Implement the small-factor proof from Figure 26 of Canetti et al. (2024), "UC Non-Interactive, Proactive, Threshold ECDSA with Identifiable Aborts" (CGGMP21).
The proof demonstrates that an RSA modulus N₀ = pq has factors above a threshold 2^ℓ without revealing p or q.