Microchip Technology CEC1736-S0-I/2ZW-PROTO2
- Part No.:
- CEC1736-S0-I/2ZW-PROTO2
- Manufacturer:
- Microchip Technology
- Category:
- Application Specific Microcontrollers
- Package:
- 84-WFBGA
- Datasheet:
-
CEC1736-S0-I/2ZW-PROTO2.pdf
- Description:
- 2-CHANNEL PFR WITH 4MB FLASH AND
- Quantity:
- Payment:

- Shipping:

Inventory:532
Please send an inquiry. Send us your inquiry, and we will respond immediately.
Product details
Overview
CEC1736-S0-I/2ZW-PROTO2 from Microchip Technology is a Real Time Platform Root of Trust controller featuring an ARM® Cortex-M4F core running at up to 96 MHz, dual SPI Flash monitoring capability, 384 KB SRAM (320 KB code + 64 KB data), and hardware-accelerated cryptography including AES-256, SHA-384, ECDSA, and RSA-4096 - deployed in server BMC/CPU boot integrity protection systems.
For engineers reviewing the CEC1736-S0-I/2ZW-PROTO2 datasheet, CEC1736-S0-I/2ZW-PROTO2 pinout, CEC1736-S0-I/2ZW-PROTO2 application, or CEC1736-S0-I/2ZW-PROTO2 equivalent, key selection criteria include dual-channel SPI flash intervention, TCG DICE compliance, 84-pin WFBGA package with VTR1/VTR2 I/O voltage separation, and fused life cycle security management for production RoT deployment.
Technical Context
The CEC1736-S0-I/2ZW-PROTO2 implements two independent QSPI analog switches and dual SPI Flash monitor blocks - one per host (BMC and CPU) - each with dedicated 64 KB match pattern RAM and real-time hash calculation on 8 KB regions. It enforces runtime SPI access control via regional permission settings and intervenes before illegal erase/write operations complete.
Its secure boot chain leverages immutable Boot ROM (CNSA-compliant SHA-384/ECC384), supports AES-256 encrypted SPI Flash images, and provides SPDM-based attestation via EC_FW. The device operates across -40°C to +85°C with 3.3 V core supply and optional 1.8 V SPI interface voltage, entering Light or Heavy Sleep modes with wake-capable GPIO, timers, and I²C events.
Key Specifications
| Parameter | Value and Actual Design Meaning |
|---|---|
| Core Processor | ARM Cortex-M4F @ 96 MHz with FPU and NVIC supporting 8 priority levels |
| Memory | 384 KB SRAM (320 KB code + 64 KB data); 8 Kbit OTP; 4 MB in-package SPI Flash |
| SPI Monitoring | Dual-channel SPI Flash monitoring with real-time signature verification and active intervention |
| Cryptography | AES-128/192/256, SHA-256/384/512, RSA-1024–4096, ECC-P384/P521, ECDSA, DRNG with NIST SP800-90B compliance |
| Package & I/O | 84-pin WFBGA; dual 1.8 V / 3.3 V configurable I/O banks (VTR1/VTR2); 71 GPIOs |
| Security Compliance | TCG DICE (immutable ROM), NIST 800-193 PFR, CNSA, SPDM attestation, fused life cycle management |
| Power Modes | Normal operation + Light Sleep + Heavy Sleep; standby current minimized; wake sources include GPIO, I²C, timers |
Pinout & Package
CEC1736-S0-I/2ZW-PROTO2 uses an 84-pin WFBGA package (2ZW variant) with separate VTR1 and VTR2 power domains for dual SPI channel isolation, 3.3 V VTR_REG core supply, and dedicated pins for QSPI0/QSPI1 interfaces, dual LED outputs, UART, JTAG/SWD debug, and tamper-sensing inputs.
| Pin/Terminal | Circuit Role | Design Meaning |
|---|---|---|
| GPIO120 / QSPI1_CS1# / SPIMON_QSPI1_CS1# | SPI Monitor Channel 1 Chip Select | Asserted during CPU-side SPI transactions to trigger real-time flash integrity verification |
| GPIO124 / QSPI1_CS0# / SPIMON_QSPI1_CS0# | SPI Monitor Channel 1 Power-Good Indicator | Signals valid power state for CPU-side SPI Flash; used in intervention timing alignment |
| GPIO020 / QSPI0_IN_CS0# | BMC-side SPI Flash Input Chip Select | Carries BMC SPI command traffic into CEC1736 for monitoring and filtering |
| GPIO021 / QSPI0_IN_CS1# | BMC-side Secondary SPI Chip Select | Enables dual-CS BMC flash configurations; monitored independently by SPI0 monitor block |
| GPIO156 / LED0 & GPIO157 / LED1 | Breathing LED Outputs | Programmable rise/fall waveforms for status indication; operational in all EC sleep states |
| GPIO104 / UART0_TX & GPIO105 / UART0_RX | Debug/Host Communication Interface | NS16C550A-compatible UART with 16-byte FIFOs; supports baud rates up to 1.5 Mbps |
| GPIO170 [JTAG_STRAP] | JTAG Configuration Strap | Pull-down required at power-up to disable JTAG; enables secure production mode |
Key Features
| Feature | Design Value |
|---|---|
| Dual SPI Flash Monitor Blocks | Each with 64 KB match RAM and SHA-384 engine - enables independent, real-time BMC/CPU firmware integrity enforcement |
| TCG DICE-Compliant RoT | Immutable Boot ROM generates DICE CDI and UDS; supports attestation via SPDM in EC_FW |
| Fused Life Cycle Management | OTP-controlled progression through development → test → production states; prevents unauthorized key access or debug enablement |
| Hardware Crypto Acceleration | Dedicated engines for AES-GCM, SHA-2, RSA/ECC, and DRNG - offloads cryptographic operations from Cortex-M4F core |
| VTR1/VTR2 Dual I/O Banks | Electrically isolated 1.8 V / 3.3 V I/O domains - allows simultaneous interfacing with mixed-voltage BMC and CPU flash devices |
| Active SPI Intervention | QSPI analog switches physically isolate hosts from flash during violations - blocks chip erase, write, or read before completion |
Applications
| Server BMC Firmware Integrity | Telecom Baseband Processor RoT |
|---|---|
|
Use Scenario: BMC boots first and initializes platform; CEC1736-S0-I/2ZW-PROTO2 monitors BMC SPI Flash reads/writes during boot and runtime. IC Role / Device Role / Timing Role: Real-time SPI Flash monitor and intervention controller; operates synchronously with BMC SPI clock domain. Use Value: Prevents malicious firmware injection or rollback by blocking unauthorized flash writes and verifying signed image blocks before execution. |
Use Scenario: Baseband processor in 5G radio unit requires cryptographically verified boot and runtime attestation for regulatory compliance. IC Role / Device Role / Timing Role: Platform Root of Trust enforcing DICE-compliant identity and measurement reporting via SPDM. Use Value: Enables remote attestation of baseband firmware integrity using EC-generated certificates and runtime measurements. |
| Industrial Edge Controller Secure Boot | Network Switch Trusted Execution Environment |
|
Use Scenario: Edge gateway boots Linux kernel and safety-critical firmware; CEC1736-S0-I/2ZW-PROTO2 validates both images before loading. IC Role / Device Role / Timing Role: Immutable Boot ROM authenticates primary/fallback images from internal SPI Flash using ECC384 signatures. Use Value: Guarantees only authorized, unmodified firmware executes - critical for functional safety certification (IEC 61508 SIL2+). |
Use Scenario: Managed switch ASIC loads microcode from external flash; CEC1736-S0-I/2ZW-PROTO2 mediates all flash accesses. IC Role / Device Role / Timing Role: SPI Flash proxy with region-based access control and opcode filtering (e.g., blocks "Chip Erase" commands). Use Value: Mitigates supply-chain attacks targeting switch firmware by preventing unauthorized flash reprogramming in field deployments. |
Equivalent & Alternatives
The following parts are listed as comparable options for similar embedded controller security applications.
| Alternative Part | Technical Difference | Application Difference | Selection Advice |
|---|---|---|---|
| CEC1736-S0-I/2HW | 64-pin VFBGA; single SPI monitor channel; 2 MB internal SPI Flash; 52 GPIOs | Targeted for cost-sensitive single-host (BMC-only) platforms without CPU-side flash monitoring | Select when dual-host monitoring is unnecessary and PCB space/layout constraints favor smaller package |
| MAX32570 | ARM Cortex-M4 @ 100 MHz; 512 KB SRAM; no integrated SPI Flash; standalone secure element architecture | Used as companion RoT alongside main MCU; lacks built-in flash monitoring and dual-channel QSPI analog switches | Select when system already includes discrete flash controllers and requires higher SRAM or external flash flexibility |
Compared with CEC1736-S0-I/2HW, the CEC1736-S0-I/2ZW-PROTO2 adds dual SPI monitoring, 2× flash capacity, and 19 additional GPIOs - enabling full BMC+CPU platform integrity coverage in a single IC. Versus MAX32570, it integrates flash storage, analog isolation, and host-aware intervention logic - reducing BOM count and eliminating external signal routing for flash protection.
Availability
CEC1736-S0-I/2ZW-PROTO2 is available at Aetrix Electronics and suitable for server BMC firmware integrity, telecom baseband RoT, and industrial edge controller secure boot requiring stable component supply and long-term lifecycle support.
Supply support for CEC1736-S0-I/2ZW-PROTO2 includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.
Manufacturer
Microchip Technology is a global semiconductor company specializing in microcontrollers, analog components, and security ICs for industrial, automotive, and communications markets.
The CEC173x family is designed as Real Time Platform Root of Trust controllers - integrating secure boot, cryptographic acceleration, and active SPI flash monitoring specifically for server, telecom, and embedded computing platforms demanding hardware-enforced firmware integrity.
FAQ
What is the primary security function of the CEC1736-S0-I/2ZW-PROTO2?
The CEC1736-S0-I/2ZW-PROTO2 serves as a hardware-enforced Real Time Platform Root of Trust, performing dual-channel SPI Flash monitoring with active intervention, immutable secure boot via Boot ROM (SHA-384/ECC384), and SPDM-based attestation. Its core function is to verify firmware authenticity during host boot and prevent unauthorized flash modifications during runtime - directly protecting BMC and CPU boot paths in server and telecom systems. This behavior is implemented in the CEC1736-S0-I/2ZW-PROTO2 silicon and cannot be bypassed by software.
Does the CEC1736-S0-I/2ZW-PROTO2 support both 1.8 V and 3.3 V SPI interfaces?
Yes, the CEC1736-S0-I/2ZW-PROTO2 supports dual-voltage SPI operation: its VTR1 and VTR2 I/O banks are independently configurable for either 1.8 V or 3.3 V nominal operation, enabling direct interfacing with mixed-voltage SPI Flash devices used by BMC and CPU subsystems. This capability is confirmed in the DS00004571A datasheet under Operating Conditions and Pin Configuration sections, and applies specifically to the 2ZW package variant used in CEC1736-S0-I/2ZW-PROTO2.
How does the CEC1736-S0-I/2ZW-PROTO2 differ from the CEC1734-S0-I/2ZW variant?
The CEC1736-S0-I/2ZW-PROTO2 features a higher-performance ARM Cortex-M4F core (96 MHz vs. CEC1734's unspecified lower frequency), dual PWM outputs (vs. one in CEC1734), and enhanced tamper detection covering temperature and voltage (CEC1734 omits temperature sensing). Device ID 0024_41_xx h confirms CEC1736 silicon revision, and Table 1-1 explicitly lists CEC1736-S0-I/2ZW with 2× PWM, 71 GPIOs, and full tamper countermeasures - distinguishing it from CEC1734-S0-I/2ZW in CEC1736-S0-I/2ZW-PROTO2's functional scope.
Can the CEC1736-S0-I/2ZW-PROTO2 operate in low-power modes while maintaining security monitoring?
Yes, the CEC1736-S0-I/2ZW-PROTO2 maintains full SPI Flash monitoring and tamper detection functionality in both Light Sleep and Heavy Sleep modes. Its RTOS Timer runs continuously off the 32 kHz oscillator across all sleep states, and SPI monitor blocks remain active - verifying flash accesses and triggering intervention even when the Cortex-M4F core is halted. This ensures uninterrupted firmware integrity enforcement without sacrificing power efficiency in always-on platform security applications.
Is JTAG enabled by default on the CEC1736-S0-I/2ZW-PROTO2?
No, JTAG is disabled by default on the CEC1736-S0-I/2ZW-PROTO2. The GPIO170 pin functions as JTAG_STRAP and must be pulled down at power-up to keep JTAG disabled - a requirement for production security. This behavior is documented in the Pin Naming Conventions section (DS00004571A-page 9) and enforced by Boot ROM initialization. Enabling JTAG requires explicit OTP programming and physical strap modification, aligning with fused life cycle security policies for CEC1736-S0-I/2ZW-PROTO2.
CEC1736-S0-I/2ZW-PROTO2 Specifications
- Product attributes
- Attribute value
- Manufacturer:
- Microchip Technology
- Series:
- CryptoController™
- Package/Case:
- 84-WFBGA
- Packaging:
- Tray
- Product Status:
- Active
- Programmable:
- -
- Applications:
- -
- Core Processor:
- ARM® Cortex®-M4F
- Program Memory Type:
- OTP (1kB)
- Controller Series:
- CEC173X
- RAM Size:
- 384K x 8
- Interface:
- -
- Number of I/O:
- 71
- Voltage - Supply:
- 3.135V ~ 3.465V
- Operating Temperature:
- -40°C ~ 85°C
- Grade:
- -
- Qualification:
- -
- Mounting Type:
- Surface Mount
- Supplier Device Package:
- 84-WFBGA (7x7)
CEC1736-S0-I/2ZW-PROTO2 FAQ
1.How can I place an order for CEC1736-S0-I/2ZW-PROTO2 through Aetrix?
Please submit a Request for Quotation (RFQ) for CEC1736-S0-I/2ZW-PROTO2 on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.
2.Are the price and stock information for CEC1736-S0-I/2ZW-PROTO2 reliable?
The price and inventory of CEC1736-S0-I/2ZW-PROTO2 are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for CEC1736-S0-I/2ZW-PROTO2 is usually 5 days.
3.What payment methods are accepted for CEC1736-S0-I/2ZW-PROTO2?
We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for CEC1736-S0-I/2ZW-PROTO2 transactions.
Note: Certain payment methods may incur a processing fee.
4.How is shipping managed for CEC1736-S0-I/2ZW-PROTO2?
CEC1736-S0-I/2ZW-PROTO2 orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.
Once your CEC1736-S0-I/2ZW-PROTO2 order is processed, you will receive an email with the shipment details and tracking number.
Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.
5.How can I obtain technical support or documentation for CEC1736-S0-I/2ZW-PROTO2?
For technical support, including CEC1736-S0-I/2ZW-PROTO2 datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your CEC1736-S0-I/2ZW-PROTO2 requirements.
6.How does Aetrix verify that CEC1736-S0-I/2ZW-PROTO2 is sourced from the original manufacturer or authorized distributors?
All CEC1736-S0-I/2ZW-PROTO2 products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that CEC1736-S0-I/2ZW-PROTO2 meets industry standards.
7.What is the process for return or replacement of CEC1736-S0-I/2ZW-PROTO2?
All CEC1736-S0-I/2ZW-PROTO2 units undergo pre-shipment inspection (PSI). If there is an issue with CEC1736-S0-I/2ZW-PROTO2, returns or replacements are accepted under the following conditions:
1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.
2.The issue is reported within 90 days of delivery.
3.The CEC1736-S0-I/2ZW-PROTO2 part is unused and in its original packaging.
Return procedure for CEC1736-S0-I/2ZW-PROTO2:
1.Submit a request within 90 days.
2.Obtain a Return Material Authorization (RMA) from Aetrix.
CEC1736-S0-I/2ZW-PROTO2 Tags

-
CYPD3175-24LQXQ
Infineon Technologies

-
SLB9672VU20FW1523XTMA1
Infineon Technologies

-
SLB9670VQ20FW785XTMA1
Infineon Technologies

-
SLB9672XU20FW1523XTMA1
Infineon Technologies

-
SLB9673XU20FW2613XTMA1
Infineon Technologies

-
CYPD3125-40LQXIT
Infineon Technologies

-
AT97SC3204-U2A1A-20
Microchip Technology

-
AT97SC3204-U2A1A-10
Microchip Technology

-
SLM9670AQ20FW1311XTMA1
Infineon Technologies

-
SLB9672XU20FW1613XTMA1
Infineon Technologies

-
SLB9672AU20FW1613XTMA1
Infineon Technologies

-
SLB9673AU20FW2613XTMA1
Infineon Technologies
Tech Hub
TTL and CMOS logic families differ in thresholds, loading, output drive, power and timing. This engineering guide compares 74HC and 74HCT, calculates noise margins and checks 3.3 V/5 V compatibility.
A practical engineering guide to 3.3V and 5V logic compatibility, input thresholds, resistor dividers, translator ICs, MOSFET level shifting, I2C pull-ups, timing limits and power-sequencing risks.
The 74HC595 uses push-pull logic outputs, while the TPIC6B595 uses 50 V open-drain DMOS sinks for higher-power loads. This guide compares timing, current limits, 3.3 V interfacing, load wiring, thermal…
The 74HC595 converts serial data into eight stable parallel outputs. This guide covers pin functions, shift and storage timing, OE and MR behavior, drive-current limits, cascading, voltage compatibilit…
A technical comparison of level-sensitive latches and edge-triggered flip-flops, covering timing windows, setup and hold limits, master–slave operation, time borrowing, race-through, HDL inference and…
A D latch stores one bit while Enable controls when data can pass. This reference covers gate-level operation, truth tables, transparency, setup and hold timing, LE versus OE, common ICs and practical …
An SR latch stores one bit through cross-coupled feedback. This engineering reference covers NOR and NAND implementations, truth tables, forbidden-state recovery, gated operation, switch debouncing, fa…
Latch circuits retain one bit through feedback. This technical reference covers SR and D latches, truth tables, transparency, timing limits, latch-versus-flip-flop behavior, applications and common log…
An engineering guide to LED driver operation, constant-current and constant-voltage outputs, linear and switching topologies, dimming, IC selection, calculations, replacement compatibility, and fault c…
Operational amplifier guide covering op amp basics, feedback, ideal vs real op amps, common configurations, buffer circuits, offset, bias current, gain-bandwidth, slew rate, rail-to-rail limits and sel…
