You are on page 1of 10

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL

NATIONAL SECURITY AGENCY CENTRAL SECURITY SERVICE

(U) CLASSIFICATION GUIDE FOR NSA/CSS QUANTUM COMPUTING RESEARCH 10-2

E!!"#$%&" D'$"( 21 S")$"*+", 2011 R"&%-". D'$"(-)(

CLASSIFIED BY( //-//

REASON FOR CLASSIFICATION( 129 (#), (8) DECLASSIFY ON( 2 7"',-:

ENDORSED BY(

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL


(U) C1'68" R"8%-$",
C1'68" N32 C1'68" D'$" M'."
**/../77

B7
(%6%$%'/-)

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL


CLASSIFICATION GUIDE TITLE/NUMBER( (U) NSA/CSS Q5'6$5* C3*)5$%68 R"-"',#1, 10-2 PUBLICATION DATE( (U) 21 S")$"*+", 2011 OFFICE OF ORIGIN( (U) T1" L'+3,'$3,7 !3, P17-%#'/ S#%"6#"-/R= POC( (U//FOUO) ORIGINAL CLASSIFICATION AUTHORITY( (U) , C3**56%$7 I6$"8,'$%36, P3/%#7 '6. R"#3,.,

(U//FOUO) This document establishes information security guidelines on NSA/CSS-s onsored research in the field of !uantum com uting ("C)# The ob$ecti%es defining the sco e of this research acti%ity are& ') (S//()*) To assess if it is to NSA+s benefit to continue research into ,hether ractical-scale "C can be de%elo ed ,ithin a reasonable timeframe- to identify its most romising hysical embodiment(s)- and to formulate a credible scenario for its large-scale de%elo ment. /) (U//FOUO) To gain an understanding of the com utational cry tanalytic ca abilities of !uantum com uters. and 0) (U//FOUO) To identify ractical cry togra hic methods that are not susce tible to !uantum com utational attac1# (S//()*) These guidelines do not co%er the ossibility of large-scale cry tologic "C de%elo ment rograms at NSA- but only the research and lanning reliminary to- and in ossible su ort of- such rograms# (S//S2//()*) 3uch of the research in !uantum com uting is still %ery basic and is most effecti%ely ursued in NSA-funded o en research rograms# These rograms lay a critical role as the ma$or source of ne, ideas and for training future researchers in the field# 4o,e%er- NSA is ursuing more than $ust basic- unclassified research# NSA is also attem ting to reser%e the S252NT otential of !uantum com uting (i#e#- the cry tanalytic a lications of "C) ,hile simultaneously attem ting to rotect the information security of both the 5o%ernment and ri%ate sectors against hostile "C attac1s (i#e#- the cry togra hic- mission assurance a lications of "C of interest to the 2nformation Assurance community)# These goals must be ursued at the classified le%el#
(U//FOUO) There are se%eral fundamental reasons for classifying "C research&

') (TS//S2//()*) To rotect NSA+s efforts to de%elo cry tanalytic "C to attac1 highgrade ublic 1ey encry tion systems by denying ad%ersaries information concerning NSA+s assessment of- and/or lans for- large-scale "C de%elo ment.

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL


/) (S//()*) To enable us to trac1 our ad%ersaries+ degree of success or failure in similar "C de%elo ment efforts. and 0) (U//FOUO) To rotect our o,n systems against ad%ersarial cry tanalytic "C efforts# (S//()*) 6ased on this- the distinctions bet,een unclassified and classified information contained in this guide attem t to differentiate bet,een unclassified basic-le%el- academic-scale research of scientific interest- and more com rehensi%e classified research ,hich might disclose techni!ues that may other,ise be ossible to rotect- or ,hich might im ly- rightly or ,ronglyserious intent on NSA+s art to ursue large-scale de%elo ment of cry tanalytic !uantum com uters#
D"-#,%)$%36 3! I6!3,*'$%36 C/'--%!%#'$%36/ M',4%68UNC*ASS2F2)8
C'$"83,7

D"#/'--

R"*',4-

A2 (U) G"6",'/
A#'# (U) The fact that NSA& N/A N/A

(U) Ac1no,ledges the otential of "uantum Com uting ("C) in the field of cry tanalysis# (U) Trac1s the de%elo ment of "C technology# (U) Conducts "C research# (U) Funds selected "C research of uns ecified e7ternal entities# (U) Conducts and s onsors research in "C mathematics and algorithms- com le7ity theory- e7 erimental hysicstheoretical hysics- controland/or error correction#

(U) 8etails may re!uire handling as UNC*ASS2F2)8//FO( OFF2C2A* US) ON*9 or may be classified#

(U) 8iscusses "C theory ,ith uns ecified e7ternal researchers ,ithin and outside the United States# A#/# (U//FOUO) The fact that UNC*ASS2F2)8//FO( NSA conducts unspecified OFF2C2A* US) ON*9 classified research in "C ,ith no additional details# (U) Cooperation With Other Organizations A#0# (U//FOUO) The fact that UNC*ASS2F2)8 NSA coo erates ,ith other U#S# organi:ations (e#g#- academic organi:ations- national laboratories- and other U#S# intelligence agencies) on basicunclassified "C research ,ithout

N/A

N/A

(U) 8etails may re!uire classification and may be com artmented# (U) 8etails- including s ecifying ,hich U#S# organi:ation- may re!uire handling as UNC*ASS2F2)8//FO( OFF2C2A* US) ON*9 or may be classified#

N/A

N/A

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL


additional details# A#;# (U//FOUO) The fact that NSA coo erates ,ith the Second <arty artners on basicunclassified "C research ,ithout additional details# A#=# (U//FOUO) The fact that NSA coo erates ,ith other U#S# organi:ations (e#g#- academic organi:ations- national laboratories- and other U#S# intelligence agencies) or Second <arty artners- on classified "C research# (U) Research Information A#># (U) 8etails regarding or results of NSA-conducted or -s onsored unclassified research# A#?# (U//FOUO) Non-technical details (e#g#- scheduling) regarding NSA-conducted or -s onsored classified "C research# A#B# (U//FOUO) Technical details regarding or results of NSAconducted or -s onsored classified "C research# A#C# (U) The e7istence of a s ecific classified "C research ro$ect# A#'D# (U//FOUO) Any information relating to a determination that "C is or is not cry tologically useful to NSA# A#''# (U) The reason for a significant change in si:e or direction of the NSA "C research rogram# (U) Breakthroughs A#'/# (U//FOUO) The fact of or s ecific details of changes in NSA+s understanding of the li1elihood- timescale- re!uired resources- or method of im lementation of cry tanalyticscale "C because of a brea1through achie%ed through o en research# A#'0# (U//FOUO) The fact of a change in NSA+s understanding of the li1elihood- timescale- re!uired resources- or method of im lementation of cry tanalyticUNC*ASS2F2)8// FO( OFF2C2A* US) ON*9 UNC*ASS2F2)8// FO( OFF2C2A* US) ON*9 See (emar1s N/A N/A (U//FOUO) 8etails- such as the articulars of research $ointly underta1en by NSA and a s ecified Second <arty artnermay be classified# (U) 8etails- including s ecifying ,hich U#S# organi:ations or Second <arty artners- may be classified# Coordination ,ith the other arty may be re!uired to arri%e at a mutually-agreeable classification# (U) 2nformation is generally UNC*ASS2F2)8- e7ce t for information on brea1throughs# See A#'/ belo,# (U) 8etails may re!uire higher classification# (U) 8etails (e#g#- cry tanalytic a lications) on s ecific research may re!uire higher classification and/or com artmentation# (U) 4igher classification and/or com artmentation may be re!uired to rotect s ecific ro$ects# (U//FOUO) For e7am le- the fact that NSA decides to fund or not to fund a s ecific classified "C research ro$ect ,ould be classified S)C()T//()* TO USA- F@)9 or higher# (U) 8etails may re!uire higher classification and/or com artmentation# (U) Analysis by NSA of the significance of a brea1through ,ill normally re!uire classification (generally at the S//S2//()* TO USA- F@)9 le%el at a minimum) and/or com artmentation#

N/A

N/A

UNC*ASS2F2)8 See (emar1s CONF28)NT2A*// ()* TO USA- F@)9 at a minimum S)C()T//()* TO USA- F@)9 at a minimum S)C()T// ()* TO USA- F@)9 at a minimum S)C()T//()* TO USA- F@)9 at a minimum See (emar1s CONF28)NT2A*// ()* TO USA- F@)9 at a minimum UNC*ASS2F2)8//FO( OFF2C2A* US) ON*9 at a minimum See (emar1s

N/A

N/A

'#; (c)

/= yearsA

'#; (c)

/= yearsA

'#; (c) '#; (c)

/= yearsA /= yearsA

'#; (c)

/= yearsA

N/A

N/A

S)C()T//S2//()* TO USA- F@)9 at a minimum See (emar1s

'#; (c)

/= yearsA

(U) 8etails and significance of the brea1through may re!uire higher classification and/or additional com artmentation#

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL


scale "C because of a brea1through achie%ed through classified research# A#';# (U//FOUO) The s ecific details of a change in NSA+s understanding of the li1elihoodtimescale- re!uired resources- or method of im lementation of cry tanalytic-scale "C because of a brea1through achie%ed through classified research# 6#'# (U) The fact that NSA conducts *e%el A and *e%el 6 "C research ,ith no additional details# # 6#/# (U//FOUO) The fact that *e%el A is unclassified "C research and/or *e%el 6 is classified "C research# 6#0# (S//()*) The fact that NSA defines s ecific limits to distinguish *e%el A "C research from *e%el 6 "C research# 6#;# (S//()*) The s ecific %alues distinguishing *e%el A "C research from *e%el 6 "C research# C#'# (U) The fact that NSAconducted or -s onsored unclassified research has achie%ed a !uantum algorithm im ro%ement of an unclassified classical algorithm ,ith olynomial runtime#

TO< S)C()T//S2// ()* TO USA- F@)9 at a minimum See (emar1s

'#; (c)

/= yearsA

(U) 8etails and significance of the brea1through may re!uire additional com artmentation (e#g#a method of im lementation may le%erage additional e!uities rotected under a com artment)#

B2 (U) L"&"/ A/L"&"/ B QC R"-"',#1


UNC*ASS2F2)8 N/A N/A (U) See the descri tions of *e%el A and *e%el 6 in the 8efinitions section#

UNC*ASS2F2)8//FO( OFF2C2A* US) ON*9 S)C()T//()* TO USA- F@)9 S)C()T//()* TO USA- F@)9

N/A

N/A

'#; (c)

/= yearsA

'#; (c)

/= yearsA

(U//FOUO) The %alues are e7 ected to change o%er time based on achie%ements in the o en community# (U//FOUO) <ublically 1no,n algorithms are generally unclassified# 4o,e%er- because of their rele%ance to NSAEs "C effort or cry tanalytic ca abilitiesim ro%ements to an unclassified algorithm may be rotected as determined on a case-by-case basis# Contact guide <OC# (U) 5eneral algorithm research falls under this category# (U//FOUO) <ublically 1no,n algorithms are generally unclassified# 4o,e%er- because of their rele%ance to NSAEs "C effort or cry tanalytic ca abilitiesim ro%ements to an unclassified algorithm may be rotected as determined on a case-by-case basis# Contact guide <OC# (U//FOUO) A olynomial s eedu of an unclassified algorithm may ma1e some intractable cry tanalytic roblems tractable#

C2 (U) QC A/83,%$1* R"-"',#1


UNC*ASS2F2)8 at a minimum See (emar1s N/A N/A

C#/# (U) The fact that NSAconducted or -s onsored unclassified research has achie%ed a !uantum algorithm im ro%ement of an unclassified classical algorithm yielding a olynomial s eed-u #

UNC*ASS2F2)8 at a minimum See (emar1s

N/A

N/A

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL


C#0# (U) The fact that NSAconducted or -s onsored unclassified research has achie%ed a !uantum algorithm im ro%ement of a classical algorithm yielding a su er- olynomial s eed-u # UNC*ASS2F2)8 at a minimum See (emar1s N/A N/A (U//FOUO) <ublically 1no,n algorithms are generally unclassified# 4o,e%er- because of their rele%ance to NSAEs "C effort or cry tanalytic ca abilitiesim ro%ements to an unclassified algorithm may be rotected as determined on a case-by-case basis by the originating Agency# Contact guide <OC# (U) For e7am le- a olynomial time algorithm for sol%ing 5ra h 2somor hism# (U) For e7am le- it is 1no,n that "C brea1s cry tosystems based on (SA- 8iffie-4ellman- and elli tic cur%e cry tosystems# (U) For assistance in determination- contact guide <OC# S)C()T//()* USAF@)9 at a minimum See (emar1s '#; (c) /= yearsA (U) S ecific designs may re!uire higher classification and/or com artmentation

C#;# (U//FOUO) The fact that NSA has determined that a s ecific classical ublic-1ey cry togra hy design is or is not secure against "C attac1 ,here the security or non-security of the algorithms is ,idely 1no,n and ublicly a%ailable# C#=# (U//FOUO) The fact that NSA has determined that a s ecific classical ublic-1ey cry togra hy design is or is not secure against "C attac1 for algorithms for ,hich the security or non-security is not ,idely 1no,n and ublicly a%ailable#

UNC*ASS2F2)8

N/A

N/A

D2 (U) P,38,'*- '6. P/'68#'# (TS//S2//()*) The e7istence or none7istence of any NSA lan or rogram to build a cry tanalytic-scale !uantum com uter# TO< S)C()T//S2// ()* TO USA- F@)9 at a minimum See (emar1s '#; (c) /= yearsA (U) 8etails indicating s ecific lanning or rogram de%elo ment may re!uire com artmentation#

E2 (U) I6!3,*'$%36 A--5,'6#"


)#'# (U) The fact of a %ulnerability of a s ecific U#S# 5o%ernment cry tosystem to "C attac1# TO< S)C()T See (emar1s '#; (c)(g) /= yearsA (U) (efer to the 2nformation Assurance @ulnerabilities and Fea1nesses Classification 5uide0-D/- B Guly /DD=- concerning foreign releasability of information on cry tanalytic %ulnerabilities of U#S# systems# (U) 8etails may re!uire handling as UNC*ASS2F2)8//FO( OFF2C2A* US) ON*9 or may be classified#

)#/# (U) The fact that NSA is attem ting to design classical ublic-1ey cry togra hy that is secure against "C attac1#

UNC*ASS2F2)8 See (emar1s

N/A

N/A

F2 (U) M'$",%'/F#'# (U) The fact of NSA in%ol%ement in de%elo ing s eciali:ed materials for unclassified "C that ,ould not UNC*ASS2F2)8 N/A N/A

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL


in%ol%e de%elo ing s eciali:ed roduction facilities# F#/# (S//S2//()*) The fact of NSA in%ol%ement in de%elo ing s eciali:ed materials for classified cry tanalytic "C# F#0# (S//S2//()*) The fact of NSA in%ol%ement in de%elo ing s eciali:ed materials for classified cry tanalytic "C that ,ould in%ol%e de%elo ing or using s eciali:ed roduction facilities or rototy es of such facilities# F#;# (S//S2//()*) Technical details regarding NSA de%elo ment of s eciali:ed materials for cry tanalytic "C#

S)C()T//S2//()* TO USA- F@)9 See (emar1s S)C()T//S2//()* TO USA- F@)9 See (emar1s

'#; (c)

/= yearsA

'#; (c)

/= yearsA

(S//S2//()*) Such de%elo ment might include- but is not limited to- isoto ic or im urity urification- defect reductionand/or surface assi%ation# (S//S2//()*) 8e%elo ment of such roduction lants indicates a le%el of NSA commitment to cry tanalytic "C de%elo ment beyond unclassified research# (S//S2//()*) (esulting s eciali:ed materials ,ill generally be handled as S)C()T//S2// ()* TO USA- F@)9. e7ce tionally high- urity material or e7 erimental results may re!uire rotection as TO< S)C()T//S2//()* TO USAF@)9#

S)C()T//S2// ()* TO USA- F@)9 at a minimum See (emar1s

'#; (c)

/=yearsA

A (U) 8eclassification in /= years indicates that the information is classified for /= years from the date a document is created or /= years from the date of this original classification decision,hiche%er is later# (U) DEFINITIONS (U) C,7)$'6'/7-%- - The study of brea1ing codes and ci hers# (S//S2//()*) C,7)$'6'/7$%#-S#'/" - (as a lied to !uantum com uters) *arge enough to erform com utations of actual cry tanalytic im ortance to NSA# A more s ecific definition is li1ely to be com artmented- and ,ill change o%er time# (U) C,7)$38,')17 - The rinci les- means- and methods for rendering lain information unintelligible to the uninitiated and for restoring encry ted information to intelligible form# (U) C,7)$3/387 - The art and science of ma1ing codes/ci hers and brea1ing them-# Cry tology brea1s out into t,o disci lines& cry togra hy (ma1ing or using codes/ci hers) and cry tanalysis (brea1ing codes/ci hers)# (U) D"$'%/". "68%6"",%68 ."-%86 - S ecifications of a set of !ubits and the associated initiali:ation- control- and measurement hard,are and soft,are at a le%el of detail commensurate ,ith the re!uirements of industrial fabrication# (U) F%."/%$7 - <recision of !ubit o erations such as initiali:ation- logic gates- and readout#

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL


(U) H%81-!%."/%$7 N-A5+%$ D"&%#" - An engineered rocessing de%ice that integrates N cou ledhigh-fidelity hysical !ubits- i#e#- !ubits ,ith fidelity of o erations near or beyond the accuracy threshold for efficient error correction# (S//()*) L"&"/ A QC - Unclassified theoretical and/or e7 erimental research in the designhysical im lementation- and o eration of !uantum com uters- as established by the *aboratory for <hysical Sciences/(0# (S//()*) L"&"/ B QC - Classified theoretical and/or e7 erimental research in the designhysical im lementation- and o eration of !uantum com uters- as established by the *aboratory for <hysical Sciences/(0# The boundaries are based on the number and !uality of !ubits- realism and s ecificity of design- control recision- and detail of analysis# Fhile these boundaries may change o%er time- as of the ublication of this guide- the %alues are& (') (S//()*) 8etailed engineering design of =' or more hysical !ubits. (/) (S//()*) 2m lementation and o eration of a high-fidelity /'-or-more hysical-!ubit de%ice. or (0) (S//()*) 2m lementation and o eration of three (0) or more logical !ubits- ,ith sufficient s eed and recision to allo, reser%ation of !uantum information and logical gates bet,een the !ubits# (U) L38%#'/ A5+%$- - Collections of se%eral hysical !ubits configured in a circuit allo,ing detection and correction both of errors and of loss of !uantum coherence# (U) For the ur oses of this guide- the circuit configuration of a logical !ubit must allo, detection and correction of at least all errors affecting any single hysical !ubit# A logical !ubit com rising N hysical !ubits must also be a high-fidelity N-!ubit de%ice# (U) P17-%#'/ A5+%$ - A hysical entity ca able of storing a !ubit of information and being initiali:ed- o erated on- and measured# )7am les include- but are not limited to& hotonselectrons- atoms- atomic nuclei- and su erconducting Gose hson $unctions# (S//S2//()*) P,'#$%#'/-S#'/" - Cry tanalytic-scale- ,ith the added re!uirement that a roadma e7ists to construct the de%ice ,ith a cost- robability of success- and time-scale of actual cry tanalytic im ortance to NSA# A more s ecific definition is li1ely to change o%er time# (U) Q5'6$5* #31","6#" - The fundamental !uantum-mechanical ro erty of !ubits and collections of !ubits ,hich may enable some com utations to be erformed ,ith resources %astly smaller than ,ould be re!uired for classical com uters# (U) Q5'6$5* C3*)5$%68 - Com uting ,ith !uantum o erations on data stored in a collection of !ubits#

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL


(U) Q5'6$5* 8'$"- - *ogic o erations on one or more !ubits that reser%e their !uantum coherent character# (U) Q5+%$ - A H!uantum bit-I the fundamental unit of information in a !uantum com uter#

TOP SECRET//SI//REL TO USA, AUS, CAN, GBR, NZL