EnOcean Secure uses a rolling code (an incremental counter) together with a CMAC (Cipher-based MAC built on AES-128) to authenticate every telegram and block replay attacks, which is critical for security-grade applications such as alarms and wireless locks.
True
EnOcean Secure layers cryptographic protection on top of the standard telegram. A 24 or 32-bit rolling counter is incremented on every transmission, and a CMAC over (data plus counter) is appended using a shared AES-128 key. The receiver only accepts a telegram whose counter is greater than or equal to the next expected value, blocking captured-and-replayed frames. The 16-byte key is exchanged once during the Secure Teach-In. Without Secure mode, the classic EnOcean format is vulnerable to replay attacks, although the 32-bit Device ID still makes random spoofing impractical.
For door locks and alarm sensors, always enable Secure mode end-to-end; mixing one Secure sensor with a non-Secure gateway gives you no protection at all and is the single most common audit failure.
EnOcean bank in preparation
The full EnOcean bank isn't available yet. Drop your email to get notified at launch and grab an early-bird discount.
Join the waitlist →See the 9 other EnOcean practice questions
Related questions
- EnOcean is best known for its battery-less devices: energy is harvested from a piezo-electric element (mechanical push-button), a solar cell (sensors with a small photovoltaic panel) or a Peltier element (thermal gradient), eliminating battery maintenance over a 10 to 20 year service life.1. Architecture · Energy Harvesting
- The EEP (EnOcean Equipment Profile) identifies each device type by a RORG-FUNC-TYPE triplet (e.g. F6-02-01 = 2-channel Rocker push-button), enabling a receiver to decode the telegram correctly without any manual configuration.2. EEP · EnOcean Equipment Profile
- In the EnOcean Teach-In process, the transmitting device sends a special telegram containing its EEP and Device ID; the receiver memorises this information so it can decode later telegrams correctly and bind the sender to a specific action.2. EEP · Auto-Learn
- ESP3 (EnOcean Serial Protocol v3) is the communication protocol between an EnOcean radio module (TCM 310 / TCM 515) and a host gateway or PC over a UART link: packets begin with the sync byte 0x55, followed by a header, a data section and a CRC8.3. ESP3 protocol · Serielles Protokoll
- ePIRE (EnOcean Profile for Initial Resync Exchange) is the standardised protocol for secure pairing during Teach-In: it covers the generation and distribution of the shared AES key between a Secure-capable transmitter and receiver.6. Security · ePIRE