ARM public key benchmark

Niels Möller nisse at
Wed Apr 3 17:05:38 CEST 2013

Torbjorn Granlund <tg at> writes:

> Have you considered complementing C instead?

Not until now. Actually looks nice:

  A - b C = A + b (~C) + b - b B^n 

So this saves one not instruction, and we have to add and subtract the
scalar b from incoming and outgoing carry.


