source 2008 Hisil--Wong--Carter--Dawson, http://eprint.iacr.org/2008/522, Section 3.1 appliesto extended-1 assume Z2 = 1 parameter k assume k = 2 d compute A = (Y1-X1)(Y2-X2) compute B = (Y1+X1)(Y2+X2) compute C = T1 k T2 compute D = 2 Z1 compute E = B - A compute F = D - C compute G = D + C compute H = B + A compute X3 = E F compute Y3 = G H compute T3 = E H compute Z3 = F G