SM4 Decrypt
Decrypt SM4 ciphertext produced by SM4 Encrypt.
Decrypt SM4 (Chinese national block cipher) ciphertext in your browser. CBC or ECB mode. Free, offline, runs entirely client-side. Read more Show less
What is SM4 Decrypt?
SM4 Decrypt reverses the encryption performed by SM4 Encrypt. It reads a Base64 (or hex) string containing the random salt, random IV, and ciphertext, derives the SM4 key from your password with PBKDF2-SHA-256, and decrypts in the chosen mode.
SM4 is the Chinese national block cipher, defined in GB/T 32907-2016. It is the symmetric counterpart to SM3 and SM2.
How to use
Paste the Base64 or hex ciphertext, enter the same password that was used to encrypt it, choose the matching mode (CBC or ECB), and press Decrypt.
Why does decryption fail?
Three common causes:
Wrong password. The derived key will be different, and CBC decryption will produce garbage bytes. The PKCS#7 padding check at the end catches most wrong-password cases and reports "Invalid padding".
Wrong mode. CBC and ECB produce different byte sequences from the same ciphertext. Use the mode that matches how the data was encrypted.
Truncated ciphertext. SM4 ciphertext must be a multiple of 16 bytes. If copy-paste lost any characters, decryption fails with a length error.
FAQ
Can I tell if the password is correct without decrypting?
Not with SM4 alone. CBC with PKCS#7 padding catches most wrong passwords because the padding check fails, but roughly 1 in 256 wrong keys produce valid-looking padding by coincidence, in which case you get garbage plaintext instead of an error. For verifiable decryption, use AES-GCM or ChaCha20-Poly1305, which include authentication tags.
Does the byte order matter?
Yes. This tool uses the sm-crypto library, which follows the GB/T 32907-2016 byte order. Some other SM4 implementations use a different convention, in which case ciphertext is not interchangeable.
Can I decrypt OpenSSL SM4 output?
Only if you can reconstruct the salt and IV from the OpenSSL output and use matching modes and byte order. This tool only decrypts data produced by SM4 Encrypt on this site, or by another implementation using the same conventions.
Is it safe to paste ciphertext into a browser tool?
This tool runs entirely client-side. Nothing is uploaded. Verify by opening your browser's Network tab and confirming no requests are sent after page load.
Command line equivalent
# Node with sm-crypto
node -e '
const sm4 = require("sm-crypto").sm4;
const key = "0123456789abcdeffedcba9876543210";
const ctHex = "your-ciphertext-hex";
console.log(sm4.decrypt(ctHex, key));
'
# CBC mode
node -e '
const sm4 = require("sm-crypto").sm4;
const key = "0123456789abcdeffedcba9876543210";
const iv = "00000000000000000000000000000000";
const pt = sm4.decrypt("your-ciphertext-hex", key, { mode: "cbc", iv });
console.log(pt);
'
# OpenSSL 3.0+
# openssl enc -d -sm4-cbc -K <key> -iv <iv> -in ciphertext.bin