Microchip Technology CEC1736-S0-I/2ZW-TCSM
- Part No.:
- CEC1736-S0-I/2ZW-TCSM
- Manufacturer:
- Microchip Technology
- Category:
- Application Specific Microcontrollers
- Package:
- 84-WFBGA
- Datasheet:
-
CEC1736-S0-I/2ZW-TCSM.pdf
- Description:
- TRUSTCUSTOM 2-CHANNEL PFR WITH 4
- Quantity:
- Payment:

- Shipping:

Inventory:1,929
Please send an inquiry. Send us your inquiry, and we will respond immediately.
Product details
Overview
CEC1736-S0-I/2ZW-TCSM from Microchip Technology is a real-time platform root of trust controller for server and telecom infrastructure, integrating an ARM® Cortex-M4F core (96 MHz), 384 KB SRAM (320 KB code + 64 KB data), dual SPI flash monitoring blocks, 4 MB in-package SPI flash, and hardware crypto accelerators (AES-256, SHA-384, ECDSA, PUF, DRNG). It operates at 3.3 V with optional 1.8 V SPI I/O and supports -40°C to +85°C industrial temperature range.
For engineers reviewing the CEC1736-S0-I/2ZW-TCSM datasheet, CEC1736-S0-I/2ZW-TCSM pinout, CEC1736-S0-I/2ZW-TCSM application, or CEC1736-S0-I/2ZW-TCSM equivalent, key selection criteria include dual-channel SPI flash intervention capability, TCG DICE compliance, secure boot with CNSA-compliant SHA-384/ECC384, 84-pin WFBGA package with VTR1/VTR2 dual-power I/O domains, and support for SPDM-based attestation in server BMC/CPU co-verification architectures.
Technical Context
The CEC1736-S0-I/2ZW-TCSM implements two independent QSPI analog switch isolation paths - one per host (BMC and CPU) - enabling real-time SPI flash access monitoring, hash-based integrity verification (SHA-256/384 on 8 KB regions), and active intervention against illegal erase/write operations. Its dual 64 KB dedicated SRAM match buffers and per-channel 50 MHz SPI operation are confirmed for the 84-pin 2ZW variant.
It features deterministic random number generation compliant with NIST SP800-90B, tamper detection across voltage, temperature, and side-channel power, fused life-cycle management per OpenTitan spec, and immutable Boot ROM implementing DICE CDI generation, SPDM requester support, and rollback-protected dual-image boot from internal flash.
Key Specifications
| Parameter | Value and Actual Design Meaning |
|---|---|
| Core Processor | ARM Cortex-M4F @ 96 MHz with FPU, NVIC, MPU, and JTAG/SWD debug interfaces |
| Memory | 384 KB SRAM (320 KB code + 64 KB data), 8 Kbit OTP, 4 MB in-package SPI flash (dual-channel) |
| Crypto Acceleration | AES-128/192/256-GCM, SHA-256/384/512, RSA up to 4096-bit, ECC up to 521-bit prime field, PUF for ECC384 key derivation |
| SPI Flash Monitoring | Dual independent monitors (BMC & CPU), each with 64 KB match buffer, SHA-256/384 hashing, real-time intervention on illegal opcodes |
| Package & I/O | 84-pin WFBGA, dual 1.8 V / 3.3 V configurable I/O banks (VTR1/VTR2), 71 GPIOs with glitch/UV protection |
| Security Compliance | TCG DICE (immutable ROM), CNSA (SHA-384/ECC384), NIST 800-193 PFR, SPDM attestation, Life Cycle Management |
| Power & Temp | 3.3 V VTR_REG supply, -40°C to +85°C operating range, Light/Heavy Sleep modes with GPIO wake capability |
Pinout & Package
CEC1736-S0-I/2ZW-TCSM uses an 84-pin WFBGA package (2ZW suffix) with dual-voltage I/O domains: VTR1 (SPI0 channel) and VTR2 (SPI1 channel), plus VTR_REG (core 3.3 V) and VTR_ANALOG (analog reference). Pin functions include dual QSPI controllers, five SMBus/I2C hosts, two breathing LEDs, UART, PWM, RTC timers, and dedicated SPI flash monitor control signals (e.g., SPIMON_QSPI0_CS0#, SPIMON_QSPI1_CS1#).
| Pin/Terminal | Circuit Role | Design Meaning |
|---|---|---|
| GPIO020/QSPI0_IN_CS0# | SPI Monitor Channel 0 Chip Select Input | Asserted by host CPU to initiate monitored SPI transaction on first channel; enables real-time signature verification |
| GPIO120/QSPI1_CS1# | SPI Monitor Channel 1 Chip Select Input | Asserted by BMC to initiate monitored SPI transaction on second channel; isolates BMC firmware integrity path |
| GPIO055/SPIMON_QSPI0_CS0# | SPI Monitor Channel 0 Intervention Output | Active-low signal that cancels ongoing SPI flash access when violation detected on channel 0 |
| GPIO124/SPIMON_QSPI1_CS0# | SPI Monitor Channel 1 Intervention Output | Active-low signal that cancels ongoing SPI flash access when violation detected on channel 1 |
| GPIO201/32KHZ_OUT[CR_FLASH] | Crystal Oscillator Output for Flash Timing | Provides 32.768 kHz clock to external SPI flash devices; enabled only during CR_FLASH strap mode |
| GPIO170[JTAG_STRAP] | JTAG Enable Strap Input | Pulled low at reset to disable JTAG interface permanently; required for production security hardening |
Key Features
| Feature | Design Value |
|---|---|
| Dual SPI Flash Monitor Blocks | Enables independent, real-time integrity enforcement for both BMC and CPU boot images without shared resources or timing contention |
| TCG DICE Root of Trust | Immutable Boot ROM generates DICE CDI and supports SPDM attestation - enabling verifiable platform identity in zero-trust server environments |
| Hardware Crypto Engine | Offloads SHA-384/ECC384 signing, AES-256-GCM encryption, and DRNG health-tested entropy generation from firmware |
| Fused Life Cycle Management | OTP-controlled progression through development → test → production states, disabling debug interfaces and locking key storage per phase |
| QSPI Analog Switch Isolation | Physically separates host processors from flash devices during runtime, preventing unauthorized direct access even if host OS is compromised |
Applications
| Server BMC Firmware Integrity | Telecom Baseband Processor RoT |
|---|---|
Use Scenario: BMC boots from SPI flash and loads host firmware; malicious firmware update attempts must be blocked before execution. IC Role / Device Role / Timing Role: Real-time SPI flash monitor acting as hardware-enforced gatekeeper between BMC and its boot flash, verifying signatures and blocking illegal opcodes. Use Value: Prevents persistent BMC compromise via flash corruption; meets NIST 800-193 Platform Firmware Resilience requirements. |
Use Scenario: Baseband processor in 5G radio unit requires cryptographically verified boot and runtime attestation for regulatory compliance. IC Role / Device Role / Timing Role: Immutable Root of Trust providing DICE CDI, SPDM responder functionality, and hardware-accelerated certificate signing. Use Value: Enables remote attestation of baseband firmware integrity to network operator security gateways without software stack dependency. |
| Industrial Edge Controller Secure Boot | Network Switch Trusted Execution Environment |
Use Scenario: Edge controller in factory automation runs untrusted third-party applications but must guarantee bootloader and kernel integrity. IC Role / Device Role / Timing Role: Secure boot loader authenticating dual-image firmware (primary/fallback) from internal SPI flash using SHA-384/ECC384 keys stored in OTP. Use Value: Enforces rollback protection and key revocation - critical for long-lifecycle deployments where firmware patches may introduce regressions. |
Use Scenario: Managed Ethernet switch requires hardware-isolated firmware verification for both control plane (CPU) and management plane (BMC). IC Role / Device Role / Timing Role: Dual-channel SPI monitor enforcing separate integrity policies for CPU and BMC flash, with independent 64 KB match buffers and intervention logic. Use Value: Eliminates cross-plane attack surface - BMC compromise cannot corrupt CPU firmware, and vice versa, satisfying IEC 62443-4-2 SL3 requirements. |
Equivalent & Alternatives
The following parts are listed as comparable options for similar embedded controller root-of-trust applications.
| Alternative Part | Technical Difference | Application Difference | Selection Advice |
|---|---|---|---|
| CEC1736-S0-I/2HW | 64-pin VFBGA, single SPI monitor block, 2 MB internal SPI flash, no VTR2 I/O bank | Limited to single-host (BMC-only) monitoring; unsuitable for CPU+BMC dual-path architectures | Select only for cost-sensitive BMC-only designs without CPU-side flash protection requirement |
| MAX32570 | Maxim Integrated secure microcontroller; ARM Cortex-M4 @ 48 MHz, 512 KB SRAM, no integrated SPI flash, single-channel SPI monitor | Lacks dual-monitor architecture, DICE compliance, and in-package flash - requires external memory and additional isolation components | Consider when needing higher SRAM capacity and external flash flexibility, but accept added BOM complexity and reduced integration |
Compared with CEC1736-S0-I/2ZW-TCSM, the CEC1736-S0-I/2HW omits CPU-side monitoring and reduces flash capacity, while MAX32570 trades integration for configurability - neither provides the same dual-channel, in-package, DICE-compliant RoT foundation for server-grade firmware resilience.
Availability
CEC1736-S0-I/2ZW-TCSM is available at Aetrix Electronics and suitable for server BMC validation, telecom baseband certification, and industrial edge controller production requiring stable component supply, long-term lifecycle assurance, and traceable secure silicon sourcing.
Supply support for CEC1736-S0-I/2ZW-TCSM includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.
Manufacturer
Microchip Technology Inc. is a leading provider of microcontrollers, analog components, and security solutions, serving automotive, industrial, communications, and computing markets with vertically integrated silicon and software.
The CEC173x family is designed as a real-time platform root of trust controller specifically for server, telecom, and industrial systems requiring hardware-enforced firmware integrity, cryptographic acceleration, and DICE-compliant attestation capabilities.
FAQ
What is the primary security function of the CEC1736-S0-I/2ZW-TCSM in server platforms?
The CEC1736-S0-I/2ZW-TCSM serves as a hardware-enforced root of trust that performs real-time SPI flash monitoring for both BMC and CPU boot paths. It verifies firmware image authenticity using SHA-384/ECC384 signatures from OTP-stored keys, intervenes on illegal flash operations (e.g., chip erase), and generates DICE-compliant attestation evidence via SPDM - all enforced by immutable Boot ROM code in the CEC1736-S0-I/2ZW-TCSM.
Does the CEC1736-S0-I/2ZW-TCSM support dual-voltage I/O for interfacing with both 1.8 V and 3.3 V SPI flash devices?
Yes, the CEC1736-S0-I/2ZW-TCSM supports dual-voltage I/O through separate VTR1 and VTR2 power domains, allowing independent configuration of SPI0 and SPI1 channels for either 1.8 V or 3.3 V operation. This enables direct connection to mixed-voltage flash devices without level shifters - a confirmed capability of the CEC1736-S0-I/2ZW-TCSM per its 2ZW package specification.
How does the CEC1736-S0-I/2ZW-TCSM implement tamper resistance?
The CEC1736-S0-I/2ZW-TCSM integrates voltage, temperature, and side-channel power tamper detection circuits that trigger countermeasures including OTP lock, SRAM wipe, and cryptographic key erasure. These features are explicitly documented for the CEC1736-S0-I/2ZW-TCSM in DS00004571A-page 7 and are enabled by fused life-cycle bits in OTP memory.
Can the CEC1736-S0-I/2ZW-TCSM operate in low-power sleep modes while maintaining security monitoring?
Yes, the CEC1736-S0-I/2ZW-TCSM supports Light Sleep and Heavy Sleep modes with sub-µA standby current, and its RTOS timer continues counting off the 32 kHz oscillator in all sleep states. SPI flash monitoring remains active during sleep, and GPIO, timer, or SPI activity can wake the device - all confirmed operational characteristics of the CEC1736-S0-I/2ZW-TCSM.
What debug interfaces are available on the CEC1736-S0-I/2ZW-TCSM, and how are they secured?
The CEC1736-S0-I/2ZW-TCSM provides 2-pin Serial Wire Debug (SWD), 4-pin JTAG (disabled by default), and Trace FIFO Debug Port (TFDP). JTAG is disabled at power-on unless GPIO170[JTAG_STRAP] is held low during reset - a hardware fuse mechanism ensuring debug lockdown in production. SWD remains available for authorized firmware development but requires authenticated access per Boot ROM policy in the CEC1736-S0-I/2ZW-TCSM.
CEC1736-S0-I/2ZW-TCSM Specifications
- Product attributes
- Attribute value
- Manufacturer:
- Microchip Technology
- Series:
- CryptoController™
- Package/Case:
- 84-WFBGA
- Packaging:
- Tray
- Product Status:
- Active
- Programmable:
- -
- Applications:
- Real Time Platform Root
- Core Processor:
- ARM® Cortex®-M4F
- Program Memory Type:
- OTP (1kB)
- Controller Series:
- CEC173X
- RAM Size:
- 384K x 8
- Interface:
- I2C, PWM, SMBus, SPI, UART
- Number of I/O:
- 71
- Voltage - Supply:
- 1.8V ~ 3.3V
- Operating Temperature:
- -40°C ~ 85°C
- Grade:
- -
- Qualification:
- -
- Mounting Type:
- Surface Mount
- Supplier Device Package:
- 84-WFBGA (7x7)
CEC1736-S0-I/2ZW-TCSM FAQ
1.How can I place an order for CEC1736-S0-I/2ZW-TCSM through Aetrix?
Please submit a Request for Quotation (RFQ) for CEC1736-S0-I/2ZW-TCSM on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.
2.Are the price and stock information for CEC1736-S0-I/2ZW-TCSM reliable?
The price and inventory of CEC1736-S0-I/2ZW-TCSM are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for CEC1736-S0-I/2ZW-TCSM is usually 5 days.
3.What payment methods are accepted for CEC1736-S0-I/2ZW-TCSM?
We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for CEC1736-S0-I/2ZW-TCSM transactions.
Note: Certain payment methods may incur a processing fee.
4.How is shipping managed for CEC1736-S0-I/2ZW-TCSM?
CEC1736-S0-I/2ZW-TCSM orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.
Once your CEC1736-S0-I/2ZW-TCSM order is processed, you will receive an email with the shipment details and tracking number.
Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.
5.How can I obtain technical support or documentation for CEC1736-S0-I/2ZW-TCSM?
For technical support, including CEC1736-S0-I/2ZW-TCSM datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your CEC1736-S0-I/2ZW-TCSM requirements.
6.How does Aetrix verify that CEC1736-S0-I/2ZW-TCSM is sourced from the original manufacturer or authorized distributors?
All CEC1736-S0-I/2ZW-TCSM products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that CEC1736-S0-I/2ZW-TCSM meets industry standards.
7.What is the process for return or replacement of CEC1736-S0-I/2ZW-TCSM?
All CEC1736-S0-I/2ZW-TCSM units undergo pre-shipment inspection (PSI). If there is an issue with CEC1736-S0-I/2ZW-TCSM, returns or replacements are accepted under the following conditions:
1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.
2.The issue is reported within 90 days of delivery.
3.The CEC1736-S0-I/2ZW-TCSM part is unused and in its original packaging.
Return procedure for CEC1736-S0-I/2ZW-TCSM:
1.Submit a request within 90 days.
2.Obtain a Return Material Authorization (RMA) from Aetrix.
CEC1736-S0-I/2ZW-TCSM Tags

-
CYPD3175-24LQXQ
Infineon Technologies

-
SLB9672VU20FW1523XTMA1
Infineon Technologies

-
SLB9670VQ20FW785XTMA1
Infineon Technologies

-
SLB9672XU20FW1523XTMA1
Infineon Technologies

-
SLB9673XU20FW2613XTMA1
Infineon Technologies

-
CYPD3125-40LQXIT
Infineon Technologies

-
AT97SC3204-U2A1A-20
Microchip Technology

-
AT97SC3204-U2A1A-10
Microchip Technology

-
SLM9670AQ20FW1311XTMA1
Infineon Technologies

-
SLB9672XU20FW1613XTMA1
Infineon Technologies

-
SLB9672AU20FW1613XTMA1
Infineon Technologies

-
SLB9673AU20FW2613XTMA1
Infineon Technologies
Tech Hub
TTL and CMOS logic families differ in thresholds, loading, output drive, power and timing. This engineering guide compares 74HC and 74HCT, calculates noise margins and checks 3.3 V/5 V compatibility.
A practical engineering guide to 3.3V and 5V logic compatibility, input thresholds, resistor dividers, translator ICs, MOSFET level shifting, I2C pull-ups, timing limits and power-sequencing risks.
The 74HC595 uses push-pull logic outputs, while the TPIC6B595 uses 50 V open-drain DMOS sinks for higher-power loads. This guide compares timing, current limits, 3.3 V interfacing, load wiring, thermal…
The 74HC595 converts serial data into eight stable parallel outputs. This guide covers pin functions, shift and storage timing, OE and MR behavior, drive-current limits, cascading, voltage compatibilit…
A technical comparison of level-sensitive latches and edge-triggered flip-flops, covering timing windows, setup and hold limits, master–slave operation, time borrowing, race-through, HDL inference and…
A D latch stores one bit while Enable controls when data can pass. This reference covers gate-level operation, truth tables, transparency, setup and hold timing, LE versus OE, common ICs and practical …
An SR latch stores one bit through cross-coupled feedback. This engineering reference covers NOR and NAND implementations, truth tables, forbidden-state recovery, gated operation, switch debouncing, fa…
Latch circuits retain one bit through feedback. This technical reference covers SR and D latches, truth tables, transparency, timing limits, latch-versus-flip-flop behavior, applications and common log…
An engineering guide to LED driver operation, constant-current and constant-voltage outputs, linear and switching topologies, dimming, IC selection, calculations, replacement compatibility, and fault c…
Operational amplifier guide covering op amp basics, feedback, ideal vs real op amps, common configurations, buffer circuits, offset, bias current, gain-bandwidth, slew rate, rail-to-rail limits and sel…
