Communication apparatus
The communication device enables simultaneous connection management and easy switching between authentication methods, addressing usability challenges in IEEE802.1X/EAP authentication, thereby improving user convenience.
Patent Information
- Application Number
- JP2025201036
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-11-20
- Publication Date
- 2026-02-16
AI Technical Summary
Communication devices using the IEEE802.1X/EAP authentication method face challenges in convenience and usability, particularly in switching between different authentication methods and maintaining connections, leading to complex user operations.
A communication device capable of establishing multiple connections simultaneously, including one without an external authentication server, and controlling these connections based on user operations to facilitate easy switching between authentication methods.
Improves the convenience and usability of communication devices by allowing seamless switching and maintaining connections using IEEE802.1X/EAP authentication, enhancing user experience.
Smart Images

Figure 2026026120000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates generally to communication devices. [Background technology]
[0002] Among communication devices that perform a process of connecting to surrounding access points, there are some that select and connect to an access point based on an SSID (Service Set Identifier) list (see Patent Document 1). The SSID list is acquired by searching for connectable access points.
[0003] In a communication system using a wireless LAN that complies with a predetermined standard, the network can be protected by authenticating communication devices that connect to the network. A typical example of this standard is the IEEE (Institute of Electrical and Electronics Engineers) 802.11 standard. Examples of authentication methods include a PSK system that uses a Pre-Shared Key (PSK) and an SAE (Simultaneous Authentication of Equals) system that uses SAE. Another example is an EAP system that authenticates communication devices that connect to the network using an authentication server that supports IEEE802.1X / EAP (Extensible Authentication Protocol). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-127545 Summary of the Invention [Problem to be solved by the invention]
[0005] As devices that connect to wireless LANs using the IEEE802.1X / EAP authentication method become more widespread, there is a demand for improved convenience for communication devices that connect to wireless LANs using the IEEE802.1X / EAP authentication method. For example, when connecting an MFP (multifunction printer) to a wireless LAN using the IEEE802.1X / EAP authentication method, the following operations must be performed: First, the MFP and the information processing device are connected using a communication interface that does not use the IEEE802.1X / EAP authentication method; Next, the information processing device sets the setting values to be used in the IEEE802.1X / EAP authentication method in the MFP; Then, search for an access point on the MFP and select the SSID of an access point that supports the IEEE802.1X / EAP authentication method.
[0006] If connecting to a wireless LAN using IEEE802.1X / EAP authentication fails, the user must switch to a communication interface that does not use IEEE802.1X / EAP authentication and reconfigure the settings for IEEE802.1X / EAP authentication. Also, if the authentication method used between the printer and access point is IEEE802.1X / EAP authentication, it may be necessary to prevent unauthorized devices from printing via Wireless Direct. Therefore, a configuration is needed that allows relatively easy (e.g., intuitive switching with minimal user operations) switching between a communication interface that uses IEEE802.1X / EAP authentication and a communication interface that does not use IEEE802.1X / EAP authentication.
[0007] An exemplary object of the present invention is to provide a technique that is advantageous for improving the usability of a communication device that can connect to an access point that operates under an authentication method that uses an authentication server. [Means for solving the problem]
[0008] One aspect of the present invention is A communication device capable of communicating with an information processing device, a first accepting means for accepting a first operation for establishing a connection between the communication device and the information processing device as a first connection, the connection not passing through an access point external to the communication device and external to the information processing device; a first establishing means for establishing the first connection after the first operation is accepted; a second receiving means for receiving a second operation for establishing a connection between the access point and the communication device as a second connection, the connection corresponding to a predetermined authentication method using an authentication server; second establishing means for establishing the second connection after the second operation is accepted; a third accepting means for accepting a third operation for establishing a connection between the communication device and the access point that does not support the predetermined authentication method as a third connection; a third establishing means for establishing the third connection after the third operation is accepted; a first control means that, based on the fact that the first operation is accepted while the second connection is established, controls to maintain the first connection out of the first connection and the second connection, and, based on the fact that the first operation is accepted while the third connection is established, controls to maintain the first connection and the third connection in parallel, It is characterized by: [Effects of the Invention]
[0009] According to the present invention, it is possible to improve the convenience of a communication device that can execute connection to an access point that operates under an authentication method that uses an authentication server. [Brief explanation of the drawings]
[0010] [Figure 1] FIG. 1 illustrates an example of a system configuration. [Figure 2] FIG. 1 is a diagram illustrating an example of the external configuration of an MFP. [Figure 3] FIG. 1 illustrates an example of the configuration of an MFP. [Figure 4] 10A and 10B are diagrams illustrating examples of screens displayed on an operation display unit of an MFP. [Figure 5] 1 is a diagram illustrating an example of the external configuration of an information processing device. [Figure 6] FIG. 1 illustrates an example of the configuration of an information processing device. [Figure 7] FIG. 1 illustrates an example of the configuration of an access point. [Figure 8] FIG. 10 illustrates an example of the configuration of an authentication server. [Figure 9] FIG. 10 is a diagram illustrating an example of a procedure for connecting an MFP to a network operating under an authentication method that uses an authentication server. [Figure 10] FIG. 1 illustrates an example of a network configuration. [Figure 11] 10A and 10B are diagrams illustrating examples of screens displayed on the operation display unit of the MFP when LAN settings are made. [Figure 12]FIG. 10 is a diagram illustrating an example of a setting screen of an MFP displayed on an information processing apparatus. [Figure 13] FIG. 10 is a diagram for explaining a process of connecting an MFP to a network operating under an authentication method that uses an authentication server. [Figure 14] FIG. 10 is a diagram for explaining a process in which the MFP searches for a wireless access point. [Figure 15] FIG. 10 is a diagram for explaining processing in enabling settings for the wireless infrastructure of the MFP. [Figure 16] FIG. 10 is a diagram for explaining processing in enabling settings for Wireless Direct of the MFP. [Figure 17] 10 is a diagram for explaining processing for enabling IEEE802.1X / EAP settings of an MFP. FIG. [Figure 18] 10 is a diagram for explaining processing for disabling the IEEE802.1X / EAP setting of the MFP. FIG. [Figure 19] FIG. 10 is a diagram for explaining processing in resetting settings of the MFP. [Figure 20] FIG. 10 is a diagram for explaining the processing for setting the time of the MFP. [Figure 21] FIG. 10 is a diagram illustrating the operation of the MFP when changing the time setting. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the claimed invention. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.
[0012] (System Configuration) 1 shows an example of the configuration of a communication system according to this embodiment. As an example, this system is configured so that multiple communication devices can communicate wirelessly with each other. Here, the multiple communication devices are assumed to be an information processing device 200, an MFP (multifunction printer) 300, an access point 700, and an authentication server 800.
[0013] The information processing device 200 and the MFP 300 may be simply referred to as communication devices when they are not particularly distinguished from each other. For example, the MFP 300 may be referred to as the communication device 300.
[0014] The information processing device 200 is an information processing device having a communication function via a wireless LAN, a wired LAN, or the like. A wireless LAN can be expressed as a WLAN (Wireless LAN). Examples of the information processing device 200 include a smartphone, a notebook PC (notebook-type personal computer (multifunctional peripheral device)), a tablet terminal, a PDA (Personal Digital Assistant), and the like.
[0015] The MFP 300 is a printing device that has a printing function as its main function, and may further have secondary functions such as a reading function (scanning function), a FAX (facsimile) function, and a telephone function. The MFP 300 also has a communication function that enables wireless communication with the information processing device 200. While the present embodiment describes an example in which the MFP 300 is used, this is not limiting. For example, a facsimile machine, a scanner, a projector, a mobile terminal, a smartphone, a laptop PC, a tablet terminal, a PDA, or the like may be used instead of the MFP 300. Alternatively, a digital camera, a music playback device, a television, a smart speaker, AR (Augmented Reality) glasses, or the like may be used.
[0016] The access point (AP) 700 is provided separately from (externally of) the information processing device 200 and the MFP 300 and operates as a WLAN base station device or wireless base station. A communication device equipped with a WLAN communication function can communicate in WLAN infrastructure mode (wireless infrastructure mode; hereinafter, "infrastructure" may be simply referred to as "infrastructure") via the access point 700. The access point 700 performs wireless communication with a communication device that is permitted to connect to the access point 700 (i.e., an authenticated communication device) and relays wireless communication between the communication device and other communication devices. The access point 700 can also be connected to, for example, a wired communication network and relay communication between a communication device connected to the wired communication network and another communication device wirelessly connected to the access point 700.
[0017] When the authentication method of the network established by the access point 700 is a method using the authentication server 800, the access point 700 performs access control by authenticating communication devices connecting to the network in cooperation with the authentication server 800. Communication with devices other than the authentication server 800 may be restricted for communication devices connecting to the network established by the access point 700 until they are authenticated.
[0018] The authentication server (RADIUS server) 800 is provided separately from the information processing device 200, the MFP 300, and the access point 700, and collectively manages authentication information. The authentication server 800 is capable of executing authentication processing in accordance with, for example, the IEEE 802.1X standard. In this embodiment, the authentication server 800 cooperates with the access point 700 to authenticate terminals to be authenticated, and controls access to the terminals based on the authentication results.
[0019] Here, the access point 700 corresponds to an authenticator in IEEE802.1X, and the information processing device 200 and the MFP 300 correspond to a supplicant in IEEE802.1X.
[0020] The authentication server 800 performs authentication using, for example, the EAP-TLS (Transport Layer Security) method or the EAP-TTLS (Tunneled TLS) method in accordance with the IEEE 802.1X standard. The EAP-TLS method is an authentication method that uses the TLS handshake protocol, which allows authentication using a server certificate, a client certificate, etc. The EAP-TTLS method is an authentication method that uses the TLS handshake protocol, which allows authentication using a server certificate, a user name, a password, etc. As another example, the authentication server 800 can also perform authentication using the PEAP (Protected EAP) method in accordance with the IEEE 802.1X standard. The PEAP (Protected EAP) method allows authentication using a user name and a password. The information used for these IEEE 802.1X authentications can be referred to as "authentication information."
[0021] The information processing device 200 and the MFP 300 can use their respective WLAN communication functions to perform wireless communication in a wireless infrastructure mode via an external access point 700, or in a peer-to-peer (P2P) mode that does not involve the external access point 700. The P2P mode includes WFD (Wi-Fi Direct (registered trademark)) and soft AP mode. That is, the communication is realized by wireless direct that complies with the IEEE802.11 series. Note that, as will be described in detail later, the information processing device 200 and the MFP 300 can execute processes corresponding to multiple printing services using WLAN communication.
[0022] (MFP external configuration) FIG. 2 is a perspective view showing an example of the external configuration of MFP 300. MFP 300 includes an operation display unit (operation panel) 302, a print paper insertion slot 303, a print paper ejection slot 304, a document table 305, and a document cover 306. The housing of MFP 300 is provided with a power button 301, which is a hard key used to turn the power on and off. Operation display unit 302 includes a display and buttons used to operate MFP 300. For example, operation display unit 302 includes multiple keys such as character input keys, cursor keys, a confirm key, and a cancel key, and a light source such as an LED (Light Emitting Diode) or an LCD (Liquid Crystal Display). Operation display unit 302 is configured to be able to accept user operation inputs when activating individual functions of MFP 300, changing various settings, etc. Typically, a touch panel display can be used as operation display unit 302 (see FIG. 4).
[0023] Print paper insertion slot 303 is an insertion slot for setting paper of any size. Paper set in print paper insertion slot 303 is transported one sheet at a time to the printing section and printed, and the printed paper is discharged from print paper exit 304. Platen 305 is a transparent glass table that is used when placing a document on it and reading an image using the scan function. Platen pressure plate 306 is a cover that presses the document against platen 305 to prevent the document from lifting off when reading an image using the scan function, and can also block light from entering the inside of MFP300 main body from outside.
[0024] Furthermore, MFP 300 has a communication function using WLAN or wired LAN. In this embodiment, MFP 300 has a built-in antenna for realizing wireless communication, and is also provided with a communication unit 321 for wired LAN. MFP 300 also has a USB communication unit 309 that can realize communication with external information processing device 200 etc. via USB connection.
[0025] (MFP configuration) 3 is a block diagram showing an example of the configuration of MFP 300. MFP 300 includes a built-in main board 310 that controls the entire device, as well as a wireless communication unit 307 and a USB communication unit 308. Main board 310 includes a CPU (Central Processing Unit) 311, an internal bus 312, a program memory 313, a data memory 314, a print unit 316, a scan unit 317, a communication control unit 318, an operation control unit 319, and a USB communication control unit 320. Note that the processes described below as processes executed by MFP 300 are actually realized by CPU 311 executing programs stored in program memory 313, data memory 314, etc.
[0026] The CPU 311, the program memory 313, and the data memory 314 are a microprocessor, a ROM (Read Only Memory), and a RAM (Random Access Memory), respectively. In this embodiment, the CPU 311, the program memory 313, and the data memory 314 are connected to one another via a bus cable that forms an internal bus 312. The CPU 311 performs arithmetic processing to realize each function described in the embodiment, based on a control program stored in the program memory 313 and the contents of the data memory 314.
[0027] For example, CPU 311 can control scan unit 317 to read an original document and store the image (image data) in image memory 315 within data memory 314. CPU 311 can control print unit 316 to print the image stored in image memory 315 onto a recording medium. CPU 311 can control USB communication unit 308 via USB communication control unit 320 to perform USB communication with external information processing device 200 via a USB connection. CPU 311 can control operation control unit 319 to receive information indicated by operation input from power button 301 or operation display unit 302. CPU 311 can also control operation control unit 319 to display the status of MFP 300 and a function selection menu on operation display unit 302.
[0028] The wireless communication unit 307 is configured to provide WLAN communication functions, for example, providing functions similar to those of the WLAN unit 201 of the information processing device 200. That is, the wireless communication unit 307 transmits packets converted from data in a manner conforming to a predetermined standard to other devices, and also restores packets from other devices to the original data and outputs the data to the CPU 311. The wireless communication unit 307 is configured to perform data (packet) communication in a WLAN system conforming to the IEEE 802.11 standard series (IEEE 802.11a / b / g / n / ac / ax, etc.), but may also conform to other standards. Here, the wireless communication unit 307 is capable of communication in both the 2.4 GHz and 5 GHz frequency bands. As will be described in detail later, the wireless communication unit 307 is also capable of WFD-based communication, communication in software access point (soft AP) mode, communication in wireless infrastructure mode, etc. Furthermore, the information processing device 200 and the MFP 300 are capable of wireless direct communication based on WFD, and the wireless communication unit 307 may have a soft AP function or a group owner function. That is, the wireless communication unit 307 can build a P2P communication network and determine the channel to be used for P2P communication.
[0029] The wired LAN communication unit 321 is configured to be able to realize wired communication. For example, the wired LAN communication unit 321 can realize data (packet) communication in a wired LAN (Ethernet) system conforming to the IEEE802.3 series. Furthermore, wired communication using the wired LAN communication unit 321 is possible in wired mode. Here, the wired LAN communication unit 321 is connected to the main board 310 via a bus cable that forms the internal bus 312.
[0030] (MFP operation display section) 4(a) to 4(c) show schematic diagrams of examples of the configuration of the operation / display unit 302 of the MFP 300. FIG. 4(a) shows an example in which a touch panel display 401 is used as the operation / display unit 302.
[0031] A user can start up the MFP 300 by touching the power button 301. When the MFP 300 starts up, a home screen (typically the top level of the menu) is displayed on the touch panel display 401 as a screen on which the user can input operations.
[0032] The home screen includes a copy area 405, a scan area 406, and a print area 407. The copy area 405 accepts an instruction to execute a copy process. The scan area 406 accepts an instruction to execute a scan process. The print area 407 accepts an instruction to execute a print process.
[0033] The home screen may further include a status display area 402, a connection setting mode area 403, and a settings area 404. The status display area 402 indicates the settings and connection status of the MFP 300, such as infrastructure connection or direct connection. The connection setting mode area 403 allows the user to start operation in the connection setting mode at any time. The settings area 404 also allows the user to change various settings.
[0034] FIG. 4(b) shows an example in which a relatively small LCD display 408 and various hard keys 409 to 416 are used as the operation display unit 302.
[0035] When the MFP 300 starts up, a home screen is displayed on the LCD display 408. The user can operate a cursor displayed on the LCD display 408 by pressing cursor movement buttons 411 and 412. The user can press an OK button 414 to execute an operation or a back button 413 to return to the previous menu screen. Pressing the QR button 409 can also display a QR code (registered trademark) containing information necessary for direct connection with the MFP 300. The displayed code is not limited to a QR code and can be any two-dimensional code. By reading this QR code from the information processing device 200, the information processing device 200 and the MFP 300 are directly connected and can communicate wirelessly with each other. Pressing the connection setting mode button 410 can start the connection setting mode, and the MFP 300 can be connected to the access point 700 by sending connection information to the MFP 300 using the information processing device 200. Pressing the stop button 415 while the MFP 300 is performing various processes cancels the various processes. The user can also scan an original document on the MFP 300 and print it by pressing the copy start button 416 .
[0036] As shown in Fig. 4(c), the layout of Fig. 4(b) may be changed as appropriate, for example, the cursor may be operated in the left and right direction. Note that the above elements 408 to 416 may be simply expressed as screens, for example, the LCD display 408 may also be expressed as the screen 408.
[0037] (External configuration of information processing device) FIG. 5 shows an example of the external configuration of the information processing device 200. In this embodiment, the information processing device 200 is a smartphone, and includes a display unit 202, an operation unit 203, and a power key 204. The power key 204 is provided as a hard key for turning the power of the information processing device 200 on or off. In this embodiment, the display unit 202 is a display including an LCD-type display mechanism, but in other embodiments, information may be displayed using an LED or the like. Furthermore, the information processing device 200 may have a function to output information by voice, either in addition to or instead of the display unit 202. The operation unit 203 may include hard keys such as keys and buttons, or a touch panel, and may be configured to be able to detect user operation inputs.
[0038] In this embodiment, the functions of the display unit 202 and the operation unit 203 are realized by a touch panel display, that is, the display unit 202 and the operation unit 203 are realized by a single device. In this case, for example, button icons and a software keyboard are displayed using the function of the display unit 202, and user operation inputs thereto are detected by the function of the operation unit 203. In another embodiment, the display unit 202 and the operation unit 203 may be provided as separate hardware.
[0039] The information processing device 200 may also include a built-in WLAN unit 201 capable of providing WLAN communication functions. The WLAN unit 201 is configured to be capable of performing data (packet) communication in a WLAN system conforming to, for example, the IEEE 802.11 standard series (IEEE 802.11a / b / g / n / ac / ax, etc.). The WLAN unit 201 may also be capable of performing communication in a WLAN system conforming to other standards. Here, the WLAN unit 201 is capable of communication in both the 2.4 GHz and 5 GHz frequency bands. Furthermore, as will be described in detail later, the WLAN unit 201 is capable of performing WFD-based communication, soft AP mode communication, wireless infrastructure mode communication, etc.
[0040] (Configuration of information processing device) 6 shows an example of the configuration of the information processing device 200. The information processing device 200 includes a main board 211 that performs main control of the device itself, a WLAN unit 201 that performs WLAN communication, and a BT (Bluetooth (registered trademark)) unit 205.
[0041] In this embodiment, main board 211 includes CPU 212, ROM 213, RAM 214, image memory 215, and data conversion unit 216. Main board 211 also includes telephone unit 217, GPS (Global Positioning System) 219, camera unit 221, non-volatile memory 222, data storage unit 223, speaker unit 224, and power supply unit 225. These individual functional units within main board 211 are interconnected via system bus 228 and managed by CPU 212. Furthermore, main board 211 and WLAN unit 201, and main board 211 and BT unit 205 are connected via dedicated bus 226.
[0042] The CPU 212 functions as a system control unit that controls each element of the information processing device 200. Each function of the information processing device 200 illustrated here and other processes executed by the information processing device 200, which will be described later, are realized by the CPU 212 expanding a program stored in the ROM 213 onto the RAM 214 and executing it.
[0043] More specifically, the ROM 213 stores control programs and embedded operating system (OS) programs executed by the CPU 212. The CPU 212 executes corresponding programs under the embedded OS to perform software control such as scheduling and task switching. The RAM 214 is configured with a static RAM (SRAM) or the like. The RAM 214 stores various data such as variables for program control, setting values registered by the user, and management data for managing the information processing device 200. The RAM 214 can be used as various work buffers. The image memory 215 is configured with a memory such as a dynamic RAM (DRAM). The image memory 215 temporarily stores image data received via the WLAN unit 201 and image data read from the data storage unit 223, enabling the image data to be processed by the CPU 212. The non-volatile memory 222 is configured with a memory such as a flash memory, and retains the stored data even when the information processing device 200 is powered off.
[0044] The memory configuration of the information processing device 200 is not limited to the above example. For example, the image memory 215 and the RAM 214 may be provided in common, or data may be backed up using the data storage unit 223. Also, although a DRAM is given here as an example of the image memory 215, other storage media such as an HDD (hard disk drive) or nonvolatile memory may also be used.
[0045] The data conversion unit 216 performs data conversion such as color conversion and image conversion, and can also analyze data in various formats. The telephone unit 217 controls telephone lines and processes audio data input and output via the speaker unit 224, enabling telephone communication. The GPS 219 receives radio waves transmitted from satellites and acquires location information such as the current latitude and longitude of the information processing device 200. The camera unit 221 has the function of electronically recording and encoding images input through a lens. Image data captured by the camera unit 221 is stored in the data storage unit 223. The speaker unit 224 controls functions such as audio input and output for telephone functions and alarm notification. The power supply unit 225 includes a battery and controls the supply of power to individual elements within the device. Power supply states include, for example, a dead battery state in which the remaining battery power is below a certain level, a power-off state in which the power key 204 is not pressed, a power-on state (startup state) in which the power key 204 is pressed, and a power-saving state in which power consumption by individual elements is suppressed.
[0046] Display unit 202 electronically controls the display content and performs control to display operation inputs by the user, the operating status of MFP 300, status status, etc. In response to receiving operation inputs from the user, operation unit 203 outputs an electrical signal corresponding to the operation input to CPU 212. As described in FIG. 5, touch panel displays can be used for display unit 202 and operation unit 203.
[0047] The information processing device 200 is capable of wireless communication using the WLAN unit 201, and performs data communication with other devices such as the MFP 300. For example, the information processing device 200 converts data into packets and transmits them to other external devices. The information processing device 200 also receives packets from other external devices via the WLAN unit 201, restores the packets to the original data, and outputs the restored data to the CPU 212.
[0048] The configuration of the main board 211 is not limited to the above example. For example, each function of the main board 211 implemented by the CPU 212 may be implemented by a processing circuit such as an ASIC (application-specific integrated circuit), that is, may be implemented by either hardware or software.
[0049] (Access point configuration) 7 shows an example of the configuration of an access point 700 equipped with wireless LAN access point functionality. The access point 700 includes a main board 710 that performs system control, a wireless LAN unit 716, a wired LAN unit 718, and operation buttons 720. The main board 710 includes a CPU 711, a program memory 713, a data memory 714, a wireless LAN communication control unit 715, a wired LAN communication control unit 717, an operation unit control circuit 719, a terminal access control unit 721, and a channel change unit 722. These are interconnected via an internal bus 712 so as to be able to communicate with each other. Note that the processes described below as processes executed by the access point 700 are actually realized by the CPU 711 executing programs stored in the program memory 713, the data memory 714, etc.
[0050] The CPU 711 performs arithmetic processing based on a control program stored in a program memory 713 and data held in a data memory 714. The CPU 711 controls a wireless LAN unit 716 via a wireless LAN communication control unit 715, thereby enabling wireless LAN communication with other communication information processing devices. The CPU 711 controls a wired LAN unit 718 via a wired LAN communication control unit 717, thereby enabling wired LAN communication with other communication information processing devices. The CPU 711 also controls an operation unit control circuit 719, thereby enabling operation input from a user via an operation button 720.
[0051] The terminal access control unit 721 protects the network by authenticating communication devices connected to the network. Examples of authentication methods include a PSK method using a Pre-Shared Key (PSK) and an SAE (Simultaneous Authentication of Equals) method using SAE. Alternatively, an EAP method using an authentication server compatible with IEEE802.1X / EAP may be used (hereinafter, IEEE802.1X / EAP may be simply referred to as "802.1X / EAP"). The channel of communication authenticated in this way can be changed or switched by the channel change unit 722.
[0052] (Authentication Server Configuration) 8 shows an example of the configuration of an authentication server 800. The authentication server 800 includes a main board 811 that performs system control, and a communication unit 801 that performs wired LAN communication.
[0053] The main board 811 includes a CPU 812, a ROM 813, a RAM 814, an image memory 815, a nonvolatile memory 822, a data storage unit 823, and a communication control unit 826. The main board 811 further includes a display unit 802 and an operation unit 803, which are connected to each other via a system bus (bus cable) 828. The main board 811 is also connected to the communication unit 801 by the communication control unit 826.
[0054] The CPU 812 functions as a system control unit that controls the entire authentication server 800. The processing of the authentication server 800 is realized by the CPU 812 loading a program stored in the ROM 813 into the RAM 814 and executing it.
[0055] More specifically, the ROM 813 stores control programs and embedded OS programs executed by the CPU 812. The CPU 812 executes corresponding programs under the embedded OS to perform software control such as scheduling and task switching. The RAM 814 is configured with an SRAM or the like. The RAM 814 stores various data, such as variables for program control, setting values registered by the user, and management data for managing the authentication server 800. The RAM 814 can be used as various work buffers. The image memory 815 is configured with a memory such as a DRAM. The image memory 815 temporarily stores image data received via the communication unit 801 and image data read from the data storage unit 823, enabling processing by the CPU 812. The data storage unit 812 is configured with a storage medium such as an SSD (Solid State Drive), and retains stored data even when the authentication server 800 is powered off. Other storage media, such as an HDD or nonvolatile memory, may also be used as the data storage unit 212.
[0056] Note that, like the main board 211, the individual functions of the main board 811 described here may be realized by either hardware or software.
[0057] The display unit 802 electronically controls the display content and executes control for displaying operation inputs by the user, status conditions, etc. In response to receiving operation inputs from the user, the operation unit 803 outputs an electrical signal corresponding to the operation input to the CPU 812.
[0058] The authentication server 800 can perform data communication with the access point 700 (or other devices) via the communication unit 801 using the communication control unit 826, for example, converting data into packets and transmitting them to other external devices. The communication unit 801 also receives packets from other external devices, restores the original data, and outputs it to the CPU 812. The communication unit 801 is capable of data (packet) communication in a wired LAN (Ethernet) system that complies with the IEEE 802.3 series, for example.
[0059] (P2P communication method) This section describes wireless direct communication in which communication devices communicate wirelessly with each other directly (without going through the external access point 700) in WLAN communication. For example, a communication device can support multiple modes for wireless direct communication and selectively use one of the multiple modes to perform P2P communication (WLAN). The P2P modes are: Mode A (Soft AP mode) Mode B (Wi-Fi Direct (WFD) mode) Two modes are assumed:
[0060] A communication device capable of executing P2P communication can be configured to support at least one of these modes (in this specification, Mode A and Mode B can be collectively referred to as Wireless Direct). A communication device capable of executing P2P communication does not need to support all of these modes and may be configured to support only some of them.
[0061] Note that the MFP 300 operating in P2P mode acts as a master device in connection and communication with other devices. This does not apply to the WFD mode, where the MFP 300 may act as a client device by executing group owner negotiation. Furthermore, the communication device may also support wireless infrastructure mode (mode C) in addition to P2P mode.
[0062] In a communication device (e.g., information processing device 200) having a WFD communication function, an application (or a dedicated application) for realizing the communication function is called by accepting a user operation via its operation unit. The communication device displays a UI (user interface) screen provided by the application to prompt the user to input an operation, and can execute WFD communication based on the input operation.
[0063] (Wireless infrastructure mode) In the wireless infrastructure mode, communication devices (e.g., information processing device 200 and MFP 300) that communicate with each other are connected to an external access point (here, AP 700) that controls the network, and communication between the communication devices is performed via the AP. In other words, communication between the communication devices is achieved via a network established by the AP. Furthermore, MFP 300 operating in the wireless infrastructure mode operates as a slave device (station) in connection and communication with access point 700.
[0064] In the wireless infrastructure mode, each device searches for an access point by transmitting a probe request. When each device receives a probe response from the access point, it displays the SSID (Service Set Identifier) included in the probe response. When the information processing device 200 and the MFP 300 each discover the access point 700, they transmit a connection request to the access point 700, and are connected, enabling communication in the wireless infrastructure mode via the access point 700 between these communication devices.
[0065] Note that multiple communication devices may be connected to different APs. In this case, communication between the communication devices is possible by transferring data between the APs. Commands and parameters sent and received during communication between the communication devices may be compliant with the Wi-Fi standard.
[0066] The access point 700 determines the frequency band and frequency channel. For example, the access point 700 can select whether to use the 5 GHz or 2.4 GHz frequency band and which frequency channel to use within that frequency band.
[0067] When the information processing device 200 or the MFP 300 connects to the wireless LAN configured by the access point 700, authentication is performed by the access point 700. The information processing device 200 or the MFP 300 connects to the wireless LAN configured by the access point 700 using a wireless LAN authentication method such as the PSK method, the SAE method, or the EAP method in accordance with the authentication method of the wireless LAN configured by the access point 700.
[0068] (wired communication mode) In wired communication mode, a communication device (e.g., MFP 300) can communicate with other communication devices via a wired interface such as a wired LAN. For example, when MFP 300 performs communication in wired communication mode, communication in wireless infrastructure mode is restricted. In wired communication mode, data (packet) communication is possible over a wired LAN (Ethernet) conforming to the IEEE 802.3 series, for example. When operating with the IEEE 802.1X / EAP setting enabled, MFP 300 performs authentication using IEEE 802.1X when connecting to the wired LAN configured by access point 700.
[0069] (Regarding simultaneous wireless operation) When two communication modes are communications using authentication methods that do not use authentication server 800, MFP 300 can simultaneously (concurrently) execute communications in each mode. That is, MFP 300 maintains a connection for executing communications in each mode and simultaneously maintains multiple connections corresponding to multiple communication modes. Specifically, for example, MFP 300 can simultaneously execute communications in both wireless infrastructure mode and P2P mode. Therefore, MFP 300 simultaneously maintains a connection for communicating in wireless infrastructure mode and a connection for communicating in P2P mode. Such an operation may be referred to as "simultaneous wireless operation." In other words, simultaneous wireless operation can be, for example, an operation in which MFP 300 simultaneously operates as a client device in Wi-Fi communication using wireless infrastructure mode and as a parent device in Wi-Fi communication using P2P mode. On the other hand, when MFP 300 communicates using an authentication method that uses authentication server 800, MFP 300 does not simultaneously maintain both an infrastructure connection and a P2P connection.
[0070] (Processing Overview) 8 to 17 show an example of a system configuration and a sequence or flowchart that can realize the communication of this embodiment. Each step of the flowchart is performed by the corresponding CPU expanding a program stored in ROM onto RAM and executing it.
[0071] (Screen flow) 11(a) to 11(j) are screen flow diagrams when LAN setting is selected from the setting menu of screen 408 in FIG. 4(b) on operation display unit 302 of MFP 300. FIG.
[0072] 11(a) is a screen that is displayed when LAN settings are selected on the screen 408 in FIG. 4(b), and allows changes to the LAN settings. The screen i1100 displays a wireless LAN display i1201, a wired LAN display i1202, a Wireless Direct display i1203, and a common settings display i1204.
[0073] 11(b) is a screen that is displayed when wireless LAN display i1201 is selected on screen i1100 in FIG. 11(a), and allows changes to wireless LAN settings. Screen i1110 displays wireless LAN enable / disable i1211, wireless LAN setup i1212, wireless LAN setting display i1213, and advanced settings i1214. Wireless LAN enable / disable i1211 is an area for setting whether to enable or disable communication using wireless LAN by MFP 300. By accepting a user operation on the display screen after this area is selected, the state in which communication using wireless LAN by MFP 300 is enabled or disabled is set.
[0074] When the state is set to disabled, the MFP 300 does not perform communication or connection using a wireless LAN.
[0075] The screen i1120 shown in Fig. 11(c) is displayed when the Advanced Settings i1214 is selected on the screen i1110 in Fig. 11(b), and allows changes to be made to the LAN advanced settings. The screen i1120 displays the TCP / IP Settings i1221 and the 802.1X / EAP Settings i1222.
[0076] The screen i1130 shown in Fig. 11(d) is displayed when the 802.1X / EAP setting i1222 is selected on the screen i1120 in Fig. 11(c), and allows changes to the IEEE802.1X / EAP settings. The screen i1130 displays the IEEE802.1X / EAP enable / disable i1231, the EAP router search i1232, and the most recent authentication result confirmation i1233.
[0077] Screen i1140 shown in Fig. 11(e) is a screen displayed while executing a wireless access point search for an authentication method that uses the authentication server 800. The access point search can be executed in response to selecting Search for EAP Routers i1232 on screen i1130 in Fig. 11(d) when the IEEE802.1X / EAP setting is enabled.
[0078] Note that screen i1140 shown in Figure 11(e) is also displayed when Wireless LAN Setup i1212 is selected on screen i1110 in Figure 11(b) and a search for wireless access points using an authentication method that does not use authentication server 800 is being performed.
[0079] 11(f) is an example of a screen displaying a list of wireless access point identifiers (SSIDs) as a result of an access point search (AP search). The screen display i1150 displays SSIDs i1251 (WPA-EAP001), i1252 (WPA2-EAP005), and i1253 (WPA3-EAP003). These correspond to the WPA-EAP, WPA2-EAP, and WPA3-EAP methods, respectively.
[0080] As another example of the display, known methods such as WPA-PSK, WPA2-PSK, and WPA3-SAE may be displayed, and the OPEN method may also be displayed.
[0081] When EAP router search i1232 is executed, only the SSIDs of access points that use the EAP authentication method are displayed on screen i1150 shown in Fig. 11(f). Also, when wireless LAN setup i1212 is executed, only the SSIDs of access points that do not use the EAP authentication method are displayed.
[0082] Screen i1160 shown in Fig. 11(g) is a screen that is displayed when an SSID (i1251 to i1253) of an access point is selected on screen i1150 in Fig. 11(f) and while MFP 300 is performing connection processing with the access point. In other aspects, other displays indicating that connection processing is in progress may be displayed.
[0083] Screen i1170 shown in Figure 11(h) is a screen that is displayed after screen i1160 in Figure 11(g) is displayed, when an attempt to connect to an access point is completed and the connection is successful or the connection has progressed to a predetermined stage.
[0084] 11(i) is a screen i1180 on which the 802.1X / EAP enable / disable i1231 is selected on the screen i1130 of FIG. 11(d), allowing the IEEE802.1X / EAP setting to be changed to enable / disable. It is assumed that the screen i1180 displays enable i1251 and disable i1252. When the IEEE802.1X / EAP setting is set to disable, the MFP 300 does not connect to an access point using IEEE802.1X / EAP.
[0085] The screen i1190 shown in Fig. 11(j) is a screen that is displayed when the EAP router search i1232 is selected on the screen i1130 in Fig. 11(d) when the IEEE802.1X / EAP setting is disabled. In other words, in this embodiment, when the IEEE802.1X / EAP setting is disabled, a router search is not performed even if the EAP router search i1232 is selected.
[0086] Note that the control for preventing connection to an access point using IEEE 802.1X / EAP authentication, which is executed when the IEEE 802.1X / EAP setting is disabled, is not limited to the control described above. For example, MFP 300 may execute a router search, but may not display access points for which IEEE 802.1X / EAP authentication is enabled in the list of access points discovered by the router search. Alternatively, MFP 300 may display access points for which IEEE 802.1X / EAP authentication is enabled in the list, but may not execute connection processing with such access points even if the user selects them.
[0087] (IEEE802.1X / EAP authentication information settings) When the MFP 300 is connected to a network where authentication by IEEE802.1X / EAP is enabled, authentication must be started after necessary information is set in the MFP 300.
[0088] FIG. 9 shows a flowchart executed by the MFP 300 when the MFP 300 is allowed to join a network established by the access point 700 and for which authentication by IEEE802.1X / EAP is valid.
[0089] In step S901, the MFP 300 connects the information processing device 200 to the MFP 300 using a connection method in which IEEE802.1X / EAP authentication is disabled. Specifically, for example, the MFP 300 receives a connection request from the information processing device 200 and establishes a connection between the MFP 300 and the information processing device 200 operating in P2P mode.
[0090] In step S902, MFP300 receives authentication information from information processing device 200 and uses the information to perform settings related to IEEE802.1X / EAP authentication for MFP300. This setting can be performed by information processing device 200 transmitting the authentication information to MFP300 via the connection established in S901, and MFP300 receiving the information.
[0091] In step S903, the MFP 300 connects to the network for which IEEE802.1X / EAP authentication is enabled, which is established by the access point 700. In other words, the MFP 300 establishes a connection with an access point for which IEEE802.1X / EAP authentication is enabled.
[0092] Here, in step S901, by operating the information processing device 200 and the MFP 300, communication between the devices may be realized based on authentication performed by the authentication server 800 in cooperation with the access point 700, as shown in Fig. 10(a). As another aspect, as shown in Fig. 10(b), communication between the devices may be realized via the AP 700 by connecting to a network established by the AP 700 in which IEEE 802.1X authentication is disabled. As yet another aspect, as shown in Fig. 10(c), connection between the information processing device 200 and the MFP 300 may be realized by connecting the information processing device 200 to a network established by the MFP 300 as a parent station of Wireless Direct.
[0093] 12(a) shows an example of a setting screen for the MFP 300 displayed on the information processing device 200. This screen is displayed when a web browser or application running on the information processing device 200 communicates with an HTTP server running on the MFP 300. This screen may be displayed based on a standby response to an HTTP request via USB communication using the USB communication control unit 320 of the MFP 300. This screen displays the printer status i1101, main unit settings i1102, LAN settings i1103, and security settings i1104.
[0094] Fig. 12(b) is displayed when Security Settings i1104 is selected in Fig. 12(a). This screen shows SSL / TLS Settings i1111 and IEEE802.1X / EAP Settings i1112.
[0095] Fig. 12(c) is displayed when IEEE802.1X / EAP Settings i1212 is selected in Fig. 12(b). This screen displays the authentication method i1121, key and certificate settings i1122, and whether IEEE802.1X / EAP is enabled or disabled i1123.
[0096] 12(d) is displayed when authentication method i1121 is selected in FIG. 12(c). This screen displays EAP-TLS display i1131, EAP-TTLS display i1132, and PEAP display i1133 as authentication methods, a user name (login name) input field i1134, and a password input field i1135. By selecting one of i1131 to i1133, the authentication method to be used during IEEE802.1X / EAP authentication is set in the MFP 300. Furthermore, by inputting a user name and a password in fields i1134 to i1135, the user name and password to be used during IEEE802.1X / EAP authentication are set in the MFP 300.
[0097] When registering a certificate to be used during IEEE802.1X / EAP authentication in the MFP 300, first select "Set Key and Certificate" i1122 on the screen shown in Fig. 12(c). Then, select "Upload Key and Certificate" i1141 on the screen shown in Fig. 12(e) to display the screen shown in Fig. 12(f). On this screen, select a file as the certificate in field i1161, enter a password as the key in field i1162, and then select "Upload" i1163 to complete the upload of the key and certificate.
[0098] On the screen of FIG. 12(e), it is also possible to delete certificates stored in the MFP 300 in Delete Keys and Certificates i1142, and it is also possible to display a list of certificates stored in the MFP 300 in Confirm Keys and Certificates i1143.
[0099] 12(g) is displayed by selecting IEEE802.1X / EAP enable / disable i1123 in FIG. 12(c). On this screen, the IEEE802.1X / EAP setting of the MFP 300 can be enabled or disabled.
[0100] In this way, authentication information used in IEEE802.1X / EAP can be set in MFP 300. MFP 300 can be authenticated by authentication server 800 using this authentication information, and thereby connect to a network that uses authentication server 800 configured by access point 700. Here, if MFP 300 can simultaneously enable multiple communication modes (here, infrastructure connection and P2P connection), a communication device can be connected to the network that uses authentication server 800 on the infrastructure connection side and also on the P2P side. In this case, it is possible to change the settings of MFP 300 or request printing from a device that has not been authenticated by authentication server 800.
[0101] When the MFP 300 connects to a network that uses the authentication server 800 on the infrastructure connection side, it is desirable to prevent devices that are not authenticated by the authentication server 800 from changing the settings of the MFP 300 or executing printing, regardless of the order in which the communication modes are switched. Therefore, in this embodiment, the time required to set the communication mode can be reduced by dynamically switching the communication mode according to the IEEE802.1X / EAP settings of the MFP 300 and the authentication method of the wireless infrastructure.
[0102] In this embodiment, each communication mode is managed as an enabled (ON state) / disabled (OFF state). For example, in MFP 300, by controlling wireless communication unit 307 and wired LAN communication unit 321, it is possible to switch between enabled communication modes and control communication.
[0103] (Wireless Infrastructure (EAP) Setup) 13 is a flowchart showing the operation of the MFP 300 when connecting to the access point 700, which uses an authentication method that uses the authentication server 800. This flowchart is executed when the search for wireless infrastructure (EAP) router i1232 is selected on the screen i1130 in FIG. 11(d). This makes it possible to switch the communication mode regardless of the switching order when the MFP 300 is to join a wireless infrastructure network that uses an authentication method that uses an authentication server established by the AP 700. Before executing the EAP setup process, information used for IEEE 802.1X / EAP authentication is set in advance in the MFP 300 (see FIG. 9), and if the authentication information is not set in the MFP 300, the EAP authentication will fail.
[0104] In step S1301, MFP 300 receives a search request (AP search request) from access point 700. In response to receiving the search request, the process proceeds to step S1302.
[0105] In step S1302, the MFP 300 determines whether the type of the search request for the access point 700 is Enterprise. If "Search for EAP Routers i1232" is selected on screen i1130 in FIG. 11(d), the MFP 300 determines that the search request is for Enterprise. Also, if "Wireless LAN Setup i1212" is selected on screen i1110 in FIG. 11(b), the MFP 300 determines that the search request is not for Enterprise. If the MFP 300 receives a search request for the access point 700 via the communication path, or if the search request includes an instruction to search for Enterprise, the MFP 300 determines that the search request is for Enterprise. If the type of the search request for the access point is Enterprise, the MFP 300 proceeds to step i1303; if not, the MFP 300 proceeds to step S1307.
[0106] In step S1303, the MFP 300 determines whether the IEEE802.1X / EAP setting is valid or not, and if it is valid, the process proceeds to step S1304, and if it is invalid, the process proceeds to step S1305.
[0107] In step S1304, the MFP 300 responds that an Enterprise search cannot be performed. For example, if the IEEE802.1X / EAP setting is enabled and "Search for EAP routers i1232" is selected on the screen i1130 in Figure 11(d), the screen i1190 in Figure 11(j) is displayed.
[0108] In step S1305, the MFP 300 stores information that a search for an access point 700 whose authentication method is Enterprise is to be performed, and then performs the search in step S1306. Steps S1305 and S1306 may be performed in the reverse order.
[0109] In step S1307, MFP 300 stores information to search for an access point (for example, access point 700′) whose authentication method is Personal, and executes the search in step S1308. Steps S1307 and S1308 may be executed in the reverse order.
[0110] In step S1309, the MFP 300 displays a list of SSIDs of wireless APs, as exemplified in FIG. 11(f), as a result of the AP search performed in steps S1305 to S1308.
[0111] In step S1310, the user selects an access point to be connected from the list, and in response to receiving the connection request, MFP 300 proceeds to step S1311.
[0112] In step S1311, MFP 300 determines whether Wireless Direct is enabled before setup, and if it is enabled, proceeds to step S1312, and if it is disabled, proceeds to step S1316.
[0113] In step S1312, MFP 300 determines whether the IEEE802.1X / EAP setting is valid or not, and if it is valid, proceeds to step S1313, and if it is invalid, proceeds to step S1316.
[0114] In step S1313, if the authentication method of the access point to be connected to is an authentication method that uses an authentication server, MFP 300 proceeds to step S1314, otherwise proceeds to step S1316. This determination may be made based on the content (i.e., the type of AP search) stored in step S1305 or S1307.
[0115] MFP 300 disables Wireless Direct in step S1314, and then enables the wireless infrastructure in step S1315, connecting to a network that uses an authentication method that uses an authentication server configured by access point 700. Note that disabling Wireless Direct means that MFP 300 stops operating as an access point or as a Wi-Fi Direct group owner, and enters a state in which it will not establish a Wi-Fi Direct connection with other devices.
[0116] In step S1316, MFP 300 activates the wireless infrastructure and connects to the network configured by access point 700. Note that activating the wireless infrastructure means starting operation in wireless infrastructure mode.
[0117] Here, if the judgment result is YES in step S1311 and NO in step S1312, or if the judgment result is YES in step S1311 and YES in step S1312 and NO in step S1313, both the wireless infrastructure (not EAP) and wireless direct communication modes become valid.
[0118] 11(g) is displayed until an attempt to connect to the access point is started in step S1315 after the access point to be connected to is selected in step S1310. If the process proceeds to step S1316, screen i1160 is displayed until the success or failure of the connection to the access point is confirmed.
[0119] In this way, MFP 300 can participate in a wireless infrastructure network that uses an authentication server established by access point 700. This allows dynamic switching of communication modes without sacrificing convenience when a user sets up a wireless infrastructure. When a communication mode using an authentication method that uses authentication server 800 is enabled, it is possible to prevent job execution or setting changes via a communication mode using an authentication method that does not use authentication server 800.
[0120] In step S1302, the type of search request for the access point 700 may not be specified. In this case, a search request for Enterprise may be given priority, or connection to an access point may be attempted regardless of type.
[0121] (AP Search) Fig. 14 is a flowchart showing the operation when searching for an access point by the MFP 300. This flowchart is executed when Search for EAP router i1232 is selected on the screen i1130 in Fig. 11(d).
[0122] The processing contents of steps S1401 to S1408 in Fig. 14 are the same as those of steps S1301 to S1308 in Fig. 13. As a result, a search for an access point for which EAP authentication is valid is performed only when the IEEE802.1X / EAP setting is valid, making it possible to prevent an unexpected connection to an access point for which authentication is valid.
[0123] (Wireless infrastructure enablement) 15 is a flowchart showing the operation of the MFP 300 when activating the wireless infrastructure. This flowchart is executed when Enable i1251 is selected on screen i1180 in FIG. 11(i), and corresponds to step S1303 in FIG.
[0124] The processing details of steps S1501 to S1507 in Fig. 15 are the same as those of steps S1310 to S1316 in Fig. 13. As a result, when a user activates the wireless infrastructure, the communication mode can be dynamically switched without impairing user convenience, similar to the wireless infrastructure (EAP) setup in Fig. 13. Furthermore, when the communication mode of the authentication method that uses the authentication server 800 is enabled, it is possible to prevent job execution and setting changes via the communication mode of the authentication method that does not use the authentication server 800.
[0125] (Enable Wireless Direct) Fig. 16 is a flowchart showing the operation of the MFP 300 when Wireless Direct is enabled. This flowchart is executed when Wireless Direct i1203 is selected on the screen i1100 in Fig. 11(a). As a result, when a request to enable Wireless Direct is made while the MFP 300 is already connected to a wireless infrastructure network that uses an authentication method that uses an authentication server established by the AP 700, the communication mode can be switched regardless of the switching order.
[0126] In step S1601, in response to receiving a notification requesting activation of Wireless Direct, the MFP 300 proceeds to step S1602.
[0127] In step S1602, if the wireless infrastructure is valid, the MFP 300 proceeds to step S1603, and if it is invalid, the MFP 300 proceeds to step S1607.
[0128] In step S1603, if the IEEE802.1X / EAP setting is valid, the MFP 300 proceeds to step S1604, and if it is invalid, the MFP 300 proceeds to step S1607.
[0129] In step S1604, if the authentication method of the access point to be connected is an authentication method that uses an authentication server, MFP 300 proceeds to step S1605, and if not, proceeds to step S1607.
[0130] In step S1605, MFP 300 disables the wireless infrastructure, and then in step S1606, enables Wireless Direct and connects MFP 300 to a network that uses an authentication method that uses an authentication server configured by access point 700. Disabling the wireless infrastructure means that if MFP 300 is connected to an access point, it disconnects from the access point and stops operating as a client device in Wi-Fi communication.
[0131] In step S1607, the MFP 300 enables Wireless Direct. If the determination is NO in any of steps S1602 to S1604, both the Wireless Infrastructure (not EAP) and Wireless Direct communication modes are enabled.
[0132] According to this flowchart, when a user sets Wireless Direct, dynamic switching of the communication mode is possible without impairing convenience. Also, when a communication mode of an authentication method that uses authentication server 800 is valid, it is possible to prevent job execution or setting changes via a communication mode of an authentication method that does not use authentication server 800.
[0133] (Enabling EAP settings) 17 is a flowchart showing the operation of the MFP 300 when enabling the IEEE 802.1X / EAP settings. This flowchart is executed when Enable i1251 is selected on screen i1180 in FIG. 11(i), and corresponds to step S1303 in FIG. 13.
[0134] In step S1701, the MFP 300 receives a notification requesting that the IEEE802.1X / EAP setting be enabled.
[0135] In step S1702, the MFP 300 updates the IEEE802.1X / EAP setting value recorded in the MFP 300 to "enabled."
[0136] In step S1703, MFP 300 determines whether the communication mode setting is invalid (whether the communication mode is not set). If any of wired infrastructure, wireless infrastructure, and wireless direct is valid, the process proceeds to step S1704; if none of them are valid, the process ends.
[0137] In step S1704, MFP 300 disables the enabled communication mode, and then in step S1705, enables the disabled communication mode. That is, the communication mode is restarted. If the restarted communication mode is wired infrastructure, the IEEE802.1X / EAP setting is enabled in S1702, and therefore, while authentication using IEEE802.1X / EAP was not performed before the restart, authentication using IEEE802.1X / EAP is performed after the restart when connecting to access point 700.
[0138] (Disable EAP settings) FIG. 18 is a flowchart showing the operation of the MFP 300 when the EAP settings are disabled. This flowchart is executed when Disable i1252 is selected on screen i1180 in FIG. 11(i). When a request is made to disable the EAP settings, the MFP 300 disables the EAP settings and, if the authentication method of the wireless infrastructure is an authentication method that uses an authentication server, initializes the setting values of the wireless infrastructure. Note that, if the authentication method of the wireless infrastructure is not an authentication method that uses an authentication server, the setting values of the wireless infrastructure are not initialized. Furthermore, even if the wireless infrastructure communication mode is disabled, if the authentication method of the wireless infrastructure is an authentication method that uses an authentication server, the setting values of the wireless infrastructure are initialized.
[0139] In step S1801, in response to receiving a notification requesting the invalidation of the IEEE802.1X / EAP setting, the MFP 300 proceeds to step S1802.
[0140] In step S1802, the MFP 300 determines whether the IEEE802.1X / EAP setting is valid or not, and if it is valid, the MFP 300 proceeds to step S1803, and if it is not valid, the MFP 300 ends this flowchart.
[0141] In step S1803, the MFP 300 updates the IEEE802.1X / EAP setting value recorded in the MFP 300 to "disabled."
[0142] In step S1804, MFP300 determines whether the authentication method of the wireless infrastructure recorded in MFP300 is an authentication method that uses an authentication server, and if it is an authentication method that uses an authentication server, proceeds to step S1805, and if not, ends this flowchart.
[0143] In step S1805, the MFP 300 determines whether the wireless infrastructure is valid or not, and if valid, proceeds to step S1806, and if invalid, proceeds to step S1809.
[0144] The MFP 300 disables the wireless infrastructure in step S1806, then initializes the settings of the wireless infrastructure in step S1807, and enables the wireless infrastructure in step S1808. Specifically, the initialization in step S1807 can be performed by updating the SSID, authentication method, encryption method, password, etc. stored in the MFP 300 to their initial values.
[0145] In step S1809, the MFP 300 initializes the setting values of the wireless infrastructure, similar to step S1807.
[0146] (Device settings screen flow) 19(a) to 19(c) show some examples of screens that are displayed when main body settings is selected from the list of setting menus displayed on screen 408 of FIG. 4(b) on operation display unit 302 of MFP 300.
[0147] Screen i1900 in Fig. 19(a) is displayed when main unit settings is selected on screen 408 in Fig. 4(b), and allows the main unit settings to be changed. Here, LAN settings i1901, setting reset i1902, date / time settings i1903, and other main unit settings i1904 are shown.
[0148] The screen i1910 in Fig. 19(b) is displayed when the setting reset i1902 is selected on the screen i1900 in Fig. 19(a), and allows the setting reset to be executed. Here, it is assumed that the settings reset only i1911 and all reset i1912 are displayed.
[0149] Screen i1920 in Fig. 19(c) is displayed when Date / Time Setting i1903 is selected on screen i1900 in Fig. 19(a), and allows the date and / or time settings to be changed. By entering the date and / or time in field i1922 on screen i1920, the date and / or time settings can be updated.
[0150] (Reset settings) Fig. 20 is a flowchart showing the operation of the MFP 300 when a setting reset is requested. This flowchart is executed when "Reset LAN Settings Only" i1911 or "Reset All" i1912 is selected on the screen i1910 in Fig. 19(b). When a setting reset is requested, the MFP 300 initializes the setting values according to the type of setting reset.
[0151] In step S2001, in response to receiving a notification requesting a settings reset, the MFP 300 proceeds to step S2002.
[0152] In step S2002, MFP 300 determines the type of setting reset. If "Reset LAN Settings Only" i1911 is selected on screen i1910 in Fig. 19(b), it is determined to be a LAN setting reset, and the process proceeds to step S2004. If "Reset All" i1912 is selected on screen i1910 in Fig. 19(b), it is determined to be a full setting reset, and the process proceeds to step S2005.
[0153] In step S2003, MFP 300 deletes the recorded SSID, authentication method, encryption method, etc., and then in step S2004 changes the type of communication mode to the initial setting.
[0154] In step S2005, the MFP 300 initializes the recorded IEEE802.1X / EAP setting information.
[0155] (Change time settings) 21 is a flowchart showing the operation of the MFP 300 when changing the time setting. This flowchart is executed when a time is entered in field i1922 on screen i1920 in FIG.
[0156] When performing authentication using IEEE802.1X / EAP, the MFP 300 may verify the expiration date of the certificate used for authentication using the time set on the MFP 300. Therefore, if the time setting on the MFP 300 is changed, the changed time must be reflected in the communication control unit 318 and the wireless communication unit 307. If the communication control unit 318 or the wireless communication unit 307 needs to be restarted to reflect the time, the communication mode is restarted when the time setting on the MFP 300 is changed. However, restarting the communication mode temporarily disconnects communication, and it takes time before communication is possible again. It is preferable to restart the communication mode only when it is necessary to restart the communication mode.
[0157] In step S2101, in response to receiving a notification indicating a change in the time setting, MFP 300 proceeds to step S2102.
[0158] In step S2102, the MFP 300 determines whether the IEEE802.1X / EAP setting is enabled, and if it is enabled, proceeds to step S2103. On the other hand, if it is disabled, proceeds to step S2105, where the MFP 300 ends this flowchart without disabling the communication mode.
[0159] The MFP 300 disables the active communication mode in step S2103, and then re-enables the communication mode in step S2104. In this way, when the user sets the time, the communication mode can be dynamically switched only if it is necessary to restart the communication mode.
[0160] The names of the individual elements or functional units described in the above-described embodiments are expressed in this specification based on their main functions, but may also be expressed based on their sub-functions. Therefore, the present invention is not strictly limited to such expressions (the expressions may be replaced with similar expressions). In the same vein, the expression "unit" may be replaced with "component, piece," "member," "structure," "assembly," "circuit, module," "means," etc., or may be omitted.
[0161] The present invention may be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in a computer of the system or device read and execute the program. For example, the present invention may be realized by a circuit (e.g., an ASIC) that realizes one or more functions.
[0162] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]
[0163] 300: communication device, 700: access point, 800: authentication server.
Claims
1. A communication device capable of communicating with an information processing device, a first accepting means for accepting a first operation for establishing a connection between the communication device and the information processing device as a first connection, the connection not passing through an access point external to the communication device and external to the information processing device; a first establishing means for establishing the first connection after the first operation is accepted; a second accepting means for accepting a second operation for establishing a connection between the access point and the communication device as a second connection, the connection corresponding to a predetermined authentication method using an authentication server; second establishing means for establishing the second connection after the second operation is accepted; a third accepting means for accepting a third operation for establishing a connection between the communication device and the access point that does not support the predetermined authentication method as a third connection; a third establishing means for establishing the third connection after the third operation is accepted; a first control means that, based on the fact that the first operation is accepted while the second connection is established, controls the first connection of the first connection and the second connection to be maintained, and, based on the fact that the first operation is accepted while the third connection is established, controls the first connection and the third connection to be maintained in parallel, A communication device comprising:
2. The first control means the second connection is disconnected based on the first operation being accepted while the second connection is established; the first connection is established after the second connection is disconnected, and Even after the first connection is established, the second connection remains disconnected. Control so that 2. The communication device according to claim 1.
3. The communication device further comprises a second control means for controlling, based on the fact that the second operation is accepted while the first connection is established, so that the second connection of the first and second connections is maintained, and for controlling, based on the fact that the third operation is accepted while the first connection is established, so that the first connection and the third connection are maintained in parallel, 2. The communication device according to claim 1.
4. The second control means the first connection is disconnected based on the second operation being accepted while the first connection is established; the second connection is established after the first connection is disconnected, and Even after the second connection is established, the first connection remains disconnected. Control so that 4. The communication device according to claim 3.
5. The second operation includes an operation of selecting the access point corresponding to the predetermined authentication method as a connection target for the communication device, the third operation includes an operation of selecting the access point that does not support the predetermined authentication method as a connection target for the communication device.
2. The communication device according to claim 1.
6. The second operation includes an operation of causing the communication device to search for the access point corresponding to the predetermined authentication method when the second operation is accepted; the third operation includes an operation of causing the communication device to search for the access point that does not support the predetermined authentication method when the third operation is accepted; the second operation and the third operation are different from each other; 2. The communication device according to claim 1.
7. Further comprising another receiving means for receiving a request to enable or disable the setting related to the predetermined authentication method.
2. The communication device according to claim 1.
8. The method further comprises a third control means for controlling so that processing for establishing the second connection is not executed even if the second operation is accepted when the setting related to the predetermined authentication method is disabled.
8. The communication device according to claim 7,
9. The communication device further comprises an operating means for disabling the mode for the third connection and then operating the communication device in the mode for the second connection when an operation for enabling the setting related to the predetermined authentication method is accepted while the communication device is operating in the mode for the third connection.
8. The communication device according to claim 7,
10. The communication device further comprises a second operating means for, when an operation to disable the setting related to the predetermined authentication method is accepted while the communication device is operating in the mode for the second connection, disabling the mode for the second connection and then operating the communication device in the mode for the third connection.
8. The communication device according to claim 7,
11. The predetermined authentication method is an IEEE 802.1X / EAP (Extensible Authentication Protocol) authentication method.
2. The communication device according to claim 1.
12. The predetermined authentication method is one of an EAP-TLS (EAP-Transport Layer Security) method, an EAP-TTLS (EAP-Tunneled TLS) method, and a PEAP (Protected EAP) method.
2. The communication device according to claim 1.
13. The access point that does not support the predetermined authentication method is the access point that supports an authentication method that does not use the authentication server.
2. The communication device according to claim 1.
14. The printing device further includes a printing means for performing printing.
2. The communication device according to claim 1.
15. The method further comprises: scanning means for performing a scan; 2. The communication device according to claim 1.
16. The first connection is a wireless direct connection.
2. The communication device according to claim 1.
17. The authentication server is a Radius server.
2. The communication device according to claim 1.
18. A method for controlling a communication device capable of communicating with an information processing device, comprising: a first receiving step of receiving a first operation for establishing a connection between the communication device and the information processing device as a first connection, the connection not passing through an access point external to the communication device and external to the information processing device; a first establishment step of establishing the first connection after the first operation is accepted; a second receiving step of receiving a second operation for establishing a connection between the access point and the communication device as a second connection, the connection corresponding to a predetermined authentication method using an authentication server; a second establishment step of establishing the second connection after the second operation is accepted; a third receiving step of receiving a third operation for establishing a connection between the access point that does not support the predetermined authentication method and the communication device as a third connection; a third establishment step of establishing the third connection after the third operation is accepted; a first control step of controlling the first connection of the first and second connections to be maintained based on the first operation being accepted while the second connection is established, and controlling the first connection and the third connection to be maintained in parallel based on the first operation being accepted while the third connection is established, A control method comprising:
19. A program for causing a computer to execute each step of the control method described in claim 18.
Citation Information
Patent Citations
Information processing device, control method, and program
JP2016127545A