Negation Map BSGS with inlined affine addition for 28-bit ECDLP
Negation BSGS indexes baby steps by x-coordinate: table[x] = (j, y) for j in 1..m. Giant step Q_i = P - i * M * G with M = 2m + 1. Since (i*M - m, ..., i*M + m) partition Z_n without gaps, any k is represented as i*M +/- j with 1 <= j <= m (or j=0). When Q_i.x is found in baby_x: if Q_i.y == y: k = (i * M + j) % n if Q_i.y == -y % p: k = (i * M - j) % n.
With m = isqrt(n // 2) + 1, table size is ~sqrt(n/2) instead of sqrt(n), and giant step size M = 2m + 1 cuts the giant step search space in half. Total worst-case operations: ~sqrt(2n) vs 2*sqrt(n) (a 1.41x algorithmic reduction in additions). Inlining affine addition in baby and giant loops in Python avoids tuple allocation and function call overhead, cutting execution time to ~0.007s for 28-bit curves (down from 0.05s).