Microchip Technology CEC1736-S0-I/2HW-TCSM
- Part No.:
- CEC1736-S0-I/2HW-TCSM
- Manufacturer:
- Microchip Technology
- Category:
- Application Specific Microcontrollers
- Package:
- 64-VFBGA
- Datasheet:
-
CEC1736-S0-I/2HW-TCSM.pdf
- Description:
- TRUSTCUSTOM 1-CHANNEL PFR WITH 2
- Quantity:
- Payment:

- Shipping:

Inventory:4,660
Please send an inquiry. Send us your inquiry, and we will respond immediately.
Product details
Overview
CEC1736-S0-I/2HW-TCSM from Microchip Technology is a Real Time Platform Root of Trust controller featuring an ARM® Cortex-M4F core running at up to 96 MHz, 384 KB SRAM (320 KB code + 64 KB data), dual SPI Flash monitoring capability, and hardware-accelerated cryptographic engines (AES-256, SHA-384, ECDSA, PUF, DRNG) for secure boot and runtime firmware integrity enforcement in server BMC/CPU boot paths.
For engineers reviewing the CEC1736-S0-I/2HW-TCSM datasheet, CEC1736-S0-I/2HW-TCSM pinout, CEC1736-S0-I/2HW-TCSM application, or CEC1736-S0-I/2HW-TCSM equivalent, key selection criteria include dual-channel SPI flash intervention support, TCG DICE compliance, 64-pin VFBGA package with VTR1-only I/O, -40°C to +85°C industrial temperature range, and integrated 2 MB SPI flash for primary firmware storage.
Technical Context
The CEC1736-S0-I/2HW-TCSM implements two independent SPI Flash Monitor blocks-one per host channel-each with dedicated 64 KB match pattern RAM and real-time hash calculation on 8 KB regions, enabling active intervention against illegal flash operations (e.g., chip erase) during both boot and runtime. It uses dual power wells (VTR1 only in this variant) to isolate host SPI traffic and enforce access control policies.
Its security architecture integrates immutable Boot ROM (CNSA-compliant SHA-384/ECC384), life-cycle-managed OTP (8 Kbit), tamper detection (voltage/temperature), and SPDM-based attestation via EC_FW. The device supports dual SPI host controllers (QSPI-capable), five SMBus/I2C controllers with crossbar routing, and a 32-bit RTOS timer that runs continuously across all sleep states using the 32 kHz internal oscillator.
Key Specifications
| Parameter | Value and Actual Design Meaning |
|---|---|
| Core | ARM Cortex-M4F @ 96 MHz with FPU and NVIC supporting 8 priority levels |
| Memory | 384 KB SRAM (320 KB executable code + 64 KB data); 8 Kbit lockable OTP; 2 MB integrated SPI flash |
| Crypto Acceleration | AES-128/192/256, SHA-256/384/512, ECDSA/ECC up to P-521, RSA up to 4096-bit, PUF, DRNG |
| SPI Monitoring | Dual SPI Flash Monitor blocks, each with 64 KB match RAM and real-time hash verification on 8 KB regions |
| Package & I/O | 64-pin VFBGA; 52 GPIOs; VTR1 I/O bank only (3.3 V or 1.8 V configurable); no VTR2 pins |
| Power & Temp | 3.3 V nominal supply; -40°C to +85°C operating range; Light/Heavy Sleep modes with sub-μA standby current |
| Security Compliance | TCG DICE (immutable ROM), NIST SP800-193 PFR, CNSA, NIST SP800-90B DRNG certification |
Pinout & Package
CEC1736-S0-I/2HW-TCSM is housed in a 64-pin Very Thin Fine-Pitch Ball Grid Array (VFBGA) package measuring 5 mm × 5 mm × 0.65 mm, with 0.4 mm ball pitch. All I/O signals are assigned to the VTR1 power domain (no VTR2 pins present), supporting either 3.3 V or 1.8 V interface voltage levels depending on host flash requirements.
| Pin/Terminal | Circuit Role | Design Meaning |
|---|---|---|
| GPIO000 / SPI0_KILL | SPI Channel 0 Kill Signal | Asserted by CEC1736-S0-I/2HW-TCSM to disable external SPI0 peripherals during intervention events |
| QSPI0_CS0# / SPIMON_QSPI0_CS0# | SPI Monitor Chip Select 0 | Monitors and filters all transactions to primary SPI flash device; enables real-time signature verification |
| QSPI0_IN_IO0–IO3 | SPI Input Data Lines | Receive raw SPI command/data from host CPU/BMC; routed through analog switch isolation before processing |
| VTR1 | I/O Power Domain Supply | Provides regulated 3.3 V or 1.8 V to all GPIOs, QSPI, and I2C ports in this variant; no VTR2 domain present |
| nRESET_IN | External Reset Input | Asynchronous active-low reset input that triggers full system reset including Boot ROM reinitialization |
| JTAG_RST# | JTAG Boundary Scan Reset | Resets JTAG TAP controller independently; disabled by default in production mode per security policy |
Key Features
| Feature | Design Value |
|---|---|
| Dual SPI Flash Monitoring | Enables simultaneous, independent integrity enforcement for BMC and CPU boot flash devices using dedicated 64 KB match RAM per channel |
| Secure Boot with AES-256 Encryption | Boot ROM authenticates and decrypts EC firmware images stored in internal SPI flash using hardware-accelerated crypto engines |
| TCG DICE-Compliant RoT | Generates Device Identity (UDS) and CDI in immutable ROM, enabling verifiable platform attestation without external dependencies |
| Runtime Firmware Integrity Enforcement | Prevents unauthorized flash read/write/erase during host runtime by intercepting and blocking illegal opcodes in real time |
| Life Cycle Management via OTP | Fused OTP bits control access to PUF, DRNG, and key storage across development, test, and production phases per OpenTitan specification |
Applications
| Server BMC Security | Telecom Baseband Controller |
|---|---|
Use Scenario: Enforces firmware integrity for Baseboard Management Controller (BMC) during cold boot and runtime in dual-socket servers. IC Role / Device Role / Timing Role: Acts as root-of-trust controller mediating all BMC SPI flash accesses; provides deterministic 32 kHz RTOS timer for secure watchdog and hibernation scheduling. Use Value: Prevents persistent malware injection into BMC firmware by actively blocking illegal flash erase commands and verifying code signatures in real time. | Use Scenario: Secures boot path and runtime firmware updates for distributed baseband units in 5G radio access networks. IC Role / Device Role / Timing Role: Serves as platform RoT for telecom equipment, managing secure boot, attestation, and encrypted firmware delivery over I2C/SMBus interfaces. Use Value: Enables remote attestation of baseband controller firmware state using SPDM protocol, satisfying carrier-grade security compliance requirements. |
| Industrial Edge Gateway | Network Switch Trusted Execution |
Use Scenario: Protects firmware integrity in ruggedized edge gateways deployed in factory automation environments with wide temperature swings. IC Role / Device Role / Timing Role: Embedded controller enforcing secure boot and runtime flash protection while operating across -40°C to +85°C range with low-power sleep modes. Use Value: Guarantees firmware authenticity despite physical tampering attempts, leveraging voltage/temperature tamper sensors and fused life-cycle OTP controls. | Use Scenario: Provides hardware-enforced firmware validation for network switch control plane processors during boot and hot firmware patching. IC Role / Device Role / Timing Role: Dual SPI monitor enforces strict access control between switch ASIC and its boot flash, isolating channels via internal QSPI analog switches. Use Value: Eliminates risk of malicious firmware modification during in-service updates by validating hash matches on every 8 KB flash region before execution. |
Equivalent & Alternatives
The following parts are listed as comparable options for similar embedded controller security applications.
| Alternative Part | Technical Difference | Application Difference | Selection Advice |
|---|---|---|---|
| CEC1736-S0-I/2ZW | 84-pin WFBGA with dual SPI monitors, VTR1 + VTR2 I/O banks, 4 MB SPI flash, and 71 GPIOs | Supports dual-host (BMC + CPU) systems requiring independent 1.8 V/3.3 V I/O domains and higher pin count for complex I/O routing | Select when dual-voltage I/O isolation, larger flash capacity, or additional GPIOs are required beyond CEC1736-S0-I/2HW-TCSM's 64-pin footprint |
| MAX32570 | Maxim Integrated secure microcontroller with ARM Cortex-M4, 1 MB flash, but no integrated SPI flash monitor or dual-channel intervention logic | Lacks hardware-enforced SPI flash runtime protection; relies on software-based integrity checks with higher latency and attack surface | Choose only if SPI flash monitoring is not required and lower BOM cost outweighs loss of real-time intervention capability |
Compared with CEC1736-S0-I/2ZW, CEC1736-S0-I/2HW-TCSM offers identical security IP and crypto acceleration in a smaller 64-pin package optimized for single-host systems, while MAX32570 provides basic secure MCU functionality without dedicated hardware for SPI flash runtime integrity enforcement.
Availability
CEC1736-S0-I/2HW-TCSM is available at Aetrix Electronics and suitable for server BMC security, telecom baseband controller, and industrial edge gateway applications requiring stable component supply, long-term lifecycle support, and certified cryptographic functionality.
Supply support for CEC1736-S0-I/2HW-TCSM includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.
Manufacturer
Microchip Technology Inc. is a leading provider of microcontrollers, analog components, and security solutions, serving automotive, industrial, communications, and computing markets with vertically integrated silicon and software platforms.
The CEC173x family is designed as Real Time Platform Root of Trust Controllers specifically for server, telecom, networking, and industrial systems requiring hardware-enforced firmware integrity, secure boot, and SPDM-based attestation capabilities.
FAQ
What is the primary function of the CEC1736-S0-I/2HW-TCSM in a server platform?
The CEC1736-S0-I/2HW-TCSM serves as the Real Time Platform Root of Trust controller, enforcing firmware integrity for both BMC and CPU boot paths via dual SPI Flash Monitor blocks. It performs real-time signature verification during boot and actively intervenes to block illegal flash operations-including chip erase-during host runtime, ensuring persistent firmware authenticity in server platforms.
Does the CEC1736-S0-I/2HW-TCSM support dual-voltage I/O operation?
Yes, the CEC1736-S0-I/2HW-TCSM supports 3.3 V or 1.8 V interface voltages on its VTR1 I/O bank, configurable per host flash requirements. However, unlike the 84-pin CEC1736-S0-I/2ZW variant, it does not include a VTR2 power domain-so only one voltage domain is available for all I/O signals.
How does the CEC1736-S0-I/2HW-TCSM implement secure boot?
The CEC1736-S0-I/2HW-TCSM implements secure boot using an immutable Boot ROM that loads and authenticates EC firmware from internal 2 MB SPI flash. It verifies digital signatures using SHA-384/ECC384 per CNSA guidelines, supports AES-256 encrypted images, and enforces code rollback protection and public key revocation-all executed in hardware without software dependency.
What is the role of the SPI Flash Monitor blocks in the CEC1736-S0-I/2HW-TCSM?
The CEC1736-S0-I/2HW-TCSM contains one dedicated SPI Flash Monitor block for its single SPI channel. It performs real-time hash calculation on 8 KB flash regions, compares data against 64 KB match patterns, and actively cancels illegal read/write/erase operations before completion-ensuring runtime firmware integrity even with standard 8-pin NOR flash devices.
Is JTAG enabled by default on the CEC1736-S0-I/2HW-TCSM?
No, JTAG is disabled by default on the CEC1736-S0-I/2HW-TCSM for security reasons. The JTAG interface remains inaccessible until explicitly enabled via OTP fuse configuration during manufacturing or test phases, aligning with production security best practices defined in the Boot ROM life-cycle management.
CEC1736-S0-I/2HW-TCSM Specifications
- Product attributes
- Attribute value
- Manufacturer:
- Microchip Technology
- Series:
- CryptoController™
- Package/Case:
- 64-VFBGA
- Packaging:
- Tray
- Product Status:
- Active
- Programmable:
- -
- Applications:
- Real Time Platform Root
- Core Processor:
- ARM® Cortex®-M4F
- Program Memory Type:
- OTP (1kB)
- Controller Series:
- CEC173X
- RAM Size:
- 384K x 8
- Interface:
- I2C, PWM, SMBus, SPI, UART
- Number of I/O:
- 52
- Voltage - Supply:
- 1.8V ~ 3.3V
- Operating Temperature:
- -40°C ~ 85°C
- Grade:
- -
- Qualification:
- -
- Mounting Type:
- Surface Mount
- Supplier Device Package:
- 64-VFBGA (5.5x5.5)
CEC1736-S0-I/2HW-TCSM FAQ
1.How can I place an order for CEC1736-S0-I/2HW-TCSM through Aetrix?
Please submit a Request for Quotation (RFQ) for CEC1736-S0-I/2HW-TCSM on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.
2.Are the price and stock information for CEC1736-S0-I/2HW-TCSM reliable?
The price and inventory of CEC1736-S0-I/2HW-TCSM are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for CEC1736-S0-I/2HW-TCSM is usually 5 days.
3.What payment methods are accepted for CEC1736-S0-I/2HW-TCSM?
We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for CEC1736-S0-I/2HW-TCSM transactions.
Note: Certain payment methods may incur a processing fee.
4.How is shipping managed for CEC1736-S0-I/2HW-TCSM?
CEC1736-S0-I/2HW-TCSM orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.
Once your CEC1736-S0-I/2HW-TCSM order is processed, you will receive an email with the shipment details and tracking number.
Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.
5.How can I obtain technical support or documentation for CEC1736-S0-I/2HW-TCSM?
For technical support, including CEC1736-S0-I/2HW-TCSM datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your CEC1736-S0-I/2HW-TCSM requirements.
6.How does Aetrix verify that CEC1736-S0-I/2HW-TCSM is sourced from the original manufacturer or authorized distributors?
All CEC1736-S0-I/2HW-TCSM products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that CEC1736-S0-I/2HW-TCSM meets industry standards.
7.What is the process for return or replacement of CEC1736-S0-I/2HW-TCSM?
All CEC1736-S0-I/2HW-TCSM units undergo pre-shipment inspection (PSI). If there is an issue with CEC1736-S0-I/2HW-TCSM, returns or replacements are accepted under the following conditions:
1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.
2.The issue is reported within 90 days of delivery.
3.The CEC1736-S0-I/2HW-TCSM part is unused and in its original packaging.
Return procedure for CEC1736-S0-I/2HW-TCSM:
1.Submit a request within 90 days.
2.Obtain a Return Material Authorization (RMA) from Aetrix.
CEC1736-S0-I/2HW-TCSM Tags

-
CYPD3175-24LQXQ
Infineon Technologies

-
SLB9672VU20FW1523XTMA1
Infineon Technologies

-
SLB9670VQ20FW785XTMA1
Infineon Technologies

-
SLB9672XU20FW1523XTMA1
Infineon Technologies

-
SLB9673XU20FW2613XTMA1
Infineon Technologies

-
CYPD3125-40LQXIT
Infineon Technologies

-
AT97SC3204-U2A1A-20
Microchip Technology

-
AT97SC3204-U2A1A-10
Microchip Technology

-
SLM9670AQ20FW1311XTMA1
Infineon Technologies

-
SLB9672XU20FW1613XTMA1
Infineon Technologies

-
SLB9672AU20FW1613XTMA1
Infineon Technologies

-
SLB9673AU20FW2613XTMA1
Infineon Technologies
Tech Hub
TTL and CMOS logic families differ in thresholds, loading, output drive, power and timing. This engineering guide compares 74HC and 74HCT, calculates noise margins and checks 3.3 V/5 V compatibility.
A practical engineering guide to 3.3V and 5V logic compatibility, input thresholds, resistor dividers, translator ICs, MOSFET level shifting, I2C pull-ups, timing limits and power-sequencing risks.
The 74HC595 uses push-pull logic outputs, while the TPIC6B595 uses 50 V open-drain DMOS sinks for higher-power loads. This guide compares timing, current limits, 3.3 V interfacing, load wiring, thermal…
The 74HC595 converts serial data into eight stable parallel outputs. This guide covers pin functions, shift and storage timing, OE and MR behavior, drive-current limits, cascading, voltage compatibilit…
A technical comparison of level-sensitive latches and edge-triggered flip-flops, covering timing windows, setup and hold limits, master–slave operation, time borrowing, race-through, HDL inference and…
A D latch stores one bit while Enable controls when data can pass. This reference covers gate-level operation, truth tables, transparency, setup and hold timing, LE versus OE, common ICs and practical …
An SR latch stores one bit through cross-coupled feedback. This engineering reference covers NOR and NAND implementations, truth tables, forbidden-state recovery, gated operation, switch debouncing, fa…
Latch circuits retain one bit through feedback. This technical reference covers SR and D latches, truth tables, transparency, timing limits, latch-versus-flip-flop behavior, applications and common log…
An engineering guide to LED driver operation, constant-current and constant-voltage outputs, linear and switching topologies, dimming, IC selection, calculations, replacement compatibility, and fault c…
Operational amplifier guide covering op amp basics, feedback, ideal vs real op amps, common configurations, buffer circuits, offset, bias current, gain-bandwidth, slew rate, rail-to-rail limits and sel…
