Computer-readable media and communication devices
By using address information and public keys for authentication and connection information exchange between communication devices and terminal devices, the shortcomings of the existing Wi-Fi connection authentication process are resolved, and a secure and efficient wireless connection is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BROTHER KOGYO KK
- Filing Date
- 2021-05-27
- Publication Date
- 2026-04-14
Smart Images

Figure CN113746796B_ABST
Abstract
Description
Technical Field
[0001] This document discloses techniques used when establishing wireless connections between communication devices and external devices. Background Technology
[0002] The document (“Device Provisioning Protocol Specification Version 1.1.13”, Wi-Fi Alliance, 2019) describes a technique for establishing a Wi-Fi connection between a pair of devices according to the Wi-Fi standard’s Device Provisioning Protocol (DPP) scheme. In particular, the document describes how authentication can be performed via wired communication using IP addresses.
[0003] The document described above details authentication in wired communication using IP addresses; however, it does not describe other types of communication that use IP addresses in detail. Summary of the Invention
[0004] This disclosure discloses a technique that enables communication to be performed appropriately using address information between a terminal device and a communication device when a wireless connection needs to be established between a communication device and an external device.
[0005] This document discloses a computer-readable medium for storing a computer program for a first terminal device. The first terminal device may include: one or more communication interfaces; and a computer. A computer program can enable a computer to function as: a first address information sending unit, configured to send address information, which is the IP address of the first terminal device, to the first communication device via a communication network to which the first terminal device and the first communication device belong, through a first communication interface of one or more communication interfaces; a first public key sending unit, configured to send the public key of the first terminal device to the first communication device via the first communication interface using the communication network; a first authentication request receiving unit, configured to receive a first authentication request using the public key from the first communication device via the first communication interface using the communication network when the address information and the public key are sent to the first communication device, wherein the first authentication request is sent with the address information as the destination; a first authentication response sending unit, configured to send a first authentication response to the first communication device via the first communication interface using the communication network in response to receiving the first authentication request from the first communication device; and a first connection information sending unit, configured to send first connection information to the first communication device via the first communication interface using the communication network when the first authentication response is sent to the first communication device, wherein the first connection information is used by the first communication device to establish a first wireless connection between the first communication device and an external device.
[0006] According to the above configuration, the first terminal device, using the communication network to which both the first terminal device and the first communication device belong, sends address information (the IP address of the first terminal device) and the public key of the first terminal device to the first communication device. Therefore, the first terminal device can receive a first authentication request from the first communication device, sent using the public key and with the address information (i.e., the IP address) as the destination. Then, the first terminal device sends a first authentication response to the first communication device and also sends first connection information to the first communication device. Thus, the first terminal device can appropriately establish a first wireless connection between the first communication device and an external device.
[0007] The computer program can also function as: a second address information sending unit, configured to send address information to a second communication device via a first communication interface using a communication network to which the second communication device, which is different from the first communication device, belongs; a second public key sending unit, configured to send a public key to the second communication device via the first communication interface using a communication network; a second authentication request receiving unit, configured to receive a second authentication request using the public key from the second communication device via the first communication interface using a communication network when the address information and public key are sent to the second communication device, wherein the second authentication request is sent with the address information as the destination; a second authentication response sending unit, configured to send a second authentication response to the second communication device via the first communication interface using a communication network in response to receiving the second authentication request from the second communication device; and a second connection information sending unit, configured to send second connection information to the second communication device via the first communication interface using a communication network when the second authentication response is sent to the second communication device, wherein the second connection information is used by the second communication device to establish a second wireless connection between the second communication device and an external device.
[0008] After a first wireless connection has been established between the first communication device and the external device, the second connection information sending unit can send the second connection information to the second communication device.
[0009] The first terminal device may further include a display unit. The computer program may also function as: a search signal transmitting unit for transmitting a search signal to a communication network via a first communication interface; and a display control unit for, in response to the transmission of the search signal and receipt of a response signal from each of a plurality of communication devices via the first communication interface using the communication network, causing the display unit to display a device selection screen, the device selection screen including two or more pieces of device information corresponding to two or more of the plurality of communication devices, and, in the case where a specific device information corresponding to the first communication device is selected from the two or more pieces of device information in the device selection screen, the first address information transmitting unit sends address information to the first communication device.
[0010] The device selection screen may include two or more pieces of device information corresponding to two or more communication devices that are sending response signals including support information. The device selection screen may also exclude device information corresponding to communication devices that are sending response signals without support information. The support information may indicate that the communication device sending the response signal supports a predetermined wireless connectivity scheme for transmitting authentication requests using a public key.
[0011] The device selection screen may include two or more device information entries corresponding to two or more communication devices that act as a sender, providing a response signal that includes support information but not establishment information. The device selection screen may exclude device information corresponding to a communication device that acts as a sender, providing a response signal that includes establishment information. Establishment information may indicate that the communication device acting as the sender, providing the response signal, has established a wireless connection with an external device.
[0012] If a response signal is received only from the first communication device in response to the sending of a search signal, the device selection screen may not be displayed. If a response signal is received only from the first communication device, the first address information sending unit can send address information to a communication device without selecting specific device information on the device selection screen.
[0013] If support information is received from the first communication device via the first communication interface using a communication network, the first address information sending unit may send the address information to the first communication device. If support information is not received from the first communication device, the address information may not be sent. The support information may indicate that the first communication device supports a predetermined wireless connection scheme for transmitting authentication requests using a public key.
[0014] A communication network may include wired communication paths.
[0015] The first communication interface can be a wired interface used for wired communication.
[0016] The computer program can also function as: a specific information receiving unit for receiving specific information from a second terminal device different from the first terminal device via a third communication interface of one or more communication interfaces, wherein the second terminal device has generated third connection information using the specific information and has sent the generated third connection information to an external device acting as an access point, and the third connection information is used by the external device to establish a first wireless connection between the first communication device and the external device, wherein the first connection information sending unit generates first connection information using the specific information and sends the generated first connection information to the first communication device.
[0017] This disclosure also discloses another computer-readable medium storing a computer program for a first terminal device. The first terminal device may include: one or more communication interfaces; and a computer. The computer program can cause the computer to function as: a first address information sending unit, configured to send address information of the first terminal device to the first communication device via a first communication interface of one or more communication interfaces using a communication network to which the first terminal device and the first communication device belong; a first sending request receiving unit, configured to receive a first sending request from the first communication device via the first communication interface using a communication network when the address information is sent to the first communication device, wherein the first sending request is sent with the address information as the destination, and wherein the first sending request is a signal for requesting the first terminal device to send the public key of the first terminal device; and a first public key sending unit, configured to, in response to receiving the first sending request from the first communication device, send a public key via a communication network using a first communication interface. The communication network sends a public key to a first communication device via a first communication interface; a first authentication request receiving unit is configured to receive a first authentication request using the public key from the first communication device via a second communication interface of one or more communication interfaces when the public key is sent to the first communication device; a first authentication response sending unit is configured to send a first authentication response to the first communication device via the second communication interface in response to receiving the first authentication request from the first communication device; and a first connection information sending unit is configured to send first connection information to the first communication device via the second communication interface when the first authentication response is sent to the first communication device, wherein the first connection information is used by the first communication device to establish a first wireless connection between the first communication device and an external device.
[0018] According to the above configuration, the first terminal device sends its address information to the first communication device via the communication network to which both the first terminal device and the first communication device belong. Therefore, the first terminal device can receive a first transmission request from the first communication device with the address information as the destination. Then, the first terminal device can send its public key to the first communication device and receive a first authentication request using the public key from the first communication device. The first terminal device then sends a first authentication response to the first communication device and also sends first connection information to the first communication device. Therefore, the first terminal device can appropriately establish a first wireless connection between the first communication device and an external device.
[0019] The second communication interface can be the first communication interface.
[0020] The address information can be the IP address of the first terminal device.
[0021] The computer program can also function as: a second address information sending unit, configured to send address information to a second communication device via a first communication interface using a communication network to which the second communication device, which is different from the first communication device, belongs; a second sending request receiving unit, configured to receive a second sending request from the second communication device via the first communication interface using the communication network when the address information is sent to the second communication device, wherein the second sending request is sent with the address information as the destination, and wherein the second sending request is a signal for requesting the first terminal device to send a public key; and a second public key sending unit, configured to, in response to receiving the second sending request from the second communication device, send a public key via the communication network. A first communication interface for sending a public key to a second communication device; a second authentication request receiving unit for receiving a second authentication request using the public key from the second communication device via the second communication interface when the public key is sent to the second communication device; a second authentication response sending unit for sending a second authentication response to the second communication device via the second communication interface in response to receiving the second authentication request from the second communication device; and a second connection information sending unit for sending second connection information to the second communication device via the second communication interface when the second authentication response is sent to the second communication device, wherein the second connection information is used by the second communication device to establish a second wireless connection between the second communication device and an external device.
[0022] This disclosure also discloses a communication device. The communication device may include: one or more communication interfaces; an address information receiving unit, configured to receive address information, which is the IP address of the terminal device, from the terminal device via a first communication interface of the one or more communication interfaces using the communication network to which the communication device and the terminal device belong; a public key receiving unit, configured to receive the public key of the terminal device from the terminal device via the first communication interface using the communication network; an authentication request sending unit, configured to send an authentication request using the public key to the terminal device via the first communication interface, with the address information as the destination, via the communication network, upon receiving the address information and public key from the terminal device; a connection information receiving unit, configured to receive connection information from the terminal device via the first communication interface, upon receiving an authentication response from the terminal device via the first communication interface, in response to the authentication request being sent to the terminal device, wherein the connection information is used by the communication device to establish a wireless connection between the communication device and an external device; and an establishment unit, configured to establish a wireless connection between the communication device and the external device via a third communication interface of the one or more communication interfaces using the connection information, upon receiving connection information from the terminal device.
[0023] According to the above configuration, the communication device receives address information (IP address of the terminal device) and the public key of the terminal device from the terminal device through the communication network to which both the communication device and the terminal device belong. Therefore, the communication device can send an authentication request using the public key to the terminal device whose destination is the address information (i.e., the IP address), and can also receive connection information from the terminal device. Thus, the communication device can appropriately establish a wireless connection between the communication device and an external device by using the connection information.
[0024] The address information receiving unit can receive address information by receiving a processing start request from the terminal device, which includes address information as the sender's address. The processing start request requests the start of processing according to a predetermined wireless connection scheme.
[0025] The communication device may further include: a search signal receiving unit for receiving a search signal from a terminal device via a first communication interface using a communication network; and a response signal sending unit for sending a response signal to the terminal device in response to receiving the search signal from the terminal device. If a response signal not including established information is sent to the terminal device, the address information receiving unit may receive a processing start request from the terminal device. If a response signal including established information is sent to the terminal device, the processing start request may not be received. The established information may indicate that the communication device has established a wireless connection with an external device.
[0026] A communication network may include wired communication paths.
[0027] The first communication interface can be a wired interface for wired communication. The third communication interface can be a wireless interface for wireless communication according to the Wi-Fi standard.
[0028] This disclosure also discloses a communication device. The communication device may include: one or more communication interfaces; an address information receiving unit, configured to receive address information of the terminal device from the terminal device via a first communication interface of the one or more communication interfaces by using the communication device and the communication network to which the terminal device belongs; a sending request sending unit, configured to, upon receiving address information from the terminal device, send a sending request to the terminal device via the first communication interface using the communication network, with the address information as the destination, via the first communication interface, wherein the sending request is a signal requesting the terminal device to send its public key; a public key receiving unit, configured to, in response to the sending request being sent to the terminal device, receive the public key from the terminal device via the first communication interface using the communication network; and an authentication request. A sending unit, configured to send an authentication request using the public key to a terminal device via a second communication interface of one or more communication interfaces upon receiving a public key from the terminal device; a connection information receiving unit, configured to receive connection information from the terminal device via the second communication interface upon receiving an authentication response from the terminal device via the second communication interface in response to the authentication request being sent to the terminal device, wherein the connection information is used by the communication device to establish a wireless connection between the communication device and an external device; and an establishing unit, configured to establish a wireless connection between the communication device and the external device via a third communication interface of one or more communication interfaces upon receiving connection information from the terminal device by using the connection information.
[0029] According to the above configuration, the communication device receives the terminal device's address information from the terminal device using the communication network to which both the communication device and the terminal device belong. Therefore, the communication device can send a transmission request to the terminal device with the address information as its destination and can receive the public key from the terminal device. Then, the communication device can send an authentication request using the public key to the terminal device and can also receive connection information from the terminal device. Therefore, the communication device can appropriately establish a wireless connection between the communication device and the external device by using the connection information.
[0030] The second communication interface can be the first communication interface.
[0031] The address information can be the IP address of the terminal device.
[0032] The computer-readable recording medium storing the computer program for the first terminal device, the first terminal device itself, and the method implemented by the first terminal device are also novel and useful. The computer program for the corresponding communication device, the computer-readable recording medium storing these computer programs, and the method implemented by the communication device are also novel and useful. Furthermore, a communication system including two or more of the aforementioned devices (e.g., the first terminal device and the first communication device) is also novel and useful. Attached Figure Description
[0033] Figure 1 The configuration of the communication system is shown.
[0034] Figure 2 The hardware configuration of the corresponding device is shown.
[0035] Figure 3 A sequence diagram of the processes performed by the corresponding devices is shown;
[0036] Figure 4 It shows from Figure 3 The continuing sequence diagram; and
[0037] Figure 5 It shows from Figure 4 The sequence diagram continues. Detailed Implementation
[0038] (Configuration of Communication System 2:) Figure 1 )
[0039] like Figure 1 As shown, the communication system 2 includes a terminal 10, an access point (AP) 80, a personal computer (PC) 100, and multiple printers 200A to 200D.
[0040] Terminal 10, AP 80, PC 100, and printers 200C and 200D are located at XXX Company. Terminal 10 and PC 100 are used by the network administrator of XXX Company. Cables connect AP 80, PC 100, and printer 200C. That is, AP 80, PC 100, and printer 200C belong to a wired local area network (LAN) 6. Printer 200D has established a wireless connection with AP 80 according to the Wi-Fi standard (hereinafter referred to as "Wi-Fi connection"). That is, printer 200D belongs to the wireless LAN 8 formed by AP 80. AP 80 and PC 100 are connected to the Internet 4.
[0041] Printers 200A and 200B were purchased and delivered to XXX Company by XXX Company. This embodiment describes the scenario in which a Wi-Fi connection is established between each of the printers 200A and 200B and AP 80 using terminal 10 and PC 100.
[0042] (Configuration of Terminal 10:) Figure 2 )
[0043] Next, we will refer to Figure 2 The hardware configurations of the corresponding devices 10, 100, and 200A are described. Terminal 10 is a portable terminal device, such as a mobile phone (e.g., a smartphone), PDA, tablet PC, etc. Terminal 10 includes an operation unit 12, a display unit 14, a camera 16, a Wi-Fi interface 20, and a controller 30. The corresponding units 12 to 30 are connected to a bus (reference numerals are omitted).
[0044] The operation unit 12 includes multiple keys. Users can input various commands to the terminal 10 by operating the operation unit 12. The display unit 14 is a display configured to show various types of information. The camera 16 is a device configured to capture images of objects. In this embodiment, the camera 16 is used to capture the QR code (registered trademark) of the AP 80.
[0045] Wi-Fi interface 20 is a wireless interface configured to perform Wi-Fi communication according to the Wi-Fi standard. The Wi-Fi standard is a wireless communication standard used to perform wireless communication according to the IEEE (Institute of Electrical and Electronics Engineers, Ltd.) standard 802.11 and its consistent standards (e.g., 802.11a, 11b, 11g, 11n, 11ac, etc.). In particular, Wi-Fi interface 20 supports the Device Provisioning Protocol (DPP) scheme established by the Wi-Fi Alliance. Details of the DPP scheme are described in the standard "Device Provisioning Protocol Specification Version 1.1.13" created by the Wi-Fi Alliance.
[0046] The controller 30 includes a CPU 32 and a memory 34. The CPU 32 is configured to perform various processes according to programs 40 and 42 stored in the memory 34. The memory 34 is configured with volatile memory, non-volatile memory, etc. The operating system (OS) program 40 is a program used to implement the basic operations of the terminal 10. The DPP application 42 (hereinafter referred to as "DPP app 42") is a program used to establish a Wi-Fi connection between the terminal 10 and the AP 80 according to the DPP scheme. The DPP app 42 is installed in the terminal 10 on an Internet server (not shown), such as one provided by the supplier of the printer 200A.
[0047] (PC 100 configuration)
[0048] PC 100 is a fixed terminal device such as a desktop PC. In a variant, PC 100 can be a portable terminal device such as a laptop PC. PC 100 includes an operation unit 112, a display unit 114, a Wi-Fi interface 120, a wired interface 122, and a controller 130. The corresponding units 112 to 130 are connected to a bus (reference numerals are omitted).
[0049] The operation unit 112 includes multiple keys. Users can input various commands into the PC 100 by operating the operation unit 112. The display unit 114 is a monitor configured to display various types of information. The Wi-Fi interface 120 is a wireless interface configured to perform Wi-Fi communication and supports the DPP scheme.
[0050] The controller 130 includes a CPU 132 and a memory 134. The CPU 132 is configured to perform various processes according to programs 140 and 142 stored in the memory 134. The memory 134 is configured with volatile memory, non-volatile memory, etc. The OS program 140 is a program used to implement the basic operation of the PC 100. The printer application 142 (hereinafter referred to as "printer app 142") is a program used to search for printers and establish a Wi-Fi connection between printers 200A, 200B and AP 80 according to the DPP scheme. The printer app 142 can be installed in the PC 100, for example, from a server (not shown) on the Internet provided by the supplier of printer 200A or from media accompanying printer 200A.
[0051] (Configuration of printer 200A)
[0052] Printer 200A is a peripheral device configured to perform printing functions (e.g., a peripheral device of terminal 10). Printer 200A includes an operation unit 212, a display unit 214, a print execution unit 218, a Wi-Fi interface 220, a wired interface 222, and a controller 230. The corresponding units 212 to 230 are connected to a bus (reference numerals omitted).
[0053] The operation unit 212 includes multiple keys. Users can input various commands to the printer 200A by operating the operation unit 212. The display unit 214 is a display configured to show various types of information. The print execution unit 218 includes a print mechanism using either inkjet or laser technology. The Wi-Fi interface 220 is a wireless interface configured to perform Wi-Fi communication and supports the DPP scheme.
[0054] The controller 230 includes a CPU 232 and a memory 234. The CPU 232 is configured to perform various processes according to a program 240 stored in the memory 234. The memory 234 is configured with volatile memory, non-volatile memory, etc.
[0055] Each of printers 200B and 200D has the same hardware configuration as printer 200A and supports the DPP scheme. Printer 200C has the same hardware configuration as printer 200A, but does not support the DPP scheme.
[0056] (The corresponding equipment performs the following processing:) Figures 3 to 5 )
[0057] Next, we will refer to Figures 3 to 5 The processes performed by devices 10, 80, 100, and 200A to 200D are described. In the following description, for ease of understanding, the actions performed by the CPU (e.g., CPU 32) of the respective device are described as the subject of the action, rather than the CPU. Furthermore, in... Figures 3 to 5 In the diagram, solid lines and dashed lines respectively illustrate wired and wireless communication between devices.
[0058] (Establish a Wi-Fi connection between terminal 10 and AP 80:) Figure 3 )
[0059] As mentioned earlier, printers 200A and 200B were delivered to XXX Company. At XXX Company, a Wi-Fi connection was established between terminal 10 and AP 80 before establishing a Wi-Fi connection between each of the printers 200A and 200B and AP 80. (Refer to...) Figure 3 Describes the process of establishing a Wi-Fi connection between terminal 10 and AP 80. Figure 3 In this context, every communication performed by terminal 10 is performed via Wi-Fi interface 20. Therefore, in the following description of the communication performed by terminal 10, the phrase "via Wi-Fi interface 20" will be omitted.
[0060] In T100, terminal 10 receives an order from the user (i.e., the network administrator of XXX company) to start DPP app 42. All of the following processes performed by terminal 10 are implemented by DPP app 42.
[0061] AP 80 has pre-stored two sets of authentication information. The first set of authentication information includes a first public key PKap1 and its corresponding first private key skap1 (i.e., the private key skap1 paired with the public key PKap1). The second set of authentication information includes a second public key PKap2 and its corresponding second private key skap2. A QR code is attached to the casing of AP 80. The QR code is generated by encoding information such as AP 80's first public key PKap1 and AP 80's MAC address. In T102, terminal 10 receives an instruction from the user to read the QR code using camera 16.
[0062] In T104, terminal 10 reads and decodes the QR code. Terminal 10 then obtains information such as the first public key PKap1 of AP 80 and the MAC address of AP 80. The processing in T104 corresponds to the bootstrapping of the DPP scheme.
[0063] In T106, terminal 10 generates its first set of authentication information by using the MAC address of Wi-Fi interface 20. This authentication information includes a first public key PKte1 and a first private key skte1 corresponding to the first public key PKte1.
[0064] In T110, terminal 10 sends an Authentication Request to AP 80 with the MAC address of AP 80 obtained in T104 as its destination, using the first public key PKap1 obtained in T104. Hereinafter, Authentication will be referred to as "Auth," and the Request as "Req." The Auth Req is a signal requesting authentication to be performed. Specifically, terminal 10 first generates a first shared key using the first public key PKap1 obtained in T104 and the first private key skte1 generated in T106, and then generates first encrypted data by encrypting a random value using the first shared key. Terminal 10 then sends an Auth Req including the first public key PKte1 generated in T106, the first encrypted data, and the terminal 10's Capability to AP 80. The terminal 10's Capability includes a value indicating that terminal 10 can only act as a Configurator for the DPP scheme.
[0065] The aforementioned Auth Req is a communication method that uses the physical and data link layers of the Open Systems Interconnection (OSI) model, but does not use the network layer or higher layers; that is, it does not use IP addresses. Communication without IP addresses between terminal 10 and AP 80 is only performed until a Wi-Fi connection is established between terminal 10 and AP 80 (i.e., until the communication in T132 (described later)).
[0066] When AP 80 receives the Auth Req from terminal 10 in T110, it performs authentication on the Auth Req. Specifically, AP 80 generates a first shared key using the first public key PKte1 included in the Auth Req and a pre-stored first private key skap1, and then uses the first shared key to decrypt the first encrypted data. When the decryption of the first encrypted data is successful, that is, when the authentication of the Auth Req is successful, AP 80 executes the processing that began in T112.
[0067] Upon successful authentication of the Auth Req, AP 80 generates a second shared key using the first public key PKte1 included in the Auth Req and a pre-stored second private key skap2. It then uses this second shared key to encrypt a random value to generate second encrypted data. Then, in T112, AP 80 sends an Auth Response to terminal 10, including the pre-stored second public key PKap2, the second encrypted data, and AP 80's Capability. Hereinafter, the Response will be referred to as "Res". AP 80's Capability includes a value indicating that AP 80 is capable of acting solely as an Enrollee in the DPP scheme.
[0068] When Auth Res is received from AP 80 in T112, terminal 10 performs authentication on Auth Res. Specifically, terminal 10 generates a second shared key using the second public key PKap2 included in Auth Res and the first private key skte1 generated in T106, and then decrypts the second encrypted data using the second shared key. When the decryption of the second encrypted data is successful, that is, when the authentication of Auth Res is successful, terminal 10 executes the processing that began in T113.
[0069] Furthermore, terminal 10 determines that the Capability of AP 80 (i.e., Enrollee) included in Auth Res is incompatible with the Capability of terminal 10 (i.e., Configurator). In this case, in T113, terminal 10 sends a Confirm indicating successful authentication and their incompatible roles to AP 80. Then, in T114, terminal 10 determines that it is acting as a Configurator. A Configurator is a device that acts as a Configurator Object (hereinafter referred to as "CO") (described later) to the Enrollee.
[0070] When a Confirm is received from terminal 10 in T113, AP 80 determines in T116 that it will act as an Enrollee. An Enrollee is a device that acts as a receiver of COs from the configurator. The processing from T110 to T116 corresponds to Auth in the DPP scheme.
[0071] In T120, AP 80 sends a Configuration Req to terminal 10. In the following text, Configuration will be referred to as "Config". A Config Req is a signal requesting the sending of a CO.
[0072] When a Config Req is received from AP 80 in T120, in T122, terminal 10 generates a second set of authentication information using the MAC address of Wi-Fi interface 20. This authentication information includes a second public key PKte2 and a second private key skte2 corresponding to the second public key PKte2. Terminal 10 also generates a Group ID "xxx". The Group ID "xxx" is used to identify the wireless LAN 8 formed by AP 80.
[0073] Next, terminal 10 generates a CO for the AP. Specifically, terminal 10 first generates a SignedConnector for the AP, which is the information that AP 80 uses to establish a Wi-Fi connection. Hereinafter, the SignedConnector will be referred to as "SC". The SC for the AP includes, for example, the second public key PKap2 included in the Auth Res received in T112, the Group ID "xxx" generated in T122, and a digital signature obtained using the second private key skte2 generated in T122. Then, terminal 10 generates a CO for the AP, which includes the SC for the AP and the second public key PKte2 generated in T122, and sends a Config Res including the CO for the AP to AP 80 in T124.
[0074] When AP 80 receives the Config Res from terminal 10 in T124, it sends a Config result indicating that the CO for AP has been received to terminal 10 in T126. The processing from T120 to T126 corresponds to the Config of the DPP scheme.
[0075] Next, terminal 10 generates a SC for the terminal, which is information used by terminal 10 to establish a Wi-Fi connection. The SC for the terminal includes, for example, the second public key PKte2 generated in T122, a Group ID "xxx" that is the same as the Group ID included in the SC for the AP, and a digital signature obtained using the second private key skte2 generated in T122. Then, in T130, terminal 10 sends a Discovery Req including the SC for the terminal to AP 80. The Discovery Req is a signal requesting the transmission of the SC of the communication partner.
[0076] When a Discovery Req is received from terminal 10 in T130, AP 80 performs authentication on the Discovery Req. Specifically, AP 80 decrypts the digital signature included in the SC for the terminal using the second public key PKte2 included in the CO for the AP. When authentication of the SC for the terminal is successful in response to the decryption of the digital signature, AP 80 generates a connection key using the second public key PKte2 included in the CO for the AP and the pre-stored second private key skap2. Then, in T132, AP 80 sends the Discovery Res, including the SC for the AP, to terminal 10.
[0077] When a Discovery Res is received from AP 80 in T132, terminal 10 authenticates the Discovery Res. Specifically, terminal 10 decrypts the digital signature included in the SC used by the AP using the second public key PKte2 generated in T122. When authentication of the SC used by the AC is successful in response to the decryption of the digital signature, terminal 10 generates a connection key using the second public key PKap2 included in the SC used by the AP and the second private key skte2 generated in T122. This generated connection key is the same as the connection key generated by AP 80. That is, this connection key is shared between terminal 10 and AP 80. The processing in T130 and T132 corresponds to Network Access in the DPP scheme.
[0078] Next, terminal 10 performs four-way hand-shaped communication with AP 80 using the connection key. As a result, a Wi-Fi connection is established between terminal 10 and AP 80 in T140. Therefore, terminal 10 joins the wireless LAN 8 formed by AP 80 as a substation. Consequently, terminal 10 and AP 80 can perform communication with each other using the network layer and higher layers of the OSI model, that is, communication using IP addresses.
[0079] Subsequently, according to instructions from the user, terminal 10 uses the Wi-Fi connection established in T140 to send specific information to transmission server 300 on the Internet 4 via AP 80 in T150. This specific information includes multiple pieces of information generated in T122 (i.e., the second public key PKte2, the second private key skte2, and the Group ID "xxx").
[0080] In T152, based on instructions from the user, PC 100 uses printer app 142 to receive specific information from transmission server 300 via AP 80. Because transmission server 300 is used, communication of the specific information can be performed securely. Wired LAN 6 is used for communication between PC 100 and AP 80. Since PC 100 receives specific information from terminal 10, it acts as a Configurator rather than terminal 10 in the process described below, thus enabling the establishment of Wi-Fi connections between each of the printers 200A and 200B and AP 80 using the specific information.
[0081] (Specify object printer:) Figure 4 )
[0082] Next, we will refer to Figure 4 This describes the process by which PC 100 designates at least one object printer (200A and 200B in the present case) from printers 200A to 200D, which is the printer to which a Wi-Fi connection is to be established between PC 100 and printer 80. Each process performed by PC 100 below is implemented by DPP app 42.
[0083] exist Figure 4 and Figure 5 In this context, every communication performed by PC 100 is performed via wired interface 122. Therefore, in the following description of communications performed by PC 100, the phrase "via wired interface 122" will be omitted. Figure 4 In this context, every communication performed by printers 200A to 200C is conducted via their wired interfaces (e.g., 222). Therefore, regarding... Figure 4 In the description of communications performed by printers 200A to 200C, the phrase "via wired interface" will be omitted. Furthermore, each communication performed by printer 200D is performed via its Wi-Fi interface. Therefore, the phrase "via Wi-Fi interface" will be omitted in the description of communications performed by printer 200D. Communication between PC 100 and printer 200D includes wired communication between PC 100 and AP 80, and wireless communication between AP 80 and printer 200D. However, in Figure 4In the image, solid lines depict the communication between PC 100 and printer 200D.
[0084] When printers 200A and 200B are delivered to XXX Company, they are connected to wired LAN 6. As a result, PC 100 and each of printers 200A through 200D can perform communication with each other using the OSI model's network layer and higher layers, i.e., communication using IP addresses. The IP address of each of PC 100 and printers 200A through 200D can be a so-called static IP address set by the user or an IP address assigned by an IP address allocation server such as a Dynamic Host Configuration Protocol (DHCP) server.
[0085] In the T200, PC 100 sends a search signal to wired LAN 6, including PC 100's IP address (IPpc) as the sender address. This search signal is a broadcast signal that does not specify a particular IP address as the receiver address. The search signal is based on the Simple Network Management Protocol (SNMP) and requests information indicating whether the DPP scheme is supported, whether a Wi-Fi connection with AP 80 has been established, and the node name of the recipient printer. In a variant, the search signal can be, for example, a multicast signal based on the multicast Domain Name System (mDNS). Furthermore, in a variant, a sequence number can be used instead of the node name.
[0086] When printer 200A receives a search signal from PC 100 in T200, it sends a response signal in T201 that includes the IP address IPpc of PC 100 as the recipient address. That is, printer 200A sends the response signal to PC 100 with IP address IPpc as its destination. This response signal includes the IP address IPpra of printer 200A as the sender address. The response signal also includes information indicating support for the DPP scheme (hereinafter referred to as "Support Information"), information indicating that a Wi-Fi connection with AP 80 has not yet been established (hereinafter referred to as "Not Established Information"), and the node name "123" of printer 200A.
[0087] Similarly, each of printers 200B to 200D sends a response signal to PC 100 in T202 to T204. The response signal from printer 200B (see T202) includes the IP address IPprb of printer 200B as the sender address, support information, non-establishment information, and the node name "234" of printer 200B. The response signal from printer 200C (see T203) includes the IP address IPprc of printer 200C as the sender address, information indicating that DPP is not supported (hereinafter referred to as "unsupported information"), non-establishment information, and the node name "345" of printer 200C. The response signal from printer 200D (see T204) includes the IP address IPprd of printer 200D as the sender address, support information, information indicating that a Wi-Fi connection with AP 80 has been established (hereinafter referred to as "established information"), and the node name "456" of printer 200D.
[0088] In T201 to T204, PC 100 receives response signals from printers 200A to 200D, thereby obtaining information from the response signals (i.e., the printer's IP address, support or non-support information, established or unestablished information, and the printer's node name).
[0089] Then, in T210, PC 100 designates at least one target printer from printers 200A to 200D, and a new Wi-Fi connection is established between the target printer and AP 80. In case A, PC 100 designates printers 200A and 200B as target printers, which send response signals including support information and non-establishment information. PC 100 does not designate printer 200C as a target printer, which sends a response signal including non-support information. Therefore, for printer 200C, which cannot establish a Wi-Fi connection with AP 80 according to the DPP scheme, the following process for establishing a Wi-Fi connection is not required. Furthermore, PC 100 does not designate printer 200D, which sends a response signal including establishment information, as a target printer. Therefore, for printer 200D, which has already established a Wi-Fi connection with AP 80, the following process for establishing a Wi-Fi connection is not required.
[0090] In T212, PC 100 causes display unit 114 to display a selection screen including the node names "123" and "234" for printers 200A and 200B specified in T210. The selection screen also includes a message prompting the user to select the device to establish a Wi-Fi connection with AP 80. Because the selection screen is displayed, the user can select the printer to establish a Wi-Fi connection with AP 80. In T214, PC 100 accepts the user's selection of the two node names "123" and "234". When T214 is complete, PC 100 proceeds to... Figure 5 The processing is used to establish a Wi-Fi connection between each printer in printers 200A and 200B and AP 80.
[0091] Here, we will assume scenario B: Of printers 200A and 200B, only printer 200A is connected to wired LAN 6. In this case, PC 100 does not receive a response signal in T202, and only printer 200A is designated as the target printer in T210. In this case, PC 100 does not display a selection screen (see T212), and proceeds to... Figure 5 In this case, the process of selecting a node name is not accepted. Instead of establishing a Wi-Fi connection between printer 200B and AP 80, the process of establishing a Wi-Fi connection between printer 200A and AP 80 is executed. When only printer 200A is designated as the target printer, the process of establishing a Wi-Fi connection between printer 200A and AP 80 is executed without displaying a selection screen. This improves user convenience because the user does not need to select printer 200A.
[0092] Establish a Wi-Fi connection between each printer in printers 200A and 200B and AP 80: Figure 5 )
[0093] Next, we will refer to Figure 5 To describe from Figure 4 Continue processing in case A. Figure 5 The process is used to connect each of the printers 200A and 200B to AP 80 via PC 100.
[0094] exist Figure 5 In this configuration, every communication between printers 200A and 200B and PC 100 is performed via their wired interfaces (e.g., 222). Furthermore, every communication between printers 200A and 200B and AP 80 is performed via their Wi-Fi interfaces (e.g., 220). Therefore, in... Figure 5In the description of the communication performed by printers 200A and 200B, the phrases "via wired interface" and "via Wi-Fi interface" will be omitted.
[0095] First, in the T250, PC 100 uses the MAC address of Wi-Fi interface 120 to generate authentication information for PC 100. This authentication information includes a public key PKpc and a private key skpc corresponding to the public key PKpc.
[0096] Then, PC 100 specifies the IP address IPpra included in the response signal received from printer 200A (see T201), printer 200A has in Figure 4 In T214, the node name "123" is selected. Then, in T300, PC 100 sends a DPP start request to printer 200A, which includes the IP address IPpc as the sender address and the specified IP address IPpra as the receiver address. Similarly, in the following processing, every signal from PC 100 to printer 200A includes the IP address IPpc as the sender address and the IP address IPpra as the receiver address, therefore, a description of this will be omitted below. The DPP start request is a signal that requests printer 200A to begin processing according to the DPP scheme.
[0097] By receiving a DPP start request from PC 100 in T300, printer 200A obtains the IP address IPpc of PC 100. Then, printer 200A recognizes that processing according to the DPP scheme should begin, and in T302, printer 200A sends a send request to PC 100. This send request includes the IP address IPpra as the sender address and the obtained IP address IPpc as the receiver address. Similarly, in the following processing, every signal from printer 200A to PC 100 includes the IP address IPpra as the sender address and the IP address IPpc as the receiver address; therefore, a description of this will be omitted below. The send request is a signal requesting PC 100 to send PC 100's public key PKpc.
[0098] When a send request is received from printer 200A in T302, PC 100 sends a response message including the public key PKpc to printer 200A in T304.
[0099] In T304, printer 200A obtains the public key PKpc of PC 100 by receiving response information from printer 200A. Then, in T306, printer 200A generates a first set of authentication information and a second set of authentication information using the MAC address of Wi-Fi interface 220. The first set of authentication information includes a first public key PKpra1 and a first private key skpra1 corresponding to the first public key PKpra1. The second set of authentication information includes a second public key PKpra2 and a second private key skpra2 corresponding to the second public key PKpra2. Furthermore, printer 200A changes its state from a state where printer 200A cannot send Auth Res in response to receiving Auth Req to a state where printer 200A can send Auth Res in response to receiving Auth Req.
[0100] Next, in T310, printer 200A will send the Auth Req using the public key PKpc received in T304 to PC 100. This Auth Req is... Figure 3 The Auth Req for T110 is the same, except that it uses the public key PKpc of PC 100 and the first set of authentication information for printer 200A generated in T306 (i.e., public key PKpra1 and private key skpra1). The Capability of printer 200A includes a value indicating that it can act as an Enrollee only.
[0101] When the Auth Req is received from printer 200A in T310, PC 100 performs authentication on the Auth Req. This authentication is related to... Figure 3 The authentication of Auth Req in T110 is the same, except that it uses the public key PKpra1 included in Auth Req and the private key skpc generated in T250. Then, PC 100 sends Auth Res to printer 200A in T312. This Auth Res is... Figure 3 The T112 Auth Res is the same, the difference being that it uses the public key PKpra1 included in the Auth Req and in... Figure 3 The second set of authentication information (i.e., public key PKte2 and private key skte2) received by terminal 10 in T152. The Capability of PC 100 includes a value indicating that it can act as a Configurator only.
[0102] When the Auth Res is received from PC 100 in T312, printer 200A performs authentication on the Auth Res. This authentication is related to... Figure 3The authentication of Auth Res in T112 is the same, except that it uses the public key PKte2 included in Auth Res and the private key skpra1 generated in T306. The following T313 to T320 are similar. Figure 3 T113 to T120.
[0103] When a Config Req is received from printer 200A in T320, PC 100 generates a CO for the printer. The method for generating this CO for the printer is similar to that in response to... Figure 3 The method for generating the CO for the AP is the same as in the T120's Config Req. The CO for the printer includes the SC 210A for the printer and... Figure 3 The second public key PKte2 received in T152. The SC 210A for the printer includes, for example, the second public key PKpra2 received in the Config Req in T320, in... Figure 3 The Group ID “xxx” received in T152, and the electronic signature obtained using the second private key skte2 received in T152. Then, in T324, PC 100 sends Config Res, including the CO for the printer, to printer 200A. T326 is similar. Figure 3 T126.
[0104] T330 and T332 and Figure 3 The T130 and T132 are the same, except that the T130 uses the SC210A for printers instead of the SC for terminals. Then, in the T340, a Wi-Fi connection is established between the printer 200A and the AP 80. As a result, the printer 200A joins wireless LAN 8 as a substation, and in LAN 8, the AP 80 acts as the parent station.
[0105] When a Wi-Fi connection is established with AP 80 in T340, printer 200A sends a Status Query Result (hereinafter referred to as "Result") indicating that the Wi-Fi connection establishment is complete to PC 100 in T350, without going through AP80. This allows PC 100 to be notified of the completion of the Wi-Fi connection establishment.
[0106] When a Result is received from printer 200A in T350, PC 100 performs communication with printer 200B, as in T300 to T324. As described above, after a Wi-Fi connection has been established between printer 200A and AP 80, PC 100 begins processing to establish a Wi-Fi connection between printer 200B and AP 80. Therefore, it is possible to prevent multiple printers 200A and 200B from simultaneously performing Network Address processing (i.e., T330 and T332) with AP 80. In the event of such simultaneous execution, AP 80 would bear a high communication and processing load, and as a result, AP 80 might fail to establish a Wi-Fi connection with one of the printers. According to this embodiment, simultaneous execution can be prevented, thus allowing for the proper establishment of Wi-Fi connections between the respective printers 200A, 200B, and AP 80.
[0107] Printer 200B establishes a Wi-Fi connection with AP 80 in T360 by performing processes as described in T300 to T332. As a result, printer 200B also joins wireless LAN 8 as a substation, in which AP 80 acts as the parent station. Therefore, each of printers 200A and 200B can, for example, receive print data from terminal 10 via AP 80 and print an image represented by the print data. Furthermore, each of printers 200A and 200B can communicate with a server (not shown) on the Internet 4 via AP 80.
[0108] The T370 is similar to the T350. When from... Figure 4 When all printers 200A and 200B selected in T214 receive a Result, PC 100 causes display unit 114 to display a completion screen (not shown). Thus, the user can confirm that a Wi-Fi connection has been established between printers 200A and 200B and AP 80. Furthermore, the user disconnects printers 200A and 200B from the wired LAN 6 by unplugging the cables from printers 200A and 200B. This completes the processing of this embodiment.
[0109] (Effects of the Example)
[0110] PC 100 sends a DPP start request, including the IP address of IPpc, to printer 200A via wired LAN 6. Figure 5(T300). Therefore, PC 100 can receive a send request sent to IP address IPpc as the destination (T302) from printer 200A, and send the public key PKpc to printer 200A (T304). Then, PC 100 can receive an Auth Req sent to IP address IPpc as the destination using the public key PKpc and via wired LAN 6 from printer 200A (T310). In addition, PC 100 sends the Auth Res to printer 200A via wired LAN 6 (T312), and also sends SC210A for printer 200A (T324). Therefore, PC 100 can establish a Wi-Fi connection between printer 200A and AP 80 (T340). Similarly, PC 100 can use wired LAN 6 (in conjunction with printer 200B) to send the Auth Res to printer 200A (T302) and send the public key PKpc to printer 200A (T304). Figure 5 The T300 will send a DPP start request, including the IP address IPpc, to the printer 200B. Therefore, the PC 100 can communicate with the printer 200B using wired LAN 6, resulting in the appropriate establishment of a Wi-Fi connection between the printer 200B and the AP 80 (T360).
[0111] For example, consider a comparative example without using PC 100. In this example, the user of terminal 10 displays public keys such as PKpra1 on printers 200A and 200B, and then reads the displayed public keys such as PKpra1. In this case, terminal 10 can obtain the public keys such as PKpra1 of printers 200A and 200B, and send the Auth Req and SC for the printers to each of printers 200A and 200B. However, according to the configuration of the comparative example, the user must perform the operations of displaying the public keys and reading the displayed public keys on each of the multiple printers 200A and 200B. Therefore, the user experiences an increased workload. In contrast, according to this embodiment, the user does not need to perform these operations, thus facilitating the establishment of Wi-Fi connections between multiple printers 200A and 200B and AP 80 using PC 100.
[0112] (Correspondence)
[0113] PC 100, terminal 10, printers 200A and 200B, and AP 80 are examples of "first terminal device (or terminal device)," "second terminal device," "first communication device (or communication device)," "second communication device," and "external device," respectively. Printers 200A to 200D are examples of "multiple communication devices," and printers 200A and 200B are examples of "two or more communication devices." Wired LAN 6 is an example of a "communication network." The wired interface 122 of PC 100 is an example of the "first communication interface," "second communication interface," and "third communication interface" of the "first terminal device." The wired interface 222 of printer 200A is an example of the "first communication interface" and "second communication interface" of the "communication device." The Wi-Fi interface 220 of printer 200A is an example of the "third communication interface" of the "communication device."
[0114] IP address (IPpc) is an example of "address information" and "IP address". Public key (PKpc) is an example of "public key". Figure 5 The DPP start request in T300 is an example of "processing start request". The send request in T302 is an example of "first send request". The send request in T302 related to printer 200B is an example of "second send request". The Auth Req in T310 is an example of "first authentication request (or authentication request)". The Auth Req in T310 related to printer 200B is an example of "second authentication request". The Auth Res in T312 is an example of "first authentication response (or authentication response)". The Auth Res in T312 related to printer 200B is an example of "second authentication response". The SC 210A for printer in T324 is an example of "first connection information (or connection information)". The SC for printer in T324 related to printer 200B is an example of "second connection information".
[0115] exist Figure 4 The two node names "123" and "234" displayed on the selection screen in the T210 are examples of "two or more device information entries". Node name "123" is an example of "specific device information". The DPP scheme is an example of "pre-defined wireless connection scheme". Figure 3 The SC used for the AP in T132 is an example of "Third Connection Information". The public key PKte2, private key skte2, and Group ID "xxx" included in the specific information in T150 are examples of "Specific Information".
[0116] The correspondence regarding "first terminal device" is as follows. Figure 3 The processing of T152 is an example of a "specific information receiving unit". Figure 4 The processing of T200 and T212 in the example are examples of the "search signal sending unit" and "display control unit", respectively. Figure 5 The processing of T300, T302, T304, T310, T312, and T324 in the example are respectively the "first address information sending unit," "first sending request receiving unit," "first public key sending unit," "first authentication request receiving unit," "first authentication response sending unit," and "first connection information sending unit." The processing of T300, T302, T304, T310, T312, and T324 related to printer 200B are respectively the "second address information sending unit," "second sending request receiving unit," "second public key sending unit," "second authentication request receiving unit," "second authentication response sending unit," and "second connection information sending unit."
[0117] The correspondence regarding "communication equipment" is as follows. Figure 4 The processing of T200 and T201 are examples of the "search signal receiving unit" and "response signal sending unit", respectively. Figure 5 The processing of T300, T302, T304, T310, T324, and T340 are examples of "address information receiving unit", "send request sending unit", "public key receiving unit", "authentication request sending unit", "connection information receiving unit", and "establishment unit", respectively.
[0118] (Variation Example 1) PC 100 can be Figure 5 The T300 will send a DPP start request, including the IP address (IPpc) and public key (PKpc), to printer 200A. In this case... Figure 5 T302 and T304 can be omitted. Generally, the "first address information sending unit" and "first public key sending unit" executed by the "first terminal device" may include sending address information and public key at different times than in the above embodiments, or sending address information and public key at the same time as in this variant. Furthermore, the "address information receiving unit" and "public key receiving unit" executed by the "communication device" may include receiving address information and public key at different times or receiving them at the same time. In this variant, the "first sending request receiving unit" executed by the "first terminal device" and the "sending request sending unit" executed by the "communication device" may not be necessary.
[0119] (Variation 2) PC 100 and printer 200A may, for example, belong to a Wi-Fi Direct (registered trademark) wireless network instead of a wired LAN 6. In this case, PC 100 can send the IP address IPpc and public key PKpc to printer 200A via Wi-Fi interface 120. Furthermore, PC 100 can perform DPP start request, Auth Req, and CO communication with printer 200A via Wi-Fi interface 120. In this variant, the wireless network is an example of a "communication network". Furthermore, the Wi-Fi interface 120 of PC 100 is an example of a "first communication interface" of a "first terminal device", and the Wi-Fi interface 220 of printer 200A is an example of a "first communication interface" of a "communication device".
[0120] (Variant Example 3) In Figure 4 In T200 and T201, PC 100 and printer 200A can perform communication without using the network layer and higher layers of the OSI model (i.e., communication using IP addresses). That is, PC 100 and printer 200A can perform communication using the data link layer and lower layers (i.e., communication without using IP addresses). In this case, PC 100... Figure 4 The T201 receives the printer's wired MAC address as the MAC address of the wired interface 222 of the printer 200A, and... Figure 5 In T300, a DPP start request is sent to printer 200A with the printer's wired MAC address as the destination. The DPP start request includes the PC's wired MAC address, which is the MAC address of the wired interface 122 of PC 100, as the sender address. In this case, communication between T302 and subsequent processes does not use IP addresses, but instead uses the printer's wired MAC address and the PC's wired MAC address. In this variant, the PC's wired MAC address is an example of "address information".
[0121] (Variant Example 4) In Figure 4In T201, PC 100 can also receive a wireless MAC address, which serves as the MAC address of the Wi-Fi interface 220 of printer 200A. In this case, in T310 to T324, PC 100 can perform wireless communication using the wireless MAC address (i.e., communication using only the data link layer and lower layers of the OSI model), instead of wired communication. That is, PC 100 can perform Auth Req communication with printer 200A and communication with SC 210A for printer via Wi-Fi interface 120. In this variant, Wi-Fi interface 120 of PC 100 is an example of a "second communication interface" of the "first terminal device," and Wi-Fi interface 220 of printer 200A is an example of a "second communication interface" of the "communication device." Generally, the "second communication interface" can be the same as the "first communication interface" as in the above embodiments, or it can be a different interface from the "first communication interface."
[0122] (Variation 5) PC 100 can establish a Wi-Fi connection with AP 80. Furthermore, AP 80 and each of the printers 200A and 200B can connect to a wired network. In this case, PC 100... Figure 5 In T300, a DPP start request is sent to AP 80 using a wireless network. As a result, AP 80 sends the DPP start request to printer 200A using a wired network. Similarly, in the following communications between PC 100 and printer 200A (T302, T304, T310, etc.), either a wireless or wired network is used. Generally, the "communication network" may include only the wired communication path as in the above embodiments, or it may include both wired and wireless communication paths as in this variant.
[0123] (Variant Example 6) and Figure 4 The situation is the same as in case B, where printer 200B is not required. In this case, Figure 5 In this variant, T300 to T332 related to printer 200B can be omitted, and T360 and T370 can also be omitted. In this variant, the "second address information sending unit", "second sending request receiving unit", "second public key sending unit", "second authentication request receiving unit", "second authentication response sending unit" and "second connection information sending unit" executed by the "first terminal device" can be omitted.
[0124] (Variant Example 7) In Figure 4In the T200, printer 200A can periodically send information including IP address IPpra to wired LAN 6 without receiving a search signal from PC 100. In this case, PC 100 can receive IP address IPpra from printer 200A without sending a search signal to wired LAN 6. In this variant, the "search signal sending unit" performed by the "first terminal device" and the "search signal receiving unit" performed by the "communication device" can be omitted.
[0125] (Variant Example 8) can be omitted. Figure 5 The T350. In this case, Figure 5 After the Config Res is sent to printer 200A in T324, PC 100 can perform communication with printer 200B via T300 to T324 without receiving Result from printer 200A. That is, PC 100 can establish... Figure 5 The communication with printers 200B via T300 to T324 prior to the Wi-Fi connection in T340. Generally, the "second connection information sending unit" performed by the "first terminal device" may include sending second connection information to the second communication device before establishing the first wireless connection.
[0126] (Variant Example 9) can be omitted. Figure 4 T212 and T214. In this variant, the "display control unit" executed by the "first terminal device" can be omitted.
[0127] (Variation Example 10) Printers such as the 200A that support the DPP scheme can be configured to... Figure 4 The response signal in T201, etc., is sent to PC 100, while printer 200C, which does not support the DPP scheme, can be configured not to send the response signal in T203 to PC 100. With a configuration where only one printer supporting the DPP scheme sends the response signal, the response signal may not include information indicating whether the DPP scheme is supported. Generally, the "first terminal device" may not receive response signals that include support information.
[0128] (Variation Example 11) Printers such as 200A that have not yet established a Wi-Fi connection with AP 80 can be configured to... Figure 4The response signal in T201, etc., is sent to PC 100, while printer 200D, which has already established a Wi-Fi connection with AP 80, can be configured not to send the response signal in T204 to PC 100. With the configuration that only one printer that has not yet established a Wi-Fi connection with AP 80 sends a response signal, the response signal may not include information indicating whether a Wi-Fi connection has been established with AP 80. Generally, the "first terminal device" may not receive a response signal that includes establishment information.
[0129] (Variant Example 12) In Figure 4 In scenario B, PC 100 can display a selection screen that includes only the node name "123". Generally, the "display control unit" executed by the "first terminal device" can include: causing the display unit to display a device selection screen only when a response signal is received from the first communication device.
[0130] (Variation 13) Instead of terminal 10, PC 100 can execute... Figure 3 The processes T100 to T140 are performed. In this case, processes T150 and T152 can be omitted. In this variant, the "specific information receiving unit" performed by the "first terminal device" can be omitted.
[0131] (Variation Example 14) PC 100 can perform wireless communication such as Near Field Communication (NFC) communication, Bluetooth (registered trademark) (BT) communication, and not... Figure 3 T150 and T152 receive the public key PKte2, private key skte2, and Group ID "xxx" from terminal 10. In this variant, a wireless communication interface such as an NFC interface or a BT interface is an example of a "third communication interface" of the "first terminal device". In another variant, communication of specific information between PC 100 and terminal 10 can be via email communication including password-protected specific information or via network communication using Hypertext Transfer Protocol Security (HTTPS) (i.e., communication using wired LAN 6 and wireless LAN 8). Here, the aforementioned network communication can, for example, be implemented by terminal 10 acting as a client and PC 100 acting as a server.
[0132] (Variant Example 15) "The first communication device (or communication equipment)" may not be a printer, but may be another type of device, such as a scanner, multifunction device, portable terminal, PC, server, etc.
[0133] (Variant 16) The “external device” may not be AP 80, and may be, for example, PC 100. That is, in this variant, a Wi-Fi connection is established between PC 100 and printer 200A.
[0134] (Variant 17) In the above embodiment, Figures 3 to 5 The processing is implemented by software (i.e., programs 40, 42, 140, 142, 240). Conversely, at least one of these processes can be implemented by hardware such as logic circuits.
Claims
1. A computer-readable medium storing a computer program for a first terminal device, The first terminal device includes: One or more communication interfaces, and computer, The computer program enables the computer to function as: The first address information sending unit is configured to: send address information, which is the IP address of the first terminal device, to the first communication device through the communication network to which the first terminal device and the first communication device belong, and through the network layer and higher layers of the Open Systems Interconnection model, via the first communication interface of the one or more communication interfaces; The first public key sending unit is configured to: send the public key of the first terminal device to the first communication device via the first communication interface by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection (OSI) model, wherein the public key is used for a device provisioning protocol. The first authentication request receiving unit is configured to: when the address information and the public key are sent to the first communication device, receive a first authentication request using the public key from the first communication device via the first communication interface by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection model, wherein the first authentication request is sent with the address information as the IP address as the destination; A first authentication response sending unit is configured to: in response to receiving a first authentication request from the first communication device, send a first authentication response to the first communication device via the first communication interface using the communication network and by using the network layer and higher layers of the Open Systems Interconnection (OSI) model; and The first connection information sending unit is configured to: when the first authentication response is sent to the first communication device, send first connection information to the first communication device via the first communication interface by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection (OSI) model, wherein the first connection information is used by the first communication device to establish a first wireless connection between the first communication device and an external device.
2. The computer-readable medium according to claim 1, in, The computer program causes the computer to also function as: The second address information sending unit is configured to: send the address information to the second communication device via the first communication interface by using the communication network to which the second communication device, which is different from the first communication device, belongs, and by using the network layer and higher layers of the Open Systems Interconnection model; The second public key sending unit is configured to: send the public key to the second communication device via the first communication interface by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection model; The second authentication request receiving unit is configured to: receive a second authentication request using the public key from the second communication device via the first communication interface when the address information and the public key are sent to the second communication device, by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection model, wherein the second authentication request is sent with the address information as the IP address as the destination; The second authentication response sending unit is configured to: in response to receiving the second authentication request from the second communication device, send the second authentication response to the second communication device via the first communication interface using the communication network and by using the network layer and higher layers of the Open Systems Interconnection (OSI) model; and The second connection information sending unit is configured to: when the second authentication response is sent to the second communication device, send second connection information to the second communication device via the first communication interface by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection (OSI) model, wherein the second connection information is used by the second communication device to establish a second wireless connection between the second communication device and the external device.
3. The computer-readable medium according to claim 2, wherein, After the first wireless connection has been established between the first communication device and the external device, the second connection information sending unit sends the second connection information to the second communication device.
4. The computer-readable medium according to claim 1, wherein, The first terminal device also includes a display unit. The computer program causes the computer to also function as: The search signal transmitting unit is configured to: transmit a search signal to the communication network via the first communication interface; as well as The display control unit is configured to: in response to the transmission of the search signal and receipt of a response signal from each of a plurality of communication devices via the first communication interface using the communication network and through the network layer and higher layers of the Open Systems Interconnection (OSI) model, cause the display unit to display a device selection screen, the device selection screen including two or more pieces of device information corresponding to two or more of the plurality of communication devices, and When a specific device information corresponding to the first communication device is selected from two or more device information from the device selection screen, the first address information sending unit sends the address information to the first communication device.
5. The computer-readable medium according to claim 4, wherein, The device selection screen includes two or more pieces of device information corresponding to the two or more communication devices that are the senders of the response signal, which includes support information. The device selection screen does not include device information corresponding to the communication device that is the sender of the response signal that does not include the support information, and The support information indicates that the communication device, as the sender of the response signal, supports a predetermined wireless connection scheme for transmitting authentication requests using a public key.
6. The computer-readable medium according to claim 5, wherein, The device selection screen includes two or more pieces of device information corresponding to the two or more communication devices that are the senders of the response signal, which includes the support information but does not include the established information. The device selection screen does not include device information corresponding to the communication device that is the sender of the response signal including the established information, and The established information indicates that the communication device, as the sender of the response signal, has established a wireless connection with the external device.
7. The computer-readable medium according to claim 5, wherein, If, in response to the sending of the search signal, the response signal is received only from the first communication device, the device selection screen is not displayed, and If the response signal is received only from the first communication device, the first address information sending unit sends the address information to the first communication device without selecting the specific device information in the device selection screen.
8. The computer-readable medium according to claim 1, wherein, Upon receiving support information from the first communication device via the first communication interface using the communication network and through the network layer and higher layers of the Open Systems Interconnection (OSI) model, the first address information sending unit sends the address information to the first communication device. If the support information is not received from the first communication device, the address information is not sent, and The support information indicates that the first communication device supports a predetermined wireless connection scheme for transmitting authentication requests using a public key.
9. The computer-readable medium according to claim 1, wherein, The communication network includes wired communication paths.
10. The computer-readable medium according to claim 9, wherein, The first communication interface is a wired interface used for wired communication.
11. The computer-readable medium according to claim 1, wherein, The computer program causes the computer to also function as: A specific information receiving unit is configured to: receive specific information from a second terminal device different from the first terminal device via a third communication interface of the one or more communication interfaces, wherein the second terminal device has generated third connection information using the specific information and has sent the generated third connection information to the external device acting as an access point, and the third connection information is used by the external device to establish the first wireless connection between the first communication device and the external device. The first connection information sending unit generates the first connection information by using the specific information and sends the generated first connection information to the first communication device.
12. A computer-readable medium storing a computer program for a first terminal device, The first terminal device includes: One or more communication interfaces, and computer, The computer program enables the computer to function as: The first address information sending unit is configured to: send the address information of the first terminal device to the first communication device through the communication network to which the first terminal device and the first communication device belong, and through the network layer and higher layers of the Open Systems Interconnection model, via the first communication interface of the one or more communication interfaces; The first sending request receiving unit is configured to: receive a first sending request from the first communication device via the first communication interface when the address information is sent to the first communication device, using the communication network and the network layer and higher layers of the Open Systems Interconnection (OSI) model, wherein the first sending request is sent with the address information as the destination, and wherein the first sending request is a signal for requesting the first terminal device to send the public key of the first terminal device, wherein the public key is used for a device provisioning protocol; The first public key sending unit is configured to: in response to receiving the first sending request from the first communication device, send the public key to the first communication device via the first communication interface by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection model; The first authentication request receiving unit is configured to: receive a first authentication request using the public key from the first communication device via the first communication interface, when the public key is sent to the first communication device, by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection (OSI) model. A first authentication response sending unit is configured to: in response to receiving the first authentication request from the first communication device, send a first authentication response to the first communication device via the first communication interface; and A first connection information sending unit is configured to: send first connection information to the first communication device via the first communication interface when the first authentication response is sent to the first communication device, wherein the first connection information is used by the first communication device to establish a first wireless connection between the first communication device and an external device.
13. The computer-readable medium according to claim 12, wherein, The address information is the IP address of the first terminal device.
14. The computer-readable medium of claim 12, wherein, The computer program causes the computer to also function as: The second address information sending unit is configured to: send the address information to the second communication device via the first communication interface by using the communication network to which the second communication device, which is different from the first communication device, belongs, and by using the network layer and higher layers of the Open Systems Interconnection model; The second sending request receiving unit is configured to: receive a second sending request from the second communication device via the first communication interface when the address information is sent to the second communication device, by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection model, wherein the second sending request is sent with the address information as the destination, and wherein the second sending request is a signal for requesting the first terminal device to send the public key; The second public key sending unit is configured to: in response to receiving the second sending request from the second communication device, send the public key to the second communication device via the first communication interface by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection model; The second authentication request receiving unit is configured to: receive a second authentication request using the public key from the second communication device via the first communication interface when the public key is sent to the second communication device; The second authentication response sending unit is configured to: in response to receiving the second authentication request from the second communication device, send a second authentication response to the second communication device via the first communication interface; and The second connection information sending unit is configured to: send second connection information to the second communication device via the first communication interface when the second authentication response is sent to the second communication device, wherein the second connection information is used by the second communication device to establish a second wireless connection between the second communication device and the external device.
15. A communication device, comprising: One or more communication interfaces; The address information receiving unit is configured to: receive address information, which is the IP address of the terminal device, from the terminal device via a first communication interface among the one or more communication interfaces, by using the communication network to which the communication device and the terminal device belong and by using the network layer and higher layers of the Open Systems Interconnection model; A public key receiving unit is configured to: receive the public key of the terminal device from the terminal device via the first communication interface by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection (OSI) model, wherein the public key is used for a device provisioning protocol; An authentication request sending unit is configured to: upon receiving the address information and the public key from the terminal device, send an authentication request using the public key to the terminal device via the first communication interface, using the communication network and the network layer and higher layers of the Open Systems Interconnection model, with the address information as the IP address as the destination; A connection information receiving unit is configured to: in response to an authentication request being sent to the terminal device and receiving an authentication response from the terminal device via the first communication interface using the communication network and the network layer and higher layers of the Open Systems Interconnection (OSI) model, receive connection information from the terminal device via the first communication interface using the communication network and the network layer and higher layers of the OSI model, wherein the connection information is used by the communication device to establish a wireless connection between the communication device and an external device; as well as An establishment unit is configured to: upon receiving the connection information from the terminal device, establish the wireless connection between the communication device and the external device via a third communication interface among the one or more communication interfaces by using the connection information.
16. The communication device according to claim 15, wherein, The address information receiving unit receives the address information by receiving a processing start request from the terminal device, which includes the address information as the sender's address, wherein the processing start request requests to begin processing according to a predetermined wireless connection scheme.
17. The communication device according to claim 16, further comprising: The search signal receiving unit is configured to: receive a search signal from the terminal device via the first communication interface by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection model; as well as A response signal transmitting unit, the response signal transmitting unit being configured to: transmit a response signal to the terminal device in response to receiving the search signal from the terminal device. in, If the response signal, excluding established information, is sent to the terminal device, the address information receiving unit receives the processing start request from the terminal device. If the response signal including the established information is sent to the terminal device, the processing start request is not received, and The established information indicates that the communication device has established a wireless connection with the external device.
18. The communication device according to claim 15, wherein, The communication network includes wired communication paths.
19. The communication device according to claim 18, wherein, The first communication interface is a wired interface for wired communication, and The third communication interface is a wireless interface used for wireless communication according to the Wi-Fi standard.
20. A communication device, comprising: One or more communication interfaces; The address information receiving unit is configured to: receive the address information of the terminal device from the terminal device through a first communication interface of the one or more communication interfaces by using the communication network to which the communication device and the terminal device belong and by using the network layer and higher layers of the Open Systems Interconnection model; A sending request sending unit is configured to: upon receiving the address information from the terminal device, send a sending request to the terminal device via the first communication interface using the communication network and by using the network layer and higher layers of the Open Systems Interconnection model, with the address information as the destination, wherein the sending request is a signal for requesting the terminal device to send the public key of the terminal device, wherein the public key is used for a device provisioning protocol; A public key receiving unit is configured to: in response to the sending request being sent to the terminal device, receive the public key from the terminal device via the first communication interface by using the communication network and by using the network layer and higher layers of the Open Systems Interconnection (OSI) model; An authentication request sending unit is configured to: upon receiving the public key from the terminal device, send an authentication request using the public key to the terminal device via the first communication interface using the communication network and by using the network layer and higher layers of the Open Systems Interconnection model; A connection information receiving unit is configured to: upon receiving an authentication response from the terminal device via the first communication interface in response to an authentication request being sent to the terminal device, receive connection information from the terminal device via the first communication interface, wherein the connection information is used by the communication device to establish a wireless connection between the communication device and an external device; and An establishment unit is configured to: upon receiving the connection information from the terminal device, establish the wireless connection between the communication device and the external device via a third communication interface among the one or more communication interfaces by using the connection information.
21. The communication device according to claim 20, wherein, The address information is the IP address of the terminal device.
Citation Information
Patent Citations
Terminal device, communication device, and recording medium
CN110324825A
Communication Device
US20160254916A1