Access control for electronic blasting machines
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- ORICA INTERNATIONAL PTE LTD
- Filing Date
- 2024-06-13
- Publication Date
- 2026-04-22
AI Technical Summary
Existing electronic blasting systems face challenges in securely and efficiently registering a large number of remote blasters, particularly in scenarios where physical dongles need to be transported across significant distances, such as underground mining operations, which is time-consuming and risky.
A system utilizing a central controller that provides a public-private asymmetric encryption key pair to remote blasters, enabling secure communication and eliminating the need for physical dongle transportation by using a remote registration device to transfer and store configuration keys, allowing blasters to communicate securely via a data network.
This solution enables secure and efficient registration of multiple remote blasters without the need for physical dongle transportation, enhancing security and reducing the time and risk associated with changing blasting plans, allowing for up to thousands of blasters to connect securely to the central controller.
Smart Images

Figure SG2024050395_19122024_PF_FP_ABST
Abstract
Description
ACCESS CONTROL FOR ELECTRONIC BLASTING MACHINESRELATED APPLICATION
[0001] The present patent application is related to Singaporean Patent Application No. 10202301672W, entitled "Access Control For Electronic Blasting Machines" and filed on 13 June 2023 in the name of Orica International Pte Ltd. the as-filed specification of which is hereby incorporated herein by reference in its entirety.TECHNICAL FIELD
[0002] Aspects of the present disclosure relate to systems and methods that provide sccunty and access control in commercial blasting operations having remotely controlled electronic blasting systems with detonators / initiators, including by preventing unauthorized operation of the blasting systems. Such electronic blasting systems may include wireless electronic blasting (WEB) systems. Such commercial blasting operations may include surface mining operations, underground mining operations, quarrying operations, demolition operations, and / or seismic surveying.BACKGROUND
[0003] In order to achieve security in prior remote blasting systems, two phy sical dongles may have been required to initiate a blast successfully, including a remote dongle and a firing dongle. At startup of a remote blaster (also known as a “remote electronic blasting machine”), an individual physical remote dongle was written by the remote blaster with details of the remote blaster, such as attached loggers, number of detonators, serial numbers of the devices attached to the remote blaster, its ID number, and a random digital key generated by the remote blaster. A human operator took the physical remote dongle back to ablasting system controller (also known as the “controller blaster”, “control station”, “control blaster”, or “central command station”) to register the remote blaster, e.g., see US Patent Ser. No. 6851369 (“Access control for electronic blasting machines”, Feb. 08, 2005, to Orica Explosives Technology Pty Ltd, with inventors Dirk Hummel and Olaf Cramer). Only a registered remote blaster was taklen into consideration for the next blasting sequence. The random digital key on the remote dongle was used to encrypt information transmitted between the blasting system controller and the remote blaster. After initialization of the remote blaster via the blasting system controller, the firing dongle was required at the blasting system controller to enable activation of firing voltage on the remote blasters. The firing dongle enabled activation of the firing voltage and stored the final FIRE c ommands, thus only if the firing dongle was inserted into a communication port of the controller (e.g., its 7-pin port, or a USB port) was the operator able to progress the blasting sequence. After pressing the fire keys on the blasting system controller, the blasting system controller read out the FIRE commands from the firing dongle. Those commands were required to initiate the detonators attached to the remote blaster.
[0004] However, in applications where a large number of remote blasting machines or remote blasters is required, e.g., over 100 remote blasting machines, carr i ng physical dongles or authorization keys from each remote blasting machine back to the controller may be too slow / difficult within relevant time limits, particularly when there is a change in the blasting plans, e.g., when the remote blasting machines are underground, and the blasting system controller is on the surface (thus not underground) and some distance away, e.g., accessed by a slow elevator, while still ensuring the remote blasters are securely and reliably registered at the blasting system controller. For example, in underground mining, more detonators may be connected ready for blasting than are eventually required (depending on effects of earlier blasts), and it may be undesirable / dangerous to take physical dongles or authorization keys from each remote blaster back to the blasting system controller when there is a change in the blasting plan.
[0005] It is desired to address or ameliorate one or more disadvantages or limitations associated with the prior art, or to at least provide a useful alternative.SUMMARY
[0006] In accordance with the present invention, there is provided a system for access control of an electronic blasting system, the system including: a physical remote registration device configured to communicatively connect to a central controller of the electronic blasting system and to a plurality of remote blasters of the electronic blasting system, the central controller configured to provide a public -private asymmetric encryption key pair with a public key and a private key, and to write the public key to the remote registration device when the remote registration device is communicatively connected to the controller; and each remote blaster configured to read the public key from the remote registration device when the remote registration device is communicatively connected to the remote blaster, wherein each remote blaster and the central controller are configured to communicate with each other via a data network using the key pair.
[0007] In one or more embodiments, each remote blaster is configured to provide a handshake encryption key that is unique / quasi-unique to each remote blaster, and to encrypt and send the handshake encryption key to the central controller using the public key and the data network.
[0008] In one or more embodiments, the central controller is configured to provide a communications encryption key that is unique / quasi-unique to each remote blaster, and to encrypt and send the communications encryption key in a second handshake message to each remote blaster using the handshake key and the data network.
[0009] In one or more embodiments, the central controller and the remote blaster arc configured communicate using the communications encryption key and the data network.
[0010] In one or more embodiments, the central controller is configured to provide a broadcast encryption key that is not unique / quasi-unique to each remote blaster, and to send the broadcast encryption key to each remote blaster using the data network.
[0011] In one or more embodiments, the central controller is configured to encrypt and send blasting command instructions to each remote blaster using the broadcast encryption key and the data network.
[0012] In accordance with the present invention, there is provided method for access control of an electronic blasting system, the method including: a central controller of the electronic blasting system providing a public-private asymmetric encryption key pair with a public key and a private key; the central controller communicatively connecting to a physical remote registration device to write the public key to the remote registration device; each of a plurality of remote blasters of the electronic blasting system separately communicatively connecting to the remote registration device to each separately read the public key, and each of the remote blasters communicating with the central controller via a data network using the public key.
[0013] Tn one or more embodiments, the method includes each remote blaster providing a handshake encryption key7that is unique / quasi-unique to each remote blaster, and encrypting and sending the handshake encryption key to the central controller using the public key and the data network.
[0014] In one or more embodiments, the method includes the central controller providing a communications encry ption key that is unique / quasi-unique to each remote blaster, andencrypting and sending the communications encryption key in a second handshake message to each remote blaster using the handshake key and the data network.
[0015] In one or more embodiments, the method includes the central controller and the remote blaster communicating using the communications encryption key and the data network.
[0016] In one or more embodiments, the method includes the controller providing a broadcast encryption key that is not unique / quasi-unique to each remote blaster, and sending the broadcast encryption key to each remote blaster using the data network.
[0017] In one or more embodiments, the method includes the central controller encrypting and sending blasting command instructions to each remote blaster using the broadcast encryption key and the data network.
[0018] In accordance with the present invention, there is provided a system for access control of an electronic blasting system, the system including: a central controller of the electronic blasting system, wherein the central controller has a secure communications interface; and a plurality of remote blasters of the electronic blasting system, wherein each remote blaster has a secure communications interface corresponding to the secure communications interface of the central controller, wherein the central controller is configured to provide a public-private asymmetric encryption key pair with a public key and a private key, and to write the public key individually to each of the plurality of the remote blasters when each remote blaster is connected via the secure communications interfaces, wherein each remote blaster configured to read the public key from the central controller when connected via the secure communications interfaces, andwherein each remote blaster and the controller arc configured to communicate with each other via a data network using the key pair.
[0019] In one or more embodiments, each remote blaster is configured to provide a handshake encryption key that is unique / quasi-unique to each remote blaster, and to encrypt and send the handshake encryption key to the controller using the public key and the data network.
[0020] In one or more embodiments, the central controller is configured to provide a communications encryption key that is unique / quasi-unique to each remote blaster, and to encrypt and send the communications encryption key in a second handshake message to each remote blaster using the handshake key and the data network.
[0021] In one or more embodiments, the central controller and the remote blaster are configured communicate using the communications encryption key and the data network.
[0022] In one or more embodiments, the central controller is configured to provide a broadcast encryption key that is not unique / quasi-unique to each remote blaster, and to send the broadcast encryption key to each remote blaster using the data network.
[0023] In one or more embodiments, the central controller is configured to encrypt and send blasting command instructions to each remote blaster using the broadcast encryption key and the data network.
[0024] In accordance with the present invention, there is provided a method for access control of an electronic blasting system, the method including: a central controller of the electronic blasting system providing a public-private asymmetric encryption key pair with a public key and a private key; the central controller communicatively connecting to each of a plurality of remote blasters of the electronic blasting system via secure communications interfaces to separately provide the public key to each remote blaster; andeach of the remote blasters communicating with the central controller via a data network using the public key.
[0025] In one or more embodiments, method includes each remote blaster providing a handshake encryption key that is unique / quasi-unique to each remote blaster, and encrypting and sending the handshake encryption key to the central controller using the public key and the data network.
[0026] In one or more embodiments, method includes the central controller providing a communications encryption key that is unique / quasi-unique to each remote blaster, and encrypting and sending the communications encryption key in a second handshake message to each remote blaster using the handshake key and the data network.
[0027] In one or more embodiments, method includes the central controller and the remote blaster communicating using the communications encryption key and the data network
[0028] In one or more embodiments, method includes the controller providing a broadcast encryption key that is not unique / quasi-unique to each remote blaster, and sending the broadcast encryption key to each remote blaster using the data network.
[0029] In one or more embodiments, method includes the central controller encrypting and sending blasting command instructions to each remote blaster using the broadcast encryption key and the data network.BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Some embodiments are hereinafter described, by way of example only, with reference to the accompanying drawings, in which: a) FIG. 1 is a schematic diagram of an electronic blasting system including an access control system for a plurality of electronic blasting machines (“remote blasters”); andb) FIG. 2 is a flow chart of an access control method performed by the access control system of FIG 1.DETAILED DESCRIPTIONSystem
[0031] As shown in FIG. 1, an electronic blasting system 100 (also referred to as a “centralised firing system”) disclosed herein includes an access control system for controlling access to and of a plurality of electronic blasting machines in the form of remote blasters 102 of the electronic blasting system 100.
[0032] The electronic blasting system 100 includes a central controller 104, which may also be referred to as a "central electronic blasting system controller", “central command station”, “controller blaster”, “controller” or "ORBS controller"
[0033] The central controller 104 is configured to transmit at least one blasting command instruction (e.g., representing a FIRE command) to either a selected one of the remote blasters 102, or a selected group of the remote blasters 102.
[0034] Each remote blaster 102 is substantially remote from the central controller 104, thus located at a significant spatial distance from the central controller 104 during operation, wherein the significant spatial distance can be as close as one meter up to several tens of kilometers.
[0035] The central controller 104 is configured to communicatively connect to each remote blaster 102 during configuration using a secure communications interface of the central controller 104 and a corresponding secure communications interface of the remote blaster 102, in some instances via a device-based secure communications interface of a remote registration device 106, described hereinafter.
[0036] In one or more implementations, the secure communications interface and the corresponding secure communications interface provide a direct communications connection between the central controller 104 and each of the remote blasters 102 individually or in turn (because the remote blasters 102 and generally configured one by one). In one or more implementations, the secure communications interface and the corresponding secure communications interface can include a wireless near-field communications interface, e.g., configured to communicatively connect using a radio-frequency identification (RFID) protocol or a Near-Field Communication (NFC) protocol. In one or more implementations, the secure communications interface and the corresponding secure communications interface can include a wireless short-range communications interface, e.g., configured to communicatively connect using a Bluetooth protocol, e.g., Bluetooth Low Energy. In one or more implementations, the secure communications interface and the corresponding secure communications interface can include a wired communications interface for use with a corresponding cable (having connector terminals) and / or a plug, e.g., configured to communicatively connect using a Universal Serial Bus interface and a USB cable, e.g., USB 3, or a One Wire Bus interface, or a Secure Digital (SD) interface. In one or more implementations, the secure communications interface and the corresponding secure communications interface can include a wired communications interface for use with a corresponding cable (having connector terminals), e.g., configured to communicatively connect using a Universal Serial Bus interface and a USB cable, e.g., USB 3. In use, the remote blaster 102 may be tested and configured in a secure room (accessible only by authorized persons) with the central controller 104. There may be a "commissioning day" for each area in a mine site, and the remote blasters 102 being commissioned on that day can be brought very' close to the central controller 104, e.g., touching the central controller 104 or connected by the corresponding cable (mentioned hereinbefore), without requiring a separate individual / unique physical configuration device to carry a configuration key 108 described hereinafter.
[0037] In one or more implementations, the secure communications interface of the central controller 104 provides a direct communications connection between the central controller 104 and the remote registration device 106. The remote registration device 106 is anindividual / uniquc physical device, which includes the device-based secure communications interface and a machine-readable memory for data storage, which may be described as "persistent memory", e.g., a flash memory’ chip. The remote registration device 106 reads the configuration key 108 from the central controller 104, stores the configuration key 108 in the machine-readable memory , and wntes the configuration key 108 to the connected remote blaster 102. The remote registration device 106 may be referred to as a "dongle" or "remote registration dongle", and the configuration key 108 may be referred to as a "dongle key". In these implementations, the corresponding secure communications interface of each of the remote blasters 102 provides a direct communications connection between the remote registration device 106 and each of the remote blasters 102 (in turn because the remote blasters 102 and generally configured one by one). In these implementations, the central controller 104 is not directly connected to the remote blasters 102 during commissions because the remote registration device 106 is instead used to transfer the public key generated by the central controller 104. In these implementations, it may be desirable to provide only- one remote registration device 106, or only a selected limited number of the remote registration device 106 that are able to transfer the public key, to improve the security’ of the remote blasters 102 and to thus improve site safety, hi one or more implementations, the secure communications interface, the device-based secure communications interface and the corresponding secure communications interface can include a wireless near-field communications interface, e.g., configured to communicatively connect using a radiofrequency identification (RFID) protocol or a Near-Field Communication (NFC) protocol. If the device-based secure communications interface is the wireless near-field communications interface, the remote registration device 106 may be powered by the wireless near-field communications interface to operate, and may be in the form an RFID card, NFC card, or smart card. In one or more implementations, the secure communications interface, the device-based secure communications interface and the corresponding secure communications interface can include a wireless short-range communications interface, e.g., configured to communicatively connect using a Bluetooth protocol, e.g., Bluetooth Tow Energy. In one or more implementations, the secure communications interface, the device-based secure communications interface and the corresponding secure communications interface caninclude a wired communications interface for use with a corresponding cable (having connector terminals) and / or a plug, e.g., configured to communicatively connect using a Universal Serial Bus interface and a USB cable, e.g., USB 3, or a One Wire Bus interface, or a Secure Digital (SD) interface. If the device-based secure communications interface is a USB interface, the remote registration device 106 may be referred to as a "USB dongle", "USB drive" or "thumb drive" and may be powered by the USB interface. The remote registration device 106 is a physical configuration device with a housing that can be carried by a person, e.g., by hand. The remote registration device 106 may be powered by the device-based secure communications interface to operate, as mentioned hereinbefore. Alternatively, the remote registration device 106 may have an internal power source that powers the device-based secure communications interface: in some implementations, the remote registration device 106 is a hand-held communications device — e.g., a smart / ccll phone or personal communicator (e.g., an iPhone) — with the machine-readable memory and the dcvicc-bascd secure communications interface installed, e.g., Bluetooth and / or NFC as in commercially available smart / cell phones. Hie remote registration device 106 may require personal authentication to operate the device-based secure communications interface, e.g., a biometric lock or user-password combination, e.g., a face identification or a finger / thumb print identification. In the implementations with the wired communications interface, the remote registration device 106 is physically connectable to the central controller 104, e.g., to be plugged into the port 110, to create the communications connection for receipt of the configuration key 108, and it physically connectable to each of the remote blasters 102, in turn, to create the communications connection for transmission of the configuration key 108 to the remote blaster 102. In use, having the separate individual / unique physical configuration device to carry the configuration key 108 may be more safe, secure and / or "idiot proof than allowing direct secure connections between the central controller 104 and the remote blasters 102. In some implementations, the remote registration device 106 can include a plurality of secure communications interfaces, including a first secure communications interface corresponding to the secure communications interface of the central controller 104, and one or more second secure communications interfaces corresponding to the secure communications interfaces of the remote blasters 102, such thatthe central controller 104 can have a different secure communications interface from one or more of the remote blasters 102, allowing flexibility and back compatibility between the central controller 104 and the remote blasters 102 — for example, if the remote registration device 106 is a smart / cell phone, it can receive the configuration key 108 (and other data described hereinafter) via USB or Bluetooth (a first device-based secure communications interface) from the central controller 104, and then transfer the configuration key 108 (and the other data) to the remote blasters 102 via NFC (a second device-based secure communications interface); however, some implementations may have just one device-based secure communications interface for testing and simplicity. It is noted that the device-based secure communications interface or interfaces do not limit the types of the second signals connections 112 that are established by the configuration key 108 and the other data: the second signals connections 112 can include a multitude of communications interfaces, including any one or more of LAN, 4G / 5G, radio modem, and telephone line.
[0038] In addition to its secure communications interface, the central controller 104 lias a data network connection to a data network (e.g., an existing mine network as desenbed hereinafter) that includes first signal connections 112, shown in FIG. 1, between the central controller 104 and each of the remote blasters 102. The first signal connections 112 are thus data network connections for electronic communication as described hereinafter.
[0039] The access control system includes the remote registration device 106.
[0040] The central controller 104 is configured to provide — by way of randomly generating or accessing — a public-private asymmetric encryption key pair with a public key and a private key, and to write the public key (also referred to herein as the configuration key 108) to each remote blaster 102 when connected to the secure communications interface either directly or via the remote registration device (when the remote registration device 106 is communicatively connected to the central controller 104, e g., in or to a port 1 10 of the central controller 104).
[0041] Each of the remote blasters 102 (also referred to as “remote blast boxes” or “remote blasting machines”) has a data network connection to the first signal connections 112 in thedata network. Each of the remote blasters 102 has a second signal connection 114 to at least one set of blast initiators / detonators 116. The second signal connection 114 can include: (i) a direct connection from a remote blaster 102 to its blast initiators / detonators 116; or (li) a connection via at least one logger between a remote blaster 102 and its blast initiators / detonators 116, e.g., at least one i-kon (TM) Logger.
[0042] Each remote blaster 102 is configured to receive the at least one blasting command instruction from the central controller 104 via the first signal connections 112.
[0043] The remote blasters 102 are configured to control the loggers and / or the initiators / detonators 116 via the respective second signal connections 114.
[0044] Each remote blaster 102 has a port 1 18 configured to connect and receive the remote registration device 106, and to access / read data on the remote registration device 106, specifically including the configuration key 108, whilst the remote registration device 106 is communicatively connected to the remote blaster 102 via electronic communication via the port 118. The port 118 is configured to support the secure communications protocols, which depend in the implementation, as described hereinbefore.
[0045] While the remote registration device 106 is communicatively connected one of the plurality of the remote blasters 102, that remote blaster 102 is configured to read the configuration key 108 from the remote registration device 106, including when the remote registration device 106 is physically connected to the remote blaster 102 (depending on the implementation) .
[0046] There is generally on lx one central controller 104 in the access control system, and the secure communications interface is generally arranged such that the configuration key 108 can be transferred to one remote registration device 106 or to the plurality of the remote blasters 102 at any time. In general, the remote registration device 106 ("dongle") is attached to one of the remote blasters 102 during commissioning. The remote registration device 106 ("dongle") may be one of potentially many separate physical devices, e.g.,multiple separate physical remote registration devices 106 (“dongles”) can be used to configure multiple remote blasters 102, essentially simultaneously.
[0047] Instead of, or in addition to the remote registration device 106, the system 100 can include a direct connection from the central controller 104 to each remote blaster 102 — separate from the first signal connections 112 — which can take the form of a cable connection, or other direct connection that does not itself store the configuration key 108 (and other configuration data) internally in its machine-readable memory . Thus the direct secure connection of the remote blaster 102 to the central controller 104 (e.g., via cable or wireless connection in the control room) may perform the function of the remote registration device 106 ("dongle"). In implementations where the central controller 104 transfers the configuration key directly to each remote blaster 102, the secure communications interface can connect to one or more of the corresponding secure communications interfaces at a time. In some implementations, multiple (e.g. ten) remote blasters 106 can be placed in a secure room (e.g., the control room) and set up largely simultaneously, using the secure communications interfaces (e.g., Bluetooth); this may be done at the same time as one or more remote blasters 102 are configured by one or more of the remote registration devices 106 ("dongles"), which may be relevant if there is an implementation with dozens of remote blasters 102. It may be desirable to use both secure communications interfaces simultaneously in some implementations, i.e., both the direct secure communications interface from the central controller 104 to each remote blaster 102 and the at least one remote registration device 106 ("dongle"), e.g., the remote registration devices 106 ("dongles") can be used to avoid needing to go to the control room from underground where the remote blasters 106 are installed remotely (e.g. for repairs, replacements, and resets), while the direct secure communications interface can be used in the control room to set up and install new remote blasters 106 (e.g., when installing new remotes, or commissioning new systems).
[0048] In implementations with the remote registration device 106, there may be a limited number of the remote registration devices 106, e.g., one, in the access control system, so while one of the plurality of the remote blasters 102 is communicatively connected to theremote registration device 106 (e.g., plugged into the port 118), the others of the plurality of the remote blasters 102 are not communicatively connected to the remote registration device 106. Alternatively, the access control system may include a plurality of the remote registration device 106, each having the configuration key 108, in which case the remote registration devices 106 are duplicates that allow many of the remote blasters 102 to be registered in parallel, e.g., in large mining operations.
[0049] The remote registration device 106 is physically transferable from the central controller 104, e.g., above ground, to each of the remote blasters 102, e.g., below ground, e.g., by a human operator. The remote registration device 106 needs to be transported to each of the remote blasters 102 for commissioning thereof, but only once each. For example, this need only happen one time at first introduction of each remote blaster 102 to the electronic blasting system 100. The configuration key 108 is stored on / in the remote blaster 102 permanently (for the duration of the blasting operation) and the configuration key 108 is used in every new blasting session to encrypt a handshake key 120, which is generated newly for each new blasting session.
[0050] As shown in FIG. 1, the encrypted symmetric handshake key 120 is sent to the central controller 104 in a first handshake message 122 (described hereinafter), which uses its private asymmetric key corresponding to the configuration key 108 to decrypt the first handshake message 122 and read / access / store the handshake key 120, and to send an encrypted second handshake message 126 (“handshake reply”) with a specific communications key 124 selected for each remote blaster 102. All further communication messages 130 between the central controller 104 and the remote blaster 102 can then be encrypted with the remote blaster's specific communications key 124.
[0051] Each remote blaster 102 is configured to provide — by way of randomly generating or accessing — the handshake key 120 that is unique / quasi-unique to the or each remote blaster 102, thus different from the handshake keys 120 of the other remote blasters 102 connected to the central controller 104. Accordingly, the handshake key 120 uniquely identifies each remote blaster 102 in the electronic blasting system 100.
[0052] Each remote blaster 102 is configured to encrypt its handshake key 120 with its received configuration key 108, and then send the encrypted handshake key 120 in the encrypted first handshake message 122 to the central controller 104 unit via the first signal connections 112.
[0053] The central controller 104 is configured to receive the encrypted first handshake message 122 (with the handshake key 120), and responsively to decrypt the encrypted first handshake message 122 using the private key — a copy of which is store / retained in / by the central controller 104, including after the remote registration device 106 has been removed from the central controller 104. Having decrypted the first handshake message 122, the central controller 104 is configured to read / access the handshake key 120 from the first handshake message 122 from each remote blaster 102.
[0054] The central controller 104 is configured to store the handshake keys 120 in a data store that associates / identifies the respective remote blasters 102 in a blast plan / blast planning data, thus allowing the central controller 104 to selectively send messages to selected remote blasters 102 using their respective handshake keys 120. In particular, the central controller 104 is configured to provide (generate / access) a third data encryption key in the form of a communications key 124 for each of the remote blasters 102, and to encrypt these communications keys 124 into encrypted messages for the remote blasters 102 in the form of the second handshake messages 126. The second handshake messages 126 each contain the communications kev 124 for a selected one of the remote blasters 102. The central controller 104 is configured to send the second handshake messages 126 to the respective remote blasters 102 using the first signal connections 112.
[0055] Each remote blaster 102 is configured to receive its one of the second handshake messages 126, and to then decrypt its second handshake message 126 using its handshake key 120 that it stored / retained after sending the first handshake message 122. Each remote blaster 102 is configured to access its communications key 124 from the decrypted second handshake message 126, and to store / retain this communications key 124 for use in encrypting communications messages 130 to send to the central controller 104, and in decrypting communications messages 130 received from tire central controller 104. Thecentral controller 104 is configured to send blasting command instructions, c.g., representing the FIRE command, to each remote blaster 102 using the communications messages 130 that are encry pted by the central controller 104 for that remote blaster 102 using the communications key 124 associated with that remote blaster 102. The communications key 124, used by each remote blaster 102 and the central controller 104, thus establishes a form of encrypted communications channel between the central controller 104 and each respective remote blaster 102 based on the corresponding communications key 124. This use of encryption between the central controller 104 and each remote blaster 102 means the messages, including status messages from the remote blasters 102 and firing commands from the central controller 104, can be secure, and access to the operation of the electronic blasting system 100 can be safely and securely controlled, e.g., secure from unauthorised third party' manipulation, c.g., eavesdropping, manipulation, spoofing or other forms of ’‘hacking”.
[0056] In addition to the communications messages 130, which arc encry pted with the communications key 124 uniquely associated with one of the remote blasters 102, and sent to that remote blaster 102, the central controller 104 may be configured to generate, encrypt and send broadcast messages 132, which are sent to all remote blasters 102, e.g., substantially simultaneously. The central controller 104 may be configured encrypt and send the broadcast message 132 with all of the plurality of the communications keys 124 respectively so that all of the plurality of the remote blasters 102 can deciy pt and read one instance of the broadcast message 132. Alternatively, the central controller 104 may provide (generate / access) and store / use a fourth data encryption key in the form of a broadcast key (not shown) that can be distributed to the plurality of the remote blasters 102 (at least to every active remote blaster 102). Once all of the active remote blasters 102 have received the broadcast key, it allows all active remote blasters 102 to understand the encrypted broadcast / multicast messages 132 (encrypted with the broadcast key). The broadcast key is distributed by the communications messages 130, or in the second handshake message 126, so each remote blaster 102 can access, read and store a copy of the broadcast key, and then use that broadcast key to decrypt the broadcast message 132. In embodiments, communications key 124 is different for each remote blaster 102, therefore only the communication between central controller 104 and an individual one of the remote blasters 102 can be encrypted with the communications key 124,and, to send broadcast / multicast communication between the central controller 104 and the selected group (including two or more, or many, or all) of the remote blasters 102 at once (thus substantially simultaneously), the broadcast key is required, and the broadcast key is known / stored / accessed / used by all of the connected remote blasters 102 (that are members of the blast). The broadcast key can be the second symmetric key generated by the central controller 104, second to the communications key 124, which is the first symmetric key: in other words, the central controller 104 can generate two sets of mutually separate symmetric keys: one set for the communications keys 124 (including one key for each active remote blaster 102), and another set for broadcast keys (including perhaps just one key per blasting session or per group of blast initiators / detonators 116).
[0057] In summary , the access control system can provide and use at least the first three of the following four data encryption key sets: a) the configuration key pair, which is a public / private key pair (the configuration key 108 is the public key that is transported by / in the remote registration device 106 and the private key is kept secure in the central controller 104, stored in a secure data file system of the central controller 104), which is provided by the central controller 104 (e.g., during a configuration process, e.g., in response to a user input / command at the central controller 104), and which encrypts the first handshake message 122; b) the handshake key 120, which may be a symmetric key, which is stored in a data memory of the remote blaster 102, which is provided by the remote blaster 102 (e.g., during a registration process that includes registering the remote blaster 102 at the central controller 104 as an active blaster that can be used for a or the next blasting sequence), which is sent in the first handshake message 122 from the remote blaster 102 to the central controller 104 via the first signal connections 112, and which encrypts the second handshake message 126 (also referred to as the “handshake reply message”); c) the communications key 124, which may be a symmetric key, which is stored in a registry / database (also referred to as the “blaster manager”) of the central controller104, and in the data memory of the remote blaster 102, which is provided by the central controller 104 (e.g., by a router service of the central controller 104 during the registration process), which is sent in the second handshake message 126 from the central controller 104 to the remote blaster 102 via the first signal connections 112, and which encrypts the communications messages 130 (including any non- broadcast / multicast messages); and d) the broadcast key, which may be a symmetric key, which is stored in the registry / database of the central controller 104, and in the data memory of the remote blaster 102, which is provided by the central controller 104 (e.g., by a blasting service of the central controller 104 during a blast start process), which is sent in the second handshake message 126 or one of the communications messages 130 from the central controller 104 to the remote blaster 102 via the first signal connections 1 12, and which encrypts the broadcast messages 132 (including any broadcast / multicast messages).
[0058] In example implementations, the configuration key pair (including the shared configuration key 108) can provide RS A encryption, the handshake key 120 can provide AES encryption, the communications key 124 can provide AES encryption, and the broadcast key can provide AES encryption. In other example implementations, the configuration key pair can provide AES encryption, or another suitable available encryption.
[0059] The configuration key 108 may be 1024 bits long, and may be used for two or more, or many, blasts. The configuration key pair need only be selectively re-generated, e.g., at the end of a site life cycle. The configuration key pair may be generated using a toolbox function, e g., an OpenSSL toolbox function, in the central controller 104. The configuration key 108 may have a substantially greater complexity (based on bit length) than the handshake key 120, the communications key 124, and / or the broadcast key: having the communications key 124 and the broadcast key less complex than the configuration key 108 can allow for high security (as the configuration key 108 is hard to hack / break) while allowing for high system performance during the blasting operations (as cncr ptmg / dccrypting with thecommunications key 124 and the broadcast key is more efficient than with the configuration key pair)
[0060] The handshake key 120 may be generated by a function, e.g., an OpenSSL function, on the remote blaster 102. The handshake key 120 may be valid for one blasting session. In example implementations, the handshake key 120 may be 256 bits long.
[0061] The communications key 124 may be generated by an OpenSSL function in the central controller 104. The communications key 124 may be 256 bits long and / or may be valid for one blasting session (thus the communications key 124 may have the same complexity and / or duration as the handshake key 120). Although the communications key 124 may have the same complexity and / or duration as the handshake key 120, it can be preferable to generate and use the communications key 124 for the communications messages 130 (instead of just rc-using the handshake key 120) because it may be preferable to have the communications key 124 — which is the key used for most of the encrypted communication in the electronic blasting system 100 — provided by the central controller 104 rather than by the individual remote blasters 102, e.g., because there may be better security, monitoring and control of the central controller 104 than the individual remote blasters 102.
[0062] The broadcast key may be generated by an OpenSSL function in the central controller 104. The broadcast key may be 256 bits long and / or may be valid for one blasting session (thus the broadcast key may have the same complexity and / or duration as the handshake key 120 and / or the communications key 124).
[0063] The messages between the central controller 104 and each remote blaster 102 include the encry pted communications messages 130 and / or the broadcast messages 132. The messages between the central controller 104 and each remote blaster 102 may also include unencrypted messages, e.g., messages not related to safety, e.g., messages representing signal strength requests from the central controller 104 and / or representing signal strength answers from the remote blasters 102.
[0064] The access control system described herein allows the remote blasters 102 to securely and reliably register at the central controller 104, and to establish secure communications (by way of the encrypted messages 130,132) without the need to share any physical key / dongle each time the remote blaster 102 is switched on for blasting, or for each remote blaster 102 to have a physical dongle transferred from its remote location to a secure / central location of the central controller 104; once the configuration key 108 has been transferred to each remote blaster 102 during commissioning (in a commissioning process), the remote blasters 102 and the central controller 104 share the digital public and symmetric keys for a plurality of blasting sessions instead of having to carry / transport a physical dongle for each blasting session as in prior systems. After commissioning, each remote blaster 102 and the central controller 104 share the asymmetric key pair of the configuration key 108, consisting of the public key (existing on every’ remote blaster 102) and the private key (located on the central controller 104): on power-on, each remote blaster 102 provides the handshake key 120, which is sent, encrypted by the configuration key 108, to the central controller 104, which in turn decrypts it by means of the asymmetric private key (which is the private keycorresponding to the configuration key 108). After this decryption of the first handshake message 122 to obtain the handshake key 120, the asymmetric key (of the configuration key 108) is no longer used for this particular blasting session, and instead the communications key 124 is used for the blasting session.
[0065] Technical advantages of the access control sy stem described herein may include that a physical dongle / key only is required at first commissioning of the electronic blasting system 100: once the remote blasters 102 are registered at the central controller 104, substantial messages / communication between the central controller 104 and the remote blasters 102 is securely encrypted; e.g., in contrast to the system of US 6851369 that requires a separate dongle to be physically transported from each remote blaster 102, thus requiring many dongles to be physically7collected, carried and separately connected to its central controller for each blasting session. Unlike the system of US 68 1369, tire access control system described herein may allow for up to many, e.g., up to several thousands, of the remote blasters 102 to securely connect to the central controller 104, and connecting such a large number of remote blasters using prior technology may have been impractical or undesirable.
[0066] For improved security, the remote registration device 106 can only be crcatcd / writtcn by a person authenticated as a system administrator by way of a usemame / password combination provided to the central controller 104 by its secure user interface (Ul). Specifically, the central controller 104 is configured to only allow w riting of the configuration key 108 to the remote registration device 106 and / or directly to the remote blasters 102 (depending on the implementation) after successful authentication of the usemame / password combination of the system administrator in the central controller 104 by its secure user interface (UI).
[0067] In addition to the configuration key 108, the remote registration device 106 may carry / include system connection information representing a network location identifier (ID) of the central controller 104 in the data network that defines the first signal connections 112. The system connection information may include a static internet protocol (IP) address and / or a network port number of the central controller 104 on the data network. Each remote blaster 102 can be configured to read this system connection information from the remote registration device 106, and to use this system connection information to address / direct at least the first handshake message 122, and optionally the communications messages 130, to the central controller 104. Each remote blaster 102 can also be configured to recognise the communications messages 130 and / or broadcast messages 132 from the central controller 104 based on this system connection information.
[0068] The remote blasters 102 are configured to encode and send their remote network locations IDs to the central controller 104 in the encrypted first handshake message 122 and / or in the communications messages 130, and the central controller 104 is configured to decrypt the respective remote location IDs and store them associated with the identifiers of the remote blasters 102, e.g., in the blaster manager. For example, the remote network location ID may include an IP address and / or a network port number respectively of each remote blaster 102 on the data network. The network connections of the remote blasters 102 define remote ends of the first signal connections 112, and the network connection of the central controller 104 defines the other ends of the first signal connections 112. The central controller 104 uses the remote location IDs to addrcss / dircct at least the second handshakemessage 126 (“handshake reply”), and optionally the communications messages 130, to the selected ones of the remote blasters 102 The remote blasters 102 are configured to send additional characteristic information of the remote blaster 102 to the central controller 104 in the encry pted first handshake message 122 and / or in the communications messages 130, including one or more of: interface information, a blaster ID of the remote blaster 102, identification of loggers attached to the remote blaster 102, identification of the blast initiators / detonators 116 connected to the remote blaster 102, and other registration data described hereinafter. During operation, the communications messages 130 may carry' the following from the remote blasters 102 to the central controller 104: detonator / initiator information, including delay times, measured vibration data, and / or firing flags.
[0069] In summary, the encrypted messages generated, transmitted (via the first signal connections 1 12) and used by the access control system include: a) the first handshake message 122 (also referred to as the “handshake command” or “handshake CMD”), which is transmitted from each remote blaster 102 to the central controller 104, which is encry pted by the configuration key 108 (e.g., using RSA encryption), and which is used to provide initial contact / registration of each remote blaster 102 in the electronic blasting system 100, and to provide the handshake key 120 (a sy mmetric key) to the central controller 104 (for use in encrypting the second handshake message 126); b) the second handshake message 126 (also referred to as the “handshake reply”), which is transmitted from the central controller 104 to each remote blaster 102, which is encrypted by the handshake key 120 (e.g., using AES encryption), and which is used to send the communications key 124 to each remote blaster 102 (for use in encrypting the communications messages 130 to the central controller 104); c) the communications messages 130 from each remote blaster 102 to the central controller 104, which are encrypted by tire communications key 124 (e.g., using AES encryption), and which can include a register-blaster command that provides registration data of the remote blaster 102, including one or more of: a unique localblaster ID, a local password, a blaster scnal number, a blaster Alias, blaster remote interface address information, and the remote network locations IDs; d) the communications messages 130 from the central controller 104 to each remote blaster 102, which are encrypted by the communications key 124 (e.g., using AES encryption), and which can include: a register-blaster reply that confirms registration of each remote blaster 102 after processing of a corresponding the register-blaster command (correspondingly from each remote blaster 102), and / or provides a temporary blaster ID to each remote blaster 102; and e) the broadcast messages 132 from the central controller 104 to each remote blaster 102, which are encrypted by the broadcast key (e.g., using AES encryption), and which can include multicast or broadcast blasting commands.
[0070] As shown in FIG. 1, the access control system includes a further physical dongle, in addition to the remote registration device 106, in the form of a firing dongle 134. The central controller 104 is configured to only allow the blasting command instructions (representing the blasting commands and / or firing commands) to be sent in the messages 130,132 when the firing dongle 134 is physically coupled, or at least communicatively connected with, the central controller 104. The firing dongle 134 is registered by the central controller 104. The UI asks to insert the firing dongle 134, and registration of the firing dongle 134 is performed in a back end of the central controller 104 in a dongle sendee. In most blasting operations, only one firing dongle 134 is valid as a time, and if a new firing dongle 134 is registered, any previous firing dongles 134 become invalid. Each remote blaster will only relay firing codes to the blast initiators / detonators 116 when in receipt of appropriate command(s) and data package(s) from the central controller 104 that can only be generated when the firing dongle 134 is connected.
[0071] As explained hereinbefore, the central controller 104 is configured to:a) provide (randomly generate or rcccivc / acccss) the communications key 124, which can be the first symmetric encryption key, and the broadcast key, which can be the second symmetric encryption key; b) transmit the communications key 124 to the remote blasters 102 using a first secure channel provided by the handshake key 120 and the first signal connections 112; c) establish a second secure channel using the communi cations key 124 and / or the broadcast key (tire second secure channel is not equal to the second signal connection because the second signal channel refers to communication on the first signal connection between the controller 104 and the remote blasters 102); and d) transmit commands / requests (e g., status requests, and / or multicast or broadcast blasting commands, e.g., a DISARM / DISABLE command or a FIRE command) to two or more of the remote blasters 102 via the second secure channel.
[0072] In use, the central controller 104 provides the configuration key 108 and the communications key 124, and optionally the broadcast key. The communications key 124 may be a static key that does not change after a blasting session is completed, or a dynamic random key that can be generated by the central controller 104 for every blasting session. The dynamic generation of a new communications key 124, and optionally a new broadcast key, may be triggered by a registration of a new one of the remote blasters 102 with the central controller 104.
[0073] In use, on commissioning of the electronic blasting system 100 on the site, each remote blaster 102 requires configuration using the central controller 104, which provides the configuration key 108 (including the public key) to each remote blaster 102. The central controller 104 has the secure communications interface to transmit the configuration key 108: (a) directly to the remote registration device 106 in some implementations, or (b) directly to the corresponding secure communications interface of each remote blaster 102, in other implementations. The central controller 104 generates the public-private key pair for the remote registration device 106, and stores the public key in the form of the configuration key108 on the physical remote registration device 106. The individual / uniquc physical remote registration device 106 is taken by a human operator and / or a remote / autonomous vehicle to each remote blaster 102 on the site. Each remote blaster 102 reads the configuration key (public key) and the connection information (described hereinbefore) from the remote registration device 106. Each remote blaster 102 generates the unique remote symmetric key in the form of the handshake key 120, which uniquely corresponds to the remote blaster 102, during the registration process. This handshake key 120 is encrypted by the remote blaster 102 using the configuration key 108 (public key) from the remote registration device 106. The encrypted handshake key 120 (symmetric key) is then used for a handshake process between the remote blaster 102 and the central controller 104. The central controller 104 decrypts the handshake key 120 using its private kev and uses the handshake key 120 to encry pt its own symmetric key in the form of the communications key 124 for further communication with the remote blaster 102. Further communication between the central controller 104 and the remote blasters 102 use the communications key 124 (symmetric keys) for encryption.
[0074] Tire communications key 124 may be stored in the central controller 104, e.g., in a service provided by the central controller 104 (e.g., a Docker (TM) sendee), depending on structural design of the central controller 104. Structurally, the central controller 104 may include a front end, including a web user interface, and the back end, which includes various services, and between the services and the front end there are included communication application programming interfaces (APIs). In example implementations, the central controller 104 may include a single-board computer, e.g., a BeagleBone (TM) computer, and the services may include the blasting service, the blasting manager, the dongle sendee, the UI, the router sendee, a proxy service and / or an LED senice.
[0075] The first signal connections 112 may include one or more communications connections in series and / or parallel between the remote blaster 102 and the central controller 104, e.g., communications connections including: a local area network (LAN), a wireless LAN (WLAN, e.g., WiFi), an LTE communications link, a Radio Frequency (RF) communications link, an analogue telephone line, and / or a leaky feeder network (e.g., usingcommercially available RF modems). The communications connections may form part of existing mine communications infrastructure, thus the communications connections may be used for communications between other on-site equipment, e.g., fortelephony / data communications, at the same time as being used for the first signal connections 112 because the first signal connections 112 are secured by the encryption and thus not accessible / readable / writable by any of the other on-site equipment.
[0076] The second signal connections 114 may include wired connections from the remote blaster 102 to its loggers and / or blast initiators / detonators 116, e.g., using a blasting cable or harness, or the second signal connections 114 may include a wireless connection from the remote blaster 102 to the blast initiators / detonators 116, e.g., using through-the-earth (TTE) magnetic induction (MI) signalling from the remote blaster 102 to the blast initiators / detonators 1 16, e.g., as used in Orica’s WebGen 200 (TM) wireless electronic blasting system. The second signal connections 114 may include a blasting cable connection to the one or more loggers if loggers are present, and harness wire connection from the loggers to the initiators / detonators 116.
[0077] The blast initiators / detonators 116 may include wireless electronic detonators or initiators, e g., Orica’s i-kon detonators, eDev (TM) detonators, and / or Orica’s WebGen 200 (TM) initiators.
[0078] The central controller 104 may communicate with the remote registration device 106, when it is connected to the port 110, using the dongle service, e.g., running in a container on the central controller 104. The central controller 104 may include additional services in respective containers, e.g., user interface (UI) services, blasting services (to control the blasting sequence), and blast manager services, as described hereinbefore.
[0079] Tire secure first signal connections 1 12 are used for two-way communications between the remote blasters 102 and the central controller 104 so the central controller 104 can monitor status of the remote blasters 102, and thus the connected initiators, during a programming sequence. The status may include: an active status, a no-reply status, an inactive status, and / or an errors status.
[0080] The remote registration device 106 includes the device-based secure communications interface, which can include one or more of a One Wire Bus, a Universal Serial Bus (USB) interface, a Secure Digital (SD) interface, radio-frequency identification (RFID) interface, Bluetooth (TM) interface, or Bluetooth Low Energy interface, as described hereinbefore, providing an interface to communicatively connect to the ports 110, 118), integrated with the machine-readable memory providing electronic non-volatile computer memory storage, e.g., flash memory. The remote registration device 106 may thus take the form of a USB dongle, USB “stick” or “thumb drive”, as described hereinbefore.
[0081] The remote blaster 102 may7include a waterproof / water resistant housing that protects the electronic components of the remote blaster 102 from water in the site, e.g., with an ingress protection (IP) rating of 54 or more, or 67 or more. The electronic components include a power source (e g., internal battery7and / or external power connection), modules for wircd / wirclcss communications (e.g., WiFi, Bluetooth, Ethernet, cellular chips) via the first signal connection, a microprocessor, machine-readable memory' that stores commands for the microprocessor, a port or Ml antenna for the second signal connections 114, and the port 118 for connection of the remote registration device 106 (e g., a physical data carrier interface, which may include a USB port, 1-wire port, proprietary dongle port, SD-card slot).
[0082] The central controller 104 may include a power source (e.g., external power source), modules for wired / wireless communications (e.g., WiFi, Ethernet, cellular chips) via the first signal connection, a microprocessor, machine-readable memory' that stores commands for the microprocessor (including an operating system and a user interface), and the port 110 for connection of the remote registration device 106 (e g., a physical data carrier interface, which may7include a USB port, 1-wire port, proprietary dongle port, SD-card slot). The central controller 104 includes the port for connection of the firing dongle 134 (e.g., a physical data carrier interface, which may include a USB port, 1-wire port, proprietary dongle port, SD- card slot).
[0083] Tire blasting commands include ARM, FIRE, or DISARM commands. The FIRE command is the same for all of the blast initiators / detonators 116, it also does not include the delay information, which is programmed by the loggers / blaster at an earlier programmingtime. Each of the blast initiators / detonators 116 has a device ID which is read by the logger / scanner during blast preparation. The device ID is associated with the delay time. At blasting, each of the blast initiators / detonators 116 gets programmed with its assigned delay time, addressed by the device ID, from a blasting plan. After sequentially programming each of the blast initiators / detonators 116, the blast gets armed (by sending an ARM command) and then fired (by sending a FIRE command). The ARM and FIRE command are broadcast commands in the broadcast messages 132 to all of the blast initiators / detonators 116 in the blast.Method
[0084] As shown in FIG. 2, the electronic blasting system 100 is configured to perform a method 200, which includes: a) the central controller 104 generating the configuration key pair and the communications key 124 for each blasting session (202); b) the central controller 104 writing the configuration key 108 (and the system connection information) to the remote registration device 106 whilst it is communicatively connected to the port 110 (204) — or in other implementations, writing the configuration key 108 directly from the central controller 104 to each of the remote blasters 102 individually or in turn by the secure communications connections described hereinbefore; c) the remote registration device 106 physically being transported, and thus transporting the configuration key 108 to each remote blaster 102 (206) — or in other implementations, each of the remote blasters 102 receiving the configuration key 108 directly from the central controller 104 instead of via the remote registration device 106;d) each remote blaster 102 generating the handshake key 120 in the registration process (208); e) each remote blaster 102 reading the configuration key 108 (and the system connection information) from the remote registration device 106 whilst it is communicatively connected to the port 118 (210); f) each remote blaster 102 encoding the handshake key 120 using the configuration key 108 to generate the first handshake message 122 (212); g) each remote blaster 102 sending the first handshake message 122 to the central controller 104 via the first signal connections 112 (214); h) the central controller 104 decrypting the first handshake message 122 using the configuration key 108 to access the handshake key 120 (216); i) the central controller 104 encrypting the communications key 124 using the handshake key 120 to generate the second handshake message 126 (also referred to as the “handshake reply”) (218); j) the central controller 104 sending the second handshake message 126 to each remote blaster 102 via the first signal connections 112 (220); k) each remote blaster 102 receiving and decrypting the second handshake message 126 using the handshake key 120 to access the communications key 124 (222); l) each remote blaster 102 encry pting information for the central controller 104 using the communications key 124 and sending these communications messages 130 to the central controller 104 via the first signal connections 112 (224); m) the central controller 104 receiving and decrypting the communications messages 130 from each remote blaster 102 using the communications key 124 to access the information from each remote blaster 102 (226);n) the central controller 104 encrypting information for each remote blaster 102 using the communications key 124 and sending these communications messages 130 to each remote blaster 102 da the first signal connections 112 (228); o) each remote blaster 102 receiving and decrypting the communications messages 130 from the central controller 104 using the communications key 124 to access the information from the central controller 104 (230); p) the central controller 104 encrypting broadcast information for the plurality of remote blasters 102 using the broadcast key and sending these communications messages 130 to the plurality of remote blasters 102 via tire first signal connections 112 (232); and q) the plurality of remote blasters 102 receiving and decrypting the broadcast messages 132 from the central controller 104 using the broadcast key to access the broadcast information from the central controller 104 (234).Interpretation
[0085] The process of encrypting described herein may also be referred to as “encoding”, and correspondingly the process of decrypting described herein may also be referred to as “decoding”.
[0086] The term “initiation” refers to the initiation or triggering of combustion, a deflagration, a deflagration to detonation transition (DDT), or detonation in a material or substance carrying an explosive composition, and the associated formation of different chemical species, or the initiation of chemical reactions that result in combustion and the associated formation of different chemical species in the material or substance. The term “explosive initiation” refers to initiation giving rise to an explosion or detonation, the occurrence of which corresponds to or is defined by at least some of a rapid energy release, volume increase, temperature increase, and gas production or release, as well as the generation of at least a subsonic shock wave. The term “detonation” refers to the generationof a supersonic detonation wave or shock front in an explosive material or substance, in a manner understood by individuals having ordinary skill in the relevant art.
[0087] The term “commercial blasting operation” includes the initiation and / or detonation of explosive materials or substances disposed in the physical media, e.g., a geological formation, by way of initiation devices as part of mining, quarrying, civil construction / demolition, seismic exploration, and / or another non-military blasting operation. Such initiation and / or detonation explosively blasts, e.g., fractures and / or heaves, or the physical media in which the commercial blasting operation occurs. Such initiation and / or detonation can be referred to as blasting, in a manner readily understood by individuals having ordinary7skill in the relevant art. The physical media in which the commercial blasting operation occurs is located in a commercial blasting environment, such as a mining environment, e.g., an open cut or underground mine.
[0088] As used herein, the tenn “set” corresponds to or is defined as a non-empty finite organization of elements that mathematically exhibits a cardinality of at least 1 (i.e., a set as defined herein can correspond to a unit, singlet, or single element set, or a multiple element set), in accordance with known mathematical definitions (for instance, in a manner corresponding to that described in An Introduction to Mathematical Reasoning: Numbers, Sets, and Functions, "Chapter 11 : Properties of Finite Sets" (e.g., as indicated on p. 140), by Peter J. Eccles, Cambridge University Press (1 98)). Thus, a set includes at least one element. In general, an element of a set can include or be one or more portions of a system, an apparatus, a device, a structure, an object, a process, a procedure, physical parameter, or a value depending upon the type of set under consideration.
[0089] The FIGs. included herewith show aspects of non-limiting representative embodiments in accordance with the present disclosure, and particular structural elements shown in the FIGs. may not be shown to scale or precisely to scale relative to each other. The depiction of a given element or consideration or use of a particular element number in a particular FIG. or a reference thereto in corresponding descriptive material can encompass the same, an equivalent, an analogous, categorically analogous, or similar element or element number identified in another FIG. or descriptive material associated therewith. Hie presenceof " / " in a FIG. or text herein is understood to mean "and / or" unless otherwise indicated, i.c., “A / B” is understood to mean “A” or “B” or “A and B”. The recitation of a particular numerical value or value range herein is understood to include or be a recitation of an approximate numerical value or value range, for instance, within + / - 20%, + / - 15%, + / - 10%, + / - 5%, + / - 2.5%, + / - 2%, + / - 1%, + / - 0.5%, or + / - 0%. The term "essentially all" or "substantially" can indicate a percentage greater than or equal to 50%, 60%, 70%, 80%, or 90%, for instance, 92.5%, 95%, 97.5%, 99%, or 100%.
[0090] Many modifications will be apparent to those skilled in the art without departing from the scope of the present invention. Reference to one or more embodiments herein, e.g., as various embodiments, many embodiments, several embodiments, multiple embodiments, some embodiments, certain embodiments, particular embodiments, specific embodiments, or a number of embodiments, need not or does not mean or imply all embodiments.
[0091] Throughout this specification and the claims which follow, unless the context requires otherwise, the word "comprise", and variations such as "comprises" and "comprising", will be understood to imply the inclusion of a stated integer or step or group of integers or steps but not the exclusion of any other integer or step or group of integers or steps.
[0092] The reference in this specification to any prior publication (or information derived from it), or to any matter which is known, is not, and should not be taken as an acknowledgment or admission or any form of suggestion that the prior publication (or information derived from it) or known matter forms part of the common general knowledge in the field of endeavour to which this specification relates.
Claims
CLAIMS1. A system for access control of an electronic blasting system, the system including: a physical remote registration device configured to communicatively connect to a central controller of the electronic blasting system and to a plurality of remote blasters of the electronic blasting system; the central controller configured to provide a public -private asymmetric encryption key pair with a public key and a private key, and to write the public key to the remote registration device when the remote registration device is communicatively connected to the controller; and each remote blaster configured to read the public key from the remote registration device when the remote registration device is communicatively connected to the remote blaster, wherein each remote blaster and the central controller arc configured to communicate with each other via a data network using the key pair.
2. The system of claim 1, wherein each remote blaster is configured to provide a handshake encryption key that is unique / quasi-unique to each remote blaster, and to encrypt and send the handshake encryption key to the central controller using the public key and the data network.
3. The system of claim 2, wherein the central controller is configured to provide a communications encry ption key that is unique / quasi-unique to each remote blaster, and to encrypt and send the communications encryption key in a second handshake message to each remote blaster using the handshake key and the data network.
4. The system of claim 3, wherein the central controller and the remote blaster arc configured communicate using the communications encryption key and the data network.
5. The system of any one of claims 2 to 4, wherein the central controller is configured to provide a broadcast encryption key that is not unique / quasi-unique to each remote blaster, and to send the broadcast encryption key to each remote blaster using the data network.
6. The system of claim 5, wherein the central controller is configured to encrypt and send blasting command instructions to each remote blaster using the broadcast encryption key and the data network.
7. A method for access control of an electronic blasting system, the method including: a central controller of the electronic blasting system providing a public-private asymmetric encryption key pair with a public key and a private key; the central controller communicatively connecting to a physical remote registration device to write the public key to the remote registration device; each of a plurality of remote blasters of the electronic blasting system separately communicatively connecting to the remote registration device to each separately read the public key; and each of the remote blasters communicating with the central controller via a data network using the public key.
8. The method of claim 7, including each remote blaster providing a handshake encry ption key that is unique / quasi-unique to each remote blaster, and encry pting and sending the handshake encryption key to the central controller using the public key and the data network.
9. The method of claim 8, including the central controller providing a communications encryption key that is unique / quasi-unique to each remote blaster, and encrypting and sending the communications encryption key7in a second handshake message to each remote blaster using the handshake key and the data network.
10. The method of claim 9, including the central controller and the remote blaster communicating using the communications encryption key and the data network.
11. The method of any one of claims 8 to 10, including the central controller providing a broadcast encryption key that is not unique / quasi-unique to each remote blaster, and sending the broadcast encryption key to each remote blaster using the data network.
12. The method of claim 11, including the central controller encrypting and sending blasting command instructions to each remote blaster using the broadcast encryption key and the data network.
13. A system for access control of an electronic blasting system, the system including: a central controller of the electronic blasting system, wherein the central controller has a secure communications interface; and a plurality of remote blasters of the electronic blasting system, wherein each remote blaster has a secure communications interface corresponding to the secure communications interface of the central controller, wherein the central controller is configured to provide a public-private asymmetric encryption key pair with a public key and a private key, and to write the public key individually to each of the plurality of the remote blasters when each remote blaster is connected via the secure communications interfaces, wherein each remote blaster configured to read the public key from the central controller when connected via the secure communications interfaces, and wherein each remote blaster and the central controller are configured to communicate with each other via a data network using the key pair.
14. The system of claim 13, wherein each remote blaster is configured to provide a handshake encryption key that is unique / quasi-unique to each remote blaster, and to encryptand send the handshake encryption key to the controller using the public key and the data network.
15. The system of claim 14, wherein the central controller is configured to provide a communications encry ption key that is unique / quasi-unique to each remote blaster, and to encrypt and send the communications encryption key in a second handshake message to each remote blaster using the handshake key and the data network.
16. The system of claim 15, wherein the central controller and the remote blaster are configured communicate using the communications encryption key and the data network.
17. The system of any one of claims 14 to 16, wherein the central controller is configured to provide a broadcast encryption key that is not unique / quasi-unique to each remote blaster, and to send the broadcast encryption key to each remote blaster using the data network.
18. The system of claim 17, wherein the central controller is configured to encrypt and send blasting command instructions to each remote blaster using the broadcast encryption key and the data network.
19. A method for access control of an electronic blasting system, the method including: a central controller of the electronic blasting system providing a public-private asymmetric encryption key pair with a public key and a private key; the central controller communicatively connecting to each of a plurality of remote blasters of the electronic blasting system via secure communications interfaces to separately provide the public key to each remote blaster; and each of the remote blasters communicating with the central controller via a data network using the public key.
20. The method of claim 19, including each remote blaster providing a handshake encryption key that is unique / quasi-unique to each remote blaster, and encrypting andsending the handshake encryption key to the central controller using the public key and the data network.
21. The method of claim 20, including the central controller providing a communications enciyption key that is unique / quasi-unique to each remote blaster, and encrypting and sending the communications encryption key in a second handshake message to each remote blaster using the handshake key and the data network.
22. The method of claim 21, including the central controller and the remote blaster communicating using the communications encryption key and the data network.
23. The method of any one of claims 20 to 22, including the central controller providing a broadcast encryption key that is not unique / quasi-unique to each remote blaster, and sending the broadcast encryption key to each remote blaster using the data network.
24. The method of claim 23, including the central controller encrypting and sending blasting command instructions to each remote blaster using the broadcast encryption key and the data network.