Communication device and computer program for a communication device

The communication device effectively manages multiple coexisting standards by switching states based on detected standards, ensuring secure and appropriate service reception, particularly in environments with both WPA3 and earlier standard support.

JP7694124B2Active Publication Date: 2025-06-18BROTHER KOGYO KK
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021069960
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-04-16
Publication Date
2025-06-18
Estimated Expiration
2041-04-16

AI Technical Summary

Technical Problem

In a scenario where multiple communication standards coexist, existing communication devices struggle to appropriately receive services provided by a specific communication standard, leading to potential security vulnerabilities and connectivity issues.

Method used

A communication device equipped with a communication interface and a first receiving unit that can distinguish between different communication standards. It operates in a first state allowing connections to devices supporting both the first and second communication standards, and changes to a second state upon detecting a specific device supporting the first standard, thereby prioritizing its service.

Benefits of technology

Enables the communication device to appropriately receive services from the desired communication standard, enhancing security by preventing connections to potentially vulnerable devices that do not support the latest standards, such as WPA3.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007694124000001
    Figure 0007694124000001
  • Figure 0007694124000002
    Figure 0007694124000002
  • Figure 0007694124000003
    Figure 0007694124000003
Patent Text Reader

Abstract

To disclose a technique for appropriately receiving a service provided according to a specific communication standard in a situation where various communication standards are mixed.SOLUTION: A communication device receives signals from one or more external devices present around the communication device while the state of the communication device is a first state. The first state is a state for permitting both use of first connection with a first external device supporting a first communication standard and use of second connection with a second external device supporting a second communication standard and not supporting the first communication standard. When receiving a signal indicating that a specific external device of the one or more external devices is the first external device, the communication device changes the state of the communication device from the first state to a second state different from the first state. The second state is a state for permitting the use of the first connection and not permitting the use of the second connection.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology disclosed in this specification relates to a communication device connectable to an external device.

Background Art

[0002] As shown in Non-Patent Document 1, the Wi-Fi Alliance (registered trademark) has established WPA3, a new communication standard in the Wi-Fi system. WPA3 provides a next-generation security protocol. Also, other security protocols may be provided in communication standards other than WPA3.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Patent Document 2

Patent Document 3

Non-Patent Documents

[0004]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] With the establishment of new communication standards, a situation where various communication standards coexist is assumed. In this specification, in the above coexisting situation, a technology for appropriately receiving services provided by a specific communication standard is disclosed.

Means for Solving the Problems

[0006] The communication device disclosed in this specification includes a communication interface and a first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface while the state of the communication device is in a first state. The first state permits both the use of a first connection via the communication interface with a first external device that supports a first communication standard and the use of a second connection via the communication interface with a second external device that supports a second communication standard and does not support the first communication standard. The second communication standard is a communication standard different from the first communication standard. The first receiving unit and a first changing unit that changes the state of the communication device from the first state to a second state different from the first state when a signal indicating that a specific external device among the one or more external devices is the first external device is received. The second state permits the use of the first connection and does not permit the use of the second connection. The communication device comprises the first receiving unit and the first changing unit.

[0007] The presence of a first external device that supports a first communication standard among one or more external devices and the reception of a signal indicating that the first external device supports the first communication standard are presumed to indicate that the user of the communication device desires to receive a service provided by the first communication standard. According to the above configuration, when it is presumed that the user of the communication device desires to receive a service provided by the first communication standard, the state of the communication device is changed from the first state to the second state. In the second state, the use of the first connection according to the first communication standard is permitted, but the use of the second connection according to the second communication standard is not permitted. In a situation where the first communication standard and the second communication standard coexist, a service provided by the first communication standard can be appropriately received.

[0008] Other communication devices disclosed in this specification include a communication interface, a first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface, and when the signal indicating that a specific external device among the one or more external devices is a first external device supporting a first communication standard is not received, the communication device is operated in a first state, and when the signal indicating that the specific external device is the first external device is received, the communication device is operated in a second state. The operation control unit, wherein the first state is a state that permits both the use of a first connection via the communication interface with the first external device and the use of a second connection via the communication interface with a second external device that does not support the first communication standard, and the second state is a state that permits the use of the first connection and does not permit the use of the second connection. The first connection is a connection according to the first communication standard, and the second connection is a connection according to a second communication standard different from the first communication standard, and the operation control unit.

[0009] If there is a first external device that supports the first communication standard among one or more external devices, and a signal indicating that the first external device supports the first communication standard is received from the first external device, it is presumed that the user of the communication device wishes to receive the service provided by the first communication standard. According to the above configuration, when it is presumed that the user of the communication device wishes to receive the service provided by the first communication standard, the communication device operates in the second state. And in the second state, although the use of the first connection according to the first communication standard is permitted, the use of the second connection according to the second communication standard is not permitted. In a situation where the first communication standard and the second communication standard coexist, the service provided by the first communication standard can be appropriately received.

[0010] Also, not receiving a signal from the first external device that supports the first communication standard is presumed that the user of the communication device desires to receive services provided by the second communication standard rather than the first communication standard. According to the above configuration, when it is presumed that the user of the communication device desires to receive services provided by the second communication standard, the communication device operates in the first state. In the first state, not only the use of the first connection according to the first communication standard but also the use of the second connection according to the second communication standard is permitted. In a situation where the first communication standard and the second communication standard coexist, services provided by the second communication standard can be appropriately received.

[0011] Also, the above-described control method of the communication device, the computer program for the communication device, and the storage medium storing the computer program are also novel and useful.

Brief Description of Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Embodiments for Carrying Out the Invention

[0013] (First Embodiment) (Configuration of Communication System 2; Fig. 1) As shown in Fig. 1, the communication system 2 includes an MFP (abbreviation of Multifunction Peripheral) 10, a terminal device 100, and APs (abbreviations of Access Point) 200, 300, 400. Each of the APs 200, 300, 400 can form a wireless LAN (abbreviation of Local Area Network). The MFP 10 is connected to the wireless LAN formed by an AP (for example, 200) and can communicate with other devices (for example, the terminal device 100) connected to the wireless LAN. The terminal device 100 is a mobile terminal, a desktop PC, a notebook PC, etc.

[0014] (Configuration of MFP10; Fig. 1) The MFP 10 is a peripheral device (for example, a peripheral device of the terminal device 100) that can execute functions such as a printing function and a scanning function. The MFP 10 includes an operation unit 12, a display unit 14, a Wi-Fi interface 16, a printing execution unit 20, a scanning execution unit 22, and a control unit 30. Each of the units 12 to 30 is connected to a bus line (reference numeral omitted). Hereinafter, the interface is simply described as "I / F".

[0015] The operation unit 12 is provided with a plurality of keys. By operating the operation unit 12, the user can input various instructions into the MFP 10. The display unit 14 is a display for displaying various information. Note that the display unit 14 may function as a touch panel (i.e., the operation unit 12).

[0016] The Wi-Fi I / F 16 is a wireless I / F for performing wireless communication according to the Wi-Fi (registered trademark) standard. The Wi-Fi standard is a standard for performing wireless communication, for example, according to the 802.11 standard of IEEE (abbreviation for The Institute of Electrical and Electronics Engineers, Inc.) and standards equivalent thereto (such as 802.11a, 11b, 11g, 11n, etc.).

[0017] Also, the Wi-Fi I / F 16 supports WPA3's Personal and Enterprise. Personal is a method of authenticating slave stations in a small-scale wireless LAN such as a home. Enterprise is a method of authenticating slave stations in a large-scale wireless LAN such as a company. In Enterprise, an authentication server (see the third embodiment) that performs authentication according to IEEE's 802.1X authenticates the slave stations in the Wi-Fi standard. On the other hand, in Personal, no authentication server is used, and for example, the AP uses a PSK (Pre-Shared Key) to authenticate the slave stations.

[0018] WPA3 is a communication standard formulated by the Wi-Fi Alliance (registered trademark) after WPA2. WPA3 provides a next-generation security protocol. For example, in WPA3, SAE (Simultaneous Authentication of Equals) is newly provided as a method of authenticating slave stations.

[0019] In addition, in WPA3, the wireless connection is protected by PMF (short for Protected Management Frames). On the other hand, in WPA2, the wireless connection may or may not be protected by PMF.

[0020] The printing execution unit 20 is provided with a printing mechanism such as an inkjet method or a laser method. The scanning execution unit 22 is provided with a scanning mechanism such as a CCD (Charge Coupled Device) image sensor or a CIS (Contact Image Sensor).

[0021] The control unit 30 includes a CPU 32 and a memory 34. The CPU 32 executes various processes according to a program 40 stored in the memory 34. The memory 34 is composed of a volatile memory, a non-volatile memory, etc.

[0022] The memory 34 further stores WPA3 setting information 42. The WPA3 setting information 42 indicates any one of a plurality of settings including the setting "WPA3 Transition Mode" and the setting "WPA3 Only Mode". The setting "WPA3 Transition Mode" is a setting that permits both the establishment of a wireless connection according to WPA3 and the establishment of a wireless connection according to WPA2. For example, in the setting "WPA3 Transition Mode", both the authentication of slave stations using PSK and the authentication of slave stations using SAE are permitted. Here, PSK is a method available in standards prior to WPA2. Also, the setting "WPA3 Only Mode" is a setting that permits the establishment of a wireless connection according to WPA3 and does not permit the establishment of a wireless connection according to WPA2. For example, in the setting "WPA3 Only Mode", the authentication of slave stations using PSK is not permitted, and the authentication of slave stations using SAE is permitted.

[0023] At the shipping stage of the MFP10, the WPA3 setting information 42 indicates the setting "WPA3 Transition Mode". And the WPA3 setting information 42 after the power of the MFP10 is turned on for the first time indicates the setting "WPA3 Transition Mode" by default. Note that in a modified example, the default of the WPA3 setting information 42 may be another setting different from both the setting "WPA3 Transition Mode" and the setting "WPA3 Only Mode" (for example, a setting that only uses WPA2).

[0024] (Configuration of APs 200, 300, 400; FIG. 1) AP200 does not support WPA3. AP200 supports WPA2. Hereinafter, the fact that it does not support WPA3 may be described as "not WPA3 compatible". AP200 stores an SSID (abbreviation for Service Set Identifier) "ap01" that identifies the wireless network formed by AP200 and a password "xxxx" used in the wireless network.

[0025] AP300 supports WPA3. Hereinafter, the fact that it supports WPA3 may be described as "WPA3 compatible". AP300 stores an SSID "ap02" and a password "yyyy" used in the wireless network formed by AP300.

[0026] AP400 is an AP that is not WPA3 compatible. AP400 is an AP that can form an open network that does not require authentication of slave stations. AP400 supports, for example, Wi-Fi CERTIFIED Enhanced Open.

[0027] (Problem example) Before explaining this embodiment, a problem example will be described with reference to FIG. 2. In this problem example, Personal is used. The WPA3 setting information of the MFP850 in this problem example indicates the setting "WPA3 Transition Mode", and the WPA3 setting information of the MFP850 is not changed. In this problem example, a malicious third party attempts to prepare an AP900 and connect the MFP850 to the wireless network formed by the AP900. The SSID of the AP900 is set to the same "ap02" as the SSID of the AP300. The AP900 is an AP that supports WPA3.

[0028] When the MFP850 receives a connection instruction at Y10, it broadcasts a Probe request externally at T12. In this problem example, both AP300 and AP900 exist around the MFP850. The third party installs an AP900 around the MFP850 to block the communication of the AP300. Therefore, the MFP850 does not receive a Probe response from the AP300 at Y14 and receives a Probe response from the AP900.

[0029] At Y20, the MFP850 displays a selection screen including the SSID "ap02" of the AP900. At Y22, the MFP850 receives the selection of the SSID "ap02" within the selection screen. Y30 to Y34 indicate the Authentication communication for the AP900 to authenticate the MFP850 in this problem example. The AP900 supports WPA3. In this problem example, SAE Authentication is executed.

[0030] In Y30, the MFP850 executes communication with the AP900 for Commit. In the communication for Commit, a signal requesting the execution of SAE is sent from the MFP850 to the AP900. If the AP900 approves the request by this signal, the SAE Authentication is successful. However, in this problem example, the AP900 is designed to ignore the request by this signal by a third party. Therefore, in Y34, the MFP850 receives a Confirm Failed signal indicating that the SAE Authentication has failed from the AP900.

[0031] In this problem example, the WPA3 setting information of the MFP850 indicates the setting "WPA3 Transition Mode". Therefore, in Y36, instead of SAE Authentication, the MFP850 executes PSK Authentication. In Y36, the encryption key generated by the PSK is provided to both the AP900 and the MFP850.

[0032] In Y40, the MFP850 executes 4-way handshake communication with the AP900 using the encryption key provided in Y36. As a result, in Y50, a wireless connection for executing wireless communication according to the Wi-Fi standard is established between the MFP850 and the AP900.

[0033] Although the AP900 supports WPA3, it operates as a WPA3-incompatible AP. Therefore, the AP900 does not use the security protocol provided by WPA3. A third party attempts to eavesdrop on the communication using, for example, the vulnerable AP900.

[0034] (Case C1, C2; Figure 3) Referring to Figure 3, specific cases C1 and C2 realized by the communication system 2 of this embodiment will be described. Case C1 shows a case of dealing with the problem example in Figure 2 in this embodiment. Case C2 is a case of establishing a wireless connection between the MFP10 and the AP300.

[0035] In cases C1 and C2, and cases C2 to C5 in FIGS. 3 to 6 and the second embodiment in FIG. 8 described below, WPA3 Personal is used. In the initial stage of this case, the WPA3 setting information 42 of the MFP 10 indicates the setting "WPA3 Transition Mode" by default. In the first embodiment and the second to fourth embodiments described below, all the following communications executed by the MFP 10 are executed via the Wi-Fi I / F 16. Hereinafter, when explaining the processing related to communication, the description "via the Wi-Fi I / F 16" may be omitted. Further, hereinafter, for the sake of easy understanding, the operations executed by the CPU (for example, CPU 32, etc.) of each device may be described mainly with each device (for example, MFP 10) instead of mainly with the CPU.

[0036] (Case C1; FIG. 3) When the MFP 10 receives an instruction to establish a wireless connection at the operation unit 12 at T10, at T12, the MFP 10 broadcasts a Probe request for searching for an AP existing around the MFP 10 to the outside. In this case, around the MFP 10, there are a WPA3-compatible AP 900 prepared by a third party and an AP 300 prepared by the administrator of the MFP 10, and no other APs exist. Here, communication by a third party is blocked for the AP 300. Therefore, at T14, the MFP 10 receives a Probe response from the AP 900 and does not receive a Probe response from the AP 300. The Probe response from the AP 900 includes the SSID "ap02" of the AP 900 and WPA3-compatible information indicating that the AP 900 supports WPA3. The WPA3-compatible information includes, for example, information indicating the use of SAE.

[0037] In T16, MFP10 determines whether there is a WPA3 - compliant AP among one or more APs (hereinafter referred to as "one or more surrounding APs") existing around MFP10. Specifically, MFP10 determines whether there is a Probe response containing WPA3 - compliant information (hereinafter referred to as "corresponding Probe response") among one or more Probe responses received from one or more surrounding APs. And when there is a corresponding Probe response among one or more Probe responses, MFP10 determines that there is a WPA3 - compliant AP among one or more surrounding APs. On the other hand, when there is no corresponding Probe response among one or more Probe responses, MFP10 determines that there is no WPA3 - compliant AP among one or more surrounding APs.

[0038] In this case, there are two WPA3 - compliant APs, AP300 and AP900, around MFP10, and there is no WPA3 - non - compliant AP. And MFP10 receives a Probe response from the WPA3 - compliant AP900. In this case, MFP10 determines in T16 that there is a WPA3 - compliant AP among one or more surrounding APs and proceeds to the process of T18. Incidentally, if only WPA3 - non - compliant APs exist around MFP10, the process of T18 is not executed, and the WPA3 setting information 42 is maintained in the setting of "WPA3 Transition Mode".

[0039] In T18, MFP10 changes the WPA3 setting information 42 from the setting of "WPA3 Transition Mode" to the setting of "WPA3 Only Mode".

[0040] In subsequent T20, the MFP10 displays a selection screen for selecting one AP from among one or more surrounding APs. The selection screen includes, for each of the one or more surrounding APs, the SSID in the Probe response received from the AP, a button for selecting the SSID, and a message indicating whether the AP supports WPA3. In this case, the selection screen includes only the SSID "ap02" of the AP900. Also, the selection screen includes an input field for the AP password in addition to the list of SSIDs.

[0041] In T22, the user operates the operation unit 12 of the MFP10 to select the SSID "ap01" and enter the password "yyyy" on the selection screen.

[0042] Subsequent T30 and T34 are the same as Y30 and Y34 in FIG. 2 except that the MFP10 is used. In this case, at the timing when T30 is executed, the WPA3 setting information 42 is changed to the setting "WPA3 Only Mode" (T18). For this reason, the MFP10 does not execute PSK Authentication instead of SAE Authentication. In T36, the MFP10 causes the display unit 14 to display a connection error indicating that the establishment of the wireless connection has failed.

[0043] According to this case, since the WPA3 setting information 42 indicates the setting "WPA3 Only Mode" at the timing of executing Authentication, the occurrence of the problem example in FIG. 2 can be suppressed.

[0044] (Case C2; FIG. 3) In this case, the MFP10 executes the same processing as T10 to T22 with the AP300. T130 is the same as T30 except that the AP300 is used. In this case, the AP300 approves the request to execute SAE in the Commit communication. For this reason, in T134, the MFP10 receives a Confirm Success signal from the AP300 indicating that the SAE Authentication has been successful.

[0045] In the authentication at T130 and T134, authentication according to SAE is executed. When the authentication is successful, an encryption key generated using the password "yyyy" input at T22 is provided to both AP300 and MFP10. Note that after the communication for authentication is successful, communication for association (not shown in the figure) is executed.

[0046] At T140, MFP10 executes 4-way handshake communication with AP300 using the encryption key provided at T130. As a result, at T150, a wireless connection for executing wireless communication according to the Wi-Fi standard is established between MFP10 and AP300. Also, in this case, the WPA3 setting information 42 of MFP10 indicates the setting "WPA3 Only Mode", and AP300 supports WPA3. Therefore, in the 4-way handshake of this case, communication for receiving management by PMF is executed. And the wireless connection at T150 is managed by PMF.

[0047] For example, in a situation where both MFP10 and terminal device 100 are connected to a wireless LAN formed by AP300, at T160, the terminal device 100 transmits print data indicating an image to be printed to MFP10 via AP300.

[0048] When MFP10 receives print data from the terminal device 100 at T160, at T162, it causes the print execution unit 20 to execute printing of the image indicated by the received print data.

[0049] For example, a situation is assumed where a malicious third party attempts to connect the MFP10 to a wireless network formed by an AP800 prepared by the third party instead of the AP300. The SSID of the AP800 is set to the same "ap02" as the SSID of the AP300. The AP800 is an AP that does not support WPA3 and does not support the security protocol provided by WPA3. Therefore, the AP800 is more vulnerable in terms of security compared to the AP300. For example, a third party attempts to eavesdrop on the communication using the vulnerable AP800.

[0050] In the above situation, the third party first interferes with the communication between the AP300 and the MFP10 to disconnect the wireless connection between the AP300 and the MFP10. The MFP10 detects the disconnection of the wireless connection at T170. In order to attempt to re-establish the wireless connection, the MFP10 broadcasts a Probe request externally at T172. At T174, since the communication with the AP300 is being interfered with, the MFP10 receives a Probe response to the Probe request from the AP800. The Probe response includes the SSID "ap02" and WPA3 non-compliance information indicating that the AP800 supports a standard prior to WPA2.

[0051] In this case, in the above T18, the WPA3 setting information 42 is changed to the setting "WPA3 Only Mode". As described above, in the setting "WPA3 Only Mode", authentication of slave stations using PSK is not permitted, and authentication of slave stations using SAE is permitted. In this case, since the AP800 does not support WPA3, the AP800 attempts to authenticate a slave station using PSK. However, since authentication of a slave station using PSK is not permitted by the MFP10, the authentication fails. As a result, the establishment of the wireless connection between the AP800 and the MFP10 fails.

[0052] For example, a comparative example is assumed in which the above-described process of T18 is not executed and the WPA3 setting information 42 is maintained in the setting of "WPA3 Transition Mode". As described above, in the setting of "WPA3 Transition Mode", both the authentication of the child station using PSK and the authentication of the child station using SAE are permitted. Therefore, in this comparative example, the authentication of the child station using PSK attempted by the AP800 is successful, and a wireless connection can be established between the AP800 and the MFP10. In contrast, according to this case, a wireless connection is not established between the AP800 and the MFP10, and eavesdropping of communication using a third-party AP800 can be suppressed.

[0053] Also, the presence of the AP300 that supports the SAE of WPA3 among one or more surrounding APs and the reception of a Probe response including WPA3-compatible information from the AP300 are presumed that the user wishes to receive the service provided by SAE (that is, communication having a relatively high encryption strength). According to the configuration of this embodiment, when it is presumed that the user wishes to receive the service provided by SAE, the WPA3 setting information 42 is changed from the setting of "WPA3 Transition Mode" to the setting of "WPA3 Only Mode" (T18 in FIG. 3). In a situation where the SAE of WPA3 and the PSK before WPA2 coexist, the service provided by the SAE of WPA3 can be appropriately received.

[0054] (Case C3; FIG. 4) Referring to FIG. 4, another specific case C3 will be described. This case is a case where a wireless connection is established between the MFP10 and the AP in a situation where there are a WPA3-incompatible AP and a WPA3-compatible AP around the MFP10. The initial stage of this case is the same as that of case C1 in FIG. 3.

[0055] T210, T212A, T212B, and T212C are the same as T10, T12 in FIG. 3. In this case, there are three APs, AP200, AP300, and AP400, around the MFP10. AP200 is a WPA3-incompatible AP, AP300 is a WPA3-compatible AP, and AP400 is an AP that forms an open network. Therefore, in T214A, T214B, and T214C, the MFP10 receives Probe responses from each of the three APs, AP200, AP300, and AP400. The Probe response of AP200 includes the SSID "ap01" and WPA3-incompatible information. The Probe response of AP400 includes the SSID "ap03" and OPEN information indicating that AP400 is an AP that forms an open network.

[0056] T216 is the same as T16 in FIG. 3. In this case, in T216, the MFP10 determines that there is a WPA3-compatible AP among one or more surrounding APs and proceeds to the process of T218. T218 is the same as T18 in FIG. 3.

[0057] In T220, the MFP10 causes the display unit 14 to display a first selection screen that includes the SSID "ap02" of the WPA3-compatible AP300 and does not include the SSIDs "ap01" and "ap03" of the WPA3-incompatible APs, AP200 and AP400. With such a configuration, it is possible to prompt the user to connect to a WPA-compatible AP.

[0058] In addition, the first selection screen of T220 further includes an "Other AP" button. The "Other AP" button is a button for further displaying a second selection screen that allows selection of APs other than the WPA3-compatible AP. In this case, the second selection screen includes not only the SSID "ap02" of the WPA3-compatible AP300 but also the SSIDs "ap01" and "ap03" of the WPA3-incompatible APs 200 and 400. The second selection screen also includes an input field for the AP password. With such a configuration, in a situation where there are both WPA3-compatible and WPA3-incompatible APs, the user can be allowed to select a connection to the WPA3-incompatible AP. Note that in a modified example, the second selection screen may not include the SSID "ap02" of the WPA3-compatible AP300 and may include the SSIDs "ap01" and "ap03" of the WPA3-incompatible APs 200 and 400.

[0059] At T222, the user operates the operation unit 12 of the MFP10 to select the SSID "ap01" on the second selection screen and enter the password "xxxx".

[0060] At T224, the MFP10 changes the WPA3 setting information 42 from the setting "WPA3 Only Mode" to the setting "WPA3 Transition Mode". The selection of the SSID "ap01" of the WPA3-incompatible AP200 on the second selection screen is presumed to indicate that the user wishes to connect to the WPA3-incompatible AP200. According to the configuration of T224, it is possible to permit a connection to the WPA3-incompatible AP200 according to the user's wish.

[0061] At T230, the MFP10 executes PSK Authentication communication with the AP200 selected at T222. T240 is the same as T140 in FIG. 3 except that the AP200 is used, the encryption key provided by the PSK of T230 is used, and communication for receiving management by PMF is not executed. T250 is the same as T150 in FIG. 3 except that it does not receive management by PMF.

[0062] In this case, even if there is an AP that does not support WPA3 (for example, 200) among one or more surrounding APs, the MFP10 changes the WPA3 setting information 42 to the setting "WPA3 Only Mode" (T218). Even in a situation where there is an AP that does not support WPA3 among one or more surrounding APs, the occurrence of the problem in FIG. 2 can be suppressed.

[0063] (Case C4; FIG. 5) Referring to FIG. 5, Case C3, which is a continuation of T150 in Case C2 of FIG. 3, will be described. In this case, after the wireless connection with the AP300 is established at T150, a WPA3-incompatible AP200 is installed around the MFP10. In this case, for example, the power of the AP300 is turned off. At the initial stage of this case, the WPA3 setting information 42 of the MFP10 indicates the setting "WPA3 Only Mode".

[0064] T260 and T262 are the same as T10 and T12 in FIG. 3. T264 is the same as T214B in FIG. 4.

[0065] T266 is the same as T16 in FIG. 3. In this case, due to the fact that the power of the AP300 is turned off, there is no corresponding Probe response among one or more Probe responses received from one or more surrounding APs. In this case, the MFP10 determines that there is no WPA3-compatible AP among one or more surrounding APs and proceeds to the process of T268.

[0066] In T268, the MFP10 changes the WPA3 setting information 42 from the setting "WPA3 Only Mode" to the setting "WPA3 Transition Mode". T270 is the same as T20 in FIG. 3 except that the selection screen includes the SSID "ap01" of the AP200. T272 is the same as T22 in FIG. 3 except that the SSID "ap01" is selected and the password "xxxx" of the AP200 is input. T280 to T300 are the same as T230 to T250 in FIG. 4.

[0067] Failure to receive a Probe response from the AP300 that supports SAE of WPA3 is presumed to indicate that the user desires to receive services provided by PSK rather than SAE. According to this case, when it is presumed that the user desires to receive services provided by PSK, the WPA3 setting information 42 is changed from the setting "WPA3 Only Mode" to the setting "WPA3 Transition Mode" (T268). In a situation where SAE of WPA3 and PSK prior to WPA2 coexist, services provided by PSK can be appropriately received.

[0068] (Case C5; Figure 6) Referring to Figure 6, Case C5 in which the terminal device 100 is used in connection with an AP will be described. In this case, the MFP10 and the terminal device 100 are connected by a wired or wireless LAN, USB, a wireless connection according to Bluetooth (registered trademark), etc. (not shown). Further, the terminal device 100 stores connection information for connecting to the wireless LAN formed by the AP200 or AP300. The connection information includes an SSID and a password. Also, at the initial stage of this case, the WPA3 setting information 42 of the MFP10 indicates the setting "WPA3 Transition Mode".

[0069] At T305, the user operates the terminal device 100 to input an instruction to connect the MFP10 to an AP (for example, AP200) corresponding to the connection information stored in the terminal device 100.

[0070] Upon receiving the user's instruction at T305, the terminal device 100 transmits an establishment request to the MFP10 at T310 to request connection to the AP. The establishment request includes the SSID stored in the terminal device 100.

[0071] When MFP10 receives an establishment request from the terminal device 100 at T310, at T312, it unicasts a Probe request including the SSID contained in the establishment request to the AP indicated by the SSID (hereinafter referred to as the "target AP").

[0072] At T314, MFP10 receives a Probe response from the target AP as a response to the Probe request of T312. When the target AP is AP200, the Probe response includes the SSID "ap01" and non-WPA3 compatible information. When the target AP is AP300, the Probe response includes the SSID "ap02" and WPA3 compatible information.

[0073] In the subsequent T316, MFP10 determines whether the target AP is a WPA3-compatible AP. Specifically, MFP10 determines that the target AP is a WPA3-compatible AP when the Probe response received from the target AP includes WPA3-compatible information. When MFP10 determines that the target AP is a WPA3-compatible AP (YES at T316), it proceeds to T318. T318 is the same as T18 in Figure 3. When T318 ends, MFP10 proceeds to T320. On the other hand, when MFP10 determines that the target AP is a non-WPA3-compatible AP (NO at T316), it skips the processing of T318 and proceeds to T320.

[0074] At T320, MFP10 executes processing to establish a wireless connection with the target AP. When the target AP is a WPA3-compatible AP, the same processing as T130 - T150 in Figure 3 is executed. When the target AP is a non-WPA3-compatible AP, the same processing as T230 - T250 in Figure 4 is executed.

[0075] For example, even in this case, a situation is assumed where a third party prepares an AP900 instead of the AP300. According to the configuration of this case, even when a connection request is received from the terminal device 100, the WPA3 setting information 42 is changed to the setting "WPA3 Only Mode" (T318). Even in this case, the occurrence of the problem in FIG. 2 can be suppressed.

[0076] Also, according to the configuration of this case, when the target AP is an AP that does not support WPA3, the WPA3 setting information 42 is maintained at the setting "WPA3 Transition Mode". According to the wishes of the user who wishes to connect to an AP that does not support WPA3, a connection with the AP200 can be established.

[0077] (Table showing the relationship between the AP and the MFP; FIG. 7) As shown in FIG. 7, due to the formulation of WPA3, as APs, there can be APs that do not support WPA3 and support WPA or WPA2, APs that support WPA3 and support the WPA3 Transition Mode, and APs that support WPA3 and support the WPA3 Only Mode.

[0078] On the other hand, as MFPs, there can be MFPs that do not support WPA3, MFPs that support WPA3 and operate in the WPA3 Transition Mode, and MFPs that support WPA3 and operate in the WPA3 Only Mode.

[0079] In this embodiment, the WPA3 setting information 42 of the MFP10 is changed to the setting "WPA3 Only Mode" (T18 in FIG. 3). Therefore, the MFP10 can establish a wireless connection with either an AP that supports WPA3 and supports the WPA3 Transition Mode or an AP that supports WPA3 and supports the WPA3 Only Mode. In both cases, WPA3 is used. On the other hand, the MFP10 cannot establish a wireless connection with an AP that does not support WPA3.

[0080] (Corresponding relationship) The MFP10, Wi-Fi I / F 16, display unit 14, and printing execution unit 20 are each an example of a "communication device", "communication interface", "display unit", and "image processing execution unit", respectively. The terminal device 100 is an example of a "terminal device". The APs 300 and 200 are examples of a "first external device" and a "second external device", respectively. The WPA3 Transition and WPA3 Only Mode are each an example of a "first state" and a "second state", respectively. The SAE and PSK are each an example of a "first communication standard" and a "second communication standard", respectively. The Probe response including WPA3-compatible information is an example of a "signal". The instruction of T10 in FIG. 3 is an example of a "specific instruction". The print data of T160 in FIG. 3 is an example of a "specific request". The selection of T222 in FIG. 4 is an example of an "instruction to establish a second connection". The list of SSIDs in T220 in FIG. 4 is an example of a "list". Selecting the "Other AP" button in the first selection screen of T220 in FIG. 4 is an example of a "predetermined instruction". The establishment request of T310 in FIG. 6 is an example of an "establishment request". The WPA3-compatible information and WPA3-incompatible information in T314 are an example of "specific standard information".

[0081] The processes realized by T14 and T18 in FIG. 3 are examples of the processes realized by a "first receiving unit" and a "first changing unit (and operation control unit)".

[0082] (Second Embodiment) This embodiment is the same as the first embodiment, except that the processes executed when receiving a Probe response are different.

[0083] (Specific Case; FIG. 8) This case is a case where a wireless connection is established between the MFP10 and an AP in a situation where a WPA3-incompatible AP and a WPA3-compatible AP exist around the MFP10, similar to case C3 in FIG. 4. The initial stage of this case is the same as case C3 in FIG. 4.

[0084] T410 to T414C are the same as T210 to T214C in FIG. 4. At T416, MFP10 determines whether there is a WPA3 - non - compliant AP among one or more surrounding APs. In this case, there are WPA3 - non - compliant APs 200 and 400 around MFP10. In this case, MFP10 determines that there is a WPA3 - non - compliant AP among one or more surrounding APs. In this case, MFP10 maintains the WPA3 setting information 42 set to "WPA3 Transition Mode". On the other hand, if, for example, as in case C1 of FIG. 3, only the WPA3 - compliant AP 300 exists around MFP10, MFP10 determines that there is no WPA3 - non - compliant AP among one or more surrounding APs. In this case, MFP10 changes the WPA3 setting information 42 from the setting "WPA3 Transition Mode" to the setting "WPA3 Only Mode" (refer to T18 in FIG. 3).

[0085] T420 is the same as T220 in FIG. 4. In this case, the user wishes to connect to the WPA3 - compliant AP 300. At T422, the user operates the operation unit 12 of MFP10 and selects the SSID "ap02" and enters the password "yyyy" on the first selection screen. At T424, MFP10 changes the WPA3 setting information 42 from the setting "WPA3 Transition Mode" to the setting "WPA3 Only Mode". T430 to T450 are the same as T140 to T150 in FIG. 3. Incidentally, if the "Other AP" button is selected on the first selection screen and the SSID of a WPA3 - non - compliant AP is selected on the second selection screen, the WPA3 setting information 42 is maintained at the setting "WPA3 Transition Mode".

[0086] In the first embodiment, in a situation where the user wishes to connect to a WPA3-incompatible AP, the WPA3 setting information 42 is changed to the setting "WPA3 Only Mode" (T218 in FIG. 4), and then the WPA3 setting information 42 is changed back to the setting "WPA3 Transition Mode". Instead of this, in the present embodiment, in a situation where the user wishes to connect to a WPA3-incompatible AP, the WPA3 setting information 42 is maintained at the setting "WPA3 Transition Mode". In a situation where the user wishes to connect to a WPA3-incompatible AP, it is possible to suppress unnecessarily changing the WPA3 setting information 42.

[0087] In the present embodiment, when the SSID "ap01" of the WPA3-compatible AP 300 is selected on the first selection screen (T422), the WPA3 setting information 42 is changed to the setting "WPA3 Only Mode" (T424). Also in the present embodiment, similar to the first embodiment, it is possible to suppress the occurrence of the problem in FIG. 2 and execute a process for establishing a connection with the WPA3-compatible AP 300. The selection at T422 in FIG. 8 is an example of an "instruction for establishing a first connection".

[0088] (Third Embodiment) (Configuration of Communication System 2; FIG. 1) The communication system 2 of the present embodiment is the same as the first embodiment except for the following points. The APs 200 and 300 of the present embodiment are WPA3-incompatible APs and support WPA2. The AP 200 operates in PMF Capable. The AP 300 operates in PMF Required. Hereinafter, operating in PMF Required may be described as "PR operation", and not operating in PMF Required may be described as "PR non-operation". In a modification, the AP 300 may be a WPA3-compatible AP.

[0089] The memory 34 of the MFP10 stores PMF configuration information 44 instead of WPA3 configuration information 42. The PMF configuration information 44 indicates any one of a plurality of configurations including the setting "PMF Capable" and the setting "PMF Required". The setting "PMF Capable" is a setting that permits both the establishment of a wireless connection without using PMF and the establishment of a wireless connection using PMF. The setting "PMF Required" is a setting that permits the establishment of a wireless connection using PMF and does not permit the establishment of a wireless connection without using PMF.

[0090] (Specific case of this embodiment; Figure 9) Referring to Figure 9, a specific case of this embodiment will be described. The AP900 in this case operates with WPA2 and PMF Required. In the initial stage of this case, the PMF configuration information 44 of the MFP10 indicates the setting "PMF Capable" by default.

[0091] T610 and T612 are the same as T10 and T12 in Figure 3. T614 is the same as T14 in Figure 3 except that the Probe response includes PMF information. The PMF information is information indicating that the AP900 that is the source of the Probe response operates with PMF Required. If the AP that is the source of the Probe response does not support PMF Required, the Probe response does not include PMF information.

[0092] In T616, the MFP10 determines whether there is an AP operating in PR mode among one or more surrounding APs. Specifically, the MFP10 determines whether there is a Probe response including PMF information among one or more Probe responses received from one or more surrounding APs. Then, when there is a Probe response including PMF information among one or more Probe responses, the MFP10 determines that there is an AP operating in PR mode among one or more surrounding APs. On the other hand, when there is no Probe response including PMF information among one or more Probe responses, the MFP10 determines that there is no AP operating in PR mode among one or more surrounding APs.

[0093] In this case, around the MFP10, there are two APs, AP300 and AP900, operating in the PR mode, and no AP is operating in the non-PR mode. Then, the MFP10 receives a Probe response from the AP900 operating in the PR mode. In this case, at T616, the MFP10 determines that there is an AP operating in the PR mode among one or more surrounding APs, and proceeds to the process of T618. Incidentally, if only APs operating in the non-PR mode exist around the MFP10, the process of T618 is not executed, and the PMF setting information 44 is maintained at the setting of "PMF Capable".

[0094] At T618, the MFP10 changes the PMF setting information 44 from the setting of "PMF Capable" to the setting of "PMF Required".

[0095] T622 to T634 are the same as T22 to T34 in FIG. 3. At T636, PSK Authentication is executed. Also in this case, a malicious third party prepares an AP900 for the purpose of eavesdropping on communications. Although the AP900 operates with PMF Required, it is set not to use PMF.

[0096] At T640, the MFP10 executes 4-way handshake communication with the AP900 using the encryption key provided at T636. The AP900 notifies the MFP10 that it does not use PMF in the 4-way handshake communication. However, since the MFP10 does not permit the establishment of a wireless connection that does not use PMF, the 4-way handshake communication fails. T642 is the same as T36 in FIG. 3. Also in this case, the occurrence of the problem in FIG. 2 can be suppressed.

[0097] (Table showing the relationship between the AP and the MFP; FIG. 10) As shown in FIG. 10, depending on the determination of the PMF, as an AP, there may be a PR non-operating AP operating in PMF Disable, a PR non-operating AP operating in PMF Capable, and a PR operating AP operating in PMF Required. Here, PMF Disable is a setting that permits the establishment of a wireless connection without using PMF and does not permit the establishment of a wireless connection using PMF.

[0098] On the other hand, as an MFP, there may also be an MFP operating in PMF Disable, a WPA3-compatible MFP operating in PMF Capable, and a WPA3-compatible MFP operating in PMF Required.

[0099] In this embodiment, the PMF setting information 44 of the MFP 10 is changed to the setting "PMF Required" (T618 in FIG. 9). Therefore, the MFP 10 can establish a wireless connection with either a PR non-operating AP operating in PMF Capable or a PR operating AP operating in PMF Required. In both cases, PMF is used. On the other hand, the MFP 10 cannot establish a wireless connection with a PR non-operating AP operating in PMF Disable (i.e., a wireless connection without using PMF).

[0100] (Corresponding relationship) PMF Capable and PMF Required are examples of "the first state" and "the second state", respectively.

[0101] (Fourth Embodiment) (Communication System 2; FIG. 11) In this embodiment, the MFP 10 uses Enterprise. As described above, Enterprise is a communication standard used by companies and the like. Enterprise is provided not only with WPA3 but also with WPA2.

[0102] The communication system 2 of this embodiment is the same as the communication system 2 of the first embodiment, except that it includes authentication servers 210 and 310 and the content of the WPA3 setting information 42 is different.

[0103] The authentication servers 210 and 310 are authentication servers used in Enterprise. The authentication server 210 is used in the process for establishing a wireless connection with the AP 200 and is connected to the AP 200 via a wired LAN. The authentication server 310 is used in the process for establishing a wireless connection with the AP 300 and is connected to the AP 300 via a LAN (wired or wireless).

[0104] Also, the WPA3 setting information 42 of this embodiment indicates any one of a plurality of settings including the setting "SHA256 optional" and the setting "SHA256 mandatory". The setting "SHA256 optional" permits the use of both a hash function (e.g., SHA1) that is available for both WPA2 and WPA and a hash function "SHA256" that is available for WPA3 and not available for WPA2 and WPA in the communication with the authentication server in Enterprise. That is, when the WPA3 setting information 42 indicates the setting "SHA256 optional", both the establishment of a wireless connection according to WPA2 or WPA and the establishment of a wireless connection according to WPA3 are permitted. Note that the hash function available for WPA3 is not limited to SHA256 and may be, for example, SHA384 or SHA3.

[0105] On the other hand, the setting "SHA256 mandatory" permits the use of the hash function "SHA256" and does not permit the use of a hash function that is available for both WPA2 and WPA in the communication with the authentication server in Enterprise. That is, when the WPA3 setting information 42 indicates the setting "SHA256 mandatory", the establishment of a wireless connection according to WPA3 is permitted, and the establishment of a wireless connection according to WPA2 or WPA is not permitted. Note that in the setting "SHA256 mandatory", the use of SHA384 or SHA3 may be permitted.

[0106] SHA256 is a hash function that outputs a return value having a length of 256 bits. The length of the return value of SHA256 is longer than the length of the return value of SHA1. The cryptographic strength of SHA256 is higher than the cryptographic strength of SHA1.

[0107] (Specific case of this embodiment; FIG. 12) Referring to FIG. 12, a specific case of this embodiment will be described. AP900 in this case is the same as that in the first embodiment, except that it is connected to an authentication server 910 prepared by a third party. In the initial stage of this case, the WPA3 setting information 42 of the MFP10 indicates "SHA256 optional" by default.

[0108] T710 to T714 are the same as T10 to T14 in FIG. 2. Note that the WPA3 compatibility information of T714 includes information indicating the hash function "SHA256" used in communication with the authentication server. T716 is the same as T16 in FIG. 3. At T718, the MFP10 changes the WPA3 setting information 42 from "SHA256 optional" to "SHA256 mandatory".

[0109] T720 is the same as T20 in FIG. 3, except that the selection screen includes an input field for the user password used for authentication in the authentication server instead of the input field for the AP password. T722 is the same as T22 in FIG. 3, except that the user password "pppp" stored in the authentication server 310 associated with the user name indicating the user of the MFP10 is input into the input field for the user password. T730 to T734 are the same as T30 to T34 in FIG. 3. T736 is the same as Y36 in FIG. 2, except that the MPF10 is used.

[0110] At T740, the MFP10 transmits a Client Hello signal to the authentication server 910 via the AP900. The communication between the MFP10 and the AP900 is encrypted according to TLS (abbreviation for Transport Layer Security). The Client Hello signal is a signal for notifying the authentication server 310 that the MFP10 starts operating as a TLS client.

[0111] In T742, the MFP10 receives a Server Hello signal from the authentication server 910 via the AP900 as a response to the Client Hello signal. The Server Hello signal is a signal that notifies the MFP10 that the authentication server 910 starts operating as a TLS server.

[0112] In this case, a malicious third party prepares the AP900 and the authentication server 910 for the purpose of intercepting communication. The authentication server 910 is a server that executes EAP (abbreviation for Extensible Authentication Protocol) authentication according to WPA2. EAP authentication includes user authentication and key exchange. User authentication is communication for the authentication server 910 to authenticate the user of the MFP10 using the user password received from the MFP10. Key exchange is communication for the authentication server 910 to provide both the MFP10 and the AP900 with the encryption keys used in the 4-way handshake communication when the user authentication is successful.

[0113] As described above, the authentication server 910 executes EAP authentication using the hash function "SHA1". Therefore, the authentication server 910 notifies the MFP10 of the use of the hash function "SHA1" in the Server Hello signal of T742. However, in this case, in T718, the WPA3 setting information 42 is changed from the setting "SHA256 optional" to the setting "SHA256 mandatory". As described above, in the setting "SHA256 mandatory", communication with an authentication server using the hash function "SHA1" is not permitted. Therefore, the MFP10 determines that it is impossible to execute EAP authentication with the authentication server 910 in T744. T746 is the same as T36 in FIG. 3. According to this case, in WPA3 Enterprise as well, the occurrence of the same problem as in FIG. 2 can be suppressed.

[0114] (Corresponding relationship) SHA256 optional and SHA256 mandatory are examples of the "first state" and the "second state", respectively.

[0115] (Example 5) In this example, the MFP 10 communicates with a management server that manages the state of the MFP 10. The communication between the MFP 10 and the management server is executed according to TCP (abbreviation for Transmission Control Protocol). Further, the communication between the MFP 10 and the management server is encrypted according to TLS. For example, the MFP 10 periodically transmits information indicating the state of the MFP 10 (such as the remaining ink amount) to the management server.

[0116] (Configuration of Communication System 2; Fig. 13) The communication system 2 of this example is the same as the communication system 2 of the first example, except that it includes management servers 600 and 700 instead of APs 200 and 300, and the configuration of the MFP 10 is different.

[0117] The management server 600 supports TLS version 1.2. The management server 700 supports a new TLS version 1.3 formulated after version 1.2. The management servers 600 and 700 are connected to the LAN 4. The LAN 4 is a wired LAN. Note that "1.3" is a number representing the latest version and is just an example.

[0118] (Configuration of MFP 10; Fig. 13) The MFP 10 of this example is the same as that of the first example, except that it includes a LAN I / F 60 instead of a Wi-Fi I / F 16, stores TLS setting information 50 instead of WPA3 setting information 42, and the memory 34 stores a MAC address list 52. The LAN I / F 60 is an I / F for executing communication via the LAN 4 and is connected to the LAN 4. Also, the MFP 10 of this example supports TLS version 1.3.

[0119] The TLS setting information 50 indicates any one of a plurality of settings including the setting "TLS1.3 non-required" and the setting "TLS1.3 required". The setting "TLS1.3 non-required" is a setting that permits the use of both TLS version 1.3 and TLS versions prior to version 1.2. The setting "TLS1.3 required" is a setting that permits the use of TLS version 1.3 and does not permit the use of TLS versions prior to version 1.2.

[0120] The MAC address list 52 indicates a list of MAC addresses of management servers that support TLS version 1.3 and are connected to LAN4 by the administrator of the MFP10. The MAC address list 52 is stored in the MFP10 by the administrator. In a modified example, the MAC address list 52 may be stored in an external device different from the memory 34 (for example, a server separate from the MFP10, etc.).

[0121] (Specific cases of this embodiment; FIG. 14) Referring to FIG. 14, specific cases D1 and D2 of this embodiment will be described. Case D1 is a case where communication according to TLS is executed between the MFP10 and the management server 700. Case D2 shows a case of dealing with a problem example similar to the problem example in FIG. 2 in this embodiment.

[0122] In the initial stages of cases D1 and D2, the TLS setting information 50 of the MFP10 indicates the setting "TLS1.3 non-required" by default. All of the following communications executed by the MFP10 of this embodiment are executed via the LANI / F60. Hereinafter, when describing the processing related to communication, the description "via the LANI / F60" may be omitted.

[0123] Also, in cases D1 and D2, assume a situation where a new management server 700 is installed in addition to the management server 600. In this case, the user inputs the IP address of the management server 700 into the MFP10 instead of the IP address of the management server 600.

[0124] (Case D1; Figure 14) In T810, the user operates the operation unit 12 of the MFP 10 to input an instruction for a TCP connection with the management server 700. For example, communication between the MFP 10 and the management server is periodically executed while the power of the MFP 10 is on. A TCP-compliant connection with the management server 700 (hereinafter referred to as a TCP connection) is established triggered by the power of the MFP 10 being turned on after the input of the IP address of the management server 700.

[0125] In T812, the MFP 10 transmits an ARP (abbreviation for Address Resolution Protocol) request addressed to the IP address of the management server 700. The ARP request is a signal requesting the MAC address of the management server.

[0126] In T814, the MFP 10 receives, as a response to the ARP request in T812, an ARP response including the MAC address MA1 of the management server 700 from the management server 700. In T816, a TCP connection is established between the MFP 10 and the management server 700.

[0127] In T818, the MFP 10 determines whether the MAC address in the ARP response received from the management server is included in the MAC address list 52. In this case, the MFP 10 determines that the MAC address MA1 included in the ARP response in T814 is included in the MAC address list 52 and proceeds to the process of T819. On the other hand, if it is determined that the MAC address in the ARP response is not included in the MAC address list 52, the MFP 10 skips the process of T819 and proceeds to the process after T820. In this case, the MFP 10 executes communication according to TLS 1.2 with the management server 600 that supports TLS 1.2, for example.

[0128] In T819, the MFP 10 changes the TLS setting information 50 from the setting "TLS 1.3 not required" to the setting "TLS 1.3 required".

[0129] In T820, the MFP10 uses the TCP connection established in T816 to send a Client Hello signal to the management server 700. In T820, the MFP10 uses the established TCP connection to receive a Server Hello signal from the management server 700. The Server Hello signal contains information indicating that the management server 700 supports TLS version 1.3.

[0130] In T830, communication according to TLS version 1.3 is executed between the MFP10 and the management server 700 using the established TCP connection. The communication includes, for example, sending information indicating the state of the MFP10 to the management server.

[0131] In subsequent T840, the MFP10 disconnects the TCP connection of T816 triggered by a predetermined operation of the user. The predetermined operation is, for example, an operation to turn off the power of the MFP10.

[0132] (Case D2) In this case, a malicious third party prepares a management server 930 for the purpose of intercepting communication. The management server 930 does not support TLS version 1.3. The management server 930 supports, for example, an old version (e.g., 1.2) formulated before version 1.3. In TLS, new security protocols are provided with version updates. Communication according to the old version of TLS formulated before version 1.3 is less secure compared to communication according to TLS version 1.3.

[0133] In addition, the third party illegally obtains the IP address and MAC address MA1 of the management server 700. The third party sets the IP address of the management server 930 to the same IP address as the IP address of the management server 700 and sets the MAC address of the management server 930 to MAC address MA1.

[0134] A third party first interferes with the communication between the management server 700 and the LAN 4. Without knowing the existence of the third party, the user of the MFP 10 inputs an instruction for a TCP connection at the T910 in the same manner as at the T810. At the T912, the MFP 10 transmits an ARP request addressed to the IP address of the management server 700. However, since the communication of the management server 700 is interfered with and the IP address of the management server 930 is set to the same IP address as that of the management server 700, at the T914, the MFP 10 receives an ARP response including the MAC address MA1 of the management server 930 from the management server 930.

[0135] At the T916, a TCP connection is established between the MFP 10 and the management server 930. The T918, T919, and T920 are the same as the T818, T819, and T820. The T922 is the same as the T822 except that the Server Hello signal includes information indicating that the management server 930 supports a version of TLS prior to version 1.3 (e.g., 1.2).

[0136] In this case, at the above-mentioned T919, the TLS setting information 50 is changed to the setting "TLS 1.3 required". As described above, in the setting "TLS 1.3 required", the use of a version of TLS prior to version 1.2 is not permitted. In this case, the management server 930 supports a version of TLS prior to version 1.2. Therefore, at the T924, the MFP 10 does not permit the execution of communication according to the TLS of version 1.3 and causes a communication error with the management server 930 to be displayed on the display unit 14. Also in this case, in the communication according to the TLS with the management server, the occurrence of the same problem as in FIG. 2 can be suppressed.

[0137] (Table representing the relationship between the management server and the MFP; FIG. 15) As shown in FIG. 15, there may exist a server that supports a version of TLS prior to version 1.2, a server that supports a version of TLS prior to version 1.3, and a server that supports only the TLS of version 1.3.

[0138] On the other hand, as for MFPs, there may be an MFP that operates with TLS of a version prior to version 1.2, an MFP that operates with TLS of a version prior to version 1.3, and a WPA3-compatible MFP that operates only with TLS of version 1.3.

[0139] In this embodiment, the TLS setting information 50 of the MFP 10 is changed to the setting "TLS 1.3 required" (T919 in FIG. 14). Therefore, the MFP 10 can execute communication using a TCP connection with either a server that supports TLS of a version prior to version 1.3 or a server that supports only TLS of version 1.3. On the other hand, the MFP 10 cannot execute communication using a TCP connection with a server that supports TLS of a version prior to version 1.2.

[0140] (Corresponding relationship) The LANI / F60 in FIG. 12 is an example of a "communication interface". The management server 700 and the management server 600 are examples of a "first external device" and a "second external device", respectively. TLS 1.3 not required and TLS 1.3 required are examples of a "first state" and a "second state", respectively. Version 1.3 and version 1.2 are examples of a "first version" and a "second version", respectively. TLS of version 1.3 and TLS of version 1.2 are examples of a "first communication standard" and a "second communication standard", respectively. The APR response including the MAC address MA1 is an example of a "signal". The T814 and T819 in FIG. 14 are examples of processes realized by a "first receiving unit" and a "first changing unit", respectively.

[0141] As described above, specific examples of the technology disclosed in this specification have been described, but these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes of the specific examples exemplified above. For example, the following modification examples may be adopted.

[0142] (Modification Example 1) The "signal" received by the "communication device" from each of one or more external devices is not limited to the Probe response, and may be, for example, a beacon signal transmitted by the AP. In this modification example, the "request signal" can be omitted.

[0143] (Modification Example 2) The process of T224 in FIG. 4 does not have to be executed. In this modification example, the "second modification unit" can be omitted.

[0144] (Modification Example 3) The process of FIG. 6 does not have to be executed. In this modification example, the "second receiving unit" and the "third modification unit" can be omitted.

[0145] (Modification Example 4) In the first to fourth embodiments, the selection screen such as T20 in FIG. 3 does not have to be displayed. In this modification example, the "first display control unit" can be omitted.

[0146] (Modification Example 5) The first selection screen of T220 in FIG. 4 may include the SSIDs "ap01" and "ap03" of the WPA3-incompatible APs 200 and 400. Generally speaking, the "list" may include information indicating the first external device and information indicating the second external device.

[0147] (Modification Example 6) The first selection screen of T220 in FIG. 4 does not have to include the "Other APs" button. In this modification example, the "predetermined instruction" can be omitted.

[0148] (Modification Example 7) The process of T268 in FIG. 5 does not have to be executed. In this modification example, the "fourth modification unit" can be omitted.

[0149] (Modification Example 8) The "communication device" is not limited to the MFP10, and may be, for example, a terminal device such as a printer, a scanner, a PC, etc.

[0150] (Modification Example 9) The "server" is not limited to a management server 600 that manages the state of the MFP10, and may be, for example, a mail server that transmits an email in response to an instruction from the MFP10.

[0151] (Modification Example 10) In the above-described embodiment, the processes of FIGS. 2 to 14 are realized by software (for example, program 40), but at least one of these processes may be realized by hardware such as a logic circuit.

[0152] (Modification Example 11) In the fifth embodiment, the MFP 10 transmits an ARP request to the management server 700 triggered by the input of an instruction for TCP connection after the input of the IP address of the management server 700 (T810 and T812 in FIG. 14). Instead of this, the process of T810 may not be executed, and the MFP 10 may automatically transmit an ARP request to the management server 700 at a predetermined timing after the input of the IP address of the management server 700. In this modification example, the "specific instruction" can be omitted. Generally speaking, the "first receiving unit" may transmit a request signal externally at a predetermined timing while the state of the communication device is in the first state, which is the predetermined timing before the establishment of the first connection via the communication interface with the first external device.

[0153] The technical elements described in this specification or the drawings exhibit technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Also, the technology exemplified in this specification or the drawings achieves a plurality of purposes simultaneously, and achieving one of those purposes itself has technical utility. The features of the technology disclosed in this specification are listed below. (Item 1) A communication device, a communication interface, and a first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface while the state of the communication device is in a first state, wherein the first state permits both the use of a first connection via the communication interface with a first external device that supports a first communication standard and the use of a second connection via the communication interface with a second external device that supports a second communication standard and does not support the first communication standard, wherein the second communication standard is a communication standard different from the first communication standard, the first receiving unit, and a first changing unit that changes the state of the communication device from the first state to a second state different from the first state when a signal indicating that a specific external device among the one or more external devices is the first external device is received, wherein the second state permits the use of the first connection and does not permit the use of the second connection, the first changing unit, A communication device comprising. (Item 2) The first receiving unit according to item 1, which transmits a request signal externally when a specific instruction is input to the communication device and receives the signal as a response to the request signal from each of the one or more external devices. (Item 3) The communication device according to item 1 or 2, wherein when there is a second external device that supports the second communication standard and does not support the first communication standard in addition to the first external device among the one or more external devices, the state of the communication device is maintained in the first state. (Item 4) The first changing unit according to item 3, which changes the state of the communication device from the first state to the second state when an instruction to establish the first connection with the first external device is input to the communication device after signals are received from each of the one or more external devices including the first external device and the second external device. (Item 5) The first modification unit is in the one or more external devices. In addition to the first external device, when there is a second external device that supports the second communication standard and does not support the first communication standard, the communication device according to item 1 or 2 that changes the state of the communication device from the first state to the second state. (Item 6) The communication device further When an instruction to establish the second connection with the second external device is input to the communication device after the state of the communication device is changed from the first state to the second state, the communication device further includes a second modification unit that changes the state of the communication device from the second state to the first state. The communication device according to item 5. (Item 7) The communication device further When a connection establishment request for a specific external device is received from a terminal device different from the communication device while the state of the communication device is the first state, a second receiving unit that receives specific standard information indicating the communication standard supported by the specific external device from the specific external device; When the specific standard information indicates the first communication standard due to the specific external device being the first external device that supports the first communication standard, a third modification unit that changes the state of the communication device from the first state to the second state; and When the specific standard information indicates the second communication standard due to the specific external device being the second external device that supports the second communication standard and does not support the first communication standard, the state of the communication device is maintained in the first state. The communication device according to any one of items 1 to 6. (Item 8) The communication device further a display unit; a first display control unit that causes the display unit to display a list indicating the one or more external devices when the signal is received from each of the one or more external devices; The communication device according to any one of items 1 to 7, comprising (Item 9) The one or more external devices include the first external device that supports the first communication standard and the second external device that supports the second communication standard and does not support the first communication standard. The list includes information indicating the first external device and does not include information indicating the second external device. The communication device according to item 8. (Item 10) The communication device further The communication device according to item 9, comprising a second display control unit that causes the display unit to display information indicating the second external device when a predetermined instruction is input to the communication device after the list is displayed on the display unit. (Item 11) The communication device further The communication device according to any one of items 1 to 10, further comprising a fourth changing unit that changes the state of the communication device from the second state to the first state when the signal is not received from the first external device after the state of the communication device is changed from the first state to the second state. (Item 12) The first external device and the second external device are access points, The communication device according to any one of items 1 to 11, wherein the first connection and the second connection are wireless connections. (Item 13) The first state includes the WPA3 Transition Mode according to WPA3, The communication device according to item 12, wherein the second state includes the WPA3 Only Mode according to WPA3. (Item 14) The first state includes a state that permits both a first authentication of a PSK (abbreviation for Pre-Shared Key) method available in a standard prior to WPA2 and a second authentication of an SAE (abbreviation for Simultaneous Authentication of Equals) method available in WPA3 and not available in a standard prior to WPA2, The communication device according to item 12 or 13, wherein the second state includes a state that does not permit the first authentication and permits the second authentication. (Item 15) The first state includes a state that permits the use of both a first hash function available in both WPA3 and a standard prior to WPA2 and a second hash function available in WPA3 and not available in a standard prior to WPA2, The communication device according to item 12, wherein the second state includes a state that does not permit the use of the first hash function and permits the use of the second hash function. (Item 16) The first communication standard and the second communication standard include the Wi-Fi standard, The first communication standard includes PMF (abbreviation for Protected Management Frames), The second communication standard does not include the PMF, The first state includes a state indicated by PMF Capable. The communication device according to item 12, wherein the second state includes the state indicated by PMF Required. (Item 17) The communication device further includes an image processing execution unit for executing specific image processing, a third receiving unit that, after establishing the first connection, uses the first connection to receive a specific request for requesting execution of the specific image processing from the first external device via the communication interface, a processing control unit that causes the image processing execution unit to execute the specific image processing according to the specific request, and is the communication device according to any one of items 1 to 16. (Item 18) The first external device and the second external device are servers, the first communication standard includes a first version in TLS (abbreviation for Transport Layer Security) used for communication with the server, the second communication standard includes a second version in the TLS that was formulated before the first version, the first state includes a state that permits use of both the first version and the second version, The communication device according to any one of items 1 to 11, wherein the second state includes a state that does not permit use of the first version and permits use of the second version. (Item 19) A communication device, a communication interface, a first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface, an operation control unit that operates the communication device in a first state when the signal indicating that a specific external device among the one or more external devices is a first external device that supports a first communication standard is not received, and when the signal indicating that the specific external device is the first external device is received, operates the communication device in a second state, wherein the first state is a state that permits both use of a first connection via the communication interface with the first external device and use of a second connection via the communication interface with a second external device that does not support the first communication standard, the second state is a state that permits use of the first connection and does not permit use of the second connection, and the first connection is a connection according to the first communication standard. The second connection is a connection according to a second communication standard different from the first communication standard, and the operation control unit, A communication device comprising. (Item 20) A computer program for a communication device, The communication device is A communication interface, A computer, Comprising, The computer program causes the computer to perform the following parts, namely, A first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface while the state of the communication device is in a first state, The first state is a state that permits both the use of a first connection via the communication interface with a first external device that supports a first communication standard and the use of a second connection via the communication interface with a second external device that supports a second communication standard and does not support the first communication standard, The second communication standard is a communication standard different from the first communication standard, The first receiving unit, A first changing unit that changes the state of the communication device from the first state to a second state different from the first state when a signal indicating that a specific external device among the one or more external devices is the first external device is received, The second state is a state that permits the use of the first connection and does not permit the use of the second connection, The first changing unit, A computer program that functions as. (Item 21) A computer program for a communication device, The communication device is A communication interface, A computer, Comprising, The computer program causes the computer to perform the following parts, namely, A first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface, When a signal indicating that a specific external device among the one or more external devices is a first external device that supports a first communication standard is not received, the communication device is operated in a first state, An operation control unit that operates the communication device in a second state when a signal indicating that the specific external device is the first external device is received, The first state permits both the use of a first connection via the communication interface with the first external device and the use of a second connection via the communication interface with a second external device that does not support the first communication standard. The second state permits the use of the first connection and does not permit the use of the second connection. The first connection is a connection that conforms to the first communication standard. The second connection is a connection that conforms to a second communication standard different from the first communication standard, and the operation control unit. A computer program that functions as.

Explanation of Symbols

[0154] 2: Communication system, 4: LAN, 10: MFP, 12: Operation unit, 14: Display unit, 16: Wi-Fi I / F, 20: Printing execution unit, 22: Scanning execution unit, 30: Control unit, 32: CPU, 34: Memory, 40: Program, 42: WPA3 setting information, 44: PMF setting information, 50: TLS setting information, 52: MAC address list, 100: Terminal device, 200: AP, 210: Authentication server, 300: AP, 310: Authentication server, 600: Management server, 700: Management server, 800: AP, 850: MFP, 900: AP, 910: AP, 920: Authentication server, 930: Management server, MA1, MA2: MAC address

Claims

1. A communication device, a communication interface, a first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface while the state of the communication device is in a first state, wherein the first state permits both the use of a first connection via the communication interface with a first external device that supports a first communication standard and the use of a second connection via the communication interface with a second external device that supports a second communication standard and does not support the first communication standard, and the second communication standard is a communication standard different from the one communication standard, the first receiving unit, a first changing unit that changes the state of the communication device from the first state to a second state different from the first state when a signal indicating that a specific external device among the one or more external devices is the first external device is received, wherein the second state permits the use of the first connection and does not permit the use of the second connection, and the first changing unit that changes the state of the communication device from the first state to the second state even when there is a second external device that supports the second communication standard and does not support the first communication standard in addition to the first external device among the one or more external devices, A communication device comprising the above.

2. The communication device further comprises, a second changing unit that changes the state of the communication device from the second state to the first state when an instruction to establish the second connection with the second external device is input to the communication device after the state of the communication device is changed from the first state to the second state. The communication device according to Claim 1.

3. A communication device, a communication interface, A first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface while the state of the communication device is in a first state, The first state is a state that permits both the use of a first connection via the communication interface with a first external device that supports a first communication standard and the use of a second connection via the communication interface with a second external device that supports a second communication standard and does not support the first communication standard, The second communication standard is a communication standard different from the one communication standard, The first receiving unit, A first changing unit that changes the state of the communication device from the first state to a second state different from the first state when a signal indicating that a specific external device among the one or more external devices is the first external device is received, The second state is a state that permits the use of the first connection and does not permit the use of the second connection, The first changing unit, A second receiving unit that receives specific standard information indicating a communication standard supported by the specific external device from the specific external device when a connection establishment request for establishing a connection between the communication device and the specific external device is received from a terminal device different from the communication device while the state of the communication device is in the first state, A third changing unit that changes the state of the communication device from the first state to the second state when the specific standard information indicates the first communication standard due to the specific external device being the first external device that supports the first communication standard, Comprising, When the specific standard information indicates the second communication standard due to the specific external device being the second external device that supports the second communication standard and does not support the first communication standard, the state of the communication device is maintained in the first state. A communication device.

4. The first external device and the second external device are access points, The communication device according to any one of claims 1 to 3, wherein the first connection and the second connection are wireless connections.

5. The first state includes a WPA3 Transition Mode according to WPA3, The communication device according to claim 4, wherein the second state includes a WPA3 Only Mode according to the WPA3.

6. The first state includes a state that permits both a first authentication of a PSK (abbreviation for Pre-Shared Key) method available in a standard prior to WPA2 and a second authentication of an SAE (abbreviation for Simultaneous Authentication of Equals) method available in WPA3 and not available in the standard prior to WPA2, The communication device according to claim 4 or 5, wherein the second state includes a state that does not permit the first authentication and permits the second authentication.

7. The first state includes a state that permits the use of both a first hash function available in both WPA3 and a standard prior to WPA2 and a second hash function available in WPA3 and not available in the standard prior to WPA2, The communication device according to claim 4, wherein the second state includes a state that does not permit the use of the first hash function and permits the use of the second hash function.

8. The first communication standard and the second communication standard include a Wi-Fi standard, The first communication standard includes a PMF (abbreviation for Protected Management Frames), The second communication standard does not include the PMF, The first state includes a state indicated by PMF Capable, The communication device according to claim 4, wherein the second state includes a state indicated by PMF Required. Claim 9 A communication device, a communication interface, a first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface while the state of the communication device is in a first state, wherein the first state permits both the use of a first connection via the communication interface with a first external device that supports a first communication standard and the use of a second connection via the communication interface with a second external device that supports a second communication standard and does not support the first communication standard, wherein the second communication standard is a communication standard different from the one communication standard, the first receiving unit, a first changing unit that changes the state of the communication device from the first state to a second state different from the first state when a signal indicating that a specific external device among the one or more external devices is the first external device is received, wherein the second state permits the use of the first connection and does not permit the use of the second connection, the first changing unit, and comprising, wherein the first external device and the second external device are servers, wherein the first communication standard includes a first version in TLS (abbreviation for Transport Layer Security) used for communication with the server, wherein the second communication standard includes a second version in the TLS formulated before the first version, wherein the first state includes a state that permits the use of both the first version and the second version, wherein the second state includes a state that does not permit the use of the first version and permits the use of the second version, a communication device. Claim 10 When there is a second external device among the one or more external devices that supports the second communication standard and does not support the first communication standard in addition to the first external device, the state of the communication device is maintained in the first state. The communication device according to any one of claims 3 to 9.

11. After the signal is received from each of the one or more external devices including the first external device and the second external device, when an instruction to establish the first connection with the first external device is input to the communication device, the first change unit changes the state of the communication device from the first state to the second state. The communication device according to claim 10.

12. Even when there is a second external device among the one or more external devices that supports the second communication standard and does not support the first communication standard in addition to the first external device, the first change unit changes the state of the communication device from the first state to the second state. The communication device according to any one of claims 3 to 9.

13. The communication device further When an instruction to establish the second connection with the second external device is input to the communication device after the state of the communication device is changed from the first state to the second state, the communication device further includes a second change unit that changes the state of the communication device from the second state to the first state. The communication device according to claim 12.

14. The communication device further When a request for establishing a connection with a specific external device is received from a terminal device different from the communication device while the state of the communication device is in the first state, a second receiving unit that receives specific standard information indicating the communication standard supported by the specific external device from the specific external device, When the specific standard information indicates the first communication standard due to the specific external device being the first external device that supports the first communication standard, a third changing unit that changes the state of the communication device from the first state to the second state; comprising; The communication device according to claim 9, wherein when the specific external device is the second external device that supports the second communication standard and does not support the first communication standard, and the specific standard information indicates the second communication standard, the state of the communication device is maintained in the first state. **Claim 15** The first receiving unit according to any one of claims 1 to 14, wherein when a specific instruction is input to the communication device, a request signal is transmitted externally, and the signal is received from each of the one or more external devices as a response to the request signal. **Claim 16** The communication device further comprises a display unit; a first display control unit that causes the display unit to display a list indicating the one or more external devices when the signal is received from each of the one or more external devices; The communication device according to any one of claims 1 to 15, comprising. **Claim 17** The one or more external devices include the first external device that supports the first communication standard and the second external device that supports the second communication standard and does not support the first communication standard. The communication device according to claim 16, wherein the list includes information indicating the first external device and does not include information indicating the second external device. **Claim 18** The communication device further comprises a second display control unit that causes the display unit to display information indicating the second external device when a predetermined instruction is input to the communication device after the list is displayed on the display unit. The communication device according to claim 17. **Claim 19** The communication device further After the state of the communication device is changed from the first state to the second state, when the signal is not received from the first external device, a fourth changing unit that changes the state of the communication device from the second state to the first state. The communication device according to any one of claims 1 to 18.

20. The communication device further An image processing execution unit for executing specific image processing, After the establishment of the first connection, a third receiving unit that receives a specific request for requesting execution of the specific image processing from the first external device via the communication interface using the first connection. A processing control unit that causes the image processing execution unit to execute the specific image processing according to the specific request. The communication device according to any one of claims 1 to 19, comprising:

21. A communication device, A communication interface, A first receiving unit that receives a signal from each of one or more external devices existing around the communication device via the communication interface, When the signal indicating that a specific external device among the one or more external devices is a first external device supporting a first communication standard is not received, the communication device is operated in a first state. An operation control unit that operates the communication device in a second state when the signal indicating that the specific external device is the first external device is received, The first state is a state that permits both use of a first connection via the communication interface with the first external device and use of a second connection via the communication interface with a second external device that does not support the first communication standard. The second state is a state that permits use of the first connection and does not permit use of the second connection. The first connection is a connection according to the first communication standard, The second connection is a connection according to a second communication standard different from the first communication standard, the operation control unit, and includes The first external device and the second external device are servers, The first communication standard includes a first version in TLS (abbreviation for Transport Layer Security) used for communication with the server, The second communication standard includes a second version in the TLS, which was formulated before the first version, The first state includes a state that permits the use of both the first version and the second version, The second state is a communication device that does not permit the use of the first version and permits the use of the second version.

22. A computer program for a communication device, The communication device is a communication interface, a computer, and includes The computer program causes the computer to perform the following parts, namely, A first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface while the state of the communication device is in a first state, The first state is a state that permits both the use of a first connection via the communication interface with a first external device that supports a first communication standard and the use of a second connection via the communication interface with a second external device that supports a second communication standard and does not support the first communication standard, The second communication standard is a communication standard different from the first communication standard, the first receiving unit, When the signal indicating that a specific external device among the one or more external devices is the first external device is received, a first changing unit that changes the state of the communication device from the first state to a second state different from the first state, The second state is a state that permits the use of the first connection and does not permit the use of the second connection, Even when there is a second external device that supports the second communication standard and does not support the first communication standard in addition to the first external device among the one or more external devices, the state of the communication device is changed from the first state to the second state, The first changing unit and, A computer program that functions as.

23. A computer program for a communication device, The communication device includes, A communication interface, A computer, And is provided with, The computer program causes the computer to perform the following parts, namely, A first receiving unit that receives a signal from each of one or more external devices existing around the communication device via the communication interface while the state of the communication device is in a first state, The first state is a state that permits both the use of a first connection via the communication interface with a first external device that supports a first communication standard and the use of a second connection via the communication interface with a second external device that supports a second communication standard and does not support the first communication standard, The second communication standard is a communication standard different from the one communication standard, The first receiving unit and, When the signal indicating that a specific external device among the one or more external devices is the first external device is received, a first changing unit that changes the state of the communication device from the first state to a second state different from the first state, The second state is a state that permits the use of the first connection and does not permit the use of the second connection. The first changing unit; When a connection establishment request for establishing a connection with a specific external device is received from a terminal device different from the communication device while the state of the communication device is the first state, a second receiving unit that receives specific specification information indicating a communication standard supported by the specific external device; When the specific specification information indicates the first communication standard due to the specific external device being the first external device that supports the first communication standard, a third changing unit that changes the state of the communication device from the first state to the second state; function as, When the specific external device is the second external device that supports the second communication standard and does not support the first communication standard, and the specific specification information indicates the second communication standard, the state of the communication device is maintained in the first state. Computer program.

24. A computer program for a communication device, The communication device includes A communication interface; A computer; And includes The computer program causes the computer to perform the following units, namely, A first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface while the state of the communication device is in a first state, The first state permits both the use of a first connection via the communication interface with a first external device that supports a first communication standard and the use of a second connection via the communication interface with a second external device that supports a second communication standard and does not support the first communication standard. The second communication standard is a communication standard different from the first communication standard. The first receiving unit A first changing unit that changes the state of the communication device from the first state to a second state different from the first state when a signal indicating that a specific external device among the one or more external devices is the first external device is received. The second state permits the use of the first connection and does not permit the use of the second connection. The first changing unit Function as The first external device and the second external device are servers. The first communication standard includes a first version in TLS (abbreviation for Transport Layer Security) used for communication with the server. The second communication standard includes a second version in TLS that was established prior to the first version. The first state includes a state that permits the use of both the first version and the second version. The second state includes a state that does not permit the use of the first version and permits the use of the second version, a computer program.

25. A computer program for a communication device, The communication device A communication interface A computer And includes The computer program causes the computer to perform the following units, namely, A first receiving unit that receives signals from each of one or more external devices existing around the communication device via the communication interface; When the signal indicating that a specific external device among the one or more external devices is a first external device that supports a first communication standard is not received, the communication device is operated in a first state; An operation control unit that operates the communication device in a second state when the signal indicating that the specific external device is the first external device is received, The first state is a state that permits both the use of a first connection via the communication interface with the first external device and the use of a second connection via the communication interface with a second external device that does not support the first communication standard; The second state is a state that permits the use of the first connection and does not permit the use of the second connection; The first connection is a connection according to the first communication standard; The second connection is a connection according to a second communication standard different from the one communication standard, the operation control unit; Function as; The first external device and the second external device are servers, The first communication standard includes a first version in TLS (abbreviation for Transport Layer Security) used for communication with the server; The second communication standard includes a second version in the TLS formulated before the first version; The first state includes a state that permits the use of both the first version and the second version; The second state includes a state that does not permit the use of the first version and permits the use of the second version, a computer program.

Citation Information

Patent Citations

  • Communication device

    JP2016019085A

  • Information processing device and information processing method

    JP2016208448A

  • Communication device, and control method, and program thereof

    JP2018060441A

  • Communication device and image forming apparatus

    JP2018067749A

  • Wireless LAN slave unit, wireless LAN slave unit communication control method, and wireless LAN slave unit communication control program

    JP2019106610A