An Automated Synthesis Framework for Benchmarking Quantum Resource Costs of Symmetric-Key Cryptography
Abstract
1. Introduction
- We propose ADOQ, an automated framework that synthesizes and depth-optimizes quantum circuits directly from S-box truth tables, enabling consistent circuit generation across different S-box implementations. We demonstrate that the proposed framework can handle larger S-boxes, including the 5-qubit S-box of ASCON and the 8-qubit S-box of AES, which prior work could not address due to methodological limitations.
- We introduce a unified evaluation framework for quantum circuit synthesis and depth optimization. The proposed framework provides a fair and reproducible benchmarking basis by standardizing quantum circuit synthesis and depth optimization across different S-box implementations.
2. Related Work
3. Bidirectional Quantum Circuit Synthesis
3.1. Reversibility and Design Considerations
- NOT Gate: Performs a single-qubit inversion.
- CNOT Gate: Performs a conditional inversion on a target qubit controlled by a single control qubit.
- Toffoli Gate: Performs a conditional inversion on a target qubit controlled by two control qubits (controlled-controlled-NOT).
3.2. Bidirectional Synthesis Procedure
| Algorithm 1 Bidirectional Synthesis Procedure for Reversible Circuits |
|
3.3. Extending Synthesis to Four or More Qubits
4. Depth-Oriented Optimization Techniques
- MCT decomposition;
- Bidirectional optimization;
- Ancilla use optimization;
- Simulated annealing.
4.1. MCT Decomposition
- The number of control qubits;
- The dependency relationships between adjacent gates;
- The potential for gate elimination;
- The potential for concurrent execution with neighboring gates.
4.2. Bidirectional Optimization
4.3. Ancilla Optimization
4.4. Simulated Annealing
- Initial Circuit: Set the circuit synthesized by the bidirectional synthesis algorithm as the initial state. Alternatively, the reversible truth table alone can be used as the initial input.
- Perturbation: Apply random perturbations by adding, replacing, or deleting an elementary gate (NOT, CNOT, or Toffoli) at arbitrary locations in the current circuit.
- Cost Function: Compute the Hamming distance to evaluate functional correctness with respect to the reversible truth table. In addition, circuit depth or gate count is incorporated into the cost function to reflect the optimization objective.
- Acceptance Criterion: Let . If , accept the new circuit; otherwise, if the probability is ≥ , accept—probability is defined in Equation (4):
4.5. Optimization Policy Summary
5. Optimization Framework and Case Study
5.1. Design Objectives and Principles
5.1.1. Benchmarking Objective and Rationale for Staged Design
5.1.2. Architecture and Automation Boundary
- BSPM constructs an initial reversible circuit satisfying the given truth table using the bidirectional synthesis algorithm.
- MDPM decomposes MCT gates into combinations of standard Toffoli gates, improving hardware compatibility and preparing the circuit for subsequent depth optimization. In our benchmarking setting, MDPM follows the same minimum T-depth Toffoli decomposition as DORCIS; details and the ancilla clean-up property are specified in Section 6.
- COPM applies depth-oriented optimization techniques such as gate reordering/elimination and ancilla-assisted parallelization while preserving logical equivalence.
- SAPM performs global stochastic refinement using simulated annealing to further reduce circuit depth or overall cost by escaping local optima.
5.1.3. Key Design Principles
- Modularity: Each synthesis and optimization algorithm is implemented as an independent module. This modular design allows individual components to be enabled, disabled, or replaced without affecting the overall framework, facilitating easy integration of new algorithms and future extensions.
- Automation: ADOQ provides end-to-end automation under a fixed default configuration; see Section 5.1.2 for the automation boundary and reproducibility settings (seeded simulated annealing enabled by default).
- Flexibility: The framework supports the selective activation of optimization modules, enabling users to tailor the optimization process according to specific performance objectives, hardware constraints, or available computational resources.
- Focus on depth optimization: While maintaining functional correctness, ADOQ prioritizes the reduction of circuit depth, as shorter execution depth directly translates to improved reliability and execution fidelity on real quantum hardware.
5.2. Case Study: PRØST S-Box Optimization
6. Experimental Results
6.1. Experimental Setup
6.1.1. Benchmarks and Evaluation Protocol
6.1.2. Default Configuration (Used Throughout Experiments)
- Input: Reversible truth table/permutation in CSV with a fixed I/O convention.
- BSPM: Bidirectional synthesis with fixed parameters.
- MDPM: Minimum T-depth Toffoli decomposition consistent with DORCIS; ancilla clean-up enabled (Figure 11).
- COPM: Bidirectional optimization + ancilla optimization enabled.
- SAPM: Simulated annealing enabled by default; fixed schedule, fixed scaling parameter K, and the optimization budget.
- Reporting: Logical-level depth, logical qubits, and gate counts under the fixed cost model.
6.1.3. Determinism and Variability
6.2. Results on 4-Qubit S-Boxes
6.2.1. Input Specification and Conversion
6.2.2. Representative Circuit Comparison
- LIGHTER-R synthesizes the S-box using six Toffoli gates, each contributing a depth of 7, along with three Clifford gates of depth 1, resulting in a total circuit weighted depth of 45.
- DORCIS employs four Toffoli gates and five Clifford gates. By identifying Clifford operations that can be executed in parallel, DORCIS reduces the overall circuit weighted depth to 31.
- ADOQ synthesizes the same S-box using four Toffoli gates and eight Clifford gates. Although the number of Clifford operations is higher, ADOQ exploits concurrency among gates to achieve a total circuit weighted depth of 32.
6.2.3. Aggregate Results and Discussion
6.3. Results on Larger S-Boxes
6.3.1. Main Results
6.3.2. Ablation and Sensitivity
7. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Correction Statement
References
- Grover, L.K. A fast quantum mechanical algorithm for database search. In Twenty-Eighth Annual ACM Symposium on Theory of Computing; Association for Computing Machinery: New York, NY, USA, 1996; pp. 212–219. [Google Scholar]
- Dasu, V.A.; Baksi, A.; Sarkar, S.; Chattopadhyay, A. Lighter-r: Optimized reversible circuit implementation for sboxes. In 2019 32nd IEEE International System-on-Chip Conference (SOCC); IEEE: New York, NY, USA, 2019; pp. 260–265. [Google Scholar]
- Chun, M.; Baksi, A.; Chattopadhyay, A. DORCIS: Depth Optimized Quantum Implementation of Substitution Boxes. Cryptol. Eprint Arch. 2023, 2023, 1–10. [Google Scholar]
- Pan, D.; Long, G.L.; Yin, L.; Sheng, Y.B.; Ruan, D.; Ng, S.X.; Lu, J.; Hanzo, L. The Evolution of Quantum Secure Direct Communication: On the Road to the Qinternet. IEEE Commun. Surv. Tutor. 2024, 26, 1898–1949. [Google Scholar] [CrossRef]
- Baksi, A. Classical and Physical Security of Symmetric Key Cryptographic Algorithms; Springer: Singapore, 2022. [Google Scholar]
- Dobraunig, C.; Eichlseder, M.; Mendel, F. Ascon v1.2: Lightweight Authenticated Encryption and Hashing. J. Cryptol. 2021, 34, 33. [Google Scholar] [CrossRef]
- FIPS PUB 197; Announcing the Advanced Encryption Standard (AES). National Institute of Standards and Technology: Gaithersburg, MD, USA, 2001. Available online: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.197.pdf (accessed on 18 January 2026).
- Shende, V.V.; Prasad, A.K.; Markov, I.L.; Hayes, J.P. Synthesis of Reversible Logic Circuits. IEEE Trans.-Comput.-Aided Des. Integr. Circuits Syst. 2003, 22, 710–722. [Google Scholar] [CrossRef]
- Prasad, A.K.; Shende, V.V.; Markov, I.L.; Hayes, J.P.; Patel, K.N. Data Structures and Algorithms for Simplifying Reversible Circuits. ACM J. Emerg. Technol. Comput. Syst. 2006, 2, 277–293. [Google Scholar] [CrossRef]
- Li, Z.; Chen, H.; Xu, B.; Song, X.; Xue, X. An Algorithm for Synthesis of Optimal 3-qubit Reversible Circuits Based on Bit Operation. In Proceedings of the Second International Conference on Genetic and Evolutionary Computing (WGEC 2008), Jinzhou, China, 25–26 September 2008; pp. 455–458. [Google Scholar] [CrossRef]
- Yang, G.; Song, X.; Hung, W.N.N.; Perkowski, M.A. Bi-Directional Synthesis of 4-Bit Reversible Circuits. Comput. J. 2008, 51, 207–215. [Google Scholar] [CrossRef]
- Golubitsky, O.; Falconer, S.M.; Maslov, D. Synthesis of the Optimal 4-bit Reversible Circuits. In Proceedings of the 47th Annual Design Automation Conference (DAC ’10), Anaheim, CA, USA, 13–18 June 2010; pp. 653–656. [Google Scholar] [CrossRef]
- Golubitsky, O.; Maslov, D. A Study of Optimal 4-Bit Reversible Toffoli Circuits and Their Synthesis. IEEE Trans. Comput. 2012, 61, 1341–1353. [Google Scholar] [CrossRef]
- Kliuchnikov, V.; Maslov, D. Optimization of Clifford Circuits. Phys. Rev. A 2013, 88, 052307. [Google Scholar] [CrossRef]
- Feng, J.; Wei, Y.; Zhang, F.; Pasalic, E.; Zhou, Y. Novel Optimized Implementations of Lightweight Cryptographic S-Boxes via SAT Solvers. IEEE Trans. Circuits Syst. Regul. Pap. 2024, 71, 334–347. [Google Scholar] [CrossRef]
- Jeon, Y.; Baek, S.; Kim, J. A Novel Framework to Construct S-Box Quantum Circuits Using System Modeling: Application to 4-Bit S-Boxes. Comput. Model. Eng. Sci. 2024, 141, 545–561. [Google Scholar] [CrossRef]
- Chung, D.; Lee, S. Quantum Implementation of S-Boxes Based on Polynomial Evaluation. Electron. Lett. 2025, 61, e70337. [Google Scholar] [CrossRef]
- Lin, D.; Yang, C.; Xu, S.; Tian, S.; Sun, B. On the construction of quantum circuits for S-boxes with different criteria based on the SAT solver. Quantum Inf. Process. 2026, 25, 39. [Google Scholar] [CrossRef]
- Miller, D.M.; Maslov, D.; Dueck, G.W. A transformation based algorithm for reversible logic synthesis. In Proceedings of the 40th Annual Design Automation Conference, Anaheim, CA, USA, 2–6 June 2003. [Google Scholar]
- Bogdanov, A.; Knudsen, L.R.; Leander, G.; Paar, C.; Poschmann, A.; Robshaw, M.J.B.; Seurin, Y.; Vikkelsoe, C. PRESENT: An ultra-lightweight block cipher. In CHES 2007; Springer: Berlin/Heidelberg, Germany, 2007; Volume 4727, pp. 450–466. [Google Scholar]
- Lee, J.; Kang, Y.; Lee, Y.S.; Chung, B.; Choi, D. MPMCT gate decomposition method reducing T-depth quickly in proportion to the number of work qubits. Quantum Comput. Eng. 2023, 22, 381. [Google Scholar]
- Zhu, C.; Huang, Z. Optimizing the depth of quantum implementations of linear layers. In International Conference on Information Security and Cryptology; Springer: Cham, Switzerland, 2022; pp. 129–147. [Google Scholar]
- Abdessaied, N.; Wille, R.; Soeken, M.; Drechsler, R. Reducing the Depth of Quantum Circuits Using Additional Circuit Lines. In Reversible Computation (RC 2013), Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2013; Volume 7948, pp. 221–233. [Google Scholar] [CrossRef]
- Shahidi, S.M.; Borujeni, S.E. A new method for reversible circuit synthesis using a Simulated Annealing algorithm and don’t-cares. J. Comput. Electron. 2021, 20, 718–734. [Google Scholar] [CrossRef]
- Kavun, E.B.; Lauridsen, M.M.; Leander, G.; Rechberger, C.; Schwabe, P.; Yalçın, T. Prøst v1.1. CAESAR Submission. 2014. Available online: http://competitions.cr.yp.to/round1/proestv11.pdf (accessed on 29 June 2025).
- Selinger, P. Quantum circuits of T-depth one. Phys. Rev. A 2013, 87, 042302. [Google Scholar] [CrossRef]
- Banik, S.; Pandey, S.K.; Peyrin, T.; Sasaki, Y.; Sim, S.M.; Todo, Y. GIFT: A small present—Towards reaching the limit of lightweight encryption. In Proceedings of the CHES 2017: Cryptographic Hardware and Embedded Systems, Taipei, Taiwan, 25–28 September 2017; pp. 321–345. [Google Scholar]
- Daemen, J.; Peeters, M.; Assche, G.V.; Rijmen, V. The Noekeon Block Cipher. 2000. Available online: https://gro.noekeon.org/Noekeon-spec.pdf (accessed on 10 January 2026).
- Shibutani, K.; Isobe, T.; Hiwatari, H.; Mitsuda, A.; Akishita, T.; Shirai, T. Piccolo: An ultralightweight blockcipher. In Proceedings of the CHES 2011, Nara, Japan, 28 September–1 October 2011; pp. 342–357. [Google Scholar]
- Goudarzi, D.; Jean, J.; Kölbl, S.; Peyrin, T.; Rivain, M.; Sasaki, Y.; Sim, S.M. Pyjamask. v1.0; 2019. Available online: https://csrc.nist.gov/CSRC/media/Projects/lightweight-cryptography/documents/round-2/spec-doc-rnd2/pyjamask-spec-round2.pdf (accessed on 15 February 2026).
- Zhang, W.; Bao, Z.; Lin, D.; Rijmen, V.; Yang, B.; Verbauwhede, I. RECTANGLE: A bit-slice lightweight block cipher suitable for multiple platforms. Sci. China Inf. Sci. 2015, 58, 1–15. [Google Scholar] [CrossRef]
- Beierle, C.; Jean, J.; Kölbl, S.; Leander, G.; Moradi, A.; Peyrin, T.; Sasaki, Y.; Sasdrich, P.; Sim, S.M. The SKINNY family of block ciphers and its low-latency variant MANTIS. In Proceedings of the CRYPTO 2016, Part II, Santa Barbara, CA, USA, 14–18 August 2016; pp. 123–153. [Google Scholar]












| Inputs cba | Outputs c′b′a′ | Inputs cba | Outputs c′b′a′ |
|---|---|---|---|
| 000 | 000 | 000 | 000 |
| 001 | 010 | 001 | 001 |
| 010 | 111 | 010 | 010 |
| 011 | 100 | 011 | 100 |
| 100 | 110 | 100 | 101 |
| 101 | 011 | 101 | 110 |
| 110 | 101 | 110 | 011 |
| 111 | 001 | 111 | 111 |
| (a) | (b) | ||
| Artifact | Symbol | Description/Producer → Consumer |
|---|---|---|
| Reversible specification | T | Truth table (CSV); Input → BSPM |
| Circuit (MCT gates included.) | Sequence of gates; BSPM → MDPM | |
| Circuit (MCT gates decomposed.) | Sequence of gates; MDPM → COPM/SAPM | |
| QASM output | – | Exported QASM circuit; output |
| Symbol | Meaning |
|---|---|
| n | Number of input qubits (S-box bit-width) |
| A | Number of ancilla qubits |
| G | Number of gates |
| C | Circuit |
| T | Truth table |
| D | Circuit depth (number of parallel layers) |
| W | Total logical qubits, |
| K | Scaling parameter of SAPM |
| t | Temperature of SAPM (e.g., , ) |
| x | 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | a | b | c | d | e | f |
| 0 | 4 | 8 | f | 1 | 5 | e | 9 | 2 | 7 | a | c | b | d | 6 | 3 |
| Resources | Baseline (Input) | After MCT Decomposition | After Bi-Directional/Ancilla Optimization | After SA Optimization | |
|---|---|---|---|---|---|
| Qubits | 4 | 4 | 4 | 4 | |
| Ancilla Qubits | – | 1 | 2 | – | |
| Gates | CX (CNOT) | 9 | 9 | 11 | 6 |
| CCX (Toffoli) | 3 | 9 | 9 | 4 | |
| C3X (MCT) | 2 | – | – | – | |
| SUM | 14 | 18 | 20 | 10 | |
| Depth | 12 | 14 | 13 | 7 |
| S-Box | LIGHTER-R [2] | DORCIS [3] | ADOQ | ADOQ Gate Composition | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Depth | T-Depth | Depth | T-Depth | Depth | T-Depth | X | CX | CCX | SUM | |
| DEFAULT-CORE [5] | 45 | 6 | 31 | 4 | 32 | 4 | 3 | 5 | 4 | 12 |
| GIFT [27] | 32 | 4 | 31 | 4 | 32 | 4 | 2 | 4 | 4 | 10 |
| NOEKEON-GAMMA [28] | 32 | 4 | 30 | 4 | 34 | 4 | 2 | 8 | 4 | 14 |
| PICCOLO [29] | 32 | 4 | 30 | 4 | 32 | 4 | 3 | 5 | 4 | 12 |
| PRESENT [20] | 33 | 4 | 32 | 4 | 35 | 4 | 6 | 6 | 4 | 16 |
| PYJAMASK-4 [30] | 32 | 4 | 31 | 4 | 34 | 4 | 2 | 6 | 4 | 12 |
| RECTANGLE [31] | 33 | 4 | 31 | 4 | 33 | 4 | 2 | 5 | 4 | 11 |
| SKINNY [32] | 32 | 4 | 30 | 4 | 32 | 4 | 2 | 5 | 4 | 11 |
| S-Box | LIGHTER-R [2] | DORCIS [3] | ADOQ |
|---|---|---|---|
| ASCON [6]-5 qubits | - | - | 273 |
| AES [7]-8 qubits | - | - | 6093 |
| Resources | Baseline (Input) | After MCT Decomposition | After Bi-Directional/Ancilla Optimization | After SA Optimization | |
|---|---|---|---|---|---|
| Qubits | 5 | 5 | 5 | 5 | |
| Ancilla Qubits | – | 2 | 5 | 5 | |
| Gates | X (NOT) | 1 | 1 | 1 | 1 |
| CX (CNOT) | 20 | 20 | 28 | 28 | |
| CCX (Toffoli) | 14 | 43 | 43 | 43 | |
| C3X (MCT) | 9 | – | – | – | |
| C4X (MCT) | 2 | – | – | – | |
| SUM | 46 | 64 | 72 | 72 | |
| Depth | 46 | 54 | 52 | 51 | |
| Weighted Depth | – | 300 | 286 | 273 |
| Resources | Baseline (Input) | After MCT Decomposition | After Bi-Directional/Ancilla Optimization | After SA Optimization | |
|---|---|---|---|---|---|
| Qubits | 8 | 8 | 8 | 8 | |
| Ancilla Qubits | – | 5 | 9 | 9 | |
| Gates | X (NOT) | 3 | 3 | 3 | 3 |
| CX (CNOT) | 297 | 297 | 473 | 433 | |
| CCX (Toffoli) | 165 | 1238 | 1238 | 1238 | |
| C3X (MCT) | 113 | – | – | – | |
| C4X (MCT) | 95 | – | – | – | |
| C5X (MCT) | 59 | – | – | – | |
| C6X (MCT) | 27 | – | – | – | |
| C7X (MCT) | 7 | – | – | – | |
| SUM | 766 | 1538 | 1714 | 1674 | |
| Depth | 724 | 1011 | 980 | 969 | |
| Weighted Depth | – | 6495 | 6134 | 6093 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Choi, C.; Oh, J.; Lee, S.; Cho, G.; Choi, D. An Automated Synthesis Framework for Benchmarking Quantum Resource Costs of Symmetric-Key Cryptography. Mathematics 2026, 14, 719. https://doi.org/10.3390/math14040719
Choi C, Oh J, Lee S, Cho G, Choi D. An Automated Synthesis Framework for Benchmarking Quantum Resource Costs of Symmetric-Key Cryptography. Mathematics. 2026; 14(4):719. https://doi.org/10.3390/math14040719
Chicago/Turabian StyleChoi, Chanho, Jinseob Oh, SangMan Lee, Geumhwan Cho, and Dooho Choi. 2026. "An Automated Synthesis Framework for Benchmarking Quantum Resource Costs of Symmetric-Key Cryptography" Mathematics 14, no. 4: 719. https://doi.org/10.3390/math14040719
APA StyleChoi, C., Oh, J., Lee, S., Cho, G., & Choi, D. (2026). An Automated Synthesis Framework for Benchmarking Quantum Resource Costs of Symmetric-Key Cryptography. Mathematics, 14(4), 719. https://doi.org/10.3390/math14040719

