Control Method of Communication Device and Information Processing Device and Control Method of System
Patent Information
- Application Number
- JP2022068467
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-04-18
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2042-04-18
AI Technical Summary
Communication devices using the IEEE802.1X/EAP authentication method for wireless LAN connections face challenges in convenience and efficiency during connection processing.
A communication device that can switch between a first and second communication mode, disconnecting from the first mode upon receiving connection information, performing authentication in the second mode, storing the result, and then transitioning back to the first mode to transmit the authentication result.
Improves the convenience and efficiency of connection processing by optimizing the authentication process for IEEE802.1X/EAP authentication methods.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical field
[0001] The present invention relates to a communication device, its control method, and program. [Background technology]
[0002] Among communication devices that execute processing for connecting to an access point, there is one that selects and connects to an access point based on an SSID (Service Set Identifier) list (Patent Document 1). The SSID list is obtained by searching for connectable access points.
[0003] In a communication system using a wireless LAN that complies with a predetermined standard, the network can be protected by authenticating communication devices that connect to the network. A typical example of this standard is the IEEE (Institute of Electrical and Electronics Engineers) 802.11 standard. Examples of authentication methods include a PSK method using a pre-shared key (PSK), an SAE method using SAE (Simultaneous Authentication of Equals), and the like. Another example is an EAP method that authenticates a communication device connected to a network using an authentication server compatible with IEEE802.1X / EAP (Extensible Authentication Protocol). [Prior art documents] [Patent document]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 2004-274232 [Summary of the invention] [Problem to be solved by the invention]
[0005] As devices that perform connection processing to a wireless LAN using the IEEE802.1X / EAP authentication method become widespread, communication devices that perform connection processing to a wireless LAN using the IEEE802.1X / EAP authentication method There is a need to improve the convenience of devices that transmit information for processing.
[0006] The present invention aims to improve the convenience of a device that transmits information for connection processing to a communication device that performs connection processing to a wireless LAN using the IEEE802.1X / EAP authentication method. . [Means to solve the problem]
[0007] In order to solve this problem, for example, a communication device of the present invention has the following configuration. That is, A communication device that communicates with an external information processing device, A communication means capable of selecting either a first communication mode or a second communication mode and communicating in the selected communication mode; control means for controlling the communication means and performing predetermined authentication; When the control means receives information for connection with the access point corresponding to the predetermined authentication from the information processing device in the first communication mode via the communication means, disconnecting communication in the first communication mode; performing authentication in a second communication mode using the authentication information and storing the result of the authentication; disconnecting the second communication mode and transitioning to communication in the first communication mode; The method is characterized in that the stored authentication result is transmitted to the information processing device.
Effect of the invention
[0008] According to the present invention, it is possible to improve the convenience of a device that transmits information for connection processing to a communication device that performs connection processing to a wireless LAN using the IEEE802.1X / EAP authentication method. . [Brief explanation of drawings]
[0009]
Figure 1
Figure 2
[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the claimed invention. Although a plurality of features are described in the embodiments, not all of these features are essential to the invention, and the plurality of features may be arbitrarily combined. Furthermore, in the accompanying drawings, the same or similar components are designated by the same reference numerals, and redundant description will be omitted.
[0011] [System configuration] FIG. 1 shows a configuration example of a communication system according to this embodiment. As an example, the present system is configured such that a plurality of communication devices can communicate with each other wirelessly. Here, the description will be made assuming that an information processing device 200, an MFP (multifunction printer) 300, an access point 700, and an authentication server 800 exist as a plurality of communication devices.
[0012] Note that the information processing device 200 and the MFP 300 may also be simply expressed as a communication device unless there is a particular need to distinguish them. For example, MFP 300 may be expressed as communication device 300.
[0013] The information processing device 200 is an information processing device that has a communication function using a wireless LAN, a wired LAN, or the like. Wireless LAN can be expressed as WLAN (Wireless LAN). Examples of the information processing device 200 include a smartphone, a notebook PC (notebook personal computer (multifunctional peripheral device)), a tablet terminal, a PDA (Personal Digital Assistant), and the like.
[0014] The MFP 300 is a printing device that has a print function as its main function, and can also have sub-functions such as a document reading function (scan function), a FAX (facsimile) function, and a telephone function. Additionally, the MFP 300 has a communication function that allows wireless communication with the information processing device 200. Furthermore, in this embodiment, a case will be described in which the MFP 300 is used as an example, but the present invention is not limited to this. For example, instead of the MFP 300, a facsimile, scanner, projector, mobile terminal, smartphone, notebook PC, tablet terminal, PDA, etc. may be used. Alternatively, a digital camera, music playback device, television, smart speaker, AR (Augmented Reality) glasses, etc. may be used. MFP 300 receives print data including image data from an information processing device connected via access point 700, for example, and forms an image based on the data. Alternatively, the MFP 300 transmits, for example, image data read using a scanner function to an information processing device connected via the access point 700. Other control information and the like can also be exchanged with networks connected via the access point 700.
[0015] Access point (AP) 700 is provided separately from information processing device 200 and MFP 300 (outside them), and operates as a WLAN base station device or wireless base station. A communication device equipped with a WLAN communication function can perform communication in a WLAN infrastructure mode (wireless infrastructure mode; hereinafter, infrastructure may be simply expressed as infrastructure) via the access point 700. The access point 700 performs wireless communication with a communication device that is permitted to connect to its own device (ie, an authenticated communication device), and relays wireless communication between that communication device and other communication devices. The access point 700 can also be connected to, for example, a wired communication network and relay communication between a communication device connected to the wired communication network and another communication device wirelessly connected to the access point 700. It is.
[0016] If the authentication method of the network constructed by the access point 700 uses the authentication server 800, the access point 700 performs access control by collaborating with the authentication server 800 and authenticating communication devices connected to the network. conduct. Communication devices connected to the network constructed by access point 700 may be restricted from communicating with devices other than authentication server 800 until they are authenticated. Note that the access point 700 may be compatible with an authentication method that does not use an authentication server. Details of the authentication method using an authentication server and the authentication method not using an authentication server will be described later.
[0017] Authentication server (Radius server) 800 is provided separately from information processing device 200, MFP 300, and access point 700, and collectively manages authentication information. The authentication server 800 is capable of executing authentication processing based on, for example, the IEEE802.1X standard. In this embodiment, the authentication server 800 cooperates with the access point 700 to authenticate a terminal to be authenticated, and controls access to the terminal based on the authentication result.
[0018] Here, the access point 700 corresponds to an authenticator in IEEE802.1X. Further, the information processing device 200 and the MFP 300 correspond to a supplicant in IEEE802.1X. The authentication server 800 corresponds to an authentication server in IEEE802.1X.
[0019] The authentication server 800 performs authentication using, for example, an EAP-TLS (Transport Layer Security) method or an EAP-TTLS (Tunneled TLS) method in accordance with the IEEE802.1X standard. The EAP-TLS method is an authentication method that uses the TLS handshake protocol, which allows authentication using server certificates, client certificates, etc. The EAP-TTLS method is an authentication method that uses the TLS handshake protocol, and can be authenticated using a server certificate, user name, password, etc. As another example, the authentication server 800 can also perform authentication using the PEAP (Protected EAP) method in accordance with the IEEE802.1X standard. In the PEAP (Protected EAP) method, authentication can be performed using a user name and password. The information used for these IEEE802.1X authentications can be expressed as "authentication information."
[0020] The information processing device 200 and MFP 300 use their respective WLAN communication functions to communicate wirelessly in wireless infrastructure mode via an external access point 700 or peer-to-peer (P2P) mode without via an external access point 700. It can be performed. The P2P mode includes WFD (Wi-Fi Direct (registered trademark)), soft AP mode, and the like. That is, the above communication is realized by wireless direct compliant with the IEEE802.11 series. Although details will be described later, the information processing apparatus 200 and MFP 300 are capable of executing processes corresponding to a plurality of print services using WLAN communication.
[0021] [External configuration of MFP] FIG. 2 is a perspective view showing an example of the external configuration of the MFP 300. The MFP 300 includes an operation display section (operation panel) 302, a printing paper insertion port 303, a printing paper ejection port 304, a document table 305, and a document lid 306. A hard key as a power button 301 used to turn on and off the power is provided on the casing of the MFP 300. Operation display unit 302 includes a display and buttons used when operating MFP 300. For example, the operation display unit 302 includes a plurality of keys such as a character input key, a cursor key, an enter key, and a cancel key, and a light source such as an LED (Light Emitting Diode) or an LCD (Liquid Crystal Display). The operation display unit 302 is configured to be able to accept user operation inputs when activating individual functions included in the MFP 300, changing various settings, and the like. Typically, a touch panel display can be used as the operation display unit 302 (see FIG. 4).
[0022] The printing paper insertion slot 303 is an insertion slot for setting paper of any size. The sheets set in the print paper insertion port 303 are conveyed one by one to the print section and printed, and the printed sheets are discharged from the print paper discharge port 304. The document table 305 is a glass-like transparent table, and is used when placing a document and using the scan function to read the image. The original platen pressure plate 306 is a cover for pressing the original against the original platen so that the original does not lift up from the original platen 305 when reading an image using the scan function. Further, the document table pressure plate 306 blocks light from entering the MFP 300 main body from the outside.
[0023] Additionally, the MFP300 is equipped with communication functions via WLAN and wired LAN. In this embodiment, the MFP 300 has a built-in antenna for realizing wireless communication, and is also provided with a communication unit 321 for wired LAN. The MFP 300 is also provided with a USB communication unit 309 that can communicate with an external information processing device 200 or the like through a USB connection. [MFP configuration] FIG. 3 is a block configuration diagram showing an example of the configuration of MFP 300. The MFP 300 includes a built-in main board 310 that controls the entire device, and further includes a wireless communication unit 307 and a USB communication unit 308. The main board 310 includes a CPU (central processing unit) 311, an internal bus 312, a program memory 313, a data memory 314, a print section 316, a scan section 317, a communication control section 318, an operation control section 319, and a USB communication control section 320. include. Note that the processes described below as processes executed by MFP 300 are actually realized by CPU 311 executing programs stored in program memory 313, data memory 314, and the like.
[0024] The CPU 311, program memory 313, and data memory 314 are a microprocessor, ROM (Read Only Memory), and RAM (Random Access Memory), respectively. In this embodiment, CPU 311, program memory 313, and data memory 314 are interconnected via a bus cable forming internal bus 312. The CPU 311 performs arithmetic processing to realize each function described in the embodiment based on the control program stored in the program memory 313 and the contents of the data memory 314.
[0025] For example, the CPU 311 can control the scanning unit 317 to read a document and store the image (image data) in the image memory 315 within the data memory 314. The CPU 311 can control the print unit 316 to print the image stored in the image memory 315 onto a recording medium. The CPU 311 can control the USB communication unit 308 via the USB communication control section 320 and perform USB communication with the external information processing device 200 via USB connection. The CPU 311 can control the operation control section 319 to receive information indicated by operation inputs from the power button 301 and the operation display section 302. Further, the CPU 311 can also control the operation control unit 319 to display the status of the MFP 300 and a function selection menu on the operation display unit 302.
[0026] The wireless communication unit 307 is configured to be able to provide a WLAN communication function, and provides the same function as the WLAN unit 201 of the information processing device 200, for example. That is, the wireless communication unit 307 transmits packets converted from data to other devices in a manner compliant with a predetermined standard, and also restores packets from other devices to original data and outputs the restored data to the CPU 311. The wireless communication unit 307 is configured to be able to perform data (packet) communication in a WLAN system that complies with the IEEE802.11 standard series (IEEE802.11a / b / g / n / ac / ax, etc.); It may be based on the . Here, it is assumed that the wireless communication unit 307 is capable of communicating in any channel in both the 2.4 GHz band and the 5 GHz frequency band. Although the details will be described later, the wireless communication unit 307 further enables communication based on WFD, communication in software access point (soft AP) mode, communication in wireless infrastructure mode, and the like. Further, the information processing device 200 and the MFP 300 are capable of wireless direct communication based on WFD, and the wireless communication unit 307 can have a soft AP function or a group owner function. That is, the wireless communication unit 307 can construct a P2P communication network and determine a channel to be used for P2P communication.
[0027] The wired communication unit 320 is configured to be able to perform wired communication. For example, the wired communication unit 320 can realize data (packet) communication in a wired LAN (Ethernet) system compliant with the IEEE802.3 series. Further, in wired communication using the wired communication unit 320, communication in wired mode is possible. Here, the wired communication unit 320 is connected to the main board 310 via a bus cable forming an internal bus 312.
[0028] [MFP operation display] FIGS. 4(a) to 4(c) schematically show an example of the configuration of the operation display section 302 of the MFP 300.
[0029] FIG. 4(a) is a display example when the MFP 300 employs the touch panel display 401 as the operation display section 302.
[0030] The user can start up the MFP 300 by touching the power button 301. When the MFP 300 starts up, a home screen (typically the top layer of the menu) is displayed on the touch panel display 401 as a screen on which the user can input operations.
[0031] The home screen includes a copy area 405, a scan area 406, and a print area 407. Copy area 405 accepts instructions to execute copy processing. The scan area 406 receives instructions to execute scan processing. The print area 407 receives instructions to execute print processing.
[0032] Further, the home screen may further include a status display area 402, a connection setting mode area 403, and a setting area 404. The status display area 402 shows the settings and connection status of infrastructure connections, P2P connections, etc. of the MFP 300. The connection setting mode area 403 allows the user to start operation in the connection setting mode at any timing. Further, using the settings area 404, the user can change various settings.
[0033] FIG. 4(b) is an example in which the MFP 300 employs a relatively small LCD display 408 and various hard keys 409 to 416 as the operation display section 302.
[0034] When the MFP 300 starts up, a home screen is displayed on the LCD display 408. The user can operate the cursor displayed on LCD display 408 by pressing cursor movement buttons 411 and 412. The user only has to press the OK button 414 when performing an operation, and press the return button 413 when returning to the previous menu screen. Furthermore, by pressing the QR button 409, a QR code (registered trademark) containing information necessary for P2P connection with the MFP 300 can be displayed. Note that the code displayed here is not limited to a QR code, but may be a two-dimensional code. By reading this QR code with a camera unit or the like included in the information processing device 200, the information processing device 200 and the MFP 300 are connected P2P and can communicate wirelessly with each other. Furthermore, by pressing the connection setting mode button 410, it is possible to start the connection setting mode, and by sending connection information to the MFP 300 using the information processing device 200, the MFP 300 can be connected to the access point 700. . If the stop button 415 is pressed while the MFP 300 is executing various processes, the various processes are canceled. The user can also press copy start button 416 to scan and print a document with MFP 300.
[0035] As shown in FIG. 4(c), the layout in FIG. 4(b) may be changed as appropriate; for example, the cursor operation may be performed in the left / right direction. Note that the above-mentioned elements 408 to 416 may be simply expressed as screens; for example, the LCD display 408 may also be expressed as the screen 408.
[0036] [External configuration of information processing device] FIG. 5 shows an example of the external configuration of the information processing device 200. In this embodiment, the information processing device 200 is a smartphone, and includes a display section 202, an operation section 203, and a power key 204. The power key 204 is provided as a hard key for turning on or off the power of the information processing device 200. Although the display unit 202 is a display including an LCD type display mechanism in this embodiment, information may be displayed using an LED or the like in other embodiments. Further, the information processing device 200 may have a function of outputting information by voice, in addition to or in place of the display unit 202. The operation unit 203 includes hard keys such as keys and buttons, or a touch panel, and can be configured to be able to detect user operation input.
[0037] In this embodiment, a touch panel display that has both the functions of the display section 202 and the operation section 203 is used. In this case, for example, button icons and software keyboards are displayed using the functions of the display unit 202, and user operation inputs thereon are detected using the functions of the operation unit 203. As another embodiment, the display section 202 and the operation section 203 may be provided as separate hardware.
[0038] Further, the information processing device 200 may include a WLAN unit 201 that can provide a WLAN communication function. The WLAN unit 201 is configured to be able to perform data (packet) communication in a WLAN system based on, for example, the IEEE802.11 standard series (IEEE802.11a / b / g / n / ac / ax, etc.). The WLAN unit 201 may be capable of performing communication in a WLAN system compliant with other standards. Here, it is assumed that the WLAN unit 201 is capable of communicating in both the 2.4 GHz and 5 GHz frequency bands. Further, although the details will be described later, the WLAN unit 201 is capable of executing communication based on WFD, communication in soft AP mode, communication in wireless infrastructure mode, and the like.
[0039] [Configuration of information processing device] FIG. 6 is a block diagram of the information processing device 200. The information processing device 200 includes a main board 211 that performs main control of the device itself, a WLAN unit 201 that performs WLAN communication, and a BT (Bluetooth (registered trademark)) unit 205.
[0040] In this embodiment, main board 211 includes CPU 212, ROM 213, RAM 214, image memory 215, and data converter 216. Main board 211 further includes a telephone section 217, a GPS (Global Positioning System) 219, a camera section 221, a nonvolatile memory 222, a data storage section 223, a speaker section 224, and a power supply section 225. These individual functional units within main board 211 are interconnected via system bus 228 and managed by CPU 212. Furthermore, the main board 211 and the WLAN unit 201 and the main board 211 and the BT unit 205 are connected via a dedicated bus 226.
[0041] The CPU 212 functions as a system control unit that controls individual elements of the information processing device 200. The individual functions of the information processing device 200 exemplified here and the processing described below as the processing executed by the information processing device 200 are executed by the CPU 212 while expanding the program stored in the ROM 213 onto the RAM 214. This is achieved by
[0042] More specifically, the ROM 213 stores control programs executed by the CPU 212, embedded operating system (OS) programs, and the like. The CPU 212 executes compatible programs under the embedded OS to perform software control such as scheduling and task switching. The RAM 214 is composed of SRAM (Static RAM) or the like. The RAM 214 stores various data such as variables for program control, setting values registered by the user, and management data for managing the information processing device 200. RAM214 can be used as a buffer for various works. The image memory 215 is composed of a memory such as DRAM (Dynamic RAM). The image memory 215 temporarily stores image data received via the WLAN unit 201 and image data read from the data storage section 223, and allows the CPU 212 to process the image data. The nonvolatile memory 222 is configured with a memory such as a flash memory, and retains stored data even when the information processing device 200 is powered off.
[0043] Note that the memory configuration of the information processing device 200 is not limited to the above example. For example, the image memory 215 and the RAM 214 may be provided in common, or the data storage section 223 may be used to back up data. Furthermore, although DRAM is used here as an example of the image memory 215, other storage media such as an HDD (hard disk drive) or nonvolatile memory may be used.
[0044] The data conversion unit 216 can perform data conversion such as color conversion and image conversion, as well as analysis of data in various formats. The telephone unit 217 controls the telephone line and processes audio data input and output via the speaker unit 224, thereby enabling communication by telephone. The GPS 219 receives radio waves transmitted from a satellite and obtains current position information such as latitude and longitude of the information processing device 200. The camera unit 221 has a function of electronically recording and encoding an image input through a lens. Image data obtained by imaging by the camera section 221 is stored in the data storage section 223. The speaker unit 224 performs control to implement functions such as audio input / output for telephone functions and alarm notification. Power supply unit 225 includes a battery and controls the supply of power to individual elements within the device. The power state includes, for example, a dead battery state where the remaining battery level is below a standard, a power off state where the power key 204 is not pressed, a power on state (startup state) where the power key 204 is pressed, and an individual element state. Includes power saving states where power consumption is suppressed.
[0045] The display unit 202 electronically controls display contents and performs control for displaying operation input by the user, operating status of the MFP 300, status status, and the like. In response to receiving an operation input from the user, the operation unit 203 outputs an electrical signal corresponding to the operation input to the CPU 212. As described in FIG. 5, a touch panel display can be used for the display unit 202 and the operation unit 203.
[0046] The information processing device 200 can perform wireless communication using the WLAN unit 201, and performs data communication with other devices such as the MFP 300. For example, the information processing device 200 converts data into a packet and transmits it to another external device. Additionally, the information processing device 200 receives packets from other external devices via the WLAN unit 201, restores them to original data, and outputs the restored data to the CPU 212.
[0047] The configuration of main board 211 is not limited to the above example. For example, the individual functions of the main board 211 realized by the CPU 212 may be realized by a processing circuit such as an ASIC (Application Specific Integrated Circuit), that is, they may be realized by either hardware or software.
[0048] [Access point configuration] FIG. 7 is a block diagram of an access point 700 having a wireless LAN access point function. The access point 700 includes a main board 710 that performs system control, a wireless LAN unit 716, a wired LAN unit 718, and an operation button 720. The main board 710 includes a CPU 711, a program memory 713, a data memory 714, a wireless LAN communication control section 715, a wired LAN communication control section 717, an operation section control circuit 719, a terminal access control section 721, and a channel change section 722. These are connected by an internal bus 712 so that they can communicate with each other. Note that the processes described below as processes executed by the access point 700 are actually realized by the CPU 711 executing programs stored in the program memory 713, the data memory 714, and the like.
[0049] CPU 711 performs arithmetic processing based on the control program stored in program memory 713 and data held in data memory 714. The CPU 711 can control the wireless LAN unit 716 using the wireless LAN communication control section 715 to perform wireless LAN communication with other communication information processing devices. The CPU 711 can control the wired LAN unit 718 using the wired LAN communication control section 717 to perform wired LAN communication with other communication information processing devices. Further, the CPU 711 can receive operation input from the user using the operation button 720 by controlling the operation unit control circuit 719.
[0050] The terminal access control unit 721 protects the network by authenticating communication devices connected to the network. Examples of such authentication methods include a PSK method using a pre-shared key (PSK), an SAE method using SAE (Simultaneous Authentication of Equals), and the like. Furthermore, as an authentication method when performing authentication according to the WPA3-Enterprise standard, there is an IEEE802.1X authentication method that uses an authentication server that operates according to EAP (Extensible Authentication Protocol) as the authentication protocol. Since the IEEE802.1X authentication method uses EAP, the IEEE802.1X authentication method is referred to as the IEEE802.1X / EAP authentication method. An EAP method using an authentication server compatible with IEEE802.1X / EAP may be used (hereinafter, IEEE802.1X / EAP may be simply referred to as "802.1X / EAP"). Further, in the following, the IEEE802.1X / EAP authentication method is simply referred to as the EAP method or IEEE802.1X / EAP. The communication channel authenticated in this manner can be changed or switched by the channel change unit 722. Note that in this embodiment, the authentication method that does not use an authentication server is the PSK method or the SAE method, and the authentication method that uses an authentication server is the EAP method. Further, an authentication method that does not use an authentication server is also called a personal method, and an authentication method that uses an authentication server is also called an enterprise method.
[0051] [Authentication server configuration] FIG. 8 is a block diagram of the authentication server 800. Authentication server 800 includes a main board 811 that performs system control and a communication unit 801 that performs wired LAN communication.
[0052] Main board 811 includes CPU 812, ROM 813, RAM 814, image memory 815, nonvolatile memory 822, data storage section 823, and communication control section 826. Main board 811 further includes a display section 802 and an operation section 803. These are interconnected via a system bus (bus cable) 828. Further, the main board 811 is connected to the communication unit 801 by a communication control section 826.
[0053] The CPU 812 functions as a system control unit that controls the entire authentication server 800. The processing of the authentication server 800 is realized by the CPU 812 loading a program stored in the ROM 813 into the RAM 814 and executing it.
[0054] More specifically, the ROM 813 stores control programs executed by the CPU 812, built-in OS programs, and the like. The CPU 812 executes compatible programs under the embedded OS to perform software control such as scheduling and task switching. The RAM 814 is composed of SRAM or the like. The RAM 814 stores various data such as variables for program control, setting values registered by the user, and management data for managing the authentication server 800. RAM814 can be used as a buffer for various works. Image memory 815 is composed of memory such as DRAM. Image memory 815 temporarily stores image data received via communication unit 801 and image data read from data storage section 823, and enables processing by CPU 812. The data storage unit 823 is configured by a storage medium such as an SSD (Solid State Drive), and retains stored data even when the authentication server 800 is powered off. Further, as another example of the data storage section 823, other storage media such as an HDD or a nonvolatile memory may be used.
[0055] Note that, like the main board 211 shown in FIG. 6, the individual functions of the main board 811 described here may be realized by either hardware or software.
[0056] The display unit 802 electronically controls display content and executes control for displaying user operation input, status status, and the like. In response to receiving an operation input from the user, the operation unit 803 outputs an electrical signal corresponding to the operation input to the CPU 812.
[0057] The authentication server 800 can perform data communication with the access point 700 (or other device) via the communication unit 801 by the communication control unit 826. For example, the authentication server 800 can convert data into a packet and send it to another external device. . Furthermore, the communication unit 801 receives packets from other external devices, restores them to original data, and outputs the restored data to the CPU 812. The communication unit 801 is capable of data (packet) communication in a wired LAN (Ethernet) system compliant with the IEEE802.3 series, for example.
[0058] [P2P (Peer to Peer) mode] Wireless direct communication in which communication devices directly communicate and connect wirelessly (without going through an external access point 700) in WLAN communication will be described. For example, a communication device can support multiple modes for wireless direct communication and selectively use any of the multiple modes to perform P2P communication (WLAN). A connection with an MFP 300 operating in P2P mode that does not go through an external access point 700 is called a P2P connection. As P2P mode, ·Mode A (Soft AP mode) ·Mode B (Wi-Fi Direct (WFD) mode) Two modes are assumed.
[0059] A communication device capable of performing P2P communication can be configured to support at least one of these modes (in this specification, mode A and mode B can be collectively expressed as wireless direct). A communication device capable of performing P2P communication does not need to support all of these modes, and may be configured to support only some of them. Note that the MFP00 operating in P2P mode operates as a master device in connection and communication with other devices. That is, in the soft AP mode, the MFP 300 operates as a soft AP (access point). In WFDAP mode, the MFP300 operates as a group owner. Note that the WFD mode is not limited to this, and the MFP 300 may operate as a slave device by executing group owner negotiation. Note that the communication device can support a wireless infrastructure mode (mode C) in addition to the P2P mode. FIG. 10(c) shows a state in which the MFP300 operates in P2P mode. In this state, communication between MFP 300 and information processing device 200 can be realized without going through authentication server 800 or access point 700.
[0060] In a communication device (for example, the information processing device 200) having a WFD communication function, by receiving a user operation through its operation unit, an application (or a dedicated application) for realizing the communication function is called. This communication device can display a UI (user interface) screen provided by the application to prompt the user to input an operation, and can execute WFD communication based on the input operation.
[0061] [Wireless infrastructure mode] In wireless infrastructure mode, communication devices that communicate with each other (for example, information processing device 200 and MFP 300) are connected to an external access point (AP700 in this case) that controls the network, and the AP is Communication between the communication devices is performed through the communication device. In other words, communication between communication devices is realized via the network constructed by the AP. Furthermore, the MFP00 operating in wireless infrastructure mode operates as a slave station in connection and communication with the access point 700. A connection with an MFP 300 operating in wireless infrastructure mode via an external access point 700 is called an infrastructure connection.
[0062] In wireless infrastructure mode, a device searches for an access point by transmitting a device search request (Probe Request). When a device receives a device search response (Probe Response) from an access point, it displays the SSID (Service Set Identifier) included in the device search response. The information processing device 200 and the MFP 300 discover the access point 700 as described above, send a connection request to this access point 700, and are connected to the wireless infrastructure via the access point 700 of these communication devices. mode communication is possible.
[0063] Note that the plurality of communication devices may be connected to different APs. In that case, data transfer between APs enables communication between communication devices. Commands and parameters sent and received during communication between communication devices may be those that comply with the Wi-Fi standard.
[0064] Access point 700 determines the frequency band and frequency channel. For example, the access point 700 can select which frequency band, 5 GHz or 2.4 GHz, to use, and which frequency channel to use in that frequency band.
[0065] When the information processing device 200 or the MFP 300 connects to the wireless LAN configured by the access point 700, the access point 700 performs authentication. The information processing device 200 and the MFP 300 connect to the wireless LAN configured by the access point 700 using a wireless LAN authentication method such as a PSK method, an SAE method, or an EAP method according to the authentication method of the wireless LAN configured by the access point 700.
[0066] Note that FIG. 10(a) shows a state in which the MFP 300 operates in a wireless infrastructure mode connected to an access point 700 that supports IEEE802.1X / EAP. In this state, communication between MFP 300 and information processing device 200 can be realized based on authentication performed by cooperation of authentication server 800 with access point 700.
[0067] Further, FIG. 10(b) shows a state in which the MFP 300 operates in a wireless infrastructure mode connected to an access point 700 that does not support IEEE802.1X / EAP. In this state, communication between MFP 300 and information processing device 200 can be realized without authentication performed by cooperation of authentication server 800 with access point 700.
[0068] [Wired communication mode] In the wired communication mode, the communication device (for example, MFP 300) can communicate with other communication devices via a wired interface such as a wired LAN. For example, when performing communication in the wired communication mode in the MFP 300, communication in the wireless infrastructure mode is restricted. In the wired communication mode, data (packet) communication is possible in a wired LAN (Ethernet) compliant with the IEEE802.3 series, for example. When operating with the IEEE802.1X / EAP settings enabled, the MFP 300 performs IEEE802.1X authentication when connecting to the wired LAN configured by the access point 700.
[0069] [About simultaneous wireless operation] If the communication in the two modes is authentication type communication that does not use the authentication server 800, the MFP 300 can execute communication in each mode simultaneously (in parallel). That is, the respective connections for performing communication in each mode are maintained simultaneously. Specifically, for example, it is possible to simultaneously perform communication in wireless infrastructure mode and communication in P2P mode. Therefore, the MFP 300 simultaneously maintains both a connection for communicating in wireless infrastructure mode and a connection for communicating in P2P mode. Such operation may be expressed as "wireless simultaneous operation." In other words, the simultaneous wireless operation is an operation in which, for example, the MFP 300 simultaneously performs an operation as a child device in Wi-Fi communication in wireless infrastructure mode and an operation as a parent device in Wi-Fi communication in P2P mode. On the other hand, when the MFP 300 performs communication using the authentication method using the authentication server 800, it does not maintain both the infrastructure connection and the P2P connection at the same time. Maintains connection via Wi-Fi communication in either mode at a time. When changing the communication mode, the maintained connection is released and a connection is established using a new communication mode.
[0070] [Processing overview] Processing related to communication in this embodiment will be described below with reference to FIGS. 9 to 16. Here, each step in the flowcharts in Figures 9, 13, and 15 will be explained as being executed by the device, but correctly, the CPU of the device that executes each flowchart will load the program stored in the ROM onto the RAM. It is assumed that this is done by expanding and executing the file.
[0071] [Screen flow] FIGS. 11(a) to 11(j) are screen flow diagrams when LAN settings are selected from the settings menu on the screen 408 of FIG. 4(b) on the operation display unit 302 of the MFP 300.
[0072] FIG. 11(a) is a screen on which the LAN settings can be changed, which is displayed when the selection item "LAN settings" is selected by the user on the screen 408 shown in FIG. 4(b). The screen in the figure shows "wireless LAN" 1201, "wired LAN" 1202, "P2P mode" (wireless direct) 1203, and "common settings" 1204 as selection items that can be selected by the user. When connecting the MFP 300 to an access point compatible with the Personal method, the user selects the wireless LAN 1201.
[0073] FIG. 11(b) is a screen that is displayed when the user selects "Wireless LAN" 1201 on the screen of FIG. 11(a), and allows the user to change the wireless LAN settings. On the screen in Figure 11(b), the selection items that the user can select are "enable / disable wireless LAN" 1211, "wireless LAN setup" 1212, "wireless LAN settings display" 1213, and "detailed settings". 1214 is shown.
[0074] "Wireless LAN enable / disable" 1211 is an area for setting whether communication using wireless LAN by the MFP300 is enabled (enabled) or disabled (disabled). It is. By accepting a user operation on the display screen after the area is selected, the state in which communication using the wireless LAN by the MFP 300 is enabled is set to disabled or enabled. Note that in a state where this state is set to disabled, the MFP 300 does not perform communication or connection using the wireless LAN.
[0075] FIG. 11(c) is a screen that is displayed when the user selects detailed settings 1214 on the screen of FIG. 11(b) and allows the user to change the LAN detailed settings. In the screen of FIG. 11(c), "TCP / IP settings" 1221 and "802.1X / EAP settings" 1222 are shown as selection items that can be selected by the user.
[0076] Figure 11(d) is a screen that is displayed when the user selects 802.1X / EAP settings 1222 on the screen of Figure 11(c), and allows the user to change the IEEE802.1X / EAP settings. . On the screen in Figure 11(d), the selection items that the user can select are "enable / disable IEEE802.1X / EAP" 1231, "Search for EAP router" 1232, and "Confirm previous authentication result" 1233. shown. Note that the EAP router to be searched here is a wireless LAN router that has a wireless access point function that supports EAP. "EAP router" is an example of a display, and the EAP router to be searched may be a wireless access point that functions as an authenticator in IEEE802.1X.
[0077] FIG. 11(e) is a screen displayed while performing a wireless access point search using the authentication method using the authentication server 800. Access point search is performed when "Search EAP router" 1232 is selected on the screen shown in Figure 11(d) when "IEEE802.1X / EAP settings" is enabled. It can be done. Screen 1240 is displayed during the search.
[0078] Note that the screen shown in FIG. 11(e) is the screen shown in FIG. 11(b) when the user selects the wireless LAN setup 1212 and executes a wireless access point search using an authentication method that does not use the authentication server 800. It is also displayed in between.
[0079] The screen shown in Figure 11(f) is an example of a screen that displays a list of wireless access point identification names (SSID) as a result of an EAP wireless LAN router search, that is, an access point search (AP search). be. FIG. 11(f) shows an example in which "SSIDWPA-EAP001" 1251, "WPA2-EAP005" 1252, and "WPA3-EAP003" 1253 are shown as the selection items (discovered SSIDs). Note that these correspond to the WPA-EAP method, WPA2-EAP method, and WPA3-EAP method, respectively.
[0080] Note that as other examples of the display, a known method such as a WPA-PSK method, a WPA2-PSK method, or a WPA3-SAE method may be shown, or an OPEN method may be shown incidentally. When "EAP router search" 1232 is selected on the screen shown in FIG. 11(d), only the SSID of the access point whose authentication method is EAP is displayed on the screen shown in FIG. 11(f). Furthermore, when "wireless LAN setup" 1212 is executed, only the SSIDs of access points whose authentication method is not EAP are displayed.
[0081] The screen shown in Figure 11(g) is the screen shown in Figure 11(f), where the user selects one of the SSIDs (1251 to 1253) of the access point, and the MFP300 executes the connection process with the selected access point. This is the screen that is displayed while As another aspect, another display indicating that the connection process is in progress may be performed.
[0082] The screen shown in Figure 11(h) is displayed after the screen in Figure 11(g) is displayed when the attempt to connect with the access point is completed and the connection is successful or the connection has progressed to the specified stage. This is the screen displayed when
[0083] The screen shown in Figure 11(i) is the screen shown in Figure 11(d), where the user selects enable / disable 1231 of 802.1X / EAP, and enables / disables the IEEE802.1X / EAP settings. It's a screen. It is assumed that valid 1281 and invalid 1282 are displayed as selection items on the screen in FIG. 11(i). A state in which the IEEE802.1X / EAP authentication method is valid in the MFP300 is a state in which authentication using the IEEE802.1X / EAP authentication method and authentication using the Personal method are possible. In other words, it is possible to connect to an access point that supports the IEEE802.1X / EAP authentication method, and also to an access point that supports the Personal method. Furthermore, a state in which IEEE802.1X / EAP is disabled in the MFP 300 is a state in which authentication using the IEEE802.1X / EAP authentication method is not possible, and a state in which authentication using the Personal method is possible. In other words, it is in a state where it is not possible to connect to an access point that supports the IEEE802.1X / EAP authentication method, but it is possible to connect to an access point that supports the Personal method.
[0084] The screen shown in Figure 11(j) is displayed when EAP router search 1232 is selected on the screen shown in Figure 11(d) when "IEEE802.1X / EAP enable / disable" 1231 is disabled. This is the screen that appears. That is, in this embodiment, when the IEEE802.1X / EAP setting is disabled, even if the EAP router search 1232 is selected, the router search is not executed. At that point, a warning message as shown in FIG. 11(j) is displayed.
[0085] Note that the control for not connecting to the access point using IEEE802.1X / EAP authentication, which is executed when the IEEE802.1X / EAP setting is invalid, is not limited to the above-mentioned control. For example, the MFP 300 performs a router search, but does not need to display access points for which IEEE802.1X / EAP authentication is valid in the list of access points discovered by the router search. Alternatively, access points with valid IEEE802.1X / EAP authentication are also displayed in the list, but even if the user selects one, the MFP300 will not perform connection processing with the access point with valid IEEE802.1X / EAP authentication. You don't have to.
[0086] [IEEE802.1X / EAP authentication information settings] When the MFP 300 executes a connection process to connect to a network for which IEEE802.1X / EAP authentication is enabled, settings for the connection process need to be configured for the MFP 300 before starting. In this embodiment, the settings are executed by the information processing device 200 transmitting information for executing the settings to the MFP 300, and the MFP 300 receiving the information.
[0087] FIG. 9 shows a flowchart executed by the MFP 300 (or more accurately, the CPU 311) for connection processing to connect to a network in which authentication by IEEE802.1X / EAP is enabled.
[0088] In S901, MFP 300 establishes a connection between information processing device 200 and MFP 300. Specifically, for example, MFP 300 receives a connection request from information processing device 200 and establishes a connection between MFP 300 operating in P2P mode and information processing device 200. Note that the type of connection established here is not limited to a wireless P2P connection, and may be a connection using a wired LAN or USB, for example. Alternatively, for example, an infrastructure connection via an access point compatible with the personal method may be used.
[0089] In S902, the MFP 300 transmits information for displaying a settings screen for executing settings of the MFP 300 regarding authentication by IEEE802.1X / EAP, which will be described later, to the information processing apparatus 200. The information processing device 200 then displays a settings screen (the screen shown in FIG. 12) using the information, and receives input regarding the settings from the user. Information processing device 200 then transmits authentication information based on the received input to MFP 300. Authentication information for MFP 300 is received from information processing device 200, and settings related to IEEE802.1X / EAP authentication are executed using that information. This setting can be performed by the information processing device 200 transmitting authentication information to the MFP 300 via the connection established in S901, and the MFP 300 receiving it.
[0090] In S903, the MFP 300 connects to the network based on the settings performed in S902. In other words, the MFP 300 establishes a connection with an access point for which IEEE802.1X / EAP authentication is enabled based on the settings performed in S902. Note that at this time, depending on the contents of the settings executed in S902, establishment of the connection between the MFP 300 and the access point may fail.
[0091] 12(a) to (k) show various display examples related to the setting screen of the MFP 300 displayed on the display unit 202 of the information processing device 200. These screens are displayed on the display unit 202 by a web browser or application running on the information processing device 200 communicating with an HTTP server running on the MFP 300. Specifically, for example, the information processing device 200 accesses the MFP 300 by inputting the IP address of the MFP 300 in a web browser running on the information processing device 200. In response to the access, MFP 300 provides screen information for displaying the screen shown in FIG. 12 to information processing device 200. Information processing device 200 then displays the screen shown in FIG. 12 based on the screen information provided by MFP 300. That is, the screen in FIG. 12 shows an example of a remote user interface (remote UI) related to settings that is displayed on information processing apparatus 200 based on screen information provided by MFP 300. This screen may be displayed based on a standby response to an HTTP request via USB communication using the USB communication control unit 320 of the MFP 300.
[0092] FIG. 12(a) is a screen of the first menu of the setting screen of MFP 300 displayed on information processing device 200. This screen includes "printer status" 1101, "main unit settings" 1102, "LAN settings" 1103, and "security settings" 1104 as selection items.
[0093] FIG. 12(b) shows the screen displayed when "Security Settings" 1104 is selected in FIG. 12(a). This screen includes "SSL / TLS settings" 1111 and "(IEEE)802.1X / EAP settings" 1112 as selection items.
[0094] FIG. 12(c) shows a screen displayed when "802.1X / EAP settings" 1112 is selected in FIG. 12(b). This screen includes "Authentication method" 1121, "Key and certificate settings" 1122, and "(IEEE) 802.1X / EAP enable / disable" 1123 as selection items.
[0095] FIG. 12(d) is a screen displayed when "authentication method" 1121 is selected in FIG. 12(c). This screen includes "EAP-TLS" 1131, "EAP-TTLS" 1132, and "PEAP" 1133 as authentication method selection items. This screen also includes a “user name (login name)” input field 1134 and a password input field 1135. When the user selects one of the selection items 1131 to 1133 here, the authentication method to be used during IEEE802.1X / EAP authentication is set from the information processing device 200 to the MFP 300. Further, by entering a user name in input field 1134 and a password in input field 1135, the user name and password to be used during IEEE802.1X / EAP authentication are set from information processing device 200 to MFP 300.
[0096] When registering a certificate to be used during IEEE802.1X / EAP authentication in the MFP 300, the user first selects "key and certificate settings" 1122 on the screen shown in FIG. 12(c). As a result, for example, in the case of EAP-TLS, the screen shown in FIG. 12(e) is displayed. Then, when the user selects one of the selection items "upload key and certificate" 1141 on the screen of FIG. 12(e), the screen of FIG. 12(f) is displayed. On this screen, the user can select the file as the certificate in field 1161, enter the password as the key in field 1162, and then select the upload button 1163 to create the key and certificate for the MFP300. upload (send) is completed. The key and certificate specified for upload are set on the MFP300, and the entered user name and password are also set on the MFP300. The MFP 300 acquires the location and file name of the certificate file, key information, user name, and password from the information processing device 200, and uses the acquired information to execute settings related to IEEE802.1X / EAP authentication.
[0097] Note that the screen in FIG. 12(e) includes "Delete key and certificate" 1142 and "Confirm key certificate" 1143 as selection items. When the user selects "Delete key and certificate" 1142, the user can delete the certificate stored in the MFP 300. Furthermore, by selecting “Confirm keys and certificates” 1143, the user can also display a list of certificates stored in the MFP 300.
[0098] FIG. 12(g) is a screen displayed when the user selects "enable / disable IEEE802.1X / EAP" 1123 on the screen of FIG. 12(c). On this screen, you can select whether to enable or disable the IEEE802.1X / EAP settings of the MFP300 (the example shown is when disable is selected). Then, by selecting the OK button, the selection will be reflected. Note that enabling the IEEE802.1X / EAP setting means putting the MFP 300 into a state where IEEE802.1X / EAP is enabled. In other words, disabling the IEEE802.1X / EAP settings means putting the MFP 300 into a state where IEEE802.1X / EAP is disabled.
[0099] FIG. 12(h) is a screen displayed when the user selects "LAN settings" on the screen of FIG. 12(a). This screen displays the same selection items as those shown in FIG. 11(a) displayed on the operation display unit 302 of the MFP 300.
[0100] FIG. 12(i) is a screen displayed when the user selects "wireless LAN" in FIG. 12(h). This screen has the same meaning as that shown in FIG. 11(b) displayed on the operation display unit 302 of the MFP 300.
[0101] FIG. 12(j) is a screen displayed when the user selects "detailed settings" on the screen of FIG. 12(i). This screen has the same meaning as FIG. 11(c) displayed on the operation display unit 302 of the MFP 300.
[0102] FIG. 12(k) is a screen displayed when the user selects "IEEE8021X / EAP settings" on the screen of FIG. 12(j). This screen has the same meaning as FIG. 11(d) displayed on the operation display unit 302 of the MFP 300.
[0103] By performing a user operation on each screen in FIG. 12, authentication information based on the content of the user operation is transmitted to MFP 300. Then, the MFP 300 receives the authentication information, and the settings related to EAP are executed for the MFP 300 based on the information. In other words, authentication information corresponds to each IEEE802.1X authentication method among the authentication method used during IEEE802.1X / EAP authentication, the user name and password used during authentication, and the key and certificate used during authentication. Contains information to By being authenticated by authentication server 800 using these authentication information, MFP 300 can connect to a network using authentication server 800 configured by access point 700. Here, since the MFP300 cannot simultaneously enable an infrastructure connection using IEEE802.1X / EAP authentication and a P2P connection, the P2P connection is disconnected when it starts searching for an EAP router.
[0104] Note that in the present embodiment, the valid (ON state) / invalid (OFF state) state of each communication mode is managed. For example, in the MFP 300, by controlling the wireless communication unit 307 and the wired LAN communication unit 321, effective communication modes can be switched and communication can be controlled.
[0105] [EAP method AP search and storage of authentication results] FIG. 13 is a flowchart showing operations when MFP 300 connects to access point 700 using an authentication method using authentication server 800. That is, FIG. 13 is a flowchart showing details of S903.
[0106] The flowchart in FIG. 13 is performed when "Search EAP router" (FIG. 11(d)) displayed on the operation display unit 302 of the MFP 300 is operated, or when "Search EAP router" displayed on the information processing device 200 is operated. This is executed when "Search for" (Figure 12(k))) is operated. In S1301, the MFP 300 accepts a search request (AP search request) for the access point 700 issued in response to the "Search EAP router" operation. Note that when FIG. 11(d)) is operated, the MFP 300 issues an AP search request, and the MFP 300 accepts the AP search request. Moreover, when FIG. 12(k) is operated, information processing device 200 issues an AP search request, and MFP 300 accepts the AP search request.
[0107] In S1302, the MFP 300 searches for an access point 700 that supports IEEE802.1X / EAP.
[0108] In S1303, MFP 300 determines whether the received AP search request was issued by information processing device 200. In other words, it is determined whether the request source of the AP search is an external device of the information processing device 200. If YES, proceed to S1304; if NO, proceed to S1305.
[0109] In S1304, the MFP 300 transmits a list of SSIDs of the access points 700 searched as a result of the AP search in S1303 to the information processing device 200 that has issued the AP search request.
[0110] In S1305, MFP 300 displays on operation display unit 302 a list of SSIDs of access points 700 searched as a result of the AP search in S1303. Then, the MFP 300 connects to the access point corresponding to the SSDI selected by the user from the list. Then, the access point requests IEEE802.1X / EAP authentication to the authentication server corresponding to the access point based on the settings performed in S902, and attempts the authentication. Thereafter, the MFP 300 may display the IEEE802.1X / EAP authentication result on the operation display unit 302. Additionally, if the IEEE802.1X / EAP authentication result is a failure, the reason for the failure may also be displayed.
[0111] FIG. 13(b) shows the processing executed after S1304.
[0112] In S1306, the MFP 300 receives from the information processing apparatus 200 a connection request to an AP that includes the SSID of the AP selected by the user as a connection target (connection target AP).
[0113] In S1307, MFP 300 stores the communication mode of MFP 300 when receiving the connection request. Here, it is assumed that the communication mode of MFP 300 when receiving the connection request is stored as P2P mode.
[0114] In S1308, MFP 300 acquires identification information (identifier) of information processing device 200 from information processing device 200.
[0115] In S1309, if the MFP 300 is operating in a communication mode that is incompatible with the IEEE802.1X / EAP connection, it stops the communication mode and disconnects from the information processing device 200. This is because IEEE802.1X / EAP connection will be attempted later. In this embodiment, it is assumed that the communication mode that is incompatible with IEEE802.1X / EAP connection is the wireless infrastructure mode used for connection with an access point that supports P2P mode or personal authentication. Note that the communication mode is not limited to this mode, and other modes may be communication modes that are incompatible with IEEE802.1X / EAP connection. Communication modes compatible with IEEE802.1X / EAP connection are wired LAN mode and USB communication mode. Note that the communication mode is not limited to this mode, and other modes may be compatible with IEEE802.1X / EAP connection. Note that IEEE802.1X / EAP connection refers to connection with an AP that supports IEEE802.1X / EAP. The MFP 300 then connects to the connection target AP that corresponds to the connection request received in S1306.
[0116] In S1310, the MFP 300 requests IEEE802.1X / EAP authentication from the authentication server corresponding to the connection target AP based on the settings performed in S902, and attempts the authentication.
[0117] In S1311, MFP 300 stores the IEEE802.1X / EAP authentication result in data memory 314. This authentication result includes success or failure of authentication and the detected reason for failure.
[0118] In S1312, the MFP 300 determines whether the communication mode stored in S1307 is a communication mode that is incompatible with the IEEE802.1X / EAP connection. If YES, proceed to S1312; if NO, proceed to S1314.
[0119] In S1313, the MFP300 disconnects the IEEE802.1X / EAP connection.
[0120] Then, in S1314, the MFP 300 validates the communication mode stored in S1307 and resumes operation in the communication mode. Then, MFP 300 re-establishes the connection with information processing device 200.
[0121] In S1315, MFP 300 receives the identification information of information processing apparatus 200 from information processing apparatus 200, and determines whether the received identification information matches the identification information stored in S1308. If YES, the process advances to S1316; if NO, the process ends. Note that if the answer is NO, the connection with the information processing device 200 may be disconnected.
[0122] In S1316, MFP 300 transmits the IEEE802.1X / EAP authentication result stored in S1311 to information processing device 200. When information processing device 200 receives the IEEE802.1X / EAP authentication result, it displays the IEEE802.1X / EAP authentication result. At this time, if the IEEE802.1X / EAP authentication result is a failure, the reason for the failure may also be displayed.
[0123] In S1317, the MFP 300 determines whether IEEE802.1X / EAP authentication is successful or not. If the MFP 300 determines that the authentication has failed, it ends the processing of this flow. Note that at this time, the IEEE802.1X / EAP authentication result and the reason for failure may be displayed on the operation display unit 302. Further, if the MFP 300 determines that the authentication was successful, the process advances to S1318. Further, if it is determined that the authentication was successful, the operation display unit 302 may display an IEEE802.1X / EAP authentication result indicating success.
[0124] In S1317, the MFP 300 reconnects to the connection target AP, which is the AP corresponding to the connection request received in S1306. If IEEE802.1X / EAP authentication is required again after this, the MFP300 requests IEEE802.1X / EAP authentication from the authentication server corresponding to the connection target AP based on the settings performed in S902, and performs the relevant authentication. try. After that, the process ends.
[0125] [Wireless infrastructure (EAP) setup from information processing device 200] In the following, wireless infrastructure (EAP) setup by operations from the information processing device 200 will be described.
[0126] 14(a) to (e) are screen flows on the information processing device 200 when the MFP 300 connects to the access point 700 using the authentication method using the authentication server 800.
[0127] Further, FIG. 15 is a flowchart showing the internal processing of the information processing device 200 at this time. The process related to the flowchart in FIG. 15 is started in response to the user selecting "Search for EAP router" on the screen in FIG. 12(k).
[0128] In S1501, information processing device 200 transmits an AP (access point) search request to MFP 300. Then, in S1502, the information processing apparatus 200 displays the screen shown in FIG. 14(a) on the display unit 202 to notify the user that the MFP 300 is searching for an AP. Note that at this time, the MFP 300 enters the processing state of S1303 in FIG.
[0129] When the MFP 300 completes the AP search, it transmits a list of AP SSIDs to the information processing device 200. Therefore, in S1503, information processing apparatus 200 receives a list of AP SSIDs from MFP 300 as a search result.
[0130] In S1504, the information processing apparatus 200 displays a list of SSIDs of connection target APs on the screen 202, as shown in FIG. 14(b), and waits for a selection from the user. When the user selects an AP to be connected, in S1505, the information processing apparatus 200 transmits a connection request to which the SSID of the selected AP is added to the MFP 300.
[0131] Upon receiving the above connection request, the MFP 300 will perform IEEE802.1X / EAP connection to the AP to be connected and perform an authentication attempt with the authentication server. Since the information processing apparatus 200 waits for the authentication result from the MFP 300, the screen shown in FIG. 14(c) is displayed on the display unit 202 in S1506.
[0132] In S1507, information processing device 200 receives the authentication result from MFP 300. Then, in S1508, the information processing apparatus 200 determines whether the authentication is successful or unsuccessful. If the information processing device 200 determines that the authentication has failed, the process proceeds to S1517, and displays on the display unit 202 that the authentication result was a failure and the reason for the failure. This is an example of the display shown in FIG. 14(e). The information processing device 200 then displays the original menu screen in S1516, and ends this process.
[0133] On the other hand, if the information processing apparatus 200 determines in S1508 that the authentication is successful, the process advances to S1509. In S1509, the information processing apparatus 200 displays on the display unit 202 the screen of FIG. 14(d) indicating that the authentication result is successful. The screen of FIG. 14(d) includes a message 1443 asking the user whether to shift to IEEE802.1X / EAP connection, and a "Yes" button 1441 and a "No" button 1442 for making the selection.
[0134] In S1510, the information processing apparatus 100 waits until the "Yes" button 1441 or the "No" button 1442 on the screen of FIG. 14(d) is pressed. If any button has been pressed, the information processing device 100 advances the process to S1551 and determines which button has been pressed. That is, in S1551, the information processing device 200 determines whether the user has requested a transition to an IEEE802.1X / EAP connection or a request to cancel the transition.
[0135] If the user requests transition to IEEE802.1X / EAP connection on the screen of FIG. Send an IEEE802.1X / EAP connection request to. Note that this connection request means that the IEEE802.1X / EAP connection will be used permanently from now on, so when the MFP 300 receives the connection request, the P2P connection is automatically disabled. Therefore, these setting screens by the web browser or application in the information processing device 200 cannot be used until the user intentionally disables the IEEE802.1X / EAP connection and enables the P2P connection. Therefore, a message is displayed on the screen in FIG. 14(d) indicating that if the "Yes" button 1441 is pressed, the application will be automatically terminated because communication with the MFP 300 will be disconnected. Further, in S1513, the information processing device 200 closes the screen or the application when the time has elapsed.
[0136] If the user requests to cancel the transition to IEEE802.1X / EAP connection on the screen of FIG. Proceed. In S1515, information processing device 200 transmits an IEEE802.1X / EAP connection cancellation request to MFP 300.
[0137] Further, the information processing device 200 displays the screen shown in FIG. 14(d) and measures the elapsed time when the user leaves the "Yes" button 1441 and the "No" button 1442 unpressed (S1514). ). Even if that time has passed, the information processing device 200 assumes that the user has no intention of making an IEEE802.1X / EAP connection, advances the process from S1514 to S1515, and cancels the IEEE802.1X / EAP connection to the MFP 300. Submit your request. Therefore, message 1443 indicates that the IEEE802.1X / EAP connection will be automatically terminated in 10 seconds. After that, the information processing device 200 advances the process to S1516, displays the menu screen before AP search (FIG. 12(k)), and ends the process of this flow.
[0138] [Example of authentication result] FIG. 16 shows an example of a correspondence table showing authentication results and display messages in the embodiment. In S1319 of FIG. 13, the states when the MFP 300 transmits an authentication request to the authentication server and executes authentication processing are listed in the status column. The ID column is an identifier for uniquely identifying each state. The message string is the display text that should be notified to the user in each state.
[0139] As described above, according to the present embodiment, the user of the information processing device 200 can perform settings and operations for the MFP 300 up to IEEE802.1X / EAP connection only by remote control from the information processing device 200. be able to.
[0140] (Other examples) In the above description, when an AP search request is received from the information processing device 200, the authentication result is sent to the information processing device 200, and when the AP search request is accepted by the operation on the operation display unit 302, the information processing device 200 explained the form in which the authentication results are not sent. However, the present invention is not limited to this form, and even when an AP search request is accepted by operating the operation display unit 302, the authentication result is sent to the information processing apparatus 200 at the timing when the information processing apparatus 200 and the MFP 300 are connected. Good too.
[0141] Although the names of the individual elements or functional units explained in the above-described embodiments are expressed based on the main function in this specification, they may be expressed based on the sub-function. Therefore, the present invention is not strictly limited to this expression (the expression can be replaced with a similar expression).
[0142] The present invention provides a system or device with a program that implements one or more functions of the embodiments described above via a network or a storage medium, and one or more processors in the computer of the system or device reads and executes the program. This can also be achieved by processing. It can also be realized by a circuit (eg, ASIC) that realizes one or more functions.
[0143] The disclosure of this specification includes the following communication device, its control method, and program. (Item 1) A communication device that communicates with an external information processing device, A communication means capable of selecting either a first communication mode or a second communication mode and communicating in the selected communication mode; control means for controlling the communication means and performing predetermined authentication; When the control means receives information for connection with the access point corresponding to the predetermined authentication from the information processing device in the first communication mode via the communication means, disconnecting communication in the first communication mode; performing authentication in a second communication mode using the authentication information and storing the result of the authentication; disconnecting the second communication mode and transitioning to communication in the first communication mode; transmitting the stored authentication result to the information processing device; A communication device characterized by: (Item 2) 2. The communication device according to item 1, wherein the control means performs authentication using a predetermined authentication server during communication in the second communication mode. (Item 3) The control means includes: storing identification information for identifying an information processing device when authentication information for performing authentication processing in the second communication mode is received from the information processing device in the first communication mode via the communication means; death, If the identification information of the information processing device obtained through communication in the first communication mode when transitioning from the second communication mode to the first communication mode matches the stored identification information, Send the authentication result The communication device according to item 1 or 2, characterized in that: (Item 4) The control means cancels the connection in the second communication mode when a preset time has elapsed after transmitting the authentication result. 4. The communication device according to any one of items 1 to 3, characterized in that: (Item 5) The control means includes: If authentication information for performing authentication processing in the second communication mode is received from an external information processing device in the first communication mode via the communication means, in the second communication mode, performing a search for access points and transmitting a list of access points obtained through the search to the information processing device that has transmitted the authentication information; After receiving the selection of an access point from the information processing device that has transmitted the authentication information, disconnecting the first communication mode and performing authentication in the second communication mode. 5. The communication device according to any one of items 1 to 4, characterized in that: (Item 6) 6. The communication device according to any one of items 1 to 5, wherein the first communication mode is a P2P mode, and the second communication mode is IEEE802.1X / EPA. (Item 7) 7. The communication device according to any one of items 1 to 6, comprising a printing means for use by the information processing device. (Item 8) 8. The communication device according to any one of items 1 to 7, wherein in communication in the first communication mode, the communication device communicates with the information processing device as an HTTP server. (Item 9) A communication device that is capable of selecting either a first communication mode or a second communication mode, has communication means for communicating in the selected communication mode, and communicates with an external information processing device via the communication means. A control method, a control step for controlling the communication means and performing predetermined authentication; In the control step, when information for connection with an access point corresponding to the predetermined authentication is received from the information processing device in a first communication mode via the communication means, disconnecting communication in the first communication mode; performing authentication in a second communication mode using the authentication information and storing the result of the authentication; disconnecting the second communication mode and transitioning to communication in the first communication mode; transmitting the stored authentication result to the information processing device; A method for controlling a communication device, characterized in that: (Item 10) A program that, when read and executed by a computer, causes the computer to function as each means of the apparatus described in any one of items 1 to 8.
[0144] The invention is not limited to the embodiments described above, and various changes and modifications can be made without departing from the spirit and scope of the invention. Therefore, the following claims are hereby appended to disclose the scope of the invention. [Explanation of symbols]
[0145] 200...Information processing device, 300...MFP, 700...Access point, 800...Authentication server
Claims
1. A communication device capable of communicating with an information processing device, comprising: first transmission means for transmitting to the information processing device information for displaying a setting screen for receiving input of setting information regarding EAP authentication, which is authentication based on IEEE 802.1X / EAP (Extensible Authentication Protocol); receiving means for receiving the setting information input to the setting screen from the information processing device; trial means for attempting EAP authentication with a predetermined authentication server based on the setting information input to the setting screen; second transmission means for transmitting to the information processing device information for displaying a screen based on the fact that the EAP authentication has failed, based on the fact that the EAP authentication has failed; A communication device characterized by comprising the above.
2. The communication device according to claim 1, wherein the screen based on the fact that the EAP authentication has failed includes an area for indicating to the user that the EAP authentication has failed.
3. The communication device according to claim 1, wherein the screen based on the fact that the EAP authentication has failed includes an area for indicating to the user the reason why the EAP authentication has failed.
4. The communication device according to claim 3, wherein the reason why the EAP authentication has failed includes at least one of the fact that the client certificate is invalid, the fact that the certificate of the authentication server has expired, and the occurrence of a client authentication error.
5. The communication device according to claim 1, wherein the EAP authentication is attempted after the communication device corresponding to IEEE 802.1X / EAP is connected to an access point.
6. The communication device according to claim 1, further comprising receiving means for receiving a request for execution of the EAP authentication, wherein the EAP authentication is executed when the request is received.
7. When the request is received while the communication device operating in the first communication mode is connected to another device, the connection based on the first communication mode is disconnected, and then the EAP authentication is attempted. When the request is received while the communication device operating in the second communication mode is connected to the other device, the EAP authentication is attempted without disconnecting the connection based on the second communication mode. The communication device according to claim 6, characterized in that. The communication device according to claim 7, further comprising re - establishment means for re - establishing a connection based on the first communication mode after the EAP authentication is attempted after the connection based on the first communication mode is disconnected. The communication device according to claim 8, wherein information for displaying a screen based on the fact that the EAP authentication has failed is transmitted via the connection based on the first communication mode that has been re - established. The communication device according to claim 7, wherein the connection based on the first communication mode is at least one of a wireless connection with another device corresponding to authentication in the Personal mode and a wireless connection with another device by peer - to - peer. The communication device according to claim 7, wherein the connection based on the second communication mode is at least one of a connection with another device by a wired LAN and a connection with another device by USB. The communication device according to claim 6, wherein the request is received by communication between the communication device and another device. The communication device according to claim 1, further comprising third transmission means for transmitting information for displaying a screen based on the fact that the EAP authentication has succeeded to the information processing device when the EAP authentication has succeeded. The communication device according to claim 1, further comprising display means for displaying a screen based on the fact that the EAP authentication has failed on a display unit of the communication device when the EAP authentication has failed. The communication device according to claim 1, wherein the setting information includes at least one of information on an authentication method used for the EAP authentication, information on a user name used for the EAP authentication, information on a password used for the EAP authentication, and information on a certificate used for the EAP authentication. The communication device according to claim 1, wherein the information for displaying the setting screen is transmitted to the information processing device by inputting the IP address of the communication device in a WEB browser operating on the information processing device. The communication device according to claim 1, further comprising printing means for executing printing. The communication device according to claim 1, further comprising scanning means for reading a document and acquiring image data. A control method for an information processing device capable of communicating with a communication device, comprising: a first display step of displaying a setting screen for receiving input of setting information regarding EAP authentication, which is authentication based on IEEE 802.1X / EAP (Extensible Authentication Protocol); a transmission step of transmitting the setting information input to the setting screen to the communication device; a second display step of displaying a screen based on the fact that the EAP authentication with a predetermined authentication server attempted by the communication device based on the setting information input to the setting screen has failed; A control method characterized by comprising: A control method for a system including an information processing device and a communication device, wherein the communication device has a first transmission step of transmitting information for displaying a setting screen for receiving input of setting information regarding EAP authentication, which is authentication based on IEEE 802.1X / EAP (Extensible Authentication Protocol), to the information processing device; the information processing device when receiving information for displaying the setting screen, has a first display step of displaying the setting screen; and a second transmission step of transmitting the setting information input to the setting screen to the communication device; the communication device has a reception step of receiving the setting information input to the setting screen from the information processing device; a trial step of attempting EAP authentication with a predetermined authentication server based on the setting information input to the setting screen; and a third transmission step of transmitting information for displaying a screen based on the fact that the EAP authentication has failed to the information processing device based on the fact that the EAP authentication has failed; the information processing device when receiving information for displaying a screen based on the fact that the EAP authentication has failed, has a second display step of displaying a screen based on the fact that the EAP authentication has failed; A control method characterized by comprising: