Communication device, control method thereof, and program
Patent Information
- Application Number
- JP2022088877
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-05-31
- Publication Date
- 2025-06-02
- Estimated Expiration
- 2042-05-31
AI Technical Summary
Existing communication technologies face challenges in balancing convenience and security when establishing connections between communication devices and external devices, particularly in the context of secure authentication using the Device Provisioning Protocol (DPP).
A communication device that includes standby, output, and updating mechanisms to manage public key information for authentication, with timed protocols to ensure security and convenience by periodically updating keys and adjusting standby durations based on user interaction.
Enhances both convenience and security in device connections by improving authentication reliability and reducing the risk of unauthorized access through timed key updates and standby adjustments.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a communication device, a control method thereof, and a program. [Background technology]
[0002] There is known a technology for connecting a communication device such as a printer to an external device such as an access point using an information processing device such as a PC (personal computer) or a smartphone. Patent Document 1 proposes that, in connecting a communication device to an external device, network information is transmitted and received between the devices using the Device Provisioning Protocol (hereinafter, referred to as DPP) established by the Wi-Fi Alliance. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2019-180036 Summary of the Invention [Problem to be solved by the invention]
[0004] The above-mentioned conventional technology proposes that information about an external device held by an information processing device be provided to the communication device using DPP, thereby easily establishing a connection between the communication device and the external device. The above-mentioned conventional technology also shows an example in which, in DPP-based bootstrapping, an enrollee provides bootstrap information including a public key to a configurator using a QR code (registered trademark). Secure authentication is then achieved by trusting this key pair of a public key and a private key. Specifically, authentication is performed based on the key pair in DPP authentication, and security is ensured by encryption using a shared key. When establishing a connection between a communication device and an external device, it is desirable to achieve both improved convenience by easily establishing a connection and improved security.
[0005] The present invention provides a technique for achieving both improved convenience and improved security when establishing a connection between a communication device and an external device. [Means for solving the problem]
[0006] According to the present invention, a waiting means for waiting for first information for connecting to a first external device to be transmitted from a second external device using a predetermined communication protocol; an output means for outputting second information including public key information used for authenticating communication with the second external device according to the predetermined communication protocol in a standby state of the standby means; an update unit that updates the public key information output by the output unit in the standby state. A communication device is provided. [Effects of the Invention]
[0007] According to the present invention, it is possible to achieve both improved convenience and improved security in establishing a connection between a communication device and an external device. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is a diagram showing the configuration of a system according to an embodiment. [Figure 2] FIG. 10 is a sequence diagram showing the processing of the information processing device and the communication device 151. [Figure 3] FIG. 10 is a diagram showing an example of a screen of an information processing device. [Figure 4] 10A to 10F are diagrams showing examples of a UI (User Interface) of a communication device. [Figure 5] 10 is a flowchart showing an example of control of a communication device. [Figure 6] 10 is a flowchart showing an example of control of a communication device. [Figure 7] 10 is a flowchart showing an example of control of a communication device. [Figure 8] 10 is a flowchart showing an example of control of a communication device. DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention claimed. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.
[0010] [First embodiment] First, an information processing device and a communication device included in the communication system of this embodiment will be described. In this embodiment, a smartphone is used as an example of the information processing device, but this is not limiting. For example, various devices such as a mobile terminal, a PC (personal computer), a tablet terminal, a PDA (personal digital assistant), and a digital camera can be used as the information processing device.
[0011] Furthermore, although a printer is used as an example of a communication device in this embodiment, the present invention is not limited to this and various devices capable of wireless communication with an information processing device can be applied. For example, printers can be applied to inkjet printers, full-color laser beam printers, monochrome printers, etc. Furthermore, in addition to printers, the present invention can be applied to copiers, facsimile machines, mobile terminals, smartphones, notebook PCs, tablet terminals, PDAs, digital cameras, music playback devices, televisions, smart speakers, etc. In addition, the present invention can be applied to multifunction peripherals having multiple functions such as a copying function, a fax function, and a printing function.
[0012] In this embodiment, the information processing device and the communication device are capable of wireless communication based on a standard such as Wi-Fi (registered trademark), which is a communication standard conforming to the IEEE802.11 series.
[0013] In this embodiment, the information processing device is assumed to support a function called Wi-Fi Easy Connect (hereinafter, WEC). WEC is a function that executes network setup of other devices using the Device Provisioning Protocol (hereinafter, DPP) established by the Wi-Fi Alliance. Specifically, the network setup of other devices is a process of connecting the other devices to an access point that forms a network with the other devices.
[0014] In WEC, communication takes place between a device that acts as a "Configurator" (hereafter referred to as the "Configurator device") and a device that acts as an "Enrollee" (hereafter referred to as the "Enrollee device"). The Configurator device obtains bootstrapping information from the Enrollee device. Bootstrapping information includes, for example, the Enrollee device's identification information (MAC address, etc.) and public key information used for secure communication with the Enrollee device.
[0015] In this embodiment, the bootstrapping information will be described as "WEC-related information." Note that other information may also be treated as WEC-related information. The Configurator device then uses the acquired bootstrapping information to perform wireless communication with the Enrollee device. Specifically, for example, the Configurator device encrypts a protocol key using the public key included in the bootstrapping information and transmits the encrypted protocol key to the Enrollee device. The Configurator device then encrypts a common key based on the encrypted protocol key and transmits information encrypted using the common key to the Enrollee device. Note that the information transmitted here is, for example, connection information for connecting to an access point. The Enrollee device then establishes a wireless connection with the access point using the connection information received from the Configurator device.
[0016] In the network setup using WEC in this embodiment, the information processing device that supports WEC will be described as operating as a configurator device, and the communication device that supports WEC will be described as operating as an enrollee device.
[0017] <System configuration> First, the configuration of a system including an information processing device 101 according to this embodiment and a communication device 131 capable of communicating with the information processing device 101 will be described with reference to the block diagram of Fig. 1. In addition, the following description will be given using the configuration shown in Fig. 1 as an example, but the functions are not particularly limited to those shown in this diagram.
[0018] (Information processing device) The information processing device 101 includes an input interface 102, a CPU 103, a ROM 104, a RAM 105, an external storage device 106, output interfaces 107 and 108, a communication unit 110, a short-range wireless communication unit 111, and an imaging unit 112. The CPU 103, the ROM 104, the RAM 105, etc. form a computer of the information processing device 101.
[0019] The input interface 102 is an interface for receiving data inputs and operation instructions from a user by operating an operation unit such as a keyboard 109. The operation unit may be a physical keyboard, physical buttons, etc., or a soft keyboard, soft buttons, etc. displayed on the display unit 108. In other words, the input interface 102 may receive inputs from the user via the display unit 108.
[0020] The CPU 103 is a system control unit that controls the entire information processing device 101 .
[0021] The ROM 104 stores fixed data such as control programs and data tables executed by the CPU 103, and embedded operating system (hereinafter referred to as OS) programs. In this embodiment, each control program stored in the ROM 104 controls software execution such as scheduling, task switching, and interrupt processing under the management of the embedded OS stored in the ROM 104.
[0022] The RAM 105 is configured with an SRAM (Static Random Access Memory) or the like that requires a backup power source. Note that the RAM 105 holds data using a primary battery (not shown) for data backup, so that important data such as program control variables can be stored without volatilization. The RAM 105 also has a memory area for storing setting information for the information processing device 101, management data for the information processing device 101, and the like. The RAM 105 is also used as the main memory and work memory for the CPU 103.
[0023] The external storage device 106 stores an application program (hereinafter, a setting application) for executing network setup of the communication device 151, a print information generation program for generating print information that can be interpreted by the communication device 151, and the like. In this embodiment, the setting application is an application program for configuring an access point to which the communication device 151 is connected using a WEC or the like. The setting application may have functions other than the network setup function. For example, the setting application may have a function for causing the communication device 151 to execute printing, a function for causing a document placed in the communication device 151 to be scanned, a function for checking the status of the communication device 151, and the like. The setting application is stored in the external storage device 106 by being installed from an external server, for example, via Internet communication via the communication unit 110. The external storage device 106 also stores various programs, such as an information transmission / reception control program, transmitted and received between the communication device 151 connected via the communication unit 110 and the communication device 151, as well as various information used by these programs.
[0024] The output interface 107 is an interface that controls the display unit 108 to display data and notify the status of the information processing device 101 .
[0025] The display unit 108 is configured with an LED (light emitting diode) and an LCD (liquid crystal display), and displays data and notifies the status of the information processing device 101.
[0026] The communication unit 110 is configured to connect to devices such as the communication device 151 and the access point 131 to perform data communication. For example, the communication unit 110 can connect to an access point (not shown) within the communication device 151. By connecting the communication unit 110 to the access point within the communication device 151, the information processing device 101 and the communication device 151 can communicate with each other. The communication unit 110 may communicate directly with the communication device 151 via wireless communication, or may communicate via an external device located outside the information processing device 101 or the communication device 151. The external device includes an external access point (such as the access point 131) located outside the information processing device 101 and the communication device 151, and a device other than an access point that can relay communication. In this embodiment, the wireless communication method used by the communication unit 110 is based on the Wi-Fi (registered trademark) standard. The above-mentioned WEC is performed through communication by the communication unit 110. The access point 131 may be, for example, a device such as a wireless LAN router. In this embodiment, a connection method in which the information processing device 101 and the communication device 151 are connected directly without going through an external access point is called a direct connection. Also, a connection method in which the information processing device 101 and the communication device 151 are connected through an external access point is called an infrastructure connection.
[0027] The short-range wireless communication unit 111 is configured to perform data communication by wirelessly connecting to a device such as the communication device 151 at a short distance, and performs communication using a communication method different from that of the communication unit 110. The short-range wireless communication unit 111 can be connected to, for example, a short-range wireless communication unit 157 in the communication device 151. Examples of communication methods include Near Field Communication (NFC), Bluetooth (registered trademark) Classic, Bluetooth Low Energy (BLE), and Wi-Fi Aware.
[0028] The photographing unit 112 is, for example, a camera, and operates when a photographing function is executed by an application running on the information processing device 101. When the photographing function is executed by the application, for example, information acquired from the photographing unit 112 is processed by the CPU 103 and displayed as a live view on the display unit 108. Here, when a photographing operation is executed by the application, the information acquired from the photographing unit 112 is processed by the CPU 103 and saved as a photographed image in the RAM 105. Furthermore, when a QR code acquisition function is executed by the application, the information acquired from the photographing unit 112 is processed by the CPU 103 and analyzed as a QR code (registered trademark), and various pieces of information included in the QR code (registered trademark) are acquired.
[0029] In this embodiment, the information processing apparatus 101 executes the WEC using the OS of the information processing apparatus 101 based on a WEC execution instruction from the setting application.
[0030] (Communication equipment) The communication device 151 is a communication device of this embodiment. The communication device 151 includes a ROM 152, a RAM 153, a CPU 154, a print engine 155, a scan engine 162, an input interface 158, an output interface 160, an operation unit 159, a display unit 161, a communication unit 156, and a short-range wireless communication unit 157. The CPU 154, the ROM 152, the RAM 153, and the like form a computer of the communication device 151.
[0031] The CPU 154 is a system control unit that controls the entire communication device 151 .
[0032] The ROM 152 stores fixed data such as control programs, data tables, and OS programs executed by the CPU 154. In this embodiment, each control program stored in the ROM 152 controls software execution such as scheduling, task switching, and interrupt processing under the management of the embedded OS stored in the ROM 152.
[0033] The RAM 153 is composed of an SRAM or the like that requires a backup power source. Since the RAM 153 holds data using a primary battery (not shown) for data backup, it can store important data such as program control variables without volatilizing it. The RAM 153 also has a memory area for storing setting information for the communication device 151, management data for the communication device 151, and the like. The RAM 153 is also used as the main memory and work memory for the CPU 154, and stores a receive buffer for temporarily storing print information received from the information processing device 101, etc., as well as various other information.
[0034] Note that the communication device 151 may be equipped with an optional memory such as an external HDD or SD card, and the information stored in the communication device 151 may be stored in the memory.
[0035] The print engine 155 forms an image on a recording medium such as paper by applying a recording agent such as ink to the recording medium based on information stored in the RAM 153 and a print job received from the information processing device 101 or the like, and outputs the print result. Generally, the amount of data in a print job transmitted from the information processing device 101 or the like is large, so a communication method capable of high-speed communication is required for communicating the print job. Therefore, the communication device 151 receives the print job via the communication unit 156, which is capable of communication at higher speeds than the short-range wireless communication unit 157.
[0036] The scan engine 162 reads image data or document data from a set document or the like based on input from the operation unit 158 or a scan job received from the information processing device 101 or the like. The read data is stored in the RAM 153 as a scan result or transmitted to the information processing device 101 or the like. Generally, the amount of data of the scan result transmitted from the communication device 151 to the information processing device 101 or the like is large, so a communication method capable of high-speed communication is required for such communication. Therefore, the communication device 151 transmits the scan result via the communication unit 156, which is capable of communication at higher speeds than the short-range wireless communication unit 157.
[0037] The input interface 158 is an interface for receiving data inputs and operation instructions from a user by operating an operation unit 159 such as a physical button. Note that the operation unit 159 may be a soft keyboard, soft buttons, or the like displayed on the display unit 161. In other words, the input interface 158 may receive inputs from the user via the display unit 161.
[0038] The output interface 160 is an interface that controls the display unit 161 to display various data and notify the status of the communication device 151 .
[0039] Display unit 161 is configured with an LED (light emitting diode), an LCD (liquid crystal display), etc., and displays data and notifies the status of communication device 151. Note that in this embodiment, a case will be described in which operation unit 159 and display unit 161 are configured as an operation display unit made up of a touch panel display.
[0040] The communication unit 156 has an access point as an internal access point of the communication device 151 for connecting to devices such as the information processing device 101. The access point can be connected to the communication unit 110 of the information processing device 101. When the communication unit 156 enables the access point, the communication device 151 operates as an access point. The communication unit 156 may wirelessly connect to the information processing device 101 directly or via the access point 131. In this embodiment, the wireless communication method used by the communication unit 156 is a communication standard conforming to the IEEE 802.11 series. In the following description, Wi-Fi (registered trademark) (Wireless Fidelity) is a communication standard conforming to the IEEE 802.11 series. If the communication device 151 supports WEC, the WEC described above is executed through communication by the communication unit 156. The communication unit 156 may be provided with hardware that functions as an access point, or may operate as an access point using software that causes it to function as an access point.
[0041] The communication device 151 of this embodiment is operable in infrastructure mode and P2P (Peer to Peer) mode as modes for performing communication using the communication unit 156.
[0042] The infrastructure mode is a mode in which the communication device 151 communicates with other devices such as the information processing device 101 via an external device (e.g., the access point 131) that forms a network. That is, the infrastructure mode is a mode in which the communication device 151 establishes an infrastructure connection with the information processing device 101 via an external access point (the access point 131). In this embodiment, in the infrastructure connection, the communication device 151 operates as a slave station, and the external access point operates as a master station. In this embodiment, the master station is a device that determines a communication channel to be used in the network to which the master station belongs, and the slave station is a device that does not determine a communication channel to be used in the network to which the slave station belongs, but uses the communication channel determined by the master station.
[0043] The P2P mode is a mode in which the communication device 151 communicates directly with other devices, such as the information processing device 101, without going through an external device that forms a network. That is, the P2P mode is a mode in which the communication device 151 establishes a direct connection with the information processing device 101 without going through an external access point (access point 131). In this embodiment, in the P2P mode, for example, the communication device 151 may communicate with other devices using Wi-Fi DIRECT (registered trademark) (hereinafter, WFD). Note that which of multiple WFD-compatible devices will act as the master station is determined, for example, according to a sequence called Group Owner Negotiation. Note that the master station may be determined without executing Group Owner Negotiation. A WFD-compatible device that acts as the master station is particularly referred to as a Group Owner. Other examples of the P2P mode include AP mode and ad hoc mode in which the communication device 151 acts as an access point and communicates according to the normal Wi-Fi standard. The user may be able to arbitrarily set connection information (SSID and password) of the access point that is enabled in communication device 151 in AP mode. In this embodiment, in a direct connection, communication device 151 operates as a parent station, and other devices operate as child stations.
[0044] In addition, in this embodiment, the communication device 151 can operate in a network setup mode, which is a mode for performing network setup of the communication device 151, by receiving a predetermined operation from the user. When operating in the network setup mode, the communication device 151 operates as a setup access point that is valid while operating in the network setup mode, by using the communication unit 156. The setup access point is an access point that is different from the access point that is valid in the AP mode described above. The SSID of the setup access point includes a predetermined character string that can be recognized by the setting application of the information processing device 101. The setup access point is an access point that does not require a password for connection. The communication device 151 operating in the network setup mode uses a predetermined communication protocol (setup communication protocol) to communicate with the information processing device 101 connected to the setup access point. A specific example of the setup communication protocol is SNMP (Simple Network Management Protocol). Another specific example of the setup communication protocol is HTTP (Hypertext Transfer Protocol). After starting operation in the network setup mode, the communication device 151 stops operation in the network setup mode and disables the setup access point after a predetermined time has elapsed. This is because, as described above, the setup access point is an access point that does not require a password, and if it is enabled for a long period of time, there is a high possibility that an inappropriate device will request connection. Note that the setup access point may be an access point that requires a password. In this case, the password used to connect to the setup access point is a fixed password (that cannot be changed by the user) that is known in advance by the setting application.
[0045] Furthermore, in this embodiment, communication device 151 can also operate in a mode for executing network setup of communication device 151 using a communication protocol different from the setup communication protocol. In this embodiment, the communication protocol different from the setup communication protocol is the above-mentioned DPP, and this mode is referred to as DPP standby mode. When communication device 151 is operating in DPP standby mode and receives a network setup request using DPP from information processing device 101, it executes network setup using DPP. Therefore, DPP standby mode is, in other words, a mode in which it waits for a network setup request using DPP.
[0046] The short-range wireless communication unit 157 is configured to establish a short-range wireless connection with a device such as the information processing device 101, and can be connected to, for example, the short-range wireless communication unit 111 in the information processing device 101. Examples of communication methods include NFC, Bluetooth Classic, BLE, and Wi-Fi Aware.
[0047] <Example of a sequence between an information processing device and a communication device> 2 and 3, the processing executed by the information processing device 101 and the communication device 151 in a WEC using DPP will be described. The sequence shown in Fig. 2 is realized, for example, by the CPU of each device reading out a program stored in the ROM of each device or an external storage device into the RAM of each device and executing it.
[0048] In S200, communication device 151 starts DPP standby mode. A trigger for starting DPP standby mode (hereinafter sometimes referred to as a start trigger) may be, for example, a user operation via operation unit 159, or the receipt of a specific signal from an external device such as information processing device 101. This will be described in more detail below. When DPP standby mode starts, communication device 151 outputs WEC-related information. An example of outputting WEC-related information is when communication device 151 generates a QR code (registered trademark) based on the WEC-related information and displays the generated QR code (registered trademark) on display unit 161. Note that instead of a QR code (registered trademark), another code such as a barcode may be generated and displayed on display unit 161. From the time communication device 151 starts DPP standby mode until it ends DPP standby mode through processing described below, communication device 151 remains in a standby state in which it waits to receive connection information (SSID, password, etc.) required for connecting to an access point from information processing device 101.
[0049] In S201, bootstrapping is performed between the information processing device 101 and the communication device 151. More specifically, the information processing device 101 acquires WEC-related information through bootstrapping. For example, when a QR code (registered trademark) is used for bootstrapping, the information processing device 101 executes a QR code capturing function in the setting app. The QR code capturing function uses the image capturing unit 112 to capture an image of the QR code (registered trademark), and analyzes the QR code (registered trademark) from the captured image. This allows the setting app to acquire the WEC-related information included in the QR code (registered trademark).
[0050] In S202, the information processing device 101 starts WEC using DPP using a function of the OS. Specifically, the information processing device 101 first starts the WEC app by issuing a startup instruction for the WEC app from the settings app to the OS. As a result, the WEC app runs in the foreground and the settings app runs in the background. Note that, for example, execution of the startup instruction corresponds to an instruction to run WEC. As a result, the information processing device 101 displays a WEC start screen using the WEC app. Note that the WEC app is a program pre-installed in the information processing device 101 and is provided by the OS vendor of the information processing device 101. Furthermore, when the WEC app is started, WEC-related information acquired by the settings app is provided to the WEC app.
[0051] FIG. 3 shows an example of a WEC start screen displayed by a WEC application. Areas 301, 302, and 303 are displayed on the WEC start screen 300. Area 301 is an area for changing the access point set as the WEC configuration target. Note that before area 301 is operated, the access point set as the WEC configuration target is the access point to which the information processing device 101 is currently connected. When area 301 is selected, the information processing device 101 displays a list of access points and sets the access point selected by the user from the list as the new WEC configuration target. Note that the access point list includes access points to which the information processing device 101 has previously connected. Area 302 is an area for canceling WEC execution, and area 303 is an area for instructing WEC execution. When area 302 is operated, the information processing device 101 ends the processing in this sequence diagram. When area 303 is pressed, the information processing device 101 proceeds to step S203.
[0052] In S203, a process called DPP Authentication is executed between the information processing device 101 and the communication device 151 by a function of the OS of the information processing device 101. Specifically, the WEC application of the information processing device 101 instructs the OS to execute WEC by executing an API for WEC using WEC-related information and information about an access point set as a target for WEC configuration. Then, DPP Authentication is executed between the information processing device 101 and the communication device 151 by a function of the OS. In DPP Authentication, authentication information, information used for encrypting information, and the like are communicated between the information processing device 101 and the communication device 151, thereby authenticating communication between the devices. Note that various pieces of information transmitted from the information processing device 101 during communication in DPP Authentication are encrypted based on WEC-related information acquired by the information processing device 101 from the communication device 151. In DPP Authentication, specifically, first, the information processing device 101 transmits an Authentication Request as a network setup request according to DPP. Next, communication device 151, which is operating in DPP standby mode, receives the Request sent from information processing device 101 because it is operating in DPP standby mode, which is a mode that waits for an Authentication Request. Having received the Authentication Request, communication device 151 attempts to decrypt the received Request using the decryption key that it currently possesses. If the decryption is successful, communication device 151 transmits an Authentication response to information processing device 101 and authenticates communication with information processing device 101. Note that if information processing device 101 has not acquired accurate WEC-related information and has not been able to encrypt information accurately, decryption in communication device 151 will fail, authentication will fail, and an Authentication response will not be sent. DPP Authentication is completed when information processing device 101 receives the Authentication response.In addition, in DPP Authentication, communication is performed using DPP.
[0053] In S204, a process called DPP Configuration is executed between the information processing device 101 and the communication device 151 by a function of the OS of the information processing device 101. In DPP Configuration, the information processing device 101 transmits connection information for connecting to an access point set as a target for configuration by WEC to the communication device 151 using WEC. Note that the connection information may include at least one of the SSID, password, encryption method, and the like of the access point set as a target for configuration by WEC. The password transmitted at this time is information entered by the user on a screen displayed by an application compatible with the OS when a connection between the information processing device 101 and the access point is established. The password is information held by the OS when a connection between the information processing device 101 and the access point is established. The password is information not held by the setting application. The password transmitted at this time is information already held by the OS, and DPP Configuration is a process executed by the OS, so there is no need for the user to newly input the password on a screen displayed by the setting application. That is, WEC allows the password as connection information to be transmitted from the information processing device 101 to the communication device 151 through secure communication without requiring a new password to be entered on the screen displayed by the setting application. Note that DPP is also used to execute communication in DPP Configuration.
[0054] In S205, communication device 151 ends the DPP standby mode in response to the completion of DPP Configuration.
[0055] In S206, the communication device 151 transitions to infrastructure mode after successfully acquiring connection information using the DPP Configuration. Then, using the connection information acquired in S204, the communication device 151 attempts to connect to the access point corresponding to the connection information. If the connection is successful, the communication device 151 can then perform communication via the network formed by the connected access point. Note that communication via the network formed by the connected access point is performed using a protocol different from DPP (specifically, for example, Port9100, SNMP, HTTP, or a protocol unique to the vendor of the communication device 151).
[0056] The communication device 151 may transmit, to the information processing device 101, information indicating whether or not a connection with an access point corresponding to the connection information acquired by WEC was successful. Furthermore, if a connection with an access point corresponding to the connection information acquired by WEC fails, the communication device 151 may transmit, to the information processing device 101, information indicating the cause of the failure. This information transmission may be performed using DPP. The cause of a failure in a connection with an access point corresponding to the connection information acquired by WEC may include a communication error in WEC, the access point not being found, or the WEC-related information acquired from the communication device 151 being inappropriate. Another example of a failure may be an encryption method used in a connection with an access point set as a configuration target by WEC that is not supported by the communication device 151. Another example of a failure may be an encryption method used in a connection with an access point set as a configuration target by WEC that is not supported by the WEC. The information processing device 101 may display, on the display unit 108, information indicating whether or not a connection between the communication device 151 and the access point corresponding to the connection information acquired by WEC was successful. Furthermore, if the connection between the communication device 151 and the access point corresponding to the connection information acquired by WEC fails, information indicating the cause of the failure may be displayed on the display unit 108.
[0057] In step S207, an infrastructure connection is established between the information processing device 101 and the communication device 151. Specifically, based on the completion of the WEC execution, the information processing device 101 switches the application running in the foreground from the WEC application to the setting application. Then, the information processing device 101 searches for the communication device 151 on the network to which the information processing device 101 belongs. This process is implemented by the setting application that receives a notification from the OS that the WEC execution has completed. When the information processing device 101 finds the communication device 151, it requests capability information from the communication device 151, and the communication device 151 transmits the capability information to the information processing device 101. This registers information about the communication device 151 in the setting application, and thereafter, communication with the communication device 151 becomes possible using the setting application. Specifically, for example, the setting application makes it possible to send a print job to the communication device 151. At this time, if the information processing device 101 belongs to a network formed by an access point to which the communication device 151 is connected by WEC, communication with the communication device 151 becomes possible via that access point. If communication between the information processing device 101 and the communication device 151 cannot be performed, for example, if the access point to which the communication device 151 is connected is not the access point to which the information processing device 101 is connected, the request and acquisition of capability information is omitted. The communication in S207 is performed using, for example, a communication protocol different from the DPP and the setup communication protocol. The information processing device 101 then terminates the processing in this sequence diagram.
[0058] Although the above description assumes that the WEC app displays the WEC start screen and the WEC app executes the WEC API to instruct the OS to run WEC, this is not a limitation. For example, the WEC start screen may be displayed by a settings app. Alternatively, the settings app may execute the WEC API to instruct the OS to run WEC. Although the method using a QR code (registered trademark) as a means of bootstrapping has been exemplified here, the present invention is not limited to this. For example, short-range wireless communication such as NFC or BLE may be used as a means of bootstrapping. Alternatively, communication using a communication protocol such as SNMP or HTTP via a setup access point activated in DPP standby mode may be used as another means.
[0059] As described above, when attempting to connect to an external access point, communication device 151 enters DPP standby mode and waits for information about the access point to be connected to from information processing device 101 while outputting WEC-related information. From the perspective of ensuring security, DPP standby mode can be set to time out after a certain period of time, but from the perspective of user convenience, a longer standby period is preferable. This is because a short standby period can result in an unintended timeout, requiring the user to perform an operation to re-enter DPP standby mode. Therefore, in order to achieve both user convenience and security, communication device 151 of this embodiment performs the processing shown in FIG. 5 and provides UIs such as those shown in FIGS. 4(a) to 4(f).
[0060] <Example of communication device UI> 4(a) to 4(f) are diagrams showing examples of a UI (User Interface) of the communication device 151. Specifically, FIGS. 4(a) to 4(f) show examples of a UI displayed on the communication device 151 when, for example, WEC using DPP is executed. Note that, although an example is shown here in which the operation unit 159 and the display unit 161 are configured as an operation display unit made up of a touch panel display, the configuration of the communication device 151 is not limited to this. Furthermore, because these are merely examples of a UI, the design, wording, details of the UI configuration, and the like can be changed as appropriate.
[0061] 4(a) shows an example of an idle screen 400. The idle screen 400 displays a copy function button 401, a scan function button 402, a wireless LAN easy setting button 403, and an other settings button 404. The copy function button 401 is a button for displaying a menu of the copy function of the communication device 151. The scan function button 402 is a button for displaying a menu of the scan function of the communication device 151. The wireless LAN easy setting button 403 is a button for starting the wireless LAN easy setting function of the communication device 151, and the network setup of the communication device 151 is executed by the wireless LAN easy setting function. In other words, in this embodiment, pressing the wireless LAN easy setting button 403 is one of the triggers for starting the DPP standby mode.
[0062] The start trigger is not limited to pressing the wireless LAN simple setting button 403. For example, it may be a user operation other than the operation via the operation unit 159, or it may be receiving a specific signal from an external device such as the information processing device 101. A specific example of a user operation other than the operation via the operation unit 159 is turning on the power by pressing the power button of the communication device 151. A specific example of receiving a specific signal from an external device such as the information processing device 101 is receiving a specific BLE beacon or receiving a specific wireless LAN communication. The other settings button 404 is a button for displaying a menu of other setting functions of the communication device 151. Here, the processing performed when the copy function button 401, the scan function button 402, and the other settings button 404 are pressed is not included in the processing of the DPP standby mode to be described, and therefore will not be described here.
[0063] 4(b) shows a wireless LAN simple setting processing screen 410. The wireless LAN simple setting processing screen 410 is a screen that is temporarily displayed when starting, stopping, or canceling wireless LAN simple setting, updating WEC-related information, or the like is performed.
[0064] 4(c) shows a wireless LAN easy setting main screen 420. The wireless LAN easy setting main screen 420 is a screen that is primarily displayed when the communication device 151 is operating in DPP standby mode, and displays a WEC-related information area 421 and a cancel button 422. The WEC-related information area 421 is an area that displays WEC-related information. In this embodiment, the WEC-related information is encoded into a QR code (registered trademark) and displayed. This is because, in this embodiment, the WEC-related information is output by displaying a QR code (registered trademark) on the display unit 161.
[0065] Note that if the WEC-related information is output in a different manner, the content displayed in the WEC-related information area 421 may be different. For example, if the WEC-related information is output via near-field communication using NFC, a message such as "Please perform an NFC touch" may be displayed in the WEC-related information area 421. Furthermore, if the WEC-related information is output via communication using a communication protocol such as SNMP or HTTP via a setup access point, a message such as "Please operate the setting app" may be displayed in the WEC-related information area 421. The cancel button 422 is a button for canceling the operation of the communication device 151 in the DPP standby mode. Pressing this button causes the communication device 151 to accept a cancel instruction. That is, in this embodiment, pressing this button serves as one of the triggers for stopping the DPP standby mode (hereinafter, sometimes referred to as a "stop trigger"). Note that the stop trigger is not limited to pressing this button. For example, it may be a user operation other than the operation via the operation unit 159, or it may be receiving a specific signal from an external device such as the information processing device 101. A specific example of a user operation different from the operation via operation unit 159 is a power-off operation by pressing the power button on communication device 151. A specific example of receiving a specific signal from an external device such as information processing device 101 is receiving a specific BLE beacon or receiving a specific wireless LAN communication. DPP standby mode may also be stopped if connection information with an access point required for wireless LAN setup is successfully received by executing processing of the wireless LAN easy setup function. Furthermore, DPP standby mode may also be stopped if a timer indicating the time limit for DPP standby mode times out.
[0066] 4(d) shows a wireless LAN easy setting completion screen 430. The wireless LAN easy setting completion screen 430 is a screen indicating that the wireless LAN easy setting function has been completed, and displays an OK button 431. Pressing the OK button 431 causes the display on the display unit 161 to return to the idle screen 400.
[0067] 4(e) shows a wireless LAN easy setting cancel screen 440. The wireless LAN easy setting cancel screen 440 is a screen indicating that the wireless LAN easy setting function has been stopped by a cancel instruction, and displays an OK button 441. Pressing the OK button 441 returns the display on the display unit 161 to the idle screen 400.
[0068] 4(f) shows a wireless LAN simple setting timeout screen 450. The wireless LAN simple setting timeout screen 450 is a screen indicating that the wireless LAN simple setting has been completed, and displays an OK button 431. Pressing the OK button 431 causes the display on the display unit 161 to return to the idle screen 400.
[0069] <Example of communication device control> 5 is a flowchart showing an example of control of the communication device 151. This flowchart is realized, for example, by the CPU 154 of the communication device 151 reading a program stored in the ROM 152 or the like into the RAM 153 and executing it.
[0070] This flowchart also starts when a start trigger for the DPP standby mode is received. The start trigger is, for example, the user pressing the wireless LAN easy setting button 403. Pressing the wireless LAN easy setting button 403 causes the display unit 161 to transition from the idle screen 161 to a wireless LAN easy setting processing screen 410.
[0071] In S501, the communication device 151 performs processing to start the DPP standby mode. Specifically, the communication device 151 uses the communication unit 156 to start a setup access point (not shown) and prepares for connection and communication for setup with the information processing device 101. Furthermore, the communication device 151 generates WEC-related information to be output by bootstrapping. Here, a public key is present as an element constituting the WEC-related information, and this is based on a key pair of a public key and a private key used in subsequent DPP authentication. This key pair may be generated during the processing to start the DPP standby mode, or may be generated in advance. As a specific example, the key pair may be generated when the communication device 151 is powered on, or may be generated in the background while the idle screen 400 is displayed on the display unit 161. The key pair generated in advance is stored in RAM 153 and read out when the processing of S501 begins. By starting this DPP standby mode, communication device 151 waits for connection information for connecting to an access point (e.g., access point 131) as an external device to be transmitted from information processing device 101 using DPP as a predetermined protocol.
[0072] In S502, the communication device 151 determines whether the start trigger was caused by an operation of the operation unit 159 of the communication device 151 (main body UI operation). If it is determined that the start trigger was caused by an operation of the operation unit 159, the communication device 151 executes S503, and if not, executes S504. An example of a case where the start trigger was not caused by an operation of the operation unit 159 is receiving a specific signal from an external device such as the information processing device 101.
[0073] In S503, a predetermined period (referred to as period TP1) designated as the time limit for the DPP standby mode is set and measurement is started in timer T1 held by communication device 151. Note that the measurement by timer T1 may be based on a hardware timer or a software timer.
[0074] In S504, communication device 151 starts measuring a predetermined period (period TP2) that is specified as the time limit for outputting WEC-related information, in timer T1 held by communication device 151. Here, when the time limit for DPP standby mode (period TP2) is compared with the time limit for WEC-related information (period TP2), it is assumed that the time limit for WEC-related information (period TP2) is shorter.
[0075] Timer T1 is a timer for stopping the DPP standby mode when a timeout occurs. In other words, the flow described in S502 to S504 allows the duration of DPP standby mode started without operation of operation unit 159 to be shorter than the duration of DPP standby mode started by operation of operation unit 159. This takes into consideration the possibility that an attacker at a distant location may remotely activate the DPP standby mode of communication device 151 and attempt to illegally configure a wireless LAN. In this embodiment, the duration of DPP standby mode is shortened when a remote instruction is issued, thereby improving security against remote attacks. On the other hand, when the start trigger is an operation of operation unit 159, which is relatively unlikely to result in a remote attack, the duration of DPP standby mode can be relatively lengthened, thereby improving user convenience.
[0076] In S505, a period TP2 designated as the time limit for the WEC-related information is set in a timer T2 held by the communication device 151, and measurement is started. The timer T2 may be based on a hardware timer or a software timer.
[0077] Timer T2 is a timer for updating WEC-related information when a timeout occurs. In particular, it updates the public and private key pair used in DPP Authentication. By periodically updating the key pair in DPP standby mode, the security of DPP communications can be improved.
[0078] In S506, the communication device 151 sets a period (referred to as period TP3) slightly shorter than the period TP2 specified as the time limit for the WEC-related information in the timer T3 held by the communication device 151, and starts measuring the time. Note that the timer T3 may be based on a hardware timer or a software timer.
[0079] Timer T3 is a timer for stopping the output of WEC-related information prior to updating the WEC-related information when a timeout occurs. In DPP, there can be a slight time lag between when information processing device 101 acquires the WEC-related information output by communication device 151 and when DPP authentication is performed. If communication device 151 updates the WEC-related information during this time lag, authentication failure in DPP authentication is expected. Therefore, by stopping the output of WEC-related information prior to updating the WEC-related information, authentication failure in DPP authentication due to the above-mentioned time lag can be prevented. That is, communication device 151 is switchable in DPP standby mode between an output state in which it outputs WEC-related information and an output stop state in which it stops outputting WEC-related information, based on timers T2 and T3.
[0080] In S507, the communication device 151 starts outputting the generated WEC-related information. In other words, the communication device 151 outputs information including public key information used to authenticate communication with the information processing device 101 using DPP. The display unit 161 transitions from the wireless LAN simple setting processing screen 410 to the wireless LAN simple setting main screen 420. Here, starting the output of the WEC-related information means, for example, encoding the WEC-related information into a QR code (registered trademark) and displaying it in the WEC-related information area 421. Note that output of the WEC-related information may be performed by other methods. For example, the WEC-related information may be stored in a memory area on the RAM 153 that can be read by an external device such as the information processing device 101 using near-field wireless communication such as NFC, thereby making the WEC-related information readable. Furthermore, for example, the WEC-related information may be stored in a memory area on the RAM 153 that can be read by an external device such as the information processing device 101 using protocol communication such as SNMP, thereby making the WEC readable.
[0081] In S508, the communication device 151 enters an event waiting state. Examples of events include exchanges with external devices such as bootstrapping, DPP authentication, and DPP configuration, user operation input, and timeouts of timers T1 to T3. Another example of an event is successful reception of connection information. When an event occurs, the communication device 151 determines the event type through the determinations shown in the following S509, S514, S518, S522, and S525.
[0082] In S509, the communication device 151 determines whether the event that has occurred is successful reception of connection information. The connection information here refers to information such as the SSID and password of the access point 131, acquired from an external device such as the information processing device 101. If the event that has occurred is successful reception of connection information, the communication device 151 proceeds to S510, and if not, the communication device 151 proceeds to S514. A specific example of determining whether reception of connection information has been successful will be described later (see FIG. 6).
[0083] In S510, the communication device 151 stops outputting any WEC-related information that is currently being output. For example, if the communication device 151 is displaying a QR code (registered trademark) as WEC-related information in the WEC-related information area 421 of the wireless LAN simple setting main screen 420 on the display unit 161, the communication device 151 stops displaying the QR code. For example, if the communication device 151 has enabled an external device to read the WEC-related information through near-field wireless communication such as NFC, the communication device 151 clears the WEC-related information stored in a predetermined memory area on the RAM 153 to make the information unreadable. For example, if the communication device 151 has enabled an external device to read the WEC-related information through protocol communication such as SNMP, the communication device 151 clears the WEC-related information stored in a predetermined memory area on the RAM 153 to make the information unreadable. At this time, the display unit 161 transitions from the wireless LAN simple setting main screen 420 to the wireless LAN simple setting processing screen 410.
[0084] In S511, the communication device 151 stops and clears the timers T1 to T3.
[0085] In S512, communication device 151 performs processing to complete DPP standby mode. Specifically, communication device 151 stops the setup access point (not shown) using communication unit 156. Communication device 151 also deletes information such as WEC-related information and key pairs. Then, display unit 161 transitions from wireless LAN simple setting processing screen 410 to wireless LAN simple setting completion screen 430.
[0086] In S513, the communication device 151 performs wireless LAN setting processing. This corresponds to the processing of S206 and S207 in Fig. 2, and therefore detailed description thereof will be omitted. In summary, the communication device 151 transitions to infrastructure mode and uses the communication unit 156 to connect to the access point 131 based on the received connection information.
[0087] On the other hand, if the process proceeds from S509 to S514, the communication device 151 determines whether the event that occurred is acceptance of a cancellation instruction. If the event that occurred is a cancellation instruction, the communication device 151 proceeds to S515, and if not, the process proceeds to S518.
[0088] In S515, if there is any WEC-related information being output, the communication device 151 stops this output. The processing content is the same as in S510.
[0089] In S516, the communication device 151 stops and clears the timers T1 to T3.
[0090] In S517, communication device 151 performs processing to cancel the DPP standby mode. Specifically, communication device 151 stops the setup access point (not shown) using communication unit 156. Communication device 151 also deletes information such as WEC-related information and key pairs. Then, display unit 161 transitions from wireless LAN simple setting processing screen 410 to wireless LAN simple setting cancel screen 440.
[0091] On the other hand, if the process proceeds from S514 to S518, the communication device 151 determines whether the event that has occurred is the timeout of the timer T1. If the event that has occurred is the timeout of the timer T1, the communication device 151 proceeds to S519, and if not, the process proceeds to S522.
[0092] In S519, if there is any WEC-related information being output, the communication device 151 stops this output. The processing contents are the same as those in S510 and S515.
[0093] In S520, the communication device 151 stops and clears the timers T1 to T3.
[0094] In S521, communication device 151 performs timeout processing for the DPP standby mode. Specifically, communication device 151 stops a setup access point (not shown) using communication unit 156. Communication device 151 also deletes information such as WEC-related information and key pairs. Then, display unit 161 transitions from wireless LAN simple setting processing screen 410 to wireless LAN simple setting timeout screen 450. Through S518 to S521, communication device 151 ends the standby state if TP1 has elapsed without performing a predetermined process (receiving connection information or accepting a cancel instruction) in the standby state.
[0095] On the other hand, if the process proceeds from S518 to S522, the communication device 151 determines whether the event that has occurred is the timeout of timer T3. If the event that has occurred is the timeout of timer T3, the communication device 151 proceeds to S523, and if not, the process proceeds to S525.
[0096] In S523, if any WEC-related information is being output, the communication device 151 stops this output. The processing content is the same as S510, S515, and S519. However, while in S510, S515, and S519, the output of WEC-related information is stopped in preparation for ending the DPP standby mode, the significance of the output stop in S523 is different. That is, S523 is processing for stopping the output of WEC-related information prior to updating the WEC. Furthermore, when the communication device 151 finishes displaying the QR code (registered trademark) as the output of WEC-related information, it displays the wireless LAN simple setting processing screen 410 on the display unit 161.
[0097] In S524, the communication device 151 stops and clears the timer T3. Then, the communication device 151 returns to the event waiting state in S508. That is, the communication device 151 waits for an event without displaying the QR code (registered trademark) as WEC-related information on the display unit 161 (with the wireless LAN simple setting processing screen 410 displayed).
[0098] On the other hand, if the process proceeds from S522 to S525, the communication device 151 determines whether the event that has occurred is the timeout of timer T2. If the event that has occurred is the timeout of timer T2, the process proceeds to S626; if not, the process returns to S508 and waits for an event.
[0099] In S526, if there is any WEC-related information being output, the communication device 151 stops this output. The processing content is the same as that described in S510. The processing content is the same as that in S510, S515, S519, and S523.
[0100] In S527, the communication device 151 stops and clears the timer T2. If the timer T3 has not been stopped at this time, the communication device 151 also stops and clears the timer T3.
[0101] In S528, communication device 151 performs an update process for the WEC-related information. That is, communication device 151 updates the WEC-related information, including public key information, output by display unit 161 while in a standby state for receiving connection information. Specifically, communication device 151 regenerates the WEC-related information to be output by bootstrapping. Here, a public key exists as one element of the WEC-related information, and this is based on a key pair of a public key and a private key used in subsequent DPP authentication. In other words, by performing the update process for the WEC-related information, the public key included in the previous WEC-related information becomes invalid. Here, "invalidating" refers to the failure of DPP authentication if the invalid public key is used. The key pair may be regenerated during the update process for the WEC-related information or may be generated in advance. As a specific example, communication device 151 may display wireless LAN simple setting main screen 420 on display unit 161, and the next key pair may be generated in the background while waiting for an event in S580. The key pair regenerated in advance is stored in RAM 153 and is read out when the process of S528 starts. As a result of S525 to S528, in the standby state of communication device 151, communication device 151 updates the WEC-related information as time period TP2, which is shorter than time period TP1, elapses.
[0102] Furthermore, before the update process of the WEC-related information is performed in S528, the output of the WEC-related information is stopped in S523. Therefore, the output of the WEC-related information is stopped for a predetermined period including the timing of updating the WEC-related information. At this time, a screen 410 indicating that the QR code (registered trademark) is being updated is displayed on the display unit 161.
[0103] When the communication device 151 completes the WEC-related information update process in S528, it returns to S505 and resumes the process. That is, timer T2 is reset in S505, timer T3 is reset in S506, and output of WEC-related information different from the previous time is started in S507. Then, if no events occur such as successful reception of connection information or acceptance of a cancel instruction, this process is repeated until timer T1 times out.
[0104] According to the flowchart described above, timeout control is performed using timer T1, which is set with a time limit for DPP standby mode, and timer T2, which is set with a shorter time limit for WEC-related information. The key pair used in DPP Authentication can be updated in a relatively short time, improving security in DPP standby mode. At the same time, setting a relatively long timeout for DPP standby mode prevents an unintended timeout from occurring, forcing the user to re-enter DPP standby mode, improving user operability.
[0105] 5, if the start trigger is not due to operation of operation unit 159, the period TP2 is set in timer T2. In other words, if the start trigger is not due to operation of operation unit 159, the set period of timer T1 is shortened. This shortens the duration of DPP standby mode if the start trigger is not due to operation of operation unit 159, thereby ensuring security.
[0106] In this embodiment, if the start trigger is not due to operation of operation unit 159, then "the set period of timer T1 = the set period of timer T2," and therefore WEC-related information is not updated while DPP standby mode is running. However, it is also possible to adopt a mode in which WEC-related information is updated even when the start trigger is not due to operation of operation unit 159. For example, a period other than period TP2 (and shorter than period TP1) may be set for timer T2. Even when set in this manner, the time limit for DPP standby mode when the start trigger is not due to operation of operation unit 159 is shorter than when the start trigger is due to operation of operation unit 159. Therefore, security can be ensured when the start trigger is not due to operation of operation unit 159.
[0107] In this embodiment, timers T1 and T2 are described as different timers, but other configurations that can achieve the same function may be adopted. For example, timer T1 may not actually exist, but may be processed to count the number of times timer T2 has timed out, and when that count reaches a predetermined number, timer T1 may be considered to have timed out. In other words, communication device 151 may end DPP standby mode in accordance with the number of updates to WEC-related information while in DPP standby mode.
[0108] In addition, although the present embodiment has been described with timers T2 and T3 as separate timers, other configurations that can achieve similar functions may be employed. For example, timer T3 may not actually exist, but may be configured to periodically monitor the time remaining until timer T2 times out, and if the time remaining on timer T2 becomes shorter than a predetermined length, timer T3 may be deemed to have timed out. In other words, communication device 151 may stop outputting WEC-related information for a predetermined period of time until the WEC-related information update process is started.
[0109] As described above, in this embodiment, the time limit for DPP standby mode and the time limit for updating the WEC-related information are processing-related elements. Therefore, the WEC-related information may include information about the time limit for DPP standby mode and the time limit for updating the WEC-related information. For example, a method can be considered in which the numerical value stored as the time limit for DPP standby mode and the numerical value stored as the time limit for updating the WEC-related information are directly included in the WEC-related information. Another example can be considered in which the communication device 151 calculates the time at which each time limit is reached based on time information stored therein and includes this information in the WEC-related information. In this way, including information about the time limit for DPP standby mode and information about the time limit for the WEC-related information in the WEC-related information can be used to later determine whether the WEC-related information acquired by the information processing device 101 is valid at that time.
[0110] 6 is a flowchart showing an example of control of the communication device 151. This flowchart is for determining whether successful reception of connection information has occurred as an event. This flowchart corresponds to S203 to S204 in the sequence of FIG. 2 and S508 to S509 in the flowchart of FIG. 5.
[0111] In S601, the communication device 151 executes DPP authentication processing. As described above in detail, in the DPP authentication processing, authentication information, information used for encrypting information, and the like are communicated between the information processing device 101 and the communication device 151, thereby authenticating communication between the devices. Note that in DPP authentication, communication is executed using DPP.
[0112] In S602, the communication device 151 determines whether the DPP authentication process with the information processing device 101 was successful. As described above in detail, various pieces of information transmitted from the information processing device 101 during communication in DPP authentication are encrypted based on the WEC-related information acquired by the information processing device 101 in the process shown in FIG. 2. If the communication device 151 successfully decrypts the information received from the information processing device 101 using a decryption key stored in advance, the communication device 151 authenticates communication with the information processing device 101. Note that if the information processing device 101 is unable to acquire accurate WEC-related information and therefore is unable to accurately encrypt the information, decryption in the communication device 151 fails, and authentication therefore fails. Therefore, if authentication of communication with the information processing device 101 is successful, the communication device 151 determines that the DPP authentication process is successful; if authentication is unsuccessful, the communication device 151 determines that the DPP authentication process has failed. If the determination in S602 is NO, the communication device 151 terminates this flowchart. On the other hand, if the determination in S602 is YES, the communication device 151 proceeds to S603.
[0113] In S603, the communication device 151 executes DPP Configuration processing. In the DPP Configuration processing, the communication device 151 receives, via WEC, connection information for connecting to an access point that has been set as a configuration target by WEC from the information processing device 101. Note that the connection information includes information indicating the SSID, password, encryption method, etc. of the access point that has been set as a configuration target by WEC.
[0114] In S604, the communication device 151 determines whether the DPP Configuration process with the information processing device 101 was successful. Specifically, if the communication device 151 receives, via WEC, connection information for connecting to an access point set as a configuration target by WEC from the information processing device 101, the communication device 151 determines that the process was successful; if the communication device 151 is unable to receive the connection information, the communication device 151 determines that the process was unsuccessful. If the determination in S604 is NO, the communication device 151 ends this flowchart. On the other hand, if the determination in S604 is YES, the communication device 151 proceeds to S605. If the DPP Configuration process is successful, the communication device 151 acquires the SSID, encryption method, and password of the access point.
[0115] In S605, the communication device 151 determines whether or not an SSID is included in the information about the access point that is set as a setting target by WEC and that has been received from the information processing device 101. If the determination in S605 is NO, the communication device 151 ends this flowchart. On the other hand, if the determination in S605 is YES, the communication device 151 proceeds to S606.
[0116] In S606, the communication device 151 determines whether or not an encryption method is included in the information about the access point that is set as a setting target by WEC and that has been received from the information processing device 101. If the determination in S606 is NO, the communication device 151 ends this flowchart. On the other hand, if the determination in S606 is YES, the communication device 151 proceeds to S607.
[0117] In S607, the communication device 151 determines whether or not a password is included in the information about the access point that is set as a setting target by WEC and that is received from the information processing device 101. Note that when connecting to an access point using DPP communication, the communication device 151 may determine whether or not public key information is included instead of a password. If the determination in S607 is NO, the communication device 151 ends this flowchart.
[0118] In S608, communication device 151 determines that the connection information has been received successfully. If so determined, communication device 151 proceeds to the processing from S509 to S510 onwards in the flowchart of Fig. 5, ends the DPP standby mode, and attempts wireless LAN setting processing.
[0119] <Modification> A modification of the above embodiment will be described. In the above embodiment, (1) updating of WEC-related information while in DPP standby mode and (2) changing of the time limit for DPP standby mode are performed as methods for ensuring security when establishing a connection between communication device 151 and an access point. A configuration in which only one of these is performed can also be employed.
[0120] First, we will explain the configuration corresponding to (1) above, that is, a configuration in which the duration of DPP standby mode is not changed depending on whether the start trigger is due to operation of operation unit 159 or not. In this modified example, even if the duration of DPP standby mode is not relatively short when the start trigger is not due to operation of operation unit 159, it is possible to achieve both improved security and user convenience by updating WEC-related information while DPP standby mode is running. An overview of the processing of this modified example is shown in Figure 7.
[0121] S701 is the same process as S501. In S702, the communication device 151 starts measuring timers T1 to T2. Here, timer T1 is set to a predetermined period TP1 regardless of the type of start trigger. S703 is the same process as S507.
[0122] In S704, the communication device 151 determines whether or not connection information has been received, and if it is determined that connection information has been received, the process proceeds to S705, and if not, the process proceeds to S706. S704 is a process corresponding to S509.
[0123] In S705, the communication device 151 executes wireless LAN setting processing and ends this flowchart. S705 corresponds to S513. Note that, although this flowchart shows only an overview of the processing, the communication device 151 executes processing corresponding to S510 to S512 in FIG. 5 as necessary before executing S705, although this is omitted.
[0124] In S706, the communication device 151 checks whether the time limit for the DPP standby mode has elapsed, and if it is determined that the time limit has elapsed, the process proceeds to S707, and if not, the process proceeds to S708. S706 is processing corresponding to S518.
[0125] In S707, communication device 151 performs timeout processing for the DPP standby mode. S707 corresponds to S521. Note that, although this flowchart shows only an overview of the processing, communication device 151 performs processing corresponding to S519 to S521 in FIG. 5 as necessary before executing S707, although this is omitted.
[0126] In S708, the communication device 151 checks whether the time limit for the WEC-related information has elapsed, and if it is determined that the time limit has elapsed, proceeds to S709, and if not, returns to S704. S708 corresponds to S525.
[0127] In S709, the communication device 151 executes a process of updating WEC-related information. S709 corresponds to S528. Note that, although this flowchart shows only an overview of the process and is therefore omitted, the communication device 151 executes processes corresponding to S526 to S527 in FIG. 5 as necessary before executing S709.
[0128] Furthermore, communication device 151 may stop outputting WEC-related information for a predetermined time until the time limit for the WEC-related information has elapsed. That is, it may execute the processes corresponding to S522 to S524. Furthermore, communication device 151 may execute a process for canceling the DPP standby mode if it receives a cancellation instruction by operating operation unit 159 or the like before the time limit for the DPP standby mode has elapsed. That is, it may execute the processes corresponding to S514 to S517.
[0129] The above-described process also allows WEC-related information to be updated at predetermined intervals while the DPP standby mode is in operation, thereby achieving both improved security and user convenience.
[0130] Next, a configuration corresponding to (2) above will be described, i.e., a configuration in which the time limit for DPP standby mode when the start trigger is not due to operation of operation unit 159 is set shorter than when the start trigger is due to operation of operation unit 159, and WEC-related information is not updated while DPP standby mode is running. In this modification, when the possibility of an external attack is relatively low (when the start trigger is due to operation of operation unit 159), the duration of DPP standby mode is set relatively longer, thereby improving user convenience. Also, when the possibility of an external attack is relatively high (when the start trigger is not due to operation of operation unit 159), the duration of DPP standby mode is set relatively shorter, thereby ensuring security. An overview of the processing in this case is shown in FIG. 8.
[0131] Steps S801 and S802 are the same as steps S501 and S502, respectively. If the determination in step S802 is "Yes," the communication device 151 sets the timer T1 to a period TP1 and starts measurement in step S803. On the other hand, if the determination in step S803 is "No," the communication device 151 sets the timer T1 to a period shorter than the period TP1 and starts measurement in step S804.
[0132] S805 corresponds to S507. S806 to S809 correspond to S704 to S707 in Fig. 7, respectively. Note that although this flowchart is omitted because it shows only an overview of the processing, communication device 151 performs processing such as stopping the output of WEC-related information, stopping timer T1, or completing DPP standby mode (in the case of S807) as necessary before executing S807 and S809. Furthermore, communication device 151 may perform processing to cancel DPP standby mode if it receives a cancellation instruction via operation on operation unit 159 or the like before the time limit for DPP standby mode has elapsed. In other words, it may perform processing corresponding to S514 to S517.
[0133] Even with the processing described above, if the trigger for starting the DPP standby mode is not from the operation unit 159 of the communication device 151, the time limit for the DPP standby mode can be set relatively short, thereby achieving both improved security and user convenience.
[0134] As another variation, the update frequency of the WEC-related information (or the public key information included therein) may be changed depending on whether the start trigger is due to an operation of the operation unit 159 or not. Specifically, the set time of the timer T2 may be changed. For example, the timer T1 may be set to the same period whether the start trigger is due to an operation of the operation unit 159 or not, and the period of the timer T2 may be set to be shorter when the start trigger is not due to an operation of the operation unit 159. This makes it possible to update the WEC-related information (or the public key information included therein) more frequently when the start trigger is not due to an operation of the operation unit 159 than when the start trigger is due to an operation of the operation unit 159. This makes it easier to avoid external attacks.
[0135] The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0136] [Note] The above-described embodiment discloses at least the following communication device, connection establishment method, and program. (Item 1) a waiting means for waiting for first information for connecting to a first external device to be transmitted from a second external device using a predetermined communication protocol; an output means for outputting second information used for authenticating communication with the second external device according to the predetermined communication protocol in a standby state of the standby means; and an update means for updating the second information output by the output means in the standby state. A communication device comprising: (Item 2) Item 1, the communication device the standby means ends the standby state when a first period has elapsed since the start of the standby state without a predetermined process being executed, the updating means updates the second information in response to the passage of a second period in the standby state, the second period being shorter than the first period. A communication device comprising: (Item 3) A communication device according to any one of items 1 and 2, an input means for accepting an operation input by a user; a first receiving means for receiving a start instruction for starting the standby state by the input means; a second receiving means for receiving the start instruction via wireless communication; the standby means starts the standby state in response to the reception of the start instruction by the first reception means or the second reception means, and ends the standby state when a first period has elapsed since the start of the standby state without a predetermined process being executed. A communication device comprising: (Item 4) Item 3. The communication device according to item 3, the first period when the start instruction is received by the first receiving means is longer than the first period when the start instruction is received by the second receiving means; A communication device comprising: (Item 5) Item 3. The communication device according to item 3, When the first reception means receives the start instruction, the update means updates the second information in response to the passage of a second period in the standby state, the second period being shorter than the first period; When the second receiving means receives the start instruction, the updating means updates the second information in response to the passage of a third period in the standby state, the third period being shorter than the second period. A communication device comprising: (Item 6) Item 3. The communication device according to item 3, The update frequency of the second information by the update means is higher when the first reception means receives the start instruction than when the second reception means receives the start instruction. A communication device comprising: (Item 7) Item 3. The communication device according to item 3, When the first reception means receives the start instruction, the update means updates the second information in response to the passage of a second period in the standby state, the second period being shorter than the first period; Even if the update means has received the start instruction, if the start instruction has been received by the second reception means, the update means does not update the second information in the standby state. A communication device comprising: (Item 8) 8. The communication device according to any one of items 1 to 7, the output means is switchable, in the standby state, between an output state in which the second information is output and an output stop state in which output of the second information is stopped; the output means is in the output stop state during a fourth period including a timing when the update means updates the second information. A communication device comprising: (Item 9) Item 9. A communication device according to any one of items 1 to 8, the output means displays a code corresponding to the second information, which is readable by the second external device, on a display unit of the communication device. A communication device comprising: (Item 10) Item 8. The communication device according to item 8, the output means, in the output state, displays a code that corresponds to the second information and that is readable by the second external device on a display unit of the communication device; The output means displays a screen indicating that the code is being updated on the display unit in the output stop state. A communication device comprising: (Item 11) 11. The communication device according to any one of items 1 to 10, the standby means ends the standby state depending on the number of updates of the second information by the update means. A communication device comprising: (Item 12) 12. A communication device according to any one of items 1 to 11, and further comprising an establishment unit for establishing a connection with the first external device using the first information acquired from the second external device according to the predetermined communication protocol. A communication device comprising: (Item 13) 13. The communication device according to any one of items 1 to 12, The predetermined communication protocol is a Device Provisioning Protocol. A communication device comprising: (Item 14) 14. The communication device according to any one of items 1 to 13, the updating means updates the public key information included in the second information. A communication device comprising: (Item 15) a standby means for waiting in a standby state for first information for connecting to a first external device to be transmitted from a second external device using a predetermined communication protocol; an input means for accepting an operation input by a user; a first receiving means for receiving a start instruction for starting the standby state by the input means; a second receiving means for receiving the start instruction via wireless communication; an output means for outputting second information including second information used for authenticating communication with the second external device according to the predetermined communication protocol in the standby state; When the first reception means receives the start instruction, the standby means ends the standby state if a fifth period has elapsed since the start of the standby state without a predetermined process being executed; When the second receiving means receives the start instruction, the standby means ends the standby state when a sixth period shorter than the fifth period has elapsed since the start of the standby state without the predetermined process being executed. A communication device comprising: (Item 16) A method for controlling a communication device, comprising: a waiting step of waiting for first information for connecting to a first external device to be transmitted from a second external device using a predetermined communication protocol; an output step of outputting, by the communication device in a standby state in the standby step, second information used for authenticating communication with the second external device according to the predetermined communication protocol; an updating step of updating the second information outputted in the output step by the communication device in the standby state, A connection establishment method comprising: (Item 17) A program for causing a computer to function as each means of the communication device described in any one of items 1 to 15.
[0137] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]
[0138] 101: Information processing device, 131: Access point, 151: Communication device, 154: CPU
Claims
1. A communication device capable of receiving first information for connecting to a first external device by a predetermined communication protocol and outputting second information for authenticating with a communication device according to the predetermined communication protocol, waiting means for starting, based on a predetermined trigger, an operation in a waiting state for waiting for a request for the authentication according to the predetermined communication protocol transmitted from a second external device that has acquired the second information output from the communication device; output means for starting the output of the second information based on the predetermined trigger; authentication means for executing the authentication according to the predetermined communication protocol based on communication between the communication device and the second external device according to the predetermined communication protocol when a request for the authentication is received from the second external device while the communication device is operating in the waiting state; receiving means for receiving the first information from the second external device authenticated by the authentication according to the predetermined communication protocol according to the predetermined communication protocol; establishing means for establishing a connection between the first external device and the communication device based on receiving the first information; updating means for updating the second information output by the output means in a state where the communication device is operating in the waiting state, and comprising: the waiting means terminates the waiting state of the communication device based on the elapse of a first period without a predetermined process being executed after the communication device starts operating in the waiting state; the updating means updates the second information based on the elapse of a second period shorter than the first period after the communication device starts operating in the waiting state, A communication device characterized by the above.
2. The communication device according to claim 1, input means for receiving an operation input by a user; first receiving means for receiving a start instruction for starting the waiting state by the input means; further comprising second receiving means for receiving the start instruction by wireless communication, wherein the predetermined trigger is receiving the start instruction by the first receiving means or the second receiving means, A communication device characterized by the above.
3. The communication device according to claim 2, When the first receiving means receives the start instruction, the first period is longer than the first period when the second receiving means receives the start instruction. A communication device characterized by the above.
4. The communication device according to claim 2, When the first receiving means receives the start instruction, the updating means updates the second information based on the elapse of the second period after the communication device starts operating in the standby state. When the second receiving means receives the start instruction, the updating means updates the second information based on the elapse of a third period shorter than the second period after the communication device starts operating in the standby state. A communication device characterized by the above.
5. The communication device according to claim 2, The update frequency of the second information by the updating means is higher when the first receiving means receives the start instruction than when the second receiving means receives the start instruction. A communication device characterized by the above.
6. The communication device according to claim 2, When the first receiving means receives the start instruction, the updating means updates the second information based on the elapse of the second period after the communication device starts operating in the standby state. Even when the updating means receives the start instruction, when the second receiving means receives the start instruction, the second information is not updated in the standby state. A communication device characterized by the above.
7. The communication device according to claim 1, In the standby state, the output means can be switched between an output state in which the second information is output and an output stop state in which the output of the second information is stopped. The output means is in the output stop state during a fourth period including the timing at which the updating means updates the second information. A communication device characterized by the above.
8. The communication device according to claim 1, The output means displays, on the display unit of the communication device, a code corresponding to the second information that can be read by the second external device. A communication device characterized by the above.
9. The communication device according to claim 7, In the output state, the output means displays, on the display unit of the communication device, a code corresponding to the second information that can be read by the second external device. In the output stop state, the output means displays, on the display unit, a screen indicating that the code is being updated. A communication device characterized by the above.
10. The communication device according to claim 1, wherein the waiting means ends the waiting state according to the number of times of updating the second information by the updating means. A communication device characterized by the above.
11. The communication device according to claim 1, wherein the predetermined communication protocol is Device Provisioning Protocol. A communication device characterized by the above.
12. The communication device according to claim 11, wherein the updating means updates the public key information included in the second information. A communication device characterized by the above.
13. The communication device according to claim 1, wherein the predetermined process is a process of receiving the first information. A communication device characterized by the above.
14. The communication device according to claim 1, wherein the predetermined process is a process of receiving an operation for stopping the operation in the waiting state. A communication device characterized by the above.
15. The communication device according to claim 1, further comprising receiving means for receiving a print job after a connection between the first external device and the communication device is established, and printing means for executing printing based on the print job. A communication device characterized by the above.
16. A control method for a communication device capable of receiving first information for connecting to a first external device by a predetermined communication protocol and outputting second information for authenticating with the communication device by the predetermined communication protocol, a waiting step of starting, based on a predetermined trigger, an operation in a waiting state for waiting for a request for the authentication by the predetermined communication protocol transmitted from a second external device that has acquired the second information output from the communication device; an output step of starting the output of the second information based on the predetermined trigger; an authentication step of executing the authentication by the predetermined communication protocol based on communication between the communication device and the second external device by the predetermined communication protocol when a request for the authentication is received from the second external device while the communication device is operating in the waiting state. A receiving step of receiving the first information from the second external device authenticated by the authentication using the predetermined communication protocol; An establishing step of establishing a connection between the first external device and the communication device based on receiving the first information; An updating step of updating the second information output in the output step in a state where the communication device is operating in the standby state; and The standby step ends the standby state of the communication device based on the elapse of a first period without executing a predetermined process after the communication device starts operating in the standby state. The updating step updates the second information based on the elapse of a second period shorter than the first period after the communication device starts operating in the standby state. A control method characterized by the above. **Claim 17** A program for causing a computer to function as each means of the communication device according to any one of claims 1 to 15.