Elevator Master Module

AXON Elevator Master

Elevator master with direct controller integration
AXON ELM-GEIn development — pilots on request

The elevator master tier of the AXON platform. It validates a credential against stacked access policies and sends a real destination call to the elevator controller — not a simulated button press.

Direct controller integration
Ethernet + GSM dual uplink
RS-485 bus to readers and modules
Stacked policy validation
2uplinks
Ethernet + GSM fallback
10/100Mbps
Ethernet primary uplink
RS-485
Downstream bus (TIA-485-A)
6policy layers
Checked on every event
Local
Cached policy, offline audit
Overview

A real call, not a fake button press

AXON ELM-GE is the master controller for elevator-class AXON installs. Three communication domains meet on the board: Ethernet and GSM upstream to the central AXON platform for credential sync, audit offload and remote management; an RS-485 bus downstream to landing readers, converters and output expansion modules; and a direct command path into the elevator controller itself. When a credential passes validation, ELM-GE issues a destination command over the controller's own interface, so the call enters the controller's scheduler as a normal request rather than as a contact closed across a floor-button input.

That distinction is the load-bearing design choice. Button simulators work mechanically but are invisible to group dispatch, destination dispatch, priority handling and service modes, and they cannot be logged as a real call event on the elevator side. Direct integration keeps the controller's dispatch intelligence intact and produces a log entry on both sides. In a full ELM-GE deployment the landing hardware reduces to a reader; the floor-button matrix becomes largely optional, with a small override panel kept for service and emergency use where the building wants one.

Validation stacks six policy layers before any command is issued: credential identity, time window, per-credential floor list, priority class, lockdown state and active override or VIP flags. Denials are logged with the layer that failed. ELM-GE then supervises the controller's response and flags a rejected or ignored call as an anomaly. Cached policy and a local audit buffer keep access working and records intact through a brief uplink outage. The product is in development; the role and capability set are stable, while controller integrations, uplink security profile and production hardware details are being finalised.

Key capabilities

What the board does for the site

Direct elevator controller command

On a validated credential ELM-GE issues a destination command through the controller's own command interface — serial, CAN or Ethernet depending on the make. The call is treated identically to a manual destination request, so group and destination dispatch, priority handling and service modes keep working above the access layer.

Ethernet primary, GSM fallback

Ethernet 10/100 Mbps carries credential sync, audit offload and management traffic. A GSM or cellular modem takes over for management and emergency commands when the building LAN drops — a common event in elevator machine rooms. GSM is a lifeline, not a continuous data path, so its data use stays small.

RS-485 bus to readers and modules

Downstream, one half-duplex RS-485 bus (TIA-485-A) reaches URX-Secure readers, AMS Wiegand converters and RBN-2 or SSR-32 output modules. Each device carries an individual address per the AXON bus convention; the master polls them over shielded twisted pair with 120 Ω termination at both physical ends.

Six-layer policy stack

Every credential event passes identity, time window, per-credential floor list, priority class, lockdown state and any active override or VIP flag before a command goes out. Each layer passes or denies; a denial is logged with the failing reason and no controller command is issued, so operators see failures rather than silence.

Cached policy and local audit

The credential cache is populated from the central platform over Ethernet or GSM. If both uplinks are down, ELM-GE keeps honouring cached policy for a configurable offline grace period and buffers every event locally. When either uplink returns, queued events upload; a full buffer is itself a logged event.

Battery-backed RTC and NTP

Time-window policy collapses without reliable time, so ELM-GE carries a real-time clock with battery backup and syncs to NTP over Ethernet. Audit timestamps and time-of-day rules survive power cycles even when the uplink is unavailable at boot.

How it works

One credential, one real destination call

Credential read

A resident presents a card at a landing reader. The reader sends the credential over the RS-485 bus to ELM-GE.

Identity and policy stack

ELM-GE resolves the credential in its local cache, then applies time window, floor list, priority, lockdown and override layers. Any denial is logged with its reason.

Direct controller command

On a full pass ELM-GE resolves the destination floor and issues a destination command through the elevator controller's own command interface.

Reconcile and report

ELM-GE supervises the controller's response, logs an accepted call as an authorisation or a rejected one as an anomaly, buffers the event and pushes it upstream.

System events flow the other way: lockdown, emergency unlock, schedule changes and revocations are pushed from the platform, validated by the master and applied locally. During an uplink outage ELM-GE keeps honouring cached policy until the link restores or the configurable offline grace period expires; audit events wait in the local buffer for replay.
Communication Architecture

Three legs meet in one machine-room cabinet

Upstream

Ethernet primary, GSM fallback

Ethernet 10/100 Mbps (IEEE 802.3) to the building LAN is the primary path for credential sync, audit log offload and management. A GSM or LTE-class modem, per 3GPP standards and depending on the modem fitted, keeps the master reachable for management and emergency commands when the LAN is down. The two paths are deliberately asymmetric.

IEEE 802.3 · 3GPP cellular fallback
Downstream

RS-485 bus in the riser

A linear RS-485 backbone (TIA-485-A) runs through the building riser with short stubs to each landing reader, converter and output module. Every device has an individual address. Shielded twisted pair, 120 Ω termination at the two physical ends only, no star topology and no termination at every device.

TIA-485-A · 120 Ω at both ends
Lateral

Elevator controller interface

The unique leg. ELM-GE talks to the elevator controller over the controller's own command interface — destination command, floor lock-out, service-mode entry, whatever the make exposes. Physical and protocol layer vary: some controllers use serial, some a dedicated CAN variant, some Ethernet. An integration layer hides those differences from the policy engine.

Serial · CAN · Ethernet, per make
Technical specifications

The numbers, from the datasheet

Target interface layout from the development spec. Supply voltage, MCU, dimensions, cellular bands, audit storage capacity and certifications are not final and are omitted.

2uplinks
Ethernet + GSM
RS-485
Downstream bus
Direct
Elevator controller command
System01
RoleElevator master controller
Access decisionLocal, from cached policy
Elevator linkDirect controller command — not button simulation
Policy layersIdentity, time, floor list, priority, lockdown, override
AuditLocal event buffer with offline replay to platform
StatusIn development
Connectivity02
Primary uplinkEthernet 10/100 Mbps, RJ45 (IEEE 802.3)
Fallback uplinkGSM / cellular modem, SIM slot, external antenna
Downstream busRS-485 A/B/GND, half-duplex (TIA-485-A)
Bus termination120 Ω at the two physical ends only
Bus devicesURX-Secure, AMS (Wiegand), RBN-2, SSR-32
Elevator interfaceSerial, CAN or Ethernet — depends on controller make
Power & timekeeping03
Power inputDedicated DC feed with margin for GSM modem peak draw
SupervisionBoard power supply with watchdog
Real-time clockBattery-backed RTC
Time sourceNTP over Ethernet, RTC across power cycles
Security04
ValidationSix policy layers, denying layer logged
ReconciliationController response supervised, anomalies logged
Life safetyFire-service / emergency mode overrides ELM-GE
Key storageSecure element / TPM — planned
Uplink securityTLS / mutual-auth profile being finalised
Dry-contact inputsFire alarm interlock, override panel — planned
Environment & mechanical05
MountingSealed enclosure in or adjacent to machine room
IsolationAway from the drive cabinet; own cable trunking
AntennaGSM antenna routed outside the machine room
Status indicatorsUplink state, bus activity, controller link

Terminals & connectors (target layout)

Ethernet (RJ45)

Primary uplink to the building LAN. Patch to a switch port that survives building network maintenance, not a shared printer hub.

SIM slot + GSM antenna

Fallback uplink. External antenna recommended, routed out of the machine room; verify signal with a survey before commissioning.

RS-485 A / B / GND

Downstream bus, daisy-chained to landing readers, converters and expansion modules. 120 Ω termination at the two physical ends only.

Elevator controller terminals

Direct integration. Layout depends on the supported controller make; run in its own trunking, label both ends, do not splice in the field.

Power input

Board supply. Dedicated DC feed sized for the board plus margin for GSM modem peak draw.

Dry-contact inputs (planned)

Fire alarm interlock and override panel — life-safety inputs that take precedence over access logic.

Status indicators

Uplink state, bus activity and controller link state for at-a-glance commissioning and triage.

Read the full technical guide Request the datasheet PDF Values marked as targets are subject to change until production release.
Compared

How ELM-GE compares to elevator retrofits

AspectAXON ELM-GEButton simulators & dry-contact retrofits
Elevator linkDestination command over the controller's own interfaceContact closed across a floor-button input, or dry-contact go/no-go per floor
Dispatch intelligenceGroup and destination dispatch, priority and service modes preservedInvisible to the controller's higher-level features
LoggingReal call event logged on the controller and on ELM-GECannot be logged as a real call on the elevator side
Landing hardwareReader only; button matrix largely optionalFull call panel remains, brittle when the panel changes
Vendor lock-inBrand-agnostic credentials, per-make controller integrationOEM access modules are manufacturer-locked with their own credential platform
Deployment scenarios

Where AXON ELM-GE fits

Typical configurations we size for integrators. Every scenario below is a planning example, not a customer reference.

Residential · 25 floors

Reader-only landings in a high-rise tower

A new 25-floor residential tower installs ELM-GE in the elevator machine room. Each landing carries only a reader, no full button panel. A resident presents a card, ELM-GE validates the credential against the resident's authorised floors and issues a destination command; the cabin arrives with the floor already selected. Guests use temporary credentials, staff a separate priority class.

Office · 14 floors

Floor-by-floor tenant separation

A 14-floor office building uses ELM-GE to enforce access by tenant. Tenant A occupies floors 3 and 4, tenant B floors 5 to 8, building services floors 9 to 14. One elevator serves everyone, but each credential can only call its authorised destinations. In a security incident a lockdown from the platform makes ELM-GE deny everything below a configured tier.

Hotel · staff floors

Staff-only floors on shift windows

A hotel reserves its top two floors for back-of-house areas. ELM-GE refuses to call those floors for any guest card while serving guest floors normally. Cleaning staff hold a priority class that authorises the staff floors only during their shift windows. Every authorisation and every denial is logged, including the policy layer that denied it.

Hospital · controlled wards

Ward access without losing dispatch

A hospital main elevator block enforces ward-by-ward access. Medical, administrative, cleaning and contractor staff each have a credential class with its own floor list and time windows. Visiting hours open and close visitor floors automatically. Because ELM-GE talks to the controller directly, group dispatch — cabin selection, wait-time optimisation — keeps operating while access is filtered upstream.

Questions integrators ask

AXON ELM-GE FAQ

What does direct elevator controller integration actually mean?
ELM-GE talks to the elevator controller over the controller's own command interface and issues real destination calls. It does not close a contact across a floor-button input. Real calls are visible to the controller's dispatch logic and are logged on both sides; button simulations are not.
Why both Ethernet and GSM?
Ethernet is the primary path. GSM is the management lifeline when the building LAN fails — elevator machine rooms see more incidental LAN disruption than expected, and an isolated master leaves residents waiting on a landing. GSM keeps management and emergency commands flowing until the LAN is restored.
Are floor buttons still needed?
In a full ELM-GE deployment they become largely optional. Most buildings keep only readers visible on the landings; a small override panel may remain for service and emergency. The default access flow no longer needs every floor to expose a full button matrix.
Which elevator controllers does ELM-GE integrate with?
Integration is built per controller make, and the supported list is part of the in-development scope. For a specific project, share the elevator controller make and model with AXON to confirm the integration path before specifying ELM-GE in a tender.
What happens during a fire or emergency event?
The elevator controller takes precedence: it enters fire-service mode and runs its own emergency program, ignoring ELM-GE commands by design. ELM-GE logs the transition and stops issuing access-driven calls. Access control is always subordinate to life safety.
Is ELM-GE shipping today?
No. It is in development. The role and capability set are defined, controller integrations are being completed make by make, and uplink security details and production timelines will be published with the production release. Pilots can be arranged for planned installs. Development-unit photographs are confidential.
Plan the integration early

Ready to specify AXON ELM-GE?

ELM-GE is in development. Share your elevator controller make and model and the building's floor plan; AXON confirms the integration path, sizes the RS-485 bus and reader count, and can arrange a pilot on a planned install.