Tooleux

Compute the SM3 (GB/T 32905-2016) cryptographic hash of any input.

Runs in your browser. Nothing leaves your device.
Calculate SM3 (GB/T 32905-2016) hashes of any input. The Chinese national cryptographic hash standard. Free, offline, runs client-side. Read more Show less

What is SM3?

SM3 is a cryptographic hash function standardized by the Chinese Office of State Commercial Cryptography Administration (OSCCA) in 2010. It produces a 256-bit (32-byte) digest, shown as 64 hexadecimal characters. It is defined in the Chinese national standard GB/T 32905-2016 and its successor standards.

SM3 is mandatory for commercial cryptographic applications in China. It appears in Chinese TLS suites, VPN equipment, blockchain systems (notably the Chinese national blockchain infrastructure BSN), and in the SM2/SM4 family of Chinese cryptographic standards.

It has a security level comparable to SHA-256. It is not widely deployed outside China, but it is required by Chinese regulatory frameworks and appears in some international standards for interoperability.

How to compute SM3

Type or paste your input. Choose the input encoding (UTF-8, hex, or Base64). For example, the UTF-8 string abc produces:

66c7f0f462eeedd9d1f2d46bdc10e4e24167c4875cf2f7a2297da02b8f4ba8e0

Design

SM3 uses a Merkle-Damgard construction with a 256-bit state and 64 rounds per block. The compression function uses boolean functions similar to SHA-256 but with different constants and a different message expansion schedule. Message padding is the same as SHA-256 (a single 0x80 byte, zeros, and a 64-bit length).

Unlike SHA-256, SM3 has no hardware acceleration on most CPUs outside China, so it runs at roughly half the speed of SHA-256 in software.

FAQ

Is SM3 secure?

Yes. No practical attack exists against the full SM3. Its 256-bit output gives 128-bit collision resistance, matching SHA-256.

Where is SM3 used?

Primarily in China: TLS, VPN, banking, e-government, and Chinese blockchain systems. Some international products include it for Chinese market compatibility. If you need to interoperate with a Chinese system, you probably need SM3.

SM3 vs SHA-256

Comparable security, different design. SM3 has been analyzed less by the international cryptographic community, but no weaknesses have been found. Its primary practical downside is slower software performance and less hardware support.

SM3 vs SM2 vs SM4

They form the Chinese commercial cryptography suite: SM2 is public-key cryptography (signatures and key exchange), SM3 is the hash function, SM4 is the symmetric block cipher. Together they are the Chinese equivalent of ECDSA/SHA-256/AES.

Can I use SM3 for password hashing?

No. SM3 is a fast hash and provides no protection against offline brute force. Use Argon2id or scrypt instead.

Command line equivalent
# OpenSSL 3.x
echo -n "abc" | openssl dgst -sm3

# Python with gmssl
pip install gmssl
python3 -c 'from gmssl import sm3, func; print(sm3.sm3_hash(func.bytes_to_list(b"abc")))'

# Node with @noble/hashes
npm i @noble/hashes
node --input-type=module -e '
import { sm3 } from "@noble/hashes/sm3";
console.log(Buffer.from(sm3(new TextEncoder().encode("abc"))).toString("hex"));
'

# Python with gmssl-tools
python3 -c 'from gmssl import sm3; print(sm3.sm3_hash(b"abc".hex()))'
Loads a test value into the form
Input
SM3