source 1987 Montgomery "Speeding the Pollard and elliptic curve methods of factorization", page 261, sixth display, plus common-subexpression elimination parameter a24 assume 4 a24 = a+2 compute A = X1+Z1 compute AA = A^2 compute B = X1-Z1 compute BB = B^2 compute C = AA-BB compute X3 = AA BB compute Z3 = C(BB + a24 C)