English

On the success probability of quantum order finding

Quantum Physics 2024-06-07 v2 Computational Complexity Cryptography and Security

Abstract

We prove a lower bound on the probability of Shor's order-finding algorithm successfully recovering the order rr in a single run. The bound implies that by performing two limited searches in the classical post-processing part of the algorithm, a high success probability can be guaranteed, for any rr, without re-running the quantum part or increasing the exponent length compared to Shor. Asymptotically, in the limit as rr tends to infinity, the probability of successfully recovering rr in a single run tends to one. Already for moderate rr, a high success probability exceeding e.g. 11041 - 10^{-4} can be guaranteed. As corollaries, we prove analogous results for the probability of completely factoring any integer NN in a single run of the order-finding algorithm.

Keywords

Cite

@article{arxiv.2201.07791,
  title  = {On the success probability of quantum order finding},
  author = {Martin Ekerå},
  journal= {arXiv preprint arXiv:2201.07791},
  year   = {2024}
}

Comments

This revision resolves a minor issue in Alg. 4, and addresses a number of other minor issues. It furthermore adds a number of extensions and clarifications, in particular with respect to potential optimizations. No key results or findings in the original version of the manuscript are affected by this revision

R2 v1 2026-06-24T08:55:37.814Z