diff --git a/SM2-MFMM-(2).md b/SM2-MFMM-(2).md index cd8cccc..9e8a587 100644 --- a/SM2-MFMM-(2).md +++ b/SM2-MFMM-(2).md @@ -104,17 +104,17 @@ $t_0=t_0 - a_1$ \ // First reduction step, [p3, p2, p1, p0] = [1, -0x100000000, 0, (1 - 0x100000000), -1] MOVQ acc0, AX \ MOVQ acc0, DX \ - MOVQ acc0, CX \ SHLQ $32, AX \ // AX = L(acc0 * 2^32), low part SHRQ $32, DX \ // DX = H(acc0 * 2^32), high part \// calculate the negative part: [0, -0x100000000, 0, -0x100000000] * acc0 SUBQ AX, acc1 \ SBBQ DX, acc2 \ SBBQ AX, acc3 \ + MOVQ acc0, AX \ SBBQ DX, acc0 \ \ // calculate the positive part: [1, 0, 0, 1] * acc0 + [0, acc3, acc2, acc1], \ // due to (-1) * acc0 + acc0 == 0, so last lowest lamb 0 is dropped directly, no carry. - ADDQ CX, acc1 \ // acc1' = L (acc0 + acc1) + ADDQ AX, acc1 \ // acc1' = L (acc0 + acc1) ADCQ $0, acc2 \ // acc2' = acc2 + carry1 ADCQ $0, acc3 \ // acc3' = acc3 + carry2 ADCQ $0, acc0 \ // acc0' = acc0 + carry3