Shor's algorithm could threaten RSA by factoring large integers through quantum period finding. Yet a patent claim covering the method may struggle under current US eligibility rules
Shor's algorithm carries a rare double significance: it offers a quantum route to factoring large integers while exposing a legal weakness that could block patent protection for the method itself. The algorithm threatens public-key systems such as RSA because it turns factoring into a period-finding problem that a quantum computer can solve far more efficiently than the best known classical approaches. But speed alone may not make the invention patentable.
Its importance is scientific as well as strategic. The method separates the workload between coherent quantum processing and classical computation: a quantum processor extracts information about a hidden period, while a conventional algorithm interprets measurement results and derives candidate factors. That division is central to how quantum-information researchers at institutions such as MIT describe the practical boundary between a quantum subroutine and the surrounding classical system.
Factoring Through Periods
The method begins with a quantum superposition of possible inputs and a quantum gate that evaluates modular exponentiation. Controlled powers of that gate act on a second register through phase kick-back. An inverse quantum Fourier transform then extracts information about the repeating period of the function. Once that period is estimated, a classical procedure can use it to derive the prime factors of the target integer, typically by applying number-theoretic relations and checking the resulting candidates.
In an RSA decryption scenario, the first register contains eigenvalue qubits and the second contains eigenvector qubits associated with the number being factored. Hadamard gates place the first register into superposition. Controlled unitary operations apply successive modular-exponentiation powers to the second register. Quantum phase estimation follows through the inverse quantum Fourier transform, and the resulting period is passed to classical factorization steps before the recovered factors are used with the public key and product number to decrypt the message.
Quantum phase estimation does not reveal the prime factors in a single measurement. It encodes a phase related to the period into amplitudes of a register, and repeated measurements produce samples from which a classical reconstruction procedure estimates that period. This is why the physical implementation involves state preparation, controlled operations, coherent evolution, readout, and classical post-processing rather than a single gate that directly performs factorization.
The important distinction is between the algorithm's mathematical task and the machine that executes it. Superposition and controlled gates are physical operations on a quantum processor, but the claimed improvement may be characterized as more efficient number-theoretic processing rather than a new way to build or operate that processor. The scientific literature, including work discussed in journals such as Nature, generally treats the algorithmic advantage and the engineering of a fault-tolerant processor as related but separate challenges.
The Eligibility Barrier
Under the current Mayo/Alice framework, a critical US Patent and Trademark Office examiner could treat the claim as directed to an abstract mathematical method. The period search, quantum phase estimation, and inverse quantum Fourier transform are all expressible as mathematical operations. If the claim merely instructs a conventional quantum computer to perform them, it may not identify a technological improvement to the computer itself. The USPTO's eligibility guidance describes this analysis as a two-step inquiry: whether the claim is directed to an abstract idea, including a mathematical concept, and whether additional elements provide an inventive concept that turns it into a patent-eligible application.
That objection would also focus on preemption. A broad patent over Shor's core operations could restrict the use of foundational mathematical principles across quantum systems rather than protect a specific architecture, control technique, or hardware improvement. The likely result is an uphill prosecution and potentially an eligibility challenge before a judicial decision maker. The available materials do not establish that the USPTO or a court has issued a decision specifically resolving the patent eligibility of Shor's algorithm.
The comparison with RSA complicates the analysis. In Example 41 of its 2019 guidance, the PTO treated an RSA-related method as patent eligible after identifying concrete communications steps. That example covered receiving plaintext at one computer terminal, transforming it into message blocks, encoding those blocks, and transmitting ciphertext to another terminal. The practical application of sending the ciphertext through a communications channel was considered sufficient to integrate the mathematical concepts into a patentable application.
Application Versus Algorithm
That guidance gives an applicant an argument: Shor's method could be described as improving a decryption computer by making it more efficient than a classical system operating without the relevant RSA decryption key. The analogy is not decisive. RSA encryption is tied to a communications process in the PTO example, whereas Shor's algorithm can be framed as a general method for factoring numbers regardless of a particular computer network or device configuration.
The distinction matters because the legal question is not simply whether quantum hardware performs the computation faster. It is whether the claim captures a specific practical application or instead monopolizes a mathematical concept implemented with known quantum processes. Without a defined improvement in processor architecture, control, readout, error management, or another technical feature, the latter characterization is difficult to avoid.
For quantum companies, the implication is practical. Patent drafting must identify the parts of an invention that improve the operation of a machine rather than rely on the algorithm's computational value alone. Claims tied to a particular quantum-gate arrangement, modular-exponentiation implementation, measurement protocol, or system-level control method may present a stronger eligibility case than claims that recite Shor's mathematical sequence in broad terms. The available material does not establish that any such hardware improvement has been demonstrated in a specific patent dispute.
Innovation Under Uncertainty
Quantum computing is approaching a period in which hardware and software inventions will need protection at the same time. Hardware claims may have clearer technical anchors, while algorithm claims can collide with the US exclusion for abstract ideas. That uncertainty matters for investment and development because companies may be unable to secure meaningful protection for methods that are central to future quantum workloads.
Congress has not resolved the issue. The Patent Eligibility Restoration Act of 2025, S. 1546, was introduced on May 1, 2025, and remains pending before the Senate Judiciary Committee. The proposal could change the legal framework, but it has not become law and the available material provides no basis for predicting when Congress will act or what final language might govern quantum inventions.
The most defensible reading is therefore narrow: Shor's algorithm remains a powerful example of why quantum computing matters to cryptography, but its mathematical efficiency does not automatically translate into patent eligibility. Until the law changes or applicants connect such algorithms to concrete machine improvements, quantum innovators should treat eligibility as an engineering and claim-design problem rather than assume that a major computational consequence will carry legal protection.
For the same reason, a technically ambitious claim should distinguish among the mathematical transformation, the quantum circuit implementing it, and the surrounding device that prepares, controls, measures, and verifies the computation. A claim that specifies how those components interact may be more defensible than one that simply names period finding, phase estimation, and factor recovery. That distinction reflects the broader policy tension also visible in discussions of quantum technology at institutions such as CERN: scientific significance does not by itself determine whether a legal monopoly is available.