fixed carry bug in FIPS prf