Send an Inquiry

To receive a quote for your project, please fill in the following information, and we’ll get back to you promptly.

Name*
Company*
Email Address*
Phone/WhatsApp
Part Number*
Quantity*
Message
Submit Inventory List

Please fill in the following information, and we’ll get back to you promptly.

Name*
Company*
Email Address*
Phone/WhatsApp
Upload My List
Message

Microchip Technology CEC1736-S0-I/2HW-TCSM

Part No.:
CEC1736-S0-I/2HW-TCSM
Manufacturer:
Microchip Technology
Category:
Application Specific Microcontrollers
Package:
64-VFBGA
Datasheet:
AetrixCEC1736-S0-I/2HW-TCSM.pdf
Description:
TRUSTCUSTOM 1-CHANNEL PFR WITH 2
Quantity:
Payment:
Payment
Shipping:
Shipping

Inventory:4,660

Please send an inquiry. Send us your inquiry, and we will respond immediately.

Part Number
Quantity*
Price
Name*
Company
Email*
Comments

Product details

Overview

CEC1736-S0-I/2HW-TCSM from Microchip Technology is a Real Time Platform Root of Trust controller featuring an ARM® Cortex-M4F core running at up to 96 MHz, 384 KB SRAM (320 KB code + 64 KB data), dual SPI Flash monitoring capability, and hardware-accelerated cryptographic engines (AES-256, SHA-384, ECDSA, PUF, DRNG) for secure boot and runtime firmware integrity enforcement in server BMC/CPU boot paths.

For engineers reviewing the CEC1736-S0-I/2HW-TCSM datasheet, CEC1736-S0-I/2HW-TCSM pinout, CEC1736-S0-I/2HW-TCSM application, or CEC1736-S0-I/2HW-TCSM equivalent, key selection criteria include dual-channel SPI flash intervention support, TCG DICE compliance, 64-pin VFBGA package with VTR1-only I/O, -40°C to +85°C industrial temperature range, and integrated 2 MB SPI flash for primary firmware storage.

Technical Context

The CEC1736-S0-I/2HW-TCSM implements two independent SPI Flash Monitor blocks-one per host channel-each with dedicated 64 KB match pattern RAM and real-time hash calculation on 8 KB regions, enabling active intervention against illegal flash operations (e.g., chip erase) during both boot and runtime. It uses dual power wells (VTR1 only in this variant) to isolate host SPI traffic and enforce access control policies.

Its security architecture integrates immutable Boot ROM (CNSA-compliant SHA-384/ECC384), life-cycle-managed OTP (8 Kbit), tamper detection (voltage/temperature), and SPDM-based attestation via EC_FW. The device supports dual SPI host controllers (QSPI-capable), five SMBus/I2C controllers with crossbar routing, and a 32-bit RTOS timer that runs continuously across all sleep states using the 32 kHz internal oscillator.

Key Specifications

ParameterValue and Actual Design Meaning
CoreARM Cortex-M4F @ 96 MHz with FPU and NVIC supporting 8 priority levels
Memory384 KB SRAM (320 KB executable code + 64 KB data); 8 Kbit lockable OTP; 2 MB integrated SPI flash
Crypto AccelerationAES-128/192/256, SHA-256/384/512, ECDSA/ECC up to P-521, RSA up to 4096-bit, PUF, DRNG
SPI MonitoringDual SPI Flash Monitor blocks, each with 64 KB match RAM and real-time hash verification on 8 KB regions
Package & I/O64-pin VFBGA; 52 GPIOs; VTR1 I/O bank only (3.3 V or 1.8 V configurable); no VTR2 pins
Power & Temp3.3 V nominal supply; -40°C to +85°C operating range; Light/Heavy Sleep modes with sub-μA standby current
Security ComplianceTCG DICE (immutable ROM), NIST SP800-193 PFR, CNSA, NIST SP800-90B DRNG certification

Pinout & Package

CEC1736-S0-I/2HW-TCSM is housed in a 64-pin Very Thin Fine-Pitch Ball Grid Array (VFBGA) package measuring 5 mm × 5 mm × 0.65 mm, with 0.4 mm ball pitch. All I/O signals are assigned to the VTR1 power domain (no VTR2 pins present), supporting either 3.3 V or 1.8 V interface voltage levels depending on host flash requirements.

Pin/TerminalCircuit RoleDesign Meaning
GPIO000 / SPI0_KILLSPI Channel 0 Kill SignalAsserted by CEC1736-S0-I/2HW-TCSM to disable external SPI0 peripherals during intervention events
QSPI0_CS0# / SPIMON_QSPI0_CS0#SPI Monitor Chip Select 0Monitors and filters all transactions to primary SPI flash device; enables real-time signature verification
QSPI0_IN_IO0–IO3SPI Input Data LinesReceive raw SPI command/data from host CPU/BMC; routed through analog switch isolation before processing
VTR1I/O Power Domain SupplyProvides regulated 3.3 V or 1.8 V to all GPIOs, QSPI, and I2C ports in this variant; no VTR2 domain present
nRESET_INExternal Reset InputAsynchronous active-low reset input that triggers full system reset including Boot ROM reinitialization
JTAG_RST#JTAG Boundary Scan ResetResets JTAG TAP controller independently; disabled by default in production mode per security policy

Key Features

FeatureDesign Value
Dual SPI Flash MonitoringEnables simultaneous, independent integrity enforcement for BMC and CPU boot flash devices using dedicated 64 KB match RAM per channel
Secure Boot with AES-256 EncryptionBoot ROM authenticates and decrypts EC firmware images stored in internal SPI flash using hardware-accelerated crypto engines
TCG DICE-Compliant RoTGenerates Device Identity (UDS) and CDI in immutable ROM, enabling verifiable platform attestation without external dependencies
Runtime Firmware Integrity EnforcementPrevents unauthorized flash read/write/erase during host runtime by intercepting and blocking illegal opcodes in real time
Life Cycle Management via OTPFused OTP bits control access to PUF, DRNG, and key storage across development, test, and production phases per OpenTitan specification

Applications

Server BMC SecurityTelecom Baseband Controller

Use Scenario: Enforces firmware integrity for Baseboard Management Controller (BMC) during cold boot and runtime in dual-socket servers.

IC Role / Device Role / Timing Role: Acts as root-of-trust controller mediating all BMC SPI flash accesses; provides deterministic 32 kHz RTOS timer for secure watchdog and hibernation scheduling.

Use Value: Prevents persistent malware injection into BMC firmware by actively blocking illegal flash erase commands and verifying code signatures in real time.

Use Scenario: Secures boot path and runtime firmware updates for distributed baseband units in 5G radio access networks.

IC Role / Device Role / Timing Role: Serves as platform RoT for telecom equipment, managing secure boot, attestation, and encrypted firmware delivery over I2C/SMBus interfaces.

Use Value: Enables remote attestation of baseband controller firmware state using SPDM protocol, satisfying carrier-grade security compliance requirements.

Industrial Edge GatewayNetwork Switch Trusted Execution

Use Scenario: Protects firmware integrity in ruggedized edge gateways deployed in factory automation environments with wide temperature swings.

IC Role / Device Role / Timing Role: Embedded controller enforcing secure boot and runtime flash protection while operating across -40°C to +85°C range with low-power sleep modes.

Use Value: Guarantees firmware authenticity despite physical tampering attempts, leveraging voltage/temperature tamper sensors and fused life-cycle OTP controls.

Use Scenario: Provides hardware-enforced firmware validation for network switch control plane processors during boot and hot firmware patching.

IC Role / Device Role / Timing Role: Dual SPI monitor enforces strict access control between switch ASIC and its boot flash, isolating channels via internal QSPI analog switches.

Use Value: Eliminates risk of malicious firmware modification during in-service updates by validating hash matches on every 8 KB flash region before execution.

Equivalent & Alternatives

The following parts are listed as comparable options for similar embedded controller security applications.

Alternative PartTechnical DifferenceApplication DifferenceSelection Advice
CEC1736-S0-I/2ZW84-pin WFBGA with dual SPI monitors, VTR1 + VTR2 I/O banks, 4 MB SPI flash, and 71 GPIOsSupports dual-host (BMC + CPU) systems requiring independent 1.8 V/3.3 V I/O domains and higher pin count for complex I/O routingSelect when dual-voltage I/O isolation, larger flash capacity, or additional GPIOs are required beyond CEC1736-S0-I/2HW-TCSM's 64-pin footprint
MAX32570Maxim Integrated secure microcontroller with ARM Cortex-M4, 1 MB flash, but no integrated SPI flash monitor or dual-channel intervention logicLacks hardware-enforced SPI flash runtime protection; relies on software-based integrity checks with higher latency and attack surfaceChoose only if SPI flash monitoring is not required and lower BOM cost outweighs loss of real-time intervention capability

Compared with CEC1736-S0-I/2ZW, CEC1736-S0-I/2HW-TCSM offers identical security IP and crypto acceleration in a smaller 64-pin package optimized for single-host systems, while MAX32570 provides basic secure MCU functionality without dedicated hardware for SPI flash runtime integrity enforcement.

Availability

CEC1736-S0-I/2HW-TCSM is available at Aetrix Electronics and suitable for server BMC security, telecom baseband controller, and industrial edge gateway applications requiring stable component supply, long-term lifecycle support, and certified cryptographic functionality.

Supply support for CEC1736-S0-I/2HW-TCSM includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.

Manufacturer

Microchip Technology Inc. is a leading provider of microcontrollers, analog components, and security solutions, serving automotive, industrial, communications, and computing markets with vertically integrated silicon and software platforms.

The CEC173x family is designed as Real Time Platform Root of Trust Controllers specifically for server, telecom, networking, and industrial systems requiring hardware-enforced firmware integrity, secure boot, and SPDM-based attestation capabilities.

FAQ

What is the primary function of the CEC1736-S0-I/2HW-TCSM in a server platform?

The CEC1736-S0-I/2HW-TCSM serves as the Real Time Platform Root of Trust controller, enforcing firmware integrity for both BMC and CPU boot paths via dual SPI Flash Monitor blocks. It performs real-time signature verification during boot and actively intervenes to block illegal flash operations-including chip erase-during host runtime, ensuring persistent firmware authenticity in server platforms.

Does the CEC1736-S0-I/2HW-TCSM support dual-voltage I/O operation?

Yes, the CEC1736-S0-I/2HW-TCSM supports 3.3 V or 1.8 V interface voltages on its VTR1 I/O bank, configurable per host flash requirements. However, unlike the 84-pin CEC1736-S0-I/2ZW variant, it does not include a VTR2 power domain-so only one voltage domain is available for all I/O signals.

How does the CEC1736-S0-I/2HW-TCSM implement secure boot?

The CEC1736-S0-I/2HW-TCSM implements secure boot using an immutable Boot ROM that loads and authenticates EC firmware from internal 2 MB SPI flash. It verifies digital signatures using SHA-384/ECC384 per CNSA guidelines, supports AES-256 encrypted images, and enforces code rollback protection and public key revocation-all executed in hardware without software dependency.

What is the role of the SPI Flash Monitor blocks in the CEC1736-S0-I/2HW-TCSM?

The CEC1736-S0-I/2HW-TCSM contains one dedicated SPI Flash Monitor block for its single SPI channel. It performs real-time hash calculation on 8 KB flash regions, compares data against 64 KB match patterns, and actively cancels illegal read/write/erase operations before completion-ensuring runtime firmware integrity even with standard 8-pin NOR flash devices.

Is JTAG enabled by default on the CEC1736-S0-I/2HW-TCSM?

No, JTAG is disabled by default on the CEC1736-S0-I/2HW-TCSM for security reasons. The JTAG interface remains inaccessible until explicitly enabled via OTP fuse configuration during manufacturing or test phases, aligning with production security best practices defined in the Boot ROM life-cycle management.

CEC1736-S0-I/2HW-TCSM Specifications

Product attributes
Attribute value
Manufacturer:
Microchip Technology
Series:
CryptoController™
Package/Case:
64-VFBGA
Packaging:
Tray
Product Status:
Active
Programmable:
-
Applications:
Real Time Platform Root
Core Processor:
ARM® Cortex®-M4F
Program Memory Type:
OTP (1kB)
Controller Series:
CEC173X
RAM Size:
384K x 8
Interface:
I2C, PWM, SMBus, SPI, UART
Number of I/O:
52
Voltage - Supply:
1.8V ~ 3.3V
Operating Temperature:
-40°C ~ 85°C
Grade:
-
Qualification:
-
Mounting Type:
Surface Mount
Supplier Device Package:
64-VFBGA (5.5x5.5)

CEC1736-S0-I/2HW-TCSM FAQ

1.How can I place an order for CEC1736-S0-I/2HW-TCSM through Aetrix?

Please submit a Request for Quotation (RFQ) for CEC1736-S0-I/2HW-TCSM on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.

2.Are the price and stock information for CEC1736-S0-I/2HW-TCSM reliable?

The price and inventory of CEC1736-S0-I/2HW-TCSM are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for CEC1736-S0-I/2HW-TCSM is usually 5 days.

3.What payment methods are accepted for CEC1736-S0-I/2HW-TCSM?

We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for CEC1736-S0-I/2HW-TCSM transactions.

Note: Certain payment methods may incur a processing fee.

4.How is shipping managed for CEC1736-S0-I/2HW-TCSM?

CEC1736-S0-I/2HW-TCSM orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.

Once your CEC1736-S0-I/2HW-TCSM order is processed, you will receive an email with the shipment details and tracking number.

Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.

5.How can I obtain technical support or documentation for CEC1736-S0-I/2HW-TCSM?

For technical support, including CEC1736-S0-I/2HW-TCSM datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your CEC1736-S0-I/2HW-TCSM requirements.

6.How does Aetrix verify that CEC1736-S0-I/2HW-TCSM is sourced from the original manufacturer or authorized distributors?

All CEC1736-S0-I/2HW-TCSM products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that CEC1736-S0-I/2HW-TCSM meets industry standards.

7.What is the process for return or replacement of CEC1736-S0-I/2HW-TCSM?

All CEC1736-S0-I/2HW-TCSM units undergo pre-shipment inspection (PSI). If there is an issue with CEC1736-S0-I/2HW-TCSM, returns or replacements are accepted under the following conditions:

1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.

2.The issue is reported within 90 days of delivery.

3.The CEC1736-S0-I/2HW-TCSM part is unused and in its original packaging.

Return procedure for CEC1736-S0-I/2HW-TCSM:

1.Submit a request within 90 days.

2.Obtain a Return Material Authorization (RMA) from Aetrix.

CEC1736-S0-I/2HW-TCSM Tags

  • CEC1736-S0-I/2HW-TCSM
  • CEC1736-S0-I/2HW-TCSM PDF
  • CEC1736-S0-I/2HW-TCSM Datasheet
  • CEC1736-S0-I/2HW-TCSM Specifications
  • CEC1736-S0-I/2HW-TCSM Images
  • Microchip Technology
  • Microchip Technology CEC1736-S0-I/2HW-TCSM
  • Buy CEC1736-S0-I/2HW-TCSM
  • CEC1736-S0-I/2HW-TCSM Price
  • CEC1736-S0-I/2HW-TCSM Distributor
  • CEC1736-S0-I/2HW-TCSM Supplier
  • CEC1736-S0-I/2HW-TCSM Wholesale
Related Products
CYPD3175-24LQXQ
CYPD3175-24LQXQ

Infineon Technologies

SLB9672VU20FW1523XTMA1
SLB9672VU20FW1523XTMA1

Infineon Technologies

SLB9670VQ20FW785XTMA1
SLB9670VQ20FW785XTMA1

Infineon Technologies

SLB9672XU20FW1523XTMA1
SLB9672XU20FW1523XTMA1

Infineon Technologies

SLB9673XU20FW2613XTMA1
SLB9673XU20FW2613XTMA1

Infineon Technologies

CYPD3125-40LQXIT
CYPD3125-40LQXIT

Infineon Technologies

AT97SC3204-U2A1A-20
AT97SC3204-U2A1A-20

Microchip Technology

AT97SC3204-U2A1A-10
AT97SC3204-U2A1A-10

Microchip Technology

SLM9670AQ20FW1311XTMA1
SLM9670AQ20FW1311XTMA1

Infineon Technologies

SLB9672XU20FW1613XTMA1
SLB9672XU20FW1613XTMA1

Infineon Technologies

SLB9672AU20FW1613XTMA1
SLB9672AU20FW1613XTMA1

Infineon Technologies

SLB9673AU20FW2613XTMA1
SLB9673AU20FW2613XTMA1

Infineon Technologies

Tech Hub

Search

Search

PRODUCT

PRODUCT

PHONE

PHONE

USER

USER