---
title: "Secure CAN FD MCUs — Hardware Security Reference Table"
canonical_url: https://can-security.net/resources/secure-can-mcus/
description: "A maintained reference of microcontroller families that pair a CAN FD interface with on-chip security: TRNG, secure key storage, and crypto accelerators."
last_updated: 2026-09-17
---
# Secure CAN FD Microcontrollers

Cryptographic protection of CAN traffic starts with the silicon. The controls cataloged on this site assume a device that can both speak CAN FD and hold a key where firmware cannot read it back. This page lists microcontroller families that meet both conditions, so a designer scoping a secured CAN node can see which parts carry the hardware to support it. A family appears only when it has at least one CAN FD interface and at least one hardware security feature.

## Microcontroller Families with CAN FD and Hardware Security

The table below is sorted by core architecture, weakest performance first, then by top clock speed within each architecture. Read it as an orientation aid, not a recommendation: it records what each family offers on paper, compiled from public product pages and datasheets. Once a part is in view, the [MCU Crypto Benchmarks](https://can-security.net/resources/crypto-benchmarks/) page measures what the cryptographic primitives actually cost in flash, stack, and time on parts like these.

*Microcontroller families combining at least one CAN FD interface with at least one hardware security feature, sorted by core architecture (weakest first) then top clock speed. Compiled from public datasheets; neutral orientation aid, not an endorsement. Last reviewed 30 September 2026.*

| Mfr | Family | Architecture | Max MHz | CAN FD | Security features |  |  |
| --- | --- | --- | --- | --- | --- | --- | --- |
| TRNG | Key store | Accelerators |  |  |  |  |  |
| Microchip | [PIC32CM JH01](https://www.microchip.com/en-us/products/microcontrollers/32-bit-mcus/pic32-sam/pic32cm-jh) | Cortex-M0+ | 48 | 2 | – | – | SHA-256 (ICM) |
| TI | [MSPM0 G3xxx](https://www.ti.com/product/MSPM0G3519) | Cortex-M0+ | 80 | 2 | ✓ | ✓ | AES-256 (GCM, CCM) |
| Microchip | [PIC32CM SG](https://www.microchip.com/en-us/products/microcontrollers/32-bit-mcus/pic32-sam/pic32cm-sg) | Cortex-M23 | 72 | 2 | ✓ | ✓ | AES, RSA, ECC, SHA-2 (HSM Lite) |
| Microchip | [dsPIC33C MPT](https://www.microchip.com/en-us/products/microcontrollers/dspic-dscs/dspic33c/secure-dscs) | dsPIC33 DSC (16-bit) | 100 | 2 | ✓ | ✓ | AES-128, RSA, ECC, SHA-256 |
| NXP | [MCX E24](https://www.nxp.com/products/MCX-E24) | Cortex-M4F | 112 | 3 | ✓ | ✓ | AES-128 (CSEc) |
| Microchip | [SAM E51/E54](https://www.microchip.com/en-us/solutions/technologies/motor-control-and-drive/motor-control-products/32-bit-microcontrollers-for-motor-control-applications/sam-d5x-and-e5x) | Cortex-M4F | 120 | 2 | ✓ | – | AES-256, RSA/ECC (PUKCC), SHA |
| Microchip | [PIC32CX SG](https://www.microchip.com/en-us/products/microcontrollers/32-bit-mcus/pic32-sam/pic32cx-sg) | Cortex-M4F | 120 | 2 | ✓ | ✓ | AES-256, RSA/ECC (PUKCC), SHA (HSM on SG60/SG61) |
| Infineon | [PSoC 6](https://www.infineon.com/products/microcontroller/32-bit-psoc-arm-cortex/psoc-6-m4-mcu) | Cortex-M4F | 150 | 1 | ✓ | ✓ | AES, 3DES, RSA, ECC, SHA |
| ST | [STM32G4](https://www.st.com/en/microcontrollers-microprocessors/stm32g4-series.html) | Cortex-M4 | 170 | 3 | ✓ | – | AES-256 (crypto line) |
| NXP | [LPC54S0xx](https://www.nxp.com/products/LPC540XX) | Cortex-M4F | 180 | 2 | ✓ | ✓ | AES-256, SHA-2 (PUF) |
| Nuvoton | [M460](https://www.nuvoton.com/products/microcontrollers/arm-cortex-m4-mcus/m467-ethernet-crypto-series/) | Cortex-M4F | 200 | 4 | ✓ | ✓ | AES-256, RSA, ECC, SHA-2, HMAC |
| Microchip | [dsPIC33AK MPS](https://www.microchip.com/en-us/products/microcontrollers/dspic-dscs/dspic33a) | dsPIC33A DSC (32-bit) | 200 | 2 | ✓ | ✓ | AES, RSA, ECC, SHA-2 |
| Renesas | [RX26T](https://www.renesas.com/en/products/rx26t) | RXv3 | 120 | 1 | ✓ | ✓ | AES-256, CMAC (TSIP-Lite) |
| Espressif | [ESP32-C5](https://www.espressif.com/en/products/socs/esp32-c5) | RISC-V (RV32) | 240 | 2 | ✓ | ✓ | AES, RSA, ECC, SHA-2, HMAC |
| Renesas | [RA4L1/RA4C1](https://www.renesas.com/en/products/ra4c1) | Cortex-M33 | 80 | 1 | ✓ | ✓ | AES, ECC, SHA (RSIP) |
| Renesas | [RA4E2/RA4T1](https://www.renesas.com/en/products/ra4e2) | Cortex-M33 | 100 | 1 | ✓ | – | – |
| ST | [STM32L5](https://www.st.com/en/microcontrollers-microprocessors/stm32l5-series.html) | Cortex-M33 | 110 | 1 | ✓ | ✓ | AES-256, RSA/ECC (PKA), SHA |
| Microchip | [PIC32CK SG](https://www.microchip.com/en-us/products/microcontrollers/32-bit-mcus/pic32-sam/pic32ck-sg-gc) | Cortex-M33 | 120 | 2 | ✓ | ✓ | AES, 3DES, ChaCha20, RSA, ECC, SHA-2/3 (HSM) |
| ST | [STM32C5](https://www.st.com/en/microcontrollers-microprocessors/stm32c5-series.html) | Cortex-M33 | 144 | 2 | ✓ | ✓ | AES, SAES, PKA (RSA/ECC), SHA |
| NXP | [LPC55Sxx](https://www.nxp.com/products/processors-and-microcontrollers/arm-microcontrollers/general-purpose-mcus/lpc5500-arm-cortex-m33:LPC5500_SERIES) | Cortex-M33 | 150 | 1 | ✓ | ✓ | AES, RSA, ECC (CASPER), SHA |
| NXP | [MCX Nxx](https://www.nxp.com/products/MCX-N94-N54-N53-N52-N24) | Cortex-M33 (dual) | 150 | 2 | ✓ | ✓ | AES-256, ECC, SHA-2 (EdgeLock) |
| ST | [STM32U5](https://www.st.com/en/microcontrollers-microprocessors/stm32u5-series.html) | Cortex-M33 | 160 | 1 | ✓ | ✓ | AES, RSA/ECC (PKA), SHA |
| Infineon | [PSoC Control C3](https://www.infineon.com/products/microcontroller/32-bit-psoc-arm-cortex/32-bit-psoc-control-arm-cortex-m33-mcu) | Cortex-M33 | 180 | 2 | ✓ | ✓ | AES-128, RSA, ECC, SHA-256 |
| GigaDevice | [GD32E5xx](https://www.gigadevice.com/product/mcu/high-performance-mcus/gd32e5xx-series) | Cortex-M33 | 180 | 3 | ✓ | ✓ | AES, 3DES, RSA/ECC, SHA |
| GigaDevice | [GD32G5xx](https://www.gigadevice.com/product/mcu/high-performance-mcus/gd32g5xx-series) | Cortex-M33 | 216 | 3 | ✓ | ✓ | AES, 3DES, SHA |
| Renesas | [RA6](https://www.renesas.com/en/products/microcontrollers-microprocessors/ra-cortex-m-mcus?field-series-name=RA6) | Cortex-M33 | 240 | 2 | ✓ | ✓ | AES, RSA, ECC, SHA, GHASH |
| NXP | [MCX A26/A36](https://www.nxp.com/products/MCX-A26) | Cortex-M33 | 240 | 2 | ✓ | ✓ | AES-256 (SGI), RSA/ECC (PKC) |
| ST | [STM32H5](https://www.st.com/en/microcontrollers-microprocessors/stm32h5-series.html) | Cortex-M33 | 250 | 2 | ✓ | ✓ | AES, SAES, RSA/ECC (PKA), SHA |
| GigaDevice | [GD32F5xx](https://www.gigadevice.com/product/mcu/high-performance-mcus/gd32f5xx-series) | Cortex-M33 | 280 | 2 | ✓ | ✓ | AES, 3DES, RSA/ECC, SHA |
| Nordic | [nRF54H20](https://www.nordicsemi.com/Products/nRF54H20) | Cortex-M33 (multi-core) | 320 | 1 | ✓ | ✓ | AES, ChaCha20, ECC, Ed25519, SHA-2/3 |
| TI | [C2000 F28x](https://www.ti.com/product/TMS320F28P650DK) | C28x DSP (dual) | 200 | 2 | – | – | AES |
| TI | [C2000 F29H85x](https://www.ti.com/product/F29H850TU) | C29x DSP (triple) | 200 | 6 | ✓ | ✓ | AES, RSA, ECC, SHA-2, SM2/3/4 (HSM) |
| Microchip | [SAM E7x/V7x](https://www.microchip.com/en-us/products/microcontrollers/32-bit-mcus/pic32-sam/sam-e) | Cortex-M7 | 300 | 2 | ✓ | – | AES-256, SHA |
| Microchip | [PIC32CZ CA9x](https://www.microchip.com/en-us/products/microcontrollers/32-bit-mcus/pic32-sam/pic32cz-ca) | Cortex-M7 | 300 | 6 | ✓ | ✓ | AES, 3DES, ChaCha20, RSA, ECC, SHA-2/3 (HSM) |
| NXP | [S32K3](https://www.nxp.com/products/S32K3) | Cortex-M7 | 320 | 12 | ✓ | ✓ | AES, RSA, ECC, SHA-2 (HSE) |
| Infineon | [XMC7000](https://www.infineon.com/products/microcontroller/32bit-industrial-arm-cortex-m/xmc7000-m7) | Cortex-M7 (dual) | 350 | 2 | ✓ | ✓ | AES, RSA, ECC, SHA |
| ST | [STM32H7](https://www.st.com/en/microcontrollers-microprocessors/stm32h7-series.html) | Cortex-M7 | 550 | 3 | ✓ | – | AES-256, 3DES, SHA (crypto line) |
| GigaDevice | [GD32H7xx](https://www.gigadevice.com/product/mcu/high-performance-mcus/gd32h7xx-series) | Cortex-M7 | 600 | 3 | ✓ | ✓ | AES, 3DES, SHA |
| ST | [STM32H7R/S](https://www.st.com/en/microcontrollers-microprocessors/stm32h7rs-series.html) | Cortex-M7 | 600 | 2 | ✓ | ✓ | AES, ECC (PKA), SHA (S line) |
| NXP | [i.MX RT106x](https://www.nxp.com/products/i.MX-RT1060) | Cortex-M7 | 600 | 1 | ✓ | ✓ | AES-128, SHA-256 (DCP) |
| NXP | [i.MX RT1180](https://www.nxp.com/products/i.MX-RT1180) | Cortex-M7 + M33 | 800 | 3 | ✓ | ✓ | AES, RSA-4096, ECC, SHA-2 (EdgeLock) |
| NXP | [i.MX RT1170](https://www.nxp.com/products/i.MX-RT1170) | Cortex-M7 + M4 | 1000 | 3 | ✓ | ✓ | AES, 3DES, RSA-4096, ECC, SHA (PUF) |
| Infineon | [AURIX TC3xx](https://www.infineon.com/products/microcontroller/32-bit-tricore/aurix-tc3xx) | TriCore (multi-core) | 400 | 3 | ✓ | ✓ | AES-128, ECC, SHA-2 (HSM) |
| Infineon | [AURIX TC4x](https://www.infineon.com/products/microcontroller/32-bit-tricore/aurix-tc4x) | TriCore (multi-core) | 500 | 5 | ✓ | ✓ | AES, ECC, SHA (CSRM) |
| Nuvoton | [M55M1](https://www.nuvoton.com/products/microcontrollers/arm-cortex-m55-mcus/m55m1-series/) | Cortex-M55 | 220 | 2 | ✓ | ✓ | AES-256, RSA-4096, ECC-571, SHA-512 |
| Infineon | [PSoC Edge](https://www.infineon.com/products/microcontroller/32-bit-psoc-arm-cortex/32-bit-psoc-edge-arm) | Cortex-M55 + M33 | 400 | 1 | ✓ | ✓ | AES, 3DES, RSA-4096, ECC, SHA-2/3 |
| ST | [STM32N6](https://www.st.com/en/microcontrollers-microprocessors/stm32n6-series.html) | Cortex-M55 | 800 | 3 | ✓ | ✓ | AES ×2 (DPA-hard), ECC (PKA), SHA |
| Renesas | [RA8](https://www.renesas.com/en/products/microcontrollers-microprocessors/ra-cortex-m-mcus?field-series-name=RA8) | Cortex-M85 (+M33) | 1000 | 2 | ✓ | ✓ | AES, ChaCha20, RSA, ECC, SHA-2/3, Ed25519 (RSIP) |
| TI | [AM273x](https://www.ti.com/product/AM2732) | Cortex-R5F + C66x DSP | 400 | 2 | ✓ | ✓ | AES-256, RSA/ECC (PKA) (HSM) |
| TI | [AM26x](https://www.ti.com/product/AM2634) | Cortex-R5F | 500 | 8 | ✓ | ✓ | AES, 3DES, RSA/ECC (PKA), SHA-2 (HSM) |
| TI | [AM243x](https://www.ti.com/product/AM2434) | Cortex-R5F (+M4F) | 800 | 2 | ✓ | ✓ | AES, 3DES, RSA/ECC (PKA), SHA-2 (SA2UL) |
| Renesas | [RZ/T2](https://www.renesas.com/en/products/rz-t2m) | Cortex-R52 (dual) | 800 | 2 | ✓ | ✓ | AES, RSA, ECC, SHA (RSIP) |
| TI | [AM275x](https://www.ti.com/product/AM2754-Q1) | Cortex-R5F + C7x DSP | 1000 | 5 | ✓ | ✓ | AES, RSA, ECC, SHA-2 (HSM) |

## Frequently Asked Questions

### Why does this table list only CAN FD parts?

Cryptographic frame protection needs room for an authentication tag and a freshness counter, and the classical CAN payload of eight bytes leaves almost none. CAN FD carries up to 64 bytes per frame, which is what makes authenticated and encrypted CAN traffic practical. A controller that pairs a CAN FD interface with on-chip security is therefore the natural target for the controls cataloged on this site, so the table is scoped to that combination. A part qualifies only when it has at least one CAN FD interface and at least one hardware security feature.

### What counts as secure key storage?

Any on-chip mechanism that holds key material so that firmware and an attacker with debug access cannot read it back. In practice this ranges from a simple write-only or one-time-programmable key region, through immutable secure-boot root keys, to a physically unclonable function or a separate security subsystem such as an HSM or secure enclave that performs cryptographic operations without ever exposing the key. The table marks the feature as present when the datasheet documents such a mechanism; the note names which kind.

### Does listing a part imply a recommendation?

No. The table is a neutral orientation aid compiled from public product pages and datasheets. It records what the silicon offers, not a judgment of fitness for any particular design, and inclusion is not an endorsement. EmSA has no commercial relationship with the manufacturers listed. Confirm every specification against the current datasheet before making a selection, because vendors revise part lineups and feature sets over time.
