Communication device, computer program for communication device, and method performed by communication device
The communication device integrates NFC, Bluetooth, and Wi-Fi interfaces to enhance biometric authentication in FIDO systems, offering secure and convenient authentication options through QR codes or NFC, addressing inefficiencies in existing methods.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- BROTHER KOGYO KK
- Filing Date
- 2024-10-30
- Publication Date
- 2026-05-15
AI Technical Summary
Existing authentication methods lack efficient integration of biometric authentication with key-based systems, particularly in communication devices, leading to inefficiencies and reduced user convenience.
A communication device equipped with multiple interfaces (NFC, Bluetooth, and Wi-Fi) facilitates biometric authentication using a FIDO method, enabling encrypted communication and authentication execution instructions, allowing seamless key and biometric authentication through QR codes or NFC, enhancing user convenience and security.
The solution provides secure and user-friendly authentication processes, reducing processing load and improving convenience by allowing users to choose between NFC and QR code methods, ensuring efficient and reliable authentication.
Smart Images

Figure 2026079547000001_ABST
Abstract
Description
Technical Field
[0004] , , , ,
[0005] , , , , ,
[0003] , ,
[0001] This specification discloses a technology related to a predetermined authentication method using a pair of keys and biometric authentication information.
Background Art
[0002] Patent Document 1 discloses a system including an image processing device, a terminal device, a FIDO server, and a cloud server. The image processing device displays an encoded image. The terminal device reads the encoded image and transmits advertising to the image processing device. A BLE connection is established between the terminal device and the image processing device, and when biometric authentication is successful, CTAP communication is executed between the terminal device and the image processing device. The image processing device transmits an authentication request to the FIDO server.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] This specification provides a novel and useful technology for performing authentication according to a predetermined authentication method using a pair of keys and biometric authentication information.
Means for Solving the Problems
[0005] This specification discloses a communication device. The communication device includes a first communication interface that operates according to a first communication method, a second communication interface that operates according to a second communication method different from the first communication method, an authentication request transmission unit that transmits an authentication request to a server via the second communication interface when an authentication start instruction is obtained, a response receiving unit that receives a response to the authentication request from the server via the second communication interface in response to the authentication request being transmitted to the server, and when the response is received from the server, transmits first communication-related information to an authenticator via the first communication interface. The device may also include: a first communication-related information transmission unit, wherein the first communication-related information is information for performing encrypted communication between the communication device and the authenticator using the second communication interface; and an authentication execution instruction transmission unit, which, after the first communication-related information has been transmitted to the authenticator, transmits an authentication execution instruction to the authenticator via the second communication interface using the encrypted communication, wherein the authentication execution instruction is information for instructing the authenticator to perform authentication in accordance with a predetermined authentication method using a pair of keys and biometric authentication information.
[0006] According to the above configuration, when the communication device receives a response to an authentication request from the server, it transmits first communication-related information to the authenticator via the first communication interface. After transmitting the first communication-related information to the authenticator, the communication device transmits an authentication execution instruction to the authenticator via the second communication interface using encrypted communication. Therefore, in response to the transmission of the first communication-related information to the authenticator via the first communication interface, authentication can be performed according to a predetermined authentication method that utilizes a pair of keys and biometric authentication information.
[0007] The computer program for the above-mentioned communication device, the computer-readable recording medium for storing the computer program, and the method executed by the communication device are also novel and useful. Furthermore, the communication system including the communication device, authenticator, and server is also novel and useful. Here, the above-mentioned recording medium may be a single medium or multiple mediums. [Brief explanation of the drawing]
[0008] [Figure 1] This shows the configuration of the communication system. [Figure 2] This is a sequence diagram for Case A, where FIDO authentication is performed. [Figure 3] This is a continuation of Figure 2. [Figure 4] This is a sequence diagram for Case B, where FIDO authentication is performed. [Figure 5] This is a continuation of Figure 4. [Figure 6] This is a sequence diagram for Case C, where FIDO authentication is performed. [Figure 7] This is a sequence diagram for Case D, where FIDO authentication is performed. [Modes for carrying out the invention]
[0009] (First embodiment) (Configuration of communication system 2; Figure 1) As shown in Figure 1, the communication system 2 comprises a printer 10, a terminal 100, a PC 200, an authentication server 300, a connection server 400, and a service provider server 500. Hereafter, the service provider server will be referred to as the "SP server." The printer 10, terminal 100, PC 200, authentication server 300, connection server 400, and SP server 500 are connected to the Internet 6. The printer 10, terminal 100, PC 200, authentication server 300, connection server 400, and SP server 500 can communicate with each other via the Internet 6.
[0010] (Printer 10 configuration) Printer 10 is a peripheral device (for example, a peripheral device of PC200) capable of performing printing functions. Printer 10 can operate according to the Fast Identity Online (FIDO) authentication method, which uses a pair of keys and biometric authentication information. The FIDO authentication method is an authentication method that uses a pair of keys, namely a private key and a public key. Hereafter, the private key and public key will be referred to as the "private key for server authentication" and the "public key for server authentication," respectively. Furthermore, the FIDO authentication method is an authentication method that uses biometric authentication information (for example, fingerprint authentication information, voiceprint authentication information, facial authentication information) to authenticate users instead of using password authentication. Hereafter, authentication according to the FIDO authentication method will be referred to as "FIDO authentication."
[0011] The printer 10 comprises an operation unit 12, a print execution unit 16, an NFCI / F 18, a BTI / F 20, a Wi-Fi I / F 22, and a control unit 30. Hereafter, interfaces will be referred to as "I / F". BT is an abbreviation for "Bluetooth". Bluetooth is a registered trademark of Bluetooth SIG.
[0012] The control unit 12 is a user interface that allows the user to input various information to the printer 10. The control unit 12 includes, for example, hardware keys. Hardware keys include, for example, buttons or switches.
[0013] The printing execution unit 16 includes an electrophotographic, inkjet, or thermal printing engine. An inkjet printing engine includes a print head that ejects ink droplets. An electrophotographic printing engine includes a photoreceptor and an exposure device that emits light to expose the photoreceptor. A thermal printing engine includes a print head that generates heat using a heater.
[0014] NFCI / F18 is an interface for performing wireless communication according to the NFC method. Hereafter, wireless communication according to the NFC method will be referred to as "NFC communication." The NFC method is a wireless communication method for so-called short-range wireless communication, and is a wireless communication method based on international standards such as ISO / IEC 21481 or 18092.
[0015] The BTI / F20 is an interface for performing wireless communication in accordance with the BT standard. Hereafter, wireless communication in accordance with the BT standard will be referred to as "BT communication." The BT standard includes, for example, the IEEE 802.15.1 standard and equivalent standards. More specifically, the BTI / F20 supports Bluetooth Low Energy (BLE). BLE is implemented in BT standard version 4.0 and later.
[0016] The Wi-Fi I / F22 is a wireless interface for performing wireless communication in accordance with the Wi-Fi standard. The Wi-Fi standard is a wireless communication standard for performing wireless communication in accordance with the 802.11 standard and equivalent standards, such as 802.11a, 11b, 11n, and 11ac, from, for example, The Institute of Electrical and Electronics Engineers, Inc. (IEEE). The Wi-Fi I / F22 can perform wireless communication in accordance with the standard Wi-Fi method. For example, wireless communication in accordance with the standard Wi-Fi method is wireless communication using an AP (not shown in the diagram). Hereafter, wireless communication in accordance with the standard Wi-Fi standard will be referred to as "standard Wi-Fi communication".
[0017] Here, the differences between normal Wi-Fi communication, BT communication, and NFC communication will be described. The communication speeds of each communication are, in order, the communication speed of normal Wi-Fi communication (for example, the maximum communication speed is 600 Mbps), the communication speed of BT communication (for example, the maximum communication speed is 24 Mbps), and the communication speed of NFC communication (for example, the maximum communication speed is 424 kbps), with normal Wi-Fi communication being the fastest. The carrier frequencies in each communication are such that the carrier frequency in normal Wi-Fi communication is in the 2.4 GHz band or the 5.0 GHz band, the carrier frequency in BT communication is in the 2.4 GHz band, and the carrier frequency in NFC communication is 13.56 MHz. That is, when the 5.0 GHz band is adopted as the carrier frequency in normal Wi-Fi communication, the carrier frequencies in each communication are different from each other. Also, the maximum distances at which each communication can be executed are, in order, the maximum distance at which normal Wi-Fi communication can be executed (for example, 100 m), the maximum distance at which BT communication can be executed (for example, about several tens of meters), and the maximum distance at which NFC communication can be executed (for example, about 10 cm), with BT communication and NFC communication being so-called short-range wireless communications.
[0018] The control unit 30 includes a CPU 32 and a memory 34. The memory 34 includes a main storage device and an auxiliary storage device. As an example, the main storage device includes a RAM and a cache memory. As an example, the auxiliary storage device may be a ROM, a flash memory, a Solid State Drive (SSD), a Hard Disk Drive (HDD), or a combination thereof. A program 40 is stored in the auxiliary storage device of the memory 34. The CPU 32 realizes various processes according to the program loaded from the auxiliary storage device to the main storage device.
[0019] (Configuration of the terminal 100) The terminal 100 is a portable terminal device such as a mobile phone, a smartphone, a PDA, or a tablet PC. The terminal 100 is operable according to the FIDO authentication method. The terminal 100 operates as a so-called authenticator in the FIDO authentication method.
[0020] The operation unit 112 is a user interface that allows the user to input various information to the terminal 100. The operation unit 112 includes, for example, a touch panel, hardware keys, or both for displaying software keys (operation areas). Hardware keys include, for example, buttons or switches. The display unit 114 is a display or panel for displaying various information and various screens described later. The display is, for example, a liquid crystal display or an organic EL display. The panel may or may not be a touch panel. The panel is, for example, a liquid crystal panel or an organic EL panel.
[0021] The NFCI / F118 has the same configuration as the NFCI / F18 of printer 10. The BTI / F120 has the same configuration as the BTI / F20 of printer 10. The Wi-FiI / F122 has the same configuration as the Wi-FiI / F22 of printer 10.
[0022] Camera 124 is a device for photographing objects. In this embodiment, camera 124 is used to photograph a QR code. QR Code is a registered trademark of DENSO WAVE INCORPORATED.
[0023] The control unit 130 comprises a CPU 132 and a memory 134. The memory 134 comprises a main memory and an auxiliary memory. The auxiliary memory of the memory 134 stores an Operating System (OS) program 140, an authentication application 142, and biometric authentication information 144. The OS program 140 controls the basic operation of the terminal 100. The authentication application 142 is a program that makes the terminal 100 operate as an authenticator for FIDO authentication. The CPU 132 performs various processes according to the program loaded from the auxiliary memory to the main memory. The biometric authentication information 144 is the fingerprint information of the user using the terminal 100. The biometric authentication information 144 is used in FIDO authentication. The auxiliary memory of the memory 134 may store the username "Yamada" and the server authentication secret key PRK1. The username "Yamada" and the server authentication secret key PRK1 are registered when a registration process is executed to register a pair of keys used for FIDO authentication.
[0024] (PC200 configuration) PC200 refers to PCs such as desktop PCs, notebook PCs, and tablet PCs. PC200 is used by users of terminal 100. PC200 can operate according to the FIDO authentication method.
[0025] (Each server has a configuration of 300, 400, and 500 units) Each of the servers 300, 400, and 500 is a server installed on the Internet 6. Each of the servers 300, 400, and 500 is a server provided by, for example, the vendor of printer 10. In a modified version, each of the servers 300, 400, and 500 may be installed on the Internet 6 by a different operator than the vendor. In another modified version, the vendor may not prepare the hardware for each of the servers 300, 400, and 500 themselves, but may use an environment provided by an external cloud computing service. In this case, the vendor may prepare the programs (i.e., software) for each of the servers 300, 400, and 500 and implement them in the above environment to realize each of the servers 300, 400, and 500.
[0026] The authentication server 300 can operate according to the FIDO authentication scheme. The authentication server 300 operates as a so-called authentication server in the FIDO authentication scheme. The memory 334 of the authentication server 300 stores the management table 340. The management table 340 stores the username and the public key for server authentication in association with each other. The username and the public key for server authentication in the management table 340 are registered in the management table 340 when the registration process for registering the pair of keys used for FIDO authentication is executed.
[0027] The connection server 400 mediates communication between the printer 10 and the terminal 100. The connection server 400 is a server that provides tunnel services.
[0028] The SP server 500 provides services related to the printer 10. For example, the SP server 500 provides remote operation services and printing services. The remote operation service is a service that allows the user to operate the printer 10 via the SP server 500 using a terminal. The printing service is a service that mediates the transmission of print data from the terminal to the printer 10. For example, the SP server 500 stores the print data received from the terminal (upload process) and, when it receives a download request for the print data from the printer 10, sends the print data to the printer 10 (download process).
[0029] (Specific cases) Referring to Figures 2 to 5, a specific case realized by the communication system 2 of this embodiment will be described. In the following, each device (e.g., printer 10) will be described as the main focus, rather than the CPU of each device (e.g., the CPU 32 of printer 10). Also, in order to make it easier to understand the types of communication used between each device, Wi-Fi communication is usually shown with a thin solid line, BT communication with a thin dashed line, and NFC communication with a thick solid line.
[0030] (Case A; Figures 2 and 3) Refer to Figures 2 and 3 to explain Case A. In Case A, a pair of keys used for FIDO authentication are registered. That is, the registration process is executed.
[0031] At T10, the user performs a registration operation on PC200. The registration operation is an operation to request the registration of a pair of keys used for FIDO authentication. The registration operation includes entering the username "Yamada". As a result, at T12, PC200 sends a first authentication request including the username "Yamada" to authentication server 300.
[0032] When the authentication server 300 receives the first authentication request from the PC 200 at T12, it generates verification information VE1 at T14 and stores the verification information VE1. At T16, the authentication server 300 sends a first response signal containing the verification information VE1 to the PC 200.
[0033] When PC200 receives the first response signal from the authentication server 300 at T16, it displays a confirmation screen at T18. The confirmation screen is for confirming whether or not to perform authentication using a QR code. Hereafter, authentication using a QR code will be referred to as "QR code authentication".
[0034] At T20, the user performs a QR code authentication selection operation on PC200 to select QR code authentication. This causes PC200 to generate a public key for encrypted communication, key information, and domain information. The public key for encrypted communication is information used in the encrypted communication process described later. The key information is information used for encrypting and decrypting the advertised signal. The domain information is information that PC200 knows about the tunnel service and also indicates the domain of the server providing the tunnel service. PC200 stores the public key for encrypted communication, key information, and domain information. At T22, PC200 generates a QR code obtained by encoding the public key for encrypted communication, key information, and domain information, and at T24, displays the generated QR code.
[0035] At T30, the user uses the camera 124 of terminal 100 to photograph the QR code displayed on PC 200. At T32, terminal 100 decodes the photographed QR code to obtain the public key for encrypted communication, key information, and domain information. Terminal 100 generates websocket information using the obtained information and stores the websocket information in memory 134. The websocket information includes a tunnel ID, a root ID, and a tunnel service identifier. The tunnel ID and root ID are information used in the tunnel service. The tunnel service identifier is information determined using the domain information. The tunnel service identifier is information indicating the server providing the tunnel service to be used, i.e., the connecting server 400. At T34, terminal 100 encrypts the generated websocket information using the obtained key information and generates an advertisement signal. At T36, terminal 100 sends the advertisement signal to PC 200 via BTI / F120.
[0036] At T36, when PC200 receives an advertisement signal from terminal 100, at T38, it decrypts the advertisement signal using stored key information. As a result, PC200 obtains the websocket information generated by terminal 100. Next, PC200 determines that it has obtained the websocket information from terminal 100 and terminates the display of the QR code at T40. At T50, a first encrypted communication process is executed to perform encrypted communication between terminal 100, PC200, and connection server 400. The first encrypted communication process includes a first connection process in which terminal 100 connects to connection server 400, a second connection process in which PC200 connects to connection server 400, and a first handshake process in which a handshake is performed between terminal 100 and PC200. In the first connection process, the tunnel service identifier is used. In the second connection process, the websocket information is used. In the first handshake process, the public key for encrypted communication (see T22) contained in the QR code is used. This establishes a WebSocket connection between terminal 100 and PC 200. Terminal 100 can then perform encrypted communication with PC 200 via the connection server 400.
[0037] At T60 in Figure 3, PC200 uses encrypted communication to send an authentication execution instruction to terminal 100, which includes the acquired verification information VE1 (see T16 in Figure 2) and the acquired username "Yamada" (see T10 in Figure 2). The authentication execution instruction is a signal to instruct the execution of biometric authentication.
[0038] When terminal 100 receives an authentication execution instruction from PC 200 via Wi-Fi I / F 122 using encrypted communication at T60, it displays a fingerprint authentication screen on the display unit 114 at T62. The fingerprint authentication screen displays a message requesting the execution of fingerprint authentication. The user performs a fingerprint authentication operation on terminal 100 at T64. Terminal 100 determines that fingerprint authentication is successful because the fingerprint information obtained by the fingerprint authentication operation matches the biometric authentication information 144 in memory 134. In this case, terminal 100 generates a server authentication private key PRK1 and a server authentication public key PUK1 at T66, and stores the server authentication private key PRK1 and the username "Yamada" in memory 134 at T68. The server authentication private key PRK1 and the server authentication public key PUK1 are a pair of keys used for FIDO authentication. Terminal 100, using encrypted communication via Wi-Fi I / F122 on T70, sends a first authentication response to PC200, which includes the server authentication public key PUK1.
[0039] When PC200 receives the first authentication response from terminal 100 using encrypted communication at T70, it sends the first authentication response to authentication server 300 at T72.
[0040] When the authentication server 300 receives the first authentication response from PC200 at T72, at T74, it associates and stores the server authentication public key PUK1 included in the first authentication response with the received username "Yamada" (see T12 in Figure 2). This completes the registration of the pair of keys used for FIDO authentication. At T76, the authentication server 300 sends the registration completion screen data to PC200.
[0041] When PC200 receives registration completion screen data from authentication server 300 at T76, it displays the registration completion screen represented by the registration completion screen data at T78. This allows the user to know that the registration of the pair of keys used for FIDO authentication has been completed.
[0042] (Case B; Figures 4 and 5) Case B will be explained with reference to Figures 4 and 5. In Case B, the remote operation service is provided upon successful FIDO authentication. Case B is the state after Case A in Figures 2 and 3. Specifically, the memory 134 of terminal 100 stores the server authentication private key PRK1 and the username "Yamada" in association. The authentication server 300 also stores the server authentication public key PUK1 and the username "Yamada" in association.
[0043] At T110, the user brings terminal 100 close to printer 10. As a result, at T112, an NFC connection is established between printer 10 and terminal 100.
[0044] When printer 10 establishes an NFC connection with terminal 100 at T112, it determines that it has received an authentication start instruction and, at T114, sends a second authentication request to authentication server 300 via Wi-Fi I / F 22.
[0045] When the authentication server 300 receives a second authentication request from the printer 10 at T114, it generates verification information VE2 at T116 and stores the verification information VE2. At T118, the authentication server 300 sends a second response signal containing the verification information VE2 to the printer 10.
[0046] When printer 10 receives a second response signal from authentication server 300 via Wi-Fi I / F22 at T118, it generates Passkey information at T120. Passkey information is a string of information including a public key for encrypted communication, key information, and domain information. The types of information included in the Passkey information are the same as the types of information included in a QR code. At T122, printer 10 supplies the generated Passkey information to NFCI / F18. As a result, at T124, printer 10's NFCI / F18 transmits the Passkey information to terminal 100 using NFC communication. That is, printer 10 transmits Passkey information to terminal 100 via NFCI / F18.
[0047] When terminal 100 receives Passkey information from printer 10 via NFCI / F118 at T124, it obtains the encrypted public key, key information, and domain information contained in the Passkey information. Similar to when a QR code is obtained, terminal 100 generates WebSocket information using the received information and stores the WebSocket information in memory 134. At T130, terminal 100 encrypts the generated WebSocket information using the obtained key information and generates an advertisement signal, and at T132, it sends the advertisement signal to printer 10 via BTI / F120.
[0048] At T132, when printer 10 receives an advertisement signal from terminal 100 via BTI / F20, at T134, it decrypts the advertisement signal using stored key information. As a result, printer 10 obtains the websocket information generated by terminal 100. At T140, a second encrypted communication process is performed between terminal 100, printer 10, and connection server 400. The second encrypted communication process includes a third connection process in which terminal 100 connects to connection server 400, a fourth connection process in which printer 10 connects to connection server 400, and a second handshake process in which a handshake is performed between terminal 100 and printer 10. In the third connection process, a tunnel service identifier is used. In the fourth connection process, websocket information is used. In the second handshake process, the public key for encrypted communication (see T120) contained in the Passkey information is used. As a result, a websocket connection is established between terminal 100 and printer 10. Then, terminal 100 can perform encrypted communication with printer 10 via connection server 400. Printer 10, at T150, uses encrypted communication via Wi-Fi I / F22 to send an authentication execution instruction to terminal 100, which includes the acquired verification information VE2 (see T118). As described above, printer 10 sends an authentication execution instruction to terminal 100 when it receives an advertisement signal from terminal 100 via BTI / F20. In this case, since BT communication is short-range wireless communication, printer 10 can know that terminal 100 is in close proximity to it. Therefore, printer 10 can appropriately determine terminal 100, which is in close proximity to it, as a device to perform FIDO authentication on.
[0049] When terminal 100 receives an authentication execution instruction from printer 10 via Wi-Fi I / F 122 using encrypted communication at T150, it displays a fingerprint authentication screen on display unit 114 at T152. The user performs a fingerprint authentication operation on terminal 100 at T154. Terminal 100 determines that fingerprint authentication was successful and generates signature information SI2 at T156 by encrypting the received verification information VE2 using the server authentication secret key PRK1 in memory 134. Terminal 100 also identifies the username "Yamada" in memory 134. At T160, terminal 100 sends a second authentication response to printer 10 via Wi-Fi I / F 122 using encrypted communication, containing the identified username "Yamada" and the generated signature information SI2.
[0050] When printer 10 receives a second authentication response from terminal 100 via Wi-Fi 22 using encrypted communication at T160, printer 10 sends the second authentication response to authentication server 300 via Wi-Fi 22 at T162.
[0051] When the authentication server 300 receives the second authentication response from the printer 10 at T162, it identifies the server authentication public key PUK1 stored in the management table 340 in association with the username "Yamada" in the second authentication response. The authentication server 300 uses the identified server authentication public key PUK1 to decrypt the signature information SI2 in the second authentication response. Since the server authentication private key PRK1 and the server authentication public key PUK1 are a pair of keys, the verification information VE2 is obtained by decrypting the signature information SI2 using the server authentication public key PUK1. The authentication server 300 determines that the obtained verification information VE2 matches the stored verification information VE2 (see T116 in Figure 4), and at T170 in Figure 5, it determines that FIDO authentication was successful. In this case, at T172, the authentication server 300 sends an authentication success notification including a token to the printer 10. The token is authentication information shared between the authentication server 300 and the SP server 500. If the authentication server 300 determines that FIDO authentication is unsuccessful, it sends an authentication failure notification to the printer 10 indicating that FIDO authentication has failed.
[0052] At T172, when printer 10 receives an authentication success notification from authentication server 300 via Wi-Fi I / F22, it identifies the token in the authentication success notification. At T180, printer 10 sends the service URL and the identified token to terminal 100 via NFCI / F18. The service URL is information indicating the location of SP server 500 on the internet 6.
[0053] When terminal 100 receives the service URL and token from printer 10 via NFCI / F118 at T180, it provides a service start request including the service URL and token to SP server 500 via Wi-FiI / F122 at T182.
[0054] When the SP server 500 receives a service start request from terminal 100 in T182, it sends service screen data to terminal 100 in T184. The SP server 500 also determines that the service start request contains a token and sends access detection information to printer 10 in T190.
[0055] When terminal 100 receives service screen data from SP server 500 via Wi-Fi I / F 122 at T184, it displays the service screen represented by the service screen data on display unit 114 at T186. The service screen is a screen for using the remote operation service. For example, the service screen displays an object corresponding to the operation unit 12 of printer 10. As described above, printer 10 sends a service URL to terminal 100 in response to successful FIDO authentication. Therefore, the user of terminal 100 can use the remote operation service in response to successful FIDO authentication. Thus, user convenience is improved.
[0056] When printer 10 receives access detection information from SP server 500 via Wi-Fi 22 at T190, it erases the Passkey information (see T120 in Figure 4) that has been generated at T192 and disconnects the NFC connection established between it and terminal 100.
[0057] Furthermore, if the printer 10 receives an authentication failure notification from the authentication server 300 after sending the second authentication response to the authentication server 300, it executes T192 without executing T180 to T190.
[0058] (Effects of this embodiment) As described above, when the printer 10 receives a second response signal from the authentication server 300 to the second authentication request (T118 in Figure 4), it transmits Passkey information to the terminal 100 via NFCI / F18 (T124). After transmitting the Passkey information to the terminal 100, the printer 10 transmits an authentication execution instruction to the authenticator via Wi-FiI / F22 using encrypted communication (T150). Therefore, FIDO authentication can be performed in response to the transmission of the public key for encrypted communication to the terminal 100 via NFCI / F18.
[0059] (Correspondence) Printer 10 is an example of a "communication device". NFC method and NFCI / F18 are examples of a "first communication method" and a "first communication interface", respectively. A communication method conforming to the Wi-Fi standard and Wi-FiI / F22 are examples of a "second communication method" and a "second communication interface", respectively. The second authentication request at T114 in Figure 4 is an example of an "authentication request". Authentication server 300 is an example of a "server". The second response signal at T118 in Figure 4 is an example of a "response to an authentication request". Passkey information is an example of "first communication-related information". Terminal 100 is an example of an "authentication device". FIDO authentication method is an example of a "predetermined authentication method". Server authentication private key PRK1 and server authentication public key PUK1 are examples of a "first private key" and a "first public key", respectively. The authentication success notification at T172 in Figure 5 is an example of "success information". T180 in Figure 5 is an example of a "predetermined process". The service URL is an example of "service information." BTI / F20 is an example of a "third communication interface." The advertised signal is an example of "second communication-related information."
[0060] T114 in Figure 4 is an example of the process performed by the "authentication request transmission unit". T118 in Figure 4 is an example of the process performed by the "response reception unit". T124 in Figure 4 is an example of the process performed by the "first communication-related information transmission unit". T150 in Figure 4 is an example of the process performed by the "authentication execution instruction transmission unit".
[0061] (Second example) A second embodiment will now be described. As shown in Figure 1, the printer 10 of the second embodiment includes a display unit 14. The display unit 14 is a display or panel for displaying various information. The display is, for example, a liquid crystal display or an organic EL display. The panel may or may not be a touch panel. The panel is, for example, a liquid crystal panel or an organic EL panel.
[0062] (Specific cases) Referring to Figures 6 and 7, a specific case realized by the communication system 2 of this embodiment will be described.
[0063] (Case C; Figure 6) Refer to Figure 6 to explain Case C. In Case C, the use of NFC communication is selected on the selection screen described later. The initial state of Case C is the same as the initial state of Case B in Figures 4 and 5.
[0064] At T210, the user performs an authentication start operation on the printer 10 to initiate FIDO authentication. The printer 10 then determines that it has received the authentication start instruction and, at T214, sends a second authentication request to the authentication server 300 via the Wi-Fi I / F 22. T216 and T218 are the same as T116 and T118 in Figure 4, respectively.
[0065] At T220, printer 10 generates Passkey information including the public key for encrypted communication, key information, and domain information, and stores the Passkey information in memory 34. At T222, printer 10 generates a QR code obtained by encoding the public key for encrypted communication, key information, and domain information, and stores the QR code in memory 34. At T230, printer 10 displays a selection screen on the display unit 14. The selection screen allows the user to choose whether to use NFC communication or a QR code. At T232, the user performs an NFC selection operation on printer 10 to select to use NFC communication. As a result, at T234, printer 10 supplies the generated Passkey information to NFCI / F18, and at T236, erases the QR code.
[0066] At T240, the user brings terminal 100 close to printer 10. This establishes an NFC connection between printer 10 and terminal 100 at T242. At T244, printer 10's NFCI / F18 uses NFC communication to send Passkey information to terminal 100. Subsequently, the same processes as those shown at T130-T162 in Figure 4 and T170-T192 in Figure 5 are performed between terminal 100, printer 10, authentication server 300, connection server 400, and SP server 500.
[0067] (Case D; Figure 7) Refer to Figure 7 to explain Case D. In Case D, the option to use a QR code is selected on the selection screen. The initial state of Case D is the same as the initial state of Case C in Figure 6.
[0068] T310, T314-T330 are the same as T210, T214-T230 in Figure 6. At T332, the user performs a QR code selection operation on the printer 10 to select the use of a QR code. As a result, at T334, the printer 10 displays the QR code on the display unit 14, and at T336, it erases the Passkey information.
[0069] At T340, the user uses the camera 124 of terminal 100 to photograph the QR code displayed on printer 10. At T342, terminal 100 decodes the photographed QR code to obtain the public key and key information for encrypted communication. Terminal 100 generates web socket information and stores the web socket information in memory 134. At T344, terminal 100 encrypts the generated web socket information using the obtained key information and generates an advertisement signal. At T346, terminal 100 sends the advertisement signal to printer 10 via BTI / F120. T348 and T350 are the same as T38 and T40 in Figure 2, respectively. Subsequently, the same processes as T130-T162 in Figure 4 and T170-T192 in Figure 5 are executed between terminal 100, printer 10, authentication server 300, connection server 400, and SP server 500.
[0070] If an NFC connection is established between the printer 10 and the terminal 100 without the printer 10 accepting an authentication start operation, the same processing as T114~T162 in Figure 4 and T170~T192 in Figure 5 will be performed between the printer 10, the terminal 100, the authentication server 300, the connection server 400, and the SP server 500. In this case, the printer 10 will not generate a QR code.
[0071] (Effects of Case C and Case D) As described above, the printer 10 can perform FIDO authentication using NFC communication and also FIDO authentication using QR codes. Therefore, user convenience is improved.
[0072] As shown in Case C of Figure 6, when the printer 10 accepts an NFC selection operation, it erases the QR code without displaying it on the display unit 14. Also, as shown in Case D of Figure 7, when the printer 10 accepts a QR code selection operation, it erases the Passkey information without supplying the Passkey information to the NFCI / F18. With this configuration, the processing load on the printer 10 can be reduced compared to a configuration in which the printer 10 displays the QR code on the display unit 14 and supplies the Passkey information to the NFCI / F18.
[0073] As mentioned above, users can choose whether to use NFC communication or QR codes on the selection screen. Therefore, user convenience is improved.
[0074] (Correspondence) A QR code is an example of a "code image". T232 in Figure 6 is an example of the "first case". T332 in Figure 7 is an example of the "second case".
[0075] Although specific examples of the present invention have been described in detail above, these are merely illustrative and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes to the specific examples illustrated above. Modifications of the above embodiments are listed below.
[0076] (First variation) The term "communication device" is not limited to a printer, but may also refer to a scanner, multifunction device, etc.
[0077] (Second Modification) BTI / F20 may be an example of the "first communication interface". In this modification, communication using the BTI / F20 of the printer 10 is performed at T112 and T124 in Figure 4, and T242 and T244 in Figure 6. Also in this modification, the selection screen in the second embodiment is a screen that allows the user to select whether to use BT communication or QR code.
[0078] (Third Modification) In addition to normal Wi-Fi communication, Wi-Fi I / F22 and 122 may also be capable of performing wireless communication according to the Wi-Fi Aware method, which is wireless communication that does not utilize an AP. That is, Wi-Fi I / F22 and 122 may support the Wi-Fi Aware method developed by the Wi-Fi Alliance. Details of the Wi-Fi Aware method are described in the standard document "Wi-Fi Aware Specification Version 4.0" created by the Wi-Fi Alliance. Wi-Fi Aware is also called Wi-Fi Neighbor Awareness Network (NAN). Each device that supports the Wi-Fi Aware method can participate in a Wi-Fi Aware Neighbor Awareness Network (NAN) cluster. Proximity information is sent and received between devices that support the Wi-Fi Aware method. That is, wireless communication according to the Wi-Fi Aware method is so-called short-range wireless communication.
[0079] In this modified example, the Wi-Fi Aware method and a Wi-Fi I / F22 operating according to the Wi-Fi Aware method may be an example of the "first communication method" and "first communication interface." The normal Wi-Fi method and a Wi-Fi I / F22 operating according to the normal Wi-Fi method are examples of the "second communication method" and "second communication interface." In this modified example, communication according to the Wi-Fi Aware method is performed at T112 and T124 in Figure 4, and T242 and T244 in Figure 6. Also, in this modified example, the selection screen in the second embodiment is a screen that allows the user to choose whether to use communication according to the Wi-Fi Aware method or to use a QR code.
[0080] (Fourth Modification) When the authentication server 300 determines that FIDO authentication is successful in T170 in Figure 5, it may send an authentication success notification to the printer 10 that includes a job ID corresponding to the print data uploaded to the SP500. In this case, the printer 10 displays a job ID selection screen including the job ID on the display unit 14.
[0081] (Fifth Modification) The printer 10 may receive websocket information from the terminal 100 via NFCI / F18. For example, the printer 10 receives websocket information from the terminal 100 via NFCI / F18 when an NFC connection is established between the printer 10 and the terminal 100. In this modification, T132 and T134 in Figure 4 can be omitted. In this modification, the "second communication-related information receiving unit" can be omitted.
[0082] (Sixth Modification) In the second embodiment, when the printer 10 receives a second response signal from the authentication server 300, it may supply the Passkey information to the NFCI / F18 and display the QR code on the display unit 14. That is, the printer 10 may transmit the Passkey information to the terminal 100 via the NFCI / F18 and display the QR code on the display unit 14.
[0083] (Seventh Modification) When the printer 10 accepts an authentication start operation, it may display a QR code on the display unit 14 without displaying a selection screen or generating Passkey information. In this modification, the "second display control unit" can be omitted.
[0084] (Eighth Modification) The printer 10 may display a selection screen on the display unit 14 before generating Passkey information and a QR code. In this modification, when the printer 10 accepts an NFC selection operation, it generates Passkey information without generating a QR code. Also, when the printer 10 accepts a QR code selection operation, it generates a QR code without generating Passkey information.
[0085] (9th Modification) The printer 10 may display the selection screen on the display unit 14 when an NFC connection is established between the printer 10 and the terminal 100 and a second response signal is received from the authentication server 300. In another modification, the printer 10 may generate a Passkey and a QR code when an NFC connection is established between the printer 10 and the terminal 100 and a second response signal is received from the authentication server 300, and then display the selection screen on the display unit 14.
[0086] (Tenth Modification) In the above embodiment, the processes shown in Figures 3 to 7 are implemented by software (for example, programs 40, 140, and 142), but at least one of these processes may be implemented by hardware such as a logic circuit.
[0087] Furthermore, the technical elements described herein or in the drawings demonstrate technical usefulness individually or in various combinations, and are not limited to the combinations described in the claims at the time of filing. In addition, the technologies illustrated herein or in the drawings achieve multiple objectives simultaneously, and achieving even one of these objectives constitutes technical usefulness in itself.
[0088] Even if, in the claims of this patent application, each claim depends on only some of the claims, it is not limited to the claim being dependent only on those specific claims. To the extent that it is not technically contradictory, each claim may be dependent on other claims that were not dependent at the time of application. That is, the technologies of each claim can be combined in various ways as follows: (Item 1) A communication device, A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, When an authentication start instruction is received, an authentication request transmission unit sends an authentication request to the server via the second communication interface, A response receiving unit receives a response to the authentication request from the server via the second communication interface, in response to the authentication request being sent to the server. A first communication-related information transmission unit transmits first communication-related information to an authenticator via the first communication interface when the response is received from the server, wherein the first communication-related information is information for performing encrypted communication between the communication device and the authenticator using the second communication interface, An authentication execution instruction transmission unit transmits an authentication execution instruction to the authenticator via a second communication interface using encrypted communication after the first communication-related information has been transmitted to the authenticator, wherein the authentication execution instruction is information for instructing the authenticator to perform authentication according to a predetermined authentication method using a pair of keys and biometric authentication information, A communication device equipped with the following features. (Item 2) The aforementioned authentication request includes verification information, The authentication execution instruction includes the verification information, The aforementioned pair of keys includes a first private key and a first public key, The aforementioned communication device further, After the authentication execution instruction is transmitted to the authenticator, if the authenticator successfully authenticates the target user using the biometric authentication information, the signature information receiving unit receives signature information from the authenticator via the second communication interface using encrypted communication, wherein the signature information is generated by the authenticator by encrypting the verification information using the first secret key, and the signature information receiving unit A signature information transmission unit that, when the signature information is received from the authenticator, transmits the signature information to the server via the second communication interface, wherein when the server decrypts the signature information using the first public key and obtains the verification information, the signature information transmission unit transmits success information to the communication device indicating that the authentication in accordance with the predetermined authentication method was successful, After the signature information is transmitted to the server, a success information receiving unit receives the success information from the server via the second communication interface. The communication device according to item 1, comprising: a predetermined processing execution unit that executes predetermined processing when the success information is received from the server, and the predetermined processing execution unit that restricts the execution of predetermined processing when the success information is not received from the server. (Item 3) The communication device according to item 2, wherein the predetermined processing includes the processing of transmitting service information related to the communication device to the authenticator via the first communication interface. (Item 4) The aforementioned communication device further, A second communication-related information receiving unit receives second communication-related information from the authenticator via a third communication interface after the first communication-related information has been transmitted to the authenticator, wherein the second communication-related information is information for performing the encrypted communication between the communication device and the authenticator. The communication device according to any one of items 1 to 3, wherein the authentication execution instruction transmission unit transmits the authentication execution instruction to the authenticator via the second communication interface using encrypted communication when the first communication-related information is transmitted to the authenticator and the second communication-related information is received from the authenticator. (Item 5) The aforementioned communication device is Display unit and When the response is received from the server, a first display control unit causes the display unit to display a code image representing code information including the first communication-related information via the first communication interface, A second communication-related information receiving unit receives second communication-related information from the authenticator via a third communication interface after the code image is displayed on the display unit and the code image has been read by the authenticator, wherein the second communication-related information is information for performing the encrypted communication between the communication device and the authenticator. Equipped with, The communication device according to any one of items 1 to 4, wherein the authentication execution instruction transmission unit further transmits the authentication execution instruction to the authenticator via the second communication interface using encrypted communication when the code image is read by the authenticator and the second communication-related information is received from the authenticator. (Item 6) In the first case where it is selected to transmit the first communication-related information via the first communication interface, the first communication-related information transmits the first communication-related information to the authenticator via the first communication interface. In the first case described above, the code image is not displayed on the display unit. In the second case where it is selected to display the code image on the display unit, the first display control unit displays the code image on the display unit. In the second case, the communication device described in item 5 does not transmit the first communication-related information. (Item 7) The aforementioned communication device further, The communication device according to item 6, further comprising a second display control unit that displays a selection screen on the display unit for the user to select whether to transmit the first communication-related information via the first communication interface or to display the code image on the display unit. (Item 8) A computer program for a communication device, The aforementioned communication device is A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, Equipped with a computer, The aforementioned computer program controls the computer, When an authentication start instruction is received, an authentication request transmission unit sends an authentication request to the server via the second communication interface, A response receiving unit receives a response to the authentication request from the server via the second communication interface, in response to the authentication request being sent to the server. A first communication-related information transmission unit transmits first communication-related information to an authenticator via the first communication interface when the response is received from the server, wherein the first communication-related information is information for performing encrypted communication between the communication device and the authenticator using the second communication interface, An authentication execution instruction transmission unit transmits an authentication execution instruction to the authenticator via a second communication interface using encrypted communication after the first communication-related information has been transmitted to the authenticator, wherein the authentication execution instruction is information for instructing the authenticator to perform authentication according to a predetermined authentication method using a pair of keys and biometric authentication information, A computer program that functions as such. (Item 9) A method performed by a communication device, The aforementioned communication device is A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, Equipped with, The aforementioned method, When an authentication start instruction is obtained, the authentication request transmission step involves sending an authentication request to the server via the second communication interface, A response receiving step in which, upon transmission of the authentication request to the server, the server receives a response to the authentication request via the second communication interface, A first communication-related information transmission step, in which, when the response is received from the server, first communication-related information is transmitted to the authenticator via the first communication interface, wherein the first communication-related information is information for performing encrypted communication between the communication device and the authenticator using the second communication interface, An authentication execution instruction transmission step, wherein, after the first communication-related information has been transmitted to the authenticator, an authentication execution instruction is transmitted to the authenticator via the second communication interface using the encrypted communication, wherein the authentication execution instruction is information for instructing the authenticator to perform authentication in accordance with a predetermined authentication method using a pair of keys and biometric authentication information, A method that includes [a certain feature]. [Explanation of Symbols]
[0089] 2: Communication system, 6: Internet, 10: Printer, 12: Control panel, 14: Display unit, 16: Print execution unit, 18: NFCI / F, 20: BTI / F, 22: Wi-Fi I / F, 30: Control unit, 32: CPU, 34: Memory, 40: Program, 100: Terminal, 112: Control panel, 114: Display unit, 118: NFCI / F, 120: BTI / F, 122: Wi-Fi I / F, 124: Camera, 130: Control unit, 132: CPU, 134: Memory, 140: OS program, 142: Authentication application, 144: Biometric authentication information, 200: PC, 240: Management table, 300: Authentication server, 400: Connection server, 500: SP server
Claims
1. A communication device, A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, When an authentication start instruction is received, the authentication request transmission unit transmits an authentication request to the server via the second communication interface, A response receiving unit receives a response to the authentication request from the server via the second communication interface, in response to the authentication request being sent to the server. A first communication-related information transmission unit transmits first communication-related information to an authenticator via the first communication interface when the response is received from the server, wherein the first communication-related information is information for performing encrypted communication between the communication device and the authenticator using the second communication interface, An authentication execution instruction transmission unit transmits an authentication execution instruction to the authenticator via a second communication interface using encrypted communication after the first communication-related information has been transmitted to the authenticator, wherein the authentication execution instruction is information for instructing the authenticator to perform authentication according to a predetermined authentication method using a pair of keys and biometric authentication information, A communication device equipped with the following features.
2. The aforementioned authentication request includes verification information, The authentication execution instruction includes the verification information, The aforementioned pair of keys includes a first private key and a first public key, The aforementioned communication device further, After the authentication execution instruction is transmitted to the authenticator, if the authenticator successfully authenticates the target user using the biometric authentication information, the signature information receiving unit receives signature information from the authenticator via the second communication interface using encrypted communication, wherein the signature information is generated by the authenticator by encrypting the verification information using the first secret key, and the signature information receiving unit A signature information transmission unit that, when the signature information is received from the authenticator, transmits the signature information to the server via the second communication interface, wherein when the server decrypts the signature information using the first public key and obtains the verification information, the signature information transmission unit transmits success information to the communication device indicating that the authentication in accordance with the predetermined authentication method was successful, After the signature information is transmitted to the server, a success information receiving unit receives the success information from the server via the second communication interface. A communication device according to claim 1, comprising: a predetermined processing execution unit that executes predetermined processing when the success information is received from the server, and the predetermined processing execution unit that restricts the execution of predetermined processing when the success information is not received from the server.
3. The communication device according to claim 2, wherein the predetermined processing includes the processing of transmitting service information related to the communication device to the authenticator via the first communication interface.
4. The aforementioned communication device further, A second communication-related information receiving unit receives second communication-related information from the authenticator via a third communication interface after the first communication-related information has been transmitted to the authenticator, wherein the second communication-related information is information for performing the encrypted communication between the communication device and the authenticator. The communication device according to claim 1, wherein the authentication execution instruction transmission unit transmits the authentication execution instruction to the authenticator via the second communication interface using encrypted communication when the first communication-related information is transmitted to the authenticator and the second communication-related information is received from the authenticator.
5. The aforementioned communication device is Display unit and A first display control unit, which, when the response is received from the server, causes the display unit to display a code image representing code information including the first communication-related information via the first communication interface, The code image is displayed on the display unit and the code image is read by the authenticator, and the second communication-related information receiving unit receives second communication-related information from the authenticator via a third communication interface, wherein the second communication-related information is information for performing the encrypted communication between the communication device and the authenticator, Equipped with, The communication device according to claim 1, wherein the authentication execution instruction transmission unit further transmits the authentication execution instruction to the authenticator via the second communication interface using encrypted communication when the code image is read by the authenticator and the second communication-related information is received from the authenticator.
6. In the first case where it is selected to transmit the first communication-related information via the first communication interface, the first communication-related information transmits the first communication-related information to the authenticator via the first communication interface. In the first case described above, the code image is not displayed on the display unit. In the second case where it is selected to display the code image on the display unit, the first display control unit displays the code image on the display unit. The communication device according to claim 5, wherein in the second case, the first communication-related information is not transmitted.
7. The aforementioned communication device further, The communication device according to claim 6, further comprising a second display control unit that displays a selection screen on the display unit for the user to select whether to transmit the first communication-related information via the first communication interface or to display the code image on the display unit.
8. A computer program for a communication device, The aforementioned communication device is A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, Equipped with a computer, The aforementioned computer program controls the computer, When an authentication start instruction is received, the authentication request transmission unit transmits an authentication request to the server via the second communication interface, A response receiving unit receives a response to the authentication request from the server via the second communication interface, in response to the authentication request being sent to the server. A first communication-related information transmission unit transmits first communication-related information to an authenticator via the first communication interface when the response is received from the server, wherein the first communication-related information is information for performing encrypted communication between the communication device and the authenticator using the second communication interface, An authentication execution instruction transmission unit transmits an authentication execution instruction to the authenticator via a second communication interface using encrypted communication after the first communication-related information has been transmitted to the authenticator, wherein the authentication execution instruction is information for instructing the authenticator to perform authentication according to a predetermined authentication method using a pair of keys and biometric authentication information, A computer program that functions as such.
9. A method performed by a communication device, The aforementioned communication device is A first communication interface that operates according to a first communication method, A second communication interface that operates according to a second communication method different from the first communication method, Equipped with, The aforementioned method, When an authentication start instruction is obtained, the authentication request transmission step involves sending an authentication request to the server via the second communication interface, A response receiving step in which, upon transmission of the authentication request to the server, the server receives a response to the authentication request via the second communication interface, A first communication-related information transmission step, in which, when the response is received from the server, first communication-related information is transmitted to the authenticator via the first communication interface, wherein the first communication-related information is information for performing encrypted communication between the communication device and the authenticator using the second communication interface, An authentication execution instruction transmission step, wherein, after the first communication-related information has been transmitted to the authenticator, an authentication execution instruction is transmitted to the authenticator via the second communication interface using encrypted communication, the authentication execution instruction being information for instructing the authenticator to perform authentication according to a predetermined authentication method using a pair of keys and biometric authentication information, A method that includes [a certain feature].