These trade more multiplications (but fewer than naive rtl) for greater potential parallelism, since almost all of the multiplications can be done in parallel with squarings. Signed-off-by: Daira Hopwood <daira@jacaranda.org>