Design of a silicon quantum computer chip
newsroom.unsw.edu.au
newsroom.unsw.edu.au
So no, they haven't built a many-qubit general quantum computer.
On the other hand, superconducting quantum computers followed the same road that silicon is on right now. It took a couple of years for superconducting qubits to be robust enough to perform universal quantum computation, but it's progress has accelerated in the past couple of years. So this says nothing of how fast silicon quantum computers will progress in the future.
[0]: https://en.wikipedia.org/wiki/Loss%E2%80%93DiVincenzo_quantu...
[1]: https://en.wikipedia.org/wiki/Trapped_ion_quantum_computer#H...
Are there non-classical algorithms with theoretical advantages for biological or climate simulations? Or is this just more hype-nonsense courtesy of the press office?
If anything, fast quantum calculations would make an even bigger difference in materials science than in drug discovery. That's because druglike molecules have been studied a lot, so classical approximations (though limited) at least exist.
"Simulating Physics with Computers", International Journal of Theoretical Physics, volume 21, 1982, p. 467-488, at p. 486 (final words) [0]
The limiting step in being able to manufacture any small organic molecule from raw materials is algorithmic. Imagine a molecule printer that can compile a set of synthesis steps for an arbitrary molecule via simulation. It's not as far-fetched if we can simulate hypothetical reactions easily: http://www.nature.com/news/organic-synthesis-the-robo-chemis...
The other parts of what you're saying are true but don't depend on what happens in quantum computing, they're just part of the for-profit drug industry. There are government and philanthropic drug hunters today who are doing good work, and if they had quantum drug discovery, they would be able to do even more.
The new computing model was later found to be generally useful and applicable to things like climate modeling too.
The simplistic intuition is that there are a lot of exact algorithms which are exponential, so we use clumsy polynomial approximations instead. A quantum computer makes many categories of exponential algorithms polynomial and therefore computable if a big and fast enough quantum computer can be built.
Anyone with more expertise care to point me at a relevant paper?
https://medium.com/@_NicT_/quantum-machine-learning-c5ab31f6...
With respect to biological simulations, researchers at IBM were able to implement artificial life algorithms on a quantum computer [0]. They discuss some potential advantages to simulating life on a quantum computer versus a classical one.
Researchers have also been trying to figure out if quantum computers can be used for weather predictions [1].
[0]: https://arxiv.org/abs/1711.09442
[1]: https://link.springer.com/article/10.3103/S1068373917090011
Genetic algorithms are similar in some regards to simulated annealing. Apparently, D-Wave's approach is kind of like quantum simulated annealing.
https://arstechnica.com/science/2017/01/explaining-the-upsid...
Added: that is, I thought protein conformation energy was pretty well approximated with classical molecular-mechanics models, except during actual chemical reactions, and the difficulty was the sheer amount of time it takes this huge molecule to settle down to an energy minimum that's only a little below that of many alternative conformations. Is the biggest problem rather that we can't efficiently compute a consistent-enough approximation to the energy of a given conformation, so we can't distinguish the best conformation of the ones we simulated?
https://www.youtube.com/watch?v=hFkiMWrA2Bc
So mainstream cryogenics could be a side benefit of technologies like this.
After rereading this, I'm not sure if the ESR itself can perform cooling.
Silicon CMOS architecture for a spin-based quantum computer M. Veldhorst, H. G. J. Eenink, C. H. Yang & A. S. Dzurak Nature Communications 8, Article number: 1766 (2017) doi:10.1038/s41467-017-01905-6
It can be found free at: https://www.nature.com/articles/s41467-017-01905-6
ABSTRACT: "Recent advances in quantum error correction codes for fault-tolerant quantum computing and physical realizations of high-fidelity qubits in multiple platforms give promise for the construction of a quantum computer based on millions of interacting qubits.
However, the classical-quantum interface remains a nascent field of exploration. Here, we propose an architecture for a silicon-based quantum computer processor based on complementary metal-oxide-semiconductor (CMOS) technology. We show how a transistor-based control circuit together with charge-storage electrodes can be used to operate a dense and scalable two-dimensional qubit system.
The qubits are defined by the spin state of a single electron confined in quantum dots, coupled via exchange interactions, controlled using a microwave cavity, and measured via gate-based dispersive readout.
We implement a spin qubit surface code, showing the prospects for universal quantum computation. We discuss the challenges and focus areas that need to be addressed, providing a path for large-scale quantum computing."
I have an idea that might help though: if logical qubits are so difficult to build and require thousands of times more physical qubits, and physical qubits are also difficult to build, perhaps we can simulate physical qubits with thousands of times more "ultra-physical" qubits.
Regarding claims of factoring small numbers: First note that error correction becomes exponentially more important for longer computations. Second, see this
https://arxiv.org/abs/1301.7007
Regarding building a tower of ever less noisy qubits: it turns out there is something called a threshold theorem which requires a certain minimal level of noise before concatenating error correction schemes makes things better rather than worse.
https://en.m.wikipedia.org/wiki/Quantum_threshold_theorem
Reaching this threshold for physical qubits in the laboratory is perhaps the primary goal of experimental quantum computing.
https://www.research.ibm.com/ibm-q/resources/quantum-volume....
With hundreds you can already speed-up chemistry simulations, what will have a much larger impact than breaking RSA.
You can? How?
So it's possible to simulate 25-qubit-level chemistry with a laptop, 50-qubit-level chemistry with a supercomputer, and 100-qubit-level simulation with a supercomputer is impossible and will be impossible for a very long time.
But going from a 50-qubit quantum computer to a 100-qubit one may take just 2 years (or 4, it doesn't really matter), and then another 2 years to get to 200 qubits, and so on. Quantum computers will solve chemistry problems in minutes that would otherwise have taken 100 years to simulate.
I don't think it's a given that just because I want to simulate a quantum mechanical system in some way, that a quantum computer is a useful tool. Or it might be, I don't know. I just don't think it's enough justification that there happens to be the word "quantum" in both the problem description and in the name of the computer.
See this paper for an overview https://arxiv.org/pdf/1203.1331.pdf
I doubt it's just marketing. UNSW is the leading university in researching silicon quantum computers and one of the best in researching quantum computers in general, too.
This tech is aiming to be "mainstream". Google, IBM and others' quantum computers will likely prove useful earlier, but we won't see them be paired with our personal computers. This on the other hand, offers that opportunity, but it will lag behind other types of quantum computers in terms of performance.
But this makes it possible to distribute them at more datacenters that can be much easier to reach than what Google and IBM are creating.
So in principle, there might not be any really fundamental issues preventing such things in every home, with mass production economies making them cheaper and more reliable.
The real question IMHO is whether this will be useful in some way compared to just connecting over the internet to some data center running them.
https://spectrum.ieee.org/tech-talk/computing/hardware/ibms-...
Otherwise, they may claim "quantum supremacy" and 3 months later someone else will prove that the same simulation can be done on a classical computer.
EDIT: sorry guys, I assumed the sarcasm would be transparent. Apologies.
I would say the biggest innovation here is that they have made a silicon based integrated circuit with fault-tolerant qbits (using error-correction codes they invented).
While quantum computers threaten some cryptographic schemes, it will just be the end of those schemes, not the end of cryptography in general (see: post-quantum cryptography). As long as we still have problems that are hard to compute and easy to verify, we can have cryptocurrencies. Quantum computers do not give "unlimited computing power" and do not threaten the existence of cryptocurrencies in general.
We know that Diffie Helmann, RSA and their elliptic counterparts are broken in quantum. That was essentially all we had. I know that 'lattice based cryptography' is a potential option, and believe there are more potential options. However, as far as I know it is not even clear whether these are safe against classical computers.
I should note that I don't know much more about 'lattice based crypto' than the name and the hope it is quantum resistent.
Memory-constrained algorithms, such as scrypt, should be quantum resistant based on what I know (which isn't much). If I'm not horribly misinformed, LTC mining should therefore be resistant. Again, LTC wallets would face problems.
[1]: https://eprint.iacr.org/2017/771.pdf [2]: https://crypto.stackexchange.com/questions/419/what-security... (NB: comments)
There is also no such thing as 'unlimited' computing power with regard to proof of work. Difficulty simply adjusts, and the cost of a network attack will always be related to the rewards of mining.
Remember the exitsanse of quantum computers does not prove P=NP, which is to say, even with quantum computers you can still have the class of problems which are difficult to solve but easy to verify which is the essential component of proof of work.
If it's a couple of thousand orders of magnitude, the first person with a working quantum chip might entirely dominate the hashpower, long before the chip is available commercially. So you'd end up concentrating hashpower into a couple of BigCorps's hands. Like, if I went back in time to the beginning of BTC with an ASIC I'd probably completely dominate the baby blockchain and outcompete the entire network.
https://medium.com/@neha/cryptographic-vulnerabilities-in-io...
https://www.forbes.com/sites/amycastor/2017/09/07/mit-and-bu...
To make things even worse than rolling their own hash function, they're claiming the flaw was intentional! This makes them hostile and untrustworthy to the open source community if this is true and further erodes confidence they know what they're doing if this is their attempt at PR spin:
https://hackernoon.com/why-i-find-iota-deeply-alarming-934f1...
> Next, and in my mind most damningly, Sergey Ivancheglo, Iota’s cofounder, claims that the flaws in the Curl hash function were in fact deliberate; that they were inserted as ‘copy protection’, to prevent copycat projects, and to allow the Iota team to compromise those projects if they sprang up.
The creator requested an open, live debate to put these claims to rest. They haven't accepted and probably won't.
With its use, the scarcity of numbers remain, that is, finding a clash that would allow to forge a transaction stays infeasible, and mining stays hard.
BTW while mining is so important with Bitcoin and Etherium, it's not a necessary part of a cryptocurrency. Mining is an incentive to keep doing blockchain validation. Some currencies exist without it (e.g. NXT).
Post-quantum cryptograph research is a very active area right now. If these researchers do not find a practical signature algorithm, PKI as we know it will change very significantly.
Ironically, blockchains might elevate in importance as a result, since the evolving blockchain is a useful construct for quantum resistance. It has cryptographic agility built in.
Their gates (both single and two qubit gates) are slow and their fidelities currently are below the threshold required for surface codes. There're also big questions about the readout fidelities (which is way low at the moment) and suppressing crosstalk.
That being said, quantum dots in Si/SiGE and SiMOS is a very exciting field these days.
I am not affiliated them, but noticed the listings at http://www.cqc2t.org/employment
> the complete structure is maintained at cryogenic temperatures (∼1 K or less) inside an electron spin resonance (ESR) system, which will be used to apply qubit control pulses.
Either they have made a breakthrough in number theory that allows factorisation over finite fields, or they have a quantum computer already, or they are banking on having one soon. In any case, storage is so cheap that it makes sense to just record the traffic (which is useful for sigint anyway) and refer back to it “if and when”.
Of course, much of what we consider “public-key encrypted” traffic is actually encrypted with a symmetric cipher whose encryption is impervious to Shor’s Algorithm… it is the key-exchange process that really uses the textbook public-key encryption algorithms. So much of the traffic is technically impervious to whatever advances they have made, but of course once you have captured the key-exchange “handshake” that sets up the session and exchanges the symmetric cipher keys, you’re all set to retrieve the plaintext from the intercept.
There are public-key algorithms (particularly those based on lattices) that we currently hold to be secure against attack by quantum computers. I am surprised these are not seeing more adoption amongst the “enlightened paranoid cypherpunk elite”. Here is a primer on such “post-quantum cryptography” approaches, courtesy of the good folks at Wikipedia: https://en.wikipedia.org/wiki/Post-quantum_cryptography
I thought it was a really straightforward obvious idea. I'd do it if I were them and had such deep pockets.
QC is clearly coming. Lots of news lately.
Btw on post quantum crypto: the problem is that most of it has not yet had enough conventional cryptanalysis. Makes no sense to use an algorithm immune to quantum speedup if it's conventionally vulnerable.
You do need to update yourself. There are standard gates, complete computation theories, and algorithms for lots of interesting problems. Those aren't even new.
The good news is that people have been anticipating this for a while, and there's a lot of study in the field of post-quantum encryption. From what I understand, people have come up with techniques that work (meaning nobody's discovered a reason why they wouldn't work).
The bad news is that this does nothing for the data that we're currently encrypting. There's nothing to stop someone from storing today's encrypted web traffic and decoding it in the future when working quantum computers are capable.
Thanks to Edward Snowden and others, we know that the US government is already hoarding and sifting through data, so I have no doubt that there are plenty of agencies planning on doing this exact thing.
Also, there's some related discussion in the amazing cinematographic masterpiece that is Sneakers: http://www.imdb.com/title/tt0105435/