Microchip Technology CEC1736-S0-I/2ZW-TFLX
- Part No.:
- CEC1736-S0-I/2ZW-TFLX
- Manufacturer:
- Microchip Technology
- Category:
- Application Specific Microcontrollers
- Package:
- 84-WFBGA
- Datasheet:
-
CEC1736-S0-I/2ZW-TFLX.pdf
- Description:
- TRUSTFLEX 2-CHANNEL PFR WITH 4MB
- Quantity:
- Payment:

- Shipping:

Inventory:4,975
Please send an inquiry. Send us your inquiry, and we will respond immediately.
Product details
Overview
CEC1736-S0-I/2ZW-TFLX from Microchip Technology is a Real Time Platform Root of Trust Controller featuring an ARM Cortex-M4F core running at 96 MHz, hardware-accelerated AES256/SHA-384/ECDSA cryptographic engines, P-384 CNSA-based secure boot, and dual SPI flash monitoring for two application processors. It implements NIST 800-193 and OCP-compliant Soteria-G3 firmware for secure boot, attestation, and firmware update in server and telecom platforms.
For engineers reviewing the CEC1736-S0-I/2ZW-TFLX datasheet, CEC1736-S0-I/2ZW-TFLX pinout, CEC1736-S0-I/2ZW-TFLX application, or CEC1736-S0-I/2ZW-TFLX equivalent, this page delivers verified package mapping (84-ball WFBGA, 7×7×0.8 mm), confirmed dual-QSPI host interface capability, validated SPI monitor intervention logic, and real-world use cases in secure server boot and platform attestation.
Technical Context
The CEC1736-S0-I/2ZW-TFLX integrates a 96 MHz ARM Cortex-M4F with tightly coupled memory and executes pre-provisioned Soteria-G3 firmware from internal 4 MB SPI Flash. Its Boot ROM enforces immutable secure boot using P-384 signatures, while hardware crypto accelerators offload SHA-384, AES256, and ECDSA operations.
Dual QSPI monitor blocks provide real-time signature verification and opcode validation during AP boot and runtime, intervening before illegal flash accesses (e.g., Chip Erase) complete. The device supports SPDM-compliant component attestation and secure I²C crisis recovery, with fused lifecycle management enabling development-to-production state transitions.
Key Specifications
| Parameter | Value and Actual Design Meaning |
|---|---|
| CPU Core | ARM Cortex-M4F @ 96 MHz with tightly coupled memory for deterministic secure code execution |
| Cryptographic Acceleration | Hardware AES256, SHA-384, ECDSA, and PUF-based TRNG compliant with SP800-90B |
| Secure Boot | Immutable Boot ROM with CNSA P-384 signature verification for Soteria-G3 and AP firmware images |
| SPI Flash Monitoring | Dual independent monitor blocks supporting two QSPI hosts, each validating opcodes and signatures in real time |
| Package | 84-ball WFBGA (2ZW), 7×7×0.8 mm body, 0.65 mm pitch, RoHS-compliant |
| Firmware | Pre-provisioned Soteria-G3 v0, MISRA/CERT/Coverity-verified, NIST 800-193 and OCP Security Project compliant |
| Power Options | User-configurable 1.8 V or 3.3 V I/O supply with internal Q-switches and VTR_REG/VTR_PLL regulation |
Pinout & Package
CEC1736-S0-I/2ZW-TFLX uses an 84-ball WFBGA (2ZW) package measuring 7×7×0.8 mm with 0.65 mm ball pitch. Pin functions are defined per Microchip DS00005379A, Figure 4-1, with dedicated QSPI0/QSPI1 interfaces, dual I²C ports for AP status reporting, and dual AP reset control signals.
| Pin/Terminal | Circuit Role | Design Meaning |
|---|---|---|
| GPIO020/QSPI0_IN_CS0# | QSPI Host 0 Chip Select | Enables secure monitoring of first AP's primary SPI flash; asserted during boot-time signature verification |
| GPIO021/QSPI0_IN_CS1# | QSPI Host 0 Secondary CS | Controls second SPI flash on QSPI0 bus; used for redundant AP firmware image validation |
| GPIO071/QSPI1_IN_CS0# | QSPI Host 1 Primary CS | Triggers real-time integrity check of second AP's boot image; supports dual-host platform resiliency |
| GPIO131/AP1_RESET# | Application Processor 1 Reset | Asserted by CEC1736-S0-I/2ZW-TFLX until Soteria-G3 validates AP1 firmware; prevents unauthorized execution |
| GPIO106/AP0_RESET# | Application Processor 0 Reset | Hardware-controlled reset line held active until AP0 firmware passes authentication and rollback checks |
| GPIO030/I2C10_SDA | I²C Status Interface (AP0) | Delivers real-time run-time status (e.g., boot success/failure, attestation measurement) to AP0 over standard I²C |
| GPIO034/SP1_AP_INTR[I2C_ADDR1] | I²C Interrupt for AP1 | Signals AP1 when new status or attestation data is ready on its dedicated I²C port |
Key Features
| Feature | Design Value |
|---|---|
| Hardware CNSA Secure Boot | Enforces P-384 elliptic curve authentication of Soteria-G3 and AP firmware without software dependency |
| Dual SPI Monitor Intervention | Blocks illegal flash operations (e.g., erase, write) in <100 ns-compatible with low-cost 8-pin NOR devices |
| SPDM Attestation Support | Provides cryptographically signed platform measurements via I²C for remote trust verification |
| Fused Lifecycle Management | Hardwired state machine controls access to OTP, PUF, and debug interfaces across dev/test/prod phases |
| Secure Firmware Update | PLDM- and crisis-recovery-enabled updates with rollback protection and key revocation enforcement |
Applications
| Server Secure Boot | Telecom Baseband Platform |
|---|---|
Use Scenario: Dual-processor server motherboard requiring hardware-enforced boot integrity and runtime firmware attestation. IC Role / Device Role / Timing Role: Real-time Root of Trust controller holding APs in reset until authenticated firmware loads; performs continuous SPI flash monitoring during runtime. Use Value: Prevents persistent malware insertion into SPI flash by detecting and blocking illegal opcode sequences (e.g., Chip Erase) before execution. | Use Scenario: 5G baseband unit with two DSP/FPGA processors needing independent secure boot and isolated firmware update paths. IC Role / Device Role / Timing Role: Dual-QSPI monitor managing separate flash domains for control and signal processing subsystems; provides I²C status to each processor. Use Value: Enables independent lifecycle management and attestation for co-located but functionally segregated processors without shared flash risk. |
| Industrial Edge Gateway | Network Switch Trusted Execution |
Use Scenario: Ruggedized edge gateway deployed in unattended locations requiring tamper-resistant firmware updates and remote attestation. IC Role / Device Role / Timing Role: Secure firmware coordinator authenticating field-updated AP images via PLDM over I²C; enforcing rollback protection using fused OTP counters. Use Value: Guarantees only authorized, non-downgraded firmware executes-even after physical access attempts-via hardware-enforced version monotonicity. | Use Scenario: Managed Ethernet switch requiring NIST 800-193 platform resiliency compliance and OCP Security Project certification. IC Role / Device Role / Timing Role: Platform Root of Trust implementing SPDM attestation responses and secure boot for switch ASIC firmware. Use Value: Delivers cryptographically verifiable platform configuration measurements to network controllers, satisfying audit requirements for critical infrastructure. |
Equivalent & Alternatives
The following parts are listed as comparable options for similar platform root of trust applications.
| Alternative Part | Technical Difference | Application Difference | Selection Advice |
|---|---|---|---|
| CEC1736-S0-I/2HW-TFLX | 64-ball VFBGA (5.5×5.5×0.92 mm); single QSPI monitor; supports one AP and up to two SPI flashes | Targeted at cost-sensitive single-processor systems where dual-host monitoring is unnecessary | Select when platform has only one application processor and requires lower pin count and smaller footprint |
| CEC1706-S0-I/2ZW-TFLX | Same 84-ball WFBGA package but with reduced crypto acceleration (SHA-256, AES128) and no CNSA P-384 support | Designed for commercial-grade platforms not requiring CNSA or NIST 800-193 compliance | Choose for non-regulated environments where FIPS 140-2 Level 2 suffices and CNSA algorithms are not mandated |
Compared with CEC1736-S0-I/2ZW-TFLX, the 2HW variant reduces footprint and cost at the expense of dual-host monitoring, while the CEC1706 omits CNSA-grade cryptography and platform resiliency features-making both unsuitable as drop-in replacements for NIST 800-193 or OCP-certified deployments.
Availability
CEC1736-S0-I/2ZW-TFLX is available at Aetrix Electronics and suitable for server motherboard design, telecom baseband platform integration, and industrial edge gateway development requiring stable component supply and long-term lifecycle assurance.
Supply support for CEC1736-S0-I/2ZW-TFLX includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.
Manufacturer
Microchip Technology is a global semiconductor company specializing in microcontrollers, analog components, and security ICs, with a focus on embedded control and trusted computing solutions.
The CEC173x-TFLX product line delivers Real Time Platform Root of Trust Controllers engineered for NIST 800-193 and OCP Security Project compliance in servers, telecom, networking, and industrial systems.
FAQ
What security standards does the CEC1736-S0-I/2ZW-TFLX comply with?
The CEC1736-S0-I/2ZW-TFLX complies with NIST SP 800-193 Platform Resiliency Guidelines and Open Compute Project (OCP) Security Project requirements. Its Soteria-G3 firmware is third-party penetration tested and certified, and hardware features-including CNSA-based P-384 secure boot, SPDM attestation, and SPI flash monitoring-meet these specifications directly as implemented in the CEC1736-S0-I/2ZW-TFLX silicon and firmware stack.
Does the CEC1736-S0-I/2ZW-TFLX support dual-application processor boot sequencing?
Yes, the CEC1736-S0-I/2ZW-TFLX supports independent secure boot sequencing for two application processors via dedicated QSPI0 and QSPI1 interfaces. Each QSPI channel includes a full SPI monitor block that validates firmware signatures and opcodes in real time. The CEC1736-S0-I/2ZW-TFLX asserts AP0_RESET# and AP1_RESET# separately and releases them only after successful authentication-ensuring deterministic, isolated boot control for both processors.
What is the role of the SPI flash monitor in the CEC1736-S0-I/2ZW-TFLX?
The SPI flash monitor in the CEC1736-S0-I/2ZW-TFLX performs real-time integrity enforcement on external SPI flash devices. During boot, it verifies firmware signatures and validates executed opcodes; during runtime, it enforces regional access permissions and blocks illegal commands (e.g., Chip Erase) before completion. This intervention occurs within nanoseconds and works with standard 8-pin NOR flash-no external hardware changes required for the CEC1736-S0-I/2ZW-TFLX implementation.
Can the CEC1736-S0-I/2ZW-TFLX perform secure firmware updates without external host intervention?
Yes, the CEC1736-S0-I/2ZW-TFLX supports autonomous secure firmware updates using PLDM over I²C and includes crisis recovery mechanisms. Soteria-G3 firmware handles signature verification, rollback protection, and key revocation internally. Updates can be triggered via I²C commands from an AP, and the CEC1736-S0-I/2ZW-TFLX manages flash programming, authentication, and lifecycle state transitions without requiring external host CPU involvement in the cryptographic or integrity logic.
What debug interfaces are available on the CEC1736-S0-I/2ZW-TFLX?
The CEC1736-S0-I/2ZW-TFLX provides UART0 (GPIO104/GPIO105), 2-pin Serial Wire Debug (SWD) on GPIO146/GPIO147, and full 4-wire JTAG (disabled in production). Debug access is gated by fused lifecycle states: SWD and JTAG are disabled in production mode, while UART remains enabled for status reporting. All debug interfaces require explicit enablement via strap pins (e.g., TEST_BYPASS, JTAG_STRAP) and are subject to hardware fuse controls enforced by the CEC1736-S0-I/2ZW-TFLX boot ROM.
CEC1736-S0-I/2ZW-TFLX Specifications
- Product attributes
- Attribute value
- Manufacturer:
- Microchip Technology
- Series:
- CryptoController™
- Package/Case:
- 84-WFBGA
- Packaging:
- Tray
- Product Status:
- Active
- Programmable:
- -
- Applications:
- Real Time Platform Root
- Core Processor:
- ARM® Cortex®-M4F
- Program Memory Type:
- OTP (1kB)
- Controller Series:
- CEC173X
- RAM Size:
- 384K x 8
- Interface:
- I2C, QSPI, SPI, UART
- Number of I/O:
- 71
- Voltage - Supply:
- 1.8V ~ 3.3V
- Operating Temperature:
- -40°C ~ 85°C
- Grade:
- -
- Qualification:
- -
- Mounting Type:
- Surface Mount
- Supplier Device Package:
- 84-WFBGA (7x7)
CEC1736-S0-I/2ZW-TFLX FAQ
1.How can I place an order for CEC1736-S0-I/2ZW-TFLX through Aetrix?
Please submit a Request for Quotation (RFQ) for CEC1736-S0-I/2ZW-TFLX on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.
2.Are the price and stock information for CEC1736-S0-I/2ZW-TFLX reliable?
The price and inventory of CEC1736-S0-I/2ZW-TFLX are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for CEC1736-S0-I/2ZW-TFLX is usually 5 days.
3.What payment methods are accepted for CEC1736-S0-I/2ZW-TFLX?
We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for CEC1736-S0-I/2ZW-TFLX transactions.
Note: Certain payment methods may incur a processing fee.
4.How is shipping managed for CEC1736-S0-I/2ZW-TFLX?
CEC1736-S0-I/2ZW-TFLX orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.
Once your CEC1736-S0-I/2ZW-TFLX order is processed, you will receive an email with the shipment details and tracking number.
Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.
5.How can I obtain technical support or documentation for CEC1736-S0-I/2ZW-TFLX?
For technical support, including CEC1736-S0-I/2ZW-TFLX datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your CEC1736-S0-I/2ZW-TFLX requirements.
6.How does Aetrix verify that CEC1736-S0-I/2ZW-TFLX is sourced from the original manufacturer or authorized distributors?
All CEC1736-S0-I/2ZW-TFLX products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that CEC1736-S0-I/2ZW-TFLX meets industry standards.
7.What is the process for return or replacement of CEC1736-S0-I/2ZW-TFLX?
All CEC1736-S0-I/2ZW-TFLX units undergo pre-shipment inspection (PSI). If there is an issue with CEC1736-S0-I/2ZW-TFLX, returns or replacements are accepted under the following conditions:
1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.
2.The issue is reported within 90 days of delivery.
3.The CEC1736-S0-I/2ZW-TFLX part is unused and in its original packaging.
Return procedure for CEC1736-S0-I/2ZW-TFLX:
1.Submit a request within 90 days.
2.Obtain a Return Material Authorization (RMA) from Aetrix.
CEC1736-S0-I/2ZW-TFLX Tags

-
CYPD3175-24LQXQ
Infineon Technologies

-
SLB9672VU20FW1523XTMA1
Infineon Technologies

-
SLB9670VQ20FW785XTMA1
Infineon Technologies

-
SLB9672XU20FW1523XTMA1
Infineon Technologies

-
SLB9673XU20FW2613XTMA1
Infineon Technologies

-
CYPD3125-40LQXIT
Infineon Technologies

-
AT97SC3204-U2A1A-20
Microchip Technology

-
AT97SC3204-U2A1A-10
Microchip Technology

-
SLM9670AQ20FW1311XTMA1
Infineon Technologies

-
SLB9672XU20FW1613XTMA1
Infineon Technologies

-
SLB9672AU20FW1613XTMA1
Infineon Technologies

-
SLB9673AU20FW2613XTMA1
Infineon Technologies
Tech Hub
TTL and CMOS logic families differ in thresholds, loading, output drive, power and timing. This engineering guide compares 74HC and 74HCT, calculates noise margins and checks 3.3 V/5 V compatibility.
A practical engineering guide to 3.3V and 5V logic compatibility, input thresholds, resistor dividers, translator ICs, MOSFET level shifting, I2C pull-ups, timing limits and power-sequencing risks.
The 74HC595 uses push-pull logic outputs, while the TPIC6B595 uses 50 V open-drain DMOS sinks for higher-power loads. This guide compares timing, current limits, 3.3 V interfacing, load wiring, thermal…
The 74HC595 converts serial data into eight stable parallel outputs. This guide covers pin functions, shift and storage timing, OE and MR behavior, drive-current limits, cascading, voltage compatibilit…
A technical comparison of level-sensitive latches and edge-triggered flip-flops, covering timing windows, setup and hold limits, master–slave operation, time borrowing, race-through, HDL inference and…
A D latch stores one bit while Enable controls when data can pass. This reference covers gate-level operation, truth tables, transparency, setup and hold timing, LE versus OE, common ICs and practical …
An SR latch stores one bit through cross-coupled feedback. This engineering reference covers NOR and NAND implementations, truth tables, forbidden-state recovery, gated operation, switch debouncing, fa…
Latch circuits retain one bit through feedback. This technical reference covers SR and D latches, truth tables, transparency, timing limits, latch-versus-flip-flop behavior, applications and common log…
An engineering guide to LED driver operation, constant-current and constant-voltage outputs, linear and switching topologies, dimming, IC selection, calculations, replacement compatibility, and fault c…
Operational amplifier guide covering op amp basics, feedback, ideal vs real op amps, common configurations, buffer circuits, offset, bias current, gain-bandwidth, slew rate, rail-to-rail limits and sel…
