Communication device, communication method, and program

JP2022188745A5Active Publication Date: 2025-05-07CANON KK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022073892
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-06-09
Filing Date
2022-04-27
Publication Date
2025-05-07
Estimated Expiration
2042-04-27

AI Technical Summary

Technical Problem

In Multi-Link communication, using a common PTK across multiple links increases the risk of encryption vulnerabilities, particularly when communicating in the 6 GHz band, as different security methods may be required for different frequency channels.

Method used

A communication device that can perform authentication using both WPA2 and WPA3 methods, controlling the frequency channels used for communication to ensure that authentication and encryption are performed using WPA3 when operating in the 6 GHz band, while allowing WPA2 for other bands to accommodate legacy devices.

Benefits of technology

Ensures secure communication in the 6 GHz band by enforcing WPA3 authentication and encryption, while still supporting legacy devices through WPA2, thereby enhancing security without compromising compatibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To perform authentication and encryption by using specific authentication methods in respective links when performing communication with the other communication device through a plurality of frequency channels and operating in a specific frequency channel.SOLUTION: A communication device can execute authentication using a Wi-Fi Protected Access (WPA) 2 system and authentication using a WPA3 system, and when performing communication with the other communication device while establishing links with the other communication device through a plurality of frequency channels, executes authentication by using the WPA3 system based on the fact that at least one frequency channel of the plurality of frequency channels is a frequency channel included in a specific frequency band.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a communication device that performs wireless communication. [Background technology]

[0002] Wireless LAN (Local Area Network) technology standards are established by IEEE802.11, a standardization organization for wireless LAN technology, and wireless LAN technology standards include IEEE802.11 / a / b / g / n / ac / ax, where IEEE stands for Institute of Electrical and Electronics Engineers.

[0003] IEEE802.11ax, described in Patent Document 1, uses OFDMA to achieve a high peak throughput of up to 9.6 gigabits per second (Gbps), as well as improved communication speeds under congested conditions. OFDMA stands for Orthogonal Frequency-Division Multiple Access.

[0004] To further improve throughput, a task group was established to develop the IEEE802.11be standard as the successor to IEEE802.11ax.

[0005] Conventionally, IEEE802.11 APs (Access Points) establish connections with STAs (Station) via a single frequency channel to communicate. The IEEE802.11be standard considers Multi-Link communication, in which a single AP can simultaneously establish multiple links with STAs via multiple frequency channels, including the 2.4GHz, 5GHz, and 6GHz bands, to communicate.

[0006] Meanwhile, standardization by the Wi-Fi Alliance, which ensures interoperability of wireless LAN technologies, is playing an important role, and standardization of WPA3, a more secure certification program for wireless LAN technology, is currently underway. WPA stands for Wi-Fi Protected Access.

[0007] In addition, communications over wireless LANs are encrypted using a PTK, which is an encryption key used to encrypt unicast communications, and a GTK, which is an encryption key used to encrypt broadcast or multicast communications. Here, PTK stands for Pairwise Transient Key, and GTK stands for Group Transient Key.

[0008] Furthermore, in the multi-link communication being considered in the 11be standard, it is being considered to use a common PTK for each link that establishes a connection. [Prior art documents] [Patent documents]

[0009] [Patent Document 1] Japanese Patent Application Publication No. 2018-50133 Summary of the Invention [Problem to be solved by the invention]

[0010] In multi-link communication, each link uses a common PTK, so authentication and encryption for each link must be performed using the same security method. Furthermore, when communicating in the 6 GHz band, authentication and encryption must be performed using WPA3. However, when a communication device and another communication device simultaneously establish and communicate over multiple links via frequency channels in the 6 GHz band and frequency channels other than the 6 GHz band, there is a risk that different security methods may be used for authentication and encryption between the links.

[0011] In view of the above problems, the communication device of the present invention aims to perform authentication using a specific security method when operating on a specific frequency channel when communicating with another communication device while multiple links are established between the communication device and the other communication device. [Means for solving the problem]

[0012] In order to achieve the above object, the communication device of the present invention is a communication device capable of performing authentication using the WPA (Wi-Fi Protected Access) 2 method and authentication using the WPA3 method, and has an establishment means for establishing a link between the communication device and another communication device via a frequency channel, and a control means for controlling authentication for performing communication with the other communication device, and when communicating with the other communication device in a state in which multiple links have been established between the communication device and the other communication device by the establishment means, the control means performs authentication using the WPA3 method based on the fact that the frequency channel used in at least one of the multiple links is a frequency channel included in a specific frequency band.

[0013] In addition, the communication device of the present invention is a communication device that is capable of performing authentication using the WPA (Wi-Fi Protected Access) 2 method and authentication using the WPA3 method, and operates as a communication access point, and has a communication means for communicating with other communication devices, and a control means for controlling authentication of communication with the other communication devices, and is characterized in that the control means performs authentication using the WPA3 method based on the fact that a frequency channel used in communication in which cooperation is performed between the communication device and the other communication devices is a frequency channel included in a specific frequency band.

[0014] Furthermore, a communication device of the present invention is a communication device capable of performing authentication using a first security method and authentication using a second security method, and includes an establishment means for establishing a link between the communication device and another communication device via a frequency channel, and a control means for controlling authentication of communication with the other communication device, wherein when communicating with the other communication device in a state in which multiple links have been established between the communication device and the other communication device by the establishment means, the control means performs authentication using the first security method based on the frequency channel used in at least one of the multiple links being a specific frequency, and performs authentication using the first security method or the second security method based on the fact that none of the frequency channels used in the multiple links are frequency channels included in the specific frequency band.

[0015] Furthermore, a communication device of the present invention is a communication device that is capable of performing authentication using a first security method and authentication using a second security method, and operates as a communication access point, and includes a communication means for communicating with other communication devices that operate as communication access points, and a control means for controlling authentication of communication with the other communication devices, wherein the control means performs authentication using the first security method based on the frequency channel used in communication in which cooperative operation is performed between the communication device and the other communication devices being a frequency channel included in a specific frequency band, and performs authentication using the first security method or the second security method based on the frequency channel used in communication in which cooperative operation is performed being a frequency channel included in the specific frequency band. [Effects of the Invention]

[0016] According to the present invention, when a communication device communicates with another communication device via multiple frequency channels, if the communication device operates on a specific frequency channel, authentication and encryption can be performed using a specific authentication method. [Brief explanation of the drawings]

[0017] [Figure 1] FIG. 1 is a diagram showing a network configuration according to the present invention. [Figure 2] FIG. 2 is a diagram illustrating a hardware configuration of a communication device according to the present invention. [Figure 3] FIG. 2 is a diagram illustrating a functional configuration of a communication device according to the present invention. [Figure 4] 10 is an example of an element indicating an RSNE that is assigned in accordance with a security method determined by the communication device 101 of the present invention. [Figure 5] 10 is an example of an element indicating an Extended Capability that is granted in accordance with a security method determined by the communication device 101 according to the present invention. [Figure 6] 10 is an example of an element indicating RSNXE that is assigned in accordance with the security method determined by the communication device 101 according to the present invention. [Figure 7] FIG. 10 is a flowchart showing a process in which the communication device 101 in the present invention determines a security method. [Figure 8] 10 shows an example of a graphical user interface display in the present invention. [Figure 9] 10 shows an example of a graphical user interface display in the present invention. [Figure 10] 10 shows an example of a graphical user interface display in the present invention. [Figure 11] 10 shows an example of a graphical user interface display in the present invention. [Figure 12] 10 shows an example of a graphical user interface display in the present invention. [Figure 13] 10 shows an example of a graphical user interface display in the present invention. [Figure 14] 10 shows an example of a graphical user interface display in the present invention. [Figure 15] 10 shows an example of a graphical user interface display in the present invention. [Figure 16] 10 shows an example of a graphical user interface display in the present invention. [Figure 17]10 shows an example of a graphical user interface display in the present invention. [Figure 18] 10 shows an example of a graphical user interface display in the present invention. [Figure 19] 10 shows an example of a graphical user interface display in the present invention. [Figure 20] 10 shows an example of a graphical user interface display in the present invention. [Figure 21] 10 shows an example of a graphical user interface display in the present invention. [Figure 22] 10 shows an example of a graphical user interface display in the present invention. [Figure 23] 10 shows an example of a graphical user interface display in the present invention. [Figure 24] FIG. 10 is a flowchart showing a process in which the communication device 101 in the present invention determines a security method. DETAILED DESCRIPTION OF THE INVENTION

[0018] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings. Note that the configurations shown in the following embodiments are merely examples, and the present invention is not limited to the illustrated configurations.

[0019] (Configuration of wireless communication system) 1 shows the configuration of a network in which a communication device 102 according to this embodiment participates. The communication device 102 is a station (STA) that serves to participate in the network 100. The communication device 101 is an access point (AP) that serves to construct the wireless network 100. The communication device 101 is capable of communicating with the communication device 102.

[0020] Each of the communication devices 101 and 102 can perform wireless communication in accordance with the IEEE 802.11be (EHT) standard. IEEE stands for Institute of Electrical and Electronics Engineers. The communication devices 101 and 102 can communicate at frequencies in the 2.4 Hz, 5 GHz, and 6 GHz bands. The frequency bands used by each communication device are not limited to these, and different frequency bands, such as the 60 GHz band, may be used. The communication devices 101 and 102 can also communicate using bandwidths of 20 MHz, 40 MHz, 80 MHz, 160 MHz, and 320 MHz. The bandwidths used by each communication device are not limited to these, and different bandwidths, such as 240 MHz and 4 MHz, may be used.

[0021] The communication device 101 and the communication device 102 can realize multi-user (MU) communication, which multiplexes signals from multiple users, by performing OFDMA communication compliant with the IEEE802.11be standard. OFDMA stands for Orthogonal Frequency Division Multiple Access. In OFDMA communication, a portion of the divided frequency band (RU, Resource Unit) is assigned to each STA so that they do not overlap, and the carrier waves of each STA are orthogonal. Therefore, an AP can communicate with multiple STAs in parallel within a specified bandwidth.

[0022] Although the communication devices 101 and 102 are described as being compatible with the IEEE 802.11be standard, they may also be compatible with legacy standards that predate the IEEE 802.11be standard. Specifically, the communication devices 101 and 102 may be compatible with at least one of the IEEE 802.11a / b / g / n / ac / ax standards. In addition to the IEEE 802.11 series standards, they may also be compatible with other communication standards such as Bluetooth (registered trademark), NFC, UWB, ZigBee, and MBOA. UWB stands for Ultra Wide Band, and MBOA stands for Multi-Band OFDM Alliance. NFC stands for Near Field Communication. UWB includes wireless USB, wireless 1394, WiNET, and the like. They may also be compatible with wired communication standards such as wired LAN. Specific examples of the communication device 101 include, but are not limited to, a wireless LAN router and a personal computer (PC). The communication device 101 may also be an information processing device such as a wireless chip capable of performing wireless communication in accordance with the IEEE802.11be standard. Specific examples of the communication device 102 include, but are not limited to, a camera, a tablet, a smartphone, a PC, a mobile phone, a video camera, and a headset. The communication device 102 may also be an information processing device such as a wireless chip capable of performing wireless communication in accordance with the IEEE802.11be standard.

[0023] Each communication device is capable of communicating using bandwidths of 20 MHz, 40 MHz, 80 MHz, 160 MHz, and 320 MHz.

[0024] Furthermore, the communication device 101 and the communication device 102 perform multi-link communication by establishing links and communicating via multiple frequency channels. In the IEEE 802.11 series of standards, the bandwidth of each frequency channel is defined as 20 MHz. Here, a frequency channel refers to a frequency channel defined in the IEEE 802.11 series of standards, which define multiple frequency channels in each of the 2.4 GHz, 5 GHz, 6 GHz, and 60 GHz frequency bands. By bonding adjacent frequency channels, a bandwidth of 40 MHz or more may be used in a single frequency channel. For example, the communication device 101 can establish and communicate with the communication device 102 via a first frequency channel in the 2.4 GHz band. In parallel with this, the communication device 102 can establish and communicate with the communication device 101 via a link 103 via a second frequency channel in the 5 GHz band. In this case, the communication device 102 performs multi-link communication, maintaining a second link 104 via a second frequency channel in parallel with the link 103 via the first frequency channel. In this way, the communication device 101 can improve the throughput of communication with the communication device 102 by simultaneously establishing multiple links via multiple frequency channels with the communication device 102. In this embodiment, the link 103 is a 20 MHz connection on channel 6 in the 2.4 GHz band, and the link number is set to 1. The link 104 is a 320 MHz connection on channel 113 in the 6 GHz band, and the link number is set to 2.

[0025] For example, the communication device 101 and the communication device 102 may establish a third link in the 5 GHz band in addition to the link 103 in the 2.4 GHz band and the second link 104 in the 6 GHz band. Alternatively, links may be established via multiple different channels included in the same frequency band. For example, a link on channel 6 in the 2.4 GHz band may be established as a first link, and a link on channel 1 in the 2.4 GHz band may be established as a second link. Note that links in the same frequency band and links in different frequency bands may be mixed. For example, the communication device 101 and the communication device 102 may establish a link on channel 1 in the 2.4 GHz band and a link on channel 149 in the 5 GHz band in addition to the link 103 on channel 6 in the 2.4 GHz band. By establishing multiple connections with the communication device 102 using different frequencies, the communication device 101 can establish communication with the communication device 102 using another band even when one band is congested, thereby preventing a decrease in throughput and communication delays.

[0026] Although the wireless network 100 in Fig. 1 is configured with one AP and one STA, the number and arrangement of the APs and STAs are not limited to this. For example, one STA may be added to the wireless network in Fig. 1. In this case, the frequency band of each link to be established, the number of links, and the frequency width are not important.

[0027] When performing multi-link communication, communication device 101 and communication device 102 divide one piece of data and transmit it to the other device via multiple links.

[0028] Furthermore, the communication device 101 and the communication device 102 may be capable of performing MIMO (Multiple-Input And Multiple-Output) communication. In this case, the communication device 101 and the communication device 102 have multiple antennas, and one of them transmits different signals from each antenna using the same frequency channel. The receiving side simultaneously receives all signals arriving from multiple streams using multiple antennas, and separates and decodes the signals of each stream. By performing MIMO communication in this way, the communication device 101 and the communication device 102 can communicate more data in the same amount of time than when not performing MIMO communication. Furthermore, when performing multi-link communication, the communication device 101 and the communication device 102 may perform MIMO communication on some links.

[0029] In this embodiment, the communication devices 101 and 102 are assumed to support the WPA (Wi-Fi Protected Access) security standard as well as the WPA2 and WPA3 standards. WPA, WPA2, and WPA3 are standards for authenticating a remote device and encrypting communications with the remote device. Since the communication devices 101 and 102 support the WPA3 standard, they can use SAE (Simultaneous Authentication of Equals), a method for sharing encryption keys in the WPA3 standard. Furthermore, since interoperability with previous communication devices does not need to be considered for communications at 6 GHz, the Wi-Fi Alliance has decided to use WPA3 for authentication and encryption for communications at 6 GHz. Furthermore, WPA3 uses AES-CCMP or AES-GCMP as the encryption method, rather than TKIP or WEP.

[0030] 2 shows an example of the hardware configuration of the communication device 101 in this embodiment. The communication device 101 includes a storage unit 201, a control unit 202, a function unit 203, an input unit 204, an output unit 205, a communication unit 206, and an antenna 207. Note that the number of antennas may be multiple.

[0031] The storage unit 201 is configured with one or more memories such as ROM and RAM, and stores various information such as computer programs for performing various operations described below and communication parameters for wireless communication. ROM stands for Read Only Memory, and RAM stands for Random Access Memory. In addition to memories such as ROM and RAM, the storage unit 201 may also use storage media such as flexible disks, hard disks, optical disks, magneto-optical disks, CD-ROMs, CD-Rs, magnetic tapes, non-volatile memory cards, and DVDs. Furthermore, the storage unit 201 may include multiple memories.

[0032] The control unit 202 is configured with one or more processors, such as a CPU or an MPU, and controls the entire communication device 101 by executing a computer program stored in the storage unit 201. The control unit 202 may control the entire communication device 101 in cooperation with the computer program stored in the storage unit 201 and an OS (Operating System). The control unit 202 also generates data and signals (radio frames) to be transmitted in communication with other communication devices. The CPU stands for Central Processing Unit, and the MPU stands for Micro Processing Unit. The control unit 202 may also be equipped with multiple processors, such as a multi-core processor, and the entire communication device 101 may be controlled by the multiple processors.

[0033] Furthermore, the control unit 202 controls the function unit 203 to perform predetermined processes such as wireless communication, imaging, printing, projection, etc. The function unit 203 is hardware that enables the communication device 101 to perform predetermined processes.

[0034] The input unit 204 receives various operations from the user. The output unit 205 outputs various types of information to the user via a monitor screen or a speaker. Here, the output from the output unit 205 may be a display on a monitor screen, an audio output from a speaker, a vibration output, or the like. Note that both the input unit 204 and the output unit 205 may be implemented by a single module, such as a touch panel. Furthermore, the input unit 204 and the output unit 205 may be integrated with the communication device 101 or may be separate units.

[0035] The communication unit 206 controls wireless communication conforming to the IEEE 802.11be standard. The communication unit 206 may also control wireless communication conforming to other IEEE 802.11 series standards in addition to the IEEE 802.11be standard, and may control wired communication such as a wired LAN. The communication unit 206 controls the antenna 207 to transmit and receive signals generated by the control unit 202 for wireless communication.

[0036] If the communication device 101 supports the NFC standard, Bluetooth standard, or the like in addition to the IEEE802.11be standard, it may control wireless communication in accordance with these communication standards. If the communication device 101 can perform wireless communication in accordance with multiple communication standards, it may be configured to have separate communication units and antennas compatible with each communication standard. The communication device 101 communicates data such as image data, document data, and video data with the communication device 101 via the communication unit 206. The antenna 207 may be configured as a separate unit from the communication unit 206, or may be configured together with the communication unit 206 as a single module.

[0037] The antenna 207 is an antenna capable of communication in the 2.4 GHz band, the 5 GHz band, and the 6 GHz band. In this embodiment, the communication device 101 has one antenna, but it may have three antennas. Alternatively, it may have a different antenna for each frequency band. Furthermore, if the communication device 101 has multiple antennas, it may have a communication unit 206 corresponding to each antenna.

[0038] The communication device 102 has the same hardware configuration as the communication device 101.

[0039] 3 is a block diagram showing the functional configuration of the communication device 101 according to this embodiment. The communication device 102 has a similar configuration. Here, the communication device 101 is assumed to include a wireless LAN control unit 301. The number of wireless LAN control units is not limited to one, and may be two, or three or more. The communication device 101 further includes a frame generation unit 302, a transmission time control unit 303, a beacon reception control unit 304, a UI control unit 305, a storage unit 306, and a wireless antenna 307.

[0040] The wireless LAN control unit 301 includes an antenna and circuit for transmitting and receiving wireless signals to and from other wireless LAN devices, and a program for controlling them. The wireless LAN control unit 301 controls wireless LAN communications based on frames generated by the frame generation unit 302 in accordance with the IEEE 802.11 standard series.

[0041] The frame generation unit 302 generates a wireless control frame to be transmitted by the wireless LAN control unit 301. The contents of the wireless control generated by the frame generation unit 302 may be restricted by settings stored in the storage unit 305. They may also be changed by user settings from the UI control unit 305. Information on the generated frame is sent to the wireless LAN control unit 301 and transmitted to the communication partner.

[0042] The communication method determination unit 303 determines the communication method to be used when communicating with the other party based on the received frame received from the wireless LAN control unit 301 and the setting information in the UI control unit 305. The communication method determination unit 303 also notifies the authentication method determination unit 306. After determining the communication method, the wireless LAN control unit 301 communicates with the other device in accordance with the determined communication method.

[0043] Authentication method determination section 304 determines a method for authenticating the other device from information from communication method determination section 303 and setting information in UI control section 305. Wireless LAN control section 301 authenticates the other device based on the determined authentication method.

[0044] The UI control unit 305 includes hardware related to a user interface, such as a touch panel or buttons for accepting operations on the AP by a user (not shown), and a program for controlling these. The UI control unit 305 also has a function for presenting information to the user, such as displaying images or outputting audio.

[0045] The storage unit 306 is a storage device that can be configured with a ROM, a RAM, etc., that stores programs and data that the AP runs on.

[0046] Figure 4 shows a Robust Security Network element (RSNE) defined in IEEE 802.11. The RSNE is stored in a management frame that complies with IEEE 802.11.

[0047] The Element ID field 401 indicates that the element is an RSNE, i.e., the value is 48.

[0048] The Pairwise Cipher Suite Count field 405 indicates the number of supported encryption methods. The specific value is shown in the Pairwise Cipher Suite List field 406. For example, if CCMP-128 is supported, the value is 00-0F-AC-04. If the Pairwise Cipher Suite Count field 405 indicates that multiple encryption methods are supported, for example, if 405 is set to 2, then multiple 506s are used in succession. For example, if CCMP-128 and GCMP-128 are supported, the value is 00-0F-AC-04 followed by 00-0F-AC-08. This order can be reversed. Also, any number of encryption methods can be supported.

[0049] The AKM Suite Count field 407 indicates the number of supported authentication methods. Specific values ​​are shown in the AKM Suite List field 408. In this embodiment, since only WPA3-SAE is assigned to RSNE, the AKM Suite Count field 407 is set to 1, and the AKM Suite List field 408 is set to 00-0F-AC-08, which indicates SAE. Note that this value may be any value specified for WPA3 or later. That is, if an authentication method using SHA-384 hashing in SAE is added to 00-0F-AC-14, it may be indicated in addition to the above. It may also include 00-0F-AC-09, which performs FT (Fast Transition) in SAE. However, since only WPA3 is supported, 00-0F-AC-02 and 00-0F-AC-06, which indicate PSK, are not included.

[0050] Figure 5 shows the Extended Capability defined in IEEE 802.11. The Extended Capability is stored in a management frame that complies with IEEE 802.11.

[0051] The fields shown here are, from the beginning, an Element ID field 501, a Length field 502, and an Extended Capabilities field 503.

[0052] The Extended Capabilities field 503 includes an SAE Password Identifiers In Use subfield 504 and an SAE Password Identifiers Used Exclusively subfield 505. These fields are enabled when a Password ID that can be set to change the password for each user is used when building a network with the same SSID. For example, if some of the built networks have a Password ID, the SAE Password Identifiers In Use subfield 504 is enabled. If all built networks have a Password ID, the relevant subfields 504 and 505 are enabled.

[0053] These values ​​may be enabled, for example, when building a network that uses 6GHz with Multi-Link in addition to an existing network. For example, by making a Password ID mandatory when connecting to a network that includes 6GHz with Multi-Link communication, it becomes possible to force a connection using WPA3, which supports Password ID. To make a Password ID mandatory, for example, a bit could be prepared to ensure that compatible devices always connect using a specific method, and that bit could be set.

[0054] For example, when building a network including 6 GHz in Multi-Link communication, the SAE Password Identifiers In Use subfield 504 may be enabled. Using a Password ID increases the confidentiality of the password, which is thought to improve security. Therefore, by enabling the Password ID whenever Multi-Link communication includes 6 GHz, the communication device 102 can build a more secure network. Conversely, a STA may be controlled to not connect to an AP that has disabled the SAE Password Identifiers In Use but is building a network including 6 GHz in Multi-Link communication, as it is considered untrustworthy. Similarly, an AP may be controlled to not connect to a STA that does not support the Password ID and requests a connection, as it is considered untrustworthy.

[0055] Figure 6 shows the RSNXE (RSN Extension element) defined in IEEE 802.11. RSNXE is stored in a management frame that complies with IEEE 802.11.

[0056] The fields shown here are, from the beginning, an Element ID field 601, a Length field 602, and an Extended RSN Capabilities field 603.

[0057] The SAE hash-to-element subfield 606 indicates that the SAE authentication method specified in WPA3 is supported, which is the H2E (Hash to Element) method. The SAE-PK subfield 607 indicates that the SAE authentication method is supported, which is the SAE-PK (SAE Public Key) method.

[0058] SAE hash-to-element is one of the SAE authentication methods, which allows for pre-calculation of parameters to be exchanged offline. This prevents side-channel attacks that guess calculated values ​​based on calculation time, thereby improving security.

[0059] Therefore, for example, when building a network including 6 GHz in Multi-Link communication, the SAE hash-to-element subfield 606 or the SAE-PK subfield 607 may be enabled. Therefore, by always enabling SAE hash-to-element when 6 GHz is included in Multi-Link communication, the communication device 102 can build a more secure network. Conversely, the communication device 102 can determine that an AP that has built a network including 6 GHz in Multi-Link communication while SAE hash-to-element is disabled is untrustworthy and not to connect to it. Conversely, when a STA that does not support SAE hash-to-element connects, the AP can determine that the STA is untrustworthy and not to connect to it.

[0060] SAE-PK is one of the SAE authentication methods, and is a method that can verify whether a STA is attempting to connect to a legitimate AP. If the AP that the STA is attempting to connect to is a fake AP, the STA can determine this by verifying the value. This contributes to improving security in public wireless LANs. Therefore, by always enabling SAE-PK when Multi-Link includes 6 GHz, the communication device 102 can build a more secure network. Conversely, the communication device 102 can control APs that are building a network using Multi-Link communication even when SAE-PK is disabled, so that they are considered untrusted and cannot be connected to. Furthermore, when a connection request is made by a STA that does not support SAE-PK, the AP can be controlled to not connect to the STA as it is considered untrusted.

[0061] Furthermore, the above-mentioned Password ID, SAE hash-to-element, and SAE-PK may be used as connection determination conditions for the AP and STA, with a connection being made only if one of them is supported, and no connection being made if none of them is supported.

[0062] (Processing flow) (Embodiment 1) 7 shows a process of controlling authentication and encryption to be performed by WPA3 when 6 GHz is selected as the frequency band for performing Multi-Link communication, by the control unit 202 executing a program stored in the storage unit 201 of the communication device 101. The communication device 101 is assumed to have at least a wireless LAN control unit capable of communicating by Multi-Link.

[0063] The flowchart in FIG. 7 starts when the communication device 101 establishes a network or when a user instructs to change the network settings.

[0064] First, the communication device 101 displays a wireless setting screen to the user (S701). The screens displayed at this time will be described later with reference to FIGS. 8 to 19. Next, it is determined whether 6 GHz is selected as the frequency band for communication in the setting items on the screen (S702). In FIG. 8, "Basic (6 GHz)" is selected, so it can be determined in S702 that 6 GHz is selected. The determination method in S702 from FIG. 9 onwards will be described later. If it is determined in S702 that the 6 GHz setting screen is selected, only WPA3 and OWE are made selectable as security methods in GUI settings (S710). That is, a Beacon, Probe Response, or Association Response is transmitted with only WPA3-SAE or with WPA-EAP included in the AKM Suite List field 408 included in the RSNE.

[0065] An example of the GUI is shown in Figure 8. Figure 8 shows the screen for setting up a 6 GHz network. Because WPA3 authentication is required for communication in the 6 GHz band, WPA3 is displayed as the security method in Figure 8. Furthermore, it is specified that WPA / WPA2 and OPEN authentication are not permitted in the 6 GHz band. Therefore, only OPEN (AES), WPA3-SAE, and WPA3-EAP are displayed as selectable wireless authentication and encryption methods. This display method is not limited to this. Alternatively, for example, OWE, OPEN (encrypted), OPEN (OWE), OWE (passwordless communication encryption), or OWE (OPEN) may be used instead of OPEN (AES). OWE (Opportunistic Wireless Encryption) is a security method that enables communication encryption even in environments without passwords. This provides improved security compared to the conventional OPEN method, which does not encrypt communication content.

[0066] WPA3-SAE may also be expressed in a different way. For example, it may be expressed as WPA3-Personal, WPA3, SAE, or WPA3(AES). WPA3-EAP may also be expressed in a different way. For example, it may be expressed as WPA3-Enterprise, WPA3, or WPA3-Enterprise(192bit). Separate options may be provided for WPA3-Enterprise and WPA3-Enterprise(192bit).

[0067] As the authentication method options shown in FIG. 8, some of the authentication methods shown in FIG. 8 may be displayed. For example, only WPA3-SAE may be provided as an option. In this case, the 6 GHz setting screen may perform encryption based on a predetermined encryption method without providing an option corresponding to WPA3 on the display as shown in FIG. 8. The authentication method options shown in FIG. 8 may be further increased. For example, WPA3-SAE (H2E), WPA3-SAE-PK, WPA3-SAE (Password ID), WPA4, etc. may be included as options. However, options representing WEP, WPA-TKIP, WPA-AES, WPA2-TKIP, WPA2-AES, and equivalent methods are not provided as options or are displayed as unselectable.

[0068] If it is determined in S702 that the screen is not a 6 GHz setting screen, it is determined whether or not the screen is a setting screen for Multi-Link communication (S703). Explaining this with reference to FIG. 8, the determination in S703 is, for example, whether or not the "Basic (Multi)" tab at the top is selected. Here, if it is determined in S703 that the screen is not a setting screen for Multi-Link communication, the wireless authentication and encryption methods displayed on the GUI are displayed in a selectable state, including methods prior to WPA2, in addition to WPA3 and OWE (S713). Also, beacons, probe responses, and association responses are sent that include WPA2-AES to the AKM Suite List field 408 included in the RSNE in FIG. 4.

[0069] FIG. 9 shows an example of the GUI when it is determined in S703 that the setting screen is not for Multi-Link communication. In FIG. 9, "Basic (2.4 GHz)" has been selected as the setting screen for the network to be created, indicating that this is the screen for configuring a 2.4 GHz network. In this case, if the setting screen is for configuring a 2.4 GHz network, or a screen for creating a single network, it is determined in S703 that this is not the setting screen for Multi-Link communication. If it is determined in S703 that the setting screen is not for Multi-Link communication, as shown in FIG. 9, the screen displays wireless authentication and encryption methods that can be selected, including OPEN (AES), WPA3-SAE, and WPA3-EAP, as well as methods prior to OPEN and WPA2. In other words, if it is determined in S703 that the setting screen is not for Multi-Link communication, it displays authentication methods prior to WPA2 that can also be selected in S713.

[0070] The options for the authentication method displayed in Fig. 9 may be changed depending on the functions of the AP. For example, if the AP does not support EAP, WPA2-EAP(AES), WPA3-EAP(AES), and WPA2 / WPA3-EAP(AES) may be excluded from the options shown in Fig. 9.

[0071] For example, if the AP does not support Personal, only OPEN and EAP may be displayed. Alternatively, options other than OPEN may be displayed. The notations (TKIP / AES) and (AES) may not be displayed. Also, WPA2-PSK / WPA3-SAE may be displayed differently. For example, they may be WPA2 / WPA3 or WPA2 / PA3-Personal. Similarly, WPA3-SAE may be displayed as WPA3, WPA3-Personal, or WPA3-SAE(Personal).

[0072] OPEN (AES) may be different. For example, OPEN (OWE), OWE, and WPA / WPA2-PSK may be displayed as MIX. Also, WPA / WPA2 / WPA3 may be displayed. This may be displayed as WPA-MIX.

[0073] Alternatively, as shown in FIG. 10, when "Basic (Multi)" is selected, it may be determined that the setting screen is for Multi-Link communication. That is, when "Basic (Multi)" is selected, which means that Multi-Link communication is to be performed, as shown in FIG. 10, it is determined in S703 that the setting screen is for Multi-Link communication. At this time, it is determined in S704 whether or not there is a possibility that a frequency channel operating in the 6 GHz band is included in at least one of the links. The determination in S704 is made, for example, when the 6 GHz frequency band is specified as the frequency band of the channel set for each link, as shown in FIG. 10, or when a specific channel in the 6 GHz frequency band is specified. For example, in FIG. 10, "2.4 GHz Auto" is selected for Link 1 and "5 GHz Auto" is selected for Link 2. In this case, it can be seen that Multi-Link does not operate in 6 GHz. That is, it can be seen from FIG. 10 that Multi-Link communication in the 2.4 GHz band and the 5 GHz band is selected, but Multi-Link communication in the 6 GHz band is not to be performed. In this case, it is determined in S704 that there is no possibility that a frequency channel operating in 6 GHz is included. On the other hand, in the case of Figure 11, "2.4GHz Auto" is selected for Link1 and "6GHz Auto" is selected for Link2. In this case, in S704, it is determined that 6GHz is included as a channel for Multi-Link operation. Also, even if the channel is set to "Auto" and operation is possible in any band, as in Figure 12, it may be determined that operation in 6GHz is possible.

[0074] If it is determined that there is no possibility of operation at 6 GHz (No in S704), the screen will display options including methods prior to WPA2 (S713). In this case, the screen will look something like Figure 10. The authentication and encryption method options are the same as those explained in Figure 9 above, so they will be omitted here. Figure 10 shows the settings screen for Multi-Link communication, but because communication using the 6 GHz frequency band has not been selected, WPA3 is displayed as an authentication method option in addition to the authentication methods prior to WPA2.

[0075] If it is determined that there is a possibility that 6 GHz is included, it is checked whether or not there is an already connected STA (S705). Note that the determination in S705 may be performed immediately before S701, or it may not be performed at all. If there is no STA to establish a connection (No in S705), control is performed so that only OPEN (AES) and WPA3 are displayed (S710). The authentication and encryption method options are the same as those explained in Figure 8 above, so they are omitted here.

[0076] If there is a STA establishing a connection at the time of the setting update (Yes in S705), it is determined whether the STA establishing a connection has established a connection using an authentication and encryption method earlier than WPA2 (S706). If it is determined in S706 that the connection has been established using WPA3 or later, a display is displayed so that only WPA3 can be selected (S710). If it is determined in S706 that the connection has been established using a method earlier than WPA2, selecting 6 GHz after the setting change will build a network using only WPA3, which may prevent STAs that have already established a connection using a method earlier than WPA2 from reconnecting. Therefore, a warning such as that shown in FIG. 13 is displayed (S707). Here, if "OK" is pressed in the warning to acknowledge the warning (Yes in S708), the STA that has established a connection is disconnected, and a display is displayed so that only WPA3 can be selected (S710). Note that disconnection from the STA that has established a connection may be performed when the "Settings" button (described later) is pressed (S711). In the warning shown in Figure 13, if "OK" is not pressed but "Cancel" is pressed or the screen is simply closed (No in S708), the settings are changed to create a network that does not include 6 GHz (S709). For example, in S709, the 6 GHz selected in Figure 11 may be changed to 5 GHz as shown in Figure 10. Note that in S707 to S709, it is also possible to select to create a network separate from an existing network, i.e., a network that has already established a connection with a STA. In this case, the authentication and encryption method options are always displayed so that WPA3 is selected. Existing networks are managed on a separate screen.

[0077] Examples of this case are shown in Figures 14 and 15. At step S703, the setting screen shown in Figure 14 is displayed. If the user selects to operate at 6 GHz (Yes in S704), it is determined whether a STA has established a connection in an existing network (S705). If a STA already has an established connection, a warning is displayed (S707), and the process transitions to Figure 15. Here, the warning message displayed in S707 may be a confirmation such as "Are you sure you want to create a new network?" In other words, in S707, the user is asked to confirm that they will create a network different from the existing network. If the user accepts the warning and presses "OK," a new "Network 2" is created with the settings of "Network 1" shown in Figure 14 left as is, and the 6 GHz band is also added, and the setting screen shown in Figure 15 is displayed. In Figure 14, 6 GHz was not checked in Network 1, but in Figure 15, the network is changed to "Network 2" and the 6 GHz band is checked. That is, if the user agrees to build a network different from the existing network, a 6 GHz network corresponding to Network 2 is built in addition to the existing networks (2.4 GHz / 5 GHz). Also, since operation is performed at 6 GHz in FIG. 15, the displayed authentication and encryption methods are limited to OPEN (AES) and WPA3-SAE. That is, a Beacon, Probe Response, or Association Response is transmitted with only WPA3-SAE or WPA-EAP included in the AKM Suite List field 408 included in the RSNE. Alternatively, when the present invention is applied to the communication device 102, it is added to the RSNE of the Probe Request or Association Request.

[0078] Once the communication device 101 has constructed a WPA3-SAE network, it waits for a connection request from a remote device. Alternatively, if the present invention is applied to the communication device 102, it searches for a remote device and issues a connection request to a remote device that meets the conditions. Here, a connection request refers to a probe request or an association request.

[0079] When the communication device 101 receives a connection request from a remote device (S712), it determines whether the remote device is requesting a Multi-Link connection and a WPA3 connection (S716). Specifically, it checks whether information indicating WPA3 compatibility is stored in the AKM Suite List field 408 of the Probe Request or Association Request received in S712. If it is determined in S716 that the remote device is not requesting a WPA3 connection despite being Multi-Link, the connection is rejected (S717). Here, a different network may be recommended in S717. Alternatively, if a Multi-Link communication connection is requested but the connection only includes 2.4 GHz and 5 GHz, the communication device 101 may proceed with authentication for the WPA2 connection request. However, in this case, the request will always be rejected even if a request to increase the bandwidth to 6 GHz is made later.

[0080] As described above, if Password ID, SAE hash-to-element, and SAE-PK are required for connections including 6 GHz in Multi-Link communication, these may be used as conditions for connection approval in addition to WPA3 determination. When the present invention is applied to the communication device 102, when searching for APs, a connection request will be sent only to APs that build networks that satisfy the above.

[0081] If the connection request from the STA satisfies the conditions, the communication device 101 proceeds with authenticating the STA (S718). If the authentication is successful in S718 (Yes in S719), the communication device connects to the other device and starts communication (S720). If the authentication is not successful (No in S719), the connection is rejected (S717). One possible method for rejecting the connection in S717 is to set the Status Code in the Association Response to Failure.

[0082] After S713, the setting button is pressed to create a network using the authentication and encryption method that has been set (S714). Here, it is assumed that WPA2-PSK / WPA3-SAE has been selected.

[0083] In S713, the AKM Suite List field 408 of the RSNE shown in Fig. 4 includes the value 00-0F-AC-08 indicating support for SAE, as well as values ​​00-0F-AC-02 and 00-0F-AC-06 indicating support for PSK. 00-0F-AC-02 indicates that SHA-128 is used as the hash function for PSK, and 00-0F-AC-06 indicates that SHA-256 is used as the hash function. Only one of these may be included.

[0084] After the network is established, the system waits for the other device to request a connection (S715). If the other device requests a connection, authentication proceeds (S718), and if authentication is successful (Yes in S719), the system connects and starts communication (S720). If authentication is not successful (No in S719), the system rejects the connection (S717).

[0085] According to this embodiment, when 6 GHz is included in Multi-Link communication, by controlling the display to authenticate with WPA3 on both links, it is possible to maintain communication limited to WPA3 in 6 GHz communication. Furthermore, when the 6 GHz band is not included, communication can also be performed with WPA2, so that existing devices that do not support WPA3 can join the network and communicate. Note that there are other ways to display the information using a GUI besides those shown above. Below is an example of a setting screen for an AP that can build multiple networks.

[0086] Figure 16 shows an example of the GUI for an AP that can create multiple networks. The type of network is displayed on the left side of the screen. For example, in the Wireless LAN Advanced Settings (2.4 GHz), options are displayed that allow you to create a network using Single Link, including security methods older than WPA2 and Open. On the other hand, if you select Wireless LAN Advanced Settings (2.4+6) as shown in Figure 16, it indicates that you want to create a network using Multi-Link at 2.4+6 GHz. In this case, since Multi-Link communication using the 6 GHz frequency band has been selected, only OWE and WPA3 are displayed as selectable options, and security methods older than WPA2 and Open are not displayed.

[0087] 17 and 18 show examples of the AP GUI when determining the frequency band when selecting the operation mode. In Fig. 16, the frequency band is determined in the wireless channel, but in Figs. 17 and 18, the frequency band is determined in the operation mode, which is different.

[0088] 17, when 2.4 GHz + 5 GHz is selected as the wireless operation mode, it can be determined in S704 that operation at 6 GHz will not be performed. In other words, although Multi-Link communication has been selected, since it is indicated that Multi-Link communication will be performed without using 6 GHz, options including WPA2 and Open are displayed as the security method.

[0089] When 5 GHz + 6 GHz is selected as the wireless operation mode as shown in Figure 18, it is determined in S704 that operation will be performed at 6 GHz. In other words, since it indicates that Multi-Link communication will be performed using 6 GHz, only OWE and WPA3 are displayed as selectable options on the display, and security methods prior to WPA2 and Open are not displayed. Note that the frequency channels selected for Multi-Link may be, for example, two from 6 GHz. Alternatively, one from 2.4 GHz and two from 5 GHz may be selected.

[0090] 19 and 20 show an example of the AP UI, which displays a screen for setting the frequency band for operating in Multi-Link communication and a screen for setting security on separate screens.

[0091] In Figure 19, 6GHz is checked on the Multi-Link settings screen, so in S704 it is determined that Multi-Link will operate at 6GHz. Figure 20 shows an example of the transition to the screen for setting the security method in this case. Because it has been determined that Multi-Link will operate at 6GHz, the Security settings screen displays only OWE and WPA3 as selectable options, and does not display security methods prior to WPA2 or Open. Note that if 6GHz is not checked in Figure 19 and it has been determined that Multi-Link will not operate at 6GHz, security method options displayed include WPA2 and Open in addition to WPA3.

[0092] FIG. 21 shows an example of a UI that pops out when selecting a security method. The method for selecting a frequency band is the same as in FIGS. 9 to 19. As shown in FIG. 21, when selecting a security method, a pop-out may be displayed to show options. When Multi-Link communication including 6 GHz is selected, only OWE and WPA3 are displayed as options. On the other hand, when Multi-Link communication is selected without including 6 GHz, options including WPA2 and Open in addition to WPA3 are displayed as security methods.

[0093] An example of a UI for controlling the selection of specific security methods by graying them out is shown in Figure 22. For example, if Multi-Link communication including 6 GHz is selected, only WPA3 can be selected, and security methods prior to WPA2 are grayed out to make them unselectable.

[0094] Fig. 23 shows an example of a UI for determining the wireless channel to be used when selecting a wireless function. For example, in Fig. 23, if 2.4GHz+5GHz is selected, it is determined in S704 that the device will not operate in the 6GHz band, and options for the security method are displayed that include WPA2 and Open in addition to WPA3. On the other hand, if 2.4GHz+6GHz is selected, it is determined in S704 that Multi-Link communication will be performed, including 6GHz, and only OWE and WPA3 are displayed as options.

[0095] In this way, security can be improved by limiting the security methods that can be selected by the user on the UI when building a network. Also, communication authenticated and encrypted using methods prior to WPA2 will no longer be performed at 6GHz, where authentication and encryption methods prior to WPA2 are prohibited.

[0096] Note that even if Multi-Link is selected in the UI, the options provided for the security method may not change, and the communication device may automatically switch the security method when actually creating a network. For example, when creating multiple networks simultaneously, assume that WPA2 / 3 is selected in the UI. Networks that do not use 6GHz with Multi-Link may operate with WPA2 / 3, while networks that use 6GHz with Multi-Link may operate with only WPA3. In this case, the WPA2-only option may be removed once 6GHz is selected with Multi-Link, or the WPA2-only option may not be selectable for any network. In this case, a connection with a high security method is guaranteed when using Multi-Link.

[0097] (Embodiment 2) In this embodiment, a case will be described in which control is performed so that authentication and encryption are performed using WPA3 when 6 GHz is selected in Multi-AP communication.

[0098] FIG. 24 shows the flow of processing when 6 GHz is selected in Multi-AP communication by the control unit 202 executing a program stored in the storage unit 201 of the communication device 101.

[0099] Multi-AP communication is a technology that enables improved communication performance by having multiple APs cooperate to communicate data with STAs, improving communication rates and reducing radio interference using beamforming. APs participating in Multi-AP communication are classified into a Sharing AP, which manages other APs, and a Shared AP, which operates under the management of a Sharing AP.

[0100] It should be noted that the contents already explained in the above embodiment will not be explained in this embodiment.

[0101] FIG. 24 is a flowchart showing the process for selecting a security method depending on the communication format when the communication device 101 connects to the communication device 102 in this embodiment.

[0102] The communication device 101 is assumed to have at least a wireless LAN control unit capable of multi-AP communication.

[0103] The flowchart in FIG. 24 starts when the communication device 101 establishes a network or when a user instructs to change the network settings.

[0104] Much of the processing overlaps with that of the first embodiment, so a description thereof will be omitted.

[0105] After displaying wireless, the communication device 101 determines whether Multi-AP communication has been selected (S2403). If it is determined in S2403 that Multi-AP communication has been selected, the process proceeds to S704. If it is not determined in S2403 that Multi-AP communication has been selected, the process proceeds to S713 in FIG. 7.

[0106] When constructing a network using multi-AP communication, it is determined whether or not an AP that uses 6 GHz to communicate with a STA or between APs is included (S705). If an AP that uses 6 GHz to communicate with a STA or between APs is included, the process proceeds to S706. If it is determined in S705 that an AP is not included, the process proceeds to S713, where WPA2 is displayed as an option in addition to WPA3.

[0107] It is determined whether a STA requesting connection to a network established with Multi-AP, including 6 GHz, is sending a WPA3 connection request (S716), and if it is determined in S716 that it is a WPA3 connection request, authentication proceeds (S718). If it is determined in S716 that it is not a WPA3 connection request, the connection is rejected (S717). Note that SAE-PK or SAE hash-to-element may be used instead of WPA3. Alternatively, the determination may be made based on a connection request using a password ID.

[0108] In addition, the communication partner to which the connection request is made in S716 may be an AP. When building a network using multi-AP communication, the display may be controlled so that WPA3 is selected. The UI display method for controlling the display to only WPA3 is the same as in the first embodiment, and therefore a description thereof will be omitted.

[0109] In this way, when building a 6GHz-compatible network for Multi-AP communication, by controlling the selection of WPA3 as the security method, it is possible to improve security by preventing communication using methods earlier than WPA2. It also prevents the use of methods earlier than WPA2 in 6GHz band communication.

[0110] (Other embodiments) In each embodiment, when "Auto" is selected as the setting channel, it is determined that 6 GHz may be included, and control is exercised to display only WPA3 and OPEN (AES), but this is not limiting. For example, when WPA3-SAE is selected as the authentication / encryption method, a Multi-Link link is configured including 6 GHz. When WPA2-PSK / WPA3-SAE is selected, a Multi-Link link is constructed only at 2.4 GHz and 5 GHz. Control such as the above may be exercised. This allows the user to configure a network without being aware of restrictions on security strength depending on the band.

[0111] Although each embodiment shows a GUI with two links, it may have three or more links. For example, a wireless channel (Link 1), a wireless channel (Link 2), and a wireless channel (Link 3) may be displayed on the GUI screen.

[0112] Furthermore, in each embodiment, when the setting screen shows WPA2 and communication is selected using 6 GHz, processing may be performed to automatically switch to WPA3 even if the frequency is 2.4 GHz or 5 GHz. This allows control so that WPA3 is selected even if the existing network is operating using an authentication and encryption method prior to WPA2. In this case, the passphrase used for WPA2 may be reused. The user may also be notified that the setting has been changed to WPA3. Furthermore, if an STA that does not support WPA3 is connected when attempting to automatically switch, the user may be notified that the setting cannot be changed.

[0113] In each embodiment, the communication method and security method are set on a screen, but this is not limiting. For example, they may be set by voice input. Or they may be set by command input using a character string. In the case of command input, for example, if an attempt is made to set only WPA2 even though Multi-Link is used, an error may be displayed to indicate that the setting is not possible.

[0114] In each embodiment, an error message is displayed when the user selects an option that cannot be selected, but a beep may also be output in response.

[0115] In this embodiment, WPA3 has been used as an example, but the present invention is also applicable to future standards such as WPA4 that will succeed WPA3.

[0116] The communication devices 101 and 102 described in this embodiment may be printers having printing means. When operating as a printer, for example, it is possible to print data acquired by communicating with a partner device.

[0117] Furthermore, the communication devices 101 and 102 described in this embodiment may be cameras having imaging means. When operating as a camera, it is possible to transmit captured image data by communicating with a partner device, for example.

[0118] It is also possible to provide a system or device with a recording medium storing software program code for implementing the above-described functions, and have the computer (CPU, MPU) of the system or device read and execute the program code stored in the recording medium. In this case, the program code itself read from the recording medium will implement the functions of the above-described embodiments, and the recording medium storing the program code will constitute the above-described device.

[0119] Examples of storage media that can be used to supply the program code include flexible disks, hard disks, optical disks, magneto-optical disks, CD-ROMs, CD-Rs, magnetic tapes, non-volatile memory cards, ROMs, and DVDs.

[0120] In addition, the above-mentioned functions may be realized not only by the computer executing the read program code, but also by the operating system (OS) running on the computer performing some or all of the actual processing based on the instructions of the program code. OS is an abbreviation for Operating System.

[0121] Furthermore, the program code read from the storage medium may be written to a memory provided on a function expansion board inserted into a computer or a function expansion unit connected to the computer, and a CPU provided on the function expansion board or function expansion unit may then perform some or all of the actual processing based on the instructions of the program code to realize the above-mentioned functions.

[0122] The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program. It can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.

[0123] The disclosure of this embodiment includes the following configuration.

[0124] (Configuration 1) A communication device capable of performing authentication using a WPA (Wi-Fi Protected Access) 2 method and authentication using a WPA3 method, the communication device comprising: an establishment means for establishing a link between the communication device and another communication device via a frequency channel; and a control means for controlling authentication of communication with the other communication device, wherein when communicating with the other communication device in a state in which multiple links have been established between the communication device and the other communication device by the establishment means, the control means performs authentication using the WPA3 method based on the fact that the frequency channel used in at least one of the multiple links is a frequency channel included in a specific frequency band.

[0125] (Configuration 2) The communication device according to configuration 1 further includes a receiving means for receiving an instruction to communicate with the other communication device in a state where multiple links are established between the communication device and the other communication device, and based on the instruction from the receiving means to perform the communication using a frequency channel included in the specific frequency band, the communication device controls a display unit to perform authentication using the WPA3 method.

[0126] (Configuration 3) The communication device according to configuration 1 or 2, characterized in that the communication performed with the other communication device in a state in which the plurality of links are established between the communication device and the other communication device by the establishing means is multi-link communication conforming to the IEEE802.11 standard series.

[0127] (Configuration 4) A communication device that can perform authentication using the WPA (Wi-Fi Protected Access) 2 method and authentication using the WPA3 method and operates as a communication access point, the communication device having a communication means for communicating with other communication devices and a control means for controlling authentication of communication with the other communication devices, wherein the control means controls authentication to be performed using the WPA3 method based on the fact that a frequency channel used in communication in which cooperation is performed between the communication device and the other communication devices is a frequency channel included in a specific frequency band.

[0128] (Configuration 5) The communication device according to configuration 4, further comprising a receiving means for receiving an instruction to perform communication in which the communication device and the other communication device cooperate with each other, and based on the instruction from the receiving means to perform the communication using a frequency channel included in the specific frequency band, controls a display unit to perform authentication using the WPA3 method.

[0129] (Configuration 6) The communication device according to any one of configurations 1 to 5, characterized in that when the communication device does not receive a frame from the other communication device that stores information indicating that authentication will be performed using the WPA3 method, the communication device controls so as not to establish a connection with the other communication device.

[0130] (Configuration 7) A communication device capable of performing authentication using a first security method and authentication using a second security method, the communication device comprising: an establishment means for establishing a link between the communication device and another communication device via a frequency channel; and a control means for controlling authentication of communication with the other communication device, wherein when communicating with the other communication device with a plurality of links established by the establishment means, the communication device controls to perform authentication using the first security method based on the frequency channel used in at least one of the plurality of links being a frequency channel in a specific frequency band, and to perform authentication using the first security method or the second security method based on the frequency channels used in the plurality of links not being frequency channels included in the specific frequency band.

[0131] (Configuration 8) The communication device according to configuration 7, further comprising a receiving means for receiving an instruction to communicate with the other communication device in a state where multiple links are established between the communication device and the other communication device, and based on the instruction from the receiving means to perform the communication using a frequency channel included in the specific frequency band, the communication device controls a display unit to perform authentication using the first security method.

[0132] (Configuration 9) The communication device according to configuration 7 or 8, wherein the communication performed with the other communication device in a state where the plurality of links are established between the communication device and the other communication device by the establishing means is multi-link communication conforming to the IEEE802.11 standard series.

[0133] (Configuration 10) A communication device capable of performing authentication using a first security method and authentication using a second security method, and operating as a communication access point, comprising: communication means for communicating with other communication devices; and control means for controlling authentication of communication with the other communication devices, wherein the control means controls to perform authentication using the first security method based on the fact that a frequency channel used in communication in which cooperative operation is performed between the communication device and the other communication device is a frequency channel included in a specific frequency band, and to perform authentication using the first security method or the second security method based on the fact that the frequency channel used in communication in which cooperative operation is performed is not a frequency channel included in the specific frequency band.

[0134] (Configuration 11) The communication device described in configuration 10 is characterized in that it further has a receiving means for receiving an instruction to perform communication in which the communication device and the other communication device operate cooperatively, and controls a display unit to perform authentication using the first security method based on an instruction from the receiving means to perform the communication using a frequency channel included in the specific frequency band.

[0135] (Configuration 12) 12. The communication device according to any one of configurations 7 to 11, characterized in that, when the communication device does not receive a frame from the other communication device that stores information indicating that authentication will be performed using the first security method, the communication device controls not to establish a connection with the other communication device.

[0136] (Configuration 13) 13. The communication device according to any one of configurations 1 to 12, wherein the specific frequency is in the 6 GHz band.

[0137] (Configuration 14) 14. The communication device according to any one of configurations 7 to 13, wherein the first security method is Wi-Fi Protected Access (WPA3).

[0138] (Configuration 15) 15. The communication device according to any one of configurations 7 to 14, wherein the second security method is WPA or WPA2.

[0139] (Configuration 16) A program for causing a computer to function as each means of the communication device described in any one of configurations 1 to 15. [Explanation of symbols]

[0140] 100 Network 101 Communication equipment (AP) 102 Communication equipment (STA) 103 Links 104 Links

Claims

1. A communication device capable of performing authentication using at least WPA (Wi-Fi Protected Access) 2 and authentication using WPA3, An establishment means for establishing a link with another communication device; A control means for controlling an authentication method used in an authentication process performed with the other communication device; having When the establishing means establishes a plurality of links with the other communication device, and when the establishing means establishes a link with the other communication device using a channel included in a predetermined frequency band, the control means controls so that the WPA3 is used in the authentication process performed with the other communication device, and does not use the WPA2. A communication device comprising:

2. When the communication device is capable of performing authentication using an Open method using OWE, When the establishing means establishes a plurality of links with the other communication device, and when the establishing means establishes a link with the other communication device using a channel included in a predetermined frequency band, the control means controls so that the WPA3 or the Open method using the OWE is used in the authentication process performed with the other communication device, and does not use the WPA2.

2. The communication device according to claim 1 .

3. The present invention further includes a communication means for performing communication using a first link and a second link of the multiple links in parallel when multiple links are established between the communication device and the other communication device by the establishment means.

2. The communication device according to claim 1 .

4. When the establishing means establishes a plurality of links with the other communication device, and when the establishing means establishes a link with the other communication device using a channel included in a predetermined frequency band, the establishing means transmits an association frame when establishing a link with the other communication device, and the association frame includes information indicating that SAE (Simultaneous Authentication of Equals) is used in an RSNE (Robust Security Network element).

2. The communication device according to claim 1 .

5. When the other communication device does not support authentication using the WPA3 and authentication using the Open method using the OWE, the establishing means does not establish the multiple links and a link using a channel included in the specified frequency band with the other communication device.

3. The communication device according to claim 2.

6. When the establishing means establishes a plurality of links including a link using a channel included in the predetermined frequency band with the other communication device, the control means controls so that the WPA3 is used in an authentication process performed with the other communication device.

2. The communication device according to claim 1 .

7. The predetermined frequency band is the 6 GHz band.

6. The communication device according to claim 1, wherein the first and second inputs are connected to the first and second inputs.

8. A communication device capable of operating as an access point capable of performing at least authentication using WPA2 and authentication using WPA3, a display control means for executing control for displaying on a display means a setting screen for receiving a selection related to wireless communication settings of the communication device from a user; a constructing means for constructing a network having a plurality of links, the plurality of links including a first link in a first frequency band and a second link in a second frequency band; When the first frequency band is the 6 GHz band, the user can select only the WPA3 or Open using OWE as the authentication method for the second link on the setting screen. A communication device comprising:

9. When the first frequency band is the 6 GHz band, the user cannot select the WPA2 as an authentication method for the second link on the setting screen.

9. The communication device according to claim 8.

10. When the first frequency band and the second frequency band are not in the 6 GHz band, the user can select the WPA2 as an authentication method for the second link on the setting screen.

10. The communication device according to claim 9 .

11. When the first frequency band is the 6 GHz band, the WPA2 is grayed out in a selection item of an authentication method for the second link on the setting screen, thereby preventing the user from selecting it.

9. The communication device according to claim 8.

12. The display means is separate from the communication device.

9. The communication device according to claim 8.

13. The present invention further comprises a determination means for determining an authentication method to be used for authentication with another communication device based on setting information based on the selection by the user received by the display means.

9. The communication device according to claim 8.

14. A method for controlling a communication device capable of performing authentication using at least WPA (Wi-Fi Protected Access) 2 and authentication using WPA3, comprising: an establishment step of establishing a link with another communication device; a control step of controlling an authentication method used in an authentication process performed with the other communication device; having When a plurality of links are established with the other communication device in the establishing step, and when a link using a channel included in a predetermined frequency band is established with the other communication device in the establishing step, the control step performs control so that the WPA3 is used in the authentication process performed with the other communication device, and the WPA2 is not used. A method for controlling a communication device comprising:

15. A method for controlling a communication device capable of operating as an access point capable of performing at least authentication using WPA2 and authentication using WPA3, comprising: a display control step of executing control for displaying on a display unit a setting screen for receiving a selection from a user regarding a wireless communication setting of the communication device; constructing a network having a plurality of links, the plurality of links including a first link in a first frequency band and a second link in a second frequency band; When the first frequency band is the 6 GHz band, the user can select only the WPA3 or Open using OWE as the authentication method for the second link on the setting screen. A method for controlling a communication device comprising: