TPM 2.0 security MCU adds certified hardware trust for connected devices

To maintain embedded security over long product lifecycles, the Infineon SLB9673 combines hardware-based identity protection, cryptographic key storage, measured boot, and PQC-protected firmware updates to ensure resilient IoT device security and CRA compliance.

The SLB9673 MCU is designed for practical Trusted Platform Module (TPM) integration into embedded and industrial systems without significantly increasing board space, interface complexity, or standby power, while adding a standardized trust anchor for secure connected products. The SLB9673 is optimized for Internet of Things (IoT) and Information and Communications Technology (ICT) applications by adhering to Trusted Computing Group (TCG) TPM 2.0 specifications. The MCU uses an I2C host interface, supports automatic low-power operation after command transactions, and is available in extended temperature variants up to 105°C.

Connected systems are protected against unauthorized firmware, software tampering, and rollbacks to untrusted states with secure device identity and measured boot. The SLB9673 TPM accomplishes this by combining provisioned endorsement keys (EKs), EK certificates, and platform configuration registers (PCRs). The EKs provide a cryptographically backed identity for the TPM, while PCRs store hash measurements of firmware, bootloader, and software components as the platform starts. These measurements can then be used for attestation, allowing a local or remote verifier to verify whether the device has booted into a known, trusted configuration. Long-term firmware maintenance is also supported by firmware protection from a post-quantum cryptography (PQC) update mechanism, helping connected products maintain a stronger security posture over extended deployment lifecycles. 

This hardware-level security extends to cryptographic functions that reduce the need for the main processor or application software to handle sensitive key material directly. The SLB9673 allows these keys to be generated, protected, and used locally within the TPM, with support for Rivest-Shamir-Adleman (RSA), elliptic curve cryptography (ECC), secure hash algorithm (SHA) hashing, advanced encryption standard (AES) and a standards-based random number generator (RNG), giving engineers a hardware-backed foundation for authentication, signing, integrity checking, encrypted data workflows and attestation.

Buy now Datasheet Samples