COMMUNICATION DEVICE, COMPUTER PROGRAM FOR THE COMMUNICATION DEVICE, AND COMPUTER PROGRAM FOR A FIRST EXTERNAL DEVICE

The system allows for flexible wireless connection establishment between devices using multiple interfaces and public keys, addressing the limitations of existing protocols by enabling various connection methods.

JP7732532B2Active Publication Date: 2025-09-02BROTHER KOGYO KK
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024067016
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-04-17
Publication Date
2025-09-02
Estimated Expiration
2038-12-28

AI Technical Summary

Technical Problem

Existing wireless communication technologies, such as the Device Provisioning Protocol (DPP), lack flexibility in establishing connections between devices, as they often require specific methods for different scenarios and do not support wired connections effectively.

Method used

A communication device and external device system that utilizes multiple wireless interfaces and public keys to establish different types of wireless connections based on specific methods, allowing for flexible connection establishment through a first wireless interface and authentication responses.

Benefits of technology

Enables the establishment of multiple wireless connections between devices using appropriate methods, enhancing flexibility and compatibility in wireless communication setups.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007732532000001
    Figure 0007732532000001
  • Figure 0007732532000002
    Figure 0007732532000002
  • Figure 0007732532000003
    Figure 0007732532000003
Patent Text Reader

Abstract

To provide a technology for establishing a wireless connection different from the wireless connection by a communication device according to an appropriate connection method of a plurality of connection methods in response to establishment of the wireless connection between the communication device and an external device.SOLUTION: A communication device supplies a first public key and specific information to a first wireless interface. As a result, the first public key and the specific information are transmitted to a first external device via a first wireless interface. Then, when the communication device receives a first authentication request from the first external device, the communication device transmits a first authentication response to the first external device, receives first connection information from the first external device, and establishes a second wireless connection with a second external device using the first connection information. Further, when a specific signal is received from the first external device after the first public key and the specific information are transmitted to the first external device, the communication device establishes a third wireless connection with the first external device.SELECTED DRAWING: Figure 11
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] SUMMARY Disclosed herein are techniques for establishing a wireless connection between a communication device and an external device. [Background technology]

[0002] Non-Patent Document 1 describes the DPP (abbreviation of Device Provisioning Protocol), a connection method established by the Wi-Fi Alliance. In the DPP method, for example, wireless communication according to the DPP method is executed in response to the establishment of an NFC connection between a first device and a second device. [Prior art documents] [Non-patent literature]

[0003] [Non-Patent Document 1] “Device Provisioning Protocol Technical Specification Version 1.0” Wi-Fi Alliance, 2018 Summary of the Invention [Problem to be solved by the invention]

[0004] D There are situations where wireless communication according to the PP method should be performed, and there are situations where communication according to the DPP method should be performed. How to There are situations in which compliant wireless communication should be performed.

[0005] In this specification, DPP method and other methods that are different from DPP method. According to the appropriate connection method, the communication device There is no Techniques for establishing a wired connection are disclosed. [Means for solving the problem]

[0006] This specification discloses a communication device, the communication device including: a first wireless interface; one or more wireless interfaces different from the first wireless interface; and a first provider configured to provide a first public key, which is a public key of the communication device, and identification information to the first wireless interface, wherein when a first wireless connection is established between the communication device and a first external device via the first wireless interface, the first public key and the identification information are transmitted to the first external device via the first wireless interface, the first public key is used to establish a second wireless connection between the communication device and a second external device via a second wireless interface of the one or more wireless interfaces according to a first connection method, and the identification information is used to establish a third wireless connection between the communication device and the first external device via a third wireless interface of the one or more wireless interfaces according to a second connection method different from the first connection method. an authentication response transmitting unit that, when a first authentication request using the first public key is received from the first external device via the second wireless interface after the first authentication request using the first public key is transmitted to the first external device, transmits a first authentication response that is a response to the first authentication request to the first external device via the second wireless interface; a connection information receiving unit that receives first connection information from the first external device via the second wireless interface after the first authentication response is transmitted to the first external device, the first connection information being information for establishing the second wireless connection between the communication device and the second external device via the second wireless interface; a first establishment unit that, when the first connection information is received from the first external device, establishes the second wireless connection between the communication device and the second external device via the second wireless interface using the first connection information; and, after the first public key and the identification information are transmitted to the first external device, receives from the first external device via the third wireless interfaceand a second establishment unit that establishes the third wireless connection between the communication device and the first external device via the third wireless interface when a specific signal including the specific information is received.

[0007] According to the above configuration, the communication device provides the first public key and identification information of the communication device to the first wireless interface. As a result, when a first wireless connection is established between the communication device and the first external device, the first public key and the identification information are transmitted to the first external device using the first wireless connection. After transmitting the first public key and the identification information to the first external device, when the communication device receives a first authentication request from the first external device using the first public key, the communication device transmits a first authentication response to the first external device, receives first connection information from the first external device, and establishes a second wireless connection between the communication device and the second external device using the first connection information. That is, the communication device can establish a second wireless connection with the second external device according to the first connection method. On the other hand, when the communication device receives a specific signal including the specific information from the first external device after the first public key and the specific information are transmitted to the first external device, the communication device establishes a third wireless connection between the communication device and the first external device. That is, the communication device can establish the third wireless connection with the first external device according to the second connection method. Therefore, in response to the establishment of the first wireless connection between the communication device and the first external device, the communication device can establish a second or third wireless connection different from the first wireless connection according to an appropriate connection method from among the plurality of connection methods.

[0008] A computer program for implementing the above-described communication device and a computer-readable recording medium for storing the computer program are also novel and useful. Also, a method executed by the above-described communication device is novel and useful.

[0009] This specification also discloses a computer program for a first external device, the first external device including a first wireless interface, one or more wireless interfaces different from the first wireless interface, and a computer, the computer program configuring the computer to include the following units: a receiving unit that, when a first wireless connection is established between a communication device and the first external device via the first wireless interface, receives a public key and specific information of the communication device from the communication device via the first wireless interface, the public key being used to establish a second wireless connection between the communication device and a second external device according to a first connection method, and the specific information being used to establish a third wireless connection between the communication device and the first external device via a third wireless interface of the one or more wireless interfaces according to a second connection method different from the first connection method; and a receiving unit that, when the public key and the specific information are received from the communication device, determines which of the second wireless connection and the third wireless connection should be established. an authentication request transmitting unit configured to transmit an authentication request using the public key to the communication device via a second wireless interface among the one or more wireless interfaces when it is determined that the second wireless connection should be established; an authentication response receiving unit configured to receive an authentication response that is a response to the authentication request from the communication device via the second wireless interface when the authentication request is transmitted to the communication device; a connection information transmitting unit configured to transmit connection information to the communication device via the second wireless interface when the authentication response is received from the communication device, the connection information being information for establishing the second wireless connection between the communication device and the second external device when the connection information is received from the first external device, the connection information transmitting unit configured to establish the second wireless connection between the communication device and the second external device using the connection information; and a connection information transmitting unit configured to transmit connection information to the communication device via the third wireless interface when it is determined that the third wireless connection should be established.The communication device may function as a specific signal transmitting unit that transmits a specific signal including the specific information to the communication device, and an establishing unit that establishes the third wireless connection between the communication device and the first external device via the third wireless interface after the specific signal is transmitted to the communication device.

[0010] According to the above configuration, when a first wireless connection is established between the communication device and the first external device, the first external device receives a public key and identification information from the communication device and determines whether a second wireless connection or a third wireless connection should be established. When the first external device determines that the second wireless connection should be established, it transmits an authentication request using the public key to the communication device, receives an authentication response from the communication device, and transmits connection information to the communication device. As a result, the second wireless connection is established between the communication device and the second external device using the connection information. On the other hand, when the first external device determines that a third wireless connection should be established, it transmits an identification signal including the identification information to the communication device and establishes a third wireless connection between the communication device and the first external device. Therefore, in response to the establishment of a wireless connection between the communication device and the first external device, the communication device can establish a second or third wireless connection different from the first wireless connection according to an appropriate connection method from among multiple connection methods.

[0011] A computer-readable recording medium storing the above computer program is also novel and useful. The above first external device itself and a method executed by the first external device are also novel and useful. [Brief explanation of the drawings]

[0012] [Figure 1] 1 shows the configuration of a communication system. [Figure 2] 10 shows an explanatory diagram for explaining an outline of case A in which a Wi-Fi connection according to the DPP method is established between a printer and an access point. [Figure 3] A sequence diagram of Bootstrapping process is shown below. [Figure 4]A sequence diagram of authentication processing is shown below. [Figure 5] A sequence diagram of Configuration processing is shown below. [Figure 6] A sequence diagram of the Network Access process is shown below. [Figure 7] 10 shows a sequence diagram of processing in Case B in which a WFD connection is established between a terminal and a printer. [Figure 8] 10 shows a sequence diagram of processing in Case C in which the terminal and printer have already established a Wi-Fi connection with the access point. [Figure 9] 10 shows a sequence diagram of processing in case D when a mode transition operation is executed in the printer. [Figure 10] 1 shows a flowchart of a process executed by a terminal. [Figure 11] 1 shows a flowchart of a process performed by a printer. [Figure 12] 10 shows a flowchart of a process executed by a terminal according to a second embodiment. [Figure 13] 10 shows a flowchart of a process executed by a printer according to a second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0013] (Configuration of communication system 2; Figure 1) 1, the communication system 2 includes an access point (hereinafter simply referred to as "AP") 6, a terminal 10, and a printer 100. In this embodiment, it is assumed that a user uses the terminal 10 to establish a wireless connection (hereinafter referred to as "Wi-Fi connection") between the printer 100 and the AP 6 according to the Wi-Fi standard.

[0014] (Configuration of Terminal 10) The terminal 10 is a portable terminal device such as a mobile phone (e.g., a smartphone), a PDA, or a tablet PC. In a modified example, the terminal 10 may be a desktop PC, a notebook PC, or the like. The terminal 10 includes an operation unit 12, a display unit 14, a Wi-Fi interface 16, an NFC interface 18, and a control unit 30. The units 12 to 30 are connected to a bus line (reference numerals omitted). In the following, the interface will be simply referred to as "I / F."

[0015] The operation unit 12 includes a plurality of keys. A user can input various instructions to the terminal 10 by operating the operation unit 12. The display unit 14 is a display for displaying various pieces of information.

[0016] The Wi-Fi I / F 16 is a wireless interface for performing Wi-Fi communication according to the Wi-Fi standard. The Wi-Fi standard is a wireless communication standard for performing wireless communication according to, for example, the IEEE (The Institute of Electrical and Electronics Engineers, Inc.) 802.11 standard and its equivalent standards (e.g., 802.11a, 11b, 11g, 11n, etc.). The Wi-Fi I / F 16 can establish a Wi-Fi connection with the AP 6 when an SSID (Service Set Identifier) ​​identifying a wireless network in which the AP 6 operates as a master station and a password used in the wireless network are input via the operation unit 12. The Wi-Fi I / F 16 can also establish a Wi-Fi connection with the AP 6 using a so-called PIN code method or a PBC (Push Button Configuration) method even if the information is not input via the operation unit 12. Hereinafter, a Wi-Fi connection established in this manner may be referred to as a "normal Wi-Fi connection."

[0017] The Wi-Fi I / F 16 also supports the WFD (short for Wi-Fi Direct (registered trademark)) method established by the Wi-Fi Alliance and the DPP (short for Device Provisioning Protocol) method established by the Wi-Fi Alliance. The WFD method is a connection method described in the Wi-Fi Peer-to-Peer (P2P) Technical Specification Version 1.1 standard created by the Wi-Fi Alliance. The WFD standard defines three WFD device states: Group Owner state (hereinafter referred to as "G / O state"), client state, and device state. A WFD device can selectively operate in one of the three states. The DPP method is described in the Device Provisioning Protocol Technical Specification Version 1.0 standard created by the Wi-Fi Alliance, and is a connection method for easily establishing a Wi-Fi connection between a pair of devices (e.g., the printer 100 and the AP 6) using the terminal 10. In the following, a Wi-Fi connection established according to the DPP method may be referred to as a "DPP connection," and a Wi-Fi connection established according to the WFD method may be referred to as a "WFD connection."

[0018] The NFC I / F 18 is an I / F for executing NFC communication in accordance with the NFC standard. The NFC standard is a wireless communication standard based on international standards such as ISO / IEC 14443, 15693, and 18092. Known types of I / Fs for executing NFC communication include an I / F called an NFC Forum Device and an I / F called an NFC Forum Tag. In this embodiment, the NFC I / F 18 is an NFC Forum Device.

[0019] Here, differences between Wi-Fi I / F and NFC I / F will be explained. The communication speed of wireless communication via Wi-Fi I / F (for example, a maximum communication speed of 11 to 600 Mbps) is faster than the communication speed of wireless communication via NFC I / F (for example, a maximum communication speed of 100 to 424 Kbps). Furthermore, the frequency used for wireless communication via Wi-Fi I / F (for example, the 2.4 GHz band or the 5.0 GHz band) is different from the frequency used for wireless communication via NFC I / F (for example, the 13.56 MHz band). Furthermore, the maximum distance over which wireless communication via Wi-Fi I / F can be performed (for example, a maximum of approximately 100 m) is longer than the maximum distance over which wireless communication via NFC I / F can be performed (for example, a maximum of approximately 10 cm).

[0020] The control unit 30 includes a CPU 32 and a memory 34. The CPU 32 executes various processes in accordance with an OS (short for Operating System) program 36 stored in the memory 34. The memory 34 is configured with volatile memory, non-volatile memory, etc. The memory 34 also stores a print application 38 (hereinafter simply referred to as "app 38"). The app 38 is a program for causing the printer 100 to execute printing, and is installed on the terminal 10 from, for example, a server on the Internet provided by the vendor of the printer 100.

[0021] (Configuration of printer 100) The printer 100 is a peripheral device (for example, a peripheral device of the terminal 10) that can execute a printing function. The printer 100 includes an operation unit 112, a display unit 114, a Wi-Fi I / F 116, an NFC I / F 118, a print execution unit 120, and a control unit 130. The units 112 to 130 are connected to a bus line (reference numerals omitted).

[0022] The operation unit 112 has a plurality of keys. A user can input various instructions to the printer 100 by operating the operation unit 112. The display unit 114 is a display for displaying various information. The print execution unit 120 has a printing mechanism such as an inkjet system or a laser system.

[0023] The Wi-Fi I / F 116 is the same as the Wi-Fi I / F 16 of the terminal 10. That is, the Wi-Fi I / F 116 supports the WFD method and the DPP method. Therefore, the printer 100 can establish a Wi-Fi connection with the AP 6 according to the DPP method (i.e., a DPP connection), and can also establish a Wi-Fi connection with the terminal 10 according to the WFD method (i.e., a WFD connection). The printer 100 can also establish a normal Wi-Fi connection with the AP 6.

[0024] The control unit 130 includes a CPU 132 and a memory 134. The CPU 132 executes various processes in accordance with a program 136 stored in the memory 134. The memory 134 is configured by a volatile memory, a non-volatile memory, or the like.

[0025] The memory 134 also stores a WFD flag 138. The WFD flag 138 indicates either "ON", which means that the printer 100 is in a state where it can operate according to the WFD method, or "OFF", which means that the printer 100 is in a state where it cannot operate according to the WFD method. When the WFD flag 138 is "ON", the operating state of the printer 100 is one of the three states of the WFD method (i.e., G / O state, client state, and device state). When the WFD flag 138 is "OFF", the operating state of the printer 100 is none of the three states of the WFD method.

[0026] (Examples: Figures 2 to 9) 2 to 9, a specific example of the processing executed by each of the devices 6, 10, and 100 will be described. First, a processing of Case A in which a DPP connection is established between the printer 100 and the AP 6 will be described with reference to FIGS.

[0027] (Overview of Case A; Figure 2) First, an overview of the processing for Case A will be described with reference to Figure 2. As mentioned above, the terminal 10 and printer 100 support the DPP method, and the AP 6 also supports the DPP method. In this embodiment, the devices 6, 10, and 100 communicate according to the DPP method, thereby establishing a DPP connection between the printer 100 and the AP 6. In the following, for ease of understanding, the operations performed by the CPU of each device (e.g., CPU 32, 132) will be described with reference to each device (e.g., terminal 10, printer 100) rather than the CPU.

[0028] At T5, the terminal 10 executes DPP-based Bootstrapping (hereinafter simply referred to as "BS") with the AP 6. The BS is a process in which, in response to the terminal 10 capturing an image of a QR code (registered trademark) attached to the AP 6, the AP 6 provides the terminal 10 with information used in Authentication (hereinafter simply referred to as "Auth") at T10, which will be described later.

[0029] At T10, the terminal 10 uses the information already acquired at the BS at T5 to perform DPP-based Auth with the AP 6. This Auth is a process in which the terminal 10 and the AP 6 each authenticate the other party with which they communicate.

[0030] At T15, the terminal 10 executes a DPP-based Configuration (hereinafter simply referred to as "Configuration") with the AP 6. This Configuration is a process for sending information to the AP 6 for establishing a DPP connection between the printer 100 and the AP 6. Specifically, in this Configuration, the terminal 10 generates an AP Configuration Object (hereinafter simply referred to as "Configuration Object") for establishing a DPP connection between the printer 100 and the AP 6, and sends the AP CO to the AP 6. As a result, the AP CO is stored in the AP 6.

[0031] Next, in T20, the terminal 10 executes DPP-based BS with the printer 100. The BS is a process in which the printer 100 provides the terminal 10 with information used in Auth in T25, which will be described later, by using an NFC connection established between the NFC I / F 18 of the terminal 10 and the NFC I / F 118 of the printer 100.

[0032] In T25, the terminal 10 uses the information already acquired in the BS in T20 to execute DPP-based Auth with the printer 100. This Auth is a process in which the terminal 10 and the printer 100 each authenticate the other party with which they communicate.

[0033] At T30, the terminal 10 executes a DPP-based Config with the printer 100. This Config is a process for sending information to the printer 100 for establishing a DPP connection between the printer 100 and the AP 6. In this Config, the terminal 10 generates a printer CO for establishing a DPP connection between the printer 100 and the AP 6, and sends the printer CO to the printer 100. As a result, the printer CO is stored in the printer 100.

[0034] At T35, the printer 100 and AP 6 use the stored AP and printer COs to execute DPP Network Access (hereinafter simply referred to as "NA"). NA is a process for sharing a connection key between the printer 100 and AP 6 to establish a DPP connection.

[0035] In T40, the printer 100 and the AP 6 perform 4-way handshake communication. During at least a portion of the 4-way handshake communication, the printer 100 and the AP 6 communicate encrypted information using the connection key shared in the NA of T35. If the encrypted information is successfully decrypted, a DPP connection is established between the printer 100 and the AP 6. This allows the printer 100 to participate as a slave station in the wireless network formed by the AP 6, and as a result, it can communicate with other devices participating in the wireless network via the AP 6. In a modified example, the printer 100 and the AP 6 may perform SAE (Simultaneous Authentication of Equals, commonly known as "Dragonfly") communication instead of 4-way handshake communication.

[0036] In T45, the printer 100 displays a completion screen on the display unit 114, indicating that a DPP connection has been established with the AP 6. When the processing in T45 ends, the processing in FIG. 2 ends.

[0037] In the DPP method, in order to establish a Wi-Fi connection between the printer 100 and the AP 6, the user does not need to input information (such as SSID and password) of the wireless network in which the AP 6 operates as the master station into the printer 100. Therefore, the user can easily establish a Wi-Fi connection between the printer 100 and the AP 6.

[0038] (Explanation of each process: Figures 3 to 6) Next, the details of the processes executed in T20 to T35 in Fig. 2 will be described with reference to Fig. 3 to Fig. 6. Note that the processes in T5 to T15 are the same as the processes in T20 to T30 except that AP6 is used instead of printer 100, and therefore detailed description thereof will be omitted.

[0039] (Bootstrapping (BS); Figure 3) First, the BS processing of T20 in Fig. 2 will be described with reference to Fig. 3. In the initial state of Fig. 3, the memory 134 of the printer 100 pre-stores the public key PPK1 and private key psk1 of the printer 100. Also, in the initial state of Fig. 3, the WFD flag 138 of the printer 100 indicates "OFF."

[0040] In response to receiving a power-on operation from the user in T100, the printer 100 determines in T102 that a normal Wi-Fi connection with the AP 6 has not been established and transitions the printer 100's operating mode from the non-configuration mode to the configuration mode. The printer 100 determines that a normal Wi-Fi connection with the AP 6 has not been established if AP information (e.g., SSID, password, etc.) for establishing a normal Wi-Fi connection with the AP 6 is not stored in the memory 134, or if the printer 100 transmits a confirmation signal via the Wi-Fi I / F 116 to confirm whether a normal Wi-Fi connection has been established and does not receive a response to the confirmation signal from the AP 6. The non-configuration mode is a mode in which the printer 100 does not supply BS information used to establish a DPP connection between the printer 100 and the AP 6 to the NFC I / F 118 in response to the establishment of an NFC connection. The configuration mode is a mode in which the printer 100 supplies BS information to the NFC I / F 118 in response to the establishment of an NFC connection. In other words, the non-configuration mode is a mode in which a DPP connection cannot be established according to the DPP method, and the configuration mode is a mode in which a DPP connection can be established according to the DPP method.

[0041] In T103, the user launches the application 38 of the terminal 10 and brings the terminal 10 close to the printer 100. In response to this, in T104, an NFC connection is established between the NFC I / F 18 of the terminal 10 and the NFC I / F 118 of the printer 100. In this case, in T105, the printer 100 acquires a signal from the NFC I / F 118 indicating that the NFC connection has been established, determines that the operating mode of the printer 100 is the setting mode, and provides WFD information and BS information to the NFC I / F 118. The WFD information is information used to establish a WFD connection between the terminal 10 and the printer 100 and includes the SSID "wfd." The SSID "wfd" is information identifying the wireless network in which the printer 100 operating in a G / O state operates as a master station. The SSID "wfd" may be pre-stored in the memory 134 or may be generated by the printer 100 in response to the establishment of the NFC connection. The BS information includes the public key PPK1 of the printer 100 stored in memory 134, a channel list pre-stored in memory 134, and the MAC address of the printer 100. The channel list is information indicating a plurality of communication channels pre-determined in the printer 100 (i.e., a plurality of communication channels available to the printer 100).

[0042] At T106, the printer 100 changes the WFD flag 138 in the memory 134 from "OFF" to "ON" and transitions from the device state to the G / O state.

[0043] In T108, the printer 100 transitions from the impossible state to the possible state. The impossible state is a state in which the Wi-Fi I / F 116 does not transmit a DPP Authentication Response (hereinafter simply referred to as "ARes") (see T220 described below) even when it receives a DPP Authentication Request (hereinafter simply referred to as "AReq") (see T210 in FIG. 4 described below) from the terminal 10. The possible state is a state in which the Wi-Fi I / F 116 transmits an ARes to the terminal 10 in response to receiving an AReq from the terminal 10. In other words, by transitioning from the impossible state to the possible state, the printer 100 becomes capable of executing Auth (see T25 in FIG. 2). Specifically, in this embodiment, the impossible state is a state in which the Wi-Fi I / F 116 does not supply an external signal to the CPU 132 even when it receives the signal. The possible state is a state in which, in response to receiving a signal from the outside, the Wi-Fi I / F 116 supplies the signal to the CPU 132 and transmits a response to the signal. The possible state is a state in which the CPU 132 processes the signal received from the outside, and therefore has a higher processing load than the impossible state. In a modified example, the impossible state may be a state in which the Wi-Fi I / F 116 is not powered, and the possible state may be a state in which the Wi-Fi I / F 116 is powered. In another modified example, the impossible state may be a state in which the Wi-Fi I / F 116 does not supply a notification indicating that the AReq has been received to the CPU 132 even when it receives an AReq from the outside, and the possible state may be a state in which the Wi-Fi I / F 116 supplies a notification indicating that the AReq has been received to the CPU 132 in response to receiving an AReq from the outside.

[0044] In T110, the NFC I / F 118 of the printer 100 transmits the WFD information and the BS information to the terminal 10 using the established NFC connection.

[0045] When the terminal 10 starts the application 38 in T103, it executes the following processes in accordance with the application 38. When the terminal 10 receives WFD information and BS information from the printer 100 via the NFC I / F 18 in T110, it displays a selection screen on the display unit 14. The selection screen includes an "AP" button indicating that processing should be performed to establish a DPP connection between the printer 100 and the AP 6, and a "Terminal" button indicating that processing should be performed to establish a WFD connection between the terminal 10 and the printer 100. In other words, the selection screen is a screen for allowing the user to select one of the DPP and WFD connection methods.

[0046] In T120, the terminal 10 accepts an operation from the user to select the "AP" button in the selection screen. When the process of T120 ends, the process of FIG.

[0047] (Authentication (Auth); Figure 4) Next, the Auth processing at T25 in Fig. 2 will be described with reference to Fig. 4. In response to the user selecting the "AP" button on the selection screen at T120 in Fig. 3, the terminal 10 generates a public key TPK1 and a secret key tsk1 of the terminal 10 at T200. Next, in T202, the terminal 10 generates a shared key SK1 using the generated secret key tsk1 and the public key PPK1 of the printer 100 received at T110 in Fig. 3 according to ECDH (an abbreviation for Elliptic curve Diffie-Hellman key exchange). Then, in T204, the terminal 10 encrypts a random value RV1 using the generated shared key SK1 to generate encrypted data ED1.

[0048] In T210, the terminal 10 transmits an AReq to the printer 100 via the Wi-Fi I / F 16, with the MAC address of the printer 100 received in T110 of FIG. 3 as the destination. The AReq is a signal requesting the printer 100 to perform authentication. Here, the terminal 10 repeatedly transmits the AReq to the printer 100, sequentially using multiple communication channels in the channel list received in T110. The AReq includes the public key TPK1 of the terminal 10 generated in T200, the encrypted data ED1 generated in T204, and the capability of the terminal 10.

[0049] Capability is information that is pre-specified in devices that support the DPP method, and includes one of the following values: a value indicating that the device can operate only as a DPP Configurator; a value indicating that the device can operate only as a DPP Enrollee; or a value indicating that the device can operate as both a Configurator and an Enrollee. Note that a Configurator refers to a device that, in a Config (T30 in FIG. 2), sends a CO to be used in an NA (T35 in FIG. 2) to an Enrollee. On the other hand, an Enrollee refers to a device that, in a Config, receives a CO to be used in an NA from a Configurator. As described above, in this embodiment, the terminal 10 generates a CO for an AP or a printer and sends it to the AP 6 or the printer 100. Therefore, the capability of the terminal 10 includes a value indicating that the device can operate only as a Configurator.

[0050] At T210, the printer 100 receives the AReq from the terminal 10 via the Wi-Fi I / F 116. As described above, the AReq is transmitted with the MAC address of the printer 100 as the destination. Therefore, the printer 100 can properly receive the AReq from the terminal 10.

[0051] 3, the printer 100 monitors whether one of the communication channels in the channel list is used to receive the AReq. As described above, the AReq in T210 is transmitted sequentially using the communication channels in the channel list. Therefore, the printer 100 can properly receive the AReq from the terminal 10.

[0052] Next, the printer 100 performs the following process to authenticate the sender of the AReq (i.e., the terminal 10). Specifically, first, in T212, the printer 100 generates a shared key SK1 according to ECDH using the public key TPK1 of the terminal 10 in the AReq and the private key psk1 of the printer 100 pre-stored in the memory 134. Here, the shared key SK1 generated by the terminal 10 in T202 is the same as the shared key SK1 generated by the printer 100 in T212. Therefore, in T214, the printer 100 can properly decrypt the encrypted data ED1 in the AReq using the generated shared key SK1, and as a result, can obtain the random value RV1. If the printer 100 successfully decrypts the encrypted data ED1, it determines that the sender of the AReq is the device with which an NFC connection was established in T104 of FIG. 3, that is, determines that authentication was successful, and performs the processes from T216 onward. On the other hand, if the printer 100 is unable to successfully decrypt the encrypted data ED1, it determines that the sender of the AReq is not the device with which an NFC connection was established in T104, i.e., it determines that authentication has failed, and does not execute the processing from T216 onwards.

[0053] At T216, the printer 100 generates a new public key PPK2 and a new private key psk2 for the printer 100. Note that, in a modified example, the public key PPK2 and private key psk2 may be stored in advance in the memory 134. Next, at T217, the printer 100 generates a shared key SK2 using the public key TPK1 of the terminal 10 in the AReq of T210 and the private key psk2 for the printer 100 that has been generated, in accordance with ECDH. Then, at T218, the printer 100 encrypts the acquired random value RV1 and the new random value RV2 using the generated shared key SK2 to generate encrypted data ED2.

[0054] In T220, the printer 100 transmits an ARes to the terminal 10 via the Wi-Fi I / F 116. The ARes includes the public key PPK2 of the printer 100 generated in T216, the encrypted data ED2 generated in T218, and the capability of the printer 100. The capability includes a value indicating that the printer 100 can operate only as an Enrollee.

[0055] In response to receiving an ARes from the printer 100 via the Wi-Fi I / F 16 in T220, the terminal 10 executes the following process to authenticate the sender of the ARes (i.e., the printer 100). Specifically, first, in T222, the terminal 10 generates a shared key SK2 according to ECDH using the private key tsk1 of the terminal 10 generated in T200 and the public key PPK2 of the printer 100 in the ARes. Here, the shared key SK2 generated by the printer 100 in T217 is the same as the shared key SK2 generated by the terminal 10 in T222. Therefore, in T224, the terminal 10 can appropriately decrypt the encrypted data ED2 in the ARes using the generated shared key SK2, and as a result, can obtain the random values ​​RV1 and RV2. If the terminal 10 is successful in decrypting the encrypted data ED2, it determines that the sender of the ARes is a device with which an NFC connection was established in T104 of Fig. 3, that is, it determines that authentication was successful, and executes the processes from T230 onwards. On the other hand, if the terminal 10 is not successful in decrypting the encrypted data ED2, it determines that the sender of the ARes is not a device with which an NFC connection was established in T104, that is, it determines that authentication was unsuccessful, and does not execute the processes from T230 onwards.

[0056] In T230, the terminal 10 sends Confirm to the printer 100 via the Wi-Fi I / F 16. The Confirm includes information indicating that the terminal 10 operates as a Configurator and the printer 100 operates as an Enrollee. As a result, in T232, the terminal 10 decides to operate as a Configurator, and in T234, the printer 100 decides to operate as an Enrollee. When the processing of T234 ends, the processing of FIG. 4 ends.

[0057] (Configuration(Config); Figure 5) Next, the Config processing at T30 in Fig. 2 will be described with reference to Fig. 5. At T300, the printer 100 sends a DPP Configuration Request (hereinafter simply referred to as "CReq") to the terminal 10 via the Wi-Fi I / F 116. The CReq is a signal requesting the transmission of a CO (i.e., information for establishing a DPP connection between the printer 100 and the AP 6).

[0058] In T300, the terminal 10 receives the CReq from the printer 100 via the Wi-Fi I / F 16. In this case, in T301, the terminal 10 acquires the group ID “Group,” the public key TPK2, and the private key tsk2 from the memory 34 of the terminal 10. As described above, the terminal 10 has already executed the Config of T15 in FIG. 2 with the AP 6, and at this time, the terminal 10 generates the group ID “Group,” the public key TPK2, and the private key tsk2 and stores them in the memory 34. The group ID “Group” is information that identifies the wireless network formed by establishing a DPP connection between the printer 100 and the AP 6. Note that, in a modified example, a character string specified by the user may be used as the group ID. That is, in T301, the terminal 10 acquires the information stored in T15 in FIG. 2. Next, in T302, the terminal 10 generates a printer CO (see T30 in FIG. 2). Specifically, the terminal 10 executes the following processes.

[0059] The terminal 10 generates a hash value HV by hashing the public key TPK2 of the terminal 10. The terminal 10 also generates a specific value by hashing a combination of the hash value HV, the group ID "Group," and the public key PPK2 of the printer 100 in the ARes of T220 in FIG. 4. The terminal 10 then encrypts the generated specific value using the private key tsk2 of the terminal 10 according to ECDSA (Elliptic Curve Digital Signature Algorithm) to generate a digital signature DSpr. As a result, the terminal 10 can generate a printer Signed-Connector (hereinafter, the Signed-Connector will be simply referred to as "SCont") that includes the hash value HV, the group ID "Group," the public key PPK2 of the printer 100, and the digital signature DSpr. The terminal 10 then generates a printer CO that includes the printer SCont and the public key TPK2 of the terminal 10.

[0060] In T310, the terminal 10 transmits a DPP Configuration Response (hereinafter simply referred to as “CRes”) including a CO for the printer to the printer 100 via the Wi-Fi I / F 16.

[0061] In T310, the printer 100 receives the CRes from the terminal 10 via the Wi-Fi I / F 116. In this case, in T312, the printer 100 stores the printer CO in the CRes in the memory 134. When the processing of T312 ends, the processing of FIG. 5 ends.

[0062] (Network Access (NA); Figure 6) Next, with reference to FIG. 6, the NA process at T35 in FIG. 2 executed between the printer 100 and the AP 6 will be described. As described above, the processes at T5 to T15 in FIG. 2 have already been executed between the terminal 10 and the AP 6, similar to T20 to T30 in FIG. 2. However, the AP 6 does not execute the processes at T102 to T110 in FIG. 3. The AP 6 pre-stores its public key APK1 and private key ask1. A QR code obtained by encoding the AP 6's public key APK1, the AP 6's channel list, and the AP 6's MAC address is affixed to the housing of the AP 6. When the terminal 10 photographs the QR code, processes similar to those from T200 onward in FIG. 4 are executed between the terminal 10 and the AP 6. As a result, the AP 6 stores the AP 6's public key APK2 and private key ask2 (see T216 in FIG. 4) and further stores the AP CO received from the terminal 10 (see T312 in FIG. 5). The AP CO includes the AP SCont and the public key TPK2 of the terminal 10. The public key TPK2 is the same as the public key TPK2 included in the printer CO. The AP SCont also includes a hash value HV, a group ID "Group", the public key APK2 of the AP 6, and an electronic signature DSap. The hash value HV and the group ID "Group" are the same as the hash value HV and the group ID "Group" included in the printer CO, respectively. The electronic signature DSap is information obtained by hashing a combination of the hash value HV, the group ID "Group", and the public key APK2, and encrypting it with the private key tsk2 of the terminal 10, and is a different value from the electronic signature DSpr included in the printer CO.

[0063] In T400, the printer 100 transmits a DPP Peer Discovery Request (hereinafter simply referred to as "DReq") including the printer-specific SCont to the AP 6 via the Wi-Fi I / F 116. The DReq is a signal requesting the AP 6 to perform authentication and transmit the AP-specific SCont.

[0064] In response to receiving the DReq from the printer 100, the AP 6 executes processing to authenticate the sender of the DReq (i.e., the printer 100) and each piece of information in the DReq (i.e., the hash value HV, “Group,” and public key PPK2) in T400. Specifically, in T402, the AP 6 first executes a first AP determination process to determine whether the hash value HV and group ID “Group” in the received printer-SCont match the hash value HV and group ID “Group” in the AP-SCont included in the stored AP-CO, respectively. In the case of FIG. 6, the AP 6 determines that they “match” in the first AP determination process, and therefore determines that the authentication of the sender of the DReq (i.e., the printer 100) has been successful. Note that a match between the hash value HV in the received printer-SCont and the hash value HV in the AP-SCont included in the stored AP-CO means that the printer-SCont and the AP-SCont were generated by the same device (i.e., the terminal 10). Therefore, the AP 6 also determines that the authentication of the generator of the received printer-SCont (i.e., the terminal 10) has been successful. Furthermore, the AP 6 decrypts the electronic signature DSpr in the received printer-SCont using the public key TPK2 of the terminal 10 included in the stored AP CO. In the case of FIG. 6, the decryption of the electronic signature DSpr is successful, so the AP 6 executes a second AP determination process to determine whether or not the specific value obtained by decrypting the electronic signature DSpr matches the value obtained by hashing each piece of information in the received printer-SCont (i.e., the hash value HV, "Group", and public key PPK2). In the case of FIG. 6, the AP 6 determines that the specific value matches in the second AP determination process, so it determines that the authentication of each piece of information in the DReq has been successful, and executes the processes from T404 onwards. A determination of "match" in the second AP determination process means that the information in the received printer SCont (i.e., hash value HV, "Group", and public key PPK2) has not been tampered with by a third party after the printer CO was stored in printer 100.On the other hand, if the first AP judgment process determines that there is no match, if the decryption of the electronic signature DSpr fails, or if the second AP judgment process determines that there is no match, AP6 determines that the authentication has failed and does not perform the processing from T404 onwards.

[0065] Next, in T404, the AP6 generates a connection key (ie, a shared key) CK using the public key PPK2 of the printer 100 that has been acquired and the secret key ask2 of the AP6 that has been stored in accordance with ECDH.

[0066] At T410, the AP 6 transmits a DPP Peer Discovery Response (hereinafter simply referred to as “DRes”) including the SCont for the AP to the printer 100.

[0067] In response to receiving the DRes from the AP 6 via the Wi-Fi I / F 116 in T410, the printer 100 executes processing to authenticate the sender of the DRes (i.e., the AP 6) and each piece of information in the DRes (i.e., the hash value HV, "Group," and public key APK2). Specifically, in T412, the printer 100 first executes a first PR determination process to determine whether the hash value HV and group ID "Group" in the received AP-SCont match the hash value HV and group ID "Group" in the printer-SCont included in the stored printer-SCont, respectively. In the case of FIG. 6, the printer 100 determines that they "match" in the first PR determination process, and therefore determines that authentication of the sender of the DRes (i.e., the AP 6) has been successful. Note that a match between the hash value HV in the received AP-SCont and the hash value HV in the printer-SCont included in the stored printer-SCont CO means that the printer-SCont and the AP-SCont were generated by the same device (i.e., the terminal 10). Therefore, the printer 100 also determines that the authentication of the generator of the received AP-SCont (i.e., the terminal 10) was successful. Furthermore, the printer 100 decrypts the electronic signature DSap in the received AP-SCont using the public key TPK2 of the terminal 10 included in the stored printer-SCont CO. In the case of FIG. 6, since the decryption of the electronic signature DSap is successful, the printer 100 executes a second PR determination process to determine whether or not the specific value obtained by decrypting the electronic signature DSap matches the value obtained by hashing each piece of information in the received AP-SCont (i.e., the hash value HV, "Group", and public key APK2). 6, the printer 100 determines that the information in the DRes is a match in the second PR determination process, and therefore determines that the authentication of each piece of information in the DRes has been successful, and executes the processes from T414 onward. The determination that the information is a match in the second PR determination process means that the information in the AP SCont (i.e., the hash value HV, "Group", and public key APK2) has not been tampered with by a third party after the AP CO was stored in the AP6.On the other hand, if the first PR determination process determines that there is no match, if the decryption of the electronic signature DSap fails, or if the second PR determination process determines that there is no match, the printer 100 determines that the authentication has failed and does not perform the processes from T414 onwards.

[0068] In T414, the printer 100 generates a connection key CK according to ECDH using the stored private key psk2 of the printer 100 and the public key APK2 of the AP 6 in the received SCont for AP. Here, the connection key CK generated by the AP 6 in T404 and the connection key CK generated by the printer 100 in T414 are the same. As a result, the connection key CK for establishing a DPP connection is shared between the printer 100 and the AP 6. When T414 ends, the processing in FIG. 6 ends.

[0069] As described above, after the connection key CK is shared between the printer 100 and the AP 6, at T40 in Fig. 2, the printer 100 and the AP 6 use the connection key CK to perform 4-way handshake communication. As a result, a DPP connection is established between the printer 100 and the AP 6. When establishing a DPP connection with the AP 6, the printer 100 changes the WFD flag 138 from "ON" to "OFF."

[0070] (Case B; Figure 7) Next, referring to Fig. 7, the processing of Case B in which a WFD connection is established between the terminal 10 and the printer 100 will be described. T500 to T512 are the same as T100 to T112 in Fig. 3. In response to the user selecting the "Terminal" button in the selection screen in T520, the terminal 10 executes a search process in T522 to search for a device to which the terminal 10 is to be connected (i.e., the printer 100). Specifically, the following process is executed.

[0071] First, the terminal 10 broadcasts a Probe Request (hereinafter simply referred to as "PReq") via the Wi-Fi I / F 16. After broadcasting the PReq, the terminal 10 receives PRes from each of one or more devices including the printer 100. In this case, the terminal 10 identifies the printer 100 to be connected to by identifying a PRes including the SSID "wfd" received by T510 from among the one or more PRes. Then, the terminal 10 transmits (i.e., transmits by unicast) a PReq including the SSID "wfd" of the identified printer 100 to the printer 100 via the Wi-Fi I / F 16.

[0072] In response to receiving a PReq including the SSID “wfd” from the terminal 10 via the Wi-Fi I / F 116, the printer 100 transmits a PRes to the terminal 10.

[0073] In T530, the terminal 10 executes various communications (Provision Discovery, Association, WPS Negotiation, 4-way handshake) with the printer 100. In WPS Negotiation, the terminal 10 receives wireless setting information including the SSID "wfd" and password stored in the memory 134 from the printer 100. Then, the terminal 10 executes 4-way handshake communication with the printer 100 using the SSID "wfd" and password, and establishes a WFD connection with the printer 100.

[0074] When a WFD connection with the terminal 10 is established in T530, the printer 100 transitions from the available state to the unavailable state in T540. In a situation where a WFD connection is established between the terminal 10 and the printer 100, it is unlikely that communication in accordance with the DPP method will be executed between the terminal 10 and the printer 100. In such a situation, the printer 100 transitions from the available state to the unavailable state, which can prevent the available state, which has a higher processing load than the unavailable state, from being maintained.

[0075] In response to receiving a print operation from the user in T550 to cause the printer 100 to execute printing, the terminal 10 sends print data to the printer 100 in T552 via the Wi-Fi I / F 16 using the established WFD connection.

[0076] When the printer 100 receives print data from the terminal 10 via the Wi-Fi I / F 116 in T552, the printer 100 causes the print execution unit 120 to execute printing in accordance with the print data in T554. When the processing of T554 ends, the processing of FIG. 7 ends.

[0077] (Case C; Figure 8) Next, processing for Case C will be described with reference to FIG. 8. In Case C, the terminal 10 and the printer 100 have established a normal Wi-Fi connection with AP 6. Therefore, the memory 34 of the terminal 10 and the memory 134 of the printer 100 store AP information for establishing a normal Wi-Fi connection with AP 6. The AP information includes the SSID "ap6" that identifies the wireless network formed by AP 6. In the initial state of FIG. 8, the printer 100 operates in the non-configuration mode because the AP information is stored in the memory 134.

[0078] T600 and T602 are the same as T100 and T102 in Fig. 3. In T604, the printer 100 acquires a signal indicating that an NFC connection has been established from the NFC I / F 118, determines that the operating mode of the printer 100 is the non-configuration mode, and supplies the NFC I / F 118 with WFD information including the SSID "wfd" and AP information including the SSID "ap6".

[0079] T606 is the same as T106 in Fig. 3. In T610, the NFC I / F 118 of the printer 100 transmits the WFD information and AP information to the terminal 10 using the established NFC connection.

[0080] In T610, when the terminal 10 receives WFD information and AP information from the printer 100 via the NFC I / F 18, the terminal 10 determines that the SSID "ap6" included in the received AP information matches the SSID "ap6" in the AP information stored in the memory 34. In this case, the terminal 10 determines that communication with the printer 100 is currently possible, and in T612 displays a notification screen indicating that communication with the printer 100 is currently possible.

[0081] T650 to T654 are the same as T550 to T554 in Fig. 7. In T660, the printer 100 determines that a predetermined time has passed since the WFD 138 was changed to "ON" in T606, and in T652 changes the WFD 138 from "ON" to "OFF." When the processing of T662 ends, the processing of Fig. 8 ends.

[0082] As described above, when an NFC connection with the terminal 10 is established (T602) while a normal Wi-Fi connection with the AP 6 has been established, the printer 100 supplies AP information to the NFC I / F 118 (T604). This causes the AP information to be transmitted from the NFC I / F 118 to the terminal 10, allowing the terminal 10 to determine whether communication with the printer 100 is currently possible using the received AP information. If the terminal 10 determines that communication with the printer 100 is currently possible, the printer 100 displays a notification screen. In other words, when the terminal 10 and the printer 100 are currently able to communicate with each other, the printer 100 does not execute processing for establishing a DPP connection between the printer 100 and the AP 6 or processing for establishing a WFD connection between the terminal 10 and the printer 100. This reduces the processing load on the terminal 10 and the printer 100.

[0083] (Case D; Figure 9) Next, referring to FIG. 9, the processing of Case D, in which a mode transition operation is performed on the printer 100, will be described. In Case D, the printer 100 has already established a normal Wi-Fi connection with AP6. Therefore, the printer 100 stores AP information including the SSID "ap6" in the memory 134. In addition, in the initial state of FIG. 9, the printer 100 operates in the non-configuration mode.

[0084] When the printer 100 receives a transition instruction from the user in T700 to transition the operating mode of the printer 100, the printer 100 transitions from the non-setting mode to the setting mode in T702. T703 and T704 are the same as T103 and T104 in FIG.

[0085] In T705, the printer 100 receives a signal from the NFC I / F 118 indicating that an NFC connection has been established, determines that the operating mode of the printer 100 is the setting mode, and supplies WFD information and BS information to the NFC I / F 118. T706 to T712 are the same as T106 to T112 in Fig. 3. That is, the WFD information and BS information are sent from the NFC I / F 118 of the printer 100 to the terminal 10, and a selection screen is displayed on the terminal 10. When the processing of T712 ends, the processing of Fig. 9 ends.

[0086] As described above, in a situation where a normal Wi-Fi connection is established between the printer 100 and the AP 6, that is, in a situation where the printer 100 is operating in the non-configuration mode, the printer 100 transitions to the configuration mode when it receives a transition instruction from the user (T702). Then, in response to the establishment of an NFC connection with the terminal 10, the printer 100 supplies the WFD information and BS information to the NFC I / F 118 (T705). As a result, the WFD information and BS information are transmitted from the NFC I / F 118 to the terminal 10 (T710). As a result, in a situation where the user desires to execute communication between the terminal 10 and the printer 100 in accordance with the DPP method, for example, in a situation where the user desires to establish a DPP connection between the printer 100 and an AP other than the AP 6, the user can execute communication between the terminal 10 and the printer 100 in accordance with the DPP method by executing a transition instruction on the printer 100 operating in the non-configuration mode.

[0087] (Processing on terminal 10; Figure 10) Next, with reference to Fig. 10, a description will be given of the processing executed by the CPU 32 of the terminal 10 to realize the processing of Figs. 2 to 9. When an NFC connection is established between the NFC I / F 18 of the terminal 10 and the NFC I / F 118 of the printer 100, the processing of Fig. 10 is executed.

[0088] In S10, the terminal 10 determines whether or not it has received BS information from the printer 100 using the established NFC connection via the NFC I / F 18. If the terminal 10 has received WFD information and BS information from the printer 100 (for example, T110 in FIG. 3), the terminal 10 determines YES in S10 and proceeds to S15. On the other hand, if the terminal 10 has received WFD information and AP information from the printer 100 (for example, T610 in FIG. 8), the terminal 10 determines NO in S10 and proceeds to S35.

[0089] In S15, the terminal 10 displays a selection screen on the display unit 14 (for example, T112 in FIG. 3).

[0090] In S20, the terminal 10 determines whether the "Terminal" button has been selected by the user on the selection screen. If the "Terminal" button has been selected by the user on the selection screen (for example, T520 in FIG. 7), the terminal 10 determines YES in S20 and proceeds to S25. On the other hand, if the "AP" button has been selected on the selection screen (for example, T120 in FIG. 3), the terminal 10 determines NO in S20 and proceeds to S30.

[0091] In S25, the terminal 10 executes various communications (Probe, Provision Discovery, Association, WPS Negotiation, 4-way handshake) with the printer 100 via the Wi-Fi I / F 16 in accordance with the WFD method to establish a WFD connection with the printer 100 (for example, T522 and T530 in FIG. 7). When the processing of S25 ends, the processing of FIG. 10 ends.

[0092] In S30, the terminal 10 executes Auth and Config with the printer 100 via the Wi-Fi I / F 16 (FIGS. 4 and 5). When the process of S30 ends, the process of FIG. 10 ends.

[0093] In S35, the terminal 10 uses the received AP information to determine whether or not communication with the printer 100 is currently possible. If the terminal 10 determines that communication with the printer 100 is currently possible, the terminal 10 determines YES in S35 and displays a notification screen on the display unit 14 in S40 (for example, T612 in FIG. 8). On the other hand, if the terminal 10 determines that communication with the printer 100 is currently impossible, the terminal 10 determines NO in S35 and establishes a WFD connection with the printer 100 in S25 using the received WFD information. When the processing of S25 or S40 ends, the processing of FIG. 10 ends.

[0094] (Processing of printer 100; Figure 11) Next, with reference to Fig. 11, a process executed by the CPU 132 of the printer 100 to realize the processes of Fig. 2 to Fig. 9 will be described. When an NFC connection is established between the NFC I / F 18 of the terminal 10 and the NFC I / F 118 of the printer 100, the process of Fig. 11 is executed.

[0095] In S100, the printer 100 determines whether a normal Wi-Fi connection is being established with the AP 6. If AP information is stored in the memory 134, the printer 100 determines YES in S100 and proceeds to S103. On the other hand, if AP information is not stored in the memory 134, the printer 100 determines NO in S100 and proceeds to S135.

[0096] In S103, the printer 100 determines whether it is operating in the non-setting mode. If the printer 100 determines that it is operating in the non-setting mode (YES in S103), it proceeds to S105. On the other hand, if the printer 100 determines that it is operating in the setting mode (NO in S103), it proceeds to S135.

[0097] In S105, the printer 100 supplies the WFD information and AP information to the NFC I / F 118 (for example, T604 in FIG. 8). The WFD information includes an SSID that identifies the wireless network in which the printer 100, operating in a G / O state, operates as a master station. The AP information includes an SSID that identifies the wireless network in which the AP to which the printer 100 normally establishes a Wi-Fi connection operates as a master station.

[0098] In S110, the printer 100 determines whether the WFD flag 138 stored in the memory 134 indicates "ON." If the WFD flag 138 indicates "ON," the printer 100 determines YES in S110 and proceeds to S120. On the other hand, if the WFD flag 138 indicates "OFF," the printer 100 determines NO in S110 and proceeds to S115.

[0099] In S115, the printer 100 changes the WFD flag 138 stored in the memory 134 from "OFF" to "ON" (for example, T606 in FIG. 8). As a result, the printer 100 operates in the device state.

[0100] In S120, the printer 100 transitions from the device state to the G / O state (for example, T606 in FIG. 8).

[0101] In S125, the printer 100 monitors whether a PReq is received from the terminal 10 via the Wi-Fi I / F 116. If the printer 100 receives a PReq from the terminal 10, the printer 100 determines YES in S125 and proceeds to S130. On the other hand, if a predetermined time has passed without receiving a PReq from the terminal 10 (for example, T660 in FIG. 8), the printer 100 determines NO in S125 and proceeds to S132.

[0102] In S130, the printer 100 executes various communications (Probe, Provision Discovery, Association, WPS Negotiation, 4-way handshake) with the terminal 10 in accordance with the WFD method to establish a WFD connection with the terminal 10. When the processing of S130 ends, the processing of FIG. 11 ends.

[0103] In S132, the printer 100 changes the WFD flag stored in the memory 134 from "ON" to "OFF" (for example, T662 in FIG. 8). When the process of S132 ends, the process of FIG. 11 ends.

[0104] In S135, the printer 100 provides the WFD information and BS information to the NFC I / F 118 (for example, T105 in FIG. 3). The BS information includes the public key of the printer 100, a channel list, and the MAC address of the printer 100.

[0105] S140 and S145 are similar to S110 and S115. In S150, the printer 100 transitions from the device state to the G / O state, and from the disabled state to the enabled state (for example, T106 and T108 in FIG. 3).

[0106] S155 is the same as S125. When the printer 100 receives a PReq from the terminal 10 via the Wi-Fi I / F 116 (for example, T522 in FIG. 7), the printer 100 determines YES in S155 and proceeds to S160. On the other hand, when the printer 100 receives an AReq from the terminal 10 via the Wi-Fi I / F 116 (for example, T210 in FIG. 4), the printer 100 determines NO in S155 and proceeds to S170.

[0107] S160 is the same as S130. In S165, the printer 100 transitions from the possible state to the impossible state (for example, T540 in FIG. 7). When the process of S165 ends, the process of FIG. 11 ends.

[0108] In S170, the printer 100 performs Auth and Config with the terminal 10 (e.g., Figures 4 and 5), and performs NA and 4-way handshake with the AP 6 (e.g., Figure 6, T40 in Figure 2), and establishes a DPP connection with the AP 6.

[0109] In S175, the printer 100 changes the WFD flag stored in the memory 134 from "ON" to "OFF." When the process of S175 ends, the process of FIG.

[0110] (Effects of this embodiment) According to this embodiment, the printer 100 provides the NFC I / F 118 with BS information including the public key PPK1 of the printer 100 and WFD information including the SSID "wfd" (T105 in FIG. 3). As a result, when an NFC connection with the printer 100 is established (T104 in FIG. 3), the terminal 10 receives the BS information and WFD information from the printer 100 (T110) and displays a selection screen (T112). When the "AP" button is selected by the user on the selection screen (T120), that is, when the terminal 10 determines that a DPP connection between the printer 100 and AP6 should be established, the terminal 10 transmits an AReq to the printer 100 (T210 in FIG. 4). When the printer 100 receives the AReq from the terminal 10, the printer 100 transmits an ARes to the terminal 10 (T220). When the terminal 10 receives an ARes from the printer 100, it transmits a CRes including a printer CO to the printer 100 (T310 in FIG. 5). When the printer 100 receives a CRes from the terminal 10, it establishes a DPP connection between the printer 100 and the AP 6 using the printer CO (T35 and T40 in FIG. 2). That is, the printer 100 can establish a Wi-Fi connection with the AP 6 according to the DPP method (i.e., a DPP connection). On the other hand, when the user selects the "Terminal" button on the selection screen (T520 in FIG. 7), that is, when the terminal 10 determines that a WFD connection should be established between the terminal 10 and the printer 100, it transmits a PReq including the SSID "wfd" included in the WFD information to the printer 100 (T522). When the printer 100 receives a PReq from the terminal 10, it establishes a WFD connection between the terminal 10 and the printer 100 (T530). That is, the printer 100 can establish a WFD connection with the terminal 10 according to the WFD method. Therefore, in response to the establishment of an NFC connection between the printer 100 and the terminal 10, the printer 100 can establish a DPP connection or a WFD connection, which is different from the NFC connection, according to an appropriate connection method from among a plurality of connection methods.

[0111] (Correspondence) The printer 100, the terminal 10, and the AP 6 are examples of a "communication device," a "first external device," and a "second external device," respectively. The NFC I / F18 and the NFC I / F118 are examples of a "first wireless interface" of the "first external device" and a "first wireless interface" of the "communication device," respectively. The Wi-Fi I / F16 is an example of a "second wireless interface" and a "third wireless interface" of the "first external device." The Wi-Fi I / F116 is an example of a "second wireless interface" and a "third wireless interface" of the "communication device." The public key PPK1 and the SSID "wfd" of the printer 100 are examples of a "first public key (or public key)" and "specific information," respectively. The NFC connection of T104 in FIG. 3, the DPP connection of T40 in FIG. 2, and the WFD connection of T530 in FIG. 7 are examples of a "first wireless connection," a "second wireless connection," and a "third wireless connection," respectively. The DPP method and the WFD method are examples of a "first connection method" and a "second connection method," respectively. The AReq of T210, the ARes of T220, and the CO for the printer in FIG. 4 are examples of a "first authentication request (or authentication request)," a "first authentication response (or authentication response)," and a "first connection information (or connection information)," respectively. The PReq including the SSID "wfd" transmitted from terminal 10 in the search process of T522 is an example of a "specific message."

[0112] The print data of T552 in FIG. 7 is an example of "target data." The non-setting mode and setting mode are examples of "first mode" and "second mode," respectively. The AP information of T610 in FIG. 8 is an example of "determination information." A NO determination in S20 in FIG. 10 is an example of "a case where it is determined that a second wireless connection should be established," and a YES determination in S20 is an example of "a case where it is determined that a third wireless connection should be established."

[0113] The processing of S135 in Figure 11, the processing of T220 in Figure 4, the processing of T310 in Figure 5, the processing of T35 and T40 in Figure 2, and the processing of T530 in Figure 7 are examples of processing executed by the "first supply unit," "authentication response sending unit," "connection information receiving unit," "first establishment unit," and "second establishment unit" of the "communication device," respectively.

[0114] The processing of S10 and S20 in Figure 10, the processing of T210 and T220 in Figure 4, the processing of T310 in Figure 5, and the processing of T522 and T530 in Figure 7 are examples of processing executed by the "receiving unit," "determination unit," "authentication request transmitting unit," "authentication response receiving unit," "connection information transmitting unit," "specific signal transmitting unit," and "establishment unit" of the "first external device," respectively.

[0115] (Second embodiment; Figures 12 and 13) Next, a second embodiment will be described with reference to Figures 12 and 13. The second embodiment differs from the first embodiment in that the processing in Figure 12 is executed by the terminal 10 instead of the processing in Figure 10, and the processing in Figure 12 is executed by the printer 100 instead of the processing in Figure 11. First, the processing executed by the CPU 32 of the terminal 10 will be described with reference to Figure 12.

[0116] S210 is the same as S10 in Fig. 10. When the terminal 10 receives WFD information and BS information from the printer 100, it determines YES in S210 and proceeds to S215. S215 to S230 are the same as S15 to S30 in Fig. 10. On the other hand, when the terminal 10 receives a Read command conforming to the NFC method from the printer 100, it determines NO in S210 and proceeds to S235.

[0117] In S235, the terminal 10 supplies the public key of the terminal 10, a channel list indicating a plurality of communication channels predetermined in the terminal 10 (i.e., a plurality of communication channels available to the terminal 10), and the MAC address of the terminal 10 to the NFC I / F 18. As a result, the NFC I / F 18 transmits the public key, channel list, and MAC address to the printer 100 using the established NFC connection.

[0118] In S240, the terminal 10 changes the value of the capability of the terminal 10 from a value indicating that it can operate as a Configurator to a value indicating that it can operate as an Enrollee.

[0119] In S245, the terminal 10 transitions from the disabled state to the enabled state, i.e., the terminal 10 starts a process of monitoring whether one of the communication channels in the channel list receives the used AReq.

[0120] In S250, the terminal 10 first executes Auth and Config with the printer 100. In Auth, the terminal 10 receives an AReq from the printer, sends an ARes to the printer 100, receives a Confirm from the printer 100, and decides to operate as an Enrollee. In Config, the terminal 10 sends a CReq to the printer 100, receives a CRes including a terminal CO from the printer 100, and stores the terminal CO for establishing a DPP connection between the terminal 10 and the AP 6. Next, the terminal 10 executes NA with the AP 6 using the terminal CO, shares a connection key with the AP 6 for establishing a DPP connection with the AP 6, executes a 4-way handshake with the AP 6, and establishes a DPP connection with the AP 6. When the processing of S250 ends, the processing of FIG. 12 ends.

[0121] (Printer processing; Figure 13) Next, the processing executed by the CPU 132 of the printer 100 will be described with reference to FIG. 13. S300 is the same as S100 in FIG. 11. If the printer 100 determines that a normal Wi-Fi connection with the AP 6 is being established (YES in S300), the printer 100 proceeds to S305. On the other hand, if the printer 100 determines that a normal Wi-Fi connection with the AP 6 is not being established (NO in S300), the printer 100 proceeds to S335. S335 to S375 are the same as S135 to S175 in FIG. 11.

[0122] In S305, the printer 100 changes the value of the capability of the printer 100 from a value indicating that the printer 100 can operate as an Enrollee to a value indicating that the printer 100 can operate as a Configurator.

[0123] In S310, the printer 100 causes the NFC I / F 118 to transmit a Read command. As a result, the NFC I / F 118 transmits the Read command to the terminal 10 using the established NFC connection.

[0124] In S315, the printer 100 receives the public key, channel list, and MAC address of the terminal 10 from the terminal 10 via the NFC I / F 118.

[0125] In S320, the printer 100 executes Auth and Config with the terminal 10. In Auth, the printer 100 transmits an AReq to the terminal 10, receives an ARes from the terminal 10, transmits a Confirm to the terminal 10, and decides to operate as a Configurator. In Config, the printer 100 receives a CReq from the terminal 10, generates a CO for the terminal, and transmits a CRes including the CO for the terminal to the terminal 10. When the processing of S320 ends, the processing of FIG. 13 ends.

[0126] (Effects of this embodiment) In this embodiment, when the printer 100 determines that a normal Wi-Fi connection with the AP 6 is being established (YES in S300), it sends a Read command to the terminal 10 via the NFC I / F 118 (S310), receives the public key, channel list, and MAC address of the terminal 10 from the terminal 10 (S315), executes Auth and Config with the terminal 10 via the Wi-Fi I / F 116, and sends a terminal CO to the terminal 10 (S320). As a result, the terminal 10 receives the terminal CO from the printer 100, executes NA with the AP 6 using the terminal CO, executes a 4-way handshake with the AP 6, and establishes a DPP connection with the AP 6. This enables the printer 100 to communicate with the terminal 10 via the AP 6.

[0127] (Correspondence) The public key of the terminal 10 in S315 of Fig. 13 is an example of a "second public key." The AReq sent from the printer to the terminal 10 in Auth in S320 and the ARes sent from the terminal 10 to the printer 100 are examples of a "second authentication request" and a "second authentication response," respectively. The CO for the terminal is an example of "second connection information."

[0128] Although specific examples of the present invention have been described above in detail, these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and variations of the specific examples exemplified above. Modifications of the above-mentioned embodiments are listed below.

[0129] (Variation 1) At T35 in Fig. 2, NA processing may be executed between the terminal 10 and the printer 100, and a DPP connection may be established between the terminal 10 and the printer 100. In other words, the "second external device" may be the same device as the "first external device."

[0130] (Variation 2) In the above embodiment, a DPP connection is established between the printer 100 and AP 6 using the terminal 10. Alternatively, for example, a DPP connection may be established between the printer 100 and another device operating as a G / O (i.e., a device operating as a parent station) using the terminal 10. Also, for example, a DPP connection may be established between the printer 100 operating as a G / O (i.e., a device operating as a parent station) and another device (i.e., a device operating as a child station) using the terminal 10. In other words, the "second external device" does not have to be an "access point."

[0131] (Variation 3) The terminal 10 and the printer 100 may further include a Bluetooth (registered trademark, hereinafter simply referred to as "BT") interface for wireless communication according to the Bluetooth (registered trademark) standard. The above-mentioned BT standard includes BT standard version 4.0 or later (so-called Bluetooth Low Energy). In this case, the printer 100 supplies the NFC I / F 118 with BT information for establishing a wireless connection according to the BT standard (hereinafter simply referred to as "BT connection"), instead of WFD information, at T105 in FIG. 3, for example. As a result, the NFC I / F 118 transmits the BT information and BS information to the terminal 10 using an NFC connection. When receiving the BT information and BS information from the printer 100, the terminal 10 displays a selection screen on the display unit 14, and establishes a BT connection with the printer 100 using the received BT information in response to the "Terminal" button being selected on the selection screen. In this modification, the BTI / F of the terminal 10 is an example of a "third wireless interface" of a "first external device," and the BTI / F of the printer 100 is an example of a "third wireless interface" of a "communication device." Also, the BT method and the BT connection are examples of a "second connection method" and a "third wireless connection," respectively.

[0132] (Variation 4) The printer 100 may operate in the setting mode even when a normal Wi-Fi connection is established with the AP 6. In this variation, the "mode transition unit" and the "second supply unit" can be omitted.

[0133] (Modification 5) The process of S165 in Fig. 11 (or S365 in Fig. 13) may be omitted. In this modification, the "second state transition unit" can be omitted.

[0134] (Variation 6) The processing of S15 in FIG. 10 (or S215 in FIG. 12) may be omitted. In this case, when the terminal 10 receives the WFD information and BS information from the printer 100, the terminal 10 may determine whether the public key TPK2 and the private key tsk2 are stored in the memory 34, that is, whether Config with the AP 6 has been executed. If the terminal 10 determines that Config with the AP 6 has been executed, the terminal 10 executes Auth and Config with the printer 100 in S30. On the other hand, if the terminal 10 determines that Config with the AP 6 has not been executed, the terminal 10 establishes a WFD connection with the printer 100 in S25. In this variation, the case where it is determined that Config with the AP 6 has been executed is an example of "when it is determined that a second wireless connection should be established," and the case where it is determined that Config with the AP 6 has not been executed is an example of "when it is determined that a third wireless connection should be established."

[0135] (Variation 7) In S105 of FIG. 11, the printer 100 may supply the MAC address of the printer 100 to the NFC I / F 118 instead of the AP information. When the terminal 10 receives WFD information and a MAC address from the printer 100 via the NFC I / F 18, the terminal 10 determines that it has not received BS information from the printer 100 (NO in S10 of FIG. 10), and in S35, uses the received MAC address to determine whether it is currently able to communicate with the printer 100. Specifically, the terminal 10 first determines whether a normal Wi-Fi connection with the AP 6 has been established. When the terminal 10 determines that a normal Wi-Fi connection with the AP 6 has not been established, the terminal 10 determines NO in S35 and proceeds to S25. On the other hand, when the terminal 10 determines that a normal Wi-Fi connection with the AP 6 has been established, the terminal 10 broadcasts a request signal using the AP 6 via the Wi-Fi I / F 16. In response to transmitting a request signal by broadcast, the terminal 10 receives a response signal in response to the request signal from each of one or more devices connected to the AP 6. In this case, the terminal 10 determines whether or not one or more response signals contain a response signal containing the MAC address of the printer 100 that has already been received. If the terminal 10 determines that one or more response signals contain a response signal containing the MAC address of the printer 100, the terminal 10 determines YES in S35 and proceeds to S40. On the other hand, if the terminal 10 determines that one or more response signals do not contain a response signal containing the MAC address of the printer 100, the terminal 10 determines NO in S35 and proceeds to S25. In this modified example, the MAC address of the printer 100 is an example of "determination information."

[0136] (Variation 8) In the above embodiment, the terminal 10 performed each process in accordance with the application 38. However, the terminal 10 may also perform each of the following processes in accordance with the OS program 36. That is, the terminal 10 establishes an NFC connection with the printer 100 in accordance with the OS program 36 and receives WFD information and BS information from the printer 100 via the NFC I / F 18. In this case, the terminal 10 determines whether the application 38 has been launched. If the terminal 10 determines that the application 38 has not been launched, the terminal 10 determines that a DPP connection between the printer 100 and the AP 6 should be established and performs the same processes as those shown in FIGS. 4 and 5. On the other hand, if the terminal 10 determines that the application 38 has been launched, the terminal 10 determines that a WFD connection between the terminal 10 and the AP 6 should be established and performs the same processes as those shown in T522 and T530 in FIG. 7. In this variation, when the printer 100 receives an AReq from the terminal 10, the printer 100 transmits an ARes to the terminal 10, receives a CRes including a printer-use CO from the terminal 10, and can establish a DPP connection with the AP 6 using the printer-use CO. On the other hand, when the printer 100 receives a PReq including the SSID "wfd" from the terminal 10, it can establish a WFD connection with the terminal 10. Therefore, in response to the establishment of an NFC connection between the printer 100 and the terminal 10, the printer 100 can establish a DPP connection or a WFD connection, which is different from the NFC connection, according to an appropriate connection method from among a plurality of connection methods.

[0137] (Variation 9) The process (for example, T202 and T212 in FIG. 4) for generating a shared key (for example, SK1) is not limited to the process according to ECDH in the above embodiment, but may be other processes according to ECDH. Furthermore, the process for generating a shared key is not limited to the process according to ECDH, but may be a process according to another method (for example, DH (abbreviation for Diffie-Hellman key exchange) or the like). Furthermore, in the above embodiment, the digital signatures DSap and DSpr were generated according to ECDSA, but they may be generated according to another method (for example, DSA (abbreviation for Digital Signature Algorithm), RAS (abbreviation for Rivest-Shamir-Adleman cryptosystem), or the like).

[0138] (Variation 10) The terminal 10 may be provided with a different wireless interface conforming to a wireless method different from the NFC method (for example, the BT method or the TransferJet method) instead of the NFC IFC I / F 18. In this case, the printer 100 may also be provided with a different wireless interface conforming to a wireless method different from the NFC method instead of the NFC IFC I / F 18. The printer 100 transmits the WFD information and the BS information to the terminal 10 via the wireless interface, for example, at T110 in FIG. 3. In this variation, the different wireless interface conforming to a wireless method different from the NFC method is an example of a "first wireless interface."

[0139] (Variation 11) For example, instead of operating as a WFD-based G / O, the printer 100 may operate as a so-called SoftAP. In this case, for example, at T105 in FIG. 3, the printer 100 generates an SSID and a password to be used in the wireless network on which the printer 100 operates as a SoftAP, and provides SoftAP information including the SSID and password to the NFC I / F 118. As a result, at T110, the NFC I / F 118 transmits the SoftAP information and BS information to the NFC I / F 118 using the established NFC connection. In this variation, the SSID in the SoftAP information is an example of "specific information."

[0140] (Variation 12) When the printer 100 determines NO in S155 of FIG. 11 (or S355 of FIG. 13), that is, when it receives an AReq from the terminal 10 via the Wi-Fi I / F 116 (for example, T210 of FIG. 4), it may change the WFD flag from "ON" to "OFF" before executing the process of S170. In this case, the printer 100 ends the process of FIG. 11 (or FIG. 13) when the process of S170 (or S370) ends. In a situation where an AReq is received from the terminal 10, it is unlikely that communication according to the WFD method will be executed between the terminal 10 and the printer 100. In such a situation, the printer 100 changes the WFD flag from "ON" to "OFF," thereby preventing the state in which the WFD flag indicates "ON," that is, the state in which the printer 100 is operable according to the WFD method, from being maintained.

[0141] (Variation 13) The "communication device" does not have to be a printer, but may be other devices such as a scanner, a multi-function device, a mobile terminal, a PC, or a server.

[0142] (Variant 14) In each of the above embodiments, the processes in Figures 2 to 13 are realized by software (i.e., application 38, program 136), but at least one of these processes may be realized by hardware such as a logic circuit.

[0143] Furthermore, the technical elements described in this specification or drawings may exhibit technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Furthermore, the technologies illustrated in this specification or drawings simultaneously achieve multiple objectives, and achieving one of those objectives is itself technically useful. The following is what was stated in the specification at the time of filing. In response to the establishment of an NFC connection between a first device and a second device, there are situations in which wireless communication according to the DPP method should be performed, and there are also situations in which wireless communication according to a connection method other than the DPP method should be performed. The following is a description corresponding to the claims at the time of filing. (Item 1) A communication device, a first wireless interface; one or more wireless interfaces different from the first wireless interface; a first supply unit that supplies a first public key, which is a public key of the communication device, and identification information to the first wireless interface, wherein when a first wireless connection is established between the communication device and a first external device via the first wireless interface, the first public key and the identification information are transmitted to the first external device via the first wireless interface, using the first wireless connection, the first public key is used to establish a second wireless connection between the communication device and a second external device via a second wireless interface of the one or more wireless interfaces according to a first connection method, and the identification information is used to establish a third wireless connection between the communication device and the first external device via a third wireless interface of the one or more wireless interfaces according to a second connection method different from the first connection method; an authentication response transmission unit that, when a first authentication request using the first public key is received from the first external device via the second wireless interface after the first public key and the identification information are transmitted to the first external device, transmits a first authentication response that is a response to the first authentication request to the first external device via the second wireless interface; a connection information receiving unit that receives first connection information from the first external device via the second wireless interface after the first authentication response is transmitted to the first external device, the first connection information being information for establishing the second wireless connection between the communication device and the second external device via the second wireless interface; a first establishment unit that, when the first connection information is received from the first external device, establishes the second wireless connection between the communication device and the second external device via the second wireless interface by using the first connection information; a second establishment unit that establishes the third wireless connection between the communication device and the first external device via the third wireless interface when a specific signal including the specific information is received from the first external device via the third wireless interface after the first public key and the specific information are transmitted to the first external device; A communication device comprising: (Item 2) the second external device is a different access point from the first external device; The communication device described in item 1, wherein when the first connection information is received from the first external device, the first establishment unit uses the first connection information to establish the second wireless connection between the communication device and the second external device, which is the access point, via the second wireless interface, and participates as a slave station in a wireless network in which the second external device operates as a master station. (Item 3) The communication device further comprises: 3. The communication device according to claim 1, further comprising a data communication unit that, when the third wireless connection is established between the communication device and the first external device, uses the third wireless connection to communicate target data with the first external device without going through an access point. (Item 4) the first providing unit provides the first public key and the identification information to the first wireless interface when the first wireless connection is established between the communication device and the first external device in a situation where a wireless connection via the second wireless interface is not established between the communication device and an access point; A communication device described in any one of items 1 to 3, wherein when the first wireless connection is established between the communication device and the first external device while the wireless connection via the second wireless interface is established between the communication device and the access point, the first public key is not provided to the first wireless interface. (Item 5) The communication device further comprises: a mode transition unit that transitions the operation mode of the communication device from a first mode to a second mode when a transition instruction for transitioning the operation mode of the communication device is received from a user in a situation where the wireless connection via the second wireless interface is established between the communication device and the access point, the first mode being a mode in which the second wireless connection cannot be established between the communication device and the second external device according to the first connection method, and the second mode being a mode in which the second wireless connection can be established between the communication device and the second external device according to the first connection method; when the wireless connection is established between the communication device and the first external device via the second wireless interface and the operation mode of the communication device is the first mode, the first public key is not provided to the first wireless interface; The communication device described in item 4, wherein the first supply unit supplies the first public key and the identification information to the first wireless interface when the first wireless connection is established between the communication device and the first external device in a situation where the wireless connection is established between the communication device and the access point via the second wireless interface and the operating mode of the communication device is the second mode. (Item 6) The communication device further comprises: 6. The communication device according to item 4 or 5, further comprising: a second supply unit that supplies the identification information and judgment information for determining whether the communication device and the first external device can communicate via the access point to the first wireless interface when the first wireless connection is established between the communication device and the first external device in a situation where the wireless connection via the second wireless interface is established between the communication device and the access point, and the identification information and the judgment information are transmitted to the first external device via the first wireless interface using the first wireless connection. (Item 7) the first providing unit provides the first public key and the identification information to the first wireless interface when the first wireless connection is established between the communication device and the first external device in a situation where a wireless connection via the second wireless interface is not established between the communication device and an access point; when the first wireless connection is established between the communication device and the first external device in a situation where the wireless connection via the second wireless interface is established between the communication device and the access point, the first public key and the identification information are not supplied to the first wireless interface; The communication device further comprises: a public key receiving unit that receives, when the first wireless connection is established between the communication device and the first external device in a state where the wireless connection via the second wireless interface is established between the communication device and the access point, a second public key that is a public key of the first external device from the first external device via the first wireless interface using the first wireless connection; an authentication request sending unit that, when the second public key is received from the first external device, sends a second authentication request using the second public key to the first external device via the second wireless interface; an authentication response receiving unit that receives, after the second authentication request is transmitted to the first external device, a second authentication response that is a response to the second authentication request from the first external device via the second wireless interface; a connection information transmitting unit that transmits second connection information to the first external device via the second wireless interface when the second authentication response is received from the first external device, the second connection information being information for establishing a wireless connection between the first external device and the access point; 4. The communication device according to any one of items 1 to 3, comprising: (Item 8) The communication device further comprises: a first state transition unit that transitions an operation state of the communication device from an unavailable state to an available state after the first public key and the identification information are supplied to the first wireless interface, the unavailable state being a state in which the communication device does not transmit the first authentication response to the first external device even if the first authentication request is received from the first external device, and the available state being a state in which the communication device transmits the first authentication response to the first external device in response to receiving the first authentication request from the first external device; the authentication response transmission unit, when receiving the first authentication request from the first external device after the operation state of the communication device has transitioned from the disabled state to the enabled state, transmits the first authentication response to the first external device via the second wireless interface; The communication device further comprises: 8. The communication device according to any one of items 1 to 7, further comprising a second state transition unit that transitions the operating state of the communication device from the possible state to the impossible state when the third wireless connection is established between the communication device and the first external device. (Item 9) 1. A computer program for a communication device, comprising: The communication device a first wireless interface; one or more wireless interfaces different from the first wireless interface; a computer; The computer program controls the computer to operate as follows: a first supply unit that supplies a first public key, which is a public key of the communication device, and identification information to the first wireless interface, wherein when a first wireless connection is established between the communication device and a first external device via the first wireless interface, the first public key and the identification information are transmitted to the first external device via the first wireless interface, using the first wireless connection, the first public key is used to establish a second wireless connection between the communication device and a second external device via a second wireless interface of the one or more wireless interfaces according to a first connection method, and the identification information is used to establish a third wireless connection between the communication device and the first external device via a third wireless interface of the one or more wireless interfaces according to a second connection method different from the first connection method; an authentication response transmission unit that, when a first authentication request using the first public key is received from the first external device via the second wireless interface after the first public key and the identification information are transmitted to the first external device, transmits a first authentication response that is a response to the first authentication request to the first external device via the second wireless interface; a connection information receiving unit that receives first connection information from the first external device via the second wireless interface after the first authentication response is transmitted to the first external device, the first connection information being information for establishing the second wireless connection between the communication device and the second external device via the second wireless interface; a first establishment unit that, when the first connection information is received from the first external device, establishes the second wireless connection between the communication device and the second external device via the second wireless interface by using the first connection information; a second establishment unit that establishes the third wireless connection between the communication device and the first external device via the third wireless interface when a specific signal including the specific information is received from the first external device via the third wireless interface after the first public key and the specific information are transmitted to the first external device; A computer program that functions as a (Item 10) A computer program for a first external device, comprising: The first external device is a first wireless interface; one or more wireless interfaces different from the first wireless interface; a computer; The computer program controls the computer to operate as follows: a receiving unit that receives a public key and identification information of the communication device from the communication device via the first wireless interface using the first wireless connection when a first wireless connection is established between the communication device and the first external device via the first wireless interface, the public key being used to establish a second wireless connection between the communication device and a second external device according to a first connection method, and the identification information being used to establish a third wireless connection between the communication device and the first external device via a third wireless interface among the one or more wireless interfaces according to a second connection method different from the first connection method; a determination unit that determines whether the second wireless connection or the third wireless connection should be established when the public key and the identification information are received from the communication device; an authentication request sending unit that sends an authentication request using the public key to the communication device via a second wireless interface among the one or more wireless interfaces when it is determined that the second wireless connection should be established; an authentication response receiving unit that receives, when the authentication request is transmitted to the communication device, an authentication response that is a response to the authentication request from the communication device via the second wireless interface; a connection information transmitting unit that transmits connection information to the communication device via the second wireless interface when the authentication response is received from the communication device, the connection information being information for establishing the second wireless connection between the communication device and the second external device, and in the communication device, when the connection information is received from the first external device, the connection information transmitting unit uses the connection information to establish the second wireless connection between the communication device and the second external device; a specific signal transmitting unit that transmits a specific signal including the specific information to the communication device via the third wireless interface when it is determined that the third wireless connection should be established; an establishment unit that establishes the third wireless connection between the communication device and the first external device via the third wireless interface after the specific signal is transmitted to the communication device; A computer program that functions as a (Item 11) The computer program further causes the computer to: when the public key and the identification information are received from the communication device, functioning as a display control unit that displays a selection screen on a display unit of the first external device to allow a user to select one of the first connection method and the second connection method; The determination unit determining that the second wireless connection should be established when the first connection method is selected by the user on the selection screen; Item 11. The computer program according to item 10, which determines that the third wireless connection should be established when the second connection method is selected by the user on the selection screen. [Explanation of symbols]

[0144] 2: Communication system, 6: AP, 10: Terminal, 12,112: Operation unit, 14,114: Display unit, 16,116: Wi-Fi I / F, 18,118: NFC I / F, 30,130: Control unit, 32,132: CPU, 34,134: Memory, 36: OS program, 38: Connection application, 100: Printer, 120: Print execution unit, 136: Program, 138: WFD flag

Claims

1. A communication device, an output unit; one or more wireless interfaces; a first output control unit that causes the output unit to output the public key and the specific information; a first establishing unit that, when a first authentication request using the public key is received from the first external device via a first wireless interface among the one or more wireless interfaces after the public key and the identification information are output and acquired by a first external device, establishes a first wireless connection between the communication device and a second external device via the first wireless interface in accordance with a DPP (abbreviation of Device Provisioning Protocol) method; a second establishment unit that, when a specific signal using the specific information is received from the first external device via a second wireless interface among the one or more wireless interfaces after the public key and the specific information are output and acquired by the first external device, establishes a second wireless connection between the communication device and the first external device via the second wireless interface in accordance with a method different from the DPP method; A communication device comprising:

2. the second external device is a different access point from the first external device; 2. The communication device according to claim 1, wherein the first establishment unit establishes the first wireless connection between the communication device and the second external device, which is the access point, via the first wireless interface, and participates as a slave station in a wireless network in which the second external device operates as a master station.

3. The communication device further comprises:

3. The communication device according to claim 1, further comprising a data communication unit that, when the second wireless connection is established between the communication device and the first external device, uses the second wireless connection to communicate target data with the first external device without going through an access point.

4. the first output control unit causes the output unit to output the public key and the specific information when a specific situation occurs in which the public key and the specific information should be output by the output unit in a situation in which a wireless connection via the first wireless interface is not established between the communication device and an access point; 4. The communication device according to claim 1, wherein the public key is not output even when the specific situation occurs when the wireless connection is established between the communication device and the access point via the first wireless interface.

5. The communication device further comprises: a mode transition unit that transitions the operation mode of the communication device from a first mode to a second mode when a transition instruction for transitioning the operation mode of the communication device is received from a user in a situation where the wireless connection via the first wireless interface is established between the communication device and the access point, the first mode being a mode in which the first wireless connection cannot be established between the communication device and the second external device according to the DPP method, and the second mode being a mode in which the first wireless connection can be established between the communication device and the second external device according to the DPP method; when the wireless connection is established between the communication device and the access point via the first wireless interface and the operation mode of the communication device is the first mode, the public key is not output even when the specific situation occurs; The communication device described in claim 4, wherein the first output control unit causes the output unit to output the public key and the specific information when the specific situation occurs in a situation where the wireless connection via the first wireless interface is established between the communication device and the access point and the operating mode of the communication device is the second mode.

6. The communication device further comprises:

6. The communication device according to claim 4, further comprising a second output control unit that causes the output unit to output the specific information and judgment information for determining whether the communication device and the first external device can communicate via the access point when the specific situation occurs in a situation where the wireless connection via the first wireless interface is established between the communication device and the access point.

7. The communication device further comprises: an authentication response transmitting unit that, when the first authentication request is received from the first external device via the first wireless interface after the public key and the identification information are output and acquired by the first external device, transmits a first authentication response that is a response to the first authentication request to the first external device via the first wireless interface; a first state transition unit that transitions an operation state of the communication device from an incapable state to a capable state after the public key and the specific information are output, the incapable state being a state in which the communication device does not transmit the first authentication response to the first external device even if the first authentication request is received from the first external device, and the capable state being a state in which the communication device transmits the first authentication response to the first external device in response to receiving the first authentication request from the first external device; the authentication response transmission unit, when receiving the first authentication request from the first external device after the operation state of the communication device has transitioned from the disabled state to the enabled state, transmits the first authentication response to the first external device via the first wireless interface; The communication device further comprises:

7. The communication device according to claim 1, further comprising a second state transition unit that transitions the operating state of the communication device from the possible state to the impossible state when the second wireless connection is established between the communication device and the first external device.

8. 1. A computer program for a communication device, comprising: The communication device an output unit; one or more wireless interfaces; a computer; The computer program controls the computer to operate as follows: an output control unit that causes the output unit to output the public key and the specific information; a first establishing unit that, when a first authentication request using the public key is received from the first external device via a first wireless interface among the one or more wireless interfaces after the public key and the identification information are output and acquired by a first external device, establishes a first wireless connection between the communication device and a second external device via the first wireless interface in accordance with a DPP (abbreviation of Device Provisioning Protocol) method; a second establishment unit that, when a specific signal using the specific information is received from the first external device via a second wireless interface among the one or more wireless interfaces after the public key and the specific information are output and acquired by the first external device, establishes a second wireless connection between the communication device and the first external device via the second wireless interface in accordance with a method different from the DPP method; A computer program that functions as a

9. A computer program for a first external device, comprising: The first external device is one or more wireless interfaces; a computer; The computer program controls the computer to operate as follows: an acquisition unit that acquires a public key and specific information from a communication device; a determination unit that determines which of a first wireless connection and a second wireless connection should be established when the public key and the specific information are acquired, the first wireless connection being a wireless connection established between the communication device and a second external device in accordance with a DPP (abbreviation of Device Provisioning Protocol) method, and the second wireless connection being a wireless connection established between the communication device and the first external device in accordance with a method different from the DPP method; an authentication request transmission unit that transmits an authentication request using the public key to the communication device via a first wireless interface among the one or more wireless interfaces when it is determined that the first wireless connection should be established, and when the authentication request is received from the first external device, the communication device establishes the first wireless connection between the communication device and the second external device in accordance with the DPP method; a specific signal transmitting unit that transmits a specific signal using the specific information to the communication device via a second wireless interface among the one or more wireless interfaces when it is determined that the second wireless connection should be established; an establishment unit that establishes the second wireless connection between the communication device and the first external device via the second wireless interface in accordance with the different scheme after the specific signal is transmitted to the communication device; A computer program that functions as a

10. The computer program further causes the computer to: When the public key and the specific information are acquired, the first external device functions as a display control unit that displays a selection screen on a display unit of the first external device to allow a user to select one of the DPP method and the different method; The determination unit determining that the first wireless connection should be established when the DPP method is selected by the user on the selection screen; The computer program product according to claim 9 , wherein the computer program determines that the second wireless connection should be established if the different method is selected by the user on the selection screen.

Citation Information

Patent Citations

  • Communication device and computer program for communication device

    JP2017034613A

  • Communication device, communication method and program

    JP2017135517A

  • Communication apparatus, control method for communication apparatus, and program

    JP2018042057A