Reversibly test whether the measured integer is a nontrivial divisor of , and phase-flip exactly those computational basis states. This implements the good-subspace reflection in classical and quantum polynomial time. The reflection in is
which is polynomial size by the stated assumption.
Here , so . Two amplification iterations give
The final measurement therefore returns a nontrivial factor with certainty whenever is composite. Only two uses each of up to a constant factor and polynomial-size verification circuits are required, so the complete algorithm is polynomial in .

Articles by others on the same topic (0)

There are currently no matching articles.