SM4 Encrypt / Decrypt

Encrypt or decrypt with SM4 — GB/T 32907-2016, the Chinese national standard 128-bit block cipher — in ECB and CBC modes with PKCS#7 padding. Output is byte-for-byte compatible with openssl enc -sm4-ecb / -sm4-cbc. Everything runs in your browser; nothing is uploaded.
PKCS#7 padding is always applied, exactly like OpenSSL enc.
Read input as:
Write output as:
OpenSSL cross-check — encrypt here, then run openssl enc -d -sm4-cbc -K <hexkey> -iv <hexiv> -in file.sm4 -out file.txt (or -sm4-ecb without -iv): the bytes match exactly, because this page applies the same PKCS#7 padding OpenSSL does.
Self-test
Replays the GB/T 32907-2016 appendix A.1 known-answer vector, six deterministic ECB/CBC cross-vectors produced by an independent Python reference implementation, all four sample pools, and the negative paths (wrong key size, non-block-multiple ciphertext, tampered padding must be rejected).
What is SM4?
In one sentence: SM4 is the Chinese national standard block cipher — a 128-bit block, 128-bit key, 32-round cipher with an unbalanced Feistel structure, published as GB/T 32907-2016 (earlier GM/T 0002-2012), playing the role in the Chinese "SM" suite that AES plays in the NIST world.
SM4 vs AES at a glance
SM4AES
Block size128 bits128 bits
Key sizes128 bits only128 / 192 / 256 bits
Rounds3210 / 12 / 14
Structureunbalanced Feistel (one 32-bit word updated per round)substitution–permutation network (whole state every round)
S-boxone 8×8 box, used 4× per roundone 8×8 box, 16× per round + MixColumns
Standard modesECB, CBC (this page); GCM/CTR in TLS suites (RFC 8998)ECB, CBC, CTR, GCM, ...
Published2012 (GM/T 0002-2012; GB/T 32907-2016); in ISO/IEC 18033-3:20102001 (FIPS 197)

Same job, different design: both are 128-bit block ciphers with a public 8×8 S-box, but SM4 iterates 32 lightweight Feistel rounds while AES applies 10–14 heavier whole-state rounds. In software AES is usually faster thanks to hardware instructions (AES-NI); SM4 reached comparable standing with dedicated CPU extensions in Chinese platforms. Neither has a practical attack; the 128-bit key is the 128-bit key.

Why would I use SM4 instead of AES?

Compliance and interop, not strength: Chinese commercial-cryptography regulations (商用密码) require the SM suite in certified sectors, and protocols such as TLCP and TLS 1.3 with RFC 8998 suites negotiate SM4. If your counterparty, regulator or hardware only speaks SM4, you use SM4. If you are free to choose, AES-256 on this site's AES page remains the global default.

Common mistakes
  • ECB on structured data. Identical plaintext blocks produce identical ciphertext blocks — the classic penguin. Use CBC (this page's default) with a fresh IV whenever the data is longer than one block.
  • A key is 16 bytes, exactly. Unlike AES, SM4 has no 192/256-bit variants. A passphrase like "password" is not a key — derive one with a KDF first (see the Password Hash Generator).
  • Assuming padding is optional. This page — like OpenSSL enc — always applies PKCS#7, so a 16-byte plaintext encrypts to 32 bytes. Raw unpadded SM4 is deliberately not offered.
  • Reusing an IV in CBC. A repeated key+IV pair in CBC leaks equality of message prefixes. Generate a random IV per message and ship it alongside the ciphertext.
FAQ

Is this compatible with OpenSSL? Yes — byte for byte. openssl enc -sm4-cbc -K 0011... -iv 4455... -in in.txt -out out.sm4 (OpenSSL 1.1.1+) produces exactly the ciphertext this page prints for the same key, IV and input; GmSSL is the same.

Why no SM4-GCM here? The standards-adjacent library ecosystem exposes SM4-GCM mainly inside TLS stacks; the file-oriented command-line convention this page matches (enc) covers ECB/CBC. Authenticated SM4 belongs at the protocol layer.

Is SM4 in WebCrypto? No — no browser implements it. That is why this page runs a from-scratch implementation in JavaScript, with the standard's own test vectors wired into the self-test above.

Can I decrypt something encrypted elsewhere? Yes, if you know the mode, key, IV and that PKCS#7 was used — paste the ciphertext as hex or Base64, switch to Decrypt, and go.