Solution

ID: past-exam-of-the-mathematics-course-of-the-university-of-cambridge/2021/iii/paper-324/3/a/ii/solution

Reversibly test whether the measured integer is a nontrivial divisor of , and phase-flip exactly those computational basis states. This implements the good-subspace reflection in classical and quantum polynomial time. The reflection in is
which is polynomial size by the stated assumption.
Here , so . Two amplification iterations give
The final measurement therefore returns a nontrivial factor with certainty whenever is composite. Only two uses each of up to a constant factor and polynomial-size verification circuits are required, so the complete algorithm is polynomial in .

New to topics? Read the docs here!