source 2008 Hisil--Wong--Carter--Dawson, http://eprint.iacr.org/2008/522, Section 3.2 appliesto extended-1 assume Z2 = 1 compute A = (Y1-X1)(Y2+X2) compute B = (Y1+X1)(Y2-X2) compute C = Z1 2 T2 compute D = 2 T1 compute E = D + C compute F = B - A compute G = B + A compute H = D - C compute X3 = E F compute Y3 = G H compute T3 = E H compute Z3 = F G