Communication devices, control methods, programs

The communication device notifies users of incomplete setup processes due to restrictive security policies, addressing the unawareness of setup failures.

JP2026076819APending Publication Date: 2026-05-12CANON KK
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CANON KK
Filing Date
2024-10-24
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Users may not realize that they cannot complete the wireless LAN connection setup process due to restrictive security policies, leading to incomplete setup configurations.

Method used

A communication device with connection setting means, setting means, and control means to restrict functions and notify users when setup cannot be completed.

Benefits of technology

Notifies users when connection setup cannot be completed, ensuring they are aware of the limitations and potential issues.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026076819000001_ABST
    Figure 2026076819000001_ABST
Patent Text Reader

Abstract

If the connection setup process cannot be completed for a given setting, the communication device is provided that can notify the user that the connection setup process cannot be completed for that setting. [Solution] The communication device includes connection setting means for performing a connection setting process to connect the communication device to an external access point, setting means for setting the functions of the communication device to be restricted, and first control means for controlling the connection setting process not to start and displaying information indicating that the functions necessary to perform the connection setting process are restricted by the setting means.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a communication device, a control method, and a program capable of executing connection setting processing.

Background Art

[0002] Image processing devices such as printers that communicate with terminal devices such as personal computers (PCs) and smartphones are known. Such an image processing device executes connection setting processing for communicating with a terminal device by a predetermined communication method such as WiFi (registered trademark), for example. Regarding the connection setting processing, there is a technique for minimizing the setting operation of the wireless LAN connection on the image processing device side by executing the connection setting using a tool (application) of the terminal device (Patent Document 1).

[0003] On the other hand, personal computers (PCs) and server devices (file servers, authentication servers, etc.) connected to a network in an office or the like are preferably operated according to a security policy determined for each office. Here, complying with the security policy means, for example, making user authentication essential when operating an image processing device, making encryption of the communication path essential, etc., and imposing restrictions on the security operation of the image processing device in order to prevent unauthorized use and information leakage That is to say. In such an image processing device, control is performed to maintain a state in accordance with the security policy. Specifically, when a certain security policy is set, specific setting items related to the security policy become fixed values and cannot be changed by users other than the security administrator (Patent Document 2).

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Patent Document 2

Summary of the Invention

[0005] When a communication device is configured to restrict communication for a wireless LAN connection setup process, the user may not realize that they cannot complete the setup process due to that configuration.

[0006] The present invention aims to provide a communication device, control method, and program that can notify that the connection setup process cannot be completed for a given setting, if such a setting cannot be completed. [Means for solving the problem]

[0007] The communication device according to the present invention is a communication device comprising: connection setting means for performing a connection setting process for connecting the communication device to an external access point; setting means for setting the functions of the communication device to be restricted; and first control means for controlling the connection setting process not to start and displaying information indicating that the functions necessary for performing the connection setting process are restricted by the setting means. [Effects of the Invention]

[0008] According to the present invention, if the connection setup process cannot be completed for a given setting, it is possible to notify the user that the connection setup process cannot be completed for that setting. [Brief explanation of the drawing]

[0009] [Figure 1] This diagram shows the system configuration. [Figure 2] This diagram shows the configuration of the MFP (Multi-Functional Processor). [Figure 3] This is a diagram showing the operation display section of an MFP (Multifunction Printer). [Figure 4] This is a diagram showing the configuration of a mobile terminal device. [Figure 5]This diagram shows the configuration of the access point. [Figure 6] This diagram shows the software configuration of the MFP. [Figure 7] This flowchart shows the processes performed by the MFP. [Figure 8] This flowchart shows the processes performed by the MFP. [Figure 9] This is a diagram showing the user interface screen. [Figure 10] This is a sequence diagram of the processes performed between devices. [Figure 11] This flowchart shows the processes performed by the MFP. [Modes for carrying out the invention]

[0010] The embodiments will be described in detail below with reference to the attached drawings. Note that the following embodiments do not limit the invention as defined in the claims. While the embodiments describe multiple features, not all of these features are essential to the invention, and the features may be combined in any way. Furthermore, in the attached drawings, identical or similar configurations are given the same reference numerals, and redundant descriptions are omitted.

[0011] (System Configuration) Figure 1 shows an example of the system configuration according to this embodiment. In one example, this system is a wireless communication system in which multiple communication devices can communicate with each other wirelessly. In the example in Figure 1, the communication devices include a mobile terminal device 103, an MFP 100, an access point AP 101, a server 102, and a network 110. AP 101 may sometimes be shown as AP1. Specifically, AP 101 is, for example, a wireless LAN router. The mobile terminal device 103 is a device that has wireless communication functionality such as wireless LAN. Hereinafter, wireless LAN may be referred to as WLAN. The mobile terminal device 103 may be a personal information terminal such as a PDA (Personal Digital Assistant), a mobile phone (smartphone), a digital camera, a personal computer, etc. In this embodiment, the connection between the mobile terminal device 103 and AP 101, and the connection between MFP 100 and AP 101 are assumed to be connections based on the IEEE 802.11 series standard. The communication method based on the IEEE 802.11 series standards is specifically Wi-Fi (Wireless Fidelity) (registered trademark).

[0012] The MFP100 is a printing device or image forming device having a printing function, and may also have a reading function (scanner), a fax function, or a telephone function. Furthermore, the MFP100 in this embodiment has a communication function that enables wireless communication with the mobile terminal device 103. In this embodiment, the use of the MFP100 is described as an example, but it is not limited to this. For example, a scanner device, projector, mobile terminal, smartphone, notebook PC, tablet terminal, PDA, digital camera, music playback device, television, smart speaker, etc., each having a communication function, may be used instead of the MFP100. Note that MFP is an acronym for Multi Function Peripheral.

[0013] AP101 is provided separately (externally) from the mobile terminal device 103 and the MFP100 and operates as a WLAN base station device. A communication device having a WLAN communication function can perform communication in the infrastructure mode of the WLAN via AP101. Hereinafter, the access point may be referred to as "AP". Also, the infrastructure mode may be referred to as the "infrastructure connection mode". AP101 performs wireless communication with a communication device that has permitted (authenticated) connection to itself and relays wireless communication between that communication device and other communication devices. Also, AP101 can be connected to, for example, a wired communication network and relay communication between a communication device connected to that wired communication network and another communication device wirelessly connected to AP101.

[0014] The server 102 is connected to the MFP100 via the AP101 and the network 110, and provides services to the MFP100 by responding to requests from the MFP100. Here, the network 110 may be the so-called Internet, or may be a closed network within a company or a mobile phone network. The system according to the present embodiment is not limited to the configuration shown in FIG. 1, and may include, for example, an authentication server that performs the above authentication.

[0015] (Appearance configuration of MFP) FIG. 2(a) shows an example of the external configuration of the MFP100. The MFP100 has, for example, an operation display unit 201, a printing paper insertion port 202, a printing paper discharge port 203, a document table 204, and a document cover 205.

[0016] The operation display unit 201 is composed of keys such as character input keys, cursor keys, enter keys, cancel keys, etc., and includes LEDs, LCDs, etc., and is configured to be able to receive the activation of various functions as an MFP by the user and the operations of various settings. Further, the operation display unit 201 may be composed of a touch panel display. The printing paper insertion slot 202 is an insertion slot into which papers of various sizes can be set. The printing paper discharge port 203 is a discharge port for discharging the printed papers. The papers set in the printing paper insertion slot 202 are conveyed one by one to the printing unit, and after being printed in the printing unit, they are discharged from the printing paper discharge port 203. The document table 204 is a table on which the document to be read is placed. The document cover 205 is a cover for pressing the document placed on the document table 204 and preventing the light from the light source irradiating the document during reading from leaking outside.

[0017] The MFP 100 has a USB communication function, and the USB communication unit 206 is composed of a circuit for communication by USB connection and a USB connector. The MFP 100 has a wireless communication function by WLAN. Although it does not necessarily need to be visually recognized from the outside, the communication unit 207 for its wireless communication is composed of an antenna for wireless communication. The MFP 100 can perform wireless communication in the frequency bands of 2.4 GHz and 5 GHz by WLAN, similar to the mobile terminal device 103. The MFP 100 has a FAX communication function, and the FAX communication unit 208 is equipped with a circuit for sending and receiving FAX and a connector for a telephone line. The power supply unit 209 is equipped with a power supply circuit and a power jack for supplying power to the MFP 100.

[0018] (Configuration of MFP) FIG. 2(b) shows a configuration example of the MFP 100. The MFP 100 is composed of a main board 210 for controlling the entire device, an operation display unit 201, a USB communication unit 206, a wireless LAN communication unit 207, a FAX communication unit 208, a power supply unit 209, a print unit 221, and a scan unit 222.

[0019] The microprocessor-type CPU 211 located on the main board 210 operates according to the control program stored in the ROM 213, which is connected via the internal bus 212, and the data stored in the RAM 214. In one example, the processing of the MFP 100 described below is realized by the CPU 211 executing the program stored in the ROM 213. Dedicated hardware may be provided for each process. The ROM 213 is an example of a computer-readable storage medium that stores the control program executed by the CPU 211, the embedded OS program, etc. OS refers to the operating system. In this embodiment, the CPU 211 performs software control such as scheduling and task switching by executing each control program stored in the ROM 213 under the management of the embedded OS, which is also stored in the ROM 213.

[0020] RAM214 is composed of SRAM or the like. RAM214 stores data such as program control variables, user-registered settings, and MFP100 management data. RAM214 can also be used as a buffer for various work tasks. Non-volatile memory 215 is composed of memory such as flash memory and continues to store data even when the MFP100 is powered off. RAM214 and non-volatile memory 215 can be used, for example, as image memory to store image data received via the wireless LAN communication unit 207 and image data that has undergone code-decoding processing.

[0021] The CPU 211 controls the scanning unit 222 via the scan control unit 217 to read the document and store it in, for example, the image memory which is part of the RAM 214. The CPU 211 also controls the printing unit 221 via the print control unit 216 to print the image data held in, for example, the image memory which is part of the RAM 214, onto a recording medium such as printing paper. The scan unit 222 optically reads the document placed on the document table 204, for example, using a CIS (contact image sensor). The scan control unit 217 converts the image obtained by optically reading the document into electrical image data (image signal) and outputs it. At this time, the scan control unit 217 may perform various image processing such as binarization and halftone processing before outputting the image data. The print control unit 216 performs various image processing such as smoothing, print density correction, and color correction on the image data to be printed and outputs the processed image data to the print unit 221. The print unit 221 is configured to perform, for example, an inkjet printing process, ejecting ink supplied from an ink tank from a print head to print an image onto a recording medium such as printing paper. The print unit 221 may also be configured to perform other printing processes such as electrophotography. The print control unit 216 can periodically read information from the print unit 221 and update status information stored in the RAM 214, including the remaining ink level in the ink tanks and the status of the print head.

[0022] The CPU 211 performs USB communication with external devices via USB connection by controlling the USB communication unit 206 via the USB communication control unit 218. Furthermore, the CPU 211 performs wireless LAN communication with external devices via infrastructure connection or direct connection by controlling the wireless LAN communication unit 207, which is a single communication module that performs WLAN communication using at least one common antenna, via the wireless LAN communication control unit 219.

[0023] The wireless LAN communication unit 207 is a unit capable of providing WLAN communication functions, and can provide functions similar to, for example, the WLAN unit 429 of the mobile terminal device 103. That is, the wireless LAN communication unit 207 converts data into packets according to the WLAN standard and sends the packets to other devices, and also restores packets from other external devices to their original data and outputs it to the CPU 211. The wireless LAN communication unit 207 is capable of communication compliant with the IEEE 802.11 standard series. In particular, it is capable of communication compliant with IEEE 802.11a / b / g / n / ac / ax.

[0024] Furthermore, the mobile terminal device 103 and the MFP 100 are capable of direct communication based on Wi-Fi Direct (WFD), and the wireless LAN communication unit 207 has a software access point (soft AP) function or a group owner function. In other words, the wireless LAN communication unit 207 can build a direct communication network and determine the channel to be used for direct communication.

[0025] The CPU 211 controls the FAX communication unit 208 via the FAX communication control unit 220 to perform FAX communication with an external device using a telephone line. The CPU 211 can receive operation information from the operation display unit 201 via the operation display control unit 221. Furthermore, the CPU 211 controls the operation display unit 201 via the operation display control unit 221 to perform actions such as displaying information on the display and generating signals in response to user operations. Note that the operation display unit 201 corresponds to the operation display unit 201 in Figure 2(a).

[0026] (MFP operation display) Figure 3 schematically shows an example of the screen display on the display (touch panel display) included in the operation display unit 201 of the MFP100. Figure 3(a) is an example of the home screen displayed when the MFP100 is powered on and no operations such as printing or scanning are being performed (idle state, standby state). In Figure 3(a), display items (menu items) corresponding to copy, scan, and cloud are displayed. Cloud is a menu item related to cloud functions that utilize internet communication. By selecting any of the menu items through key operations or touch panel operations, the MFP100 can start executing the corresponding settings or functions. The MFP100 can seamlessly display a screen different from Figure 3(a) by accepting key operations or touch panel operations on the home screen of Figure 3(a).

[0027] Figure 3(b) shows an example of another part of the home screen, which is accessed by performing an action (such as sliding left or right) to display other pages of the home screen from the state shown in Figure 3(a). In Figure 3(b), display items (menu items) corresponding to communication settings, print, and photo are shown. When any of these menu items is selected, the function corresponding to the selected menu item, namely the print function, photo function, or communication settings, is executed.

[0028] Figure 3(c) shows an example of the communication settings menu screen displayed when communication settings are selected in the screen shown in Figure 3(b). The communication settings menu screen displays the following menu items (options): "Wireless LAN," "Wired LAN," "Wireless Direct," "Bluetooth," and "Common Settings." "Wireless LAN," "Wired LAN," and "Wireless Direct" are menu items for LAN settings, and from these items, it is possible to configure settings such as wired connection settings, enabling / disabling infrastructure connection mode, and enabling / disabling direct connection modes such as WFD and soft AP mode. If the "Wireless LAN" item is selected and wireless LAN is enabled by user operation, infrastructure connection mode is enabled. If the "Wireless Direct" item is selected and wireless direct is enabled by user operation, direct connection mode is enabled. In addition, if the "Common Settings" item is selected, a common settings menu for each connection type is displayed, and the user can configure settings such as the wireless LAN frequency band and frequency channel.

[0029] (External configuration of a mobile terminal device) Figure 4(a) shows an example of the external configuration of the mobile terminal device 103. In this embodiment, as an example, the case where the mobile terminal device 103 is a general-purpose smartphone is shown. The mobile terminal device 103 is composed of, for example, a display unit 402, an operation unit 403, and a power key 404. The display unit 402 is a display that includes, for example, an LCD (Liquid Crystal Display) type display mechanism. The display unit 402 may also display information using, for example, an LED (Light Emitting Diode). In addition to or instead of the display unit 402, the mobile terminal device 103 may also have a function to output information by voice. The operation unit 403 is composed of hard keys such as keys and buttons, a touch panel, etc., for detecting user operations. In this example, since the information display on the display unit 402 and the reception of user operations by the operation unit 403 are performed using a common touch panel display, the display unit 402 and the operation unit 403 are realized by a single device. In this case, for example, button icons or a software keyboard are displayed using the display function of the display unit 402, and the operation reception function of the operation unit 403 detects when the user touches these areas. Alternatively, the display unit 402 and the operation unit 403 may be separated, with separate hardware for display and hardware for operation reception. The power key 404 is a hard key for receiving user input to turn the power of the mobile terminal device 103 on or off.

[0030] The mobile terminal device 103 does not necessarily need to be visible from its external appearance, but it has a WLAN unit 401 that provides WLAN communication functionality. The WLAN unit 401 is configured to perform data (packet) communication in a WLAN system compliant with, for example, the IEEE 802.11 standard series (IEEE 802.11a / b / g / n / ac / ax, etc.). It is also capable of communication compatible with Wi-Fi Agile Multiband (trademark). However, it is not limited to this, and the WLAN unit 401 may be capable of performing communication in WLAN systems compliant with other standards. In this example, the WLAN unit 401 is assumed to be capable of communication in both the 2.4GHz band and the 5GHz band. Furthermore, the WLAN unit 401 is assumed to be capable of performing communication based on WFD, communication in soft AP mode, communication in infrastructure connection mode, etc. The operation in these modes will be described later.

[0031] (Configuration of mobile terminal devices) Figure 4(b) shows an example of the configuration of the mobile terminal device 103. In one example, the mobile terminal device 103 has a main board 411 that performs the main control of the device itself, and a WLAN unit 429 that performs WLAN communication. The main board 411 includes, for example, a CPU 412, ROM 413, RAM 414, image memory 415, data conversion unit 416, telephone unit 417, GPS 419, camera unit 421, non-volatile memory 422, data storage unit 423, speaker unit 424, and power supply unit 425. Here, CPU is an acronym for Central Processing Unit, ROM for Read Only Memory, RAM for Random Access Memory, and GPS for Global Positioning System. The mobile terminal device 103 also includes a display unit 420 and an operation unit 418. These functional units within the main board 411 are interconnected via a system bus 427 managed by the CPU 412. Furthermore, the main board 411 and the WLAN unit 429 are connected, for example, via a dedicated bus 426.

[0032] The CPU 412 is a system control unit including at least one processor, and controls the entire mobile terminal device 103. In one example, the processing of the mobile terminal device 103 described below is realized by the CPU 412 executing a program stored in the ROM 413. Dedicated hardware may be provided for each process. The ROM 413 stores control programs and embedded operating system (OS) programs that the CPU 412 executes. In this embodiment, the CPU 412 performs software control such as scheduling and task switching by executing each control program stored in the ROM 413 under the management of the embedded OS, which is also stored in the ROM 413.

[0033] RAM 414 is composed of SRAM (Static RAM) or the like. RAM 414 stores data such as program control variables, user-registered settings, and management data for the mobile terminal device 103. RAM 414 can also be used as a buffer for various tasks. Image memory 415 is composed of memory such as DRAM (Dynamic RAM). Image memory 415 temporarily stores image data received via the WLAN unit 429 and image data read from the data storage unit 423 for processing by the CPU 412. Non-volatile memory 422 is composed of memory such as flash memory, and continues to store data even when the power to the mobile terminal device 103 is turned off. Note that the memory configuration of the mobile terminal device 103 is not limited to the above configuration. For example, image memory 415 and RAM 414 may be shared, or data backup may be performed using the data storage unit 423. In this embodiment, DRAM is given as an example of image memory 415, but other storage media such as hard disks or non-volatile memory may be used.

[0034] The data conversion unit 416 performs data analysis of various formats and data conversions such as color conversion and image conversion. The telephone unit 417 controls the telephone line and processes the voice data input and output via the speaker unit 424 to enable telephone communication. The GPS unit 419 receives radio waves transmitted from satellites and acquires location information such as the current latitude and longitude of the mobile terminal device 103.

[0035] The camera unit 421 has the function of electronically recording and encoding images input through the lens. Image data obtained by imaging with the camera unit 421 is stored in the data storage unit 423. The speaker unit 424 has the function of inputting or outputting sound for telephone functions, and also controls functions such as alarm notifications. The power supply unit 425 is, for example, a portable battery and controls the power supply to the device. Power states include, for example, a battery-dead state where there is no remaining battery power, a power-off state where the power key 404 is not pressed, a normal startup state, and a power-saving state where the device is running but power-saving.

[0036] The display unit 420 is the same as the display unit 402 described with reference to Figure 4(a), and, based on the control of the CPU 412, displays various input operations, the operating status of the mobile terminal device 103, and the status of the mobile terminal device 103. The operation unit 418 is the same as the operation unit 403 described with reference to Figure 4(a), and, upon receiving a user operation, performs control such as generating an electrical signal corresponding to that operation and outputting it to the CPU 412.

[0037] The mobile terminal device 103 uses the WLAN unit 429 to perform wireless communication and communicate data with other devices such as the MFP 100. The WLAN unit 429 converts data into packets and transmits them to other devices. The WLAN unit 429 also restores packets from external devices back to their original data and outputs it to the CPU 412. The WLAN unit 429 is a unit that enables communication compliant with WLAN standards. The WLAN unit 429 can operate in parallel in at least two communication modes, including infrastructure connection mode and direct connection mode. The frequency bands used in these communication modes may be limited by the hardware functions and performance.

[0038] (Access point configuration) Figure 5 is a block diagram showing the configuration of AP101, which has wireless LAN access point functionality. It consists of a main board 510 that controls AP101, a wireless LAN unit 516, a wired LAN unit 518, and operation buttons 520.

[0039] The microprocessor-type CPU 511 located on the main board 510 operates according to the control program stored in the ROM-type program memory 513, which is connected via the internal bus 512, and the contents of the RAM-type data memory 514. The CPU 511 performs wireless LAN communication with other communication terminal devices by controlling the wireless LAN unit 516 through the wireless LAN communication control unit 515. The CPU 511 also performs wired LAN communication with other communication terminal devices by controlling the wired LAN unit 518 through the wired LAN communication control unit 517. The CPU 511 can accept user input via the operation buttons 520 by controlling the operation control circuit 519. The CPU 511 includes at least one processor.

[0040] The AP101 also includes an interference wave detection unit 521 and a channel changing unit 522. The interference wave detection unit 521 performs interference wave detection processing when wireless communication is being performed in a band where DFS (Dynamic Frequency Selection) is implemented. The channel changing unit 522 performs channel changing processing when an interference wave is detected while wireless communication is being performed in a band where DFS is implemented, and when it is necessary to immediately switch to an available channel.

[0041] (Direct connection mode) Next, we will outline the direct connection mode in WLAN communication, which allows devices to communicate wirelessly directly with each other without going through an external access point. Communication using the direct connection mode can be implemented using multiple methods. For example, a communication device can support multiple modes as direct connection mode and selectively use one of these modes to perform communication using the direct connection mode (direct communication). For example, there are the following two modes as direct connection mode.

[0042] • Soft AP mode • Wi-Fi Direct (WFD) mode A communication device capable of direct communication may be configured to support at least one of these modes. On the other hand, a communication device capable of direct communication is not required to support all of these modes, but may be configured to support only some of them.

[0043] A communication device with WFD communication capabilities (for example, a mobile terminal device 103) receives user input via its control panel, thereby calling a (possibly dedicated) application to implement the communication function. The communication device then displays a UI (user interface) screen provided by the application to prompt user input, and based on the received user input, can perform communication in WFD mode (WFD communication).

[0044] ● Soft AP mode In soft AP mode, a communication device (e.g., mobile terminal device 103) acts as a client requesting various services. The other communication device (e.g., MFP100) acts as a soft AP capable of performing WLAN AP functions through software configuration. The soft AP is equivalent to a Wi-Fi master station, and the client is equivalent to a Wi-Fi slave station. In soft AP mode, the client searches for a device that will become a soft AP using a device discovery command. Once a soft AP is found, the remaining wireless connection processing (such as establishing a wireless connection) takes place between the client and the soft AP, followed by IP connection processing (such as assigning an IP address). The commands and parameters sent and received when establishing a wireless connection between the client and the soft AP can be those specified in the Wi-Fi standard, and are therefore omitted from this explanation. In addition, the MFP100 operating in soft AP mode determines the frequency band and frequency channel as the master station. Therefore, the MFP100 can, for example, select which frequency band to use, from 5GHz and 2.4GHz, and which frequency channel to use within that frequency band.

[0045] ●WFD mode The mode in which a direct connection is performed using WFD is called WFD mode. WFD is a standard developed by the Wi-Fi Alliance and is included in the IEEE 802.11 series of communication standards. In WFD mode, after the device to be communicated with is discovered using a device discovery command, the roles of group owner (GO) and client are determined, and then the remaining wireless connection processing is performed. The group owner corresponds to the Wi-Fi base station (access point), and the client corresponds to the Wi-Fi slave station (slave device). This role determination corresponds to, for example, GO Negotiation. In WFD mode before the role determination is performed, the MFP100 is neither a base station nor a slave station. Specifically, first, one device issues a device discovery command to the other device to search for a device to connect to in WFD mode. Once the other device to be communicated with is discovered, the two devices confirm information about the services and functions that can be supplied by each other. Note that this confirmation of device supply information is optional and not mandatory. This equipment supply information verification phase corresponds, for example, to P2P (Peer to Peer) Provision Discovery.

[0046] Next, by mutually confirming this equipment supply information, they determine which will be the client and which will be the group owner. Once the client and group owner are determined, they exchange parameters for communication using WFD. Based on the exchanged parameters, the client and group owner process the remaining wireless connection and IP connection. In WFD mode, the MFP100 may operate as GO without performing the GO Negotiation described above. In other words, the MFP100 may operate in WFD mode, which is Autonomous GO mode. The state in which the MFP100 is operating in WFD mode means, for example, a state in which the WFD connection has not been established but the MFP100 is operating as GO, or a state in which the WFD connection has been established and the MFP100 is operating as GO.

[0047] In this embodiment, when the MFP100 establishes and maintains a direct connection, it operates as a master station within the network to which it belongs. A master station is a device that constructs a wireless network and provides slave stations with parameters used to connect to the wireless network. Parameters used to connect to the wireless network include, for example, parameters related to the channel used by the master station. By receiving these parameters, the slave station connects to the wireless network constructed by the master station using the channel used by the master station. In direct connection mode, since the MFP100 operates as a master station, it is possible for the MFP100 to determine which frequency band and which channel to use for communication in direct connection mode. In this embodiment, for example, the MFP100 is capable of using channels corresponding to the 2.4 GHz frequency band and channels corresponding to the 5 GHz frequency band for communication in direct connection mode.

[0048] (Infrastructure connection mode) In infrastructure connection mode communication, the communication devices communicating with each other (for example, the mobile terminal device 103 and the MFP 100) connect to an external AP (for example, AP 101) that manages the network, and communication between the communication devices takes place via AP 101. In other words, communication between communication devices is performed via the network established by the external AP 101. The mobile terminal device 103 and the MFP 100 each search for AP 101 using a device discovery command. Once AP 101 is found, the remaining wireless connection processing (establishing the wireless connection, etc.) is carried out between each communication device and AP 101, followed by IP connection processing (assigning an IP address, etc.). The commands and parameters sent and received when establishing a wireless connection between each device and AP 101 can be those specified in the Wi-Fi standard, and are therefore omitted from this explanation.

[0049] In this embodiment, when the MFP100 operates with an infrastructure connection, the AP101 operates as the master station and the MFP100 operates as the slave station. That is, in this embodiment, the infrastructure connection refers to the connection between the MFP100 operating as a slave station and the device (AP101) operating as the master station. If the MFP100 has established an infrastructure connection and the mobile terminal device 103 has also established an infrastructure connection with the AP101, then communication between the MFP100 and the mobile terminal device 103 is possible via the AP101. The channel used for communication in the infrastructure connection is determined by the AP101, so the MFP100 performs communication in the infrastructure connection using the channel determined by the AP101. In this embodiment, the MFP100 is capable of using channels corresponding to the 2.4GHz frequency band and channels corresponding to the 5GHz frequency band for communication in the infrastructure connection. The MFP100 can also use channels corresponding to the DFS band within the 5GHz frequency band for communication in the infrastructure connection. Furthermore, in order to communicate with the MFP100 via the AP101, the mobile terminal device 103 recognizes and identifies that the MFP100 belongs to the network formed by the AP101 and to which the mobile terminal device 103 belongs.

[0050] (Connection configuration process for connecting to an external AP in infrastructure connection mode) The mobile terminal device 103 performs a connection setup process (configuration) to operate the MFP 100 in at least one of the infrastructure connection mode and direct connection mode, using direct communication with the MFP 100. In this embodiment, the connection setup process is performed by temporarily connecting the devices via direct communication, and this process is also called network setup. The connection setup process may also be performed when communication between the mobile terminal device 103 and the MFP 100 can be confirmed by wired communication or other means.

[0051] The MFP100 operates in connection setup mode (network setup mode) to perform connection configuration processing. Specifically, for example, the MFP100 performs the functions of a wireless LAN access point based on the vendor-specific SSID (Service Set Identifier), security, and password. Hereafter, the connection configuration processing will be referred to as network setup, and the connection configuration mode will be referred to as network setup mode.

[0052] (Regarding network setup mode) This section describes the network setup mode of the MFP100. The MFP100 can operate in network setup mode. The trigger for the MFP100 to start operating in network setup mode may be, for example, the user pressing the network setup mode button, or the MFP100 being started (powered on) for the first time after delivery. The network setup mode button may be a hardware (physical) button on the MFP100, or a software button displayed on the operation display unit 201 of the MFP100.

[0053] When the MFP100 starts operating in network setup mode, it enables Wi-Fi communication. Specifically, for example, as part of the Wi-Fi communication activation process, the MFP100 activates an internal AP (setup AP) dedicated to network setup mode. The SSID of the setup AP corresponds to the vendor-specific SSID mentioned above. This allows the MFP100 to establish a direct Wi-Fi connection with the mobile terminal device 103. The connection information (SSID and password) for connecting to the setup AP is assumed to be pre-stored in the application (setup app) installed on the mobile terminal device 103. In other words, the mobile terminal device 103 is assumed to be aware of the connection information for connecting to the setup AP in advance. Therefore, unlike the connection information for the AP activated in direct connection mode, the connection information for connecting to the setup AP cannot be arbitrarily changed by the user. Note that in network setup mode, the MFP100 may connect to the mobile terminal device 103 using Wi-Fi Direct (WFD) instead of normal Wi-Fi. In other words, the MFP100 may operate as a group owner and receive connection information from the mobile terminal device 103 via WFD communication. This connection information is, for example, connection information for the MFP100 to connect to an external AP (e.g., AP101). In network setup mode, the MFP100 may also connect to the mobile terminal device 103 via Bluetooth. Here, Bluetooth includes Bluetooth Classic and Bluetooth Low Energy (BLE). In other words, for example, the MFP100 may operate as a BLE slave device in network setup mode and receive connection information from the mobile terminal device 103 via BLE communication. In network setup mode, the MFP100 may also be capable of performing both Wi-Fi network setup and BLE network setup.In other words, when the MFP100 starts operating in network setup mode, it may enable both Wi-Fi communication and BLE communication. Specifically, when the MFP100 starts operating in network setup mode, it may enable the setup AP and enable the advertising state, which is a state in which advertising information can be sent via BLE to enable BLE connection. In addition, the MFP100 may receive connection information from the mobile terminal device 103 via wired LAN or USB.

[0054] As described above, the MFP100 operates in network setup mode to perform network setup of the MFP100 in response to predetermined conditions, including when a user presses a button or during initial setup. When the wireless LAN communication unit 207 operates in network setup mode, it operates as a setup AP that is only valid while operating in network setup mode. This setup AP is a different access point from the access point that is enabled in the soft AP mode described above. The SSID of this setup AP shall contain a predetermined string that can be recognized by the setup application of the mobile terminal device 103.

[0055] Furthermore, when the MFP100 is operating in network setup mode, it shall use a predetermined communication protocol (setup communication protocol) when communicating with the mobile terminal device 103 connected to the setup AP. Specifically, the setup communication protocol is, for example, SNMP (Simple Network Management Protocol).

[0056] After starting operation in network setup mode, the MFP100 will stop operating in network setup mode and disable the setup AP after a predetermined time has elapsed. Furthermore, if the MFP100 receives connection information for connecting to an external AP and instructions to change the wireless communication operating mode from the mobile terminal device 103 while in network setup mode, it will also disable the setup AP. Hereinafter, instructions transmitted from the mobile terminal device 103, including the above connection information and change instructions, will be referred to as "connection setting instructions."

[0057] The mobile terminal device 103 performs network setup when the CPU 412 reads and executes a predetermined computer program stored in the ROM 413. The predetermined program is an application program that includes a function to perform network setup, as well as a printing function to print image data, document data, etc., from the mobile terminal device 103 to the MFP 100, and is the setup app described above. The setup app may also include functions other than the function to perform network setup and the printing function. For example, the setup app may include a scanning function to scan a document set in the MFP 100, a function to perform other settings on the MFP 100, a function to check the status of the MFP 100, etc. The setup app of the mobile terminal device 103 establishes a connection as a client to the SSID on which the MFP 100 is running in network setup mode.

[0058] Figure 6 is a block diagram conceptually illustrating the software configuration for the MFP100, which enables configuration changes for various network functions and security policy settings. The software elements and configurations shown in Figure 6 are merely examples and do not limit the elements and configurations. The software group schematically shown in Figure 6 consists of the control program stored in ROM213 and a portion of the data stored in the associated RAM214. This software group mainly consists of a communication program unit 600 that performs communication control, an application program unit 610 that mainly controls application functions, and a device control program unit 620 that mainly performs low-level control in the MFP100.

[0059] The communication program unit 600 includes a network communication control module 601, a security module 602, a USB communication control module 603, a web server module 604, and a static content database 605.

[0060] The network communication control module 601 controls the wireless LAN communication control unit 219 and is responsible for the transport layer of the communication protocol stack, enabling TCP / IP communication for the MFP100. Furthermore, the network communication control module 601 also handles the overall network function processing, acquiring the network setting status via the network setting application 613 in conjunction with the MFP100's power ON or power OFF, and starting or stopping each network function accordingly.

[0061] The security module 602 is responsible for encrypting and decrypting communications, as well as related authentication and hashing processes, enabling TLS (Transport Layer Security) / SSL (Secure Sockets Layer) communication for the MFP100. The USB communication control module 603 controls the USB communication control unit 218 and is responsible for the operation required for the MFP100 to behave as a USB device, enabling USB communication for the MFP100.

[0062] The Web server module 604 is responsible for the operations necessary for the MFP 100 to function as a Web server, and it enables HTTP (Hypertext Transfer Protocol) communication with an external mobile terminal device 103 running a Web browser. Specifically, for example, it analyzes HTTP requests received from the external mobile terminal device 103, operates the WebUI control module 611 and the static content database 605 according to the analysis results, and formats the generated data as an HTTP response before sending it. The Web server module 604 performs request reception and response transmission using TCP / IP communication, TLS / SSL communication, or USB communication.

[0063] The static content database 605 is a module that operates as a file system and reads JPEG data, HTML data, and other content stored in ROM213 or RAM214. Note that the content database is not limited to static content; it may also contain dynamically generated content.

[0064] The application program unit 610 includes a WebUI control module 611, a device UI control module 612, application modules for network setting applications 613 to setting reset applications 615, and a network setting database 616.

[0065] The WebUI control module 611 generates data to display the MFP100's WebUI on the Web browser of an external mobile terminal device 103, in accordance with a request from the Web server module 604. The WebUI control module 611 obtains the operating status and configuration status of the MFP100 from each application module and responds with the formatted data to the mobile terminal device 103, thereby displaying the operating status and configuration status of the MFP100 on the WebUI. Furthermore, the WebUI displayed in the Web browser of the mobile terminal device 103 is configured to allow the user to instruct the MFP100 to change its settings or perform password authentication. When a user operates the Web browser and instructs the MFP100 to change its settings or perform password authentication from the WebUI, the MFP100 receives an HTTP request containing the details of that instruction. The WebUI control module 611 receives the instruction via the Web server module 604 and, according to the content of the instruction, instructs the corresponding application module to perform the processing such as changing settings or performing password authentication. Once processing is complete, the WebUI control module 611 stores the processing result, such as success or failure, in the HTTP response and sends it to the mobile terminal device 103.

[0066] The device UI control module 612 controls the operation display control unit 221 to display the UI of the MFP100 main unit. The device UI control module 612 stores menu hierarchy information and controls the operation display unit 201 to display operation menus etc. according to the current menu hierarchy. The device UI control module 612 also acquires and formats the operating status and setting status of the MFP100 from each application module and controls the operation display unit 201 to display it. Furthermore, the device UI control module 612 receives operation information such as setting changes and password authentication from the operation display control unit 221 and causes the corresponding application module to perform processing according to the operation information. Once processing is complete, the device UI control module 612 controls the operation display unit 201 to display the processing result, such as success or failure.

[0067] The network configuration application 613 receives instructions from the network communication control module 601, the WebUI control module 611, and the device UI control module 612, and performs actions such as obtaining the network configuration status and changing the network configuration.

[0068] The security policy setting application 614 receives instructions from the WebUI control module 611 and the device UI control module 612, and performs actions such as obtaining the security policy setting status and changing the security policy settings.

[0069] The setting reset application 615 receives instructions from the WebUI control module 611 and the device UI control module 612 and performs the process of resetting the settings of the MFP100.

[0070] The network configuration database 616 has a synchronization restriction flag 617, and when the MFP 100 is powered on, it stores a copy of each network configuration stored in NVRAM 215 in RAM 214. The network configuration database 616 then receives instructions from the network configuration application 613 and the security policy configuration application 614 and performs referencing and modification processing for each network configuration. When modifying each network configuration, the network configuration database 616 switches whether or not to save the network configuration to NVRAM 215 via the configuration value saving module 622, based on the state of the synchronization restriction flag 617 and the configuration change. The synchronization restriction flag 617 has two states: ON and OFF. When the synchronization restriction flag 617 is ON, it indicates that synchronization is restricted between the copy of the network configuration held by the network configuration database 616 in RAM 214 and the network configuration held by the configuration value saving module 622 in NVRAM 215. Furthermore, the synchronization restriction flag 617 being OFF indicates that synchronization is not restricted between the copy of the network settings held in RAM 214 by the network settings database 616 and the network settings held in NVRAM 215 by the setting value storage module 622.

[0071] The device control program unit 620 includes a system control module 621 and a setting value storage module 622.

[0072] The system control module 621 is responsible for coordinating the entire software system, including the startup and shutdown of the MFP100. For example, the system control module 621 receives a restart request from the security policy setting application 614 and performs the restart process for the MFP100. The restart process for the MFP100 is a process in which the MFP100 performs a power-off process while in the startup state, followed by a power-on process. The system control module 621 also performs the power-on and power-off processes for the MFP100 when the user presses the power button. During the power-on and power-off processes, the system control module 621 notifies the main software modules of the MFP100, such as the network communication control module 601, of the power-on or power-off command and waits for the processing result (not shown).

[0073] The setting value storage module 622 operates to manage the saving of setting values ​​for the MFP100. The setting value storage module 622 receives instructions to save setting values ​​from other modules, such as application modules, and writes the setting values ​​to the NVRAM 215. The setting value storage module 622 also receives instructions to retrieve setting values ​​from other modules, such as application modules, and reads the setting values ​​from the NVRAM 215.

[0074] Next, the process from powering on the MFP100 to performing network setup will be explained using the flowcharts in Figures 7 and 8. The process shown in Figure 7 is achieved, for example, by the MFP100's CPU 211 reading and executing a computer program stored in ROM 213. The process in Figure 7 starts based on the fact that the MFP100 has been powered on.

[0075] In S701, the CPU211 determines whether the MFP100 retains the settings for an external access point (external AP). Specifically, for example, it refers to the wireless configuration information stored inside the MFP100 to determine whether the connection information (SSID, etc.) to the external AP to which the MFP100 was connected is retained. If it is determined that the external AP settings are retained, the process proceeds to S707. In S707, the CPU211 attempts to connect to the external AP, and then proceeds to S708. On the other hand, if it is determined that the external AP settings are not retained, the process proceeds to S702.

[0076] In S702, CPU211 determines whether the conditions for automatically starting network setup to connect to an external AP are met. In other words, S702's determination determines whether the conditions for starting in network setup mode are met. Here, if even one of the multiple conditions for starting in network setup mode is not met, it is determined that the conditions for starting in network setup mode are not met.

[0077] In the S702, specifically, whether or not network settings such as LAN have already been configured is one of the above multiple conditions. If network settings such as LAN have already been configured, it is determined that the condition for automatically starting network setup to connect to an external AP is not met. Also, for example, whether or not WFD is set to always be running is one of the above multiple conditions. If WFD is set to always be running, it is determined that the condition for automatically starting network setup to connect to an external AP is not met. Also, for example, whether or not the protocols etc. necessary to perform network setup are operational is one of the above multiple conditions. If the protocols etc. necessary to perform network setup are not operational, it is determined that the condition for automatically starting network setup to connect to an external AP is not met.

[0078] This section describes the state in which the protocols and other necessary components for performing network setup are operational. For example, during network setup, SNMP is used as the setup communication protocol so that the MFP100 can obtain connection information from the mobile terminal device 103. In this embodiment, the MFP100 can accept operations from the user to enable or disable the use of SNMP. In this embodiment, the above operations can be accepted on both the settings screen for network settings and the settings screen for security policy settings. However, if the above operations are accepted on the settings screen for security policy settings, the above operations cannot be accepted on the settings screen for network settings, and the SNMP-related settings cannot be changed. That is, if the above operations are not accepted on the settings screen for security policy settings, they can be accepted on the settings screen for network settings. Furthermore, any user can change settings on the settings screen for network settings, but only administrator users (security administrators) can change settings on the settings screen for security policy settings. The above operations may also be accepted on the settings screen for changing the settings of the MFP100, which is displayed on the mobile terminal device 103 to which the MFP100 is connected. In this case, an instruction corresponding to the operation is sent to the MFP100 from the settings screen, and the MFP100, upon receiving the instruction, either enables or disables the use of SNMP based on that instruction. When SNMP is enabled, the MFP100 can use SNMP in the communications it performs. When SNMP is disabled, the MFP100 cannot use SNMP in any communications it performs. In the following explanation, the states where SNMP is enabled and where SNMP is disabled may be simply referred to as "SNMP enabled" and "SNMP disabled," respectively.Furthermore, if SNMP is disabled in the MFP100, it cannot perform network setup, which is a process that uses SNMP. In other words, it cannot complete network setup. That is, if SNMP is disabled in the network settings or security settings, the protocols necessary to perform network setup are not operational. Conversely, if SNMP is not disabled in the network settings or security policy settings, for example, if it is enabled, the protocols necessary to perform network setup are operational. In this embodiment, the condition related to SNMP among the above multiple conditions is that SNMP is enabled. Therefore, S702 determines whether SNMP is enabled or not, and if SNMP is enabled, it is considered that the condition related to SNMP is met.

[0079] Furthermore, for example, when Wi-Fi communication is enabled when the MFP100 is started in network setup mode, the HTTP Server function is used. In this embodiment, the MFP100 can receive operations from the user to enable or disable the use of the HTTP Server function. In this embodiment, the above operations can be received on both the settings screen for network settings and the settings screen for security policy settings. However, if the above operations are received on the settings screen for security policy settings, the above operations cannot be received on the settings screen for network settings, and the settings related to the HTTP Server function cannot be changed. That is, if the above operations are not received on the settings screen for security policy settings, they can be received on the settings screen for network settings. The above operations may also be received on the settings screen for changing the settings of the MFP100, which is displayed on the mobile terminal device 103 to which the MFP100 is connected. In this case, an instruction corresponding to the operation is sent to the MFP100 from the settings screen, and the MFP100, upon receiving the instruction, enables or disables the use of the HTTP Server function based on the instruction. When the HTTP Server function is enabled, the MFP100 can use the HTTP Server function in the communications it performs. When the HTTP Server function is disabled, the MFP100 cannot use the HTTP Server function in any communications it performs. In the following explanation, the states where the HTTP Server function is enabled and disabled may be simply referred to as "the state where the HTTP Server function is enabled" and "the state where the HTTP Server function is disabled."Furthermore, if the HTTP Server function is disabled, the MFP100 cannot perform network setup, which is a process that uses the HTTP Server function. In other words, it cannot complete network setup. That is, if the HTTP Server function is disabled by network settings or security policy settings, the protocols necessary to perform network setup are not operational. Conversely, if the HTTP Server function is not disabled by network settings or security policy settings, for example, if it is enabled, the protocols necessary to perform network setup are operational. In this embodiment, the condition related to the HTTP Server function among the above multiple conditions is that the HTTP Server function is enabled. Therefore, S702 determines whether the HTTP Server function is enabled or not, and if the HTTP Server function is enabled, it is considered that the condition related to the HTTP Server function is met.

[0080] The multiple conditions may include conditions other than those related to SNMP and HTTP Server functionality mentioned above. For example, the MFP100 may accept operations to enable or disable the wireless LAN communication function in the network settings screen and the security policy settings screen. When the wireless LAN communication function is enabled, the MFP100 will be able to use the wireless LAN communication function. When the wireless LAN communication function is disabled, the MFP100 will not be able to use the wireless LAN communication function. Furthermore, the multiple conditions may include a condition related to the wireless LAN communication function, such as the condition that the wireless LAN communication function is enabled.

[0081] If S702 determines that all of the above conditions are met, the process proceeds to S703. In S703, the CPU211 starts the MFP100 in network setup mode. Specifically, for example, it controls the MFP100 to transmit a beacon signal containing a predetermined SSID. In S703, the process shown in Figure 8, described later, is executed. On the other hand, if S702 determines that any of the above conditions are not met, the process proceeds to S704.

[0082] In S704, the CPU 211 determines whether the one of the above multiple conditions that was not met is a specific condition. In this embodiment, the specific condition is that SNMP is disabled. Therefore, if SNMP is disabled, the CPU 211 determines YES in this determination and proceeds to S705. If SNMP is not disabled but the condition is not met in S702, the process proceeds to S708. One example of a case where the process proceeds to S708 is when the HTTP Server function is disabled. Furthermore, if multiple of the above multiple conditions are not met, the process proceeds to S708 even if the specific condition is included among the unmet conditions.

[0083] In S705, CPU211 determines whether or not it is possible to change SNMP settings. Specifically, for example, if SNMP is disabled through operations on the security policy settings screen, only security administrators can change SNMP settings. In other words, it is not possible to change SNMP settings without authentication verification of being a security administrator. Therefore, if SNMP is disabled through operations on the security policy settings screen, it is determined that it is not possible to change SNMP settings.

[0084] On the other hand, if SNMP is disabled through operations on the network settings screen, any user can change the setting regardless of their user privileges. Therefore, if SNMP is disabled through operations on the network settings screen, it is determined that it is possible to change the SNMP settings.

[0085] If it is determined in S705 that it is possible to change the SNMP settings, the process proceeds to S706. In S706, the CPU 211 temporarily removes the functional restriction on the setting. Specifically, for example, if SNMP is disabled, it is temporarily enabled. Here, "temporarily" is used because the function will be restricted again in a later process. This process will be described later. Specifically in this embodiment, the CPU 211 temporarily enables SNMP until it is disabled based on the reception of AP connection information sent from the mobile terminal device 103. After S705, in S703, the CPU 211 starts the MFP 100 in network setup mode. On the other hand, if it is determined in S705 that it is not possible to change the SNMP settings, the process proceeds to S708. In S706, the SNMP settings may be changed permanently, rather than temporarily, until a new operation on the network settings screen or the security policy settings screen is accepted.

[0086] In this embodiment, if it is determined that the conditions for starting in network setup mode are not met, the system controls the process to switch depending on whether the setting that caused the determination can be changed. For example, if the reason is that the protocols necessary for performing network setup are not in an operational state, and the setting can be temporarily changed, the setting is changed so that the protocols can operate (function restriction is removed), and the MFP100 is started in network setup mode. Alternatively, if the reason is that the protocols necessary for performing network setup are not in an operational state, and the setting cannot be temporarily changed, the system proceeds to S708 without starting the MFP100 in network setup mode.

[0087] It is also possible to omit the execution of process S705. Specifically, for example, the specific condition referenced in the determination of S704 may be that SNMP is disabled by an operation on the network settings screen. In this configuration, if SNMP is disabled by an operation on the network settings screen, CPU211 proceeds to S706 without executing S705. If SNMP is not disabled by an operation on the network settings screen, but S702 determines that the condition is not met, it proceeds to S708. Cases in which it proceeds to S708 include, for example, cases where SNMP is disabled by an operation on the security policy settings screen, cases where the HTTP Server function is disabled by an operation on the network settings screen, and cases where the HTTP Server function is disabled by an operation on the security policy settings screen. Furthermore, if multiple of the above conditions are not met, even if the specific condition is included among the unmet conditions, it proceeds to S708.

[0088] In the S708, the CPU 211 displays the home screen on the operation display unit 201. The home screen is a screen that accepts user selections for various menus that can be executed on the MFP100, such as printing and scanning, and is, for example, the screen shown in Figure 3(a).

[0089] In step S709, the CPU 211 determines whether or not a user selection for a menu item has been received on the home screen. If it is determined that a user selection for a menu item has been received, the process proceeds to step S710. The process in step S709 is repeated until it is determined that a user selection for a menu item has been received.

[0090] In S710, the CPU211 determines whether or not the user has selected to power off the MFP100. If it is determined that the user has selected to power off, the process shown in Figure 7 is terminated. On the other hand, if it is determined that the user has not selected to power off, the process proceeds to S711.

[0091] In S711, the CPU 211 determines whether the menu for manually starting network setup mode has been selected. If it is determined that the menu for manually starting network setup mode has been selected, the process proceeds to S712. On the other hand, if it is determined that the menu for manually starting network setup mode has not been selected, the process shown in Figure 7 is terminated, and then the CPU 211 executes the process corresponding to the selected menu.

[0092] In S712, CPU211 determines whether the conditions for starting network setup to connect to an external AP are met. In other words, the determination in S712 is whether the conditions for starting in network setup mode are met. Here, if even one of the multiple conditions for starting in network setup mode is not met, it is determined that the conditions for starting in network setup mode are not met. This determination is the same as in S702.

[0093] In S712, specifically, whether or not network-based printing or scanning is currently being performed is one of the multiple conditions mentioned above. If network-based printing or scanning is currently being performed, it is determined that the conditions for starting network setup to connect to an external AP are not met. Also, for example, whether or not the protocols necessary for performing network setup are operational is one of the multiple conditions mentioned above. If the protocols necessary for performing network setup are not operational, it is determined that the conditions for starting network setup to connect to an external AP are not met.

[0094] If the conditions are met in S712, the CPU 211 starts the MFP 100 in network setup mode in S713. Specifically, for example, the CPU 211 controls the device to transmit a beacon signal containing a predetermined SSID. In S713, the process shown in Figure 8, described later, is executed. On the other hand, if the conditions are not met in S712, the process proceeds to S714.

[0095] In S714, the CPU 211 determines whether the one of the above multiple conditions that was not met is a specific condition. This process is the same as in S704. If the result of this determination is YES, proceed to S715; if the result of this determination is NO, proceed to S716.

[0096] In S715, CPU211 determines whether it is possible to change the SNMP settings. This process is the same as in S705. If the result is YES, proceed to S717; if the result is NO, proceed to S716.

[0097] In S716, the CPU211 displays a message screen on the MFP100's operation display unit 201 indicating the reason why network setup mode cannot be started. At this time, the CPU211 displays a message based on the condition that was not met among the above multiple conditions. Specifically, for example, if the condition that was not met was related to SNMP, a message indicating that SNMP is disabled or a message prompting the user to enable SNMP will be displayed. Also, for example, if the condition that was not met was related to the HTTP Server function, a message indicating that the use of the HTTP Server function is disabled or a message prompting the user to enable the use of the HTTP Server function will be displayed. Furthermore, the message displayed on the message screen may be based on whether the setting corresponding to the unmet condition was made by an operation on the network settings screen or by an operation on the security policy settings screen. After that, the process from S708 is repeated.

[0098] Figure 9(a) shows an example of a message screen displayed in S716. Figure 9(a) is a screen displayed based on the fact that SNMP is disabled by an operation on the settings screen for security policy settings. As shown in Figure 9(a), for example, a message is displayed indicating that SNMP is disabled in the security policy settings. Other reasons for the display of the message screen in Figure 9(a) include, for example, that WFD is set to always be running. Such a screen is displayed, for example, when proceeding from S714 to S716. On the message screen in Figure 9(a), the OK button 901 is displayed as selectable, and when the user selects it, the process proceeds to S708.

[0099] In S717, the CPU211 displays a confirmation screen on the MFP100's operation display unit201 to ask whether or not to change the SNMP settings. This screen includes, for example, a message indicating why network setup mode cannot be started. The process then proceeds to S718.

[0100] Figure 9(b) shows an example of a confirmation screen displayed in S717. As shown in Figure 9(b), for example, a message is displayed indicating that SNMP is disabled in the network settings. Other reasons for the screen shown in Figure 9(b) include, for example, that the HTTP Server function is disabled in the network settings. On the confirmation screen in Figure 9(b), buttons 902 and 903 are displayed as selectable buttons. Button 902 is a button that accepts an instruction to change the setting, and button 903 is a button that accepts an instruction not to change the setting. Once either button is selected, the process proceeds to S718.

[0101] In S718, CPU211 determines whether or not to change the SNMP settings. Specifically, for example, if button 902 in Figure 9(b) is selected, it is determined that the SNMP settings will be changed; if button 903 in Figure 9(b) is selected, it is determined that the SNMP settings will not be changed. If it is determined that the SNMP settings will not be changed, the process from S708 is repeated. On the other hand, if it is determined that the SNMP settings will be changed, the process proceeds to S719.

[0102] In S719, CPU211 removes the functional restrictions on the setting. Specifically, for example, if SNMP is disabled, it is enabled. In this process, the SNMP setting is changed permanently, not temporarily as in the S706 process, until a new operation on the network settings screen or the security policy settings screen is accepted. After that, the process proceeds to S713, and CPU211 starts the MFP100 in network setup mode.

[0103] In steps S703 and S713, the process shown in Figure 8 is executed. Before explaining the process in Figure 8, we will describe the network setup process performed between the mobile terminal device 103 and the MFP 100.

[0104] Figure 10 is a sequence diagram showing the network setup process performed by the mobile terminal device 103 and the MFP 100. The process of the mobile terminal device 103 shown in Figure 10 is achieved, for example, by the CPU 412 reading a program stored in ROM 413 into RAM 414 and executing it. Similarly, the process of the MFP 100 shown in Figure 10 is achieved, for example, by the CPU 211 reading a program stored in ROM 213 into RAM 214 and executing it. In addition, a setup communication protocol, such as SNMP, is used for communication between the MFP 100 and the mobile terminal device 103 via a Wi-Fi connection when the MFP 100 is operating in network setup mode.

[0105] In S1000, the mobile terminal device 103 requests a list of access points from the MFP 100 via a Wi-Fi connection between the MFP 100, which is operating in network setup mode, and the mobile terminal device 103, using a setup application.

[0106] Next, in S1001, the MFP100 transmits a list of access points to the mobile terminal device 103 via a Wi-Fi connection between the MFP100, which is operating in network setup mode, and the mobile terminal device 103. The list transmitted here is a list of one or more access points that the MFP100 can connect to, which were discovered by the MFP100 performing an AP search.

[0107] Next, in S1002, the mobile terminal device 103 transmits connection information for one of the access points included in the received list to the MFP 100 via the Wi-Fi connection between the MFP 100, which is operating in network setup mode, and the mobile terminal device 103. This process is realized by the setup application controlling the mobile terminal device 103 to transmit connection information for one of the access points included in the received list. Specifically in this process, if the received list includes a connected AP, the mobile terminal device 103 transmits the connection information for the connected AP. In this embodiment, since the list only includes access points that the MFP 100 can connect to, if the received list includes a connected AP, it means that the MFP 100 can connect to the connected AP. If the received list does not include a connected AP, the mobile terminal device 103 displays the received list and accepts the user's selection of an access point from the list. The mobile terminal device 103 then transmits the connection information for the selected access point. In this embodiment, the list only includes access points that the MFP100 can connect to. Therefore, if a connected AP is not included in the received list, it means that the MFP100 cannot connect to the connected AP. Furthermore, access points that can be connected using encryption methods not supported by the MFP100 are not included in the list because the MFP100 cannot connect to them. Similarly, access points that can be connected using frequency bands not supported by the MFP100 are not included in the list because the MFP100 cannot connect to them. Before the connection information is transmitted, the mobile terminal device 103 accepts the user's input of a password for connecting to the access point on a screen displayed by the setup application. The received password is then included in the connection information, and the connection information is transmitted.

[0108] In S1003, the MFP100 notifies the mobile terminal device 103 that it has received connection information via the Wi-Fi connection between the MFP100, which is operating in network setup mode, and the mobile terminal device 103.

[0109] In S1004, the MFP100 exits network setup mode and switches to infrastructure mode. The MFP100 then attempts to connect to the access point corresponding to the connection information obtained in S1002. If the connection is successful, the MFP100 can then communicate via the network formed by the connected access point.

[0110] In S1005, the mobile terminal device 103 uses the connection information stored by the setup application to reconnect with the access point to which it was connected when the network setup operation was performed. However, it is not limited to this configuration. For example, if the mobile terminal device 103 has sent connection information for a different access point to the MFP 100 than the access point to which it was connected via Wi-Fi when the network setup operation was performed, it may connect to that other access point.

[0111] In S1006, the mobile terminal device 103 searches for the MFP 100 on its network using a setup application. If the MFP 100 is found, the mobile terminal device 103 requests capability information from the MFP 100, and the MFP 100 sends the capability information to the mobile terminal device 103. This registers the MFP 100's information in the setup application, enabling communication with the MFP 100 via the setup application. Specifically, for example, the setup application can send print jobs to the MFP 100. At this time, if the mobile terminal device 103 belongs to the network formed by the access point to which the MFP 100 is connected via network setup, communication with the MFP 100 can be performed via that access point. If the access point to which the MFP 100 is connected is not the same access point to which the mobile terminal device 103 is connected, or if communication between the mobile terminal device 103 and the MFP 100 is not possible, the request and acquisition of capability information are omitted. Note that the communication in S1006 is performed using a different communication protocol than the setup communication protocol (specifically, CHMP, for example). After that, the process shown in the sequence diagram in Figure 10 is completed.

[0112] Figure 11 is a flowchart of the network setup performed by the MFP100. The process in Figure 11 is achieved, for example, by the CPU 211 of the MFP100 reading a program stored in ROM 213 into RAM 214 and executing it. The process in Figure 11 is initiated in processes S703 and S713 in Figure 7.

[0113] In S1101, the CPU 211 uses the wireless LAN communication unit 207 to search for nearby beacons and creates an SSID list. The SSID list is a list of one or more access points that the MFP100 can connect to, which are discovered when the MFP100 performs an AP search.

[0114] In S1102, the CPU 211 starts network setup mode and prepares for a direct connection via wireless connection with the mobile terminal device 103. Preparing for a direct connection involves operating the wireless LAN communication unit 207 in network setup mode, transmitting a beacon, and waiting for a connection from the mobile terminal device 103. At this point, the MFP 100 operates in network setup mode.

[0115] When the mobile terminal device 103 connects to the wireless LAN communication unit 207 of the MFP 100, which is operating in network setup mode, and a direct connection is established via wireless connection, the process proceeds to S1103.

[0116] In S1103, the CPU 211 confirms the information acquisition request from the mobile terminal device 103. In S1104, the CPU 211 determines whether the mobile terminal device 103 has requested an SSID list from the MFP 100 as part of the information acquisition request. The SSID list request here refers to the request for an SSID list made from the mobile terminal device 103 to the MFP 100, and corresponds to the access point list request in S1000 in Figure 10. If it is determined that there is an SSID list request, the process proceeds to S1106; if it is determined that there is no SSID list request, the process proceeds to S1105. In S1106, the CPU 211 sends the SSID list to the requesting mobile terminal device 103. After that, the process from S1103 is repeated.

[0117] In S1105, the CPU 211 checks for instructions from the mobile terminal device 103. In S1107, the CPU 211 determines whether there is a connection setting instruction from the mobile terminal device 103 to the MFP 100. A connection setting instruction here is an instruction from the mobile terminal device 103 to the MFP 100 to send information for connecting to the AP 101, and corresponds to the transmission of access point connection information in S1002 in Figure 10. If it is determined that there is a connection setting instruction, the process proceeds to S1108; if it is determined that there is no connection setting instruction, the process from S1103 is repeated.

[0118] In S1108, the CPU 211 exits network setup mode and transitions to infrastructure connection mode. Specifically, the CPU 211 connects the wireless LAN communication unit 207 to the SSID of AP 101 as instructed by the mobile terminal device 103, establishing a wireless connection in infrastructure connection mode. From this point onward, the MFP 100 can communicate via the network formed by the connected AP 101. After S1108, the process shown in Figure 11 is terminated.

[0119] As explained in Figures 10 and 11, during the network setup process, the MFP100 exits network setup mode. In this embodiment, when the MFP100 exits network setup mode, the process shown in Figure 8 is executed to revert the temporarily changed settings in S706 back to their original settings. This allows the settings to be maintained in the state before the network setup was performed.

[0120] Figure 8 is a flowchart showing the processes that are executed after network setup is performed in S703 or S713. The processes shown in Figure 8 are achieved, for example, by the CPU 211 of the MFP100 reading and executing a computer program stored in ROM 213.

[0121] In S801, CPU211 starts the MFP100 in network setup mode. This process corresponds to the process in S1102 in Figure 11.

[0122] In S802, connection information for the AP transmitted from the mobile terminal device 103 is received. The processing in S802 corresponds to the case where Yes is determined in S1002 in Figure 10 and S1107 in Figure 11.

[0123] In S803, the CPU 211 determines whether the function restrictions were temporarily removed in S706 before starting the network setup mode. Here, even if the function restrictions in the settings are removed in S719, this removal is not considered to be a temporary removal. This is because proceeding to S719 means that the network setup mode has been manually started, and furthermore, user confirmation is performed by displaying the option of whether or not to change the settings in S717. In other words, in this embodiment, the removal of function restrictions based on the user's will is not considered a temporary removal of function restrictions in S803.

[0124] If S803 determines that the function restriction was temporarily removed in S706, then in S804, CPU211 sets the function restriction again and proceeds to S805. On the other hand, if S803 determines that the function restriction was not temporarily removed, then the process proceeds from S803 to S805.

[0125] In S805, CPU211 exits network setup mode. The process in S805 corresponds to S1004 in Figure 10 and S1108 in Figure 11.

[0126] As described above, according to this embodiment, when the MFP100 is started in network setup mode, if the protocols and functions necessary for network setup are disabled, it is determined whether it is possible to temporarily enable them based on whether or not they are settings made by security policy settings. If it is possible to temporarily enable them, they are enabled and network setup is started. Furthermore, when the network setup mode is terminated, the settings are disabled again to maintain the network settings before the change. In addition, according to this embodiment, if the MFP100 cannot be started in network setup mode, the reason for this failure can be notified to the user.

[0127] The present invention is applicable to personal computers, PDAs, tablet terminals, mobile phone terminals such as smartphones, music players, game consoles, e-book readers, smartwatches, and various measuring devices (sensor devices) such as thermometers and hygrometers. Furthermore, the present invention is applicable to digital cameras (including still cameras, video cameras, network cameras, and security cameras), printers, scanners, and drones. It is also applicable to video output devices, audio output devices (e.g., smart speakers), media streaming players, and wireless LAN adapters with USB or LAN cable connections. Video output devices include, for example, devices that acquire (download) videos from the internet identified by a URL instructed by an electronic device and output them to a display device connected via a video output terminal such as HDMI®, thereby enabling streaming playback on the display device or mirroring display (displaying content displayed on an electronic device on a display device). Video output devices also include media players such as televisions, hard disk recorders, Blu-ray recorders, and DVD recorders, head-mounted displays, projectors, televisions, display devices (monitors), and signage devices. Furthermore, the present invention can also be applied to Wi-Fi-connected devices known as smart home appliances, such as air conditioners, refrigerators, washing machines, vacuum cleaners, ovens, microwave ovens, lighting fixtures, heating appliances, and cooling appliances.

[0128] The present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions.

[0129] This embodiment includes a communication device, a control method, and a program. (Item 1) A communication device, Connection setting means for performing connection setting processing to connect the communication device to an external access point, A setting means for setting the functions of the communication device to be restricted, If the functions necessary to perform the connection setting process are restricted by the setting means, the first control means controls the connection setting process not to start and to display information indicating that the functions are restricted. A communication device characterized by having the following features. (Item 2) The communication device according to item 1, characterized in that the setting means includes a first setting means capable of setting restrictions on the functions of the communication device by accepting operations from a user with specific privileges, and a second setting means capable of setting restrictions on the functions of the communication device regardless of the user's privileges. (Item 3) The communication device according to item 2, characterized in that, if the first setting means sets a restriction on the function of the communication device, the first control means controls to display a first screen that includes a message indicating that the function is restricted. (Item 4) The communication device according to item 3, characterized in that the first screen is a screen that does not accept a selection of whether or not to release the restriction on the functions of the communication device set by the first setting means. (Item 5) The communication device according to item 3 or 4, characterized in that, if the second setting means sets a restriction on the function of the communication device, the first control means controls to display a second screen that includes a message indicating that the function is restricted. (Item 6) The communication device according to item 5, characterized in that the second screen is a screen capable of accepting a selection of whether or not to release the restriction on the functions of the communication device set by the second setting means. (Item 7) The communication device according to item 6, characterized in that, when a selection to remove the restriction on the functions of the communication device is received on the second screen, the first control means removes the restriction on the functions of the communication device set by the second setting means and controls the connection setting means to start the connection setting process. (Item 8) The system further includes a first determination means for determining whether or not the connection setup process can be executed when an instruction to execute the connection setup process is received by a user, The control by the first control means is performed when the first determination means determines that it is not possible to perform the connection setting process. A communication device as described in item 6 or 7, characterized by the features described herein. (Item 9) The communication device according to item 8, characterized in that, if the first determination means determines that the connection setting process can be executed, the first control means controls the connection setting means to start the connection setting process. (Item 10) The communication device according to item 8 or 9, characterized in that, after the first screen is displayed, or after the user selects not to release the restrictions on the functions of the communication device on the second screen, if the user receives an instruction to execute the connection setting process, the determination by the first determination means is repeatedly performed. (Item 11) When the communication device is started, a second determination means determines whether or not the connection setting process can be executed, If the second determination means determines that the connection setting process cannot be executed, or if the functions necessary to execute the connection setting process are restricted by the first setting means, the second control means controls the connection setting process not to start. A communication device according to any one of items 8 to 10, further comprising: (Item 12) The communication device according to item 11, characterized in that the control by the first control means is performed after the home screen of the communication device is displayed, and the control by the second control means is performed before the home screen is displayed. (Item 13) The communication device according to item 12, characterized in that, if the second determination means determines that the connection setting process can be executed, the second control means controls the connection setting means to start the connection setting process. (Item 14) The communication device according to item 12 or 13, characterized in that, if the second determination means determines that the connection setting process cannot be executed, and the second setting means sets a restriction on the function of the communication device, the second control means releases the restriction on the function of the communication device set by the second setting means and controls the connection setting means to start the connection setting process. (Item 15) The connection setting process includes a process to terminate the operation of the communication device in a predetermined mode, The communication device according to item 14, characterized in that the second control means controls the process to restrict the function again when the restriction on the function of the communication device set by the second setting means is released. (Item 16) The communication device according to any one of items 12 to 15, characterized in that, if the second determination means determines that the connection setting process cannot be executed, and the first setting means sets a restriction on the function of the communication device, the second control means controls the device to display the home screen without starting the connection setting process. (Item 17) The connection setup process is initiated when the communication device operates in a predetermined mode. The first control means and the second control means control the communication device so as not to start the connection setting process by not setting it to the predetermined mode. A communication device according to any one of items 11 to 16, characterized in that it is a communication device. (Item 18) The communication device according to any one of items 2 to 17, characterized in that the setting by the first setting means is the setting of a security policy, and the setting by the second setting means is the network setting. (Item 19) The communication device described in any one of items 1 to 18, characterized in that the communication device is a printing device. (Item 20) A control method performed in a communication device, A connection setup step which performs connection setup processing to connect the communication device to an external access point, A setting step to configure the communication device to restrict its functions, If the functions necessary to perform the connection setting process are restricted in the setting step, a control step is provided to prevent the connection setting process from starting and to display information indicating that the functions are restricted. A control method characterized by having the following features. (Item 21) A program for causing a computer to function as one of the means of a communication device described in any one of items 1 through 19.

[0130] The invention is not limited to the embodiments described above, and various modifications and variations are possible without departing from the spirit and scope of the invention. Accordingly, claims are attached to disclose the scope of the invention. [Explanation of Symbols]

[0131] 100 MFP: 101 AP: 103 Mobile Terminal Device: 211 CPU: 213 ROM: 214 RAM

Claims

1. A communication device, Connection setting means for performing connection setting processing to connect the communication device to an external access point, A setting means for setting the functions of the communication device to be restricted, If the functions necessary to perform the connection setting process are restricted by the setting means, the first control means controls the connection setting process not to start and to display information indicating that the functions are restricted. A communication device characterized by having the following features.

2. The communication device according to claim 1, characterized in that the setting means includes a first setting means capable of setting restrictions on the functions of the communication device by accepting operations from a user with specific privileges, and a second setting means capable of setting restrictions on the functions of the communication device regardless of the user's privileges.

3. The communication device according to claim 2, characterized in that, if the first setting means sets a restriction on the function of the communication device, the first control means controls to display a first screen that includes a message indicating that the function is restricted.

4. The communication device according to claim 3, characterized in that the first screen is a screen that does not accept a selection of whether or not to release the restriction on the functions of the communication device set by the first setting means.

5. The communication device according to claim 3, characterized in that, if the second setting means sets a restriction on the function of the communication device, the first control means controls to display a second screen that includes a message indicating that the function is restricted.

6. The communication device according to claim 5, characterized in that the second screen is a screen capable of accepting a selection of whether or not to release the restriction on the functions of the communication device set by the second setting means.

7. The communication device according to claim 6, characterized in that, when a selection to remove the restriction on the functions of the communication device is received on the second screen, the first control means removes the restriction on the functions of the communication device set by the second setting means and controls the connection setting means to start the connection setting process.

8. The system further includes a first determination means for determining whether or not the connection setup process can be executed when an instruction to execute the connection setup process is received by a user, The control by the first control means is performed when the first determination means determines that the connection setting process cannot be executed. The communication device according to feature 6.

9. The communication device according to claim 8, characterized in that, if the first determination means determines that the connection setting process can be executed, the first control means controls the connection setting means to start the connection setting process.

10. The communication device according to claim 8, characterized in that, after the first screen is displayed, or after the user selects not to release the restrictions on the functions of the communication device on the second screen, if the user receives an instruction to execute the connection setting process, the determination by the first determination means is repeatedly performed.

11. When the communication device is started, a second determination means determines whether or not the connection setting process can be executed, If the second determination means determines that the connection setting process cannot be executed, or if the functions necessary to execute the connection setting process are restricted by the first setting means, the second control means controls the connection setting process not to start. The communication device according to claim 8, further comprising the features.

12. The communication device according to claim 11, characterized in that the control by the first control means is performed after the home screen of the communication device is displayed, and the control by the second control means is performed before the home screen is displayed.

13. The communication device according to claim 12, characterized in that, if the second determination means determines that the connection setting process can be executed, the second control means controls the connection setting means to start the connection setting process.

14. The communication device according to claim 12, characterized in that, if the second determination means determines that the connection setting process cannot be executed, and the second setting means sets a restriction on the function of the communication device, the second control means releases the restriction on the function of the communication device set by the second setting means and controls the connection setting means to start the connection setting process.

15. The connection setting process includes a process to terminate the operation of the communication device in a predetermined mode, The communication device according to claim 14, characterized in that the second control means controls the process to restrict the function again when the restriction on the function of the communication device set by the second setting means is released.

16. The communication device according to claim 12, characterized in that, if the second determination means determines that the connection setting process cannot be executed, and the first setting means sets a restriction on the function of the communication device, the second control means controls the device to display the home screen without starting the connection setting process.

17. The connection setup process is initiated when the communication device operates in a predetermined mode. The first control means and the second control means control the communication device so as not to start the connection setting process by not setting it to the predetermined mode. The communication device according to feature 11.

18. The communication device according to claim 2, characterized in that the setting by the first setting means is the setting of a security policy, and the setting by the second setting means is the setting of a network.

19. The communication device according to claim 1, characterized in that the communication device is a printing device.

20. A control method performed in a communication device, A connection setup step which performs connection setup processing to connect the communication device to an external access point, A setting step to configure the communication device to restrict its functions, If the functions necessary to perform the connection setting process are restricted in the setting step, a control step is provided to prevent the connection setting process from starting and to display information indicating that the functions are restricted. A control method characterized by having the following features.

21. A program for causing a computer to function as one of the means of the communication device according to any one of claims 1 to 19.