Call Rewinding: Efficient Backward Edge Protection. (2024). IACR Transactions on Cryptographic Hardware and Embedded Systems, 2025(1), 227-250. https://doi.org/10.46586/tches.v2025.i1.227-250