Is it fine if algoritm will have $32$ 128-bit numbers that will be nothing-up-my-sleeve numbers to initialize key schedule?
As I know from wikipedia the Hasty Pudding Cipher was criticized for its performance on smartcards. Specifically, some comments pointed out the difficulty of keeping over 2KB of RAM for the key table. In my case we got 0,5 KB. Isn't it still to much?