source 2008 Bernstein--Birkner--Joye--Lange--Peters http://eprint.iacr.org/2008/013 Section 6 compute A = Z1 Z2 compute B = A^2 compute C = X1 X2 compute D = Y1 Y2 compute E = d C D compute F = B-E compute G = B+E compute X3 = A F ((X1+Y1)(X2+Y2)-C-D) compute Y3 = A G (D-a C) compute Z3 = F G