Microchip Technology CEC1734-S0-I/2ZW-TCSM
- Part No.:
- CEC1734-S0-I/2ZW-TCSM
- Manufacturer:
- Microchip Technology
- Category:
- Application Specific Microcontrollers
- Package:
- 84-WFBGA
- Datasheet:
-
CEC1734-S0-I/2ZW-TCSM.pdf
- Description:
- TRUSTCUSTOM 2-CHANNEL PFR WITH 4
- Quantity:
- Payment:

- Shipping:

Inventory:1,905
Please send an inquiry. Send us your inquiry, and we will respond immediately.
Product details
Overview
CEC1734-S0-I/2ZW-TCSM from Microchip Technology is a real-time platform root of trust controller for server, telecom, and industrial embedded systems. It integrates an ARM® Cortex-M4F core (96 MHz), 384 KB SRAM (320 KB code + 64 KB data), dual SPI flash monitoring blocks, hardware crypto accelerators (AES-256, SHA-384, ECDSA, PUF), and operates at 3.3 V with -40°C to +85°C temperature range - deployed as a secure boot and runtime integrity monitor between BMC and CPU host processors.
For engineers reviewing the CEC1734-S0-I/2ZW-TCSM datasheet, CEC1734-S0-I/2ZW-TCSM pinout, CEC1734-S0-I/2ZW-TCSM application, or CEC1734-S0-I/2ZW-TCSM equivalent, key selection criteria include dual QSPI channel isolation capability, TCG DICE compliance, SPI flash intervention enforcement, and support for 1.8 V/3.3 V I/O voltage domains on VTR1/VTR2 power wells.
Technical Context
The CEC1734-S0-I/2ZW-TCSM implements two independent SPI flash monitor blocks - one per host (BMC and CPU) - each with dedicated 64 KB match RAM, real-time hash calculation (SHA-256/SHA-384) on 8 KB regions, and QSPI analog switch isolation. It uses dual runtime power wells (VTR1/VTR2) to independently supply SPI interface logic at either 1.8 V or 3.3 V, enabling coexistence with heterogeneous flash devices.
Its immutable Boot ROM enforces CNSA-compliant secure boot (SHA-384/ECC384), supports AES-256 encrypted SPI flash images, and implements life cycle management via fused OTP bits. The device delivers SPDM-based attestation, key revocation, rollback protection, and DICE-compliant CDI generation - all rooted in ROM-resident immutable code.
Key Specifications
| Parameter | Value and Actual Design Meaning |
|---|---|
| Core Processor | ARM Cortex-M4F @ 96 MHz with FPU and NVIC supporting 8 priority levels |
| Memory | 384 KB SRAM (320 KB code + 64 KB data); 8 Kbit OTP; 4 MB in-package SPI flash |
| SPI Monitoring | Dual-channel SPI flash monitoring with real-time intervention, 64 KB match RAM per channel |
| Crypto Acceleration | AES-128/192/256, SHA-256/384/512, ECDSA/P-384, RSA up to 4096-bit, DRNG with NIST SP800-90B compliance |
| Package & I/O | 84-pin WFBGA; dual 1.8 V/3.3 V configurable I/O banks (VTR1/VTR2); 71 GPIOs with glitch/UV protection |
| Security Compliance | TCG DICE (immutable ROM), NIST 800-193 PFR, CNSA, SPDM attestation, fused life cycle management |
| Power Management | Light Sleep and Heavy Sleep modes; always operates in lowest power state during normal operation |
Pinout & Package
CEC1734-S0-I/2ZW-TCSM is housed in an 84-pin WFBGA package (2ZW variant), supporting dual SPI flash monitoring with dedicated QSPI I/O banks for BMC and CPU channels. VTR1 and VTR2 power wells enable independent 1.8 V/3.3 V I/O voltage configuration per host interface.
| Pin/Terminal | Circuit Role | Design Meaning |
|---|---|---|
| GPIO055 / SPIMON_QSPI0_CS0# | SPI Monitor Channel 0 Chip Select | Asserted during BMC flash access; triggers real-time signature verification and intervention |
| GPIO124 / SPIMON_QSPI1_CS0# | SPI Monitor Channel 1 Chip Select | Asserted during CPU flash access; enables parallel, isolated integrity enforcement |
| GPIO020 / QSPI0_IN_CS0# | BMC Flash Input Chip Select | Direct connection to BMC SPI flash device; monitored by Channel 0 SPI filter |
| GPIO071 / QSPI1_IN_CS0# | CPU Flash Input Chip Select | Direct connection to CPU SPI flash device; monitored by Channel 1 SPI filter |
| VTR1 / VTR2 | Independent I/O Power Wells | VTR1 powers BMC-side QSPI I/O (e.g., GPIO020–GPIO023); VTR2 powers CPU-side QSPI I/O (e.g., GPIO070–GPIO071) |
| GPIO156 / LED0 & GPIO157 / LED1 | Breathing LED Outputs | Programmable blink/breathe waveforms for status indication; operational in all EC sleep states |
Key Features
| Feature | Design Value |
|---|---|
| Dual SPI Flash Monitoring | Two independent hardware monitors with 64 KB match RAM each, enabling concurrent BMC/CPU firmware integrity enforcement |
| QSPI Analog Switch Isolation | Hardware-level isolation between hosts and flash devices prevents unauthorized read/write/erase during runtime |
| TCG DICE Root of Trust | Immutable ROM-based DICE implementation generates cryptographically bound CDI for chain-of-trust attestation |
| Fused Life Cycle Management | OTP-controlled security state transitions (dev/test/prod) enforce phase-appropriate access to PUF, keys, and debug interfaces |
| SPDM Attestation Support | EC_FW implements SPDM responder commands returning certificates and runtime measurements for remote platform verification |
Applications
| Server BMC Integrity Enforcement | Telecom Baseband Controller Security |
|---|---|
|
Use Scenario: Enforcing firmware integrity during BMC boot and runtime in dual-socket x86 servers. IC Role / Device Role / Timing Role: Real-time SPI flash monitor acting as hardware-enforced gatekeeper between BMC SoC and its boot flash. Use Value: Prevents malicious firmware persistence by detecting and blocking illegal opcodes (e.g., chip erase) before execution, using per-channel 64 KB match RAM and SHA-384 hashing. |
Use Scenario: Securing boot and update paths for distributed baseband units in 5G RAN infrastructure. IC Role / Device Role / Timing Role: Platform root of trust controller validating signed firmware images and enforcing cryptographic rollback protection across field-upgradable modules. Use Value: Enables NIST 800-193 PFR-compliant recovery from compromised firmware via authenticated fallback image loading from internal 4 MB SPI flash. |
| Industrial Edge Gateway Trust Anchor | Network Equipment Secure Boot Manager |
|
Use Scenario: Providing hardware-rooted attestation and secure boot for time-sensitive industrial edge gateways with dual host processors. IC Role / Device Role / Timing Role: TCG DICE-compliant RoT generating CDI for SPDM-based remote verification of firmware health and configuration state. Use Value: Delivers cryptographically verifiable evidence of boot integrity and runtime behavior to cloud-based security orchestration platforms. |
Use Scenario: Mediating SPI flash access between network processor and control plane CPU in carrier-grade routers. IC Role / Device Role / Timing Role: Dual-channel SPI monitor enforcing regional access permissions and opcode whitelisting on shared flash resources. Use Value: Eliminates cross-host flash corruption risks by isolating BMC and CPU flash traffic through independent QSPI analog switches and per-channel intervention logic. |
Equivalent & Alternatives
The following parts are listed as comparable options for similar embedded controller security applications.
| Alternative Part | Technical Difference | Application Difference | Selection Advice |
|---|---|---|---|
| CEC1734-S0-I/2HW | 64-pin VFBGA; single SPI monitor channel; 2 MB internal SPI flash; 52 GPIOs | Supports only BMC-side flash monitoring; no CPU-side isolation or dual-voltage I/O banks | Select when system requires only one host (e.g., BMC-only architecture) and space/power constraints favor smaller package. |
| CEC1736-S0-I/2ZW | Same 84-pin WFBGA; adds tamper detection (temperature/voltage/side-channel); higher ECC key support (P-521) | Required for environments demanding physical tamper resistance and extended public-key flexibility | Select when deployment mandates NIST SP800-193 Class 3 tamper response or elliptic curve operations beyond P-384. |
Compared with CEC1734-S0-I/2ZW-TCSM, the CEC1734-S0-I/2HW lacks CPU-side monitoring and dual-voltage I/O, limiting it to single-host use cases; the CEC1736-S0-I/2ZW adds tamper sensing and extended crypto but shares identical dual-monitor architecture and pin compatibility - making it a drop-in upgrade for enhanced threat models.
Availability
CEC1734-S0-I/2ZW-TCSM is available at Aetrix Electronics and suitable for server BMC integrity enforcement, telecom baseband controller security, and industrial edge gateway trust anchor applications requiring stable component supply, long-term lifecycle support, and certified secure boot functionality.
Supply support for CEC1734-S0-I/2ZW-TCSM includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.
Manufacturer
Microchip Technology Inc. is a global semiconductor company specializing in microcontrollers, analog, FPGA, and security solutions, with emphasis on industrial, automotive, and communications markets.
The CEC173x family is designed as a real-time platform root of trust controller - delivering hardware-enforced firmware integrity, cryptographic acceleration, and SPDM-based attestation for servers, telecom infrastructure, and embedded computing systems.
FAQ
What is the primary security function of the CEC1734-S0-I/2ZW-TCSM in server platforms?
The CEC1734-S0-I/2ZW-TCSM serves as a hardware-enforced root of trust that monitors and intervenes in real time on both BMC and CPU SPI flash transactions. It validates firmware signatures during boot using SHA-384/ECC384, enforces regional access permissions at runtime, and blocks illegal opcodes - all implemented in dedicated dual-channel monitor logic within the CEC1734-S0-I/2ZW-TCSM die.
Does the CEC1734-S0-I/2ZW-TCSM support dual-voltage I/O for interfacing with mixed 1.8 V and 3.3 V flash devices?
Yes. The CEC1734-S0-I/2ZW-TCSM features two independent I/O power wells - VTR1 and VTR2 - each configurable for either 1.8 V or 3.3 V operation. This allows simultaneous interfacing with heterogeneous SPI flash devices (e.g., 1.8 V BMC flash and 3.3 V CPU flash), a capability confirmed in the CEC1734-S0-I/2ZW-TCSM datasheet Section 2.2 and Table 1-1.
How does the CEC1734-S0-I/2ZW-TCSM implement TCG DICE compliance?
The CEC1734-S0-I/2ZW-TCSM implements TCG DICE in immutable ROM code, generating a Device Identity Composite Identifier (CDI) derived from hardware-unique entropy and firmware measurements. Its DICE-compliant boot flow ensures cryptographically bound attestation evidence, validated by external requesters via SPDM protocols - a feature explicitly documented for the CEC1734-S0-I/2ZW-TCSM in DS00004571A-page 6 and page 15.
What is the role of the 64 KB match RAM in each SPI monitor block of the CEC1734-S0-I/2ZW-TCSM?
Each of the two SPI monitor blocks in the CEC1734-S0-I/2ZW-TCSM includes 64 KB of dedicated match RAM used to store pattern templates for real-time comparison against live SPI channel data. During boot, it verifies 8 KB flash regions via SHA-256/SHA-384; during runtime, it enforces access rules by matching command sequences - a hardware resource allocated exclusively per channel and confirmed in Table 1-1 of the CEC1734-S0-I/2ZW-TCSM datasheet.
Can the CEC1734-S0-I/2ZW-TCSM operate in low-power states while maintaining SPI flash monitoring capability?
Yes. The CEC1734-S0-I/2ZW-TCSM supports Light Sleep and Heavy Sleep modes where SPI flash monitoring remains fully active - including real-time hash calculation, pattern matching, and intervention logic. Its RTOS timer runs continuously off the 32 kHz oscillator across all sleep states, ensuring uninterrupted integrity enforcement without host processor involvement - a capability specified in DS00004571A-page 3 and page 5 for the CEC1734-S0-I/2ZW-TCSM.
CEC1734-S0-I/2ZW-TCSM Specifications
- Product attributes
- Attribute value
- Manufacturer:
- Microchip Technology
- Series:
- CryptoController™
- Package/Case:
- 84-WFBGA
- Packaging:
- Tray
- Product Status:
- Active
- Programmable:
- -
- Applications:
- Real Time Platform Root
- Core Processor:
- ARM® Cortex®-M4F
- Program Memory Type:
- OTP (1kB)
- Controller Series:
- CEC173X
- RAM Size:
- 384K x 8
- Interface:
- I2C, PWM, SMBus, SPI, UART
- Number of I/O:
- 71
- Voltage - Supply:
- 1.8V ~ 3.3V
- Operating Temperature:
- -40°C ~ 85°C
- Grade:
- -
- Qualification:
- -
- Mounting Type:
- Surface Mount
- Supplier Device Package:
- 84-WFBGA (7x7)
CEC1734-S0-I/2ZW-TCSM FAQ
1.How can I place an order for CEC1734-S0-I/2ZW-TCSM through Aetrix?
Please submit a Request for Quotation (RFQ) for CEC1734-S0-I/2ZW-TCSM on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.
2.Are the price and stock information for CEC1734-S0-I/2ZW-TCSM reliable?
The price and inventory of CEC1734-S0-I/2ZW-TCSM are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for CEC1734-S0-I/2ZW-TCSM is usually 5 days.
3.What payment methods are accepted for CEC1734-S0-I/2ZW-TCSM?
We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for CEC1734-S0-I/2ZW-TCSM transactions.
Note: Certain payment methods may incur a processing fee.
4.How is shipping managed for CEC1734-S0-I/2ZW-TCSM?
CEC1734-S0-I/2ZW-TCSM orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.
Once your CEC1734-S0-I/2ZW-TCSM order is processed, you will receive an email with the shipment details and tracking number.
Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.
5.How can I obtain technical support or documentation for CEC1734-S0-I/2ZW-TCSM?
For technical support, including CEC1734-S0-I/2ZW-TCSM datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your CEC1734-S0-I/2ZW-TCSM requirements.
6.How does Aetrix verify that CEC1734-S0-I/2ZW-TCSM is sourced from the original manufacturer or authorized distributors?
All CEC1734-S0-I/2ZW-TCSM products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that CEC1734-S0-I/2ZW-TCSM meets industry standards.
7.What is the process for return or replacement of CEC1734-S0-I/2ZW-TCSM?
All CEC1734-S0-I/2ZW-TCSM units undergo pre-shipment inspection (PSI). If there is an issue with CEC1734-S0-I/2ZW-TCSM, returns or replacements are accepted under the following conditions:
1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.
2.The issue is reported within 90 days of delivery.
3.The CEC1734-S0-I/2ZW-TCSM part is unused and in its original packaging.
Return procedure for CEC1734-S0-I/2ZW-TCSM:
1.Submit a request within 90 days.
2.Obtain a Return Material Authorization (RMA) from Aetrix.
CEC1734-S0-I/2ZW-TCSM Tags

-
CYPD3175-24LQXQ
Infineon Technologies

-
SLB9672VU20FW1523XTMA1
Infineon Technologies

-
SLB9670VQ20FW785XTMA1
Infineon Technologies

-
SLB9672XU20FW1523XTMA1
Infineon Technologies

-
SLB9673XU20FW2613XTMA1
Infineon Technologies

-
CYPD3125-40LQXIT
Infineon Technologies

-
AT97SC3204-U2A1A-20
Microchip Technology

-
AT97SC3204-U2A1A-10
Microchip Technology

-
SLM9670AQ20FW1311XTMA1
Infineon Technologies

-
SLB9672XU20FW1613XTMA1
Infineon Technologies

-
SLB9672AU20FW1613XTMA1
Infineon Technologies

-
SLB9673AU20FW2613XTMA1
Infineon Technologies
Tech Hub
TTL and CMOS logic families differ in thresholds, loading, output drive, power and timing. This engineering guide compares 74HC and 74HCT, calculates noise margins and checks 3.3 V/5 V compatibility.
A practical engineering guide to 3.3V and 5V logic compatibility, input thresholds, resistor dividers, translator ICs, MOSFET level shifting, I2C pull-ups, timing limits and power-sequencing risks.
The 74HC595 uses push-pull logic outputs, while the TPIC6B595 uses 50 V open-drain DMOS sinks for higher-power loads. This guide compares timing, current limits, 3.3 V interfacing, load wiring, thermal…
The 74HC595 converts serial data into eight stable parallel outputs. This guide covers pin functions, shift and storage timing, OE and MR behavior, drive-current limits, cascading, voltage compatibilit…
A technical comparison of level-sensitive latches and edge-triggered flip-flops, covering timing windows, setup and hold limits, master–slave operation, time borrowing, race-through, HDL inference and…
A D latch stores one bit while Enable controls when data can pass. This reference covers gate-level operation, truth tables, transparency, setup and hold timing, LE versus OE, common ICs and practical …
An SR latch stores one bit through cross-coupled feedback. This engineering reference covers NOR and NAND implementations, truth tables, forbidden-state recovery, gated operation, switch debouncing, fa…
Latch circuits retain one bit through feedback. This technical reference covers SR and D latches, truth tables, transparency, timing limits, latch-versus-flip-flop behavior, applications and common log…
An engineering guide to LED driver operation, constant-current and constant-voltage outputs, linear and switching topologies, dimming, IC selection, calculations, replacement compatibility, and fault c…
Operational amplifier guide covering op amp basics, feedback, ideal vs real op amps, common configurations, buffer circuits, offset, bias current, gain-bandwidth, slew rate, rail-to-rail limits and sel…
