source 2008 Bernstein--Birkner--Joye--Lange--Peters http://eprint.iacr.org/2008/013 Section 6, plus Z2=1, plus Z1=1, plus standard simplification assume Z1 = 1 assume Z2 = 1 compute C = X1 X2 compute D = Y1 Y2 compute E = d C D compute X3 = (1-E) ((X1+Y1)(X2+Y2)-C-D) compute Y3 = (1+E) (D-a C) compute Z3 = 1-E^2