Abstract: Grover’s algorithm provides a quantum attack against block ciphers by searching for a k-bit key using \(O(\sqrt{2^k})\) calls to the cipher, when given a small number of plaintext-ciphertext pairs. Recent works by Grassl et al. in PQCrypto’16 and Almazrooie et al. in QIP’18 have estimated the cost of this attack against AES by analyzing the quantum circuits of the cipher.
Loading