Good afternoon (evening) MATZOV,
Thank you very kindly for releasing this paper! I’m sure it must have been a challenge. I’m looking forward to reading it in much detail.
In the paper, you highlight in multiple places that your analysis occurs in the RAM model.
There are several variables involved in assessing the cost of an actual attack. Have you considered “more realistic” memory-costing in your analyses?
There is a long history of discussion on this forum this past summer and fall about what the proper way to model attacker memory costs are. Broadly, there is the RAM model as compared to a variety of so-called “local”