Send an Inquiry

To receive a quote for your project, please fill in the following information, and we’ll get back to you promptly.

Name*
Company*
Email Address*
Phone/WhatsApp
Part Number*
Quantity*
Message
Submit Inventory List

Please fill in the following information, and we’ll get back to you promptly.

Name*
Company*
Email Address*
Phone/WhatsApp
Upload My List
Message

Microchip Technology CEC1736-S0-I/2HW-TFLX

Part No.:
CEC1736-S0-I/2HW-TFLX
Manufacturer:
Microchip Technology
Category:
Application Specific Microcontrollers
Package:
64-VFBGA
Datasheet:
AetrixCEC1736-S0-I/2HW-TFLX.pdf
Description:
TRUSTFLEX 1-CHANNEL PFR WITH 2MB
Quantity:
Payment:
Payment
Shipping:
Shipping

Inventory:1,267

Please send an inquiry. Send us your inquiry, and we will respond immediately.

Part Number
Quantity*
Price
Name*
Company
Email*
Comments

Product details

Overview

CEC1736-S0-I/2HW-TFLX from Microchip Technology is a Real Time Platform Root of Trust Controller implementing hardware-enforced secure boot (P-384), AES256, SHA-384, ECDSA, and SP800-90B-compliant TRNG for server, telecom, and industrial embedded systems. It features an ARM Cortex-M4F core at 96 MHz, 64-pin VFBGA (5.5×5.5×0.92 mm), and supports secure boot of one Application Processor with dual SPI flash monitoring.

For engineers reviewing the CEC1736-S0-I/2HW-TFLX datasheet, CEC1736-S0-I/2HW-TFLX pinout, CEC1736-S0-I/2HW-TFLX application, or CEC1736-S0-I/2HW-TFLX equivalent, this page delivers verified technical context, exact pin functions, NIST 800-193–compliant security features, and validated alternative parts for platform root-of-trust design in OCP-aligned infrastructure.

Technical Context

The CEC1736-S0-I/2HW-TFLX implements a two-stage immutable root of trust: Boot ROM authenticates Soteria-G3 firmware from internal flash, then Soteria-G3 enforces AP image authentication before releasing AP_RESET#. Its dedicated SPI Monitor block performs real-time signature verification during AP boot and runtime opcode-level integrity checks on QSPI0 traffic only.

This variant integrates hardware crypto acceleration (AES256, SHA-384, ECDSA), PUF-based key generation, lockable OTP memory, and lifecycle management with fused security states. It supports 1.8V or 3.3V I/O operation, light/heavy sleep modes, and uses a single QSPI port (QSPI0) with two chip selects-unlike the 84-pin 2ZW variant which supports dual QSPI ports.

Key Specifications

Parameter Value and Actual Design Meaning
Core ARM Cortex-M4F @ 96 MHz - enables deterministic real-time execution of Soteria-G3 firmware and cryptographic operations.
Crypto Acceleration AES256, SHA-384, ECDSA, P-384 - offloads asymmetric signing, hash, and encryption from CPU to hardened hardware engines.
TRNG SP800-90B–certified True Random Number Generator - provides entropy for key derivation and nonce generation meeting FIPS 140-3 requirements.
Secure Boot Scope One Application Processor with up to two external SPI flash devices - enforced via QSPI0_IN_CS0# and QSPI0_IN_CS1# monitoring.
Package 64-pin VFBGA (2HW), 5.5×5.5×0.92 mm - optimized for space-constrained server motherboard and telecom line card layouts.
Internal Flash 2 MB or 4 MB options - stores signed/encrypted Soteria-G3 images, certificate chains, and runtime configuration data.
Power Options User-configurable 1.8V or 3.3V I/O - allows direct interfacing with APs and flash devices operating at either voltage without level shifters.

Pinout & Package

CEC1736-S0-I/2HW-TFLX uses a 64-pin Very Thin Fine-Pitch Ball Grid Array (VFBGA) package, designated 2HW, measuring 5.5 mm × 5.5 mm × 0.92 mm with 0.4 mm ball pitch. This package supports one QSPI interface (QSPI0), two I2C ports (I2C00, I2C10), UART0, SWD/JTAG debug, and 48 GPIOs with configurable alternate functions including reset control, watchdog, and LED signaling.

Pin/Terminal Circuit Role Design Meaning
GPIO020/QSPI0_IN_CS0# QSPI0 Chip Select 0 Input Monitors and intervenes on SPI commands targeting first external flash device connected to AP0.
GPIO021/QSPI0_IN_CS1# QSPI0 Chip Select 1 Input Monitors and intervenes on SPI commands targeting second external flash device connected to AP0.
GPIO106/AP0_RESET# Application Processor 0 Reset Output Holds AP0 in reset until Soteria-G3 completes authentication of all critical firmware images.
GPIO003/I2C00_SDA(FATAL_ERROR#) I2C00 Data / Fatal Error Indicator Provides status reporting to AP0; asserts low on unrecoverable security violation or boot failure.
GPIO004/I2C00_SCL I2C00 Clock Enables run-time status queries (e.g., image authentication result, attestation measurements) from AP0.
GPIO131/AP1_RESET# Application Processor 1 Reset Output Not functional in 2HW package - reserved pin; no AP1 support per datasheet Section 5.1.

Key Features

Feature Design Value
Hardware CNSA-Based Secure Boot (P-384) Immutable Boot ROM enforces cryptographic chain-of-trust using NIST-approved P-384 elliptic curve, preventing unauthorized firmware execution.
SPI Boot Flash Monitoring and Intervention Real-time detection and hardware-level blocking of illegal SPI commands (e.g., chip erase, write to protected regions) on QSPI0 bus only.
NIST 800-193 & OCP Security Compliance Delivers platform resiliency via firmware rollback protection, crisis recovery, and SPDM-based component attestation out-of-box.
PUF-Based Key Management Engine Generates device-unique cryptographic keys tied to silicon variation - eliminates need for external key storage and prevents cloning.
Secure Firmware Updates (PLDM + Crisis Recovery) Supports authenticated, encrypted firmware updates over I2C using PLDM protocol, with fallback to secure recovery mode if update fails.

Applications

Server BMC Security Telecom Line Card Trust Anchor

Use Scenario: Embedded in Baseboard Management Controller (BMC) of rack-mounted servers to enforce secure boot of host CPU firmware and BIOS/UEFI images.

IC Role / Device Role / Timing Role: Platform Root of Trust controller that holds CPU in reset until authenticated firmware is verified; provides real-time SPI flash monitoring during boot and runtime.

Use Value: Prevents persistent malware injection into SPI flash by detecting and blocking unauthorized erase/write commands - validated against NIST 800-193 attack vectors.

Use Scenario: Integrated into 5G radio unit line cards to authenticate fronthaul processor firmware and protect against supply-chain tampering.

IC Role / Device Role / Timing Role: Secure boot coordinator and attestation endpoint that validates AP firmware prior to release of AP_RESET#, then reports status via I2C00 to host processor.

Use Value: Enables SPDM-compliant platform attestation for remote verification of firmware integrity and version compliance in O-RAN deployments.

Industrial Edge Gateway Root of Trust Network Switch Secure Boot Controller

Use Scenario: Deployed in industrial edge gateways requiring certified secure boot for Linux kernel and real-time OS images stored in external SPI flash.

IC Role / Device Role / Timing Role: Cryptographic co-processor managing key revocation, rollback protection, and transfer-of-ownership workflows for field-upgradable firmware.

Use Value: Supports firmware rollback protection with automatic enforcement - blocks execution of downgraded firmware versions known to contain CVE-2023-XXXX vulnerabilities.

Use Scenario: Used in enterprise network switches to isolate and monitor SPI flash access by switch ASIC during boot and runtime.

IC Role / Device Role / Timing Role: Dedicated SPI monitor enforcing memory protection regions and intervening on illegal opcodes (e.g., chip erase) targeting boot flash.

Use Value: Provides hardware-level intervention capability compatible with low-cost 8-pin NOR flash - eliminates need for external flash security controllers.

Equivalent & Alternatives

The following parts are listed as comparable options for similar platform root-of-trust applications.

Alternative Part Technical Difference Application Difference Selection Advice
CEC1736-S0-I/2ZW-TFLX 84-pin WFBGA (7×7×0.8 mm); supports dual QSPI ports (QSPI0 + QSPI1) for two independent Application Processors. Required when securing two APs (e.g., dual-CPU server nodes or redundant control planes) with separate flash monitoring domains. Select 2ZW only if dual-AP architecture and QSPI1 signal routing are implemented; 2HW is pin-incompatible and lacks QSPI1 signals.
MAX32590EVKIT# Maxim Integrated evaluation kit for MAX32590 - discrete secure microcontroller with ARM Cortex-M4, but no integrated SPI monitor or Soteria-G3 firmware stack. Requires full firmware development for secure boot, attestation, and flash monitoring - not drop-in replacement for pre-provisioned Soteria-G3 workflow. Choose only for custom security stack development where Microchip's certified Soteria-G3 firmware is not required.

Compared with CEC1736-S0-I/2HW-TFLX, the 2ZW variant adds hardware support for dual-AP monitoring but increases PCB area and BOM cost; the MAX32590EVKIT requires significant firmware investment and lacks NIST 800-193 certification out-of-box, making it unsuitable for OCP-compliant deployments needing pre-validated security features.

Availability

CEC1736-S0-I/2HW-TFLX is available at Aetrix Electronics and suitable for server BMC, telecom line card, and industrial edge gateway designs requiring stable component supply, long-term lifecycle assurance, and NIST 800-193–compliant platform resiliency.

Supply support for CEC1736-S0-I/2HW-TFLX includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.

Manufacturer

Microchip Technology Inc. is a U.S.-based semiconductor manufacturer specializing in microcontrollers, analog devices, and security ICs, with global design centers and ISO 9001-certified manufacturing.

The CEC173x-TFLX product line delivers pre-provisioned, NIST 800-193–compliant Root of Trust controllers for infrastructure equipment, enabling rapid integration of certified secure boot, attestation, and firmware resilience without custom firmware development.

FAQ

What is the primary security function of the CEC1736-S0-I/2HW-TFLX?

The CEC1736-S0-I/2HW-TFLX serves as a Real Time Platform Root of Trust Controller, enforcing hardware-based secure boot of one Application Processor using P-384 cryptography, real-time SPI flash monitoring, and Soteria-G3 firmware. It holds AP0 in reset until authenticated firmware images pass validation, and provides SPDM-compliant attestation over I2C. The CEC1736-S0-I/2HW-TFLX implements these functions with immutable Boot ROM and pre-provisioned firmware, eliminating software-only attack surfaces.

Does the CEC1736-S0-I/2HW-TFLX support dual Application Processors?

No, the CEC1736-S0-I/2HW-TFLX supports only one Application Processor (AP0) via its single QSPI0 interface with two chip selects (QSPI0_IN_CS0# and QSPI0_IN_CS1#). Dual-AP support requires the 84-pin CEC1736-S0-I/2ZW-TFLX variant, which includes QSPI1 signals and dedicated monitoring logic for a second AP domain. Pinout documentation confirms GPIO131/AP1_RESET# is reserved and non-functional in the 2HW package.

What firmware is pre-installed on the CEC1736-S0-I/2HW-TFLX?

The CEC1736-S0-I/2HW-TFLX ships with pre-provisioned Soteria-G3 firmware, certified to MISRA, Coverity®, and CERT® C standards and validated by third-party penetration testing. This firmware implements NIST 800-193–compliant secure boot, SPDM attestation, PLDM-based secure updates, crisis recovery, and key revocation. The Boot ROM loads and authenticates Soteria-G3 from internal flash, establishing an immutable root of trust before any customer code executes.

How does the SPI Monitor feature work on the CEC1736-S0-I/2HW-TFLX?

The CEC1736-S0-I/2HW-TFLX SPI Monitor operates exclusively on the QSPI0 bus, performing real-time signature verification during AP0 boot and opcode-level integrity checks during runtime. It detects violations such as illegal commands (e.g., chip erase) or unauthorized memory accesses, then intervenes by asserting hardware control over QSPI0 signals to cancel the offending transaction before completion. This intervention works with standard 8-pin NOR flash devices and requires no external components.

What package and pin count does the CEC1736-S0-I/2HW-TFLX use?

The CEC1736-S0-I/2HW-TFLX uses a 64-pin Very Thin Fine-Pitch Ball Grid Array (VFBGA) package, designated 2HW, with dimensions of 5.5 mm × 5.5 mm × 0.92 mm and 0.4 mm ball pitch. It contains 48 GPIOs, two I2C interfaces (I2C00 and I2C10), UART0, SWD/JTAG debug, and dedicated QSPI0 monitoring pins - all mapped per Microchip's DS00005397A-page 10 pinout table. The 2HW package excludes QSPI1 signals present in the 84-pin 2ZW variant.

CEC1736-S0-I/2HW-TFLX Specifications

Product attributes
Attribute value
Manufacturer:
Microchip Technology
Series:
CryptoController™
Package/Case:
64-VFBGA
Packaging:
Tray
Product Status:
Active
Programmable:
-
Applications:
Real Time Platform Root
Core Processor:
ARM® Cortex®-M4F
Program Memory Type:
OTP (1kB)
Controller Series:
CEC173X
RAM Size:
384K x 8
Interface:
I2C, QSPI, SPI, UART
Number of I/O:
52
Voltage - Supply:
1.8V ~ 3.3V
Operating Temperature:
-40°C ~ 85°C
Grade:
-
Qualification:
-
Mounting Type:
Surface Mount
Supplier Device Package:
64-VFBGA (5.5x5.5)

CEC1736-S0-I/2HW-TFLX FAQ

1.How can I place an order for CEC1736-S0-I/2HW-TFLX through Aetrix?

Please submit a Request for Quotation (RFQ) for CEC1736-S0-I/2HW-TFLX on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.

2.Are the price and stock information for CEC1736-S0-I/2HW-TFLX reliable?

The price and inventory of CEC1736-S0-I/2HW-TFLX are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for CEC1736-S0-I/2HW-TFLX is usually 5 days.

3.What payment methods are accepted for CEC1736-S0-I/2HW-TFLX?

We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for CEC1736-S0-I/2HW-TFLX transactions.

Note: Certain payment methods may incur a processing fee.

4.How is shipping managed for CEC1736-S0-I/2HW-TFLX?

CEC1736-S0-I/2HW-TFLX orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.

Once your CEC1736-S0-I/2HW-TFLX order is processed, you will receive an email with the shipment details and tracking number.

Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.

5.How can I obtain technical support or documentation for CEC1736-S0-I/2HW-TFLX?

For technical support, including CEC1736-S0-I/2HW-TFLX datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your CEC1736-S0-I/2HW-TFLX requirements.

6.How does Aetrix verify that CEC1736-S0-I/2HW-TFLX is sourced from the original manufacturer or authorized distributors?

All CEC1736-S0-I/2HW-TFLX products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that CEC1736-S0-I/2HW-TFLX meets industry standards.

7.What is the process for return or replacement of CEC1736-S0-I/2HW-TFLX?

All CEC1736-S0-I/2HW-TFLX units undergo pre-shipment inspection (PSI). If there is an issue with CEC1736-S0-I/2HW-TFLX, returns or replacements are accepted under the following conditions:

1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.

2.The issue is reported within 90 days of delivery.

3.The CEC1736-S0-I/2HW-TFLX part is unused and in its original packaging.

Return procedure for CEC1736-S0-I/2HW-TFLX:

1.Submit a request within 90 days.

2.Obtain a Return Material Authorization (RMA) from Aetrix.

CEC1736-S0-I/2HW-TFLX Tags

  • CEC1736-S0-I/2HW-TFLX
  • CEC1736-S0-I/2HW-TFLX PDF
  • CEC1736-S0-I/2HW-TFLX Datasheet
  • CEC1736-S0-I/2HW-TFLX Specifications
  • CEC1736-S0-I/2HW-TFLX Images
  • Microchip Technology
  • Microchip Technology CEC1736-S0-I/2HW-TFLX
  • Buy CEC1736-S0-I/2HW-TFLX
  • CEC1736-S0-I/2HW-TFLX Price
  • CEC1736-S0-I/2HW-TFLX Distributor
  • CEC1736-S0-I/2HW-TFLX Supplier
  • CEC1736-S0-I/2HW-TFLX Wholesale
Related Products
CYPD3175-24LQXQ
CYPD3175-24LQXQ

Infineon Technologies

SLB9672VU20FW1523XTMA1
SLB9672VU20FW1523XTMA1

Infineon Technologies

SLB9670VQ20FW785XTMA1
SLB9670VQ20FW785XTMA1

Infineon Technologies

SLB9672XU20FW1523XTMA1
SLB9672XU20FW1523XTMA1

Infineon Technologies

SLB9673XU20FW2613XTMA1
SLB9673XU20FW2613XTMA1

Infineon Technologies

CYPD3125-40LQXIT
CYPD3125-40LQXIT

Infineon Technologies

AT97SC3204-U2A1A-20
AT97SC3204-U2A1A-20

Microchip Technology

AT97SC3204-U2A1A-10
AT97SC3204-U2A1A-10

Microchip Technology

SLM9670AQ20FW1311XTMA1
SLM9670AQ20FW1311XTMA1

Infineon Technologies

SLB9672XU20FW1613XTMA1
SLB9672XU20FW1613XTMA1

Infineon Technologies

SLB9672AU20FW1613XTMA1
SLB9672AU20FW1613XTMA1

Infineon Technologies

SLB9673AU20FW2613XTMA1
SLB9673AU20FW2613XTMA1

Infineon Technologies

Tech Hub

Search

Search

PRODUCT

PRODUCT

PHONE

PHONE

USER

USER