Fast constant-time gcd computation and modular inversion

Torbjörn Granlund tg at
Mon Jun 6 11:03:14 CEST 2022

nisse at (Niels Möller) writes:

  Extract least significant 96 bits of each number.

Is that 3 32-bit limbs or 1.5 64-bit limbs?

