Why Orcon 866MHz Remotes Cannot Be Cloned
Orcon remotes use rolling codes, frequency hopping and cryptographic keys stored inside the MCU. This combination makes replay attacks and cloning impossible.
Orcon 866MHz Remote Analysis
Signal analysis and rolling codes
The Orcon remote control operates on 866MHz and uses advanced rolling code technology to prevent unauthorized duplication. Using SDR++, we analyzed the radio signals, capturing the frequency hopping pattern. On the MCU side, we connected to the SPI bus, observing SCK and MISO lines to understand communication timing.
Despite these measurements, cloning the remote is impossible. The rolling code changes with every button press, and the cryptographic key is securely stored in the MCU memory, which cannot be read or extracted. This makes direct replication of the remote strictly unfeasible.
SPI sniffing result
button 1, 5 x pressed
0xE2 0x31 0x9B 0x27 0x96 0x76 0x82 0x63 0x82 0x20 0xA2 0xE9 0x8E 0xE0 0xAF 0x6C 0xE2 0x60 0xB6 0xB1 0xFB 0x6F
0xA2 0xA9 0xB6 0xEC 0xAE 0x6C 0x82 0xBA 0xC3 0xB9 0xC7 0x32 0xD6 0x36 0xBF 0x61 0x9E 0x20 0xEB 0xF7 0xDB 0x7F
0x8A 0x22 0x93 0x2B 0x27 0x57 0x51 0xF8 0x05 0x1C 0x04 0x82 0xAA 0xA6 0x6A 0x82 0xF2 0xB3 0xA2 0x82 0xA8 0xC7
0xF2 0xBE 0xAA 0xAD 0xAA 0xAB 0x9E 0xA0 0xB7 0xF0 0xEF 0x71 0xD3 0x75 0x83 0x6F 0xDA 0x27 0x92 0x3A 0x8B 0x6A
0x83 0xBE 0xF7 0xAA 0x82 0x65 0xF3 0xA0 0xFB 0xA0 0xDA 0x76
0xE7 0xA5 0xC6 0x75 0x9E 0x22 0xDA 0x22 0x8E 0x24 0x82 0xAA 0xA6 0x6A 0x82 0xF2 0xB3 0xA2 0x82 0xA8 0xC7 0xF2
0xBE 0xA8 0xA6 0xAA 0xB3 0x73 0x51 0x59 0x9D 0x8E 0xAE 0xE4 0x0F 0xDA 0x9E 0x20 0xEB 0xF7 0xDB 0x7F 0x8A 0x22
0x93 0xE5 0xCC 0xCA 0x65 0x8B 0x60 0x8A 0x60 0x92 0x28 0xAA 0xA3 0xAA 0x2B 0xCA 0xB8 0x8A 0x2D 0xA3 0x3E 0xCA
0xE8 0xA2 0xAD 0xAA 0xAB 0x9E 0xA0 0xB7 0xF0 0xEF 0x71 0xD3 0x75 0x83 0x6F 0xDA 0x27 0x92 0x3A 0x8B 0x6A 0x83
0xBE 0xF7 0xAA 0x82 0x65 0xF3 0xA0 0xCF 0x41 0xB4 0x4F
0xB8 0x97 0x26 0xD6 0x65 0x8B 0x60 0x8A 0x60 0x92 0x28 0xAA 0xA3 0xB8 0x57 0x3B 0xD1 0x12 0xC6 0x66 0x6F 0xA2
0xA9 0xB6 0xEC 0xAE 0x6A 0x2D 0xEB 0x3B 0xCF 0x34 0xCB 0x20 0xDA 0xF6 0x86 0x64 0x83 0x7E 0xDF 0x76 0xFE 0x64
0x8A 0x3E 0x97 0x26 0xD6 0x65 0x8B 0x60 0x8A 0x60 0x92 0x28 0xAA 0xA3 0xAA 0x2B 0xCA 0xB8 0x8A 0x2D 0xA2 0x7D
0x95 0xE8 0xA2 0xAD 0xAA 0xAB 0x9E 0xA0 0xB7 0xF0 0xEF 0x73 0x32 0xD6 0x36 0xEA 0xB3 0x15 0x33 0xB3 0x1E 0xFB
0xBD 0xAA 0x22 0x97 0xBC 0x83 0xFD 0x83 0x62 0xDB
0xB8 0x97 0x26 0xD6 0x65 0x8B 0x60 0x8A 0x60 0x92 0x21 0x55 0x23 0xAA 0x57 0x95 0x98 0x8A 0x2D 0xA3 0x3E 0xCA
0xE8 0xA2 0xAD 0xAA 0xAB 0x9E 0xA0 0xB7 0xF0 0xEF 0x71 0xD3 0x75 0x83 0x6F 0xDA 0x27 0x92 0x3A 0xFB 0x76 0xFF
0x8A 0x22 0x93 0xE5 0xC6 0x75 0x9E 0x22 0xB8 0x05 0x1C 0x04 0x82 0xAA 0xA6 0x6A 0x82 0xF2 0xB3 0xA2 0x85 0xA8
0xC7 0xF2 0x7D 0x4D 0xBC 0xEB 0xBD 0x42 0xF3 0x8E 0xCD 0x74 0xCB 0x20 0xD7 0xDA 0x27 0x92 0x3A 0x8B 0x6A 0x83
0xBE 0xF7 0xAA 0x82 0x65 0xF3 0x81 0xF7 0xA0 0xDA 0x76
0xE7 0xA5 0xC6 0xDA 0x9E 0x22 0xC8 0x05 0x1C 0x04 0x82 0xAA 0xA6 0x6A 0x82 0xF2 0xB3 0xA2 0x82 0xA8 0xC7 0xF2
0xBE 0xA8 0xA6 0xAA 0xB2 0xE7 0xB2 0x2D 0xEB 0x3B 0xCF 0x34 0xCB 0x20 0xDD 0xF6 0x86 0x64 0x83 0xFE 0xDF 0x76
0xFE 0x64 0x8A 0x3E 0x97 0x26 0xD6 0x65 0x8B 0x60 0x8A 0x60 0x92 0x28 0xAA 0xA3 0x98 0x46 0x25 0xC9 0x89 0x44
0xEE 0x76 0x95 0x96 0xAA 0xAB 0x9E 0xC1 0x6F 0x50 0xEF 0x71 0xD3 0x75 0x83 0x6F
Suspected burst structure (example)
Below is a structured breakdown of burst 1:
[E2 31 9B 27 96 76 82 63] ← rolling / nonce
[82 20 A2 E9 8E E0 AF 6C] ← command / state
[E2 60 B6 B1 FB 6F] ← counter / seed
[A2 A9 B6 EC AE 6C] ← protocol fixed
[82 BA C3 B9 C7 32 D6 36] ← checksum input
[BF 61 9E 20 EB F7 DB 7F] ← encrypted payload
Safe Integration with ESPHome & Home Assistant
Why optocouplers are the only safe method
The recommended approach is to control the original Orcon remote using an ESP32 or Arduino. By connecting optocouplers to the remote’s buttons, ESPHome can safely trigger the commands without attempting to bypass the rolling code. This ensures full compatibility and maintains security.
Additionally, you can extend your smart home setup by reading sensor outputs or fan rotations, integrating them into Home Assistant dashboards for real-time monitoring. This allows automation and logging without ever breaking the security model of the Orcon remote.
Example Setup: ESP32 + Optocouplers
ESP32 Integration
Connect optocouplers to the original Orcon remote. Use ESPHome to trigger each button press safely. Log status and integrate sensors in Home Assistant for full automation. Coming soon
Conclusion
Attempting to clone an Orcon 866MHz rolling code remote is impossible due to frequency hopping and secure key storage on the MCU. The only reliable and secure method is to control the original remote via ESP32 or Arduino using optocouplers. Combined with ESPHome and Home Assistant, you can automate your smart devices while keeping the system fully secure.