Communication device and computer program for communication device
The communication device dynamically adjusts its operational state to allow or disallow connections based on user preferences, addressing the challenge of managing multiple communication standards and enhancing security by preventing unauthorized access.
Patent Information
- Application Number
- JP2025122238
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-07-22
- Publication Date
- 2025-09-30
AI Technical Summary
Existing communication devices struggle to appropriately manage connections with multiple coexisting communication standards, particularly when transitioning between WPA3 and earlier security protocols, leading to potential security vulnerabilities and service disruptions.
The communication device includes a control unit that dynamically adjusts its operational state based on user instructions, allowing it to permit or restrict connections according to specific communication standards, ensuring secure and appropriate service reception by changing states to either allow or disallow connections conforming to different standards.
This approach enables secure and reliable service reception by permitting only desired communication standards, preventing unauthorized connections and enhancing security by preventing eavesdropping, thus ensuring seamless operation in environments with mixed communication standards.
Smart Images

Figure 2025142235000001_ABST
Abstract
Description
[Technical Field]
[0001] The technology disclosed in this specification relates to a communication device that can be connected to an external device. [Background technology]
[0002] As shown in Non-Patent Document 1, the Wi-Fi Alliance (registered trademark) has formulated WPA3, a new communication standard for the Wi-Fi system. WPA3 provides a next-generation security protocol. In addition, other security protocols may be provided for communication standards other than WPA3. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-019085 [Patent Document 2] Japanese Patent Application Laid-Open No. 2016-208448 [Patent Document 3] Japanese Patent Application Publication No. 2019-106610 [Non-patent literature]
[0004] [Non-Patent Document 1] “WPA3 Specification Version 3.0” Wi-Fi Alliance, 2020, https: / / www.wi-fi.org / ja / discover-wi-fi / security Summary of the Invention [Problem to be solved by the invention]
[0005] With the establishment of new communication standards, it is expected that various communication standards will coexist. This specification discloses a technique for appropriately receiving services provided by a specific communication standard in such a coexistence situation. [Means for solving the problem]
[0006] A communication device disclosed in this specification includes a communication interface, an operation unit, and a first change unit that, when the operation unit receives an instruction to establish a first connection with a first external device via the communication interface while the communication device is in a first state, changes the state of the communication device from the first state to a second state different from the first state, wherein the first state is a state that permits use of both the first connection and use of a second connection with a second external device via the communication interface, the second state is a state that permits use of the first connection but does not permit use of the second connection, the first connection is a connection conforming to a first communication standard, and the second connection is a wireless connection conforming to a second communication standard different from the first communication standard. The first change unit.
[0007] When the operation unit receives an instruction to establish a connection in accordance with the first communication standard, it is assumed that the user of the communication device wishes to receive a service provided by the first communication standard. According to the above configuration, when it is estimated that a user of the communication device wishes to receive a service provided by a first communication standard, the state of the communication device is changed from a first state to a second state. In the second state, use of a first connection according to the first communication standard is permitted, but use of a second connection according to the second communication standard is not permitted. In a situation where the first standard and the second standard coexist, it is possible to appropriately receive the service provided by the first communication standard.
[0008] Another communication device disclosed in this specification comprises a communication interface, an operation unit, and a control unit that causes the communication device to operate in a third state when the operation unit receives an instruction to establish a first connection with a first external device via the communication interface, and causes the communication device to operate in a fourth state when the operation unit receives an instruction to establish a second connection with a second external device via the communication interface, wherein the third state is a state in which use of the first connection is permitted and use of the second connection is not permitted, and the fourth state is a state in which use of both the first connection and the second connection is permitted, the first connection being a connection conforming to a first communication standard, and the second connection being a connection conforming to a second communication standard different from the first communication standard.
[0009] When the operation unit receives an instruction to establish a first connection according to the first communication standard, it is presumed that the user of the communication device wishes to receive a service provided by the first communication standard. According to the above configuration, when it is presumed that the user of the communication device wishes to receive a service provided by the first communication standard, the control unit causes the communication device to operate in a third state. In the third state, use of the first connection according to the first communication standard is permitted, but use of the second connection according to the second communication standard is not permitted. In a situation where the first communication standard and the second communication standard coexist, it is possible to appropriately receive a service provided by the first communication standard.
[0010] Furthermore, when the operation unit receives an instruction to establish a connection according to the second communication standard, it is presumed that the user of the communication device wishes to receive services provided by the second communication standard. According to the above configuration, when it is presumed that the user of the communication device wishes to receive services provided by the second communication standard, the control unit causes the communication device to operate in a fourth state. In the fourth state, not only the use of the first connection according to the first communication standard but also the use of the second connection according to the second communication standard is permitted. In a situation where the first communication standard and the second communication standard coexist, it is possible to appropriately receive services provided by the second communication standard.
[0011] Furthermore, the above-mentioned control method for the communication device, the computer program for the communication device, and the storage medium for storing the computer program are also novel and useful. [Brief explanation of the drawings]
[0012] [Figure 1] 1 shows the configuration of a communication system. [Figure 2] The sequence diagram for case C1 where there are no APs that do not support WPA3 is shown below. [Figure 3] The sequence diagram for Case C2 where a WPA3-incompatible AP exists is shown below. [Figure 4] A sequence diagram of Case C3, which is a continuation of Case C1, is shown. [Figure 5] An example problem is shown below. [Figure 6] A sequence diagram of case C4 that addresses the example problem of FIG. 5 is shown below. [Figure 7] 1 shows a table representing the relationship between APs and MFPs in the first embodiment. [Figure 8] 10 shows a sequence diagram of a specific case in the second embodiment. [Figure 9] 10 shows a table representing the relationship between APs and MFPs in the second embodiment. [Figure 10] 10 shows the configuration of a communication system according to a third embodiment. [Figure 11]10 shows a sequence diagram of a specific case in the third embodiment. [Figure 12] 10 shows the configuration of a communication system according to a fourth embodiment. [Figure 13] 10 shows a sequence diagram of a specific case in the fourth embodiment. [Figure 14] 13 shows a table representing the relationship between APs and servers in the fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0013] (First Example) (Configuration of communication system 2; Figure 1) 1, the communication system 2 includes an MFP (abbreviation of Multifunction Peripheral) 10, a terminal device 100, and APs (abbreviation of Access Points) 200 and 300. Each of the APs 200 and 300 is capable of forming a wireless LAN (abbreviation of Local Area Network). The MFP 10 is connected to a wireless LAN formed by an AP (e.g., 200), and is capable of communicating with other devices (e.g., terminal device 100) connected to the wireless LAN. The terminal device 100 is a mobile terminal, a desktop PC, a notebook PC, or the like.
[0014] (MFP10 configuration; Figure 1) The MFP 10 is a peripheral device (for example, a peripheral device of the terminal device 100) that can perform functions such as printing and scanning. The MFP 10 includes an operation unit 12, a display unit 14, a Wi-Fi interface 16, a print execution unit 20, a scan execution unit 22, and a control unit 30. Each unit 12 to 30 is connected to a bus line (reference numerals omitted). Below, the interface will be simply referred to as "I / F."
[0015] The operation unit 12 has a plurality of keys. A user can input various instructions to the MFP 10 by operating the operation unit 12. The display unit 14 is a display for displaying various information. The display unit 14 may also function as a touch panel (i.e., the operation unit 12).
[0016] The Wi-Fi I / F 16 is a wireless I / F for performing wireless communication in accordance with the Wi-Fi (registered trademark) standard. The Wi-Fi standard is a standard for performing wireless communication in accordance with, for example, the IEEE (The Institute of Electrical and Electronics Engineers, Inc.) 802.11 standard and its equivalent standards (e.g., 802.11a, 11b, 11g, 11n, etc.).
[0017] The Wi-Fi I / F 16 also supports WPA3 Personal and Enterprise. Personal is a method for authenticating a slave station in a small-scale wireless LAN such as a home. Enterprise is a method for authenticating a slave station in a large-scale wireless LAN such as a company. In Enterprise, an authentication server (see the third embodiment) that performs authentication in accordance with IEEE 802.1X authenticates a slave station in the Wi-Fi standard. On the other hand, in the Personal mode, an authentication server is not used, and the AP authenticates the slave station using, for example, a PSK (short for Pre-Shared Key).
[0018] WPA3 is a communications standard established by the Wi-Fi Alliance (registered trademark) as the successor to WPA2. WPA3 provides next-generation security protocols. For example, WPA3 provides a new method for authenticating client stations, SAE (Simultaneous Authentication of Equals).
[0019] In addition, in WPA3, wireless connections are protected by PMF (short for Protected Management Frames), whereas in WPA2, wireless connections may or may not be protected by PMF.
[0020] The print execution unit 20 has a printing mechanism such as an inkjet system, a laser system, etc. The scan execution unit 22 has a scanning mechanism such as a CCD (abbreviation of Charge Coupled Device) image sensor, a CIS (abbreviation of Contact Image Sensor), etc.
[0021] The control unit 30 includes a CPU 32 and a memory 34. The CPU 32 executes various processes in accordance with a program 40 stored in the memory 34. The memory 34 is configured by a volatile memory, a non-volatile memory, or the like.
[0022] The memory 34 further stores WPA3 setting information 42. The WPA3 setting information 42 indicates one of a plurality of settings, including a setting "WPA3 Transition Mode" and a setting "WPA3 Only Mode." The setting "WPA3 Transition Mode" is a setting that allows both establishment of a wireless connection according to WPA3 and establishment of a wireless connection according to WPA2. For example, the setting "WPA3 Transition Mode" allows both authentication of a slave station using PSK and authentication of a slave station using SAE. Here, PSK is a method that can be used in standards prior to WPA2. The setting "WPA3 Only Mode" is a setting that allows establishment of a wireless connection according to WPA3 but does not allow establishment of a wireless connection according to WPA2. For example, the setting "WPA3 Only Mode" does not allow authentication of a slave station using PSK, but allows authentication of a slave station using SAE.
[0023] When the MFP 10 is shipped, the WPA3 setting information 42 indicates the setting "WPA3 Transition Mode." After the MFP 10 is powered on for the first time, the WPA3 setting information 42 indicates the setting "WPA3 Transition Mode" by default. Note that in a modified example, the default of the WPA3 setting information 42 may be another setting different from both the setting "WPA3 Transition Mode" and the setting "WPA3 Only Mode" (for example, a setting that uses only WPA2).
[0024] (Configuration of AP200 and 300; Figure 1) The AP200 does not support WPA3. The AP200 supports WPA2. In the following, non-support of WPA3 may be referred to as "not WPA3 compatible." The AP200 stores the SSID (short for Service Set Identifier) "ap01" that identifies the wireless network formed by the AP200, and the password "xxxx" used for that wireless network.
[0025] The AP300 supports WPA3. Hereinafter, support for WPA3 may be referred to as "WPA3 compatible." The AP300 stores the same SSID "ap01" as the AP200 and the password "yyyy" used in the wireless network formed by the AP300. In a modified example, the password for the AP300 may be the same as the password for the AP200, "xxxx."
[0026] (Case C1; Figure 2) Referring to FIG. 2, a specific case C1 realized by the communication system 2 of this embodiment will be described. In this case, a wireless connection is established between the MFP 10 and an AP in a situation where there are no WPA3-incompatible APs around the MFP 10. In this case and in cases C2 to C4 in FIGS. 3 to 6 described later, WPA3 Personal is used. In the initial stage of this case, the WPA3 setting information 42 of the MFP 10 indicates the setting "WPA3 Transition Mode" by default. Note that in the first embodiment and the second and third embodiments described later, all of the following communications performed by the MFP 10 are performed via the Wi-Fi I / F 16. In the following description of communication processing, the phrase "via the Wi-Fi I / F 16" may be omitted. In addition, for ease of understanding, in the following description, operations performed by the CPU of each device (e.g., CPU 32) may be described primarily in terms of each device (e.g., MFP 10) rather than the CPU.
[0027] When the MFP 10 receives an instruction to establish a wireless connection via the operation unit 12 at T10, the MFP 10 broadcasts a Probe request to the outside at T12 to search for APs present around the MFP 10. In this case, a WPA3-compatible AP 300 is present around the MFP 10, and no other APs are present. Therefore, at T14, the MFP 10 receives a Probe response to the Probe request from only one AP 300. The Probe response includes the SSID "ap01" of the AP 300 and WPA3 compatibility information indicating that the AP 300 supports WPA3. The WPA3 compatibility information includes, for example, information indicating the use of SAE.
[0028] At the next T20, the MFP10 displays a selection screen for selecting one AP from one or more APs (hereinafter referred to as "one or more surrounding APs") present around the MFP10. The selection screen includes, for each of the one or more surrounding APs, the SSID in the Probe response received from that AP, a button for selecting that SSID, and a message indicating whether that AP supports WPA3. In this case, the selection screen includes only the SSID "ap01" of AP300. In addition to the list of SSIDs, the selection screen also includes an input field for the AP's password.
[0029] At T22, the user operates operation unit 12 of MFP 10 to select SSID "ap01" on the selection screen and enters password "yyyy".
[0030] When the MFP 10 receives selection of the SSID "ap01" of the WPA3-compatible AP 300 and input of the password "yyyy" at T22, it determines at T24 whether a WPA3-incompatible AP exists among one or more surrounding APs in addition to a WPA3-compatible AP. Specifically, the MFP 10 determines whether a probe response not including WPA3 compatibility information (hereinafter referred to as a "non-compatible probe response") exists among one or more probe responses received from one or more surrounding APs in addition to a probe response including WPA3 compatibility information. Then, if a non-compatible probe response exists among one or more probe responses, the MFP 10 determines that a WPA3-incompatible AP exists among one or more surrounding APs. On the other hand, if a non-compatible probe response does not exist among one or more probe responses, the MFP 10 determines that a WPA3-incompatible AP does not exist among one or more surrounding APs. If a WPA3-incompatible AP is selected, the processes of T24 and T26 are not executed, and a process for establishing a wireless connection with the WPA3-incompatible AP is executed (see T230 to T250 in FIG. 4). Also, if only WPA3-incompatible APs exist among one or more surrounding APs, the processes of T24 and T26 are not executed.
[0031] In this case, one WPA3-compatible AP 300 is present around the MFP 10, and no WPA3-incompatible APs exist. In this case, the MFP 10 determines in T24 that no WPA3-incompatible APs exist among the one or more surrounding APs, and proceeds to the processing of T26. Here, a case in which a WPA3-incompatible AP exists among the one or more surrounding APs in addition to a WPA3-compatible AP will be described later with reference to FIG. 3.
[0032] At T26, the MFP 10 changes the WPA3 setting information 42 from the setting "WPA3 Transition Mode" to the setting "WPA3 Only Mode."
[0033] In T30, authentication communication is executed between the MFP 10 and the AP 300 selected in T22, so that the AP 300 can authenticate the MFP 10. In the authentication, authentication is executed according to SAE, and if the authentication is successful, an encryption key generated using the password "yyyy" entered in T22 is provided to both the AP 300 and the MFP 10. After the authentication communication is successful, association communication (not shown) is executed.
[0034] In T40, the MFP 10 performs 4-way handshake communication with the AP 300 using the encryption key provided in T30. As a result, in T50, a wireless connection is established between the MFP 10 and the AP 300 for performing wireless communication in accordance with the Wi-Fi standard. In this case, the WPA3 setting information 42 of the MFP 10 indicates the setting "WPA3 Only Mode," and the AP 300 supports WPA3. Therefore, in this 4-way handshake, communication is performed for management by the PMF. The wireless connection of T50 is then managed by the PMF.
[0035] For example, in a situation where both the MFP 10 and the terminal device 100 are connected to a wireless LAN formed by the AP 300, the terminal device 100 transmits print data indicating an image to be printed to the MFP 10 via the AP 300 at T60.
[0036] When the MFP 10 receives print data from the terminal device 100 in T60, it causes the print execution unit 20 to print the image indicated by the received print data in T62.
[0037] For example, a situation may be assumed in which a malicious third party attempts to connect MFP10 to a wireless network formed by AP800 prepared by the third party, instead of AP300. The SSID of AP800 is set to "ap01," the same as the SSID of AP300. AP800 is a non-WPA3 AP and does not support the security protocols provided by WPA3. Therefore, AP800 has weaker security than AP300. For example, the third party may attempt to intercept communications using AP800, which has weak security.
[0038] In the above situation, the third party first disrupts communication between the AP 300 and the MFP 10, disconnecting the wireless connection between the AP 300 and the MFP 10. The MFP 10 detects the disconnection of the wireless connection at T70. To attempt to re-establish the wireless connection, the MFP 10 broadcasts a Probe request to the outside at T72. At T74, because communication with the AP 300 has been disrupted, the MFP 10 receives a Probe response to the Probe request from the AP 800. The Probe response includes the SSID "ap01" and WPA3 non-compatibility information indicating that the AP 800 supports standards earlier than WPA2.
[0039] In this case, at T26 described above, the WPA3 setting information 42 is changed to the setting "WPA3 Only Mode." As described above, in the setting "WPA3 Only Mode," authentication of a client station using PSK is not permitted, but authentication of a client station using SAE is permitted. In this case, because the AP 800 does not support WPA3, the AP 800 attempts to authenticate the client station using PSK. However, because the MFP 10 does not permit authentication of a client station using PSK, the authentication fails. As a result, establishment of a wireless connection between the AP 800 and the MFP 10 fails.
[0040] For example, consider a comparative example in which the process of T26 described above is not executed and the WPA3 setting information 42 is maintained in the setting "WPA3 Transition Mode." As described above, the setting "WPA3 Transition Mode" allows both authentication of the slave station using PSK and authentication of the slave station using SAE. Therefore, in this comparative example, the authentication of the slave station using PSK attempted by the AP 800 may be successful, and a wireless connection may be established between the AP 800 and the MFP 10. In contrast, according to this case, a wireless connection is not established between the AP 800 and the MFP 10, and eavesdropping of communications using the AP 800 by a third party may be prevented.
[0041] Furthermore, when the operation unit 12 receives an instruction to establish a wireless connection with the AP 300, i.e., when the user selects the SSID "ap01" at T22, it is assumed that the user wishes to receive a service provided by SAE of WPA3 (i.e., communication with relatively high encryption strength). According to this case, when it is assumed that the user wishes to receive a service provided by SAE (T22), the WPA3 setting information 42 is changed from the setting "WPA3 Transition Mode" to the setting "WPA3 Only Mode" (T26). In a situation where SAE of WPA3 and PSK of WPA2 or earlier coexist, it is possible to appropriately receive a service provided by SAE of WPA3.
[0042] (Case C2; Figure 3) Another specific case C2 will be described with reference to Fig. 3. This case is a case where a wireless connection is established between the MFP 10 and an AP in a situation where a WPA3-incompatible AP and a WPA3-compatible AP are present around the MFP 10. The initial stage of this case is similar to case C1 in Fig. 2.
[0043] T110, T112A, and T112B are the same as T10 and T12 in Figure 2. In this case, there are two APs 200 and 300 around the MFP 10, AP 200 is an AP that does not support WPA3, and AP 300 is an AP that supports WPA3. Therefore, in T114A and T114B, the MFP 10 receives a probe response from each of the two APs 200 and 300. The probe response from AP 200 includes the SSID "ap01" and information that WPA3 is not supported.
[0044] In T120, the MFP 10 displays a selection screen including two SSIDs, "ap01." T122 is the same as T20 in FIG.
[0045] In T124, the MFP 10 executes the same determination as in T24 in Fig. 2. In this case, in addition to the WPA3-compatible AP 300, a WPA3-incompatible AP 200 exists around the MFP 10. Therefore, in T124, the MFP 10 determines that, in addition to the WPA3-compatible AP 300, a WPA3-incompatible AP exists among one or more surrounding APs, and proceeds to T126.
[0046] In T126, the MFP 10 determines whether the SSID of a WPA3-incompatible AP among one or more surrounding APs is the same as the SSID of the WPA3-compatible AP selected in T122. In this case, the SSID "ap01" of AP 300 is the same as the SSID "ap01" of AP 200. Therefore, the MFP 10 determines that the two SSIDs are the same and skips the process of T26 in FIG. 2. That is, the WPA3 setting information 42 is maintained in the setting "WPA3 Transition Mode." T130 to T150 are the same as T20 to T50 in FIG. 2. On the other hand, if it is determined that the two SSIDs are not the same, the MFP 10 executes the same processes as T26 to T50 in FIG. 2. Note that, in a modified example, the determination of T126 may be executed before the determination of T124.
[0047] As described above, the same SSID "ap01" is assigned to AP200 and AP300. AP200 is, for example, an AP installed by a user before AP300 is installed. For example, in a situation where not only WPA3-compatible AP300 but also WPA3-incompatible AP200 exist around MFP10, when the SSID of WPA3-compatible AP300 is selected, a comparative example is assumed in which WPA3 setting information 42 is changed to the setting "WPA3 Only Mode." In this comparative example, a situation is assumed in which MFP10 is moved away from AP300 after a wireless connection with AP300 is established. In this case, the wireless connection with AP300 is disconnected, and MFP10 attempts to connect to another wireless network identified by the same SSID "ap01" (i.e., a wireless network formed by AP200). However, because the WPA3 setting information 42 has been changed to the setting "WPA3 Only Mode," the MFP 10 fails to establish a wireless connection with the AP 200, even though the previous AP 200 is present around the MFP 10. In contrast, according to this case, the WPA3 setting information 42 is maintained in the setting "WPA3 Transition Mode." As described above, the setting "WPA3 Transition Mode" permits the establishment of a wireless connection with an AP that does not support WPA3. Therefore, for example, it is possible to prevent failure in establishing a wireless connection with the previous AP 200, thereby ensuring user convenience. Note that the above comparative example may be adopted in a modified example.
[0048] (Case C3; Figure 4) 4, a case C3 following T50 in case C1 in FIG. 2 will be described. In this case, after a wireless connection with AP 300 is established in T50, AP 200 that does not support WPA3 is installed around MFP 10. In the initial stage of this case, WPA3 setting information 42 of MFP 10 indicates the setting "WPA3 Only Mode."
[0049] T210 to T220 are the same as T110 to T120 in Fig. 3. In T222, the user selects the SSID "ap01" of the WPA3-incompatible AP 200 on the selection screen and enters the password "xxxx".
[0050] In T226, the MFP 10 changes the WPA3 setting information 42 from the setting "WPA3 Only Mode" to the setting "WPA3 Transition Mode." T230 is the same as T30 in FIG. 2 except that authentication according to PSK is performed. T240 and T250 are the same as T40 and T50 in FIG. 2. Note that in a modified example, communication for receiving management by the PMF does not have to be performed in T240.
[0051] In this case, after a wireless connection with the AP 300 is established, the SSID "ap01" of the AP 200 that does not support WPA3 is selected on the selection screen, which indicates that the user wishes to receive services provided by WPA2 PSK. According to this case, when it is estimated that the user wishes to receive services provided by PSK (T222), the WPA3 setting information 42 is changed from the setting "WPA3 Only Mode" to the setting "WPA3 Transition Mode" (T226). In a situation where WPA3 SAE and pre-WPA2 PSK are mixed, services provided by PSK can be appropriately received.
[0052] (Example problem) With reference to FIG. 5 , an example problem will be described to further illustrate the effects of this embodiment. In this example problem, the WPA3 setting information of the MFP850 indicates the setting "WPA3 Transition Mode," and the WPA3 setting information of the MFP850 is not changed. In this example problem, a third party prepares an AP900 and attempts to connect the MFP850 to a wireless network formed by the AP900. The SSID of the AP900 is set to "ap01," the same as the SSID of the AP300. The AP900 is a WPA3-compatible AP.
[0053] Y10 to Y22 are the same as T10 to T22 in Figure 2, except that the MFP 850 and AP 900 are used. Y30 to Y34 show the details of SAE authentication in this problem example. At Y30, the MFP 850 executes Commit communication with the AP 900. In the Commit communication, the MFP 850 sends a signal to the AP 900 requesting execution of SAE. If the AP 900 accepts the request in this signal, SAE authentication is successful. However, in this problem example, the AP 900 is designed by a third party to ignore the request in this signal. Therefore, at Y34, the MFP 850 receives a Confirm Failed signal from the AP 900, indicating that SAE authentication has failed.
[0054] In this example problem, the WPA3 setting information of the MFP 850 indicates the setting "WPA3 Transition Mode." Therefore, the MFP 850 performs PSK authentication instead of SAE authentication at Y36. Y40 and Y50 are similar to T40 and T50 in Figure 2, except that they use encryption keys generated using PSK. AP900 supports WPA3 but operates as a non-WPA3 AP. A third party may attempt to intercept communications using AP900, which has weak security, for example.
[0055] (Case C4; Figure 6) With reference to FIG. 6, case C4, which addresses the problem example of FIG. 5 in this embodiment, will be described. T310 to T326 are the same as T10 to T26 in FIG. 2, except that an AP 900 prepared by a third party is used. T330 and T334 are the same as Y30 and Y34 in FIG. 5, except that the MFP 10 is used. In this case, when T334 is executed, the WPA3 setting information 42 is changed to the setting "WPA3 Only Mode" (T326). Therefore, the MFP 10 does not execute PSK authentication instead of SAE authentication. In T336, the MFP 10 displays a connection error on the display unit 14, indicating that establishment of a wireless connection has failed.
[0056] For example, as shown in T24A and T26A in FIG. 2, a comparative example is assumed in which the WPA3 setting information 42 is changed to the setting "WPA3 Only Mode" after the wireless connection at T50 is established. In this comparative example, the WPA3 setting information 42 indicates the setting "WPA3 Transition Mode" when authentication is performed. This may result in the problem example in FIG. 5. In contrast, according to the configuration of this embodiment, the WPA3 setting information 42 indicates the setting "WPA3 Only Mode" when authentication is performed, thereby preventing the problem example in FIG. 5 from occurring. Note that the above comparative example may be employed in a modified example, and even in this comparative example, it is possible to prevent a third party from intercepting communications using the AP 800, similar to T70 to T74 in FIG. 2.
[0057] (Table showing the relationship between APs and MFPs; Figure 7) As shown in Figure 7, with the formulation of WPA3, there may be APs that are non-WPA3 compliant but support WPA or WPA2, WPA3 compliant APs that support WPA3 Transition Mode, and WPA3 compliant APs that support WPA3 Only Mode.
[0058] Meanwhile, there may be MFPs that are not WPA3 compatible, MFPs that are WPA3 compatible and operate in WPA3 Transition Mode, and MFPs that are WPA3 compatible and operate in WPA3 Only Mode.
[0059] In this embodiment, the WPA3 setting information 42 of the MFP 10 is changed to the setting "WPA3 Only Mode" (T26 in FIG. 2). As a result, the MFP 10 can establish a wireless connection with either a WPA3-compatible AP that supports WPA3 Transition Mode or a WPA3-compatible AP that supports WPA3 Only Mode. WPA3 is used in both cases. On the other hand, the MFP 10 cannot establish a wireless connection with an AP that does not support WPA3.
[0060] (Correspondence) The MFP 10, the operation unit 12, the Wi-Fi I / F 16, the print execution unit 20, and the control unit 30 are examples of a "communication device," a "communication interface," an "operation unit," an "image processing execution unit," and a "control unit," respectively. The AP 300 and the AP 200 are examples of a "first external device" and a "second external device." WPA3 Transition and WPA3 Only Mode are examples of a "first state (and a fourth state)" and a "second state (and a second state)," respectively. SAE and PSK are examples of a "first communication standard" and a "second communication standard," respectively. T22 in FIG. 2 and T222 in FIG. 4 are examples of an "instruction to establish a first connection" and an "instruction to establish a second connection," respectively. WPA3 compatibility information and WPA3 non-compatibility information are examples of "standard information." The print data of T60 in FIG. 2 is an example of a "specific request." T26 in FIG. 2 is an example of a process implemented by a "first change unit."
[0061] (Second Example) (Configuration of communication system 2; Figure 1) The communication system 2 of this embodiment is similar to that of the first embodiment except for the following points: The APs 200 and 300 of this embodiment are APs that do not support WPA3 and support WPA2. AP200 operates in PMF Capable mode. AP300 operates in PMF Required mode. Hereinafter, operation in PMF Required mode may be referred to as "PR operation," and not operation in PMF Required mode may be referred to as "PR non-operation." In a modified example, AP300 may be a WPA3-compatible AP.
[0062] The memory 34 of the MFP 10 stores PMF setting information 44 instead of the WPA3 setting information 42. The PMF setting information 44 indicates one of a plurality of settings including a setting "PMF Capable" and a setting "PMF Required." The setting "PMF Capable" is a setting that allows both the establishment of a wireless connection that does not use PMF and the establishment of a wireless connection that uses PMF. The setting "PMF Required" is a setting that allows the establishment of a wireless connection that uses PMF, but does not allow the establishment of a wireless connection that does not use PMF.
[0063] (Specific case of this example; Figure 8) A specific case of this embodiment will be described with reference to Fig. 8. In the initial stage of this case, the PMF setting information 44 of the MFP 10 indicates the setting "PMF Capable" by default.
[0064] T410 and T412 are the same as T10 and T12 in Fig. 2. T414 is the same as T14 in Fig. 2 except that the probe response includes PMF information. The PMF information is information indicating that AP 300, which is the source of the probe response, is operating in PMF Required. If the AP, which is the source of the probe response, is not operating in PMF Required, the probe response does not include PMF information.
[0065] T420 is similar to T20 in Fig. 2 except that it includes a message indicating whether the AP that sent the probe response is an AP operating as a PR. T422 is similar to T22 in Fig. 2.
[0066] In T424, the MFP 10 determines whether or not a PR-inactive AP exists among one or more surrounding APs. Specifically, the MFP 10 determines whether or not a Probe response that does not include PMF information exists among one or more Probe responses received from one or more surrounding APs. In this case, one AP 300 with PR active exists around the MFP 10, and no APs with PR inactive exist. In this case, the MFP 10 determines in T424 that no AP with PR inactive exists among one or more surrounding APs, and proceeds to processing in T426. Note that if it is determined that an AP with PR inactive exists among one or more surrounding APs, the MFP 10 skips processing in T426 and proceeds to processing in T430 (see FIG. 3 of the first embodiment).
[0067] In T426, the MFP 10 changes the PMF setting information 44 from the setting "PMF Capable" to the setting "PMF Required." T430 to T450 are the same as T30 to T50 in FIG.
[0068] In this case, as in Figure 2, a malicious third party prepares AP910 with the purpose of intercepting communications. AP910 is an AP with PR disabled and operates with PMF Disable. PMF Disable is a setting that allows the establishment of wireless connections that do not use PMF, but does not allow the establishment of wireless connections that use PMF. A wireless connection with AP910 that does not use PMF has weaker security than a wireless connection with AP300 that uses PMF.
[0069] T470 to T474 are the same as T70 to T74 in Fig. 2 except that AP 910 is used. Here, the probe response of T474 does not include PMF information.
[0070] In this case, in T426, the PMF setting information 44 is changed from the setting "PMF Capable" to the setting "PMF Required." As described above, the setting "PMF Required" does not permit establishment of a wireless connection without using PMF. In this case, the AP 910 is a PMF Disable AP. Therefore, the AP 910 notifies the MFP 10 that it will not use PMF in the 4-way handshake communication. However, because the MFP 10 does not permit establishment of a wireless connection without using PMF, the 4-way handshake communication fails. As a result, establishment of a wireless connection between the AP 910 and the MFP 10 fails. Even in this case, a wireless connection is not established between the AP 910 and the MFP 10, preventing a third party from intercepting communication using the AP 910.
[0071] (Table showing the relationship between APs and MFPs; Figure 9) As shown in Figure 9, by formulating the PMF, there may be APs that do not operate with PR but operate with PMF Disable, APs that do not operate with PR but operate with PMF Capable, and APs that operate with PR but operate with PMF Required.
[0072] On the other hand, there may be MFPs that operate in PMF Disable mode, WPA3-compatible MFPs that operate in PMF Capable mode, and WPA3-compatible MFPs that operate in PMF Required mode.
[0073] In this embodiment, the PMF setting information 44 of the MFP 10 is changed to the setting "PMF Required" (T426 in FIG. 8). As a result, the MFP 10 can establish a wireless connection with either a PR-inoperative AP operating in PMF Capable mode, or a PR-operative AP operating in PMF Required mode. PMF is used in both cases. On the other hand, the MFP 10 cannot establish a wireless connection with a PR-inoperative AP operating in PMF Disable mode (i.e., a wireless connection that does not use PMF).
[0074] (Correspondence) PMF Capable and PMF Required are examples of the "first state (and fourth state)" and the "second state (and third state)", respectively.
[0075] (Third Example) (Communication System 2; Figure 10) In this embodiment, the MFP 10 uses Enterprise. As described above, Enterprise is a communication standard used by businesses, etc. Enterprise is provided not only in WPA3 but also in WPA2.
[0076] The communication system 2 of this embodiment is similar to the communication system 2 of the first embodiment, except that it includes authentication servers 210 and 310 and that the content of the WPA3 setting information 42 is different.
[0077] The authentication servers 210 and 310 are authentication servers used in the Enterprise. The authentication server 210 is used in the process of establishing a wireless connection with the AP 200, and is connected to the AP 200 via a wired LAN. The authentication server 310 is used in the process of establishing a wireless connection with the AP 300, and is connected to the AP 300 via a LAN (wired or wireless).
[0078] Furthermore, the WPA3 setting information 42 of this embodiment indicates one of a plurality of settings, including the setting "SHA256 optional" and the setting "SHA256 required." The setting "SHA256 optional" is a setting that allows the use of both a hash function (e.g., SHA1) that can be used in both WPA2 and WPA, and the hash function "SHA256" that can be used in WPA3 but cannot be used in WPA2 or WPA, in communication with the authentication server in Enterprise. In other words, when the WPA3 setting information 42 indicates the setting "SHA256 optional," both the establishment of a wireless connection according to WPA2 or WPA and the establishment of a wireless connection according to WPA3 are permitted. Note that the hash function that can be used in WPA3 is not limited to SHA256, but may be, for example, SHA384 or SHA3.
[0079] On the other hand, the setting "SHA256 required" allows the use of the hash function "SHA256" in communication with the authentication server in Enterprise, but does not allow the use of hash functions that can be used in both WPA2 and WPA. In other words, when the WPA3 setting information 42 indicates the setting "SHA256 required," establishment of a wireless connection conforming to WPA3 is permitted, but establishment of a wireless connection conforming to WPA2 or WPA is not permitted. Note that the setting "SHA256 required" may also allow the use of SHA384 and SHA3.
[0080] SHA256 is a hash function that outputs a return value that is 256 bits long. The length of the returned value of SHA256 is longer than the length of the returned value of SHA1. The encryption strength of SHA256 is stronger than that of SHA1.
[0081] (Specific case of this example; Figure 11) A specific case of this embodiment will be described with reference to Fig. 11. In the initial stage of this case, the WPA3 setting information 42 of the MFP 10 indicates the setting "SHA256 any" by default.
[0082] T510 to T514 are the same as T10 to T14 in Figure 2. Note that the WPA3 support information in T514 includes information indicating the hash function "SHA256" used in communication with the authentication server. In T526, the MFP 10 changes the WPA3 setting information 42 from the setting "SHA256 optional" to the setting "SHA256 required."
[0083] T520 is the same as T20 in Fig. 2 except that the selection screen includes an input field for a user password used for authentication in the authentication server instead of an input field for the AP password. T522 is the same as T22 in Fig. 2 except that the user password "zzzz" stored in authentication server 310 in association with the user name indicating the user of MFP10 is entered in the user password input field. T524 is the same as T24 in Fig. 2.
[0084] T730 is the same as T30 in Fig. 2 except that OPEN authentication is performed instead of SAE authentication. In T731, association communication is performed with AP300.
[0085] At T732, the MFP 10 transmits a Client Hello signal to the authentication server 310 via the AP 300. Communication between the MFP 10 and the AP 300 is encrypted in accordance with TLS (Transport Layer Security). The Client Hello signal is a signal that notifies the authentication server 210 that the MFP 10 has started operating as a TLS client.
[0086] At T734, the MFP 10 receives a Server Hello signal from the authentication server 210 via the AP 300 as a response to the Client Hello signal. The Server Hello signal is a signal that notifies the MFP 10 that the authentication server 310 has started operating as a TLS server.
[0087] In T736, MFP10 executes EAP (Extensible Authentication Protocol) authentication communication with authentication server 310 via AP 300 in accordance with TLS. EAP authentication includes user authentication and key exchange. User authentication is communication in which authentication server 210 authenticates the user of MFP10 using a user password received from MFP10. Key exchange is communication in which, if user authentication is successful, authentication server 210 provides both MFP10 and AP 300 with an encryption key to be used in communication in T740, which will be described later.
[0088] T740 is the same as T70 in Figure 3, except that the encryption key provided in EAP authentication is used. T750 is the same as T50 in Figure 2.
[0089] In this case, a malicious third party prepares an AP 900 and an authentication server 920 with the purpose of intercepting communications. The authentication server 920 is a server that performs EAP authentication in accordance with WPA2. For example, the authentication server 920 performs EAP authentication using the hash function "SHA1."
[0090] T770 to T774 are the same as T70 to T74 in Fig. 2. T776 is the same as T730 except that PSK authentication is performed. T778 and T780 are the same as T732 and T734 except that the AP 900 and authentication server 920 are used.
[0091] In this case, in T526, the WPA3 setting information 42 is changed from the setting "SHA256 optional" to the setting "SHA256 required." As described above, the setting "SHA256 required" does not permit communication with the authentication server using the hash function "SHA1." In this case, the authentication server 920 uses the hash function "SHA1." Therefore, the authentication server 920 notifies the MFP10 that the hash function "SHA1" will be used. However, because the MFP10 does not permit the use of the hash function "SHA1," EAP authentication fails. As a result, establishment of a wireless connection between the AP 900 and the MFP10 fails. Even in this case, a wireless connection is not established between the AP 900 and the MFP10, preventing a third party from intercepting communication using the AP 900.
[0092] (Correspondence) SHA256 optional and SHA256 required are examples of the "first state (and fourth state)" and the "second state (and third state)", respectively.
[0093] (Fourth Example) In this embodiment, the MFP 10 communicates with a management server that manages the status of the MFP 10. The communication between the MFP 10 and the management server is performed in accordance with TCP (Transmission Control Protocol). Furthermore, the communication between the MFP 10 and the management server is encrypted in accordance with TLS. For example, the MFP 10 periodically transmits information indicating the status of the MFP 10 (e.g., the amount of remaining ink, etc.) to the management server.
[0094] (Configuration of communication system 2; Figure 12) The communication system 2 of this embodiment is similar to the communication system 2 of the first embodiment, except that it includes management servers 600 and 700 instead of the APs 200 and 300, and that the configuration of the MFP 10 is different.
[0095] The management server 600 supports TLS version 1.2. The management server 700 supports TLS version 1.3, which is newer than version 1.2. The management servers 600 and 700 are connected to LAN4, which is a wired LAN. Note that "1.3" is a number representing the latest version and is merely an example.
[0096] (MFP10 configuration; Figure 12) The MFP 10 of this embodiment is similar to the first embodiment except that it includes a LAN I / F 60 instead of the Wi-Fi I / F 16 and stores TLS setting information 50 instead of the WPA3 setting information 42. The LAN I / F 60 is an I / F for executing communication via the LAN 4 and is connected to the LAN 4. The MFP 10 of this embodiment also supports TLS version 1.3.
[0097] The TLS setting information 50 indicates one of a number of settings, including the setting "TLS 1.3 not required" and the setting "TLS 1.3 required." The setting "TLS 1.3 not required" is a setting that allows the use of both TLS version 1.3 and versions of TLS prior to version 1.2. The setting "TLS 1.3 required" is a setting that allows the use of TLS version 1.3 but does not allow the use of versions of TLS prior to version 1.2.
[0098] (Specific case of this example; Figure 13) A specific case of this embodiment will be described with reference to FIG. 13. In the initial stage of this case, the TLS setting information 50 of the MFP 10 indicates the setting "TLS1.3 not required" by default. Note that all of the following communications executed by the MFP 10 of this embodiment are executed via the LAN I / F 60. In the following, when describing processing related to communication, the expression "via the LAN I / F 60" may be omitted.
[0099] In this case, it is assumed that a management server 700 is newly installed in addition to the management server 600. In this case, the user inputs the IP address of the management server 700 into the MFP 10 instead of the IP address of the management server 600.
[0100] In T810, the user operates operation unit 12 of MFP 10 to input an instruction for a TCP connection with management server 700. For example, communication between MFP 10 and the management server is periodically performed while MFP 10 is powered on. A connection according to TCP with management server 700 (hereinafter referred to as a TCP connection) is established when MFP 10 is powered on after inputting the IP address of management server 700. The instruction to power on MFP 10 in T810 can be said to be an instruction for a TCP connection with management server 700.
[0101] At T812, the MFP 10 transmits an ARP (short for Address Resolution Protocol) request addressed to the IP address of the management server 700. The ARP request is a signal requesting the MAC address of the management server.
[0102] At T814, the MFP 10 receives, from the management server 700, an ARP response including the MAC address MA1 of the management server 700 as a response to the ARP request of T812. At T816, a TCP connection is established between the MFP 10 and the management server 700.
[0103] At T820, the MFP 10 uses the established TCP connection to send a Client Hello signal to the management server 700. At T820, the MFP 10 receives a Server Hello signal from the management server 700 using the established TCP connection. The Server Hello signal includes information indicating that the management server 700 supports TLS version 1.3.
[0104] In T830, communication in accordance with TLS version 1.3 is executed between the MFP 10 and the management server 700 using the established TCP connection. This communication includes, for example, transmission of information indicating the status of the MFP 10 to the management server.
[0105] In the next step T840, the MFP 10 disconnects the TCP connection of T816, triggered by a predetermined operation by the user. The predetermined operation is, for example, an operation to turn off the power of the MFP 10.
[0106] In T842, the MFP 10 determines whether communication according to TLS version 1.3 has been executed. In this case, communication according to TLS version 1.3 has been executed in T830. In this case, the MFP 10 determines that communication according to TLS version 1.3 has been executed, and proceeds to processing T844. Note that if the MFP 10 determines that communication according to TLS version 1.3 has not been executed, processing T844 is skipped.
[0107] In T844, the MFP 10 changes the TLS setting information 50 from the setting "TLS1.3 not required" to the setting "TLS1.3 required."
[0108] In this case, a malicious third party also prepares a management server 930 with the purpose of intercepting communications. The management server 930 does not support TLS version 1.3. For example, the management server 930 supports an older version (e.g., 1.2) that was established before version 1.3. With TLS, new security protocols are provided with each version update. Communications that comply with older versions of TLS that were established before version 1.3 have weaker security than communications that comply with TLS version 1.3.
[0109] The third party first interferes with communication between the management server 700 and the MFP 10, and disconnects the TCP connection with the management server 700. The MFP 10 detects the disconnection of the TCP connection at T872. To attempt to re-establish the TCP connection, the MFP 10 sends an ARP request addressed to the IP address of the management server 700 at T872. Here, the third party fraudulently sets the IP address of the management server 930 to the same IP address as the IP address of the management server 700. As a result, at T874, the MFP 10 receives an ARP response from the management server 930, including the MAC address MA2 of the management server 930.
[0110] In T876, a TCP connection is established between MFP 10 and management server 930. T880 is similar to T820 except that management server 930 is used. T882 is similar to T822 except that the Server Hello signal includes information indicating that management server 930 supports TLS versions prior to version 1.3 (e.g., 1.2).
[0111] In this case, in the above T844, the TLS setting information 50 is changed to the setting "TLS 1.3 Request." As described above, the setting "TLS 1.3 Request" does not permit the use of TLS versions prior to version 1.2. In this case, the management server 930 supports TLS versions prior to version 1.2. Therefore, the MFP 10 does not permit the execution of communications in accordance with TLS version 1.3, and, for example, information indicating the status of the MFP 10 is not transmitted to the management server 930. This makes it possible to prevent a third party from intercepting communications using the management server 930.
[0112] (Table showing the relationship between the management server and MFP; Figure 14) As shown in FIG. 14, there may be servers that support TLS versions prior to version 1.2, servers that support TLS versions prior to version 1.3, and servers that support only TLS version 1.3.
[0113] Meanwhile, there may be MFPs that operate with TLS version 1.2 or earlier, MFPs that operate with TLS version 1.3 or earlier, and WPA3-compatible MFPs that operate only with TLS version 1.3.
[0114] In this embodiment, the TLS setting information 50 of the MFP 10 is changed to the setting "TLS 1.3 Request" (T844 in FIG. 13). As a result, the MFP 10 can communicate using a TCP connection with either a server that supports TLS version 1.3 or earlier, or a server that supports only TLS version 1.3. On the other hand, the MFP 10 cannot communicate using a TCP connection with a server that supports TLS version 1.2 or earlier.
[0115] (Correspondence) The LAN I / F 60 in FIG. 12 is an example of a "communication interface." The management server 700 and the management server 600 are examples of a "first external device" and a "second external device," respectively. TLS 1.3 not required and TLS 1.3 required are examples of a "first state (and fourth state)" and a "second state (and third state)," respectively. Version 1.3 and version 1.2 are examples of a "first version" and a "second version," respectively. TLS version 1.3 and TLS version 1.2 are examples of a "first communication standard" and a "second communication standard," respectively. The connection instruction T810 in FIG. 13 is an example of an "instruction to establish a first connection." T844 is an example of a process implemented by a "first change unit."
[0116] Although specific examples of the technology disclosed in this specification have been described above, these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and variations of the specific examples exemplified above. For example, the following modifications may be adopted.
[0117] (Modification 1) The process of case C3 in Fig. 4 does not have to be executed. In this modification, the "second change unit" can be omitted.
[0118] (Modification 2) The process of case C2 in Fig. 3 does not have to be executed. Generally speaking, "the state of the communication device does not have to be maintained in the first state."
[0119] (Modification 3) T60 and T62 in Fig. 2 do not have to be executed. In this modification, the "image processing execution unit", "establishment unit", "request reception unit", and "processing control unit" can be omitted.
[0120] (Modification 4) The "communication device" is not limited to the MFP 10, but may be, for example, a printer, a scanner, a terminal device such as a PC, or the like.
[0121] (Variation 5) The "server" is not limited to the management server 600 that manages the state of the MFP 10, but may be, for example, a mail server that sends e-mail in response to an instruction from the MFP 10.
[0122] (Variation 6) In the above embodiment, the processes of FIGS. 2 to 14 are realized by software (for example, the program 40), but at least one of these processes may be realized by hardware such as a logic circuit.
[0123] The following reference examples are also novel and useful. In a fourth embodiment, MFP 10 transmits an ARP request to management server 700, triggered by input of a TCP connection instruction after input of the IP address of management server 700 (T810 and T812 in FIG. 13). Alternatively, the process of T810 may not be executed, and MFP 10 may automatically transmit an ARP request to management server 700 at a predetermined timing after input of the IP address of management server 700. Generally speaking, the "first change unit" may change the state of the communication device from the first state to a second state different from the first state at a predetermined timing while the state of the communication device is in the first state, at which a first connection with a first external device via a communication interface should be established.
[0124] The technical elements described in this specification or drawings exhibit technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Furthermore, the techniques illustrated in this specification or the drawings achieve multiple objectives simultaneously, and achieving one of these objectives is itself technically useful. [Explanation of symbols]
[0125] 2: Communication system, 4: LAN, 10: MFP, 12: Operation unit, 14: Display unit, 16: Wi-Fi I / F, 20: Print execution unit, 22: Scan execution unit, 30: Control unit, 32: CPU, 34: Memory, 40: Program, 42: WPA3 setting information, 44: PMF setting information, 50: TLS setting information, 100: Terminal device, 200: AP, 210: Authentication server, 300: AP, 310: Authentication server, 600: Management server, 700: Management server, 800: AP, 850: MFP, 900: AP, 910: AP, 920: Authentication server, 930: Management server, MA1, MA2: MAC address
Claims
1. A communication device, a communication interface; An operation unit; a first change unit that changes a state of the communication device from the first state to a second state different from the first state when the operation unit receives an instruction to establish a first connection with a first external device via the communication interface while the communication device is in the first state, the first state is a state in which both use of the first connection and use of a second connection with a second external device via the communication interface are permitted; the second state is a state in which use of the first connection is permitted and use of the second connection is not permitted, the first connection is a connection conforming to a first communication standard, the second connection is a wireless connection conforming to a second communication standard different from the first communication standard; the first change unit; A communication device comprising:
2. 2. The communication device according to claim 1, wherein the first change unit changes the state of the communication device from the first state to the second state in response to an instruction to establish the first connection before the first connection with the first external device is established.
3. 2. The communication device according to claim 1, wherein the first change unit changes the state of the communication device from the first state to the second state after the first connection with the first external device is established in response to an instruction to establish the first connection.
4. The communication device further comprises:
4. The communication device according to claim 1, further comprising a second change unit that changes the state of the communication device from the second state to the first state when the operation unit receives an instruction to establish the second connection while the communication device is in the second state.
5. the first external device and the second external device are access points; The communication device according to claim 1 , wherein the first connection and the second connection are wireless connections.
6. the SSID (abbreviation of Service Set Identifier) of the wireless network formed by the first external device is the same as the SSID of the wireless network formed by the second external device; The communication device further comprises: an information receiving unit that receives, while the communication device is in the first state, standard information indicating a communication standard supported by each of one or more external devices present around the communication device; 6. The communication device according to claim 5, wherein when the one or more external devices include both the first external device and the second external device, and the one or more standards information includes both first standards information indicating that the first external device supports the first communication standard and second standards information indicating that the second external device supports the second communication standard, the state of the communication device is maintained in the first state even when the operation unit receives an instruction to establish the first connection.
7. the first communication standard includes WPA3 in the Wi-Fi standard; The communication device according to claim 5 or 6, wherein the second communication standard includes a standard that precedes WPA2 in the Wi-Fi standard.
8. the first state includes a WPA3 Transition Mode according to the WPA3; The communication device according to claim 7 , wherein the second state includes a WPA3 Only Mode according to the WPA3.
9. the first state includes a state in which both a first authentication using a PSK (abbreviation of Pre-Shared Key) method that can be used in standards prior to WPA2 and a second authentication using an SAE (abbreviation of Simultaneous Authentication of Equals) method that can be used in WPA3 but cannot be used in standards prior to WPA2 are permitted; The communication device according to claim 7 , wherein the second state includes a state in which the first authentication is not permitted and the second authentication is permitted.
10. the first state includes a state permitting use of both a first hash function that can be used in both the WPA3 and the standard before WPA2, and a second hash function that can be used in the WPA3 but cannot be used in the standard before WPA2; The communication device according to claim 7 , wherein the second state includes a state in which use of the first hash function is not permitted and use of the second hash function is permitted.
11. the first communication standard and the second communication standard include a Wi-Fi standard; the first communication standard includes PMF (short for Protected Management Frames), the second communication standard does not include the PMF; the first state includes a state indicated by PMF Capable; The communication device according to claim 5 or 6, wherein the second state includes a state indicated by PMF Required.
12. The communication device further comprises: an image processing execution unit for executing specific image processing; an establishment unit that establishes the first connection with the first external device when the operation unit receives an instruction to establish the first connection; a request receiving unit that receives, after the first connection is established, a specific request for executing the specific image processing from the first external device via the communication interface using the first connection; a processing control unit that causes the image processing execution unit to execute the specific image processing in accordance with the specific request; 12. A communication device according to claim 1, comprising:
13. the first external device and the second external device are servers, the first communication standard includes a first version of TLS (Transport Layer Security) used in communication with the server; the second communication standard includes a second version of the TLS established before the first version; the first state includes a state in which use of both the first version and the second version is permitted; The communication device according to claim 1 , wherein the second state includes a state in which use of the first version is not permitted and use of the second version is permitted.
14. The communication device of claim 1 , wherein a default state of the communication device after the communication device is powered on is the first state.
15. A communication device, a communication interface; An operation unit; when the operation unit receives an instruction to establish a first connection with a first external device via the communication interface, the operation unit operates the communication device in a third state; a control unit that operates the communication device in a fourth state when the operation unit receives an instruction to establish a second connection with a second external device via the communication interface, the third state being a state in which use of the first connection is permitted and use of the second connection is not permitted; the fourth state is a state in which use of both the first connection and the second connection is permitted, the first connection is a connection conforming to a first communication standard, the control unit, wherein the second connection is a connection conforming to a second communication standard different from the first communication standard; A communication device comprising:
16. 1. A computer program for a communication device, comprising: The communication device a communication interface; An operation unit; A computer, Equipped with The computer program causes the computer to: a first change unit that changes a state of the communication device from the first state to a second state different from the first state when the operation unit receives an instruction to establish a first connection with a first external device via the communication interface while the communication device is in the first state, the first state is a state in which both use of the first connection and use of a second connection with a second external device via the communication interface are permitted; the second state is a state in which use of the first connection is permitted and use of the second connection is not permitted, the first connection is a connection conforming to a first communication standard, the second connection is a wireless connection conforming to a second communication standard different from the first communication standard; A computer program that functions as the first change unit.
17. 1. A computer program for a communication device, comprising: The communication device a communication interface; An operation unit; A computer, Equipped with The computer program causes the computer to: when the operation unit receives an instruction to establish a first connection with a first external device via the communication interface, the operation unit operates the communication device in a third state; a control unit that operates the communication device in a fourth state when the operation unit receives an instruction to establish a second connection with a second external device via the communication interface, the third state being a state in which use of the first connection is permitted and use of the second connection is not permitted; the fourth state is a state in which use of both the first connection and the second connection is permitted, the first connection is a connection conforming to a first communication standard, The second connection is a connection conforming to a second communication standard different from the first communication standard.
Citation Information
Patent Citations
Communication device, and control method, and program thereof
JP2018060441A
Communication device and image forming apparatus
JP2018067749A
Communication device and computer program for communication device
JP2020068456A
Communication device, control method, and program
JP2022136600A
Communication device
JP2016019085A