source 2001 Liardet--Smart "Preventing SPA/DPA in ECC systems using the Jacobi form" compute a0 = S1 compute a1 = C1 compute a2 = D1 compute a3 = Z1 compute l1 = a3 a1 compute l2 = a0 a2 compute l3 = 2(a1 a2)^2 compute r0 = 2 l1 l2 compute r3 = (l1+l2)^2-r0 compute r1 = r3-2 l2^2 compute r2 = -r1+l3 compute S3 = r0 compute C3 = r1 compute D3 = r2 compute Z3 = r3