- Open Access
Integer factorization via tensor-network Schnorr's sieving
Phys. Rev. A 113, 032418 – Published 11 March, 2026
DOI: https://doi.org/10.1103/d9dl-ctt4
Abstract
Classical public-key cryptography standards rely on the Rivest-Shamir-Adleman (RSA) encryption protocol. The security of this protocol is based on the exponential computational complexity of the most efficient classical algorithms for factoring large semiprime numbers into their two prime components. Here, we address RSA factorization building on Schnorr's mathematical framework where factorization translates into a combinatorial optimization problem. We solve the optimization task via tensor network methods, a quantum-inspired classical numerical technique. This tensor network Schnorr's sieving algorithm displays numerical evidence of polynomial scaling of resources with the bit-length of the semiprime. We factorize RSA numbers up to 100 bits and assess how computational resources scale through numerical simulations up to 130 bits, encoding the optimization problem in quantum systems with up to 256 qubits. Only the high-order polynomial scaling of the required resources limits the factorization of larger numbers. Although these results do not currently undermine the security of the present communication infrastructure, they strongly highlight the urgency of implementing postquantum cryptography or quantum key distribution.
Physics Subject Headings (PhySH)
Article Text
References (55)
- R. L. Rivest, A. Shamir, and L. Adleman, A method for obtaining digital signatures and public-key cryptosystems, Commun. ACM 21, 120 (1978).
- S. D. Galbraith, Mathematics of Public Key Cryptography (Cambridge University Press, Cambridge, England, 2012).
- D. Aggarwal and U. Maurer, Breaking RSA generically is equivalent to factoring, IEEE Trans. Inf. Theory 62, 6251 (2016).
- R. Crandall and C. Pomerance, Prime Numbers: A Computational Perspective, 2nd ed. (Springer, New York, 2006).
- K. Rabah, Review of methods for integer factorization applied to cryptography, J. Appl. Sci. 6, 458 (2006).
- F. Boudot, P. Gaudry, A. Guillevic, N. Heninger, E. Thomé, and P. Zimmermann, The state of the art in integer factoring and breaking public-key cryptography, IEEE Security & Privacy 20, 80 (2022).
- C. Pomerance, A Tale of Two Sieves, in Biscuits of Number Theory, edited by A. Benjamin and E. Brown (American Mathematical Society, Providence, RI, 2009), pp. 85–104.
- P. Stevenhagen, The Number Field Sieve, in Algorithmic Number Theory: Lattices, Number Fields, Curves and Cryptography, Mathematical Sciences Research Institute Publications, edited by J. P. Buhler and P. Stevenhagen (Cambridge University Press, Cambridge, England, 2008), Vol. 44, pp. 83–100.
- T. Kleinjung, K. Aoki, J. Franke, A. K. Lenstra, E. Thomé, J. W. Bos, P. Gaudry, A. Kruppa, P. L. Montgomery, D. A. Osvik, H. te Riele, A. Timofeev, and P. Zimmermann, Factorization of a 768-Bit RSA modulus, in Advances in Cryptology–CRYPTO 2010, Lecture Notes in Computer Science, edited by T. Rabin (Springer, Berlin, 2010), Vol. 6223, pp. 333–350.
- F. Boudot, P. Gaudry, A. Guillevic, N. Heninger, E. Thomé, and P. Zimmermann, Comparing the difficulty of factorization and discrete logarithm: A 240-digit experiment, in Advances in Cryptology – CRYPTO 2020, Lecture Notes in Computer Science, edited by D. Micciancio and T. Ristenpart (Springer International, Cham, Switzerland, 2020), Vol. 12171, pp. 62–91.
- P. W. Shor, Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer, SIAM J. Comput. 26, 1484 (1997).
- C. Gidney and M. Ekerå, How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits, Quantum 5, 433 (2021).
- C.-P. Schnorr, Fast Factoring Integers by SVP Algorithms, corrected, Cryptology ePrint Archive, Report 2021/933 (2021).
- L. Babai, On Lovász' lattice reduction and the nearest lattice point problem, Combinatorica 6, 1 (1986).
- B. Yan, Z. Tan, S. Wei, H. Jiang, W. Wang, H. Wang, L. Luo, Q. Duan, Y. Liu, W. Shi, Y. Fei, X. Meng, Y. Han, Z. Shan, J. Chen, X. Zhu, C. Zhang, F. Jin, H. Li, C. Song, et al., Factoring integers with sublinear resources on a superconducting quantum processor, arXiv:2212.12372.
- P. Silvi, F. Tschirsich, M. Gerster, J. Jünemann, D. Jaschke, M. Rizzi, and S. Montangero, The tensor networks anthology: Simulation techniques for many-body quantum lattice systems, SciPost Phys. Lect. Notes 8, 8 (2019).
- M. Ballarin, P. Silvi, S. Montangero, and D. Jaschke, Optimal sampling of tensor networks targeting wave function's fast decaying tails, Quantum 9, 1714 (2025).
- C.-P. Schnorr, Factoring integers and computing discrete logarithms via diophantine approximation, in Advances in Cryptology—EUROCRYPT '91, Lecture Notes in Computer Science Vol. 547, edited by D. W. Davies (Springer, Berlin, 1991), pp. 281–293.
- P. van Emde-Boas, Another NP-Complete Partition Problem and the Complexity of Computing Short Vectors in a Lattice, Technical Report (Department of Mathematics, University of Amsterdam, Amsterdam, The Netherlands, 1981).
- D. Micciancio, The hardness of the closest vector problem with preprocessing, IEEE Trans. Inf. Theory 47, 1212 (2001).
- U. Schollwöck, The density-matrix renormalization group in the age of matrix product states, Ann. Phys. (N.Y.) 326, 96 (2011).
- S. Montangero, Introduction to Tensor Network Methods: Numerical Simulations of Low-Dimensional Many-Body Quantum Systems (Springer, Cham, Switzerland, 2018).
- S. V. Grebnev, M. A. Gavreev, E. O. Kiktenko, A. P. Guglya, A. R. Efimov, and A. K. Fedorov, Pitfalls of the sublinear QAOA-based factorization algorithm, IEEE Access 11, 134760 (2023).
- T. Khattar and N. Yosri, A comment on “Factoring integers with sublinear resources on a superconducting quantum processor”, arXiv:2307.09651.
- W. Aboumrad, D. Widdows, and A. Kaushik, Quantum and classical combinatorial optimizations applied to lattice-based factorization, arXiv:2308.07804.
- D. Coppersmith, Solving linear equations over GF(2): Block Lanczos algorithm, Linear Algebra Appl. 192, 33 (1993).
- S. Yang, An improvement of Babai's rounding procedure for CVP, Int. J. Netw. Secur. 25, 332 (2023).
- A. K. Lenstra, J. Lenstra, H. W. Lenstra, Jr., and L. Lovász, Factoring polynomials with rational coefficients, Math. Ann. 261, 515 (1982).
- Y. Y. Shi, L.-M. Duan, and G. Vidal, Classical simulation of quantum many-body systems with a tree tensor network, Phys. Rev. A 74, 022320 (2006).
- Quantum TEA, Quantum tea–the quantum tensor network emulator applications (2025), Accessed: September 29, 2025, https://www.quantumtea.it/.
- F. Baccari, D. Bacilieri, M. Ballarin, F. P. Barone, F. Campaioli, A. G. Catalano, G. Cataldi, A. Coppi, A. Costantini, A. Datta, A. D. Girolamo, D. Jaschke, S. B. Kožić, G. Magnifico, C. Mordini, S. Montangero, S. Notarnicola, A. Pagano, L. Pavesic, D. Rattacaso, et al., Quantum tea: Qtealeaves (2025), https://doi.org/10.5281/zenodo.14883066.
- G. V. Bard, Algebraic Cryptanalysis (Springer, New York, 2009).
- C. Pomerance, Smooth numbers and the quadratic sieve, in Algorithmic Number Theory: Lattices, Number Fields, Curves and Cryptography, MSRI Publications Vol. 44, edited by J. P. Buhler and P. Stevenhagen (Cambridge University Press, Cambridge, England, 2008), pp. 69–81.
- L. Ducas, SchnorrGate, GitHub repository (2022), Accessed: June 14, 2024, https://github.com/lducas/SchnorrGate.
- B. Kaliski, RSA factoring challenge, in Encyclopedia of Cryptography and Security, edited by H. C. A. van Tilborg (Springer, Boston, 2005), pp. 531–532.
- N. Klein, Big Primes (2024), Accessed: June 14, 2024, www.bigprimes.org.
- The Development of the Number Field Sieve, Lecture Notes in Mathematics, edited by A. K. Lenstra and H. W. Lenstra (Springer, Berlin, 1993), Vol. 1554.
- J. Wagstaff, S. S., The Joy of Factoring, Student Mathematical Library (American Mathematical Society, Providence, RI, 2013), Vol. 68.
- E. Farhi, J. Goldstone, and S. Gutmann, A quantum approximate optimization algorithm, arXiv:1411.4028.
- K. Blekos, D. Brand, A. Ceschini, C.-H. Chou, R.-H. Li, K. Pandya, and A. Summer, A review on quantum approximate optimization algorithm and its variants, Phys. Rep. 1068, 1 (2024).
- A. Lucas, Ising formulations of many NP problems, Front. Phys. 2, 5 (2014).
- R. Orús, A practical introduction to tensor networks: Matrix product states and projected entangled pair states, Ann. Phys. (N.Y.) 349, 117 (2014).
- M. L. Wall and L. D. Carr, Out-of-equilibrium dynamics with matrix product states, New J. Phys. 14, 125015 (2012).
- P. C. G. Vlaar and P. Corboz, Simulation of three-dimensional quantum systems with projected entangled-pair states, Phys. Rev. B 103, 205137 (2021).
- J. Tindall, M. Fishman, E. Miles Stoudenmire, and D. Sels, Efficient tensor network simulation of IBM's Eagle kicked Ising experiment, PRX Quantum 5, 010308 (2024).
- T. Felser, P. Silvi, M. Collura, and S. Montangero, Two-dimensional quantum-link lattice quantum electrodynamics at finite density, Phys. Rev. X 10, 041040 (2020).
- G. Magnifico, T. Felser, P. Silvi, and S. Montangero, Lattice quantum electrodynamics in (3+1)-dimensions at finite density with tensor networks, Nat. Commun. 12, 3600 (2021).
- S. Cavinato, T. Felser, M. Fusella, M. Paiusco, and S. Montangero, Optimizing radiotherapy plans for cancer treatment with tensor networks, Physics in Medicine & Biology 66, 125015 (2021).
- D. Jaschke, M. L. Wall, and L. D. Carr, Open source matrix product states: Opening ways to simulate entangled many-body quantum systems in one dimension, Comput. Phys. Commun. 225, 59 (2018).
- E. M. Stoudenmire and S. R. White, Minimally entangled typical thermal state algorithms, New J. Phys. 12, 055026 (2010).
- F. Verstraete, J. J. García-Ripoll, and J. I. Cirac, Matrix product density operators: Simulation of finite-temperature and dissipative systems, Phys. Rev. Lett. 93, 207204 (2004).
- M. Zwolak and G. Vidal, Mixed-state dynamics in one-dimensional quantum lattice systems: A time-dependent superoperator renormalization algorithm, Phys. Rev. Lett. 93, 207205 (2004).
- A. H. Werner, D. Jaschke, P. Silvi, M. Kliesch, T. Calarco, J. Eisert, and S. Montangero, Positive tensor network approach for simulating open quantum many-body systems, Phys. Rev. Lett. 116, 237201 (2016).
- M. R. Chernick, Bootstrap Methods: A Guide for Practitioners and Researchers, 2nd ed., Wiley Series in Probability and Statistics (John Wiley & Sons, Hoboken, NJ, 2008).
- S. M. Bhattacharjee and F. Seno, A measure of data collapse for scaling, J. Phys. A: Math. Gen. 34, 6375 (2001).