“Call Rewinding: Efficient Backward Edge Protection”. IACR Transactions on Cryptographic Hardware and Embedded Systems, vol. 2025, no. 1, Dec. 2024, pp. 227-50, https://doi.org/10.46586/tches.v2025.i1.227-250.