|Designers||Anatoly Lebedev, Alexey Volchkov|
|Key sizes||128, 192, or 256 bits|
|Block sizes||64, 128, or 256 bits|
|Rounds||9, 17, or 33|
|Best public cryptanalysis|
|A linear attack faster than exhaustive search has been found.|
NUSH exists in several different variants, using keys of 128, 192, or 256 bits, and a block size of 64, 128, or 256 bits. The number of rounds is 9, 17, or 33, depending on the block size. The algorithm uses key whitening, but no S-boxes; the only operations it uses are AND, OR, XOR, modular addition, and bit rotation.
- Lars Knudsen, Håvard Raddum (2001-03-07). "A first report on Whirlpool, NUSH, SC2000, Noekeon, Two-Track-MAC and RC6" (PDF). Retrieved 2018-09-13.
- Wenling Wu, Dengguo Feng (23 July 2001). "Linear cryptanalysis of NUSH block cipher". Science China Information Sciences. 45 (1): 59–67. doi:10.1360/02yf9005 (inactive 2019-08-20). ISSN 1009-2757.
|This cryptography-related article is a stub. You can help Wikipedia by expanding it.|