source 2002 Izu--Takagi "A fast parallel elliptic curve multiplication resistant against side channel attacks", page 295, Formula 1
compute T1 = X2 X3
compute T2 = Z2 Z3
compute T3 = X2 Z3
compute T4 = Z2 X3
compute T5 = a T2
compute T6 = T1 - T5
compute T7 = T6^2
compute T8 = b T2
compute T9 = 4 T8
compute T10 = T3 + T4
compute T11 = T9 T10
compute T12 = T7 - T11
compute X4 = Z1 T12
compute T13 = T3 - T4
compute T14 = T13^2
compute Z4 = X1 T14
