prime factors | type | cost | acpb^{†} |
elliptic operations | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|

DBL | DBL_{ε} | TPL | TPL_{ε} | ADD | ADD_{ε} | ADD_{M} | dDBL | dADD | ||||||

109 · 73 · 37 · 19 · 13 · 7 · 5 · 3^{3} |
C | 2^{36}−1 |
261 M | 7.250 | 35 | 1 | 1 | |||||||

113 · 107 · 97 · 89 · 67 · 61 · 47 · 43 · 17 · 7 | C | 2^{47}· 3^{6}+2^{32}· 3^{5}+2^{27}· 3^{5}−2^{24}· 3^{4}+2^{19}· 3^{2}−1 |
442 M | 7.822 | 42 | 5 | 6 | 4 | 1 | |||||

101 · 83 · 71 · 41 · 11 · 3 | C | 2^{28}· 3−2^{13}−2^{11}+1 |
233 M | 7.876 | 25 | 3 | 1 | 2 | 1 | |||||

79 · 59 · 29 | C | 2^{17}+2^{12}+1 |
136 M | 7.979 | 15 | 2 | 1 | 1 | ||||||

103 · 31 · 23 | C | 2^{13}· 3^{2}−2^{5}· 3^{2}−1 |
132 M | 8.166 | 11 | 2 | 2 | 1 | 1 | |||||

switch to Montgomery, last ADD_{ε} is in fact a ADD_{M} |
-4 M | -1 | 1 | |||||||||||

5 | M | 17 M | 7.322 | 1 | 2 | |||||||||

53 | M | 50 M | 8.729 | 4 | 5 | |||||||||

2^{6} |
M | 30 M | 5.000 | 6 | ||||||||||

Total | 1297 M | 7.659 | 128 | 13 | 9 | 8 | 4 | 1 | 11 | 7 |

^{†}acpb = arithmetic cost per bit