Montgomery exponentiation needs no final subtractions
Colin D. Walter · Electronics Letters · 1999
Montgomery's modular multiplication algorithm is commonly used in implementations of the RSA cryptosystem. It has been observed that there is no need for extra cleaning up at the end of an exponentiation if the method is correctly set up.