Electronic device, control method of electronic device, storage medium, and computer program product
By setting security setting values in the electronic device to control the AP change request, the security risks brought about by AP switching in the wireless LAN environment are solved, and the security protection of electronic device communication security is achieved.
Patent Information
- Application Number
- CN202411557368.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-06
- Filing Date
- 2024-11-04
- Publication Date
- 2025-05-06
AI Technical Summary
In a wireless LAN environment, when dynamically switching to the destination access point (AP), there are security risks, such as being hijacked by a malicious AP, resulting in leaks in communication content or firmware vulnerability attacks.
By receiving the AP change request in the electronic device, and determining whether to suppress the AP change request based on the preset security setting value, dynamic switching of the connection destination AP is controlled.
It effectively avoids security risks caused by AP handover and ensures the communication security of electronic devices.
Smart Images

Figure CN119946760A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an electronic device that can be connected via a wireless LAN, a control method of the electronic device, a computer-readable storage medium storing a program, and a computer program product. Background Art
[0002] In a wireless LAN environment to which electronic devices are connected, there is a technology that dynamically switches a connection destination access point (AP) so that data can be efficiently exchanged between an AP and a station (STA) in an extended service set (ESS) including a plurality of APs. When it is determined that the connection destination AP should be switched based on the congestion state of the AP to which the STA is connected, the idle state of other APs, radio wave conditions, etc., the AP to which the STA is connected sends a connection destination AP change request to the STA. When the AP change request is received, the STA switches the connection destination AP according to the request, and thus can connect to an appropriate AP.
[0003] Japanese Patent Publication No. 2021-175068 discloses the following processing: requesting to change the connection destination from a router with an AP function to a wireless slave device connected to the router. A mobile router (MR1) that can be connected to multiple wireless slave devices confirms whether the wireless slave terminal supports IEEE 802.11v. It can be determined whether the wireless slave terminal supports IEEE802.11v based on an association request frame sent from the wireless slave terminal to MR1 when the wireless slave terminal establishes a wireless connection with MR1. If the wireless slave terminal supports IEEE 802.11v, a BSS transition management (BTM) request frame is sent to the wireless slave terminal. In the BSS transition candidate list entry field of the BTM request frame, the BSSID of the master device router RT2 is specified as the connection destination. Therefore, the connection destination of the slave terminal is switched, and the wireless slave terminal switches the connection destination from MR1 to RT2 according to the received BTM request frame. Summary of the invention
[0004] The present invention provides an electronic device capable of controlling dynamic switching of a connection destination AP to avoid security risks of the electronic device, a control method of the electronic device, a computer-readable storage medium storing a program, and a computer program product.
[0005] The present invention provides an electronic device in its first aspect, comprising: a receiving unit configured to receive a change request for an access point used as a connection destination from a connected access point; a setting unit configured to set a setting value related to the security of the electronic device; and a control unit configured to control whether to suppress the change of the access point used as a connection destination based on the change request based on the setting value set by the setting unit.
[0006] In its second aspect, the present invention provides a control method for an electronic device, the control method comprising: receiving a change request for an access point used as a connection destination from a connected access point; setting a setting value related to the security of the electronic device; and controlling whether to suppress the change of the access point used as the connection destination based on the change request based on the set setting value.
[0007] The present invention, in its third aspect, provides a computer-readable storage medium storing a program, wherein the program is configured to cause a computer of an electronic device to perform the following operations: receiving a change request for an access point used as a connection destination from a connected access point; setting a setting value related to the security of the electronic device; and controlling whether to suppress a change in the access point used as a connection destination based on the change request based on the set setting value.
[0008] In its fourth aspect, the present invention provides a computer program product configured to cause a computer of an electronic device to perform the following operations: receive a change request for an access point used as a connection destination from a connected access point; set a setting value related to the security of the electronic device; and control whether to suppress the change of the access point used as the connection destination based on the change request based on the set setting value.
[0009] According to the present invention, it is possible to control dynamic switching of a connection destination AP to avoid security risks of an electronic device.
[0010] Further features of the present invention will become apparent from the following description of exemplary embodiments with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1 It is a diagram showing the system configuration.
[0012] Figure 2A and Figure 2B is a diagram showing the configuration of a multifunction peripheral (MFP).
[0013] Figure 3A , Figure 3B and Figure 3C : is a diagram showing an operation display unit of the MFP.
[0014] Figure 4A and Figure 4B is a diagram showing the configuration of a portable terminal device.
[0015] Figure 5 is a diagram showing the structure of an access point (AP).
[0016] Figure 6 is a sequence diagram showing processing performed based on a connection destination change request from an AP.
[0017] Fig. 7A , Figure 7B , Figure 7C , Fig.7D , Fig. 7E , Figure 7F and Figure 7G : is a diagram showing a screen example of the operation display unit of the MFP.
[0018] Figure 8 is a diagram showing setting values of security setting items for each security type.
[0019] Fig. 9 : is a flowchart showing an example of processing performed by the MFP in response to a connection destination change request.
[0020] Fig. 10A and Fig. 10B is a conceptual diagram illustrating a method for determining whether a connection destination AP can be changed.
[0021] Fig.11 : is a flowchart showing another example of processing performed by the MFP in response to the connection destination change request.
[0022] Fig.12 : is a flowchart showing the processing performed at the time of reboot after the security type is set. DETAILED DESCRIPTION
[0023] Hereinafter, the embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments are not intended to limit the scope of the present invention. A plurality of features are described in the embodiments, but are not limited to the invention requiring all of these features, and these features may be appropriately combined. In addition, in the accompanying drawings, the same reference numerals are given to the same or similar configurations, and their redundant descriptions will be omitted.
[0024] Depending on the state of the STA, there are cases where no problem occurs even if the AP is switched and cases where a problem occurs when the AP is switched. In these cases where a problem occurs when the AP is switched, it is not desirable to switch the connection destination AP in response to an AP change request received from the AP.
[0025] For example, a case where there is a security risk in the AP to which the connection destination is to be switched can be conceived. If the connection destination is switched to a malicious AP pretending to be a secure AP, the communication content with the STA may be leaked. In another case, if the STA is connected to an AP operating with old firmware without updating the firmware, the STA may be attacked by exploiting a firmware vulnerability. Therefore, when the electronic device determines that there is a security risk when switching the AP, it is desirable not to switch the AP according to the AP switching request.
[0026] According to the present invention, dynamic switching of a connection destination AP can be controlled to avoid security risks of an electronic device.
[0027] System Configuration
[0028] Figure 1 An example of the configuration of a system according to the present embodiment is shown. The system is, for example, a wireless communication system in which a plurality of communication devices can wirelessly communicate with each other. Figure 1 In the example shown, the system includes a portable terminal device 104, a multifunction peripheral (MFP) 100, APs 101 and 102 as access points, a DHCP server 103, and a network 110 as communication devices. Note that APs 101 and 102 may be shown as AP1 and AP2 in the figure. The portable terminal device 104 is a device having a wireless communication function using a wireless LAN or the like. In the following description, a wireless LAN may be referred to as a "WLAN". The portable terminal device 104 may be a personal information terminal such as a personal digital assistant (PDA), a mobile phone (smartphone), a digital camera, a personal computer, etc.
[0029] The MFP 100 has a printing function, and may also have a reading (scanning) function, a FAX function, and a telephone function. In addition, the MFP 100 of the present embodiment has a communication function that enables wireless communication with a portable terminal device 104. In the present embodiment, a case where the MFP 100 is used is described as an example, but is not limited to the example. For example, a printer, a scanner, a projector, a portable terminal, a smart phone, a notebook computer, a tablet terminal, a PDA, a digital camera, a music reproduction device, a television, a smart speaker, etc. having a communication function may also be used instead of the MFP 100. Note that MFP is an abbreviation for "Multi Function Peripheral".
[0030] AP 101 is separately provided from portable terminal device 104 and MFP 100 (provided outside portable terminal device 104 and MFP 100), and operates as a base station device of WLAN. A communication device having a WLAN communication function can communicate via AP 101 in the infrastructure mode of WLAN. In the following description, an access point may be referred to as an "AP". In addition, the infrastructure mode may be referred to as a "wireless infrastructure mode". AP 101 communicates wirelessly with (authenticated) communication devices that are allowed to connect to AP 101, and relays wireless communications between the communication device and other communication devices. In addition, AP 101 is connected to a wired communication network, for example, and can relay communications between a communication device connected to the wired communication network and other communication devices that have established a wireless connection with AP 101.
[0031] The AP 102 has the same function as that of the AP 101, and the MFP 100 switches the connection destination from the AP 101 to the AP 102 as needed. The DHCP server 103 is connected to the MFP 100 via the AP 101 and the network 110, and provides services to the MFP 100 in response to a request from the MFP 100. Figure 1 In the embodiment, the DHCP server 103 is connected as a device different from the AP 101 and the AP 102, but a configuration in which the AP 101 and the AP 102 have a DHCP server function may be adopted. The DNS server 105 is connected to the MFP 100 and the portable terminal device 104 via the AP 101 and the network 110, and provides a service for name resolution in response to a request from the MFP 100 or the portable terminal device 104. Here, the network 110 may be the Internet, a closed network of a company, or a mobile phone network.
[0032] External structure of MFP
[0033] Figure 2A An example of the external configuration of the MFP 100 is shown. For example, the MFP 100 includes a document table 201, a document cover 202, a printing paper inlet 203, a printing paper outlet 204, and an operation display unit 205. The document table 201 is a table on which a document to be scanned is placed. The document cover 202 is a cover for pressing the document placed on the document table 201 and preventing light for scanning emitted from a light source to the document from leaking to the outside. The printing paper inlet 203 is an inlet to which paper sheets of various sizes are set. The printing paper outlet 204 is an outlet from which printed sheets are discharged. The paper sheets set on the printing paper inlet 203 are conveyed to the printing unit one by one, are subjected to printing in the printing unit, and then are discharged from the printing paper outlet 204. The operation display unit 205 includes keys such as letter input keys, cursor keys, an enter key, and a cancel key, LEDs, LCDs, etc., and is configured to be able to accept operations made by a user to start various functions of the MFP and set various settings. The operation display unit 205 may also include a touch panel display. The MFP 100 has a wireless communication function for communicating via WLAN and includes a wireless communication antenna 206 to be used for wireless communication, but the antenna is not necessarily visible from the outside. Similar to the portable terminal device 104, the MFP 100 can perform wireless communication via WLAN in the 2.4 GHz band and the 5 GHz band.
[0034] MFP Structure
[0035] Figure 2BAn example configuration of the MFP 100 is shown. The MFP 100 includes: a main unit 211 that performs main control of the MFP 100; and a wireless unit 226 that is a communication module that performs WLAN communication using at least one common antenna. In addition, the MFP 100 includes, for example, a modem 229 for wired communication. The main unit 211 is simply a unit that includes functional blocks other than the wireless unit 266 and the modem 229. For example, the main unit 211 includes a central processing unit (CPU) 212, a ROM 213, a RAM 214, a nonvolatile memory 215, an image memory 216, a reading control unit 217, a data conversion unit 218, a reading unit 219, and a coding and decoding processing unit 221. The main unit 211 also includes, for example, a printing unit 222, a paper feeding unit 223, a printing control unit 224, an operation display unit 220, and a FAX control unit 227. These functional units included in the main unit 211 are connected to each other via a system bus 230 controlled by the CPU 212. Furthermore, for example, the main unit 211 and the wireless unit 226 are connected via a dedicated bus 225 , and the main unit 211 and the modem 229 are connected via a bus 228 .
[0036] The CPU 212 is a system control unit including at least one processor, and controls the entire MFP 100. For example, the processing performed by the MFP 100 described below is realized by the CPU 212 executing the program stored in the ROM 213. Note that dedicated hardware may also be prepared for each processing. The control program executed by the CPU 212, the embedded OS program, and the like are stored in the ROM 213. In the present embodiment, the CPU 212 performs software control such as scheduling and task switching by executing each control program stored in the ROM 213 under the management of the embedded OS also stored in the ROM 213.
[0037] RAM 214 is composed of, for example, SRAM. Data such as program control variables, setting values registered by the user, and data such as management data of MFP 100 are stored in RAM 214. RAM 214 can also be used as a buffer for various jobs. Non-volatile memory 215 is composed of, for example, a memory such as a flash memory, and the data stored therein is retained even if the power of MFP 100 is turned off. Image memory 216 is composed of a memory such as DRAM. Image data received via wireless unit 226, image data processed by encoding and decoding processing unit 221, etc. are accumulated in image memory 216. Note that the memory structure of MFP 100 is not limited to the above structure. Data conversion unit 218, for example, analyzes data in various forms and converts image data into print data.
[0038] The reading control unit 217 controls the reading unit 219 (e.g., a contact image sensor (CIS)) to optically read the document placed on the document table 201. The reading control unit 217 converts the image obtained by optically reading the document into electrical image data (image signal) and outputs the image data. At this time, the reading control unit 217 may output the image data after performing various types of image processing such as binarization processing or halftone processing.
[0039] For example, the operation display unit 220 is referred to Figure 2A The described operation display unit 205, and performs display on the display under display control performed by the CPU 212, and generates a signal in response to a user operation.
[0040] The codec processing unit 221 performs coding processing, decoding processing, and scaling processing on image data (JPEG, PNG, etc.) processed by the MFP 100 .
[0041] The paper feed unit 223 holds paper sheets for printing. The paper feed unit 223 can supply the set paper sheets under the control performed by the print control unit 224. The paper feed unit 223 may include a plurality of paper feed units so as to hold a plurality of types of sheets in a single device, and the print control unit 224 may control from which paper feed unit the sheets are supplied.
[0042] The print control unit 224 performs various types of image processing (such as smoothing processing, print density correction processing, and color correction) on the image data to be printed, and outputs the processed image data to the print unit 222. For example, the print unit 222 is configured to be able to perform an inkjet printing process, and causes the print head to eject ink supplied from an ink tank so as to record an image on a printing medium such as paper. Note that the print unit 222 may also be configured to be able to perform other printing processes such as an electrophotographic printing process. In addition, for example, the print control unit 224 may periodically read information about the print unit 222, and update status information including the amount of ink in the ink tank, the status of the print head, and the like stored in the RAM 214.
[0043] For example, the wireless unit 226 may provide a WLAN communication function, such as a function similar to that achieved by combining the WLAN unit 401 of the portable terminal device 104. That is, the wireless unit 226 converts data into data packets according to the standard of the WLAN and sends the data packets to other devices, and also restores the original data according to the data packets received from the external device and outputs the data to the CPU 212. The wireless unit 226 may communicate as a station according to the IEEE 802.11 standard series. In particular, the wireless unit 226 may communicate as a station according to IEEE 802.11a / b / g / n / ac / ax. In the following description, a station may be referred to as a "STA". In addition, the wireless unit 226 may communicate as a STA supporting Wi-Fi Agile Multiband (trademark).
[0044] The wireless unit 226 supports IEEE 802.11ax, i.e., Wi-Fi 6 (trademark), and can be processed according to IEEE 802.11ax. That is, the MFP 100 can operate (process) as one or both of a STA supporting (compliant with) OFDMA and a STA supporting (compliant with) TWT. OFDMA is the abbreviation of "Orthogonal Frequency-Division Multiple Access". TWT is the abbreviation of "Target Wake Time". MFP 100 supports TWT, so the timing of data communication from the host device to the STA is adjusted. The wireless unit 226 (MFP 100), i.e., the STA, transitions the communication function to a sleep state when there is no need to wait for a signal to be received. This saves power consumption. The wireless unit 226 also supports Wi-Fi 6E (trademark). That is, the wireless unit 226 can communicate in the 6GHz band (5.925GHz to 7.125GHz). The 6 GHz band does not include a range in which dynamic frequency selection (DFS) is performed as in the 5 GHz band. Therefore, communication performed in the 6 GHz band does not cause communication disconnection due to the standby time of DFS, and more comfortable communication can be expected.
[0045] Note that the portable terminal device 104 and the MFP 100 can perform P2P (WLAN) communication based on WFD, and the wireless unit 226 has a software access point (soft AP) function or a group owner function. That is, the wireless unit 226 can establish a P2P communication network and determine a channel for P2P communication.
[0046] Operation display unit of MFP
[0047] FIG. 3A to FIG. 3CAn example of a screen displayed on a display (touch panel display) included in the operation display unit 220 of the MFP 100 is schematically shown. Figure 3A An example of the home screen displayed in a state (idle state or standby state) in which the power of the MFP 100 is turned on and operations such as printing and scanning are not being performed is shown. Figure 3A , display items (menu items) corresponding to copy, scan, and cloud, respectively, are shown in FIG. Cloud is a menu item related to a cloud function provided using Internet communication. When any menu item is selected by an operation made on a key or a touch panel, the MFP 100 may start to execute the corresponding setting or function. The MFP 100 receives a message received via Figure 3A The main screen shown can be displayed seamlessly when operations are performed on the keys or touch panel Figure 3A A screen other than the one shown.
[0048] Figure 3B An example of display of other parts of the home screen is shown, and the home screen changes from the home screen to the home screen in response to an operation for displaying other pages of the home screen (for example, a sliding operation to the left or right). Figure 3A The state shown changes to Figure 3B Status shown. Figure 3B Display items (menu items) corresponding to communication setting, printing, and main unit setting, respectively, are shown in . When any one of these menu items is selected, a function corresponding to the selected menu item, ie, printing function, main unit setting, or communication setting, is executed.
[0049] Figure 3C Shown in Figure 3B An example of a display of a menu screen for communication settings that is displayed when communication settings are selected on the screen shown. In the menu screen for communication settings, "Wireless LAN", "Wired LAN", "Wireless Direct", "Bluetooth", and "General Settings" are displayed as menu items (options). "Wireless LAN", "Wired LAN", and "Wireless Direct" are menu items related to LAN settings, and can be used to select wired connection settings, enable or disable wireless infrastructure mode, or enable or disable P2P modes such as WFD mode or soft AP mode. When the "Wireless LAN" item is selected by user operation to enable the wireless LAN, the wireless infrastructure mode is enabled. When the "Wireless Direct" item is selected by user operation to enable the wireless direct connection, the P2P (WLAN) mode is enabled. In addition, a general settings menu related to each connection type is displayed in this screen. In addition, the user can set the frequency band and frequency channel of the wireless LAN via this screen.
[0050] External structure of portable terminal equipment
[0051] Figure 4A4 is a diagram of an example of the external configuration of the portable terminal device 104. In the present embodiment, a case where the portable terminal device 104 is a general smart phone is shown as an example. Note that the portable terminal device 104 includes, for example, a display unit 402, an operation unit 403, and a power key 404. The display unit 402 is, for example, a display including a display mechanism of a liquid crystal display (LCD). Note that the display unit 402 may also display information by using, for example, a light emitting diode (LED). In addition to or in place of the display unit 402, the portable terminal device 104 may also have a function of outputting information by using audio. The operation unit 403 includes a hardware key (such as a key or button), a touch panel, and the like for detecting user operations. Note that in the present example, a common touch panel display is provided for the display unit 402 to display information and for the operation unit 403 to accept user operations, and therefore, the display unit 402 and the operation unit 403 are implemented by a single device. In this case, a button icon and a software keyboard are displayed using the display function of the display unit 402, and, for example, a touch made by a user at any of these positions is detected by the operation acceptance function of the operation unit 403. Note that a configuration is also possible in which the display unit 402 and the operation unit 403 are separated from each other and hardware for display and hardware for accepting operation can be prepared separately. The power key 404 is a hardware key for accepting a user operation for turning the power of the portable terminal device 104 on or off.
[0052] The portable terminal device 104 includes a WLAN unit 401 that provides a WLAN communication function, but the WLAN unit is not necessarily visible from the outside. For example, the WLAN unit 401 is constructed to be able to perform data (data packet) communication in a WLAN system according to the IEEE 802.11 standard series (e.g., IEEE802.11a / b / g / n / ac / ax). In addition, the WLAN unit 401 can communicate as an AP supporting Wi-Fi Agile Multiband (trademark). However, there is no restriction on this construction, and the WLAN unit 401 can also perform communication in a WLAN system according to other standards. In this example, the WLAN unit 401 can communicate in the 2.4GHz band and the 5GHz band. In addition, for example, the WLAN unit 401 can also perform communication based on WFD, communication in soft AP mode, and communication in wireless infrastructure mode. The operations in these modes are described later.
[0053] Structure of portable terminal equipment
[0054] Figure 4BAn example configuration of the portable terminal device 104 is shown. In the example, the portable terminal device 104 includes a main unit 411 that performs main control of the portable terminal device 104 and a WLAN unit 429 that performs WLAN communication. The main unit 411 is simply a unit that includes functional blocks other than the WLAN unit 429. For example, the main unit 411 includes a CPU 412, a ROM 413, a RAM 414, an image memory 415, a data conversion unit 416, a telephone unit 417, a GPS 419, a camera unit 421, a nonvolatile memory 422, a data accumulation unit 423, a speaker unit 424, and a power supply unit 425. Here, CPU is an abbreviation of "Central Processing Unit", ROM is an abbreviation of "Read Only Memory", RAM is an abbreviation of "Random Access Memory", and GPS is an abbreviation of "Global Positioning System". In addition, the portable terminal device 104 includes a display unit 420 and an operation unit 418. These functional units included in the main unit 411 are connected to each other via a system bus 628 controlled by the CPU 412. Furthermore, the main unit 411 and the WLAN unit 429 (the above-described WLAN unit 401) are connected via a dedicated bus 426, for example.
[0055] The CPU 412 is a system control unit including at least one processor, and controls the entire portable terminal device 104. For example, the processing performed by the portable terminal device 104 described below is realized by the CPU 412 executing the program stored in the ROM 413. Note that dedicated hardware may also be prepared for each processing. The control program executed by the CPU 412, the embedded operating system (OS) program, and the like are stored in the ROM 413. In the present embodiment, the CPU 412 performs software control such as scheduling and task switching by executing each control program stored in the ROM 413 under the management of the embedded OS also stored in the ROM 413.
[0056] The RAM 414 is composed of, for example, a static RAM (SRAM). Data such as program control variables, setting values registered by a user, and data such as management data of the portable terminal device 104 are stored in the RAM 414. The RAM 414 can also be used as a buffer for various jobs. The image memory 415 is composed of a memory such as a dynamic RAM (DRAM). Image data received via the WLAN unit 429 and image data read out from the data accumulation unit 423 are temporarily stored in the image memory 415 so as to be processed by the CPU 412. The nonvolatile memory 422 is composed of, for example, a memory such as a flash memory, and the data stored therein is retained even if the power supply of the portable terminal device 104 is disconnected. Note that the memory configuration of the portable terminal device 104 is not limited to the above configuration. For example, the image memory 415 and the RAM 414 can be configured as a common memory, and the data accumulation unit 423 can be used for data backup, etc. In addition, in the present embodiment, the DRAM is described as an example of the image memory 415, but other storage media such as a hard disk or a nonvolatile memory can also be used as the image memory 415.
[0057] The data conversion unit 416 performs various forms of data analysis and data conversion such as color conversion and image conversion. The telephone unit 417 realizes telephone communication by controlling the telephone line and processing audio data input or output via the speaker unit 424. The GPS 419 obtains position information such as the current latitude and longitude of the portable terminal device 104 by receiving radio waves transmitted from satellites.
[0058] The camera unit 421 has a function of electronically recording and encoding an image input through a lens. Image data obtained by the camera unit 421 by taking an image is stored in the data accumulation unit 423. For example, the speaker unit 424 controls to realize a function of inputting or outputting audio for a telephone function and an alarm function. The power supply unit 425 is, for example, a portable battery, and controls to supply power to the portable terminal device. The power supply state includes a battery exhaust state in which the battery power is 0, a power disconnection state in which the power key 404 is not pressed, a startup state in which the portable terminal device has been normally started, and a power saving state in which the portable terminal device has been started but power consumption is saved.
[0059] The display unit 420 is a reference Figure 4A The display unit 402 described above accepts various input operations and displays the operation status and status of the MFP 100 under the control of the CPU 412. The operation unit 418 is, for example, a display unit 402 of the embodiment of the present invention. Figure 4A The operating unit 403 described above, and upon accepting a user operation, performs control to generate an electric signal corresponding to the operation and output the signal to the CPU 412.
[0060] The portable terminal device 104 performs wireless communication by using the WLAN unit 429 to perform data communication with other devices such as the MFP 100. The WLAN unit 429 converts data into a data packet and sends the data packet to other devices. In addition, the WLAN unit 429 restores the original data from the data packet received from the external device and outputs the data to the CPU 412. The WLAN unit 429 is a unit that implements communication according to each WLAN standard. The WLAN unit 429 can operate in parallel in at least two communication modes including a wireless infrastructure mode and a P2P (WLAN) mode. Note that the frequency band used in these communication modes may be limited due to the function and performance of the hardware.
[0061] Access point configuration
[0062] Figure 5 1 is a block diagram showing the configuration of the AP 101 having a wireless LAN access point function. The AP 101 includes a main unit 510 that controls the AP 101, a wireless LAN unit 516, a wired LAN unit 518, and an operation button 520. The main unit 510 is simply a unit that includes functional blocks other than the wireless LAN unit 516, the wired LAN unit 518, and the operation button 520.
[0063] The CPU 511 (i.e., a microprocessor included in the main unit 510) operates according to the control program stored in the program memory 513 (i.e., a ROM connected to the CPU 511 via the internal bus 512) and the contents in the data memory 514 (i.e., RAM). The CPU 511 controls the wireless LAN unit 516 via the wireless LAN communication control unit 515 to perform wireless LAN communication with other communication terminal devices. In addition, the CPU 511 controls the wired LAN unit 518 via the wired LAN communication control unit 517 to perform wired LAN communication with other communication terminal devices. The CPU 511 can accept the operation made by the user on the operation button 520 by controlling the operation unit control circuit 519. The CPU 511 includes at least one processor.
[0064] The AP 101 further includes an interference wave detection unit 521 and a channel change unit 522. The interference wave detection unit 521 performs processing for detecting interference waves when wireless communication is performed within a range where dynamic frequency selection (DFS) is performed. For example, if an interference wave is detected when wireless communication is performed within a range where DFS is performed, the channel change unit 522 performs processing for changing the current channel to a channel used when it is necessary to immediately change the used channel to an available channel.
[0065] Note that the construction of AP 102 is similar to that of AP 101 .
[0066] P2P communication method
[0067] Next, the following describes an overview of a P2P (WLAN) communication method in which devices directly communicate with each other wirelessly without going through an external access point in WLAN communication. P2P (WLAN) communication can be implemented by using a variety of methods. For example, a communication device can support a variety of modes of P2P (WLAN) communication and perform P2P (WLAN) communication by selectively using any one of the multiple modes.
[0068] The following two modes can be thought of as the P2P mode.
[0069] -Soft AP mode
[0070] -Wi-Fi Direct (WFD) mode
[0071] A communication device that can perform P2P communication may be configured to support at least one of these modes. On the other hand, even if a communication device can perform P2P communication, the communication device does not have to support all of these modes, but may be configured to support only some of these modes.
[0072] In a communication device (e.g., portable terminal device 104) having a communication function based on WFD, an application (which may be a dedicated application) for implementing the communication function is called in response to the operation unit of the communication device accepting a user operation. The communication device may then display a screen including a user interface (UI) provided by the application to prompt the user to operate, and perform WFD communication based on the user operation.
[0073] Soft AP Mode
[0074] In the soft AP mode, a communication device (e.g., the portable terminal device 104) operates as a client requesting various services. Other communication devices (e.g., the MFP 100) operate as a soft AP, which can perform the functions of an AP in a WLAN according to the settings set by the software. Note that the commands and parameters defined in the Wi-Fi (registered trademark) standard can be used as the commands and parameters sent to establish a wireless connection between a client and a soft AP, so their description is omitted. In addition, the MFP 100 operating in the soft AP mode determines the frequency band and frequency channel as a master station. Therefore, the MFP 100 can select the frequency band to be used from the 5 GHz band and the 2.4 GHz band, and can select the frequency channel to be used in the selected frequency band.
[0075] WFD Mode
[0076] In WFD mode, the MFP 100 can always start as a master station (autonomous group owner). In this case, there is no need to perform GO negotiation processing for determining the role. In addition, in this case, the MFP 100 determines the frequency band and frequency channel as the master station. Therefore, the MFP 100 can select a frequency band to be used from the 5 GHz band and the 2.4 GHz band, and can select a frequency channel to be used in the selected frequency band.
[0077] Wireless Infrastructure Mode
[0078] In the wireless infrastructure mode, the communication devices (e.g., portable terminal device 104 and MFP 100) that communicate with each other are connected to an external AP (e.g., AP 101) that monitors the network, and the communication between the communication devices is performed via the AP. In other words, the communication between the communication devices is performed via the network established by the external AP. The portable terminal device 104 and the MFP 100 each find the AP 101 and send a connection request to the AP 101 to connect to the AP 101, so in the wireless infrastructure mode, the communication between these communication devices can be performed via the AP 101. Note that multiple communication devices can also be connected to different APs. In this case, the communication between the communication devices can be performed through data transmission between APs. The commands and parameters defined in the Wi-Fi standard can be used as the commands and parameters sent by the access point for communication between the communication devices, so the description thereof is omitted. In addition, in this case, the AP 101 determines the frequency band and the frequency channel. Therefore, the AP 101 can select the frequency band to be used from the 5 GHz band, the 2.4 GHz band, and the 6 GHz band, and can select the frequency channel to be used in the selected frequency band.
[0079] Processing in response to a connection destination change request from an AP to a STA
[0080] The portable terminal device 104 and the MFP 100 support a function open to the public as Wi-Fi Agile Multiband (trademark). Wi-Fi Agile Multiband is a function that can select the best environment according to the changing conditions of the Wi-Fi network. Specifically, STAs such as the portable terminal device 104 and the MFP 100 and APs such as the AP 101 exchange information about the network environment using the communication standards included in the IEEE802.11 series. Through this information exchange, when the network is congested, the AP can guide the STA (cause the STA to change the connection destination) to other APs, other frequency bands or channels, or other cellular services in some cases.
[0081] Figure 61 is a sequence diagram showing a case where the MFP 100 switches the connection destination AP from the AP 101 to the AP 102 according to a connection destination change request (a change request of the access point serving as the connection destination) from the AP 101. The processing performed by each device in the sequence is realized by the CPU included in the device by loading various programs stored in a memory such as a ROM included in the device into the RAM included in the device and executing the programs.
[0082] exist Figure 6 In the initial state of the illustrated process, the MFP 100 has established a connection with the AP 101 in the wireless infrastructure mode. Furthermore, when the connection is established between the MFP 100 and the AP 101 in the wireless infrastructure mode, the AP 101 has obtained information indicating whether the MFP 100 supports IEEE 802.11v. In the case where the AP 101 has obtained information indicating that the MFP 100 supports IEEE 802.11v, the following process is performed.
[0083] In step S601, AP 101 transmits an inquiry (measurement request) to MFP 100 regarding the strength of radio waves received from APs located in the surrounding area of MFP 100. For example, the inquiry is transmitted as a beacon frame request or a beacon report request. That is, the request may be transmitted using a method defined in the IEEE 802.11k standard.
[0084] In step S602, the MFP 100 measures the radio wave strength by receiving frames transmitted from APs located in the surrounding area in response to the request received in step S601. Thus, the strength of radio waves received from a plurality of APs including the AP 101 and the AP 102 is measured.
[0085] In step S603, as a response to the request received in step S601, the MFP 100 transmits a list of the strengths of radio waves received from APs located in the surrounding area of the MFP 100 measured in step S602. Note that in addition to or instead of the information measured in step S602, information stored in the RAM 214 and the nonvolatile memory 215 of the MFP 100 may be included in the response as the radio wave strengths. For example, the response is transmitted as a beacon report or a measurement report.
[0086] In step S604, the AP 101 determines whether it is necessary to switch the connection destination of the MFP 100 based on the congestion state of the network recognized by the AP 101 and the radio wave strength received from the MFP 100 in step S603. For example, when the number of STAs connected to the AP 101 is large, the communication traffic volume is large, the congestion level of other APs is lower than that of the AP 101, there are interfering radio waves, or the AP function stops, the AP 101 determines that it is necessary to switch the connection destination. When it is determined that it is necessary to switch the connection destination of the MFP 100, and the SSID, channel, or frequency band of the other AP designated as the switching destination of the MFP 100 is determined, the process proceeds to step S605.
[0087] In step S605, AP 101 sends an AP change request (connection destination change request) to MFP 100. The connection destination change request includes information indicating the SSID, channel, or frequency band of the other AP designated as the switching destination of MFP 100 determined in step S604. Note that multiple SSIDs can be specified. For example, the connection destination change request is sent as a BTM request. That is, a BSS transition management (BTM) request frame defined in the IEEE 802.11v standard is sent. Figure 6 In the illustrated example, the AP 102 is specified as the switching destination included in the connection destination change request.
[0088] When the MFP 100 complies with the connection destination change request received in step S605, the MFP 100 transmits a response indicating approval of the switching to the AP 101 in step S606. When the MFP 100 does not comply with the connection destination change request, the MFP 100 may transmit a response indicating rejection of the switching. This response is transmitted as a BTM response. Figure 6 In the example shown, a response is sent indicating consent.
[0089] In step S607, the connection between the AP 101 and the MFP 100 in the wireless infrastructure mode is cut off.
[0090] In step S608 , the MFP 100 transmits a connection request to the AP 102 specified in the connection destination change request received in step S605 to connect to the AP 102 .
[0091] Thus, in step S609, a connection is established between the MFP 100 and the AP 102 in the wireless infrastructure mode.
[0092] As described above, the MFP 100 operating as the STA can change the connection destination from the AP 101 to the AP 102 based on the connection destination change request from the AP 101 to which the MFP 100 is initially connected. The AP 101 and the AP 102 may be APs installed at different locations. Figure 6 By the process shown in the figure, the MFP 100 can switch the connection destination to another AP installed at a location different from the location of the AP to which the MFP 100 initially connected. Alternatively, the AP 101 and the AP 102 can be APs corresponding to different frequency bands among a plurality of frequency bands (two or three of the 2.4 GHz band, the 5 GHz band, and the 6 GHz band) provided by the same device. That is, by Figure 6 By the process shown, the MFP 100 can switch the connection destination to another frequency band provided by the same device as the AP to which the MFP 100 initially connects. For example, the connection destination can be switched to an AP corresponding to the 6 GHz frequency band based on the connection destination change request.
[0093] Note that in this embodiment, the case where a measurement request and a connection destination change request are sent from an AP using a method according to Wi-Fi Agile Multiband and the STA responds to these requests is described as an example, but it is not limited to this example. This embodiment is also applicable to the case where the STA responds and changes the connection destination AP (switches, deletes, or adds the connection destination AP) in response to a measurement request and a connection destination change request sent from an AP using a method other than the method used in the above example.
[0094] There are cases where no problem occurs even if the connection destination AP is changed based on a connection destination AP change request sent from the currently connected AP and cases where it is not desired to change the connection destination AP. In the case where it is not desired to change the connection destination AP based on the change request, one of the following types of processing, or a combination of two or more types of processing may be performed as processing for suppressing the change of the connection destination in response to the change request. Each of the following types of processing is processing for avoiding changing the connection destination AP based on the change request or processing for suppressing the change of the connection destination AP.
[0095] Inhibition treatment 1
[0096] Even if the change request described in relation to step S605 is received, the connection destination AP is not changed based on the received change request, and no response is made to the change request, or a response indicating rejection (not changing the connection destination AP) is sent to the currently connected AP in response to the change request. In the case where a response indicating rejection is sent, the priority of change of the connection destination of other STAs connected to the AP to which the MFP 100 is connected becomes high, while the priority of change of the connection destination of the MFP 100 that has sent the response indicating rejection becomes low, so the MFP 100 can maintain the connection with the currently connected AP. In the case where no response is made (the request is ignored), it is considered that the currently connected AP will maintain the connection with the MFP 100 because the AP waits for a response until the response waiting time expires. Therefore, in the case where the connection is immediately cut off when any response to the change request is received from the MFP 100, the connection with the currently connected AP can be maintained for a longer time than in the case where no response is made. Therefore, different types of processing can be performed based on the information indicating the reason for the change included in the change request. For example, if the reason is weak, a response indicating a rejection may be sent; if the reason is strong, the change request may be ignored. For example, the change reason may be determined based on information in the BTM request indicating a reason among the multiple reasons included in the request pattern. For example, when the upcoming disassociation bit or the BSS termination inclusion bit in the request pattern is 1, the change reason may be determined to be strong. Otherwise, the change reason may be determined to be weak.
[0097] Inhibition treatment 2
[0098] In response to the measurement request described in connection with step S601, information indicating that the radio wave reception condition (signal reception condition) of a non-connected AP other than the currently connected AP is worse than the actual measurement condition (i.e., the signal quality is worse than the actually measured signal quality) is given as a response (false response). In this case, the response may be made by actually performing a measurement in response to the received measurement request, or the response may be made without actually performing a measurement. Specifically, in the response described in connection with step S603 (e.g., a beacon report), a value obtained by reducing the received signal strength or / and increasing the noise (signal-to-noise ratio) is given as the signal quality measured for the signal received from the non-connected AP. Alternatively, information about at least one non-connected AP may not be included in the response. Alternatively, processing may be performed based on information about non-connected APs measured in the past to make a response indicating that the received signal strength is significantly low or a response indicating a value obtained by significantly increasing the noise. Alternatively, even if a measurement request is received, measurement (AP search) is not actually performed and information about non-connected APs is not included in the response, and a response indicating that a favorable received signal strength and a favorable noise condition can be obtained only for the currently connected AP may be made. Giving a response that does not include information about non-connected APs in response to a measurement request is equivalent to giving a response indicating that no other non-connected APs can be found through AP search. That is, a response that does not include information about non-connected APs indicates that at least some signal qualities of signals received from non-connected APs are worse than the signal qualities obtained when an AP search is actually performed.
[0099] In this case, it is expected that a request to change the connection destination to another AP is avoided from being sent from the currently connected AP. Therefore, the connection destination is suppressed from being changed in response to the connection destination change request.
[0100] Inhibition treatment 3
[0101] The connection with the currently connected AP is temporarily cut off, and after information indicating that the MFP does not support the change request is given, the connection with the same AP is established again. Specifically, the wireless connection with the currently connected AP is temporarily cut off, and data of an association request frame including information indicating that the MFP does not support IEEE 802.11v is generated as a preparation for establishing the wireless connection again. Thereafter, the process of establishing a connection with the AP is performed using the data of the generated association request frame. Therefore, in the case of generating an association request frame including information indicating that the MFP does not support IEEE 802.11v, the MFP is connected to the AP as an electronic device that does not support the function of Agile Multiband. Therefore, the connected AP recognizes the MFP 100 as an electronic device that does not support IEEE 802.11v, and no longer sends a request for changing the destination of the wireless connection to the MFP 100. Since the request for changing the destination of the wireless connection is no longer sent to the MFP 100, the wireless connection between the MFP 100 and the currently connected AP may be maintained. Furthermore, when the MFP 100 is recognized by the currently connected AP as an electronic device that does not support IEEE 802.11v, the transmission of a measurement request (the request described in relation to step S601) from the currently connected AP to the MFP 100 is also suppressed. Therefore, it is possible to avoid the MFP 100 performing measurement (AP search) in response to the measurement request and responding to the measurement request (processing in step S603). Therefore, it is possible to reduce the processing load, save power consumption, and apply resources to other processing.
[0102] For example, it may not be desirable to change the connection destination AP based on a change request in a state of receiving print data. The state in which the MFP 100 is receiving print data is a state in which a portion of the print data of the image to be printed has been received from the portable terminal device 104, and the remaining portion of the print data has not yet been received. The MFP 100 does not store all the print data to be printed on a single sheet. Therefore, when the MFP 100 receives a portion of the print data, it prints the received data (for example, receives the print data corresponding to a line and prints the line), and repeats the reception and printing of subsequent data. If the connection destination AP is changed based on a connection destination change request while receiving print data as described above, a time lag due to the connection destination switching process occurs, which may result in a decrease in print quality, such as uneven printing. In addition, the following situation may occur: after switching the connection destination, a problem occurs in the communication with the portable terminal device 104, and subsequent data cannot be received, resulting in a printing failure. Therefore, it is preferable to perform at least one of the above-mentioned suppression processing 1 and suppression processing 2 as processing for suppressing the change of the connection destination in response to the change request while receiving the print data, or perform the above-mentioned suppression processing 3 before starting to receive the print data.
[0103] Also, changing the connection destination AP based on a change request may not be desirable depending on the security status set in the MFP 100. A configuration for performing control to change the connection destination AP by the MFP 100 or to suppress the change based on the security setting set in the MFP 100 is described below.
[0104] Security Settings for MFP 100
[0105] Electronic devices connected to a network face security risks. Therefore, it is necessary to appropriately perform various settings related to security. For example, MFP 100 (i.e., a multifunction printer that performs copying, printing, scanning, etc. of images) can be used in various environments (such as large offices, small offices, public spaces, or home work environments). Therefore, security settings corresponding to various risk levels are prepared for MFP 100. These types of security settings include many items, and these items include items that are difficult to set for users who do not have knowledge of security technology. Therefore, MFP 100 in this embodiment may have a function of collectively setting multiple security setting items based on a selected security type. Examples of methods for selecting a security type include a method for selecting a usage environment type corresponding to the installation environment of MFP 100 and a method for selecting a security level indicating the security strength of MFP 100.
[0106] How to set security settings by selecting the type of environment to use
[0107] FIG. 7A to FIG. 7G An example of a screen displayed in the operation display unit 205 of the MFP 100 for operations related to a function for collectively setting security setting values of device main units is shown. Fig. 7A Shown in Figure 3B The "Main Unit Settings" screen displayed when "Main Unit Settings" is selected on the screen shown. This screen shows "Print Settings", "Security Settings", "Language Settings" and "Other Settings" as further selection items. Figure 7B Shown from Fig. 7A The security setting screen displayed when the security setting 701 is selected among the selection items on the screen shown. This screen shows "recommended security setting", "lock setting" and "administrator password setting" as further selection items.
[0108] Figure 7C Shown in Figure 7BThe "recommended security settings" screen is displayed when the recommended security settings 702 are selected on the screen shown. The screen shown shows six usage environment types (company intranet type 703a, Internet access prohibited type 703b, Internet direct connection type 703c, home type 703d, public space type 703e, and highly confidential information management type 703f) as example options 703 of the security types set in the MFP 100.
[0109] Fig.7D Shown in Figure 7C 705 is a confirmation screen displayed after selecting any one of the usage environment types on the screen shown in FIG. 706 and before executing the security setting (collective setting) corresponding to the selected usage environment type. Message 704 is displayed for final confirmation before executing the collective setting, and message 704 indicates that MFP 100 will be automatically restarted after executing the collective setting. Security type 705 is the same as the one selected by the user on the previous screen ( Figure 7C ) and indicates the environment type selected on Fig.7D In the example shown, the company intranet type 703a has been selected. A "Yes" button 706 for allowing execution of security settings and a "No" button 707 for canceling execution of security settings are provided at the lower portion of the screen.
[0110] Fig. 7E Shown in the user Fig.7D 706 is selected on the screen shown in FIG. 708. Indicator 708 indicates that internal processing is being performed in MFP 100. At this time, a plurality of security setting items are collectively set in MFP 100 according to the selected use environment type, and the setting values are stored in RAM 214 and nonvolatile memory 215 together with the selected security type. When the series of processing is completed, MFP 100 displays the following information: Figure 7F As described above, the MFP 100 has a function of collectively setting a plurality of security-related setting values to values suitable for the use environment by causing the user to select the use environment in which the MFP 100 is installed as the "security type".
[0111] Figure 8 A correspondence table showing security setting values set by the collective setting function of the MFP 100 according to each usage environment type is shown. Figure 8 The top row in the shown table shows the usage environment type, which is set to the security type and includes the company intranet type, Internet access prohibited type, Internet direct connection type, home type, public space type and highly confidential information management type as described above.
[0112] Figure 8The leftmost column in the table shown shows the security setting items of the MFP 100 that are collectively set. "Screen lock setting" indicates a function that prevents unauthorized operations and information leakage by people other than authorized users by switching the screen (lock screen) to a screen that requires a password input when no operation is performed for a certain period of time on the operation display unit 205. "Use Bluetooth" indicates a setting as to whether to prohibit access from an external device via Bluetooth communication. "Use SNMPv1" indicates a setting as to whether to prohibit communication with a specific version (version 1 in this example) of the Simple Network Management Protocol (SNMP). "Usable TLS version" indicates a setting as to an available version of Transport Layer Security (TLS), i.e., an encrypted communication protocol used in the server function of the MFP 100. "Firmware update notification" indicates a setting as to whether to enable a function that prompts the user to update the firmware by displaying a message on the operation display unit 205 when there is an updated version of the firmware included in the MFP 100.
[0113] Each security setting item can be set individually from the main unit setting menu or the communication setting menu on the operation display unit 205, but the security setting items can also be set collectively by selecting a security type (in this example, a usage environment type). In the case of collective setting, the security setting items are respectively set to the setting values shown in the table according to the selected security type. Note that the hyphen "-" shown in the table indicates that the setting values set when the MFP 100 is shipped or the setting values set by the user after shipping are not changed. That is, the state immediately before the collective setting is performed (i.e., the setting values set when the MFP is shipped or the setting values set by the user) is maintained.
[0114] The usage environment types are described below. The Internet access prohibited type corresponds to security settings suitable for the use of MFP 100 in an environment isolated from the Internet. The company intranet type corresponds to security settings suitable for the use of MFP 100 in an intranet environment managed by a company, etc. The Internet direct connection type corresponds to security settings suitable for the use of MFP 100 in an environment where MFP 100 is directly connected to the Internet. The home type corresponds to security settings suitable for the use of MFP 100 in a home network (home LAN) environment managed by an individual. The public space type corresponds to security settings suitable for the use of MFP 100 in an environment where MFP 100 is used by a large number of unspecified people or in a public network environment. The highly confidential information management type corresponds to security settings suitable for the use of MFP 100 in an environment that has a significant impact in the event of an attack or information leakage. For example, in the security settings corresponding to the Internet access prohibited type, priority is given to connectivity in an isolated network, so only basic security measures are performed so that the use of information devices using traditional passwords or protocols is not restricted. As Figure 8 As shown in the corresponding table in , security items are set so that the security level becomes higher in the following order: Internet access prohibition type, company intranet type, Internet direct connection type, home type, public space type, and highly confidential information management type. For the highly confidential information management type, security is given top priority, and functions that are conceivable even with a small risk are restricted.
[0115] In the security setting item, the screen lock setting is a setting for locking the displayed operation screen to restrict the printer operation by the user and requiring the user to enter a password. When the screen lock setting is effective, security is improved, but additional operations are required. Therefore, in the present embodiment, the screen lock setting is effective only for a public space type in which the MFP is assumed to be used by a large number of unspecified people and a highly confidential information management type that requires a very high security level. When a usage environment type other than these two usage environment types is selected, the collective setting function does not make the screen lock setting affirmatively "effective", but maintains the current setting value (such as Figure 8 In addition, for the settings regarding the use of Bluetooth, "Prohibit" is set in the collective settings for the home type, public space type, and highly confidential information management type (i.e., usage environments where Bluetooth communication may pose a security risk). The settings regarding the usable TLS version restrict the version of TLS, which is a security method for network communication. Figure 8 In addition to the "TLS1.2 / 1.3" shown in the figure, TLS versions also include TLS1.0 and TLS1.1, but these versions are older and include security risks. Figure 8As shown in the table, for usage environments other than "Internet access prohibited type", the usable TLS version is set to TLS1.2 / 1.3 in the collective settings. In the usage environment corresponding to "Internet access prohibited type", the MFP is not connected to the Internet, so TLS1.0 / 1.1 can be allowed, so a "hyphen (-)" is shown in the table.
[0116] Note that the security setting items set according to each security type are not limited to the above items. For example, for each security type, the security setting items may also include usable encryption schemes (3DES, AES, AES-GCM, etc.) and usable hash functions (SHA-1, SHA-2, etc.). In addition, for each security type, the security setting items may also include settings for whether to use IPP security, HTTPS security, and enhanced WSD security. Note that the above security items do not limit the security setting items that are set collectively, and there is no need to set all of the above security items collectively.
[0117] Note that these security setting items include items that require resetting the relevant processing unit to make the changed setting value effective. Therefore, when the security type (in this example, the use environment type) is changed, the MFP 100 automatically restarts and applies the setting value after restarting. In addition, the user can not select any security type, that is, the user can choose not to use the security collective setting function.
[0118] Fig. 9 2 is a flowchart showing processing performed by the MFP 100 in response to a connection destination AP change request according to the state (set security state) of the MFP 100. The CPU 212 implements the processing performed by the MFP 100 in the flowchart by loading various programs stored in a memory such as the ROM 213 into the RAM 214 and executing the programs.
[0119] exist Fig. 9 In the initial state of the illustrated process, the MFP 100 has established a connection with the AP 101 in the wireless infrastructure mode. Furthermore, when the connection is established between the MFP 100 and the AP 101 in the wireless infrastructure mode, the AP 101 obtains information indicating whether the MFP 100 supports IEEE 902.11v. In this example, the AP 101 has obtained information indicating that the MFP 100 supports IEEE 902.11v, makes an inquiry about the radio wave strength, and issues a connection destination AP change request to the MFP 100.
[0120] In step S901, the CPU 212 of the MFP 100 determines whether an inquiry (measurement request) regarding the strength of radio waves received from an AP located in the surrounding area of the MFP 100 has been received from the AP 101. The inquiry is sent as a beacon frame request or a beacon report request. The inquiry regarding the strength of radio waves received in this step is the same as the inquiry regarding the strength of radio waves received in the AP 101. Figure 6 101. When the CPU 212 determines that the query about the radio wave strength has been received ("Yes" in step S901), the processing proceeds to step S902. On the other hand, when the CPU 212 determines that the query about the radio wave strength has not been received ("No" in step S901), the processing proceeds to step S903. In step S902, the CPU 212 measures the strength of the radio waves received from the APs located in the surrounding area of the MFP 100, and sends a list of the strengths of the radio waves received from the APs to the AP 101 as a beacon report, as described above. Figure 6 The description related to step S602 and step S603 shown in FIG.
[0121] In step S903, the CPU 212 determines whether a connection destination AP change request transmitted from the AP 101 has been received. Figure 6 The CPU 212 receives a request for a change in the AP 101. The request in step S605 corresponds to the request sent by the AP 101. When the CPU 212 determines that the change request has been received ("YES" in step S903), the process proceeds to step S904. On the other hand, when the CPU 212 determines that the change request has not been received ("NO" in step S903), the process proceeds to step S911.
[0122] In step S904, the CPU 212 of the MFP 100 obtains the FIG. 7A to FIG. 7G In this example, the security setting value is stored in the nonvolatile memory 215 or the RAM 214, and the CPU 212 reads the security setting value from the nonvolatile memory 215 or the RAM 214. In step S905, the CPU 212 obtains security information about the following AP (hereinafter referred to as "switching destination AP"), which is Figure 6The candidate for switching connection destination included in the connection destination change request received in step S605 is shown. The security information indicates the security method used in the communication between the MFP 100 and the switching destination AP. The security information is included in the robust security network (RSN) information field of the beacon frame received from the switching destination AP. In the processing performed in step S905, security information about the switching destination AP can be obtained by receiving a beacon frame from the switching destination AP. Alternatively, when the radio wave strength is obtained in step S902, the security information about each AP can be stored in the RAM 214 and the non-volatile memory 215, and the security information about the switching destination AP can be read out from the RAM 214 or the non-volatile memory 215.
[0123] In step S906, the CPU 212 determines whether the connection destination AP can be changed based on the security setting value of the MFP obtained in step S904 and the security information about the switching destination AP obtained in step S905. Fig. 10A and Fig. 10B Describe the determination. In step S907, the CPU 212 branches the processing according to the result of the determination performed in step S906. When the CPU 212 determines in step S907 that the connection destination can be changed ("Yes" in step S907), the processing proceeds to step S908; when it is determined that the connection destination cannot be changed ("No" in step S907), the processing proceeds to step S910. In step S908, the CPU 212 sends the following response to the AP 101, which indicates that the CPU 212 obeys the received connection destination change request. In step S909, the CPU 212 cuts off the connection with the AP 101 and executes processing for establishing a connection with the connection destination AP included in the connection destination change request. Step S908 corresponds to Figure 6 , and step S909 corresponds to step S606 shown in Figure 6 The processing performed in steps S607, S608 and S609 shown in FIG.
[0124] In step S910, the CPU 212 sends a response indicating that the MFP 100 rejects the change in response to the change request to the AP 101, and proceeds to step S911. This process corresponds to Figure 6 The sending of the response indicating rejection in step S606 is shown, and corresponds to the above-mentioned suppression process 1. In step S911, it is determined whether the connection with AP 101 is maintained, and if the connection is maintained, the process proceeds to step S901, and if it is determined that the connection has been cut, the process ends.
[0125] Fig. 10AThe determination table 1001 is shown for determining whether the AP can be changed based on the security type (usage environment type) of the device and the security information about the AP recommended as the switching destination. Fig. 10A Determination table 1001 shown in determines whether the connection destination AP can be changed. Determination table 1001 shows the conditions for determining whether the connection destination AP can be changed. In determination table 1001, "Device security" shows the type of use environment of MFP 100 selected by the user. For example, "Security of switching destination AP" shows the security information about the switching destination AP obtained in step S905 (i.e., WPA, WPA2, or WPA3). WPA3 corresponds to the highest security level, and the security level decreases in the order of WPA2 and WPA. WPA is the abbreviation of Wi-Fi Protected Access. Fig. 10A In the determination table 1001 shown, when "Allow" is shown in the cell corresponding to the combination of the security of the device (type of usage environment) and the security of the switching destination AP, the CPU 212 determines that the connection destination AP can be changed, and when "Not Allowed" is shown in the cell, the CPU 212 determines that the connection destination AP cannot be changed. That is, the combination of the security of the device and the security of the switching destination AP showing "Allowed" in the corresponding cell indicates that the condition of changing the connection destination AP according to the change request is suppressed. In addition, the combination of the security of the device and the security of the switching destination AP showing "Not Allowed" in the corresponding cell indicates that the condition of changing the connection destination AP according to the change request is suppressed. For example, when the security of the device is a company intranet type and the security of the switching destination AP is WPA, it is determined that the connection destination AP can be changed. However, when the security of the device is a public space type that requires a higher security level, if the security of the switching destination AP is WPA, it is determined that the connection destination AP cannot be changed.
[0126] In the above configuration, whether the connection destination AP can be changed is determined based on the use environment type set in the MFP 100. However, the security status used as a basis for determining whether the AP can be changed is not limited to the use environment type. For example, the security type can be determined based on a specified security level. In this case, the user can Figure 7G The screen 721 showing security level options (rather than Figure 7C The security level of the MFP 100 is selected on the screen for selecting the type of use environment shown in FIG. Then, in step S906, the security level of the MFP 100 is selected according to the Fig. 10BThe determination table 1002 shown determines whether the connection destination AP can be changed. That is, the CPU 212 determines whether the AP can be changed by referring to the determination table 1002 based on the security level set in the MFP 100 and security information on the switching destination AP.
[0127] In the determination table 1002, "Security of the device" shows the security level of the MFP 100 selected by the user. The security level indicates the security strength and is represented by 0, 1, or 2 in this example. When the security level is 0, the security strength is the lowest; when the security level is 1, the security strength is the second lowest; and when the security level is 2, the security strength is the highest. In the determination table, when "Allow" is shown in the cell corresponding to the combination of the security of the device and the security of the switching destination AP, it is determined that the connection destination AP can be changed; when "Not allowed" is shown in the cell, it is determined that the connection destination AP cannot be changed. For example, when the security of the device is level 0 and the security of the switching destination AP is WPA, the CPU 212 determines that the connection destination AP can be changed. In addition, when the security of the device is level 2 and the security of the switching destination AP is WPA, the CPU 212 determines that the connection destination AP cannot be changed.
[0128] As described above, "usage environment type" or security level can be selected as the security type. However, as long as the security type is a setting value that can be used to specify collective settings of setting items related to the security of the device, there is no limitation on the security type and the method for specifying the security type.
[0129] according to Fig. 10A In the determination table 1001 shown in the figure, in the case of the highly confidential information management type, the connection destination AP cannot be changed regardless of the security information about the switching destination AP. As described above, when it is set that the security type of the connection destination AP is prohibited from being changed regardless of the security of the switching destination AP, the above-mentioned suppression process 2 can be used for control. For example, when it is set that the use environment type of the connection destination AP is prohibited from being changed regardless of the security of the switching destination AP (in this example, the highly confidential information management type), the CPU 212 can Fig. 9 Suppression processing 2 is executed in step S902 shown. When suppression processing 2 is executed, a beacon report indicating a radio wave condition (signal quality) worse than an actually measured condition is transmitted, and therefore, transmission of a connection destination change request to the MFP 100 is suppressed.
[0130] Alternatively, if Fig.11 As shown, when it is determined in step S1101 that the highly confidential information management type is set, the process may immediately proceed to step S910, and the suppression process 1 may be performed without considering the security of the switching destination AP. Fig. 10A According to the determination table shown, in the case of the company intranet type, the connection destination AP can be changed regardless of the security of the switching destination AP. Therefore, when it is determined in step S1102 that the company intranet type is set, the processing can immediately proceed to step S908, and the connection destination AP can be changed according to the change request without considering the security of the switching destination AP. As described above, in the case of the highly confidential information management type and the company intranet type, it can be determined whether to suppress the change of the connection destination without obtaining the security of the switching destination AP or considering the security of the switching destination AP in step S905.
[0131] Furthermore, when it is set that the security type of the connection destination AP is prohibited from being changed regardless of the security of the switching destination AP, the suppression process 3 can also be used. FIG. 7C to FIG. 7F Therefore, when it is set to prohibit changing the security type of the connection destination AP (the highly confidential information management type in this example) regardless of the security of the switching destination AP, as described above, the CPU 212 controls to execute the suppression process 3 when the MFP is restarted.
[0132] Specifically, the process can be implemented as Fig.12. When the MFP 100 is restarted in step S1201, the CPU 212 determines in step S1202 whether the highly confidential information management type is set to the security type. When the CPU 212 determines that the highly confidential information management type is set ("Yes" in step S1202), the processing proceeds to step S1203. In step S1203, the CPU 212 generates an association request frame, which includes information indicating that the MFP does not support IEEE 802.11v. On the other hand, when the CPU 212 determines that the highly confidential information management type is not set ("No" in step S1202), the processing proceeds to step S1204. In step S1204, the CPU 212 generates an association request frame, which includes information indicating that the MFP supports IEEE 802.11v. In step S1205, the CPU 212 performs processing for establishing a connection with the AP using the association request frame generated in step S1203 or step S1204. In the case where an association request frame including information indicating that the MFP does not support IEEE 802.11v is generated in step S1203, the MFP 100 is connected to the AP as an electronic device that does not support the function of Agile Multiband. Therefore, a connection destination AP change request will no longer be sent to the MFP 100. On the other hand, in the case where an association request frame including information indicating that the MFP supports IEEE802.11v is generated, the MFP is connected to the AP as an electronic device that supports the function of Agile Multiband.
[0133] As described above, in one aspect of the present embodiment, whether to suppress the change of the connection destination AP is controlled based only on the security type set in the MFP 100 .
[0134] According to this embodiment, when a connection destination AP change request is received, the occurrence of security risks due to switching APs based on the change request can be suppressed. That is, optimization of the connection destination using the technology of dynamically switching the connection destination AP and avoiding security risks of the device can be achieved at the same time.
[0135] Note that the above-described various types of control as control performed by a CPU included in each device may be performed by a single hardware, or a plurality of hardware (eg, processors or circuits) may share processing to control the entire device.
[0136] In addition, the preferred embodiments of the present invention have been described in detail, but the present invention is not limited to these specific embodiments, but includes various forms within the scope of the gist of the present invention. In addition, the above-mentioned embodiments are only embodiments of the present invention, and the embodiments can also be appropriately combined.
[0137] In addition, in the above-mentioned embodiment, the case where the present invention is applied to MFP is described as an example, but the present invention is not limited to this example, and the present invention is applicable to a wireless device connected to an AP and used as a STA, which is an electronic device that can set security settings. That is, the present invention is applicable to personal computers, PDAs, tablet computer terminals, mobile phone terminals such as smartphones, music players, game consoles, e-book readers, smart watches, and various measuring devices (sensor devices) such as thermometers and hygrometers. In addition, the present invention is applicable to digital cameras (including still cameras, video cameras, web cameras, and security cameras), printers, scanners, and drones. In addition, the present invention is applicable to video output devices, audio output devices (such as smart speakers), streaming media players, and wireless LAN adapters that can be connected to USB terminals or LAN cable terminals. For example, the video output device includes a device that obtains (downloads) a moving image on the Internet identified by a URL specified by an electronic device, and outputs the image to a display device connected via a video output terminal such as HDMI (registered trademark), thereby realizing streaming reproduction or mirror display in the display device (displaying the content displayed on the electronic device on the display device). Video output devices also include televisions, media players (such as hard disk recorders, blue-ray recorders, and DVD recorders), head-mounted displays, projectors, display devices (monitors), and identification devices. In addition, the present invention is applicable to so-called smart home appliances that can establish Wi-Fi connections, such as air conditioners, refrigerators, washing machines, vacuum cleaners, ovens, microwave ovens, lighting devices, heating devices, and air cooling devices.
[0138] The present invention is not limited to the above-described embodiments, and various changes and modifications may be made without departing from the spirit and scope of the present invention. Therefore, in order to make the public aware of the scope of the present invention, the following claims are made.
[0139] Other embodiments
[0140] The embodiments of the present invention may also be implemented by reading and executing computer executable instructions (e.g., one or more programs) recorded on a storage medium (which may also be more completely referred to as a "non-transitory computer-readable storage medium") to perform one or more functions in the above-mentioned embodiments, and / or a computer of a system or device including one or more circuits (e.g., an application-specific integrated circuit (ASIC)) for performing one or more functions in the above-mentioned embodiments, and the embodiments of the present invention may be implemented by, for example, reading and executing the computer executable instructions from the storage medium by the computer of the system or device to perform one or more functions in the above-mentioned embodiments, and / or controlling the one or more circuits to perform one or more functions in the above-mentioned embodiments. The computer may include one or more processors (e.g., a central processing unit (CPU), a microprocessing unit (MPU)), and may include a network of separate computers or separate processors to read and execute the computer executable instructions. The computer executable instructions may be provided to the computer, for example, from a network or the storage medium. The storage medium may include, for example, a hard disk, a random access memory (RAM), a read-only memory (ROM), a memory of a distributed computing system, an optical disk (such as a compact disc (CD), a digital versatile disc (DVD), or a Blu-ray disc (BD) TM ), flash memory devices, memory cards, etc.
[0141] The embodiments of the present invention may also be implemented by providing software (program) for performing the functions of the above-described embodiments to a system or device via a network or various storage media, and a computer or a central processing unit (CPU) or a microprocessing unit (MPU) of the system or device reads and executes the program.
[0142] While the present invention has been described with reference to exemplary embodiments, it is to be understood that the invention is not limited to the disclosed exemplary embodiments.The scope of the following claims is to be accorded the broadest interpretation so as to encompass all such modifications and equivalent structures and functions.
Claims
1. An electronic device, comprising: a receiving unit configured to receive, from the connected access point, a request for changing the access point serving as a connection destination; a setting unit configured to set a setting value related to the safety of the electronic device; as well as A control unit is configured to control whether to suppress a change of an access point serving as a connection destination based on the change request based on the setting value set by the setting unit.
2. The electronic device according to claim 1, in, The control unit controls to change the connection destination based on the change request when the first setting value is set by the setting unit, and controls to suppress changing the connection destination based on the change request when the second setting value is set by the setting unit.
3. The electronic device according to claim 1, further comprising: an obtaining unit configured to obtain a security method used in communication with an access point that is a candidate for a connection destination after a change is made based on the change request, and The control unit controls whether to suppress changing the access point serving as the connection destination based on the change request based on the setting value set by the setting unit and the security method used in communication with the access point serving as a candidate for the connection destination.
4. The electronic device according to claim 3, in, The control unit executes changing the connection destination based on the change request when the setting value set by the setting unit and the security method obtained by the obtaining unit satisfy a first condition, and suppresses changing the connection destination based on the change request when the setting value and the security method satisfy a second condition.
5. The electronic device according to claim 1, further comprising: an obtaining unit configured to obtain a security method used in communication with an access point that is a candidate for a connection destination after a change is made based on the change request, and When the security method obtained by the obtaining unit is the first method and the first setting value is set by the setting unit, the control unit controls to change the connection destination based on the change request, and when the security method is the first method and the second setting value is set by the setting unit, the control unit controls to suppress the change of the connection destination based on the change request.
6. The electronic device according to claim 5, in, The first method is WPA or WPA2.
7. The electronic device according to claim 5, in, When the security method acquired by the acquisition unit is a second method more secure than the first method, the control unit changes the connection destination based on the change request both when the first setting value is set by the setting unit and when the second setting value is set by the setting unit.
8. The electronic device according to claim 7, in, The second method is WPA3.
9. The electronic device according to claim 1, in, The setting value set by the setting unit indicates a security level of the electronic device.
10. The electronic device according to claim 1, in, The setting value set by the setting unit indicates a usage environment type of the electronic device.
11. The electronic device according to claim 1, in, Determine at least two of the following based on the setting value set by the setting unit: whether to enable a function for locking the screen when no operation is performed for a certain period of time; whether to prohibit the use of Bluetooth; whether to prohibit the use of a specific version of SNMP; the version of TLS that can be used; Whether to enable firmware update notifications; available encryption schemes; available hash functions; Whether IPP security is required; whether HTTPS security is required; and whether enhanced WSD security is required.
12. The electronic device according to claim 1, in, The electronic device establishes a connection with an access point and performs processing according to the IEEE 802.11ax standard.
13. The electronic device according to claim 1, in, The electronic device is capable of performing at least one of a process according to OFDMA and a process according to a target wake-up time.
14. The electronic device according to claim 1, in, The electronic device is capable of changing the connection destination to an access point using a 6 GHz frequency band by changing the connection destination based on the change request.
15. The electronic device according to claim 1, further comprising: The printing unit is configured to print an image on a printing medium.
16. A control method for an electronic device, the control method comprising the following steps: receiving a change request of an access point serving as a connection destination from a connected access point; Setting a setting value related to the security of the electronic device; and Based on the setting value that is set, whether to suppress a change of the access point serving as a connection destination based on the change request is controlled.
17. A computer-readable storage medium storing a program, wherein the program is configured to cause a computer of an electronic device to perform the following operations: receiving a change request of an access point serving as a connection destination from a connected access point; Setting a setting value related to the security of the electronic device; as well as Based on the setting value that is set, whether to suppress a change of the access point serving as a connection destination based on the change request is controlled.
18. A computer program product configured to cause a computer of an electronic device to perform the following operations: receiving a change request of an access point serving as a connection destination from a connected access point; Setting a setting value related to the security of the electronic device; and Based on the setting value that is set, whether to suppress a change of the access point serving as a connection destination based on the change request is controlled.
Citation Information
Patent Citations
Mobile router, mobile router control method and mobile router control program
JP2021175068A