SE051 - EdgeLock IoT Secure Element, CC EAL6+ | NXP
MPN: SE051 β Active| Qty | Unit Price | Extended |
|---|---|---|
| 1 | $2.85 | $2.85 |
| 10 | $2.56 | $25.60 |
| 100 | $2.2 | $220.00 |
| 500 | $1.92 | $960.00 |
| 1,000 | $1.68 | $1,680.00 |
SE051 Overview
A secure element is a dedicated, tamper-resistant hardware IC that provides a root of trust at the chip level. Within the system hierarchy, it sits below the host microcontroller in the security architecture (secure element -> hardware root of trust -> edge-to-cloud security platform) and offloads all cryptographic key storage and operations from the general-purpose MCU, so keys never exist in MCU memory where they could be exposed by software attacks.
Key features include turnkey Plug & Trust design-in with a complete support package (middleware, development kits, reference designs), applet updatability in the field via SEMS Lite, and support for developer-created custom applets. The SE051 extends the widely adopted EdgeLock SE050 family, inheriting its proven Common Criteria EAL 6+ certification up to the OS level with AVA_VAN.5 vulnerability assessment.
Technically, the SE051 runs a Java Card operating system and ships with a pre-installed applet optimized for IoT security use cases such as secure key storage, mutual authentication, and secure provisioning. Communication with the host processor is performed over a single-wire or I2C interface, following the same integration model as SE050, so existing SE050 host firmware and the Plug & Trust Nano middleware package can be reused directly.
Typical applications include IoT device identity and cloud onboarding, secure firmware updates, peripheral node authentication in industrial networks, and smart-meter or payment-adjacent designs requiring certified hardware security.
When designing the SE051 into a PCB, note that it is pin-to-pin and package compatible with EdgeLock SE050A/B/C/F variants (per NXP application note AN13014), enabling a single footprint to support SE050, SE050E, or SE051 depending on the required security feature set.
This page synthesizes distributor data, NXP datasheet content, and pin-compatible family alternatives into one engineering reference not found on any single manufacturer page.
Drop-in alternatives for SE051 β same package, pin-to-pin compatible. Different-package parts requiring PCB rework are excluded.
Quick Comparison Tool β Select alternative parts for side-by-side comparison:
SE050C2HQ2/Z01CDZ
β Drop-Inπ Reference alternative (not in catalog)
SE050E
β Drop-Inπ Reference alternative (not in catalog)
SE051A2HQ1/Z01XEZ
β Drop-Inπ Reference alternative (not in catalog)
SE051C2HQ1/Z01XDZ
β Drop-Inπ Reference alternative (not in catalog)
SE051W
β Drop-Inπ Reference alternative (not in catalog)
SE051 Specifications
| Product Type | Plug & Trust IoT Secure Element |
| Product Family | EdgeLock SE05x (SE050 extension) |
| Operating System | Java Card OS with updatable applet pre-installed |
| Security Certification | Common Criteria EAL 6+ (AVA_VAN.5) up to OS level |
| Applet Updatability | Yes, via SEMS Lite; custom applets supported |
| Package | 20-HX2QFN (SOT1969-1), 3x3 mm |
| Pin Count | 20 |
| Host Interface | Single-wire / I2C |
| Pin Compatibility | Pin-to-pin and package compatible with EdgeLock SE050A/B/C/F and SE050E |
| Middleware | Plug & Trust middleware / Nano package for host applications |
| Role | Hardware root of trust, edge-to-cloud security |
| Mounting Type | Surface Mount |
| Crypto Interfaces | Secure key storage, mutual authentication, secure provisioning |
SE051 20-hx2qfn (sot1969-1), 3x3 mm Pin Configuration Guide
Pin configuration for SE051 (20-hx2qfn (sot1969-1), 3x3 mm package). Pin numbering, functions, and connection diagrams are defined in the manufacturer datasheet. Refer to it for the exact footprint and soldering guidelines.
No detailed pinout data available for SE051.
Refer to the datasheet for full pin configuration.
Typical Applications
SE051 is suitable for 6 applications: IoT Device Identity and Cloud Onboarding, Secure Firmware Update Signing, Industrial Peripheral Node Authentication, Smart Metering and Utility Edge Devices, Ultra-Wideband (UWB) System Security, Prototype and Evaluation with Plug&Trust Click.
IoT Device Identity and Cloud Onboarding
The SE051 fits IoT device identity applications because its pre-installed, updatable applet and CC EAL 6+ (AVA_VAN.5) hardware root of trust let each device carry a unique, injection-protected identity from the factory to the cloud. Device keys are generated and stored inside the secure element, so private material never appears on the host MCU bus or in MCU memory. In use, the host processor connects over single-wire or I2C and issues Plug & Trust APDUs through the NXP middleware to sign cloud attestation challenges. The quantified benefit is design speed: Plug & Trust middleware, Nano package, and development kits reduce provisioning software effort from months to weeks, while SEMS Lite keeps the identity applet updatable over the product lifetime.
Recommended
Secure Firmware Update Signing
For secure over-the-air firmware updates, the SE051 fits because it can hold the verification root key in CC EAL 6+ certified hardware and perform signature verification support in the element rather than trusting host code. The host MCU forwards the update manifest hash to the SE051 over I2C or single-wire, and the secure element performs the cryptographic operation internally, resisting glitching and key-extraction attacks that compromise software-only verification. Because the SE051 is pin-compatible with SE050 variants per AN13014, a bootloader designed around the SE050 footprint upgrades to updatable trust anchors via SEMS Lite without a PCB respin, protecting the investment as signing algorithms or certificate chains evolve across the deployed fleet.
Recommended
Industrial Peripheral Node Authentication
Industrial networks benefit from authenticating sensors, actuators, and field modules before granting bus access, and the SE051 fits this role because its single-wire interface needs only one MCU GPIO plus ground, keeping per-node cost and board area minimal in the 3x3 mm HX2QFN20 package. Each peripheral board carries its own SE051 holding a unique certificate pair; the controller challenges the node at power-up through the Plug & Trust middleware, and cloned or counterfeit boards fail attestation. The Java Card OS with updatable applet lets operators rotate credentials in the field using SEMS Lite without recalling hardware, a measurable maintenance advantage over fixed-key authentication ICs in long-lifecycle factory deployments.
Recommended
Smart Metering and Utility Edge Devices
Smart meters demand certified, tamper-resistant storage of billing and cryptographic keys, and the SE051 fits because CC EAL 6+ (AVA_VAN.5) certification up to the OS level satisfies the security audits typical of utility deployments. Its single-wire host interface minimizes isolation-boundary complexity, while the 20-pin 3x3 mm SOT1969-1 package occupies little PCB area on space-constrained meter mainboards. In operation, metering secrets and load-profile signing keys live exclusively inside the element; the metering SoC issues commands via the Plug & Trust middleware. Because the SE051 supports custom Java Card applets and field updates via SEMS Lite, utilities can add regional encryption schemes or re-key the fleet during a 15-plus-year service life without hardware change.
Recommended
Ultra-Wideband (UWB) System Security
NXP pairs the SE051W secure element variant with the SR150 UWB chipset in UWB designs such as the Foxhound evaluation board, because UWB ranging and access-control systems (digital car keys, asset tracking) must authenticate before accepting range data. The SE051W stores the UWB session keys and device identity in EAL 6+ certified hardware, preventing cloning of UWB tags, while sharing the same SOT1969-1 HX2QFN20 footprint as the rest of the SE05x family per AN13014. Designers integrating the Murata Type 2BP module or an SR150-based radio can drop the SE051W onto the same footprint reserved for any SE050/SE051, so one carrier PCB supports secure ranging, plain ranging, or non-UWB identity products with component swaps only.
Recommended
Prototype and Evaluation with Plug&Trust Click
For evaluation, the SE051 fits rapid prototyping through the MIKROE-5392 SE051 Plug&Trust Click board, which places an SE051C2 on a mikroBUS form factor so any MCU with an SPI/I2C-capable mikroBUS socket can exercise the device in minutes. This shortens the path from concept to production: the same APDU commands and Plug & Trust Nano middleware used against the Click board run unchanged against the production SOT1969-1 part, because the Click uses the identical 20-pin HX2QFN device. Teams can validate provisioning flows, key injection, and SEMS Lite update procedures on the evaluation board before committing to PCB layout, and the Click board doubles as a reference schematic for the host-interface wiring and decoupling.
Recommended
Recommended Products Summary
Engineering reference data for SE051 β comparison, design guidance, and compliance information.
Selection Guide
Comparison with Alternatives
| Parameter | This Product | SE050C2HQ2/Z01CDZ | SE050E | SE051A2HQ1/Z01XEZ | SE051C2HQ1/Z01XDZ | SE051W |
|---|---|---|---|---|---|---|
| Package | 20-HX2QFN (SOT1969-1), 3x3 mm | 20-HX2QFN (SOT1969-1) - same | 20-HX2QFN (SOT1969-1) - same | 20-HX2QFN (SOT1969-1) - same | 20-HX2QFN (SOT1969-1) - same | 20-HX2QFN (SOT1969-1) - same |
| Brand | NXP Semiconductors | NXP Semiconductors | NXP Semiconductors | NXP Semiconductors | NXP Semiconductors | NXP Semiconductors |
| Security Certification | CC EAL 6+ (AVA_VAN.5) to OS level | CC EAL 6+ (AVA_VAN.5) | CC EAL 6+ (AVA_VAN.5) | CC EAL 6+ (AVA_VAN.5) | CC EAL 6+ (AVA_VAN.5) | CC EAL 6+ (AVA_VAN.5) |
| Applet Updatability | Yes - SEMS Lite + custom applets | No - fixed applet set | No - fixed enhanced applet | Yes - SEMS Lite | Yes - SEMS Lite | Yes - SEMS Lite (UWB-focused) |
| Operating System | Java Card OS with updatable applet | NXP SE050 OS (fixed applet) | NXP SE050E OS (fixed applet) | Java Card OS | Java Card OS | Java Card OS |
| Custom Applet Support | Yes | No | No | Yes | Yes | Yes |
| Pin Compatibility with SE050 | Yes (per AN13014) | Native SE050 | Yes (per AN13014) | Yes | Yes | Yes |
| Target Use Case | General IoT security, updatable identity | General IoT security (fixed) | Enhanced SE050 IoT security | General IoT security (A2 applet) | General IoT security (C2 applet) | UWB system security (SR150 pairing) |
Key Differentiators
- Field-updatable applet via SEMS Lite (vs SE050C2HQ2/Z01CDZ)
- Java Card OS flexibility (vs SE050E)
- Turnkey Plug & Trust onboarding (vs SE051A2HQ1/Z01XEZ)
- General IoT applet focus (vs SE051W)
Design Notes
Design the PCB footprint as the SOT1969-1 HX2QFN20 3x3 mm land pattern and reserve the SE050 pinout; per NXP application note AN13014, SE051, SE050E, and SE050A/B/C/F are pin-to-pin and package compatible, so a single footprint lets you qualify cost-optimized SE050 variants and the updatable SE051 on the same board. Place the 3x3 QFN with short traces to the host; the single-wire interface is sensitive to bus capacitance, so keep the SCL/SDA or S1 wire under a few centimeters where possible.
Supply the SE051 from a clean, always-on rail so keys and the updatable applet survive main-power cycles. Decouple VDD with a 100 nF ceramic capacitor placed within 2 mm of the package per standard QFN practice, and verify the supply sequencing requirements in the SE051 datasheet before sharing a regulator with the host MCU. Exact voltage range and current figures should be taken from the NXP SE051 datasheet table (see [DATA_NEEDED] markers on this page) rather than from secondhand values.
Do not assume all SE051 order codes are identical: SE051A2, SE051C2, and SE051W differ in pre-installed applet configuration and target use case (SE051W is oriented to UWB designs with the SR150). Confirm the variant code (e.g., SE051C2HQ1/Z01XDZ stocked at DigiKey) matches your provisioning plan before layout sign-off. Also note that migration from SE050 requires checking the AN13014 integration guidance - hardware is compatible, but applet behavior and SEMS Lite update flows differ from fixed SE050 applets.
Compliance Information
Compliance status not stated in the provided web data; consult the NXP SE051 datasheet and product page for RoHS/REACH declarations.