“Recovering the CTR_DRBG state in 256 traces” (2019) IACR Transactions on Cryptographic Hardware and Embedded Systems, 2020(1), pp. 37–65. doi:10.13154/tches.v2020.i1.37-65.