What Has Quantum Mechanics to Do With Factoring? Things I wish they had told me about Peter Shor s algorithm



Similar documents
Quantum Computing Lecture 7. Quantum Factoring. Anuj Dawar

Introduction to computer science

Bits Superposition Quantum Parallelism

0.1 Phase Estimation Technique

Breaking The Code. Ryan Lowe. Ryan Lowe is currently a Ball State senior with a double major in Computer Science and Mathematics and

Factoring by Quantum Computers

Notes on Factoring. MA 206 Kurt Bryan

QUANTUM COMPUTERS AND CRYPTOGRAPHY. Mark Zhandry Stanford University

Quantum Algorithms in NMR Experiments. 25 th May 2012 Ling LIN & Michael Loretz

8 Primes and Modular Arithmetic

Shor s algorithm and secret sharing

Primes. Name Period Number Theory

Lecture 1 Version: 14/08/28. Frontiers of Condensed Matter San Sebastian, Aug , Dr. Leo DiCarlo l.dicarlo@tudelft.nl dicarlolab.tudelft.

Introduction to Quantum Computing

The finite field with 2 elements The simplest finite field is

Quantum Computing. Robert Sizemore

A Recent Improvements in Quantum Model and Counter Measures in Quantum Computing

Quotient Rings and Field Extensions

U.C. Berkeley CS276: Cryptography Handout 0.1 Luca Trevisan January, Notes on Algebra

Math Review. for the Quantitative Reasoning Measure of the GRE revised General Test

POLYNOMIALS and FACTORING

= = 3 4, Now assume that P (k) is true for some fixed k 2. This means that

Using quantum computing to realize the Fourier Transform in computer vision applications

The Mathematics of the RSA Public-Key Cryptosystem

Lecture 13: Factoring Integers

PYTHAGOREAN TRIPLES KEITH CONRAD

Quantum Computing Architectures

3 1. Note that all cubes solve it; therefore, there are no more

Some facts about polynomials modulo m (Full proof of the Fingerprinting Theorem)

SUBGROUPS OF CYCLIC GROUPS. 1. Introduction In a group G, we denote the (cyclic) group of powers of some g G by

Factoring Polynomials

Quantum Computers. And How Does Nature Compute? Kenneth W. Regan 1 University at Buffalo (SUNY) 21 May, Quantum Computers

Computational complexity theory

OSTROWSKI FOR NUMBER FIELDS

Chapter 4, Arithmetic in F [x] Polynomial arithmetic and the division algorithm.

arxiv:quant-ph/ v2 25 Jan 1996

Homework until Test #2

An Overview of Integer Factoring Algorithms. The Problem

CHAPTER SIX IRREDUCIBILITY AND FACTORIZATION 1. BASIC DIVISIBILITY THEORY

Revised Version of Chapter 23. We learned long ago how to solve linear congruences. ax c (mod m)

Chapter 11 Number Theory

Examples of Functions

Faster deterministic integer factorisation

Monday January 19th 2015 Title: "Transmathematics - a survey of recent results on division by zero" Facilitator: TheNumberNullity / James Anderson, UK

The Method of Partial Fractions Math 121 Calculus II Spring 2015

Integer Operations. Overview. Grade 7 Mathematics, Quarter 1, Unit 1.1. Number of Instructional Days: 15 (1 day = 45 minutes) Essential Questions

Chapter 7 - Roots, Radicals, and Complex Numbers

a 11 x 1 + a 12 x a 1n x n = b 1 a 21 x 1 + a 22 x a 2n x n = b 2.

Factoring Algorithms

7. Show that the expectation value function that appears in Lecture 1, namely

Elementary factoring algorithms

Lecture 13 - Basic Number Theory.

The majority of college students hold credit cards. According to the Nellie May

Partial Fractions. Combining fractions over a common denominator is a familiar operation from algebra:

Mathematics Course 111: Algebra I Part IV: Vector Spaces

SOLUTIONS FOR PROBLEM SET 2

Polynomials and Factoring. Unit Lesson Plan

Learning Objectives 9.2. Media Run Times 9.3

Quantum Computing and Grover s Algorithm

Modern Factoring Algorithms

Keywords Quantum logic gates, Quantum computing, Logic gate, Quantum computer

The van Hoeij Algorithm for Factoring Polynomials

March 29, S4.4 Theorems about Zeros of Polynomial Functions

High School Algebra Reasoning with Equations and Inequalities Solve equations and inequalities in one variable.

Factoring Algorithms

THE NUMBER OF REPRESENTATIONS OF n OF THE FORM n = x 2 2 y, x > 0, y 0

Primality - Factorization

South Carolina College- and Career-Ready (SCCCR) Pre-Calculus

Performance Assessment Task Which Shape? Grade 3. Common Core State Standards Math - Content Standards

Factoring & Primality

5544 = = = Now we have to find a divisor of 693. We can try 3, and 693 = 3 231,and we keep dividing by 3 to get: 1

Study of algorithms for factoring integers and computing discrete logarithms

Binary Division. Decimal Division. Hardware for Binary Division. Simple 16-bit Divider Circuit

Solve addition and subtraction word problems, and add and subtract within 10, e.g., by using objects or drawings to represent the problem.

If A is divided by B the result is 2/3. If B is divided by C the result is 4/7. What is the result if A is divided by C?

RSA Encryption. Tom Davis October 10, 2003

Quantum Computers vs. Computers

CORRELATED TO THE SOUTH CAROLINA COLLEGE AND CAREER-READY FOUNDATIONS IN ALGEBRA

Elementary Number Theory and Methods of Proof. CSE 215, Foundations of Computer Science Stony Brook University

MATH Fundamental Mathematics IV

RSA Question 2. Bob thinks that p and q are primes but p isn t. Then, Bob thinks Φ Bob :=(p-1)(q-1) = φ(n). Is this true?

1. I have 4 sides. My opposite sides are equal. I have 4 right angles. Which shape am I?

parent ROADMAP MATHEMATICS SUPPORTING YOUR CHILD IN HIGH SCHOOL

Ummmm! Definitely interested. She took the pen and pad out of my hand and constructed a third one for herself:

Chapter 3. if 2 a i then location: = i. Page 40

Introduction to Finite Fields (cont.)

Chapter 1. Computation theory

Cryptography and Network Security Department of Computer Science and Engineering Indian Institute of Technology Kharagpur

Quantum Algorithms Lecture Notes Summer School on Theory and Technology in Quantum Information, Communication, Computation and Cryptography

Lukasz Pater CMMS Administrator and Developer

COMP 250 Fall 2012 lecture 2 binary representations Sept. 11, 2012

FACTORING LARGE NUMBERS, A GREAT WAY TO SPEND A BIRTHDAY

Computer and Network Security

PROPERTIES OF ELLIPTIC CURVES AND THEIR USE IN FACTORING LARGE NUMBERS

Lagrange Interpolation is a method of fitting an equation to a set of points that functions well when there are few points given.

Linear Codes. Chapter Basics

Grade 5 Math Content 1

6.1 The Greatest Common Factor; Factoring by Grouping

Basic Algorithms In Computer Algebra

Transcription:

What Has Quantum Mechanics to Do With Factoring? Things I wish they had told me about Peter Shor s algorithm 1

Question: What has quantum mechanics to do with factoring? Answer: Nothing! 2

Question: What has quantum mechanics to do with factoring? Answer: Nothing! But quantum mechanics has a lot to do with waves. And waves have a lot to do with periodicity. And being good at diagnosing periodicity has a lot to do with factoring. 3

Case of cryptographic interest: Factoring N = pq, where p and q are enormous (e.g. 300 digit) primes. Closely tied to the ability to find the period of a x modulo N for integers a that share no factors with N. 4

Periodic functions a x in modular arithmetic a (mod N) = remainder when a divided by N 5 = 5 (mod 7) 5 2 = 4 (mod 7) 5 3 = 6 (mod 7) 5 4 = 2 (mod 7) 5 5 = 3 (mod 7) 5 6 = 1 (mod 7) 5 x (mod 7) is periodic with period 6 4 = 4 (mod 7) 4 2 = 2 (mod 7) 4 3 = 1 (mod 7) 4 x (mod 7) is periodic with period 3 6 = 6 (mod 7) 6 2 = 1 (mod 7) 6 x (mod 7) is periodic with period 2 2 x (mod 7) has period 3 3 x (mod 7) has period 6 5

Periods mod N, where N = pq, and p and q are enormous primes. If a shares no factors with N then a s 1 (mod N) for some integer s, For there are only N different mod N numbers, so there must be x and y > x with a y = a x (mod N). Then a x (a s 1) is a multiple of N, y = x + s. Since a shares no factors with N, neither does a x, so a s 1 must be multiple of N: a s = 1 (mod N) If r is the smallest integer with a r 1 (mod N) then a x (mod N) is a periodic function of x with period r. 6

Digression: The reason all periods modulo 7 divide 6: If p is prime all a < p share no factors with p, so a r = 1 (mod p) for some (smallest positive) r a has an inverse (mod p). So the p 1 integers, 1, 2,... p 1 are a group under multiplication (mod p). The r distinct powers of a are a subroup of that group. And the number of members of any subgroup divides the number of members of the whole group. 7

Further digression: Periods modulo N = pq divide (p 1)(q 1) There are pq 1 integers less than pq. Among them are p 1 multiples of q, and another q 1 multiples of p. So the number of integers a < pq that share no factors with pq is (pq 1) (p 1) (q 1) = pq p q + 1 = (p 1)(q 1). These (p 1)(q 1) integers are a group under multiplication modulo pq. The r distinct powers of a are a subgroup of that group. And the number of members r of that subgroup divides the number of members (p 1)(q 1) of the group. 8

Back to business: How to factor the product of two enormous primes, N = pq, using a good period-finding machine (e.g. a quantum computer). Pick a random integer a. (It is astronomically unlikely to be multiple of p or q.) Use the period-finding machine to get the smallest r with a r = 1 (mod N). Pray for two pieces of good luck. 9

Quantum computer gives smallest r with a r 1 divisible by N = pq First piece of luck: r even. Then (a r/2 1)(a r/2 + 1) divisible by N. but a r/2 1 is not divisible by N (since r is smallest number with a r 1 divisible by N.) Second piece of luck: a r/2 + 1 is also not divisible by N. Then product of a r/2 1 and a r/2 + 1 is divisible by both p and q although neither factor is divisible by both. Since p, q primes, one factor divisible by p and other divisible by q. So p is greatest common divisor of N and a r/2 1 and q is greatest common divisor of N and a r/2 + 1 FINISHED! 10

Finished, because: 1. Finding the greatest common divisor of two integers can be done by anybody who can do long division using a simple and efficient procedure that was know to the ancient Greeks. 2. If a is picked at random, a two-hour argument shows that the probability is at least 50% that both pieces of luck will hold. New York Times, November 14, 2006: When my oldest child, an A-plus stellar student, was in sixth grade, I realized he had no idea, no idea at all, how to do long division, Ms. Backman said, so I went to school and talked to the teacher, who said, We don t teach long division; it stifles their creativity. N. David Mermin, Introduction to Quantum Computer Science, Appendix M, Cambridge University Press, August, 2007. 11

Incorrect (but amazing): [After the quantum computation] the solutions the factors of the number being analyzed will all be in superposition. George Johnson, A Shortcut Through Time. [A quantum computer will] try out all the possible factors simultaneously, in superposition, then collapse to reveal the answer. Ibid. Correct (but unexciting): A quantum computer is efficient at factoring because it is efficient at period-finding. 12

BUT WHAT S SO HARD ABOUT PERIOD-FINDING? Given a graph of sin(kx) it s easy to find the period 2π/k. Since no value repeats inside a period, a x (mod N) is even simpler. 13

BUT WHAT S SO HARD ABOUT PERIOD-FINDING? Given a graph of sin(kx) it s easy to find the period 2π/k. Since no value repeats inside a period, a x (mod N) is even simpler. What makes it hard: Within a period, unlike the smooth, continuous sin(kx), the function a x (mod N) looks like random noise. Nothing in a list of r consecutive values gives a hint that the next one will be the same as the first. 14

PERIOD FINDING WITH A QUANTUM COMPUTER Represent n bit number x = x 0 + 2x 1 + 4x 2 + + 2 n 1 x n 1 (each x j is 0 or 1) by product of states 0 and 1 of n 2-state systems: x = x n 1 x 1 x 0 Qbits 15

Qbits, not qubits because: 1. Classical two state systems are Cbits (not clbits) 2. Ear cleaners are Qtips (not Qutips) 3. Dirac wrote about q-numbers (not qunumbers) (q-bit awkward: 2-Qbit gate OK; 2-q-bit gate unreadable.) 16

More terminology: Set of states x = x n 1 x 1 x 0 called the computational basis. Better term: classical basis. Remark: Because it is a basis, linear transformations on Qbits can be defined by specifying their action on the classical basis. 17

STANDARD QUANTUM COMPUTATIONAL ARCHITECTURE Represent function f taking n-bit to m-bit integers by a linear, norm-preserving (unitary) transformation U f acting on n-qbit input register and m-qbit output register: input register U f x 0 = x f(x). output register (More generally, U f x y = x y f(x). y z = bitwise modulo 2 sum: 1010 0111 = 1101.) 18

QUANTUM PARALLELISM U f x 0 = x f(x) Put input register into superposition of all possible inputs: φ = ( 1 2 ) n 0 x<2 n x = 1 2 ( 0 + 1 ) 1 2 ( 0 + 1 ). Applying linear U f to input and output registers gives U f ( φ 0 ) = ( 1 2 ) n 0 x<2 n x f(x). e.g. ( 0 + 1 )( 0 + 1 ) = 0 0 + 0 1 + 1 0 + 1 1 19

Question: QUANTUM PARALLELISM U f ( φ 0 ) = ( 1 2 ) n 0 x<2 n x f(x). Has one invocation of U f computed f(x) for all x? 20

Question: Answer: QUANTUM PARALLELISM U f ( φ 0 ) = ( 1 2 ) n 0 x<2 n x f(x). Has one invocation of U f computed f(x) for all x? No. Given a single system in an unknown state, there is no way to learn what that state is. Information is acquired only through measurement. Direct measurement of input register gives random x 0 ; Direct measurement of output register then gives f(x 0 ). 21

QUANTUM PARALLELISM U f ( φ 0 ) = ( 1 2 ) n 0 x<2 n x f(x). Special form when f(x) = a x (mod N): 0 x<2 n x a x = 0 x<r ( ) x + x + r + x + 2r + a x 22

THE QUANTUM FOURIER TRANSFORM (QFT) V F T x = ( 1 2 ) n 0 y<2 n e 2πixy/2 Acting on superpositions, V F T Fourier-transforms amplitudes: n y V F T α(x) x = β(x) x β(x) = ( 1 2 ) n 0 z<2 n e 2πixz/2 n α(z) If α has period r, as in x + x + r + x + 2r +, then β is sharply peaked at integral multiples of 2 n /r. 23

HO-HUM! V F T is boring: 1. Just familiar transformation from position to momentum representation. 2. Everybody knows Fourier transform sharply peaked at multiples of inverse period. But V F T is not ho-humish because: 1. x has nothing to do with position, real or conceptual. x is arithmetically useful but physically meaningless: x = x 0 + 2x 1 + 4x 2 + 8x 3 +, where x j = 0 or 1 is state of j-th 2-state system. 2. Sharp means sharp compared with resolution of apparatus. The period r is hundreds of digits long. Error in r of 1 in 10 10 messes up almost every digit. 24

Using the QFT : V F T x = ( 1 2 ) n 0 y<2 n e 2πixy/2 n y V F T ( 1 2 ) n 0 x<r ( ) x + x + r + x + 2r + a x = = ( ) 1 n ( 2 1 + α + α 2 + α 3 + ) y 0 y<2 n ( ) α = exp 2πiy/(2 n /r). 0 x<r Sum of phases α sharply peaked at values of y within 1 2 of integral multiples of 2n /r. Question: How sharply peaked? e 2πixy/2n a x, Answer: Probability that measurement of input register gives such a value of y exceeds 40%. 25

Significant (> 40%) chance of getting integer y as close as possible to (i.e. within 1 2 of) j(2n /r) for some (more or less) random integer j. Then y/2 n is within 1/2 n+1 of j/r. Question: Does this pin down unique rational number j/r? Answer: It depends. Suppose second candidate, j /r with j /r j/r. j r j = j r jr r rr 1 rr 1 N 2 So answer is Yes, if 2 n > N 2. Input register must be large enough to represent N 2. Then have 40% chance of learning a divisor r 0 of r. (r 0 is r divided by factors it shares with (random) j) 26

A comment: When N = pq, easy to show period r necessarily < N/2. So j r j > 4 r N 2 and therefore don t need y as close as possible to integral multiple of 2 n /r. Second, third, or fourth closest do just as well. Raises probability of learning divisor of r from 40% to 90%. a p 1 = 1 (mod p) a (p 1)(q 1)/2 = 1 (mod p), a q 1 = 1 (mod q) a (q 1)(p 1)/2 = 1 (mod q), a (p 1)(q 1)/2 = 1 (mod pq). 27

Another comment: Should the period r be 2 m, then 2 n /r is itself an integer, and probability of y being multiple of that integer is easily shown to be 1, even if input register contains just a single period. A pathologically easy case. Question: When are all periods r powers of 2? Answer: When p and q are both of form 2 j + 1. (Periods are divisors of (p 1)(q 1).) Therefore factoring 15 = (2 + 1) (4 + 1) i.e. finding periods modulo 15 is not a serious demonstration of Shor s algorithm. 28

SOME NEAT THINGS ABOUT THE QFT V F T x = ( 1 2 ) n 0 y<2 n e 2πixy/2 1. Constructed entirely out of 1-Qbit and 2-Qbit gates. 2. Number of gates (and therefore time) grows only as n 2. 3. With just one application, n y α(x) x β(x) x, β(x) = ( 1 2 ) n 0 z<2 n e 2πixz/2 n α(z) In classical Fast Fourier Transform time grows as n2 n. But (as usual) classical FFT gives all the β(x), While QFT only gives β(x) x. Can t learn any β(x) from one application of QFT. But can get powerful clues about period of α(x). 29

CIRCUIT FOR QUANTUM FOURIER TRANSFORM x 5 x 4 x x 3 V FT x x 2 x 1 x 0 } 0 { 2 1 ( 0 + 1 ) 1 1 2 ( 0 1 ) e πi /2 e πi /4 e πi /8 e πi /16 e πi /32 0 0, 0 1, 1 0 invariant; 1 1 e πi/2j 1 1 30

ACTION OF QFT ON SUPERPOSITION α(x) x β(x) x β(x) = y α(y)e 2πixy/26 Replaces amplitudes by their Fourier transforms. 31

INVERSE OF QFT 32

A PROBLEM? x 5 x 4 x x 3 V FT x x 2 x 1 x 0 e πi /2 e πi /4 e πi /8 e πi /16 e πi /32 Number n of Qbits: 2 n > N 2, N hundreds of digits. Phase gates e πi /2 m impossible to make for most m, since can t control strength or time of interactions to better than parts in 10 10 = 2 30. But need to learn period r to parts in 10 300 or more! 33

Question: So is it all based on a silly mistake? Answer: No, all is well. Question: How can that be? Answer: Because of the quantum-computational interplay between analog and digital. 34

Quantum Computation is Digital Information is acquired only by measuring Qbits. The reading of each 1-Qbit measurement gate is only 0 or 1. The 10 3 bits of the output y of Shor s algorithm are given by the readings (0 or 1) of 10 3 1-Qbit measurement gates. There is no imprecision in those 10 3 readings. The output is a definite 300-digit number. But is it the number you wanted to learn? 35

Quantum Computation is Analog Before a measurement the Qbits are acted on by unitary gates with continuously variable parameters. These variations affect the amplitudes of the states prior to measurement and therefore they affect the probabilities of the readings of the measurement gates. 36

So all is well Huge errors (parts in 10 4 ) in the phase gates may result in comparable errors in the probability that the 300 digit number given precisely by the measurement gates is the right 300 digit number. So the probability of getting a useful number may not be 90% but only 89.99%. Since 90% is actually about 90% this makes no difference. 37

In fact this makes things even better x 5 x 4 x x 3 V FT x x 2 x 1 x 0 e πi /2 e πi /4 e πi /8 e πi /16 e πi /32 Since only the top 20 layers of phase gates can matter, once you get to N > 2 20 = 10 6, the running time scales not quadratically but only linearly in the number of Qbits. 38

Quantum Versus Classical Programming Styles Question: How do you calculate a x when x is a 300 digit number? Answer: Not by multiplying a by itself 10 300 times! How else, then? Write x as a binary number: x = x 999 x 998 x 2 x 1 x 0. Next square a, square the result, square that result,..., getting the 1,000 numbers a 2j. Finally, multiply together all the a 2j for which x j = 1. 999(a ) x j 2j = a j=0 j x j2 j = a x 39

Classical: Cbits Cheap; Time Precious a x = 999(a ) x j 2j j=0 Once and for all, make and store a look-up table: a, a 2, a 4, a 8,..., a 2999 A thousand entries, each of a thousand bits. For each x multiply together all the a 2j for which x j = 1. in the table 40

Quantum: Time Cheap; Qbits Precious Circuit that executes 999 a x = (a ) x j 2j j=0 is not applied 2 n times to input register for each x. It is applied just once to input register in the state φ = ( ) 2 1 n 0 x<2 n x. So after each conditional (on x j = 1) multiplication by a 2j can store ( ) 2 a 2j = a 2 j+1 using same 1000 Qbits that formerly held a 2j. 41

Another Important Simplification 1-Qbit measurement gates y 5 y 4 α(x) x y 3 y 2 y 1 y 0 e πi /2 e πi /4 e πi /8 e πi /16 e πi /32 42

The Important Simplification α(x) x y 0 e πiy 0 /2 e πiy 0 /4 e πiy 0 /8 e πiy 0 /16 e πiy 0 /32 2-Qbit operators replaced by 1-Qbit operators, conditional on measurement outcome. 43

The Important Simplification y 0 α(x) x e πiy 0 /2 e πiy 0 /4 e πiy 0 /8 e πiy 0 /16 e πiy 0 /32 You don t need anything but 1-Qbit gates! 44

Things I wish they had told me about Peter Shor s algorithm (and more general morals for the beginner): 1. Shor algorithm finds periods. Period! Periods factors solely via number-theory. 2. Period-finding is non-trivial for functions that look like random noise within a period. 3. Quantum parallelism doesn t calculate all values of a function using 10 300 computers in parallel universes. 4. Shor s quantum Fourier transform (QFT) doesn t transform from position to momentum representation. 5. To factor N = pq need enough Qbits to hold N periods of a x (mod N) except in pathological cases (like N = 15). 45

6. Quantum Fourier transform for n Qbits is built from just O(n 2 ) gates each of which acts only on single Qbits or on pairs of Qbits. 7. To use it for period finding you need only O(n) such gates. 8. To use it for period finding you can replace the 2-Qbit gates by 1-Qbit gates conditional on measurement outcomes. 9. Quantum computation is a unique blend of digital (measurement gates) and analog (unitary gates). 10. Classical: Cbits cheap, time precious. Quantum: Time cheap, Qbits precious. 11. Write Qbit, not qubit. 46

Some other things I wish they had told me: Question: Why must a quantum computation be reversible (except for measurements)? Superficial answer: Because linear + norm-preserving unitary and unitary transformations have inverses. Real answer: Because standard architecture for evaluating f(x), x 0 U f x f(x) oversimplifies the actual architecture: 47

Need additional work registers for doing the calculation: Registers Work Input Output 0 g(x) x W f 0 x f(x) If input register starts in standard state x x then final state of all registers is x g(x) x f(x). Work register entangled with input and out registers, unless final state of work register independent of x. Quantum parallelism breaks down. Quantum parallelism maintained if g(x) = 0, independent ( of x. ) Final state is then 0 x x f(x). 48

How to keep the work register unentangled: Work Input Output 0 0 x W f 0 x f(x) = 0 x V f 0 0 g(x) f(x) C g(x) f(x) f(x) V f 0 x f(x) 49

C is built out of 1-Qbit controlled-not gates: C = C = controlled-not: x x 0 x 50

Question: How do you do arithmetic on a quantum computer? Answer: By copying the (pre-existing) classical theory of reversible computation. Question (from reversible-classical-computer scientist): But that theory requires an irreducibly 3-Cbit doubly-controlled-not (Toffoli) gate! Answer: In a quantum computer 3-Qbit Toffoli gate can be built from a few 2-Qbit gates. 51

The 3-Cbit Doubly-Controlled-NOT (Toffoli) gate: x y 0 x y xy logical AND of x and y 52

How to build the 3-Qbit Doubly-Controlled-NOT gate out of 2-Qbit gates: x y x y = U z X xy z A B A B X = ( ) 0 1 1 0 = σ x U = e πi /2 A = â σ B = ˆb σ â ˆb = ˆx sin θ A 2 = B 2 = 1 AB = â ˆb + iâ ˆb σ = cos θ + iσ x sin θ ( AB ) 2 = cos 2θ + iσx sin 2θ If angle θ between â and ˆb is π/4 then ( AB ) 2 = ix = e πi/2 X 53

Reference: Quantum Computer Science N. David Mermin Cambridge University Press, August 2007 54