Electronic device, control method for electronic device, program, and storage medium
The electronic device addresses security risks in AP switching by setting and controlling security settings, effectively managing AP changes to ensure secure and stable wireless LAN operations.
Patent Information
- Application Number
- JP2023189526
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-06
- Publication Date
- 2025-05-19
AI Technical Summary
Existing wireless LAN systems face challenges in securely managing AP switching requests, as they do not adequately address potential security risks such as connecting to malicious or outdated APs.
An electronic device equipped with receiving, setting, and control means to manage AP switching requests. The device sets security-related setting values and controls whether to suppress AP changes based on these settings, ensuring secure operations.
The solution effectively controls dynamic AP switching to mitigate security risks, ensuring the device's security and maintaining stable connections.
Smart Images

Figure 2025077376000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an electronic device capable of connecting to a wireless LAN, a control method thereof, a program, and a storage medium.
Background Art
[0002] In a wireless LAN environment to which an electronic device is connected, in an ESS (Extended Service Set) composed of a plurality of APs (Access Points), there is a technology for dynamically switching the connection destination AP so that the AP and the STA (Station) can efficiently exchange data. When it is determined that the connection destination AP should be switched based on the congestion of the AP to which the STA is connected, the availability of other APs, the radio wave condition, etc., the connected AP transmits a connection AP change request to the STA. When the STA receives the AP change request, it can connect to an appropriate AP by switching the connection destination AP according to the request.
[0003] Patent Document 1 discloses the following as a process of requesting a connection destination change from a router having the function of an AP to a connected wireless slave device. A mobile router (MR1) capable of connecting to a plurality of wireless slave devices checks whether the wireless slave device terminal supports IEEE802.11v. Whether the wireless slave device terminal supports IEEE802.11v can be determined from the Association Request frame transmitted when the wireless slave device terminal makes a wireless connection to the MR1. When the wireless slave device terminal supports IEEE802.11v, a BTM (BSS Transition Management) Request frame is transmitted to the corresponding wireless slave device terminal. The BSS Transition Candidate List Entries field of the BTM Request frame designates the BSSID of the parent router RT2 as the connection destination. This prompts the connection destination switch of the slave device terminal, and the wireless slave device terminal switches the connection destination from the MR1 to the RT2 according to the received BTM Request frame.
Prior Art Documents
Patent Documents
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2021-175068 [Summary of the Invention] [Problems to be Solved by the Invention]
[0005] Depending on the state of the STA, there are cases where no problem occurs even if the AP is switched, and cases where problems occur. When problems occur due to AP switching, it is not desirable to switch the connected AP in response to the AP change request received from the AP.
[0006] For example, there may be a case where there is a security risk in the destination AP. If the connection is switched to a malicious AP pretending to be a secure AP, there is a risk of leakage of the communication content of the STA. Alternatively, if the STA is connected to an AP that is operating without being updated with the old firmware, the STA may be subject to attacks using vulnerabilities. Therefore, when it is determined that the electronic device has a security risk due to AP switching, it is desirable not to respond to the AP switching request. [Means for Solving the Problems]
[0007] An electronic device according to one aspect of the present invention includes: receiving means for receiving a change request for the connected access point from the access point; setting means for setting a setting value related to the security of the electronic device; control means for controlling whether to suppress the change of the connected access point based on the change request based on the setting value set by the setting means. [Effects of the Invention]
[0008] According to the present invention, it is possible to control the dynamic switching of the connected AP so as to avoid the security risk of the electronic device. [Brief Description of the Drawings]
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Mode for Carrying Out the Invention
[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential for the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are given the same reference numerals, and duplicate explanations are omitted.
[0011] (System Configuration) FIG. 1 shows a configuration example of the system according to the present embodiment. In one example, this system is a wireless communication system in which a plurality of communication devices can communicate with each other wirelessly. In the example of FIG. 1, as communication devices, it includes a portable terminal device 104, a multi-functional peripheral (MFP) 100, an access point AP1 (101), and AP2 (102), a DHCP server 103, and a network 110. The portable terminal device 104 is a device having a wireless communication function such as a wireless LAN. Hereinafter, the wireless LAN may be referred to as WLAN. The portable terminal device 104 can be a personal information terminal such as a PDA (Personal Digital Assistant), a mobile phone (smartphone), a digital camera, a personal computer, or the like.
[0012] The MFP 100 has a printing function, and may further have a reading function (scanner), a FAX function, and a telephone function. Also, the MFP 100 of the present embodiment has a communication function capable of wireless communication with the portable terminal device 104. In the present embodiment, the case where the MFP 100 is used as an example is described, but it is not limited thereto. For example, a printing device, a scanner device, a projector, a portable terminal, a smartphone, a notebook PC, a tablet terminal, a PDA, a digital camera, a music playback device, a television, a smart speaker, etc., each having a communication function, may be used instead of the MFP 100. Note that MFP is an acronym for Multi Function Peripheral (multi-functional peripheral device).
[0013] AP1 (101) is provided separately (externally) from the mobile terminal device 104 and the MFP100 and operates as a WLAN base station device. A communication device having a WLAN communication function can communicate in the infrastructure mode of the WLAN via AP1 (101). Hereinafter, the access point may be referred to as "AP". Also, the infrastructure mode may be referred to as the "wireless infrastructure mode". AP1 (101) performs wireless communication with a communication device that has permitted (authenticated) connection to itself and relays wireless communication between that communication device and other communication devices. Further, AP1 (101) is connected to, for example, a wired communication network and can relay communication between a communication device connected to the wired communication network and another communication device wirelessly connected to AP1 (101).
[0014] AP2 (102) has the same functions as AP1 (101), and the MFP100 switches the connection from AP1 (101) to AP2 (102) as necessary. The DHCP server 103 is connected to the MFP100 via AP1 (101) and the network 110 and provides services to the MFP100 by responding to requests from the MFP100. In FIG. 1, the DHCP server 103 is described as being connected as a device separate from AP1 (101) and AP2 (102), but AP1 (101) and AP2 (102) may have a DHCP server function. The DNS server 105 is connected to the MFP100 and the mobile terminal device 104 via AP1 (101) and the network 110 and provides a name resolution service by responding to requests from the MFP100 and the mobile terminal device 104. Here, the network 110 may be the so-called Internet, or may be a closed network within a company or a mobile phone network.
[0015] (External Configuration of MFP) Fig. 2(a) shows an example of the external configuration of the MFP100. The MFP100 has, for example, a document table 201, a document cover 202, a printing paper insertion port 203, a printing paper discharge port 204, and an operation display unit 205. The document table 201 is a table for placing a document to be read. The document cover 202 is a cover for pressing the document placed on the document table 201 and preventing light from a light source that irradiates the document during reading from leaking to the outside. The printing paper insertion port 203 is an insertion port into which papers of various sizes can be set. The printing paper discharge port 204 is a discharge port for discharging the printed paper. The paper set in the printing paper insertion port 203 is conveyed one by one to the printing unit, and after printing is performed in the printing unit, it is discharged from the printing paper discharge port 204. The operation display unit 205 is composed of keys such as a character input key, a cursor key, a decision key, a cancel key, etc., and includes an LED, an LCD, etc., and is configured to be able to receive activation of various functions as an MFP by the user and operations of various settings. Further, the operation display unit 205 may be composed of including a touch panel display. The MFP100 has a wireless communication function by WLAN, and although it does not necessarily need to be visually recognizable from the outside, it is composed of including a wireless communication antenna 206 for the wireless communication. The MFP100 can also perform wireless communication in the frequency bands of 2.4 GHz band and 5 GHz band by WLAN, similar to the mobile terminal device 104.
[0016] (Configuration of MFP) Fig. 2(b) shows a configuration example of the MFP100. The MFP100 includes a main board 211 that performs main control of the device itself, and a wireless unit 226 that is a single communication module that performs WLAN communication using at least one common antenna. Further, the MFP100 includes, for example, a modem 229 for performing wired communication. The main board 211 includes, for example, a CPU 212 (central processing unit), a ROM 213, a RAM 214, a non-volatile memory 215, an image memory 216, a reading control unit 217, a data conversion unit 218, a reading unit 219, and an encoding / decoding processing unit 221. Further, the main board 211 includes, for example, a printing unit 222, a paper feeding unit 223, a printing control unit 224, an operation display unit 220, and a FAX control unit 227. These functional units within the main board 211 are interconnected via a system bus 230 managed by the CPU 212. Also, the main board 211 and the wireless unit 226 are connected via, for example, a dedicated bus 225, and the main board 211 and the modem 229 are connected via, for example, a bus 228.
[0017] The CPU 212 is a system control unit including at least one processor, and controls the entire MFP100. In one example, the processing of the MFP100 described below is realized by the CPU 212 executing a program stored in the ROM 213. Note that dedicated hardware for each process may be provided. The ROM 213 stores a control program executed by the CPU 212, an embedded OS program, and the like. In the present embodiment, the CPU 212 performs software control such as scheduling and task switching by executing each control program stored in the ROM 213 under the management of the embedded OS also stored in the ROM 213.
[0018] The RAM 214 is composed of an SRAM or the like. The RAM 214 stores data such as program control variables, set values registered by the user, and management data of the MFP 100. Also, the RAM 214 can be used as various work buffers. The non-volatile memory 215 is composed of a memory such as a flash memory, and continues to store data even when the power of the MFP 100 is turned off. The image memory 216 is composed of a memory such as a DRAM. The image memory 216 stores image data received via the wireless unit 226, image data processed by the code decoding processing unit 221, and the like. Note that the memory configuration of the MFP 100 is not limited to the above-described configuration. The data conversion unit 218 performs analysis of various types of data, conversion of image data into print data, and the like.
[0019] The reading control unit 217 controls the reading unit 219 (for example, a CIS (Contact Image Sensor)) to optically read a document placed on the document table 201. The reading control unit 217 converts an image obtained by optically reading the document into electrical image data (image signal) and outputs it. At this time, the reading control unit 217 may perform various image processes such as binarization processing and halftone processing and then output the image data.
[0020] The operation display unit 220 is the operation display unit 205 described with reference to FIG. 2(a), and executes display on the display based on display control by the CPU 212, generation of signals according to reception of user operations, and the like.
[0021] The code decoding processing unit 221 performs encoding processing, decoding processing, and enlargement / reduction processing of image data (JPEG, PNG, etc.) handled by the MFP 100.
[0022] The paper feeding unit 223 holds paper for printing. The paper feeding unit 223 can supply the set paper under the control of the printing control unit 224. The paper feeding unit 223 may include a plurality of paper feeding units in order to hold a plurality of types of paper in one device, and can control from which paper feeding unit to feed paper under the control of the printing control unit 224.
[0023] The printing control unit 224 performs various image processes such as smoothing process, printing density correction process, and color correction on the image data to be printed, and outputs the processed image data to the printing unit 222. The printing unit 222 is configured to be capable of executing, for example, inkjet printing process, and ejects the ink supplied from the ink tank from the print head to record an image on a recording medium such as paper. Note that the printing unit 222 may be configured to be capable of executing other printing processes such as electrophotographic process. Further, the printing control unit 224 can periodically read the information of the printing unit 222 and update the status information including the remaining amount of the ink tank, the state of the print head, etc. stored in the RAM 214.
[0024] The wireless unit 226 is a unit capable of providing a WLAN communication function, and can provide a function similar to that of, for example, combining the WLAN unit 401 of the mobile terminal device 104. That is, the wireless unit 226 converts data into packets and transmits the packets to other devices according to the WLAN standard, and also restores the packets from external other devices to the original data and outputs it to the CPU 212. The wireless unit 226 can communicate as a station compliant with the IEEE802.11 standard series. In particular, it can communicate as a station compliant with IEEE802.11a / b / g / n / ac / ax. Hereinafter, the station may be referred to as STA. Also, it can communicate as a STA corresponding to Wi-Fi Agile Multiband (trademark).
[0025] The wireless unit 226 is compatible with IEEE802.11ax, that is, Wi-Fi6 (trademark), and can perform processing compliant with IEEE802.11ax. That is, the MFP100 can perform one or both of the processing as a STA compliant with OFDMA and the operation (processing) as a STA compliant with TWT. OFDMA is the abbreviation of Orthogonal Frequency-Division Multiple Access. TWT is the abbreviation of Target Wake Time. Since it is compatible with TWT, the data communication timing from the master device to the STA is adjusted. The wireless unit 226 (MFP100) as a STA shifts the communication function to the sleep state when there is no need to wait for signal reception. Thereby, power consumption can be suppressed. In addition, the wireless unit 226 is also compatible with Wi-Fi 6E (trademark). That is, communication in the 6GHz band (5.925GHz to 7.125GHz) is also possible. The band subject to Dynamic Frequency Selection (DFS) existing in the 5GHz band does not exist in the 6GHz band. Therefore, in communication in the 6GHz band, communication disconnection due to the DFS waiting time does not occur, and more comfortable communication can be expected.
[0026] Note that the mobile terminal device 104 and the MFP100 can perform P2P (WLAN) communication based on WFD, and the wireless unit 226 has a software access point (soft AP) function or a group owner function. That is, the wireless unit 226 can construct a network for P2P communication and determine a channel used for P2P communication.
[0027] (Operation display unit of MFP) FIG. 3 schematically shows an example of a screen display on a display (touch panel display) included in the operation display unit 220 of the MFP 100. FIG. 3(a) is an example of a home screen displayed while the MFP 100 is powered on and no operations such as printing or scanning are being performed (idle state, Standby state). In FIG. 3(a), display items (menu items) corresponding to copy, scan, and cloud are displayed. Cloud is a menu item related to a cloud function using Internet communication. By selecting any of the menu items through key operations or touch panel operations, the MFP 100 can start executing the corresponding settings and functions. The MFP 100 can seamlessly display a screen different from that in FIG. 3(a) by accepting key operations or touch panel operations on the home screen in FIG. 3(a).
[0028] FIG. 3(b) is an example of a display of another part of the home screen, and is a screen that transitions from the state in FIG. 3(a) by an operation (such as a slide operation to the left or right) to display another page of the home screen. In FIG. 3(b), display items (menu items) corresponding to communication settings, print, and machine settings are displayed. When any of these menu items is selected, the function corresponding to the selected menu item, that is, any of the print function, machine settings, and communication settings, is executed.
[0029] Fig. 3(c) is a display example of a communication settings menu screen that is displayed when communication settings are selected on the screen of Fig. 3(b). On the communication settings menu screen, "Wireless LAN", "Wired LAN", "Wireless Direct", "Bluetooth", and "Common" are displayed as menu items (options). "Wireless LAN", "Wired LAN", and "Wireless Direct" are menu items for performing LAN settings. From these items, settings such as wired connection settings, enabling / disabling of the wireless infrastructure mode, and enabling / disabling of P2P modes such as WFD and soft AP mode can be made. When the "Wireless LAN" item is selected and the wireless LAN is enabled by user operation, the wireless infrastructure mode becomes enabled. When the "Wireless Direct" item is selected and the wireless direct is enabled by user operation, the P2P (WLAN) mode becomes enabled. Also, on this screen, a common settings menu for each connection form is also displayed. Furthermore, the user can perform settings such as the frequency band and frequency channel of the wireless LAN from this screen.
[0030] (Appearance Configuration of Mobile Terminal Device) FIG. 4(a) is a diagram showing an example of the external configuration of the mobile terminal device 104. In the present embodiment, as an example, the case where the mobile terminal device 104 is a general type of smartphone is shown. Note that the mobile terminal device 104 includes, for example, a display unit 402, an operation unit 403, and a power key 404. The display unit 402 is, for example, a display including a display mechanism of the LCD (Liquid Crystal Display) system. Note that the display unit 402 may display information using, for example, an LED (Light Emitting Diode) or the like. In addition to or instead of the display unit 402, the mobile terminal device 104 may have a function of outputting information by voice. The operation unit 403 includes a hard key such as a key or a button, a touch panel, etc. for detecting a user operation. In this example, since the information display on the display unit 402 and the reception of the user operation by the operation unit 403 are performed using a common touch panel display, the display unit 402 and the operation unit 403 are realized by one device. In this case, for example, a button icon or a software keyboard is displayed using the display function of the display unit 402, and the fact that the user touches those locations is detected by the operation reception function of the operation unit 403. Note that the display unit 402 and the operation unit 403 may be separated, and hardware for display and hardware for operation reception may be prepared separately. The power key 404 is a hard key for receiving a user operation for turning on or off the power of the mobile terminal device 104.
[0031] The mobile terminal device 104 has a WLAN unit 401 that provides a WLAN communication function, although it does not necessarily need to be visually recognizable from the outside. The WLAN unit 401 is configured to be capable of performing data (packet) communication in a WLAN system compliant with, for example, the IEEE802.11 standard series (IEEE802.11a / b / g / n / ac / ax, etc.). Also, it can communicate as an AP corresponding to Wi-Fi Agile Multiband (trademark). However, it is not limited to this, and the WLAN unit 401 may be capable of performing communication in a WLAN system compliant with other standards. In this example, it is assumed that the WLAN unit 401 can communicate in both the 2.4 GHz band and the 5 GHz band. Also, it is assumed that the WLAN unit 401 can perform communication based on WFD, communication in soft AP mode, communication in wireless infrastructure mode, etc. The operations in these modes will be described later.
[0032] (Configuration of Mobile Terminal Device) Fig. 4(b) shows a configuration example of the mobile terminal device 104. In one example, the mobile terminal device 104 has a main board 411 that performs main control of the device itself and a WLAN unit 429 that performs WLAN communication. The main board 411 includes, for example, a CPU 412, a ROM 413, a RAM 414, an image memory 415, a data conversion unit 416, a phone unit 417, a GPS 419, a camera unit 421, a non-volatile memory 422, a data storage unit 423, a speaker unit 424, and a power supply unit 425. Here, CPU is the initialism of Central Processing Unit, ROM is of Read Only Memory, RAM is of Random Access Memory, and GPS is of Global Positioning System. Also, the mobile terminal device 104 includes a display unit 420 and an operation unit 418. These functional units within the main board 411 are interconnected via a system bus 628 managed by the CPU 412. Also, the main board 411 and the WLAN unit 429 (the aforementioned WLAN unit 401) are connected via, for example, a dedicated bus 426.
[0033] The CPU 412 is a system control unit including at least one processor, and controls the entire portable terminal device 104. In an example, the processing of the portable terminal device 104 described below is realized by the CPU 412 executing a program stored in the ROM 413. Note that dedicated hardware for each process may be prepared. The ROM 413 stores a control program executed by the CPU 412, an embedded operating system (OS) program, and the like. In the present embodiment, the CPU 412 executes each control program stored in the ROM 413 under the management of the embedded OS also stored in the ROM 413, thereby performing software control such as scheduling and task switching.
[0034] The RAM 414 is composed of an SRAM (Static RAM) or the like. The RAM 414 stores data such as variables for program control, set values registered by the user, and management data of the portable terminal device 104. Also, the RAM 414 can be used as various work buffers. The image memory 415 is composed of a memory such as a DRAM (Dynamic RAM). The image memory 415 temporarily stores image data received via the WLAN unit 429 or image data read from the data storage unit 423 for processing by the CPU 412. The non-volatile memory 422 is composed of a memory such as a flash memory, and continues to store data even when the power of the portable terminal device 104 is turned off. Note that the memory configuration of the portable terminal device 104 is not limited to the above-described configuration. For example, the image memory 415 and the RAM 414 may be shared, or data backup or the like may be performed using the data storage unit 423. Also, in the present embodiment, a DRAM is cited as an example of the image memory 415, but other storage media such as a hard disk and a non-volatile memory may be used.
[0035] The data conversion unit 416 performs analysis of various forms of data and data conversion such as color conversion and image conversion. The telephone unit 417 controls the telephone line and realizes communication by telephone by processing voice data input and output via the speaker unit 424. The GPS 419 receives radio waves transmitted from satellites and acquires position information such as the current latitude and longitude of the mobile terminal device 104.
[0036] The camera unit 421 has a function of electronically recording and encoding an image input via a lens. The image data obtained by imaging with the camera unit 421 is stored in the data storage unit 423. The speaker unit 424 performs functions such as inputting or outputting voice for the telephone function and controls for realizing other functions such as alarm notification. The power supply unit 425 is, for example, a portable battery and controls the power supply to the device. The power supply state includes, for example, a battery exhausted state with no remaining battery, a power off state with the power key 404 not pressed, a startup state in normal startup, and a power saving state in which it is started but in a power saving mode.
[0037] The display unit 420 is the display unit 402 described with reference to FIG. 4(a) and performs various input operations, displays the operation status of the MFP 100, the status status, etc. based on the control of the CPU 412. The operation unit 418 is the operation unit 403 described with reference to FIG. 4(a) and executes controls such as generating an electrical signal corresponding to the operation and outputting it to the CPU 412 when a user operation is received.
[0038] The mobile terminal device 104 performs wireless communication using the WLAN unit 429 and conducts data communication with other devices such as the MFP 100. The WLAN unit 429 converts data into packets and transmits the packets to other devices. Also, the WLAN unit 429 restores the packets from external other devices to the original data and outputs it to the CPU 412. The WLAN unit 429 is a unit for realizing communication compliant with the WLAN standard respectively. The WLAN unit 429 can operate in parallel in at least two communication modes including the wireless infrastructure mode and the P2P (WLAN) mode. Note that the frequency bands used in these communication modes can be restricted by the functions and performance of the hardware.
[0039] (Configuration of Access Point) FIG. 5 is a block diagram showing the configuration of the AP1 (101) having a wireless LAN access point function. It includes a main board 510 that controls the AP1 (101), a wireless LAN unit 516, a wired LAN unit 518, and an operation button 520.
[0040] The CPU 511 in the form of a microprocessor arranged on the main board 510 operates according to a control program stored in the program memory 513 in the form of a ROM connected via the internal bus 512 and the content of the data memory 514 in the form of a RAM. The CPU 511 controls the wireless LAN unit 516 through the wireless LAN communication control unit 515 to conduct wireless LAN communication with other communication terminal devices. Also, the CPU 511 controls the wired LAN unit 518 through the wired LAN communication control unit 517 to conduct wired LAN communication with other communication terminal devices. The CPU 511 can receive operations from the user by the operation button 520 by controlling the operation unit control circuit 519. The CPU 511 includes at least one processor.
[0041] In addition, AP1 (101) includes an interference wave detection unit 521 and a channel change unit 522. The interference wave detection unit 521 performs interference wave detection processing when wireless communication is being executed in a band where DFS (Dynamic Frequency Selection) is implemented. The channel change unit 522 performs channel change processing for use when, for example, when interference waves are detected while wireless communication is being executed in a band where DFS is implemented, it is necessary to immediately change to an available channel.
[0042] Note that AP2 (102) also has the same configuration as AP1 (101).
[0043] (P2P Communication Method) Subsequently, in WLAN communication, a P2P (WLAN) communication method in which devices communicate directly wirelessly without going through an external access point will be outlined. P2P (WLAN) communication can be realized using a plurality of methods. For example, a communication device can support a plurality of modes for P2P (WLAN) communication and selectively use any one of the plurality of modes to execute P2P communication (WLAN).
[0044] As P2P modes, the following two modes are assumed. · Soft AP mode · Wi-Fi Direct (WFD) mode A communication device capable of executing P2P communication can be configured to support at least one of these modes. On the other hand, even a communication device capable of executing P2P communication does not necessarily have to support all of these modes and may be configured to support only a part of them.
[0045] In a communication device (e.g., mobile terminal device 104) having a communication function by WFD, an (optionally dedicated) application for realizing the communication function is called by receiving a user operation via its operation unit. Then, this communication device displays a screen of a UI (user interface) provided by the application to prompt the user operation, and can execute WFD communication based on the received user operation accordingly.
[0046] ● Soft AP mode In the soft AP mode, a communication device (e.g., mobile terminal device 104) operates as a client that requests various services. And the other communication device (e.g., MFP100) operates as a soft AP capable of executing the function of a WLAN AP by software setting. Note that commands and parameters transmitted and received when establishing a wireless connection between the client and the soft AP only need to be those defined by the Wi-Fi (registered trademark) standard, so the description here is omitted. Also, the MFP100 operating in the soft AP mode determines the frequency band and frequency channel as the master station. For this reason, the MFP100 can select which frequency band to use from 5 GHz and 2.4 GHz, and which frequency channel to use in that frequency band.
[0047] ● WFD mode The MFP100 may be fixedly activated as the master station in the WFD mode (Autonomous Group Owner). In this case, the GO Negotiation process for determining the role becomes unnecessary. Also, in this case, the MFP100 determines the frequency band and frequency channel as the master station. For this reason, the MFP100 can select which frequency band to use from 5 GHz and 2.4 GHz, and which frequency channel to use in that frequency band.
[0048] (Wireless infrastructure mode) In the wireless infrastructure mode, communication devices that communicate with each other (e.g., each of the mobile terminal device 104 and the MFP 100) are connected to an external AP (e.g., AP1(101)) that manages the network, and communication between the communication devices is performed via the AP. In other words, communication between the communication devices is executed via the network constructed by the external AP. When the mobile terminal device 104 and the MFP 100 each discover AP1(101) and send a connection request to this AP1(101) to connect, wireless infrastructure mode communication via AP1(101) of these communication devices becomes possible. Note that a plurality of communication devices may be connected to separate APs. In this case, data transfer is performed between the APs, enabling communication between the communication devices. Regarding the commands and parameters transmitted and received during communication between each communication device via the access point, those defined by the Wi-Fi standard are sufficient, so the description here is omitted. Also, in this case, AP1(101) determines the frequency band and frequency channel. Therefore, AP1(101) can select which frequency band to use from 5 GHz, 2.4 GHz, and 6 GHz, and which frequency channel to use in that frequency band.
[0049] (Processing in response to a connection destination change request from the AP to the STA) The mobile terminal device 104 and the MFP 100 support a function published as Wi-Fi Agile Multiband (trademark). Wi-Fi Agile Multiband is a function that enables selection of an optimal environment according to the changing situation of the Wi-Fi network. Specifically, STAs such as the mobile terminal device 104 and the MFP 100 and APs such as AP1(101) exchange information regarding the network environment using the IEEE802.11 series of communication standards. Through such information exchange, when the network is congested, the AP can induce (change the connection destination of) the STA to another AP, frequency band, channel, and in some cases, even to another cellular service.
[0050] FIG. 6 is a sequence diagram when the MFP 100 switches the connection destination AP from AP1(101) to AP2(102) according to a connection destination change request from AP1(101). The processes executed by each device in this sequence are realized by the CPU of each device reading various programs stored in a memory such as a ROM provided in each device into the RAM and executing them.
[0051] In the initial state of the process of FIG. 6, it is assumed that the MFP 100 has established a connection with AP1(101) in the wireless infrastructure mode. Also, when the MFP 100 and AP1(101) are connected in the wireless infrastructure mode, AP1(101) acquires information on whether the MFP 100 supports IEEE802.11v. And when AP1(101) can acquire information indicating that the MFP 100 supports IEEE802.11v, the following processes are performed.
[0052] In S601, AP1(101) sends a query (measurement requests) to the MFP 100 regarding the radio wave intensity of the APs around the MFP 100. This query is sent, for example, as a beacon frame request or a beacon report request. That is, this request can use the mechanism defined in the IEEE 802.11k standard.
[0053] In S602, the MFP 100 receives the frames transmitted by the surrounding APs in response to the request received in S601 and measures the radio wave intensity. As a result, the radio wave intensity of each of a plurality of APs including AP1(101) and AP2(102) is measured.
[0054] In S603, the MFP100 transmits a list of the radio wave intensities of the APs around the MFP100 measured in S602 as a response to the request received in S601. Note that as the radio wave intensities to be responded, in addition to or instead of the information measured in S602, the information stored in the RAM 214 and the non-volatile memory 215 of the MFP100 may be used. This response is transmitted, for example, as a Beacon Report or measurement reports.
[0055] In S604, based on the congestion status in the network grasped by the AP1(101) and the radio wave intensity received from the MFP100 in S603, the AP1(101) determines whether it is necessary to switch the connection destination of the MFP100. The factors for the AP1(101) to determine that the connection switch is necessary include a large number of connected STAs, a large amount of traffic, less congestion in other APs, the presence or absence of interference radio waves, and the stop of the AP function. If it is determined that it is necessary to switch the connection destination of the MFP100 and the SSID, channel, and frequency band of another AP designated as the switch destination of the MFP100 are determined, the process proceeds to S605.
[0056] In S605, the AP1(101) transmits a request to change the AP (connection destination change request) to the MFP100. The connection destination change request includes the information of the SSID, channel, and frequency band of another AP designated as the switch destination for the MFP100 determined in S604. Note that multiple SSIDs may be specified. The connection destination change request is transmitted, for example, as a BTM Request. That is, a BTM (BSS Transition Management) Request frame defined in the IEEE802.11v standard is transmitted. In the example of FIG. 6, it is assumed that the AP2(102) is designated as the switch destination included in the connection destination change request.
[0057] In S606, if the MFP100 follows the connection destination change request received in S605, it transmits a response indicating switching approval to the AP1(101). If it does not follow the connection destination change request, it may transmit a switching rejection as a response. The response is transmitted as a BTM Response. In the example of FIG. 6, it is assumed that a response indicating approval is transmitted.
[0058] In S607, the AP1(101) and the MFP100 disconnect the connection in the wireless infrastructure mode.
[0059] In S608, the MFP100 transmits a connection request to the AP2(102) so as to connect to the AP2(102) specified in the connection destination change request received in S605.
[0060] As a result, in S609, a connection in the wireless infrastructure mode between the MFP100 and the AP2(102) is established.
[0061] With such a mechanism, the MFP100, which is a STA, can change the connection destination from the originally connected AP1(101) to the AP2(102) based on the connection destination change request from the AP1(101). The AP1(101) and the AP2(102) may be APs installed in different locations. That is, by the process of FIG. 6, the MFP100 can switch to another AP installed at a position different from the originally connected AP. Also, among a plurality of frequency bands (any two or three of the 2.4 GHz, 5 GHz, and 6 GHz bands) provided by the same device, they may be APs corresponding to different frequency bands. That is, by the process of FIG. 6, the MFP100 can switch to another frequency band provided by the same device as the originally connected AP. For example, based on the connection destination change request, the connection destination can be changed to an AP in the 6 GHz band.
[0062] Note that in this embodiment, an example is described in which a measurement request and a connection destination change request are transmitted from an AP according to the Wi-Fi Agile Multiband mechanism, and the STA responds thereto. However, the present invention is not limited to this. The present embodiment is applicable even when the STA responds to a measurement request or a connection destination change request transmitted from the AP using a mechanism different from the above example, or changes the connection destination AP (switching, deleting, or adding the AP to be the connection destination).
[0063] There are situations where it is not a problem to change the connection destination AP based on a connection destination AP change request transmitted from the currently connected AP, and situations where it is not preferable. In a situation where it is not preferable to change the connection destination AP based on the change request, as a process for suppressing the change of the connection destination according to the change request, one or more of the following processes can be combined and performed. Each of the following processes is a process for preventing or making it difficult to perform the change of the connection destination AP based on the change request.
[0064] (Suppression Process 1) Even if the change request described in S605 is received, the connection destination AP is not changed based on the received connection request, no response to the change request is returned, or a response indicating rejection (indicating that the connection destination AP will not be changed) is sent to the AP during connection. When a rejection response is sent, the priority of connection destination change for other STAs connected to the AP connected to the MFP100 increases, and the priority of connection destination change for the MFP100 that has returned the rejection response decreases, and as a result, the connection to the AP that was being connected may be maintained. Also, when no response is returned (ignored), the AP during connection is considered to maintain the connection with the MFP100 while waiting for a response until the response waiting time times out. Therefore, in the case where the connection would be immediately disconnected in response to any response from the MFP100 to the change request, not returning any response can extend the time for maintaining the connection with the AP during connection compared to returning some response. Therefore, for example, different processes can be performed according to the reason, such as responding with rejection for a weak reason and ignoring it for a strong reason based on the information on the reason for change included in the change request. The reason for change can be determined based on information on which of several reasons the Request Mode included in the BTM Request corresponds to. For example, when the Disassociation Imminent bit or the BSS Termination Included bit in the Requestmode is 1, the change request can be determined as a change request with a strong reason for change. Otherwise, it can be determined as a change request with a weak reason for change.
[0065] (Suppression Process 2) In response to the measurement request described in S601, for the radio wave reception status (signal reception status) of non-connected APs other than the connected AP, respond (falsely respond) with information indicating that the radio wave status (poor signal quality) is worse than the actually measured status. In this case, actual measurement may be performed and a response may be made in response to the reception of the measurement request, or a response may be made without actually performing the measurement. Specifically, in the response (such as beacon report) described in S603, respond with a value obtained by reducing the received signal strength and / or a value obtained by increasing the noise (signal-to-noise ratio) with respect to the signal quality measured as the signal received from the non-connected AP. Alternatively, a response may be made that does not include at least one piece of information about the non-connected AP. Also, based on the information measured in the past regarding the non-connected AP, either process of setting the received signal strength to a significantly low value or setting the noise to a significantly large value and responding may be performed. Also, even if the measurement request is received, without actually performing the measurement (AP search), a response may be made indicating that only the connected AP has a good received signal strength and noise status without including information about the non-connected AP. Responding to the measurement request without including information about the non-connected AP corresponds to the content that no other non-connected AP is found even if an AP search is performed. That is, responding without including information about the non-connected AP indicates that at least a part of the signal quality from the non-connected AP is worse than when an actual AP search is performed. By doing so, it can be expected that a connection destination change request from the connected AP to another AP is suppressed. Therefore, a change in the connection destination in response to the connection destination change request is suppressed.
[0066] (Suppression Process 3) Disconnect from the connected AP once, notify information indicating that the change request has not been responded to, and then reconnect to the same AP. Specifically, disconnect the wireless connection with the connected AP once, and create data for an Association Request frame including information indicating non - compliance with IEEE802.11v as a preparation for reconnecting wirelessly. Then, perform the connection process with the AP using the created data for the Association Request frame. As a result, if an Association Request frame including information indicating non - compliance with IEEE802.11v is created, the connection will be made with the AP as an electronic device that does not support (is non - compliant with) the Agile Multiband function. As a result, the connected AP will recognize that the MFP100 is non - compliant with IEEE802.11v and will not send a wireless connection destination change request to the MFP100. In this way, since a change in the wireless connection to the MFP100 is not requested, the wireless connection between the MFP100 and the connected AP is likely to be maintained. Also, when the connected AP recognizes that the MFP100 is non - compliant with IEEE802.11v, the transmission of measurement requests (the requests described in S601) from the connected AP to the MFP100 is also suppressed. Therefore, measurements (AP search) in response to measurement requests in the MFP100 and responses to measurement requests (the process of S603) can also be suppressed. Accordingly, the processing load can be reduced, power consumption can be reduced, and resources can be allocated to other processes.
[0067] When it is not preferable to change the destination AP based on a change request, for example, printing data is being received. When the MFP 100 is receiving printing data, it has already received a part of the printing data of the image to be printed from the mobile terminal device 104 which is the counter machine, and the reception of the remaining part of the printing data is not completed. The MFP 100 does not store all of the printing data for one sheet of paper. Therefore, the MFP 100 prints as much as it has received when it receives a part of the printing data (for example, receives and prints one line), and repeats printing by receiving the subsequent data and printing that amount as well. If the destination AP is changed based on a change request during the reception of this printing data, a time lag associated with the destination switching process will occur, which may cause a deterioration in print quality such as uneven printing. Also, after the destination is switched, communication with the mobile terminal device 104 which is the counter machine may not work well, and there is a possibility that the subsequent data cannot be received and the printing fails. Therefore, during the reception of printing data, as a process for suppressing the change of the destination according to the change request, at least one of the above (suppression process 1) and (suppression process 2) should be performed, or the above (suppression process 3) should be performed before the start of the reception of printing data.
[0068] Similarly, depending on the security state set in the MFP 100, it may not be preferable to change the destination AP based on a change request. Below, based on the security set in the MFP 100, the configuration for the MFP 100 to control the execution and suppression of the change of the destination AP will be described.
[0069] [Security Settings of MFP 100] Electronic devices connected to a network are exposed to security threats. Therefore, various security settings need to be properly configured. For example, the MFP100, which is a multifunction printer that can perform operations such as copying, printing, and scanning images, can be used in various types of environments, such as large offices, small offices, public spaces, and telecommuting environments. Therefore, the MFP100 is provided with security settings that can handle various threat levels. This type of security setting has numerous items, some of which are difficult to configure for users without specialized security knowledge. Therefore, the MFP100 of the present embodiment has a function of collectively configuring multiple items of security settings by selecting a security type. For selecting the security type, for example, there are methods such as selecting the type of usage environment in which the MFP100 is placed and selecting a security level that represents the security strength of the MFP100.
[0070] [Security Setting Method by Selecting Usage Environment Type] Figure 7 shows an example of a screen related to the operation of the function for collectively setting the security setting values of the device body on the operation display unit 205 of the MFP100. Figure 7(a) shows the "Main Body Settings" screen displayed when "Main Body Settings" is selected by the user on the screen of Figure 3(b). On this screen, as further selection items, "Print Settings", "Security Settings", "Language Settings", and "Other Settings" are displayed. Figure 7(b) is the security settings screen displayed when the security settings 701 among the selection items are selected on the screen of Figure 7(a). On this screen, as further selection items, "Recommended Security Settings", "Lockout Settings", and "Administrator Password Settings" are displayed.
[0071] Figure 7(c) represents the screen of "Recommended Security Settings" that is displayed when the recommended security setting 702 is selected on the screen of Figure 7(b). In the illustrated screen, as an example of the selection options 703 of the security type set in the MFP 100, six usage environment types (intra-company intranet type 703a, internet connection prohibited type 703b, internet direct connection type 703c, at-home type 703d, public space type 703e, highly confidential information management type 703f) are shown.
[0072] Figure 7(d) represents the confirmation screen that is displayed after any one of the usage environment types is selected on the screen of Figure 7(c) and before the execution of the security settings (batch settings) corresponding to the selected usage environment type. The message 704 represents the final confirmation before the execution of the batch settings and that the MFP 100 will automatically restart after the execution of the batch settings. The security type 705 corresponds to the environment type selected by the user on the previous screen (Figure 7(c)), and in the example of Figure 7(d), it shows that the intra-company intranet type 703a is selected. At the lower part of the screen, a "Yes" button 706 that permits the execution of the security settings and a "No" button 707 that cancels the execution of the security settings are arranged.
[0073] Figure 7(e) is the processing screen that is displayed after the user selects the "Yes" button 706 on the screen of Figure 7(d). The indicator 708 indicates that the internal processing of the MFP 100 is in progress. At this time, inside the MFP 100, a plurality of security setting items are batch-set according to the selected usage environment type, and each setting value is stored in the RAM 214 and the non-volatile memory 215 together with the selected security type. When a series of processing is completed, the MFP 100 displays the ending screen shown in Figure 7(f) and automatically restarts after shutdown. As described above, the MFP 100 has a function of batch-setting a plurality of security-related setting values to values suitable for the usage environment by allowing the user to select the usage environment where the device is placed as the "security type".
[0074] FIG. 8 is a correspondence table showing security setting values by the batch setting function for each usage environment type of the MFP 100. The uppermost row of the table in FIG. 8 shows the usage environment type as the security type. As described above, there are an in-company intranet type, an Internet connection prohibited type, an Internet direct connection type, a telecommuting type, a public space type, and a highly confidential information management type.
[0075] The leftmost column of the table in FIG. 8 shows the security setting items subject to batch setting that the MFP 100 has. "Screen lock setting" is a function that prevents unauthorized operations and information leakage from non-regular users by switching to a screen that requests password input (locking the screen) when the operation display unit 205 has not been operated for a certain period of time. "Bluetooth usage" is a setting for whether to prohibit the connection of external devices by Bluetooth communication. "SNMPv1 usage" is a setting for whether to prohibit communication by a specific version of SNMP (Simple Network Management Protocol) (version 1 in this example). "Available TLS version" is a setting for the available version of TLS (Transport Layer Security), which is an encryption communication protocol in the server function of the MFP 100. "Firmware update notification" is a setting for whether to enable a function that prompts the user to update the firmware by displaying a message on the operation display unit 205 when there is an updated version of the firmware of the MFP 100.
[0076] Any of the security setting items can be set individually from the main body settings or the communication setting menu of the operation display unit 205, but it is also possible to perform batch setting by selecting the security type (in this example, the usage environment type). In the case of batch setting, each security setting item is set to the setting value as shown in the table according to the selected security type. Note that the "-" (hyphen) in the table means not to change from the setting value at the time of factory shipment of the MFP 100 or the setting value set by subsequent user settings. That is, the state immediately before the batch setting is activated (factory shipment value or user setting value) is maintained.
[0077] Regarding the usage environment types, the Internet connection prohibited type is a security setting suitable for using the MFP100 in an environment isolated from the Internet. The intranet type within the company is a security setting suitable for using the MFP100 in an intranet environment managed by a company or the like. The Internet direct connection type is a security setting suitable for using the MFP100 in an environment directly connected to the Internet. The home type is a security setting suitable for using the MFP100 in a home network (LAN within the home) environment managed by an individual. The public space type is a security setting suitable for using the MFP100 in an environment used by an unspecified number of people or a public network environment. The highly confidential information management type is a security setting suitable for using the MFP100 in an environment where the impact is significant when an attack or information leakage occurs. In the security setting of the Internet connection prohibited type, since connectivity within the isolated network is prioritized, only basic security measures are implemented so that the use of information devices using conventional encryption and protocols is not restricted. As shown in the correspondence table in FIG. 8, each security item is set so that the security becomes stronger in the order of the Internet connection prohibited type, the intranet type within the company, the Internet direct connection type, the home type, the public space type, and the highly confidential information management type. In the highly confidential information management type, security is given top priority, and all functions for which even a slight threat is assumed are restricted.
[0078] Among the security setting items, the screen lock setting locks the screen display of the operation screen and requires password input to restrict the user's printer operation. Enabling the screen lock setting improves security but makes the operation cumbersome. Therefore, in this embodiment, it is enabled only in the case of the public space type assumed to be used by an unspecified number of users and the highly confidential information management type that requires very high security. When a type other than these two usage environments is selected, it is not actively set to "enabled" by the batch setting function, and the setting at that time is maintained (indicated by "-(hyphen)" in Fig. 8). Regarding the setting of Bluetooth usage, in the batch setting, "prohibited" is set for the home type, public space type, and highly confidential information management type, which are usage environments where security risks may occur due to Bluetooth communication. Also, the setting of the available TLS version restricts the version of TLS, which is a security method for network communication. In addition to "TLS1.2 / 1.3" shown in Fig. 8, there are TLS1.0 and TLS1.1, but these are old methods and have security risks. Therefore, as shown in Fig. 8, in the batch setting, the available TLS version is set to TLS1.2 / 1.3 in usage environments other than the "Internet connection prohibited type". Since it is not necessary to connect to the Internet in the usage environment of the "Internet connection prohibited type", the use of TLS1.0 / 1.1 may be allowed, so it is set as "-(hyphen)".
[0079] Note that the security setting items set for each security type are not limited to the above. For example, available encryption methods (such as 3DES, AES, AES-GCM, etc.) and available Hash functions (such as SHA-1, SHA-2, etc.) for each security type may be included. Furthermore, for each security type, the necessity of using IPP security, HTTPS security, and Enhanced WSD security may be set. Note that the above-mentioned security items do not limit the security setting items set by batch setting, and not all of the above-mentioned security items need to be set by batch setting.
[0080] Note that among these security setting items, some require resetting the related processing unit to enable the changed setting value. Therefore, when changing the security type (in this example, the usage environment type), the MFP100 will be automatically restarted, and each setting value will be applied after the restart. Also, it is possible for the user not to select any security type, that is, not to use the security batch setting function.
[0081] FIG. 9 is a flowchart showing the process by which the MFP100 responds to a connection destination AP change request according to the state (security setting state) of the MFP100. In this flowchart, the process executed by the MFP100 is realized by the CPU212 reading out various programs stored in a memory such as the ROM213 and executing them in the RAM214.
[0082] In the initial state of the process in FIG. 9, it is assumed that the MFP100 has established a connection with AP1 (101) in the wireless infrastructure mode. Also, when the MFP100 and AP1 (101) connect in the wireless infrastructure mode, AP1 (101) acquires information on whether the MFP100 supports IEEE902.11v. Here, it is assumed that AP1 (101) has acquired information indicating that the MFP100 supports IEEE902.11v, and AP1 (101) makes an inquiry about the radio wave intensity and a connection destination AP change request to the MFP100.
[0083] In S901, the CPU 212 of the MFP 100 determines whether it has received a query (measurement requests) about the radio wave intensity of the APs around the MFP 100 from the AP1 (101). This query is transmitted as a beacon frame request or a beacon report request. The query about the radio wave intensity confirmed to be received in this step corresponds to what the AP1 (101) transmits in S601 of FIG. 6. When the CPU 212 determines that it has received the query about the radio wave intensity (YES in S901), the process proceeds to S902. On the other hand, when the CPU 212 determines that it has not received the query about the radio wave intensity (NO in S901), the process proceeds to S903. In S902, as described in S602 and S603 of FIG. 6, the CPU 212 measures the radio wave intensity of the APs around the MFP 100 and transmits a list of the radio wave intensities of the APs to the AP1 (101) as a Beacon report.
[0084] In S903, the CPU 212 determines whether it has received a request to change the destination AP transmitted by the AP1 (101). This change request corresponds to what the AP1 (101) transmits in S605 of FIG. 6. When the CPU 212 determines that it has received the change request (YES in S903), the process proceeds to S904. On the other hand, when the CPU 212 determines that it has not received the change request (NO in S903), the process proceeds to S911.
[0085] In S904, the CPU 212 of the MFP 100 acquires the security setting value set from the operation screen of FIG. 7 described above. In this example, the security setting is stored in the non-volatile memory 215 or the RAM 214, and the CPU 212 reads the security setting value from the non-volatile memory 215 or the RAM 214. In S905, the CPU 212 acquires the security information of the AP (hereinafter referred to as the destination AP to be changed), which is a candidate for the changed destination included in the connection destination change request received in S605 of FIG. 6. The security information indicates the security method of communication between the MFP 100 and the destination AP. The security information is included in the RSN Information (Robust Security Network Information) field of the Beacon frame of the destination AP. The security information of the destination AP can be acquired by receiving the Beacon from the destination AP again during the process of S905. Alternatively, the security information of the destination AP may be acquired by storing the security information for each AP in the RAM 214 and the non-volatile memory 215 when the radio wave intensity is acquired in S902, and then reading the security information of the destination AP therefrom.
[0086] In S906, the CPU 212 determines whether the change of the connection destination AP is possible based on the device security setting value acquired in S904 and the security information of the destination AP acquired in S905. This determination will be described later with reference to FIG. 10. In S907, the CPU 212 branches the process according to the determination result of S906. That is, if it is determined by the CPU 212 in S907 that the change of the connection destination is possible (YES in S907), the process proceeds to S908, and if it is determined that the change is not possible (NO in S907), the process proceeds to S910. In S908, the CPU 212 transmits a response indicating that it follows the received connection destination change request to the AP1 (101). Then, in S909, the CPU 212 disconnects the connection with the AP1 (101) and executes the connection process with the connection destination AP included in the connection destination change request. S908 corresponds to S606 in FIG. 6, and S909 corresponds to the processes of S607, S608, and S609.
[0087] In S910, the CPU 212 sends a response to the change request that the MFP 100 rejects the change to the AP1 (101) and proceeds to S911. This process corresponds to the rejection response transmission in S606 of FIG. 6 and corresponds to the suppression process 1 described above. In S911, it is determined whether the connection to the connected AP1 (101) is continued. If the connection is continued, the process proceeds to S901. If it is determined that the connection has ended, the process ends.
[0088] FIG. 10(a) shows a determination table 1001 for determining whether an AP can be changed based on the security type (usage environment type) of the device and the security information of the recommended AP for change. In S906, the CPU 212 determines whether the destination AP can be changed by referring to the determination table 1001 shown in FIG. 10(a). The determination table 1001 shows the conditions for determining whether the destination AP can be changed. In the determination table 1001, "device security" is the usage environment type of the MFP 100 selected by the user. "Security of the destination AP for change" is the security information of the destination AP acquired in S905 and has values such as WPA, WPA2, and WPA3, for example. WPA3 has the highest security, and the security decreases in the order of WPA2 and WPA. WPA is the abbreviation of Wi-Fi Protected Access. The CPU 212 determines that the destination AP can be changed if "Yes" is described in the cell corresponding to the combination of the device security (usage environment type) and the security of the destination AP for change in the determination table 1001 of FIG. 10(a), and determines that the destination AP cannot be changed if "No" is described. That is, the security combination with "Yes" described in the cell is the condition for permitting the change of the destination AP in response to the change request. Also, the security combination with "No" described in the cell is the condition for suppressing the change of the destination AP in response to the change request. For example, if the device security is of the intra-company intranet type and the security of the destination AP for change is WPA, it is determined that the destination AP can be changed. However, when the device security is of the public space type that requires higher security, it is determined that the destination AP cannot be changed when the "security of the destination AP for change" is WPA.
[0089] The above described the configuration for determining whether the destination AP can be changed according to the usage environment type set in the MFP100. However, the security state when determining whether the AP can be changed is not limited to this. For example, the security type may be determined by specifying the security level. In this case, the user selects the security level of the MFP100 from the screen for selecting security level options as shown in FIG. 7(g), rather than the screen for selecting the usage environment type as shown in FIG. 7(c). Then, in S906, whether the destination AP can be changed is determined according to the determination table 1002 shown in FIG. 10(b). That is, the CPU212 determines whether the AP can be changed based on the security level set in the MFP100 and the security information of the destination AP by referring to the determination table 1002.
[0090] In the determination table 1002, "Device Security" is the security level of the MFP100 selected by the user. The security level indicates the degree of security strength. In this example, it takes values of level 0, 1, and 2. Level 0 has the weakest security strength, followed by level 1, and level 2 has the strongest security strength. If "Yes" is described in the cell corresponding to the combination of the device security and the security of the destination AP in the determination table, it is determined that the destination AP can be changed; if "No" is described, it is determined that the destination AP cannot be changed. For example, when the device security is level 0 and the security of the destination AP is WPA, the CPU212 determines that the destination AP can be changed. Also, when the device security is level 2 and the security of the destination AP is WPA, the CPU212 determines that the destination AP cannot be changed.
[0091] The above described that "Usage Environment Type" and security level can be used as the selection of the security type. However, the security type can be any setting value that can specify a batch setting of configuration items related to the security of the device, and there is no limitation on how to specify the security type.
[0092] According to the decision table 1001 in Fig. 10(a), in the case of the highly confidential information management type, the change of the destination AP is not allowed regardless of the security information of the destination AP. Thus, when a security type is set where the change of the destination AP is not allowed regardless of the security of the destination AP, the control using the above suppression process 2 is possible. For example, in S902 of Fig. 9, when a usage environment type where the change of the destination AP is not allowed regardless of the security of the destination AP is set (in this example, in the case of the highly confidential information management type), the CPU 212 may execute the suppression process 2. By executing the suppression process 2, a Beacon report indicating that the radio wave situation (poor signal quality) is worse than the actually measured situation is transmitted, so that the request for changing the destination to the MFP 100 is suppressed.
[0093] Also, as shown in Fig. 11, when it is determined in S1101 that the highly confidential information management type is set, without considering the security of the destination AP, it may immediately proceed to S910 and execute the suppression process 1. Also, according to the decision table in Fig. 10(a), in the case of the intra-company intranet type, the change of the destination AP is allowed regardless of the security of the destination AP. Therefore, when it is determined in S1102 that the intra-company intranet type is set, without considering the security of the destination AP, it may immediately proceed to S908 and respond to the request for changing the destination AP. Thus, in the case of the highly confidential information type or the intra-company intranet type, it is possible to determine whether to suppress the change of the destination without obtaining or considering the security of the destination AP in S905.
[0094] Furthermore, when a security type is set such that the change of the destination AP is prohibited regardless of the security of the destination AP, it is also possible to use the suppression process 3. As described in FIGS. 7(c) to 7(f), when the security type is set, the MFP 100 restarts. Therefore, when a security type (in this example, the highly confidential information management type) is set such that the change of the destination AP is prohibited regardless of the security of the destination AP, the CPU 212 controls to execute the suppression process 3 at the time of this restart.
[0095] This process can be specifically realized by the process shown in FIG. 12. That is, in S1201, when the MFP 100 restarts, in S1202, the CPU 212 determines whether the highly confidential information management type is set as the security type. If it is determined by the CPU 212 that the highly confidential information management type is set (YES in S1202), the process proceeds to S1203. In S1203, the CPU 212 generates an Association Request frame including information indicating non - compliance with IEEE802.11v. On the other hand, if it is determined by the CPU 212 that the highly confidential information management type is not set (NO in S1202), the process proceeds to S1204. In S1204, the CPU 212 generates an Association Request frame including information indicating compliance with IEEE802.11v. In S1205, the CPU 212 performs connection processing with the AP using the Association Request frame generated in S1203 or S1204. When an Association Request frame including information indicating non - compliance with IEEE802.11v is created in S1103, the MFP 100 connects to the AP as an electronic device that does not support the Agile Multiband function. As a result, a change request for the destination AP is not made to the MFP 100. On the other hand, when an Association Request frame including information indicating compliance with IEEE802.11v is generated, it will connect to the AP as an electronic device having the Agile Multiband function.
[0096] As is clear from the above, this embodiment has an aspect of controlling whether to suppress the change of the destination AP based only on the security type set in the MFP100.
[0097] As described above, according to this embodiment, when a destination AP change request is received, it is possible to suppress the occurrence of a security risk due to switching the AP based on the change request. That is, it is possible to achieve both connection destination optimization by a technique of dynamically switching the destination AP and avoidance of the security risk of the device.
[0098] Note that each of the various controls described as being performed by the CPU included in each device may be performed by one piece of hardware, or the entire device may be controlled by a plurality of pieces of hardware (for example, a plurality of processors or circuits) sharing the processing.
[0099] In addition, although the present invention has been described in detail based on its preferred embodiments, the present invention is not limited to these specific embodiments, and various forms within the scope not departing from the gist of the present invention are also included in the present invention. Furthermore, each of the above-described embodiments merely shows one embodiment of the present invention, and it is also possible to appropriately combine the embodiments.
[0100] In addition, in the above-described embodiments, the case where the present invention is applied to an MFP has been described as an example. However, this is not limited to this example, and the present invention is applicable to any wireless device that connects to an AP and functions as a STA, and is an electronic device capable of security settings. That is, the present invention is applicable to personal computers, PDAs, tablet terminals, mobile phone terminals such as smartphones, music players, game machines, e-book readers, smartwatches, and various measurement devices (sensor devices) such as thermometers and hygrometers. Further, the present invention is applicable to digital cameras (including still cameras, video cameras, network cameras, and security cameras), printers, scanners, and drones. Further, the present invention is applicable to video output devices, audio output devices (e.g., smart speakers), media streaming players, wireless LAN sub-devices (adapters) capable of connecting to USB terminals and LAN cable terminals. The video output device, for example, acquires (downloads) a video on the Internet specified by a URL instructed from an electronic device and outputs it to a display device connected via a video output terminal such as HDMI (registered trademark), thereby realizing streaming playback on the display device or realizing mirroring display (displaying the content displayed on the electronic device on the display device). The video output device includes, for example, a device that realizes streaming playback on a display device or realizes mirroring display (displaying the content displayed on the electronic device on the display device). Further, the video output device includes TVs, hard disk recorders, Blu-ray recorders, DVD recorders, any media players, head-mounted displays, projectors, TVs, display devices (monitors), signage devices, and the like. Further, the present invention is also applicable to so-called smart home appliances such as air conditioners, refrigerators, washing machines, vacuum cleaners, ovens, microwave ovens, lighting fixtures, heating appliances, and cooling appliances that can be connected to Wi-Fi.
[0101] (Other Embodiments) The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in a computer of the system or device read and execute the program. Further, it can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0102] The disclosure of this specification includes the following electronic devices, control methods for electronic devices, programs, and storage media. (Item 1) An electronic device, a receiving means for receiving a request to change the access point of the connection destination from an access point, a setting means for setting a setting value related to the security of the electronic device, a control means for controlling whether to suppress the change of the access point of the connection destination based on the change request based on the setting value set by the setting means, and an electronic device characterized by having the same. (Item 2) The control means performs the change of the connection destination based on the change request when the first setting value is set by the setting means, and suppresses the change of the connection destination based on the change request when the second setting value is set by the setting means. The electronic device according to Item 1, characterized in that it controls as described above. (Item 3) further comprising an acquisition means for acquiring a security method used for communication with an access point that is a candidate for the connection destination after the change by the change request, The control means controls whether to suppress the change of the access point of the connection destination based on the change request based on the setting value set by the setting means and the security method of communication with the access point that is a candidate for the connection destination. The electronic device according to Item 1, characterized in that it has the same. (Item 4) The control means executes the change of the connection destination in response to the change request when the setting value set by the setting means and the security method acquired by the acquisition means satisfy the first condition, and suppresses the change of the connection destination in response to the change request when the second condition is satisfied. The electronic device according to Item 3, characterized in that it has the same. (Item 5) further comprising an acquisition means for acquiring a security method of communication with an access point that is a candidate for the change of the connection destination by the change request, When the security method of the communication acquired by the acquisition means is the first method and the first set value is set by the setting means, the control means controls to change the connection destination based on the change request. When the second set value is set by the setting means, the control means controls to suppress the change of the connection destination based on the change request. The electronic device according to item 1, characterized in that. (Item 6) The first method is WPA (Wi-Fi Protected Access) or WPA2. The electronic device according to item 5, characterized in that. (Item 7) When the security method of the communication acquired by the acquisition means is a second method that is more secure than the first method, the control means changes the connection destination based on the change request even if the first set value is set by the setting means or the second set value is set. The electronic device according to item 5, characterized in that. (Item 8) The second method is WPA3. The electronic device according to item 7, characterized in that. (Item 9) The set value set by the setting means represents the security level of the electronic device. The electronic device according to any one of items 1 to 8, characterized in that. (Item 10) The set value set by the setting means represents the usage environment type of the electronic device. The electronic device according to any one of items 1 to 8, characterized in that. (Item 11) Based on the set value set by the setting means, at least two of whether to enable the function of locking the screen when not operated for a certain period of time, whether to prohibit the use of Bluetooth, whether to prohibit the use of a specific version of SNMP, the available TLS version, whether to enable the firmware update notification, the available encryption method, the available Hash function, the necessity of IPP security, the necessity of HTTPS security, and the necessity of Enhanced WSD security are determined. The electronic device according to any one of items 1 to 10, characterized in that. (Item 12) An electronic device according to any one of Items 1 to 11, characterized in that it performs connection and processing conforming to the standard of IEEE 802.11ax with an access point. (Item 13) An electronic device according to any one of Items 1 to 12, characterized in that it is capable of executing at least one of processing conforming to Orthogonal Frequency-Division Multiple Access (OFDMA) and processing conforming to Target Wake Time (TWT). (Item 14) The electronic device according to any one of Items 1 to 13, characterized in that the electronic device can change the connection destination to an access point in the 6 GHz band by changing the connection destination based on the change request. (Item 15) An electronic device according to any one of Items 1 to 14, further comprising printing means for printing an image on a recording medium. (Item 16) A control method for an electronic device, a receiving step of receiving a change request for the connection destination access point from an access point; a setting step of setting a setting value related to the security of the electronic device; a control step of controlling whether to suppress the change of the connection destination access point based on the change request based on the setting value set in the setting step, characterized by having. (Item 17) A program for causing a computer to function as each means of the electronic device according to any one of Items 1 to 15. (Item 18) A computer-readable storage medium storing a program for causing a computer to function as each means of the electronic device according to any one of Items 1 to 15.
[0103] The invention is not limited to the above embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Therefore, claims are attached to disclose the scope of the invention.
Explanation of Signs
[0104] 104: Mobile terminal device, 100: MFP, 101: AP1, 102: AP2, 110: Network
Claims
1. An electronic device, A receiving means for receiving a request to change a destination access point from an access point; a setting means for setting a security-related setting value of the electronic device; and a control means for controlling whether or not to suppress a change of a destination access point based on the change request, based on the setting value set by the setting means.
2. 2. The electronic device according to claim 1, wherein the control means controls to change the connection destination based on the change request when a first setting value is set by the setting means, and to suppress the change of the connection destination based on the change request when a second setting value is set by the setting means.
3. The access point change request further includes an acquisition unit for acquiring a security method to be used for communication with an access point that is a candidate for a connection destination after the change request is made, The electronic device according to claim 1, characterized in that the control means controls whether or not to suppress the change of the access point to be connected to based on the change request, based on the setting value set by the setting means and a security method for communication with the access point that is a candidate for the connection destination.
4. 4. The electronic device according to claim 3, wherein the control means executes a change of the connection destination in response to the change request when the setting value set by the setting means and the security method acquired by the acquisition means satisfy a first condition, and suppresses the change of the connection destination in response to the change request when the setting value set by the setting means and the security method acquired by the acquisition means satisfy a second condition.
5. The access point change request further includes an acquisition unit for acquiring a security method for communication with an access point that is a candidate for a connection destination change in response to the change request, The electronic device according to claim 1, characterized in that when the communication security method acquired by the acquisition means is a first method and a first setting value is set by the setting means, the control means controls to change the connection destination based on the change request, and when a second setting value is set by the setting means, the control means controls to suppress the change of the connection destination based on the change request.
6. 6. The electronic device according to claim 5, wherein the first method is WPA (Wi-Fi Protected Access) or WPA2.
7. The electronic device according to claim 5, characterized in that when the communication security method acquired by the acquisition means is a second method which is more secure than the first method, the control means changes the connection destination based on the change request regardless of whether the first setting value or the second setting value is set by the setting means.
8. The electronic device according to claim 7 , wherein the second method is WPA3.
9. 2. The electronic device according to claim 1, wherein the setting value set by said setting means represents a security level of the electronic device.
10. 2. The electronic device according to claim 1, wherein the setting value set by said setting means represents a type of an environment in which the electronic device is used.
11. 2. The electronic device according to claim 1, wherein at least two of the following are determined based on the setting values set by the setting means: whether to enable a function of locking a screen when no operation is performed for a certain period of time; whether to prohibit use of Bluetooth; whether to prohibit use of a specific version of SNMP; a usable TLS version; whether to enable a firmware update notification; an available encryption method; an available Hash function; whether IPP security is required; whether HTTPS security is required; and whether Enhanced WSD security is required.
12. 2. The electronic device according to claim 1, wherein the electronic device performs connection and processing with the access point in compliance with the IEEE 802.11ax standard.
13. 2. The electronic device according to claim 1, characterized in that the electronic device is capable of executing at least one of a process conforming to Orthogonal Frequency-Division Multiple Access (OFDMA) and a process conforming to Target Wake Time (TWT).
14. 2. The electronic device according to claim 1, wherein the electronic device is capable of changing the connection destination to an access point in the 6 GHz band by changing the connection destination based on the change request.
15. 2. The electronic device according to claim 1, further comprising a printing unit for printing an image on a recording medium.
16. A method for controlling an electronic device, comprising: a receiving step of receiving a request to change a destination access point from an access point; a setting step of setting a security-related setting value of the electronic device; a control step of controlling whether or not to suppress a change of a destination access point based on the change request, based on the setting value set in the setting step.
17. A program for causing a computer to function as each of the means of the electronic device according to any one of claims 1 to 15.
18. A computer-readable storage medium storing a program for causing a computer to function as each of the means of the electronic device according to any one of claims 1 to 15.
Citation Information
Patent Citations
Mobile router, mobile router control method and mobile router control program
JP2021175068A