Analog Devices Inc./Maxim Integrated MAXQ1062ETP+
- Part No.:
- MAXQ1062ETP+
- Manufacturer:
- Analog Devices Inc./Maxim Integrated
- Category:
- Application Specific Microcontrollers
- Package:
- 20-WFQFN Exposed Pad
- Datasheet:
-
MAXQ1062ETP+.pdf
- Description:
- CRYPTO CTLR 8KB EEP 20TQFN
- Quantity:
- Payment:

- Shipping:

Inventory:4,107
Please send an inquiry. Send us your inquiry, and we will respond immediately.
Product details
Overview
MAXQ1062ETP+ from Maxim Integrated is a DeepCover® cryptographic controller IC designed as a secure coprocessor for embedded systems, providing hardware-accelerated TLS/DTLS key negotiation, ECDSA authentication, AES-128/-256 encryption (ECB/CBC/CCM/GCM), SHA-256/384/512 hashing, and true random number generation. It features 8KB of secure EEPROM for certificates, keys, and monotonic counters, and communicates via SPI or I²C in industrial temperature range (–40°C to +109°C).
For engineers reviewing the MAXQ1062ETP+ datasheet, MAXQ1062ETP+ pinout, MAXQ1062ETP+ application, or MAXQ1062ETP+ equivalent, this device delivers FIPS- and Common Criteria EAL4+-aligned security for IoT edge nodes, smart meters, PLCs, and gateways requiring certified key storage, secure boot, tamper detection, and offloaded TLS record processing without host firmware development.
Technical Context
The MAXQ1062ETP+ implements two distinct operational modes: TLS/DTLS toolbox mode for full protocol offload (including ECDHE, ECDSA, certificate chain validation, and master secret export), and AES-SPI mode for high-speed stream encryption (up to 20Mb/s) using dedicated hardware AES-GCM/ECB with DMA-linked SPI interface. Its dual-mode architecture isolates sensitive operations from the host while enabling flexible integration.
Security enforcement relies on physical tamper detection (voltage, frequency, temperature, light), life cycle management with one-way state transitions, secure file system access control per object, and immutable key storage-where private keys are never exposed in plaintext and require internal generation or cryptographically verified import. The true RNG feeds all key derivation and nonces.
Key Specifications
| Parameter | Value and Actual Design Meaning |
|---|---|
| Secure EEPROM | 8KB nonvolatile memory with atomic write, integrity protection, and 500K endurance cycles for keys, certs, and arbitrary data |
| Cryptographic Algorithms | AES-128/-256 (ECB/CBC/CCM/GCM), ECC NIST P-256/-384/-521 & Brainpool curves, SHA-256/-384/-512, HMAC-SHA256/384/512, ECDSA (FIPS 186-4) |
| Interface Options | I²C slave (400kbit/s fast mode, address 0x60 configurable) and SPI slave (Mode 0, LSB-first, active-low SSEL) |
| AES-SPI Engine | Dedicated 128-bit hardware engine supporting AES-GCM (SP 800-38D) and AES-ECB (SP 800-38A) at up to 20Mb/s with DMA-linked SPI |
| Security Certifications | Designed to meet FIPS 140-2 and Common Criteria EAL4+ requirements for physical, environmental, and logical protections |
| Operating Temperature | –40°C to +109°C industrial grade range, validated across full specification |
| Tamper Detection | Hardware-monitored voltage, frequency, temperature, and optical sensors with configurable RESET_OUT assertion |
Pinout & Package
MAXQ1062ETP+ is housed in a 20-pin TQFN package (4mm × 4mm, 0.5mm pitch) with wettable flanks, optimized for space-constrained industrial PCB layouts and reflow compatibility.
| Pin/Terminal | Circuit Role | Design Meaning |
|---|---|---|
| VDD | Power supply input | 3.0V to 3.6V main supply; decoupling required per layout guidelines |
| GND | Ground reference | Common return path for analog/digital domains; separate GND pins support noise isolation |
| SCL / SDA | I²C bus interface | Open-drain bidirectional lines; SDA supports clock stretching; default slave address 0x60 |
| SCLK / MOSI / MISO / SSEL | SPI bus interface | Four-wire full-duplex; Mode 0 timing; SSEL active-low enables SPI-AES or TLS-SPI mode selection |
| WDI | Watchdog input | Host-driven toggle signal; timeout configurable via register; asserts RESET_OUT on failure if enabled |
| RESET_OUT | Reset output | Open-drain signal driven by tamper events, WDT timeout, or internal fault; requires external pull-up |
| INT | Interrupt output | Active-low interrupt indicating command completion, error, or event (e.g., tamper detection) |
| VBAT | Backup power input | Optional 1.71V–3.6V supply for maintaining RTC/tamper state during main power loss |
Key Features
| Feature | Design Value |
|---|---|
| Secure Boot Support | Enables host MCU code/data integrity verification via SHA-256 hash and ECDSA signature before execution |
| Flexible File System | User-programmable access conditions per stored object (e.g., require authentication, lifecycle state, or tamper status) |
| Dual-Mode Operation | Runtime-selectable TLS/DTLS toolbox mode (full handshake offload) or AES-SPI mode (stream encryption acceleration) |
| True Random Number Generator | Hardware entropy source meeting NIST SP 800-90B requirements for on-chip ECC/AES key generation |
| Life Cycle Management | One-way state machine (e.g., Secure Provisioning → Operational → Locked) controlling read/write permissions per object |
Applications
| Smart Metering | Industrial PLCs |
|---|---|
Use Scenario: Secure firmware updates and meter data signing in ANSI C12.22 or DLMS/COSEM-compliant smart meters operating in utility substations. IC Role / Device Role / Timing Role: Cryptographic coprocessor handling ECDSA signature generation, certificate chain validation, and AES-GCM encryption of consumption data packets. Use Value: Prevents unauthorized firmware modification and ensures data origin authenticity with hardware-enforced private key protection-meeting ANSI C12.22 Annex B and IEC 62056-47 security mandates. |
Use Scenario: Securing Modbus TCP communications and firmware integrity in programmable logic controllers deployed in factory automation environments. IC Role / Device Role / Timing Role: TLS/DTLS coprocessor performing ECDHE key exchange and session key derivation for encrypted controller-to-HMI traffic. Use Value: Enables TLS 1.2 client authentication without exposing private keys to the PLC's main MCU-reducing attack surface against remote code execution exploits. |
| IoT Edge Gateways | Secure Access Control Systems |
Use Scenario: Certificate-based mutual authentication between field sensors and cloud platforms in industrial IoT gateways with constrained MCU resources. IC Role / Device Role / Timing Role: Offloads TLS 1.2 handshake, certificate revocation list (CRL) checking, and session key export to host stack for record-layer processing. Use Value: Reduces host CPU load by >70% during TLS negotiation and eliminates need for software-based crypto libraries vulnerable to side-channel attacks. |
Use Scenario: Enabling PKI-based door lock authentication and audit log signing in enterprise access control panels with tamper-evident enclosure requirements. IC Role / Device Role / Timing Role: Secure key vault and digital signature generator verifying credential certificates and signing access event logs with ECDSA. Use Value: Provides FIPS 140-2 Level 3-aligned key storage and tamper-responsive reset-ensuring logs cannot be forged or backdated after physical intrusion. |
Equivalent & Alternatives
The following parts are listed as comparable options for similar cryptographic coprocessor applications.
| Alternative Part | Technical Difference | Application Difference | Selection Advice |
|---|---|---|---|
| ATECC608A-TFLXT | 8KB secure EEPROM, SHA-256/ECC P-256 only, no AES-GCM hardware engine, I²C-only interface | Limited to basic TLS 1.2 client auth and key storage; lacks DTLS, AES-SPI streaming, or SHA-384/512 support | Select when cost-sensitive designs require only fundamental PKI functions and lack bandwidth-intensive encryption needs |
| SE050N-A110 | 16KB EEPROM, SHA-256/ECC P-256/P-384, AES-128/-256 GCM/ECB, I²C/SPI, but no dedicated AES-SPI DMA engine or TLS host stack integration | Requires more host-side TLS stack integration; no built-in secure boot verification or monotonic counter support | Select when broader algorithm coverage is needed but host has sufficient resources for TLS record layer implementation |
Compared with ATECC608A-TFLXT and SE050N-A110, the MAXQ1062ETP+ uniquely integrates TLS/DTLS offload with hardware-accelerated AES-SPI streaming, secure boot verification, and tamper-aware life cycle management-making it optimal for resource-constrained industrial devices requiring certified, end-to-end protocol security without host firmware development.
Availability
MAXQ1062ETP+ is available at Aetrix Electronics and suitable for smart metering, industrial PLCs, IoT edge gateways, and secure access control systems requiring stable component supply, long-term lifecycle assurance, and RoHS-compliant packaging.
Supply support for MAXQ1062ETP+ includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.
Manufacturer
Maxim Integrated (now part of Analog Devices) designs high-performance analog and mixed-signal ICs for industrial, automotive, and computing applications, with emphasis on reliability, precision, and security.
The MAXQ1062ETP+ belongs to the DeepCover® cryptographic controller product line, engineered specifically to provide certified, hardware-enforced security for embedded devices where firmware-based crypto is impractical or insufficiently robust.
FAQ
What communication interfaces does the MAXQ1062ETP+ support?
The MAXQ1062ETP+ supports both I²C and SPI interfaces. I²C operates in slave mode at up to 400kbit/s (fast mode) with a default address of 0x60, configurable via software. SPI operates in slave mode using Mode 0 timing, LSB-first data order, and active-low SSEL. The SPI interface also enables AES-SPI mode for high-speed hardware encryption. Both interfaces are fully supported in the MAXQ1062ETP+'s TLS/DTLS and secure storage functions.
How does the MAXQ1062ETP+ handle secure key storage and access control?
The MAXQ1062ETP+ provides 8KB of secure EEPROM with atomic write capability and integrity protection. Keys and certificates are stored in a flexible file system where each object has user-programmable access conditions-such as requiring authentication, specific life cycle state, or tamper status. Private keys are never readable in plaintext and must be generated internally or imported only after successful signature verification using a pre-stored public key. This enforcement is implemented in hardware within the MAXQ1062ETP+.
Does the MAXQ1062ETP+ support TLS 1.2 and DTLS 1.2 protocols?
Yes, the MAXQ1062ETP+ supports TLS 1.2 and DTLS 1.2 in client mode. Its TLS/DTLS cryptographic toolbox handles full key negotiation (ECDH, ECDHE, PSK), ECDSA-based authentication, certificate chain validation, and master secret export. The MAXQ1062ETP+ performs all sensitive operations-including private key use and session key derivation-internally, ensuring no exposure to the host processor. It integrates with Arm Mbed TLS for host stack compatibility.
What tamper detection mechanisms are built into the MAXQ1062ETP+?
The MAXQ1062ETP+ includes multiple independent tamper detection features: voltage glitch monitoring, frequency deviation detection, temperature threshold sensing, and optical intrusion detection. Each can be individually enabled and configured to assert the open-drain RESET_OUT signal upon violation. These mechanisms are hardened at the silicon level and aligned with Common Criteria EAL4+ requirements. Tamper response behavior-including whether to erase keys or trigger reset-is configurable per the MAXQ1062ETP+'s life cycle state.
Can the MAXQ1062ETP+ function as a secure bootloader for an external microcontroller?
Yes, the MAXQ1062ETP+ supports secure boot functionality by verifying the integrity and authenticity of external MCU firmware images using SHA-256 hashing and ECDSA signature verification. Upon successful validation, the MAXQ1062ETP+ releases access to protected resources (e.g., keys or configuration objects). This capability is implemented in hardware and enforced through the MAXQ1062ETP+'s life cycle management and secure file system, ensuring that only cryptographically signed and trusted code executes.
MAXQ1062ETP+ Specifications
- Product attributes
- Attribute value
- Manufacturer:
- Analog Devices Inc./Maxim Integrated
- Series:
- -
- Package/Case:
- 20-WFQFN Exposed Pad
- Packaging:
- Tray
- Product Status:
- Obsolete
- Programmable:
- Not Verified
- Applications:
- Security
- Core Processor:
- MAXQ
- Program Memory Type:
- EEPROM (8kB)
- Controller Series:
- MAXQ™
- RAM Size:
- -
- Interface:
- I2C, SPI
- Number of I/O:
- -
- Voltage - Supply:
- -
- Operating Temperature:
- -40°C ~ 109°C
- Grade:
- -
- Qualification:
- -
- Mounting Type:
- Surface Mount
- Supplier Device Package:
- 20-TQFN (4x4)
MAXQ1062ETP+ FAQ
1.How can I place an order for MAXQ1062ETP+ through Aetrix?
Please submit a Request for Quotation (RFQ) for MAXQ1062ETP+ on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.
2.Are the price and stock information for MAXQ1062ETP+ reliable?
The price and inventory of MAXQ1062ETP+ are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for MAXQ1062ETP+ is usually 5 days.
3.What payment methods are accepted for MAXQ1062ETP+?
We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for MAXQ1062ETP+ transactions.
Note: Certain payment methods may incur a processing fee.
4.How is shipping managed for MAXQ1062ETP+?
MAXQ1062ETP+ orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.
Once your MAXQ1062ETP+ order is processed, you will receive an email with the shipment details and tracking number.
Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.
5.How can I obtain technical support or documentation for MAXQ1062ETP+?
For technical support, including MAXQ1062ETP+ datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your MAXQ1062ETP+ requirements.
6.How does Aetrix verify that MAXQ1062ETP+ is sourced from the original manufacturer or authorized distributors?
All MAXQ1062ETP+ products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that MAXQ1062ETP+ meets industry standards.
7.What is the process for return or replacement of MAXQ1062ETP+?
All MAXQ1062ETP+ units undergo pre-shipment inspection (PSI). If there is an issue with MAXQ1062ETP+, returns or replacements are accepted under the following conditions:
1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.
2.The issue is reported within 90 days of delivery.
3.The MAXQ1062ETP+ part is unused and in its original packaging.
Return procedure for MAXQ1062ETP+:
1.Submit a request within 90 days.
2.Obtain a Return Material Authorization (RMA) from Aetrix.
MAXQ1062ETP+ Tags

-
CYPD3175-24LQXQ
Infineon Technologies

-
SLB9672VU20FW1523XTMA1
Infineon Technologies

-
SLB9670VQ20FW785XTMA1
Infineon Technologies

-
SLB9672XU20FW1523XTMA1
Infineon Technologies

-
SLB9673XU20FW2613XTMA1
Infineon Technologies

-
CYPD3125-40LQXIT
Infineon Technologies

-
AT97SC3204-U2A1A-20
Microchip Technology

-
AT97SC3204-U2A1A-10
Microchip Technology

-
SLM9670AQ20FW1311XTMA1
Infineon Technologies

-
SLB9672XU20FW1613XTMA1
Infineon Technologies

-
SLB9672AU20FW1613XTMA1
Infineon Technologies

-
SLB9673AU20FW2613XTMA1
Infineon Technologies
Tech Hub
A practical engineering guide to 3.3V and 5V logic compatibility, input thresholds, resistor dividers, translator ICs, MOSFET level shifting, I2C pull-ups, timing limits and power-sequencing risks.
The 74HC595 uses push-pull logic outputs, while the TPIC6B595 uses 50 V open-drain DMOS sinks for higher-power loads. This guide compares timing, current limits, 3.3 V interfacing, load wiring, thermal…
The 74HC595 converts serial data into eight stable parallel outputs. This guide covers pin functions, shift and storage timing, OE and MR behavior, drive-current limits, cascading, voltage compatibilit…
A technical comparison of level-sensitive latches and edge-triggered flip-flops, covering timing windows, setup and hold limits, master–slave operation, time borrowing, race-through, HDL inference and…
A D latch stores one bit while Enable controls when data can pass. This reference covers gate-level operation, truth tables, transparency, setup and hold timing, LE versus OE, common ICs and practical …
An SR latch stores one bit through cross-coupled feedback. This engineering reference covers NOR and NAND implementations, truth tables, forbidden-state recovery, gated operation, switch debouncing, fa…
Latch circuits retain one bit through feedback. This technical reference covers SR and D latches, truth tables, transparency, timing limits, latch-versus-flip-flop behavior, applications and common log…
An engineering guide to LED driver operation, constant-current and constant-voltage outputs, linear and switching topologies, dimming, IC selection, calculations, replacement compatibility, and fault c…
Operational amplifier guide covering op amp basics, feedback, ideal vs real op amps, common configurations, buffer circuits, offset, bias current, gain-bandwidth, slew rate, rail-to-rail limits and sel…
Jumper cables guide covering safe connection order, red and black clamp placement, final ground connection, cable gauge, length, clamp quality, copper vs CCA cables, jump starter comparison and battery…
