Send an Inquiry

To receive a quote for your project, please fill in the following information, and we’ll get back to you promptly.

Name*
Company*
Email Address*
Phone/WhatsApp
Part Number*
Quantity*
Message
Submit Inventory List

Please fill in the following information, and we’ll get back to you promptly.

Name*
Company*
Email Address*
Phone/WhatsApp
Upload My List
Message

STMicroelectronics ST33KTPM2X32DKG9

Part No.:
ST33KTPM2X32DKG9
Manufacturer:
STMicroelectronics
Category:
Application Specific Microcontrollers
Package:
32-UFQFN Exposed Pad
Datasheet:
AetrixST33KTPM2X32DKG9.pdf
Description:
TPM 2.0 DEVICE FOR CONSUMER
Quantity:
Payment:
Payment
Shipping:
Shipping

Inventory:2,660

Please send an inquiry. Send us your inquiry, and we will respond immediately.

Part Number
Quantity*
Price
Name*
Company
Email*
Comments

Product details

Overview

ST33KTPM2X32DKG9 from STMicroelectronics is a certified Trusted Platform Module (TPM) 2.0 security IC compliant with TCG Library 2.0 rev 1.59 errata 1.5 and PC Client PTP v1.06, featuring flash-based firmware, dual SPI/I²C interfaces (up to 66 MHz / 1 Mb/s), −40 °C to 105 °C operation, and FIPS 140-3 Level 3 physical security. It serves as a hardware root of trust in PC, server, and industrial edge platforms for secure boot, key attestation, and platform integrity verification.

For engineers reviewing the ST33KTPM2X32DKG9 datasheet, ST33KTPM2X32DKG9 pinout, ST33KTPM2X32DKG9 application, or ST33KTPM2X32DKG9 equivalent, this page delivers verified interface configurations, certified cryptographic capabilities (RSA up to 4096-bit, ECC NIST P-521, SHA-3, AES-256, SP800-90B TRNG), fault-tolerant firmware update with LMS PQC signature, and EAL4+ Common Criteria certification details - all essential for secure system integration and compliance validation.

Technical Context

The ST33KTPM2X32DKG9 implements a hardened ARM SecurCore SC300 CPU with active shield, environmental monitoring, and countermeasures against fault injection and side-channel attacks. Its firmware version 0x00.09.01.01 (9.257) supports configurable background RSA key generation, SHA-512, hibernate state, and PQC-secured updates using LMS (SP800-208) alongside ECC NIST P-384.

It integrates NIST SP800-90A/B-compliant DRBG and TRNG, AIS20/AIS31-certified entropy sources, and cryptographic accelerators for RSA, ECC, AES, HMAC, and SHA-1/2/3. The device ships with four pre-provisioned endorsement keys (RSA2048/3072, ECC P-256/P-384) and three factory-loaded 2048-bit RSA key pairs to accelerate provisioning.

Key Specifications

ParameterValue and Actual Design Meaning
Firmware Version0x00.09.01.01 (9.257); enables SHA-512, hibernate state, and PQC firmware upgrade with LMS + ECC P-384
Interface SpeedSPI up to 66 MHz; I²C up to 1 Mb/s - ensures low-latency command/response in high-throughput TPM applications
Operating Temp−40 °C to 105 °C - supports deployment in automotive under-hood, industrial control, and server chassis environments
Cryptographic SupportRSA 1024–4096, ECC NIST P-256/384/521, AES-128/192/256, SHA-1/2/3, HMAC, ECDSA/ECSchnorr/ECDAA
Security CertificationsFIPS 140-3 Level 3 (physical security), Common Criteria EAL4+ (augmented AVA_VAN.5), TCG certified
Power Supply1.8 V or 3.3 V single rail - simplifies power design with no auxiliary voltage rails required
ESD Protection4 kV HBM - meets robustness requirements for motherboard-level integration without external protection

Pinout & Package

UFQFPN32 package: 5 × 5 × 0.55 mm, 32-pin ultra-thin fine-pitch quad flat no-lead with exposed thermal pad (pin 33, unconnected to die but recommended soldered to PCB ground).

Pin/TerminalCircuit RoleDesign Meaning
VPS (Pins 1, 23)Power supply inputAccepts 1.8 V or 3.3 V DC; requires 100 nF + 1 µF local decoupling per ST recommendation
GND (Pins 2, 16)Ground referenceMust connect to main motherboard ground; central exposed pad also tied to GND for thermal and EMI performance
RST (Pin 20)Active-low resetRe-initializes TPM state; requires external pull-up if not actively driven by host
SPI_MISO/MOSI/CLK/CS (Pins 24, 22, 21, 25)SPI interface signalsFull-duplex SPI slave interface; CS requires optional 56 pF capacitor for clean edge timing at high speeds
I2C_SDA/SCL (Pins 29, 30)I²C bidirectional data/clockOpen-drain I²C interface; requires external 1 kΩ pull-ups; GPI_I2C_Select (Pin 6) must be pulled down to enable I²C mode
PIRQ (Pin 19)Interrupt request outputActive-low open-drain interrupt; mandatory 10 kΩ pull-up to reduce standby power consumption
GPIO_PP (Pin 7)Physical presence inputActive-high signal indicating user-initiated secure operations; internal weak pull-down

Key Features

FeatureDesign Value
Fault-tolerant firmware loaderGuarantees TPM remains operational during interrupted firmware updates via automatic dual-image recovery
PQC-secured firmware updateLMS (SP800-208) signature required alongside ECC P-384 - provides post-quantum resilience for future-proof firmware integrity
Pre-provisioned endorsement keysFour factory-loaded EKs (RSA2048, RSA3072, ECC P-256, ECC P-384) with certificates - eliminates on-site EK generation delay
Configurable background key generationEnables RSA 4096 key pair creation without blocking host commands - improves responsiveness in multi-tenant systems
SP800-193 complianceHardware-enforced protection, detection, and recovery against firmware corruption - satisfies UEFI Secure Boot and platform attestation requirements

Applications

Server Platform IntegrityIndustrial Edge Device Authentication

Use Scenario: Verifying firmware and bootloader integrity during cold boot and runtime attestation in rack-mounted servers.

IC Role / Device Role / Timing Role: Hardware root of trust executing TPM 2.0 commands (TPM2_Startup, TPM2_PCR_Read, TPM2_Quote) to bind measurements to cryptographic keys.

Use Value: Prevents unauthorized firmware modification and enables remote attestation to cloud management platforms using certified EKs and PCR values.

Use Scenario: Securing over-the-air (OTA) firmware updates and device identity provisioning in programmable logic controllers (PLCs) operating at 105 °C ambient.

IC Role / Device Role / Timing Role: TPM 2.0 cryptographic accelerator performing ECDSA signature verification and AES-256 decryption of signed firmware images.

Use Value: Ensures only authenticated, unaltered firmware executes - critical for functional safety compliance (IEC 62443) in harsh industrial environments.

PC Client Secure BootEmbedded Linux Trusted Execution

Use Scenario: Enforcing Windows 10/11 BitLocker encryption key sealing and measured boot chain validation on desktop motherboards.

IC Role / Device Role / Timing Role: TPM 2.0 co-processor interfacing via SPI at 66 MHz to respond to UEFI firmware calls within strict boot-time latency budgets.

Use Value: Enables hardware-backed disk encryption and prevents bootkit persistence - required for Microsoft Modern Standby and OEM certification.

Use Scenario: Providing trusted key storage and attestation services for confidential computing workloads running in Linux containers on edge gateways.

IC Role / Device Role / Timing Role: Isolated security enclave managing sealed storage, remote attestation (TPM2_ActivateCredential), and protected key derivation (TPM2_HMAC).

Use Value: Allows service providers to verify runtime integrity before releasing sensitive keys - foundational for zero-trust architecture in distributed IoT deployments.

Equivalent & Alternatives

The following parts are listed as comparable options for similar TPM 2.0 security module applications.

Alternative PartTechnical DifferenceApplication DifferenceSelection Advice
Infineon SLB9670Supports SPI only (no I²C); firmware version 7.85; lacks PQC firmware update (LMS) and SHA-512 supportTargeted at legacy PC platforms requiring TCG PTP v1.03 compliance; no extended temperature ratingSelect when SPI-only interface suffices and PQC readiness is not required; verify compatibility with existing BIOS/UEFI stack.
NXP ATTPM20Based on ARM Cortex-M33; supports I²C only; includes additional tamper-detection pins; certified to FIPS 140-3 Level 2 (not Level 3)Optimized for automotive infotainment with AEC-Q100 Grade 2 qualification; no 105 °C extended temp supportChoose for automotive-grade designs needing tamper-evident packaging and AEC-Q100 compliance - not suitable for server or industrial thermal profiles.

Compared with SLB9670 and ATTPM20, the ST33KTPM2X32DKG9 uniquely combines dual SPI/I²C flexibility, FIPS 140-3 Level 3 physical security, −40 °C to 105 °C operation, and LMS-based PQC firmware updates - making it the only option qualified for next-generation server, industrial edge, and high-assurance PC platforms requiring quantum-resilient trust anchors.

Availability

ST33KTPM2X32DKG9 is available at Aetrix Electronics and suitable for server platform integrity, industrial edge device authentication, and PC client secure boot requiring stable component supply, long-term lifecycle assurance, and certified cryptographic functionality.

Supply support for ST33KTPM2X32DKG9 includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.

Manufacturer

STMicroelectronics is a global semiconductor leader headquartered in Geneva, Switzerland, designing and manufacturing microcontrollers, analog ICs, MEMS, and secure elements for industrial, automotive, and computing markets.

The STSAFE-TPM product line delivers standardized, certified Trusted Platform Modules targeting Common Criteria EAL4+, FIPS 140-3 Level 3, and TCG compliance - engineered specifically for hardware-rooted trust in PCs, servers, industrial controllers, and edge AI devices.

FAQ

What firmware version is shipped on ST33KTPM2X32DKG9?

This part ships with factory firmware version 0x00.09.01.01 (9.257), which supports SHA-512, hibernate power state, configurable background RSA key generation (including RSA 4096), and PQC firmware updates requiring both LMS (SP800-208) and ECC NIST P-384 signatures. It does not include the SHA-512 or PQC enhancements introduced in later firmware 9.512.

Does ST33KTPM2X32DKG9 support both SPI and I²C simultaneously?

No - the interface is selected at boot time via the GPI_I2C_Select pin (Pin 6). Pulling it low activates I²C mode; leaving it unconnected (default internal weak pull-up) selects SPI mode. Both protocols are supported on the same silicon, but only one can operate at a time, as confirmed in the DB5174 data brief Section 3.

What certifications apply specifically to ST33KTPM2X32DKG9 with firmware 9.257?

This variant is certified to Common Criteria EAL4+ (TPM 2.0 PP augmented with AVA_VAN.5), TCG TPM 2.0 certification, and Microsoft Windows 10/11 and Linux driver compliance. While FIPS 140-3 Level 3 certification applies to the ST33KTPM2X family, ST confirms that firmware 9.257 is included in the validated configuration for that certification per official ST documentation.

How is the exposed thermal pad (Pin 33) handled in the UFQFPN32 package?

Pin 33 is an unconnected exposed pad on the underside of the UFQFPN32 package. Though not electrically connected to the die, ST recommends soldering it to PCB ground to improve thermal dissipation (θJB = 20 °C/W) and reduce EMI. Mechanical data in DB5174 Section 5.1 confirms it has no electrical function but contributes to thermal performance when grounded.

ST33KTPM2X32DKG9 Specifications

Product attributes
Attribute value
Manufacturer:
STMicroelectronics
Series:
-
Package/Case:
32-UFQFN Exposed Pad
Packaging:
Tape & Reel (TR)
Product Status:
Active
Programmable:
-
Applications:
Trusted Platform Module (TPM)
Core Processor:
ARM® SecurCore® SC300
Program Memory Type:
-
Controller Series:
ST33K
RAM Size:
-
Interface:
I2C, SPI
Number of I/O:
7
Voltage - Supply:
1.8V, 3.3V
Operating Temperature:
-40°C ~ 105°C (TA)
Grade:
-
Qualification:
-
Mounting Type:
Surface Mount
Supplier Device Package:
32-UFQFPN (5x5)

ST33KTPM2X32DKG9 FAQ

1.How can I place an order for ST33KTPM2X32DKG9 through Aetrix?

Please submit a Request for Quotation (RFQ) for ST33KTPM2X32DKG9 on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.

2.Are the price and stock information for ST33KTPM2X32DKG9 reliable?

The price and inventory of ST33KTPM2X32DKG9 are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for ST33KTPM2X32DKG9 is usually 5 days.

3.What payment methods are accepted for ST33KTPM2X32DKG9?

We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for ST33KTPM2X32DKG9 transactions.

Note: Certain payment methods may incur a processing fee.

4.How is shipping managed for ST33KTPM2X32DKG9?

ST33KTPM2X32DKG9 orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.

Once your ST33KTPM2X32DKG9 order is processed, you will receive an email with the shipment details and tracking number.

Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.

5.How can I obtain technical support or documentation for ST33KTPM2X32DKG9?

For technical support, including ST33KTPM2X32DKG9 datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your ST33KTPM2X32DKG9 requirements.

6.How does Aetrix verify that ST33KTPM2X32DKG9 is sourced from the original manufacturer or authorized distributors?

All ST33KTPM2X32DKG9 products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that ST33KTPM2X32DKG9 meets industry standards.

7.What is the process for return or replacement of ST33KTPM2X32DKG9?

All ST33KTPM2X32DKG9 units undergo pre-shipment inspection (PSI). If there is an issue with ST33KTPM2X32DKG9, returns or replacements are accepted under the following conditions:

1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.

2.The issue is reported within 90 days of delivery.

3.The ST33KTPM2X32DKG9 part is unused and in its original packaging.

Return procedure for ST33KTPM2X32DKG9:

1.Submit a request within 90 days.

2.Obtain a Return Material Authorization (RMA) from Aetrix.

ST33KTPM2X32DKG9 Tags

  • ST33KTPM2X32DKG9
  • ST33KTPM2X32DKG9 PDF
  • ST33KTPM2X32DKG9 Datasheet
  • ST33KTPM2X32DKG9 Specifications
  • ST33KTPM2X32DKG9 Images
  • STMicroelectronics
  • STMicroelectronics ST33KTPM2X32DKG9
  • Buy ST33KTPM2X32DKG9
  • ST33KTPM2X32DKG9 Price
  • ST33KTPM2X32DKG9 Distributor
  • ST33KTPM2X32DKG9 Supplier
  • ST33KTPM2X32DKG9 Wholesale
Related Products
CYPD3175-24LQXQ
CYPD3175-24LQXQ

Infineon Technologies

SLB9672VU20FW1523XTMA1
SLB9672VU20FW1523XTMA1

Infineon Technologies

SLB9670VQ20FW785XTMA1
SLB9670VQ20FW785XTMA1

Infineon Technologies

SLB9672XU20FW1523XTMA1
SLB9672XU20FW1523XTMA1

Infineon Technologies

SLB9673XU20FW2613XTMA1
SLB9673XU20FW2613XTMA1

Infineon Technologies

CYPD3125-40LQXIT
CYPD3125-40LQXIT

Infineon Technologies

AT97SC3204-U2A1A-20
AT97SC3204-U2A1A-20

Microchip Technology

AT97SC3204-U2A1A-10
AT97SC3204-U2A1A-10

Microchip Technology

SLM9670AQ20FW1311XTMA1
SLM9670AQ20FW1311XTMA1

Infineon Technologies

SLB9672XU20FW1613XTMA1
SLB9672XU20FW1613XTMA1

Infineon Technologies

SLB9672AU20FW1613XTMA1
SLB9672AU20FW1613XTMA1

Infineon Technologies

SLB9673AU20FW2613XTMA1
SLB9673AU20FW2613XTMA1

Infineon Technologies

Tech Hub

Search

Search

PRODUCT

PRODUCT

PHONE

PHONE

USER

USER