COMMUNICATION DEVICE, COMPUTER PROGRAM FOR TERMINAL DEVICE, AND TERMINAL DEVICE

By using public key acceptors, private key generators and other units between communication devices and terminal devices, and using Wi-Fi standard authentication request and response mechanisms, the security and stability problems of wireless connection between communication devices and external devices in the prior art are solved, and a safe and reliable wireless connection is achieved.

JP7673479B2Active Publication Date: 2025-05-09BROTHER KOGYO KK
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2021076391
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-04-28
Publication Date
2025-05-09
Estimated Expiration
2041-04-28

AI Technical Summary

Technical Problem

The prior art is difficult to securely establish a wireless connection between a communication device and an external device, and there are problems with security and connection stability.

Method used

By using public key receivers, private key generators, authentication request receivers, authentication response transmitters and other units between communication devices and terminal devices, the Wi-Fi standard authentication request and response mechanism is adopted to ensure the secure transmission of public keys and the integrity of the authentication process.

Benefits of technology

A secure wireless connection between the communication device and the external device is realized, which improves the stability and security of the connection and prevents unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007673479000001
    Figure 0007673479000001
  • Figure 0007673479000002
    Figure 0007673479000002
  • Figure 0007673479000003
    Figure 0007673479000003
Patent Text Reader

Abstract

To provide a technique that can securely establish radio connection between a communication device and an external device.SOLUTION: A communication device comprises: a public key receiving unit that executes communication equal to or higher than a network layer of an OSI reference model to receive a public key from a terminal device; an authentication request receiving unit that, after the public key is received from the terminal device, receives, from the terminal device, an authentication request in which the public key is used; an authentication execution unit that, when the authentication request is received from the terminal device, executes authentication of the terminal device that is a transmission source of the authentication request; an authentication response transmission unit that, when the authentication of the terminal device is successful, transmits the authentication response to the terminal device; a first connection information receiving unit that, after the authentication response is transmitted to the terminal device, receives first connection information from the terminal device; and a second establishment unit that, when the first connection information is received from the terminal device, establishes second radio connection with an external device by using the first connection information.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] This specification discloses techniques for establishing a wireless connection between a communication device and an external device. [Background technology]

[0002] Patent Document 1 discloses a technique for establishing a Wi-Fi connection between a printer and an access point (hereinafter referred to as "AP") using a terminal. In particular, a technique for establishing a Wi-Fi connection between a printer and an AP according to the DPP (abbreviation of Device Provisioning Protocol) method is disclosed. In this technique, the terminal obtains the public keys of the printer and the AP by reading a QR code (registered trademark) in which information including the public keys is encoded, and establishes a Wi-Fi connection between the printer and the AP using these public keys. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2020-113851 A [Patent Document 2] JP 2020-088620 A Summary of the Invention [Problem to be solved by the invention]

[0004] This specification provides a technique that can securely establish a wireless connection between a communication device and an external device. [Means for solving the problem]

[0005] This specification discloses a communication device. The communication device includes a first establishment unit that establishes a first wireless connection with a terminal device in accordance with the Wi-Fi standard, a public key receiving unit that receives a public key to be used by the communication device from the terminal device by executing communication at or above the network layer of the OSI (abbreviation of Open Systems Interconnection) reference model using the first wireless connection, a private key generating unit that generates a private key corresponding to the public key using the public key when the public key is received from the terminal device, an authentication request receiving unit that receives from the terminal device an authentication request using the public key and conforms to a predetermined method of the Wi-Fi standard after the public key is received from the terminal device, and a private key generating unit that performs authentication of the terminal device, which is a sender of the authentication request, using the private key when the authentication request is received from the terminal device. the authentication response sending unit is configured to send to the terminal device an authentication response according to the specified method when the authentication of the terminal device is successful, the authentication response indicating that the authentication of the terminal device has been successful, and when the authentication of the terminal device is unsuccessful, the authentication response is not sent; a first connection information receiving unit is configured to receive from the terminal device first connection information according to the specified method after the authentication response is sent to the terminal device; and a second establishment unit is configured to establish a second wireless connection with an external device different from the terminal device using the first connection information when the first connection information is received from the terminal device.

[0006] According to the above configuration, the communication device receives the public key from the terminal device by performing communication at the network layer or higher of the OSI reference model. In this way, the communication device performs communication at the network layer or higher, and therefore can securely receive the public key from the terminal device. Therefore, a wireless connection can be securely established between the communication device and an external device.

[0007] This specification also discloses a computer program for a terminal device. The computer program controls a computer of the terminal device to communicate with the following units, that is, a first wireless connection established between the terminal device and a communication device, the first wireless connection being in compliance with the Wi-Fi standard, and to communicate with an OSI (Open Systems Interconnection)-based communication device. and a first communication control unit that executes a first control process for executing the wireless communication according to the predetermined method between the terminal device and the communication device after the public key is transmitted to the communication device, wherein the wireless communication according to the predetermined method includes an authentication request transmission process for transmitting to the communication device an authentication request using a public key of the communication device, an authentication response reception process for receiving an authentication response from the communication device when the authentication request is transmitted to the communication device, and a first connection information transmission process for transmitting first connection information to the communication device after the authentication response is received from the communication device, wherein the first connection information is information used by the communication device to establish a second wireless connection according to the Wi-Fi standard between the communication device and an external device different from the terminal device.

[0008] According to the above configuration, the terminal device transmits the public key to the communication device by performing communication at the network layer or higher of the OSI reference model. In this way, since the terminal device performs communication at the network layer or higher, the public key can be securely transmitted to the communication device. Therefore, a wireless connection can be securely established between the communication device and the external device.

[0009] A computer program for the above-mentioned communication device, a computer-readable recording medium storing the computer program, and a method executed by the communication device are also novel and useful. Also, a computer-readable recording medium storing a computer program for the above-mentioned terminal device, a terminal device realized by the computer program, and a method executed by the terminal device are also novel and useful. Also, a communication system including the above-mentioned communication device and a terminal device realized by the above-mentioned computer program is novel and useful. [Brief description of the drawings]

[0010] [Figure 1] 1 shows the configuration of a communication system. [Diagram 2] A sequence diagram of the processes executed by each device is shown. [Diagram 3] 3 shows a flowchart of a process executed by an application in the first embodiment. [Figure 4] A sequence diagram for case A-1 is shown below. [Diagram 5] The sequence diagram continues from Figure 4. [Figure 6] A sequence diagram for case A-2 is shown. [Figure 7] The sequence diagram for case B is shown below. [Figure 8] The sequence diagram for case C is shown below. [Figure 9] 13 shows a flowchart of a process executed by an application according to a second embodiment. [Figure 10] A sequence diagram of cases D-1 and D-2 is shown. [Figure 11] The sequence diagram for case E is shown below. [Figure 12] 13 shows a flowchart of a process executed by an application according to a third embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0011] (First Example) (Configuration of communication system 2; Figure 1) 1, the communication system 2 includes a plurality of terminals 10A and 10B, a plurality of printers 100A and 100B, and an AP (short for Access Point) 6. The technology of this embodiment is a technology that uses a terminal (e.g., 10A) to establish a wireless connection (hereinafter, referred to as "Wi-Fi connection") between a printer (e.g., 100A) and the AP 6 in accordance with the Wi-Fi standard.

[0012] (Configuration of terminal 10A) The terminal 10A is a portable terminal device such as a mobile phone (e.g., a smartphone), a PDA, or a tablet PC. In a modified example, the terminal 10A may be a stationary PC, a notebook PC, or the like. The terminal 10A includes an operation unit 12A, a display unit 14A, a Wi-Fi interface 16A, a camera 18A, and a control unit 30A. Each unit 12A to 30A is connected to a bus line (reference numerals omitted). In the following, the interface is referred to as "I / F".

[0013] The operation unit 12A includes a plurality of keys. A user can input various instructions to the terminal 10A by operating the operation unit 12. The display unit 14A is a display for displaying various information. The camera 18A is a device for photographing an object. In this embodiment, the camera 18A is used for photographing the QR code of the AP 6 and the QR code displayed on the printer (e.g., 100A).

[0014] The Wi-Fi I / F 16A is a wireless I / F for performing Wi-Fi communication according to the Wi-Fi standard. The Wi-Fi standard is a wireless communication standard for performing wireless communication according to, for example, the IEEE (The Institute of Electrical and Electronics Engineers, Inc.) 802.11 standard and standards equivalent thereto (for example, 802.11a, 11b, 11g, 11n, 11ac, etc.). In particular, the Wi-Fi I / F 16A supports the DPP (abbreviation of Device Provisioning Protocol) method established by the Wi-Fi Alliance. Details of the DPP method are described in the specification "Device Provisioning Protocol Specification Version 1.1.13" created by the Wi-Fi Alliance.

[0015] The Wi-Fi I / F 16A also supports the WFD (short for Wi-Fi Direct (registered trademark)) method established by the Wi-Fi Alliance. Details of the WFD method are described in the standard "Wi-Fi Peer-to-Peer (P2P) Technical Specification Version 1.1" created by the Wi-Fi Alliance. The WFD method defines a Group Owner state (hereinafter referred to as "G / O state") and a client state (hereinafter referred to as "CL state"). The G / O state is a state in which the station operates as a parent station in a wireless connection established according to the WFD method, and the CL state is a state in which the station operates as a child station in the wireless connection. In the following, a Wi-Fi connection established according to the WFD method may be referred to as a "WFD connection."

[0016] Furthermore, the terminal 10A can establish a Wi-Fi connection with the AP6 according to a normal Wi-Fi method that is different from the DPP method and the WFD method (hereinafter, this may be described as "supporting the normal Wi-Fi method"). Specifically, in the normal Wi-Fi method, the terminal 10A can establish a Wi-Fi connection with the AP6 by using the SSID (short for Service Set Identifier) ​​and password of the wireless network formed by the AP6. Hereinafter, the password will be described as "PW".

[0017] The control unit 30A includes a CPU 32A and a memory 34A. The CPU 32A executes various processes in accordance with programs 36A and 38A stored in the memory 34A. The memory 34A is configured by a volatile memory, a non-volatile memory, or the like.

[0018] The OS (abbreviation of Operating System) program 36A is a program for realizing the basic operation of the terminal 10A. The application 38A is a program for establishing a Wi-Fi connection between the terminal 10A and the AP6, and for establishing a Wi-Fi connection between a printer (e.g., 100A) and the AP6. In the following, the OS program and the application are referred to as "OS" and "app", respectively. The app 38A can establish a Wi-Fi connection between the terminal 10A and the AP6, or between the printer (e.g., 100A) and the AP6 by having the OS 36A execute processing according to the DPP method. The app 38A is installed in the terminal 10A from a server (not shown) on the Internet provided by the vendor of the printers 100A and 100B, for example.

[0019] (Configuration of terminal 10B) The terminal 10B is a portable terminal device such as a mobile phone (e.g., a smartphone), a PDA, or a tablet PC. In a modified example, the terminal 10B may be a desktop PC, a notebook PC, or the like. The terminal 10B includes an operation unit 12B, a display unit 14B, a Wi-Fi I / F 16B, a camera 18B, and a control unit 30B. The units 12B to 30B are connected to a bus line (reference numbers omitted). The control unit 30B includes a CPU 32B and a memory 34B. The configuration of each of the units 12B to 34B is the same as the configuration of each of the units 12A to 34A of the terminal 10A, except that the Wi-Fi I / F 16B does not support the DPP method. That is, the Wi-Fi I / F 16B supports the WFD method and the normal Wi-Fi method, but does not support the DPP method.

[0020] (Printer 100A Configuration) The printer 100A is a peripheral device (for example, a peripheral device of the terminal 10A) capable of executing a printing function. In a modified example, the printer 100A may be a multi-function device capable of executing a scanning function, a FAX function, etc. in addition to a printing function. The printer 100A has a printer ID "AAA". The printer 100A includes an operation unit 112A, a display unit 114A, a Wi-Fi I / F 116A, a print execution unit 118A, and a control unit 130A. Each unit 112A to 130A is connected to a bus line (reference numerals omitted).

[0021] The operation unit 112A has a plurality of keys. A user can input various instructions to the printer 100A by operating the operation unit 112A. The display unit 114A is a display for displaying various information. The print execution unit 118A has a printing mechanism such as an inkjet system or a laser system. The Wi-Fi I / F 116A is the same as the Wi-Fi I / F 16A of the terminal 10A. That is, the Wi-Fi I / F 116A supports the DPP system, the WFD system, and the normal Wi-Fi system.

[0022] The control unit 130A includes a CPU 132A and a memory 134A. The CPU 132A executes various processes according to a program 136A stored in the memory 134A. The memory 134A is configured with a volatile memory, a non-volatile memory, etc. The memory 134A stores a MAC address 140A of the Wi-Fi I / F 116A.

[0023] (Configuration of Printer 100B) The printer 100B is a peripheral device (for example, a peripheral device of the terminal 10A) capable of executing a printing function. In a modified example, the printer 100B may be a multi-function device capable of executing a scanning function, a FAX function, and the like in addition to a printing function. The printer 100B has a printer ID "BBB". The printer 100B includes an operation unit 112B, a display unit 114B, a Wi-Fi I / F 116B, a print execution unit 118B, and a control unit 130B. The units 112B to 130B are connected to a bus line (reference numerals omitted). The control unit 130B includes a CPU 132B and a memory 134B. The configuration of each of the units 112B to 134B is the same as the configuration of each of the units 112A to 134A of the printer 100A, except that the Wi-Fi I / F 116B does not support the DPP method and the memory 134B stores the MAC address 140B of the Wi-Fi I / F 116B. That is, the Wi-Fi I / F 116B supports the WFD method and the normal Wi-Fi method, but does not support the DPP method.

[0024] (AP6 Configuration) AP6 is not a device in the G / O state of WFD, but a normal access point called a wireless access point or wireless LAN router. AP6 supports the DPP method and the normal Wi-Fi method. AP6 relays communication between a pair of devices that belong to the Wi-Fi network in which AP6 acts as the parent station.

[0025] The AP6 stores a public key PKap, a private key pkap, a MAC address 8 of the Wi-Fi I / F (not shown) of the AP6, channel information CI1, an SSID "S1", and a PW "P1". The public key PKap and the private key pkap are used when performing authentication according to the DPP method. The channel information CI1 is information indicating one or more channels among a plurality of channels (in other words, a frequency range) available to the AP6. A QR code obtained by encoding the public key PKap, the MAC address 8, and the channel information CI1 is attached to the housing of the AP6. The SSID "S1" is information for identifying the Wi-Fi network formed by the AP6. The PW "P1" is authentication information used when a device is made to belong to the Wi-Fi network.

[0026] (Establishment of a Wi-Fi connection between terminal 10A and AP6 according to the DPP method; Figure 2) Next, referring to FIG. 2, a process for establishing a Wi-Fi connection according to the DPP method between the terminal 10A and the AP 6 will be described. In the following description of FIG. 2, for ease of understanding, the operations executed by the CPU (e.g., CPU 32A, 132A, etc.) of each device will be described as being mainly executed by each device (e.g., terminal 10A, printer 100A, etc.) rather than being mainly executed by the CPU. Also, instead of describing the terminal (e.g., terminal 10A) as being mainly executed, the OS (e.g., OS 36A) or the application (e.g., application 38A) may be described as being mainly executed. Also, all communications executed by the terminals 10A, 10B and the printers 100A, 100B are executed via the Wi-Fi I / F 16A, etc. Therefore, in the following description of communications, the description "via the Wi-Fi I / F" will be omitted. The same applies to the description of FIGS. 4 to 8.

[0027] At T10, application 38A receives an operation from the user to start application 38A. As a result, at T12, application 38A is started.

[0028] At T14, the application 38A accepts a setup start operation from the user. In this embodiment, "setup" means establishing a Wi-Fi connection between the terminal 10A and the AP 6, and then establishing a Wi-Fi connection between the printer and the AP 6. When the application 38A accepts the setup start operation, at T16, the application 38A starts up the camera 18A. Then, at T18, the application 38A accepts an operation from the user to photograph the QR code attached to the housing of the AP 6 with the camera 18A.

[0029] In T19, the application 38A decodes the captured QR code. As a result, the application 38A acquires the public key PKap, the MAC address 8, and the channel information CI1. The process of T19 corresponds to Bootstrapping in the DPP method.

[0030] When the application 38A acquires the public key PKap etc., at T20 it supplies a DPP start instruction to the OS 36A. The DPP start instruction includes the public key PKap, the MAC address MAC8, and the channel information CI1.

[0031] When OS36A acquires a DPP start instruction from application 38A at T20, it transmits an Authentication Request to AP6 at T22 using public key PKap included in the DPP start instruction and with MAC address 8 included in the DPP start instruction as the destination. Hereinafter, Authentication will be referred to as "Auth" and Request will be referred to as "Req." Hereinafter, OS36A repeatedly transmits Auth Req to AP6 using one or more channels indicated by channel information CI1 included in the DPP start instruction in sequence. In this way, OS36A transmits Auth Req using a channel available to AP6, and therefore Auth Req can be properly received by AP6.

[0032] Auth Req is a signal requesting the execution of authentication of the transmitting terminal 10A. Specifically, OS36A first generates a shared key using the private key (not shown) of terminal 10A and the public key PKap of AP6, and generates encrypted data by encrypting a random value using the shared key. Then, OS36A transmits Auth Req including the public key (not shown) of terminal 10A, the encrypted data, and the Capability of terminal 10A to AP6. The Capability of terminal 10A includes a value indicating that it can operate only as a DPP-based Configurator.

[0033] When the AP 6 receives an Auth Req from the terminal 10A in T22, the AP 6 authenticates the encrypted data included in the Auth Req in T23. Specifically, the AP 6 generates a shared key using the public key of the terminal 10A included in the Auth Req and the private key pkap of the AP 6, and decrypts the encrypted data using the shared key. If the decryption of the encrypted data is successful, the AP 6 determines that the authentication is successful, and executes the processes from T24 onward.

[0034] At T24, the AP 6 transmits an Auth Response including the Capability of the AP 6 to the terminal 10A. Hereinafter, the Response will be referred to as "Res." The Capability of the AP 6 includes a value indicating that it can operate only as an Enrollee of the DPP method.

[0035] When OS36A receives Auth Res from AP6 in T24, it determines that there is no conflict between the capability of AP6 included in Auth Res (i.e., Enrollee) and the capability of terminal 10A itself (i.e., Configurator). Then, OS36A transmits Auth Confirm to AP6 in T25. Auth Confirm includes information indicating that terminal 10A operates as a Configurator and AP6 operates as an Enrollee. As a result, OS36A decides to operate as a Configurator in T26. The Configurator is a device responsible for transmitting a Configuration Object (hereinafter referred to as "CO"), described below, to the Enrollee.

[0036] In addition, in T28, the AP 6 decides to operate as an Enrollee. The Enrollee is a device that receives a CO from the Configurator. The processing from T22 to T28 corresponds to Auth in the DPP method.

[0037] At T30, the AP 6 transmits a Configuration Req to the terminal 10A. Hereinafter, the configuration will be referred to as "Config." The Config Req is a signal that requests the transmission of a CO.

[0038] When the OS36A receives a Config Req from the AP6 in T30, it generates a CO for the AP. Specifically, the OS36A first generates a Signed Connector for the AP (hereinafter, referred to as "SC"), which is information to be used by the AP6 to establish a Wi-Fi connection. The SC for the AP includes, for example, a group ID, which is an identifier for identifying a wireless network. Then, the OS36A generates a CO for the AP including the SC for the AP, and transmits a Config Res including the CO for the AP to the AP6 in T32.

[0039] When the AP 6 receives the Config Res from the terminal 10A in T32, it transmits a Config Result to the terminal 10A in T34. The Config Result includes the code "STATUS_OK" indicating that the Config was successful. The processing from T30 to T34 corresponds to the Config in the DPP method.

[0040] Next, OS36A generates a terminal SC, which is information to be used by terminal 10A to establish a Wi-Fi connection. The terminal SC includes the same group ID as the group ID included in the AP SC. Then, OS36A transmits a Discovery Req including the terminal SC to AP6 at T40. Discovery Req is a signal that requests the transmission of the other party's SC.

[0041] When the AP 6 receives a Discovery Req from the terminal 10A in T40, the AP 6 uses the SC for AP to authenticate the SC for the terminal included in the Discovery Req. If the authentication of the SC for the terminal is successful, the AP 6 generates a connection key. Then, in T42, the AP 6 transmits a Discovery Res including the SC for AP to the terminal 10A.

[0042] When OS36A receives Discovery Res from AP6 in T42, it uses the SC for terminal to authenticate the SC for AP included in Discovery Res. If authentication of the SC for AP is successful, OS36A generates a connection key. The connection key generated here is the same as the connection key generated by AP6. That is, the connection key is shared by terminal 10A and AP6. The processing of T40 and T42 corresponds to Network Access in the DPP method.

[0043] Next, OS 36A uses the connection key to execute 4-way handshake communication with AP 6. As a result, at T50, a Wi-Fi connection is established between terminal 10A and AP 6. As a result, a wireless network is formed in which AP 6 operates as a parent station, and terminal 10A belongs to the wireless network as a child station.

[0044] Next, at T52, the AP6 transmits a Status Query Result (hereinafter, referred to as "Result") to the terminal 10A. The Result includes information indicating that a Wi-Fi connection between the terminal 10A and the AP6 has been established, and the SSID "S1" of the AP6.

[0045] At T52, the OS36A receives a Result from the AP6 and thereby obtains the SSID "S1" of the AP6.

[0046] (App processing; Figure 3) Next, referring to FIG. 3, a process executed by an application (e.g., application 38A) installed in a terminal (e.g., terminal 10A) will be described. The process in FIG. 3 is triggered by the establishment of a WFD connection between the terminal and the printer in response to pre-processing being executed in the terminal and the printer. The pre-processing will be described later with reference to FIG. 4. In the following, the terminal and the printer to which the WFD connection is established will be referred to as the "target terminal" and the "target printer", respectively. Furthermore, when describing the process in FIG. 3, the process will be described mainly with reference to the application (hereinafter referred to as the "target application") installed in the target terminal, rather than the CPU of the target terminal.

[0047] In the initial state of FIG. 3, a Wi-Fi connection has been established between the target terminal and AP6. Here, the Wi-Fi connection established between the target terminal and AP6 is either a Wi-Fi connection according to the DPP method or a Wi-Fi connection according to the normal Wi-Fi method. When the target terminal has established a Wi-Fi connection with AP6 according to the DPP method, the target terminal has stored the SSID "S1" of AP6 in its memory (see T52 in FIG. 2). Also, when the target terminal has established a Wi-Fi connection with AP6 according to the normal Wi-Fi method, the target terminal has stored the SSID "S1" of AP6 in its memory. That is, when the target terminal has established a Wi-Fi connection with AP6 according to either the DPP method or the normal Wi-Fi method, the target terminal has stored the SSID "S1" of AP6 in its memory.

[0048] In S10, the target application displays an authentication screen SC1 on the display unit of the target terminal. The authentication screen SC1 includes a message prompting the user to enter a user name and password for logging in to the target printer, a user name input area, a password input area, an OK button, and a cancel button. Hereinafter, the combination of the user name and password will be referred to as "user authentication information."

[0049] In S12, the target application accepts input of user authentication information from the user. Specifically, the target application accepts input of a username and password on the authentication screen SC1 from the user, and then accepts selection of the OK button.

[0050] In S14, the target application uses the established WFD connection to send the user authentication information entered in S12 to the target printer.

[0051] In S16, the target application determines whether or not the user authentication has been successful. Specifically, first, in S14, in response to the user authentication information being sent to the target printer, the target printer executes authentication of the user authentication information. If the user authentication information is stored in the target printer, the authentication is successful, and if the user authentication information is not stored in the target printer, the authentication is unsuccessful. If the target application receives information indicating that the authentication has been successful from the target printer using the established WFD connection, the target application determines that the user authentication has been successful (YES in S16) and proceeds to S20. On the other hand, if the target application receives information indicating that the authentication has been unsuccessful from the target printer using the established WFD connection, the target application determines that the user authentication has been unsuccessful (NO in S16) and ends the processing of FIG. 3 without executing the processing from S20 onward.

[0052] If a configuration is adopted in which authentication of user authentication information is not performed, a third party who is not a legitimate user of the target printer may establish a Wi-Fi connection between the target printer and an AP. In this embodiment, the process from S20 onwards is executed only if authentication of user authentication information is successful, so that it is possible to prevent a third party from establishing a Wi-Fi connection between the target printer and an AP. As a result, it is possible to improve the security of the target printer.

[0053] In S20, the target application determines whether or not the target terminal supports the DPP method. Specifically, the memory of the target terminal stores information (not shown) indicating whether or not the Wi-Fi I / F of the target terminal supports the DPP method. If the information indicating that the DPP method is supported is stored in the memory, the target application determines YES in S20 and proceeds to S22. On the other hand, if the information is not stored in the memory, the target application determines NO in S20 and proceeds to S60.

[0054] In S22, the target application determines whether or not various communications according to the DPP method (i.e., T22 to T52 in FIG. 2) have been executed between the target terminal and AP6. Specifically, if various communications according to the DPP method have been executed between the target terminal and the target AP, the memory of the target terminal stores information indicating that (e.g., a CO for AP). If the information is stored in the memory, the target application determines YES in S22 and proceeds to S30. On the other hand, if the information is not stored in the memory, the target application determines NO in S22 and proceeds to S60.

[0055] In S30, the target application uses the WFD connection to execute communication at or above the network layer of the OSI (Open System Interconnection) reference model to send a query to the target printer. The query is a signal for inquiring whether the target printer supports the DPP method, and for inquiring about the printer ID, capability information, and current status of the target printer. The capability information is information indicating capabilities that the target printer can execute (e.g., color printing, double-sided printing, etc.).

[0056] In S30, the target application further receives a response from the target printer using the WFD connection. The response includes information indicating whether the target printer supports the DPP method, a printer ID, capability information, and a status. If the target printer supports the DPP method, the response further includes a MAC address and channel information. The MAC address and channel information are information used in various communications (e.g., Auth) according to the DPP method, together with a public key described below.

[0057] In S32, the target application determines whether the target printer supports the DPP method. Specifically, if the target application receives a response including information indicating that the DPP method is supported, the target application determines YES in S32 and proceeds to S34. On the other hand, if the target application receives a response including information indicating that the DPP method is not supported in S30, the target application determines NO in S32 and proceeds to S62.

[0058] In S34, the target application displays a confirmation screen SC2 on the display unit of the target terminal. The confirmation screen SC2 is a screen for asking the user whether or not to execute a process for establishing a Wi-Fi connection between the target printer and the AP 6, and includes some of the information already received in S30 (i.e., the printer ID, capability information, and status), an OK button, and a Cancel button. By looking at the confirmation screen SC2, the user can check the information of the printer (i.e., the target printer) that should establish a Wi-Fi connection with the AP 6.

[0059] In S36, the target application determines whether the OK button or the Cancel button in the confirmation screen SC2 is selected. If the OK button is selected, the target application determines YES in S36 and proceeds to S40, and if the Cancel button is selected, the target application determines NO in S36 and ends the processing in FIG. 3 without executing the processing after S40.

[0060] In S40, the target application uses the MAC address included in the response already received in S30 to generate a public key to be used by the target printer.

[0061] In S42, the target application uses the WFD connection to transmit the generated public key to the target printer by using communication at the network layer or higher of the OSI reference model. This allows the target printer to obtain the public key of the target printer. The processes of S40 and S42 correspond to Bootstrapping in the DPP method.

[0062] In S44, the target application uses the WFD connection to execute communication at the network layer or higher to send a transition request to the target printer. The transition request is a signal requesting that the state of the target printer be transitioned from a DPP non-response state to a DPP response state. Here, the DPP non-response state is a state in which Auth Res cannot be transmitted, and the DPP response state is a state in which Auth Res can be transmitted. For this reason, printer 100A can transmit Auth Res to terminal 10A in response to receiving Auth Req from terminal 10A. Also, the DPP response state is usually a state in which the printer's processing load is higher than that of the DPP non-response state. Since the transition request is transmitted to the target printer at the timing when Auth is executed from now on, and the target printer transitions to the DPP response state, the processing load of the target printer can be reduced.

[0063] In S50, the target application supplies a DPP start instruction to the OS of the target terminal. The DPP start instruction includes the public key generated in S40, the MAC address included in the response received in S30, and the channel information included in the response received in S30. When the DPP start instruction is acquired by the OS, various communications according to the DPP method are executed between the target terminal and the target printer, and between the target printer and AP6, and a Wi-Fi connection according to the DPP method is established between the target printer and AP6. When the processing of S50 ends, the processing of FIG. 3 ends.

[0064] Also, in S60, the target application uses the WFD connection to execute communication at the network layer or higher to send an inquiry to the target printer and receive a response from the target printer. This inquiry is similar to the inquiry sent in S30, except that it does not inquire whether the target printer supports the DPP method. Also, the response received in S60 is similar to the response received in S30, except that it does not include information indicating whether the target printer supports the DPP method.

[0065] In S62, the target application displays a confirmation screen SC2 on the display unit of the target terminal. In S62 after S30, the target application displays a confirmation screen SC2 including each piece of information received in S30 (i.e., printer ID, capability information, status). In S62 after S60, the target application displays a confirmation screen SC2 including some of the information received in S60 (i.e., printer ID, capability information, status).

[0066] In S64, the target application determines whether the OK button or the Cancel button in the confirmation screen SC2 is selected. If the OK button is selected, the target application determines YES in S64 and proceeds to S66, and if the Cancel button is selected, the target application determines NO in S64 and ends the processing in FIG. 2 without executing the processing from S66 onward.

[0067] In S66, the target application acquires the SSID "S1" of the AP 6. Specifically, the target application supplies an SSID request to the OS of the target terminal and acquires the SSID "S1" of the AP 6 from the OS of the target terminal.

[0068] In S70, the target application displays an input screen SC3 on the display unit of the target terminal. The input screen SC3 includes a message prompting the user to input a password, the SSID "S1" acquired in S66, a password input area, an OK button, and a cancel button (see FIG. 6).

[0069] In S72, the target application judges whether or not the input of PW has been accepted. Specifically, when the target application accepts the input of PW and the selection of the OK button on the input screen SC3, the target application judges YES in S72 and proceeds to S74. On the other hand, when the target application accepts the selection of the Cancel button on the input screen SC3, the target application judges NO in S72 and ends the processing of FIG. 3 without executing the processing of S74.

[0070] In S74, the target application uses the WFD connection to send the SSID acquired in S66 and the PW entered in S72 to the target printer. As a result, the SSID and PW are used in the target printer, and a Wi-Fi connection according to the normal Wi-Fi method is established between the target printer and the AP 6. When the process of S74 ends, the process of FIG. 3 ends.

[0071] (Case A-1; Figures 4 and 5) Next, a specific case realized by the process of Fig. 3 will be described. First, with reference to Figs. 4 and 5, a case A-1 will be described in which a Wi-Fi connection is established between the printer 100A and the AP6 by using the terminal 10A that has already established a Wi-Fi connection with the AP6 according to the DPP method. In the initial state of Fig. 4, a Wi-Fi connection according to the DPP method has already been established between the terminal 10A and the AP6. That is, in the initial state of Fig. 4, the process of Fig. 2 has been executed in the terminal 10A and the AP6, and the AP6 has already stored the CO for the AP (see T32 in Fig. 2). In Fig. 4, first, the preliminary process of T110 to T140 is executed.

[0072] In T110, the printer 100A accepts a setup start operation from the user. In this case, the printer 100A transitions to the G / O state of the WFD method in T112. In the wireless network in which the printer 100A operates as the G / O state, the SSID "S2" and PW "P2" are used. In this way, the printer 100A transitions to the G / O state in response to accepting a setup start operation from the user, so the printer 100A can transition to the G / O state at the timing desired by the user.

[0073] In T114, printer 100A displays on display 114A a QR code obtained by encoding SSID "S2" and PW "P2".

[0074] The processes of T120 to T126 are similar to the processes of T10 to T16 in Fig. 2. Moreover, the process of T128 is similar to the process of T28 in Fig. 2, except that the QR code photographed by terminal 10A is the QR code displayed in T114.

[0075] In T130, the application 38A decodes the captured QR code. As a result, the application 38A obtains the SSID “S2” and the PW “P2”.

[0076] In T132, the application 38A provides a WFD connection instruction to the OS 36A. The WFD connection instruction includes the SSID "S2" and the PW "P2".

[0077] When the OS 36A acquires a WFD connection instruction from the application 38A in T132, the OS 36A establishes a WFD connection with the printer 100A in T140. Specifically, the OS 36A executes various communications with the printer 100A, such as authentication, association, and 4way-handshake. In the process of the various communications, the printer 100A executes authentication using the SSID "S2" and PW "P2", and if the authentication is successful, a WFD connection is established between the terminal 10A and the printer 100A. In this way, a QR code in which the SSID "S2" and PW "P2" are encoded is displayed by the printer 100A, and the QR code is read by the terminal 10A, so that a WFD connection is appropriately established between the terminal 10A and the printer 100A. Although not shown in the figure, when a WFD connection is established between the terminal 10A and the printer 100A, information indicating that the WFD connection has been established is supplied from the OS 36A to the application 38A. In addition, all of the following communications using the WFD connection are communications at or above the network layer of the OSI reference model.

[0078] When the application 38A acquires information indicating that a WFD connection has been established from the OS 36A (trigger of the process in FIG. 3), the application 38A displays the authentication screen SC1 (see FIG. 3) at T142 (S10).

[0079] In T144, the application 38A accepts the input of the user ID "U1" and the password "P3" from the user, and then accepts the selection of the OK button (S12). In this case, in T150, the application 38A uses the WFD connection to send user authentication information including the input user ID "U1" and password "P3" to the printer 100A (S14).

[0080] When the printer 100A receives the user authentication information from the terminal 10A in T150, the printer 100A executes authentication of the user authentication information. In this case, the printer 100A determines that the authentication is successful in T152, and transmits information indicating that the authentication is successful to the terminal 10A using the WFD connection in T154.

[0081] When the application 38A receives information from the printer 100A in T154 indicating that authentication was successful (YES in S16), since the terminal 10A supports the DPP method (YES in S20) and various communications in accordance with the DPP method have been executed between the terminal 10A and the AP6 (YES in S22), in T160 the application 38A uses the WFD connection to send an inquiry to the printer 100A (S30).

[0082] When the printer 100A receives an inquiry from the terminal 10A in T160, the printer 100A transmits a response to the terminal 10A using the WFD connection in T162. The response includes information indicating that the printer 100A supports the DPP method, the MAC address 140A of the printer 100A, channel information CI2, and each piece of information about the printer 100A (i.e., the printer ID "AAA", capability information, and status). The channel information CI2 is information indicating one or more channels among a plurality of channels (in other words, a frequency range) available to the printer 100A.

[0083] When the application 38A receives a response from the printer 100A in T162 (S30), it determines that the printer 100A supports the DPP method (YES in S32), and displays the confirmation screen SC2 (see FIG. 3) in T164 (S34). After that, in T166, the application 38A accepts selection of the OK button in the confirmation screen SC2 from the user (YES in S36).

[0084] (Continuation of Figure 4; Figure 5) In T170 of Fig. 5, the application 38A generates a public key PKpr to be used by the printer 140A, using the MAC address 140A of the printer 100A received in T162 of Fig. 4 (S40 of Fig. 3). Then, in T172, the application 38A transmits the generated public key Pkpr to the printer 100A, using the WFD connection (S42).

[0085] When the printer 100A receives the public key PKpr from the terminal 10A in T172, the printer 100A generates, in T174, a private key pkpr that corresponds to the received public key PKpr. For this reason, the printer 100A does not need to store the public key PKpr and the private key pkpr before receiving the public key PKpr from the terminal 10A. In particular, the printer 100A does not need to generate the public key PKpr.

[0086] Furthermore, in T176, the application 38A uses the WFD connection to send a transition request to the printer 100A (S44).

[0087] When the printer 100A receives a transition request from the terminal 10A in T176, the printer 100A transitions the state of the printer 100A from a DPP non-responsive state to a DPP responsive state in T178.

[0088] In T180, the application 38A supplies a DPP start instruction to the OS 36A (S50). The DPP start instruction includes the public key PKpr already received in T172, the MAC address 140A already received in T162, and the channel information CI2 already received in T162.

[0089] The processes of T182 to T196 are similar to the processes of T22 to T42 in FIG. 2, except that the subject that executes each process is different, and the information used in each process is different. In particular, since the OS36A transmits the Auth Req using a channel that can be used by the printer 100A, the Auth Req can be appropriately received by the printer 100A. After the processes of T182 to T196, in T198, a Wi-Fi connection based on the DPP method is established between the printer 100A and the AP 6. The process of T199 is similar to the process of T52, except that the subject that executes the process is different.

[0090] Through the above processes, both the terminal 10A and the printer 100A belong to the wireless network formed by the AP 6. This allows the printer 100A to receive print data from the terminal 10A via the AP 6 and execute printing according to the print data.

[0091] (Case A-2; Figure 6) Next, referring to Fig. 6, a case A-2 will be described in which a Wi-Fi connection is established between the printer 100A and the AP6 using the terminal 10A that has already established a Wi-Fi connection with the AP6 according to the normal Wi-Fi method. The initial state of Fig. 6 is the same as the initial state of Fig. 4, except that a Wi-Fi connection according to the normal Wi-Fi method has already been established between the terminal 10A and the AP6. That is, in the initial state of Fig. 6, the process of Fig. 2 has not been executed, and a Wi-Fi connection using SSID "S1" and PW "P1" has been established between the terminal 10A and the AP6.

[0092] In Fig. 6, first, the same processes as T110 to T154 in Fig. 4 are executed. Then, when the application 38A receives information indicating that authentication has been successful from the printer 100A at T154 referred to in Fig. 6 (YES in S16 in Fig. 3), the application 38A transmits an inquiry to the printer 100A at T260 using the WFD connection (S60) because the terminal 10A supports the DPP method (YES in S20) and various communications according to the DPP method have not yet been executed between the terminal 10A and the AP6 (NO in S22).

[0093] When the printer 100A receives an inquiry from the terminal 10A in T260, the printer 100A transmits a response to the terminal 10A using the WFD connection in T262. The response is the same as the response transmitted in T162 in Fig. 4, except that the response does not include information indicating whether the printer 100A supports the DPP method, the MAC address, and channel information. The processes in T264 and T266 are the same as those in T164 and T166.

[0094] The application 38A provides an SSID request to the OS 36A at T270.

[0095] When the OS 36A acquires the SSID request from the application 36A in T270, the OS 36A supplies the SSID "S1" of the AP 6 to which the terminal 10A currently has established a Wi-Fi connection to the application 38A in T272. As a result, the application 38A acquires the SSID "S1" of the AP 6 (S66).

[0096] In T274, the application 38A displays the input screen SC3 (S70). The input screen SC3 includes the SSID “S1” acquired in T272.

[0097] In T276, the application 38A accepts input of the PW "P1" from the user, and then accepts selection of the OK button (YES in S72). In this case, in T278, the application 38A uses the WFD connection to transmit the SSID "S1" and the PW "P1" to the printer 100A (S74).

[0098] In T278, the printer 100A receives the SSID "S1" and PW "P1" from the terminal 10A. As a result, in T280, the printer 100A establishes a Wi-Fi connection with the AP6 according to the normal Wi-Fi method. Specifically, the printer 100A executes various communications with the AP6, such as authentication, association, and 4-way handshake. In the course of the various communications, the AP6 executes authentication using the SSID "S1" and PW "P1", and if the authentication is successful, a Wi-Fi connection according to the normal Wi-Fi method is established between the printer 100A and the AP6. In this case, both the terminal 10A and the printer 100A can belong to the wireless network formed by the AP6.

[0099] (Case B; Figure 7) Next, a case B will be described with reference to Fig. 7, in which a Wi-Fi connection is established between the printer 100A and the AP6 by using the terminal 10B that has already established a Wi-Fi connection with the AP6 according to the normal Wi-Fi method. The processes from T310 to T354 are the same as the processes from T110 to T154 in Fig. 4.

[0100] When the application 38B receives information indicating that the authentication was successful from the printer 100A in T354 (YES in S16 of FIG. 3), since the terminal 10B does not support the DPP method (NO in S20), in T360 it sends an inquiry to the printer 100A (S60). The processes from T360 to T380 are the same as the processes from T260 to T280 in FIG. 6. In this case, both the terminal 10B and the printer 100A can belong to the wireless network formed by the AP6.

[0101] (Case C; Figure 8) Next, referring to Fig. 8, a case C will be described in which a Wi-Fi connection is established between the printer 100B and the AP6 using the terminal 10A that has already established a Wi-Fi connection with the AP6 according to the DPP method. The processes of T410 to T460 are the same as the processes of T110 to T160 in Fig. 4, except that the SSID and PW used to establish a WFD connection between the terminal 10A and the printer 100B are SSID "S4" and PW "P4", respectively. The process of T462 is the same as the process of T162, except that the response includes information indicating that the printer 100B does not support the DPP method and each piece of information about the printer 100B (i.e., the printer ID "BBB", capability information, and status), but does not include the MAC address and channel information of the printer 100B.

[0102] When the application 38A receives a response from the printer 100B at T462 (S30), it determines that the printer 100B does not support the DPP method (NO at S32), and displays a confirmation screen SC2 at T464 (S62). The processes from T466 to T480 are the same as the processes from T266 to T280 in Fig. 6. In this case, both the terminal 10A and the printer 100B can belong to the wireless network formed by the AP6.

[0103] (Effects of this embodiment) According to the above configuration, the terminal 10A can establish a Wi-Fi connection between the printer 100A and the AP 6 according to the DPP method by executing various communications according to the DPP method with the printer 100A that supports the DPP method (T182 to T196 in FIG. 5). The terminal 10A can also establish a Wi-Fi connection between the printer 100B and the AP 6 according to the normal Wi-Fi method by executing various communications according to the normal Wi-Fi method with the printer 100B that does not support the DPP method. In this way, the terminal 10A can establish a Wi-Fi connection between the printers 100A, 100B and the AP 6 according to an appropriate method.

[0104] Moreover, the printer 100A establishes a Wi-Fi connection with the AP 6 according to the DPP method (T198) by receiving a printer CO including a printer SC (T192 in FIG. 5). On the other hand, the printer 100A establishes a Wi-Fi connection with the AP 6 according to the normal Wi-Fi method (T380) by receiving the SSID "S1" and PW "P1" of the wireless network formed by the AP 6 from the terminal 10B that does not support the DPP method (T378 in FIG. 7). In particular, the printer 100A receives a printer CO including a printer SC from the terminal 10A that supports the DPP method, and receives the SSID "S1" and PW "P1" from the terminal 10B that does not support the DPP method. In this way, the printer 100A can establish a Wi-Fi connection between the printer 100A and the AP 6 according to an appropriate method by using the terminal 10A or 10B.

[0105] In particular, the printer 100A can establish a Wi-Fi connection with the AP 6 according to the DPP method (case A-1 in FIG. 4 and FIG. 5), and can also establish a Wi-Fi connection with the AP 6 according to the normal Wi-Fi method (case A-2 in FIG. 6). If the application 38A can establish a Wi-Fi connection between the printer 100A and the AP 6 according to the DPP method, the application 38A prioritizes establishing a Wi-Fi connection according to the DPP method (if YES in S32 in FIG. 3, executes S34 to S50). As described above, in the DPP method, the user does not need to input a password. In this way, by prioritizing the establishment of a Wi-Fi connection according to the DPP method, the number of operations that the user must perform can be reduced, and user convenience can be improved.

[0106] Also, a comparative example is assumed in which the user is prompted to execute various communications between the terminal 10A and the AP6 according to the DPP method when various communications between the terminal 10A and the AP6 according to the DPP method have not been executed. In this comparative example, various processes for establishing a Wi-Fi connection between the printer 100A and the AP6 are interrupted, and various communications between the terminal 10A and the AP6 according to the DPP method are executed. For this reason, it takes a relatively long time to establish a Wi-Fi connection between the printer 100A and the AP6. On the other hand, in this embodiment, when various communications between the terminal 10A and the AP6 according to the DPP method have not been executed (NO in S22 of FIG. 3), a Wi-Fi connection is established between the printer 100A and the AP6 according to the normal Wi-Fi method. Therefore, since it is not necessary to interrupt various processes for establishing a Wi-Fi connection between the printer 100A and the AP6 as in the above comparative example, a Wi-Fi connection can be established between the printer 100A and the AP6 relatively quickly.

[0107] Generally, the SSID "S1" of the AP6 can be changed by the administrator of the AP6, but the CO for the AP, including the SC for the AP, cannot be changed by the administrator. Therefore, in a Wi-Fi connection based on the DPP method, even if the SSID "S1" of the AP6 is changed by the administrator, the Wi-Fi connection established between the printer 100A and the AP6 is not disconnected. For this reason, by prioritizing the establishment of a Wi-Fi connection based on the DPP method, it is possible to reduce the possibility that the Wi-Fi connection between the printer 100A and the AP6 will be disconnected.

[0108] Also, a comparative example is assumed in which the QR code used when establishing a Wi-Fi connection between the printer 100A and the AP6 according to the DPP method is different from the QR code used when establishing a Wi-Fi connection between the printer 100A and the AP6 according to the normal Wi-Fi method. In this comparative example, a user who is not familiar with Wi-Fi connection does not know which QR code should be used to establish a Wi-Fi connection between the printer 100A and the AP6, and as a result, there is a possibility that a Wi-Fi connection is not established between the printer 100A and the AP6. On the other hand, in this embodiment, the user can establish a Wi-Fi connection between the printer 100A and the AP6 according to an appropriate method by photographing the same QR code (see T114 in FIG. 4) displayed on the printer 100A, whether in a situation where a Wi-Fi connection according to the DPP method should be established or in a situation where a Wi-Fi connection according to the normal Wi-Fi method should be established. This improves user convenience.

[0109] Furthermore, the application 38A transmits the public key PKpr to the printer 100A by executing communication at or above the network layer of the OSI reference model (S42 in FIG. 3, T172 in FIG. 5). In this way, the application 38A transmits communication at or above the network layer, and therefore can transmit the public key PKpr securely, as compared to a configuration in which the public key PKpr is transmitted by executing communication at a layer lower than the network layer, such as a Probe Req. This allows a wireless connection to be established securely between the printer 100A and the AP6.

[0110] (Correspondence) In case A-1 and case A-2, the printer 100A and the terminal 10A are examples of a "communication device" and a "terminal device", respectively. In case B, the printer 100A and the terminal 10B are examples of a "communication device" and a "terminal device", respectively. In case C, the printer 100B and the terminal 10A are examples of a "communication device" and a "terminal device", respectively. The AP6 is an example of an "external device". The DPP method and the normal Wi-Fi method are examples of a "predetermined method" and a "different method", respectively. The public key PKpr of the printer 100A and the private key of the printer 100A are examples of a "public key" and a "private key", respectively. The printer CO including the printer SC is an example of a "first connection information". The SSID "S2" and the PW "P2" of the wireless network in which the printer 100A operates as a G / O are an example of a "second connection information". The SSID "S1" and the PW "P1" of the AP6 are an example of a "third connection information". The display unit 114A of printer 100A is an example of an "output unit." The G / O status of the WFD method is an example of a "parent station status." The combination of user ID "U1" and PW "P3" is an example of "user authentication information." The MAC address 140A of printer 100A is an example of "identification information." The printer ID, capability information, and status are examples of "device information." Channel information CI2 is an example of "channel information." Information included in the response indicating whether the DPP method is supported is an example of "availability information."

[0111] The WFD connection established at T140 in Fig. 4, the Wi-Fi connection established at T198 in Fig. 5, and the Wi-Fi connection established at T280 in Fig. 6 are examples of the “first wireless connection”, the “second wireless connection”, and the “third wireless connection”, respectively. The setup start operation accepted at T110 in Fig. 4 is an example of an “establishment instruction”.

[0112] The process of T110, the process of T112, and the process of T114 in FIG. 4 are examples of processes executed by the "reception unit", the "second transition unit", and the "output control unit" of the "communication device", respectively. The process of T140, the process of T150, and the process of T162 are examples of processes executed by the "first establishment unit", the "authentication information reception unit", and the "device information transmission unit (identification information transmission unit and channel information transmission unit)" of the "communication device", respectively. The process of T172, the process of T174, the process of T176, and the process of T178 in FIG. 5 are examples of processes executed by the "public key reception unit", the "private key generation unit", the "transition request reception unit", and the "first transition unit" of the "communication device", respectively. The process of T182, the process of T183, the process of T184, the process of T192, and the process of T198 are examples of processes executed by the "authentication request reception unit", the "authentication execution unit", the "authentication response transmission unit", the "first connection information reception unit", and the "second establishment unit" of the "communication device", respectively. The process of T378 and the process of T380 in FIG. 7 are examples of processes executed by a "second connection information receiving unit" and a "third establishing unit" of the "communication device", respectively.

[0113] The process of S14 in FIG. 3 is an example of a process executed by the "authentication information transmission unit" of the "computer program". The process of S30 is an example of a process executed by the "identification information reception unit", "channel information reception unit", "device information reception unit", and "availability information reception unit" of the "computer program". The process of S60 is an example of a process executed by the "device information reception unit" of the "computer program". The processes of S34 and S62, the process of S40, the process of S42, and the process of S44 are examples of a process executed by the "display control unit", "public key generation unit", "public key transmission unit", and "transition request transmission unit" of the "computer program", respectively. The process of S50, and the processes of S66 to S74 are examples of a process executed by the "first communication control unit" and "second communication control unit" of the "computer program", respectively. In particular, the process of S74 is an example of a "second connection information transmission process". The process of T182, the process of T184, and the process of T192 in FIG. 5 are examples of "authentication request transmission process", "authentication response reception process", and "first connection information transmission process" of the "terminal device", respectively.

[0114] (Second Example) Next, a second embodiment will be described. The second embodiment differs from the first embodiment in that the process of S122 in Fig. 9 is executed instead of the process of S22 in Fig. 3, the specific process of S50 in Fig. 3 is different, and the specific process of S66 in Fig. 3 may be different.

[0115] (Application processing; Figure 9) The process executed by the application of the second embodiment will be described with reference to Fig. 9. Note that in the initial state of Fig. 9, a Wi-Fi connection may not be established between the target terminal and an AP (for example, AP6).

[0116] 9, the target application determines in S122 whether or not a Wi-Fi connection has been established between the target terminal and AP6. Specifically, the memory of the target terminal stores flag information (not shown) indicating whether or not a Wi-Fi connection has been established between the target terminal and AP6. If flag information indicating that a Wi-Fi connection has been established between the target terminal and AP6 is stored in the memory, the target application determines YES in S122 and proceeds to S20. On the other hand, if flag information indicating that a Wi-Fi connection has not been established between the target terminal and AP6 is stored in the memory, the target application determines NO in S122 and proceeds to S60.

[0117] If the answer to S122 is YES, the target application determines whether the Wi-Fi connection established between the target terminal and the AP6 is a Wi-Fi connection according to the DPP method or a Wi-Fi connection according to the normal Wi-Fi method, and stores the determination result. That is, the application determines whether various communications according to the DPP method have been performed between the target terminal and the AP6, and stores the determination result. The specific process is the same as the process of S22 in FIG. 3.

[0118] In S150, the target application supplies a DPP start instruction to the OS of the target terminal. In addition to the public key, MAC address, and channel information, the DPP start instruction includes information (see S122) indicating whether the Wi-Fi connection established between the target terminal and AP6 is a Wi-Fi connection according to the DPP method or a Wi-Fi connection according to the normal Wi-Fi method. This information is used when Config is executed between the target terminal and the target printer.

[0119] 9, the specific process is different depending on whether NO is returned from S122 or NO is returned from S20 or NO is returned from S32. The specific process of S166 after NO is returned from S20 or NO is returned from S32 is the same as the process of S66 in FIG.

[0120] In S166 after NO in S122, the target application transmits Probe Req by broadcast and receives Probe Res including the SSID of the AP from the AP present around the target terminal, thereby acquiring the SSID of the AP. Note that, when one or more SSIDs are acquired, the target application may display a selection screen for allowing the user to select one SSID from one or more SSIDs on the display unit of the target terminal before executing the process of S70. Then, in S70, the target application displays an input screen SC3 including one SSID among the acquired SSIDs on the display unit of the target terminal. In a modified example, when NO in S122, the target application may omit the process of S166. In this case, instead of the process of S70, an input screen including an SSID input field, a PW input field, an OK button, and a cancel button may be displayed on the display unit of the target terminal. Then, in S72, if the target application accepts the selection of the OK button after accepting the input of the SSID and PW, it may transmit the entered SSID and PW to the target printer in S74.

[0121] (Case D-1; Figure 10) Next, specific cases executed by the process of Fig. 9 will be described. First, with reference to Fig. 10, case D-1 will be described in which a Wi-Fi connection is established between the printer 100A and the AP6 using the terminal 10A that has already established a Wi-Fi connection with the AP6 according to the DPP method. Fig. 10 is a continuation of the process of Fig. 4. That is, in case D-1, a Wi-Fi connection according to the DPP method has been established between the terminal 10A and the AP6 (YES in S122 and YES in S20 in Fig. 9), and the printer 100A supports the DPP method (YES in S32).

[0122] First, in case D-1, the same processes as those from T170 to T178 in Fig. 5 are executed. Then, at T510, the application 38A supplies a DPP start instruction to the OS 36A (S150). The DPP start instruction includes the public key PKpr, the MAC address 140A, the channel information CI2, and information indicating that a Wi-Fi connection based on the DPP method has been established between the terminal 10A and the AP6. Then, the same processes as those from T182 to T188 are executed.

[0123] At T520 to T524, a DPP-based Config is executed. The processing at T520 to T524 is similar to the processing at T190 to T194 in Fig. 5. Thereafter, the same processing as at T195 to T199 in Fig. 5 is executed, and a Wi-Fi connection based on the DPP method is established between the printer 100A and the AP6. In this case as well, both the terminal 10A and the printer 100A can belong to the wireless network formed by the AP6.

[0124] (Case D-2; Figure 10) 10, a case D-2 will be described in which a Wi-Fi connection is established between the printer 100A and the AP 6 using the terminal 10A that has already established a Wi-Fi connection according to the normal Wi-Fi method with the AP 6. In case D-2, a Wi-Fi connection using SSID "S1" and PW "P1" (i.e., a Wi-Fi connection according to the normal Wi-Fi method) has already been established between the terminal 10A and the AP 6 (YES in S122), the terminal 10A supports the DPP method (YES in S22), and the printer 100A supports the DPP method (YES in S32).

[0125] First, in case D-2, the same processes as T110 to T166 in Fig. 4 and T170 to T178 in Fig. 5 are executed. Then, at T530, the application 38A supplies a DPP start instruction to the OS 36A. The DPP start instruction includes the public key PKpr, the MAC address 140A, the channel information CI2, and information indicating that a Wi-Fi connection in accordance with the normal Wi-Fi method has been established between the terminal 10A and the AP6. Then, the same processes as T182 to T188 are executed.

[0126] In T540 to T544, a DPP-based Config is executed. The processing in T540 to T544 is similar to the processing in T190 to T194 in FIG. 5, except that the printer CO transmitted from the terminal 10A to the printer 100A in T542 includes the SSID “S1” and PW “P1” of the AP6.

[0127] In T550, the printer 100A establishes a Wi-Fi connection with the AP6 according to the normal Wi-Fi method. Specifically, the printer 100A executes various communications with the AP6, such as authentication, association, and 4-way handshake. In the process of the various communications, the AP6 executes authentication using the SSID "S1" and PW "P1", and if the authentication is successful, a Wi-Fi connection according to the normal Wi-Fi method is established between the printer 100A and the AP6. The process of T552 is the same as the process of T199. In this case, both the terminal 10A and the printer 100A can belong to the wireless network formed by the AP6. The printer CO including the SSID "S1" and PW "P1" of the AP6 is an example of the "first connection information".

[0128] (Case E; Figure 11) Next, with reference to Fig. 11, a case E will be described in which a Wi-Fi connection is established between the printer 100A and the AP 6 by using the terminal 10A that has not yet established a Wi-Fi connection with the AP. In the initial state of Fig. 11, a Wi-Fi connection has not been established between the terminal 10A and the AP 6 (NO in S122).

[0129] First, in case E, the same processes as those from T110 to T154 in Fig. 4 are executed. The processes from T660 to T666 are the same as those from T260 to T266 in Fig. 6.

[0130] In T670, the application 38A transmits a Probe Req by broadcast, and in T672 receives a Probe Res from the AP 6. The Probe Res includes the SSID "S1" of the AP 6. The processes of T674 to T680 are the same as the processes of T274 to T280 in Fig. 6. In this way, even in a situation where the terminal 10A has not yet established a Wi-Fi connection with the AP 6, a Wi-Fi connection can be established between the printer 100A and the AP 6.

[0131] (Effects of this embodiment) As described above, when the terminal 10A has already established a Wi-Fi connection with the AP6 (cases D-1 and D-2 in FIG. 10), the printer 100A establishes a Wi-Fi connection with the AP6 (T198 (or T550) in FIG. 5 referred to in FIG. 10)) by receiving a printer CO including a printer SC (or SSID “S1” and PW “P1” of the AP6) (T522 (or T542) in FIG. 10). On the other hand, when the terminal 10A has not already established a Wi-Fi connection with the AP6 (case E in FIG. 11), the printer 100A establishes a Wi-Fi connection with the AP6 by receiving the SSID “S1” and PW “P1” of the wireless network formed by the AP6 from the terminal 10A (T678 in FIG. 11) (T680). In this way, the printer 100A can appropriately establish a Wi-Fi connection with the AP6 according to the information received from the terminal 10A.

[0132] (Third Example) Next, a third embodiment will be described. In the third embodiment, the timing at which the processes of S30 and S32 in FIG. 3 are executed is different. Also, in the third embodiment, the process of S60 is not executed. The following will focus on the differences from the first embodiment. Also, in FIG. 12, the same step numbers are used for the steps of the process that are the same as those in the first embodiment, and detailed descriptions thereof will be omitted.

[0133] (Application processing; Figure 12) The process executed by the application of the third embodiment will be described with reference to Fig. 12. If YES is determined in S16 of Fig. 12, the target application executes the processes of S30 and S32. If YES is determined in S32, the target application proceeds to S20, and if NO is determined in S32, the target application proceeds to S62. If NO is determined in S20, the target application proceeds to S62. Similarly, if NO is determined in S22, the target application proceeds to S62.

[0134] That is, in the third embodiment, whether or not the printer supports the DPP method is determined before whether or not the terminal supports the DPP method. Even in such a case, the terminal can establish a Wi-Fi connection between the printer and the AP in accordance with an appropriate method.

[0135] Although specific examples of the technology disclosed in this specification have been described in detail above, these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and variations of the specific examples exemplified above. Modifications of the above embodiments are listed below.

[0136] (Modification 1) The printer 100A may transition to a parent station of SoftAP instead of transitioning to a G / O of the WFD method at T112 in FIG. 4. In this modification, the process of transitioning to a parent station of SoftAP is an example of a process executed by the "second transition unit" of the "communication device". In another modification, the printer 100A may display a QR code including information indicating that a terminal (for example, the terminal 10A) should become a parent station in response to receiving a setup start operation. Then, in response to the QR code being photographed by the terminal 10A, the terminal 10A may transition to a G / O state of the WFD method, and a WFD connection may be established between the terminal 10A and the printer 100A. In this modification, the "output control unit" and the "second transition unit" of the "communication device" can be omitted. Generally speaking, in the "first wireless connection", the "communication device" may operate as a parent station, or the "terminal device" may operate as a parent station.

[0137] (Variation 2) The application 38A may store multiple public keys in advance, and select one of the multiple public keys as the public key PKpr to be used by the printer 100A at T170 in Fig. 5. In this variation, the "identification information transmission unit" of the "communication device" may be omitted, and the "identification information reception unit" and "public key generation unit" of the "computer program" may be omitted.

[0138] (Variation 3) Public key PKpr does not have to be information obtained using MAC address 140A of printer 100A, and may be information obtained using, for example, the serial number or printer ID of printer 100A. In other words, the "identification information" may be information for identifying printer 100A. In another variation, public key PKpr does not have to be information obtained using "identification information".

[0139] (Variation 4) Printer 100A may always operate in the DPP response state. In this variation, the "transition request receiving unit" and the "first transition unit" of the "communication device" may be omitted, and the "transition request transmitting unit" of the "computer program" may be omitted.

[0140] (Variation 5) The printer 100A may transmit a response that does not include the channel information CI2 to the terminal 10A at T162 in FIG. 4. For example, the printer 100A may transmit the channel information CI2 to the terminal 10A after the process of T172 in FIG. 5 is executed. That is, the timing of the processes executed by the "channel information transmitting unit" of the "communication device" and the "channel information receiving unit" of the "computer program" is not limited to the form of the above embodiment. In another variation, the printer 100A may not transmit the channel information CI2 to the terminal 10A. In this variation, the "channel information transmitting unit" of the "communication device" can be omitted, and the "channel information receiving unit" of the "computer program" can be omitted.

[0141] (Variation 6) In T162 of FIG. 4, the printer 100A may send a response to the terminal 10A that does not include the printer ID "AAA", capability information, and status. In this variation, the "device information transmission unit" of the "communication device" may be omitted. Also, if NO is determined in S20 or NO in S22, the application 38 may skip the processes of S60 to S64 in FIG. 3 and proceed to the process of S66. In this variation, the "device information transmission unit" of the "communication device" may be omitted, and the "device information reception unit" and "display control unit" of the "computer program" may be omitted.

[0142] (Variation 7) The application 38A can omit the processes of S10 to S16 in Fig. 3. In this variation, the "authentication information receiving unit" of the "communication device" can be omitted, and the "authentication information transmitting unit" of the "computer program" can be omitted.

[0143] (Variation 8) The printer 100A may cause the print execution unit 118A to print a QR code in which the SSID "S2" and PW "P2" are encoded at T114 in FIG. 4. In this variation, the print execution unit 118A is an example of an "output unit", and printing the QR code is an example of a process executed by an "output control unit" of a "communication device". In another variation, the printer 100A may supply the SSID "S2" and PW "P2" to an NFC (short for Near Field Communication) I / F at T114. In this case, the terminal (e.g., the terminal 10A) acquires the SSID "S2" and PW "P2" in response to the terminal (e.g., the terminal 10A) being brought closer to the printer 100A. In this variation, the NFC I / F is an example of an "output unit", and supplying the SSID "S2" and PW "P2" to the NFC I / F is an example of a process executed by an "output control unit" of a "communication device". In another variation, printer 100A may supply SSID "S2" and PW "P2" to a BT (short for Bluetooth (registered trademark)) I / F at T114. In this case, a terminal (e.g., terminal 10A) acquires SSID "S2" and PW "P2" via the BTI / F. In this variation, the BTI / F is an example of an "output unit," and supplying SSID "S2" and PW "P2" to the BTI / F is an example of processing executed by an "output control unit."

[0144] 4, printer 100A may receive access to printer 100A functioning as a web server from a terminal (e.g., terminal 10A) and receive a SEPP start operation from the terminal via the web server. In this modification, receiving a setup start operation from the terminal via the web server is an example of a process executed by the "reception unit" of the "communication device."

[0145] (Modification 10) After the process of T354 in FIG. 7 is completed, the printer 100A may receive information from the terminal 10B indicating that the terminal 10B does not support the DPP method. Then, in response to receiving the information, the printer 100A may display a notification screen notifying the user that Wi-Fi according to the DPP method cannot be established with the AP6. In this modification, the "second connection information receiving unit" and the "third establishment unit" of the "communication device" may be omitted. In another modification, in response to receiving a response including information indicating that the printer 100B does not support the DPP method in T462 in FIG. 8, the application 38A may display a notification screen notifying the user that Wi-Fi according to the DPP method cannot be established between the printer 100B and the AP6. In this modification, the "second communication control unit" of the "computer program" may be omitted. In another modification, the printer 100A may transmit a response not including information indicating that the printer 100A supports the DPP method to the terminal 10A in T162 in FIG. 4. In this modified example, the "possibility information receiving unit" of the "computer program" can be omitted.

[0146] (Modification 11) In the above embodiment, the processes of T182 to T194 in FIG. 5 are executed by the OS 36A of the terminal 10A, but instead, these various processes may be executed by the application 38A.

[0147] (Variation 12) The terminal 10A and the printer 100A may support a method other than the DPP method, and the printer 100A may execute various communications between the terminal 10A and the printer 100A, such as an authentication request, an authentication response, and first connection information, according to a method other than the DPP method. Generally speaking, the "predetermined method" is not limited to the DPP method.

[0148] (Variation 13) In each of the above embodiments, the processes in Figures 2 to 12 are realized by software (e.g., OS 36A, 36B, applications 38A, 38B, programs 136A, 136B), but at least one of these processes may be realized by hardware such as a logic circuit.

[0149] The technical elements described in this specification or drawings have technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. In addition, the technologies illustrated in this specification or drawings can achieve multiple objectives simultaneously, and achieving one of these objectives is itself technically useful. [Explanation of symbols]

[0150] 2: communication system, 6: AP, 8, 140A, 140B: MAC address, 10A, 10B: terminal, 12A, 12B, 112A, 112B: operation unit, 14A, 14B, 114A, 114B: display unit, 16A, 16B, 116A, 116B: Wi-Fi I / F, 18A, 18B: camera, 30A, 30B, 130A, 130B: control unit, 32A, 32B, 132A, 132B: CPU, 34A, 34B, 134A, 134B: memory, 36A, 36B: OS program, 38A, 38B: application, 100A, 100B: printer, 118A, 118B: print execution unit, 136A, 136B: program

Claims

1. 1. A communication device, comprising: a first establishing unit that establishes a first wireless connection with a terminal device in accordance with the Wi-Fi standard; a public key receiving unit that receives a public key to be used by the communication device from the terminal device by performing communication at a network layer or higher of an OSI (short for Open Systems Interconnection) reference model using the first wireless connection; a private key generation unit that generates a private key corresponding to the public key by using the public key when the public key is received from the terminal device; an authentication request receiving unit that receives, after the public key is received from the terminal device, an authentication request using the public key from the terminal device, the authentication request conforming to a predetermined method of the Wi-Fi standard; an authentication execution unit that, when the authentication request is received from the terminal device, uses the private key to authenticate the terminal device that is a sender of the authentication request; an authentication response transmission unit that transmits to the terminal device an authentication response according to the predetermined method, the authentication response indicating that the authentication of the terminal device has been successful, when the authentication of the terminal device is successful, and that does not transmit the authentication response when the authentication of the terminal device fails; a first connection information receiving unit that receives, after the authentication response is transmitted to the terminal device, first connection information according to the predetermined method from the terminal device; a second establishment unit that, when the first connection information is received from the terminal device, establishes a second wireless connection with an external device different from the terminal device by using the first connection information; A communication device comprising:

2. The communication device further comprises:

2. The communication device of claim 1, further comprising: an identification information transmitter configured to transmit identification information of the communication device to the terminal device, the identification information being utilized by the terminal device to generate the public key.

3. The communication device further comprises: a transition request receiving unit that receives a transition request for a state of the communication device from the terminal device by using the first wireless connection; a first transition unit that transitions a state of the communication device from a non-response state to a response state when the transition request is received from the terminal device, the non-response state being a state in which the authentication response cannot be transmitted to the terminal device, and the response state being a state in which the authentication response can be transmitted to the terminal device; The communication device according to claim 1 , wherein the authentication response transmission unit transmits the authentication response to the terminal device when a state of the communication device is transitioned to the response state and the authentication of the terminal device is successful.

4. The communication device further comprises: a channel information transmitting unit configured to transmit, to the terminal device, channel information indicating one or more wireless channels available to the communication device, by using the first wireless connection; The communication device according to claim 1 , wherein the authentication request receiving unit receives the authentication request from the terminal device by using one of the one or more wireless channels indicated by the channel information.

5. The communication device further comprises:

5. The communication device according to claim 1, further comprising: a device information transmitting unit that transmits device information related to the communication device to the terminal device using the first wireless connection, the device information being displayed on a display unit of the terminal device in response to the device information being received by the terminal device.

6. The communication device further comprises: an authentication information receiving unit that receives user authentication information from the terminal device by using the first wireless connection; the second establishment unit establishes the second wireless connection with the external device when authentication of the user authentication information is successful and the first connection information is received from the terminal device; The communication device according to claim 1 , wherein if authentication of the user authentication information fails, the second wireless connection is not established.

7. the first wireless connection is a wireless connection for the communication device to operate as a master station and the terminal device to operate as a slave station; The communication device further comprises: an output control unit that causes an output unit to output second connection information for establishing the first wireless connection, the output control unit being configured to cause the terminal device to acquire the second connection information in response to the second connection information being output; The communication device according to claim 1 , wherein the first establishment unit establishes the first wireless connection with the terminal device when the second connection information is acquired by the terminal device.

8. The communication device further comprises: a reception unit that receives an instruction for establishing a wireless connection with the external device from a user; a second transition unit that transitions a state of the communication device from a non-master station state in which the communication device does not operate as a master station to a master station state in which the communication device operates as a master station when the establishment instruction is accepted, The communication device according to claim 7 , wherein the first establishment unit establishes the first wireless connection with the terminal device after a state of the communication device is transitioned to the master station state.

9. the public key receiving unit receives the public key from the terminal device when the terminal device supports the predetermined method; The communication device further comprises: a second connection information receiving unit that receives, when the terminal device does not support the predetermined method, from the terminal device by using the first wireless connection without receiving the public key from the terminal device, third connection information conforming to a method different from the predetermined method of the Wi-Fi standard; a third establishment unit that, when the third connection information is received from the terminal device, establishes a third wireless connection with the external device in accordance with the Wi-Fi standard by using the third connection information; A communication device according to claim 1 , comprising:

10. The predetermined method is a DPP (Device Provisioning Protocol) method, The communication device according to claim 1 , wherein the first connection information is a Configuration Object in the DPP format.

11. A computer program for a terminal device, comprising: The computer program controls the computer of the terminal device to include the following units: a public key transmission unit that transmits a public key to be used by the communication device to the communication device by performing communication at or above a network layer of an OSI (short for Open Systems Interconnection) reference model using a first wireless connection established between the terminal device and the communication device, the first wireless connection conforming to a Wi-Fi standard; a first communication control unit that executes a first control process for executing wireless communication according to a predetermined method between the terminal device and the communication device after the public key is transmitted to the communication device, The wireless communication according to the predetermined method includes: an authentication request transmission process for transmitting an authentication request using the public key to the communication device; an authentication response receiving process for receiving an authentication response from the communication device when the authentication request is transmitted to the communication device; a first connection information transmission process for transmitting first connection information to the communication device after the authentication response is received from the communication device, the first connection information being information used by the communication device to establish a second wireless connection in accordance with the Wi-Fi standard between the communication device and an external device other than the terminal device; The first communication control unit includes: A computer program that functions as a

12. The computer program further causes the computer to an identification information receiving unit that receives identification information of the communication device from the communication device by using the first wireless connection; a public key generation unit that generates the public key by using the identification information; The computer program product of claim 11 .

13. The computer program further causes the computer to a transition request transmission unit that transmits a transition request to the communication device using the first wireless connection, the transition request being a request for transitioning a state of the communication device from a non-response state to a responsive state, the non-response state being a state in which the authentication response cannot be transmitted to the terminal device, and the responsive state being a state in which the authentication response can be transmitted to the terminal device; 13. The computer program product according to claim 11, wherein the authentication response receiving process receives the authentication response from the communication device when the authentication request is sent to the communication device after the state of the communication device is transitioned to the response state and the public key is sent to the communication device.

14. The computer program further causes the computer to a channel information receiving unit configured to receive, from the communication device, channel information indicating one or more channels available to the communication device, by using the first wireless connection; 14. The computer program product according to claim 11, wherein the authentication request transmission process transmits the authentication request to the communication device using one of the one or more wireless channels indicated by the channel information.

15. The computer program further causes the computer to a device information receiving unit configured to receive device information related to the communication device from the communication device using the first wireless connection; a display control unit that displays the received device information on a display unit of the terminal device; 15. A computer program as claimed in any one of claims 11 to 14, which causes a computer to function as follows:

16. The computer program further causes the computer to functioning as an authentication information transmission unit that transmits user authentication information to the communication device by using the first wireless connection; when the authentication of the user authentication information is successful and the first connection information is received from the terminal device, the second wireless connection is established between the communication device and the external device; The computer program product of claim 11 , wherein in the communication device, if authentication of the user authentication information fails, the second wireless connection is not established.

17. The computer program further causes the computer to a support information receiving unit configured to receive support information indicating whether the communication device supports the predetermined method from the communication device by using the first wireless connection; the public key transmission unit transmits the public key to the communication device when the support information indicates that the communication device supports the predetermined method; The computer program further causes the computer to a second communication control unit that executes a second control process for executing wireless communication between the terminal device and the communication device according to a method different from the predetermined method of the Wi-Fi standard when the support / non-support information indicates that the communication device does not support the predetermined method, The wireless communication according to the different schemes includes: a second connection information transmission process for transmitting third connection information to the communication device using the first wireless connection without transmitting the public key to the communication device, the third connection information being information used by the communication device to establish a third wireless connection between the communication device and the external device in accordance with the Wi-Fi standard; The computer program product according to claim 11 , further comprising:

18. The predetermined method is a DPP (Device Provisioning Protocol) method, The computer program product according to claim 11 , wherein the first connection information is a Configuration Object in the DPP format.

19. A terminal device, a first establishing unit that establishes a first wireless connection with a communication device according to the Wi-Fi standard; a public key transmission unit that transmits a public key to be used by the communication device to the communication device by performing communication at a network layer or higher of an OSI (short for Open Systems Interconnection) reference model using the first wireless connection; an authentication request transmission unit that transmits, after the public key is transmitted to the communication device, an authentication request using the public key, the authentication request conforming to a predetermined method of the Wi-Fi standard, to the communication device; an authentication response receiving unit that receives an authentication response according to the predetermined method from the communication device when the authentication request is transmitted to the communication device; a first connection information transmission unit that transmits first connection information according to the predetermined method to the communication device after the authentication response is received from the communication device, the first connection information being information used by the communication device to establish a second wireless connection according to the Wi-Fi standard between the communication device and an external device other than the terminal device; A terminal device comprising:

Citation Information

Patent Citations

  • Method of securing binding update by using address based key

    JP2003324419A

  • Image formation apparatus, image processing system, control program and communication management method

    JP2016225798A

  • Communication device, control method, and program

    JP2020072441A

  • Communication device, control method, and program

    JP2020088620A

  • Terminal apparatus and computer program for terminal apparatus

    JP2020113851A