Tooleux

Generate a fresh SM2 elliptic curve key pair.

Runs in your browser. Nothing leaves your device.
Generate an SM2 elliptic curve key pair (Chinese national standard) in your browser. Free, offline, runs entirely client-side. Read more Show less

What is SM2?

SM2 is a public-key cryptographic standard published by the Chinese Office of State Commercial Cryptography Administration (OSCCA) in 2010. It covers digital signatures, public-key encryption, and key exchange, all based on elliptic curve cryptography over the sm2p256v1 curve - a 256-bit prime curve unique to SM2.

SM2 is mandatory for commercial cryptographic applications in China. It appears in Chinese TLS suites, VPN equipment, e-government systems, banking infrastructure, and Chinese national blockchain infrastructure. It is the asymmetric counterpart to SM3 (hash) and SM4 (block cipher).

How to generate a key pair

Click Generate. The tool produces a fresh 256-bit SM2 key pair using the browser cryptographic random source.

The private key is a 32-byte integer, shown as 64 hex characters. The public key is a point on the curve, shown in the uncompressed format used by sm-crypto: 130 hex characters starting with 04 (the SEC1 point prefix), followed by 64 hex characters for the X coordinate and 64 for the Y coordinate.

Key format

SM2 keys are usually exchanged in one of three forms:

Raw hex (uncompressed) - 130 hex characters, starts with 04. This is what sm-crypto produces by default.

Compressed hex - 66 hex characters, starts with 02 or 03. Half the size, same information. The leading byte encodes the parity of the Y coordinate.

DER/PEM - wrapped in ASN.1. Used by OpenSSL and enterprise systems.

This tool produces the raw uncompressed hex form, which is what sm-crypto expects for encryption and signature verification.

FAQ

Is SM2 secure?

Yes. No practical attack exists against the full SM2 algorithm, and the underlying curve has no known weaknesses. It provides roughly 128-bit security at a 256-bit key size.

SM2 vs ECDSA P-256

Both give ~128-bit security over 256-bit curves. SM2 uses a different curve, a different hash (SM3), and a signature scheme that includes the signer's identity in the hash, which provides some domain separation that ECDSA does not. For a new system outside China, P-256 or Ed25519 are more common; SM2 is required for Chinese market compatibility.

Can I use these keys with OpenSSL?

OpenSSL 1.1.1 and later support SM2. You may need to convert the raw hex to PEM/DER format. The openssl ec commands and SM2-specific tools can do this, but the conversion is not trivial for uncompressed hex keys.

Is the private key protected?

No. This tool outputs the raw private key. It is not encrypted, not password-protected, and not stored. If you use it in production, secure it with the same care you would any private key: encrypt at rest, never commit to a repository, and rotate if leaked.

How do I know the key pair is valid?

Generate the pair, then try the sign and verify tools on any short message. If a signature verifies with the public key, the pair is valid. This tool also runs an internal validity check on the generated public key.

Command line equivalent
# Node with sm-crypto
npm i sm-crypto
node -e '
const sm2 = require("sm-crypto").sm2;
const kp = sm2.generateKeyPairHex();
console.log("Public: ", kp.publicKey);
console.log("Private:", kp.privateKey);
'

# Python with gmssl
pip install gmssl
python3 -c '
from gmssl import sm2
private_key = "00" + "1" * 63   # example
public_key = sm2.CryptSM2(private_key=private_key, public_key="")._kg(int(private_key, 16), sm2.default_ecc_table["g"], sm2.default_ecc_table)
print(public_key)
'

# OpenSSL 1.1.1+
openssl ecparam -genkey -name SM2 -out sm2-key.pem
openssl ec -in sm2-key.pem -pubout -out sm2-pub.pem
Loads a test value into the form
Key pair