Access Control Controller

AXON Master E

Wired access master with four relays and readers on board
AXON ICM-EIn development — hardware v1.4

The wired sibling of the AXON Master. Same decision engine and encrypted CAN backbone, no cellular modem — and readers and door relays connect straight to the board, so a small site needs one unit and no floor nodes at all.

4 relay outputs on board
RS-485 + Wiegand reader inputs
2× CAN ports 250 kbit/s
Ethernet uplink no modem
AXON ICM-E — Wired access master with four relays and readers on board
4relays
Doors driven from the board
2reader ports
RS-485 and Wiegand
2CAN ports
Independent 250 kbit/s buses
32,704cards
Per database bank
12–24V DC
Supply input
Overview

One board for a small site

AXON ICM-E is the AXON Master without the cellular modem, and with the first four access points built in. Where the ICM-GE reaches every door through a per-floor AXON Node, the ICM-E carries an RS-485 reader port, a Wiegand reader port and four relay channels on the board itself. A single entrance, a garage gate and two internal doors need one unit, one Ethernet drop and no bus wiring at all.

It is the same architecture underneath. The card database lives on the board, the access decision is made locally and never waits for the network, and the cloud is used only to synchronise the database, collect events and deliver firmware. Both CAN ports are still there, so the day the building grows past four doors you add AXON Nodes on a twisted pair instead of replacing the controller.

Dropping the modem removes the SIM, the antenna and the carrier subscription from the bill of materials. That is the right trade for a site that already has structured cabling and a switch port to spare — an office floor, a clinic, a small commercial building — and the wrong one for a site with no wired uplink, where the ICM-GE and its Axon Network connectivity are the answer.

Key capabilities

What the board does for the site

Four relays on the controller

Four Omron relay channels, CH1 to CH4, are wired straight to the board's terminal blocks. A door strike, a garage gate, a barrier and an alarm channel can all be driven from the controller that made the decision, with no bus device in between and nothing to address.

Readers connect directly

An RS-485 port carries the encrypted AXON reader protocol for a URX-Secure, and a Wiegand port takes any third-party 26-bit reader on D0/D1. Both terminals supply 12 V to the reader, so a door needs one four-core cable and no separate power run.

The decision stays on the board

The full card database sits in on-board flash — up to 32,704 records, looked up by binary search against the credential, its permission mask and its validity dates. No access decision waits for the network, so a switch reboot or an ISP outage changes nothing at the door.

Two CAN buses when the site grows

Both Classic CAN 2.0B ports at 250 kbit/s are fitted, each addressing up to 63 AXON Nodes. Start with the four on-board relays and add nodes on a twisted pair as floors or entrances are added, without changing the controller or re-issuing a single card.

Per-node encrypted CAN link

Every node on the bus has its own AES-128 key derived from the master's root key with AES-CMAC. Sessions open with a 3-pass mutual authentication, then each command and event is AES-CTR encrypted and CMAC-tagged with monotonic counters, so a frame cannot be replayed or moved to another node.

One wired uplink, used sparingly

A W5500 Ethernet controller reaches the AXON cloud over MQTT/TLS on port 8883 with DHCP addressing. It carries database sync, events and OTA firmware — never the access decision. There is no modem, no SIM slot and no antenna on this variant.

How it works

A door on the board itself

Card presented

A resident taps a DESFire EV3 card on a URX-Secure on the RS-485 port, or a legacy card on the Wiegand port.

Credential arrives

The reader hands the authenticated credential to the controller over the reader port — no bus hop, no node in between.

Local lookup

The master finds the record in its on-board database and checks the permission mask and the validity dates.

Relay pulses

On a grant it pulses the matching channel of CH1 to CH4 and records the event for the server.

The whole path is on one board and entirely offline — the uplink is not consulted at any step. When the network returns, the events are reported and any database change is applied.
How it is wired

Readers and doors first, bus second

On the board

Readers and 4 relays

One RS-485 port for an encrypted AXON reader and one Wiegand port for a third-party reader, both with 12 V supply on the terminal block. Four relay channels drive strikes, gates, barriers or signal lines directly from the controller.

RS-485 A/B · Wiegand D0/D1 · CH1–CH4
When the site grows

2× CAN, 250 kbit/s

Two independent Classic CAN 2.0B ports, 11-bit IDs, up to 63 AXON Nodes each. Split a building into two segments, or leave the ports unused on a small site. Segment power is switched on the board, so a shorted run can be isolated without a site visit.

Classic CAN 2.0B · 63 nodes/port · 120 Ω
Uplink

Ethernet only

A W5500 Ethernet controller on SPI, MQTT over TLS on port 8883, DHCP or a fixed lease. Give it a dedicated switch port or a managed VLAN on the building's management network. No cellular hardware is fitted on this variant.

W5500 · MQTT/TLS 8883 · RJ-45
Technical specifications

The numbers, from the datasheet

Values are read from the v1.4 board (AX-MAIN-02) and the shared AXON master platform; electrical ratings are confirmed at production release.

4relays
Doors driven from the board
2reader ports
RS-485 encrypted and Wiegand
32,704cards
On-board database
System01
RoleWired access master — doors on board, nodes optional
BoardAX-MAIN-02, hardware v1.4
Card databaseOn-board flash, sorted 64-byte records, up to 32,704 cards
Access decisionLocal binary search, offline, no network in the path
Permission modelPer-node and per-relay masks, valid-from and valid-to dates
Real-time clockOn-board RTC with coin-cell backup
Doors & readers02
Relay outputs4 channels (CH1–CH4), Omron relays, dry contacts
Encrypted reader portRS-485 (A / B / GND) with 12 V reader supply
Legacy reader portWiegand (D0 / D1 / GND) with 12 V reader supply
Card platformMIFARE DESFire EV3 via URX-Secure; Wiegand 26-bit for retrofit
CAN node bus03
Ports2× Classic CAN 2.0B, 11-bit IDs
Bit rate250 kbit/s
AddressingUp to 63 AXON Nodes per port
Segment powerSwitched per port, on-board high-side switch
Termination120 Ω at the two physical ends of each segment
Uplink04
EthernetW5500 10/100, RJ-45
CellularNot fitted — this is the wired variant
Cloud protocolMQTT over TLS, port 8883
Cloud roleDatabase sync, events, OTA — never the access decision
Firmware updateOTA over MQTT into a second flash bank, CRC-32 verified
Security05
Node linkAES-128, 3-pass mutual auth, AES-CTR + CMAC
Key modelPer-node key derived from the master root (AES-CMAC)
Anti-replay4-byte monotonic counters per direction
Reader linkEncrypted AXON protocol on RS-485; Wiegand is cleartext by nature
Power & mechanical06
Input12 V or 24 V DC
IndicatorsStatus LEDs: CAN 1, CAN 2, Ethernet, error, general status
ControlsBus-power button, reset button, service button
Service portSWD debug header for commissioning

Terminals & connectors

CAN Bus #1 (H / L / GND)

First CAN segment to AXON Nodes. Leave unused on a site that only needs the on-board doors.

CAN Bus #2 (H / L / GND)

Second, independent segment — a separate riser, wing or entrance group.

Axon Reader — RS-485 (12V / GND / A / B)

Encrypted AXON reader port with reader supply on the same block; one four-core cable per door.

Wiegand (12V / GND / D0 / D1)

Third-party 26-bit reader input with reader supply, for retrofits that keep existing readers.

CH1–CH4 relay outputs

Four dry-contact channels for strikes, gates, barriers or signal lines.

Ethernet RJ-45

Uplink to the AXON cloud over MQTT/TLS. DHCP by default.

Power input

12 V or 24 V DC. Size the supply for the controller plus every reader and lock it feeds.

Request the datasheet PDF Values marked as targets are subject to change until production release.
Compared

ICM-E or ICM-GE?

AspectAXON ICM-EAXON ICM-GE
UplinkEthernet only — needs a switch port on siteEthernet plus LTE over an Axon Network soft SIM
First access pointsFour relays and two reader ports on the boardReached through an AXON Node on the CAN bus
Smallest useful systemOne board, one Ethernet drop, four doorsOne board plus one Node per door or landing
Growth pathSame two CAN ports — add Nodes when neededSame two CAN ports, up to 63 Nodes each
Running costNo SIM, no data planConnectivity included with the Axon Network SIM
Deployment scenarios

Where AXON ICM-E fits

Typical configurations we size for integrators. Every scenario below is a planning example, not a customer reference.

Clinic · 4 doors

A whole building on one controller

Front entrance, staff door, records room and rear exit run from CH1 to CH4. One URX-Secure on the RS-485 port covers the entrance; the internal doors use the existing readers through the Wiegand port. No nodes, no CAN wiring, one Ethernet drop.

Office floor · retrofit

Keeping the readers already on the wall

A tenant fit-out inherits Wiegand readers at two doors. The ICM-E takes them on its Wiegand port and drives the existing strikes from its relays, so the visible hardware does not change while the decision moves on-site and the audit trail starts.

Commercial · phased

Four doors now, a riser later

A small building starts with the entrance and garage on the board. When the upper floors are fitted out, AXON Nodes go onto CAN port 1 on a twisted pair and the same controller, the same database and the same cards cover them.

Campus · wired site

Where a SIM makes no sense

A site with structured cabling and a managed switch has no use for a cellular modem, an antenna or a data plan. The ICM-E drops the lot and puts a dedicated VLAN port between the controller and the AXON cloud.

Questions integrators ask

AXON ICM-E FAQ

What exactly is different from the AXON Master (ICM-GE)?
Two things. The ICM-E has no cellular modem, SIM or antenna — Ethernet is its only uplink. And it carries four relay channels plus an RS-485 and a Wiegand reader port on the board, so the first doors need no AXON Node. The decision engine, the card database, the encrypted CAN buses and the cloud role are the same.
Can I still add floor nodes later?
Yes. Both CAN ports are fitted and each addresses up to 63 AXON Nodes. A site can start with the four on-board doors and grow onto the bus without replacing the controller or re-issuing cards.
Can I mix an encrypted AXON reader and an old Wiegand reader?
Yes — one of each connects directly, and both supply 12 V to the reader from the same terminal block. Bear in mind that Wiegand carries the card number in the clear on the cable, so use the RS-485 port for the doors that matter most.
What happens if the network drops?
Nothing at the door. The card database is on the board and the decision never leaves it. Events are recorded locally and reported when the link returns; the cloud is only used for database sync, reporting and firmware.
Which one should I buy?
Take the ICM-E when the site has a switch port and four doors or fewer to start with. Take the ICM-GE when there is no wired uplink, when the building is large enough to need nodes from day one, or when you want the connectivity to come with the product rather than from the building's IT.
Is it available now?
The v1.4 board is in development. The architecture, the terminal layout and the role are settled; final electrical ratings and availability are published at production release. Pilots on planned installations can be arranged with us directly.
Size it for your building

Four doors, or forty?

Tell us the entrances, doors and readers. We will say whether the ICM-E covers it on its own, or whether the ICM-GE and per-floor nodes are the better fit.