China's Quantum Computing Program: Jiuzhang, Zuchongzhi, and the Post Quantum Cryptography Race

Why China's Program Matters for Your PQC Timeline
China has made more public investment and more public announcements in quantum computing than any country except the United States. For security professionals evaluating when to migrate to Post Quantum Cryptography, China's program is one of two bellwethers (the other being the US national quantum program). The headlines can be confusing, so this guide separates verified facts from marketing claims.
The Jiuzhang Photonic Systems
The Jiuzhang family is a series of photonic quantum computers at the University of Science and Technology of China (USTC) in Hefei, led by Pan Jianwei. They perform Gaussian boson sampling, a specialized quantum computation that demonstrates quantum advantage but does not run Shor's algorithm.
- Jiuzhang 1.0 (December 2020): 76 detected photons in a 100-mode interferometer. Published in Science 370:1460 (DOI: 10.1126/science.abe8770).
- Jiuzhang 2.0 (2021): 113 photons, 144 modes. Claimed 10^24 speedup over classical simulation of the same problem.
- Jiuzhang 3.0 (October 2023): 255 detected photons. Claimed 10^16 speedup.
Important caveat: Jiuzhang is not a universal quantum computer. It cannot run Shor's algorithm on any RSA key. It performs one specific type of sampling problem. The quantum advantage is real but not transferable to cryptanalysis.
The Zuchongzhi Superconducting Systems
Zuchongzhi is the gate-based superconducting line at USTC. These are closer in design to Google Sycamore and IBM Condor.
- Zuchongzhi 1.0 (early 2021): 62 qubits.
- Zuchongzhi 2.0/2.1 (2021): 66 qubits, 110 tunable couplers, 97.74 percent average readout fidelity. Published as PRL 127.180501.
- Zuchongzhi 3.0 (March 2025): 105 qubits, 182 couplers, 72 microsecond coherence, 99.90 percent single-qubit fidelity, 99.62 percent two-qubit fidelity. Published as PRL 134.090601 cover article.
Zuchongzhi 3.0 matches Google Willow's 105 physical qubit count. Neither is cryptographically relevant.
The Micius Quantum Satellite
Micius (also known as QUESS, Quantum Experiments at Space Scale) launched on August 16, 2016 from Jiuquan. It demonstrated:
- Satellite-to-ground quantum key distribution over 2,500 kilometers (Xinjiang to Xinglong).
- Beijing-Vienna quantum-secured video call in 2017 with an Austrian group.
- Entanglement-based QKD over 1,120 km.
Micius is a QKD demonstration, which is complementary to (not a replacement for) Post Quantum Cryptography. PQC protects classical channels against quantum attack. QKD provides quantum-protected channels in specific geographies.
The 2022 RSA-Attack Paper Controversy
On December 23, 2022, a paper titled "Factoring integers with sublinear resources on a superconducting quantum processor" was posted to arXiv (2212.12372). Lead authors from Tsinghua and Chinese Academy of Sciences claimed RSA-2048 could be broken with 372 qubits using a hybrid Schnorr plus QAOA approach.
The experimental demonstration factored a 48-bit integer using 10 qubits. The claim that this scales to RSA-2048 was sharply criticized:
- Scott Aaronson (UT Austin) wrote that "a miracle would be required for the approach here to yield any benefit at all, compared to just running the classical Schnorr's algorithm on your laptop."
- Bruce Schneier echoed concerns that the underlying Schnorr's algorithm "falls apart at larger sizes" and the paper inherits this problem.
- The paper has never been peer-reviewed in a venue of cryptographic record.
The paper is a useful reminder that qubit count alone is not a reliable signal; the algorithmic approach matters as much as the hardware.
Investment Figures (Verified vs Reported)
- Hefei National Laboratory for Quantum Information Sciences: 37-hectare campus in Anhui. Phase 1 construction ~$1B USD is widely reported.
- Total national investment: Figures of $10-15 billion circulate in Western press. OECD has flagged these as not independently verified. Treat as estimates, not audited numbers.
- Xinhua press releases suggest Chinese government has committed to quantum dominance as a strategic priority, with specific funding levels classified or diffused across agencies.
What This Means for Your PQC Migration
- Jiuzhang and Zuchongzhi are scientific milestones, not CRQC candidates. A 105-qubit Zuchongzhi 3.0 is not materially closer to breaking RSA than a 105-qubit Willow.
- The 2022 RSA paper is not credible evidence of a near-term break. Treat it as research, not a warning shot.
- China's serious investment is real. If you project forward 10-20 years, China is one of the handful of countries likely to produce CRQC capability, which is the reason Mosca's theorem applies.
- HNDL from Chinese signals intelligence should be assumed to be operating at scale. If your data would be valuable to a Chinese adversary in 2040, encrypt it today with Post Quantum Cryptography.
Frequently Asked Questions
Has China broken RSA?
No. The 2022 paper by Bao Yan et al. (arXiv:2212.12372) claimed a theoretical approach with 372 qubits but actually factored only a 48-bit integer. Scott Aaronson, Bruce Schneier, and other cryptographers publicly criticized the claim. The paper has not been peer-reviewed in a cryptography venue.
Is Zuchongzhi 3.0 more powerful than Google Willow?
Both have 105 physical qubits. Willow demonstrated below-threshold quantum error correction across 3x3, 5x5, and 7x7 surface codes. Zuchongzhi 3.0 has reported slightly higher two-qubit gate fidelity. Neither is cryptographically relevant.
Is Micius satellite QKD a replacement for PQC?
No. QKD provides quantum-protected key distribution over specific physical channels (fiber or satellite). PQC protects classical data channels against future quantum attack. They address different parts of the problem. NIST and NSA guidance both recommend PQC for general use.
Should I trust Chinese quantum announcements?
Trust the peer-reviewed results in Nature, Science, PRL, and PRX. Be skeptical of press releases with large unverified numbers. The peer-reviewed Chinese results are real and scientifically significant, but they do not change the CRQC timeline.
Sources
- Jiuzhang 1.0 Science paper
- Zuchongzhi 3.0 PRL
- Bao Yan RSA paper critique
- Micius / QUESS
- Scott Aaronson blog
Related Articles
Protect Your Data Before Q-Day Arrives
QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.
Try QNSQYOriginally published at quantumsequrity.com/blog/china-quantum-computing-program.