SM2 Decrypt
Decrypt SM2 ciphertext produced by SM2 Encrypt.
Decrypt SM2 ciphertext with a private key (Chinese national standard). Free, offline, runs entirely client-side. Read more Show less
What is SM2 Decrypt?
SM2 Decrypt reverses the encryption performed by SM2 Encrypt. It reads a hex ciphertext and uses the matching SM2 private key to recover the plaintext.
SM2 encryption is the asymmetric counterpart to SM2 signatures, defined in the GB/T 32918 standard. It is used in Chinese TLS stacks, secure messaging, and enterprise systems that must comply with Chinese commercial cryptography regulations.
How to use
Paste the hex ciphertext, paste the SM2 private key (64 hex characters), choose the ciphertext mode (C1C3C2 or C1C2C3), and press Decrypt.
If the ciphertext was produced by SM2 Encrypt on this site, the mode will be C1C3C2 unless you explicitly changed it.
Why does decryption fail?
Four common causes:
Wrong private key. SM2 encryption is public-key encryption. The private key you paste must be the pair of the public key that was used to encrypt.
Wrong ciphertext mode. C1C3C2 and C1C2C3 produce different byte sequences from the same ciphertext hex. If the mode is wrong, the C3 integrity check fails and decryption aborts.
Tampered ciphertext. The C3 component is the SM3 hash of the shared secret and message. Any modification to the ciphertext will make C3 verification fail.
Not SM2 ciphertext. If the input does not start with a valid curve point, decryption fails immediately.
FAQ
Can I decrypt without the private key?
No. SM2 is a public-key encryption scheme whose security is based on the elliptic curve discrete logarithm problem. There is no practical way to recover the plaintext without the private key.
Is the plaintext recoverable from the ciphertext by brute force?
Only if the message space is very small. For a message of a few characters, an attacker could encrypt every possible value with the public key and compare. That is why SM2 should not be used directly to encrypt short secrets like passwords - hash them first or use a different scheme.
Does decryption verify integrity?
Yes, via the C3 component. If the ciphertext has been modified, C3 verification fails and the tool reports an error rather than producing garbage plaintext. This is stronger than SM2's design requirements, which allow the C3 check to be skipped.
Can I decrypt OpenSSL output?
Yes if you know the ciphertext mode. OpenSSL 1.1.1+ supports SM2 but may default to a different ordering or wrap the ciphertext in ASN.1. Try both modes if the first fails.
Is it safe to paste my private key here?
This tool runs entirely client-side. Nothing is uploaded. Verify by opening your browser's Network tab - no requests are sent after page load. For production keys, always audit any tool before pasting secrets.
Command line equivalent
# Node with sm-crypto
npm i sm-crypto
node -e '
const sm2 = require("sm-crypto").sm2;
const ctHex = "your-ciphertext-hex";
const privateKey = "your-64-hex-private-key";
const mode = 1;
console.log(sm2.doDecrypt(ctHex, privateKey, mode));
'
# Python with gmssl
pip install gmssl
python3 -c '
from gmssl import sm2
private_key = "your-64-hex-private-key"
decryptor = sm2.CryptSM2(private_key=private_key, public_key="")
print(decryptor.decrypt(bytes.fromhex("your-ciphertext-hex")).decode())
'