Communication device and computer program for a communication device

The communication device addresses the risk of accidentally selecting an access point that does not support the required method by displaying a selection screen that prioritizes compliant access points, thereby enhancing security and reliability.

JP7697254B2Active Publication Date: 2025-06-24BROTHER KOGYO KK
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021069959
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-04-16
Publication Date
2025-06-24
Estimated Expiration
2041-04-16

AI Technical Summary

Technical Problem

When a new wireless standard is introduced, there is a risk of users accidentally selecting an access point that does not support the required method, leading to potential security vulnerabilities and connectivity issues.

Method used

A communication device is equipped with a wireless interface, a display unit, and a first receiving unit that distinguishes between access points supporting a predetermined encryption method and those that do not. The device displays a selection screen that prioritizes access points supporting the predetermined method, thereby reducing the likelihood of accidental selection of non-compliant access points.

Benefits of technology

This solution effectively prevents users from selecting access points that do not support the required encryption method, enhancing security and ensuring reliable connectivity by prioritizing access points that meet the predetermined criteria.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007697254000001
    Figure 0007697254000001
  • Figure 0007697254000002
    Figure 0007697254000002
  • Figure 0007697254000003
    Figure 0007697254000003
Patent Text Reader

Abstract

To provide a technique to prevent an access point not supporting a predetermined system from being mistakenly selected.SOLUTION: In a situation in which two or more access points are present around a communication device, the communication device receives signals from the two or more access points. The two or more access points include a first access point supporting a predetermined system and a second access point not supporting the predetermined system. The communication device comprises a first display control unit that, when the signals are received from the two or more access points, displays, on a display, a first selection screen for selecting one access point from the two or more access points, and on the first selection screen, information indicating the first access point is displayed preferentially over information indicating the second access point.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification discloses a communication device that displays a selection screen for selecting an access point.

Background Art

[0002] As shown in Non-Patent Document 1, the Wi-Fi Alliance (registered trademark) has formulated WPA3, a new communication standard in the Wi-Fi standard. In WPA3 Enterprise, a 192-bit Option is provided as a next-generation security protocol. Also, in communication standards other than WPA3, other security protocols may be provided.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Patent Document 2

Patent Document 3

Non-Patent Documents

[0004]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] When a new predetermined wireless standard is formulated, a situation is assumed in which an access point supporting a predetermined method in the predetermined wireless standard and an access point not supporting the predetermined method coexist. For example, when a user desires to use an access point supporting a predetermined method, if the above two types of access points are searched, the user may accidentally select an access point that does not support the predetermined method.

[0006] In this specification, in the above coexistence situation, a technique is provided to suppress the accidental selection of an access point that does not support a predetermined method.

Means for Solving the Problem

[0007] The communication device disclosed in this specification includes a wireless interface for performing wireless communication according to a predetermined wireless standard, a display unit, and in a situation where two or more access points exist around the communication device, a first receiving unit that receives signals from each of the two or more access points via the wireless interface. The two or more access points include a first access point that supports a predetermined method in the predetermined wireless standard and a second access point that does not support the predetermined method. The predetermined method includes an encryption method that satisfies a predetermined criterion. The signal received from the first access point includes first method information indicating the encryption method supported by the first access point. The signal received from the second access point includes second method information indicating the encryption method supported by the second access point. The encryption method indicated by the first method information is a method that satisfies the predetermined criterion, and the encryption method indicated by the second method information is a method that does not satisfy the predetermined criterion. The first receiving unit and a first display control unit that causes the display unit to display a first selection screen for selecting one access point from among the two or more access points when the signal is received from each of the two or more access points. In the first selection screen, information indicating the first access point that supports the encryption method indicated by the first method information is displayed preferentially over information indicating the second access point that supports the encryption method indicated by the second method information.

[0008] If an access point supports an encryption method that meets a predetermined standard, it is presumed that the access point supports a predetermined method. According to the above configuration, in a situation where signals are received from each of two or more access points, a first access point that supports an encryption method meeting a predetermined standard is displayed preferentially over a second access point that supports an encryption method not meeting the predetermined standard. In a situation where a first access point that supports a predetermined method and a second access point that does not support the predetermined method are mixed, it is possible to suppress the incorrect selection of the second access point that does not support the predetermined method.

[0009] Also, the above method for controlling a communication device, a computer program for the communication device, and a storage medium storing the computer program are novel and useful.

Brief Description of Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Best Mode for Carrying Out the Invention

[0011] (First Embodiment) (Configuration of Communication System 2; FIG. 1) As shown in FIG. 1, the communication system 2 includes an MFP (abbreviation for Multifunction Peripheral) 10, a terminal device 100, APs (abbreviations for Access Point) 200, 300, 400, and authentication servers 210, 410. Each of the APs 200 to 400 can form a wireless LAN (abbreviation for Local Area Network). The MFP 10 is connected to the wireless LAN formed by any one of the APs 200 to 400 and can communicate with other devices (for example, the terminal device 100) connected to the wireless LAN.

[0012] The terminal device 100 is a mobile terminal, a desktop PC, a notebook PC, or the like. The authentication servers 210, 410 are servers that authenticate users who use the MFP 10 and provide the AP and the MFP 10 with encryption keys used in wireless communication via the AP. The authentication server 210 is used in the process of establishing a wireless connection with the APs 200, 300 and is connected to the APs 200, 300 via a wired LAN. The authentication server 410 is used in the process of establishing a wireless connection with the AP 400 and is connected to the AP 400 via a wired LAN.

[0013] (Configuration of MFP 10; FIG. 1) The MFP 10 is a peripheral device (for example, a peripheral device of the terminal device 100) that can execute functions such as a printing function and a scanning function. The MFP 10 includes an operation unit 12, a display unit 14, a Wi-Fi interface 16, a printing execution unit 20, a scanning execution unit 22, and a control unit 30. Each of the units 12 to 30 is connected to a bus line (reference numerals omitted). Hereinafter, the interface will be simply referred to as "I / F".

[0014] The operation unit 12 is provided with a plurality of keys. By operating the operation unit 12, the user can input various instructions to the MFP 10. The display unit 14 is a display for displaying various information. Note that the display unit 14 may function as a touch panel (i.e., the operation unit 12).

[0015] The Wi-Fi I / F 16 is a wireless I / F for performing wireless communication according to the Wi-Fi standard. The Wi-Fi standard is a standard for performing wireless communication according to, for example, the 802.11 standard of IEEE (abbreviation of The Institute of Electrical and Electronics Engineers, Inc.) and standards conforming thereto (such as 802.11a, 11b, 11g, 11n, etc.).

[0016] In addition, the Wi-Fi I / F 16 supports WPA3 Personal and Enterprise formulated by the Wi-Fi Alliance. Personal is a method for authenticating slave stations in a small-scale wireless LAN such as a home. Enterprise is a method for authenticating slave stations in a large-scale wireless LAN such as a company. In Enterprise, an authentication server (such as 210) that performs authentication according to IEEE's 802.1X authenticates the slave stations in the Wi-Fi standard. On the other hand, in Personal, no authentication server is used, and for example, the AP uses a PSK (Pre-Shared Key) to authenticate the slave stations.

[0017] In addition, in WPA3 Enterprise, a 192-bit Option is provided as the next-generation security protocol. In communication conforming to the 192-bit Option, an encryption method that meets a predetermined criterion with an encryption strength of 192 bits or more is required. The encryption method includes a symmetric-key encryption algorithm, a public-key encryption algorithm, a hash function, and the like. The symmetric-key encryption algorithm that meets the predetermined criterion is an algorithm that uses a key with a length of 192 bits or more, for example, 192-bit AES (abbreviation for Advanced Encryption Standard), 256-bit AES, and the like. The public-key encryption algorithm that meets the predetermined criterion is an algorithm that uses a key with a length of 384 bits or more, for example, 7680-bit RSA (abbreviation for Rivest-Shamir-Adleman cryptosystem), 7680-bit DSA (abbreviation for Digital Signature Algorithm), 7680-bit DH (abbreviation for Diffie-Hellman key exchange), 384-bit ECDSA (abbreviation for Elliptic Curve Digital Signature Algorithm), 384-bit ECDH (abbreviation for Elliptic curve Diffie-Hellman key exchange), and the like. The hash function that meets the predetermined criterion is a function that outputs a return value of 384 bits or more, for example, SHA-384, SHA-512, SHA-3. Wi-Fi I / F 16 supports the 192-bit Option.

[0018] The printing execution unit 20 includes a printing mechanism such as an inkjet method or a laser method. The scanning execution unit 22 includes a scanning mechanism such as a CCD (abbreviation for Charge Coupled Device) image sensor or a CIS (abbreviation for Contact Image Sensor).

[0019] The control unit 30 includes a CPU 32 and a memory 34. The CPU 32 executes various processes according to a program 40 stored in the memory 34. The memory 34 is composed of a volatile memory, a non-volatile memory, and the like.

[0020] The memory 34 further stores screen setting information 42. The screen setting information 42 indicates either a value of "ON" that permits the display of a partial selection screen (see S12 in FIG. 6) described later, or "OFF" that does not permit the display of the partial selection screen (see FIG. 6). The screen setting information 42 is input by the user via the operation unit 12.

[0021] (Configuration of AP200, 300, 400; FIG. 1) AP200 to 400 support WPA3. AP200 does not support the 192-bit Option. AP300 and 400 support the 192-bit Option. Each of AP200, 300, and 400 is assigned an SSID (abbreviation for Service Set Identifier) of "ap01", "ap02", and "ap03".

[0022] (Establishment process of wireless connection; FIG. 2) With reference to FIG. 2, the process for establishing a wireless connection between the MFP10 and the AP will be described. All the following communications executed by the MFP10 are executed via the Wi-Fi I / F 16. Hereinafter, when describing the process related to communication, the description of "via the Wi-Fi I / F 16" may be omitted. Also, hereinafter, for ease of understanding, the operations executed by the CPU (e.g., CPU32, etc.) of each device may be described mainly based on each device (e.g., MFP10) instead of mainly based on the CPU.

[0023] In the case of FIG. 2, there are three APs 200 to 400 around the MFP10. Each of the APs 200 to 400 broadcasts a beacon signal.

[0024] When the MFP10 receives an instruction to establish a wireless connection at T5 via the operation unit 12, at T10A to T10C, the MFP10 receives a beacon signal including the SSID of the corresponding AP from each of the three APs 200 to 400 around the MFP10.

[0025] In T20, the MFP10 executes a selection screen process (Fig. 6) described later. The selection screen process is a process for displaying a selection screen that selects one AP to be connected from among the three APs 200 to 400 that are the transmission sources of the three beacon signals T10A to T10C. In this case, the MFP10 accepts the selection of the SSID "ap02" assigned to the AP300 on the selection screen displayed in T20.

[0026] In T30, the MFP10 transmits a Probe request to the AP300 indicated by the selected SSID "ap02". In T32, the MFP10 receives a Probe response to the Probe request from the AP300.

[0027] In T40, an Authentication communication for the AP300 to authenticate the MFP10 is executed. In this case, the Authentication communication is successful, and in T42, an Association communication is executed.

[0028] In T50, the MFP10 transmits an EAPoL (abbreviation for EAP over LAN) Start signal to the AP300. The EAPoL Start signal is a signal that requests the AP300 to start authentication according to EAP (Extensible Authentication Protocol). In T52, the MFP10 receives an EAP Request signal as a response to the EAPoL Start signal. The EAP Request signal is a signal that requests user information (user name and password) used for authentication in the authentication server 210.

[0029] In T54, the MFP10 transmits an EAP Response signal including user information (for example, user name and password) indicating the user who uses the MFP10 to the AP300 as a response to the EAP Request signal. Thereby, the AP300 transmits the EAP Response signal to the authentication server 210.

[0030] When the authentication server 210 receives an EAP Response signal from the AP 300 at T54, at T56, it transmits an EAP Request PEAP signal to the MFP 10 as a response to the EAP Response signal via the AP 300.

[0031] When the MFP 10 receives an EAP Request PEAP signal from the authentication server 210 at T56, at T58, it transmits a Client Hello signal to the authentication server 210. The communication between the MFP 10 and the authentication server 210 is encrypted according to TLS (abbreviation for Transport Layer Security). The Client Hello signal is a signal that notifies the authentication server 210 that the MFP 10 starts operating as a TLS client.

[0032] At T60, the MFP 10 receives a Server Hello signal from the authentication server 210 via the AP 300 as a response to the Client Hello signal. The Server Hello signal is a signal that notifies the MFP 10 that the authentication server 210 starts operating as a TLS server. The Server Hello signal includes Cipher Suites information (hereinafter referred to as "CS information") indicating the encryption method used in the EAP authentication at T62 described later. The EAP authentication is a process for the authentication server 210 to authenticate the user of the MFP 10 and provide both the AP 300 and the MFP 10 with the encryption key used for establishing the wireless connection with the AP 300.

[0033] In T62, the MFP10 performs communication for EAP authentication with the authentication server 210. Specifically, the EAP authentication includes user authentication and key exchange. The user authentication is communication for the authentication server 210 to authenticate the user of the MFP10 by using the user information in the EAP Response signal of T54 and a public-key cryptography algorithm (such as RSA) according to the CS information in the Sever Hello signal of T60. The key exchange is communication for the authentication server 210 to provide both the MFP10 and the AP300 with the encryption key to be used in the communication of T70 described later by using a public-key cryptography algorithm (such as DH) according to the CS information when the user authentication is successful.

[0034] In T70, the MFP10 performs communication of 4-way handshake with the AP300 by using the encryption key provided in T62. As a result, in T80, a wireless connection for performing wireless communication according to the Wi-Fi standard is established between the MFP10 and the AP300. That is, the MFP10 is connected to the wireless LAN formed by the AP300.

[0035] For example, in a situation where the MFP10 and the terminal device 100 are connected to the wireless LAN formed by the AP300, the terminal device 100 transmits print data indicating an image to be printed to the MFP10 via the AP300 in T90.

[0036] When the MFP10 receives the print data from the terminal device 100 in T90, the MFP10 causes the print execution unit 20 to execute printing of the image indicated by the received print data in T92.

[0037] In the case of Fig. 2, three APs 200 to 400 exist around the MFP 10. And the three APs 200 to 300 include one AP 200 that does not support the 192-bit Option and two APs 300 and 400 that support the 192-bit Option. For example, when the user desires to use an AP (for example, 300) that supports the 192-bit Option, if a beacon signal is received from the AP 200 that does not support the 192-bit Option, the user may erroneously select the AP 200. In this embodiment, in order to address the problem, the selection screen process of T20 (see Fig. 6) is executed.

[0038] (Packet configuration of beacon signal; Figs. 3 to 5) In the selection screen process of Fig. 6 described later, the information in the beacon signal is used to determine whether the AP that is the source of the beacon signal supports the 192-bit Option. With reference to Figs. 3 to 5, the configuration of the packet of the beacon signal will be described. In Figs. 3 to 5, part of the description of the packet of the beacon signal is omitted.

[0039] Figure 3 shows an example of the packet configuration of the beacon signal transmitted by AP200 in a situation where AP200 is operating in a mode to perform wireless communication according to WPA3 Personal. As shown in Figure 3, in WPA3 Personal, the packet includes a tag of SSID Parameter set (hereinafter referred to as "SSID tag") and a tag of RSN Information (hereinafter referred to as "RSN tag"). The SSID tag includes the SSID "ap01" of AP200. Also, the RSN tag includes values related to the encryption method used in the communication for establishing a wireless connection. In this case, the RSN tag includes the values "AES(CCM)" and "SAE(SHA256)". Here, SAE (abbreviation of Simultaneous Authentication of Equals) is a communication method executed in Authentication in Personal (see T40 in Figure 2). In Personal, in Authentication, the encryption key used in the 4way-handshake (see T70 in Figure 2) is provided to both MFP10 and AP300.

[0040] Figure 4 shows an example of the packet configuration of the beacon signal transmitted by AP200 in a situation where AP200 is operating in a mode to perform wireless communication according to WPA3 Enterprise. As described above, AP200 does not support the 192bit Option. In this case, the RSN tag includes the values "AES(CCM)" and "WPA(SHA256)". As shown in Figures 3 and 4, in Personal, the RSN tag includes the value "SAE(SHA256)", while in Enterprise, the RSN tag includes the value "WPA(SHA256)". The value "WPA(SHA256)" indicates that the communication method of Authentication in Enterprise is different from that in Personal.

[0041] FIG. 5 shows an example of the packet configuration of the beacon signal transmitted by the AP300 when it is operating in a mode where it performs wireless communication according to WPA3 Enterprise. As described above, the AP300 supports a 192-bit Option. In this case, the RSN tag includes the values "GCMP(256)" and "WPA(SHA384-SuiteB)". Further, the RSN tag in this case has an item "Group Manegement Cipher Suite" that is not included in the case of FIG. 4, and the RSN tag includes the value "BIP(GCMC-256)" as this item.

[0042] The configurations shown in FIGS. 3 to 5 are merely examples. For example, in the case of FIG. 5, the value "GCMP(256)" indicates the use of 256-bit AES as the common key encryption algorithm, and the value "WPA(SHA384-SuiteB)" indicates the use of SHA384 as the hash function. In a modified example, for example, in the case of FIG. 5, the RSN tag may include a value different from the value "GCMP(256)", for example, a value indicating an algorithm different from 256-bit AES (for example, 192-bit AES). Also, the RSN tag may include a value different from the value "WPA(SHA384-SuiteB)", for example, a value indicating a hash function different from SHA384 (for example, SHA512).

[0043] (Selection Screen Processing; FIG. 6) Referring to FIG. 6, the selection screen processing executed in T20 of FIG. 2 will be described. The CPU 32 of the MFP 10 executes the selection screen processing according to the program 40 in the memory 34.

[0044] In S2, the CPU 32 determines whether the screen setting information 42 in the memory 34 indicates "ON". When the CPU 32 determines that the screen setting information 42 indicates "ON" (YES in S2), it proceeds to S10.

[0045] In S10, the CPU 32 determines whether there is an AP that supports the 192-bit Option among the two or more APs (for example, three APs 200 to 300) existing around the MFP 10 by using two or more beacon signals received from the two or more APs. As shown in the case of FIG. 5, in the beacon signal of the AP that supports the 192-bit Option, the RSN tag has the item "Group Manegement Cipher Suite". When there is a beacon signal including the RSN tag having the item "Group Manegement Cipher Suite" among the two or more beacon signals, the CPU 32 determines that there is an AP that supports the 192-bit Option among the two or more APs. On the other hand, when there is no beacon signal including the RSN tag having the item "Group Manegement Cipher Suite" among the two or more beacon signals, the CPU 32 determines that there is no AP that supports the 192-bit Option among the two or more APs.

[0046] When the CPU 32 determines that there is an AP that supports the 192-bit Option among the two or more APs (YES in S10), it proceeds to S12. In S12, the CPU 32 causes the display unit 14 to display a partial selection screen. The partial selection screen is a screen for selecting one AP from among the one or more APs that support the 192-bit Option among the two or more APs existing around the MFP 10. The partial selection screen includes, for each of the one or more APs, the SSID assigned to the AP and a button for selecting the SSID. The partial selection screen does not include the SSIDs assigned to the remaining APs other than the one or more APs among the two or more APs. Thereby, it is possible to prevent the user from mistakenly selecting an AP that does not support the 192-bit Option from among the two or more APs.

[0047] It should be noted that there may be a misspelling in the original text where "Group Manegement Cipher Suite" should probably be "Group Management Cipher Suite". This has been left as is in the translation to match the original.Further, the partial selection screen further includes an "Other AP" button. The "Other AP" button is a button for displaying a first full selection screen described later, which is a screen where APs that do not support the 192-bit Option can also be selected.

[0048] In S14, the CPU 32 monitors that the "Other AP" button in the partial selection screen is selected, and in S16, monitors that any SSID in the partial selection screen is selected. When the "Other AP" button is selected (YES in S14), the CPU 32 causes the first full selection screen to be displayed on the display unit 14 in S30. The first full selection screen includes not only the SSIDs of APs that support the 192-bit Option but also the SSIDs of APs that do not support the 192-bit Option. For example, even in a situation where there are APs that support the 192-bit Option around the MFP 10, the user may desire to use an AP that does not support the 192-bit Option. According to the above configuration, the user can use an AP that does not support the 192-bit Option.

[0049] In the subsequent S32, the CPU 32 monitors that any SSID in the first full selection screen is selected. When any SSID in the first full selection screen is selected (YES in S32), the CPU 32 ends the process of FIG. 6. Thereby, the CPU 32 executes a process for establishing a wireless connection with the AP selected on the first full selection screen.

[0050] Also, when any SSID in the partial selection screen is selected (YES in S16), the CPU 32 ends the process of FIG. 6. Thereby, the CPU 32 executes a process for establishing a wireless connection with the AP selected on the partial selection screen, that is, an AP that supports the 192-bit Option (see the case of FIG. 2).

[0051] Also, when the CPU 32 determines that there is no AP among two or more APs that supports the 192-bit Option (NO in S10), it proceeds to S22. In S22, the CPU 32 causes the display unit 14 to display a confirmation screen. The confirmation screen includes a message for confirming the display of a second full selection screen described later and a "YES" button (see FIG. 7).

[0052] In S24, the CPU 32 monitors whether the "YES" button in the confirmation screen is selected. When the "YES" button in the confirmation screen is selected (YES in S24), the CPU 32 proceeds to S40. With such a configuration, in a situation where there is no AP that supports the 192-bit Option around the MFP 10, it is possible to confirm with the user the use of an AP that does not support the 192-bit Option. Also, before confirming with the user the use of an AP that does not support the 192-bit Option, it is possible to prevent the user from accidentally selecting an AP that does not support the 192-bit Option.

[0053] In S40, the CPU 32 causes the display unit 14 to display a second full selection screen for selecting one AP from among two or more APs existing around the MFP 10. The second full selection screen includes the SSID of each of the two or more APs existing around the MFP 10, that is, all of the two or more APs that do not support the 192-bit Option. With such a configuration, even in a situation where there is no AP that supports the 192-bit Option around the MFP 10, the user can use an AP that does not support the 192-bit Option to cause the MFP 10 to execute communication via the AP.

[0054] In S42, the CPU 32 monitors whether any SSID in the second full selection screen is selected. When any SSID in the second full selection screen is selected (YES in S42), the CPU 32 ends the process of FIG. 6. Thereby, the CPU 32 executes a process for establishing a wireless connection with the AP selected in the second full selection screen.

[0055] Also, when the CPU 32 determines that the screen setting information 42 indicates "OFF" (NO in S2), it proceeds to S40. For example, in a situation where there are three APs 200 to 400 around the MFP 10, when the screen setting information 42 indicates "ON", a partial selection screen including the two SSIDs "ap02" and "ap03" of the two APs 300 and 400 is displayed (S12). On the other hand, in the same situation, when the screen setting information 42 indicates "OFF", a second full selection screen including the three SSIDs "ap01", "ap02", and "ap03" of the three APs 200 to 400 is displayed (S40). According to such a configuration, by inputting "OFF" as the screen setting information 42, one AP can be selected from two or more APs existing around the MFP 10 regardless of the presence or absence of support for the 192-bit Option.

[0056] According to the process of FIG. 6, in a situation where beacon signals are received from each of two or more APs existing around the MFP 10, a partial selection screen that does not include the SSID of an AP that does not support the 192-bit Option and includes the SSID of an AP that supports the 192-bit Option among the two or more APs is displayed (S12). In a situation where an AP that supports the 192-bit Option and an AP that does not support the 192-bit Option are mixed, it is possible to prevent an AP that does not support the 192-bit Option from being erroneously selected.

[0057] (Specific form of the partial selection screen; FIG. 6) In the situation where there are two AP300s and 400s that support the 192-bit Option around the MFP10, the specific form of the partial selection screen displayed will be described. The key length of the common key encryption algorithm supported by the AP300 is longer than the key length of the common key encryption algorithm supported by the AP400. For example, the beacon signal transmitted by the AP300 includes a value indicating 256-bit AES as the value of the RSN tag. Here, "256" indicates the key length in the AP300. Also, the beacon signal transmitted by the AP400 includes a value indicating 192-bit AES as the value of the RSN tag. Here, "192" indicates the key length in the AP400. In this case, the CPU32 obtains the key length of the common key encryption algorithm supported by the corresponding AP from each of the two beacon signals received from the two AP300s and 400s. Then, the CPU32 causes the display unit 14 to display a partial selection screen in which the SSID "ap02" of the AP300 corresponding to the 256-bit key length is positioned above the SSID "ap03" of the AP400 corresponding to the 192-bit key length (S12). Generally, the longer the key length used in the encryption algorithm, the stronger the encryption strength. According to such a configuration, it is possible to prompt the user to use an AP with relatively strong encryption strength.

[0058] In addition, the information for determining the order of the SSIDs within the partial selection screen is not limited to the key length of the common key encryption algorithm. For example, assume that the output value length of the hash function supported by AP300 is longer than the output value length of the hash function supported by AP400. In this case, for example, the beacon signal transmitted by AP300 includes a value indicating SHA512 as the value of the RSN tag. Here, "512" indicates the output value length in AP300. Also, the beacon signal transmitted by AP400 includes a value indicating SHA384 as the value of the RSN tag. Here, "384" indicates the output value length in AP400. In this case, CPU32 obtains the output value length of the hash function supported by each of the two beacon signals received from the two APs, AP300 and 400. Then, CPU32 causes display unit 14 to display a partial selection screen in which the SSID "ap02" of AP300 corresponding to the 512-bit output value length is positioned above the SSID "ap03" of AP400 corresponding to the 384-bit output value length (S12). Generally, the longer the output value length of the hash function, the stronger the encryption strength. Even with such a configuration, it is possible to prompt the user to use an AP with relatively strong encryption strength.

[0059] (Specific case; FIG. 7) With reference to FIG. 7, a specific case realized by the screen selection process of FIG. 6 will be described. At the initial stage of this case, only AP200 that does not support the 192-bit Option exists around MFP10. Also, at the initial stage of this case, the screen setting information of MFP10 indicates "ON".

[0060] T95 is the same as T5 in FIG. 2. In T100, MFP10 receives a beacon signal from AP200. In T101, MFP10 determines that the screen setting information 42 indicates "ON" (YES in S2 of FIG. 6). In T102, MFP10 determines that there is no AP around MFP10 that supports the 192-bit Option (NO in S10). In T104, MFP10 displays a confirmation screen (S22). In T106, MFP10 receives the selection of the "YES" button within the confirmation screen (YES in S24). In T108, MFP10 displays a second full selection screen including the SSID "ap01" of AP200 (S40).

[0061] In T122, MFP10 receives the selection of the SSID "ap01" within the second full selection screen from the user. Further, MFP10 receives the input of user information from the user. T140 to T180 are the same as T40 to T80 in FIG. 2 except that AP200 is used. Thereby, a wireless connection is established between MFP10 and AP200. Note that in FIG. 7, the same communication as T30, T32, T50 to T60 in FIG. 2 is also executed, but the description thereof is omitted.

[0062] Subsequently, in this case, the wireless connection connected in T180 is disconnected, and further, AP300 is newly installed around MFP10. In such a situation, when MFP10 receives an instruction to establish a wireless connection at T195, MFP10 receives beacon signals from each of the two APs, AP200 and 300, at T200A and T200B. T201 is the same as T101. In T202, MFP10 determines that there is an AP300 that supports the 192-bit Option around MFP10 (YES in S10). In T202, MFP10 displays a partial selection screen that includes the SSID "ap02" of AP300 and does not include the SSID "ap01" of AP200 (S12 in FIG. 6).

[0063] According to this case, even after the wireless connection with the AP200 that does not support the 192-bit Option is established, when beacon signals are received from each of the two AP200s and 300s, a partial selection screen that includes the SSID "ap02" of the AP300 and does not include the SSID "ap01" of the AP200 is displayed (T202). Although there is a record of establishing a wireless connection with the AP200 that does not support the 192-bit Option, the user can be prompted to establish a new wireless connection with the AP300 that supports the 192-bit Option rather than the AP200 with which a connection has been made.

[0064] (Corresponding relationship in the first embodiment) The MFP10, the display unit 14, and the Wi-Fi I / F 16 are each an example of a "communication device", a "display unit", and a "wireless interface", respectively. The AP200 to 400 are an example of two or more access points. The AP300, the AP200, and the AP400 are each an example of a "first access point", a "second access point", and a "third access point", respectively. The authentication server 210 is an example of an "external server". The 192-bit Option and the criterion for the encryption strength in the 192-bit Option are each an example of a "predetermined method" and a "predetermined criterion", respectively. The screen setting information 42, "ON", and "OFF" are each an example of "predetermined setting information", a "first value", and a "second value", respectively. The information in the packet in FIG. 5 and the information in the packet in FIG. 4 are each an example of "first method information" and "second method information", respectively.

[0065] A beacon signal is an example of a "signal". In the partial selection screen of S12 in FIG. 6, the "Other AP" button is an example of a "first selection screen" and a "predetermined button". The first full selection screen of S30 in FIG. 6 is an example of a "second selection screen". The key of the common key encryption algorithm supported by the AP and the output value of the hash function are examples of "values used in the encryption method supported by each access point". AP200 in FIG. 7 is an example of "one or more access points". The "YES" button in the confirmation screen of T104 in FIG. 7 is an example of a "confirmation button". The second full selection screen of T108 in FIG. 7 is an example of a "fourth selection screen".

[0066] T10A in FIG. 2 and S12 in FIG. 6 are examples of processes realized by a "first receiving unit" and a "first display control unit", respectively.

[0067] (Modification of the First Embodiment; FIG. 6) In the partial selection screen of the first embodiment, the SSID "ap02" of AP300 that supports a common key encryption algorithm using a relatively long key is located above the SSID "ap03" of AP300 that supports a common key encryption algorithm using a relatively short key. In the partial selection screen of this modification, the SSID "ap03" of AP300 that supports a common key encryption algorithm using a relatively short key is located above the SSID "ap02" of AP300 that supports a common key encryption algorithm using a relatively long key. Generally, as the length of the key used in the encryption algorithm increases, the encryption strength becomes stronger, but the time for encryption and decryption processes also becomes longer. According to such a configuration, it is possible to prompt the user to use an AP with a faster encryption and decryption process time.

[0068] (Second Embodiment) This embodiment is the same as the first embodiment except that the content of the wireless connection establishment process is partially different.

[0069] (Wireless Connection Establishment Process; FIG. 8) Referring to FIG. 8, the process for establishing a wireless connection between the MFP 10 and the AP in this embodiment will be described.

[0070] T295 to T300C are the same as T5 to T10C in FIG. 2. At T310A, the MFP 10 transmits an inquiry signal for inquiring about CS information to the authentication server 210 via the AP 300. At T312A, the MFP 10 receives the CS information CS1 of the authentication server 210 from the authentication server 210 as a response to the inquiry signal via the AP 300. Further, at T310B, the MFP 10 transmits an inquiry signal to the authentication server 410 via the AP 400, and at T312B, the MFP 10 receives the CS information CS2 of the authentication server 410 via the AP 400.

[0071] The table in FIG. 8 exemplifies multiple types of CS information. For example, the first type of CS information indicates that ECDH is used in the key exchange of EAP authentication, RSA is used in the user authentication of EAP authentication, 256-bit AES is used as the common key encryption algorithm used in EAP authentication, and SHA384 is used as the hash function in EAP authentication. Also, the second type of CS information is the same as the first type of CS information except that DH is used in the key exchange of EAP authentication. Also, the third type of CS information is the same as the first type of CS information except that ECDSA is used in the user authentication of EAP authentication. Note that the table in FIG. 8 is only an example of multiple types of CS information. For example, the multiple types of CS information may include a fourth type of CS information indicating that SHA512 is used as the hash function in EAP authentication.

[0072] The T320 is the same as the T30 in FIG. 2, except that it determines the order of the SSIDs in the partial selection screen using the CS information CS1 of the T312A and the CS information CS2 of the T312B. For example, assume a situation where the CS information CS1 is the second type of CS information indicating that DH is used in the key exchange of EAP authentication, and the CS information CS2 is the first type of CS information indicating that ECDH is used in the key exchange of EAP authentication. As described above, in DH, a key with a length of 7680 bits is used, and in ECDH, a key with a length of 384 bits is used. In the partial selection screen of this embodiment, the SSID "ap02" of the AP300 connected to the authentication server 210 that executes EAP authentication using DH is located above the SSID "ap03" of the AP400 connected to the authentication server 410 that executes EAP authentication using ECDH. That is, in the partial selection screen of this embodiment, the SSID "ap02" of the AP300 that uses EAP authentication using a relatively long key is located above the SSID "ap03" of the AP400 that uses EAP authentication using a relatively short key. Even with such a configuration, it is possible to prompt the user to use an AP with a relatively strong encryption strength. Also, in the partial selection screen of the modified example, the SSID "ap03" of the AP400 that uses EAP authentication using a relatively short key may be located above the SSID "ap02" of the AP300 that uses EAP authentication using a relatively long key. Even with such a configuration, it is possible to prompt the user to use an AP with a faster encryption and decryption processing time. Note that in the modified example of this embodiment, the order of the SSIDs may be determined based on the length of the output value of the hash function used in EAP authentication.

[0073] Also, for example, a comparative example is assumed in which, without executing the processes of T310A to T312B, for all two or more APs existing around the MFP10, the processes from T30 to T60 in FIG. 2 are executed, and the order of the SSIDs in the partial selection screen is determined using the CS information received at T60. In this comparative example, the processes from T30 to T60 in FIG. 2 are executed for all two or more APs. The processes of T30 to T60 are processes for establishing a wireless connection with the AP. In this comparative example, the processes of T30 to T60 are unnecessarily executed for APs that are not the target of establishing a wireless connection. On the other hand, in this embodiment, before executing the processes from T30 to T60 in FIG. 2, the processes of T310A to T312B are executed to display the partial selection screen. In this embodiment, it is possible to suppress the unnecessary execution of the processes of T30 to T60 for APs that are not the target of establishing a wireless connection. Note that in a modification, the configuration of the above comparative example may be adopted. In this modification, the CS information at T60 is an example of "value length information".

[0074] (Corresponding relationship of the second embodiment) EAP authentication is an example of "authentication processing". The key of the encryption algorithm and the output value of the hash function used in EAP authentication are examples of "values used in authentication processing". The inquiry signal of T310A in FIG. 7 is an example of "a predetermined request".

[0075] As described above, specific examples of the technology disclosed in this specification have been described, but these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes of the specific examples exemplified above. For example, the following modifications may be adopted.

[0076] (Modification 1) In each of the above embodiments, although the AP200 supports WPA3, it does not support the 192bit Option. Instead, the AP200 may not support the 192bit Option due to not supporting WPA3. In this modification, the AP200 that does not support WPA3 is an example of the "second access point".

[0077] (Modification Example 2) The "signal" is not limited to a beacon signal, and for example, it may be a Probe response to a Probe request broadcast by the MFP10.

[0078] (Modification Example 3) In the partial selection screen in each of the above embodiments, the SSID of an AP that does not support the 192-bit Option (hereinafter referred to as "non-compatible SSID") is not included. Instead, in the partial selection screen, the SSID of an AP that supports the 192-bit Option (hereinafter referred to as "compatible SSID") is displayed in a first mode, and the non-compatible SSID may be displayed in a second mode different from the first mode (for example, grayed out, light color, small font, etc.). Also, in another modification example, in the partial selection screen, the compatible SSID may be arranged above the non-compatible SSIS. These modification examples are also examples of "prioritizing" the display of "information indicating the first access point".

[0079] (Modification Example 4) The process of S2 in FIG. 6 may not be executed. In this modification example, the "predetermined setting information" can be omitted.

[0080] (Modification Example 5) The processes of S14 and S30 in FIG. 2 may not be executed. In this modification example, the "predetermined button" and the "third selection screen" can be omitted.

[0081] (Modification Example 6) The processes of S22 to S42 when it is determined as NO in S10 of FIG. 6 may not be executed. In this modification example, the "fourth selection screen" can be omitted.

[0082] (Modification Example 7) The processes of S22 and S24 in FIG. 6 may not be executed. In this modification example, the "confirmation button" can be omitted.

[0083] (Modification Example 8) The process of FIG. 7 may not be executed. For example, after the wireless connection with AP200 is established, a second full selection screen may be displayed. Generally speaking, the "first selection screen" may not be displayed "after the wireless connection with the second access point is established".

[0084] (Modification Example 9) In the partial selection screen of each of the above embodiments, the SSIDs are arranged based on the key length of the encryption method used in the process for establishing a wireless connection with the AP (for example, Authentication, EAP authentication). Instead, the SSIDs may be arranged based on the version of the encryption method. For example, the SSID of the AP that supports the latest version of the encryption method may be arranged above the SSID of the AP that supports an older version of the encryption method.

[0085] (Modification Example 10) In the partial selection screen of each of the above embodiments, the SSID "ap02" of AP300 corresponding to a key length of 256 bits is located above the SSID "ap03" of AP400 corresponding to a key length of 192 bits. Instead, the SSID "ap02" may be located to the left of the SSID "ap03". In this modification example, the left side is an example of the "preferred position".

[0086] (Modification Example 11) In the second embodiment above, the MFP10 transmits an inquiry signal to the authentication server 210 and receives CS information from the authentication server 210 (T310A, T312A in FIG. 8). Instead, the MFP10 may obtain CS information from a predetermined database (not shown). The predetermined database may store, for each of a plurality of APs, the SSID of the AP and the CS information of the authentication server connected to the AP in association with each other. In this modification example, the "second receiving unit" can be omitted.

[0087] (Modification Example 12) The "communication device" is not limited to the MFP10, and may be, for example, a terminal device such as a printer, a scanner, a PC, etc.

[0088] (Modification Example 13) In the above-described embodiment, the processes of FIGS. 2 to 8 are realized by software (for example, program 40), but at least one of these processes may be realized by hardware such as a logic circuit.

[0089] The technical elements described in this specification or the drawings exhibit technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Further, the technologies exemplified in this specification or the drawings achieve a plurality of purposes simultaneously, and achieving one of these purposes itself has technical utility. The features of the technology disclosed in this specification are listed below. (Item 1) A communication device, a wireless interface for performing wireless communication according to a predetermined wireless standard, a display unit, a first receiving unit that receives signals from each of the two or more access points via the wireless interface in a situation where two or more access points exist around the communication device, the two or more access points include a first access point that supports a predetermined method in the predetermined wireless standard and a second access point that does not support the predetermined method, the predetermined method includes an encryption method that meets a predetermined criterion, the signal received from the first access point includes first method information indicating the encryption method supported by the first access point, the signal received from the second access point includes second method information indicating the encryption method supported by the second access point, the encryption method indicated by the first method information is a method that meets the predetermined criterion, the encryption method indicated by the second method information is a method that does not meet the predetermined criterion, the first receiving unit, a first display control unit that causes the display unit to display a first selection screen for selecting one access point from among the two or more access points when the signal is received from each of the two or more access points, and in the first selection screen, information indicating the first access point that supports the encryption method indicated by the first method information is displayed preferentially over information indicating the second access point that supports the encryption method indicated by the second method information, the first display control unit, A communication device comprising. (Item 2) The communication device further includes a memory for storing predetermined setting information, the first display control unit causes the display unit to display the first selection screen when the predetermined setting information indicates a first value, The communication device further includes A second display control unit that causes the display unit to display a second selection screen different from the first selection screen when the predetermined setting information indicates a second value different from the first value. In the second selection screen, the information indicating the first access point and the information indicating the second access point are displayed in a display mode different from the display mode of the first selection screen. The communication device according to item 1, comprising the second display control unit. (Item 3) The communication device according to item 1 or 2, wherein the first selection screen includes the information indicating the first access point and does not include the information indicating the second access point. (Item 4) The first selection screen includes a predetermined button. The communication device according to item 3, wherein the first display control unit causes the display unit to display a third selection screen including the information indicating the second access point when the predetermined button in the first selection screen is selected. (Item 5) When one or more access points including the second access point exist around the communication device and the first access point does not exist around the communication device, the first receiving unit receives the signal from each of the one or more access points via the wireless interface. The communication device further includes A third display control unit that causes the display unit to display a fourth selection screen for selecting one access point from among the one or more access points when the signal is received from each of the one or more access points. The fourth selection screen includes information indicating each of the one or more access points. The communication device according to any one of items 1 to 4, comprising the third display control unit. (Item 6) The communication device further includes A fourth display control unit that causes the display unit to display a screen including a confirmation button for confirming the display of the fourth selection screen when the signal is received from each of the one or more access points. The communication device according to item 5, wherein the third display control unit causes the display unit to display the fourth selection screen when the confirmation button is selected. (Item 7) The communication device further includes When the second access point among the one or more access points is selected on the fourth selection screen, an establishment unit is provided that establishes a wireless connection with the second access point that does not support the predetermined method via the wireless interface. After the wireless connection with the second access point is established, the first receiving unit receives the signal from each of the two or more access points including the first access point in the situation where the two or more access points exist around the communication device via the wireless interface. The communication device according to item 5 or 6, wherein the first display control unit causes the display unit to display the first selection screen in which the information indicating the first access point is preferentially displayed over the information indicating the second access point when the signal is received from each of the two or more access points even after the wireless connection with the second access point is established. (Item 8) The two or more access points include, in addition to the first access point, a third access point that supports the predetermined method. The first selection screen includes the information indicating the first access point and the information indicating the third access point. In the first selection screen, the information indicating the first access point and the information indicating the third access point are arranged based on the length of the value used in the encryption method supported by each access point. The communication device according to any one of items 1 to 7. (Item 9) In the first selection screen, the information indicating the first access point that supports the encryption method using the value of the first length that satisfies the predetermined criterion is arranged in a position prior to the information indicating the third access point that supports the encryption method using the value of the second length that satisfies the predetermined criterion and is shorter than the first length. The communication device according to item 8. (Item 10) In the first selection screen, the information indicating the first access point that supports an encryption method using a value of a first length that meets the predetermined criteria is arranged in a position prior to the information indicating the third access point that supports an encryption method using a value of a third length that meets the predetermined criteria and is longer than the first length. The communication device according to item 8. (Item 11) The predetermined wireless standard is the Wi-Fi standard, The predetermined method includes Enterprise in the Wi-Fi standard, The process for establishing a wireless connection according to the Enterprise includes an authentication process in which an external server authenticates the communication device, The two or more access points include, in addition to the first access point, a third access point that supports the predetermined method, The first selection screen includes the information indicating the first access point and the information indicating the third access point, In the first selection screen, the information indicating the first access point and the information indicating the third access point are arranged based on the length of the value used in the authentication process. The communication device according to any one of items 1 to 7. (Item 12) In the first selection screen, the information indicating the first access point that can establish the wireless connection in response to the success of the authentication process using a value of a first length that meets the predetermined criteria is arranged in a position prior to the information indicating the third access point that can establish the wireless connection in response to the success of the authentication process using a value of a second length that meets the predetermined criteria and is shorter than the first length. The communication device according to item 11. (Item 13) In the first selection screen, the information indicating the first access point that can establish the wireless connection in response to the success of the authentication process using a value of a first length that meets the predetermined criteria is arranged in a position prior to the information indicating the third access point that can establish the wireless connection in response to the success of the authentication process using a value of a third length that meets the predetermined criteria and is longer than the first length. The communication device according to item 11. (Item 14) The communication device further A second receiving unit that transmits a predetermined request to each of two or more of the servers and receives, from each of the two or more servers, value length information indicating the length of a value used in the authentication process executed by the server as a response to the predetermined request, wherein the two or more servers include a first server used in a process for establishing a wireless connection with the first access point and a second server used in a process for establishing a wireless connection with the third access point, and the second receiving unit is provided. The communication device according to any one of items 11 to 13, wherein, on the first selection screen, the information indicating the first access point and the information indicating the third access point are arranged based on the value length information received from the first server and the value length information received from the second server. (Item 15) A computer program for a communication device, The communication device includes a wireless interface for performing wireless communication according to a predetermined wireless standard, a display unit, a computer, and is provided with The computer program causes the computer to perform the following steps: A first receiving unit that receives signals from each of the two or more access points via the wireless interface in a situation where two or more access points exist around the communication device, The two or more access points include a first access point that supports a predetermined method in the predetermined wireless standard and a second access point that does not support the predetermined method, The predetermined method includes an encryption method that satisfies a predetermined criterion, The signal received from the first access point includes first method information indicating the encryption method supported by the first access point, The signal received from the second access point includes second method information indicating the encryption method supported by the second access point, The encryption method indicated by the first method information is a method that satisfies the predetermined criterion, The encryption method indicated by the second method information is a method that does not satisfy the predetermined criterion, The first receiving unit, A first display control unit that causes the display unit to display a first selection screen for selecting one access point from among the two or more access points when the signal is received from each of the two or more access points, wherein, on the first selection screen, information indicating the first access point that supports the encryption method indicated by the first method information is displayed preferentially over information indicating the second access point that supports the encryption method indicated by the second method information; the first display control unit; A computer program that functions as.

Explanation of Symbols

[0090] 2: Communication System 10: MFP 12: Operation Unit 14: Display Unit 16: Wi-Fi I / F 20: Printing Execution Unit 22: Scanning Execution Unit 30: Control Unit 32: CPU 34: Memory 40: Program 42: Screen Setting Information 100: Terminal Device 210, 410: Authentication Server CS1, CS2: CS Information

Claims

1. A communication device, a wireless interface for performing wireless communication according to a predetermined wireless standard, a display unit, a first receiving unit that receives signals from each of the two or more access points via the wireless interface in a situation where two or more access points exist around the communication device, wherein the two or more access points include a first access point that supports a predetermined method in the predetermined wireless standard and a second access point that does not support the predetermined method, wherein the predetermined method includes an encryption method that satisfies a predetermined criterion, wherein the signal received from the first access point includes first method information indicating an encryption method supported by the first access point, wherein the signal received from the second access point includes second method information indicating an encryption method supported by the second access point, wherein the encryption method indicated by the first method information is a method that satisfies the predetermined criterion, wherein the encryption method indicated by the second method information is a method that does not satisfy the predetermined criterion, the first receiving unit, a first display control unit that causes the display unit to display a first selection screen for selecting one access point from among the two or more access points when the signal is received from each of the two or more access points, wherein in the first selection screen, information indicating the first access point that supports the encryption method indicated by the first method information is displayed preferentially over information indicating the second access point that supports the encryption method indicated by the second method information, comprising, wherein the first receiving unit receives the signals from each of the one or more access points including the second access point around the communication device via the wireless interface in a situation where the first access point does not exist around the communication device and the one or more access points including the second access point exist around the communication device, the communication device further A third display control unit that causes the display unit to display a fourth selection screen for selecting one access point from among the one or more access points when the signal is received from each of the one or more access points, wherein the fourth selection screen includes information indicating the access point for all of the one or more access points, the third display control unit, When the second access point among the one or more access points is selected on the fourth selection screen, an establishment unit that establishes a wireless connection with the second access point that does not support the predetermined method via the wireless interface, Comprising, After the wireless connection with the second access point is established, the first receiving unit receives the signal from each of the two or more access points including the first access point in a situation where the two or more access points exist around the communication device via the wireless interface, Even after the wireless connection with the second access point is established, when the signal is received from each of the two or more access points, the first display control unit causes the display unit to display the first selection screen in which the information indicating the first access point is preferentially displayed over the information indicating the second access point. Communication device.

2. The communication device further includes a memory that stores predetermined setting information, The first display control unit causes the display unit to display the first selection screen when the predetermined setting information indicates a first value, The communication device further includes, A second display control unit that causes the display unit to display a second selection screen different from the first selection screen when the predetermined setting information indicates a second value different from the first value, wherein on the second selection screen, the information indicating the first access point and the information indicating the second access point are displayed in a display mode different from the display mode of the first selection screen. The communication device according to claim 1, comprising the second display control unit.

3. The communication device according to claim 1 or 2, wherein the first selection screen includes the information indicating the first access point and does not include the information indicating the second access point.

4. The first selection screen includes a predetermined button, The communication device according to claim 3, wherein when the predetermined button in the first selection screen is selected, the first display control unit causes the display unit to display a third selection screen including the information indicating the second access point.

5. The communication device further includes, a fourth display control unit that causes the display unit to display a screen including a confirmation button for confirming the display of the fourth selection screen when the signal is received from each of the one or more access points, The communication device according to any one of claims 1 to 4, wherein the third display control unit causes the display unit to display the fourth selection screen when the confirmation button is selected.

6. The two or more access points include, in addition to the first access point, a third access point that supports the predetermined method, The first selection screen includes the information indicating the first access point and the information indicating the third access point, In the first selection screen, the information indicating the first access point and the information indicating the third access point are arranged based on the length of the value used in the encryption method supported by each access point. The communication device according to any one of claims 1 to 5.

7. In the first selection screen, the information indicating the first access point that supports the encryption method using a value of a first length that satisfies the predetermined criterion is shorter than the first length, and is more prioritized than the information indicating the third access point that supports the encryption method using a value of a second length that satisfies the predetermined criterion. The communication device according to claim 6, which is arranged at a position.

8. In the first selection screen, the information indicating the first access point that supports the encryption method using a value of a first length that satisfies the predetermined criterion is longer than the first length, and is more prioritized than the information indicating the third access point that supports the encryption method using a value of a third length that satisfies the predetermined criterion. The communication device according to claim 6, which is arranged at a position.

9. The predetermined wireless standard is the Wi-Fi standard, The predetermined method includes Enterprise in the Wi-Fi standard, The process for establishing a wireless connection according to the Enterprise includes an authentication process in which an external server authenticates the communication device. The two or more access points include, in addition to the first access point, a third access point that supports the predetermined method. The first selection screen includes the information indicating the first access point and the information indicating the third access point. The communication device according to any one of claims 1 to 5, wherein, on the first selection screen, the information indicating the first access point and the information indicating the third access point are arranged based on the length of the value used in the authentication process.

10. On the first selection screen, the information indicating the first access point capable of establishing the wireless connection in response to the success of the authentication process using a value of a first length that satisfies the predetermined criterion is more than the first length. The information indicating the third access point capable of establishing the wireless connection in response to the success of the authentication process using a value of a second length that satisfies the predetermined criterion is arranged in a more preferential position. The communication device according to claim 9.

11. On the first selection screen, the information indicating the first access point capable of establishing the wireless connection in response to the success of the authentication process using a value of a first length that satisfies the predetermined criterion is more than the first length. The information indicating the third access point capable of establishing the wireless connection in response to the success of the authentication process using a value of a third length that satisfies the predetermined criterion is arranged in a more preferential position. The communication device according to claim 9.

12. The communication device further includes a second receiving unit that transmits a predetermined request to each of the two or more servers and receives, from each of the two or more servers, value length information indicating the length of the value used in the authentication process executed by the server as a response to the predetermined request. The two or more servers include a first server used in a process for establishing a wireless connection with the first access point and a second server used in a process for establishing a wireless connection with the third access point. The communication device includes the second receiving unit. In the first selection screen, the information indicating the first access point and the information indicating the third access point are arranged based on the value length information received from the first server and the value length information received from the second server. The communication device according to any one of claims 9 to 11.

13. A computer program for a communication device, The communication device includes a wireless interface for performing wireless communication according to a predetermined wireless standard, a display unit, a computer, and is provided with The computer program causes the computer to perform the following steps: In a situation where two or more access points exist around the communication device, a first receiving unit that receives signals from each of the two or more access points via the wireless interface, The two or more access points include a first access point that supports a predetermined method in the predetermined wireless standard and a second access point that does not support the predetermined method. The predetermined method includes an encryption method that satisfies a predetermined criterion. The signal received from the first access point includes first method information indicating the encryption method supported by the first access point. The signal received from the second access point includes second method information indicating the encryption method supported by the second access point. The encryption method indicated by the first method information is a method that satisfies the predetermined criterion. The encryption method indicated by the second method information is a method that does not satisfy the predetermined criterion. The first receiving unit; A first display control unit that causes the display unit to display a first selection screen for selecting one access point from among the two or more access points when signals are received from each of the two or more access points. In the first selection screen, information indicating the first access point that supports the encryption method indicated by the first method information is displayed preferentially over information indicating the second access point that supports the encryption method indicated by the second method information. The first display control unit; function as The first receiving unit receives the signal from each of the one or more access points via the wireless interface in a situation where one or more access points including the second access point exist around the communication device and the first access point does not exist around the communication device. The computer program further causes the computer to a third display control unit that causes the display unit to display a fourth selection screen for selecting one access point from among the one or more access points when the signal is received from each of the one or more access points, wherein the fourth selection screen includes information indicating each of the one or more access points. an establishing unit that establishes a wireless connection with the second access point that does not support the predetermined method via the wireless interface when the second access point among the one or more access points is selected on the fourth selection screen. function as After the wireless connection with the second access point is established, the first receiving unit receives the signal from each of the two or more access points including the first access point around the communication device via the wireless interface in a situation where the two or more access points including the first access point exist around the communication device. Even after the wireless connection with the second access point is established, when the signal is received from each of the two or more access points, the first display control unit causes the display unit to display the first selection screen in which the information indicating the first access point is displayed preferentially over the information indicating the second access point. Computer program.

Citation Information

Patent Citations

  • Communication device

    JP2016019085A

  • Information processor, information processing method and program

    JP2016131333A

  • Information processing device and information processing method

    JP2016208448A

  • Wireless LAN slave unit, wireless LAN slave unit communication control method, and wireless LAN slave unit communication control program

    JP2019106610A