Sitemap
Press enter or click to view image in full size

Member-only story

If You Don’t Want AES and ChaCha20 … There’s SM4

2 min readOct 9, 2021

--

While AES has been proven to be secure, it hasn’t stopped Google from promoting ChaCha20. While AES is highly secure, in some applications it is perhaps too resource-intensive for some devices. ChaCha20 — a stream cipher — often has lesser processing requirements. So while AES and ChaCha20 are popular, in China, OSCCA (Organization of State Commercial Administration of China) has also authorized SM4 for public use [here]:

Press enter or click to view image in full size
Figure 1

The method was invented by Shu-Wang in 2003 and focused on efficient Wi-Fi use. It was then published as SM4 in 2012 by OSCCA. Overall, SM4 uses a 128-bit key, a 128-bit cipher block, has 32 rounds, and uses an 8-bit S-box. Each round uses XOR, 32-bit circular shifts and S-Box operations:

Press enter or click to view image in full size
Figure 2

In this case rki is the round key, and provides 32 bits of the encryption key each round. The S-box function takes an 8-bit value and then maps to an output 8-bit value:

--

--

Prof Bill Buchanan OBE FRSE
Prof Bill Buchanan OBE FRSE

Written by Prof Bill Buchanan OBE FRSE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.