[[Daniel J. Bernstein|Bernstein]], [[Nadia Heninger|Heninger]], Lou, & Valenta suggest GEECM, a quantum version of ECM with Edwards curves.<ref>Bernstein D.J., [[NadiaHeninger|Heninger N.]], Lou P., Valenta L. (2017) [https://eprint.iacr.org/2017/351 Post-quantum RSA]. In: Lange T., Takagi T. (eds), ''Post-Quantum Cryptography''. PQCrypto 2017. Lecture Notes in Computer Science, vol 10346. Springer, Cham</ref> suggest GEECM, a quantum version of ECM with Edwards curves. It uses [[Grover's algorithm]] to roughly double the size of the primes found compared to standard EECM, assuming a quantum computer with sufficiently many qubits and of comparable speed to the classical computer running EECM.