source 2002 Izu--Takagi "A fast parallel elliptic curve multiplication resistant against side channel attacks", page 295, Formula 1 compute T1 = X2 X3 compute T2 = Z2 Z3 compute T3 = X2 Z3 compute T4 = Z2 X3 compute T5 = a T2 compute T6 = T1 - T5 compute T7 = T6^2 compute T8 = b T2 compute T9 = 4 T8 compute T10 = T3 + T4 compute T11 = T9 T10 compute T12 = T7 - T11 compute X5 = Z1 T12 compute T13 = T3 - T4 compute T14 = T13^2 compute Z5 = X1 T14