Wireless LAN communication device, security method, and program

By generating dummy training signals when no person is detected, the wireless LAN devices address security risks by altering CSI patterns to deter unauthorized access.

JP2026083862APending Publication Date: 2026-05-20KYOCERA DOCUMENT SOLUTIONS INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
KYOCERA DOCUMENT SOLUTIONS INC
Filing Date
2024-11-08
Publication Date
2026-05-20

AI Technical Summary

Technical Problem

The current wireless LAN communication systems face security risks due to the lack of encryption for training signals, allowing third parties to detect the presence of individuals using CSI, potentially leading to unauthorized access.

Method used

Implementing wireless LAN devices with a control unit that generates and transmits dummy training signals when no person is detected, misleading external terminals into believing a person is present by altering CSI patterns.

Benefits of technology

This approach reduces security risks by misleading unauthorized devices into believing there are individuals present, thereby preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026083862000001_ABST
    Figure 2026083862000001_ABST
Patent Text Reader

Abstract

To provide technologies such as wireless LAN communication devices that can reduce security risks. [Solution] The wireless LAN device according to this technology comprises a communication unit and a control unit. The communication unit is capable of wireless LAN communication with other wireless LAN communication devices. The control unit detects the presence of a person in its vicinity based on a CSI generated based on a training signal in the wireless LAN communication, and if the presence of a person is not detected, it generates a dummy training signal by assigning a predetermined weight to the training signal and has the communication unit transmit the dummy training signal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0004] , , ,

[0006] , ,

[0005] , ,

[0007] , [[ID=!]]

[0001] This technology relates to technologies such as wireless LAN communication devices that perform wireless LAN communication (LAN: Local Area Network) with other devices.

Background Art

[0002] In recent years, an object detection method called Wi-Fi sensing (Wi-Fi: Wireless Fidelity) has attracted attention. This Wi-Fi sensing is expected to be applied in various fields such as security, monitoring of the elderly, and ON / OFF of electronic devices.<000001!>

[0003] In Wi-Fi sensing, two devices having a wireless LAN function by Wi-Fi are required. For example, assume that one of the two devices is an access point and the other is a terminal device.

[0004] In this case, a training signal such as LTF (Long Training Field) is transmitted from the access point, and this training signal is received by the terminal device. The terminal device that has received the training signal generates CSI (Channel State Information) based on the training signal and transmits the CSI to the access point. CSI is information representing the state of the propagation path of the wireless LAN signal between the two devices. [[ID=2!]]

[0005] The access point considers the state of the propagation path between the two devices indicated by the CSI, and makes a predetermined change to the data signal and transmits it to the terminal device so that the receiving terminal device can accurately restore the data signal.

[0006] On the other hand, the value of CSI changes depending on whether an object exists in the propagation path between the two devices or not. By utilizing this relationship, an object such as a person can be detected using CSI.

[0007] For example, Patent Document 1 below discloses technology related to wireless LAN sensing. [Prior art documents] [Patent Documents]

[0008] [Patent Document 1] Japanese Patent Publication No. 2023-143743 [Overview of the project] [Problems that the invention aims to solve]

[0009] Currently, the training signal is not encrypted or otherwise processed, and any device with wireless LAN capabilities can acquire this training signal. Misuse of CSI based on this training signal could potentially allow a third party to determine the presence or absence of people in a certain space, such as an office, store, or home, posing a security risk.

[0010] In light of the above circumstances, the objective is to provide technologies such as wireless LAN communication devices that can reduce security risks. [Means for solving the problem]

[0011] The wireless LAN device relating to this technology comprises a communication unit and a control unit. The aforementioned communication unit is capable of wireless LAN communication with other wireless LAN communication devices. The control unit detects the presence of a person in its vicinity based on the CSI generated based on the training signal in the wireless LAN communication. If no person is detected, it generates a dummy training signal by assigning a predetermined weight to the training signal and has the communication unit transmit the dummy training signal.

[0012] By transmitting a dummy training signal in this way, it is possible to mislead an external terminal that receives the dummy training signal, and its owner (a third party), into believing that a person is present or not. Therefore, security risks can be reduced.

[0013] The security method relating to this technology includes detecting the presence of a person in the surrounding area based on a CSI generated based on a training signal in wireless LAN communication, and if the presence of a person is not detected, generating a dummy training signal by assigning a predetermined weight to the training signal, and transmitting the dummy training signal from the communication unit.

[0014] The program related to this technology detects the presence of a person in the surrounding area based on a CSI generated based on a training signal in wireless LAN communication. If no person is detected, it generates a dummy training signal by assigning a predetermined weight to the training signal and causes the wireless LAN communication device to transmit the dummy training signal from the communication unit. [Effects of the Invention]

[0015] As described above, this technology makes it possible to provide wireless LAN communication devices and other technologies that can reduce security risks. [Brief explanation of the drawing]

[0016] [Figure 1] This figure shows a wireless LAN communication system according to the first embodiment of this technology. [Figure 2] This is a block diagram showing the internal configuration of a wireless LAN communication system according to the first embodiment. [Figure 3] A diagram to explain CSI [Figure 4] This diagram illustrates a method for detecting people using CSI (Computer Sensor Inspection). [Figure 5] This diagram illustrates the security problems caused by the misuse of CSI. [Figure 6] This is a diagram for explaining a method for reducing security risks. [Figure 7] This is a diagram showing the process when generating a list of MAC addresses. [Figure 8] This is a flowchart showing the process of the control unit of the access point. [Figure 9] This is a flowchart showing the process of the control unit of the access point. [Figure 10] This is a diagram showing the state when a training signal and a dummy training signal are transmitted from the access point to an external terminal. [Figure 11] This is a flowchart showing the process by the control unit of the terminal device according to the second embodiment. [Figure 12] This is a diagram showing the state when a dummy training signal is transmitted from the terminal device in access point mode to an external terminal.

Embodiments for Carrying Out the Invention

[0017] Hereinafter, embodiments according to the present technology will be described with reference to the drawings.

[0018] ≪First Embodiment≫ <Overall Configuration and Configuration of Each Part> FIG. 1 is a diagram showing a wireless LAN communication system 100 according to the first embodiment of the present technology. As shown in FIG. 1, the wireless LAN communication system 100 (security system) according to the present embodiment includes an access point 10 and a terminal device 20 that can perform wireless LAN communication (Wi-Fi communication) with each other.

[0019] A local area network is configured by this access point 10 and the terminal device 20. In the example shown in FIG. 1, the case where the number of terminal devices 20 is one is shown, but the number of terminal devices 20 may be plural.

[0020] Access point 10 (wireless LAN communication device) is the base station for wireless LAN communication (Wi-Fi communication). Access point 10 is connected to a router, for example, and connects terminal device 20 to the internet. Note that access point 10 may also have router functionality (i.e., access point 10 may be a wireless LAN router).

[0021] Terminal device 20 (wireless LAN communication device) is a client device in wireless LAN communication (Wi-Fi communication). Terminal device 20 can be, for example, various PCs (personal computers) such as laptops and tablets, printers, copiers, fax machines, and multifunction printers. Typically, terminal device 20 can be any device that has wireless LAN communication capabilities (and is typically a device placed in a space when no people are present).

[0022] In this embodiment, the access point 10 and terminal device 20 are arranged within a certain space, such as an office, store, or residence. In Figure 1, the rectangular lines surrounding the access point 10 and terminal device 20 represent the walls that constitute a certain space, such as an office, store, or residence.

[0023] In Figure 1, an external terminal 30 is located on the other side of the wall. The external terminal 30 can function as a client device in wireless LAN communication (Wi-Fi communication). In this embodiment, this external terminal 30 is a terminal that may be used by a malicious third party who is trying to illegally confirm the presence or absence of people inside an office or other location using the external terminal 30.

[0024] The external terminal 30 is, for example, a smartphone, a tablet PC, or a laptop PC. Typically, the external terminal 30 can be any device that has wireless LAN communication capabilities (and is typically portable).

[0025] Figure 2 is a block diagram showing the internal configuration of a wireless LAN communication system 100 according to the first embodiment of this technology.

[0026] The access point 10 includes a control unit 11, a storage unit 12, and a communication unit 13. The control unit 11 of the access point 10 is composed of, for example, a CPU (Central Processing Unit). The control unit 11 of the access point 10 comprehensively controls each part of the access point 10.

[0027] The storage unit 12 of the access point 10 includes a non-volatile memory that stores various data and programs necessary for processing by the control unit 11 of the access point 10, and a volatile memory used as a work area for the control unit 11 of the access point 10. The above programs may be downloaded via a network or read from a portable recording medium.

[0028] The communication unit 13 of the access point 10 is configured to enable wireless LAN communication between the terminal device 20 and the external terminal 30. This communication unit 13 of the access point 10 has an antenna array with multiple antennas, enabling MIMO (Multiple-Input and Multiple-Output) communication. Furthermore, the communication unit 13 of the access point 10 is capable of communication using multi-carrier transmission methods such as OFDM (Orthogonal Frequency-Division Multiplexing).

[0029] The terminal device 20 includes a control unit 21, a storage unit 22, and a communication unit 23. The control unit 21 of the terminal device 20 is composed of, for example, a CPU. The control unit 21 of the terminal device 20 comprehensively controls each part of the terminal device 20.

[0030] The storage unit 22 of the terminal device 20 includes a non-volatile memory that stores various data and programs necessary for processing by the control unit 21 of the terminal device 20, and a volatile memory used as a work area for the control unit 21 of the terminal device 20. The above programs may be downloaded via a network or read from a portable recording medium.

[0031] The communication unit 23 of the terminal device 20 is configured to enable wireless LAN communication between the access point 10 and the external terminal 30. This communication unit 23 of the terminal device 20 has an antenna array with multiple antennas, enabling MIMO communication. Furthermore, the communication unit 23 of the terminal device 20 is capable of communication using multi-carrier transmission methods such as OFDM.

[0032] [CSI] Next, we will explain CSI. Figure 3 is a diagram illustrating CSI. As shown in Figure 3, the access point 10 modulates training signals such as LTF (Long Training Field), HT-LTF (High Throughput - Long Training Field), and VHT-LTF (Very High Throughput - Long Training Field) using an OFDM method with multiple subcarriers and transmits them to the terminal device 20.

[0033] When terminal device 20 receives a training signal, it demodulates the received training signal using the OFDM method. Then, terminal device 20 generates a CSI for each subcarrier based on the received training signal. The CSI can be obtained, for example, by subtracting the received waveform of the training signal on terminal device 20 from the transmitted waveform of the training signal on access point 10 (ideal received waveform: known on terminal device 20 side).

[0034] This CSI is information extracted at the physical layer of wireless communication that represents the state of the propagation path between two devices (in this example, between access point 10 and terminal device 20). CSI can represent, for example, propagation loss of transmitted radio waves, amplitude changes due to multipath such as reflection or diffraction, and phase changes.

[0035] The terminal device 20 calculates the CSI for each subcarrier and transmits this CSI to the access point 10. The access point 10 modulates the data signal using OFDM, taking this CSI into account, and transmits it to the terminal device 20.

[0036] When the terminal device 20 receives a data signal, it demodulates the received data signal using the OFDM method. The resulting data signal is free from the influence of objects intervening in the data signal propagation path, and therefore the terminal device 20 can reconstruct an accurate data signal.

[0037] [Human detection using CSI] Next, we will explain the method of detecting people using CSI (Wi-Fi sensing). Figure 4 is a diagram illustrating the method of detecting people using CSI.

[0038] As shown in Figure 4, access point 10 transmits training signals such as LTF at predetermined intervals. The top of Figure 4 shows the CSI when no one is present in a certain space such as an office.

[0039] For example, when a person enters an office or similar room, the propagation path between the access point 10 and the terminal device 20 is affected, so the CSI changes compared to when there is no one in the office or similar room (second from the top in Figure 4).

[0040] If a person is stationary, the CSI does not change (third from the top in Figure 4). However, if a person moves within an office or similar space, the CSI changes. Therefore, if a person is present inside an office or similar space, the CSI will generally change.

[0041] When a person leaves an office or similar space, the CSI changes compared to when the person was inside the office or space, and then returns to its original state (bottom of Figure 4). After a person leaves, the CSI basically does not change.

[0042] Therefore, changes in CSI can be used to determine whether or not a person is present in an office or other similar space.

[0043] Human detection can be used, for example, to turn lights and other devices on and off, to monitor the elderly, and for security against illegal intrusions.

[0044] [Security issues due to misuse of CSI] Next, we will discuss the security problems caused by the misuse of CSI. Figure 5 is a diagram illustrating the security problems caused by the misuse of CSI.

[0045] Currently, CSIs are generally encrypted, so a third party cannot intercept the CSI generated by terminal device 20 via external terminal 30. On the other hand, training signals transmitted from access point 10 are generally not encrypted. Therefore, external terminal 30 can receive training signals from access point 10 and generate its own CSI. In this case, external terminal 30 does not need to have established a connection with access point 10.

[0046] As shown in Figure 5, the external terminal 30 generates a CSI based on a training signal transmitted from the access point 10 at predetermined intervals. As mentioned above, the CSI basically changes when there are people inside the office, but basically does not change when there are no people. Figure 5 shows the situation when there are no people inside the office, and the CSI does not change.

[0047] This relationship could be exploited, potentially allowing unrelated third parties to check whether or not people are present inside offices or other premises. If this third party has malicious intent, they could illegally enter the office or other premises when no one is present. Thus, there are security problems associated with the misuse of CSI.

[0048] [Methods for reducing security risks] Next, we will explain the methods for reducing security risks related to this technology. Figure 6 is a diagram illustrating the methods for reducing security risks.

[0049] Access point 10 transmits training signals such as LTF to terminal device 20 for human detection. Access point 10 determines whether a person is present in the office or other space based on the CSI received from terminal device 20. When access point 10 determines that no person is present, it generates and transmits a dummy training signal by assigning predetermined weights to the training signal.

[0050] In Figure 5, the external terminal 30 initially receives a training signal from the access point 10 and generates a CSI. However, partway through, the external terminal 30 receives a dummy training signal from the access point 10 and generates a CSI. Since the dummy training signal is weighted according to a predetermined formula, the received waveform on the external terminal 30 side changes even though no human is present, and this causes a change in the CSI.

[0051] External terminal 30 and its third-party owner perceive (mistakenly believe) that a person is present based on the change in CSI, even though no person is actually present. Thus, in this embodiment, security risks can be reduced because external terminal 30 and its third-party owner can be made to perceive (mistakenly believe) that a person is present, even though no person is actually present.

[0052] <Operation Description> Next, we will describe the processing in the wireless LAN communication system 100. This explanation will focus on the processing in the control unit 11 of the access point 10.

[0053] The control unit 11 of the access point 10 first performs a preliminary step of collecting and listing the MAC addresses (MAC: Media Access Control) of terminal devices 20 in the vicinity of the access point 10. A MAC address is a unique identification number assigned to individually identify a device. The generated list is used to distinguish between terminal devices 20 and external terminals 30.

[0054] Figure 7 shows the process for generating a list of MAC addresses. As shown in Figure 7, first, the control unit 11 of the access point 10 determines whether a probe request has been received from the terminal device 20 (ST101).

[0055] When a probe request is received from terminal device 20 (YES in ST101), the control unit 11 of access point 10 extracts the MAC address of terminal device 20 included in the probe request (ST102). Then, the control unit 11 of access point 10 stores the extracted MAC address in the storage unit 11 and lists it (ST103), and then returns to ST101.

[0056] Furthermore, the control unit 11 of the access point 10 sends a probe response to the terminal device 20 in response to a probe request, thereby establishing a connection between the access point 10 and the terminal device 20.

[0057] Figures 8 and 9 are flowcharts showing the processing of the control unit 11 of the access point 10.

[0058] First, the control unit 11 of the access point 10 generates a training signal (LTF, etc.) and transmits this training signal to the terminal device 20 via the communication unit 11 (ST201). Since this training signal is not encrypted, it can be acquired not only by the terminal device 20 but also by an external terminal 30.

[0059] The control unit 21 of the terminal device 20 generates a CSI based on the training signal received from the access point 10 and transmits the generated CSI to the access point 10. Since this CSI is encrypted using WPA (Wi-Fi Protected Access) or similar methods, the CSI generated by the terminal device 20 cannot be intercepted by a third party via the external terminal 30.

[0060] The control unit 11 of the access point 10 determines whether the CSI has been received from the terminal device 20 after transmitting the training signal (ST202).

[0061] When a CSI is received from the terminal device 20 (YES in ST202), the control unit 11 of the access point 10 analyzes the CSI (ST203) and determines whether a person is present in a certain space such as an office based on this analysis (ST204). The control unit 11 of the access point 10 can learn the CSI patterns when a person is present and when a person is not present through machine learning, and can then determine the presence or absence of a person based on the CSI at that time.

[0062] If the presence of a person is detected (YES in ST204), the control unit 11 of the access point 10 determines whether a predetermined time has elapsed since the previous transmission of the training signal (ST205). If a predetermined time has elapsed since the previous transmission of the training signal (YES in ST205), the control unit 11 of the access point 10 returns to ST201 and transmits the training signal again.

[0063] If no human presence is detected in ST204 (NO in ST204), the control unit 11 of the access point 10 determines whether a probe request has been received (ST206). If no probe request has been received (NO in ST206), the control unit 11 of the access point 10 determines whether a predetermined amount of time has elapsed since the transmission of the previous training signal (ST207).

[0064] If a predetermined amount of time has not elapsed since the previous training signal was transmitted (ST207 NO), the control unit returns to ST206 and determines again whether a probe request has been received. If no probe request has been received (ST206 NO) and a predetermined amount of time has elapsed since the previous training signal was transmitted (ST207 YES), the control unit 11 of the access point 10 returns to ST201 and transmits the training signal again.

[0065] On the other hand, if no human presence is detected (ST204 NO) and a new probe request is received (ST206 YES), the control unit 11 of the access point 10 extracts the MAC address included in the new probe request (ST208). The control unit 11 of the access point 10 then compares the extracted MAC address with the MAC addresses included in the list (see Figure 7) to determine whether the extracted MAC address is included in the list (ST209).

[0066] Furthermore, the control unit 11 of the access point 10 determines, using ST206, ST208, and ST209, whether or not there are other unknown wireless LAN devices in its vicinity, such as an external terminal 30.

[0067] In ST209, if the MAC address is included in the list (YES in ST209) (i.e., if the surrounding devices are known devices), the control unit 11 of the access point 10 returns to ST207.

[0068] On the other hand, if the MAC address is not included in the list in ST209 (YES in ST209) (i.e., if the surrounding devices are unknown devices), the control unit 11 of the access point 10 proceeds to the next ST210.

[0069] In ST210, the control unit 11 of the access point 10 generates a dummy training signal by assigning a predetermined weight to the training signal. Next, the control unit 11 of the access point 10 transmits the dummy training signal via the communication unit 11 (ST211). Since this dummy training signal is not encrypted or otherwise protected, it can be acquired by the external terminal 30.

[0070] After transmitting a dummy training signal, the control unit 11 of the access point 10 increments the counter's count value by +1 (ST212). Next, the control unit determines whether the counter's count value is N (ST213).

[0071] If the counter's count value is not N (NO in ST213), the control unit 11 of the access point 10 determines whether a predetermined time has elapsed since the previous transmission of the dummy training signal (ST214).

[0072] If a predetermined time has elapsed since the previous transmission of the dummy training signal (YES in ST214), the control unit 11 of the access point 10 changes the weighting of the training signal (ST215) and returns to ST210. The control unit 11 of the access point 10 then weights the training signal with the changed weighting and generates a dummy training signal. The control unit 11 of the access point 10 then transmits this dummy training signal via the communication unit 11 (ST211).

[0073] In this embodiment, the weighting is changed every cycle, and accordingly, the dummy training signal changes every cycle. The external terminal 30 receives this dummy training signal and generates a CSI, but this CSI changes even though no people are present in the office or other space. As a result, the external terminal 30 and its owner (a third party) perceive (mistakenly believe) that people are present based on the change in the CSI, even though no people are actually present.

[0074] Figure 10 shows how training signals and dummy training signals are transmitted from access point 10 to external terminal 30. First, if a person is present in a certain space such as an office, a training signal is transmitted from access point 10 to external terminal 30. When a person is present, the training signal basically changes.

[0075] When no one is present inside the office or other location, a dummy training signal is sent from access point 10 to external terminal 30. Because the training signal is switched to the dummy training signal, the received waveform on the external terminal 30 changes at the time of this switch, and the CSI also changes.

[0076] Subsequently, a dummy training signal is transmitted from the access point 10 to the external terminal 30 at predetermined intervals. This dummy training signal changes with each cycle due to changes in weighting. As a result, the received waveform on the external terminal 30 changes, and the CSI also changes, which can cause the external terminal 30 and third parties to mistakenly believe that a person is present.

[0077] In changing the weighting (see ST215), the control unit 11 of the access point 10 may change the weighting randomly, or it may change the weighting based on the CSI change pattern when a person is present.

[0078] This explanation describes a case where the weighting and dummy training signals change with each transmission cycle, but the weighting and dummy training signals may change with multiple cycles. Furthermore, the weighting and dummy training signals may change with random cycles, not just regular cycles.

[0079] Returning to Figure 9, if the counter's count value in ST213 is N (YES in ST213), the control unit 11 of the access point 10 resets the counter's count value to zero (ST216). Next, the control unit 11 of the access point 10 sends a normal training signal to the terminal device 20 instead of a dummy training signal (ST217).

[0080] Then, the control unit 11 of the access point 10 determines whether a CSI has been received from the terminal device 20 (ST218). If a CSI has been received from the terminal device 20 (YES in ST218), the control unit 11 of the access point 10 analyzes the CSI (ST219) and determines whether a person is present in the office or other space (ST220).

[0081] If no human presence is detected (ST220 NO), the control unit 11 of the access point 10 determines that the person has not yet returned and returns to ST214. The control unit 11 of the access point 10 then continues to transmit dummy training signals via the communication unit 11 at predetermined intervals.

[0082] On the other hand, if the presence of a person is detected (YES in ST220), the control unit 11 of the access point 10 determines that the person has returned and returns to ST205. As long as the presence of a person is detected, it sends a training signal to the terminal device 20 at predetermined intervals to acquire the CSI, and detects whether or not a person is present based on this CSI (loop of ST201 to ST205).

[0083] In ST203, ST216-ST220, the control unit 11 of the access point 10 transmits a normal dummy training signal at a predetermined interval (once every N times the dummy training signal is transmitted) while transmitting a dummy training signal, and continuously detects the presence or absence of a person. Then, when a person returns and their presence is detected, the control unit 11 of the access point 10 stops transmitting the dummy training signal. This allows the dummy training signal to be stopped at the appropriate timing.

[0084] In this explanation, a normal training signal is sent once for every N dummy training signals sent. However, the value of N can be set arbitrarily within this range as long as it is an integer greater than or equal to 1. In other words, if the decision of whether a person has returned should be made frequently (or if the processing load is low), the value of N should be set low (for example, N < 5), and if the decision does not need to be made frequently (or if the processing load is high), the value of N should be set high (for example, N ≥ 5). The timing of sending the normal training signal can also be determined by counting time.

[0085] In this explanation, we describe the case in which a dummy training signal is transmitted from access point 10 when the following two conditions (1) and (2) are met. (1) No human presence is detected within a certain space, such as an office. (2) An unknown device is present around access point 10. On the other hand, if only condition (1) of the two conditions (1) and (2) is met, a dummy training signal may be transmitted.

[0086] <Effect, etc.> As explained above, in this embodiment, if the presence of a person is not detected in a certain space such as an office, a dummy training signal is transmitted from the access point 10. This can cause the external terminal 30 and its owner (a third party) to mistakenly believe that a person is present or not. This reduces security risks.

[0087] Furthermore, in this embodiment, if the presence of a person is not detected and an unknown device is present around the access point 10, a dummy training signal is transmitted from the access point 10. This prevents the unnecessary transmission of a dummy training signal from the access point 10 and allows the access point 10 to appropriately transmit a dummy training signal when necessary.

[0088] Furthermore, in this embodiment, the weighting of the training signal is changed at predetermined intervals (regular or random intervals), and the dummy training signal is changed at predetermined intervals (regular or random intervals). This makes it possible to more appropriately mislead the external terminal 30 and its owner (a third party) into believing that a person is present or not, and further reduces security risks (see Figure 10).

[0089] Furthermore, in this embodiment, the weighting of the training signal and the dummy training signal generated therefrom are randomly changed. Alternatively, the weighting of the training signal and the dummy training signal generated therefrom are changed based on the CSI when a person is present. This makes it possible to more appropriately mislead the external terminal 30 and its owner (a third party) about the presence or absence of a person, and further reduces security risks.

[0090] Furthermore, in this embodiment, after it is determined that no human presence is detected, if the presence of a human is subsequently detected in the surrounding area, and the presence of a human is detected (i.e., it is determined that a person has returned), the transmission of the dummy training signal is stopped. This allows the transmission of the dummy training signal to be stopped at the appropriate timing.

[0091] ≪Second Embodiment≫ Next, a second embodiment of this technology will be described. In the description of the second embodiment, the explanation of parts having the same configuration and function as the first embodiment described above will be omitted or simplified.

[0092] First, let me briefly explain the difference between this second embodiment and the first embodiment described above. In the first embodiment described above, the detection of the presence of a person was performed on the access point 10 side. On the other hand, in the second embodiment, the detection of the presence of a person is performed on the terminal device 20 side. In other words, since the CSI that is the basis for detecting the presence of a person is generated on the terminal device 20 side, the detection of the presence of a person can also be performed on the terminal device 20 side.

[0093] Furthermore, in the first embodiment described above, the transmission of the dummy training signal was performed on the access point 10 side. On the other hand, in the second embodiment, the transmission of the dummy training signal is performed on the terminal device 20 side to a reasonable extent.

[0094] Furthermore, the terminal device 20 does not have the functionality to process probe requests like the access point 10; therefore, in the second embodiment, MAC address listing and MAC address comparison are not performed. In other words, in the second embodiment, whether or not an unknown device exists around the terminal device 20 is not a condition for transmitting a dummy tracking signal.

[0095] Figure 11 is a flowchart showing the processing performed by the control unit 21 of the terminal device 20 according to the second embodiment.

[0096] In the second embodiment, the access point 10 performs a process of transmitting a training signal (unencrypted) to the terminal device 20 at a predetermined interval. In the second embodiment, the terminal device 20 has two operating modes, a normal mode and an access point mode, and these two operating modes are switchable.

[0097] The normal mode is a mode in which the terminal device 20 operates as a normal terminal device 20. On the other hand, the access point mode is a mode in which the terminal device 20 operates as an access point 10 that generates a dummy training signal and causes the communication unit 23 to transmit the dummy training signal.

[0098] First, the control unit 21 of the terminal device 20 determines whether a training signal has been received from the access point 10 (ST301). If a training signal has been received (YES in ST301), the control unit 21 of the terminal device 20 generates a CSI based on the received training signal (ST302).

[0099] Next, the control unit 21 of the terminal device 20 encrypts the generated CSI and transmits it to the access point 10 (ST303). Then, the control unit 21 of the terminal device 20 analyzes the generated CSI (ST304) to determine whether a person is present in a certain space such as an office (ST305).

[0100] If no human presence is detected (NO in ST305), the control unit 21 of the terminal device 20 determines whether the current operating mode is normal mode (ST306). If the current operating mode is not normal mode (NO in ST306), that is, if the current operating mode is access point mode, the control unit 21 of the terminal device 20 skips the following ST307 and 308 and proceeds to ST309.

[0101] On the other hand, if the current operating mode is normal mode (YES in ST306), the control unit 21 of the terminal device 20 determines whether there will be any problems in switching the operating mode from normal mode to access point mode (ST307).

[0102] In this case, if there are no people inside the office or other location, the terminal device 20 will not be directly operated by a person, so ST307 basically determines that there is no problem in switching to access point mode.

[0103] However, if, for example, terminal device 20 is a printer / multifunction device and is performing tasks such as printing or faxing using external signals via the network, it will be exceptionally determined that there will be problems switching to access point mode. In this case, the normal mode will be switched to access point mode after the printing or faxing process is completed.

[0104] If switching the operating mode from normal mode to access point mode would cause problems (ST307 NO), the control unit 21 of the terminal device 20 returns to ST301. On the other hand, if switching the operating mode from normal mode to access point mode would not cause problems (ST307 YES), the control unit 21 of the terminal device 20 switches the operating mode from normal mode to access point mode (ST308) and proceeds to the next ST309.

[0105] In ST309, the control unit 21 of the terminal device 20 generates a training signal and applies predetermined weights to the generated training signal to generate a dummy training signal (ST309). Then, the control unit 21 of the terminal device 20 transmits the dummy training signal (unencrypted) via the communication unit 23 (ST310).

[0106] Next, the control unit 21 of the terminal device 20 changes the weighting values ​​for the training signal (ST311) and returns to ST301. The weighting may be changed randomly or based on the change in CSI when a person is present.

[0107] The control unit 21 of the terminal device 20 transmits a dummy training signal at predetermined intervals unless the presence of a person is detected. This dummy training signal is received by the external terminal 30, which generates a CSI based on the dummy training signal. Because this CSI changes in the external terminal 30, the external terminal 30 and its owner (a third party) mistakenly perceive that a person is present inside the office or other location, even though no one is actually there.

[0108] Figure 12 shows the process when a dummy training signal is transmitted from terminal device 20 in access point mode to external terminal 30.

[0109] When no one is present inside the office or other location, a dummy training signal is transmitted from the access point terminal 20 to the external terminal 30 at predetermined intervals. This dummy training signal changes with each cycle due to changes in its weighting. Consequently, the received waveform on the external terminal 30 changes, and the CSI also changes, thus misleading the external terminal 30 and third parties into believing that people are present.

[0110] Returning to Figure 11, if the presence of a person is detected in ST305 (YES in ST305), the control unit 21 of the terminal device 20 determines whether the current operating mode is access point mode (ST312). If the current operating mode is not access point mode (NO in ST312), that is, if the current operating mode is normal mode, the control unit 21 of the terminal device 20 skips the next ST313 and returns to ST301.

[0111] On the other hand, if the current operating mode is access point mode (YES in ST312), the control unit 21 of the terminal device 20 determines that a person has returned and switches the operating mode from access point mode to normal mode (ST313), returning to step 301. This stops the transmission of the dummy training signal.

[0112] As explained above, even if the terminal device 20 determines whether or not a person is present and transmits a dummy training signal, it is possible to mislead the external terminal 30 and its owner (a third party) into believing that a person is present, similar to the first embodiment. Therefore, security risks can be reduced, similar to the first embodiment.

[0113] In the description of the second embodiment, the case was described in which the transmission period of the dummy training signal matches the reception period of the training signal from access point 10 (the period for detecting the presence of a person). On the other hand, the transmission period of the dummy training signal may be different from the reception period of the training signal from access point 10 (the period for detecting the presence of a person). [Explanation of symbols]

[0114] 10…Access point 11…Access point control unit 12... Access point memory 13…Communication section of access point 20…Terminal device 21…Control unit of the terminal device 22...Storage unit of the terminal device 23...Communication section of terminal device 30…External terminals 100... Wireless LAN communication system

Claims

1. A communication unit capable of wireless LAN communication with other wireless LAN communication devices, A control unit that detects the presence of a person in the surrounding area based on a CSI generated based on a training signal in the aforementioned wireless LAN communication, and if no person is detected, generates a dummy training signal by assigning a predetermined weight to the training signal, and causes the communication unit to transmit the dummy training signal. Wireless LAN communication device.

2. A wireless LAN communication device according to claim 1, The control unit determines whether an unknown wireless LAN communication device is present in its vicinity. If the presence of the person is not detected, and the unknown wireless LAN communication device is present, it generates a dummy training signal and has the communication unit transmit it. Wireless LAN communication device.

3. A wireless LAN communication device according to claim 2, The control unit determines whether the unknown other wireless LAN communication device is present in its vicinity based on the MAC address included in the probe request received from the other wireless LAN communication device. Wireless LAN communication device.

4. A wireless LAN communication device according to claim 3, The control unit lists and stores the MAC addresses included in probe requests received from other wireless LAN communication devices in its vicinity, and determines whether an unknown other wireless LAN communication device exists in its vicinity by comparing the MAC addresses in the list with the MAC addresses included in newly received probe requests. Wireless LAN communication device.

5. A wireless LAN communication device according to claim 1, The control unit generates the dummy training signal at a predetermined interval and transmits it from the communication unit. Wireless LAN communication device.

6. A wireless LAN communication device according to claim 5, The control unit changes the weighting at predetermined intervals to change the training signal of the dummy. Wireless LAN communication device.

7. A wireless LAN communication device according to claim 6, The control unit randomly changes the dummy training signal. Wireless LAN communication device.

8. A wireless LAN communication device according to claim 6, The control unit changes the dummy training signal based on the change in the CSI when the person is present. Wireless LAN communication device.

9. A wireless LAN communication device according to claim 1, After determining that no person is present, the control unit continues to detect the presence of people in the surrounding area, and if a person is detected, it stops transmitting the dummy training signal. Wireless LAN communication device.

10. A wireless LAN communication device according to claim 1, The wireless LAN communication device is an access point that transmits the training signal to a terminal device, receives the CSI generated by the terminal device, and detects the presence of people in its vicinity based on the received CSI. Wireless LAN communication device.

11. A wireless LAN communication device according to claim 1, The wireless LAN communication device is a terminal device that receives the training signal from the access point, generates a CSI based on the received training signal and transmits it to the access point, and detects the presence of people in its vicinity based on the generated CSI. Wireless LAN communication device.

12. A wireless LAN communication device according to claim 11, The control unit switches between an access point mode, in which it generates the dummy training signal and operates as an access point that transmits the dummy training signal from the communication unit, and a normal mode, in which it operates as a normal terminal device. Wireless LAN communication device.

13. Based on the CSI generated from the training signal in wireless LAN communication, the presence of a person in the surrounding area is detected. If the presence of the person is not detected, a predetermined weight is applied to the training signal to generate a dummy training signal. The dummy training signal is transmitted from the communication unit. Security methods.

14. Based on the CSI generated from the training signal in wireless LAN communication, the presence of a person in the surrounding area is detected. If the presence of the person is not detected, a predetermined weight is applied to the training signal to generate a dummy training signal. The dummy training signal is transmitted from the communication unit. A program that instructs a wireless LAN communication device to perform a process.