
RIJNDAEL 
ANUBIS 
Block size (bits) 
128, 192, or 256 
always 128 
Key size (bits) 
128, 192, or 256 
128, 160, 192, 224, 256, 288, or 320 
Number of rounds 
10, 12, or 14 
12, 13, 14, 15, 16, 17, or 18 
Key schedule 
dedicated a priori algorithm 
key evolution (variant of the round function),
plus key selection (projection) 
GF(2^{8}) reduction polynomial 
x^{8} + x^{4} + x^{3} + x + 1 (0x11B) 
x^{8} + x^{4} + x^{3} + x^{2} + 1 (0x11D) 
Origin of the Sbox 
mapping u > u^{1} over GF(2^{8}), plus affine transform 
pseudorandom involution
(tweak: recursive structure)

Origin of the round constants 
polynomials x^{i} over GF(2^{8}) 
successive entries of the Sbox 