Wireless connection setting system, authentication server, slave device, master device, wireless connection setting method, and program

The authentication server system automates wireless connection setup for smart devices by associating slave device identification information with bootstrap information, eliminating user operation and additional hardware, thus ensuring secure and cost-effective connections.

JP7708443B2Active Publication Date: 2025-07-15NEC PLATFROMS LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023002231
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-01-11
Publication Date
2025-07-15
Estimated Expiration
2043-01-11

AI Technical Summary

Technical Problem

Existing wireless connection methods for smart devices require user operation or additional hardware on the access point (AP) to obtain bootstrap information, increasing costs and user burden.

Method used

A system utilizing an authentication server to manage and associate slave device identification information with bootstrap information, allowing the AP to obtain this information without user intervention or additional hardware, by transmitting identification information to the server for authentication and connection setup.

Benefits of technology

Enables secure, automated wireless connection between a master device and slave devices without user operation or additional hardware, reducing costs and ensuring security by managing bootstrap information through the authentication server.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007708443000001
    Figure 0007708443000001
  • Figure 0007708443000002
    Figure 0007708443000002
  • Figure 0007708443000003
    Figure 0007708443000003
Patent Text Reader

Abstract

To provide a system, method, server or the like for performing wireless connection setting between a slave unit and a master unit safely without an operation of a user without installing a new function on a master unit AP.SOLUTION: There is provided a wireless connection setting system including an authentication server 300, a master unit 200 and a slave unit 100. The slave unit transmits a connection setting request including first identification information being identification information of the own device. When receiving the connection setting request, the master unit transmits a bootstrap information request including the first identification information to the authentication server. The authentication server manages the identification information in association with the bootstrap information as slave unit identification information for each slave unit, and transmits the bootstrap information managed by associating it with the corresponding information to the master unit being the transmission source in a case where the slave unit identification information corresponding to the first identification information included in the bootstrap information request is managed when the bootstrap information request is received. The master unit uses the first identification information and the bootstrap information received from the authentication server to establish connection with the slave unit.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a wireless connection setting system, an authentication server, a slave device, a master device, a wireless connection setting method, and a program.

Background Art

[0002] In recent years, with the spread of IoT devices, devices that were not conventionally connected to a network, such as televisions, lighting fixtures, and air conditioning devices, can now be connected to the network. As a result, by using a smartphone or an AI speaker, a user can operate these devices without touching them. Therefore, these devices are called smart devices.

[0003] A smart device (hereinafter also referred to as a slave device) is connected to a network via an access point (AP). In order to communicate with each slave device securely, the AP needs to obtain the bootstrap information preset in each slave device and perform connection settings. The bootstrap information is information for the slave device to connect to the AP, and includes, for example, information such as a public key used for communication and a used channel. This information is set in each slave device at the time of manufacture and / or shipment. For example, it is made into a QR code (registered trademark) and pasted.

[0004] The connection settings are made using, for example, methods such as the WPS (Wi-Fi Protected Setup) function or EasyConnect. However, each of these methods has the following problems. In the WPS function, in order for the AP and the slave device to perform connection settings, the user needs to operate a dedicated button mounted on the AP. Also, for EasyConnect, the user needs to read a QR code containing the bootstrap information, or the AP needs to be equipped with a QR code reading (Scan) mechanism. These are, for example, communication mechanisms such as a camera mechanism, NFC (Near field communication), and Bluetooth (registered trademark). Mounting these on the AP will result in a significant cost increase.

[0005] For example, in the case where the slave device is a device capable of installing an application, there is a technique for realizing connection to an access point by a user operating the application (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0006]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0007] The following analysis is provided by the present invention.

[0008] Even in the technology disclosed in Patent Document 1, user operation is still required. Also, not all slave devices are necessarily capable of installing an application.

[0009] The present invention has been made in view of the above circumstances, and an object thereof is to perform wireless connection setting between a slave device and a master device safely without user operation without adding a new function to the master device (AP).

Means for Solving the Problems

[0010] According to a first aspect of the present invention, an authentication server, a master device, a slave device, and includes, the slave device transmits a connection setting request including first identification information that is identification information of the own device, when the master device receives the connection setting request, it transmits a bootstrap information request including the first identification information to the authentication server, the authentication server, for each of the slave devices to be managed, manages by associating the identification information of the slave device with the bootstrap information of the slave device as slave device identification information, When receiving the bootstrap information request, if the slave device identification information that matches the first identification information included in the bootstrap information request is managed, the bootstrap information managed in association with the matching slave device identification information is transmitted to the master device that is the transmission source. A wireless connection setting system is provided, in which the master device establishes a connection with the slave device by using the first identification information received from the slave device and the bootstrap information received from the authentication server.

[0011] According to a second aspect of the present invention, An initial information management unit that manages, in association with each slave device to be managed, slave device identification information that is the identification information of the slave device and the bootstrap information of the slave device; When receiving a bootstrap information request including first identification information that is the identification information of the slave device that requests connection to the master device from the master device, it is determined whether the slave device identification information that matches the first identification information included in the bootstrap information request is managed by the initial information management unit. If it is determined that it is managed, an authentication unit that transmits the bootstrap information managed in association with the matching slave device identification information to the master device that is the transmission source is provided.

[0012] According to a third aspect of the present invention, A self-device information management unit that manages the identification information of the self-device; A slave device is provided, which includes a connection processing unit that transmits the identification information as a connection setting request to the master device and, in response to the transmission, executes a connection procedure with the master device when receiving an authentication procedure request including the bootstrap information of the self-device from the master device.

[0013] According to a fourth aspect of the present invention, When the master device receives a connection setting request including the identification information of the slave device from the slave device, it transmits a bootstrap information request including the identification information to the authentication server, receives the bootstrap information of the slave device from the authentication server in response to the transmission, and uses the identification information and the bootstrap information to establish a connection with the slave device. A master device including a connection processing unit is provided.

[0014] According to a fifth aspect of the present invention, A wireless connection setting method in a system including an authentication server, a master device, and a slave device, wherein the authentication server manages, for each of the slave devices to be managed, the identification information of the slave device as slave device identification information in association with the bootstrap information of the slave device, the slave device transmits a connection setting request including first identification information that is the identification information of its own device, when the master device receives the connection setting request, it transmits a bootstrap information request including the first identification information to the authentication server, when the authentication server receives the bootstrap information request, if the slave device identification information that matches the first identification information included in the bootstrap information request is managed, it transmits the bootstrap information managed in association with the matching slave device identification information to the master device that is the transmission source, A wireless connection setting method is provided in which the master device uses the first identification information received from the slave device and the bootstrap information received from the authentication server to establish a connection with the slave device.

[0015] According to a sixth aspect of the present invention, a computer, initial information management means for managing, for each of the slave devices to be managed, the slave device identification information that is the identification information of the slave device in association with the bootstrap information of the slave device, When the master device receives a bootstrap information request including first identification information, which is the identification information of the slave device that requests connection to the master device, from the master device, it determines whether the slave device identification information that matches the first identification information included in the bootstrap information request is managed by the initial information management means. If it is determined that it is managed, a program is provided to function as authentication means for transmitting the bootstrap information managed in association with the corresponding slave device identification information to the master device that is the transmission source.

[0016] Note that these programs can be recorded on a computer-readable storage medium. The storage medium can be non-transient ones such as semiconductor memories, hard disks, magnetic recording media, and optical recording media. The present invention can also be embodied as a computer program product.

Advantages of the Invention

[0017] According to the present invention, without installing a new function in the master device (AP), the wireless connection setting between the slave device and the master device can be safely performed without user operation.

Brief Description of the Drawings

[0018]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Embodiments for Carrying Out the Invention

[0019] Hereinafter, an overview of an embodiment of the present invention (hereinafter referred to as this embodiment) will be described with reference to the drawings. Note that the appended reference numerals in the drawings are for convenience of each element as an example to assist understanding, and are not intended to limit the present invention to the illustrated embodiments. Also, the connection lines between blocks in the drawings and the like referred to in the following description include both bidirectional and unidirectional ones. The one-way arrow schematically shows the flow of the main signal (data) and does not exclude bidirectionality.

[0020] Also, ports and interfaces are provided at the connection points of the inputs and outputs of each block in the figure, but their illustration is omitted. Also, in the following description, "A and / or B" is used to mean A or B, or A and B.

[0021] First, the environment in which the wireless connection setting system 400 of this embodiment is used will be described. In this embodiment, the setting of a wireless LAN connection or the like is simplified when connecting so-called smart devices such as home appliances each assigned an IP address to a network such as a LAN.

[0022] As shown in FIG. 1, smart devices (hereinafter referred to as slave devices 100) individually assigned with IP addresses and the like are each connected to a network 900 via an access point (AP) 200 that is a master device. At this time, the slave device 100 and the AP 200 are wirelessly connected by a method such as Wi-Fi (registered trademark).

[0023] In order to establish this wireless connection, it is necessary to first perform connection setting processing. For this connection setting processing, as described above, the AP 200 needs to acquire the bootstrap information of the slave device 100.

[0024] Prior to the description of the present application, a conventional bootstrap information acquisition procedure will be described. FIG. 2 shows the flow of processing when a conventional AP 200 acquires the bootstrap information of a slave device 100 that wants to be connected to a network via the AP 200.

[0025] Here, as an example, the Easy Connect standard will be described. In Easy Connect, connection is established by scanning the respective QR codes of the AP 200 and the slave device 100 using a smartphone or tablet (hereinafter represented by a smartphone).

[0026] Note that all slave devices compatible with Easy Connect are pre-assigned with unique identification information (ID). As the ID, for example, the MAC address assigned to each slave device is used. The ID is described in the QR code together with the above-described bootstrap information.

[0027] In Easy Connect, there are two roles: Enrollee (registration target) and Configurator (configuration administrator).

[0028] As shown in FIG. 2, first, the AP 200 becomes the registration target and the smartphone becomes the configuration administrator. In this state, a connection is established between the smartphone and the AP 200.

[0029] The establishment of the connection uses the "Device Provisioning Protocol (DPP)". In DPP, the connection is established in four steps. Specifically, first, Bootstrapping is performed, then the Authentication procedure, the Configuration procedure follows, and finally the Network connection is completed.

[0030] Bootstrapping is a process of obtaining bootstrap information. In this conventional example, it is realized by the smartphone reading (scanning) the QR code attached to the AP200 (step S9101).

[0031] Then, the Authentication procedure and Configuration are performed (step S9102).

[0032] In the authentication procedure, a Request is made from the configuration administrator (smartphone). When making a request in the authentication procedure, the smartphone encrypts and transmits its own bootstrap information, etc. using the public key of the AP200 obtained in bootstrapping. Also, the AP200 that receives this decrypts it with its own private key, creates response information, and responds with a Response to the smartphone. The smartphone authenticates the received response information and sends a Confirm. Thus, the authentication procedure is completed. The subsequent data transmission and reception are performed using the common encryption key created during the authentication process.

[0033] In the configuration procedure, a Request is made from the registration target (AP200) side. In the setting procedure, data in which information called "DPP Objects" is stored is sent from the configuration administrator to the registration target. The DPP Objects include, for example, profile information necessary for connecting to an access point. The profile information includes information such as SSID (Service Set Identifier) and channel, and information necessary for securely accessing the access point, including AKM (Authentication and Key Management) parameters.

[0034] With the above method, first, a connection is established between the smartphone and the AP200 (step S9103).

[0035] Next, a connection is established between the smartphone and the slave unit 100. Here, the slave unit 100 is the registration target, and the smartphone is the configuration administrator.

[0036] Similar to the above, first, the smartphone reads the QR code attached to the slave unit 100 and acquires bootstrap information (step S9104).

[0037] After that, an authentication procedure and a setting procedure are performed between the smartphone (configuration administrator) and the slave unit 100 (registration target) in the same manner as above (step S9105). At this time, the smartphone (configuration administrator) sends the information for connecting to the initially acquired AP200 to the slave unit 100 as DPP Objects.

[0038] Then, the slave unit 100 interprets the DPP Objects and executes a connection procedure for connecting to the AP200 (step S9106). Thereby, a connection is established between the slave unit 100 and the AP200. And thereafter, a normal wireless connection sequence is executed between the slave unit 100 and the AP200 (step S9107).

[0039] Also, for the function that AP200 can read the QR code of the slave device 100, for example, regarding the wireless connection setting procedure when equipped with a camera, it will be described with reference to FIG. 3.

[0040] In this case, AP200 becomes the Configurator, and the slave device 100 is the Enrollee.

[0041] AP200 obtains the bootstrap information of the slave device 100 by scanning the QR code of the slave device 100 (step S9201).

[0042] Then, AP200 performs the authentication procedure and the setting procedure in the same manner as above using the obtained bootstrap information (step S9202). At this time, AP200 sends DPP Objects to the slave device 100.

[0043] The slave device 100 interprets the DPP Objects and executes the connection procedure to connect to AP200 (step S9203). Thereby, a connection is established between the slave device 100 and AP200, and a normal wireless connection sequence is executed (step S9204).

[0044] In this way, in the conventional method, since AP200 obtains the bootstrap information of the slave device 100, for example, it is necessary to do so via a smartphone or add a special configuration for AP200 to read the QR code. The former places a heavy burden on the user. Also, the latter increases the manufacturing cost.

[0045] To simplify this connection setting, the wireless connection setting system of this embodiment includes an authentication server. And in this authentication server, in advance, the information of the master device that functions as the management target AP200, the information of the slave device 100 such as a smart device, and the information associated with the bootstrap information of the slave device 100 are registered. Then, when the AP200 which is the master device accesses the authentication server, the connection setting between AP200 and the slave device 100 is automatically performed.

[0046] Next, a wireless connection setting system 400 according to the present embodiment for realizing this will be described. FIG. 4 is a functional block diagram of each component of the wireless connection setting system 400 according to the present embodiment.

[0047] As shown in this figure, the wireless connection setting system 400 according to the present embodiment includes a slave unit 100, an AP 200, and an authentication server 300. In the present embodiment, the slave unit 100 is an Enrollee (registration target), and the AP 200 is a Configurator (setting administrator).

[0048] As described above, each slave unit 100 is a smart device to which identifiable information is given. As shown in this figure, it includes a communication unit 110, a self-device information management unit 120, a profile information management unit 130, and a connection processing unit 140.

[0049] The self-device information management unit 120 manages the device information of the self-device. The device information includes bootstrap information and the identification information (slave unit identification information) of the self-device. Hereinafter, in the present embodiment, a case where the MAC address of the slave unit 100 is used as the slave unit identification information will be described as an example.

[0050] The profile information management unit 130 manages the profile information necessary for communication with the AP 200. The profile information includes a wireless network name (ESSID (Extended Service Set Identifier) or SSID), an authentication / encryption method, an encryption key, and the like.

[0051] The communication unit 110 communicates with the AP 200. At this time, the profile information managed by the profile information management unit 130 is used.

[0052] The connection processing unit 140 establishes a connection with the AP 200. Specifically, before establishing a connection with the AP 200, the connection processing unit 140 transmits (broadcasts) Probe Request, DPP Presence Announcement, etc. as connection setting requests to the surroundings. These include the MAC address of the own device.

[0053] Probe Request and DPP Presence Announcement are signals periodically transmitted from the slave unit 100 (Enrollee) side. They are signals that notify the AP 200 (Configurator) of the presence of the slave unit 100 and trigger the start of the DPP procedure.

[0054] When the connection processing unit 140 receives a request for the above-described authentication procedure by DPP (DPP Authentication Request; authentication procedure request) from the AP 200, it performs the above-described authentication, setting, and connection procedures with the AP 200 to establish a connection with the AP 200. At this time, the information of the own device managed by the own device information management unit 120 is used. Also, the above-described profile information is generated in this procedure.

[0055] The AP 200 connects a wireless LAN-compatible device to the LAN. It is also a device that can be connected to the network and communicate with a server on a network such as the cloud. In the present embodiment, it includes a communication unit 210, a linked device information management unit 220, a profile information management unit 230, and a connection processing unit 240.

[0056] The linked device information management unit 220 manages the device information of the slave unit 100 connected to itself (established a connection with the AP 200). For example, the device information to be managed includes the above-described MAC address, etc.

[0057] The profile information management unit 230 manages profile information. The profile information is managed for each slave unit 100 connected to itself.

[0058] The communication unit 210 communicates with the authentication server 300 and the slave unit 100 connected to itself. The communication with the slave unit 100 is performed using the profile information managed by the profile information management unit 230.

[0059] The connection processing unit 240 establishes a connection with the slave unit 100. In this embodiment, as described above, since the slave unit 100 transmits a Probe Request, the connection processing unit 240 receives the signal. Then, it extracts the MAC address included therein, generates a bootstrap information request using the MAC address and the identification information (master unit identification information) of its own device, and transmits it to the authentication server 300. In this embodiment, the case where the master unit identification information also uses the MAC address of the AP 200 will be described as an example.

[0060] When the connection processing unit 240 receives the bootstrap information from the authentication server 300, it uses the bootstrap information to execute a connection establishment procedure by DPP with the source slave unit 100 and establishes a connection with the slave unit 100.

[0061] The authentication server 300 manages the master unit identification information, manages the slave unit identification information and the bootstrap information in association with each other, and returns the bootstrap information of the slave unit 100 in response to a request from the AP 200. To achieve this, the authentication server 300 includes a communication unit 310, an authentication unit 320, and an initial information management unit 330. Note that the authentication server 300 is connected to the network 900. The connection method to the network is not limited.

[0062] The communication unit 310 communicates with the AP 200.

[0063] The initial information management unit 330 manages a slave unit table 331 that associates the slave unit identification information (MAC address) of the slave unit 100, the bootstrap information, and the compatible wireless standard, and a master unit table 332 that associates the master unit identification information (MAC address) of the AP 200 and the compatible wireless standard.

[0064] Fig. 5(a) and Fig. 5(b) respectively show an example of the slave device table 331 and the master device table 332 managed by the initial information management unit 330.

[0065] As shown in Fig. 5(a), in the slave device table 331, the bootstrap information 331b of the device and the compatible wireless standard 331c are registered as initial information in association with the MAC address 331a of the slave device 100.

[0066] Also, as shown in Fig. 5(b), in the master device table 332, the compatible wireless standard 332c of the device is registered as initial information in association with the MAC address 332a of the AP 200.

[0067] These initial information are registered by, for example, the manufacturer at the time of manufacturing or shipping of each device.

[0068] The authentication unit 320 authenticates the slave device 100, and if it is a legitimate slave device 100, it transmits the bootstrap information managed by the initial information management unit 330 to the source AP 200.

[0069] In this embodiment, the authentication unit 320 collates the MAC address of the slave device 100 transmitted from the AP 200 and the MAC address of the source AP 200 with the initial information pre-registered in the initial information management unit 330 respectively. Then, when the MAC addresses 331a and 332a that match each of the two MAC addresses are registered as initial information, it is determined that the device information of the legitimate slave device 100 is transmitted via the legitimate AP 200. And when the compatible wireless standards 331c and 332c registered in association with the respective MAC addresses 331a and 332a are included, it is determined that the authentication is successful.

[0070] When the authentication unit 320 determines that the authentication is successful, it pays out (assigns) the bootstrap information 331b registered in the slave device table 331 corresponding to the MAC address 331a of the slave device 100, and returns it to the source AP 200. In other cases, information indicating authentication failure is returned to the source AP 200.

[0071] In addition, after paying out the bootstrap information, the MAC address of the source AP 200, the MAC address of the received slave device 100, and the bootstrap information may be managed in association with each other. However, in the subsequent communication between the AP 200 and the slave device 100, the authentication server 300 is not involved, so the associated information does not necessarily need to be retained.

[0072] [Wireless Connection Setting Process] Next, the flow (procedure) of the wireless connection setting process between the slave device 100 and the AP 200 in the present embodiment will be described. FIG. 6 shows the processing flow of the wireless connection setting process in the present embodiment. In the present embodiment, as described above, the slave device 100 is the Enrollee (object to be registered), and the AP 200 is the Configurator (setting administrator).

[0073] First, the connection processing unit 140 of the slave device 100 transmits (broadcasts) a connection setting request (step S1101). The connection setting request is a Probe Request, a DPP Presence Announcement, etc. that includes the MAC address of the slave device 100 itself as described above.

[0074] When the connection processing unit 240 of the AP 200 receives the connection setting request from the slave device 100, it transmits a bootstrap information request to the authentication server 300 (step S1102). The bootstrap information request includes the MAC address of the slave device 100 extracted from the connection setting request and the MAC address of the AP 200 itself.

[0075] When the authentication unit 320 of the authentication server 300 receives a bootstrap information request, it performs authentication processing (step S1103). Details of the authentication processing will be described later. If the authentication is successful, the bootstrap information 331b managed in the slave device table 331 is issued in association with the MAC address 331a of the slave device 100.

[0076] When the authentication is successful, the authentication server 300 returns the issued bootstrap information as the bootstrap information of the slave device 100 to the source AP200 (step S1104).

[0077] When the connection processing unit 240 of the AP200 receives the bootstrap information from the authentication server 300, it uses the information to execute the authentication and setting procedure (step S1105) and the connection procedure (step S1106) with the connection processing unit 140 of the slave device 100, and establishes a connection. Thereafter, a normal wireless connection sequence using profile information is executed between the slave device 100 and the AP200 (step S1107). Since the details of each procedure are the same as those of the above prior art, the description is omitted here.

[0078] [Authentication Processing] Here, the flow of the authentication processing in the authentication server 300 in step S1103 will be described. FIG. 7 is a processing flow of the authentication processing by the authentication server 300 of the present embodiment.

[0079] The communication unit 310 of the authentication server 300 determines whether or not it has received bootstrap information at a predetermined time interval (step S1201). If it is determined that the information has not been received, the determination continues as it is.

[0080] If it is determined that the information has been received (S1201; Yes), the authentication unit 320 extracts the MAC address of the slave device 100 and the MAC address of the source AP200 from the bootstrap information (step S1202).

[0081] The authentication unit 320 collates each extracted MAC address with the MAC addresses (identification information) 331a and 332a managed in the slave unit table 331 and the master unit table 332 of the initial information management unit 330, respectively (step S1203).

[0082] The authentication unit 320 determines whether the matching MAC addresses 331a and 332a are managed (step S1204). Then, if a matching one is managed, the authentication unit 320 collates the compatible wireless standards 331c and 332c managed in association with the matching MAC addresses 331a and 332a, and determines whether a matching one is registered (step S1205).

[0083] If a matching one is registered, the authentication unit 320 determines that authentication is successful, and delivers the bootstrap information 331b managed in association with the MAC address 331a of the slave unit 100 (step S1206). Then, the delivered bootstrap information is transmitted to the source AP200 via the communication unit 310 (step S1207), and the process returns to step S1201.

[0084] On the other hand, if a MAC address that matches at least one of the MAC addresses of the slave unit 100 or the AP200 is not managed (S1204; No), and in step S1205, the same compatible wireless standard is not registered, information (Fail) indicating authentication failure is transmitted to the source AP200 via the communication unit 310 (step S1208), and the process returns to step S1201.

[0085] The above process is repeated while the authentication server 300 is running.

[0086] [Hardware Configuration] Note that the authentication server 300 of the present embodiment can be realized by a so-called general-purpose information processing device (computer).

[0087] As shown in FIG. 8, the authentication server 300 of the present embodiment includes, for example, a CPU (Central Processing Unit) 191, a main storage device (memory) 192, an auxiliary storage device 193, a communication I / F 194, and an expansion I / F 195, which are interconnected by an internal bus.

[0088] The CPU 191 realizes each of the above functions and comprehensively controls the entire authentication server 300 by, for example, loading a program stored in the auxiliary storage device 193 into the main storage device 192 and executing it. Note that one or more processors such as an MPU (Micro Processing Unit) may be used instead of the CPU 191.

[0089] The main storage device 192 is a memory such as a RAM (Random Access Memory). The main storage device 192 is a work area when the CPU 191 processes programs and the like executed by the authentication server 300.

[0090] The auxiliary storage device 193 is, for example, a ROM (Read Only Memory), an HDD (Hard Disk Drive), an SSD (Solid State Drive), or the like. The auxiliary storage device 193 stores various programs executed by the information exchange device. Note that the auxiliary storage device 193 may include storage media such as a flexible disk, a hard disk, an optical disk, a CD-ROM, a CD-R, a magnetic tape, a non-volatile memory card, and a DVD.

[0091] Note that the program stored in the auxiliary storage device 193 can be provided as a program product recorded on a non-transitory computer-readable storage medium. The auxiliary storage device 193 can be used to store various programs recorded on a non-transitory computer-readable storage medium in the medium to long term.

[0092] The communication I / F 194 transmits and receives signals and data, either wired or wirelessly. Further, as the communication I / F 194, for example, a NIC (Network Interface Card) or the like may be provided.

[0093] The expansion I / F 195 is an interface for connecting a display device, an input device, etc. The display device is, for example, a liquid crystal monitor or the like. The input device is a device that receives user operations such as a keyboard and a mouse.

[0094] Each of the above functions of the authentication server 300 of the present embodiment is realized by the CPU 191 loading and executing a program stored in the auxiliary storage device 193 into the main storage device 192.

[0095] Also, the information managed by the initial information management unit 330 may be constructed in the auxiliary storage device 193. Further, data generated during processing is stored in the main storage device 192 or the auxiliary storage device 193.

[0096] Note that the hardware configuration of the authentication server 300 is not limited to this. It may include hardware not shown.

[0097] Also, the program for realizing each of the above functions of the authentication server 300 of the present embodiment can be recorded on a computer-readable storage medium. The storage medium can be a non-transient one such as a semiconductor memory, a hard disk, a magnetic recording medium, an optical recording medium, etc. The present invention can also be embodied as a computer program product.

[0098] Also, the slave unit 100 and the AP 200 include at least an arithmetic device such as a CPU, a storage device such as a memory, and a communication interface. Each of the above functions is realized by the arithmetic device loading and executing a program stored in the storage device into its work area, similar to the authentication server 300. Also, various types of information (data) are stored in the storage device.

[0099] As described above, the wireless connection setting system 400 of the present embodiment includes an authentication server 300 that pre-associates and holds the MAC address (slave device identification information) of each slave device 100 with the bootstrap information. Then, the AP 200 acquires the bootstrap information of the slave device 100 that requests connection setting from the authentication server 300. That is, the bootstrapping procedure is performed via the authentication server 300.

[0100] Therefore, according to the present embodiment, no operation by the user is required at the time of wireless connection setting. Also, there is no need to use a device such as a smartphone that can acquire the bootstrap information of each slave device. For this reason, when setting up the connection between the master device and the slave device, the user does not need to perform an operation such as reading a QR code with a device such as a smartphone. That is, the wireless connection setting can be automatically performed between the master device and the slave device without performing an operation such as reading a QR code. Also, there is no need to install a mechanism (such as a camera) in the AP 200 for acquiring the bootstrap information of the slave device 100.

[0101] That is, without installing a new function in the existing master device (AP), the wireless connection between the slave device and the master device can be safely set without user operation, reducing the labor of the user.

[0102] And the authentication server 300 pays out the pre-registered bootstrap information of the slave device 100 only when it is a bootstrap information request from the pre-registered AP 200. Therefore, the bootstrap information of the slave device 100 does not leak outside the pre-registered AP 200, and safety can be ensured.

[0103] By the authentication server 300 managing the identification information of the master device in association with the identification information and bootstrap information of the slave device, the exchange of profile information until the master device receives the bootstrap information is reduced.

[0104] <Modification Example 1> In the above-described embodiment, the slave device 100 transmits (broadcasts) a Probe request or the like to the surrounding devices including the AP 200. However, the present invention is not limited to this method. For example, the AP 200 may periodically transmit a beacon. Then, the slave device 100 that has received the beacon may transmit a connection setting request including the MAC address to the AP 200.

[0105] <Modification Example 2> In the above-described embodiment, the slave device 100 includes its own MAC address in the connection setting request and transmits it. However, what is transmitted at this time is not limited to the MAC address. For example, it may be ID information assigned in advance to the slave device 100. The ID information is information that can uniquely identify the slave device 100.

[0106] The wireless connection setting process in this case will be described with reference to FIG. 9. Here, the description will focus on the points different from the above-described embodiment.

[0107] First, a connection setting request is transmitted from the slave device 100 to the AP 200 (step S2101). At this time, in this modification example, for example, a Probe Request is transmitted. At this time, the ID information of the slave device 100 is stored in the Vender Specific IE (Information Element) of this Probe Request.

[0108] An example of the Probe Request 160 transmitted in this case is shown in FIG. 10(a). As shown in this figure, the Probe Request 160 includes a Vender Specific IE 161. And the Vender Specific IE 161 includes the ID information 162 of the slave device.

[0109] The ID information 162 of this slave device 100 is set in the slave device 100 at the time of manufacture or shipment, etc., and is managed by the own device information management unit 120 of the slave device 100.

[0110] Then, in the AP200, when a connection setting request is received, the ID information is extracted therefrom, added to the bootstrap information request, and the bootstrap information request is transmitted to the authentication server 300 (step S2102).

[0111] In the authentication server 300 that has received the bootstrap information request, authentication processing is performed in the same manner as in the above embodiment using the ID information included in the bootstrap information request and the MAC address (AP information) of the source AP200 (step S2103).

[0112] Note that the ID information of the slave device 100 and its bootstrap information are registered in advance in the authentication server 300 at the time of manufacturing or shipping of the slave device 100. The initial information management unit 330 of the authentication server 300 manages these information as a slave device table 333. An example of the managed slave device table 333 is shown in FIG. 10(b).

[0113] The slave device table 333 of this modified example basically has the same configuration as the slave device table 331 of the first embodiment. However, it has ID information 333a instead of the MAC address 331a. And, corresponding to the ID information 333a, it has bootstrap information 333b and a compatible wireless standard 333c.

[0114] The authentication method, the distribution of the bootstrap information, and the subsequent authentication, setting, and connection procedures (steps S1104 to S1107) between the AP200 and the slave device 100 by the above DPP are the same as in the above embodiment.

[0115] As described above, in this modified example, the information of the slave device 100 registered in the authentication server 300 in advance is used as the ID information. And this ID information is included in the Probe Request and transmitted by the slave device 100 to the AP200. That is, the MAC address preset in the slave device 100 is not used. Therefore, for example, even a device with a random MAC address that randomly assigns a MAC address for each network can be supported.

[0116] Also, similar to the above-described embodiment, the AP200 can obtain bootstrap information other than one-to-one wireless LAN with the slave unit 100. This improves security.

[0117] <Modification Example 3> In the above embodiment, the authentication server 300 holds information regarding the compatible wireless standards of each of the slave unit 100 and the AP200, but these pieces of information do not necessarily have to be held. In this case, in the authentication process, the process of step S1205 does not have to be performed.

[0118] In the flowchart used in the above description, a plurality of steps (processes) are described in order, but the execution order of each step is not limited to the described order. For example, the order of the illustrated steps can be changed within a range that does not substantially interfere with the content, such as executing each process in parallel.

[0119] As described above, each embodiment of the present invention has been described. However, the present invention is not limited to the above-described embodiments, and further modifications, substitutions, and adjustments can be made without departing from the basic technical idea of the present invention. For example, the network configurations and the configurations of each element shown in each drawing are examples for assisting the understanding of the present invention and are not limited to the configurations shown in these drawings.

[0120] Finally, the preferred forms of the present invention are summarized. (Appendix 1) An authentication server, A master unit, A slave unit, and The slave unit transmits a connection setting request including first identification information which is its own device's identification information, When the master unit receives the connection setting request, it transmits a bootstrap information request including the first identification information to the authentication server, The authentication server For each of the slave units to be managed, manages the identification information of the slave unit as slave unit identification information in association with the bootstrap information of the slave unit, When receiving the bootstrap information request, if the slave device identification information that matches the first identification information included in the bootstrap information request is managed, the bootstrap information managed in association with the matching slave device identification information is transmitted to the master device that is the transmission source. The master device is a wireless connection setting system that establishes a connection with the slave device by using the first identification information received from the slave device and the bootstrap information received from the authentication server. (Appendix 2) In the wireless connection setting system according to Appendix 1, The authentication server further manages, for each of the master devices to be managed, master device identification information that is the identification information of the master device. The master device further includes its own device identification information as second identification information in the bootstrap information request and transmits it to the authentication server. The authentication server preferably transmits the bootstrap information to the master device that is the transmission source when the master device identification information that matches the transmitted second identification information is managed. (Appendix 3) In the wireless connection setting system according to Appendix 1 or Appendix 2, It is desirable that the first identification information and the slave device identification information are identification information preset in the slave device. (Appendix 4) In the wireless connection setting system according to Appendix 1 or Appendix 2, It is desirable that the first identification information and the slave device identification information are MAC addresses preset in the slave device. (Appendix 5) An initial information management unit that manages, in association with each slave device to be managed, slave device identification information that is the identification information of the slave device and the bootstrap information of the slave device. When the authentication server receives a bootstrap information request including first identification information, which is the identification information of the slave device that requests connection to the master device, from the master device, it determines whether the slave device identification information that matches the first identification information included in the bootstrap information request is managed by the initial information management unit. If it is determined that it is managed, the authentication server transmits the bootstrap information managed in association with the matching slave device identification information to the master device that is the transmission source. (Appendix 6) A slave device information management unit that manages the identification information of the own device; A slave device including a connection processing unit that transmits the identification information as a connection setting request to the master device, and when receiving an authentication procedure request including the bootstrap information of the own device from the master device in response to the transmission, executes a connection procedure with the master device. (Appendix 7) When the master device receives a connection setting request including the identification information of the slave device from the slave device, it transmits a bootstrap information request including the identification information to the authentication server, and when receiving the bootstrap information of the slave device from the authentication server in response to the transmission, establishes a connection with the slave device using the identification information and the bootstrap information, and includes a connection processing unit. (Appendix 8) An authentication server, a master device, and a slave device, and a wireless connection setting method in a system in which the authentication server manages the identification information of each of the slave devices to be managed as slave device identification information in association with the bootstrap information of the slave device, The slave device transmits a connection setting request including first identification information, which is the identification information of the own device, When the master device receives the connection setting request, it transmits a bootstrap information request including the first identification information to the authentication server, When the authentication server receives the bootstrap information request, if the slave device identification information that matches the first identification information included in the bootstrap information request is managed, it transmits the bootstrap information managed in association with the matching slave device identification information to the master device that is the transmission source, A wireless connection setting method in which the master device establishes a connection with the slave device using the first identification information received from the slave device and the bootstrap information received from the authentication server. (Appendix 9) A computer, For each slave device to be managed, initial information management means for associating and managing the slave device identification information, which is the identification information of the slave device, and the bootstrap information of the slave device, When receiving a bootstrap information request including first identification information, which is the identification information of the slave device that requests connection to the master device, from the master device, it determines whether the slave device identification information that matches the first identification information included in the bootstrap information request is managed by the initial information management means. If it is determined that it is managed, it functions as an authentication means for transmitting the bootstrap information managed in association with the matching slave device identification information to the master device that is the transmission source. A program for this. In addition, each form of Appendices 5-9 can be developed into the forms of Appendices 2-4.

[0121] In addition, each disclosure of the above patent documents and the like is incorporated herein by reference. Within the scope of the entire disclosure of the present invention (including the claims), further changes and adjustments of the embodiments or examples can be made based on the basic technical idea. Also, within the scope of the disclosure of the present invention, various combinations or selections of various disclosure elements (including each element of each claim, each element of each embodiment or example, each element of each drawing, etc.) are possible. That is, the present invention naturally includes all disclosures including the claims and various modifications and corrections that a person skilled in the art could make according to the technical idea. In particular, regarding the numerical ranges described in this document, any numerical value or small range included within the range should be interpreted as being specifically described even if there is no separate description.

Explanation of Signs

[0122] 100: Slave device, 110: Communication unit, 120: Self-device information management unit, 130: Profile information management unit, 140: Connection processing unit, 160: Probe Request, 161: Vender Specific IE, 162: ID information, 191: CPU, 192: Main memory device, 193: Auxiliary storage device, 194: Communication I / F, 195: Expansion I / F, 200: Access Point (AP), 210: Communication unit, 220: Cooperative device information management unit, 230: Profile information management unit, 240: Connection processing unit, 300: Authentication server, 310: Communication unit, 320: Authentication unit, 330: Initial information management unit, 331: Slave device table, 331a: MAC address, 331b: Bootstrap information, 331c: Compatible wireless standard, 332: Master device table, 332a: MAC address, 332c: Compatible wireless standard, 333: Slave device table, 333a: ID information, 333b: Bootstrap information, 333c: Compatible wireless standard, 400: Wireless connection setting system, 900: Network

Claims

1. An authentication server, a master device, and a slave device, and the slave device transmits a connection setting request including first identification information that is the identification information of the own device, when the master device receives the connection setting request, it transmits a bootstrap information request including the first identification information to the authentication server, the authentication server for each of the slave devices to be managed, manages by associating the identification information of the slave device as slave device identification information with the bootstrap information of the slave device, when receiving the bootstrap information request, if the slave device identification information that matches the first identification information included in the bootstrap information request is managed, it transmits the bootstrap information managed in association with the matching slave device identification information to the master device that is the transmission source, the master device establishes a connection with the slave device using the first identification information received from the slave device and the bootstrap information received from the authentication server, the authentication server further manages, for each of the master devices to be managed, master device identification information that is the identification information of the master device, the master device includes its own identification information as second identification information in the bootstrap information request and transmits it to the authentication server, the authentication server further transmits the bootstrap information to the master device that is the transmission source if the master device identification information that matches the transmitted second identification information is managed. A wireless connection setting system.

2. The wireless connection setting system according to claim 1, wherein the first identification information and the slave device identification information are identification information preset in the slave device. A wireless connection setting system.

3. The wireless connection setting system according to claim 1, wherein the first identification information and the slave device identification information are MAC addresses preset in the slave device. A wireless connection setting system.

4. An initial information management unit that manages by associating, for each of the slave devices to be managed, slave device identification information that is the identification information of the slave device with the bootstrap information of the slave device, and manages, for each of the master devices to be managed, master device identification information that is the identification information of the master device, When receiving a bootstrap information request including first identification information, which is the identification information of the slave device that requests connection to the master device, and second identification information, which is the identification information of the master device, from the master device, it determines whether the slave device identification information that matches the first identification information included in the bootstrap information request is managed by the initial information management unit. If it is determined that it is managed, it further determines whether the master device identification information that matches the transmitted second identification information is managed. If it is determined that it is managed, an authentication unit that transmits the bootstrap information managed in association with the matching slave device identification information to the source master device. An authentication server comprising.

5. An authentication server, a master device, and a slave device, wherein the authentication server manages, for each of the slave devices to be managed, the identification information of the slave device as slave device identification information in association with the bootstrap information of the slave device, and further manages, for each of the master devices to be managed, the master device identification information, which is the identification information of the master device. A wireless connection setting method in a system, comprising: The slave device transmits a connection setting request including first identification information, which is the identification information of its own device. When the master device receives the connection setting request, it transmits a bootstrap information request including the first identification information and second identification information, which is the identification information of its own device, to the authentication server. When the authentication server receives the bootstrap information request, if the slave device identification information that matches the first identification information included in the bootstrap information request is managed, and the master device identification information that matches the second identification information transmitted together with the bootstrap information is managed, it transmits the bootstrap information managed in association with the matching slave device identification information to the source master device. A wireless connection setting method in which the master device establishes a connection with the slave device using the first identification information received from the slave device and the bootstrap information received from the authentication server.

6. A computer, Initial information management means for managing, for each of the slave devices to be managed, the slave device identification information, which is the identification information of the slave device, in association with the bootstrap information of the slave device, and further managing, for each of the master devices to be managed, the master device identification information, which is the identification information of the master device. When receiving a bootstrap information request including first identification information, which is the identification information of the slave unit that requests connection to the master unit, and second identification information, which is the identification information of the master unit, from the master unit, it determines whether the slave unit identification information that matches the first identification information included in the bootstrap information request is managed by the initial information management means. If it is determined that it is managed, it further determines whether the master unit identification information that matches the transmitted second identification information is managed. If it is determined that it is managed, it functions as an authentication means for transmitting the bootstrap information managed in association with the matching slave unit identification information to the transmitting source master unit. A program for this purpose.

Citation Information

Patent Citations

  • Cloud-based control of your Wi-Fi network

    JP2019509703A

  • Connecting internet of thing (IOT) devices to a wireless network

    US20220400118A1