“Guessing Bits: Improved Lattice Attacks on (EC)DSA with Nonce Leakage” (2021) IACR Transactions on Cryptographic Hardware and Embedded Systems, 2022(1), pp. 391–413. doi:10.46586/tches.v2022.i1.391-413.