kenji.blog/en/p/post-quantum-blockchain-and-crypto/</link><pubDate>Fri, 11 Sep 2026 17:00:00 +0900</pubDate><guid>http://kenji.blog/en/p/post-quantum-blockchain-and-crypto/</guid><description>&lt;img src="http://kenji.blog/p/post-quantum-blockchain-and-crypto/img/eyecatch.jpg" alt="Featured image of post How Will Blockchain and Cryptocurrencies Change in the Post-Quantum Era?" />&lt;h2 id="1-introduction-the-footsteps-of-the-post-quantum-era-and-the-crisis-of-blockchain">1. Introduction: The Footsteps of the Post-Quantum Era and the Crisis of Blockchain
&lt;/h2>&lt;p>Since the birth of Bitcoin by Satoshi Nakamoto in 2009, blockchain technology has grown to become the foundation of financial systems and applications worldwide as a &amp;ldquo;decentralized and tamper-proof ledger.&amp;rdquo; This robust security is supported by modern cryptographic technologies: &lt;strong>Public Key Cryptography&lt;/strong> and &lt;strong>Cryptographic Hash Functions&lt;/strong>.&lt;/p>
&lt;p>These cryptographic technologies guarantee security based on the mathematical &amp;ldquo;computational difficulty&amp;rdquo; that classical computers (the PCs and supercomputers we currently use) cannot decipher even if they took time equivalent to the lifespan of the universe.&lt;/p>
&lt;p>However, this premise is about to be fundamentally overturned by the rapid development and practical application of &lt;strong>Quantum Computers&lt;/strong>, the frontier of physics and information science. Quantum computers, which utilize quantum mechanics specifics such as &amp;ldquo;Superposition&amp;rdquo; and &amp;ldquo;Entanglement,&amp;rdquo; demonstrate computational power that overwhelms conventional classical computers in specific mathematical problems, a phenomenon known as &amp;ldquo;Quantum Supremacy.&amp;rdquo;&lt;/p>
&lt;p>In this article, we will thoroughly and deeply delve into what specific threats blockchain technology faces from quantum computers, the latest trends in &lt;strong>Post-Quantum Cryptography (PQC)&lt;/strong> that serve as a solution, and the transition scenarios for crypto asset networks from a technical and mathematical perspective.&lt;/p>
&lt;hr>
&lt;h2 id="2-basics-of-quantum-computers-and-two-major-threats-to-blockchain">2. Basics of Quantum Computers and Two Major Threats to Blockchain
&lt;/h2>&lt;p>Current blockchain systems are primarily composed of the following two cryptographic elements, each of which is exposed to different threats from quantum algorithms.&lt;/p>
&lt;div class="mermaid">graph TD
A["Astonishing computational power of quantum computers"] --> B["Shor's Algorithm"]
A --> C["Grover's Algorithm"]
B --> D["Collapse of Public Key Cryptography (ECDSA/RSA/DSA)"]
C --> E["Impact on Cryptographic Hash Functions (SHA-256)"]
D --> F["Identification of others' private keys and transaction forgery"]
E --> G["PoW mining dominance and attacks on certain addresses"]
F --> H["Fatal and direct threat to blockchain"]
G --> I["Threat manageable by algorithm adjustments (e.g., key length extension)"]
style H fill:#ff9999,stroke:#cc0000,stroke-width:2px;
style I fill:#ffff99,stroke:#cccc00,stroke-width:2px;&lt;/div>
&lt;h3 id="21-basics-of-elliptic-curve-cryptography-ecdsa-and-computational-difficulty">2.1. Basics of Elliptic Curve Cryptography (ECDSA) and Computational Difficulty
&lt;/h3>&lt;p>Many blockchains, including Bitcoin and Ethereum, employ the &lt;strong>Elliptic Curve Digital Signature Algorithm (ECDSA)&lt;/strong> as their digital signature algorithm. Specifically, Bitcoin uses an elliptic curve with the parameter &lt;code>secp256k1&lt;/code>.&lt;/p>
&lt;p>The security of elliptic curve cryptography relies on the computational difficulty of the &lt;strong>Elliptic Curve Discrete Logarithm Problem (ECDLP)&lt;/strong>.
An elliptic curve is defined by the following equation in the Weierstrass normal form:&lt;/p>
$$
y^2 \equiv x^3 + ax + b \pmod{p}
$$
&lt;p>In Bitcoin&amp;rsquo;s &lt;code>secp256k1&lt;/code>, $a = 0, b = 7$, and $p$ is a very large prime number.
Let $G$ be the base point (reference point) on this curve, and $k$ be the private key, which is a randomly chosen massive 256-bit integer. The public key $K$ is then obtained by adding the base point $k$ times (scalar multiplication).&lt;/p>
$$
K = k \times G = \underbrace{G + G + \dots + G}_{k \text{ times}}
$$
&lt;p>Calculating the private key $k$ (finding the discrete logarithm) from the exposed public key $K$ and base point $G$ using classical computers requires an exponential computational time of $\mathcal{O}(\sqrt{p})$, even when using the best classical algorithms like Pollard&amp;rsquo;s rho algorithm. For a 256-bit key, it takes about $2^{128}$ operations, a level that cannot be solved even if current supercomputers are run for billions of years.&lt;/p>
&lt;h3 id="22-collapse-by-shors-algorithm">2.2. Collapse by Shor&amp;rsquo;s Algorithm
&lt;/h3>&lt;p>However, &lt;strong>Shor&amp;rsquo;s Algorithm&lt;/strong>, published by Peter Shor in 1994, completely destroyed this premise. Shor&amp;rsquo;s algorithm was originally proposed to solve the prime factorization problem (the foundation of RSA cryptography) in polynomial time, but it can also be applied to the discrete logarithm problem and the elliptic curve discrete logarithm problem.&lt;/p>
&lt;p>The core of Shor&amp;rsquo;s algorithm lies in rapidly finding the &amp;ldquo;Period&amp;rdquo; of a function using the &lt;strong>Quantum Fourier Transform (QFT)&lt;/strong>.&lt;/p>
$$
\text{Classical computational complexity} = \mathcal{O}(2^{n/2}) \quad (\text{where } n \text{ is the bit length})
$$
$$
\text{Quantum algorithm computational complexity} = \mathcal{O}(n^3)
$$
&lt;p>In this way, Shor&amp;rsquo;s algorithm dramatically reduces exponential time to &lt;strong>Polynomial Time&lt;/strong>. If a quantum computer with sufficient logical qubits is completed, it will be possible to determine the private key $k$ from the public key $K$ exposed on the network in minutes or seconds. This allows attackers to easily obtain the private keys of others&amp;rsquo; wallets and take full control of their funds.&lt;/p>
&lt;h4 id="221-step-by-step-explanation-of-ecdlp-decryption-by-shors-algorithm">2.2.1 Step-by-Step Explanation of ECDLP Decryption by Shor&amp;rsquo;s Algorithm
&lt;/h4>&lt;p>Let&amp;rsquo;s look at the internal process of how a quantum computer solves the Elliptic Curve Discrete Logarithm Problem (ECDLP) step by step.&lt;/p>
&lt;p>Problem setting: In $K = k \times G$, $G$ and $K$ are known, and we want to find the unknown integer $k$ (private key). Let the order of the elliptic curve be $N$.&lt;/p>
&lt;p>&lt;strong>Step 1: Creation of a superposition state&lt;/strong>
First, prepare two quantum registers and apply a Hadamard Gate to each to create a superposition state of all possible integer combinations.
&lt;/p>
$$
|\psi_1\rangle = \frac{1}{N} \sum_{x=0}^{N-1} \sum_{y=0}^{N-1} |x\rangle |y\rangle |0\rangle
$$
&lt;p>&lt;strong>Step 2: Application of the quantum oracle (evaluation of the function)&lt;/strong>
Next, using a quantum circuit (oracle) that performs point addition on the elliptic curve, compute the function $f(x, y) = x \times G + y \times K$ in the third register.
&lt;/p>
$$
|\psi_2\rangle = \frac{1}{N} \sum_{x=0}^{N-1} \sum_{y=0}^{N-1} |x\rangle |y\rangle |x \times G + y \times K\rangle
$$
&lt;p>
The important point here is that since $K = k \times G$, we can rewrite it as $f(x, y) = (x + y \cdot k) \times G$.&lt;/p>
&lt;p>&lt;strong>Step 3: Measurement of the third register&lt;/strong>
When the third register is measured, it collapses to a point $R$ on the elliptic curve. As a result, the first and second registers collapse to a superposition state of pairs $(x, y)$ that satisfy $x + y \cdot k \equiv c \pmod{N}$ (where $c$ is a constant).
&lt;/p>
$$
|\psi_3\rangle = \frac{1}{\sqrt{N}} \sum_{y=0}^{N-1} |c - y \cdot k \pmod{N}\rangle |y\rangle
$$
&lt;p>&lt;strong>Step 4: Application of the Quantum Fourier Transform (QFT)&lt;/strong>
This state has a periodicity related to the period $k$. By applying the Inverse QFT here, phase interference is induced, converting the period information into amplitudes.&lt;/p>
&lt;p>&lt;strong>Step 5: Measurement and classical post-processing&lt;/strong>
When the first and second registers are measured, a value containing information about $k$ is obtained with high probability. By applying classical number theory algorithms such as Continued Fractions to the measured value, the unknown private key $k$ can be completely determined.&lt;/p>
&lt;p>The number of quantum gates required for this entire process is $\mathcal{O}(\log^3 N)$, uncovering the private key at ultra-high speeds completely incomparable to the $\mathcal{O}(\sqrt{N})$ search by classical computers.&lt;/p>
&lt;h3 id="23-grovers-algorithm-and-its-impact-on-hash-functions">2.3. Grover&amp;rsquo;s Algorithm and its Impact on Hash Functions
&lt;/h3>&lt;p>Another threat is &lt;strong>Grover&amp;rsquo;s Algorithm&lt;/strong>, proposed by Lov Grover in 1996. This significantly impacts hash functions (e.g., SHA-256).&lt;/p>
&lt;p>In blockchain, hash functions are used to ensure data integrity, generate addresses, and serve as the foundation for &lt;strong>PoW (Proof of Work) mining&lt;/strong> in Bitcoin. Reversing a hash function (preimage computation) can be seen as an &amp;ldquo;unstructured database search problem&amp;rdquo; to find the input value $x$ such that $H(x) = y$ for a specific output value $y$.&lt;/p>
&lt;p>For classical computers, finding the correct answer out of $N$ possibilities requires an average of $\frac{N}{2}$ trials and a worst-case of $N$ trials. That is, the computational complexity is $\mathcal{O}(N)$.
However, Grover&amp;rsquo;s algorithm uses a quantum technique called &amp;ldquo;Amplitude Amplification.&amp;rdquo; By iteratively amplifying the probability amplitude of the correct state from among all possibilities in a superposition state, it reduces the search time to its square root.&lt;/p>
$$
\text{Computational complexity of Grover's Algorithm} = \mathcal{O}(\sqrt{N})
$$
&lt;p>For SHA-256, since $N = 2^{256}$, a classical brute-force search requires about $2^{256}$ trials. But using Grover&amp;rsquo;s algorithm, it only takes $\sqrt{2^{256}} = 2^{128}$ trials. This means that a 256-bit hash function&amp;rsquo;s security strength is &lt;strong>effectively halved to 128 bits&lt;/strong> against quantum computers.&lt;/p>
&lt;h4 id="231-will-sha-256-survive-quantum-supremacy-in-hashing">2.3.1. Will SHA-256 Survive? (Quantum Supremacy in Hashing)
&lt;/h4>&lt;p>Even if the security is halved, &amp;ldquo;128-bit security&amp;rdquo; remains extremely robust. The $2^{128}$ operations is an astronomical number even from the current technological level, requiring a timescale of the lifespan of the universe.
Therefore, it is widely believed that &lt;strong>&amp;ldquo;SHA-256 maintains practical security against quantum computers.&amp;rdquo;&lt;/strong> If it becomes necessary to increase the security margin in the future, simply doubling the hash output length (e.g., migrating from SHA-256 to SHA-512) will preserve classical 256-bit security in the quantum world.&lt;/p>
&lt;p>In conclusion, the quantum threat to hash functions is &amp;ldquo;minor and manageable,&amp;rdquo; whereas the threat to public key cryptography (ECDSA) is &amp;ldquo;fatal.&amp;rdquo;&lt;/p>
&lt;hr>
&lt;h2 id="3-specific-impact-analysis-on-current-crypto-assets-bitcoin-ethereum">3. Specific Impact Analysis on Current Crypto Assets (Bitcoin, Ethereum)
&lt;/h2>&lt;p>In a world where ECDSA decryption by quantum computers is possible, what specific vulnerabilities will crypto asset networks face? Here, we provide a detailed analysis using Bitcoin&amp;rsquo;s mechanism as an example, from the perspective of &lt;strong>&amp;ldquo;the timing of public key exposure.&amp;rdquo;&lt;/strong>&lt;/p>
&lt;h3 id="31-address-generation-and-the-privacy-of-public-keys">3.1. Address Generation and the &amp;ldquo;Privacy&amp;rdquo; of Public Keys
&lt;/h3>&lt;p>Bitcoin addresses (P2PKH: Pay-to-Public-Key-Hash or P2WPKH: Pay-to-Witness-Public-Key-Hash) use a public key hashed multiple times rather than the public key itself.&lt;/p>
$$
\text{Bitcoin Address} = \text{Base58Check}(\text{RIPEMD160}(\text{SHA256}(\text{Public Key})))
$$
&lt;p>As mentioned earlier, since hash functions are resistant to quantum attacks (Grover&amp;rsquo;s algorithm), reversing the original &amp;ldquo;public key&amp;rdquo; from the &amp;ldquo;address&amp;rdquo; (which is a hash value) is impossible even for a quantum computer.
In other words, for &lt;strong>&amp;ldquo;unused addresses (those that have never sent funds),&amp;rdquo;&lt;/strong> the public key is not exposed on the blockchain at all, and only the hash value is recorded. Therefore, as long as the public key is unknown, there is no target to execute Shor&amp;rsquo;s algorithm, and the private key cannot be identified. Wallets in this state can be said to be Quantum-safe.&lt;/p>
&lt;h3 id="32-fatal-vulnerability-during-transaction-transmission-front-running-attack">3.2. Fatal Vulnerability During Transaction Transmission (Front-running Attack)
&lt;/h3>&lt;p>The problem arises when users send funds.
When broadcasting (sending) a transaction to the network, the user must &lt;strong>include their public key in the transaction data along with the digital signature and expose it to the entire network&lt;/strong> for verification.&lt;/p>
&lt;div class="mermaid">sequenceDiagram
participant User as "User (Alice)"
participant Mempool as "Mempool (Unconfirmed Transaction Pool)"
participant QuantumAttacker as "Quantum Attacker"
participant Miner as "Miner (Block Generation)"
User->>Mempool: Send transaction (including public key + signature)
Mempool-->>QuantumAttacker: Intercept public key on the network
note right of QuantumAttacker: Execute Shor's algorithm in minutes&lt;br/>(Calculate private key from public key)
QuantumAttacker->>QuantumAttacker: Generate a new signature using Alice's private key
QuantumAttacker->>Mempool: Broadcast fraudulent transfer with a higher miner fee
Miner->>Miner: Prioritize fraudulent transaction with higher fee (Gas) into a block
Miner-->>User: Recorded on blockchain (Alice loses funds)&lt;/div>
&lt;p>Once the public key is sent to the Mempool (the waiting area for unconfirmed transactions), that data is shared with nodes worldwide. If an attacker possesses an ultra-fast quantum computer, they can steal funds through the following process:&lt;/p>
&lt;ol>
&lt;li>Intercept a legitimate user&amp;rsquo;s (Alice&amp;rsquo;s) transaction from the Mempool and &lt;strong>extract the public key&lt;/strong>.&lt;/li>
&lt;li>Execute Shor&amp;rsquo;s algorithm and &lt;strong>calculate the private key from the public key within minutes (before the block is confirmed)&lt;/strong>.&lt;/li>
&lt;li>Using the obtained private key, &lt;strong>create a fake transaction&lt;/strong> sending Alice&amp;rsquo;s funds to the attacker&amp;rsquo;s address.&lt;/li>
&lt;li>Set a &lt;strong>much higher miner fee&lt;/strong> for this fake transaction than Alice&amp;rsquo;s original transaction and send it to the network.&lt;/li>
&lt;/ol>
&lt;p>Miners prioritize transactions with higher fees into blocks according to economic incentives. As a result, the attacker&amp;rsquo;s fraudulent transfer is confirmed first, and Alice&amp;rsquo;s legitimate transfer is discarded as a &amp;ldquo;Double Spend&amp;rdquo; due to insufficient balance.
This series of events is called a &lt;strong>Front-running Attack&lt;/strong>, and in a world where quantum computers are commercialized, it will cause a terrifying situation where funds are stolen by hackers the moment someone presses the send button.&lt;/p>
&lt;h3 id="33-the-crisis-of-reused-addresses-and-old-addresses-p2pk">3.3. The Crisis of Reused Addresses and Old Addresses (P2PK)
&lt;/h3>&lt;p>An even more serious problem is that addresses that have sent funds at least once in the past (such as when reused as change addresses) already have their public keys permanently recorded on the blockchain. These are in danger of having their private keys calculated and balances stolen at any time, without even waiting to send a transaction.&lt;/p>
&lt;p>Additionally, in the &lt;strong>P2PK (Pay-to-Public-Key)&lt;/strong> format, which was mainstream around 2009-2010 and includes Satoshi Nakamoto&amp;rsquo;s early mining rewards (over 1 million BTC), the public key itself was recorded directly on the blockchain as the address instead of a hash. These massive amounts of dormant Bitcoins would be the easiest targets for quantum computers, and if stolen all at once and dumped on the market, could cause a massive price crash.&lt;/p>
&lt;hr>
&lt;h2 id="4-transition-scenarios-to-post-quantum-cryptography-pqc">4. Transition Scenarios to Post-Quantum Cryptography (PQC)
&lt;/h2>&lt;p>To avoid such a &amp;ldquo;Q-Day (the day quantum computers break cryptography)&amp;rdquo; catastrophe, the cryptography and blockchain communities are planning a transition to &lt;strong>Post-Quantum Cryptography (PQC)&lt;/strong>, which is difficult even for quantum algorithms to decrypt.
The National Institute of Standards and Technology (NIST) has been progressing with the standardization process of PQC for many years, and after several rounds of rigorous evaluation, some promising cryptographic schemes have been selected as final standards.&lt;/p>
&lt;p>We will explain in detail the major PQC algorithms that are drawing attention as digital signature alternatives for blockchains, along with their mathematical mechanisms.&lt;/p>
&lt;h3 id="41-hash-based-signatures">4.1. Hash-Based Signatures
&lt;/h3>&lt;p>Hash-based signatures are a cryptographic scheme whose security relies solely on a very simple and robust foundation: the &amp;ldquo;collision resistance of hash functions.&amp;rdquo; Since the safety of hash functions against quantum computers has already been proven (as mentioned above, a 128-bit security margin is sufficient), this is a highly reliable approach.
Representative examples include &lt;strong>Lamport Signatures&lt;/strong>, WOTS (Winternitz One-Time Signature) which extended it, and the NIST standardization candidate &lt;strong>SPHINCS+&lt;/strong> (now called SLH-DSA under FIPS 205).&lt;/p>
&lt;h4 id="411-mathematical-details-of-lamport-signatures-one-time-signature">4.1.1. Mathematical Details of Lamport Signatures (One-Time Signature)
&lt;/h4>&lt;p>Let&amp;rsquo;s look at the mechanism of Lamport signatures in more mathematical detail.
Let the hash function be $H: \{0, 1\}^* \to \{0, 1\}^{256}$.&lt;/p>
&lt;p>&lt;strong>[Key Generation]&lt;/strong>
Alice (sender) generates 256 pairs of private keys using a True Random Number Generator (TRNG).
&lt;/p>
$$
\text{sk}_{i,0} \in \{0, 1\}^{256}, \quad \text{sk}_{i,1} \in \{0, 1\}^{256} \quad (1 \le i \le 256)
$$
&lt;p>
Thus, the private key $\text{sk}$ consists of a total of 512 256-bit strings (Size: $512 \times 32 = 16,384$ bytes).&lt;/p>
&lt;p>Next, she computes the public key $\text{pk}$. Each private key component is individually hashed.
&lt;/p>
$$
\text{pk}_{i,0} = H(\text{sk}_{i,0}), \quad \text{pk}_{i,1} = H(\text{sk}_{i,1})
$$
&lt;p>
The public key is also $16,384$ bytes. This is published to the blockchain network.&lt;/p>
&lt;p>&lt;strong>[Signature Generation]&lt;/strong>
To sign a transaction data $M$, Alice first calculates its hash value.
&lt;/p>
$$
h = H(M) \in \{0, 1\}^{256}
$$
&lt;p>
Let the $i$-th bit of the hash value $h$ be $h_i \in \{0, 1\}$.
Alice&amp;rsquo;s signature $\sigma$ is a set of private key components corresponding to each bit $h_i$.
&lt;/p>
$$
\sigma = (\text{sk}_{1, h_1}, \text{sk}_{2, h_2}, \dots, \text{sk}_{256, h_{256}})
$$
&lt;p>
In other words, if the message hash bit is &lt;code>0&lt;/code>, $\text{sk}_{i,0}$ is revealed, and if &lt;code>1&lt;/code>, $\text{sk}_{i,1}$ is revealed. The signature size is $256 \times 32 = 8,192$ bytes.&lt;/p>
&lt;p>&lt;strong>[Signature Verification]&lt;/strong>
The miner (verifier) verifies using the received transaction $M$, signature $\sigma = (s_1, s_2, \dots, s_{256})$, and the public key $\text{pk}$.
They recalculate the hash of the transaction $h = H(M)$, and check whether hashing each $s_i$ matches the corresponding element $\text{pk}_{i, h_i}$ of the public key.
&lt;/p>
$$
H(s_i) \overset{?}{=} \text{pk}_{i, h_i} \quad (\text{for all } 1 \le i \le 256)
$$
&lt;p>This process is mathematically extremely simple, and it is impossible to forge a signature unless a quantum computer can reverse $H$. However, once signed, half of the private key is exposed to the network, so if another message is signed with the same key pair, the exposed private keys combine to give the attacker room for forgery, creating a strong restriction that it can only be used &amp;ldquo;One-Time.&amp;rdquo;
To make this practical, technologies like &lt;strong>XMSS&lt;/strong>, which bundles many one-time keys into a single root public key using a Merkle tree, and the stateless &lt;strong>SPHINCS+&lt;/strong> have been developed, but they have the drawback of signature sizes reaching tens of kilobytes.&lt;/p>
&lt;h3 id="42-lattice-based-cryptography">4.2. Lattice-Based Cryptography
&lt;/h3>&lt;p>Currently, the most anticipated mainstream of PQC, adopted as NIST&amp;rsquo;s main standard specification (FIPS 204: ML-DSA / formerly CRYSTALS-Dilithium, and Falcon, etc.), is &lt;strong>Lattice-Based Cryptography&lt;/strong>.&lt;/p>
&lt;p>The security of lattice cryptography depends on mathematically proven hard problems such as the &amp;ldquo;Shortest Vector Problem (SVP) in multi-dimensional lattices&amp;rdquo; or the &amp;ldquo;Learning With Errors (LWE) problem.&amp;rdquo; No algorithm has been found to solve lattice problems efficiently even using quantum computers.&lt;/p>
&lt;p>&lt;strong>Mathematical Model of LWE (Learning With Errors):&lt;/strong>
The basic idea of the LWE problem is to dramatically increase the difficulty of a problem by intentionally adding &amp;ldquo;small noise (errors)&amp;rdquo; to a system of linear equations.
Let the secret vector be $\mathbf{s} \in \mathbb{Z}_q^n$.
There is a massive randomly chosen public matrix $\mathbf{A} \in \mathbb{Z}_q^{m \times n}$ and an intentionally added small noise vector $\mathbf{e} \in \mathbb{Z}_q^m$.
The public key $\mathbf{b}$ is calculated as follows:&lt;/p>
$$
\mathbf{b} = \mathbf{A}\mathbf{s} + \mathbf{e} \pmod{q}
$$
&lt;p>Even if matrix $\mathbf{A}$ and vector $\mathbf{b}$ (public key) are public, reversing them to find the private key $\mathbf{s}$ becomes extremely difficult due to the presence of the noise $\mathbf{e}$. Without the noise, it could be solved by simple Gaussian elimination, but with the noise, the search space in all dimensions explodes, providing robust security against both classical and quantum computers.
In actual algorithms used in blockchain and elsewhere (like Dilithium), &lt;strong>Ring-LWE (or Module-LWE)&lt;/strong>, which expands this over polynomial rings, is used to reduce key sizes and speed up computations.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Pros&lt;/strong>: Compared to hash-based signatures, public key and signature sizes are relatively small (a few kilobytes), and signature generation/verification computation speeds are extremely fast (equivalent to or better than ECDSA).&lt;/li>
&lt;li>&lt;strong>Cons&lt;/strong>: The mathematical structure is complex, and because the historical verification period is short, the risk of a new decryption algorithm being discovered in the future is not zero.&lt;/li>
&lt;/ul>
&lt;hr>
&lt;h2 id="5-technical-challenges-in-migrating-blockchains-to-pqc">5. Technical Challenges in Migrating Blockchains to PQC
&lt;/h2>&lt;p>Just because PQC algorithms (like Dilithium and SPHINCS+) exist doesn&amp;rsquo;t mean they can be introduced to Bitcoin or Ethereum tomorrow. There are several heavy challenges unique to decentralized systems.&lt;/p>
&lt;h3 id="51-signature-size-bloat-and-the-collapse-of-scalability">5.1. Signature Size Bloat and the Collapse of Scalability
&lt;/h3>&lt;p>The biggest barrier to introducing PQC is the significant bloat in data size.
While the current ECDSA signature size is about 70 bytes, the lattice-based Dilithium (ML-DSA) has a signature size of about 2,420 to 4,595 bytes (depending on the security level), and a public key size exceeding 1,300 bytes. For the hash-based SPHINCS+, the signature alone reaches tens of thousands of bytes.&lt;/p>
&lt;p>If Bitcoin introduces PQC with the current block size limit (about 4MB weight including SegWit), the number of transactions that can be stored in one block will drastically decrease. Network throughput (TPS: Transactions Per Second) would fall devastatingly, and transaction congestion would become normal.
To solve this, a massive increase in block size is necessary, but this would increase the storage and network bandwidth requirements for full nodes, making it difficult for individuals to operate nodes, resulting in the dilemma of causing &lt;strong>centralization of the network&lt;/strong>.&lt;/p>
&lt;div class="mermaid">pie title "Comparison of Signature Data Sizes in Blockchain (Conceptual Diagram)"
"ECDSA (approx. 70 Bytes)" : 2
"Dilithium ML-DSA (approx. 2,500 Bytes)" : 58
"SPHINCS+ (approx. 17,000 Bytes)" : 40&lt;/div>
&lt;p>&lt;em>(Note: Transaction data bloat due to PQC introduction is a fatal bottleneck for scalability)&lt;/em>&lt;/p>
&lt;h3 id="52-impact-on-the-ethereum-virtual-machine-evm-and-precompiled-contracts">5.2. Impact on the Ethereum Virtual Machine (EVM) and Precompiled Contracts
&lt;/h3>&lt;p>In a Turing-complete smart contract platform like Ethereum, the introduction of PQC demands a fundamental upgrade to the EVM (Ethereum Virtual Machine).
In the current EVM, a precompiled contract &lt;code>ecrecover&lt;/code> (address: &lt;code>0x01&lt;/code>) is provided for ECDSA signature verification, optimized to perform signature verification at a very low gas cost (3000 Gas).&lt;/p>
&lt;p>However, the verification process of new lattice-based cryptographic algorithms like Dilithium and Falcon involves complex polynomial and matrix operations. Implementing this using only existing EVM Opcodes could consume millions to tens of millions of gas for just one signature verification. This is a level that would deplete the current block gas limit (about 30 million Gas) with a single transaction.&lt;/p>
&lt;p>To avoid this, it is necessary to incorporate a new Precompiled Contract for PQC verification (e.g., assigning DilithiumVerify to &lt;code>0x10&lt;/code>) into the EVM itself through a network hard fork. This requires a long-term process where core developers of each Ethereum client (Geth, Nethermind, Erigon, etc.) collaborate to optimally implement lattice cryptography verification logic at the language level (C++, Go, Rust, etc.) and conduct security audits.&lt;/p>
&lt;h3 id="53-difficulties-in-consensus-building-through-hard-forks">5.3. Difficulties in Consensus Building Through Hard Forks
&lt;/h3>&lt;p>Changing the underlying signature algorithm inherently requires a &lt;strong>Hard Fork&lt;/strong> that updates the entire network protocol. However, in communities like Bitcoin that emphasize &amp;ldquo;not changing rules, being decentralized,&amp;rdquo; the consensus-building process is politically very difficult. From the time a BIP (Bitcoin Improvement Proposal) for migrating to PQC is proposed until it is implemented, years of discussion and testing will be required.&lt;/p>
&lt;hr>
&lt;h2 id="6-when-will-q-day-arrive-a-roadmap-for-transition">6. When Will &amp;ldquo;Q-Day&amp;rdquo; Arrive? A Roadmap for Transition
&lt;/h2>&lt;p>When will &amp;ldquo;Q-Day (the day a quantum computer completely decrypts 256-bit elliptic curve cryptography)&amp;rdquo; arrive?
Although opinions are divided even among researchers, many experts predict that large-scale quantum computers with at least thousands to tens of thousands of stable logical qubits (error-corrected qubits with noise tolerance) will emerge &lt;strong>&amp;ldquo;from the mid-2030s to the 2040s.&amp;rdquo;&lt;/strong> However, depending on breakthroughs in hardware architecture or the discovery of more efficient quantum algorithms, the possibility of this arriving sooner (around 2030) cannot be ruled out.&lt;/p>
&lt;p>The roadmap the crypto asset ecosystem must take before it&amp;rsquo;s too late is as follows:&lt;/p>
&lt;h3 id="phase-1-hybrid-signatures-and-account-abstraction-present-to-around-2028">Phase 1: Hybrid Signatures and Account Abstraction (Present to around 2028)
&lt;/h3>&lt;p>The current blockchain scene, particularly Ethereum developers (like Vitalik Buterin), is considering &lt;strong>&amp;ldquo;Hybrid Signatures&amp;rdquo;&lt;/strong> that combine ECDSA and PQC (hash-based signatures or lattice cryptography). This approach attaches both the existing secure ECDSA signature and a PQC signature to a transaction, maintaining security even if one of them is broken.
Additionally, by utilizing Account Abstraction (ERC-4337), efforts are underway to implement and support PQC signatures on an opt-in basis (only for users who want it) on smart contract wallets without waiting for a protocol-level hard fork.&lt;/p>
&lt;h3 id="phase-2-utilizing-zero-knowledge-proofs-zk-rollups-2025-onwards">Phase 2: Utilizing Zero-Knowledge Proofs (ZK-Rollups) (2025 onwards)
&lt;/h3>&lt;p>The trump card expected to solve PQC&amp;rsquo;s biggest weakness, &amp;ldquo;signature data bloat,&amp;rdquo; is the utilization of &lt;strong>ZK-Rollups (Zero-Knowledge Proofs)&lt;/strong>, a Layer 2 technology.
Instead of writing massive PQC signature data directly to Layer 1 (the main chain), numerous PQC transactions are verified and aggregated on Layer 2. Then, using ZK-SNARKs or ZK-STARKs, they are compressed into a single extraordinarily small &amp;ldquo;Proof&amp;rdquo; and recorded on Layer 1.
Note that since some SNARKs configurations (like Groth16) are themselves vulnerable to quantum attacks, adopting &lt;strong>ZK-STARKs&lt;/strong>, which rely solely on quantum-resistant hash functions, is key.&lt;/p>
&lt;h3 id="phase-3-protocol-level-hard-forks-around-2030">Phase 3: Protocol-Level Hard Forks (Around 2030)
&lt;/h3>&lt;p>Once NIST&amp;rsquo;s PQC standardization is fully established, and industry-standard libraries are available and well-tested, it is expected that a hard fork completely transitioning the default signature scheme to PQC will be implemented on major chains like Bitcoin and Ethereum. During this transition period, a massive announcement urging users to &amp;ldquo;move funds from old wallets to new PQC-compatible wallets&amp;rdquo; will take place.&lt;/p>
&lt;h3 id="pioneering-project-examples">Pioneering Project Examples
&lt;/h3>&lt;p>Some blockchain projects have anticipated this quantum threat and have been developed with quantum resistance from their initial stages.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>QRL (Quantum Resistant Ledger)&lt;/strong>: An early blockchain that natively implemented a hash-based PQC called XMSS (eXtended Merkle Signature Scheme) at the protocol level.&lt;/li>
&lt;li>&lt;strong>Algorand / Cellframe&lt;/strong>: A group of projects actively exploring the integration of lattice cryptography, possessing a flexible cryptographic layer modular architecture anticipating future PQC updates.&lt;/li>
&lt;/ul>
&lt;hr>
&lt;h2 id="7-conclusion-the-future-of-crypto-assets-and-protecting-our-wealth">7. Conclusion: The Future of Crypto Assets and Protecting Our Wealth
&lt;/h2>&lt;p>The arrival of the &amp;ldquo;Post-Quantum Era&amp;rdquo; goes beyond mere science fiction fantasy; it is already looming before us as a concrete technical challenge to real-world cryptographic systems.&lt;/p>
&lt;p>The two swords of quantum computers, Shor&amp;rsquo;s algorithm and Grover&amp;rsquo;s algorithm, threaten public key cryptography and hash functions, respectively, which are the foundations of current blockchains. In particular, the vulnerability of ECDSA is fatal, and to avoid the risk of fund theft through front-running attacks, transitioning to Post-Quantum Cryptography (PQC) is an absolutely unavoidable path.&lt;/p>
&lt;p>However, the technology sector and blockchain community are not just twiddling their thumbs waiting for destruction. The selection and standardization of PQC algorithms like lattice cryptography and hash-based signatures are steadily progressing, and a path to overcoming PQC&amp;rsquo;s biggest hurdle, &amp;ldquo;data size bloat,&amp;rdquo; is beginning to emerge by utilizing Zero-Knowledge Proofs (ZK-STARKs) and Layer 2 scaling technologies.&lt;/p>
&lt;p>There is no need for everyday crypto asset users and investors to panic right now and sell all their funds. However, it is important to have the following basic literacy and sense of self-defense:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Avoid address reuse&lt;/strong>: Thoroughly avoid keeping funds long-term in &amp;ldquo;used addresses (addresses that have sent funds even once, exposing their public key on the blockchain)&amp;rdquo; from a security perspective, not just a privacy one.&lt;/li>
&lt;li>&lt;strong>Pay attention to technology trends&lt;/strong>: Keep an antenna up for discussions on major networks&amp;rsquo; PQC transitions and hard fork news (like Bitcoin&amp;rsquo;s BIPs and Ethereum&amp;rsquo;s EIPs), so that you can appropriately transition your wallet when necessary.&lt;/li>
&lt;/ul>
&lt;p>The history of blockchain is also a history of continuous upgrades and resilience against new technological threats. Just as it has overcome scalability issues and environmental problems (like the transition from PoW to PoS), the entire ecosystem will surely seek solutions and adapt to this unprecedented quantum threat.
We look forward to a future where the new human wisdom of quantum computers and the trusted technology of decentralized ledgers do not collapse through collision, but rather sublimate into a higher-dimension, robustly fused system.&lt;/p>
&lt;hr>
&lt;p>&lt;em>References &amp;amp; Related Links:&lt;/em>&lt;/p>
&lt;ul>
&lt;li>National Institute of Standards and Technology (NIST) - Post-Quantum Cryptography Standardization Project&lt;/li>
&lt;li>Shor, P. W. (1994). Algorithms for quantum computation: discrete logarithms and factoring.&lt;/li>
&lt;li>Grover, L. K. (1996). A fast quantum mechanical algorithm for database search.&lt;/li>
&lt;li>Buterin, V. (2024). How to hard-fork to save most users&amp;rsquo; funds in a quantum emergency.&lt;/li>
&lt;/ul></description></item></channel></rss>