Smart Home Automation

Understanding Orcon 866MHz Remotes with ESPHome

Learn how Orcon 866MHz rolling code remotes work, why cloning is impossible, and how to safely integrate them with ESPHome and Home Assistant using ESP32 and optocouplers.

Why Orcon 866MHz Remotes Cannot Be Cloned

Orcon remotes use rolling codes, frequency hopping and cryptographic keys stored inside the MCU. This combination makes replay attacks and cloning impossible.

Orcon 866MHz Remote Analysis

Signal analysis and rolling codes

The Orcon remote control operates on 866MHz and uses advanced rolling code technology to prevent unauthorized duplication. Using SDR++, we analyzed the radio signals, capturing the frequency hopping pattern. On the MCU side, we connected to the SPI bus, observing SCK and MISO lines to understand communication timing.

Despite these measurements, cloning the remote is impossible. The rolling code changes with every button press, and the cryptographic key is securely stored in the MCU memory, which cannot be read or extracted. This makes direct replication of the remote strictly unfeasible.

SPI sniffing result

button 1, 5 x pressed


0xE2 0x31 0x9B 0x27 0x96 0x76 0x82 0x63 0x82 0x20 0xA2 0xE9 0x8E 0xE0 0xAF 0x6C 0xE2 0x60 0xB6 0xB1 0xFB 0x6F 
0xA2 0xA9 0xB6 0xEC 0xAE 0x6C 0x82 0xBA 0xC3 0xB9 0xC7 0x32 0xD6 0x36 0xBF 0x61 0x9E 0x20 0xEB 0xF7 0xDB 0x7F 
0x8A 0x22 0x93 0x2B 0x27 0x57 0x51 0xF8 0x05 0x1C 0x04 0x82 0xAA 0xA6 0x6A 0x82 0xF2 0xB3 0xA2 0x82 0xA8 0xC7 
0xF2 0xBE 0xAA 0xAD 0xAA 0xAB 0x9E 0xA0 0xB7 0xF0 0xEF 0x71 0xD3 0x75 0x83 0x6F 0xDA 0x27 0x92 0x3A 0x8B 0x6A 
0x83 0xBE 0xF7 0xAA 0x82 0x65 0xF3 0xA0 0xFB 0xA0 0xDA 0x76 

0xE7 0xA5 0xC6 0x75 0x9E 0x22 0xDA 0x22 0x8E 0x24 0x82 0xAA 0xA6 0x6A 0x82 0xF2 0xB3 0xA2 0x82 0xA8 0xC7 0xF2 
0xBE 0xA8 0xA6 0xAA 0xB3 0x73 0x51 0x59 0x9D 0x8E 0xAE 0xE4 0x0F 0xDA 0x9E 0x20 0xEB 0xF7 0xDB 0x7F 0x8A 0x22 
0x93 0xE5 0xCC 0xCA 0x65 0x8B 0x60 0x8A 0x60 0x92 0x28 0xAA 0xA3 0xAA 0x2B 0xCA 0xB8 0x8A 0x2D 0xA3 0x3E 0xCA 
0xE8 0xA2 0xAD 0xAA 0xAB 0x9E 0xA0 0xB7 0xF0 0xEF 0x71 0xD3 0x75 0x83 0x6F 0xDA 0x27 0x92 0x3A 0x8B 0x6A 0x83 
0xBE 0xF7 0xAA 0x82 0x65 0xF3 0xA0 0xCF 0x41 0xB4 0x4F 

0xB8 0x97 0x26 0xD6 0x65 0x8B 0x60 0x8A 0x60 0x92 0x28 0xAA 0xA3 0xB8 0x57 0x3B 0xD1 0x12 0xC6 0x66 0x6F 0xA2 
0xA9 0xB6 0xEC 0xAE 0x6A 0x2D 0xEB 0x3B 0xCF 0x34 0xCB 0x20 0xDA 0xF6 0x86 0x64 0x83 0x7E 0xDF 0x76 0xFE 0x64 
0x8A 0x3E 0x97 0x26 0xD6 0x65 0x8B 0x60 0x8A 0x60 0x92 0x28 0xAA 0xA3 0xAA 0x2B 0xCA 0xB8 0x8A 0x2D 0xA2 0x7D 
0x95 0xE8 0xA2 0xAD 0xAA 0xAB 0x9E 0xA0 0xB7 0xF0 0xEF 0x73 0x32 0xD6 0x36 0xEA 0xB3 0x15 0x33 0xB3 0x1E 0xFB 
0xBD 0xAA 0x22 0x97 0xBC 0x83 0xFD 0x83 0x62 0xDB 

0xB8 0x97 0x26 0xD6 0x65 0x8B 0x60 0x8A 0x60 0x92 0x21 0x55 0x23 0xAA 0x57 0x95 0x98 0x8A 0x2D 0xA3 0x3E 0xCA 
0xE8 0xA2 0xAD 0xAA 0xAB 0x9E 0xA0 0xB7 0xF0 0xEF 0x71 0xD3 0x75 0x83 0x6F 0xDA 0x27 0x92 0x3A 0xFB 0x76 0xFF 
0x8A 0x22 0x93 0xE5 0xC6 0x75 0x9E 0x22 0xB8 0x05 0x1C 0x04 0x82 0xAA 0xA6 0x6A 0x82 0xF2 0xB3 0xA2 0x85 0xA8 
0xC7 0xF2 0x7D 0x4D 0xBC 0xEB 0xBD 0x42 0xF3 0x8E 0xCD 0x74 0xCB 0x20 0xD7 0xDA 0x27 0x92 0x3A 0x8B 0x6A 0x83 
0xBE 0xF7 0xAA 0x82 0x65 0xF3 0x81 0xF7 0xA0 0xDA 0x76 

0xE7 0xA5 0xC6 0xDA 0x9E 0x22 0xC8 0x05 0x1C 0x04 0x82 0xAA 0xA6 0x6A 0x82 0xF2 0xB3 0xA2 0x82 0xA8 0xC7 0xF2 
0xBE 0xA8 0xA6 0xAA 0xB2 0xE7 0xB2 0x2D 0xEB 0x3B 0xCF 0x34 0xCB 0x20 0xDD 0xF6 0x86 0x64 0x83 0xFE 0xDF 0x76 
0xFE 0x64 0x8A 0x3E 0x97 0x26 0xD6 0x65 0x8B 0x60 0x8A 0x60 0x92 0x28 0xAA 0xA3 0x98 0x46 0x25 0xC9 0x89 0x44 
0xEE 0x76 0x95 0x96 0xAA 0xAB 0x9E 0xC1 0x6F 0x50 0xEF 0x71 0xD3 0x75 0x83 0x6F
          

Suspected burst structure (example)

Below is a structured breakdown of burst 1:


[E2 31 9B 27 96 76 82 63]   ← rolling / nonce
[82 20 A2 E9 8E E0 AF 6C]   ← command / state
[E2 60 B6 B1 FB 6F]         ← counter / seed
[A2 A9 B6 EC AE 6C]         ← protocol fixed
[82 BA C3 B9 C7 32 D6 36]   ← checksum input
[BF 61 9E 20 EB F7 DB 7F]   ← encrypted payload
          

Safe Integration with ESPHome & Home Assistant

Why optocouplers are the only safe method

The recommended approach is to control the original Orcon remote using an ESP32 or Arduino. By connecting optocouplers to the remote’s buttons, ESPHome can safely trigger the commands without attempting to bypass the rolling code. This ensures full compatibility and maintains security.

Additionally, you can extend your smart home setup by reading sensor outputs or fan rotations, integrating them into Home Assistant dashboards for real-time monitoring. This allows automation and logging without ever breaking the security model of the Orcon remote.

Example Setup: ESP32 + Optocouplers

ESP32 Integration

Connect optocouplers to the original Orcon remote. Use ESPHome to trigger each button press safely. Log status and integrate sensors in Home Assistant for full automation. Coming soon

Conclusion

Attempting to clone an Orcon 866MHz rolling code remote is impossible due to frequency hopping and secure key storage on the MCU. The only reliable and secure method is to control the original remote via ESP32 or Arduino using optocouplers. Combined with ESPHome and Home Assistant, you can automate your smart devices while keeping the system fully secure.

Frequently Asked Questions

Why can't Orcon 866MHz remotes be cloned?

Orcon remotes use rolling codes, frequency hopping, and cryptographic keys stored in the MCU, making cloning or replay attacks impossible.

Can I integrate Orcon remotes with ESPHome safely?

Yes. By using optocouplers to trigger the original remote's buttons, ESPHome can control the remote safely without breaking the security model.

Do I need to clone the remote to automate it?

No. Controlling the existing remote with optocouplers is sufficient for full automation while keeping the system secure.