De Meyer, L. “Recovering the CTR_DRBG State in 256 Traces”. IACR Transactions on Cryptographic Hardware and Embedded Systems, Vol. 2020, no. 1, Nov. 2019, pp. 37-65, doi:10.13154/tches.v2020.i1.37-65.