"""
Multiply U by V using table lookup; common for `table-b' and `table-l'.
- This matches the `simple_mulk_...' implementation in `gcm.c'. One-entry
+ This matches the `simple_mulk_...' implementation in `gcm.c'. One entry
per bit is the best we can manage if we want a constant-time
implementation: processing n bits at a time means we need to scan
(2^n - 1)/n times as much memory.
are processed most-significant first.
* IXMASK is a mask XORed into table indices to permute the table so that
- it's order matches that induced by GETWORD.
+ its order matches that induced by GETWORD.
The table is built such that tab[i XOR IXMASK] = U t^i.
"""