Communication device and computer program for communication device
The communication device with dual wireless interfaces and user-controlled public key transmission ensures secure, intended wireless connections by displaying an instruction screen and considering signal strength, addressing the issue of unauthorized connections in existing methods.
Patent Information
- Application Number
- JP2023221761
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2038-03-30
AI Technical Summary
Existing wireless communication methods, such as the DPP method, do not adequately restrict the transmission of public keys, allowing unintended devices to establish connections, leading to unauthorized Wi-Fi connections.
A communication device with a display unit and dual wireless interfaces (Wi-Fi and Bluetooth) that displays an instruction screen upon receiving a specific signal, allowing the user to control the transmission of public keys and authentication requests, thereby restricting unwanted connections based on user intent and signal strength.
Ensures that wireless connections are established only between intended devices, preventing unauthorized connections by requiring user confirmation and considering signal strength, thus enhancing security and user control.
Smart Images

Figure 0007708170000001 
Figure 0007708170000002 
Figure 0007708170000003
Abstract
Description
Technical Field
[0001] This specification discloses a technology related to a communication device capable of establishing a wireless connection with an external device.
Background Art
[0002] Non-Patent Document 1 describes the DPP (abbreviation for Device Provisioning Protocol) method, which is a wireless communication method formulated by the Wi-Fi Alliance. The DPP method is a wireless communication method for easily establishing a Wi-Fi connection between a pair of devices. Non-Patent Document 1 discloses, as an example for sharing public keys, that a Responder uses Bluetooth (registered trademark) communication to send a public key to an Initiator.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Non-Patent Documents
[0004]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] The above Non-Patent Document 1 does not disclose anything about restricting the transmission of public keys. For this reason, when the Responder transmits the public key using Bluetooth communication, a device different from the intended Initiator by the user may receive the public key. As a result, a Wi-Fi connection may be established between a pair of devices unintended by the user.
[0006] This specification discloses a technique that can suppress the establishment of a wireless connection between a pair of devices unintended by the user.
Means for Solving the Problem
[0007] The communication device disclosed by this specification includes a display unit, a first wireless interface, a second wireless interface different from the first wireless interface, a specific signal receiving unit that receives a specific signal from a first external device via the first wireless interface, a first display control unit that causes the display unit to display a first instruction screen for instructing to execute target processing including transmission of a public key when the specific signal is received from the first external device, a public key transmission unit that transmits the public key to the first external device via the first wireless interface when it is instructed to execute the target processing in a situation where the first instruction screen is displayed, and the public key is not transmitted when it is not instructed to execute the target processing in a situation where the first instruction screen is displayed, an authentication request receiving unit that receives an authentication request using the public key from the first external device via the second wireless interface after the public key is transmitted to the first external device, an authentication response transmission unit that transmits an authentication response, which is a response to the authentication request, to the first external device via the second wireless interface when the authentication request is received from the first external device, a connection information receiving unit that receives connection information from the first external device via the second wireless interface after the authentication response is transmitted to the first external device, where the connection information is information for establishing a wireless connection between the communication device and a second external device via the second wireless interface, and an establishment unit that establishes the wireless connection between the communication device and the second external device via the second wireless interface using the connection information when the connection information is received from the first external device.
[0008] According to the above configuration, when the communication device receives a specific signal from the first external device, it displays a first instruction screen. When the communication device is instructed to execute the target process in the situation where the first instruction screen is displayed, that is, when the user desires that communication using the public key is executed between the communication device and the first external device, the communication device transmits the public key to the first external device. As a result, the communication device receives an authentication request using the public key from the first external device, transmits an authentication response to the first external device, receives connection information from the first external device, and establishes a wireless connection with the second external device using the connection information. On the other hand, when the communication device is not instructed to execute the target process in the situation where the first instruction screen is displayed, that is, when the user does not desire that communication using the public key is executed between the communication device and the first external device, the public key is not transmitted. Therefore, the communication device does not receive an authentication request using the public key from the first external device, and as a result, a wireless connection with the second external device is not established. For this reason, it is possible to suppress the establishment of a wireless connection between a pair of devices not intended by the user.
[0009] Also, the communication device disclosed by this specification includes a first wireless interface, a second wireless interface different from the first wireless interface, a specific signal receiving unit that receives a specific signal from a first external device via the first wireless interface, a determination unit that determines whether the received radio wave intensity of the specific signal is equal to or greater than a threshold value when the specific signal is received from the first external device, a public key transmitting unit that transmits a public key to the first external device via the first wireless interface when it is determined that the received radio wave intensity is equal to or greater than the threshold value, and the transmission of the public key to the first external device is restricted when it is determined that the received radio wave intensity is less than the threshold value, the public key transmitting unit, an authentication request receiving unit that receives an authentication request in which the public key is used from the first external device via the second wireless interface after the public key is transmitted to the first external device, an authentication response transmitting unit that transmits an authentication response, which is a response to the authentication request, to the first external device via the second wireless interface when the authentication request is received from the first external device, a connection information receiving unit that receives connection information from the first external device via the second wireless interface after the authentication response is transmitted to the first external device, where the connection information is information for establishing a wireless connection via the second wireless interface between the communication device and a second external device, the connection information receiving unit, and an establishment unit that establishes the wireless connection via the second wireless interface between the communication device and the second external device using the connection information when the connection information is received from the first external device.
[0010] According to the above configuration, when the communication device receives a specific signal from a first external device, it determines whether the received radio wave intensity of the specific signal is equal to or greater than a threshold value. Here, the situation where the received radio wave intensity is equal to or greater than the threshold value means that the distance between the communication device and the first external device is relatively small, that is, it is highly likely that the user desires that communication using a public key be performed between the communication device and the first external device. In such a situation, the communication device transmits the public key to the first external device. As a result, the communication device receives an authentication request using the public key from the first external device, transmits an authentication response to the first external device, receives connection information from the first external device, and uses the connection information to establish a wireless connection with a second external device. On the other hand, the situation where the received radio wave intensity is not equal to or greater than the threshold value means that the distance between the communication device and the first external device is relatively large, that is, it is highly likely that the user does not desire that communication using a public key be performed between the communication device and the first external device. In this case, the transmission of the public key is restricted in the communication device. Therefore, in the communication device, the reception of an authentication request using the public key from the first external device is restricted, and as a result, the establishment of a wireless connection with the second external device is restricted. For this reason, it is possible to suppress the establishment of a wireless connection between a pair of devices not intended by the user.
[0011] A computer program for realizing the above communication device, and a computer-readable recording medium storing the computer program are also novel and useful. Also, the method executed by the above communication device is also novel and useful. Further, a communication system including the above communication device and other devices (for example, a first external device, a second external device) is also novel and useful.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Mode for Carrying Out the Invention
[0013] (First Embodiment) (Configuration of Communication System 2; FIG. 1) As shown in FIG. 1, the communication system 2 includes an AP (abbreviation for Access Point) 6, a plurality of terminals 10, 50, and a printer 100. In this embodiment, it is assumed that a user uses each of the terminals 10, 50 to establish a wireless connection (hereinafter referred to as "Wi-Fi connection") according to the Wi-Fi method between the printer 100 and the AP 6.
[0014] (Configuration of Each Terminal 10, 50) Each of the terminals 10 and 50 is a portable terminal device such as a mobile phone (e.g., a smartphone), a PDA, or a tablet PC. In a modified example, each of the terminals 10 and 50 may be a stationary PC, a notebook PC, or the like. The terminal 10 has a MAC address "xxx". The terminal 50 has a MAC address "yyy". Here, each of the terminals 10 and 50 has a similar configuration. Therefore, hereinafter, the configuration of the terminal 10 will be mainly described.
[0015] The terminal 10 includes a Wi-Fi interface 16 and a BT (abbreviation for Bluetooth) interface 18. Hereinafter, the interface will be simply described as "I / F".
[0016] The Wi-Fi I / F 16 is a wireless interface for executing Wi-Fi communication according to the Wi-Fi method. The Wi-Fi method is a wireless communication method for executing wireless communication according to, for example, the IEEE (abbreviation for The Institute of Electrical and Electronics Engineers, Inc.) 802.11 standard and standards conforming thereto (e.g., 802.11a, 11b, 11g, 11n, 11ac, etc.). In particular, the Wi-Fi I / F 16 supports the DPP (abbreviation for Device Provisioning Protocol) method, which is scheduled to be formulated by the Wi-Fi Alliance. The DPP method is described in "DRAFT Device Provisioning Protocol Technical Specification Version 0.2.11", which is a draft of the specification created by the Wi-Fi Alliance, and is a wireless communication method for easily establishing a Wi-Fi connection between a pair of devices (e.g., the printer 100 and the AP 6) using the terminal 10.
[0017] BTI / F18 is an interface for performing communication (so-called communication compliant with Bluetooth Low Energy) conforming to version 4.0 or higher of the BT method. The BT method is a wireless communication method based on, for example, the standard of IEEE802.15.1 and standards equivalent thereto.
[0018] The terminal 10 stores a first type of application (hereinafter simply referred to as the "first type of app") 40. The first type of app 40 is a program provided by the vendor of the printer 100, and is installed on the terminal 10, for example, from a server on the Internet provided by the vendor of the printer 100. Also, the terminal 50 stores a second type of application (hereinafter simply referred to as the "second type of app") 52. The second type of app 52 is a program provided by a business operator different from the vendor of the printer 100. The first type of app 40 and the second type of app 52 are programs for establishing a Wi-Fi connection between the printer 100 and the AP6. Also, in another modification, the second type of app 52 may be an OS program for realizing the basic operation of the terminal 50.
[0019] (Configuration of Printer 100) The printer 100 is a peripheral device capable of executing a printing function (for example, a peripheral device of the terminal 10). The printer 100 includes an operation unit 112, a display unit 114, a Wi-Fi I / F 116, a BTI / F 118, a print execution unit 120, and a control unit 130. Each of the units 112 to 130 is connected by a bus line (reference numeral omitted).
[0020] The operation unit 112 is provided with a plurality of keys. The user can input various instructions to the printer 100 by operating the operation unit 112. The display unit 114 is a display for displaying various information. The Wi-Fi I / F 116 is the same as the Wi-Fi I / F 16 of the terminal 10. That is, the Wi-Fi I / F 116 supports the DPP method. Also, the Wi-Fi I / F 116 has a MAC address "abc". The BT I / F 118 is the same as the BT I / F 18 of the terminal 10. The printing execution unit 120 is provided with a printing mechanism such as an inkjet method or a laser method.
[0021] Here, the differences between the Wi-Fi method and the BT method will be described. The communication speed of Wi-Fi communication (for example, the maximum communication speed is 600 [Mbps]) is faster than the communication speed of BT communication (for example, the maximum communication speed is 24 [Mbps]). The frequency of the carrier wave in Wi-Fi communication is in the 2.4 [GHz] band or the 5.0 [GHz] band. The frequency of the carrier wave in BT communication is in the 2.4 [GHz] band. That is, when the 5.0 [GHz] band is adopted as the frequency of the carrier wave in Wi-Fi communication, the frequency of the carrier wave in Wi-Fi communication is different from the frequency of the carrier wave in BT communication. Also, the maximum distance at which Wi-Fi communication can be executed (for example, about 100 [m]) is larger than the maximum distance at which BT communication can be executed (for example, about several tens of [m]).
[0022] The control unit 130 includes a CPU 132 and a memory 134. The CPU 132 executes various processes according to the program 136 stored in the memory 134. The memory 134 is composed of a volatile memory, a non-volatile memory, etc.
[0023] (Overview of this embodiment; Figure 2) Next, referring to FIG. 2, the outline of this embodiment will be described. Although it has been described above that each of the terminals 10 and 50 and the printer 100 supports the DPP method, the AP 6 also supports the DPP method. In this embodiment, each device 6, 10 (or 50), 100 realizes establishing a Wi-Fi connection between the printer 100 and the AP 6 by performing communication according to the DPP method. Note that the processes executed by the terminal 10 and the processes executed by the terminal 50 are the same except for some processes (for example, T714 in FIG. 11 and T814 in FIG. 12 described later). Therefore, in FIG. 2, the description of the terminal 50 will be omitted. Further, hereinafter, for ease of understanding, the operations executed by the CPU (for example, CPU 132, etc.) of each device are described mainly with each device (for example, the printer 100) as the main body without describing the CPU as the main body.
[0024] In T5, the terminal 10 performs Bootstrapping (hereinafter simply referred to as "BS") of the DPP method with the AP 6. The BS is a process of providing, from the AP 6 to the terminal 10, information to be used in Authentication (hereinafter simply referred to as "Auth") of T10 described later, in response to the QR code (registered trademark) attached to the AP 6 being photographed by the terminal 10.
[0025] In T10, the terminal 10 uses the information acquired in the BS of T5 to perform Auth of the DPP method with the AP 6. The Auth is a process for each of the terminal 10 and the AP 6 to authenticate the communication partner.
[0026] In T15, the terminal 10 executes a DPP-based Configuration (hereinafter simply referred to as "Config") with the AP6. The Config is a process of transmitting information for establishing a Wi-Fi connection between the printer 100 and the AP6 to the AP6. Specifically, in the Config, the terminal 10 generates a first Configuration Object (hereinafter simply referred to as "CO") for establishing a Wi-Fi connection between the printer 100 and the AP6, and transmits the first CO to the AP6. As a result, the first CO is stored in the AP6.
[0027] Next, in T20, the terminal 10 executes a DPP-based BS with the printer 100. The BS is a process in which the printer 100 provides the terminal 10 with information to be used in the subsequent T25 Auth via BTI / F118.
[0028] In T25, the terminal 10 executes a DPP-based Auth with the printer 100 using the information acquired in the T20 BS. The Auth is a process for each of the terminal 10 and the printer 100 to authenticate the communication partner.
[0029] In T30, the terminal 10 executes a DPP-based Config with the printer 100. The Config is a process of transmitting information for establishing a Wi-Fi connection between the printer 100 and the AP6 to the printer 100. In the Config, the terminal 10 generates a second CO for establishing a Wi-Fi connection between the printer 100 and the AP6, and transmits the second CO to the printer 100. As a result, the second CO is stored in the printer 100.
[0030] In T35, the printer 100 and the AP6 execute a DPP-based Network Access (hereinafter simply referred to as "NA") using the stored first and second COs. NA is a process for sharing a connection key for establishing a Wi-Fi connection between the printer 100 and the AP6.
[0031] In T40, the printer 100 and the AP6 execute 4-way handshake communication. In at least a part of the process of the 4-way handshake communication, the printer 100 and the AP6 communicate encrypted information encrypted by the connection key shared with the NA of T35. When the decryption of the encrypted information is successful, a Wi-Fi connection is established between the printer 100 and the AP6. As a result, the printer 100 can participate as a slave station in the wireless network formed by the AP6, and thus can communicate with other devices participating in the wireless network via the AP6. In a modified example, the printer 100 and the AP6 may execute SAE (abbreviation for Simultaneous Authentication of Equals, commonly known as "Dragonfly") communication instead of 4-way handshake communication.
[0032] In T45, the printer 100 causes the display unit 114 to display a completion screen indicating that the Wi-Fi connection has been established with the AP6. When the process of T45 ends, the process of FIG. 2 ends.
[0033] In the DPP method, in order to establish a Wi-Fi connection between the printer 100 and the AP6, the user does not need to input information (such as SSID (abbreviation for Service Set Identifier), password, etc.) of the wireless network in which the AP6 operates as the master station into the printer 100. Therefore, the user can easily establish a Wi-Fi connection between the printer 100 and the AP6.
[0034] (Explanation of each process; FIGS. 3 to 7) Next, referring to FIGS. 3 to 7, the details of each process executed in T20 to T35 in FIG. 2 will be described. Note that the processes of T5 to T15 are the same as those of T20 to T30 except that AP6 is used instead of the printer 100, and thus the detailed description thereof is omitted. FIGS. 3 and 7 show each case of BS executed between the terminal 10 and the printer 100. These cases are processes executed in one embodiment.
[0035] (Bootstrapping (BS) of Case A; FIG. 3) First, referring to FIG. 3, the process of Case A of BS in T20 of FIG. 2 will be described. In the initial state of FIG. 3, the memory 134 of the printer 100 stores in advance the public key PPK1 and the private key psk1 of the printer 100.
[0036] In T100, in response to receiving a power-on operation from the user, the printer 100 causes the display unit 114 to display the menu screen MS in T105. The screen MS is, in other words, the default screen of the printer 100, and includes a print button for causing the printer 100 to execute printing and a setting button for specifying various settings (for example, print settings, etc.) of the printer 100.
[0037] Next, since the memory 134 does not yet store the second CO (refer to T30 in FIG. 2), the printer 100 supplies, in T107, a transition instruction for shifting the operation mode of the BTI / F118 to the BTI / F118 to shift the operation mode of the BTI / F118 from the normal mode to the setting mode. Therefore, when the memory 134 does not store the second CO, simply turning on the power of the printer 100 by the user causes the operation mode of the BTI / F118 to shift from the normal mode to the setting mode. The normal mode is a mode in which a Scan Request (hereinafter simply referred to as "SReq") (T114 described later) according to the BT method cannot be interpreted (that is, a mode in which SReq is received and ignored). The setting mode is a mode in which SReq can be interpreted (that is, a mode in which when SReq is received, the information in SReq is supplied to the CPU132).
[0038] Upon receiving the startup operation of the application from the user at T110, the terminal 10 starts the first type of application 40 at T112. Each subsequent process executed by the terminal 10 is realized by the first type of application 40. Next, at T114, the terminal 10 transmits an SReq including the MAC address "xxx" of the Wi-Fi I / F 16 to the printer 100 via the BTI / F 18. The SReq is a signal capable of executing communication with the device even if the pairing with the communication target device is not completed.
[0039] Upon receiving the SReq from the terminal 10 via the BTI / F 118 at T114, the printer 100 causes the display unit 114 to display a first instruction screen FIS for instructing to execute a connection process for establishing a Wi-Fi connection at T116. The screen FIS includes a YES button indicating to execute the connection process.
[0040] In the case of the printer 100, in T120, when the YES button in the screen FIS is selected by the user, in T122, it transitions from an impossible state to a possible state. The impossible state is a state where, even if the Wi-Fi I / F 116 receives a DPP Authentication Request (hereinafter simply referred to as "AReq") from the terminal 10 (see T200 in FIG. 4 described later), it does not transmit a DPP Authentication Response (hereinafter simply referred to as "ARes") (see T210 described later). The possible state is a state where the Wi-Fi I / F 116 transmits an ARes to the terminal 10 in response to receiving an AReq from the terminal 10. That is, by transitioning from the impossible state to the possible state, the printer 100 becomes in a state where it can execute Auth (see T25 in FIG. 2). Specifically, in this embodiment, the impossible state is a state where the Wi-Fi I / F 116 does not supply a signal received from the outside to the CPU 132 even if it receives a signal from the outside. Also, the possible state is a state where the Wi-Fi I / F 116 supplies a signal received from the outside to the CPU 132 and transmits a response to the signal in response to receiving the signal from the outside. Since the possible state is a state where the CPU 132 processes a signal received from the outside, the processing load is higher compared to the impossible state. Note that in a modified example, the impossible state may be a state where the Wi-Fi I / F 116 is not powered on, and the possible state may be a state where the Wi-Fi I / F 116 is powered on. Also, in another modified example, the impossible state may be a state where the Wi-Fi I / F 116 does not supply a notification indicating that an AReq has been received to the CPU 132 even if it receives an AReq from the outside, and the possible state may be a state where the Wi-Fi I / F 116 supplies a notification indicating that an AReq has been received to the CPU 132 in response to receiving an AReq from the outside.
[0041] Note that if the YES button is not selected even after a predetermined time has elapsed since the first instruction screen FIS was displayed at T116 (i.e., in the case of a timeout), the printer 100 ends the display of the screen FIS, does not execute the processing after T120, and returns to the state of displaying the menu screen MS. In a modified example, the screen FIS includes a NO button indicating that the connection process is not executed, and the printer 100 may end the display of the screen FIS when the NO button within the screen FIS is selected by the user.
[0042] Next, at T130, the printer 100 transmits, via BTI / F118, a Scan Response (hereinafter simply referred to as "SRes") conforming to the BT method to the terminal 10. The SRes is a signal capable of executing communication with the device even if pairing with the communication target device is not completed. Further, the SRes includes a public key PPK1 pre-stored in the memory 134, a channel list pre-stored in the memory 134, and the MAC address "abc" of the Wi-FiI / F116. The channel list is a list of values of a plurality of communication channels to be used in Auth (refer to T25 in FIG. 2).
[0043] Upon receiving the SRes from the printer 100 via BTI / F18 at T130, the terminal 10 acquires each piece of information within the SRes (i.e., the public key PPK1, the channel list, and the MAC address "abc"). Next, at T132, the terminal 10 displays a terminal-side confirmation screen TCS that inquiries the user whether to execute a connection process for establishing a Wi-Fi connection between the printer 100 and the AP6. The screen TCS includes a YES button indicating execution of the connection process and a NO button indicating non-execution of the connection process. At T140, the terminal 10 accepts the selection of the YES button within the screen TCS from the user. When the processing at T140 ends, the processing of the BS in case A ends.
[0044] (Authentication (Auth); FIG. 4) Next, with reference to FIG. 4, the Auth process of T25 in FIG. 2 will be described. In T140 of FIG. 3, when the YES button in the screen TCS is selected by the user, the terminal 10 generates the public key TPK1 and the private key tsk1 of the terminal 10 in T141. Next, in T142, the terminal 10 generates the shared key SK1 using the generated private key tsk1 and the public key PPK1 of the printer 100 obtained in T130 of FIG. 3 according to ECDH (Elliptic curve Diffie-Hellman key exchange). Then, in T144, the terminal 10 encrypts the random value RV1 using the generated shared key SK1 to generate the encrypted data ED1.
[0045] In T200, the terminal 10 transmits AReq to the printer 100 with the MAC address "abc" obtained in T130 of FIG. 3 as the destination via the Wi-Fi I / F 16. AReq is a signal that requests the printer 100 to execute authentication. Here, the terminal 10 repeatedly transmits AReq to the printer 100 by sequentially using a plurality of communication channels in the channel list obtained in T130. The AReq includes the public key TPK1 of the terminal 10 generated in T141, the encrypted data ED1 generated in T144, and the capability of the terminal 10.
[0046] Capability is information that is pre-specified in a device supporting the DPP method, and includes one of the following values: a value indicating that it can operate only as a Configurator of the DPP method, a value indicating that it can operate only as an Enrollee of the DPP method, and a value indicating that it can operate as either a Configurator or an Enrollee. Note that, in Config (T30 in Figure 2), the Configurator means a device that transmits the CO used in NA (T35 in Figure 2) to the Enrollee. On the other hand, in Config, the Enrollee means a device that receives the CO used in NA from the Configurator. As described above, in this embodiment, the terminal 10 generates the first or second CO and transmits it to the AP6 or the printer 100. Therefore, the capability of the terminal 10 includes a value indicating that it can operate only as a Configurator.
[0047] The printer 100 receives an AReq from the terminal 10 via the Wi-Fi I / F 116 at T200. As described above, the AReq is transmitted with the MAC address "abc" of the printer 100 as the destination. Therefore, the printer 100 can appropriately receive the AReq from the terminal 10.
[0048] Also, when the printer 100 transitions to the enabled state at T122 in Figure 3, it monitors for receiving an AReq in which one of the multiple communication channels in the channel list is used. As described above, the AReq at T200 is transmitted using the multiple communication channels in the channel list sequentially. Therefore, the printer 100 can appropriately receive the AReq from the terminal 10.
[0049] Next, the printer 100 executes the following process to authenticate the source of the AReq (i.e., the terminal 10). Specifically, first, in T202, the printer 100 generates a shared key SK1 using the public key TPK1 of the terminal 10 in the AReq and the secret key psk1 of the printer 100 pre-stored in the memory 134 according to ECDH. Here, the shared key SK1 generated by the terminal 10 in T142 and the shared key SK1 generated by the printer 100 in T204 are the same. Therefore, in T204, the printer 100 can appropriately decrypt the encrypted data ED1 in the AReq using the generated shared key SK1, and as a result, obtain the random value RV1. If the decryption of the encrypted data ED1 is successful, the printer 100 determines that the source of the AReq is the device that sent the SReq received in T114 of FIG. 3, that is, determines that the authentication is successful, and executes the processes after T206. On the other hand, if the decryption of the encrypted data ED1 fails, the printer 100 determines that the source of the AReq is not the device that sent the SReq received in T114, that is, determines that the authentication has failed, and does not execute the processes after T206.
[0050] In T206, the printer 100 generates a new public key PPK2 and a new secret key psk2 of the printer 100. In a modified example, the public key PPK2 and the secret key psk2 may be pre-stored in the memory 134. Next, in T207, the printer 100 generates a shared key SK2 using the public key TPK1 of the terminal 10 in the AReq of T200 and the generated secret key psk2 of the printer 100 according to ECDH. Then, in T208, the printer 100 encrypts the obtained random value RV1 and the new random value RV2 using the generated shared key SK2 to generate encrypted data ED2.
[0051] In T210, the printer 100 transmits ARes to the terminal 10 via the Wi-Fi I / F 116. The ARes includes the public key PPK2 of the printer 100 generated in T206, the encrypted data ED2 generated in T208, and the capability of the printer 100. The capability includes a value indicating that it can operate only as an Enrollee.
[0052] In T210, in response to receiving ARes from the printer 100 via the Wi-Fi I / F 16, the terminal 10 executes the following process to authenticate the source (i.e., the printer 100) of the ARes. Specifically, first, in T212, the terminal 10 generates a shared key SK2 using the secret key tsk1 of the terminal 10 generated in T141 and the public key PPK2 of the printer 100 within the ARes according to ECDH. Here, the shared key SK2 generated by the printer 100 in T207 and the shared key SK2 generated by the terminal 10 in T212 are the same. Therefore, in T214, the terminal 10 can appropriately decrypt the encrypted data ED2 within the ARes using the generated shared key SK2, and as a result, obtain the random values RV1 and RV2. If the decryption of the encrypted data ED2 is successful, the terminal 10 determines that the source of the ARes is the device that is the source of the SRes received in T130 of FIG. 3, that is, determines that the authentication is successful, and executes the process after T220. On the other hand, if the decryption of the encrypted data ED2 fails, the terminal 10 determines that the source of the ARes is not the device that is the source of the SRes received in T130, that is, determines that the authentication has failed, and does not execute the process after T220.
[0053] In T220, the terminal 10 transmits Confirm to the printer 100 via the Wi-Fi I / F 16. Confirm includes information indicating that the terminal 10 operates as a Configurator and the printer 100 operates as an Enrollee. As a result, in T222, it is determined by the terminal 10 to operate as a Configurator, and in T224, it is determined by the printer 100 to operate as an Enrollee. When the process of T224 ends, the process of FIG. 4 ends.
[0054] (Configuration(Config); FIG. 5) Subsequently, referring to FIG. 5, the Config process of T30 in FIG. 2 will be described. In T300, the printer 100 transmits a DPP Configuration Request (hereinafter simply referred to as "CReq") to the terminal 10 via the Wi-Fi I / F 116. The CReq is a signal requesting the transmission of CO (i.e., information for establishing a Wi-Fi connection between the printer 100 and the AP6).
[0055] In T300, the terminal 10 receives the CReq from the printer 100 via the Wi-Fi I / F 16. In this case, in T301, the terminal 10 acquires the group ID "Group1", the public key TPK2, and the private key tsk2 from the memory (not shown) of the terminal 10. As described above, the terminal 10 has already executed Config of T15 in FIG. 2 with the AP6, and at this time, generates and stores the group ID "Group1", the public key TPK2, and the private key tsk2 in the memory. The group ID "Group1" is information for identifying a wireless network formed by establishing a Wi-Fi connection between the printer 100 and the AP6. In a modified example, a character string specified by the user may be used as the group ID. That is, in T301, the terminal 10 acquires each piece of information stored in T15 of FIG. 2. Next, in T302, the terminal 10 generates a second CO (refer to T30 in FIG. 2). Specifically, the terminal 10 executes the following respective processes.
[0056] The terminal 10 generates a hash value HV by hashing the public key TPK2 of the terminal 10. Further, the terminal 10 generates a specific value by hashing the combination of the hash value HV, the group ID "Group1", and the public key PPK2 of the printer 100 within ARes of T210 in FIG. 4. Then, the terminal 10 generates an electronic signature DS1 by encrypting the generated specific value using the private key tsk2 of the terminal 10 according to ECDSA (abbreviation for Elliptic Curve Digital Signature Algorithm). As a result, the terminal 10 can generate a printer Signed-Connector (hereinafter simply referred to as "SCont") including the hash value HV, the group ID "Group1", the public key PPK2 of the printer 100, and the electronic signature DS1. Then, the terminal 10 generates a second CO including the printer SCont and the public key TPK2 of the terminal 10.
[0057] In T310, the terminal 10 transmits a DPP Configuration Response (hereinafter simply referred to as "CRes") including the second CO to the printer 100 via the Wi-Fi I / F 16.
[0058] The printer 100 receives the CRes from the terminal 10 via the Wi-Fi I / F 116 in T310. In this case, the printer 100 stores the second CO within the CRes in the memory 134 in T312. When the process of T312 ends, the process of FIG. 5 ends.
[0059] (Network Access(NA); Figure 6) As described above, similar to T20 to T30 in FIG. 2, the processes of T5 to T15 in FIG. 2 have been executed between the terminal 10 and the AP6. However, the AP6 does not execute the processes of T105 to T124 in FIG. 3. The AP6 pre-stores the public key APK1 and the private key ask1 of the AP6. And a QR code obtained by encoding the public key APK1 of the AP6, the channel list of the AP6, and the MAC address of the AP6 is pasted on the housing of the AP6. By the terminal 10 photographing the QR code, processes similar to the processes after T134 are executed between the terminal 10 and the AP6. As a result, the AP6 stores the public key APK2 and the private key ask2 of the AP6 (see T206 in FIG. 4), and further stores the first CO received from the terminal 10 (see T312 in FIG. 5). The first CO includes the SCont for AP and the public key TPK2 of the terminal 10. The public key TPK2 is the same as the public key TPK2 included in the second CO. Also, the SCont for AP includes the hash value HV, the group ID "Group1", the public key APK2 of the AP6, and the digital signature DS2. The hash value HV and the group ID "Group1" are the same as the hash value HV and the group ID "Group1" included in the second CO, respectively. The digital signature DS2 is information in which a specific value obtained by hashing the combination of the hash value HV, the group ID "Group1", and the public key APK2 is encrypted by the private key tsk2 of the terminal 10, and is a value different from the digital signature DS1 included in the second CO.
[0060] At T400, the printer 100 transmits a DPP Peer Discovery Request (hereinafter simply referred to as "DReq") including the SCont for printer via the Wi-Fi I / F 116 to the AP6. The DReq is a signal that requests the AP6 to execute authentication and transmit the SCont for AP.
[0061] Upon receiving DReq from printer 100 in T400, AP6 executes a process for authenticating the source of DReq (i.e., printer 100) and each piece of information in DReq (i.e., hash value HV, "Group1", and public key PPK2). Specifically, in T402, AP6 first executes a first AP determination process regarding whether the hash value HV and group ID "Group1" in the received printer SCont match the hash value HV and group ID "Group1" in the AP SCont included in the stored first CO, respectively. In the case of Figure 6, since AP6 determines "match" in the first AP determination process, it determines that the authentication of the source of DReq (i.e., printer 100) is successful. Note that the fact that the hash value HV in the received printer SCont matches the hash value HV in the AP SCont included in the stored first CO means that the printer SCont and the AP SCont were generated by the same device (i.e., terminal 10). Therefore, AP6 also determines that the authentication of the source (i.e., terminal 10) of the received printer SCont is successful. Further, AP6 decrypts the digital signature DS1 in the received printer SCont using the public key TPK2 of terminal 10 included in the stored first CO. In the case of Figure 6, since the decryption of the digital signature DS1 is successful, AP6 executes a second AP determination process regarding whether the specific value obtained by decrypting the digital signature DS1 matches the value obtained by hashing each piece of information (i.e., hash value HV, "Group1", and public key PPK2) in the received printer SCont. In the case of Figure 6, since AP6 determines "match" in the second AP determination process, it determines that the authentication of each piece of information in DReq is successful and executes the processes after T404. The determination of "match" in the second AP determination process means that after the second CO is stored in printer 100, each piece of information (i.e., hash value HV, "Group1", and public key PPK2) in the received printer SCont has not been tampered with by a third party.On the other hand, if it is determined as "not matching" in the first AP determination process, if the decryption of the electronic signature DS1 fails, or if it is determined as "not matching" in the second AP determination process, AP6 determines that the authentication has failed and does not execute the processes after T404.
[0062] Next, at T404, AP6 generates a connection key (i.e., a shared key) CK using the acquired public key PPK2 of the printer 100 and the stored private key ask2 of AP6 according to ECDH.
[0063] At T410, AP6 transmits a DPP Peer Discovery Response (hereinafter simply referred to as "DRes") including AP SCont to the printer 100.
[0064] In T410, when the printer 100 receives DRes from AP6 via the Wi-Fi I / F 116, it executes a process for authenticating the source of DRes (i.e., AP6) and each piece of information in DRes (i.e., the hash value HV, "Group1", and the public key APK2). Specifically, in T412, the printer 100 first executes a first PR determination process regarding whether the hash value HV and the group ID "Group1" in the received AP SCont match the hash value HV and the group ID "Group1" in the printer SCont included in the stored second CO, respectively. In the case of FIG. 6, since the printer 100 determines "match" in the first PR determination process, it determines that the authentication of the source of DRes (i.e., AP6) has succeeded. Note that the fact that the hash value HV in the received AP SCont matches the hash value HV in the printer SCont included in the stored second CO means that the printer SCont and the AP SCont were generated by the same device (i.e., the terminal 10). Therefore, the printer 100 also determines that the authentication of the source (i.e., the terminal 10) of the received AP SCont has succeeded. Further, the printer 100 decrypts the digital signature DS2 in the received AP SCont using the public key TPK2 of the terminal 10 included in the stored second CO. In the case of FIG. 6, since the decryption of the digital signature DS2 is successful, the printer 100 executes a second PR determination process regarding whether the specific value obtained by decrypting the digital signature DS2 matches the value obtained by hashing each piece of information (i.e., the hash value HV, "Group1", and the public key APK2) in the received AP SCont. In the case of FIG. 6, since the printer 100 determines "match" in the second PR determination process, it determines that the authentication of each piece of information in DRes has succeeded and executes the processes after T414. The determination of "match" in the second PR determination process means that after the first CO is stored in AP6, each piece of information (i.e., the hash value HV, "Group1", and the public key APK2) in the AP SCont has not been tampered with by a third party.On the other hand, if it is determined as "not matching" in the first PR determination process, if the decryption of the electronic signature DS2 fails, or if it is determined as "not matching" in the second PR determination process, the printer 100 determines that the authentication has failed and does not execute the processes after T414.
[0065] At T414, the printer 100 generates a connection key CK using the stored private key psk2 of the printer 100 and the public key APK2 of AP6 in the received SCont for the AP according to ECDH. Here, the connection key CK generated by AP6 at T404 and the connection key CK generated by the printer 100 at T414 are the same. Thereby, the connection key CK for establishing the Wi-Fi connection is shared between the printer 100 and AP6. When T414 ends, the process of FIG. 6 ends.
[0066] As described above, after the connection key CK is shared between the printer 100 and AP6, at T40 in FIG. 2, the printer 100 and AP6 execute 4-way-handshake communication using the connection key CK. As a result, a Wi-Fi connection is established between the printer 100 and AP6. As described above, the printer 100 receives the AReq of T200 in FIG. 4 from the terminal 10 using one communication channel among the plurality of communication channels included in the channel list of the printer 100. That is, the printer 100 receives the AReq of T200 from the terminal 10 using a communication channel that can be used by both the printer 100 and the terminal 10. On the other hand, at T40 in FIG. 2, the printer 100 establishes a Wi-Fi connection with AP6 using a communication channel that can be used by both the printer 100 and AP6. Here, the communication channel available to the terminal 10 and the communication channel available to AP6 may be different. In this embodiment, the communication channel for the printer 100 to receive the AReq from the terminal 10 at T200 in FIG. 4 and the communication channel for the printer 100 to establish a Wi-Fi connection with AP6 at T40 in FIG. 2 are different. However, in a modification, the former communication channel and the latter communication channel may be the same.
[0067] (Bootstrapping (BS) for Case B; Figure 7) Next, with reference to Figure 7, the processing of the other Case B of BS will be described. Case B is the state after T5 to T40 in Figure 2 are executed, that is, the state where the memory 134 of the printer 100 has already stored the second CO.
[0068] T500 and T505 are the same as T100 and T105 in Figure 3. In this case, since the memory 134 of the printer 100 stores the second CO, the printer 100 does not shift the operation mode of BTI / F118 from the normal mode to the setting mode. In the situation where the printer 100 stores the second CO, the printer 100 can use the second CO to establish a Wi-Fi connection with AP6. Therefore, the possibility of BS being executed in the printer 100 is low. In such a situation, since the printer 100 does not shift the operation mode of BTI / F118 to the setting mode, even if SReq is transmitted from the terminal 10 to the printer 100, the SReq is not supplied from BTI / F118 to the CPU132, and as a result, the first instruction screen FIS is not displayed on the printer 100. Therefore, the processing load of the printer 100 can be reduced.
[0069] The user may, for example, desire to establish a Wi-Fi connection between the printer 100 and an AP different from AP6 in the state where the printer 100 stores the second CO. In this case, the user selects the setting button in the menu screen MS at T506. In this case, the printer 100 causes the setting screen SS to be displayed on the display unit 114 at T507. The screen SS includes a print setting button for changing the print settings of the printer 100 and a mode shift button for changing the operation mode of BTI / F118. Then, at T508, the user selects the mode shift button in the screen SS. In this case, the printer 100 shifts the operation mode of BTI / F118 from the normal mode to the setting mode at T509. Thereby, the printer 100 can execute the same processing as the processing after T114 in Figure 3 in response to receiving SReq from the terminal 10.
[0070] Note that the printer 100 can also establish a Wi-Fi connection with the AP6 according to the normal Wi-Fi method (i.e., the method using the SSID and password) without using the DPP method. In this case, the memory 134 of the printer 100 stores the wireless setting information (i.e., the SSID and password) for establishing the Wi-Fi connection with the AP6. Even when the power of the printer 100 is turned on in such a state, the printer 100 does not shift the operation mode of the BTI / F118 from the normal mode to the setting mode as in Case B of FIG. 7. This is because the printer 100 can establish a Wi-Fi connection with the AP6 using the wireless setting information. As a result, even if SReq is transmitted from the terminal 10 to the printer 100, the first instruction screen FIS is not displayed on the printer 100. Therefore, the processing load on the printer 100 can be reduced.
[0071] (Effect of this embodiment) Here, assume a printer of a comparative example in which the first instruction screen FIS is not displayed in response to receiving SReq from the terminal 10. And, for example, assume a situation where the user of the terminal 10 hopes that a Wi-Fi connection is established between a printer different from the printer of the comparative example and the AP6, that is, a situation where communication according to the DPP method is not desired to be executed between the printer of the comparative example and the terminal 10. In this case, the printer of the comparative example automatically executes the same processing as the processing after T122 in FIG. 3 in response to receiving SReq from the terminal 10 and transmits SRes to the terminal 10. That is, the printer 100 of the comparative example transmits SRes to the terminal 10 without receiving an instruction from the user in response to receiving SReq from the terminal 10. In this case, a Wi-Fi connection can be established between the printer of the comparative example and the AP6. That is, a Wi-Fi connection can be established between a pair of devices (i.e., the printer of the comparative example and the AP6) not intended by the user of the terminal 10.
[0072] In contrast, when the printer 100 of the present embodiment receives an SReq from the terminal 10 (T114 in FIG. 3), it displays a first instruction screen FIS (T116). As a result, when the YES button in the screen FIS is selected by the user (T120), that is, when the user desires that communication according to the DPP method (i.e., communication using the public key PPK1) be performed between the printer 100 and the terminal 10, the printer 100 transmits an SRes including the public key PPK1, etc., to the terminal 10 (T130). As a result, the printer 100 receives an AReq from the terminal 10 (T200 in FIG. 4), transmits an ARes to the terminal 10 (T210), receives a second CO from the terminal 10 (T310 in FIG. 5), and establishes a Wi-Fi connection with the AP6 using the second CO (T35, T40 in FIG. 2). For this reason, a Wi-Fi connection can be established between a pair of devices (i.e., the printer 100 and the AP6) intended by the user of the terminal 10. On the other hand, when the YES button in the screen FIS is not selected, that is, when the user does not desire that communication according to the DPP method be performed between the printer 100 and the terminal 10, the SRes including the public key PPK1, etc., is not transmitted. Therefore, in the printer 100, an AReq is not received from the terminal 10, and as a result, a Wi-Fi connection with the AP6 is not established. For this reason, it is possible to suppress the establishment of a Wi-Fi connection between a pair of devices (i.e., the printer 100 and the AP6) not intended by the user of the terminal 10.
[0073] (Corresponding relationship) The printer 100, the terminal 10, and the AP6 are examples of a "communication device", a "first external device", and a "second external device", respectively. The BTI / F118 and the Wi-FiI / F116 are examples of a "first wireless interface" and a "second wireless interface", respectively. The SReq at T114 in FIG. 3 and the public key PPK1 of the printer 100 are examples of a "specific signal" and a "public key", respectively. The AReq, the ARes, and the second CO are examples of an "authentication request", an "authentication response", and "connection information", respectively. The Wi-Fi connection established at T40 in FIG. 2 is an example of a "wireless connection".
[0074] The channel list, the communication channel used by T200 in FIG. 4, and the communication channel used by T40 in FIG. 2 are examples of "communication channel information", "first communication channel", and "second communication channel", respectively. Accepting the power-on operation from the user when the second CO is not stored in the memory 134, and accepting the selection of the mode shift button from the user when the second CO is stored in the memory 134 are examples of "predetermined conditions". The normal mode and the setting mode are examples of "first mode" and "second mode", respectively. The AP SCont and the hash value HV in the second CO are examples of "received information" and "authentication information", respectively.
[0075] The processes of T114, T116, and T130 in FIG. 3, the processes of T200 and T210 in FIG. 4, the process of T310 in FIG. 5, and the processes of T35 and T40 in FIG. 2 are examples of the processes executed by the "specific signal receiving unit", "first display control unit", "public key transmitting unit", "authentication request receiving unit", "authentication response transmitting unit", "connection information receiving unit", and "establishment unit", respectively.
[0076] (Second Embodiment; FIGS. 8 to 12) Subsequently, the second embodiment will be described. In the second embodiment, the processes executed by the printer 100 in BS and Auth are different.
[0077] (Process of BS; FIG. 8) First, with reference to FIG. 8, the details of the process executed by the printer in the BS of T20 in FIG. 2 will be described. When the operation mode of the BTI / F118 shifts from the normal mode to the setting mode, the process of FIG. 8 is executed.
[0078] In S5, the printer 100 monitors receiving an SReq via the BTI / F118. Specifically, when the printer 100 (i.e., the CPU 132) acquires the SReq from the BTI / F118, it determines YES in S5 and proceeds to S10. Hereinafter, the terminal that is the transmission source of the SReq is referred to as the "target terminal".
[0079] In S10, the printer 100 acquires the received radio wave intensity of the received SReq, and determines whether or not the received radio wave intensity is equal to or greater than a threshold value. Note that the threshold value may be a value determined by the vendor of the printer 100 at the time of shipment of the printer 100, or may be a value specified by the user after the shipment of the printer 100. When receiving the SReq, the BTI / F118 specifies the received radio wave intensity of the SReq, and supplies the specified received radio wave intensity to the printer 100 (that is, the CPU 132). Thereby, the printer 100 (that is, the CPU 132) can acquire the received radio wave intensity. When the printer 100 determines that the acquired received radio wave intensity is equal to or greater than the threshold value, it determines YES in S10 and proceeds to S25. On the other hand, when the printer 100 determines that the acquired received radio wave intensity is less than the threshold value, it determines NO in S10 and proceeds to S15.
[0080] In S15, the printer 100 causes the display unit 114 to display the first instruction screen FIS. The screen FIS is the same screen as the first instruction screen FIS of T116 in FIG. 3. That is, the screen FIS includes a YES button indicating that connection processing is to be executed.
[0081] In S20, the printer 100 determines whether or not the YES button in the screen FIS has been selected. When the YES button in the screen FIS is selected by the user, the printer 100 determines YES in S20 and proceeds to S25. On the other hand, when the YES button is not selected within a predetermined time after the screen FIS is displayed in S15 (that is, timeout), the printer 100 determines NO in S20, and ends the processing of FIG. 8 as non-execution END without executing the processing after S25 described later. Non-execution END means aborting the processing according to the DPP method.
[0082] In S25, the printer 100 determines whether the SReq obtained from the BTI / F118 in S5 includes the MAC address of the target terminal. When the SReq includes the MAC address, the printer 100 determines YES in S25, and in S30, stores the MAC address in the memory 134 and proceeds to S35. On the other hand, when the SReq does not include the MAC address, the printer 100 determines NO in S25 and proceeds to S35.
[0083] In S35, the printer 100 transitions from an impossible state to a possible state. If the printer 100 is already operating in a possible state, it skips the process of S35 and proceeds to S40.
[0084] In S40, the printer 100 transmits the SRes to the target terminal via the BTI / F118. The SRes includes the public key PPK1 of the printer 100, the channel list pre-stored in the memory 134, and the MAC address "abc" of the Wi-FiI / F116. When the process of S40 ends, the process of Auth is executed, and the process of FIG. 8 ends as the execution END.
[0085] (Auth process; FIG. 9) Subsequently, with reference to FIG. 9, the details of the process executed by the printer 100 in the Auth of T25 in FIG. 2 will be described. When the printer 100 transitions to a possible state in S35 of FIG. 8, the process of FIG. 9 is executed.
[0086] In S100, the printer 100 monitors for receiving an AReq via the Wi-Fi I / F 116. Hereinafter, the terminal that is the source of the AReq is referred to as the "specific terminal". The AReq includes the public key of the specific terminal, the encrypted data generated by the specific terminal, the MAC address of the specific terminal, and the capability of the specific terminal (see T200 in FIG. 4). When the printer 100 receives an AReq from the specific terminal, it determines YES in S100 and proceeds to S105. On the other hand, when the printer 100 does not receive an AReq within a predetermined time after transitioning to the enabled state (S35 in FIG. 8), it determines NO in S100 and ends the process in FIG. 9 as non-execution END.
[0087] In S105, the printer 100 determines whether the MAC address of the target terminal memorized in S30 of FIG. 8 matches the MAC address of the specific terminal in the AReq received in S100. When the MAC address of the target terminal matches the MAC address of the specific terminal, that is, when the specific terminal matches the target terminal, the printer 100 determines YES in S105 and proceeds to S120. On the other hand, when the MAC address of the target terminal does not match the MAC address of the specific terminal, that is, when the specific terminal is different from the target terminal, the printer 100 determines NO in S105 and proceeds to S110. Note that even when the process of S30 is skipped, that is, when the MAC address is not memorized in the memory 134, the printer 100 determines NO in S105 and proceeds to S110.
[0088] In S110, the printer 100 causes the display unit 114 to display a second instruction screen SIS for instructing to execute a connection process for establishing a Wi-Fi connection. The second instruction screen SIS includes a YES button indicating to execute the connection process.
[0089] In S115, the printer 100 determines whether the YES button on the screen SIS has been selected. When the YES button on the screen SIS is selected by the user, the printer 100 determines YES in S115 and proceeds to S120. On the other hand, when the YES button is not selected even after a predetermined time has elapsed since the screen SIS was displayed in S110 (i.e., in the case of timeout), the printer 100 ends the display of the screen SIS. In this case, the printer 100 ends the process of FIG. 9 as non-execution END without executing the processes after S120 described later. Note that in a modified example, the screen SIS includes a NO button indicating that the connection process is not executed, and when the NO button on the screen SIS is selected by the user, the printer 100 may determine NO in S115 and end the process of FIG. 9 as non-execution END.
[0090] In S120, the printer 100 executes an authentication process and an operation determination process. The authentication process is a process for the printer 100 to authenticate a communication partner (i.e., T202 to T210 in FIG. 4). The operation determination process is a process for the printer 100 to determine whether to operate as a Configurator or an Enrollee (i.e., T220 to T224). When the process of S120 ends, the printer 100 ends the process of FIG. 9 as an execution END for executing Config.
[0091] (BS and Auth in Case C; FIG. 10) Subsequently, with reference to FIG. 10, the BS and Auth processes in Case C realized by the processes of FIGS. 8 and 9 will be described. Case C assumes a situation where the distance between the terminal 10 and the printer 100 is relatively small.
[0092] T600 to T614 are the same as T100 to T114 in FIG. 3. At T616, since the distance between the terminal 10 and the printer 100 is relatively small, the printer 100 determines that the received radio wave intensity of SReq is equal to or greater than the threshold value (YES in S10 of FIG. 8). Also, the printer 100 determines that the received SReq contains the MAC address "xxx" (YES in S25). As a result, at T620, the printer 100 stores the MAC address "xxx" in the SReq in the memory 134 (S30), and at T622, it transitions from the impossible state to the possible state (S35).
[0093] T630 to T650 are the same as T130 to T140 in FIG. 3 and T141 to T200 in FIG. 4. At T652, the printer 100 determines that the MAC address "xxx" stored at T620 matches the MAC address "xxx" in the AReq received at T650 (YES in S105 of FIG. 9). In this case, the printer 100 executes the same processing as T202 to T224 in FIG. 4 and ends the processing in FIG. 10. Thereafter, the same processing as in FIGS. 5 and 6 is executed by each of the devices 6, 10, 100, and a Wi-Fi connection is established between the printer 100 and the AP6 (T40 in FIG. 2).
[0094] (BS and Auth in Case D; FIG. 11) Subsequently, referring to FIG. 11, the BS and Auth processing in Case D realized by the processing in FIGS. 8 and 9 will be described. Case D assumes a situation where the distance between the terminal 10 and the printer 100 is relatively large.
[0095] T700 to T714 are the same as T100 to T114 in FIG. 3. In this case D, since the distance between the terminal 10 and the printer 100 is relatively large, the printer 100 determines at T716 that the received radio wave intensity of SReq is less than the threshold value (NO in S10 of FIG. 8), and at T717, causes the first instruction screen FIS to be displayed on the display unit 114 (S15). Then, the printer 100 determines at T718 that the YES button in the second instruction screen SIS has not been selected within a predetermined time (i.e., timeout) (NO in S20), ends the display of the screen FIS, and ends the process of FIG. 11.
[0096] As shown in case D, in a situation where the distance between the printer 100 and the terminal 10 is relatively large, it is highly likely that the user of the terminal 10 does not desire that communication according to the DPP method (i.e., communication using the public key PPK1) be executed between the printer 100 and the terminal 10. For example, assume a situation where the terminal 10 exists at a position considerably distant from the printer 100, and the user of the terminal 10 desires that a Wi-Fi connection be established between a printer different from the printer 100 and the AP6. In such a situation, if the printer 100 automatically executes the processes after T620 in FIG. 10 and transmits SRes to the terminal 10 in response to receiving SReq from the terminal 10 (T630), a Wi-Fi connection may be established between the printer 100 and the AP6. That is, a Wi-Fi connection may be established between a pair of devices (i.e., the printer 100 and the AP6) not intended by the user of the terminal 10.
[0097] On the other hand, in Case D, when the printer 100 receives SReq from the terminal 10 (T714), if it determines that the received radio wave intensity of SReq is less than a certain level, it causes the first instruction screen FIS to be displayed on the display unit 114, thereby restricting the transmission of the public key PPK1 (T717). Since the user of the terminal 10 does not desire the printer 100 to establish a Wi-Fi connection, the user does not select the YES button within the screen FIS. As a result, the printer 100 determines that it has timed out (T718) and does not transmit SRes to the terminal 10. Therefore, it is possible to suppress the establishment of a Wi-Fi connection between the printer 100 and the AP6. That is, it is possible to suppress the establishment of a Wi-Fi connection between a pair of devices not intended by the user of the terminal 10. Note that in Case D, if the user of the terminal 10 desires the establishment of a Wi-Fi connection between the printer 100 and the AP6, the YES button within the screen FIS is selected by the user. In this case, the processing after T202 in FIG. 4 is executed, and a Wi-Fi connection is established between the printer 100 and the AP6. Therefore, a Wi-Fi connection can be established according to the user's intention.
[0098] (BS and Auth in Case E; FIG. 12) Subsequently, with reference to FIG. 12, the BS and Auth processing in Case E realized by the processing of FIGS. 8 and 9 will be described. Here, the terminal 10 is equipped with a first type of application 40 provided by the vendor of the printer 100. For this reason, it is highly likely that the user of the terminal 10 desires the printer 100 to establish a Wi-Fi connection. On the other hand, the terminal 50 is equipped with a second type of application 52 provided by a vendor different from the vendor of the printer 100. For this reason, it is less likely that the user of the terminal 50 desires the printer 100 to establish a Wi-Fi connection. And Case E assumes a situation where the user of the terminal 10 desires the establishment of a Wi-Fi connection between the printer 100 and the AP6, and the user of the terminal 50 desires the establishment of a Wi-Fi connection between a printer different from the printer 100 and an AP different from the AP6.
[0099] In Case E, first, the same processing as that of T600 to T622 in FIG. 10 is executed by the terminal 10 and the printer 100. As a result, the printer 100 stores the MAC address "xxx" of the terminal 10 in the memory 134 (T620) and transitions from the impossible state to the possible state (T622).
[0100] Thereafter, before the AReq is transmitted from the terminal 10 to the printer 100 (i.e., before T650 in FIG. 10), at T810, a start operation of the second type of application 52 is executed on the terminal 50 by the user of the terminal 50, and at T812, the second type of application 52 is started. As a result, the terminal 50 executes the following respective processes according to the second type of application 52. Note that before executing the processes after T810, the terminal 50 has already executed the same processes as T5 to T15 in FIG. 2 with the different APs described above.
[0101] At T814, the terminal 50 transmits an SReq to the printer 100. Here, unlike the first type of application 40 provided by the vendor of the printer 100, the second type of application 52 transmits an SReq that does not include the MAC address "yyy" of the terminal 50. Therefore, the MAC address "yyy" of the terminal 50 is not stored in the printer 100.
[0102] When the printer 100 receives the SReq from the terminal 50 via the BTI / F118 at T814 (YES at S5 in FIG. 8), at T816, due to the relatively short distance between the terminal 50 and the printer 100, it is determined that the received radio wave intensity of the SReq is equal to or greater than the threshold value (YES at S10), and it is determined that the SReq does not include a MAC address (NO at S25).
[0103] T830 to T850 are the same as T630 to T650 in FIG. 10, except that the public key TPK5, private key tsk5, shared key SK5, random value RV5, encrypted data ED5, and MAC address "yyy" of the terminal 50 are used. Note that the second type of application 52 does not display the terminal-side confirmation screen TCS. Therefore, the terminal 50 does not execute the processes of T632 and T640 in FIG. 10.
[0104] In T852, the printer 100 determines that the MAC address "xxx" stored in T816 does not match the MAC address "yyy" in the AReq received in T850 (NO in S105 of FIG. 9). In this case, the printer 100 causes the display unit 114 to display the second instruction screen SIS in T852 (S110). Then, in T854, the printer 100 determines that the YES button in the screen SIS has not been selected within a predetermined time (i.e., timeout) (NO in S115 of FIG. 4), ends the display of the screen SIS, and ends the process of FIG. 12.
[0105] If the printer 100 automatically executes the processes after T202 in FIG. 4 and transmits ARes to the terminal 50 in response to receiving AReq from the terminal 50 (T850), a Wi-Fi connection may be established between the printer 100 and an AP different from the above. That is, a Wi-Fi connection may be established between a pair of devices not intended by the user of the terminal 50 (i.e., the printer 100 and the AP different from the above).
[0106] In contrast, in Case E, when the printer 100 receives AReq from the terminal 50 (T850), since the MAC address "xxx" of the terminal 10 in the memory 134 does not match the MAC address "yyy" of the terminal 50 in AReq, the printer 100 restricts the transmission of ARes (T852) by causing the second instruction screen SIS to be displayed on the display unit 114. Since the user of the terminal 50 does not desire the printer 100 to establish a Wi-Fi connection, the user does not select the YES button within the screen SIS. As a result, the printer 100 determines that a timeout has occurred (T854) and does not transmit ARes to the terminal 50. Therefore, it is possible to suppress the establishment of a Wi-Fi connection between the printer 100 and an AP different from the above. That is, it is possible to suppress the establishment of a Wi-Fi connection between a pair of devices not intended by the user of the terminal 50. In Case E, when the user of the terminal 50 desires the establishment of a Wi-Fi connection between the printer 100 and an AP different from the above, the YES button within the screen SIS is selected by the user. In this case, the processing after T202 in FIG. 4 is executed, and a Wi-Fi connection is established between the printer 100 and an AP different from the above. Therefore, it is possible to establish a Wi-Fi connection according to the user's intention.
[0107] (Corresponding relationship) The MAC address "xxx" and the terminal 50 are, respectively, examples of "identification information" and "different external devices". The processing of S5, S10, S40, S100 in FIG. 8, the processing of T210 in FIG. 4, the processing of T310 in FIG. 5, and the processing of T35 and T40 in FIG. 2 are, respectively, examples of the processing executed by the "specific signal receiving unit" and "identification information receiving unit", "judgment unit", "public key transmitting unit", "authentication request receiving unit", "authentication response transmitting unit", "connection information receiving unit", and "establishing unit".
[0108] As described above, specific examples of the present invention have been described in detail, but these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes of the specific examples illustrated above. Modifications of the above embodiments are listed below.
[0109] (Modification Example 1) The processes for generating the shared key (e.g., SK1 in FIG. 4, such as T142 and T202) are not limited to the processes of the above embodiments according to ECDH, but may be other processes according to ECDH. Also, the process for generating the shared key is not limited to the process according to ECDH, and a process according to another method (e.g., DH (abbreviation for Diffie-Hellman key exchange), etc.) may be executed. Further, in the above embodiments, the electronic signatures DS1 and DS2 are generated according to ECDSA, but they may be generated according to other methods (e.g., DSA (abbreviation for Digital Signature Algorithm), RAS (abbreviation for Rivest-Shamir-Adleman cryptosystem), etc.).
[0110] (Modification Example 2) The processes of S25, S30 in FIG. 8, and S105 in FIG. 9 may be omitted. In this case, for example, in T614 of FIG. 10, the terminal 10 may send an SReq that does not include the MAC address "xxx" to the printer 100. In this modification example, the "identification information receiving unit" can be omitted.
[0111] (Modification Example 3) The processes of S15 and S20 in FIG. 8 may be omitted. In this case, when the printer 100 determines NO in S10, it ends the process of FIG. 8 as a non-execution END. In this modification example, not sending an SRes when NO in S10 is an example of "the transmission of the public key is restricted".
[0112] (Modification Example 4) The processes of S110 and S115 in FIG. 9 may be omitted. In this case, when the printer 100 determines NO in S105, it ends the process of FIG. 9 as a non-execution END. In this modification example, not sending an ARes when NO in S105 is an example of "the transmission of the authentication response is restricted". Also, in this modification example, the "second display control unit" can be omitted.
[0113] (Modification Example 5) For example, the SRes transmitted from the printer 100 at T130 in FIG. 3 may not include the channel list and the MAC address "abc". That is, the SRes may include at least the public key PPK1. In this case, when the printer 100 transitions from the impossible state to the possible state at T122, the printer 100 monitors receiving an AReq in which one of all the wireless channels available to the printer 100 is used. Also, at T200 in FIG. 4, the terminal 10 sequentially transmits the AReq by broadcast using all the wireless channels available to the terminal 10. In this modification example, the "channel information transmission unit" can be omitted.
[0114] (Modification Example 6) For example, at T114 in FIG. 3, when the printer 100 receives a signal different from the SReq from the terminal 10 and conforming to the BT method (for example, an Advertise signal), at T116, the printer 100 may cause the display unit 114 to display the first instruction screen FIS. In this modification example, the different signal is an example of the "specific signal". Also, in this case, at T130, the printer 100 may transmit a signal conforming to the above BT method (for example, an Advertise signal) including the public key PPK1, etc. to the terminal 10.
[0115] (Modification Example 7) After transmitting the SRes to the terminal 10 at T130 in FIG. 3, the printer 100 may transition from the impossible state to the possible state. That is, after receiving a specific signal from the first external device, it may be transitioned from the impossible state to the possible state.
[0116] (Modification Example 8) For example, the SReq at T614 in FIG. 10 may not include the MAC address "xxx". In this case, at T630, when the terminal 10 receives the SRes from the printer 100, the terminal 10 may transmit the MAC address "xxx" to the printer 100 via the BTI / F18. As a result, in the printer 100, the MAC address "xxx" is stored in the memory 134. In this modification example, the "specific signal" may not include the "identification information".
[0117] (Modification Example 9) The printer 100 may always operate in an enabled state. In this modification example, the "state transition unit" can be omitted.
[0118] (Modification Example 10) The BTI / F118 of the printer 100 may always operate in the setting mode. In this modification example, the "mode transition unit" can be omitted.
[0119] (Modification Example 11) In T614 of FIG. 10, the terminal 10 may transmit an SReq including the device name of the terminal 10 to the printer 100 via the BTI / F18 instead of the MAC address "xxx". In this case, in T620, the printer 100 stores the device name of the terminal in the SReq in the memory 134. Also, in T650 of FIG. 10, the printer 100 receives an AReq including the device name of the terminal 10 from the terminal 10 via the Wi-Fi I / F116 instead of the MAC address "xxx", and when the device name stored in the memory 134 matches the device name in the AReq, executes the processing after T202 in FIG. 4. In this modification example, the device name of the terminal 10 is an example of the "identification information". Generally speaking, the "identification information" may be any information that identifies the "first external device".
[0120] (Modification Example 12) In T35 of FIG. 2, NA processing may be executed between the terminal 10 and the printer 100 to establish a Wi-Fi connection between the terminal 10 and the printer 100. That is, the "second external device" may be the same device as the "first external device".
[0121] (Modification Example 13) In the above embodiment, the terminal 10 is used to establish a Wi-Fi connection between the printer 100 and the AP6. Instead, for example, the terminal 10 may be used to establish a Wi-Fi connection between a printer 100 operating as a G / O (abbreviation for Group Owner) in the WFD mode (i.e., a device operating as a parent station) and another device (i.e., a device operating as a child station). That is, the "second external device" does not have to be the "parent station device".
[0122] (Modification Example 14) Instead of the BTI / F118, the printer 100 may be provided with a wireless interface that complies with a wireless communication method different from the BT method (for example, the ZigBee method). In this modification example, the wireless interface is an example of the "first wireless interface".
[0123] (Modification Example 15) In the T850, the terminal 50 may transmit an AReq that does not include the MAC address "yyy" to the printer 100. In this case, when the printer 100 receives the AReq from the terminal 50 via the Wi-Fi I / F 116 and determines that the MAC address is not included in the AReq, the printer 100 may cause the second instruction screen SIS to be displayed on the display unit 114.
[0124] (Modification Example 16) The "communication device" does not have to be a printer, and may be other devices such as a scanner, a multifunction device, a mobile terminal, a PC, or a server.
[0125] (Modification Example 17) In each of the above embodiments, each process in FIGS. 2 to 12 is realized by software (that is, the program 136), but at least one of these processes may be realized by hardware such as a logic circuit.
[0126] Also, the technical elements described in this specification or the drawings exhibit technical utility alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Further, the technology illustrated in this specification or the drawings achieves a plurality of purposes simultaneously, and achieving one of those purposes itself has technical utility. The following items are elements described in the claims at the time of filing. (Item 1) A communication device, a display unit, a first wireless interface, a second wireless interface different from the first wireless interface, a specific signal receiving unit that receives a specific signal from a first external device via the first wireless interface, a first display control unit that causes the display unit to display a first instruction screen for instructing to execute target processing including transmission of a public key when the specific signal is received from the first external device, a public key transmitting unit that transmits the public key to the first external device via the first wireless interface when instructed to execute the target processing in a situation where the first instruction screen is displayed, and the public key is not transmitted when not instructed to execute the target processing in a situation where the first instruction screen is displayed, an authentication request receiving unit that receives an authentication request using the public key from the first external device via the second wireless interface after the public key is transmitted to the first external device, an authentication response transmitting unit that transmits an authentication response, which is a response to the authentication request, to the first external device via the second wireless interface when the authentication request is received from the first external device, a connection information receiving unit that receives connection information from the first external device via the second wireless interface after the authentication response is transmitted to the first external device, where the connection information is information for establishing a wireless connection between the communication device and a second external device via the second wireless interface, an establishing unit that establishes the wireless connection between the communication device and the second external device via the second wireless interface using the connection information when the connection information is received from the first external device, A communication device comprising the above. (Item 2) The communication device further comprises a determination unit that determines whether or not the received radio wave intensity of the specific signal is equal to or greater than a threshold value when the specific signal is received from the first external device. When the first display control unit receives the specific signal from the first external device and determines that the received radio wave intensity is not equal to or greater than the threshold value, the first display control unit causes the display unit to display the first instruction screen. When the specific signal is received from the first external device and it is determined that the received radio wave intensity is equal to or greater than the threshold value, the first instruction screen is not displayed on the display unit. The communication device according to item 1, wherein when the specific signal is received from the first external device and it is determined that the received radio wave intensity is equal to or greater than the threshold value, the public key transmission unit transmits the public key to the first external device via the first wireless interface even if it is not instructed to execute the target process. (Item 3) A communication device, A first wireless interface, A second wireless interface different from the first wireless interface, A specific signal receiving unit that receives a specific signal from a first external device via the first wireless interface, A determination unit that determines whether or not the received radio wave intensity of the specific signal is equal to or greater than a threshold value when the specific signal is received from the first external device, A public key transmission unit that transmits a public key to the first external device via the first wireless interface when it is determined that the received radio wave intensity is equal to or greater than the threshold value, and the transmission of the public key to the first external device is restricted when it is determined that the received radio wave intensity is not equal to or greater than the threshold value, An authentication request receiving unit that receives an authentication request in which the public key is used from the first external device via the second wireless interface after the public key is transmitted to the first external device, An authentication response transmission unit that transmits an authentication response, which is a response to the authentication request, to the first external device via the second wireless interface when the authentication request is received from the first external device, A connection information receiving unit that receives connection information from the first external device via the second wireless interface after the authentication response is transmitted to the first external device, wherein the connection information is information for establishing a wireless connection between the communication device and a second external device via the second wireless interface. When the connection information is received from the first external device, an establishment unit that uses the connection information to establish the wireless connection via the second wireless interface between the communication device and the second external device. A communication device comprising the above. (Item 4) The communication device further comprises an identification information receiving unit that receives, from the first external device, identification information for identifying the first external device via the first wireless interface. When the identification information is received from the first external device and the authentication request including the identification information is received from the first external device identified by the identification information, the authentication response transmission unit transmits the authentication response to the first external device via the second wireless interface. The communication device according to any one of Items 1 to 3, wherein when the identification information is received from the first external device and an authentication request not including the identification information is received from an external device different from the first external device via the second wireless interface, transmission of the authentication response to the different external device is restricted. (Item 5) The communication device further comprises a display unit, and a second display control unit that restricts transmission of the authentication response to the different external device by causing the display unit to display a second instruction screen for instructing that transmission of the authentication response to the different external device should be executed when the identification information is received from the first external device and the authentication request not including the identification information is received from the different external device. The communication device according to Item 4, wherein the authentication response transmission unit transmits the authentication response to the first external device via the second wireless interface when instructed to execute transmission of the authentication response in a situation where the second instruction screen is being displayed. (Item 6) The communication device according to Item 4 or 5, wherein the identification information is included in the specific signal. (Item 7) The communication device further comprises a state transition unit that, after the specific signal is received from the first external device, transitions the operating state of the communication device from an impossible state to a possible state, where the impossible state is a state in which the authentication response is not transmitted even when the authentication request is received, and the possible state is a state in which the authentication response is transmitted in response to receiving the authentication request. The authentication response transmission unit transmits the authentication response to the first external device via the second wireless interface when the authentication request is received from the first external device after the operating state of the communication device has shifted to the enabled state, for the communication device according to any one of items 1 to 6. (Item 8) The communication device further includes a channel information transmission unit that transmits, via the first wireless interface, channel information indicating a first communication channel predetermined in the communication device to the outside. The enabled state is a state in which reception of the authentication request using the first communication channel is monitored, and in response to receiving the authentication request, the authentication response is transmitted. The authentication response transmission unit transmits the authentication response to the first external device via the second wireless interface when the authentication request using the first communication channel is received from the first external device after the operating state of the communication device has shifted to the enabled state, for the communication device according to item 7. (Item 9) The establishing unit establishes the wireless connection via the second wireless interface between the communication device and the second external device using a second communication channel different from the first communication channel, for the communication device according to item 8. (Item 10) The first wireless interface is a wireless interface for performing wireless communication according to Bluetooth (registered trademark) version 4.0 or higher. The specific signal is a Scan Request according to Bluetooth version 4.0 or higher. The public key transmission unit transmits, to the first external device, a Scan Response according to Bluetooth version 4.0 or higher and including the public key, for the communication device according to any one of items 1 to 9. (Item 11) The communication device further includes a mode shift unit that shifts the operation mode of the first wireless interface from a first mode to a second mode when a predetermined condition is satisfied, where the first mode is a mode in which the first wireless interface cannot interpret the specific signal, and the second mode is a mode in which the first wireless interface can interpret the specific signal, and includes the mode shift unit. The specific signal receiving unit receives the specific signal from the first external device via the first wireless interface after the operation mode of the first wireless interface has shifted to the second mode. The communication device according to any one of items 1 to 10. (Item 12) The communication device further includes a memory, a storage control unit that stores the connection information in the memory when the connection information is received from the first external device, and when the power of the communication device is turned on in a situation where the connection information is not stored in the memory, the predetermined condition is satisfied, when the power of the communication device is turned on in a situation where the connection information is stored in the memory, the predetermined condition is not satisfied. The communication device according to item 11. (Item 13) The communication device further includes an operation unit, when a specific operation from a user via the operation unit is received in a situation where the connection information is stored in the memory, the predetermined condition is satisfied. The communication device according to item 12. (Item 14) The second external device is a device different from the first external device and is a parent station device that should operate as a parent station of a wireless network, the establishing unit establishes the wireless connection via the second wireless interface between the communication device and the second external device and causes the communication device to participate in the wireless network as a child station. The communication device according to any one of items 1 to 13. (Item 15) The connection information includes authentication information for authenticating received information received from the second external device. The communication device according to any one of items 1 to 14. (Item 16) The communication device further includes an operation control unit that operates the communication device as an Enrollee conforming to the Wi-Fi standard after the authentication response is transmitted to the first external device, where the first external device operates as a Configurator conforming to the Wi-Fi standard. The communication device according to any one of items 1 to 15, comprising the operation control unit. (Item 17) A computer program for a communication device, causing the computer of the communication device to perform the following respective units, namely, a specific signal receiving unit that receives a specific signal from a first external device via a first wireless interface of the communication device, A first display control unit that causes a display unit of the communication device to display a first instruction screen for instructing to execute target processing including transmission of a public key when the specific signal is received from the first external device; A public key transmission unit that transmits the public key to the first external device via the first wireless interface when it is instructed to execute the target processing in a situation where the first instruction screen is displayed, and does not transmit the public key when it is not instructed to execute the target processing in a situation where the first instruction screen is displayed; An authentication request receiving unit that receives an authentication request using the public key from the first external device via a second wireless interface of the communication device after the public key is transmitted to the first external device, where the second wireless interface is different from the first wireless interface; An authentication response transmission unit that transmits an authentication response, which is a response to the authentication request, to the first external device via the second wireless interface when the authentication request is received from the first external device; A connection information receiving unit that receives connection information from the first external device via the second wireless interface after the authentication response is transmitted to the first external device, where the connection information is information for establishing a wireless connection between the communication device and a second external device via the second wireless interface; An establishment unit that uses the connection information to establish the wireless connection between the communication device and the second external device via the second wireless interface when the connection information is received from the first external device; A computer program that functions as; (Item 18) A computer program for a communication device, The computer of the communication device is configured to include the following units, namely, A specific signal receiving unit that receives a specific signal from a first external device via a first wireless interface of the communication device; A determination unit that determines whether or not the received radio wave intensity of the specific signal is equal to or greater than a threshold value when the specific signal is received from the first external device; A public key transmission unit that transmits a public key to the first external device via the first wireless interface when it is determined that the received radio wave intensity is equal to or greater than the threshold value, and restricts the transmission of the public key to the first external device when it is determined that the received radio wave intensity is less than the threshold value. An authentication request receiving unit that receives an authentication request in which the public key is used from the first external device via the second wireless interface of the communication device after the public key is transmitted to the first external device, where the second wireless interface is different from the first wireless interface. An authentication response transmission unit that transmits an authentication response, which is a response to the authentication request, to the first external device via the second wireless interface when the authentication request is received from the first external device. A connection information receiving unit that receives connection information from the first external device via the second wireless interface after the authentication response is transmitted to the first external device, where the connection information is information for establishing a wireless connection between the communication device and a second external device via the second wireless interface. An establishment unit that establishes the wireless connection between the communication device and the second external device via the second wireless interface using the connection information when the connection information is received from the first external device. A computer program that functions as.
Explanation of Symbols
[0127] 2: Communication system, 6: AP, 10, 50: Terminal, 16, 116: Wi-Fi I / F, 18, 118: BT I / F, 40: First type of application, 52: Second type of application, 100: Printer, 112: Operation unit, 114: Display unit, 120: Printing execution unit, 130: Control unit, 132: CPU, 134: Memory, 136: Program
Claims
Claim 1 A communication device, a display unit, a first wireless interface, a second wireless interface different from the first wireless interface, the second wireless interface for performing Wi-Fi communication according to the Wi-Fi method, a specific signal receiving unit that receives a specific signal from a first external device via the first wireless interface, a first display control unit that causes the display unit to display a first instruction screen for instructing to execute connection processing according to the DPP (abbreviation for Device Provisioning Protocol) method when the specific signal is received from the first external device, a state transition unit that transitions the operating state of the communication device from an impossible state to a possible state when it is instructed to execute the connection processing in a situation where the first instruction screen is being displayed, the impossible state being a state where an authentication response that is a response to an authentication request using a public key is not transmitted, the possible state being a state where the authentication response is transmitted in response to receiving the authentication request, and in a situation where the first instruction screen is being displayed and it is not instructed to execute the connection processing, the state of the communication device does not transition from the impossible state to the possible state, the state transition unit, a public key transmission unit that transmits the public key to the first external device via the first wireless interface when it is instructed to execute the connection processing in a situation where the first instruction screen is being displayed, and the public key is not transmitted when it is not instructed to execute the connection processing in a situation where the first instruction screen is being displayed, the public key transmission unit, an authentication request receiving unit that receives the authentication request using the public key from the first external device via the second wireless interface after the public key is transmitted to the first external device, an authentication response transmission unit that transmits the authentication response to the first external device via the second wireless interface when the authentication request is received from the first external device after the operating state of the communication device has transitioned to the possible state, A connection information receiving unit that receives connection information from the first external device via the second wireless interface after the authentication response is transmitted to the first external device, where the connection information is information for establishing a wireless connection between the communication device and a second external device via the second wireless interface, the connection information receiving unit; An establishing unit that, when the connection information is received from the first external device, uses the connection information to establish the wireless connection between the communication device and the second external device via the second wireless interface; A communication device comprising the above.
2. The communication device further comprises: When the specific signal is received from the first external device and the received radio wave intensity of the specific signal is a first value, the first instruction screen is not displayed on the display unit; The first display control unit causes the first instruction screen to be displayed on the display unit when the specific signal is received from the first external device and the received radio wave intensity is a second value less than the first value; The state transition unit, when the specific signal is received from the first external device and the received radio wave intensity is the first value, shifts the operating state of the communication device from the impossible state to the possible state even if not instructed to execute the connection process. The communication device according to claim 1.
3. The communication device further comprises: An identification information receiving unit that receives identification information for identifying the first external device from the first external device via the first wireless interface; The authentication response transmitting unit transmits the authentication response to the first external device via the second wireless interface when the identification information is received from the first external device and the authentication request including the identification information is received from the first external device identified by the identification information; When the identification information is received from the first external device and an authentication request not including the identification information is received from an external device different from the first external device via the second wireless interface, transmission of the authentication response to the different external device is restricted. The communication device according to claim 1 or 2.
4. The communication device further comprises: When the identification information is received from the first external device and the authentication request that does not include the identification information is received from the different external device, a second display control unit is provided to cause the display unit to display a second instruction screen for instructing to execute transmission of the authentication response to the different external device, thereby restricting the transmission of the authentication response to the different external device. The communication device according to claim 3, wherein the authentication response transmission unit transmits the authentication response to the different external device via the second wireless interface when instructed to execute the transmission of the authentication response in a situation where the second instruction screen is displayed.
5. The communication device according to claim 3 or 4, wherein the identification information is included in the specific signal.
6. The communication device further includes a channel information transmission unit that transmits, via the first wireless interface, channel information indicating a first communication channel predetermined in the communication device to the outside. The possible state is a state of monitoring reception of the authentication request using the first communication channel and transmitting the authentication response in response to receiving the authentication request. The communication device according to any one of claims 1 to 5, wherein the authentication response transmission unit transmits the authentication response to the first external device via the second wireless interface when the authentication request using the first communication channel is received from the first external device after the operating state of the communication device has shifted to the possible state.
7. The communication device according to claim 6, wherein the establishment unit establishes the wireless connection via the second wireless interface between the communication device and the second external device using a second communication channel different from the first communication channel.
8. The first wireless interface is a wireless interface for performing wireless communication according to Bluetooth (registered trademark) version 4.0 or higher. The specific signal is a Scan Request according to Bluetooth version 4.0 or higher. The public key transmission unit is a Scan Response conforming to version 4.0 or higher of the Bluetooth method, and transmits the Scan Response including the public key to the first external device. The communication device according to any one of claims 1 to 7.
9. The communication device further includes a mode shift unit that shifts the operation mode of the first wireless interface from a first mode to a second mode when a predetermined condition is satisfied, where the first mode is a mode in which the first wireless interface cannot interpret the specific signal, and the second mode is a mode in which the first wireless interface can interpret the specific signal. The communication device includes the mode shift unit. The specific signal reception unit receives the specific signal from the first external device via the first wireless interface after the operation mode of the first wireless interface has been shifted to the second mode. The communication device according to any one of claims 1 to 8.
10. The communication device further includes a memory, and a storage control unit that stores the connection information in the memory when the connection information is received from the first external device. When the power of the communication device is turned on in a situation where the connection information is not stored in the memory, the predetermined condition is satisfied. When the power of the communication device is turned on in a situation where the connection information is stored in the memory, the predetermined condition is not satisfied. The communication device according to claim 9.
11. The communication device further includes an operation unit, and when a specific operation via the operation unit is received from a user in a situation where the connection information is stored in the memory, the predetermined condition is satisfied. The communication device according to claim 10.
12. The second external device is a device different from the first external device and is a parent station device that should operate as a parent station of a wireless network. The establishment unit establishes the wireless connection via the second wireless interface between the communication device and the second external device and allows the communication device to participate in the wireless network as a child station. The communication device according to any one of claims 1 to 11.
13. The connection information includes authentication information for authenticating reception information received from the second external device. The communication device according to any one of claims 1 to 12.
14. The communication device further comprises an operation control unit that operates the communication device as an Enrollee conforming to the Wi-Fi standard after the authentication response is transmitted to the first external device, wherein the first external device operates as a Configurator conforming to the Wi-Fi standard, the communication device according to any one of claims 1 to 13 comprising the operation control unit.
15. A computer program for a communication device, comprising causing a computer of the communication device to function as each of the following units, namely a specific signal receiving unit that receives a specific signal from a first external device via a first wireless interface of the communication device; a first display control unit that causes a first instruction screen for instructing to execute connection processing according to the DPP (abbreviation for Device Provisioning Protocol) method to be displayed on a display unit of the communication device when the specific signal is received from the first external device; a state transition unit that transitions an operation state of the communication device from an impossible state to a possible state when it is instructed to execute the connection processing in a situation where the first instruction screen is displayed, wherein the impossible state is a state in which an authentication response that is a response to an authentication request using a public key is not transmitted, the possible state is a state in which the authentication response is transmitted in response to receiving the authentication request, and in a situation where the first instruction screen is displayed and it is not instructed to execute the connection processing, the state of the communication device does not transition from the impossible state to the possible state, the state transition unit; a public key transmission unit that transmits the public key to the first external device via the first wireless interface when it is instructed to execute the connection processing in a situation where the first instruction screen is displayed, and wherein the public key is not transmitted when it is not instructed to execute the connection processing in a situation where the first instruction screen is displayed, the public key transmission unit An authentication request receiving unit that, after the public key is transmitted to the first external device, receives, from the first external device via a second wireless interface of the communication device, the authentication request in which the public key is used, where the second wireless interface is different from the first wireless interface, and the second wireless interface is an interface for performing Wi-Fi communication according to the Wi-Fi method, the authentication request receiving unit; An authentication response transmitting unit that, when the authentication request is received from the first external device after the operating state of the communication device has shifted to the enabled state, transmits the authentication response to the first external device via the second wireless interface; A connection information receiving unit that, after the authentication response is transmitted to the first external device, receives, from the first external device via the second wireless interface, connection information, where the connection information is information for establishing a wireless connection between the communication device and a second external device via the second wireless interface, the connection information receiving unit; An establishing unit that, when the connection information is received from the first external device, uses the connection information to establish the wireless connection between the communication device and the second external device via the second wireless interface; A computer program that functions as such.
Citation Information
Patent Citations
Communication device
JP2016187088A
Communication apparatus
JP2016187090A
Image processing system, image processing apparatus, and program
JP2017152927A
Communication device, communication method, and program
JP2018037978A
Communication apparatus, control method for communication apparatus, and program
JP2018042058A