Tooleux

Encrypt text with an SM2 public key.

Runs in your browser. Nothing leaves your device.
Encrypt text with an SM2 public key (Chinese national standard). Free, offline, runs entirely client-side. Read more Show less

What is SM2 encryption?

SM2 encryption uses the SM2 elliptic curve public key to encrypt a message so that only the holder of the matching private key can read it. It is the asymmetric encryption counterpart to SM2 signatures, defined in the same GB/T 32918 standard.

SM2 encryption is used in Chinese TLS stacks, secure messaging, VPN software, and anywhere confidentiality between two SM2 key holders is required.

How to use

Enter the plaintext, paste the recipient's SM2 public key (130 hex characters, starts with 04), and press Encrypt. The output is a hex ciphertext in the C1C3C2 format.

To decrypt, use SM2 Decrypt with the matching private key.

Ciphertext format

SM2 ciphertexts are made of three parts:

C1 - an ephemeral curve point (64 bytes, the kG point). Encoded as 128 hex characters.

C3 - the SM3 hash of the shared secret and message (32 bytes, 64 hex).

C2 - the message XORed with the key stream derived from the shared secret (variable length, twice the message length in hex).

There are two orderings in the wild:

C1C3C2 (mode 1, default) - used by the GB/T 32918 standard, sm-crypto, and most modern Chinese tools.

C1C2C3 (mode 0) - used by older implementations and some software that predates the standard.

This tool defaults to C1C3C2. Switch the mode if you need to interoperate with a C1C2C3 system.

Message size

SM2 has no padding and no fixed message length. It can encrypt messages of any size, but each byte of message costs two hex characters of output plus 96 bytes of overhead (C1 plus C3). For very long messages, the cost of public-key operations makes symmetric encryption (SM4, AES) a better choice with SM2 used only to wrap the symmetric key.

FAQ

Is SM2 encryption secure?

Yes. It is provably secure under standard assumptions about the sm2p256v1 curve, and no practical attack exists. The construction is similar to ECIES.

Why is the ciphertext different every time I encrypt the same message?

SM2 uses a fresh random nonce for each encryption. The same message produces a completely different ciphertext each time. This is correct and desirable.

Can I encrypt to multiple recipients?

Not in a single operation. SM2 supports only one recipient per ciphertext. For multiple recipients, encrypt separately or use a symmetric key that is itself SM2-wrapped per recipient.

Is SM2 authenticated?

Partially. The C3 component is the SM3 hash of the shared secret and the message, which acts as an integrity check. If the ciphertext is modified, C3 will not match on decryption and the tool will report an error. This is not the same as a modern AEAD tag, but it does detect tampering.

Can OpenSSL decrypt this ciphertext?

OpenSSL 1.1.1+ supports SM2, but its ciphertext format may use a different ordering or ASN.1 wrapping. If you need to interoperate with OpenSSL, use the mode toggle to match.

Command line equivalent
# Node with sm-crypto
npm i sm-crypto
node -e '
const sm2 = require("sm-crypto").sm2;
const msg = "hello";
const publicKey = "your-130-hex-public-key";
const mode = 1; // 1 = C1C3C2, 0 = C1C2C3
const ct = sm2.doEncrypt(msg, publicKey, mode);
console.log(ct);
'

# Python with gmssl
pip install gmssl
python3 -c '
from gmssl import sm2
public_key = "your-public-key-hex"
encryptor = sm2.CryptSM2(private_key="", public_key=public_key)
ct = encryptor.encrypt(b"hello")
print(ct.hex())
'

# OpenSSL 1.1.1+
openssl pkeyutl -encrypt -inkey sm2-pub.pem -in plaintext.txt -out ciphertext.bin
Loads a test value into the form
Plaintext
Ciphertext (hex)