FAQ & support

Straight answers about AXON Access

How it decides, what the cards protect, what an installation needs.

The questions integrators, building owners and elevator companies ask us most, answered from the firmware and the product documentation rather than from a brochure. If your question is not here, call or write to us — Monday to Friday, 09:00–17:00.

Access decision made locally
MIFARE DESFire EV3 cards
AES-128 encrypted RS-485 and CAN
Cloud only for sync, logs and OTA
System

How the system works

AXON is two independent subsystems that both talk directly to the server: the elevator cabin, and the building side — landings, entrances, doors and gates. Each has its own master that decides on the board.

How does the AXON system work?
There are two subsystems. Inside the elevator cabin, the AXON CCU-32 cabin master talks to URX-Secure readers over encrypted RS-485. On the building side, the AXON ICM-GE external master talks to one AXON Node per floor or door over encrypted CAN, with readers behind each node on RS-485. Each master holds the card database locally and decides offline; the cloud only synchronises the database, collects logs and delivers firmware.
What happens when a card is tapped in the elevator?
The cabin reader authenticates the MIFARE DESFire EV3 card with AES and sends an encrypted card event to the CCU-32 over RS-485. The controller checks its local permissions and replies grant or deny within the reader's 1-second window. On a grant, the relay for each allowed floor pulses for 3 seconds so the passenger can press that button. The event is logged and published over MQTT.
What happens at a landing, entrance or garage gate?
The reader authenticates the card and hands the event to the AXON Node, which forwards it over CAN to the ICM-GE master. The master looks it up in its on-board 4 MB database — a binary search with a design target under 2 ms — checks blocked flag, floor mask and validity date, and returns a verdict with a relay mask. The node pulses relays only on the master's instruction.
What happens if the internet connection drops?
Nothing changes at the door or in the cabin. Both masters keep deciding from their last synchronised database and append every event to a local log. When Ethernet or the cellular fallback returns, the log is pushed and database updates are pulled. The cloud is never in the access path, so an outage degrades visibility, not operations.
Does AXON also control garages, ramps and doors, not only elevator floors?
Yes. Each AXON Node is set by DIP switch as a floor, door, garage or ramp device, and the ICM-GE master covers landings, building entrances, internal doors and gates. Where an access point needs extra outputs — a strike plus a light, a gate plus an alarm — the RBN-2 or SC-E dual-relay modules add addressed relays on the same encrypted bus.
Is AXON only for large buildings?
No — and there is no upper limit either. A single entrance, garage or private building can run one master with one or two nodes and be managed from the mobile app. The same hardware scales to a tower of any height: up to 120 access points per CAN port, 240 per master, masters added side by side without limit, and 32 relay outputs per cabin unit with units chaining for taller panels.
Credentials

Cards & security

AXON does not trust a card's serial number. Every credential must prove it holds the right key, and every wire between reader, node and master is encrypted and authenticated.

Which cards does AXON use?
NXP MIFARE DESFire EV3, authenticated with AES-128 against the AXON ACCESS application on the card. Other NFC-A cards — MIFARE Classic, NTAG, foreign DESFire — are ignored by default. The reader never grants on a serial number alone: a card that fails mutual authentication is treated as if nothing was tapped, and can be reported to the master for logging only.
Can an AXON card be cloned?
Copying the UID is not enough. Each card carries a key derived for that specific card, and the reader challenges it with an AES mutual authentication before it will report anything as authenticated. A copied serial number without the key fails the challenge and produces no grant. This is the difference from UID-only or Wiegand-26 systems, where the number on the wire is the credential.
Is the wiring between reader, node and controller encrypted?
Yes, on both buses. Reader and master perform a 3-pass AES handshake and derive a session key; every access frame is AES-CTR encrypted and carries a counter plus an 8-byte CMAC. A stale counter or bad MAC is ignored, and eight bad frames lock the link for 5 seconds. On CAN, each node has its own AES-128 key derived from the master's root key; a compromised board exposes only itself.
How is the connection to the cloud secured, and what does it carry?
Masters connect over MQTT with TLS to AWS IoT, Ethernet first and cellular as fallback. The link carries database synchronisation, event batches and firmware — never an access decision. Firmware images download over HTTPS into a staging slot and are checked for magic tag, version and CRC32 before being applied, so an interrupted update leaves the running firmware in place.
If I keep my old Wiegand readers, is the system still secure?
Partly. The AXON AMS converter sits in the reader's back box and puts everything from there onward on the addressed, encrypted RS-485 bus, so a tap on the long cable run no longer yields a usable credential. But a MIFARE Classic UID can still be sniffed at the reader itself. For end-to-end protection, move the card population to DESFire EV3 and fit URX-Secure readers on the highest-risk doors first.
Integrators

Installation & compatibility

The system is built for retrofits: existing elevators keep their button panels, existing readers can stay during migration, and the buses run on twisted pair.

Does AXON work with my existing elevator?
In most cases, yes. The CCU-32 drives one relay per floor button, enabling or leaving disabled the buttons a card is entitled to; the elevator's original call-button wiring is not redesigned and the elevator controller brand does not matter. One unit covers 32 floors and units chain for taller buildings, so there is no upper limit on floors. For direct integration with the elevator controller's own command interface, ELM-GE is in development.
Can I keep the readers that are already installed?
Yes, for a migration period. A standard Wiegand-26 reader wires directly to the CCU-32's D0/D1 inputs, and the AXON AMS (W2R-N) converter brings Wiegand 26/34 readers onto the RS-485 bus behind any master or node. Both paths keep the credential in cleartext at the reader, so plan to replace them with URX-Secure readers as budget allows.
What cabling and power does an installation need?
Readers connect over RS-485 twisted pair, with cabin reader cable under 30 m recommended. Floor nodes hang on Classic CAN at 250 kbit/s, 120 Ω terminated at both ends of each segment — up to 120 access points per port and two ports per master. Boards run from 12–24 V DC: the CCU-32 draws 3–6 W (allow 10 W with the reader), the DIN-rail ICM-GE 4–8 W with a 15 W supply.
Does the building need internet or a network cable to the cabin?
Not for access to work — decisions are made on the board. For synchronisation and logs, Ethernet is the primary uplink. If no cable reaches the cabin, the CCU-32 falls back to a SIM7000G LTE-M / NB-IoT modem with an external antenna; the ICM-GE falls back to an LTE Cat-1 modem with a local carrier SIM. Traffic is small — events, status, occasional firmware — so data use stays modest.
Which AXON products are shipping today?
Shipping from stock in Kosovo: CCU-32 cabin master, ICM-GE external master, AXON Node, RBN-2 and SC-E relay modules and the AMS Wiegand converter. In final testing with pilot units on request: URX-Secure reader and ICM-LR LoRa master. In development: ELM-GE, PBC-Bridge, SBT-TRF touch and biometric panel, and SSR-32. Ask us before specifying an in-development board in a tender.
Operations

Management, app & support

Cards, permissions, logs and firmware are managed from the AXON web dashboard and mobile app. The controllers enforce; the platform administers.

How do I manage cards and access permissions?
From the AXON web dashboard or the mobile app. You add, block or modify each user's card and set which floors, doors, garages or ramps it may use, with a validity date where needed. Changes are pushed to the masters on the next synchronisation and enforced there — the master checks that the card exists, is not blocked, has the floor bit set and is still valid.
Can I manage the system remotely and open a door or gate from my phone?
Yes. Permissions, device status and event history are available wherever you have the dashboard or app, and a building manager can send a standalone relay command to open a gate or door without being on site. Day-to-day access decisions still happen locally on the master, so remote management never becomes a dependency for residents to get in.
What is logged, and are there notifications?
Every grant and deny is written to the master's local log with its reason — unknown card, blocked, no floor permission, expired — the moment the decision is made, and synchronised to the server when a link is available. The dashboard and app then show event history per device and can notify you of reader or device faults, offline nodes and cards approaching expiry, by email or in the app.
How are firmware updates handled — do you need a site visit?
No. Firmware arrives over the air through the cloud link. The controller keeps two slots in flash: a new image downloads over HTTPS into the staging slot, its magic tag, version and CRC32 are verified, and only then is it applied. An interrupted download leaves the running firmware untouched, so an update that fails halfway never takes a building offline.
How do I get pricing, a quotation or technical support?
Call +383 48 296 722 or use the contact form, Monday to Friday 09:00–17:00. Tell us the floor count, cabins, entrances and gates and whether cabling reaches the cabin, and we size the masters, nodes, readers and uplinks for your building. Pricing is on request. AXON is designed and built in Prishtinë and serves Kosovo, Albania, North Macedonia and B2B partners across Europe.
Still have a question?

Ask the engineers who built the system

Send us the details of your building — floors, cabins, entrances, gates and existing readers — and we will answer with a configuration, not a brochure.