SM3 Hash Generator

Compute SM3 digests — GB/T 32905-2016, the Chinese national cryptographic hash standard — of text or files entirely in your browser. Plain SM3 or keyed HMAC-SM3, hex or Base64 output, with a side-by-side SHA-256 lane for comparison. Nothing is uploaded.
AlgorithmDigest
SM3–
SHA-256 (comparison lane, text source only)–
Details–
Command-line cross-check — the digest this page prints for a file matches openssl dgst -sm3 file.bin (OpenSSL 1.1.1+) and gmssl dgst -sm3 file.bin byte for byte. For HMAC-SM3: openssl dgst -sm3 -hmac <key> with a text key.
Self-test
Re-runs the page engine against the official GB/T 32905-2016 appendix A vectors, the GB/T 15852.2 (ISO/IEC 9797-2) HMAC-SM3 vectors, a chunked 1000-byte incremental run, both sample pools, the Base64 lane against the browser's own encoder, and negative paths (malformed hex key must be rejected). Nothing is sent anywhere.
What is SM3?
In one sentence: SM3 is the cryptographic hash of the Chinese national standards body — a 256-bit Merkle–Damgård hash in the same structural family as SHA-256, but with its own initial values, round constants, Boolean functions and a 68-word message expansion, published as GM/T 0004-2012 and later GB/T 32905-2016.
SM3 vs SHA-256 at a glance
SM3SHA-256
Digest / block / word size256 / 512 / 32 bits256 / 512 / 32 bits
Compression rounds6464
Message expansionW[0..67] + derived W'[0..63], P1 permutationW[0..63] with σ0/σ1 rotates
Round constantstwo constants T0..15=0x79CC4519, T16..63=0x7A879D8A, rotated by j64 constants K[0..63]
Boolean functionsFF/GG switch at round 16Ch/Maj throughout
Byte orderbig-endianbig-endian
Published2010 (GM/T 0004-2012; GB/T 32905-2016)2001 (FIPS 180-2)
International statusincluded in ISO/IEC 10118-3:2018FIPS 180-4

Same skeleton, different muscle: both algorithms chop the message into 512-bit blocks and run 64 rounds of mixing over eight 32-bit registers, but every constant, every rotation amount and the message-expansion step differ, so they produce completely unrelated digests for the same input. SM3("abc") is 66c7f0f4...8f4ba8e0 while SHA-256("abc") is ba7816bf...f20015ad — try both with the Sample button.

Does "national standard" mean safer?

No — and that is not its job. SM3 offers security comparable to SHA-256: a 256-bit digest, no practical collision or preimage attacks known. The reason SM3 exists is suite independence and regulatory compliance: Chinese commercial-cryptography regulations (商用密码, "SM") require the domestic suite in certified sectors — banking, government, telecom infrastructure — so that the whole stack (hash, signature, cipher) is controlled by one national standards process rather than foreign ones. Outside that context, SHA-256 and SM3 are interchangeable in strength; pick SM3 when your counterpart, regulator or protocol (for example TLS 1.3 with the RFC 8998 SM cipher suites) asks for it.

Where SM3 sits inside the SM suite
  • SM3 (this page) — the hash. Also the digest inside SM2 signatures (the ZA value) and the KDF of SM2 encryption.
  • SM4 — the 128-bit block cipher (think "AES made national"), ECB/CBC on the SM4 page of this family.
  • SM2 — the elliptic-curve signature and encryption algorithm over the sm2p256v1 curve, built on SM3.
  • SM9 — identity-based cryptography: your email address is your public key.
Common mistakes
  • Hashing passwords with SM3. SM3 is a fast general-purpose hash, like SHA-256 — billions of guesses per second on a GPU. For password storage use bcrypt, scrypt, Argon2id or PBKDF2 from the Password Hash Generator.
  • Assuming the old C1C2C3 order matters here. Ciphertext ordering is an SM2 topic; SM3 has no such wrinkle. Its output is always 32 bytes.
  • Mixing up GM/T 0004-2012 and GB/T 32905-2016. Same algorithm, same test vectors — GM/T is the industry-standard publication, GB/T the national one. ISO/IEC 10118-3:2018 also carries it.
  • Trust, but verify. The self-test on this page replays the standard's own appendix vectors; if it does not say "0 failed", do not trust the output.
FAQ

Is SM3 available in OpenSSL? Yes — OpenSSL 1.1.1 and later: openssl dgst -sm3 file, HMAC via -hmac. GmSSL (the Chinese fork) has had it longer. This page needs neither: the algorithm runs in your browser.

What is HMAC-SM3 for? Message authentication: a digest that also proves who sent it, because only holders of the shared key can produce it. Standardised in GB/T 15852.2 / ISO/IEC 9797-2. The key can be any length; over 64 bytes it is first hashed.

Why does the file lane not show the SHA-256 comparison? The comparison uses the browser's built-in WebCrypto one-shot digest, which needs the whole input in memory — fine for text, not for a 200 MB file streamed in chunks. SM3 itself is computed incrementally and has no such limit here.

Can I get the digest as Base64? Yes — the Output format selector. Both lanes of every result can be copied or downloaded as a small text report.