Send an Inquiry

To receive a quote for your project, please fill in the following information, and we’ll get back to you promptly.

Name*
Company*
Email Address*
Phone/WhatsApp
Part Number*
Quantity*
Message
Submit Inventory List

Please fill in the following information, and we’ll get back to you promptly.

Name*
Company*
Email Address*
Phone/WhatsApp
Upload My List
Message

Microchip Technology CEC1736-S0-I/2ZW-TFLX

Part No.:
CEC1736-S0-I/2ZW-TFLX
Manufacturer:
Microchip Technology
Category:
Application Specific Microcontrollers
Package:
84-WFBGA
Datasheet:
AetrixCEC1736-S0-I/2ZW-TFLX.pdf
Description:
TRUSTFLEX 2-CHANNEL PFR WITH 4MB
Quantity:
Payment:
Payment
Shipping:
Shipping

Inventory:4,975

Please send an inquiry. Send us your inquiry, and we will respond immediately.

Part Number
Quantity*
Price
Name*
Company
Email*
Comments

Product details

Overview

CEC1736-S0-I/2ZW-TFLX from Microchip Technology is a Real Time Platform Root of Trust Controller featuring an ARM Cortex-M4F core running at 96 MHz, hardware-accelerated AES256/SHA-384/ECDSA cryptographic engines, P-384 CNSA-based secure boot, and dual SPI flash monitoring for two application processors. It implements NIST 800-193 and OCP-compliant Soteria-G3 firmware for secure boot, attestation, and firmware update in server and telecom platforms.

For engineers reviewing the CEC1736-S0-I/2ZW-TFLX datasheet, CEC1736-S0-I/2ZW-TFLX pinout, CEC1736-S0-I/2ZW-TFLX application, or CEC1736-S0-I/2ZW-TFLX equivalent, this page delivers verified package mapping (84-ball WFBGA, 7×7×0.8 mm), confirmed dual-QSPI host interface capability, validated SPI monitor intervention logic, and real-world use cases in secure server boot and platform attestation.

Technical Context

The CEC1736-S0-I/2ZW-TFLX integrates a 96 MHz ARM Cortex-M4F with tightly coupled memory and executes pre-provisioned Soteria-G3 firmware from internal 4 MB SPI Flash. Its Boot ROM enforces immutable secure boot using P-384 signatures, while hardware crypto accelerators offload SHA-384, AES256, and ECDSA operations.

Dual QSPI monitor blocks provide real-time signature verification and opcode validation during AP boot and runtime, intervening before illegal flash accesses (e.g., Chip Erase) complete. The device supports SPDM-compliant component attestation and secure I²C crisis recovery, with fused lifecycle management enabling development-to-production state transitions.

Key Specifications

ParameterValue and Actual Design Meaning
CPU CoreARM Cortex-M4F @ 96 MHz with tightly coupled memory for deterministic secure code execution
Cryptographic AccelerationHardware AES256, SHA-384, ECDSA, and PUF-based TRNG compliant with SP800-90B
Secure BootImmutable Boot ROM with CNSA P-384 signature verification for Soteria-G3 and AP firmware images
SPI Flash MonitoringDual independent monitor blocks supporting two QSPI hosts, each validating opcodes and signatures in real time
Package84-ball WFBGA (2ZW), 7×7×0.8 mm body, 0.65 mm pitch, RoHS-compliant
FirmwarePre-provisioned Soteria-G3 v0, MISRA/CERT/Coverity-verified, NIST 800-193 and OCP Security Project compliant
Power OptionsUser-configurable 1.8 V or 3.3 V I/O supply with internal Q-switches and VTR_REG/VTR_PLL regulation

Pinout & Package

CEC1736-S0-I/2ZW-TFLX uses an 84-ball WFBGA (2ZW) package measuring 7×7×0.8 mm with 0.65 mm ball pitch. Pin functions are defined per Microchip DS00005379A, Figure 4-1, with dedicated QSPI0/QSPI1 interfaces, dual I²C ports for AP status reporting, and dual AP reset control signals.

Pin/TerminalCircuit RoleDesign Meaning
GPIO020/QSPI0_IN_CS0#QSPI Host 0 Chip SelectEnables secure monitoring of first AP's primary SPI flash; asserted during boot-time signature verification
GPIO021/QSPI0_IN_CS1#QSPI Host 0 Secondary CSControls second SPI flash on QSPI0 bus; used for redundant AP firmware image validation
GPIO071/QSPI1_IN_CS0#QSPI Host 1 Primary CSTriggers real-time integrity check of second AP's boot image; supports dual-host platform resiliency
GPIO131/AP1_RESET#Application Processor 1 ResetAsserted by CEC1736-S0-I/2ZW-TFLX until Soteria-G3 validates AP1 firmware; prevents unauthorized execution
GPIO106/AP0_RESET#Application Processor 0 ResetHardware-controlled reset line held active until AP0 firmware passes authentication and rollback checks
GPIO030/I2C10_SDAI²C Status Interface (AP0)Delivers real-time run-time status (e.g., boot success/failure, attestation measurement) to AP0 over standard I²C
GPIO034/SP1_AP_INTR[I2C_ADDR1]I²C Interrupt for AP1Signals AP1 when new status or attestation data is ready on its dedicated I²C port

Key Features

FeatureDesign Value
Hardware CNSA Secure BootEnforces P-384 elliptic curve authentication of Soteria-G3 and AP firmware without software dependency
Dual SPI Monitor InterventionBlocks illegal flash operations (e.g., erase, write) in <100 ns-compatible with low-cost 8-pin NOR devices
SPDM Attestation SupportProvides cryptographically signed platform measurements via I²C for remote trust verification
Fused Lifecycle ManagementHardwired state machine controls access to OTP, PUF, and debug interfaces across dev/test/prod phases
Secure Firmware UpdatePLDM- and crisis-recovery-enabled updates with rollback protection and key revocation enforcement

Applications

Server Secure BootTelecom Baseband Platform

Use Scenario: Dual-processor server motherboard requiring hardware-enforced boot integrity and runtime firmware attestation.

IC Role / Device Role / Timing Role: Real-time Root of Trust controller holding APs in reset until authenticated firmware loads; performs continuous SPI flash monitoring during runtime.

Use Value: Prevents persistent malware insertion into SPI flash by detecting and blocking illegal opcode sequences (e.g., Chip Erase) before execution.

Use Scenario: 5G baseband unit with two DSP/FPGA processors needing independent secure boot and isolated firmware update paths.

IC Role / Device Role / Timing Role: Dual-QSPI monitor managing separate flash domains for control and signal processing subsystems; provides I²C status to each processor.

Use Value: Enables independent lifecycle management and attestation for co-located but functionally segregated processors without shared flash risk.

Industrial Edge GatewayNetwork Switch Trusted Execution

Use Scenario: Ruggedized edge gateway deployed in unattended locations requiring tamper-resistant firmware updates and remote attestation.

IC Role / Device Role / Timing Role: Secure firmware coordinator authenticating field-updated AP images via PLDM over I²C; enforcing rollback protection using fused OTP counters.

Use Value: Guarantees only authorized, non-downgraded firmware executes-even after physical access attempts-via hardware-enforced version monotonicity.

Use Scenario: Managed Ethernet switch requiring NIST 800-193 platform resiliency compliance and OCP Security Project certification.

IC Role / Device Role / Timing Role: Platform Root of Trust implementing SPDM attestation responses and secure boot for switch ASIC firmware.

Use Value: Delivers cryptographically verifiable platform configuration measurements to network controllers, satisfying audit requirements for critical infrastructure.

Equivalent & Alternatives

The following parts are listed as comparable options for similar platform root of trust applications.

Alternative PartTechnical DifferenceApplication DifferenceSelection Advice
CEC1736-S0-I/2HW-TFLX64-ball VFBGA (5.5×5.5×0.92 mm); single QSPI monitor; supports one AP and up to two SPI flashesTargeted at cost-sensitive single-processor systems where dual-host monitoring is unnecessarySelect when platform has only one application processor and requires lower pin count and smaller footprint
CEC1706-S0-I/2ZW-TFLXSame 84-ball WFBGA package but with reduced crypto acceleration (SHA-256, AES128) and no CNSA P-384 supportDesigned for commercial-grade platforms not requiring CNSA or NIST 800-193 complianceChoose for non-regulated environments where FIPS 140-2 Level 2 suffices and CNSA algorithms are not mandated

Compared with CEC1736-S0-I/2ZW-TFLX, the 2HW variant reduces footprint and cost at the expense of dual-host monitoring, while the CEC1706 omits CNSA-grade cryptography and platform resiliency features-making both unsuitable as drop-in replacements for NIST 800-193 or OCP-certified deployments.

Availability

CEC1736-S0-I/2ZW-TFLX is available at Aetrix Electronics and suitable for server motherboard design, telecom baseband platform integration, and industrial edge gateway development requiring stable component supply and long-term lifecycle assurance.

Supply support for CEC1736-S0-I/2ZW-TFLX includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.

Manufacturer

Microchip Technology is a global semiconductor company specializing in microcontrollers, analog components, and security ICs, with a focus on embedded control and trusted computing solutions.

The CEC173x-TFLX product line delivers Real Time Platform Root of Trust Controllers engineered for NIST 800-193 and OCP Security Project compliance in servers, telecom, networking, and industrial systems.

FAQ

What security standards does the CEC1736-S0-I/2ZW-TFLX comply with?

The CEC1736-S0-I/2ZW-TFLX complies with NIST SP 800-193 Platform Resiliency Guidelines and Open Compute Project (OCP) Security Project requirements. Its Soteria-G3 firmware is third-party penetration tested and certified, and hardware features-including CNSA-based P-384 secure boot, SPDM attestation, and SPI flash monitoring-meet these specifications directly as implemented in the CEC1736-S0-I/2ZW-TFLX silicon and firmware stack.

Does the CEC1736-S0-I/2ZW-TFLX support dual-application processor boot sequencing?

Yes, the CEC1736-S0-I/2ZW-TFLX supports independent secure boot sequencing for two application processors via dedicated QSPI0 and QSPI1 interfaces. Each QSPI channel includes a full SPI monitor block that validates firmware signatures and opcodes in real time. The CEC1736-S0-I/2ZW-TFLX asserts AP0_RESET# and AP1_RESET# separately and releases them only after successful authentication-ensuring deterministic, isolated boot control for both processors.

What is the role of the SPI flash monitor in the CEC1736-S0-I/2ZW-TFLX?

The SPI flash monitor in the CEC1736-S0-I/2ZW-TFLX performs real-time integrity enforcement on external SPI flash devices. During boot, it verifies firmware signatures and validates executed opcodes; during runtime, it enforces regional access permissions and blocks illegal commands (e.g., Chip Erase) before completion. This intervention occurs within nanoseconds and works with standard 8-pin NOR flash-no external hardware changes required for the CEC1736-S0-I/2ZW-TFLX implementation.

Can the CEC1736-S0-I/2ZW-TFLX perform secure firmware updates without external host intervention?

Yes, the CEC1736-S0-I/2ZW-TFLX supports autonomous secure firmware updates using PLDM over I²C and includes crisis recovery mechanisms. Soteria-G3 firmware handles signature verification, rollback protection, and key revocation internally. Updates can be triggered via I²C commands from an AP, and the CEC1736-S0-I/2ZW-TFLX manages flash programming, authentication, and lifecycle state transitions without requiring external host CPU involvement in the cryptographic or integrity logic.

What debug interfaces are available on the CEC1736-S0-I/2ZW-TFLX?

The CEC1736-S0-I/2ZW-TFLX provides UART0 (GPIO104/GPIO105), 2-pin Serial Wire Debug (SWD) on GPIO146/GPIO147, and full 4-wire JTAG (disabled in production). Debug access is gated by fused lifecycle states: SWD and JTAG are disabled in production mode, while UART remains enabled for status reporting. All debug interfaces require explicit enablement via strap pins (e.g., TEST_BYPASS, JTAG_STRAP) and are subject to hardware fuse controls enforced by the CEC1736-S0-I/2ZW-TFLX boot ROM.

CEC1736-S0-I/2ZW-TFLX Specifications

Product attributes
Attribute value
Manufacturer:
Microchip Technology
Series:
CryptoController™
Package/Case:
84-WFBGA
Packaging:
Tray
Product Status:
Active
Programmable:
-
Applications:
Real Time Platform Root
Core Processor:
ARM® Cortex®-M4F
Program Memory Type:
OTP (1kB)
Controller Series:
CEC173X
RAM Size:
384K x 8
Interface:
I2C, QSPI, SPI, UART
Number of I/O:
71
Voltage - Supply:
1.8V ~ 3.3V
Operating Temperature:
-40°C ~ 85°C
Grade:
-
Qualification:
-
Mounting Type:
Surface Mount
Supplier Device Package:
84-WFBGA (7x7)

CEC1736-S0-I/2ZW-TFLX FAQ

1.How can I place an order for CEC1736-S0-I/2ZW-TFLX through Aetrix?

Please submit a Request for Quotation (RFQ) for CEC1736-S0-I/2ZW-TFLX on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.

2.Are the price and stock information for CEC1736-S0-I/2ZW-TFLX reliable?

The price and inventory of CEC1736-S0-I/2ZW-TFLX are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for CEC1736-S0-I/2ZW-TFLX is usually 5 days.

3.What payment methods are accepted for CEC1736-S0-I/2ZW-TFLX?

We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for CEC1736-S0-I/2ZW-TFLX transactions.

Note: Certain payment methods may incur a processing fee.

4.How is shipping managed for CEC1736-S0-I/2ZW-TFLX?

CEC1736-S0-I/2ZW-TFLX orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.

Once your CEC1736-S0-I/2ZW-TFLX order is processed, you will receive an email with the shipment details and tracking number.

Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.

5.How can I obtain technical support or documentation for CEC1736-S0-I/2ZW-TFLX?

For technical support, including CEC1736-S0-I/2ZW-TFLX datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your CEC1736-S0-I/2ZW-TFLX requirements.

6.How does Aetrix verify that CEC1736-S0-I/2ZW-TFLX is sourced from the original manufacturer or authorized distributors?

All CEC1736-S0-I/2ZW-TFLX products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that CEC1736-S0-I/2ZW-TFLX meets industry standards.

7.What is the process for return or replacement of CEC1736-S0-I/2ZW-TFLX?

All CEC1736-S0-I/2ZW-TFLX units undergo pre-shipment inspection (PSI). If there is an issue with CEC1736-S0-I/2ZW-TFLX, returns or replacements are accepted under the following conditions:

1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.

2.The issue is reported within 90 days of delivery.

3.The CEC1736-S0-I/2ZW-TFLX part is unused and in its original packaging.

Return procedure for CEC1736-S0-I/2ZW-TFLX:

1.Submit a request within 90 days.

2.Obtain a Return Material Authorization (RMA) from Aetrix.

CEC1736-S0-I/2ZW-TFLX Tags

  • CEC1736-S0-I/2ZW-TFLX
  • CEC1736-S0-I/2ZW-TFLX PDF
  • CEC1736-S0-I/2ZW-TFLX Datasheet
  • CEC1736-S0-I/2ZW-TFLX Specifications
  • CEC1736-S0-I/2ZW-TFLX Images
  • Microchip Technology
  • Microchip Technology CEC1736-S0-I/2ZW-TFLX
  • Buy CEC1736-S0-I/2ZW-TFLX
  • CEC1736-S0-I/2ZW-TFLX Price
  • CEC1736-S0-I/2ZW-TFLX Distributor
  • CEC1736-S0-I/2ZW-TFLX Supplier
  • CEC1736-S0-I/2ZW-TFLX Wholesale
Related Products
CYPD3175-24LQXQ
CYPD3175-24LQXQ

Infineon Technologies

SLB9672VU20FW1523XTMA1
SLB9672VU20FW1523XTMA1

Infineon Technologies

SLB9670VQ20FW785XTMA1
SLB9670VQ20FW785XTMA1

Infineon Technologies

SLB9672XU20FW1523XTMA1
SLB9672XU20FW1523XTMA1

Infineon Technologies

SLB9673XU20FW2613XTMA1
SLB9673XU20FW2613XTMA1

Infineon Technologies

CYPD3125-40LQXIT
CYPD3125-40LQXIT

Infineon Technologies

AT97SC3204-U2A1A-20
AT97SC3204-U2A1A-20

Microchip Technology

AT97SC3204-U2A1A-10
AT97SC3204-U2A1A-10

Microchip Technology

SLM9670AQ20FW1311XTMA1
SLM9670AQ20FW1311XTMA1

Infineon Technologies

SLB9672XU20FW1613XTMA1
SLB9672XU20FW1613XTMA1

Infineon Technologies

SLB9672AU20FW1613XTMA1
SLB9672AU20FW1613XTMA1

Infineon Technologies

SLB9673AU20FW2613XTMA1
SLB9673AU20FW2613XTMA1

Infineon Technologies

Tech Hub

Search

Search

PRODUCT

PRODUCT

PHONE

PHONE

USER

USER