Wireless LAN access point, home network apparatus, setting information update method for wireless LAN access point, and setting information update program for wireless LAN access point

The wireless LAN access point with a setting information update function addresses security risks by changing SSIDs and encryption keys upon user change detection, ensuring secure and hassle-free continuation of network devices in rental properties.

JP2025098783APending Publication Date: 2025-07-02OPTAGE INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2023215150
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-20
Publication Date
2025-07-02

AI Technical Summary

Technical Problem

Existing wireless LAN access points and in-house network devices face security risks due to the reuse of SSID and encryption keys, which can be easily known by previous users, allowing unauthorized access, especially in rental properties or when contracts end, leading to laborious device replacements.

Method used

A wireless LAN access point with a setting information update function that includes a wireless communication unit, storage for multiple SSIDs and encryption keys, and a detection unit to change the keys upon user change detection, such as contract termination or specific operations, ensuring new users can securely connect without factory default settings.

Benefits of technology

This solution effectively prevents unauthorized access by changing SSID and encryption keys when user changes occur, allowing seamless continuation of IoT devices and in-house equipment without manual reconfiguration, thus enhancing security and reducing labor costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025098783000001_ABST
    Figure 2025098783000001_ABST
Patent Text Reader

Abstract

To provide a wireless LAC access point comprising a setting information update function for excluding the security risk that may occur in the case of reuse.SOLUTION: A wireless LAN access point 10 comprises: a wireless communication section 11 connected with a wireless communication terminal 110; a setting information storage section 13 which stores a plurality of SSID and encryption keys; a setting information update section 15 which updates combinations of the SSIDs and the encryption keys; and a network communication section 20. In the wireless LAN access point 10, in a case where a notification of contract end is received from an ISP or in a case where specific operation input is received, a non-used combination of an SSID and an encryption key is selected from the setting information storage section and set to the wireless communication section 10 by the setting information update section 15. In the case of power failure recovery and when a reset button is pressed, a value of the combination of the SSID and the encryption key which is set to the wireless communication section 10 is held.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a wireless LAN access point, an in-house network device including the wireless LAN access point, a method for updating setting information of the wireless LAN access point, and a program for updating the setting information of the wireless LAN access point.

Background Art

[0002] The following inventions are disclosed regarding the update of setting information of communication network devices and devices using a communication network. For example, Patent Document 1 (Japanese Unexamined Patent Application Publication No. 2015-091082) discloses a wireless communication device capable of changing wireless LAN settings without interrupting communication. The wireless communication device of Patent Document 1 includes a first communication unit that communicates using a first setting that is the SSID before the change or the encryption key information before the change, a second communication unit that communicates using a second setting that is the SSID after the change or the encryption key information after the change, a changing unit that changes the wireless LAN setting from the first setting to the second setting, a network communication unit that communicates with an external device connected via a network, and a setting information notification unit that notifies the first communication terminal that connects using the first setting of the second setting via the first communication unit after the wireless LAN setting is changed from the first setting to the second setting by the changing unit.

[0003] Further, Patent Document 2 (Japanese Unexamined Patent Application Publication No. 2006-279829) discloses a remote operation system that prevents unauthorized use and enables remote operation of facility equipment by a terminal device in a short time from a request for issuance of identification information. The remote operation system described in Patent Document 2 includes a facility device that enables remote operation by data communication through a communication network, a terminal device that performs data communication through the communication network with the facility device and remotely operates the facility device, and a center device that transfers data between the terminal device and the facility device on the communication network. The center device includes an identification information issuing unit that issues identification information for collating the combination of the facility device and the terminal device, and a data transfer unit that collates the facility device and the terminal device using the identification information issued by the identification information issuing unit during data communication between the facility device and the terminal device and transfers data between the facility device and the terminal device corresponding to the identification information. The facility device includes an identification information request unit that requests the generation of identification information from the center device by a specific operation input, an identification information storage unit that stores the identification information generated by the identification information issuing unit of the center device in response to the request from the identification information request unit for subsequent data communication, and an output unit that outputs the identification information stored in the identification information storage unit. The terminal device is characterized by including an input unit that inputs the identification information output from the output unit of the facility device without passing through the communication network, and an identification information setting unit that stores the identification information input from the input unit for subsequent data communication.

[0004] Further, Patent Document 3 (Japanese Unexamined Patent Application Publication No. 2019-022150) discloses a facility device that can surely invalidate remote operation by a departing occupant when the occupant of the house where the facility device is installed is replaced. The facility device described in Patent Document 3 includes a display unit, a function execution unit capable of executing a specific function, and a control unit having a memory. The control unit can store authentication information in the memory, and when receiving from a terminal device authentication information that matches the authentication information stored in the memory and a function execution instruction, it is configured to cause the function execution unit to execute a specific function. The control unit can detect that power has been restored after a power outage. When detecting that power has been restored while the first authentication information is stored in the memory, a selection screen is displayed on the display unit for allowing the user to select whether to change the first authentication information. When it is selected by the user to change the first authentication information on the selection screen, the first authentication information stored in the memory is deleted, and second authentication information different from the first authentication information is stored in the memory. When it is selected by the user not to change the first authentication information on the selection screen, the storage of the first authentication information is maintained without deleting the first authentication information stored in the memory. The facility device further includes an operation setting unit for setting whether to display the selection screen on the display unit when the control unit detects that power has been restored after a power outage.

[0005] Further, Patent Document 4 (Japanese Unexamined Patent Application Publication No. 2018-182452) discloses a communication system capable of eliminating requests related to residential equipment by a communication terminal of a former resident. The communication system described in Patent Document 4 includes a home appliance, a relay device that communicates with the home appliance, and a management device that is connected to a communication network and communicates with the relay device via the communication network and a wireless LAN router connected to the communication network. The management device associates, by a predetermined process, the identification information of the relay device, the identification information of the wireless LAN router, and the user identification information of a communication terminal that communicates with the management device via the communication network, stores these pieces of information as association information, and has a control configuration that enables the stored association information. In a state where the association information is enabled, when the identification information of the relay device and the identification information of the wireless LAN router are transmitted from the relay device, it is determined based on the association information whether the identification information of the wireless LAN router transmitted after storage matches the identification information of the wireless LAN router associated with the identification information of the relay device. If they do not match, the association information is configured to be invalidated. Also, when request information regarding the home appliance is received from the communication terminal together with the user identification information, the process corresponding to the request information is performed only when the association information including the received user identification information is valid.

[0006] Further, Patent Document 5 (Japanese Unexamined Patent Application Publication No. 2014-060627) discloses an information processing apparatus, a communication system, and a communication program capable of realizing automatic function switching according to the position of a portable terminal device. The information processing apparatus described in Patent Document 5 includes a wireless communication unit that wirelessly communicates with a portable terminal device, and a control unit that has a plurality of functions and executes each function. The control unit is characterized by switching between a restriction mode that restricts a specific function among the plurality of functions and a normal mode that releases the restriction of the specific function when the wireless communication unit recognizes that the portable terminal device is located within a preset range. Also, Patent Document 5 describes that, for example, image data (e.g., QR code (registered trademark)) indicating various information of a wireless LAN router may be displayed on a display unit, and the various information of the wireless LAN router may be registered in an access table by imaging the image data with a camera provided in a smartphone (see paragraph

[0092] of the specification).

[0007] In addition, Patent Document 6 (Japanese Patent Application Laid-Open No. 2003-316431) discloses a flow rate control device that does not require replacement of the rated nameplate even after a specification change and can always know the accurate specification. The flow rate control device described in Patent Document 6 is a flow rate control device capable of setting the type and / or flow rate of the fluid to be handled and changing its specifications, and is characterized by having a display unit that displays the changed specifications. The display unit is an electronic paper that does not require power to maintain the display of the display unit and can always display the display unit.

Prior Art Documents

Patent Documents

[0008]

Patent Document 1

Patent Document 2

Patent Document 3

Patent Document 4

Patent Document 5

Patent Document 6

Summary of the Invention

Problems to be Solved by the Invention

[0009] Generally, when performing an Internet connection using Wi-Fi, from the setting screen of a smartphone or PC that serves as a slave device, the SSID, which is the name of the wireless network transmitted by a wireless LAN access point that serves as a master device or a home NW device including the wireless LAN access point, is selected, and the encryption key necessary for connection is input to perform connection settings. If the SSID and encryption key of in-house NW devices are known to malicious third parties, there is a risk of intrusion into the Internet or theft of information within the network. Therefore, in general wireless LAN access points and in-house NW devices, the initial values of the SSID and encryption key are not unique but are preset with unique values for each individual, so that third parties other than the user cannot easily know the initial values. The user who is the administrator can change the SSID and encryption key to arbitrary values, but when the device is initialized, it returns to the preset values of the SSID and encryption key.

[0010] Since the initial values of the SSID and encryption key of in-house NW devices are preset with unique values for each individual, users can originally use Wi-Fi with confidence even with the initial values. However, in an environment assuming reuse, since previous users (terminals) may know the initial values, there is a risk that new users who inherit the device can easily intrude into the network environment. Specifically, this occurs when the occupants change in weekly condominiums or rental properties where in-house NW devices are permanently installed, or when in-house NW devices returned to the ISP (Internet Service Provider) upon the end of the line contract are lent to the next new user. Therefore, in such cases, the in-house NW devices are usually replaced, and in reality, there are labor costs required for the replacement and disposal of old devices.

[0011] The wireless communication device described in Patent Document 1 is a wireless communication device that can change the wireless LAN settings without interrupting communication by including a first communication unit and a second communication unit. From a security perspective, it is described that it is desirable to periodically change the SSID and encryption information (see paragraph

[0002] of the specification). However, Patent Document 1 does not describe that it is desirable to change the SSID and encryption information when the user changes, nor does it describe how to change the SSID and encryption information when the user changes.

[0012] The remote operation system described in Patent Document 2 is a remote operation system that, when the occupant changes, performs a specific operation input on the facility equipment to request the center device to issue identification information, and updates the identification information to prevent unauthorized use and enable the terminal device to remotely operate the facility equipment within a short time from the request for issuance of the identification information. However, in the remote operation system described in Patent Document 2, only specific facility equipment can prevent unauthorized use. For example, if the SSID and encryption key of the wireless LAN access point are the same as before the occupant changes, there is a possibility that the previous occupant can intrude into other facility equipment or a personal computer via the wireless LAN access point.

[0013] The facility device described in Patent Document 3, when detecting a return from a power outage, determines by the user whether it is an accidental power outage or a power outage associated with a change in the occupant of the house. In the case of a power outage associated with a change in the occupant, it erases the first authentication information stored in the memory and stores second authentication information different from the first authentication information in the memory. However, also in the facility device described in Patent Document 3, only specific facility devices can prevent unauthorized use. For example, if the SSID and encryption key of the wireless LAN access point are the same as before the occupant changes, there is a possibility that the previous occupant can intrude into other facility devices or a personal computer via the wireless LAN access point.

[0014] The communication system described in Patent Document 4 associates the identification information of a relay device, the identification information of a wireless LAN router, and the user identification information of a communication terminal that communicates with a management device via a communication network by a predetermined process, stores these pieces of information as association information, and determines whether the identification information of the wireless LAN router transmitted after the storage matches the identification information of the wireless LAN router associated with the identification information of the relay device. If they do not match, the association information is configured to be invalidated. However, in the communication system described in Patent Document 4, it is premised that the wireless LAN router is replaced when the occupant changes. In the case of a weekly condominium or a rental property where in-house NW equipment is permanently installed, and the wireless LAN router continues to be used as it is when the occupant changes, there is a possibility that the residential equipment may be misused by the communication terminal of the former occupant.

[0015] In the information processing apparatus described in Patent Document 5, it is described that various information of a wireless LAN router may be registered in the access table of a smartphone by displaying image data indicating the various information of the wireless LAN router on a display unit and imaging the image data with a camera provided in the smartphone. In the information processing apparatus described in Patent Document 5, when various information (such as an SSID and an encryption key) of a wireless LAN router is changed, the changed various information of the wireless LAN router can be taken into the smartphone by displaying the image data indicating the various information on the display unit. However, Patent Document 5 does not describe in what cases the various information of the wireless LAN router is changed and how to change it.

[0016] In the flow rate control device described in Patent Document 6, in a device whose specifications can be changed, even after the specification change, it is not necessary to replace the rated nameplate (corresponding to the seal on the side of the housing), and in order to be able to know the exact specifications at any time, it is described that a display unit composed of electronic paper that does not require power to maintain the display of the display unit and can always display the display unit is provided. However, Patent Document 6 is a flow control device, and its technical field is different from that of a wireless LAN access point. Moreover, since it does not describe how to set and display the currently used SSID and encryption key, the technology of the electronic paper described in Patent Document 6 is not applicable.

[0017] In recent years, in houses such as rental properties, not only wireless LAN access points or in-house network devices, but also wirelessly connected IoT devices such as network cameras and water heaters, and in-house equipment devices are provided by management companies or the owner side, and may continue to be used even when the user changes. In such a case, if the SSID and encryption key of the wireless LAN access point are changed, it is troublesome because the management company etc. has to visit and change the settings of the SSID and encryption key of the IoT devices and in-house equipment devices. In such a case, it is desirable that the settings of the wirelessly connected IoT devices and in-house equipment devices provided by the management company or the owner side can be continuously used without being changed.

[0018] The main object of the present invention is to provide a wireless LAN access point, an in-house network device, and a setting information update method having a setting information update function for eliminating security risks that occur when reusing a wireless LAN access point or an in-house network device equipped with a wireless LAN access point. Another object of the present invention is to update the setting information of a device newly installed and connected to a network by a user in a house such as a rental property where a wireless LAN access point or an in-house network device equipped with a wireless LAN access point, an IoT device, and an in-house equipment device are reused, and to provide a wireless LAN access point, an in-house network device, and a setting information update method capable of continuously using the setting information of the reused IoT devices and in-house equipment devices.

Means for Solving the Problems

[0019] (1) A wireless LAN access point according to one aspect includes a wireless communication unit that connects to a wireless communication terminal via a wireless LAN network, a setting information storage unit that stores a plurality of SSIDs and a plurality of encryption keys, a setting information update unit that updates a combination of the SSID and the encryption key set in the wireless communication unit, and a network communication unit that connects to the Internet via a network. The setting information update unit includes a user change detection unit. The user change detection unit determines that the user has been changed when receiving a notification of specific communication indicating the end of the contract from an ISP (Internet Service Provider) or when receiving a specific operation input. When the user change detection unit determines that the user has been changed, the setting information update unit selects a combination of an unused SSID and an encryption key from the setting information storage unit and sets it in the wireless communication unit, and holds the values of the combination of the SSID and the encryption key set in the wireless communication unit at the time of power failure recovery and when the reset button is pressed. When the wireless LAN access point is built in a home network device, the function of the network communication unit that connects to the Internet via a network may be included in the router device and / or the optical line termination device (ONU) of the home network device.

[0020] In an environment assuming reuse, since a previous user (or the user's terminal) knows the setting information including the SSID and the encryption key of the wireless LAN access point, there is a risk that the previous user can easily intrude into the network environment of the new user who has taken over the wireless LAN access point. In this case, although the new user can eliminate the intrusion of the previous user by changing the SSID and the encryption key while being aware of the security risk, if the new user does not change them, the SSID and the encryption key of the previous user remain valid and the previous user can easily intrude. Furthermore, with conventional wireless LAN access points, when a power outage is restored or the reset button is pressed, the factory default SSID and encryption key are set in the wireless communication unit. Therefore, even if a new user changes the SSID and encryption key, the factory default SSID and encryption key are restored, which may allow the previous user to gain access. Also, depending on the type of contract with the ISP, if a previous user cancels their contract, they may receive a specific communication notification indicating the termination of their contract. However, with conventional wireless LAN access points, it was not possible to change the SSID and encryption key in response to this notification.

[0021] In order to solve the above problems of conventional wireless LAN access points, a wireless LAN access point according to one aspect has the following functions (a) to (e) added thereto. (a) A setting information storage unit is provided to store a plurality of SSIDs and encryption keys. (b) A setting information update unit and a user change detection unit are provided within the setting information update unit, and the user change detection unit determines that the user has been changed when a notification of a specific communication indicating the termination of a contract is sent from the ISP, or when a notification is sent indicating that there has been no communication confirmation using the registered authentication ID for a certain period of time. In addition, a case where there is no communication confirmation using a registered authentication ID for a certain period of time means, for example, a case where a user neglects to terminate their line contract, and the ISP forcibly terminates the contract, resulting in the authentication ID being unusable for a certain period of time. (c) The user change detection unit also determines that the user has been changed when a specific operational input is received, such as pressing and holding a specific button or pressing two specific buttons simultaneously. In this case, it is desirable to provide a conspicuous notice on the side of the housing, in the instruction manual, etc., so that new users can perform the above operations reliably. (d) If the user change detection unit determines that the user has been changed, the setting information update unit selects an unused combination of SSID and encryption key from the setting information storage unit and sets it in the wireless communication unit. (e) When power is restored and when the reset button is pressed, the settings of the wireless communication unit do not return to the combination of the SSID and encryption key at the time of factory shipment, but instead retain the combination of the SSID and encryption key that has been set in the wireless communication unit. Note that if the user further changes the combination of the SSID and encryption key after the setting information update unit has set the combination of the SSID and encryption key in the wireless communication unit, it is desirable that when power is restored and when the reset button is pressed, it returns to the combination of the SSID and encryption key that the setting information update unit last set.

[0022] (2) The wireless LAN access point according to the second invention is a wireless LAN access point that follows one aspect, and may further include a display unit that displays the combination of the SSID and encryption key set in the wireless communication unit.

[0023] In a conventional wireless LAN access point, a sticker printed with the SSID and encryption key at the time of factory shipment was attached to the housing. However, in the wireless LAN access point of the present invention, since the SSID and encryption key used when the user changes are changed, it is not possible to print and attach the SSID and encryption key in use on a sticker. The wireless LAN access point according to the second invention includes a display unit, and when the SSID and encryption key are changed, by displaying the combination of the changed SID and encryption key on the display unit, even when the user changes, the SSID and encryption key in use are always displayed, so that the user can easily set the combination of the SSID and encryption key in a wireless terminal such as a smartphone. Also, the SSID and encryption key may be displayed in the form of a QR code (registered trademark), and by photographing the QR code (registered trademark) with the camera of a smartphone, connection information with the wireless LAN access point may be set in the smartphone.

[0024] (3) The wireless LAN access point according to the third invention, in the wireless LAN access point according to the second invention, the display unit may be configured with an electronic paper.

[0025] Since the electronic paper only needs to be supplied with power only when updating information, it consumes little power, and is lightweight and can be provided with a display unit as long as there is a little space such as the side of the housing. Therefore, it is preferable as a display unit for displaying the SSID and encryption key of the wireless LAN access point.

[0026] (4) The wireless LAN access point according to the fourth invention, in the wireless LAN access point according to any one of the third inventions from one aspect, the wireless communication unit includes a plurality of combinations of an SSID and an encryption key, and at least one of the plurality of combinations is such that when the user change detection unit determines that the user has been changed, the values of the SSID and the encryption key are also retained, and the value of the retained encryption key may be kept secret from the user.

[0027] In a residence such as a rental property, not only the wireless LAN access point or in-house network equipment, but also wirelessly connected IoT devices such as network cameras and water heaters and in-house facility equipment are provided by a management company or the owner side, and may continue to be used even when the user is replaced. In such a case, if the SSID and encryption key of the wireless LAN access point are changed, the settings of the SSID and encryption key of the IoT devices and in-house facility equipment also have to be changed, which is troublesome. In the wireless LAN access point according to the fourth invention, the wireless communication unit has a plurality of combinations of an SSID and an encryption key, and for at least one of the plurality of combinations, the values of the SSID and the encryption key are retained even when the user change detection unit determines that the user has been changed. Therefore, by setting the SSID and the encryption key of the wireless-connected IoT devices and in-house equipment devices, which are provided by a management company or the owner side and continue to be used even when the user is replaced, to the SSID and the encryption key whose values are retained even when the user change detection unit determines that the user has been changed, it is possible to continue using the IoT devices and in-house equipment devices without changing the settings of the SSID and the encryption key.

[0028] Specifically, for example, smartphones, notebook computers, TVs, etc. owned by users of rental properties connect to the network of the main SSID, and network cameras, water heaters, etc. provided by a management company or the owner side connect to the network of the sub-SSID. Then, the setting information update function may be applied only to the main SSID. In this case, there is a risk that the former user may connect to the wireless LAN access point using the SSID and the encryption key to be continuously used. In order to avoid this risk, it is necessary to keep secret at least the encryption key to be continuously used from the users of rental properties, etc. Specifically, the ID and password for users of rental properties, etc. and the ID and password for the management company or the owner are made different, and when opening the management screen of the wireless LAN access point on the WebUI, log in with their respective ID and password. Then, the user can view and change the main SSID, but cannot view or change the sub-SSID, while the management company or the owner can view and change both the main and sub-SSIDs.

[0029] (5) The wireless LAN access point according to the fifth invention is, in the wireless LAN access point according to any one of the fourth inventions from one aspect, during normal use, stores the connection information of the wireless communication terminals connected to the wireless communication unit, and the user change detection unit, at the time of power restoration after a power outage continues for a predetermined number of days, attempts to connect to each of the wireless communication terminals using the connection information stored before the power outage, and if the number of connectable units among the wireless communication terminals for which the connection information is stored is equal to or less than a predetermined number, it may be determined that the user has been changed.

[0030] In the wireless LAN access point of the present invention, it is important to surely change the SSID and the encryption key when the user of the wireless LAN access point is changed. Therefore, the user change detection unit of the wireless LAN access point according to one aspect determines that the user has been changed when it receives a notice indicating the end of the contract from the ISP and when a new user performs a specific operation. However, depending on the ISP, there may be a possibility that a notice indicating the end of a specific contract is not sent, and there may also be a case where a new user forgets the operation for changing the SSID and the encryption key.

[0031] On the other hand, in the case of weekly mansions or rental housing, etc., until the previous user cancels the contract and a new user signs a contract and moves in, that is, for a predetermined number of days, the breaker of the house is tripped and the wireless LAN access point remains in a power outage state continuously. This predetermined number of days is usually at least 7 days or more. And when a new user starts using the wireless LAN access point, the wireless LAN access point always resumes from the power outage state. However, even when resuming from a power outage, the user is not necessarily changed. For example, there may be a power outage due to a natural disaster, etc. However, when the user is changed, at least some of the wireless communication terminals used by the previous user are no longer used. For example, smartphones, notebook computers, etc. that the previous user owned and used are no longer used.

[0032] In the user change detection unit of the wireless LAN access point according to the fifth invention, when power is restored after a power outage continues for a predetermined number of days, it is determined whether it is possible to connect to a wireless communication terminal that was previously used. Specifically, during normal use, the connection information of the wireless communication terminals connected to the wireless communication unit is saved, and when power is restored, an attempt is made to connect to each of the wireless communication terminals using the saved connection information. If the number of connectable wireless communication terminals among those whose connection information was saved is equal to or less than a predetermined number, it may be determined that the user has been changed. In this case, the predetermined number of days is, for example, 7 days. Also, the predetermined number is, for example, the number of wireless communication terminals provided by the management company or the owner side and continuously used even when the user is replaced. If there are no wireless communication terminals to be continuously used, it may be determined that the user has not been changed even if there is one connectable terminal. Also, when the wireless LAN access point according to the fifth invention has a main SSID that is the SSID of the wireless communication terminal held by the user and a sub SSID that is the SSID of the wireless communication terminal provided by the management company or the owner side, that is, when it is the wireless LAN access point according to the fourth invention, an attempt is made to connect only to the wireless communication terminals connected to the main SSID, and if the connection to the wireless communication terminals connected to the main SSID fails, it may be determined that the user has been changed.

[0033] (6) The in-house network device according to another aspect includes, from one aspect, a wireless LAN access point according to any of the fifth inventions, a wired communication unit that connects to a wired communication terminal, and a router device and / or an optical network unit (ONU).

[0034] In this case, the in-house network device can eliminate the security risks that occur during reuse by updating the SSID and encryption key of the wireless LAN access point when the user is changed.

[0035] (7) A setting information update method according to still another aspect is a setting information update method for updating the SSID and encryption key of a wireless LAN access point including a wireless communication unit and a network communication unit. The method includes a setting information storage step of storing combinations of a plurality of SSIDs and encryption keys, and a setting information update step of updating the combination of the SSID and encryption key set in the wireless communication unit. When receiving a notification of a specific communication indicating the end of a contract from an ISP (Internet Service Provider), or when receiving a specific operation input, the setting information update step selects an unused combination of an SSID and an encryption key from the combinations of the SSID and the encryption key stored in the setting information storage step and sets it in the wireless communication unit. At the time of power failure recovery and when the reset button is pressed, the values of the combination of the SSID and the encryption key set in the wireless communication unit are retained.

[0036] A setting information update method according to still another aspect is an invention of a setting information update method provided in a wireless LAN access point according to one aspect. In an environment assuming reuse, since a previous user (terminal) knows the setting information including the SSID and encryption key of the wireless LAN access point, there is a security risk that the previous user can easily intrude into the network environment of a new user who has taken over the wireless LAN access point. This is an invention of a setting information update method for eliminating such a security risk.

[0037] (8) The setting information update program that follows yet another aspect is a setting information update program for updating the SSID and encryption key of a wireless LAN access point including a wireless communication unit and a network communication unit. The program includes a setting information storage process for storing combinations of a plurality of SSIDs and encryption keys, and a setting information update process for updating the combination of the SSID and encryption key set in the wireless communication unit. When receiving a notification of a specific communication indicating the end of a contract from an ISP (Internet Service Provider), or when receiving a specific operation input, the setting information update process selects an unused combination of an SSID and an encryption key from the combinations of the SSIDs and encryption keys stored in the setting information storage process and sets it in the wireless communication unit. When power is restored and when the reset button is pressed, the values of the combination of the SSID and encryption key set in the wireless communication unit are retained.

[0038] The setting information update program that follows yet another aspect is an invention of a setting information update program for a wireless LAN access point that follows one aspect. In an environment assuming reuse, since a previous user (of a terminal) knows the setting information including the SSID and encryption key of the wireless LAN access point, there is a security risk that the previous user can easily intrude into the network environment of a new user who has taken over the wireless LAN access point. This is an invention of a setting information update method for eliminating such a security risk.

Brief Description of the Drawings

[0039]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

[0040] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In the following description, the same components are denoted by the same reference numerals. Also, in the case of the same reference numerals, their names and functions are the same. Therefore, detailed descriptions thereof will not be repeated. Also, it is assumed that the respective embodiments can be implemented in appropriate combinations.

[0041] [First Embodiment] FIG. 1 is a schematic diagram showing an example of the configuration of a network system 200 including a wireless LAN access point 10, a home network device 100, and related devices according to the first embodiment, and FIG. 2 is a schematic configuration diagram showing an example of the internal configuration of the wireless LAN access point 10. Also, FIG. 3 is a schematic flowchart showing a flow of a setting information update method in the wireless LAN access point 10 according to the first embodiment. In FIG. 1, the home network device 100 includes a wireless LAN access point 10, an antenna 25, a wired communication unit 30, and a line termination unit 40. The home network device 100 is connected to the wireless communication terminal 110 by wireless communication via the antenna 25, connected to the wired communication terminal 120 by wired communication via the wired communication unit 30, and further connected to the Internet 130 and the ISP server 140 via the line termination unit 40 (ISP is an abbreviation for Internet Service Provider). The line termination unit 40 is a normal router device when the connection line to the Internet 130 is an electrical line, and an optical line termination device (ONU) when the connection line is an optical line.

[0042] In FIG. 2, the wireless LAN access point 10 includes a wireless communication unit 11, a setting information storage unit 13, a setting information update unit 15, a display unit 17, an operation unit 18, and a control unit 19. The wireless communication unit 11 is wirelessly connected to the wireless communication terminal 110 via the antenna 25. The preset unit 12 of the wireless communication unit 11 has a SSID and an encryption key used for communication with the wireless communication terminal 110 preset therein. In the storage unit 14 of the setting information storage unit 13, a plurality of SSIDs and encryption keys are stored. The storage number of each of the SSID and the encryption key is not limited and can be increased or decreased according to the memory capacity of the network device. For example, if 1000 types are stored for each, it is preferable that one million combinations can be realized by randomly combining the SSID and the encryption key.

[0043] The setting information update unit 15 includes a user change detection unit 16. When the user change detection unit 16 detects a user change, it selects an unused combination of an SSID and an encryption key from the setting information storage unit 13 and sets it in the preset unit 12 of the wireless communication unit 11. The user change detection unit 16 determines that the user has changed, for example, when receiving a notification of a specific communication indicating the end of the contract from the ISP server 140, or when receiving a specific operation input such as long-pressing a specific button or pressing two buttons simultaneously by the operation unit 18. Note that in order to surely detect the above user change, it is desirable to describe the above specific operation input in the manual of the wireless LAN access point 10 and / or on the housing as a request to a new user. In addition, it is desirable to request the user who has finished using the rental property to terminate the line contract with the ISP at the same time. Furthermore, in the case where the user who has finished using the rental property neglects to terminate the line contract, if the ISP forcibly terminates the contract and uses the specific communication indicating the end of the contract with the fact that the authentication ID cannot be used for a certain period as a flag, it is more preferable that the change of the user can be surely detected.

[0044] The display unit 17 displays the combination of the SSID and the encryption key currently set in the preset unit 12 of the wireless communication unit 11. In a conventional wireless LAN access point 10, a seal is often attached to the housing, and the combination of the SSID and the encryption key at the time of factory shipment is displayed on the seal. However, the wireless LAN access point 10 of the present invention is premised on reuse, and when the user changes it, the combination of the SSID and the encryption key is changed. Therefore, it is not possible to display the combination of the SSID and the encryption key in use with the seal attached to the housing. For this reason, the wireless LAN access point 10 of the present invention is provided with a display unit 17, and when the combination of the SSID and the encryption key is changed, the changed combination of the SSID and the encryption key is displayed on the display unit 17. As the display device of this display unit 17, a liquid crystal display can also be used. However, since it is only necessary to supply power only when updating information, the power consumption is small, and in addition, an electronic paper that is lightweight and can be provided with the display unit 17 as long as there is a small space such as the side surface of the housing is more preferable as the display device.

[0045] The operation unit 18 is usually provided with a power switch, a reset button, a WPS (Wi-Fi Protected Setup) button, and the like. In the wireless LAN access point 10 of the present invention, in addition to these operations, it is necessary to receive a specific operation input for notifying that the user has been changed. As a specific operation input method, a new button may be added. For example, the user may be notified by a method such as long-pressing the reset button or pressing the reset button and the WPS button at the same time.

[0046] The control unit 19 mediates the cooperation between the wireless communication unit 11, the setting information storage unit 13, the setting information update unit 15, the display unit 17, and the operation unit 18. Further, it detects the restoration of power after a power failure and the pressing of the reset button, and in this case, prevents the combination of the SSID and the encryption key from being updated. Note that the setting information storage unit 13, the setting information update unit 15, and the control unit 19 are not individual hardware components, but can also be realized by causing a CPU (Central Processing Unit) and a memory (D-RAM and / or non-volatile memory) built into the wireless LAN access point 10 to execute a computer program on the CPU.

[0047] (Flow of setting information change) FIG. 3 shows a schematic flowchart of a setting information update method and a setting information update program in the wireless LAN access point 10. The operations will be described step by step below. (Step S01) A plurality of SSIDs and encryption keys are stored in the storage unit 14 of the setting information storage unit 13. The number of stored SSIDs and encryption keys is not limited. For example, if 1000 types are stored for each, a combination of one million types can be realized by randomly combining the SSIDs and encryption keys, which is preferable. (Step S02) One combination is randomly selected from the SSIDs and encryption keys stored in the setting information storage unit 13 and is initially set in the preset unit 12 of the wireless communication unit 11. The wireless communication unit 11 performs wireless communication with the wireless communication terminal 110 using the SSID and encryption key set in the preset unit 12. Also, the values of the set SSID and encryption key are displayed on the display unit 17.

[0048] (Step S03) Check whether there is a notice of contract termination from the ISP server 140. If a notice of contract termination has arrived, proceed to setting information update (Step S05). (Step S04) Check whether there is a specific operation input such as long-pressing the reset button or simultaneously pressing the reset button and the WPS button on the operation unit 18. (Step S05) If a contract termination notice has arrived in step S03, or if a specific operation input has been detected in S04, the user change detection unit 16 determines that the user has been changed, and the setting information update unit 15 randomly selects one unused combination from the SSID and encryption key stored in the setting information storage unit 13 and sets it in the preset unit 12 of the wireless communication unit 11. The wireless communication unit 11 wirelessly communicates with the wireless communication terminal 110 using the SSID and encryption key set in the preset unit 12. Also, the values of the set SSID and encryption key are displayed on the display unit 17. After that, it waits until a contract termination notice arrives or a specific operation is input. By continuing the above flow, when reusing the wireless LAN access point 10, it is possible to eliminate the security risk that a previous user of the wireless LAN access point 10 accesses the wireless LAN access point 10 improperly.

[0049] [Second Embodiment] The wireless LAN access point 10 and the in-house network device 100 of the second embodiment have the same basic configuration as the wireless LAN access point 10 and the in-house network device 100 of the first embodiment. However, in the second embodiment, the wireless communication terminals 110 connected by the wireless communication unit 11 are classified into at least two wireless LAN networks, and at least two combinations of SSIDs and encryption keys corresponding to each network are preset in the preset unit 12 of the wireless communication unit 11, and wireless communication is performed using different combinations of SSIDs and encryption keys for each network. FIG. 4 is a schematic diagram showing an example of the configuration of the SSID of the wireless network according to the second embodiment. In FIG. 4, the wireless LAN access point 10 includes a plurality of combinations of an SSID and an encryption key, specifically, a main SSID and an encryption key and a sub SSID and an encryption key. In the wireless LAN access point 10 of the second embodiment, for example, wireless communication terminals 110 such as a smartphone 110a and a notebook computer 110b possessed by a user such as a rental property connect to the network of the main SSID. On the other hand, wireless communication terminals 115 such as a network camera 115a and a water heater 115b provided by a management company or an owner side connect to the network of the sub SSID. Then, the setting information update function of the present invention is applied only to the SSID and the encryption key of the main SSID, and the SSID and the encryption key of the sub SSID are not updated even when the user of the wireless LAN access point 10 changes. In a house such as a rental property, not only the wireless LAN access point 10 or the in-house network device 100, but also wirelessly connected IoT devices such as a network camera 115a and a water heater 115b and in-house equipment devices are provided by a management company or an owner side, and may continue to be used even when the user is replaced. In such a case, if the SSID and the encryption key of the network to which the wireless communication terminal 115 provided by the management company or the owner side is connected are changed, the settings of the SSID and the encryption key of the IoT device and the in-house equipment device must also be changed, which is complicated.

[0050] In this case, there is a risk that the old user connects to the wireless LAN access point 10 using the combination of the SSID and the encryption key of the network of the sub SSID to be continuously used. In order to avoid this risk, it is necessary to conceal from the user of the rental property or the like the combination of the SSID and the encryption key to be continuously used. Specifically, for example, methods such as turning on the stealth function of the wireless LAN access point 10 for the sub SSID and making it possible only for the management company or the owner side to view and set the SSID and the encryption key to be continuously used can be considered.

[0051] [Third Embodiment] In the third embodiment, the wireless LAN access point 10 and the in-house network device 100 have the same basic configuration as the wireless LAN access point 10 and the in-house network device 100 in the first embodiment. However, in the third embodiment, a new user change detection method is added to the user change detection unit 16. In the first or second embodiment, when the user change detection unit 16 receives a notification of a specific communication indicating the end of the contract from the ISP server 140, or when the operation unit 18 receives a specific operation input such as long-pressing a specific button or pressing two buttons simultaneously, it determines that the user has been changed.

[0052] However, depending on the ISP, there may be a possibility that a notification indicating the end of a specific contract is not sent, and there may also be a case where a new user forgets the operations for changing the SSID and the encryption key. On the other hand, in the case of a rental house, etc., until the previous user cancels the contract and a new user signs the contract and moves in, the circuit breaker of the house is tripped and the wireless LAN access point 10 is in a power-off state. Therefore, when a new user starts using the wireless LAN access point 10, the wireless LAN access point 10 always resumes from the power-off state. However, even when resuming from a power outage, the user is not necessarily changed. For example, there may be a power outage due to a natural disaster, etc. However, when the user is changed, at least some of the wireless communication terminals 110 that were used by the previous user are no longer used. For example, the smartphone 110a, notebook computer 110b, etc. that were used by the previous user are no longer used.

[0053] (Flow of the Added User Change Detection Method and the User Change Detection Method Program) In the third embodiment, in addition to the user detection method of the first and second embodiments, it is determined whether or not it is possible to connect to the wireless communication terminal 110 that was previously used when the power is restored. FIG. 5 is a schematic flowchart showing an example of the flow of the user change detection method added to the wireless LAN access point 10 according to the third embodiment. Hereinafter, the operation will be described for each step. (Step S11) During normal use, specifically, at the time of initial setting and when a wireless communication terminal 110 is added, connection information such as the MAC address of the connected wireless communication terminal 110 is saved. (Step S12) Wait until the power failure recovery state. In the determination of whether it is a power failure recovery, in the case of continuous power failure for a predetermined number of days, for example, only for the power failure recovery after continuous power failure for 7 days or more, it may be determined as a power failure recovery. (Step S13) When the power failure recovery state is reached, check whether each wireless communication terminal 110 can be connected using the connection information of the wireless communication terminal 110 saved before the power failure. In this case, the connection confirmation target may be limited to the wireless communication terminal 110 with a connection record within a predetermined period, for example, within 1 year. (Steps S14, S15) If the number of connected wireless communication terminals 110 is equal to or less than a predetermined value, it is determined that a user change has been detected. If it is more than the predetermined value, it is determined that the user has not been changed, and wait until the next power failure recovery state. Note that the predetermined value is, for example, the number of wireless communication terminals 110 provided by the management company or the owner side and continuously used even when the user is replaced. If there is no wireless communication terminal 110 that is continuously used, it may be determined that the user has not been changed if there is even one connected unit. Also, as in the case of the second embodiment, when the wireless LAN access point 10 has a main SSID and a sub-SSID, the wireless communication terminal 110 held by a user such as a rental property connects to the network group of the main SSID, and the wireless communication terminal 115 provided by a management company or the owner side connects to the network group of the sub-SSID, connection confirmation may be performed only for the wireless communication terminal 110 connected to the main SSID, and when connection is confirmed for even one of the wireless communication terminals 110 connected to the main SSID, it may be determined that the user has not been changed.

[0054] In the present invention, the wireless communication terminals 110 and 115 correspond to the 'wireless communication terminal', the wireless communication unit 11 corresponds to the 'wireless communication unit', the setting information storage unit 13 corresponds to the'setting information storage unit', the setting information update unit 15 corresponds to the'setting information update unit', the Internet 130 corresponds to the 'Internet', the network communication unit 20 corresponds to the 'network communication unit', the wireless LAN access point 10 corresponds to the 'wireless LAN access point', the user change detection unit 16 corresponds to the 'user change detection unit', the ISP server 140 corresponds to the 'ISP server', the display unit 17 corresponds to the 'display unit', the wired communication unit 30 corresponds to the 'wired communication unit', the wired communication terminal 120 corresponds to the 'wired communication terminal', the line termination unit 40 corresponds to the 'router device and / or optical line termination device (ONU)', and the in-house network device 100 corresponds to the 'in-house network device'.

[0055] A preferred embodiment of the present invention is as described above, but the present invention is not limited thereto. It will be understood that various embodiments may be made without departing from the spirit and scope of the present invention. Further, in the present embodiment, the actions and effects according to the configuration of the present invention are described, but these actions and effects are merely examples and do not limit the present invention.

Description of Reference Numerals

[0056] 10 Wireless LAN access point 11 Wireless communication unit 13 Setting Information Storage Unit 15 Setting Information Update Unit 16 User Change Detection Unit 17 Display Unit 20 Network Communication Unit 30 Wired Communication Unit 40 Line Termination Unit 100 In-House Network Device 110, 115 Wireless Communication Terminals 120 Wired Communication Terminal 130 Internet 140 ISP Server

Claims

1. A wireless communication unit that connects to a wireless communication terminal via a wireless LAN network; A setting information storage unit that stores a plurality of SSIDs and a plurality of encryption keys; A setting information update unit that updates the combination of the SSID and the encryption key set in the wireless communication unit; A wireless LAN access point comprising a network communication unit that connects to the Internet via a network, wherein the setting information update unit includes a user change detection unit, the user change detection unit determines that the user has changed when receiving a notification of a specific communication indicating the end of a contract from an ISP (Internet Service Provider) or when receiving a specific operation input, when the user change detection unit determines that the user has changed, the setting information update unit selects a combination of an unused SSID and an encryption key from the setting information storage unit and sets it in the wireless communication unit, A wireless LAN access point that holds the values of the combination of the SSID and the encryption key set in the wireless communication unit at the time of power failure recovery and when the reset button is pressed.

2. The wireless LAN access point according to claim 1, further comprising a display unit that displays the combination of the SSID and the encryption key set in the wireless communication unit on the display unit.

3. The wireless LAN access point according to claim 2, wherein the display unit is composed of electronic paper.

4. The wireless communication unit includes a plurality of combinations of the SSID and the encryption key, at least one of the plurality of combinations holds the values of the SSID and the encryption key even when the user change detection unit determines that the user has changed, The wireless LAN access point according to claim 1, wherein the value of the encryption key held is kept secret from the user.

5. During normal use, stores the connection information of the wireless communication terminal connected to the wireless communication unit, at the time of power failure recovery after a power failure continues for a predetermined number of days, the user change detection unit attempts to connect to each of the wireless communication terminals using the connection information stored before the power failure, and when the number of connectable units among the wireless communication terminals where the connection information is stored is equal to or less than a predetermined number, determines that the user has changed. The wireless LAN access point according to claim 1.

6. The wireless LAN access point according to any one of claims 1 to 5, a wired communication unit that connects to a wired communication terminal, and a router device and / or an optical network unit (ONU), a home network device.

7. A setting information update method for updating the SSID and encryption key of a wireless LAN access point including a wireless communication unit and a network communication unit, a setting information storage step of storing combinations of a plurality of the SSIDs and the encryption keys, and a setting information update step of updating the combination of the SSID and the encryption key set in the wireless communication unit, wherein the setting information update step when receiving a notification of specific communication indicating the end of a contract from an ISP (Internet Service Provider), or when receiving a specific operation input, selects an unused combination of the SSID and the encryption key from the combinations of the SSID and the encryption key stored in the setting information storage step and sets it in the wireless communication unit, A setting information update method for a wireless LAN access point that holds the values of the combination of the SSID and the encryption key set in the wireless communication unit at the time of power failure recovery and when the reset button is pressed.

8. A setting information update program for updating the SSID and encryption key of a wireless LAN access point including a wireless communication unit and a network communication unit, a setting information storage process of storing combinations of a plurality of the SSIDs and the encryption keys, and a setting information update process of updating the combination of the SSID and the encryption key set in the wireless communication unit, wherein the setting information update process when receiving a notification of specific communication indicating the end of a contract from an ISP (Internet Service Provider), or when receiving a specific operation input, selects an unused combination of the SSID and the encryption key from the combinations of the SSID and the encryption key stored in the setting information storage process and sets it in the wireless communication unit, A setting information update program for a wireless LAN access point that holds the values of the combination of the SSID and the encryption key set in the wireless communication unit at the time of power failure recovery and when the reset button is pressed.

Citation Information

Patent Citations

  • Equipment for flow control

    JP2003316431A

  • Remote control system

    JP2006279829A

  • Information processing device, communication system, and communication program

    JP2014060627A

  • Radio communication device, communication terminal, communication control method, and program

    JP2015091082A

  • Communication system

    JP2018182452A