source 2001 Liardet--Smart "Preventing SPA/DPA in ECC systems using the Jacobi form", plus substitution S2=1 (as suggested by 2007 Hisil--Carter--Dawson) assume S2 = 1 compute Z2D2 = Z2 D2 compute E = Z1 C2 compute F = S1 D2 compute G = C1 Z2 compute H = E G compute J = D1 F compute S3 = (E+D1)(G+F)-H-J compute C3 = H-J compute D3 = Z1 D1 Z2D2-a S1 C1 C2 compute Z3 = E^2+D1^2