SM4 / SM3 tools

SM3 hash and SM4 encryption (ECB/CBC, PKCS#7) with a one-click standard-vector self-test; local and key-safe.

In the Chinese commercial cryptography suite, SM3 is the answer to SHA-256 (a 256-bit digest) and SM4 the answer to AES-128 (128-bit block and key, 32 Feistel rounds). Finance, government and domestic IoT systems commonly require these algorithms, yet usable online tools either demand a local setup or send your keys to somebody else's server — unacceptable for key material.

This tool implements SM3 and SM4 by hand from the standard documents and runs entirely in the page: SM3 digests any text live; SM4 covers ECB and CBC with PKCS#7 padding, accepting UTF-8 text or hex and emitting Hex or Base64. The greatest risk in crypto tooling is a silent wrong answer, so a "standard vector self-test" button lives in the toolbar: one click verifies SM3("abc") and the official SM4 vector and shows the result plainly — if it fails, the page tells you not to trust its output.

ECB vs CBC

ECB encrypts each block independently, so identical plaintext blocks produce identical ciphertext — encrypting images leaks outlines (the famous penguin problem). Restrict it to short, unstructured values such as a single token. CBC chains blocks through a random IV so identical plaintexts no longer match, making it the default for general data; the cost is that the IV must be random and never reused, or relationships between messages leak.

SM4 keeps secrets, not integrity

Like AES, SM4 provides confidentiality only — it is not authenticated encryption. An attacker cannot change your plaintext, but can swap, replay or truncate blocks; the decrypt side may or may not notice (padding checks catch some cases). For integrity, layer a MAC — SM3-HMAC, or an SM2 signature in the full national suite. The tools on this page compose for exactly that: SM4 first, then SM3-HMAC over the ciphertext.

Frequently asked questions

What does the self-test actually verify?
That the page's implementation matches the national standards: the SM3 "abc" vector (66c7f0f4…) and the official SM4 vector (plaintext/key 0123456789abcdeffedcba9876543210 → ciphertext 681edf34…), plus a decrypt round trip. This implementation was also cross-verified against OpenSSL 3's sm3/sm4 across multi-block and CJK inputs during this site's build.
Where is SM2? Why only SM3/SM4 here?
SM2 is an elliptic-curve public-key algorithm (the answer to RSA/ECDSA) involving key generation, signatures and key exchange — a different interaction class from these symmetric tools. SM3/SM4 are pure functions, ideal for instant in-browser use. An SM2 tool is on the roadmap.
Are my keys safe here?
The page makes no network requests; keys, plaintext and ciphertext never leave the browser and are not written to storage. Remember the browser boundary though: key material lives in page memory, so shared or monitored machines are not the place for production keys.

Related tools