Microchip Technology CEC1736-S0-I/2HW-PROTO
- Part No.:
- CEC1736-S0-I/2HW-PROTO
- Manufacturer:
- Microchip Technology
- Category:
- Application Specific Microcontrollers
- Package:
- 64-VFBGA
- Datasheet:
-
CEC1736-S0-I/2HW-PROTO.pdf
- Description:
- 1-CHANNEL PFR WITH 2MB FLASH AND
- Quantity:
- Payment:

- Shipping:

Inventory:2,676
Please send an inquiry. Send us your inquiry, and we will respond immediately.
Product details
Overview
CEC1736-S0-I/2HW-PROTO from Microchip Technology is a pre-provisioned Real Time Platform Root of Trust Controller implementing NIST 800-193 and OCP Security compliance. It features a 96 MHz ARM Cortex-M4F core, hardware-accelerated AES256/SHA-384/ECDSA/P-384 secure boot, SPI flash monitoring for one Application Processor, and 64-pin VFBGA (5.5×5.5×0.92 mm) packaging. It enables secure boot and runtime attestation in server and telecom baseboard management.
For engineers reviewing the CEC1736-S0-I/2HW-PROTO datasheet, CEC1736-S0-I/2HW-PROTO pinout, CEC1736-S0-I/2HW-PROTO application, or CEC1736-S0-I/2HW-PROTO equivalent, key selection criteria include single-QSPI support, Soteria-G3 firmware pre-installation, PUF-based key generation, lifecycle-managed OTP, and I²C-based crisis recovery - all validated for production-grade platform resiliency.
Technical Context
The CEC1736-S0-I/2HW-PROTO implements an immutable Boot ROM that loads and authenticates Soteria-G3 firmware from internal SPI flash, then enforces secure boot of AP firmware via real-time hash verification during external flash reads. Its SPI Monitor operates on a single QSPI port (QSPI0), enforcing memory protection regions and intervening on illegal opcodes like Chip Erase before execution.
It integrates a hardware Key Management Engine with True Random Number Generator (SP800-90B), Physically Unclonable Function (PUF), and differential power analysis countermeasures. Power management supports light/heavy sleep states with configurable wake events including GPIO, and fused lifecycle security gates access to OTP, PUF, and crypto resources per development phase.
Key Specifications
| Parameter | Value and Actual Design Meaning |
|---|---|
| Core | ARM Cortex-M4F @ 96 MHz - enables deterministic real-time execution of Soteria-G3 security services with FPU support for cryptographic operations. |
| Crypto Acceleration | AES256, SHA-384, ECDSA, P-384 - offloads asymmetric signing, hashing, and encryption from firmware, reducing boot latency and CPU load. |
| SPI Monitoring | Single QSPI0 port with real-time signature calculation and intervention - protects one Application Processor's external flash against unauthorized writes/erases without requiring flash vendor-specific features. |
| Memory | 2 MB or 4 MB internal flash + OTP + SRAM - stores signed Soteria-G3 images, customer certificate chains, and runtime data with lockable key storage in OTP. |
| Package | 64-pin VFBGA (2HW), 5.5×5.5×0.92 mm - optimized for space-constrained BMS and baseboard controller layouts with standard reflow compatibility. |
| Power Options | User-configurable 1.8 V or 3.3 V I/O - allows direct interfacing with APs and flash devices operating at either voltage without level-shifting. |
| Security Compliance | NIST SP 800-193, OCP Security Project, SPDM 1.2 - delivers certified platform resiliency, component attestation, and firmware rollback protection out-of-box. |
Pinout & Package
CEC1736-S0-I/2HW-PROTO uses a 64-pin Very Thin Fine-Pitch Ball Grid Array (VFBGA) package (2HW), measuring 5.5 mm × 5.5 mm × 0.92 mm, with 0.4 mm ball pitch and bottom-side solder balls. This package supports one QSPI interface (QSPI0), dual I²C ports, UART/SWD/JTAG debug interfaces, and 48 GPIOs with configurable functions including reset control, violation detection, and LED signaling.
| Pin/Terminal | Circuit Role | Design Meaning |
|---|---|---|
| GPIO000 / SPI0_KILL# / SPI0_RESET# | Secure kill/reset signal | Asserts hardware reset or kills SPI0 transactions upon security violation or remote command - critical for fail-safe flash isolation. |
| GPIO002 / QSPI0_CS1# / SPIMON_QSPI0_CS1# | QSPI0 chip select 1 | Enables second external SPI flash device under QSPI0; monitored by SPI Monitor for integrity enforcement during AP boot/runtime. |
| GPIO020 / QSPI0_IN_CS0# | QSPI0 input chip select 0 | Directly controls first external SPI flash; monitored for illegal access patterns and used to gate AP firmware reads during authentication. |
| GPIO106 / AP0_RESET# | Application Processor 0 reset | Holds AP0 in reset until Soteria-G3 validates all critical firmware images - ensures no untrusted code executes before root-of-trust establishment. |
| GPIO144 / I2C04_SCL / REMOTE_ACCESS | I²C clock with remote access flag | Provides secure I²C channel for AP0 to query runtime status, attestations, and crisis recovery commands - isolated from general-purpose I²C buses. |
Key Features
| Feature | Design Value |
|---|---|
| Hardware CNSA-Based Secure Boot | Implements P-384 elliptic curve cryptography in ROM to establish immutable root-of-trust - eliminates software-only boot vulnerabilities and enables FIPS 140-3-aligned validation paths. |
| SPI Flash Monitoring with Intervention | Real-time opcode inspection and hardware-level transaction cancellation on illegal flash commands - works with standard 8-pin NOR flash, eliminating need for proprietary secure flash. |
| PUF-Based Key Generation | Derives device-unique cryptographic keys from silicon physical variations - eliminates key injection, provisioning overhead, and supply-chain key leakage risks. |
| Soteria-G3 Firmware Pre-Installation | Ships with MISRA-compliant, Coverity/CERT-analyzed, third-party penetration-tested firmware - reduces time-to-secure-boot from months to days for OEMs. |
| SPDM-Compliant Attestation | Supports standardized Platform Security Data Model commands for remote verification of firmware integrity and configuration - required for OCP-compliant data center platforms. |
Applications
| Server Baseboard Management | Telecom Edge Router Security |
|---|---|
Use Scenario: Embedded in server motherboard to manage BMC trust chain and validate UEFI/BIOS images prior to CPU release. IC Role / Device Role / Timing Role: Real-time Platform Root of Trust Controller enforcing secure boot, runtime attestation, and firmware rollback protection. Use Value: Prevents persistent firmware implants by verifying image hashes during AP boot and re-authenticating during runtime reads - validated against NIST 800-193 resiliency requirements. | Use Scenario: Integrated into carrier-grade edge router to protect bootloader and packet-processing firmware from tampering. IC Role / Device Role / Timing Role: Secure co-processor managing AP0 reset, SPI flash integrity, and I²C-based crisis recovery for primary network processor. Use Value: Enables zero-touch recovery of corrupted firmware via secure I²C commands without requiring physical access or JTAG - compliant with OCP Security Project v2.0. |
| Industrial Control Gateway | Embedded AI Accelerator Board |
Use Scenario: Deployed in industrial gateway to authenticate field-upgradable firmware for PLC and sensor interface modules. IC Role / Device Role / Timing Role: Lifecycle-managed security anchor validating signed firmware updates and enforcing rollback protection across multiple subsystems. Use Value: Guarantees only cryptographically signed, version-locked firmware executes - prevents downgrade attacks targeting known CVEs in older firmware revisions. | Use Scenario: Used on AI accelerator card to verify integrity of FPGA bitstreams and inference engine binaries before loading into memory. IC Role / Device Role / Timing Role: Hardware-enforced boot guard controlling AP0 reset and monitoring QSPI0 flash access for AI workload firmware. Use Value: Detects and blocks malicious bitstream modifications during PCIe hot-plug or warm-reboot sequences - supported by real-time SPI Monitor intervention on illegal flash erase commands. |
Equivalent & Alternatives
The following parts are listed as comparable options for similar platform root-of-trust applications.
| Alternative Part | Technical Difference | Application Difference | Selection Advice |
|---|---|---|---|
| CEC1736-S0-I/2ZW-TFLX | 84-pin WFBGA (7×7×0.8 mm); dual QSPI ports supporting two APs and four external flash devices. | Required for multi-processor systems (e.g., dual-CPU servers) needing independent SPI monitoring per AP. | Select when system architecture requires concurrent secure boot and runtime monitoring for two Application Processors. |
| CEC1706-S0-I/2HW | Legacy CEC170x family; lacks Soteria-G3 firmware, SPDM attestation, and PUF - relies on customer-developed firmware stack. | Suitable only for cost-sensitive designs where full NIST 800-193 compliance is not mandated and firmware development resources exist. | Choose only if backward compatibility with existing CEC170x-based designs is required and Soteria-G3 features are unnecessary. |
Compared with CEC1736-S0-I/2HW-PROTO, the 2ZW variant adds hardware scalability for dual-AP architectures but increases PCB area and BOM cost, while the CEC1706 offers lower unit cost at the expense of certified security features, longer development cycles, and no pre-validated firmware stack.
Availability
CEC1736-S0-I/2HW-PROTO is available at Aetrix Electronics and suitable for server baseboard management, telecom edge infrastructure, and industrial control gateway applications requiring stable component supply, long-term lifecycle assurance, and certified platform resiliency.
Supply support for CEC1736-S0-I/2HW-PROTO includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.
Manufacturer
Microchip Technology Inc. is a global semiconductor manufacturer specializing in microcontrollers, analog devices, and security ICs, with design centers and manufacturing facilities across the Americas, Europe, and Asia.
The CEC173x TrustFLEX family was developed to deliver production-ready, NIST 800-193–compliant platform root-of-trust controllers for data center, telecom, and industrial systems - eliminating the need for custom secure boot firmware development.
FAQ
What is the primary function of the CEC1736-S0-I/2HW-PROTO in a server platform?
The CEC1736-S0-I/2HW-PROTO serves as the Real Time Platform Root of Trust Controller, enforcing secure boot of Application Processor firmware via hardware-accelerated cryptographic verification, SPI flash monitoring, and runtime attestation. In server platforms, it holds the AP in reset until all critical images pass authentication, then releases reset and provides I²C-based status reporting - directly enabling NIST 800-193 platform resiliency compliance. The CEC1736-S0-I/2HW-PROTO integrates this functionality in a single 64-pin VFBGA package with pre-installed Soteria-G3 firmware.
Does the CEC1736-S0-I/2HW-PROTO support dual Application Processors?
No, the CEC1736-S0-I/2HW-PROTO supports only one Application Processor via its single QSPI0 interface. It is the 64-pin 2HW package variant, explicitly designated for single-AP configurations per Microchip's documentation. Dual-AP support requires the 84-pin 2ZW package (e.g., CEC1736-S0-I/2ZW-TFLX), which provides two independent QSPI ports with dedicated SPI monitors. The CEC1736-S0-I/2HW-PROTO pinout and package specifications confirm exclusive QSPI0 routing and absence of QSPI1 signals.
How does the SPI Monitor in the CEC1736-S0-I/2HW-PROTO differ from standard flash protection mechanisms?
The CEC1736-S0-I/2HW-PROTO SPI Monitor performs real-time, hardware-level intervention on illegal SPI commands - such as Chip Erase or Write Enable - before they reach the external flash device, unlike software-based or region-locking schemes. It calculates image hashes during AP reads and enforces memory protection regions with configurable violation responses. This capability works with standard 8-pin NOR flash, requires no flash vendor extensions, and operates independently of AP firmware - a feature confirmed in DS00005397A sections 6.2 and Figure 2-1. The CEC1736-S0-I/2HW-PROTO implements this on QSPI0 only.
What firmware is pre-installed on the CEC1736-S0-I/2HW-PROTO, and is it customizable?
The CEC1736-S0-I/2HW-PROTO ships with Soteria-G3 firmware pre-installed in internal flash - a MISRA-compliant, Coverity/CERT-analyzed, third-party penetration-tested implementation supporting Secure Boot, SPDM attestation, crisis recovery, and key revocation. Customers can customize behavior via OTP configuration, AP_CFG tables, and hash tables stored in external flash, but the core Soteria-G3 binary is immutable and verified at boot by the Boot ROM. This pre-provisioned state is defined in DS00005397A section 1.0 as the "partially configured and provisioned variant" of the CEC173x family.
Can the CEC1736-S0-I/2HW-PROTO operate at both 1.8 V and 3.3 V I/O voltages?
Yes, the CEC1736-S0-I/2HW-PROTO supports user-configurable 1.8 V or 3.3 V I/O power specification, as stated in the Hardware Features list on DS00005397A page 1. This is implemented via OTP settings and allows direct interfacing with APs and SPI flash devices operating at either voltage without external level shifters. The dual-voltage capability applies to all GPIOs, QSPI, I²C, and UART interfaces - a key differentiator from fixed-voltage security controllers. This flexibility is explicitly enabled in the CEC1736-S0-I/2HW-PROTO's power architecture.
CEC1736-S0-I/2HW-PROTO Specifications
- Product attributes
- Attribute value
- Manufacturer:
- Microchip Technology
- Series:
- CryptoController™
- Package/Case:
- 64-VFBGA
- Packaging:
- Tray
- Product Status:
- Obsolete
- Programmable:
- Not Verified
- Applications:
- -
- Core Processor:
- ARM® Cortex®-M4F
- Program Memory Type:
- -
- Controller Series:
- CEC173X
- RAM Size:
- 384K x 8
- Interface:
- I2C, PWM, SMBus, SPI, UART
- Number of I/O:
- 52
- Voltage - Supply:
- 3.135V ~ 3.465V
- Operating Temperature:
- -40°C ~ 85°C (TA)
- Grade:
- -
- Qualification:
- -
- Mounting Type:
- Surface Mount
- Supplier Device Package:
- 64-VFBGA (5.5x5.5)
CEC1736-S0-I/2HW-PROTO FAQ
1.How can I place an order for CEC1736-S0-I/2HW-PROTO through Aetrix?
Please submit a Request for Quotation (RFQ) for CEC1736-S0-I/2HW-PROTO on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.
2.Are the price and stock information for CEC1736-S0-I/2HW-PROTO reliable?
The price and inventory of CEC1736-S0-I/2HW-PROTO are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for CEC1736-S0-I/2HW-PROTO is usually 5 days.
3.What payment methods are accepted for CEC1736-S0-I/2HW-PROTO?
We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for CEC1736-S0-I/2HW-PROTO transactions.
Note: Certain payment methods may incur a processing fee.
4.How is shipping managed for CEC1736-S0-I/2HW-PROTO?
CEC1736-S0-I/2HW-PROTO orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.
Once your CEC1736-S0-I/2HW-PROTO order is processed, you will receive an email with the shipment details and tracking number.
Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.
5.How can I obtain technical support or documentation for CEC1736-S0-I/2HW-PROTO?
For technical support, including CEC1736-S0-I/2HW-PROTO datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your CEC1736-S0-I/2HW-PROTO requirements.
6.How does Aetrix verify that CEC1736-S0-I/2HW-PROTO is sourced from the original manufacturer or authorized distributors?
All CEC1736-S0-I/2HW-PROTO products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that CEC1736-S0-I/2HW-PROTO meets industry standards.
7.What is the process for return or replacement of CEC1736-S0-I/2HW-PROTO?
All CEC1736-S0-I/2HW-PROTO units undergo pre-shipment inspection (PSI). If there is an issue with CEC1736-S0-I/2HW-PROTO, returns or replacements are accepted under the following conditions:
1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.
2.The issue is reported within 90 days of delivery.
3.The CEC1736-S0-I/2HW-PROTO part is unused and in its original packaging.
Return procedure for CEC1736-S0-I/2HW-PROTO:
1.Submit a request within 90 days.
2.Obtain a Return Material Authorization (RMA) from Aetrix.
CEC1736-S0-I/2HW-PROTO Tags

-
CYPD3175-24LQXQ
Infineon Technologies

-
SLB9672VU20FW1523XTMA1
Infineon Technologies

-
SLB9670VQ20FW785XTMA1
Infineon Technologies

-
SLB9672XU20FW1523XTMA1
Infineon Technologies

-
SLB9673XU20FW2613XTMA1
Infineon Technologies

-
CYPD3125-40LQXIT
Infineon Technologies

-
AT97SC3204-U2A1A-20
Microchip Technology

-
AT97SC3204-U2A1A-10
Microchip Technology

-
SLM9670AQ20FW1311XTMA1
Infineon Technologies

-
SLB9672XU20FW1613XTMA1
Infineon Technologies

-
SLB9672AU20FW1613XTMA1
Infineon Technologies

-
SLB9673AU20FW2613XTMA1
Infineon Technologies
Tech Hub
TTL and CMOS logic families differ in thresholds, loading, output drive, power and timing. This engineering guide compares 74HC and 74HCT, calculates noise margins and checks 3.3 V/5 V compatibility.
A practical engineering guide to 3.3V and 5V logic compatibility, input thresholds, resistor dividers, translator ICs, MOSFET level shifting, I2C pull-ups, timing limits and power-sequencing risks.
The 74HC595 uses push-pull logic outputs, while the TPIC6B595 uses 50 V open-drain DMOS sinks for higher-power loads. This guide compares timing, current limits, 3.3 V interfacing, load wiring, thermal…
The 74HC595 converts serial data into eight stable parallel outputs. This guide covers pin functions, shift and storage timing, OE and MR behavior, drive-current limits, cascading, voltage compatibilit…
A technical comparison of level-sensitive latches and edge-triggered flip-flops, covering timing windows, setup and hold limits, master–slave operation, time borrowing, race-through, HDL inference and…
A D latch stores one bit while Enable controls when data can pass. This reference covers gate-level operation, truth tables, transparency, setup and hold timing, LE versus OE, common ICs and practical …
An SR latch stores one bit through cross-coupled feedback. This engineering reference covers NOR and NAND implementations, truth tables, forbidden-state recovery, gated operation, switch debouncing, fa…
Latch circuits retain one bit through feedback. This technical reference covers SR and D latches, truth tables, transparency, timing limits, latch-versus-flip-flop behavior, applications and common log…
An engineering guide to LED driver operation, constant-current and constant-voltage outputs, linear and switching topologies, dimming, IC selection, calculations, replacement compatibility, and fault c…
Operational amplifier guide covering op amp basics, feedback, ideal vs real op amps, common configurations, buffer circuits, offset, bias current, gain-bandwidth, slew rate, rail-to-rail limits and sel…
