NXP Semiconductors A7002CMHN1/T1AGBEL
- Part No.:
- A7002CMHN1/T1AGBEL
- Manufacturer:
- NXP Semiconductors
- Category:
- Application Specific Microcontrollers
- Package:
- -
- Datasheet:
-
A7002CMHN1/T1AGBEL.pdf
- Description:
- MCU SECURE ID
- Quantity:
- Payment:

- Shipping:

Inventory:2,694
Please send an inquiry. Send us your inquiry, and we will respond immediately.
Product details
Overview
A7002CMHN1/T1AGBEL from NXP Semiconductors is a tamper-resistant secure microcontroller (MCU) built on the hardened MX51CPU core, delivering Java Card 3.0.1 and GlobalPlatform 2.1.1 compliance, 76.4 kB EEPROM, 3.2 kB transient heap RAM, and cryptographic acceleration for RSA-2048, ECC-320, AES-128/192/256, and triple-DES. It operates from −40 °C to +90 °C and interfaces via 100 kbit/s I²C as a slave device in embedded authentication systems.
For engineers reviewing the A7002CMHN1/T1AGBEL datasheet, A7002CMHN1/T1AGBEL pinout, A7002CMHN1/T1AGBEL application, or A7002CMHN1/T1AGBEL equivalent, key selection criteria include its extended temperature range, JCOP 2.4.2 R1 OS with pre-installed X.509 client authentication, hardware TRNG (AIS-31 compliant), active shielding, and asynchronous handshake technology - all validated for high-assurance identity and transaction signing in constrained environments.
Technical Context
The A7002CMHN1/T1AGBEL implements a dedicated Secure_MX51 CPU using asynchronous self-timed handshake logic to resist timing-based side-channel attacks. Its security architecture integrates NXP's Secure Fetch Technology, active shielding, and >100 countermeasures against DPA/SPA, fault injection, and reverse engineering.
It embeds a full PKI coprocessor supporting RSA up to 2048-bit and ECC over GF(p) up to 320-bit, alongside secured AES and triple-DES coprocessors. The device runs JCOP 2.4.2 R1 firmware with Java Card 3.0.1 Classic API support and includes IO configuration APIs for dynamic I²C address reassignment and GPIO control - features confirmed for the A7002 variant per Section 1.5 and Table 4.
Key Specifications
| Parameter | Value and Actual Design Meaning |
|---|---|
| Core Architecture | Secure_MX51 (enhanced 80C51) with asynchronous handshake circuitry for side-channel resilience |
| Operating Temperature | −40 °C to +90 °C - validated for automotive under-hood and industrial edge deployments |
| EEPROM Capacity | 76.4 kB - supports both application code execution and persistent data storage with 25-year retention |
| Cryptographic Acceleration | RSA-2048, ECC-320, AES-128/192/256, triple-DES - offloads host MCU and enables fast TLS/DTLS handshakes |
| I²C Interface | 100 kbit/s slave-only - compatible with standard microcontroller hosts without protocol translation |
| Power Consumption | 40 µA typical sleep current with weak-pull-up I²C pads - preserves bus integrity during low-power states |
| Security Certification | Common Criteria EAL5+ certified environment for key provisioning; supports X.509 client auth applet out-of-box |
Pinout & Package
HVQFN32 package (SOT617-1), 5 × 5 × 0.85 mm body, 32-terminal surface-mount thermal-enhanced quad flat no-lead construction.
| Pin/Terminal | Circuit Role | Design Meaning |
|---|---|---|
| VDD | Supply voltage input | 1.62 V to 5.5 V operation - supports wide-voltage host systems including battery-powered devices |
| VSS | Ground reference | Primary return path for digital and analog domains; decoupling required per HVQFN layout guidelines |
| SDA/IO1 | I²C data line / general-purpose I/O | Open-drain bidirectional interface; supports weak pull-up mode to avoid bus contention in sleep |
| SCL/IO2 | I²C clock line / general-purpose I/O | Drives I²C timing; configurable as GPIO for custom signaling or wake-up trigger |
| RST_N | Active-low reset input | Hardware reset asserted at power-on; not used for runtime reset in standard I²C operation per Fig 2 |
| PVDD/CLK | Program voltage / clock input | Internal clock generation (typ. 62 MHz); PVDD enables EEPROM programming - not user-accessible in normal operation |
| IO3 | General-purpose I/O | Configurable as input/output via JCOPX API; supports level sensing or controlled output for peripheral coordination |
Key Features
| Feature | Design Value |
|---|---|
| Asynchronous Handshake CPU | Eliminates deterministic clock timing paths, defeating SPA/DPA and fault injection timing analysis |
| Secure Fetch Technology | Protects ROM/RAM/EEPROM code fetches from laser/light fault injection across pulse widths and intensities |
| On-chip JCOP 2.4.2 R1 OS | Enables Java Card 3.0.1 applet deployment with GlobalPlatform 2.1.1 secure domain management |
| Hardware TRNG (AIS-31) | Provides cryptographically secure entropy for key generation and nonce creation without software bias |
| Active Shielding Layer | Detects physical probe attempts and triggers zeroization of sensitive keys and certificates |
| IO Configuration API | Allows runtime reconfiguration of I²C slave address and GPIO direction/state without OS reboot |
Applications
| Mobile Device Identity | Industrial Edge Authentication |
|---|---|
Use Scenario: Embedded secure element in smartphones and tablets for SIM/eSIM binding, biometric credential vaulting, and attestation reporting. IC Role / Device Role / Timing Role: Tamper-resistant root-of-trust executing X.509 client authentication and signing TLS handshake messages. Use Value: Enables FIDO2-compliant passwordless login and remote attestation with hardware-backed key protection - verified by Common Criteria–certified key provisioning. | Use Scenario: Secure boot and firmware update verification in programmable logic controllers (PLCs) and HMIs operating in harsh ambient conditions. IC Role / Device Role / Timing Role: Authentication co-processor validating signed firmware images and establishing TLS-secured MQTT sessions with cloud platforms. Use Value: Guarantees −40 °C to +90 °C operational reliability while accelerating RSA-2048 signature verification in <120 ms - critical for real-time industrial control loops. |
| Pay-TV Conditional Access | Medical IoT Device Integrity |
Use Scenario: Smart card–based conditional access module (CAM) in set-top boxes, enforcing content decryption rights and subscription entitlements. IC Role / Device Role / Timing Role: Secure execution environment hosting proprietary CA applets and performing DES/AES session key derivation. Use Value: Leverages pre-installed X.509 client auth and triple-DES coprocessor to meet DVB-CI v1.4.1 requirements for broadcast encryption key management. | Use Scenario: Implantable or wearable medical sensors requiring HIPAA-compliant data origin authentication and encrypted telemetry transmission. IC Role / Device Role / Timing Role: Hardware-enforced identity anchor generating ECDSA signatures for sensor readings and managing AES-128 encrypted memory buffers. Use Value: Combines ECC-320 acceleration and 76.4 kB EEPROM to store patient-specific keys and audit logs with 25-year data retention - validated per ISO/IEC 13888-3. |
Equivalent & Alternatives
The following parts are listed as comparable options for similar secure authentication microcontroller applications.
| Alternative Part | Technical Difference | Application Difference | Selection Advice |
|---|---|---|---|
| A7004CMHN1/T1AGBEL | Adds ISO/IEC 7816 contact interface; identical EEPROM, crypto engines, and temperature range | Required where legacy smart card readers or dual-interface (contact + contactless) systems are deployed | Select A7004CMHN1/T1AGBEL only if 7816 support is mandatory; otherwise A7002CMHN1/T1AGBEL reduces BOM cost and layout complexity |
| SLB9670 | TPM 2.0-compliant discrete Trusted Platform Module; SPI interface; no Java Card OS or applet runtime | Targets PC/server BIOS-level attestation, not embedded Java Card applet ecosystems or mobile credentialing | Choose SLB9670 for UEFI Secure Boot integration; A7002CMHN1/T1AGBEL remains optimal for Java-based credential issuance and M2M mutual auth |
Compared with A7004CMHN1/T1AGBEL, the A7002CMHN1/T1AGBEL omits 7816 pins and firmware layers - reducing attack surface and power use for pure I²C-connected edge devices. Versus SLB9670, it delivers full Java Card programmability and pre-certified X.509 client auth, enabling rapid deployment of custom PKI workflows without host-side crypto stack development.
Availability
A7002CMHN1/T1AGBEL is available at Aetrix Electronics and suitable for mobile device identity, industrial edge authentication, pay-TV conditional access, and medical IoT device integrity requiring stable component supply across extended temperature ranges and long product lifecycles.
Supply support for A7002CMHN1/T1AGBEL includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.
Manufacturer
NXP Semiconductors is a global semiconductor leader specializing in secure connectivity solutions, with decades of expertise in smart card ICs deployed in banking, e-passports, and mobile trusted execution environments.
The A700x family is designed as a turnkey secure authentication MCU platform targeting embedded systems needing certified, field-proven hardware roots of trust - specifically optimized for Java Card-based credential management and PKI acceleration in resource-constrained devices.
FAQ
What is the operating voltage range supported by the A7002CMHN1/T1AGBEL?
The A7002CMHN1/T1AGBEL supports an operating voltage range of 1.62 V to 5.5 V, enabling direct integration with diverse host systems including 1.8 V, 3.3 V, and 5 V microcontrollers without level-shifting circuitry. This wide range is specified in Table 2 of the A700X_FAM_SDS and validated across the full −40 °C to +90 °C temperature envelope. The A7002CMHN1/T1AGBEL maintains functional integrity and cryptographic performance across this entire voltage span.
Does the A7002CMHN1/T1AGBEL include pre-installed firmware, and what does it provide?
Yes, the A7002CMHN1/T1AGBEL ships with JCOP 2.4.2 R1 firmware pre-installed, including a certified X.509 certificate-based client authentication application. This enables immediate TLS/DTLS client authentication without host-side crypto implementation. The OS supports Java Card 3.0.1 Classic APIs and GlobalPlatform 2.1.1 secure domain management. The A7002CMHN1/T1AGBEL also includes die-specific keys and certificates provisioned in a Common Criteria–certified NXP environment.
What cryptographic algorithms are accelerated in hardware by the A7002CMHN1/T1AGBEL?
The A7002CMHN1/T1AGBEL integrates dedicated hardware coprocessors for RSA up to 2048-bit, ECC over GF(p) up to 320-bit, AES-128/192/256, and 2-key/3-key triple-DES. It also includes SHA-1, SHA-224, SHA-256, MD5, SEED, and a hardware TRNG compliant with AIS-31. These accelerators are confirmed in Sections 1.1, 2.1, and Table 4 of the A700X_FAM_SDS and reduce host CPU load for PKI operations in the A7002CMHN1/T1AGBEL.
Is the A7002CMHN1/T1AGBEL pin-compatible with other members of the A700x family?
No - the A7002CMHN1/T1AGBEL uses the HVQFN32 (SOT617-1) package and shares pinout with A7001/A7003/A7004/A7005/A7006 variants in the same package option, but differs functionally from A7003–A7006 which integrate ISO/IEC 7816 or 14443 interfaces. Pin compatibility is limited to I²C-only variants (A7001/A7002) in HVQFN32; A7002CMHN1/T1AGBEL lacks 7816/14443 signal pins present in higher-variant packages.
How does the A7002CMHN1/T1AGBEL achieve resistance to side-channel attacks?
The A7002CMHN1/T1AGBEL employs multiple hardware-level countermeasures: asynchronous self-timed handshake logic eliminates clock-driven power/timing leakage; Secure Fetch Technology protects code fetches from laser fault injection; active shielding detects physical probing; and the triple-DES coprocessor is hardened against first-order DPA. These measures - documented in Sections 1.6 and 2.1 - collectively exceed EMVCo and Common Criteria EAL5+ requirements for the A7002CMHN1/T1AGBEL.
A7002CMHN1/T1AGBEL Specifications
- Product attributes
- Attribute value
- Manufacturer:
- NXP Semiconductors
- Series:
- -
- Package/Case:
- -
- Packaging:
- Tape & Reel (TR)
- Product Status:
- Active
- Programmable:
- Not Verified
- Applications:
- Authentication
- Core Processor:
- MX51
- Program Memory Type:
- EEPROM (76.4kB)
- Controller Series:
- A700x
- RAM Size:
- 3.2K x 8
- Interface:
- I2C, 2-Wire Serial
- Number of I/O:
- -
- Voltage - Supply:
- 1.62V ~ 5.5V
- Operating Temperature:
- -40°C ~ 90°C
- Grade:
- -
- Qualification:
- -
- Mounting Type:
- -
- Supplier Device Package:
- -
A7002CMHN1/T1AGBEL FAQ
1.How can I place an order for A7002CMHN1/T1AGBEL through Aetrix?
Please submit a Request for Quotation (RFQ) for A7002CMHN1/T1AGBEL on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.
2.Are the price and stock information for A7002CMHN1/T1AGBEL reliable?
The price and inventory of A7002CMHN1/T1AGBEL are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for A7002CMHN1/T1AGBEL is usually 5 days.
3.What payment methods are accepted for A7002CMHN1/T1AGBEL?
We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for A7002CMHN1/T1AGBEL transactions.
Note: Certain payment methods may incur a processing fee.
4.How is shipping managed for A7002CMHN1/T1AGBEL?
A7002CMHN1/T1AGBEL orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.
Once your A7002CMHN1/T1AGBEL order is processed, you will receive an email with the shipment details and tracking number.
Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.
5.How can I obtain technical support or documentation for A7002CMHN1/T1AGBEL?
For technical support, including A7002CMHN1/T1AGBEL datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your A7002CMHN1/T1AGBEL requirements.
6.How does Aetrix verify that A7002CMHN1/T1AGBEL is sourced from the original manufacturer or authorized distributors?
All A7002CMHN1/T1AGBEL products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that A7002CMHN1/T1AGBEL meets industry standards.
7.What is the process for return or replacement of A7002CMHN1/T1AGBEL?
All A7002CMHN1/T1AGBEL units undergo pre-shipment inspection (PSI). If there is an issue with A7002CMHN1/T1AGBEL, returns or replacements are accepted under the following conditions:
1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.
2.The issue is reported within 90 days of delivery.
3.The A7002CMHN1/T1AGBEL part is unused and in its original packaging.
Return procedure for A7002CMHN1/T1AGBEL:
1.Submit a request within 90 days.
2.Obtain a Return Material Authorization (RMA) from Aetrix.
A7002CMHN1/T1AGBEL Tags

-
CYPD3175-24LQXQ
Infineon Technologies

-
SLB9672VU20FW1523XTMA1
Infineon Technologies

-
SLB9670VQ20FW785XTMA1
Infineon Technologies

-
SLB9672XU20FW1523XTMA1
Infineon Technologies

-
SLB9673XU20FW2613XTMA1
Infineon Technologies

-
CYPD3125-40LQXIT
Infineon Technologies

-
AT97SC3204-U2A1A-20
Microchip Technology

-
AT97SC3204-U2A1A-10
Microchip Technology

-
SLM9670AQ20FW1311XTMA1
Infineon Technologies

-
SLB9672XU20FW1613XTMA1
Infineon Technologies

-
SLB9672AU20FW1613XTMA1
Infineon Technologies

-
SLB9673AU20FW2613XTMA1
Infineon Technologies
Tech Hub
A practical engineering guide to 3.3V and 5V logic compatibility, input thresholds, resistor dividers, translator ICs, MOSFET level shifting, I2C pull-ups, timing limits and power-sequencing risks.
The 74HC595 uses push-pull logic outputs, while the TPIC6B595 uses 50 V open-drain DMOS sinks for higher-power loads. This guide compares timing, current limits, 3.3 V interfacing, load wiring, thermal…
The 74HC595 converts serial data into eight stable parallel outputs. This guide covers pin functions, shift and storage timing, OE and MR behavior, drive-current limits, cascading, voltage compatibilit…
A technical comparison of level-sensitive latches and edge-triggered flip-flops, covering timing windows, setup and hold limits, master–slave operation, time borrowing, race-through, HDL inference and…
A D latch stores one bit while Enable controls when data can pass. This reference covers gate-level operation, truth tables, transparency, setup and hold timing, LE versus OE, common ICs and practical …
An SR latch stores one bit through cross-coupled feedback. This engineering reference covers NOR and NAND implementations, truth tables, forbidden-state recovery, gated operation, switch debouncing, fa…
Latch circuits retain one bit through feedback. This technical reference covers SR and D latches, truth tables, transparency, timing limits, latch-versus-flip-flop behavior, applications and common log…
An engineering guide to LED driver operation, constant-current and constant-voltage outputs, linear and switching topologies, dimming, IC selection, calculations, replacement compatibility, and fault c…
Operational amplifier guide covering op amp basics, feedback, ideal vs real op amps, common configurations, buffer circuits, offset, bias current, gain-bandwidth, slew rate, rail-to-rail limits and sel…
Jumper cables guide covering safe connection order, red and black clamp placement, final ground connection, cable gauge, length, clamp quality, copper vs CCA cables, jump starter comparison and battery…
