Communication device, computer program for communication device, and method performed by communication device
The communication device with multiple interfaces facilitates secure FIDO authentication by transmitting search signals and executing authentication instructions using biometric information, addressing inefficiencies in existing authentication methods.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- BROTHER KOGYO KK
- Filing Date
- 2024-10-30
- Publication Date
- 2026-05-15
AI Technical Summary
Existing authentication methods lack efficient and secure mechanisms for performing authentication using a pair of keys and biometric authentication information, particularly in communication systems involving printers and terminals.
A communication device equipped with multiple interfaces for different communication methods, including Bluetooth Low Energy (BLE) and Wi-Fi Aware, facilitates the transmission of search signals and execution of authentication instructions using biometric authentication, enabling secure FIDO authentication through encrypted communication with terminals.
Enables secure and efficient authentication by establishing encrypted communication channels and performing biometric authentication, even with terminals at varying distances, enhancing security and usability in communication systems.
Smart Images

Figure 2026079528000001_ABST
Abstract
Description
Technical Field
[0001] This specification discloses a technology related to a predetermined authentication method using a pair of keys and biometric authentication information.
Background Art
[0002] Patent Document 1 discloses a system including an image processing device, a terminal device, a FIDO server, and a cloud server. The image processing device displays an encoded image. The terminal device reads the encoded image and transmits advertising to the image processing device. A BLE connection is established between the terminal device and the image processing device, and when biometric authentication is successful, CTAP communication is executed between the terminal device and the image processing device. The image processing device transmits an authentication request to the FIDO server.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] This specification provides a novel and useful technology for performing authentication according to a predetermined authentication method using a pair of keys and biometric authentication information.
Means for Solving the Problems
[0005] [[ID=4l]] This specification discloses a communication device. The communication device includes a first communication interface that operates according to a first communication method, a second communication interface that operates according to a second communication method different from the first communication method, a memory configured to store, in association with each of a plurality of authenticators, authenticator information related to the authenticator and communication information related to encrypted communication between the authenticator and the communication device using the second communication interface, a first search signal transmitting unit that, when an authentication start instruction is obtained, transmits a first search signal via the first communication interface that includes at least one authenticator information from the plurality of authenticator information in the memory, and when the first search signal is transmitted... In accordance with this, the system may also include: a first response signal receiving unit that receives a first response signal including the first authenticator information from a first authenticator associated with the first authenticator information included in the at least one authenticator information via the first communication interface; and an authentication execution instruction transmitting unit that, when the first response signal is received, performs the encrypted communication using the first communication information stored in association with the first authenticator information via the second communication interface and transmits an authentication execution instruction to the first authenticator, wherein the authentication execution instruction is information for instructing the execution of authentication in accordance with a predetermined authentication method using a pair of keys and biometric authentication information.
[0006] According to the above configuration, when the communication device obtains an authentication start instruction, it transmits a first search signal to the outside via the first communication interface and receives a first response signal from the first authenticator via the first communication interface. Next, the communication device performs encrypted communication using the first communication information via the second communication interface and transmits an authentication execution instruction to the first authenticator. Thus, authentication can be performed according to a predetermined authentication method.
[0007] The computer program for the above-mentioned communication device, the computer-readable recording medium for storing the computer program, and the method executed by the communication device are also novel and useful. Furthermore, a communication system including the communication device and multiple authenticators is also novel and useful. Here, the above-mentioned recording medium may be a single medium or multiple mediums. [Brief explanation of the drawing]
[0008] [Figure 1] This shows the configuration of the communication system. [Figure 2] An example of each table is shown. [Figure 3] This is a sequence diagram for Case A, where the first link information is registered. [Figure 4] This is a continuation of Figure 3. [Figure 5] This is a sequence diagram for Case B, where the second link information is registered. [Figure 6] This is a continuation of Figure 5. [Figure 7] This is a sequence diagram for Case C, where the first link information is used. [Figure 8] This is a sequence diagram for Case D, where the first link information is used. [Figure 9] This is a sequence diagram for Case E, where the first link information is used. [Figure 10] This is a sequence diagram for case F, where the first link information is used. [Modes for carrying out the invention]
[0009] (First embodiment) (Configuration of communication system 2; Figure 1) As shown in Figure 1, the communication system 2 comprises a printer 10, multiple terminals 100A and 100B, an authentication server 200, a connection server 300, and a service provider server 400. Hereafter, the service provider server will be referred to as the "SP server." The printer 10, the multiple terminals 100A and 100B, the authentication server 200, the connection server 300, and the SP server 400 are connected to the Internet 6. The printer 10, the multiple terminals 100A and 100B, the authentication server 200, the connection server 300, and the SP server 400 can communicate with each other via the Internet 6.
[0010] (Printer 10 configuration) Printer 10 is a peripheral device (e.g., a PC peripheral) capable of performing printing functions. Printer 10 can operate according to the Fast Identity Online (FIDO) authentication method, which uses a pair of keys and biometric authentication information. The FIDO authentication method is an authentication method that uses a pair of keys, namely a private key and a public key. Hereafter, the private key and public key will be referred to as the "private key for server authentication" and the "public key for server authentication," respectively. Furthermore, the FIDO authentication method is an authentication method that uses biometric authentication information (e.g., fingerprint authentication information, voiceprint authentication information, facial authentication information) to authenticate users instead of using password authentication. Hereafter, authentication according to the FIDO authentication method will be referred to as "FIDO authentication."
[0011] The printer 10 comprises an operation unit 12, a print execution unit 16, a BTI / F 20, a Wi-Fi I / F 22, and a control unit 30. Hereafter, interfaces will be referred to as "I / F". BT is an abbreviation for "Bluetooth". Bluetooth is a registered trademark of Bluetooth SIG.
[0012] The control unit 12 is a user interface that allows the user to input various information to the printer 10. The control unit 12 includes, for example, hardware keys. Hardware keys include, for example, buttons or switches.
[0013] The printing execution unit 16 includes a printing engine of an electrophotographic method, an inkjet method, or a thermal method. The printing engine of the inkjet method includes a print head that discharges ink droplets. The printing engine of the electrophotographic method includes a photoreceptor and an exposure device that emits light to expose the photoreceptor. The printing engine of the thermal method includes a print head that generates heat by a heater.
[0014] BTI / F20 is an I / F for performing wireless communication according to the BT standard. Hereinafter, wireless communication according to the BT standard is referred to as "BT communication". The BT standard is, for example, the standard of IEEE802.15.1 and standards equivalent thereto. More specifically, BTI / F20 supports Bluetooth Low Energy (BLE). BLE is realized in versions 4.0 and later of the BT standard.
[0015] Wi-FiI / F22 is a wireless I / F for performing wireless communication according to the Wi-Fi standard. The Wi-Fi standard is a wireless communication standard for performing wireless communication according to, for example, the 802.11 standard of The Institute of Electrical and Electronics Engineers, Inc. (IEEE) and standards equivalent thereto, such as 802.11a, 11b, 11n, 11ac. Wi-FiI / F22 can normally perform wireless communication according to the Wi-Fi method. As an example, wireless communication according to the normal Wi-Fi method is wireless communication in which an AP (not shown) is used. Hereinafter, wireless communication according to the normal Wi-Fi method is referred to as "normal Wi-Fi communication".
[0016] Here, the differences between normal Wi-Fi communication and BT communication will be described. The communication speeds of each communication are in the order of the communication speed of normal Wi-Fi communication (for example, the maximum communication speed is 600 Mbps) and the communication speed of BT communication (for example, the maximum communication speed is 24 Mbps), with the former being faster. The frequencies of the carrier waves in each communication are such that the frequency of the carrier wave in normal Wi-Fi communication is in the 2.4 GHz band or 5.0 GHz band, and the frequency of the carrier wave in BT communication is in the 2.4 GHz band. That is, when the 5.0 GHz band is adopted as the frequency of the carrier wave in normal Wi-Fi communication, the frequencies of the carrier waves in each communication are different from each other. Also, the maximum distances at which each communication can be executed are in the order of the maximum distance at which normal Wi-Fi communication can be executed (for example, 100 m) and the maximum distance at which BT communication can be executed (for example, about several tens of meters), with the former being larger. That is, BT communication is so-called short-range wireless communication.
[0017] In addition, Wi-Fi I / F 22 supports the Wi-Fi Aware mode formulated by the Wi-Fi Alliance. The details of the Wi-Fi Aware mode are described in the specification "Wi-Fi Aware Specification Version 4.0" created by the Wi-Fi Alliance. In wireless communication according to the Wi-Fi Aware mode, an AP is not used. Hereinafter, wireless communication according to the Wi-Fi Aware mode will be referred to as "Wi-Fi Aware communication". Wi-Fi Aware is also called Wi-Fi Neighbor Awareness Network (NAN).
[0018] Each device that supports the Wi-Fi Aware mode can participate in the NAN cluster of the Wi-Fi Aware mode. Proximity information is transmitted and received between devices that support the Wi-Fi Aware mode. That is, wireless communication according to the Wi-Fi Aware mode is so-called short-range wireless communication.
[0019] The control unit 30 comprises a CPU 32 and a memory 34. The memory 34 comprises a main memory and an auxiliary memory. For example, the main memory includes RAM and cache memory. For example, the auxiliary memory may be ROM, flash memory, Solid State Drive (SSD), Hard Disk Drive (HDD), or a combination thereof. The auxiliary memory of the memory 34 stores a program 40 and an authentication-related table 42. The CPU 32 performs various processes according to the program loaded from the auxiliary memory to the main memory.
[0020] (Configuration of terminals 100A to 100C) Terminals 100A to 100C are portable terminal devices such as mobile phones, smartphones, PDAs, and tablet PCs. Terminals 100A to 100C can operate according to the FIDO authentication scheme. Terminals 100A to 100C function as authenticators in the FIDO authentication scheme.
[0021] Terminal 100A is assigned the MAC address "MAC1". Terminal 100A includes an operation unit 112, a display unit 114, a Wi-Fi interface 122, a camera 124, and a control unit 130.
[0022] The operation unit 112 is a user interface that allows the user to input various information to the terminal 100A. The operation unit 112 includes, for example, a touch panel, hardware keys, or both for displaying software keys (operation area). Hardware keys include, for example, buttons or switches. The display unit 114 is a display or panel for displaying various information and various screens described later. The display is, for example, a liquid crystal display or an organic EL display. The panel may or may not be a touch panel. The panel is, for example, a liquid crystal panel or an organic EL panel.
[0023] The BTI / F120 has the same configuration as the BTI / F20 of printer 10. The Wi-FiI / F122 has the same configuration as the Wi-FiI / F22 of printer 10.
[0024] Camera 124 is a device for photographing objects. In this embodiment, camera 124 is used to photograph a QR code. QR Code is a registered trademark of DENSO WAVE INCORPORATED.
[0025] The control unit 130 comprises a CPU 132 and a memory 134. The memory 134 comprises a main memory and an auxiliary memory. The auxiliary memory of the memory 134 stores an Operating System (OS) program 140, an authentication application 142, biometric authentication information 144, the username "Yamada", and the server authentication secret key PRK1. The OS program 140 controls the basic operation of the terminal 100A. The authentication application 142 is a program that makes the terminal 100A operate as an authenticator for FIDO authentication. The CPU 132 performs various processes according to the program loaded from the auxiliary memory to the main memory. The biometric authentication information 144 is the fingerprint information of the user using the terminal 100A. The username "Yamada" is the username of the user using the terminal 100A. Hereafter, the user using the terminal 100A will be referred to as "the first user". The server authentication secret key PRK1 is the key used for FIDO authentication. The username "Yamada" and the server authentication private key PRK1 are registered in memory 134 when the registration process for registering the pair of keys used for FIDO authentication is executed.
[0026] Terminal 100B has the same configuration as terminal 100A, except that it is assigned the MAC address "MAC2" and that the username "Tanaka" and the server authentication secret key PRK2 are stored in terminal 100B's memory (not shown in the diagram). Hereafter, the user using terminal 100B will be referred to as the "second user".
[0027] Terminal 100C has the same configuration as terminal 100A, except that it is assigned the MAC address "MAC3" and that the username "Sato" and the server authentication secret key PRK3 are stored in terminal 100C's memory (not shown).
[0028] (Each server has a configuration of 200, 300, and 400 units) Each of the servers 200, 300, and 400 is a server installed on the Internet 6. Each of the servers 200, 300, and 400 is a server provided by, for example, the vendor of printer 10. In a modified version, each of the servers 200, 300, and 400 may be installed on the Internet 6 by a different operator than the vendor. In another modified version, the vendor may not prepare the hardware for each of the servers 200, 300, and 400 themselves, but may use an environment provided by an external cloud computing service. In this case, the vendor may prepare the programs (i.e., software) for each of the servers 200, 300, and 400 and implement them in the above environment to realize each of the servers 200, 300, and 400.
[0029] The authentication server 200 can operate according to the FIDO authentication scheme. The authentication server 200 operates as a so-called authentication server in the FIDO authentication scheme. The management table 240 is stored in the memory 234 of the authentication server 200.
[0030] The connection server 300 mediates communication between the printer 10 and the terminal. The connection server 300 is a server that provides tunnel services.
[0031] The SP server 400 provides services related to the printer 10. For example, the SP server 400 provides remote operation services and printing services. The remote operation service allows the user to operate the printer 10 via the SP server 400 using a terminal. The printing service mediates the transmission of print data from the terminal to the printer 10. For example, the SP server 400 stores the print data received from the terminal (upload process) and, upon receiving a download request for the print data from the printer 10, transmits the print data to the printer 10 (download process).
[0032] (Explanation of each table; Figure 2) Referring to Figure 2, the authentication-related table 42 of the printer 10 and the management table 240 of the authentication server 200 will be explained.
[0033] The authentication-related table 42 of printer 10 stores link information and MAC address in association. The link information includes contact ID, link ID, shared key, public key for encrypted communication, and username. The contact ID is information used to identify the authenticator. The link ID is information used to identify the link information. The link information is information used to use the tunnel service provided by the connection server 300. The public key for encrypted communication is information used in the encrypted communication processing described later.
[0034] The management table 240 of the authentication server 200 stores the username and the server authentication public key in association. The server authentication public key is the key used for FIDO authentication. The username and the server authentication public key are registered in the management table 240 when the registration process for registering the pair of keys used for FIDO authentication is executed.
[0035] (Specific cases) Referring to Figures 3 to 8, a specific case realized by the communication system 2 of this embodiment will be described. In the following, each device (e.g., printer 10) will be described as the main focus, rather than the CPU of each device (e.g., the CPU 32 of printer 10). Also, in Figures 3 to 10, in order to make it easier to understand the types of communication used between each device, normal Wi-Fi communication is shown with a thin solid line, Wi-Fi Aware communication is shown with a thick solid line, and BT communication is shown with a thin dashed line.
[0036] (Case A; Figures 3 and 4) Case A will be explained with reference to Figures 3 and 4. In Case A, the first link information corresponding to terminal 100A is registered in the authentication-related table 42 of printer 10. In the initial state of Case A, the combination of username "Yamada" and server authentication public key PUK1, the combination of username "Tanaka" and server authentication public key PUK2, and the combination of username "Sato" and server authentication public key PUK3 are stored in the management table 240. The authentication-related table 42 is empty. Also, printer 10 and terminal 100A are participating in the same NAN cluster. That is, printer 10 and terminal 100A are configured to perform Wi-Fi Aware communication.
[0037] The first user performs a first authentication initiation operation on the printer 10 at T10. The first authentication initiation operation is an operation to request the execution of FIDO authentication. In this case, the printer 10 determines that the authentication-related table 42 is empty, that is, that the link information is not stored in the authentication-related table 42, and at T12, sends a first authentication request to the authentication server 200 via the Wi-Fi I / F 22 using normal Wi-Fi communication.
[0038] When the authentication server 200 receives a first authentication request from the printer 10 at T12, it generates verification information VE1 at T14 and stores the verification information VE1. At T16, the authentication server 200 sends a first response signal containing the verification information VE1 to the printer 10.
[0039] At T16, when printer 10 receives a first response signal from authentication server 200 via Wi-Fi I / F 22 using normal Wi-Fi communication, it determines that the authentication-related table 42 is empty. In this case, printer 10 generates a public key for encrypted communication, key information, and domain information, and stores each piece of information in memory. The key information is used for encrypting and decrypting the advertised signal. The domain information is information that printer 10 knows about, and also information that indicates the domain of the server providing the tunnel service. At T20, printer 10 generates a QR code obtained by encoding the public key for encrypted communication, key information, and domain information. At T22, printer 10 executes a printing process to print the generated QR code on paper.
[0040] The first user, at T30, uses the camera 124 of terminal 100A to photograph a QR code printed on the paper. At T32, terminal 100A decodes the photographed QR code to obtain the public key for encrypted communication, key information, and domain information. Terminal 100A generates web socket information to be used to connect with the connection server 300 and stores the web socket information in memory 134. The web socket information includes a tunnel ID, a root ID, and a tunnel service identifier. The tunnel ID and root ID are information used in the tunnel service. The tunnel service identifier is information that indicates the server providing the tunnel service to be used, i.e., the connection server 300. Terminal 100A determines the tunnel service identifier using the obtained domain information. Terminal 100A encrypts the generated web socket information using the obtained key information and generates an advertisement signal. At T34, terminal 100A sends the advertisement signal to the printer 10 via BTI / F120.
[0041] When printer 10 receives an advertisement signal from terminal 100A via BTI / F20 at T34, it decrypts the advertisement signal at T36 using stored key information. This allows printer 10 to obtain websocket information. Next, at T50, a first encrypted communication process is performed to execute encrypted communication between terminal 100A, printer 10, and connection server 300. The first encrypted communication process includes a first connection process in which terminal 100A connects to connection server 300, a second connection process in which printer 10 connects to connection server 300, and a first handshake process in which a handshake is performed between terminal 100A and printer 10. In the first connection process, a tunnel service identifier is used. In the second connection process, websocket information is used. In the first handshake process, the public key for encrypted communication contained in the QR code is used. This establishes a websocket connection between terminal 100A and printer 10. Furthermore, terminal 100A will be able to perform encrypted communication with printer 10 via connection server 300. This encrypted communication is typically included in communication following the Wi-Fi standard.
[0042] When terminal 100A completes the first encrypted communication process, it generates first link information including contact ID "CT1", link ID "LK1", common key CK1, encrypted communication public key PUK11, and username "Yamada", and stores it in memory 134. The encrypted communication public key PUK11 may be the same as or different from the encrypted communication public key in the QR code. Terminal 100A uses encrypted communication via Wi-Fi I / F 122 at T42 to send the first link information and MAC address "MAC1" to printer 10. Terminal 100A also sends contact ID "CT1" and link ID "LK1" to the connection server 300. This allows the connection server 300 to identify terminal 100A using contact ID "CT1" and link ID "LK1".
[0043] At T42, printer 10 receives the first link information and MAC address "MAC1" from terminal 100A via Wi-Fi I / F22 using encrypted communication, and at T44, stores the first link information and MAC address "MAC1" in authentication-related table 42. At T50, printer 10 sends an authentication execution instruction to terminal 100A via Wi-Fi I / F22 using encrypted communication, including the acquired verification information VE1 (see T16). The authentication execution instruction is a signal to instruct the execution of biometric authentication.
[0044] When terminal 100A receives an authentication execution instruction from printer 10 via Wi-Fi I / F 22 using encrypted communication at T50, it displays a fingerprint authentication screen on display unit 114 at T52. The fingerprint authentication screen displays a message requesting the execution of fingerprint authentication. The first user performs a fingerprint authentication operation on terminal 100A at T54. Terminal 100A determines that fingerprint authentication is successful because the fingerprint information obtained by the fingerprint authentication operation matches the biometric authentication information 144 in memory 134. In this case, at T56, terminal 100A generates signature information SI1 by encrypting the received verification information VE1 using the server authentication secret key PRK1 in memory 134. Terminal 100A also identifies the username "Yamada" in memory 134. Terminal 100A, at T60 in Figure 4, uses encrypted communication via Wi-Fi 122 to send a first authentication response to printer 10, which includes the identified username "Yamada" and the generated signature information SI1.
[0045] When printer 10 receives a first authentication response from terminal 100A via Wi-Fi 22 using encrypted communication at T60, printer 10 sends the first authentication response to authentication server 200 via Wi-Fi 22 at T62.
[0046] When the authentication server 200 receives the first authentication response from the printer 10 at T62, it identifies the server authentication public key PUK1 stored in the management table 240 in association with the username "Yamada" in the first authentication response. The authentication server 200 uses the identified server authentication public key PUK1 to decrypt the signature information SI1 in the first authentication response. Since the server authentication private key PRK1 and the server authentication public key PUK1 are a pair of keys, the verification information VE1 is obtained by decrypting the signature information SI1 using the server authentication public key PUK1. The authentication server 200 determines that the obtained verification information VE1 matches the stored verification information VE1 (see T14 in Figure 3), and at T70, it determines that FIDO authentication was successful. In this case, at T72, the authentication server 200 sends an authentication success notification including a token to the printer 10. The token is authentication information shared between the authentication server 200 and the SP server 400. Furthermore, if the authentication server 200 determines that FIDO authentication is unsuccessful, it sends an authentication failure notification to the printer 10 indicating that FIDO authentication has failed.
[0047] At T72, when printer 10 receives an authentication success notification from authentication server 200 via Wi-Fi I / F 22, it identifies the token in the authentication success notification. At T80, printer 10 sends a service start request to SP server 400, which includes the service URL and the identified token. The service URL is information indicating the location of SP server 400 on the internet 6.
[0048] When the SP server 400 receives a service start request from the printer 10 in T80, it sends service screen data to the printer 10 in T82.
[0049] When printer 10 receives service screen data from SP server 400 via Wi-Fi I / F 22 at T82, it transmits the service screen data to terminal 100A via Wi-Fi I / F 22 using encrypted communication at T84.
[0050] When terminal 100A receives service screen data from printer 10 via Wi-Fi I / F 122 using encrypted communication at T84, terminal 100A displays the service screen represented by the service screen data on display unit 114 at T86. The service screen is a screen for using the remote operation screen. In a modified example, the service screen may be a screen for selecting print data to be printed by printer 10.
[0051] Furthermore, if the printer 10 receives an authentication failure notification from the authentication server 200 after sending the first authentication response to the authentication server 200, it will not execute the process of T80.
[0052] (Case B; Figures 5 and 6) Case B will be explained with reference to Figures 5 and 6. In Case B, second link information corresponding to terminal 100B is registered in the authentication-related table 42 of printer 10. The initial state of Case B is a state after the initial state of Case A. In Case B, printer 10 and terminal 100B are participating in the same NAN cluster. In Case B, the distance between printer 10 and terminal 100B is less than the first predetermined distance. For example, the first predetermined distance is 5m.
[0053] Steps T110 to T116 are the same as steps T10 to T16 in Figure 3, except that verification information VE2 is used instead of verification information VE1. At step T116, when the printer 10 receives a first response signal from the authentication server 200 via the Wi-Fi I / F 22 using normal Wi-Fi communication, it determines that the authentication-related table 42 contains link information. In this case, the printer 10 identifies the combination of username "Yamada" and MAC address "MAC1" in the authentication-related table 42, and at step T120, it transmits a first pull signal containing "Yamada, MAC1" via the Wi-Fi I / F 22 using Wi-Fi Aware communication. The first publish signal is a signal transmitted to authenticators whose distance from the printer 10 is less than a first predetermined distance.
[0054] When terminal 100B receives the first Publish signal from printer 10 via Wi-Fi I / F using Wi-Fi Aware communication at T120, it measures the distance between itself and printer 10 using a distance measurement function (Wi-Fi RTT function) in accordance with the Wi-Fi Aware method. In this case, the distance between printer 10 and terminal 100B is less than the first predetermined distance. Therefore, terminal 100B determines that the first Publish signal is a signal sent to terminal 100B and determines whether or not the first Publish signal contains terminal 100B's MAC address "MAC2". Next, terminal 100B determines that the first Publish signal does not contain MAC address "MAC2". In this case, terminal 100B displays a registration confirmation screen on the display unit at T122. The registration confirmation screen is a screen for confirming whether or not to perform FIDO authentication. The second user performs a registration request operation to terminal 100B at T122. As a result, terminal 100B, via Wi-Fi I / F at T126, uses Wi-Fi Aware communication to send a Subscribe signal containing a registration request to printer 10.
[0055] When printer 10 receives a Subscribe signal from terminal 100B via Wi-Fi I / F 22 using Wi-Fi Aware communication at T126, it generates a public key for encrypted communication, key information, and domain information. T130 and T132 are the same as T20 and T22 in Figure 3, respectively.
[0056] The second user, at T140, uses the camera of terminal 100B to photograph the QR code printed on the paper. At T142, terminal 100B decodes the photographed QR code to obtain the public key for encrypted communication, key information, and domain information. Terminal 100B generates WebSocket information. Terminal 100B encrypts the generated WebSocket information using the obtained key information to generate an advertisement signal. At T144, terminal 100B sends the advertisement signal to printer 10 via BTI / F.
[0057] At T144, when printer 10 receives an advertisement signal from terminal 100B via BTI / F20, at T146, it decrypts the advertisement signal using key information. As a result, printer 10 obtains websocket information. At T150, the first encrypted communication process is executed between terminal 100B, printer 10, and connection server 300. The content of the first encrypted communication process at T150 is the same as the content of the first encrypted communication process at T40 in Figure 3, except that the communication target is terminal 100B.
[0058] Terminal 100B generates second link information, including contact ID "CT2", link ID "LK2", common key CK2, public key PUK12 for encrypted communication, and username "Tanaka", and stores it in memory. Terminal 100B, using encrypted communication via the Wi-Fi interface at T152, transmits the second link information and MAC address "MAC2" to printer 10.
[0059] At T152, printer 10 receives the second link information and MAC address "MAC2" from terminal 100B via Wi-Fi I / F 22 using encrypted communication, and at T154, stores the second link information and MAC address "MAC2" in the authentication-related table 42. At T160 in Figure 6, printer 10 sends an authentication execution instruction to terminal 100B via Wi-Fi I / F 22 using encrypted communication, including the acquired verification information VE2 (see T116 in Figure 5).
[0060] When terminal 100B receives an authentication execution command from printer 10 via Wi-Fi I / F using encrypted communication at T160, it displays a fingerprint authentication screen at T162. The second user performs a fingerprint authentication operation on terminal 100B at T164. Terminal 100B determines that fingerprint authentication is successful because the fingerprint information obtained by the fingerprint authentication operation matches the biometric authentication information in memory. In this case, at T166, terminal 100B generates signature information SI2 by encrypting the received verification information VE2 using the server authentication secret key PRK2 in memory. Terminal 100B also identifies the username "Tanaka" in memory. At T170, terminal 100B sends a second authentication response to printer 10 via Wi-Fi I / F using encrypted communication, containing the identified username "Tanaka" and the generated signature information SI2.
[0061] When printer 10 receives a second authentication response from terminal 100B via Wi-Fi 22 using encrypted communication at T170, printer 10 sends the second authentication response to authentication server 200 via Wi-Fi 22 at T172.
[0062] When the authentication server 200 receives a second authentication response from the printer 10 at T172, it executes a process using the server authentication public key PUK2 stored in the management table 240, which is associated with the username "Tanaka" in the second authentication response. As a result, the authentication server 200 determines at T180 that FIDO authentication was successful. In this case, the authentication server 200 sends an authentication success notification containing a token to the printer 10 at T182.
[0063] T190 to T196 are the same as T80 to T86 in Figure 4, except that the communication target is terminal 100B.
[0064] (Case C; Figure 7) Refer to Figure 7 to explain Case C. In Case C, a connection using encrypted communication is established between terminal 100A and printer 10 using the first link information. Case C is the state after Case B in Figures 5 and 6. That is, the authentication-related table 42 of printer 10 stores the combination of the first link information and MAC address "MAC1", and the combination of the second link information and MAC address "MAC2". In Case C, printer 10 and terminal 100A are participating in the same NAN cluster. In Case C, the distance between printer 10 and terminal 100A is less than the first predetermined distance.
[0065] T310 to T316 are the same as T10 to T16 in Figure 3, except that verification information VE3 is used instead of verification information VE1. At T316, when printer 10 receives a first response signal from authentication server 200 via Wi-Fi I / F 22 using normal Wi-Fi communication, it determines that the authentication-related table 42 contains link information. In this case, printer 10 identifies the combination of username "Yamada" and MAC address "MAC1" and username "Tanaka" and MAC address "MAC2" in the authentication-related table 42. At T320, printer 10 transmits a first Publish signal containing "Yamada, MAC1" and "Tanaka, MAC2" via Wi-Fi I / F 22 using Wi-Fi Aware communication. Thus, the first Publish signal contains the usernames included in all the authentication information contained in the authentication-related table 42 and the MAC addresses stored in association with those usernames.
[0066] When terminal 100A receives a first Publish signal from printer 10 via Wi-Fi I / F using Wi-Fi Aware communication at T320, it measures the distance between itself and printer 10 using a distance measurement function according to the Wi-Fi Aware method. In this case, the distance between printer 10 and terminal 100A is less than the first predetermined distance. Therefore, terminal 100A determines that the first Publish signal is a signal sent to terminal 100A and determines whether or not the first Publish signal contains the MAC address "MAC1". At T322, terminal 100A determines that the first Publish signal contains the MAC address "MAC1". In this case, at T324, terminal 100A displays an authentication confirmation screen on display unit 114 that includes the username "Yamada" corresponding to the MAC address "MAC1". The authentication confirmation screen is a screen for confirming whether or not to perform FIDO authentication. The first user performs a second authentication initiation operation on terminal 100A in T326 to instruct it to perform FIDO authentication. As a result, terminal 100A, in T328, sends a Subscribe signal containing "Yamada, MAC1" to printer 10 via Wi-Fi I / F122 using Wi-Fi Aware communication.
[0067] When printer 10 receives a Subscribe signal from terminal 100A via Wi-Fi I / F 22 using Wi-Fi Aware communication at T328, printer 10 identifies the first link information associated with the MAC address "MAC1" in the Subscribe signal in the authentication-related table 42 at T330. Printer 10 identifies the contact ID "CT1" in the first link information. Printer 10 sends a first connection request containing the contact ID "CT1" to the connection server 300 via Wi-Fi I / F 22 at T332.
[0068] When the authentication server 200 receives the first connection request from the printer 10 at T332, it identifies the contact ID "CT1" in the first connection request and identifies the terminal 100A identified by the contact ID "CT1". At T334, the authentication server 200 sends a second connection request to terminal 100A.
[0069] When terminal 100A receives a second connection request from the connection server 300 via Wi-Fi I / F 122 using normal Wi-Fi communication at T334, it displays a connection confirmation screen on the display unit 114 at T336. The connection confirmation screen is for confirming whether or not to establish a connection with the printer 10 for encrypted communication. The first user performs a connection operation on terminal 100A at T338. As a result, terminal 100A sends a Follow-up signal including "nonce" to the printer 10 via Wi-Fi I / F 122 using Wi-Fi Aware communication. This Follow-up signal indicates that terminal 100A is in close proximity to the printer 10. In the modified version, the processing at T340 can be omitted.
[0070] At T342, a second encrypted communication process is performed between terminal 100A and printer 10. In the second encrypted communication process, the public key for encrypted communication in the first link information is used. This establishes a WebSocket connection between terminal 100A and printer 10. Terminal 100A can also perform encrypted communication with printer 10 via connection server 300. At T350, printer 10 uses encrypted communication via Wi-Fi I / F22 to send an authentication execution instruction to terminal 100A, including the acquired verification information VE3 (see T314). Subsequently, the same processes as T52-T56 in Figure 3 and T60-T86 in Figure 4 are performed between terminal 100A, printer 10, authentication server 200, and SP server 400. In this case, verification information VE3 and signature information SI3 are used.
[0071] As described above, the first Publish signal is a signal that is transmitted to terminals whose distance from the printer 10 is less than the first predetermined distance. With this configuration, FIDO authentication can be performed using terminals that are close to the printer 10.
[0072] (Case D; Figure 8) Refer to Figure 8 to explain Case D. In Case D, a connection using encrypted communication is established between terminal 100A and printer 10 using the first link information. The initial state of Case D is the same as the initial state of Case C in Figure 7. In Case D, printer 10 and terminal 100A are participating in the same NAN cluster. In Case D, the distance between printer 10 and terminal 100A is less than a second predetermined distance which is greater than a first predetermined distance. For example, the second predetermined distance is 10m.
[0073] T410 to T416 are the same as T10 to T16 in Figure 3, except that verification information VE4 is used instead of verification information VE1. T420 is the same as T320 in Figure 7. In this case, terminal 100A determines that the distance between printer 10 and terminal 100A is greater than the first predetermined distance, and determines that the first Publish signal is not a signal sent to terminal 100A. In this case, terminal 100A does not determine whether the first Publish signal contains the MAC address "MAC1". That is, terminal 100A does not send a Subscribe signal containing "Yamada, MAC1" as a response to the first Publish signal.
[0074] Printer 10 determines at T422 that a first predetermined time has elapsed since it transmitted the first Publish signal and has not received a Subscribe signal. In this case, printer 10 transmits a second Publish signal, including "Yamada, MAC1" and "Tanaka, MAC2", via Wi-Fi I / F22 using Wi-Fi Aware communication at T430. The second Publish signal is transmitted to authenticators whose distance from printer 10 is less than a second predetermined distance.
[0075] At T430, terminal 100A receives a second Publish signal from printer 10 via Wi-Fi I / F 22 using Wi-Fi Aware communication, and determines that the distance between printer 10 and terminal 100A is less than a second predetermined distance. Therefore, terminal 100A determines that the second Publish signal was sent to terminal 100A and determines whether the second Publish signal contains the MAC address "MAC1". At T432, terminal 100A determines that the second Publish signal contains the MAC address "MAC1". T434 to T438 are the same as T324 to T328 in Figure 7. Subsequently, the same processing as T340 to T350 in Figure 7, T52 to T56 in Figure 3, and T60 to T86 in Figure 4 is performed between terminal 100A, printer 10, authentication server 200, connection server 300, and SP server 400. In this case, verification information VE4 and signature information SI4 will be used.
[0076] As described above, if the printer 10 does not receive the first Subscribe signal after the first Publish signal has been sent, it sends a second Publish signal via Wi-Fi I / F 22 using Wi-Fi Aware communication, including "Yamada, MAC1" and "Tanaka, MAC2" (T430). With this configuration, FIDO authentication using terminal 100A can be performed even if terminal 100A is not located within a range where the distance from printer 10 is a first predetermined distance.
[0077] (Effects of this embodiment) According to the above configuration, when printer 10 receives an authentication start instruction (T310 in Figure 7), it transmits a first Publish signal to the outside via Wi-Fi I / F22 following the Wi-Fi Aware method (T320), and receives a Subscribe signal from terminal 100A via Wi-Fi I / F22 following the Wi-Fi Aware method (T328). Next, printer 10 performs encrypted communication using the first link information via Wi-Fi I / F22 following the normal Wi-Fi method and transmits an authentication execution instruction to terminal 100A (T350). Thus, FIDO authentication can be performed.
[0078] Printer 10 is an example of a "communication device". The Wi-Fi Aware method and the Wi-Fi I / F 22 operating according to the Wi-Fi Aware method are examples of the "first communication method" and the "first communication interface", respectively. The normal Wi-Fi method and the Wi-Fi I / F 22 operating according to the normal Wi-Fi method are examples of the "second communication method" and the "second communication interface", respectively. Terminals 100A to 100C are examples of "multiple authenticators". A MAC address is an example of "authentication device information". Link information is an example of "communication information". The first Publish signal in Figures 7 and 8 is an example of a "first search signal". Terminal 100A is an example of a "first authenticator". The MAC address "MAC1" is an example of "first authenticator information". The Subscribe signal of T328 in Figure 7 is an example of a "first response signal". The first link information is an example of "first communication information". FIDO authentication is an example of "authentication according to a predetermined authentication method". The second Publish signal in Figure 8 is an example of a "second search signal". Terminal 100A is an example of a "second authenticator". The MAC address "MAC1" is an example of "second authenticator information". The Subscribe signal of T438 in Figure 8 is an example of a "second response signal". BTI / F20 is an example of a "third communication interface". The ADV signal of T34 in Figure 4 is an example of "third communication information".
[0079] T320 in Figure 7 and T420 in Figure 8 are examples of processes performed by the "first search signal transmission unit". T328 in Figure 7 is an example of a process performed by the "first response signal transmission unit". T350 in Figure 7 is an example of a process performed by the "authentication execution instruction transmission unit".
[0080] (Second example) A second embodiment will now be described. In the second embodiment, the content of the processing performed by the printer 10 when link information is stored in the authentication-related table 42 differs from the content of the processing in the first embodiment.
[0081] (Specific cases) Referring to Figure 9, a specific case realized by the communication system 2 of this embodiment will be described.
[0082] (Case E; Figure 9) Refer to Figure 9 to explain Case E. In Case E, a connection using encrypted communication is established between terminal 100A and printer 10 using the first link information. The initial state of Case E is the same as the initial state of Case C in Figure 7. In Case E, printer 10 and terminals 100A to 100C are participating in the same NAN cluster.
[0083] T510 to T516 are the same as T10 to T16 in Figure 3, except that verification information VE5 is used instead of verification information VE1. At T520, printer 10 performs a distance measurement process to measure the distance between itself and terminals 100A to 100C using a distance measurement function according to the Wi-Fi Aware method. Next, printer 10 identifies the terminal with the shortest distance from printer 10 among terminals 100A to 100C. Hereafter, the terminal with the shortest distance from printer 10 will be referred to as the "nearest terminal". In this case, at T522, printer 10 determines that terminal 100A is the nearest terminal and that the MAC address of terminal 100A, "MAC1", is already stored in the authentication-related table 42. In this case, printer 10 transmits a third Publish signal containing "Yamada, MAC1" via Wi-Fi I / F 22 using Wi-Fi Aware communication. The third Publish signal is a signal transmitted to the nearest terminal. Furthermore, if the MAC address of the nearest terminal is not stored in the authentication-related table 42, the printer 10 sends a fourth Publish signal containing registration confirmation screen data to the nearest terminal. In this case, the processing from T122 onwards in Figure 5 is executed.
[0084] T532~T540 are the same as T322~T330 in Figure 7. Subsequently, the same processing as T340~T350 in Figure 7, T52~T56 in Figure 3, and T60~T86 in Figure 4 is performed between terminal 100A, printer 10, authentication server 200, connection server 300, and SP server 400. In this case, verification information VE5 and signature information SI5 are used.
[0085] As described above, the printer 10 selects terminal 100A, which is the closest terminal to the printer 10, from among the multiple terminals 100A to 100C, and sends a third Publish signal to the selected terminal 100A. The user using the terminal closest to the printer 10 is highly likely to want to perform FIDO authentication. With the above configuration, FIDO authentication can be performed using the terminal used by the user who is most likely to want to perform FIDO authentication.
[0086] (Correspondence) The third Publish signal is an example of the "first search signal".
[0087] (Third embodiment) A third embodiment will now be described. In the third embodiment, the content of the processing performed by the printer 10 when link information is stored in the authentication-related table 42 differs from the content of the processing in the first embodiment.
[0088] (Specific cases) Referring to Figure 10, a specific case realized by the communication system 2 of this embodiment will be described.
[0089] (Case F; Figure 10) Case F will be explained with reference to Figure 10. In Case F, a connection using encrypted communication is established between terminal 100A and printer 10 using the first link information. The initial state of Case F is the same as the initial state of Case C in Figure 7. In Case F, printer 10 and terminals 100A to 100C are participating in the same NAN cluster.
[0090] T610 to T616 are the same as T10 to T16 in Figure 3, except that verification information VE6 is used instead of verification information VE1. At T620, printer 10 performs a first distance measurement process to measure the first distance between itself and terminals 100A to 100C using a distance measurement function according to the Wi-Fi Aware method.
[0091] Terminal 100A displays a proximity request confirmation screen on the display unit 114 in T622. The proximity request confirmation screen includes the message "If you are using FIDO authentication, please bring the terminal closer to the printer." The same screen is displayed on terminals 100B and 100C. In this case, the first user brings terminal 100A closer to printer 10 in T624.
[0092] Printer 10 determines that a second predetermined time has elapsed since the first distance measurement process was executed, and in T626, it executes a second distance measurement process to measure the second distance between itself and terminals 100A to 100C using a distance measurement function in accordance with the Wi-Fi Aware method. In T628, Printer 10 selects terminal 100A from among terminals 100A to 100C whose second distance is less than the first distance, and identifies the combination of username "Yamada" and MAC address "MAC1" in the authentication-related table 42. In T630, Printer 10 transmits a fifth Publish signal containing "Yamada, MAC1" via Wi-Fi I / F 22 using Wi-Fi Aware communication. If there are multiple terminals whose second distance is less than the first distance, Printer 10 may transmit a fifth Publish signal containing the usernames and MAC addresses corresponding to those multiple terminals. In another variation, if there are multiple terminals where the second distance is smaller than the first distance, the printer 10 may select the terminal with the smallest second distance from among the multiple terminals and send a fifth Publish signal including the username and MAC address corresponding to the selected terminal.
[0093] Steps T632 to T640 are the same as steps T322 to T330 in Figure 7. Subsequently, the same processes as those in steps T340 to T350 in Figure 7, T52 to T56 in Figure 3, and T60 to T86 in Figure 4 are executed between terminal 100A, printer 10, authentication server 200, connection server 300, and SP server 400. In this case, verification information VE6 and signature information SI6 are used.
[0094] As described above, the printer 10 selects terminal 100A from among multiple terminals 100A to 100C whose second distance is less than the first distance, and sends a fifth Publish signal to the selected terminal 100A. Users using terminals where the second distance is less than the first distance are likely to want to perform FIDO authentication. With the above configuration, FIDO authentication can be performed using terminals used by users who are likely to want to perform FIDO authentication.
[0095] (Correspondence) The fifth Publish signal is an example of the "first search signal".
[0096] Although specific examples of the present invention have been described in detail above, these are merely illustrative and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes to the specific examples illustrated above. Modifications of the above embodiments are listed below.
[0097] (First variation) The term "communication device" is not limited to a printer, but may also refer to a scanner, multifunction device, etc.
[0098] (Second variation) "Authentication device information" is not limited to MAC addresses, but may also include contact ID, link ID, etc.
[0099] (Third Modification) The BT communication method and BTI / F20 may be examples of the "first communication method" and "first communication interface," respectively. Assume an initial state similar to that of Case C in Figure 7. In this case, the same processing as T310 to T350 is performed, except for T320, T328, and T340 in Figure 7. In this modification, BT communication is performed instead of Wi-Fi Aware communication at T320, T328, and T340. In this modification, the printer 10 may measure the distance between the printer 10 and the terminal using the received radio wave strength, as in the second and third embodiments.
[0100] (Fourth Modification) Printer 10 and terminals 100A to 100C may further be equipped with an NFCI / F. The NFCI / F is an interface for performing wireless communication according to the NFC method. Hereinafter, wireless communication according to the NFC method will be referred to as "NFC communication". The NFC method is a wireless communication method for so-called short-range wireless communication, and is a wireless communication method based on international standards such as ISO / IEC 21481 or 18092. The communication speed of NFC communication (e.g., a maximum communication speed of 424kbps) is usually slower than the communication speed of Wi-Fi communication. The carrier frequency in NFC communication is 13.56MHz. The maximum distance over which NFC communication can be performed (e.g., about 10cm) is shorter than the maximum distance over which Wi-Fi communication can be performed. In other words, NFC communication is so-called short-range wireless communication.
[0101] NFC communication method and NFCI / F may be examples of the "first communication method" and "first communication interface," respectively. Assume an initial state similar to Case C in Figure 7. In this case, once an NFC connection is established between the printer 10 and the terminal 100A, the same processing as T310 to T350 is performed, except for T320, T328, and T340 in Figure 7. In this modified example, NFC communication is performed instead of Wi-Fi Aware communication in T320, T328, and T340.
[0102] (Fourth Modification) The first Publish signal may be a signal transmitted to all devices participating in the same NAN cluster as the printer 10. That is, the first Publish signal in this modification is not a signal transmitted to devices whose distance from the printer 10 is less than a first predetermined distance. In this modification, the printer 10 does not transmit the second Publish signal even if the first response signal is not received after the first Publish signal has been transmitted. In this modification, the "second search signal transmission unit" and the "second response signal reception unit" can be omitted.
[0103] (Sixth Modification) In the first embodiment, the printer 10 does not need to transmit a second Publish signal if a first response signal is not received after a first Publish signal has been transmitted. In this modification, the "second search signal transmission unit" and the "second response signal receiving unit" can be omitted.
[0104] (Seventh Modification) In case C of Figure 7, printer 10 may receive an advertisement signal including "nonce" from terminal 100A via BTI / F20 at T340.
[0105] (Eighth Modification) Printer 10 does not need to be equipped with BTI / F20. In this modification, terminal 100A encrypts the websocket information after T32 in Figure 3 and generates a Wi-Fi Aware Pairing according to the Wi-Fi Aware method. Then, terminal 100A sends the Wi-Fi Aware Pairing to printer 10 via Wi-FiI / F22 using Wi-Fi Aware communication. Then, printer 10 obtains the websocket information by decrypting the Wi-Fi Aware Pairing using stored key information. Similarly, terminal 100B encrypts the websocket information after T144 in Figure 5 and generates a Wi-Fi Aware Pairing.
[0106] (9th Modification) Printer 10 sends a service start request including the service URL and the identified token to SP server 400 at T80 in Figure 4. In this modification, printer 10 may send the service URL and token to terminal 100A. In this modification, after receiving the service URL and token from printer 10, terminal 100A sends a service start request including the service URL and token to SP server 400 and receives service screen data from SP server 400 without going through printer 10.
[0107] (Tenth Modification) In the second embodiment, the printer 10 selects the terminal with the shortest distance from the printer 10 after the distance measurement process is performed. In the modification, the printer 10 may identify up to the M (where M is an integer greater than or equal to 2) terminals that are at a distance from the printer 10. In this modification, the third Pulbish signal contains M "username, MAC address" entries. Note that "M" may be a fixed value or a value that changes depending on the number of terminals participating in the same NAN cluster as the printer 10. For example, "M" may be half the number of terminals participating in the same NAN cluster as the printer 10.
[0108] (11th Modification) In the above embodiment, the processes shown in Figures 3 to 10 are implemented by software (for example, programs 40, 140, and 142), but at least one of these processes may be implemented by hardware such as a logic circuit.
[0109] Furthermore, the technical elements described herein or in the drawings demonstrate technical usefulness individually or in various combinations, and are not limited to the combinations described in the claims at the time of filing. In addition, the technologies illustrated herein or in the drawings achieve multiple objectives simultaneously, and achieving even one of these objectives constitutes technical usefulness in itself.
[0110] Even if, in the claims of this patent application, each claim depends on only some of the claims, it is not limited to the claim being dependent only on those specific claims. To the extent that it is not technically contradictory, each claim may be dependent on other claims that were not dependent at the time of application. That is, the technologies of each claim can be combined in various ways as follows: (Item 1) A communication device, A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, A memory configured to store, in association with each of the multiple authenticators, authenticator information related to the authenticator and communication information related to encrypted communication using the second communication interface between the authenticator and the communication device, A first search signal transmission unit transmits a first search signal via the first communication interface, which includes at least one authenticator information from among a plurality of authenticator information in the memory, when an authentication start instruction is obtained. A first response signal receiving unit receives a first response signal containing the first authenticator information from a first authenticator associated with the first authenticator information included in the at least one authenticator information via the first communication interface in response to the transmission of the first search signal, An authentication execution instruction transmitting unit, which, upon receiving the first response signal, performs the encrypted communication using the first communication information stored in association with the first authenticator information via the second communication interface and transmits an authentication execution instruction to the first authenticator, wherein the authentication execution instruction is information for instructing the execution of authentication in accordance with a predetermined authentication method using a pair of keys and biometric authentication information, A communication device equipped with the following features. (Item 2) The first communication method described above is a method that conforms to the Wi-Fi Aware method of the Wi-Fi standard, as described in item 1. (Item 3) The first search signal is a signal targeting authenticators whose distance from the communication device is less than a first predetermined distance, and the communication device includes the information of the plurality of authenticators as described in item 2. (Item 4) The aforementioned communication device further, A second search signal transmitting unit transmits a second search signal containing the information of a plurality of authenticators via the first communication interface when no response signals are received after the first search signal has been transmitted, wherein the second search signal is a signal targeting authenticators whose distance from the communication device is less than a second predetermined distance greater than the first predetermined distance, The system includes a second response signal receiving unit that, in response to the transmission of the second search signal, receives a second response signal containing the second authenticator information from a second authenticator associated with the second authenticator information included in the plurality of authenticator information, The communication device according to item 3, wherein the authentication execution instruction transmission unit, when it receives the second response signal from the second authenticator, performs the encrypted communication using the second communication information stored in association with the second authenticator information via the second communication interface and transmits the authentication execution instruction to the second authenticator. (Item 5) The aforementioned communication device further, The device includes a measuring unit that measures the distance between the communication device and each of the N authenticators (N being an integer of 2 or more) according to the first communication method described above. The communication device according to any one of items 2 to 4, wherein the first search signal transmitting unit selects the first authenticator that is closest to the communication device from among the N authenticators, and transmits the first search signal containing the first authenticator information to the selected first authenticator. (Item 6) The aforementioned communication device further, A first measuring unit measures a first distance between the communication device and each of the N authenticators (where N is an integer of 2 or more) according to the first communication method described above, The system includes a second measuring unit that measures a second distance between the communication device and each of the N authenticators when a predetermined time has elapsed since the first distance between the communication device and each of the N authenticators was measured, The communication device according to any one of items 2 to 5, wherein the first search signal transmitting unit selects a first authenticator from among the N authenticators whose second distance is less than the first distance, and transmits the first search signal including the first authenticator information to the selected first authenticator. (Item 7) The aforementioned communication device further, A third communication interface that operates according to a third communication method different from the second communication method, When a registration instruction is obtained, the system includes a communication information receiving unit that receives third communication information from the first authenticator via the third communication interface. The authentication execution instruction transmission unit, When the registration instruction is obtained and the third communication information is received from the first authenticator, the encrypted communication using the third communication information is performed via the second communication interface, and the authentication execution instruction is sent to the first authenticator. A communication device according to any one of items 1 to 6, which, when the authentication start instruction is obtained and the first response signal is received, performs the encrypted communication using the first communication information in the memory and transmits the authentication execution instruction to the first authenticator, without performing communication with the first authenticator via the third communication interface. (Item 8) A communication device as described in any one of items 1 to 6, wherein the first communication interface and the second communication interface are physically a single interface. (Item 9) A computer program for a communication device, The aforementioned communication device is A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, A memory configured to store, in association with each of the multiple authenticators, authenticator information related to the authenticator and communication information related to encrypted communication using the second communication interface between the authenticator and the communication device, Equipped with a computer, The aforementioned computer program controls the computer, A first search signal transmission unit transmits a first search signal via the first communication interface, which includes at least one authenticator information from among a plurality of authenticator information in the memory, when an authentication start instruction is obtained. A first response signal receiving unit receives a first response signal containing the first authenticator information from a first authenticator associated with the first authenticator information included in the at least one authenticator information via the first communication interface in response to the transmission of the first search signal, An authentication execution instruction transmitting unit, which, upon receiving the first response signal, performs the encrypted communication using the first communication information stored in association with the first authenticator information via the second communication interface and transmits an authentication execution instruction to the first authenticator, wherein the authentication execution instruction is information for instructing the execution of authentication in accordance with a predetermined authentication method using a pair of keys and biometric authentication information, A computer program that functions as such. (Item 10) A method performed by a communication device, The aforementioned communication device is A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, The system includes a memory configured to store, in association with each of the multiple authenticators, authenticator information related to the authenticator and communication information related to encrypted communication between the authenticator and the communication device using the second communication interface. The aforementioned method, A first search signal transmission step, in which, when an authentication start instruction is obtained, a first search signal is transmitted via the first communication interface, which includes at least one authenticator information from among a plurality of authenticator information in the memory; A first response signal receiving step, in response to the transmission of the first search signal, receiving a first response signal including the first authenticator information from a first authenticator associated with the first authenticator information included in the at least one authenticator information via the first communication interface; An authentication execution instruction transmission step, in which, when the first response signal is received, the encrypted communication is performed via the second communication interface using the first communication information stored in association with the first authenticator information, and an authentication execution instruction is sent to the first authenticator, wherein the authentication execution instruction is information for instructing the execution of authentication in accordance with a predetermined authentication method using a pair of keys and biometric authentication information, A method that includes [a certain feature]. [Explanation of Symbols]
[0111] 2: Communication system, 6: Internet, 10: Printer, 12: Operation unit, 16: Print execution unit, 20: BTI / F, 22: Wi-Fi I / F, 30: Control unit, 32: CPU, 34: Memory, 40: Program, 42: Authentication-related table, 100A: Terminal, 100B: Terminal, 100C: Terminal, 112: Operation unit, 114: Display unit, 120: BTI / F, 122: Wi-Fi I / F, 124: Camera, 130: Control unit, 132: CPU, 134: Memory, 140: OS program, 142: Authentication application, 144: Biometric authentication information, 200: Authentication server, 234: Memory, 240: Management table, 300: Connection server, 400: SP server
Claims
1. A communication device, A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, A memory configured to store, in association with each of the multiple authenticators, authenticator information related to the authenticator and communication information related to encrypted communication using the second communication interface between the authenticator and the communication device, A first search signal transmission unit transmits a first search signal via the first communication interface, which includes at least one authenticator information from among a plurality of authenticator information in the memory, when an authentication start instruction is obtained. A first response signal receiving unit receives a first response signal including the first authenticator information from a first authenticator associated with the first authenticator information included in the at least one authenticator information via the first communication interface in response to the transmission of the first search signal, An authentication execution instruction transmitting unit, which, when the first response signal is received, performs the encrypted communication using the first communication information stored in association with the first authenticator information via the second communication interface and transmits an authentication execution instruction to the first authenticator, wherein the authentication execution instruction is information for instructing the execution of authentication in accordance with a predetermined authentication method using a pair of keys and biometric authentication information, A communication device equipped with the following features.
2. The communication device according to claim 1, wherein the first communication method is a method that conforms to the Wi-Fi Aware method of the Wi-Fi standard.
3. The communication device according to claim 2, wherein the first search signal is a signal targeting authenticators whose distance from the communication device is less than a first predetermined distance, and includes information on the plurality of authenticators.
4. The aforementioned communication device further, A second search signal transmitting unit transmits a second search signal containing the information of a plurality of authenticators via the first communication interface when no response signals are received after the first search signal has been transmitted, wherein the second search signal is a signal targeting authenticators whose distance from the communication device is less than a second predetermined distance greater than the first predetermined distance, The system includes a second response signal receiving unit that, in response to the transmission of the second search signal, receives a second response signal containing the second authenticator information from a second authenticator associated with the second authenticator information included in the plurality of authenticator information, The communication device according to claim 3, wherein when the authentication execution instruction transmission unit receives the second response signal from the second authenticator, it performs the encrypted communication using the second communication information stored in association with the second authenticator information via the second communication interface and transmits the authentication execution instruction to the second authenticator.
5. The aforementioned communication device further, The device includes a measuring unit that measures the distance between the communication device and each of the N authenticators (where N is an integer of 2 or more) according to the first communication method described above. The communication device according to claim 2, wherein the first search signal transmitting unit selects the first authenticator that is closest to the communication device from among the N authenticators, and transmits the first search signal including the first authenticator information to the selected first authenticator.
6. The aforementioned communication device further, A first measuring unit measures a first distance between the communication device and each of the N authenticators (where N is an integer of 2 or more) according to the first communication method, The system includes a second measuring unit that measures a second distance between the communication device and each of the N authenticators when a predetermined time has elapsed since the first distance between the communication device and each of the N authenticators was measured, The communication device according to claim 2, wherein the first search signal transmitting unit selects a first authenticator from among the N authenticators whose second distance is less than the first distance, and transmits the first search signal including the first authenticator information to the selected first authenticator.
7. The aforementioned communication device further, A third communication interface that operates according to a third communication method different from the second communication method described above, When a registration instruction is obtained, the system includes a communication information receiving unit that receives third communication information from the first authenticator via the third communication interface. The authentication execution instruction transmission unit, When the registration instruction is obtained and the third communication information is received from the first authenticator, the encrypted communication using the third communication information is executed via the second communication interface, and the authentication execution instruction is sent to the first authenticator. The communication device according to claim 1, wherein, when the authentication start instruction is obtained and the first response signal is received, the encrypted communication using the first communication information in the memory is performed and the authentication execution instruction is sent to the first authenticator, without performing communication with the first authenticator via the third communication interface.
8. The communication device according to claim 1, wherein the first communication interface and the second communication interface are physically a single interface.
9. A computer program for a communication device, The aforementioned communication device is A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, A memory configured to store, in association with each of the multiple authenticators, authenticator information related to the authenticator and communication information related to encrypted communication using the second communication interface between the authenticator and the communication device, Equipped with a computer, The aforementioned computer program controls the computer, A first search signal transmission unit transmits a first search signal via the first communication interface, which includes at least one authenticator information from among a plurality of authenticator information in the memory, when an authentication start instruction is obtained. A first response signal receiving unit receives a first response signal including the first authenticator information from a first authenticator associated with the first authenticator information included in the at least one authenticator information via the first communication interface in response to the transmission of the first search signal, An authentication execution instruction transmitting unit, which, when the first response signal is received, performs the encrypted communication using the first communication information stored in association with the first authenticator information via the second communication interface and transmits an authentication execution instruction to the first authenticator, wherein the authentication execution instruction is information for instructing the execution of authentication in accordance with a predetermined authentication method using a pair of keys and biometric authentication information, A computer program that functions as such.
10. A method performed by a communication device, The aforementioned communication device is A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, The system includes a memory configured to store, in association with each of the multiple authenticators, authenticator information related to the authenticator and communication information related to encrypted communication between the authenticator and the communication device using the second communication interface. The aforementioned method, A first search signal transmission step, in which, when an authentication start instruction is obtained, a first search signal is transmitted via the first communication interface, which includes at least one authenticator information from among a plurality of authenticator information in the memory; A first response signal receiving step, in response to the transmission of the first search signal, receiving a first response signal including the first authenticator information from a first authenticator associated with the first authenticator information included in the at least one authenticator information via the first communication interface, An authentication execution instruction transmission step, in which, when the first response signal is received, the encrypted communication is performed via the second communication interface using the first communication information stored in association with the first authenticator information, and an authentication execution instruction is sent to the first authenticator, wherein the authentication execution instruction is information for instructing the execution of authentication in accordance with a predetermined authentication method using a pair of keys and biometric authentication information, A method that includes [a certain feature].