emSSH
Embedded SoftwarePortable SSH-2 secure shell library with an SCP add-on for encrypted file transfer, port forwarding, and the shared emCrypt cryptographic engine. Royalty-free licensing, available in India from GSAS.
Protocol
SSH version 2 (SSH-2 only)
File Transfer
SCP add-on for secure copy
Tunneling
Port forwarding over SSH
Cipher Suites
AES, ChaCha20-Poly1305, 3DES, Twofish, Camellia (configurable at runtime)
Crypto Engine
emCrypt (shared with emSSL, emSecure)
License
Royalty-free, one-time payment
Overview
About emSSH

SEGGER emSSH is a secure shell library that enables protected remote access to any server application, whether it runs on a native PC application or on a resource-constrained embedded target. Written entirely in ANSI C, emSSH is compiler and target independent and supports SSH version 2 exclusively, giving embedded devices the same authenticated, encrypted remote-access model that Linux and network administrators already rely on for servers, without pulling in a full OpenSSH port.
Core Capabilities
- SSH-2 secure shell: authenticated, encrypted remote command access compatible with widely used SSH-2 clients
- SCP add-on: Secure Copy support for transferring files to, from, or between hosts using the same authentication and encryption as the SSH session itself
- Port forwarding: devices that need to reach an original server can open an SSH tunnel through emSSH and communicate over the resulting encrypted connection
- Runtime-configurable cipher suites: cipher suites are added dynamically at runtime rather than through compile-time preprocessor configuration, avoiding “configuration spaghetti” while keeping unused algorithms out of the build
- Compact, tunable footprint: developers can include only the cipher suites and features their application needs, keeping the library sized for small-memory embedded systems
Cipher Suites and Key Exchange
emSSH ships with a broad, configurable set of SSH-2 algorithms so it can interoperate with nearly every popular SSH server or client. Supported encryption algorithms include AES (CBC, CTR, and GCM modes at 128/192/256-bit), ChaCha20-Poly1305, 3DES, Twofish, and Camellia. Message authentication is handled through HMAC-SHA-2, HMAC-SHA-1, and related MAC variants. Key exchange and host authentication cover Diffie-Hellman (multiple group sizes), ECDH over NIST P-256/P-384/P-521 and Curve25519, plus RSA, ECDSA, and Ed25519 host keys. Because emSSH shares its cryptographic primitives with SEGGER emSSL and emSecure through the common emCrypt engine, teams that already use those libraries add SSH access without duplicating cryptographic code or certifying a second crypto implementation.
Licensing and Support
Commercial emSSH licenses are one-time-payment and royalty-free, with no subscription fees and no per-unit runtime cost, and they include six months of updates and support directly from SEGGER’s engineering team. This licensing model, shared across the emSSL, emSSH, emSecure, and emCrypt security family, lets Indian OEMs budget secure remote access as a fixed line item rather than a recurring per-device fee.
Typical Use Cases
emSSH is a fit for any product that needs authenticated remote administration without exposing an unencrypted management interface: pulling diagnostic logs from a deployed industrial gateway over SCP, pushing configuration changes to a field-installed controller, or tunneling a legacy unencrypted protocol through an SSH-forwarded connection so it never travels the network in the clear. Because the library is target-independent, the same emSSH codebase can secure remote access on an embedded Cortex-M target and on a PC-side management application built with the same source.
GSAS Micro Systems, SEGGER’s authorized engineering partner in India, supplies emSSH with competitive pricing and short lead times, GST-compliant invoicing, and application engineering support for teams in Bengaluru, Hyderabad, Chennai, Pune, Mumbai, and Delhi NCR. Request a quote for emSSH alongside emSSL, emCrypt, or emSecure for a complete SEGGER security stack.
Blog
SEGGER Insights
SEGGER emSSH: Secure Remote Management for Indian Industrial Gateways on Cortex-M
How Indian industrial gateway OEMs use SEGGER emSSH, a commercial SSH-2 server library, for secure remote management, SCP log retrieval, and fleet automation of deployed Cortex-M products across Indian solar farms, factories, and transport networks.
Choosing a SEGGER Flasher: Standalone vs Gang vs Secure vs Portable
Standalone, gang, secure, or portable, the SEGGER Flasher family covers four different production-programming problems, not one. Here is how Indian engineering and production teams should decide.
J-Trace PRO vs TRACE32: An Honest Comparison for India
SEGGER J-Trace PRO delivers much of the same core streaming-trace capability as Lauterbach TRACE32 for Arm Cortex-M/A/R and RISC-V targets, at a lower cost point. Here is where each platform is the stronger fit for Indian engineering teams.
Related products
More from SEGGER
All SEGGER products →
J-Link PRO
Professional JTAG/SWD debug probe with USB and Ethernet connectivity, supporting Arm Cortex-M/A/R and RISC-V architectures. India pricing and local support from GSAS.
View J-Link PRO →
Flasher Pro XL
Top-tier production programmer with 2 GB storage, standalone operation, Ethernet connectivity, and full traceability logging for high-volume manufacturing. Available in India from GSAS with hands-on application engineering and local support.
View Flasher Pro XL →
embOS RTOS
Safety-certified real-time operating system with zero-interrupt-latency, sub-1 KB ROM footprint, and royalty-free licensing across Classic, MPU, Ultra, and Safe editions. India pricing via GSAS.
View embOS RTOS →FAQ
Common questions about emSSH
What is SEGGER emSSH?
Is emSSH royalty-free?
Which SEGGER middleware for secure remote shell access to an embedded device?
Can I buy SEGGER emSSH in India?
What cipher suites does emSSH support?
Interested in emSSH?
Get pricing, an evaluation unit, or a technical consultation from our application engineers.