关于PIC18F87J60的TCP/IP栈SSH协议支持情况的技术问询
Hey there, as someone who’s worked extensively with Microchip’s embedded networking stacks and 8-bit MCUs, let’s break down your ELINAP team’s questions clearly:
1. Is SSH included in the PIC18F87J60’s default TCP/IP stack?
Short answer: No. Microchip’s legacy TCP/IP stack (the one typically paired with the PIC18F87J60) and older MPLAB Harmony v1 stacks don’t include a native SSH implementation. SSH is a resource-heavy protocol that requires robust cryptographic handling—something not prioritized in lightweight stacks built for basic embedded networking tasks like HTTP, FTP, or simple TCP/UDP communication.
2. Does the PIC18F87J60 support SSH at all?
Technically, you could cobble together a stripped-down SSH variant, but there are major roadblocks that make this impractical for your passenger counting system:
- Memory limits: The PIC18F87J60 only has 128KB of program flash and ~3.8KB of RAM. Even a minimal SSH implementation (like TinySSH or a custom feature-limited subset) needs significant space for cryptographic algorithms (AES, RSA, etc.) and protocol state management—this would eat up nearly all available memory, leaving almost nothing for your core passenger counting logic.
- Processing power constraints: At a max of 40MHz (translating to ~10MIPS), this 8-bit MCU is far too slow for SSH’s computational heavy lifting. Public-key encryption operations (like RSA handshakes) would take seconds to complete, leading to unacceptable latency for your system’s management protocol.
- Lack of supported tooling: There’s no pre-built, maintained SSH library for this MCU from Microchip. You’d have to port a tiny open-source SSH implementation from scratch—a massive engineering effort—and strip out most SSH features just to fit it on the device.
Practical Workarounds for TS13 149 Compliance
Since your goal is to meet TS13 149’s security requirements with SSH, here are more feasible paths:
- Offload SSH to a dedicated co-processor: Use a low-cost network module (like a small WiFi/Ethernet chip with built-in SSH support, or a Raspberry Pi Pico W) to handle all SSH handshake and encryption tasks. This module can communicate with your PIC18F87J60 over a simple serial or SPI interface, letting your MCU focus on passenger counting while delegating security work to a more capable device.
- Upgrade to a 32-bit MCU: If hardware changes are possible, switch to a Microchip 32-bit MCU like the PIC32MX or PIC32MZ series. These have far more RAM/flash, higher processing power, and work with MPLAB Harmony v3—which includes cryptographic libraries that make implementing SSH far more feasible.
- Check for alternative secure protocols: Verify if TS13 149 allows for lighter secure protocols that fit the PIC18F87J60’s capabilities, like TLS 1.2 with lightweight cipher suites (though even TLS will be tight) or a custom symmetric encryption scheme with pre-shared keys—just make sure any alternative meets the standard’s security requirements.
内容的提问来源于stack exchange,提问作者Hami Koceila

