Send an Inquiry

To receive a quote for your project, please fill in the following information, and we’ll get back to you promptly.

Name*
Company*
Email Address*
Phone/WhatsApp
Part Number*
Quantity*
Message
Submit Inventory List

Please fill in the following information, and we’ll get back to you promptly.

Name*
Company*
Email Address*
Phone/WhatsApp
Upload My List
Message

Microchip Technology CEC1736-S0-I/2HW-PROTO2

Part No.:
CEC1736-S0-I/2HW-PROTO2
Manufacturer:
Microchip Technology
Category:
Application Specific Microcontrollers
Package:
64-VFBGA
Datasheet:
AetrixCEC1736-S0-I/2HW-PROTO2.pdf
Description:
MICROCONTROLLER
Quantity:
Payment:
Payment
Shipping:
Shipping

Inventory:358

Please send an inquiry. Send us your inquiry, and we will respond immediately.

Part Number
Quantity*
Price
Name*
Company
Email*
Comments

Product details

Overview

CEC1736-S0-I/2HW-PROTO2 from Microchip Technology is a pre-provisioned Real Time Platform Root of Trust Controller implementing NIST 800-193 and OCP Security-compliant Soteria-G3 firmware. It features a 96 MHz ARM Cortex-M4F core, hardware-accelerated P-384 ECDSA, AES-256, SHA-384, SP800-90B TRNG, and SPI Flash monitoring for up to one Application Processor with dual external SPI flash devices - deployed in server boot integrity and telecom platform attestation systems.

For engineers reviewing the CEC1736-S0-I/2HW-PROTO2 datasheet, CEC1736-S0-I/2HW-PROTO2 pinout, CEC1736-S0-I/2HW-PROTO2 application, or CEC1736-S0-I/2HW-PROTO2 equivalent, key selection considerations include 64-pin VFBGA package compatibility, QSPI0-only monitoring capability, 1.8V/3.3V configurable I/O power, fused lifecycle management, and SPDM-compliant component attestation support.

Technical Context

The CEC1736-S0-I/2HW-PROTO2 implements an immutable Boot ROM that loads and authenticates Soteria-G3 firmware from internal flash before enabling secure boot of Application Processor images. Its single QSPI0 interface supports real-time signature verification and opcode-level integrity checking during AP firmware load and runtime execution.

SPI Monitor logic operates in both passive observation and active intervention modes - blocking illegal flash commands (e.g., Chip Erase) before completion using hardware-level signal control. The device integrates a Key Management Engine, PUF-based identity generation, and lockable OTP storage, all gated by fused lifecycle states (development/test/production).

Key Specifications

ParameterValue and Actual Design Meaning
CoreARM Cortex-M4F @ 96 MHz - enables deterministic real-time cryptographic processing and low-latency AP reset control.
Crypto AccelerationAES-256, SHA-384, ECDSA (P-384), DRNG - offloads crypto operations from firmware, reducing boot latency and attack surface.
Secure Boot ScopeAuthenticates up to two AP firmware images per QSPI channel - supports primary/fallback/golden image policies with criticality enforcement.
Flash MonitoringQSPI0-only SPI Monitor with real-time hash calculation and hardware intervention - protects one AP's dual SPI flash against unauthorized erase/write.
Package64-pin VFBGA (2HW), 5.5×5.5×0.92 mm - optimized for space-constrained server baseboard management controller (BMC) layouts.
I/O VoltageUser-configurable 1.8V or 3.3V - allows direct interfacing with diverse APs and flash devices without level-shifting.
Internal Memory2 MB or 4 MB internal flash + OTP + SRAM - stores signed Soteria-G3 images, certificate chains, and runtime attestation data.

Pinout & Package

CEC1736-S0-I/2HW-PROTO2 uses a 64-pin Very Thin Fine-Pitch Ball Grid Array (VFBGA) package, 5.5 mm × 5.5 mm × 0.92 mm body, with 0.4 mm ball pitch. This variant supports only QSPI0 (no QSPI1), limiting it to one Application Processor with up to two external SPI flash components.

Pin/TerminalCircuit RoleDesign Meaning
GPIO000/SPI0_KILL/SPI0_RESET#Secure kill/reset controlAsserts hardware reset to disable SPI0 access on violation - used for emergency lockdown of monitored flash.
GPIO002/QSPI0_CS1#/SPIMON_QSPI0_CS1#QSPI0 chip select 1Enables second external SPI flash device under real-time monitoring - required for dual-flash AP configurations.
GPIO020/QSPI0_IN_CS0#QSPI0 input CS0Monitors chip select activity for first external SPI flash - triggers hash calculation and violation detection during AP read/write cycles.
GPIO106/AP0_RESET#Application Processor resetHolds AP0 in reset until Soteria-G3 validates all critical firmware images - enforces boot gate enforcement.
GPIO131/AP1_RESET#Application Processor 1 resetNot functional in 2HW package - reserved but unconnected; confirms single-AP scope of this variant.
GPIO144/I2C04_SCL/REMOTE_ACCESSI²C clock with remote accessProvides authenticated status reporting and crisis recovery commands over dedicated I²C bus - supports out-of-band platform attestation.

Key Features

FeatureDesign Value
Hardware CNSA-Based Secure BootImplements P-384 elliptic curve cryptography in silicon - meets CNSA Suite requirements for high-assurance boot without software dependency.
SPI Flash Monitoring with InterventionBlocks illegal flash commands (e.g., Chip Erase) at hardware level - prevents persistent firmware corruption even if AP is compromised.
SPDM-Compliant AttestationGenerates cryptographically signed platform measurements via standardized SPDM commands - enables remote verification of runtime integrity.
Fused Lifecycle ManagementHardwired state transitions (dev → test → production) - prevents rollback to insecure configurations or re-provisioning after deployment.
PUF-Based Identity GenerationDerives unique device identity from silicon variation - eliminates need for stored keys and resists physical extraction attacks.

Applications

Server BMC SecurityTelecom Baseband Unit

Use Scenario: Embedded in server baseboard management controllers to enforce secure boot of host CPU firmware and monitor SPI flash integrity during BIOS/UEFI updates.

IC Role / Device Role / Timing Role: Root of Trust controller performing pre-boot authentication, real-time flash monitoring, and I²C-based status reporting to BMC host.

Use Value: Prevents persistent firmware implants by blocking unauthorized flash writes and validating image hashes before AP release - meeting NIST 800-193 platform resiliency requirements.

Use Scenario: Integrated into 5G radio unit baseband processors to verify integrity of FPGA configuration bitstreams and DSP firmware loaded from external SPI flash.

IC Role / Device Role / Timing Role: Dedicated security co-processor managing secure boot gating, runtime re-authentication, and SPDM attestation responses over I²C.

Use Value: Enables carrier-grade trust assurance through hardware-enforced image validation and tamper-evident runtime measurement reporting - satisfying OCP Telecom Security Project mandates.

Industrial Edge GatewayNetwork Switch Trusted Boot

Use Scenario: Deployed in industrial edge gateways to protect Linux kernel and real-time OS firmware images stored across dual SPI flash devices.

IC Role / Device Role / Timing Role: Real-time platform root of trust enforcing secure boot policy, rollback protection, and crisis recovery via I²C-managed firmware update.

Use Value: Guarantees firmware authenticity across field updates using PLDM-based secure firmware updates - eliminating risk of supply-chain compromise during remote maintenance.

Use Scenario: Used in enterprise network switches to authenticate bootloader and switch OS images prior to CPU initialization and enforce runtime flash access controls.

IC Role / Device Role / Timing Role: Hardware-enforced boot gatekeeper with SPI monitor intervention and cryptographic key revocation capability.

Use Value: Mitigates ransomware-style flash corruption by detecting and aborting malicious erase/program sequences - ensuring switch uptime and configuration continuity.

Equivalent & Alternatives

The following parts are listed as comparable options for similar platform root of trust applications.

Alternative PartTechnical DifferenceApplication DifferenceSelection Advice
CEC1736-S0-I/2ZW-TFLX84-pin WFBGA with dual QSPI ports (QSPI0 + QSPI1) - supports two independent Application Processors.Required for multi-AP systems (e.g., dual-CPU servers); not pin-compatible with 2HW package.Select when system requires concurrent monitoring of two SPI flash buses - no PCB redesign possible due to different ball count and layout.
CEC1706-S0-I/2HWLegacy CEC170x family part with Soteria-G2 firmware - lacks SPDM attestation, CNSA crypto suite, and PUF-based identity.Suitable for cost-sensitive legacy designs where NIST 800-193 compliance is not mandated.Choose only for brownfield upgrades where Soteria-G3 features are unnecessary - firmware and security capabilities are not upward compatible.

Compared with CEC1736-S0-I/2HW-PROTO2, the 2ZW variant adds QSPI1 support for dual-AP scalability but requires full mechanical redesign, while the CEC1706 offers lower security assurance and no path to Soteria-G3 feature set - making CEC1736-S0-I/2HW-PROTO2 the sole option for new NIST/OCP-compliant single-AP deployments.

Availability

CEC1736-S0-I/2HW-PROTO2 is available at Aetrix Electronics and suitable for server BMC security, telecom baseband unit integrity, and industrial edge gateway trusted boot requiring stable component supply, long-term lifecycle support, and certified firmware provisioning.

Supply support for CEC1736-S0-I/2HW-PROTO2 includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.

Manufacturer

Microchip Technology Inc. is a U.S.-based semiconductor manufacturer specializing in microcontrollers, analog devices, and security ICs, with global design, manufacturing, and support infrastructure.

The CEC173x TrustFLEX family delivers Real Time Platform Root of Trust Controllers targeting NIST 800-193 and OCP-compliant systems - designed specifically for hardware-enforced secure boot, runtime attestation, and resilient firmware update in servers, telecom, and industrial infrastructure.

FAQ

What security standards does the CEC1736-S0-I/2HW-PROTO2 comply with?

The CEC1736-S0-I/2HW-PROTO2 complies with NIST Special Publication 800-193 (Platform Firmware Resilience) and Open Compute Project (OCP) Security Project requirements. It implements CNSA Suite cryptographic algorithms (P-384 ECDSA, AES-256, SHA-384), SP800-90B TRNG, and SPDM-compliant attestation - all verified in the Soteria-G3 firmware stack shipped pre-provisioned on the device.

Does the CEC1736-S0-I/2HW-PROTO2 support dual Application Processors?

No, the CEC1736-S0-I/2HW-PROTO2 supports only one Application Processor via its single QSPI0 interface. The 2HW package variant lacks QSPI1 signals and associated pins - confirmed by the pinout table showing AP1_RESET# as reserved and unconnected. For dual-AP support, the 84-pin CEC1736-S0-I/2ZW-TFLX must be used instead.

What is the role of the SPI Monitor in the CEC1736-S0-I/2HW-PROTO2?

The SPI Monitor in the CEC1736-S0-I/2HW-PROTO2 performs real-time hash calculation and hardware-level intervention on QSPI0 traffic. It detects violations such as illegal flash commands (e.g., Chip Erase) and blocks them before completion by asserting control over SPI signals - protecting the connected SPI flash from persistent corruption even if the Application Processor is compromised.

Can the CEC1736-S0-I/2HW-PROTO2 perform runtime re-authentication of AP firmware?

Yes, the CEC1736-S0-I/2HW-PROTO2 performs runtime re-authentication of AP firmware images during normal operation. As the Application Processor reads firmware from external SPI flash, the device recalculates image hashes in real time and reports authentication status over the dedicated I²C port - enabling continuous integrity verification beyond initial boot.

How is device identity secured in the CEC1736-S0-I/2HW-PROTO2?

Device identity in the CEC1736-S0-I/2HW-PROTO2 is secured using a hardware-based Physically Unclonable Function (PUF) compliant with SP800-162. The PUF generates a unique, repeatable cryptographic key derived from intrinsic silicon variations - eliminating the need for stored secrets and resisting physical extraction or cloning attacks throughout the device's lifecycle.

CEC1736-S0-I/2HW-PROTO2 Specifications

Product attributes
Attribute value
Manufacturer:
Microchip Technology
Series:
CryptoController™
Package/Case:
64-VFBGA
Packaging:
Tray
Product Status:
Active
Programmable:
-
Applications:
Real Time Platform Root
Core Processor:
ARM® Cortex®-M4F
Program Memory Type:
OTP (1kB)
Controller Series:
CEC173X
RAM Size:
384K x 8
Interface:
I2C, PWM, SMBus, SPI, UART
Number of I/O:
52
Voltage - Supply:
3.135V ~ 3.465V
Operating Temperature:
-40°C ~ 85°C
Grade:
-
Qualification:
-
Mounting Type:
Surface Mount
Supplier Device Package:
64-VFBGA (5.5x5.5)

CEC1736-S0-I/2HW-PROTO2 FAQ

1.How can I place an order for CEC1736-S0-I/2HW-PROTO2 through Aetrix?

Please submit a Request for Quotation (RFQ) for CEC1736-S0-I/2HW-PROTO2 on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.

2.Are the price and stock information for CEC1736-S0-I/2HW-PROTO2 reliable?

The price and inventory of CEC1736-S0-I/2HW-PROTO2 are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for CEC1736-S0-I/2HW-PROTO2 is usually 5 days.

3.What payment methods are accepted for CEC1736-S0-I/2HW-PROTO2?

We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for CEC1736-S0-I/2HW-PROTO2 transactions.

Note: Certain payment methods may incur a processing fee.

4.How is shipping managed for CEC1736-S0-I/2HW-PROTO2?

CEC1736-S0-I/2HW-PROTO2 orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.

Once your CEC1736-S0-I/2HW-PROTO2 order is processed, you will receive an email with the shipment details and tracking number.

Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.

5.How can I obtain technical support or documentation for CEC1736-S0-I/2HW-PROTO2?

For technical support, including CEC1736-S0-I/2HW-PROTO2 datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your CEC1736-S0-I/2HW-PROTO2 requirements.

6.How does Aetrix verify that CEC1736-S0-I/2HW-PROTO2 is sourced from the original manufacturer or authorized distributors?

All CEC1736-S0-I/2HW-PROTO2 products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that CEC1736-S0-I/2HW-PROTO2 meets industry standards.

7.What is the process for return or replacement of CEC1736-S0-I/2HW-PROTO2?

All CEC1736-S0-I/2HW-PROTO2 units undergo pre-shipment inspection (PSI). If there is an issue with CEC1736-S0-I/2HW-PROTO2, returns or replacements are accepted under the following conditions:

1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.

2.The issue is reported within 90 days of delivery.

3.The CEC1736-S0-I/2HW-PROTO2 part is unused and in its original packaging.

Return procedure for CEC1736-S0-I/2HW-PROTO2:

1.Submit a request within 90 days.

2.Obtain a Return Material Authorization (RMA) from Aetrix.

CEC1736-S0-I/2HW-PROTO2 Tags

  • CEC1736-S0-I/2HW-PROTO2
  • CEC1736-S0-I/2HW-PROTO2 PDF
  • CEC1736-S0-I/2HW-PROTO2 Datasheet
  • CEC1736-S0-I/2HW-PROTO2 Specifications
  • CEC1736-S0-I/2HW-PROTO2 Images
  • Microchip Technology
  • Microchip Technology CEC1736-S0-I/2HW-PROTO2
  • Buy CEC1736-S0-I/2HW-PROTO2
  • CEC1736-S0-I/2HW-PROTO2 Price
  • CEC1736-S0-I/2HW-PROTO2 Distributor
  • CEC1736-S0-I/2HW-PROTO2 Supplier
  • CEC1736-S0-I/2HW-PROTO2 Wholesale
Related Products
CYPD3175-24LQXQ
CYPD3175-24LQXQ

Infineon Technologies

SLB9672VU20FW1523XTMA1
SLB9672VU20FW1523XTMA1

Infineon Technologies

SLB9670VQ20FW785XTMA1
SLB9670VQ20FW785XTMA1

Infineon Technologies

SLB9672XU20FW1523XTMA1
SLB9672XU20FW1523XTMA1

Infineon Technologies

SLB9673XU20FW2613XTMA1
SLB9673XU20FW2613XTMA1

Infineon Technologies

CYPD3125-40LQXIT
CYPD3125-40LQXIT

Infineon Technologies

AT97SC3204-U2A1A-20
AT97SC3204-U2A1A-20

Microchip Technology

AT97SC3204-U2A1A-10
AT97SC3204-U2A1A-10

Microchip Technology

SLM9670AQ20FW1311XTMA1
SLM9670AQ20FW1311XTMA1

Infineon Technologies

SLB9672XU20FW1613XTMA1
SLB9672XU20FW1613XTMA1

Infineon Technologies

SLB9672AU20FW1613XTMA1
SLB9672AU20FW1613XTMA1

Infineon Technologies

SLB9673AU20FW2613XTMA1
SLB9673AU20FW2613XTMA1

Infineon Technologies

Tech Hub

Search

Search

PRODUCT

PRODUCT

PHONE

PHONE

USER

USER