Skip to Content
Skip to content
MERICRON MCN-1

The Open American Wireless MCU

MCN-1 combines a rebuildable wireless stack, owner-controlled secure boot, and an always-on hardware security core. Wi-Fi 6 and Bluetooth 5.4 with no closed RF blackbox. Designed in Kansas for U.S. fabrication, packaging, testing, and secure provisioning.

MCN-1 target architecture

One part. Full control.

Preliminary pre-silicon targets from the current MCN-1 architecture. Final specifications remain subject to physical design, verification, and production characterization.

Application processing

2× RV32 at 400 MHz

Independent RISC-V application cores with bit-manipulation and scalar cryptography extensions.

Security core

Always on at 100 MHz

Isolated RISC-V security core with a 400 MHz burst mode for post-quantum operations.

Wireless

Wi-Fi 6 and Bluetooth 5.4 LE

Dual-band 802.11ax 1×1 on a dedicated 400 MHz open-firmware baseband core.

Package

QFN-56, 7 × 7 mm

Wettable-flank two-die SiP target. An 8 × 8 mm LGA remains the packaging fallback.

Owner control

Customer root keys

Provision your own secure-boot authority and revoke Mericron's authority over your devices.

Open radio stack

The radio firmware is the product.

MCN-1 is designed so customers can inspect, rebuild, modify, and flash the complete Wi-Fi and Bluetooth firmware stack. The SDK, drivers, MAC firmware, Bluetooth controller, PHY control code, calibration algorithms, secure-core runtime, and bootloader are published without opaque runtime blobs.

Owner-controlled trust

Your hardware. Your root key.

Customers can provision their own secure-boot authority and revoke Mericron's authority over their devices. The architecture combines secure boot, measured boot, attestation, and rollback protection without making Mericron the permanent gatekeeper for customer firmware.

RF Compliance Firewall

Open firmware inside certified limits.

A hardware and ROM enforcement layer sits below the firmware and constrains frequency, transmit power, channel configuration, DFS behavior, and other certified RF limits. This keeps customer-modifiable firmware inside the radio's approved transmission envelope.

U.S. manufacturing

An American supply chain, stage by stage.

MCN-1 is designed in Kansas around a domestic production path. The baseline plan targets GlobalFoundries Fab 8 in Malta, New York for 22FDX wafer fabrication, followed by U.S. package assembly, final test, firmware provisioning, and key custody.

Designed in Kansas

Architecture, firmware, security design, and verification from Manhattan, Kansas.

U.S. wafer fabrication

GlobalFoundries Fab 8 / 22FDX is the baseline manufacturing target, not an announced contract.

Domestic packaging and test

U.S. packaging and test partners remain under qualification.

Documented origin

Each production SKU will include a supply-chain origin statement.

Why custom silicon

If this chip existed on a shelf, we would buy it.

No catalog part combines American provenance with a radio customers can inspect, rebuild, and control.

The provenance problem

Origin follows the chip design

ESP32 shows the problem clearly. The silicon vendor controls the design, licensed radio IP, signing hierarchy, and update path. Changing the module assembler or wafer fab does not change that.

Western alternatives

The radio remains a black box

Western vendors ship capable parts with radio firmware that includes licensed third-party IP. They do not have the right to publish it. No amount of money can buy it open.

The multi-chip workaround

More parts. Same blind spot.

An MCU, radio module, and secure element cost two to four times more, take more board space, and add vendors. The radio firmware remains closed.

Why custom silicon

Make openness legal in hardware

Incumbents satisfy FCC rules by locking firmware. MCN-1 enforces the RF limits below firmware, so customers can rebuild the radio without leaving its grant. That cannot be retrofitted.

Prototype evidence

The core architecture has been proven in hardware.

A working prototype has demonstrated the multicore trust boundaries, hybrid secure boot, measured boot, attestation, independent application domains, concurrent network paths, and RF policy authorization defined by the MCN-1 architecture.

Hybrid boot proven

Ed25519 and ML-DSA-87 must both verify before protected domains are released.

Measurement proven

SHA3-384 measurements extend into PCRs and produce an inspectable attestation quote.

Isolation proven

Security, application, and transport domains execute across separate RISC-V harts.

Concurrency proven

Independent applications and network paths operate concurrently without blocking one another.

Implementation proven

The complete four-core digital design closes timing in the hardware prototype.

RF policy proven

Radio activation requires RF Compliance Firewall authorization before transmission begins.

Prototype results validate the digital architecture. Integrated RF behavior, package characteristics, power, and production performance remain pre-silicon targets.

MCN-1

Build on silicon you can explain.

Read the preliminary architecture or tell us what you are building and where open, owner-controlled wireless fits into it.

Preliminary targets

MCN-1 at a glance.

Headline design targets from the current MCN-1 architecture. All values remain preliminary until production silicon is characterized.

2× RV32 at 400 MHz Application cores with bit-manipulation and scalar cryptography extensions.
1× RV32 at 100 MHz Always-on security core with a 400 MHz post-quantum burst mode.
768 KB + 64 KB + 256 KB Main, isolated security-core, and radio SRAM targets.
Wi-Fi 6, 2.4 and 5 GHz Dedicated 400 MHz radio core with 20/40/80 MHz channels, OFDMA, TWT, and WPA3.
Bluetooth 5.4 LE LE-only v1 target with 1M/2M/coded PHY, PAwR, and EAD.
Hybrid secure boot Ed25519 and ML-DSA-87 verification proven in the hardware prototype.
QFN-56, 7 × 7 mm 38 GPIO with 2× CAN-FD and USB 2.0 Full-Speed device and host targets.
≤25 µA deep sleep RTC-retained low-power target on a 3.0 to 3.6 V supply.