Tooleux

SM4 Encrypt

SM4 (2)

Encrypt text with SM4 using a password.

Runs in your browser. Nothing leaves your device.
Encrypt text with SM4 (Chinese national block cipher, GB/T 32907-2016) in your browser. CBC mode, PBKDF2 key derivation. Free, offline, runs client-side. Read more Show less

What is SM4?

SM4 is a block cipher standardized by the Chinese Office of State Commercial Cryptography Administration (OSCCA) in 2012. It has a 128-bit block size and a 128-bit key, and uses 32 rounds of a Feistel-like structure. It is defined in the Chinese national standard GB/T 32907-2016.

SM4 is mandatory for commercial cryptographic applications in China. It appears in Chinese TLS stacks, WAPI (the Chinese equivalent of WiFi), VPN equipment, banking systems, and industrial control networks. It is the symmetric counterpart to SM3 (hash) and SM2 (asymmetric).

How to use

Enter your plaintext, enter a password, and press Encrypt. The output is a single Base64 string containing the random salt, random IV, and ciphertext. Copy it and paste into SM4 Decrypt with the same password.

The password is used to derive a 128-bit SM4 key via PBKDF2-SHA-256 with 100,000 iterations.

Mode of operation

SM4 is a block cipher and only encrypts a single 16-byte block at a time. To encrypt arbitrary-length text, this tool uses CBC mode with PKCS#7 padding. CBC chains each block to the previous one using XOR, so identical plaintext blocks produce different ciphertext blocks.

ECB mode is also available for interoperability with older systems, but it is not recommended: identical plaintext blocks always produce identical ciphertext blocks, which leaks structure. Use CBC unless a specific system requires ECB.

FAQ

Is SM4 secure?

Yes. SM4 has been publicly analyzed since 2006 and no practical attack exists against the full cipher. It provides roughly 128-bit security at a 128-bit key, matching AES-128.

SM4 vs AES-128

Both use 128-bit blocks and 128-bit keys with similar security. SM4 is slightly slower in software on most CPUs because AES has hardware acceleration on every modern x86 and ARM processor, while SM4 does not. Use AES for new systems outside China; use SM4 where Chinese market requirements demand it.

What is the difference between ECB and CBC?

ECB encrypts each block independently, so identical plaintext produces identical ciphertext. CBC XORs each plaintext block with the previous ciphertext block before encrypting, so identical plaintext produces different ciphertext. CBC is the standard choice for any data longer than one block.

Is SM4 authenticated?

No. SM4 in CBC or ECB mode provides confidentiality only. An attacker who can modify the ciphertext may be able to cause predictable changes to the plaintext. For authenticated encryption, use AES-GCM or ChaCha20-Poly1305.

Can I decrypt data from another SM4 implementation?

Only if that implementation uses the same mode, padding, byte order, and key derivation. SM4 byte order can differ between implementations. This tool uses the sm-crypto library, which follows the GB/T standard.

Command line equivalent
# Node with sm-crypto
npm i sm-crypto
node -e '
const sm4 = require("sm-crypto").sm4;
const key = "0123456789abcdeffedcba9876543210";  // 32 hex chars
const msg = "hello world";
const ct = sm4.encrypt(msg, key);  // default ECB mode
console.log(ct);
'

# CBC mode
node -e '
const sm4 = require("sm-crypto").sm4;
const key = "0123456789abcdeffedcba9876543210";
const iv  = "00000000000000000000000000000000";
const ct = sm4.encrypt("hello world", key, { mode: "cbc", iv });
console.log(ct);
'

# Python with gmssl
pip install gmssl
python3 -c '
from gmssl.sm4 import CryptSM4, SM4_ENCRYPT
key = bytes.fromhex("0123456789abcdeffedcba9876543210")
crypt = CryptSM4()
crypt.set_key(key, SM4_ENCRYPT)
print(crypt.crypt_ecb(b"hello world").hex())
'

# OpenSSL 3.0+
echo -n "hello world" | openssl enc -sm4-cbc -K 0123456789abcdeffedcba9876543210 -iv 00000000000000000000000000000000 | xxd
Loads a test value into the form
Plaintext
Ciphertext