Factoring 2048-bit RSA: resource counts from Gidney and Ekera (2019)
Logical resource counts computed from the paper's own published formulas, costed under this estimator's surface-code model, at industrial scale.
What kind of evidence this is
Every logical resource count here is computed from formulas a published paper states, with the citation attached and the arithmetic shown. Nothing is recalled from memory.
This is a reference case published by KetQat. It is not a customer's production evidence and it supports no claim about quantum advantage.
The decision
Decision overview
Under this model the computation needs 70,966,576 physical qubits and 1.14e+5 s at code distance 53. The computation is technically feasible under this model, but no economic conclusion can be made because no classical baseline was supplied. A surface-code cycle below 254 ns would be required to finish within the 28800 s target.
What is actually stopping this
Total physical qubit capacity
The binding constraint is total physical qubit capacity: the machine this workload needs is larger than the device stated for it.
- Threshold to cross
- below 253.5338 nsCycle time needed to meet the runtime target
- Economic conclusion
- Not justifiedInsufficient evidence. The missing input is named below.
- Evidence confidence
- LOWKinds of claim, not an average of them.
- Largest sensitivity
- physical error rate24.2× range in total physical qubits
What to measure next
- Measure the current classical solution on the real problem size and record the hardware and date.
- Measure the two-qubit physical error rate on the target device. It is the parameter this result depends on most, and it is measurable.
What is missing
- A dated observation of a real device meeting these physical error rate and cycle time parameters.
- A classical baseline: runtime, cost, hardware, problem size, solution quality, and the date it was measured.
What it would take
- Total machine
- 7.097e+7physical qubits
- Runtime
- 113,594.3352s
- Code distance
- 53
- Factory share
- 0%
Every figure, with its evidence class, assumptions and sensitivity, is under scenarios and evidence.
Can anyone else reproduce this?
Yes. The bundle carries the inputs, the assumptions and the conclusions under one hash, and ketqat-engine intelligence verify recomputes the decisions from those inputs rather than trusting them.
3c446ffadf9ae51c9441d2a93a3619ad93e60c03d2b1a71b52d7e13bfcaf6297
Under different assumptions
| Scenario | Logical qubitsPatches occupied, including routing space. | Total physical qubitsAlgorithm, routing and factory together. | Runtime (s)Under whichever limiter binds. | Code distanceSmallest odd distance meeting the budget. | Factory shareFraction of the machine that is the magic-state factory. | Logical errorAchieved probability of any logical error. | Required cycle (ns)Slowest cycle meeting the target or beating classical. | Required throughputMagic states per second for the runtime target. | EconomicRefused unless a baseline and a cost model both exist. | EvidenceStrength of the inputs behind the row. |
|---|---|---|---|---|---|---|---|---|---|---|
| ConservativeCONSERVATIVE · revision 1 Conditionally feasible | 12,602 | 7.097e+7 | 113,594.3352 | 53 | 0% | 0.003 | 253.5338 | 364,475.6969 | Insufficient evidence | LOW |
| BaseBASE · revision 1 Conditionally feasible | 12,602 | 1.842e+7 | 104,969.0007 | 27 | 0% | 0.004 | 274.3667 | 364,475.6969 | Insufficient evidence | LOW |
| OptimisticOPTIMISTIC · revision 1 Technically feasible under these assumptions | 12,602 | 4.265e+6 | 20,993.8001 | 13 | 0% | 0.004 | 274.3667 | 364,475.6969 | Insufficient evidence | LOW |
How the inputs were obtained
- n = 2048, lg n = 11 exactly.
- Logical qubits: 3n + 0.002 n lg n = 3(2048) + 0.002(2048)(11) = 6189.
- Toffoli count: 0.3 n^3 + 0.0005 n^3 lg n = 2.624e+9.
- Measurement depth: 500 n^2 + n^2 lg n = 2.143e+9.
- The source states its own outcome as 20 million physical qubits in 8 hours, at a 1e-3 gate error rate and a 1 microsecond surface-code cycle. That is a comparison point, not an input.
Limitations
- The source reports Toffolis and measurement depth; it does not state a Clifford or two-qubit count, so any figure this estimator derives from those is incomplete rather than zero.
- The source's 20-million-qubit result uses its own layout, factory and error-budget conventions. A difference from this estimator is a definitional difference to be explained, not an error.
- No classical baseline is attached: the classical cost of factoring a 2048-bit RSA modulus is not a figure this project has measured, and inventing one would fabricate the comparison this case exists to avoid.
- Resource estimates are modelled, not measured. No device was run.
- The logical-error prefactor is fitted and its provenance is weak; the alternative published value is reported as model sensitivity on every estimate.
- The magic-state factory footprint and throughput are models of the standard construction, not published or measured figures.
- The error budget is allocated across the algorithm's own logical qubits; routing patches are charged for space but not against the budget.
- One QEC scheme is modelled. Other codes, other layouts, and other hardware modalities are out of scope here.
- Nothing in this bundle predicts when any device will meet any condition it states.
- No classical baseline was supplied, so no economic or speedup conclusion is drawn anywhere in this bundle.