STMicroelectronics ST33HTPH2X32AHD4
- Part No.:
- ST33HTPH2X32AHD4
- Manufacturer:
- STMicroelectronics
- Category:
- Application Specific Microcontrollers
- Package:
- 32-VFQFN Exposed Pad
- Datasheet:
-
ST33HTPH2X32AHD4.pdf
- Description:
- IC MCU 32BIT FLASH 32VFQFPN
- Quantity:
- Payment:

- Shipping:

Inventory:4,970
Please send an inquiry. Send us your inquiry, and we will respond immediately.
Product details
Overview
ST33HTPH2X32AHD4 from STMicroelectronics is a Flash-memory-based Trusted Platform Module (TPM) 2.0 security IC compliant with TCG TPM Library 2.0 Level 0 Rev 138 and PC Client Specific Platform Spec 1.03, featuring Arm® SecurCore® SC300™ 32-bit RISC core, SPI interface up to 33 MHz, and extended temperature operation from −40 °C to 105 °C at 3.3 V supply.
For engineers reviewing the ST33HTPH2X32AHD4 datasheet, ST33HTPH2X32AHD4 pinout, ST33HTPH2X32AHD4 application, or ST33HTPH2X32AHD4 equivalent, key selection considerations include FIPS 140-2 Level 2 certification, SP800-193 compliance for fault recovery, hardware-enforced RNG (SHA256 DRBG + AIS-31 PTG2 TRNG), and support for RSA/ECC/SHA/AES cryptographic suites in a VFQFPN32 package.
Technical Context
This TPM implements a hardened Arm SecurCore SC300 processor with active shield, environmental sensors, and fault-injection countermeasures. It executes TPM 2.0 firmware with self-recovery capability during interrupted updates and supports full cryptographic service stacks including ECDAA on BN-256, ECDSA on NIST P-256/P-384, and RSA-2048 key generation.
The device integrates dual-voltage operation (1.8 V or 3.3 V), 4 kV HBM ESD protection, and SPI slave interface with dedicated PIRQ interrupt and physical presence GPIO. Its firmware version 0x00.01.01.01 (1.257) is designated Active per ST's ordering matrix, enabling secure boot, remote attestation, and key binding in endpoint systems.
Key Specifications
| Parameter | Value and Actual Design Meaning |
|---|---|
| Firmware Version | 0x00.01.01.01 (1.257); Active status per ST ordering code table, enabling field-deployable TPM 2.0 services. |
| SPI Clock Max | 33 MHz; enables high-throughput command/response exchange with host CPU without timing bottlenecks. |
| Operating Temp | −40 °C to 105 °C at 3.3 V; supports industrial and automotive under-hood deployments requiring extended thermal resilience. |
| Cryptographic Support | RSA-2048, ECC NIST P-256/P-384, SHA-256/384/3, AES-128/192/256, HMAC-SHA, TDES-192; meets full TCG 2.0 algorithm requirements. |
| Security Certifications | FIPS 140-2 Level 2 (physical security level 3), CC EAL4+ (AVA_VAN.5), SP800-193 compliant; validated for government and enterprise trust anchors. |
| Random Number Generation | FIPS-compliant RNG combining SHA256 DRBG (SP800-90A) and AIS-31 Class PTG2 TRNG; provides entropy for key derivation and nonces. |
| Endorsement Keys | Pre-provisioned with three EKs (RSA-2048, ECC P-256, ECC P-384) and corresponding certificates; reduces provisioning latency in OEM manufacturing. |
Pinout & Package
Delivered in VFQFPN32 (5 × 5 mm, 0.5 mm pitch) ECOPACK2 package with exposed thermal pad (Pin 33, not internally connected). Package supports reflow soldering and meets RoHS/ECOPACK environmental standards.
| Pin/Terminal | Circuit Role | Design Meaning |
|---|---|---|
| VPS | Power Supply Input | Accepts 1.8 V or 3.3 V DC rail; determines operating temperature range and voltage domain for internal logic. |
| GND | Ground Reference | Must connect to motherboard ground plane; critical for noise immunity and cryptographic side-channel resistance. |
| SPI_RST | Active-Low Reset | Hardware-initiated re-initialization; requires external pull-up if not driven by host; ensures deterministic state recovery. |
| SPI_MISO | Master-In Slave-Out | TPM data output line; carries command responses and status bits back to host SPI controller. |
| SPI_MOSI | Master-Out Slave-In | Host-to-TPM command/data input; supports full TPM 2.0 command buffer transmission. |
| SPI_CLK | Serial Clock Input | Driven by host; synchronizes all SPI transactions up to 33 MHz; defines maximum throughput for attestation flows. |
| SPI_CS | Chip Select Input | Active-low enable signal; internal pull-up allows single-wire control; isolates TPM during bus contention. |
| SPI_PIRQ | Interrupt Output | Open-drain, active-low IRQ; signals asynchronous events (e.g., command completion, error, physical presence assertion). |
| GPIO_PP | Physical Presence Input | Active-high signal indicating user-authorized TPM configuration changes; internal pull-down ensures safe default state. |
| GPIO_LP | Low-Power Mode Control | Enables/disables TPMLowPowerByGpio standby mode; configurable via NV storage index for custom power policies. |
Key Features
| Feature | Design Value |
|---|---|
| Fault-Tolerant Firmware Loader | Self-recovery mechanism preserves TPM functionality during interrupted firmware updates, eliminating need for factory reflash. |
| SP800-193 Compliance | Hardware-enforced protection, detection, and recovery against firmware corruption, ensuring continuity of trust root operations. |
| Triple Endorsement Key Provisioning | Pre-loaded RSA-2048, ECC P-256, and ECC P-384 EKs with certificates reduce OEM provisioning time and simplify key lifecycle management. |
| Hardware RNG with Dual Entropy Sources | Combines AIS-31 Class PTG2 TRNG and SP800-90A SHA256 DRBG to meet FIPS 140-2 entropy validation requirements. |
| Environmental Monitoring | Integrated sensors detect voltage, temperature, and glitch anomalies; trigger zeroization of sensitive keys upon tamper detection. |
Applications
| Secure Boot Server | Industrial Edge Gateway |
|---|---|
|
Use Scenario: Server motherboard performing measured boot with UEFI firmware integrity verification. IC Role / Device Role / Timing Role: Root-of-trust anchor storing PCR values, verifying boot components, and sealing encryption keys to platform state. Use Value: Prevents unauthorized firmware modification by cryptographically binding keys to verified boot measurements, meeting PCI-DSS and NIST SP 800-147B requirements. |
Use Scenario: Programmable logic controller (PLC) gateway aggregating sensor data in factory automation networks. IC Role / Device Role / Timing Role: Secure identity provider generating device attestation credentials and protecting TLS private keys for OPC UA communication. Use Value: Enables zero-touch onboarding into cloud platforms (e.g., Azure IoT Hub) using ECDAA-based anonymous attestation while maintaining -40°C to 105°C operational reliability. |
| Medical Imaging Workstation | Automotive Infotainment Head Unit |
|
Use Scenario: DICOM-compliant MRI workstation requiring HIPAA-compliant audit logging and encrypted patient data storage. IC Role / Device Role / Timing Role: Cryptographic service engine signing audit logs, encrypting DICOM headers, and managing AES keys for media encryption. Use Value: Meets FDA cybersecurity guidance (FDA Cybersecurity Guidance for Medical Devices) through FIPS 140-2 Level 2 certified key protection and tamper-evident logging. |
Use Scenario: In-vehicle infotainment system supporting over-the-air (OTA) software updates and secure vehicle-to-cloud telemetry. IC Role / Device Role / Timing Role: Trust anchor validating OTA update signatures, securing CAN FD message authentication keys, and enabling secure boot chain for Android Automotive OS. Use Value: Supports ISO/SAE 21434 compliance by providing hardware-rooted secure boot, rollback protection, and runtime integrity monitoring within ASIL-B functional safety context. |
Equivalent & Alternatives
The following parts are listed as comparable options for similar TPM 2.0 security applications.
| Alternative Part | Technical Difference | Application Difference | Selection Advice |
|---|---|---|---|
| Infineon SLB9670 | Uses ARM Cortex-M0+ core; supports I²C and LPC interfaces in addition to SPI; lacks built-in ECDAA support. | Preferred in legacy PC platforms with LPC bus; less suitable for space-constrained embedded designs requiring only SPI. | Select when LPC compatibility or multi-interface flexibility outweighs need for ECDAA and extended temperature range. |
| Nuvoton NPCT750 | Based on ARM Cortex-M4F; offers higher clock speed but no FIPS 140-2 Level 2 certification; operates only up to 85°C. | Better suited for cost-sensitive consumer electronics where CC EAL4+ and extended temp are not required. | Choose for non-regulated applications needing lower BOM cost and higher computational throughput, accepting reduced security assurance. |
Compared with SLB9670 and NPCT750, ST33HTPH2X32AHD4 uniquely delivers FIPS 140-2 Level 2 + CC EAL4+ + SP800-193 in a single SPI-only VFQFPN32 package with −40°C to 105°C operation-making it optimal for industrial, medical, and automotive edge devices requiring highest-tier, field-proven trust anchors.
Availability
ST33HTPH2X32AHD4 is available at Aetrix Electronics and suitable for secure boot servers, industrial edge gateways, medical imaging workstations, and automotive infotainment head units requiring stable component supply across long product lifecycles.
Supply support for ST33HTPH2X32AHD4 includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.
Manufacturer
STMicroelectronics is a global semiconductor leader headquartered in Geneva, Switzerland, designing and manufacturing microcontrollers, analog ICs, MEMS, and secure elements for industrial, automotive, and consumer markets.
The STSAFE-TPM product line delivers standardized, certified TPM 2.0 solutions targeting embedded, PC, mobile, and computing applications requiring hardware-rooted trust, with emphasis on Common Criteria and FIPS compliance for regulated sectors.
FAQ
What certifications does ST33HTPH2X32AHD4 hold?
ST33HTPH2X32AHD4 holds FIPS 140-2 Level 2 (physical security level 3), Common Criteria EAL4+ per TPM 2.0 Protection Profile (AVA_VAN.5), and SP800-193 compliance for firmware protection, detection, and recovery. It is also TCG-certified and compliant with Microsoft Windows 10, Linux drivers, and Intel vPro technology.
How does the fault-tolerant firmware loader operate?
The fault-tolerant firmware loader uses atomic update blocks and redundant metadata storage to ensure TPM remains fully functional even if power loss or reset occurs mid-update. Upon restart, it automatically validates firmware integrity and rolls back to last known-good image without host intervention or external tools.
Can ST33HTPH2X32AHD4 operate at both 1.8 V and 3.3 V simultaneously?
No. VPS accepts either 1.8 V or 3.3 V-not both. Voltage selection determines operational temperature range: 1.8 V enables −25°C to +85°C commercial operation; 3.3 V enables −40°C to +105°C extended operation. Mixed-voltage operation is not supported and may damage the device.
What cryptographic algorithms are accelerated in hardware?
All core cryptographic operations-including RSA-2048 key generation/signature, ECC NIST P-256/P-384 key exchange and signing, SHA-256/384/3 hashing, AES-128/192/256 encryption, and HMAC-are executed in dedicated hardware accelerators. The RNG combines hardware TRNG and DRBG engines, eliminating software-only bottlenecks.
ST33HTPH2X32AHD4 Specifications
- Product attributes
- Attribute value
- Manufacturer:
- STMicroelectronics
- Series:
- ST33
- Package/Case:
- 32-VFQFN Exposed Pad
- Packaging:
- Tape & Reel (TR)
- Product Status:
- Active
- Programmable:
- Not Verified
- Applications:
- Trusted Platform Module (TPM)
- Core Processor:
- ARM® SecurCore® SC300
- Program Memory Type:
- FLASH
- Controller Series:
- ST33H
- RAM Size:
- -
- Interface:
- SPI
- Number of I/O:
- 2
- Voltage - Supply:
- 1.8V, 3.3V
- Operating Temperature:
- -40°C ~ 105°C (TA)
- Grade:
- -
- Qualification:
- -
- Mounting Type:
- Surface Mount
- Supplier Device Package:
- 32-VFQFPN (5x5)
ST33HTPH2X32AHD4 FAQ
1.How can I place an order for ST33HTPH2X32AHD4 through Aetrix?
Please submit a Request for Quotation (RFQ) for ST33HTPH2X32AHD4 on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.
2.Are the price and stock information for ST33HTPH2X32AHD4 reliable?
The price and inventory of ST33HTPH2X32AHD4 are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for ST33HTPH2X32AHD4 is usually 5 days.
3.What payment methods are accepted for ST33HTPH2X32AHD4?
We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for ST33HTPH2X32AHD4 transactions.
Note: Certain payment methods may incur a processing fee.
4.How is shipping managed for ST33HTPH2X32AHD4?
ST33HTPH2X32AHD4 orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.
Once your ST33HTPH2X32AHD4 order is processed, you will receive an email with the shipment details and tracking number.
Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.
5.How can I obtain technical support or documentation for ST33HTPH2X32AHD4?
For technical support, including ST33HTPH2X32AHD4 datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your ST33HTPH2X32AHD4 requirements.
6.How does Aetrix verify that ST33HTPH2X32AHD4 is sourced from the original manufacturer or authorized distributors?
All ST33HTPH2X32AHD4 products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that ST33HTPH2X32AHD4 meets industry standards.
7.What is the process for return or replacement of ST33HTPH2X32AHD4?
All ST33HTPH2X32AHD4 units undergo pre-shipment inspection (PSI). If there is an issue with ST33HTPH2X32AHD4, returns or replacements are accepted under the following conditions:
1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.
2.The issue is reported within 90 days of delivery.
3.The ST33HTPH2X32AHD4 part is unused and in its original packaging.
Return procedure for ST33HTPH2X32AHD4:
1.Submit a request within 90 days.
2.Obtain a Return Material Authorization (RMA) from Aetrix.
ST33HTPH2X32AHD4 Tags

-
CYPD3175-24LQXQ
Infineon Technologies

-
SLB9672VU20FW1523XTMA1
Infineon Technologies

-
SLB9670VQ20FW785XTMA1
Infineon Technologies

-
SLB9672XU20FW1523XTMA1
Infineon Technologies

-
SLB9673XU20FW2613XTMA1
Infineon Technologies

-
CYPD3125-40LQXIT
Infineon Technologies

-
AT97SC3204-U2A1A-20
Microchip Technology

-
AT97SC3204-U2A1A-10
Microchip Technology

-
SLM9670AQ20FW1311XTMA1
Infineon Technologies

-
SLB9672XU20FW1613XTMA1
Infineon Technologies

-
SLB9672AU20FW1613XTMA1
Infineon Technologies

-
SLB9673AU20FW2613XTMA1
Infineon Technologies
Tech Hub
A practical engineering guide to 3.3V and 5V logic compatibility, input thresholds, resistor dividers, translator ICs, MOSFET level shifting, I2C pull-ups, timing limits and power-sequencing risks.
The 74HC595 uses push-pull logic outputs, while the TPIC6B595 uses 50 V open-drain DMOS sinks for higher-power loads. This guide compares timing, current limits, 3.3 V interfacing, load wiring, thermal…
The 74HC595 converts serial data into eight stable parallel outputs. This guide covers pin functions, shift and storage timing, OE and MR behavior, drive-current limits, cascading, voltage compatibilit…
A technical comparison of level-sensitive latches and edge-triggered flip-flops, covering timing windows, setup and hold limits, master–slave operation, time borrowing, race-through, HDL inference and…
A D latch stores one bit while Enable controls when data can pass. This reference covers gate-level operation, truth tables, transparency, setup and hold timing, LE versus OE, common ICs and practical …
An SR latch stores one bit through cross-coupled feedback. This engineering reference covers NOR and NAND implementations, truth tables, forbidden-state recovery, gated operation, switch debouncing, fa…
Latch circuits retain one bit through feedback. This technical reference covers SR and D latches, truth tables, transparency, timing limits, latch-versus-flip-flop behavior, applications and common log…
An engineering guide to LED driver operation, constant-current and constant-voltage outputs, linear and switching topologies, dimming, IC selection, calculations, replacement compatibility, and fault c…
Operational amplifier guide covering op amp basics, feedback, ideal vs real op amps, common configurations, buffer circuits, offset, bias current, gain-bandwidth, slew rate, rail-to-rail limits and sel…
Jumper cables guide covering safe connection order, red and black clamp placement, final ground connection, cable gauge, length, clamp quality, copper vs CCA cables, jump starter comparison and battery…

