Can Quantum Break ZUC? Only with a Million Qubits and a Billion Years to Spare
(2026) 28th International Conference on Information Security and Cryptology, ICISC 2025 In Lecture Notes in Computer Science 16487 LNCS. p.295-324- Abstract
The ZUC stream cipher is integral to modern mobile communication standards, including 4G and 5G, providing secure data transmission across global networks. Recently, Dutta et al. (Indocrypt, 2024) presented the first quantum resource estimation of ZUC under Grover’s search, although preliminary, this work marks the beginning of quantum security analysis for ZUC. In this paper, we present an improved quantum resource estimation for ZUC, offering tighter bounds for Grover-based exhaustive key search. Beyond traditional quantum resource estimations, we also provide a concrete timescale required to execute such attacks using the specified quantum resources. Our findings show that a full-round, low depth implementation of ZUC-128 can be... (More)
The ZUC stream cipher is integral to modern mobile communication standards, including 4G and 5G, providing secure data transmission across global networks. Recently, Dutta et al. (Indocrypt, 2024) presented the first quantum resource estimation of ZUC under Grover’s search, although preliminary, this work marks the beginning of quantum security analysis for ZUC. In this paper, we present an improved quantum resource estimation for ZUC, offering tighter bounds for Grover-based exhaustive key search. Beyond traditional quantum resource estimations, we also provide a concrete timescale required to execute such attacks using the specified quantum resources. Our findings show that a full-round, low depth implementation of ZUC-128 can be realized with a maximum of 375 ancilla qubits, a T-count of 106536, and a T-depth of 15816. Furthermore, the Grover-based key search can be performed most efficiently using 1201 logical qubits, 170681 T gates, and a T-depth of 78189, resulting in a runtime of 1.78×1011 years, an improvement of 93.43% over the estimated 2.71×1012 years by the implementation given by Dutta et al., we also provide akin analysis for ZUC-256 with an 99.23% decrease in time. These estimations are done assuming state-of-the-art superconducting qubit error-correcting technology.
(Less)
- author
- Bhaumik, Anik Basu
; Dutta, Suman
; Jang, Kyungbae
; Baksi, Anubhab
LU
; Wang, Siyi
; Saha, Amit
; Seo, Hwajeong
and Chattopadhyay, Anupam
- organization
- publishing date
- 2026
- type
- Chapter in Book/Report/Conference proceeding
- publication status
- published
- subject
- keywords
- Fault-tolerant quantum computing, Grover’s algorithm, Quantum circuit optimisation, Resource estimation, Space-depth trade-offs, Surface code, ZUC stream cipher
- host publication
- Information Security and Cryptology – ICISC 2025 : 28th International Conference, Revised Selected Papers - 28th International Conference, Revised Selected Papers
- series title
- Lecture Notes in Computer Science
- editor
- Seo, Hwajeong
- volume
- 16487 LNCS
- pages
- 30 pages
- publisher
- Springer Science and Business Media B.V.
- conference name
- 28th International Conference on Information Security and Cryptology, ICISC 2025
- conference location
- Seoul, Korea, Republic of
- conference dates
- 2025-11-19 - 2025-11-21
- external identifiers
-
- scopus:105040535897
- ISSN
- 0302-9743
- 1611-3349
- ISBN
- 9789819580330
- DOI
- 10.1007/978-981-95-8034-7_16
- language
- English
- LU publication?
- yes
- id
- 6306a763-9686-41bb-93b2-74b8fa32278b
- date added to LUP
- 2026-09-21 12:12:22
- date last changed
- 2026-09-21 12:12:49
@inproceedings{6306a763-9686-41bb-93b2-74b8fa32278b,
abstract = {{<p>The ZUC stream cipher is integral to modern mobile communication standards, including 4G and 5G, providing secure data transmission across global networks. Recently, Dutta et al. (Indocrypt, 2024) presented the first quantum resource estimation of ZUC under Grover’s search, although preliminary, this work marks the beginning of quantum security analysis for ZUC. In this paper, we present an improved quantum resource estimation for ZUC, offering tighter bounds for Grover-based exhaustive key search. Beyond traditional quantum resource estimations, we also provide a concrete timescale required to execute such attacks using the specified quantum resources. Our findings show that a full-round, low depth implementation of ZUC-128 can be realized with a maximum of 375 ancilla qubits, a T-count of 106536, and a T-depth of 15816. Furthermore, the Grover-based key search can be performed most efficiently using 1201 logical qubits, 170681 T gates, and a T-depth of 78189, resulting in a runtime of 1.78×10<sup>11</sup> years, an improvement of 93.43% over the estimated 2.71×10<sup>12</sup> years by the implementation given by Dutta et al., we also provide akin analysis for ZUC-256 with an 99.23% decrease in time. These estimations are done assuming state-of-the-art superconducting qubit error-correcting technology.</p>}},
author = {{Bhaumik, Anik Basu and Dutta, Suman and Jang, Kyungbae and Baksi, Anubhab and Wang, Siyi and Saha, Amit and Seo, Hwajeong and Chattopadhyay, Anupam}},
booktitle = {{Information Security and Cryptology – ICISC 2025 : 28th International Conference, Revised Selected Papers}},
editor = {{Seo, Hwajeong}},
isbn = {{9789819580330}},
issn = {{0302-9743}},
keywords = {{Fault-tolerant quantum computing; Grover’s algorithm; Quantum circuit optimisation; Resource estimation; Space-depth trade-offs; Surface code; ZUC stream cipher}},
language = {{eng}},
pages = {{295--324}},
publisher = {{Springer Science and Business Media B.V.}},
series = {{Lecture Notes in Computer Science}},
title = {{Can Quantum Break ZUC? Only with a Million Qubits and a Billion Years to Spare}},
url = {{http://dx.doi.org/10.1007/978-981-95-8034-7_16}},
doi = {{10.1007/978-981-95-8034-7_16}},
volume = {{16487 LNCS}},
year = {{2026}},
}