> I had neglected the significance of modular inversion for elliptic curve
> arithmetic.

In my implementation, it's needed in two places.

* For ecdsa signatures, the random nonce k is inverted mod q, the ecc
  group order.

* When converting coordinates back from jacobian representation to
  affine representation. Then the z coordinate is inverted mod p.

> My suggestion was just for a reasonably efficient fall-back.

Fair enough.


