On the Practical cost of Grover for AES Key Recovery

April 12, 2024


Sarah D. - NCSC


It has been estimated that Shor’s algorithm could be used to break 2048-bit RSA in 8 hours on a quantum device with 20 million physical qubits and 256-bit ECDSA in a day on a quantum device with 13 million physical qubits. On the other hand, the best-known quantum key recovery attack against AES uses Grover’s algorithm which provides a generic square-root speed-up over classical exhaustion in terms of the number of AES queries

Presented at

5th PQC Standardization Conference (2024) [in-person]

Event Details


    The NIST PQC conference will be held at the:
    Hilton Washington DC/Rockville Hotel
    1750 Rockville Pike
    Rockville, MD 20852

Created April 11, 2024, Updated April 15, 2024