More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Quantum computers can’t realistically halve the security of AES-128 or SHA-256 the way people often say. The confusion comes from Grover’s algorithm, which theoretically cuts search space from 2^n to 2^(n/2). In practice you must serialize each oracle call and can only parallelize by chopping the key space—something that erodes the quadratic speedup. If you throw enough quantum processors at the problem, the total work grows, not shrinks.
Running the numbers with optimistic assumptions—a 1 µs gate time, a decade of runtime, and Liao & Luo’s best-case AES-128 circuit depth of 2^32 T-gates—each instance needs a depth of about 2^64 to finish in ten years. You’d need roughly 1.4×10^14 parallel quantum circuits, each with 724 qubits, to exhaust a 128-bit key. In depth-width terms, that’s astronomically higher than any feasible quantum resource. By comparison, breaking a 256-bit elliptic curve with Shor’s algorithm needs orders of magnitude fewer gates and qubits—you’d crack ECC about 4.3×10^23 times faster than you’d break AES-128 with Grover’s.
NIST uses the same reasoning in its post-quantum standards. It defines AES-128 as Category 13 security and sets MAXDEPTH limits to force any Grover-based attack into unrealistic parallelization. Their IR 8547 roadmap even bars quantum-vulnerable public-key schemes from 2035 forward but keeps all AES key sizes fully approved. In short, experts and standards bodies agree: you don’t need to jump to 256-bit symmetric keys for quantum safety.
Questions about this article
No questions yet.