Electronic device, method of controlling electronic device, and storage medium
By introducing the design of the change unit and the control unit in the electronic device, the problem of difficulty in ensuring the appropriateness of the connection destination change request in the prior art is solved, and the effect of switching the STA to the appropriate AP is achieved, and the stability and security of data transmission are improved.
Patent Information
- Application Number
- CN202411561496.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-06
- Filing Date
- 2024-11-04
- Publication Date
- 2025-05-06
AI Technical Summary
The prior art is difficult to ensure the appropriateness of the request when processing a connection destination change request from an access point (AP), which may cause the STA to switch to an unsuitable connection destination AP.
An electronic device is provided, including a change unit and a control unit that changes the connection destination AP according to the received AP change request, while the control unit prevents changing the AP used as the connection destination to an unsuitable second AP, ensuring that an authentication method is used different from the current AP.
By more appropriately controlling the connection destination change request from the AP, ensuring that the STA switches to the appropriate AP, improving the stability and security of data transmission.
Smart Images

Figure CN119946752A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an electronic device capable of changing a connection destination access point (AP) to be connected according to a connection destination change request from the AP, a method of controlling the electronic device, and a storage medium. Background Art
[0002] The technology of an extended service set (ESS) including multiple APs involves dynamically switching a connection destination AP to which a station (STA) is to be connected in the ESS to efficiently exchange data between the AP and the STA. When it is determined that the AP as the connection destination is to be switched based on, for example, congestion of the AP to which the STA is currently connected, occupancy of other APs, or radio wave conditions, the currently connected AP sends an AP change request to the STA. Upon receiving the AP change request, the STA switches the connection destination AP according to the request to connect to an appropriate AP.
[0003] Japanese Patent Laid-Open No. 2021-175068 discloses the following process for sending a request from a router with an AP function to a currently connected wireless slave unit to change the connection destination. A mobile router (MR1) that can be connected to multiple wireless slave units checks whether the wireless slave terminal supports the Institute of Electrical and Electronics Engineers (IEEE) 802.11v. It can be determined whether the wireless slave terminal supports IEEE 802.11v to wirelessly connect to MR1 based on an association request frame sent from the wireless slave terminal. If the wireless slave terminal supports IEEE 802.11v, a basic service set (BSS) transition management (BTM) request frame is sent to the wireless slave terminal. In the BTM request frame, the BSS transition candidate list entry field specifies the basic service set identifier (BSSID) of the master router RT2 as the connection destination. Therefore, the switching of the connection destination of the slave terminal is prompted. Based on the received BTM request frame, the wireless slave terminal switches the connection destination from MR1 to the master router RT2. Summary of the invention
[0004] A mechanism capable of more appropriate control of a connection destination change request from an access point (AP) is provided.
[0005] An electronic device including at least one memory and at least one processor, the at least one processor serving as: a changing unit configured to change an access point serving as a connection destination based on a change request for an access point serving as a connection destination received from a connected access point; and a control unit configured to perform control so that the changing unit is prevented from changing the access point serving as the connection destination to a second access point as a changed connection destination, the second access point being a candidate for a change destination based on the change request and configured to connect using a second authentication method different in type from a first authentication method used for connecting to a first access point connected before the connection destination is changed.
[0006] Further features of the present invention will become apparent from the following description of embodiments with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0007] Figure 1 is a diagram showing an example configuration of a system.
[0008] Figure 2A and Figure 2B is a diagram showing an example configuration of a multifunction peripheral (MFP).
[0009] FIG. 3A to FIG. 3D is a diagram showing an example of a display on the operation display unit of the MFP.
[0010] Figure 4A and Figure 4B is a diagram showing the configuration of a mobile terminal device.
[0011] Figure 5 is a diagram showing the structure of an access point.
[0012] Figure 6 is a sequence diagram showing processing performed in response to a connection destination change request.
[0013] Figure 7 is a flowchart showing an example of processing of a measurement request and a change request.
[0014] Figure 8 is a flowchart illustrating an example of a process of storing a security method.
[0015] Fig. 9 is a flowchart illustrating an example of a determination process based on a security method.
[0016] Fig.10 is a diagram of an example of a screen for setting restrictions on a security method. DETAILED DESCRIPTION
[0017] A request to change a connection destination access point (connection destination AP) from an access point (AP) sometimes includes a candidate AP that is not suitable as a connection destination for a station (STA) to be switched to. Therefore, efforts need to be made to switch the STA to a suitable AP. The present disclosure provides a mechanism that enables more appropriate control of connection destination change requests from APs.
[0018] The exemplary embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. It should be noted that, unless otherwise stated, the described embodiments are merely examples and are not intended to limit the scope of the present invention. Although multiple features are described in the embodiments, not all features are required for the present disclosure, and multiple features can be combined arbitrarily. In the accompanying drawings, the same reference numerals are used to designate the same or similar parts, and their redundant descriptions will be omitted. The various embodiments of the present invention described below can be implemented separately, or as a combination of multiple embodiments or their features when necessary or in a single embodiment where a combination of elements or features from each embodiment is beneficial.
[0019] System Configuration
[0020] Figure 1 An example configuration of a system according to the present embodiment is shown. In one example, the system is a wireless communication system in which a plurality of communication devices can wirelessly communicate with each other. Figure 1 In the example shown, the communication device includes a mobile terminal device 104, an MFP 100, access points AP1 101 and AP2 102, a dynamic host configuration protocol (DHCP) server 103, a domain name system (DNS) server 105, and a network 110. The mobile terminal device 104 is a device having a wireless communication function using a wireless local area network (LAN) or the like. The wireless LAN may be referred to as a WLAN hereinafter. The mobile terminal device 104 may be, for example, a personal information terminal such as a personal digital assistant (PDA), a mobile phone (smartphone), a digital camera, or a personal computer (PC).
[0021] MFP is an electronic device and an information processing device. MFP 100 is a printer with a printing function. MFP 100 may also have a reading function (scanner), a fax sending (fax) function, and a telephone function. In the present embodiment, MFP 100 also has a communication function for wireless communication with a mobile terminal device 104. The present embodiment describes MFP 100 by way of example and not limitation. Any other device with a communication function, such as a scanner device, a projector, a mobile terminal, a smart phone, a laptop computer, a tablet terminal, a PDA, a digital camera, a music player, a TV, or a smart speaker, may be used instead of MFP 100. MFP is the abbreviation of "Multi Function Peripheral".
[0022] The access point AP1 101 is arranged separately from the mobile terminal device 104 and the MFP 100 (or is located outside thereof), and operates as a WLAN base station device. A communication device having a WLAN communication function can communicate in the infrastructure mode of the WLAN via the access point AP1 101. In the following description, the access point may be referred to as an "AP". The infrastructure mode of the WLAN may be referred to as a "wireless infrastructure mode". The access point AP1 101 communicates wirelessly with a communication device (authenticated communication device) that is allowed to connect to the access point AP1 101, and relays wireless communication between the communication device and another communication device. The access point AP1 101 can be connected to, for example, a wired communication network, and can relay communication between a communication device connected to the wired communication network and another communication device wirelessly connected to the access point AP1 101.
[0023] The access point AP2 102 has a function equivalent to that of the access point AP1 101. The MFP 100 switches the connection from the access point AP1 101 to the access point AP2 102 if necessary. The DHCP server 103 is connected to the MFP 100 via the access point AP1 101 and the network 110, and provides a service to the MFP 100 in response to a request from the MFP 100. Figure 1 104, the DHCP server 103 is connected as a different device from the access points AP1 101 and AP2 102. However, the access points AP1 101 and AP2 102 may have a DHCP server function. The DNS server 105 is connected to the MFP 100 and the mobile terminal device 104 via the access point AP1 101 and the network 110, and provides a service for name resolution in response to a request from the MFP 100 or the mobile terminal device 105. The network 110 may be the Internet, a closed network within a company, or a mobile phone network.
[0024] Appearance of MFP
[0025] Figure 2A An example appearance of the MFP 100 is shown. The MFP 100 includes, for example, a document table 201, a document cover 202, a print sheet insertion port 203, a print sheet discharge port 204, and an operation display unit 205. The document table 201 is a table on which a document to be read is placed. The document cover 202 is a cover that is closed to press the document placed on the document table 201 and prevent light from leaking outward from a light source that illuminates the document during reading of the document. The print sheet insertion port 203 is an insertion port in which sheets of various sizes can be set. The print sheet discharge port 204 is a discharge port from which print sheets are discharged. The sheets set in the print sheet insertion port 203 are conveyed one by one to the printing unit 222 (described below), printed by the printing unit 222, and then discharged through the print sheet discharge port 204. The operation display unit 205 includes keys such as character input keys, cursor keys, input keys, and cancel keys, a light emitting diode (LED), a liquid crystal display (LCD), and the like. The operation display unit 205 is configured to accept operations performed by a user, such as activating various MFP functions and setting various settings. The operation display unit 205 may also include a touch panel display. The MFP 100 has a wireless communication function using WLAN, and includes a wireless communication antenna 206 for wireless communication. The wireless communication antenna 206 may not be visible from the outside. Like the mobile terminal device 104, the MFP 100 may also perform wireless communication using WLAN in a frequency band such as the 2.4 GHz or 5 GHz band.
[0026] MFP Structure
[0027] Figure 2B An example configuration of the MFP 100 is shown. The MFP 100 includes a main board 211 for main control of the MFP 100, and a wireless unit 226. The wireless unit 226 is a communication module for performing WLAN communication by using at least one common antenna. The MFP 100 also includes, for example, a modem 229 for performing wired communication. The main board 211 includes, for example, a central processing unit (CPU) 212, a read-only memory (ROM) 213, a random access memory (RAM) 214, a nonvolatile memory 215, an image memory 216, a reading control unit 217, a data conversion unit 218, a reading unit 219, and an encoding / decoding processing unit 221. The main board 211 also includes, for example, a printing unit 222, a sheet feeding unit 223, a printing control unit 224, and an operation display unit 220.
[0028] The functional units in the above-mentioned main board 211 are connected to each other via a system bus 230 managed by the CPU 212. The main board 211 and the wireless unit 226 are connected via, for example, a dedicated bus 225. The main board 211 and the modem 229 are connected via, for example, a bus 228.
[0029] The CPU 212 is a system control unit including at least one processor, and controls the overall operation of the MFP 100. In one example, the processing of the MFP 100 to be described below is implemented by the CPU 212 executing a program stored in the ROM 213. Hardware dedicated to each processing may be provided. The ROM 213 stores a control program executed by the CPU 212, an embedded operating system (OS) program, and the like. In the present embodiment, the CPU 212 executes each control program stored in the ROM 213 under the management of the embedded OS stored in the ROM 213 to control software such as scheduling tasks and switching tasks.
[0030] RAM 214 includes, for example, a static random access memory (SRAM). RAM 214 stores data such as program control variables, setting values registered by users, and data for managing MFP 100. RAM 214 can also be used as a buffer for various jobs. For example, nonvolatile memory 215 includes a memory such as a flash memory, and can continuously store data even after the power of MFP 100 is disconnected. Image memory 216 includes a memory such as a dynamic random access memory (DRAM). Image memory 216 stores image data received via wireless unit 226, image data processed by encoding / decoding processing unit 221, and the like. The memory configuration of MFP 100 is not limited to the above configuration. Data conversion unit 218 performs processing such as analyzing data in various formats and conversion from image data to print data.
[0031] The reading control unit 217 controls the reading unit 219 (e.g., a contact image sensor (CIS)) to optically read the document placed on the document table 201. The reading control unit 217 converts the image obtained by optically reading the document into electrical image data (image signal) and outputs the electrical image data. At this time, the reading control unit 217 may perform various image processing such as binarization and halftoning before outputting the image data.
[0032] The operation display unit 220 corresponds to the reference Figure 2A The operation display unit 205 described above performs processing such as displaying on the display under display control of the CPU 212 and generating a signal in response to accepting a user operation.
[0033] The encoding / decoding processing unit 221 performs encoding processing, decoding processing, and enlargement / reduction processing on image data processed by the MFP 100, such as Joint Photographic Experts Group (JPEG) data or Portable Network Graphics (PNG) data.
[0034] The sheet feeding unit 223 holds sheets for printing. The sheet feeding unit 223 can feed the set sheets under the control of the print control unit 224. The sheet feeding unit 223 may include a plurality of sheet feeding units to hold a plurality of types of sheets in a single device, and may be controlled under the control of the print control unit 224 to determine from which sheet feeding unit the sheets are fed.
[0035] The print control unit 224 performs various image processing such as smoothing processing, print density correction processing, and color correction on the image data to be printed, and outputs the processed image data to the print unit 222. The print unit 222 is configured to perform, for example, an inkjet printing process. The print unit 222 ejects ink supplied from an ink tank through a print head, and records an image on a recording medium such as a paper sheet. The print unit 222 may be configured to perform another print process such as an electrophotographic print process. In addition, the print control unit 224 may periodically read information about the print unit 222 and update, for example, status information stored in the RAM 214. The status information includes, for example, the remaining amount of the ink tank and the status of the print head.
[0036] The wireless unit 226 is a unit capable of providing a WLAN communication function. For example, the wireless unit 226 can provide a function similar to the function combined with the WLAN unit 401 of the mobile terminal device 104. That is, according to the WLAN standard, the wireless unit 226 converts data into a packet and sends the packet to another device, or restores a packet from another external device to the original data and outputs the original data to the CPU 212. The wireless unit 226 can communicate as a station conforming to the IEEE 802.11 standard series. In particular, the wireless unit 226 can communicate as an IEEE 802.11a / b / g / n / ac / ax station. In the following description, the station may be referred to as a STA. In addition, the wireless unit 226 can communicate as a Wi-Fi Agile Multiband (registered trademark) STA.
[0037] The wireless unit 226 supports IEEE 802.11ax or Wi-Fi 6 (registered trademark) and can perform processing in accordance with IEEE802.11ax. That is, the MFP 100 can perform one or both of the processing of STAs supporting (or compatible with) OFDMA and the operation (processing) of STAs supporting (or compatible with) TWT. OFDMA is the abbreviation of "Orthogonal Frequency Division Multiple Access". TWT is the abbreviation of "Target Wake Time". Since the wireless unit 226 supports TWT, the timing of data communication from the host device to the STA is adjusted. When there is no need to wait for signal reception, the wireless unit 226 (ie, the MFP 100) used as a STA puts the communication function into a sleep state. This construction can reduce power consumption. The wireless unit 226 also supports Wi-Fi 6E (registered trademark). That is, the wireless unit 226 can also communicate on the 6GHz band (5.925GHz to 7.125GHz). The 6 GHz band does not include a target band for implementing dynamic frequency selection (DFS) included in the 5 GHz band. Therefore, in communication on the 6 GHz band, communication disconnection caused by DFS waiting time does not occur. Therefore, more satisfactory communication can be expected.
[0038] The mobile terminal device 104 and the MFP 100 can perform point-to-point (P2P) (WLAN) communication based on Wi-Fi Direct (WFD), and the wireless unit 226 has a software access point (Soft AP) function or a group owner function. That is, the wireless unit 226 can establish a P2P communication network and determine a channel to be used for P2P communication.
[0039] Operation display unit of MFP
[0040] FIG. 3A to FIG. 3C An example screen displayed on the display (touch panel display) included in the operation display unit 220 of the MFP 100 is schematically shown. Figure 3A An example of a home screen displayed when an operation such as printing or scanning is not performed after the power of the MFP 100 is turned on (when the MFP 100 is in an idle state or a standby state) is shown. Figure 3A , display items (menu items) labeled "Copy", "Scan", and "Cloud" are displayed. The "Cloud" item is a menu item related to a cloud function using Internet communication. When one of the menu items is selected by key operation or touch panel operation, the MFP 100 can start implementing the corresponding setting or function. Figure 3A The main screen shown accepts key operations or touch panel operations to display the Figure 3A The screen shown in the figure is different from the screen shown in the figure.
[0041] Figure 3B An example of displaying another part of the home screen is shown. In response to an operation to display another page of the home screen (such as sliding from left to right or vice versa), a switch from Figure 3A The status shown is Figure 3B The screen shown in the figure will change. Figure 3B In the display, display items (menu items) labeled "communication settings", "print" and "photo" are displayed. When one of these menu items is selected, the function corresponding to the selected menu item, that is, one of the print function, the photo function and the communication settings is implemented.
[0042] Figure 3C This shows an example of a display of the menu screen for communication settings. Figure 3B This menu screen is displayed when communication settings are selected on the screen shown. The menu screen for communication settings displays menu items (options) "Wireless LAN", "Wired LAN", "Wireless Direct", "Bluetooth", and "General Settings". The "Wireless LAN" item, the "Wired LAN" item, and the "Wireless Direct" item are menu items for making LAN settings, and one of these items is used to make settings such as setting a wired connection, enabling or disabling the wireless infrastructure mode, or enabling or disabling the P2P mode (such as WFD or soft AP mode). When the "Wireless LAN" item is selected and the wireless LAN is set to enable through user operation, the wireless infrastructure mode is enabled. When the "Wireless Direct" item is selected and the wireless direct connection is set to enable through user operation, the P2P (WLAN) mode is enabled. This screen also displays the "General Settings" menu related to each connection mode. On this screen, the user can further set the frequency band and frequency channel of the wireless LAN.
[0043] Figure 3D This shows an example of a display of the menu screen for wireless LAN settings. Figure 3C This menu screen is displayed when wireless LAN is selected on the screen shown. The menu screen for wireless LAN settings displays menu items (options) "Enable / disable wireless LAN", "Wireless LAN settings", "Wireless LAN information display", and "Wireless LAN advanced settings". These items allow configuration of settings such as enabling or disabling wireless infrastructure mode, setting up wireless LAN, displaying wireless LAN information, or configuring wireless LAN advanced settings. In addition, these items are displayed as an interface capable of receiving a user's selection instruction.
[0044] Appearance of mobile terminal equipment
[0045] Figure 4A4 is a diagram showing an example appearance of a mobile terminal device 104. In the present embodiment, as an example, the mobile terminal device 104 is a typical smart phone. The mobile terminal device 104 includes, for example, a display unit 402, an operation unit 403, and a power key 404. The display unit 402 is, for example, a display including an LCD display mechanism. The display unit 402 can display information by using, for example, an LED. In addition to the display unit 402 or instead of the display unit 402, the mobile terminal device 104 can have a function of outputting information by voice. The operation unit 403 includes hard keys such as keys and buttons, a touch panel, etc. to detect user operations.
[0046] In the example shown, a normal touch panel display is used to display information on the display unit 402 and accept user operations through the operation unit 403. Therefore, the display unit 402 and the operation unit 403 are implemented by a single device. In this case, for example, a button icon or a soft keyboard is displayed using the display function of the display unit 402, and a user's touch on the button icon or the soft keyboard is detected by the operation acceptance function of the operation unit 403. The display unit 402 and the operation unit 403 can be separated from each other, and hardware for display and hardware for operation acceptance can be provided separately. The power key 404 is a hard key for accepting a user operation for turning on or off the power of the mobile terminal device 104.
[0047] The mobile terminal device 104 includes a WLAN unit 401 that provides a WLAN communication function. The WLAN unit 401 may not be visible from the outside. The WLAN unit 401 is configured to perform data (packet) communication in a WLAN system that complies with, for example, the IEEE 802.11 series of standards (e.g., IEEE 802.11a / b / g / n / ac / ax).
[0048] In addition, the WLAN unit 401 can communicate as a Wi-Fi Agile Multiband (registered trademark) AP. However, the embodiments of the present disclosure are not limited to this configuration, and the WLAN unit 401 can be configured to perform communication in a WLAN system that complies with any other standard. In the example shown, it is assumed that the WLAN unit 401 can communicate on both the 2.4 GHz and 5 GHz frequency bands. It is also assumed that the WLAN unit 401 can perform communication based on WFD, communication in soft AP mode, communication in wireless infrastructure mode, etc. The operations in these modes will be described below.
[0049] The structure of mobile terminal equipment
[0050] Figure 4BAn example configuration of the mobile terminal device 104 is shown. In one example, the mobile terminal device 104 includes a main board 411 for main control of the mobile terminal device 101 and a WLAN unit 429 for WLAN communication. The main board 411 includes, for example, a CPU 412, a ROM 413, a RAM 414, an image memory 415, a data conversion unit 416, a telephone unit 417, a GPS 419, a camera unit 421, a nonvolatile memory 422, a data storage unit 423, a speaker unit 424, and a power supply unit 425. CPU is an abbreviation of "Central Processing Unit", ROM is an abbreviation of "Read Only Memory", and RAM is an abbreviation of "Random Access Memory". GPS is an abbreviation of "Global Positioning System". The mobile terminal device 104 also includes a display unit 420 and an operation unit 418. The functional units in the above-mentioned main board 411 are connected to each other via a system bus 628 managed by the CPU 412. The main board 411 and the WLAN unit 429 (the above-described WLAN unit 401 ) are connected to each other via, for example, a dedicated bus 426 .
[0051] The CPU 412 is a system control unit including at least one processor, and controls the overall operation of the mobile terminal device 104. In one example, the processing of the mobile terminal device 104 described below is implemented by the CPU 412 executing the program stored in the ROM 413. Hardware dedicated to each processing can be provided. The ROM 413 stores the control program executed by the CPU 412, the embedded OS program, etc. In the present embodiment, the CPU 412 executes the various control programs stored in the ROM 413 under the management of the embedded OS stored in the ROM 413 to control software such as scheduling tasks and switching tasks.
[0052] RAM 414 includes, for example, SRAM. RAM 414 stores data such as data of program control variables, setting values registered by the user, and data for managing mobile terminal device 104. RAM 414 can also be used as a buffer for various jobs. Image memory 415 includes a memory such as DRAM. Image memory 415 temporarily stores image data received via WLAN unit 429 and image data read from data storage unit 423 so that CPU 412 processes image data. For example, non-volatile memory 422 includes a memory such as flash memory, and can continuously store data even after the power supply of mobile terminal device 104 is disconnected. The memory configuration of mobile terminal device 204 is not limited to the above configuration. For example, image memory 415 and RAM 414 can be shared, or data storage unit 423 can be used to back up data. In the present embodiment, an example of image memory 415 is DRAM. However, any other storage medium such as a hard disk or non-volatile memory can be used as image memory 415.
[0053] The data conversion unit 416 performs analysis of data in various formats and data conversion such as color conversion and image conversion. The telephone unit 417 controls the telephone line and processes audio data input or output via the speaker unit 424 to achieve telephone communication. The GPS 419 receives radio waves transmitted from a satellite and acquires position information such as the latitude and longitude of the current position of the mobile terminal device 104.
[0054] The camera unit 421 has a function of electronically recording and encoding an image input via a lens. The image data of the image captured by the camera unit 421 is stored in the data storage unit 423. The speaker unit 424 controls to realize a function of inputting or outputting a voice for a telephone function, or realizes other functions such as an alarm notification. The power supply unit 425 is, for example, a portable battery, and controls the power supply to the mobile terminal device 104. The state of the power supply includes, for example, a depleted battery state in which the battery has no remaining capacity, a power-off state in which the power key 404 remains unpressed, an activated state in which the mobile terminal device 104 is normally activated, and a power saving state in which the mobile terminal device 104 is activated and in a power saving mode.
[0055] The display unit 420 corresponds to the reference Figure 4A The display unit 402 described above accepts various input operations and displays the operation status and conditions of the MFP 100 under the control of the CPU 412, for example. The operation unit 418 corresponds to the display unit 402 described above. Figure 4A The operation unit 418 performs control in response to a user operation so as to generate an electric signal corresponding to the operation and output the electric signal to the CPU 412, for example.
[0056] In the mobile terminal device 104, the WLAN unit 429 is used to perform wireless communication and data communication with other devices such as MFP 100. The WLAN unit 429 converts data into packets and sends the packets to another device. In addition, the WLAN unit 429 restores the packets from another external device to original data and outputs the original data to the CPU 412. The WLAN unit 429 is a unit for implementing communication that complies with various WLAN standards. The WLAN unit 429 can operate simultaneously in at least two communication modes including a wireless infrastructure mode and a P2P (WLAN) mode. The frequency bands used in these communication modes may be limited by hardware functions and capabilities.
[0057] Access point configuration
[0058] Figure 5 1 is a block diagram showing the configuration of an access point AP1 101 having a wireless LAN access point function. The access point AP1 101 includes a main board 510 for controlling the access point AP1 101 , a wireless LAN unit 516 , a wired LAN unit 518 , and an operation button 520 .
[0059] The CPU 511 is in the form of a microprocessor arranged on the main board 510, and operates according to the control program stored in the program memory 513 in the form of ROM and the content of the data memory 514 in the form of RAM. The program memory 513 and the data memory 514 are connected to the CPU 511 via the internal bus 512. The CPU 511 controls the wireless LAN unit 516 through the wireless LAN communication control unit 515 to perform wireless LAN communication with other communication terminal devices. In addition, the CPU 511 controls the wired LAN unit 518 through the wired LAN communication control unit 517 to perform wired LAN communication with other communication terminal devices. The CPU 511 can control the operation unit control circuit 519 to accept the operation from the user using the operation button 520. The CPU 511 includes at least one processor.
[0060] The access point AP1 101 further includes an interference wave detection unit 521 and a channel change unit 522 .
[0061] The interference wave detection unit 521 performs a process of detecting an interference wave during wireless communication performed on a frequency band implementing DFS. The channel change unit 522 performs a process of changing a channel to be used in response to detecting an interference wave during wireless communication performed on a frequency band implementing DFS, for example, when a channel immediately needs to be changed to an available channel.
[0062] The access point AP2 102 has a configuration similar to that of the access point AP1 101 .
[0063] P2P communication method
[0064] Next, a P2P (WLAN) communication method will be briefly described, which allows devices to directly communicate with each other wirelessly without using an external access point in WLAN communication. P2P (WLAN) communication can be achieved by using a variety of methods. For example, a communication device supports a variety of modes for P2P (WLAN) communication and selectively uses one of the multiple modes to perform P2P (wireless LAN) communication.
[0065] The following two P2P modes are provided:
[0066] Soft AP mode; and
[0067] WFD mode.
[0068] A communication device capable of performing P2P communication may be configured to support at least one of these modes. However, even a communication device capable of performing P2P communication does not need to support all of these modes, and may be configured to support only a portion of these modes.
[0069] A communication device with a WFD communication function (e.g., mobile terminal device 104) calls an application (or a dedicated application, if any) for implementing the communication function in response to a user operation accepted via an operation unit of the communication device. The communication device then displays a screen of a user interface (UI) provided by the application to prompt the user to perform an operation, and can perform WFD communication in response to acceptance of the operation performed by the user.
[0070] Soft AP Mode
[0071] In soft AP mode, a communication device (e.g., mobile terminal device 104) operates in the role of a client requesting various services. Then, another communication device (e.g., MFP 100) operates as a soft AP set by software to implement the function of an AP in a WLAN. Since the commands and parameters sent and received in the wireless connection established between the client and the soft AP are commands and parameters defined by the Wi-Fi (registered trademark) standard, their description will be omitted. The MFP 100 operating in soft AP mode operates as a master station and determines the frequency band and frequency channel. Therefore, the MFP 100 can select which frequency band to use from the 5 GHz band and the 2.4 GHz band, and which frequency channel to use in the band.
[0072] WFD Mode
[0073] The MFP 100 can be activated as a fixed master station (i.e., an autonomous group owner) in the WFD mode. In this case, the group owner (GO) negotiation process for determining the role is not performed. In addition, in this case, the MFP 100 operates as a master station and determines the frequency band and the frequency channel. Therefore, the MFP 100 can select which frequency band to use from the 5 GHz band and the 2.4 GHz band, and which frequency channel to use in the frequency band.
[0074] Wireless Infrastructure Mode
[0075] In the wireless infrastructure mode, communication devices (e.g., mobile terminal device 104 and MFP100) that communicate with each other are connected to an external AP (e.g., access point AP1 101) that controls the network, and communication between the communication devices is performed via the external AP. In other words, communication is performed between the communication devices via a network established by an external AP. The mobile terminal device 104 and the MFP 100 individually discover the access point AP1 101, send a connection request to the access point AP1 101, and connect to the access point AP1 101. As a result, these communication devices can communicate with each other in the wireless infrastructure mode via the access point AP1 101. Multiple communication devices can be connected to different APs. In this case, data transmission is performed between APs to allow communication between communication devices. Since the commands and parameters sent and received during communication between communication devices via one or more access points are commands and parameters defined by the Wi-Fi (registered trademark) standard, their description will be omitted. In this case, the access point AP1 101 determines the frequency band and frequency channel. Therefore, the access point AP1 101 may select which frequency band to use from among the 5 GHz frequency band, the 2.4 GHz frequency band, and the 6 GHz frequency band, and which frequency channel to use in the frequency band.
[0076] Processing in response to a connection destination change request from an AP to a STA
[0077] The mobile terminal device 104 and the MFP 100 support a feature publicly available as Wi-Fi Agile Multiband (registered trademark). The Wi-Fi Agile Multiband feature enables the selection of the best environment according to the changing situation of the Wi-Fi network. Specifically, STA (such as the mobile terminal device 104 and the MFP 100) and AP (such as the access point AP1 101) exchange information about the network environment by using the IEEE 802.11 series of communication standards. This exchange of information allows the AP to guide the STA to another AP, frequency band or channel when the network is congested, or even to other cellular services (change the connection destination) in some cases.
[0078] Figure 6 10 is a sequence diagram of a process in which the MFP 100 switches the connection destination AP to connect from the access point AP1 101 to the access point AP2 102 according to a connection destination change request from the access point AP1 101 .
[0079] The processing performed by the respective devices in the illustrated sequence is realized by the CPU included in the device reading various programs stored in a memory included in the device such as a ROM into a RAM included in the device and executing the programs.
[0080] exist Figure 6 In the illustrated process, in the initial state, the MFP 100 has established a connection in the wireless infrastructure mode with the access point AP1 101. When the MFP 100 and the access point AP1 101 are connected to each other in the wireless infrastructure mode, the access point AP1 101 has acquired information indicating whether the MFP 100 supports IEEE 802.11v. If the access point AP1 101 has acquired information indicating that the MFP 100 supports IEEE 802.11v, the following process is performed.
[0081] In S601, the access point AP1 101 transmits an inquiry (measurement request) about the radio field strength of an AP located near the MFP 100 to the MFP 100. The inquiry is transmitted as, for example, a beacon frame request or a beacon report request. That is, a request defined by the IEEE 802.11k standard may be used.
[0082] In S602, the MFP 100 receives frames transmitted from APs located near the MFP 100 in response to the request received in S601, and measures the respective radio field strengths of the APs. As a result, the radio field strengths of the respective APs including the access point AP1 101 and the access point AP2 102 are measured. This process is called AP search.
[0083] In S603, the MFP 100 sends a list of radio field strengths of APs located near the MFP 100 measured in S602 as a response to the request received in S601. The radio field strengths sent as a response may be information stored in, for example, the RAM 214 and the nonvolatile memory 215 of the MFP 100, in addition to or instead of the information measured in S602. The response is sent as, for example, a beacon report or a measurement report.
[0084] In S604, the access point AP1 101 determines whether to switch the connection destination of the MFP 100 based on the network congestion recognized by the access point AP1 101 and the radio field strength received from the MFP 100 in S603. Examples of factors for the access point AP1 101 to determine to change the connection destination include the following.
[0085] A large number of STAs connected to access point AP1 101 (at or above a threshold);
[0086] A large amount of communication (at or above a threshold) between access point AP1 101 and STAs connected to access point AP101;
[0087] the presence or absence of interfering radio waves determined based on a signal-to-noise ratio (SN); and
[0088] The AP function stops.
[0089] In addition, the determination of whether to switch the connection destination can be made based on the congestion level of the AP determined through communication between APs (the number of connected STAs and the amount of communication). When the connection destination of the MFP 100 is determined to be switched and the SSID, channel, and frequency band of another AP designated as the connection destination to which the MFP 100 will switch are determined, the process proceeds to S605. According to the present embodiment, the extended service set identifier (ESSID) of another AP designated (recommended) as the target access point for switching is the same as the ESSID of the source AP (the basic service set identifier (BSSID) is different for the AP). Alternatively, an AP having an ESSID different from the ESSID of the source AP can be recommended. The value of the BSSID is the same as the media access control (MAC) address of the AP (i.e., the identification information of the AP).
[0090] In S605, the access point AP1 101 transmits an AP change request (connection destination change request) to the MFP 100. The connection destination change request includes information on the BSSID, channel, and frequency band of other APs (hereinafter referred to as recommended APs) designated as destinations to be connected to by the MFP 100 determined in S604. There may be a case where multiple BSSIDs are designated.
[0091] Specifically, multiple APs can be designated as recommended APs for handover. The connection destination change request is sent as, for example, a basic service set (BSS) transition management (BTM) request. That is, a BTM request frame defined by the IEEE 802.11v standard is sent. Figure 6 In the illustrated example, the access point AP2 102 is specified as the destination (recommended AP) included in the connection destination change request.
[0092] In S606, if the MFP 100 follows the connection destination change request received in S605, the MFP 100 sends a response indicating acceptance of the switching of the connection destination to the access point AP1 101. If the MFP 100 does not follow the connection destination change request, the MFP 100 may send a response indicating rejection of the switching of the connection destination. This response is sent as a BTM response. Figure 6 In the illustrated example, it is assumed that a response indicating acceptance of switching of the connection destination is transmitted.
[0093] In S607, the access point AP1 101 and the MFP 100 disconnect in the wireless infrastructure mode.
[0094] In S608 , the MFP 100 transmits a connection request to the access point AP2 102 to connect to the access point AP2 102 specified by the connection destination change request received in S605 .
[0095] As a result, in S609 , a connection in the wireless infrastructure mode between the MFP 100 and the access point AP2 102 is established.
[0096] This mechanism allows the MFP 100 serving as the STA to change the connection destination from the access point AP1 101 (the AP before the connection destination change) to the access point AP2 102 according to a connection destination change request from the access point AP1 101 to which the MFP 100 was originally connected. The access point AP1 101 and the access point AP2 102 may be located at different locations. That is, by Figure 6 By the process shown, the MFP 100 can switch the connection destination from the AP to which the MFP 100 is initially connected to another AP installed at a different location. The access point AP1 101 and the access point AP2 102 can support different frequency bands among a plurality of frequency bands (two or three of the 2.4 GHz band, the 5 GHz band, and the 6 GHz band) provided by the same device. That is, by Figure 6 By the process shown, the MFP 100 can switch the frequency band to another frequency band provided by the same device as the AP to which the MFP 100 was originally connected. For example, the MFP 100 can change the connection destination to an AP in the 6 GHz frequency band in response to the connection destination change request.
[0097] This embodiment describes an example in which a measurement request and a connection destination change request are sent from an AP by using a mechanism compliant with Wi-Fi Agile Multiband (registered trademark), and the STA responds to these requests. However, the present disclosure is not limited to this example. This embodiment is also applicable when the STA responds to and changes the connection destination AP (switches, deletes, or adds an AP used as a connection destination) in response to a measurement request and a connection destination change request sent from an AP by using a mechanism different from the mechanism in the above example.
[0098] There are cases where it is acceptable to change the connection destination AP based on a request to change the connection destination AP sent from the currently connected AP and cases where it is not desirable to change the connection destination AP based on a request to change the connection destination AP sent from the currently connected AP. In the case where it is not desirable to change the connection destination AP based on the change request, one of the processes described below or a combination of any processes may be performed as a process for preventing the connection destination from being changed in response to the change request. The processes described below are processes for preventing the connection destination AP from being changed based on the change request or processes for reducing the possibility of a change occurring.
[0099] First inhibition treatment
[0100] Even when the change request described in S605 is received, the change of the connection destination AP based on the received change request is not performed, and the response to the change request is not returned, or a response indicating rejection of the change request (indicating that the connection destination AP will not be changed) is sent to the currently connected AP. In the case of sending a response indicating rejection, the priority of changing the connection destination of another STA connected to the AP currently connected to the MFP 100 is increased, and the priority of changing the connection destination of the MFP 100 that has returned a response indicating rejection is reduced, so that the connection with the currently connected AP is allowed to be maintained. In addition, in the case where no response is returned (in the case of ignoring), the currently connected AP is expected to maintain the connection with the MFP 100 while waiting for the response until the response waiting time expires. Therefore, in the case of disconnecting immediately when receiving a response to the change request from the MFP 100, not responding instead of returning a response increases the time that the connection with the currently connected AP can be maintained. Therefore, different processing can be implemented according to the reason for the change based on the information about the reason included in the change request. For example, if the reason is weak, a response indicating rejection can be returned, and if the reason is strong, the request can be ignored. The reason for the change is determined based on information included in the request pattern in the BTM request and indicating which of several reasons is applicable. For example, if the DisassociationImminent bit or the BSS Termination Included bit in the request pattern is 1, the change reason in the change request is determined to be strong. Otherwise, the reason for the change is determined to be weak.
[0101] Second inhibition treatment
[0102] In response to the measurement request described in S601, information indicating that the radio reception condition (signal reception condition) of an AP that is not the currently connected AP has a low signal quality different from the actual measurement condition is provided (a false response is provided). In this case, measurement may be performed when a measurement request is received to provide a response, or a response may be provided without performing measurement.
[0103] Specifically, in the response described in S603 (such as a beacon report), a value obtained by reducing the received signal strength from the measured signal quality of the signal received from the unconnected AP is provided, or / and a value of the noise (signal-to-noise ratio) increase is provided. Alternatively, the response may omit at least one piece of information about the unconnected AP. In addition, based on the previous measurement information about the unconnected AP, a process of reducing the received signal strength to a significantly low value or responding with a value with significantly increased noise may be performed. In addition, although a measurement request is received, a response that does not include unconnected AP information and only indicates that the received signal strength and noise conditions of the currently connected AP are good may be provided without actually performing measurement (AP search). Responding to a measurement request that does not include unconnected AP information corresponds to content indicating that no other unconnected APs were found through the AP search. In other words, a response that does not include unconnected AP information corresponds to content indicating that the signal quality from the unconnected AP is at least partially different from the actual AP search result.
[0104] By performing the above-described processing, it is possible to prevent the transmission of a request to change the connection destination from the currently connected AP to another AP. As a result, the connection destination is prevented from being changed based on the connection destination change request.
[0105] The third inhibition treatment
[0106] After temporarily disconnecting the connection with the currently connected AP, information indicating that the change request is not supported is notified, and the connection with the same AP is reestablished. Specifically, the wireless connection with the currently connected AP is temporarily disconnected, and association request frame data including information indicating that IEEE 802.11v is not supported is generated as a preparation for reconnecting wirelessly. Thereafter, the generated association request frame data is used to perform processing to connect to the AP. Therefore, in the case where the association request frame data including information indicating that IEEE 802.11v is not supported is generated, the electronic device is connected to the AP as an electronic device that does not support the Agile Multiband function. As a result, the currently connected AP recognizes that the MFP 100 does not support IEEE 802.11v, and stops sending a wireless connection destination change request to the MFP 100. Since no request to change the wireless connection is sent to the MFP 100, it is more likely to maintain the wireless connection between the MFP 100 and the currently connected AP. In addition, in the case where the currently connected AP recognizes that the MFP 100 does not support IEEE 802.11v, the measurement request (the request described in S601) is also stopped from the currently connected AP to the MFP 100. Therefore, measurement (AP search) based on the measurement request and response to the measurement request (processing of S603) by the MFP 100 are also suppressed. As a result, the processing load is reduced, and power consumption is also reduced. In addition, resources can be allocated to other processing.
[0107] An example of a state in which it is not desirable to change the connection destination AP based on the change request is a state in which print data is being received. The state in which the MFP 100 is receiving print data is a state in which a part of the print data of the image to be printed has been received from the mobile terminal device 104 as the counterpart device, but the remaining print data has not yet been received. The MFP 100 performs printing by repeating the following process: receiving a part of the print data to be printed on one sheet, printing the received part (for example, receiving one line and printing the received one line), receiving subsequent data, and printing the received subsequent data. When print data is being received, if the connection destination AP is changed based on the connection destination change request, a time delay occurs in the process of switching the connection destination, which may cause a decrease in print quality such as printing inconsistency. In addition, after the connection destination is switched, communication with the mobile terminal device 104 as the counterpart device may become unreliable, which may cause a failure to receive subsequent data, thereby causing a printing failure. Therefore, when print data is being received, at least one of the first suppression process and the second suppression process is performed as a process to prevent the connection destination from being changed based on the change request, or the above-mentioned third suppression process is performed before the start of print data reception.
[0108] Meanwhile, the connection destination change request received from the currently connected AP may include an AP as a switching candidate of the connection destination, which is not suitable as the connection destination AP of the STA.
[0109] For example, an AP whose security strength is lower than that of the currently connected AP may be included as a switching candidate for the connection destination. In this case, if the connection destination AP is switched based on a connection destination change request from the currently connected AP, the security strength of the connection to the AP may be reduced. Therefore, efforts need to be made to switch the STA to a suitable connection destination AP.
[0110] According to the present embodiment, the MFP 100 is connected to the AP based on the standard security strength method. Specifically, control is performed so as to prevent connection to an AP that is a change destination candidate in the change request and uses a security method with a strength lower than the standard security method. With the above configuration, the STA is switched to an appropriate connection destination AP.
[0111] In addition, for example, an AP using a security method that is not supported by the MFP 100 or is restricted by the setting of the MFP 100 may be included as a switching candidate for the connection destination. In this case, if the connection destination AP is switched to the switching candidate AP based on the connection destination change request, the MFP 100 may not be able to connect to the switching destination AP. Therefore, it is necessary to make an effort to switch the STA to a suitable connection destination AP.
[0112] Therefore, according to the present embodiment, the MFP 100 performs control so as to prevent processing of changing the connection destination AP to an AP that is a change destination candidate in the change request and cannot be connected using the security method available to the MFP 100.
[0113] In addition, for example, an AP having an authentication method different from that before switching may be included as a switching candidate for the connection destination. Specifically, while the authentication method of the currently connected AP is the personal mode, an AP in the enterprise mode may be included as a recommended AP. Conversely, when the authentication method of the currently connected AP is the enterprise mode (the authentication method using the authentication server), an AP having an authentication method different from the enterprise mode (such as the personal mode) may be included as a recommended AP. In this case, if the connection destination AP is switched to a switching candidate AP based on a connection destination change request, the MFP 100 may not be able to maintain the security conditions expected by the user, or may not be able to connect to the switching destination AP. Therefore, efforts need to be made to switch the STA to a suitable connection destination AP. Therefore, according to the present embodiment, control is performed so as to prevent the connection destination from being changed to an AP having a different authentication method from that of the connected AP.
[0114] In this specification, a request to change the connection destination AP received by the MFP 100 from the currently connected AP is sometimes referred to as a “connection destination change request” or a “change request.” Furthermore, in this specification, a request to change the connection destination AP is in other words a request to switch the connection destination AP.
[0115] Flow based on currently connected AP request
[0116] Figure 7 2 is a flowchart showing an example of processing corresponding to an AP search request and a connection destination change request executed by the MFP 100. In the flowchart, the processing executed by the MFP 100 is realized by the CPU 212 reading various programs stored in a memory such as the ROM 213 to the RAM 214 and executing the read programs.
[0117] In S701, the CPU 212 starts to configure the wireless LAN settings. Specifically, the CPU 212 receives an instruction to start configuring the wireless infrastructure mode. The instruction to start configuring the wireless infrastructure mode may be, for example, based on Figure 3D The instruction of the user operation on the wireless LAN setting menu screen shown in FIG. The user operation may be, for example, an operation in which the user selects "Wireless LAN Setting" on the wireless LAN setting menu screen. In addition, the instruction to start the construction of the wireless infrastructure mode may be based on receiving a specific signal from an external device such as the mobile terminal device 104.
[0118] In S702, CPU 212 obtains AP information required for constructing wireless infrastructure mode. Specifically, for example, CPU 212 obtains AP information through AP search. For example, in S702, CPU 212 starts searching for AP by sending a device discovery request (probe request). Thereafter, CPU 212 performs AP search and discovery by receiving wireless signals such as device discovery response (probe response) and beacon (information actively sent by AP at regular intervals) sent from AP. The AP information obtained from AP through the above-mentioned AP search includes information indicating at least one of the SSID, radio field strength, frequency band, MAC address, authentication method and encryption method of the AP. The content of the AP information varies depending on the model type, model number and settings of the AP.
[0119] For example, when the MFP 100 does not support the security method (authentication method, encryption method) used by the AP, the CPU 212 can exclude the AP information from the AP search results. In addition, when the security method used by the AP is not supported by the MFP 100 and / or includes only limited security methods, the CPU 212 can exclude the AP information from the AP search results.
[0120] After completing the AP search in S702, the CPU 212 displays the AP list found by the AP search on the operation display unit 220 of the MFP 100. The AP list is a content indicating the results of the AP search. The AP list is displayed as an interface capable of receiving a selection instruction from the user, for example. For example, the CPU 212 can display the AP identification information list obtained by the AP search on the operation display unit 220 as the AP list. The AP identification information can be, for example, an SSID or a device name. For example, in the case where the AP selected by the user uses a security method that requires authentication information such as a password, the CPU 212 receives the input of the password of the AP selected by the user. As described above, the CPU 212 can obtain the password of the AP selected by the user by receiving the user's input of the password for the AP. In the case where the AP selected by the user uses a security method that does not require a password, the CPU 212 does not receive the input of the password in S702. Examples of methods that do not require a password include the OPEN method and the Extensible Authentication Protocol (EAP) method described below.
[0121] The present embodiment describes an example in which the CPU 212 displays an AP search result on the operation display unit 220 of the MFP 100 and receives a password input for an AP selected by a user. However, the present disclosure is not limited to this example. For example, the AP information in S702 can be acquired from the AP using a function called Wi-Fi Protected Setup (hereinafter referred to as "WPS") (registered trademark). In addition, the AP information in S702 can be acquired from an external device such as a mobile terminal device 104 using a function called Wi-Fi Easy Connect (hereinafter referred to as "WEC") (registered trademark). In addition, the AP information in S702 and the AP selection instruction from the user can be acquired by receiving a specific signal from an external device such as the mobile terminal device 104.
[0122] In S703, the CPU 212 performs control (recording control) so that AP information required for configuring the wireless infrastructure mode is recorded in the RAM 214 and / or the nonvolatile memory 215 based on the AP information acquired in S702. Figure 8Describe the details of the processing. When storing AP information in the process, information indicating the authentication method and encryption method of the AP is centrally stored as a security method. The AP information required for constructing the wireless infrastructure mode stored in S703 includes, for example, one or more of SSID, password, security method (authentication method and / or encryption method), frequency band, channel, communication standard, certificate information, and user name. SSID is one or both of ESSID and BSSID. The above information is stored based on a user operation on the operation display unit 220 of the MFP 100 or a specific signal received from an AP or an external device such as a mobile terminal device 104.
[0123] In S704, the CPU 212 performs connection processing using the AP information acquired in S702 to connect to the AP in accordance with the IEEE802.11 standard. The connection target AP in S704 is the AP selected based on the user instruction in S702.
[0124] In S705, the CPU 212 determines whether a measurement request is received from the currently connected AP. In the case where the CPU 212 determines that a measurement request is received ("Yes" in S705), the process proceeds to S706. Otherwise ("No" in S705), the process proceeds to S713. The measurement request here corresponds to the inquiry (measurement request) about the above-mentioned radio field strength in S601. In other words, the measurement request is a request for the AP search result, and is also a request for the measurement result of the radio wave condition (signal quality) of the neighboring AP near the MFP 100.
[0125] In S706, the CPU 212 performs the AP search described above in S602 and S702. The CPU 212 stores in the RAM 214 a list of AP information found by the AP search.
[0126] The following processing of S707 to S711 is performed on each AP discovered by the AP search. The AP discovered by the AP search can be included as an AP recommended as a connection destination AP in a change request received from the currently connected AP. That is, the AP discovered by the AP search is also a candidate AP that is a candidate for the connection destination AP of the MFP 100. The processing of S708 and S709 is a processing for determining whether the AP discovered by the AP search is a suitable candidate AP for the connection destination of the MFP 100. In addition, the processing of S710 is a processing for preventing the transmission of a connection request including an inappropriate connection destination AP by providing a false response to AP information that is not a suitable connection destination as in the second suppression processing. That is, the processing of S707 to S711 is a processing for preventing the MFP 100 from connecting to an AP that is not suitable as a connection destination. In other words, the processing of S707 to S711 is a processing for changing the MFP 100 to a suitable connection destination AP. Instead of the AP search in S706, the CPU 212 may perform the processing of S707 to 712 using stored AP information from a previous search.
[0127] In S707 , the CPU 212 starts repeating the processing of S708 to S710 for each AP found by the AP search in S706 .
[0128] In S708, the CPU 212 determines whether the AP found by the AP search satisfies a predetermined condition and stores the determination result. The predetermined condition is a condition for determining whether the AP is suitable as a target connection destination. That is, in S708, the CPU 212 determines whether the AP found by the AP search is suitable as a target AP for changing the connection destination. Fig. 9 The details of this processing are described.
[0129] In S709, the CPU 212 determines whether the condition for becoming the target connection destination AP after changing the connection destination AP is satisfied based on the determination result of S708. In the case where the CPU 212 determines that the condition for becoming the target is satisfied ("Yes" in step S709), the process proceeds to S711. On the other hand, in the case where the CPU 212 determines that the condition for becoming the target is not satisfied ("No" in step S709), the process proceeds to S710. Specifically, the CPU 212 makes a determination based on the information (determination result) stored in S905 or S906 described below. That is, in the case where the determination result is as in S905 described below, the process proceeds to S711, and in the case where the determination result is as in S906 described below, the process proceeds to S710.
[0130] In S710, the CPU 212 changes the contents of the AP information list stored in S706 to different contents. For example, the CPU 212 excludes (deletes) AP information that does not meet the conditions for becoming a target from the AP information list, or the CPU 212 changes the AP information that does not meet the conditions for becoming a target in the AP information list stored in S706 to information that is different from the actual measurement conditions. The different information refers to information indicating a signal quality lower than the signal quality actually measured in the AP search. This process is described in the second suppression process described above. In other words, the signal quality is a radio wave condition, and examples include radio field strength.
[0131] As described above, in the case where the AP found by the AP search does not satisfy the condition to become the connection destination AP, the CPU 212 excludes the AP that does not satisfy the condition from the AP search results, or the CPU 212 changes the information about the AP that does not satisfy the condition to information different from the actual measurement result. This prevents an AP that does not satisfy the condition to become a target from being included as a recommended AP in a connection destination change request sent from the AP currently connected to the MFP 100. That is, the connection destination of the MFP 100 is prevented from being changed to an AP that does not satisfy the condition of the security method.
[0132] In S711, the CPU 212 continues to repeat the processing of S708 and S709 or the processing of S708 to S710 for another AP found by the AP search in S706. In the case where the processing of all APs found by the AP search in S706 is completed, the process proceeds to S712.
[0133] In S712, as described above Figure 6 As described in S603, the CPU 212 sends a response to the measurement request to the currently connected AP. For example, in the case where the processing of S710 has been performed, since the content is different from the AP search result, in S712, the AP information list is sent as a false response.
[0134] In S713, the CPU 212 determines whether a connection destination change request is received from the currently connected AP. The change request corresponds to the access point AP1 101 receiving the connection destination change request from the currently connected AP. Figure 6 In a case where the CPU 212 determines that the change request is received (YES in S713), the process proceeds to S714. Otherwise (NO in S713), the process proceeds to S718.
[0135] In S714 to S716, the CPU 212 determines whether to change the connection destination to the recommended AP included in the change request, and performs processing to prevent the connection destination from being changed in response to the change request if the change is not appropriate. This processing corresponds to the above-described first suppression processing.
[0136] In S714, the CPU 212 determines whether the recommended AP included in the received change request satisfies a predetermined condition. The predetermined condition is a condition for determining suitability (appropriateness) as a target AP for changing the connection destination. That is, in S714, the CPU 212 determines whether the recommended AP is suitable as a target AP for changing the connection destination. Fig. 9 The details of this processing are described.
[0137] In S715 , the CPU 212 determines, based on the determination result of S714 , whether the recommended AP included in the change request satisfies the condition to become a target AP after the connection destination AP is changed.
[0138] In the case where the conditions for becoming a target are satisfied ("Yes" in S715), the process proceeds to S716. Otherwise ("No" in S715), the process proceeds to S718. Specifically, in the case where the determination result is as in S905 described below, the process proceeds to S716, and in the case where the determination result is as in S906 described below, the process proceeds to S718.
[0139] In S715, in the case where the CPU 212 determines that the conditions for becoming a target are not met (No in S715), as in the first suppression process described above, a response indicating rejection is sent to the currently connected AP without connecting to the recommended AP. In other words, the indication of rejection means that the connection destination AP is not changed. In addition, in the case where the CPU 212 determines that the conditions for becoming a target are not met, the change request may be ignored without returning a response.
[0140] In S716, the CPU 212 sends a response indicating acceptance of the received connection destination change request to the currently connected AP, and the process proceeds to S717. This process corresponds to Figure 6 Processing of S606.
[0141] In S717, the CPU 212 disconnects the currently connected AP and performs processing to connect to the recommended AP included in the connection destination change request (the recommended AP determined to satisfy the conditions for becoming a target in S714). This processing corresponds to Figure 6 The processing of S607 and S608 in .
[0142] As described above, in the case where the recommended AP does not satisfy the conditions of the connection destination AP, the CPU 212 controls so that a response indicating rejection of the change request is sent to the AP currently connected to the MFP 100, or the change request is ignored ("No" in S715). This prevents the connection destination AP from being changed to an AP of the recommended AP as a change destination candidate AP, and a security method that is not suitable for the MFP 100 is used. On the other hand, in the case where the recommended AP satisfies the conditions of the connection destination AP, a response indicating acceptance of the change request is sent, and processing for connecting to the recommended AP is performed ("Yes" in S715, S716 to S717). The above control of the CPU 212 enables the MFP 100 to connect to a suitable AP.
[0143] In S718, the CPU 212 determines whether to terminate the connection with the currently connected AP. In the case where the CPU 212 determines to terminate the connection ("Yes" in S718), Figure 7 The processing shown is terminated. On the other hand, in the case where the CPU 212 determines not to terminate the connection (No in S718), the processing proceeds to S705. Specifically, for example, the CPU 212 determines whether an instruction to disconnect the MFP 100 is received. The instruction for disconnection may be an instruction based on no operation on the operation display unit 220 of the MFP 100 within a predetermined time, or an instruction based on an operation of a power button (not shown) of the MFP 100.
[0144] Figure 7 An example is shown in which the processing of S707 to S711 (second suppression processing) and the processing of S714 to S716 (first suppression processing) are performed. However, the present disclosure is not limited to this example. For example, only one of the processing of S707 to S711 (second suppression processing) and the processing of S714 to S716 (first suppression processing) may be performed without performing the other.
[0145] Processing that stores the security method used when connecting to an AP
[0146] Figure 8 2 is a flowchart showing an example of a process of collectively storing information indicating an authentication method and an encryption method of an AP as a security method used when connecting to an AP when configuring the wireless infrastructure mode of the MFP 100. In the flowchart, the process performed by the MFP 100 is realized by the CPU 212 reading various programs stored in a memory such as the ROM 213 to the RAM 214 and executing the read programs. In the case where the AP information is acquired in S702, the process is performed in S703.
[0147] The security method will be described below. The following security method is used for wireless communication using a wireless LAN based on the IEEE 802.11 standard.
[0148] <Authentication method>
[0149] Examples of authentication methods supported by wireless APs include the following types:
[0150] (1) Pre-shared key (PSK) method using a pre-shared key;
[0151] (2) SAE method using Simultaneous Authentication of Equivalent Entities (SAE); and
[0152] (3) An Extensible Authentication Protocol (EAP) method that uses an IEEE 802.1X / EAP authentication server to authenticate a communication device connected to a network.
[0153] Examples of security methods (1) using PSK include the following methods:
[0154] (1-1) Wi-Fi Protected Access (WPA)-PSK; and
[0155] (1-2)WPA2-PSK method.
[0156] The PSK method is a personal method, and the authentication method (authentication category, authentication type, security category) of the PSK method is different from the authentication method of the enterprise method.
[0157] In addition, examples of using the SAE safety method (2) include the following methods:
[0158] (2-1)WPA3-SAE method.
[0159] In addition, examples of the security method (3) using the authentication server include the following methods:
[0160] (3-1)WPA-EAP;
[0161] (3-2) WPA2-EAP; and
[0162] (3-3)WPA3-EAP method.
[0163] The security method using the authentication server is an authentication method of the enterprise, and the authentication method (authentication category, authentication type, security category) of the security method is different from the authentication method of the individual.
[0164] <Encryption method>
[0165] Examples of encryption methods include the following:
[0166] Utilizing a counter mode of the Cipher Block Chaining Message Authentication Code (CBC-MAC) Protocol (CCMP) method using the Advanced Encryption Standard (AES);
[0167] Temporal Key Integrity Protocol (TKIP) method using Rivest Cipher 4 (RC4); and
[0168] Wired Equivalent Privacy (WEP) method.
[0169] In this specification, EAP refers to Extensible Authentication Protocol.
[0170] The above-mentioned relatively safe security methods (authentication methods, encryption methods) are, for example, the WPA3-SAE method (2-1) and the WPA / WPA2 / WPA3-EAP methods (3-1) to (3-3). Next, the methods that are second only to the relatively safe methods are the WPA / WPA2-PSK methods (1-1) and (1-2). In addition, examples of relatively unsafe security methods include the WEP method. In addition, the unsafe method is OPEN (no authentication). In addition, the encryption method using AES is a relatively safe method, the TKIP method is a relatively unsafe method, and the method without encryption is an unsafe method.
[0171] The security method supported by the MFP 100 varies depending on the model type, model number, and settings of the MFP 100. Examples of the security method supported by the MFP 100 according to the present embodiment include WPA-PSK, WPA2-PSK, WPA3-SAE, WPA-EAP, WPA2-EAP, WPA3-EAP, and OPEN (no authentication, no encryption). In addition, examples of the security method not supported by the MFP 100 include a method using TKIP or WEP as an encryption method.
[0172] In S801, the CPU 212 determines whether the authentication method used to connect to the AP is the WPA3-SAE method. For example, the CPU 212 determines the authentication method used by the AP (for which the selection instruction from the user is received) based on the AP information acquired in S702. In the case where the CPU 212 determines that the authentication method is the WPA3-SAE method ("Yes" in S801), the process proceeds to S802. On the other hand, in the case where the CPU 212 determines that the authentication method is not the WPA3-SAE method ("No" in S801), the process proceeds to S803.
[0173] In S802 , the CPU 212 stores a relatively secure method (WPA3-SAE method) as a security method in the RAM 214 and / or the nonvolatile memory 215 .
[0174] In S803, the CPU 212 determines whether the authentication method used to connect to the AP is at least one of the WPA-EAP method, the WPA2-EAP method, and the WPA3-EAP method. For example, the CPU 212 determines the authentication method used by the AP (for which the selection instruction from the user is received) based on the AP information acquired in S702. In the case where the CPU 212 determines that the authentication method used to connect to the AP is at least one of the WPA-EAP method, the WPA2-EAP method, and the WPA3-EAP method ("Yes" in S803), the process proceeds to S804. On the other hand, in the case where the CPU 212 determines that the authentication method used to connect to the AP is not any of the WPA-EAP method, the WPA2-EAP method, and the WPA3-EAP method ("No" in S803), the process proceeds to S805.
[0175] In S804 , the CPU 212 stores “relatively secure method (WPA / WPA2 / WPA3-EAP method)” as a security method in the RAM 214 and / or the nonvolatile memory 215 .
[0176] In S805, the CPU 212 determines whether the authentication method used to connect to the AP is at least one of the WPA-PSK method and the WPA2-PSK method. For example, the CPU 212 determines the authentication method used by the AP (for which the selection instruction from the user is received) based on the AP information acquired in S702. In the case where the CPU 212 determines that the authentication method is at least one of the WPA-PSK method and the WPA2-PSK method ("Yes" in S805), the process proceeds to S806. On the other hand, in the case where the CPU 212 determines that the authentication method is neither the WPA-PSK method nor the WPA2-PSK method ("No" in S805), the process proceeds to S807.
[0177] In S806 , the CPU 212 stores the “medium security method (WPA / WPA2-PSK method)” as the security method in the RAM 214 and / or the nonvolatile memory 215 .
[0178] In S807, the CPU 212 determines whether the authentication method used to connect to the AP is the OPEN (no authentication) method. For example, the CPU 212 determines the authentication method used by the AP (for which the selection instruction from the user is received) based on the AP information acquired in S702. In the case where the CPU 212 determines that the authentication method is the OPEN method ("Yes" in S807), the process proceeds to S808. On the other hand, in the case where the CPU 212 determines that the authentication method is not the OPEN method ("No" in S807), the process proceeds to S809.
[0179] In S808 , the CPU 212 stores “unsecure method (OPEN method)” as a secure method in the RAM 214 and / or the nonvolatile memory 215 .
[0180] In S809, the CPU 212 records other setting information (setting details) about the wireless infrastructure mode in the RAM 214 and / or the non-volatile memory 215. The setting information refers to, for example, AP information required to configure the wireless infrastructure mode. In this process, security methods are collectively stored for each authentication method type of the AP. Therefore, in the case where the strength of the security method of the recommended AP is the same type as the strength of the security method of the MFP 100, it is possible to connect to an AP with the same settings (such as ESSID or password).
[0181] The security method used by the MFP 100 to connect to the AP may be limited by receiving a user operation on the operation display unit 220 of the MFP 100 or a specific signal from an external device such as the mobile terminal device 104 .
[0182] Fig. 9 1 is a flowchart showing an example of a process for determining whether a target AP satisfies a predetermined condition of a connection destination AP. Fig. 9 An example of a process of determining whether a target AP is suitable for an AP after changing a connection destination is shown. Also in the flowchart, the process performed by the MFP 100 is implemented by the CPU 212 reading various programs stored in a memory such as the ROM 213 to the RAM 214 and executing the read programs.
[0183] exist Figure 7 Execute in S708 and S714 Fig. 9 That is, this process is performed on the AP found by the AP search based on the recommended AP included in the measurement request and the change request. That is, this process is performed when determining whether to change the connection destination AP.
[0184] In S901, the CPU 212 determines whether the security method of the determined target AP (hereinafter, the AP will be referred to as a "candidate AP") which is a candidate for the connection switching destination is a method available for use by the MFP 100. In the case where the CPU 212 determines that the security method is an available method ("Yes" in S901), the process proceeds to S902. On the other hand, in the case where the CPU 212 determines that the security method is not an available method ("No" in S901), the process proceeds to S906. Specifically, for example, in the case where the security method used in the network formed by the candidate APs is a method supported by the MFP 100 and the MFP 100 does not restrict the use of the method, the CPU 212 determines that the security method is an available method. In addition, in the case where the security method used by the candidate AP is at least one of a method not supported by the MFP 100 and a method restricted for use by the MFP 100, the CPU 212 determines that the security method is not an available method. As described above, the security method supported by the MFP 100 varies depending on the model type, model number, and settings of the MFP 100. In addition, the security methods supported by the MFP 100 are stored in advance in the nonvolatile memory 215, for example. In addition, the security methods available to the MFP 100 can be described by, for example, referring to Fig.10 The settings limit based on user actions as described above.
[0185] As described above, in addition to whether the MFP 100 supports the security method, in the case where the security method is supported by the MFP 100 but the use is restricted due to the setting, the determination result in S901 is "No". This prevents the connection destination AP from being changed when the MFP 100 receives a change request from the currently connected AP in the case where the security method of the candidate AP is not a method available to the MFP 100.
[0186] The present embodiment describes an example in which, in addition to whether the MFP 100 supports the security method, whether the use of the security method is restricted in the MFP 100 is added to the determination condition in S901. However, the present disclosure is not limited to this example. For example, in S901, the CPU 212 may only determine whether the MFP 100 supports the security method, without determining whether the use of the security method is restricted in the MFP 100. For example, a form may be adopted in which, in the case where the CPU 212 determines that the security method of the target AP is a method supported by the MFP 100, the process proceeds to S902, and in other cases, the process proceeds to S906.
[0187] In S902, the CPU 212 determines whether the security strength of the security method of the candidate AP is greater than or equal to Figure 7 The strength of the security method stored in S703 (see Figure 8 ). In a case where the CPU 212 determines that the strength of the method is greater than or equal to the stored security method (YES in S902), the process proceeds to S903. Otherwise (NO in S902), the process proceeds to S906.
[0188] A specific example of S902 will be described below. For example, if the CPU 212 Figure 7 In S703 of the CPU 212, "WPA1 / 2-PSK method" is stored as the security method, and the strength of the security method of the candidate AP is "WPA3-SAE" or "WPA1 / 2-PSK method", the process proceeds to S903. In addition, if the CPU 212 stores "WPA1 / 2-PSK method" in S703, and the strength of the security method of the candidate AP is "OPEN", the process proceeds to S906. In addition, for example, if the CPU 212 records "WPA3-SAE" in S703, and the strength of the security method of the candidate AP is "WPA3-SAE", the process proceeds to S903. In addition, if the CPU 212 records "WPA3-SAE" in S703, and the strength of the security method of the candidate AP is "WPA1 / 2-PSK method", the process proceeds to S906.
[0189] As described above, in a case where the strength of the security method used by the candidate AP is lower than the strength of the security method of the currently connected AP, the candidate AP is determined as an AP that does not satisfy the conditions of the connection destination AP. This prevents the connection destination AP from being changed to an AP having a security strength lower than that of the currently connected AP when the MFP 100 receives a change request from the currently connected AP. On the other hand, in a case where the security strength of the security method used by the candidate AP is greater than or equal to the security strength of the security method of the currently connected AP, the candidate AP is determined as an AP that satisfies the conditions of the connection destination AP.
[0190] In S903, the CPU 212 determines whether the type of the authentication method of the candidate AP (e.g., PSK method, SAE method, EAP method, OPEN method) is the same as the stored authentication method type. In the case where the CPU 212 determines that the types of the authentication methods are the same ("Yes" in S903), the process proceeds to S905. Otherwise ("No" in S903), the process proceeds to S904.
[0191] Consider, for example, Figure 8In the case where the security method stored in the process in (the security method set when the wireless infrastructure mode is configured) is one of the above-mentioned WPA-PSK (1-1) and WPA2-PSK method (1-2). In this case, if the security method of the candidate AP is one of the WPA-PSK (1-1) and WPA2-PSK method (1-2), since the authentication method type is the same PSK, the determination result of S903 is "yes". That is, for example, in Figure 8 In a case where the security method stored in the process in is WPA-PSK (1-1) and the security method of the candidate AP is the WPA2-PSK method (1-2), the determination result of S903 is "Yes".
[0192] On the other hand, it will be considered that e.g. Figure 8 In the case where the security method stored in is one of the above-mentioned WPA-PSK (1-1) and WPA2-PSK methods (1-2). In this case, if the security method of the candidate AP is the WPA3-SAE method (2-1), since the authentication method type is PSK and SAE, the determination result of S903 is "No". Similarly, in Figure 8 In the case where the method stored in the process in is one of the above-mentioned WPA-PSK (1-1) and WPA2-PSK methods (1-2), and the method of the candidate AP is WPA-EAP (3-1) or WPA2-EAP (3-2), the determination result of S903 is "No". In addition, Figure 8 In a case where the security method stored in the process corresponds to one of the personal mode and the enterprise mode, and the type of the security method of the candidate AP corresponds to the other of the personal mode and the enterprise mode, the authentication method types are different.
[0193] In S904, the CPU 212 determines whether a setting value corresponding to the authentication method of the candidate AP (e.g., SAE method, PSK method, EAP method, OPEN method) is recorded. In a case where the CPU 212 determines that the corresponding setting value is stored ("Yes" in S904), the process proceeds to S905. On the other hand, in a case where the CPU 212 determines that the corresponding setting value is not stored ("No" in S904), the process proceeds to S906.
[0194] The setting values corresponding to the authentication method will be described below. Examples of setting values required for the SAE method include a password. Examples of setting values required for the PSK method include a password and a pre-shared key (PSK). Examples of setting values required for the EAP method include a user name, a login name, and a certificate. EAP refers to enterprise mode. In other words, the setting value is information required based on the type of authentication method when the MFP 100 is connected to the AP. For example, the setting value corresponding to the authentication method is stored in the processing of S703. In the process executed as S703, for example Figure 8 As described above, even in a case where the type of authentication method used by the AP currently connected to the MFP 100 and the type of authentication method used by the candidate AP are different from each other, if the information required to establish a connection between different types is acquired, it is determined that the conditions for becoming a target AP for changing the connection destination are satisfied despite the different types.
[0195] For example, in a case where the security method of the currently connected AP is the "WPA1 / 2-PSK method" and the security method of the candidate AP is the "WPA1 / 2EAP method", it is determined in S903 that the types of authentication methods are different. Furthermore, in S904, in a case where it is determined that the setting value of the EAP method (the user name, login name, and certificate required for authentication in the EAP method) is stored, the candidate AP is not excluded from the target for changing the connection destination. That is, the connection destination is not prevented from being changed to the candidate AP based on the change request.
[0196] The present embodiment describes an example in which, in a case where the determination result of S903 is "No", the process proceeds to the process of S904. However, the present disclosure is not limited to this example. For example, a form may be adopted in which, in a case where the determination result of S903 is "No", the process of S904 is skipped and the process proceeds to S905. That is, in a case where the type of authentication method of the currently connected AP and the type of authentication method of the candidate AP are different from each other, the CPU 212 may uniformly determine that the condition for becoming a target is not satisfied.
[0197] In S905, the CPU 212 determines that the AP is suitable as a target for changing the connection destination based on the change request. That is, after changing the connection destination, it is determined that the candidate AP meets the conditions for becoming the target AP. In addition, the CPU 212 stores the determination result in the RAM 214 and / or the non-volatile memory 215.
[0198] In S906, the CPU 212 determines that the AP is not suitable as a target for changing the connection destination based on the change request. That is, after changing the connection destination, it is determined that the candidate AP does not meet the conditions for becoming a target AP. The CPU 212 stores the determination result in the RAM 214 and / or the non-volatile memory 215.
[0199] Setting screen for limiting the security method used when connecting to an AP
[0200] Fig.10 An example of a setting screen for limiting the security method used when the MFP 100 is connected to the AP in the wireless infrastructure mode is shown. Figure 3D When “Wireless LAN Advanced Settings” is selected on the screen, the operation display unit 220 displays Fig.10 In addition, although an example in which a setting screen is displayed on the operation display unit 220 of the MFP 100 is described here, the present disclosure is not limited to this example. For example, the setting screen may be displayed on an external device such as the mobile terminal device 104 by an application or a web browser capable of configuring the settings of the MFP 100. Fig.10 The settings screen in .
[0201] The setting screen displays setting items (options) 1001 to 1004 of the security method used when connecting to an AP in wireless infrastructure mode. Setting items 1001 to 1004 can be displayed as an interface capable of receiving instructions to set a lower limit of the security method, for example. In other words, the setting screen is a screen for setting the lower limit of the security method used by the MFP 100 when connecting to an AP. In addition, the setting screen can also be described as a screen for setting the security methods available to the MFP 100 when connecting to an AP. That is, in other words, the setting screen is a security setting screen. In addition, in other words, the lower limit of the security method is the standard of the security method used when the MFP 100 is connected to an AP. As described above, the standard of the security method is set on the setting screen to prevent the connection destination of the MFP 100 from being changed to an AP that uses a security method that does not meet the standard.
[0202] The setting item 1001 displays a relatively secure security method. Examples of the relatively secure method include the WPA3-SAE (AES) method and the WPA1 / 2 / 3-EAP (AES) method.
[0203] The setting item 1002 displays a medium-security security method. Examples of the medium-security method include the WPA1 / 2-PSK (AES) method.
[0204] The relatively unsafe security method is displayed by the setting item 1003. Examples of the relatively unsafe method include the WPA-PSK (TKIP) method.
[0205] The setting item 1004 displays an unsafe security method. Examples of the unsafe method include a method that does not require authentication when connecting to an AP. Examples of the method that does not require authentication include an OPEN method.
[0206] In the case where one of the setting items 1001 to 1004 of the security method is selected by the user operation on the setting screen, the CPU 212 stores the security method of the selected setting item in the RAM 214 and / or the non-volatile memory 215. That is, the security method of the setting item selected by the user is set as the lower limit of the security method used by the MFP 100 when connecting to the AP. This restricts the MFP 100 from connecting to the AP using a method less secure than the security method selected by the user when connecting to the AP in the wireless infrastructure mode. Therefore, the MFP 100 is prevented from connecting to the AP using a security method that the user does not expect.
[0207] Specifically, for example, in the case where the setting item 1001 is selected, when the MFP 100 is connected to the AP in the wireless infrastructure mode, the security method in the setting item 1001 is available. On the other hand, the security methods of the setting items 1002 to 1004 are restricted in use.
[0208] Furthermore, for example, in the case where the setting item 1002 is selected, when the MFP 100 is connected to the AP in the wireless infrastructure mode, the security methods of the setting items 1001 to 1002 are available. On the other hand, the security methods of the setting items 1003 and 1004 are restricted in use.
[0209] In addition, the setting item 1001, 1002, 1003 or 1004 of the security method selected by the user on the setting screen can be used to determine ( Fig. 9 (S902 in FIG. 14 ) whether to change the connection destination AP based on the change request in S708 and S714 to limit the security method used to connect to the AP.
[0210] In addition, through Figure 7 In a case where all security methods used by APs acquired by the AP search in S702 and S706 are methods restricted on the setting screen, APs are excluded from the AP search results to restrict security methods used for connecting to the APs.
[0211] In addition, for example, the setting items 1001 to 1004 having high security strength may be preferentially displayed on the setting screen. For example, the items having high security strength may be displayed at a higher position or highlighted on the setting screen.
[0212] This embodiment describes an example of a security method for storing the setting items 1001, 1002, 1003, or 1004 selected by the user on the operation display unit 220 of the MFP 100. However, the present disclosure is not limited to this example. For example, in the case where the setting items 1001, 1002, 1003, or 1004 selected by the user on the operation display unit 220 of the MFP 100 are displayed as described above on an external device such as the mobile terminal device 104, Fig.10 In the case of the setting screen in , the security method settings can be stored based on a specific signal sent from an external device.
[0213] As described above, in S708 according to this embodiment, Fig. 9 In the processing of S902 in , the MFP 100 performs AP search when receiving a measurement request from the currently connected AP. The MFP 100 controls so that according to the above-mentioned second suppression processing, a false response related to information about an AP that is found through the AP search and has a security strength lower than that of the currently connected AP is included in the beacon report (response to the measurement request). This prevents the currently connected AP from sending a change request for changing the connection destination to an AP with a lower security method.
[0214] In addition, in the step S714 according to the present embodiment, Fig. 9 In the processing of S902 in , the MFP 100 performs control based on the strength of the security method of the recommended AP when receiving a connection destination AP change request from the currently connected AP. In the case where the recommended AP uses a security method with a security strength lower than that of the currently connected AP, the MFP 100 performs control according to the above-mentioned first suppression processing so that the connection destination AP is not changed to the recommended AP. That is, the MFP 100 does not change the connection destination to the recommended AP, and does not return a response to the change request, or returns a response indicating that the connection destination AP will not be changed. This prevents a reduction in the security strength of the AP due to a change in the connection destination based on the connection destination change request. While maintaining a secure connection with the AP, connection to an AP with a better communication environment is facilitated.
[0215] In S708 according to this embodiment, Fig. 9 In the processing of S901 in , in the case where the APs found by the AP search include APs that are not supported by the MFP 100 or whose use is restricted, the MFP 100 performs the following control. According to the above-mentioned second suppression processing, a false response related to information about an AP that is not supported by the MFP 100 or whose use is restricted is controlled to be included in the beacon report (response to the measurement request). This prevents a change request for changing the connection destination from being sent to an AP that uses a security method that is not supported by the MFP 100 or that is restricted in the MFP 100.
[0216] In addition, in S714 according to the present embodiment, Fig. 9 In the processing of S901 in , the MFP 100 performs the following control when receiving the connection destination AP change request. In the case where the MFP 100 does not support or restricts the security method of using the recommended AP, the connection destination is prevented from being changed to the recommended AP according to the first suppression processing. That is, the MFP 100 does not return a response to the change request, or returns a response indicating that the connection destination AP will not be changed. This prevents the MFP 100 from disconnecting from the currently connected AP when trying to change the connection destination based on the connection destination change request, but cannot connect to the recommended AP (cannot connect to recommended AP) from occurring.
[0217] For example, in a case where the MFP 100 does not perform the processing of S901 according to the present embodiment but disconnects from the currently connected AP based on the connection destination change request and attempts to connect to a recommended AP using a security method that the MFP 100 does not support or has limited use, if the MFP 100 cannot connect to the recommended AP, the following problem may occur.
[0218] The first problem is that, since the connection with the current AP is temporarily disconnected before switching, there is a period in which the MFP 100 cannot communicate with the AP. In addition, processing time is required to connect to the recommended AP, and processing time is required from the failure of an attempt to connect to the recommended AP to the successful connection to another AP. This increases the time during which communication cannot be performed. Therefore, stable communication is interrupted. The second problem is that if the information required to connect to the AP before switching is not stored after the MFP 100 disconnects from the AP based on a connection destination AP change request, it is impossible to reconnect to the AP before switching. The information required for connection refers to connection information about at least one of the SSID and password and other setting information. In order to prevent the situation where the above-mentioned problem may occur, the present embodiment reduces unnecessary disconnection from the AP while controlling to connect to an AP with a better communication environment based on a change request, which enables more stable communication.
[0219] In S708 according to this embodiment, Fig. 9 In the processing of S903 in , the MFP 100 performs AP search when receiving a measurement request from the currently connected AP. According to the above-mentioned second suppression processing, the MFP 100 includes a false response related to information about an AP discovered by the AP search and having a security method different from that of the currently connected AP in the beacon report (response to the measurement request). This prevents a change request to change the connection destination from being sent to an AP having a different type of security method.
[0220] In addition, in S714 according to the present embodiment, Fig. 9 In the processing of S903 in , the MFP 100 performs control based on the type of authentication method of the recommended AP when receiving a connection destination AP change request from the currently connected AP. In a case where the type of authentication method of the recommended AP is different from the type of authentication method of the currently connected AP, the MFP 100 performs control so that the connection destination is not changed to the recommended AP as in the first suppression process. That is, the MFP 100 does not return a response to the change request to the currently connected AP, or returns a response indicating that the connection destination AP will not change. This makes it possible to facilitate connection to an AP with a better communication environment while maintaining the type of authentication method for connection to the AP the same as the type when constructing the wireless infrastructure mode. In other words, it is possible to facilitate connection to an AP with a better communication environment based on a change request while preventing problems caused by reduced security or excessive security due to inadvertent changes in the type of authentication method of the AP.
[0221] In addition, the processing of S904 according to the present embodiment is performed so that even in the case where the authentication method type is different, if the setting value corresponding to the type of authentication method of the recommended AP is stored, the connection destination AP is changed based on the change request. This makes it possible to facilitate connection with an AP having a better communication environment while maintaining the connection with the currently connected AP for the longest possible time.
[0222] An example of a method in which the security method of the candidate AP and the security method of the AP stored when the wireless infrastructure mode is initially configured are compared in the determination of S902 ( Figure 7 However, the present disclosure is not limited to this form. For example, a comparison with a predetermined security method may be performed. Specifically, a comparison with the method described above may be performed. Fig.10 The comparison with the security method stored by the user operation on the operation display unit 220 of the MFP 100 described above may be performed. In addition, the comparison with the security method stored by receiving a specific signal from an external device such as the mobile terminal device 104 may be performed. Furthermore, in the case of the comparison with the predetermined security method in the process of S902, specifically, the comparison with the security method available and stored in one or more of the ROM 213, the RAM 214, and the nonvolatile memory 215 of the MFP 100 may be performed.
[0223] In addition, an example of a method for determining whether the security method of the candidate AP is supported or restricted by the MFP 100 in the determination of S901 has been described above. However, the present disclosure is not limited to this form. In the determination of S901, the CPU 212 can determine whether the MFP 100 and the candidate AP can be connected based on the information acquired from the candidate AP and the capability information of the MFP 100. For example, the determination can be made based on one or more of a security method (authentication method and / or encryption method), a frequency band, a channel, and a communication standard.
[0224] The present embodiment described above enables more appropriate control of a connection destination change request from an AP. That is, the MFP 100 serving as a STA can be switched to an appropriate AP.
[0225] Various controls described as being performed by the CPU 212 may be performed by a single hardware, or the processing may be distributed to a plurality of hardware (eg, a plurality of processors and circuits) to control the entire apparatus.
[0226] In addition, although the present invention has been described in detail based on the preferred embodiments of the present invention, it should be understood that the present invention is not limited to the specific embodiments, and various forms that do not depart from the essence of the present invention are also included in the present invention. In addition, the disclosed embodiments only illustrate embodiments of the present invention and can be combined as needed.
[0227] In addition, although the disclosed embodiment describes an example of a case where the present invention is applied to an MFP, the present disclosure is not limited to this example, and the present invention is applicable to any wireless device that is configured to function as a STA capable of processing based on a connection destination change request from an AP. That is, the present invention is applicable to personal computers, personal digital assistants (PDAs), tablet terminals, mobile phone terminals such as smartphones, music players, game consoles, e-book readers, smart watches, and various measuring devices (sensor devices) such as thermometers and hygrometers. In addition, the present invention is also applicable to digital cameras (including still cameras, video cameras, web cameras, and surveillance cameras), printers, scanners, and drones. In addition, the present invention is also applicable to video output devices, audio output devices (such as smart speakers), media streaming players, and wireless LAN clients (adapters) that can be connected to a universal serial bus (USB) terminal or a LAN cable terminal. The video output device includes a device such as a set-top box, and acquires (downloads) a moving image or still image on the Internet identified by a uniform resource locator (URL) specified by the electronic device, and outputs the acquired image to a display device connected via a video output terminal such as a high-definition multimedia interface (HDMI) (registered trademark), thereby enabling streaming reproduction or screen mirroring of the display device (the content displayed on the electronic device is also displayed in the display device). In addition, the video output device includes a media player such as a television, a hard disk recorder, a blue-ray recorder, and a digital versatile disk (DVD) recorder, a head-mounted display, a projector, a television, a display device (monitor), and a signage device. In addition, the present invention is also applicable to Wi-Fi-enabled devices such as air conditioners, refrigerators, washing machines, vacuum cleaners, ovens, microwave ovens, lighting fixtures, heating facilities, and cooling facilities, which are called smart home appliances.
[0228] Other embodiments
[0229] The present invention can also be implemented by a process in which a program for implementing one or more functions of the disclosed embodiments is supplied to a system or device via a network or storage medium, and one or more processors of a computer of the system or device read the program and execute the read program. In addition, the present invention can also be implemented by a circuit (e.g., an application specific integrated circuit (ASIC)) that implements one or more functions of the disclosed embodiments.
[0230] The present invention enables more appropriate control of a connection destination change request from an AP.
[0231] The embodiments of the present invention may also be implemented by reading and executing computer executable instructions (e.g., one or more programs) recorded on a storage medium (which may also be more completely referred to as a "non-transitory computer-readable storage medium") to perform one or more functions in the above-mentioned embodiments, and / or a computer of a system or device including one or more circuits (e.g., an application-specific integrated circuit (ASIC)) for performing one or more functions in the above-mentioned embodiments, and the embodiments of the present invention may be implemented by, for example, reading and executing the computer executable instructions from the storage medium by the computer of the system or device to perform one or more functions in the above-mentioned embodiments, and / or controlling the one or more circuits to perform one or more functions in the above-mentioned embodiments. The computer may include one or more processors (e.g., a central processing unit (CPU), a microprocessing unit (MPU)), and may include a network of separate computers or separate processors to read and execute the computer executable instructions. The computer executable instructions may be provided to the computer, for example, from a network or the storage medium. The storage medium may include, for example, a hard disk, a random access memory (RAM), a read-only memory (ROM), a memory of a distributed computing system, an optical disk (such as a compact disc (CD), a digital versatile disc (DVD), or a Blu-ray disc (BD) TM ), flash memory devices, memory cards, etc.
[0232] The embodiments of the present invention may also be implemented by providing software (program) for performing the functions of the above-described embodiments to a system or device via a network or various storage media, and a computer or a central processing unit (CPU) or a microprocessing unit (MPU) of the system or device reads and executes the program.
[0233] While the present invention has been described with reference to the embodiments, it is to be understood that the invention is not limited to the disclosed embodiments.The scope of the following claims is to be accorded the broadest interpretation so as to encompass all such modifications and equivalent structures and functions.
Claims
1. An electronic device, comprising: a changing unit configured to change the access point serving as a connection destination based on a change request for the access point serving as a connection destination received from the connected access point; as well as a control unit configured to perform control so that the change unit is prevented from changing the access point serving as the connection destination to a second access point serving as the connection destination after the change, the second access point being a candidate for the change destination based on the change request and configured to connect using a second authentication method different in type from a first authentication method used for connecting to the first access point connected before the connection destination was changed.
2. The electronic device according to claim 1, wherein: The control unit performs control so as to prevent the second access point from becoming the changed connection destination and prevent the connection with the first access point from being disconnected.
3. The electronic device according to claim 1, further comprising: a receiving unit configured to receive a measurement request, the measurement request being sent from the first access point and requesting a measurement result of a signal quality of a neighboring access point near the electronic device; a measuring unit configured to measure signal qualities of neighboring access points upon receiving a measurement request; as well as a sending unit configured to send a response based on a measurement result measured by the measuring unit to the first access point, Wherein, when the measurement result measured by the measuring unit includes the signal quality of the second access point, the control unit causes the sending unit to send a response with content indicating a signal quality lower than the signal quality of the second access point measured by the measuring unit, or to send a response with content not including the signal quality of the second access point.
4. The electronic device according to claim 1, in, in a case where the recommended access points that are candidate access points and are recommended as the change destination in the change request include a third access point configured to connect using the same authentication method as the first authentication method in type, the control unit controls so that the change unit changes the access point serving as the connection destination to the third access point that is the connection destination after the change, and Here, in a case where the recommended access points include the second access point, the control unit controls so that the changing unit does not change the access point serving as the connection destination to the second access point serving as the changed connection destination.
5. The electronic device according to claim 1, wherein: In a case where the recommended access point that is a candidate access point and is recommended as a change destination in the change request is an access point configured to connect using the second authentication method, the control unit controls so that the change unit does not change the access point serving as the connection destination based on the change request, and transmits a response indicating rejection of changing the connection destination based on the change request to the first access point.
6. The electronic device according to claim 1, wherein: The control unit controls not to transmit a response to the change request when the recommended access point as a candidate access point and recommended as a change destination in the change request is an access point configured to connect using an authentication method different in type from the first authentication method.
7. The electronic device according to claim 1, further comprising: a recording control unit configured to perform control so that connection information with the first access point and an authentication method used to connect to the first access point are recorded, The control unit controls a change of the connection destination based on the change request based on an authentication method used to connect to the first access point and recorded by the recording control unit.
8. The electronic device according to claim 1, further comprising: a setting unit configured to set a security method available when connecting to an access point based on an operation from a user, and Here, the authentication method used to connect to the first access point is an authentication method based on a security method set by the setting unit.
9. The electronic device according to claim 1, wherein: In a case where an access point serving as a candidate access point is configured to connect using a third authentication method that is different in type from the first authentication method and a setting value for connecting using the third authentication method is stored, the control unit controls so as not to prevent the changing unit from changing the access point serving as a connection destination to an access point connected using the third authentication method.
10. The electronic device according to claim 1, wherein: The type of the first authentication method is one of the synchronized authentication of peer entities SAE method, the pre-shared key PSK method, the extensible authentication protocol EAP method and the OPEN method, and the type of the second authentication method is another one of the SAE method, the PSK method, the EAP method and the OPEN method that is different from the type of the first authentication method.
11. The electronic device according to claim 1, wherein: The type of the first authentication method is one of personal and enterprise, and the type of the second authentication method is the other of personal and enterprise.
12. The electronic device according to claim 1, wherein: The control unit also controls so that the prevention unit changes the access point serving as the connection destination to an access point serving as the changed connection destination configured to communicate using a security method having a lower security strength than a security method used for communicating with the first access point.
13. The electronic device according to claim 1, wherein: The control unit also controls so that the prevention changing unit changes the access point serving as the connection destination to an access point serving as the changed connection destination configured to communicate using a security method not supported by the electronic device or using a restricted security method in the electronic device.
14. The electronic device according to claim 1, wherein: The electronic device performs connection with an access point and processing in accordance with the IEEE 802.11ax standard.
15. The electronic device according to claim 1, wherein: The electronic device performs at least one of a process conforming to orthogonal frequency division multiple access (OFDMA) and a process conforming to a target wake time (TWT).
16. The electronic device according to claim 1, wherein: The electronic device changes the connection destination to an access point using a 6 GHz frequency band by changing the connection destination based on the change request.
17. The electronic device according to claim 1, wherein: The electronic device further includes a printing unit configured to perform a printing process based on the print data received via the access point.
18. The electronic device according to claim 1, wherein: The control unit performs control based on the authentication method of the candidate access point.
19. A computer-readable storage medium storing one or more programs configured to cause one or more computers to function as: a changing unit configured to change the access point serving as a connection destination based on a change request for the access point serving as a connection destination received from the connected access point; and a control unit configured to perform control so that the change unit is prevented from changing the access point serving as the connection destination to a second access point serving as the connection destination after the change, the second access point being a candidate for the change destination based on the change request and configured to connect using a second authentication method different in type from a first authentication method used for connecting to the first access point connected before the connection destination was changed.
20. A method for controlling an electronic device, the method comprising: changing the access point serving as the connection destination based on a change request for the access point serving as the connection destination received from the connected access point; as well as Control is performed so that an access point serving as a connection destination is prevented from being changed to a second access point serving as a connection destination after the change, the second access point being a candidate for a change destination based on the change request and being configured to connect using a second authentication method different in type from a first authentication method used for connecting to a first access point connected before the connection destination was changed.
Citation Information
Patent Citations
Mobile router, mobile router control method and mobile router control program
JP2021175068A