Communication device, control method, and program
The communication device ensures consistent authentication levels by enabling direct communication only when the access point connection method is compatible, addressing potential security gaps in multi-connection scenarios.
Patent Information
- Application Number
- JP2021201990
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-13
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2041-12-13
AI Technical Summary
There is a possibility of a difference in authentication level between a connection side that does not connect via an access point and a connection side that connects via an access point, leading to potential security vulnerabilities.
A communication device that enables a predetermined mode for direct communication between the device and an information processing device without an access point, while preventing this mode when an authentication method used for the connection with the access point is not compatible, ensuring consistent authentication levels across different connection types.
Prevents discrepancies in authentication levels between direct and access point-based connections, enhancing security by maintaining consistent authorization standards.
Smart Images

Figure 0007752524000001 
Figure 0007752524000002 
Figure 0007752524000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a communication device capable of communicating with an external device that requires authentication, a control method, and a program. [Background technology]
[0002] In recent years, an increasing number of printing devices, such as multifunction peripherals and printers, are equipped with wireless LAN functionality. These printing devices can communicate via wireless LAN with information processing devices, such as mobile phones and personal computers operated by users, and print the received print data. The printing device and the information processing device are connected via an infrastructure connection (infrastructure connection), which communicates via a wireless LAN access point, or a wireless direct connection (direct connection), which communicates directly via wireless LAN without going through a relay device such as an access point. Furthermore, some printing devices can simultaneously execute both an infrastructure connection and a direct connection, as described in Patent Document 1.
[0003] These information processing devices, printing devices, and access points can be interconnected by operating in accordance with the IEEE802.11 standard, and only devices that are authorized by authentication processing within the wireless connection procedure can connect.
[0004] Wireless LAN authentication methods include the PSK method, which uses a pre-shared key, and the SAE (Simultaneous Authentication of Equals) method, which uses SAE. Furthermore, there is the EAP method, which is compatible with both wireless and wired LANs and uses an IEEE802.1X / EAP-compatible authentication server to authenticate communication devices connecting to the network.
[0005] In addition to the authentication process during the wireless connection procedure described above, authentication is also performed between the information processing device and the printing device during communication after the wireless connection is established. Patent Document 2 describes that authentication is performed before the printing process so that only permitted printing processes can be executed, and that whether or not to execute authentication can be switched by user settings. This prevents printing through unauthorized access by performing authentication at the application level for printing processes, separate from authentication processing during wireless connection. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2017-87506 [Patent Document 2] Japanese Patent Application Laid-Open No. 2017-7112 Summary of the Invention [Problem to be solved by the invention]
[0007] When a communication device is capable of simultaneously connecting via an access point and connecting without an access point, and the connecting side via the access point operates using an authentication method that requires an authentication server, there is a possibility that a difference in authentication level will occur between the two connecting sides.
[0008] An object of the present invention is to provide a communication device, a control method, and a program that prevent a difference in authentication level from occurring between a connection side that does not connect via an access point and a connection side that connects via an access point. [Means for solving the problem]
[0009] In order to solve the above problem, a communication device according to the present invention is a communication device capable of communicating with an information processing device and an access point, the communication device comprising: an establishment unit for establishing a connection between the access point and the communication device; a first accepting means for accepting a predetermined request to enable, in the communication device, a predetermined mode for communicating directly between the communication device and the information processing device without going through the access point; a first enabling means for enabling, in the communication device, the predetermined mode based on the acceptance of the predetermined request, when a connection between the communication device and the access point has been established and an authentication method used for the connection between the communication device and the access point is not the predetermined authentication method; and a control means for executing predetermined control to prevent the predetermined mode from being enabled in the communication device, when a connection between the communication device and the access point has been established and an authentication method used for the connection between the communication device and the access point is the predetermined authentication method. The present invention is characterized by having the following. [Effects of the Invention]
[0010] According to the present invention, it is possible to prevent a difference in authentication level between a connection side not via an access point and a connection side via an access point. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a diagram illustrating a system configuration. [Figure 2] FIG. 2 is a diagram showing the external configuration of an MFP. [Figure 3] FIG. 2 is a block diagram showing the configuration of an MFP. [Figure 4] FIG. 2 is a diagram illustrating a configuration of an operation display unit of an MFP. [Figure 5] FIG. 1 is a diagram illustrating an external configuration of an information processing apparatus. [Figure 6] FIG. 1 is a diagram illustrating a configuration of an information processing device. [Figure 7] FIG. 2 is a block diagram showing the configuration of an access point. [Figure 8] FIG. 2 is a diagram illustrating a configuration of an authentication server. [Figure 9] 10 is a flowchart showing an outline of a process for connecting an MFP to a network configured by an access point. [Figure 10] FIG. 1 is a diagram illustrating a network between devices. [Figure 11] 10A to 10C are diagrams for explaining screen transitions on the operation display unit of the MFP. [Figure 12] FIG. 2 is a diagram illustrating screen transitions in the information processing device. [Figure 13] 10 is a flowchart showing a process for connecting an MFP to a network configured by an access point. [Figure 14] 10 is a flowchart showing a process when a request to enable Wireless Direct mode is received. [Figure 15] 10 is a flowchart showing a process when a request to enable wireless infrastructure mode is received. [Figure 16] 10 is a flowchart showing a process for connecting an MFP to a network configured by an access point. [Figure 17] 10 is a flowchart showing a process when a request to enable Wireless Direct mode is received. [Figure 18] 10 is a flowchart showing a process when a request to enable wireless infrastructure mode is received. [Figure 19] 10 is a flowchart showing processing in the MFP. [Figure 20] 10 is a flowchart showing processing in the MFP. [Figure 21] 10 is a flowchart showing processing in the MFP. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention claimed. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.
[0013] [First embodiment] Fig. 1 is a diagram showing an example of a system configuration in this embodiment. The communication system 100 is a communication system in which a plurality of communication devices can wirelessly communicate with each other. As shown in Fig. 1, the communication system 100 includes, as communication devices, an information processing device 200, an MFP (Multi Function Peripheral) 300, an access point (AP) 400, and an authentication server 500. In the communication system 100, the information processing device 200 and the MFP 300 can execute processing corresponding to a printing service, for example, using wireless LAN communication.
[0014] The information processing device 200 is an information processing device having a communication function such as a wireless LAN or a wired LAN. Note that a wireless LAN may also be called a WLAN (Wireless LAN). For example, a smartphone, a laptop PC, a tablet terminal, or a PDA (Personal Digital Assistant) may be used as the information processing device 200.
[0015] The MFP 300 is an example of a printing device having a printing function. The MFP 300 may also have a reading function (scanner), a fax function, or a telephone function. The MFP 300 also has a communication function that enables wireless communication with the information processing device 200. In this embodiment, the MFP 300 is described, but devices of different types from the MFP 300 may also be used. For example, devices having a communication function, such as a facsimile machine, a scanner, a projector, a mobile terminal, a smartphone, a laptop PC, a tablet terminal, a PDA, a digital camera, a music playback device, a television, a smart speaker, or AR glasses, may also be used.
[0016] The access point 400 is a communication device that is provided separately (externally) from the information processing device 200 and the MFP 300 and operates as a WLAN base station device. The access point 400 may also be referred to as an external access point 400 or an external wireless base station. A communication device having a WLAN communication function can communicate in WLAN infrastructure mode via the access point 400. The wireless infrastructure mode may also be referred to as a "wireless infrastructure mode." In other words, the wireless infrastructure mode is a mode in which a communication device communicates with the information processing device 200 via the access point 400 to which the communication device is connected. The access point 400 communicates with a communication device that has been authorized (authenticated) to connect to the access point 400 and relays wireless communications between the communication device and other communication devices. The access point 400 is also connected to a wired LAN communication network and relays communications between a communication device connected to the network and other communication devices wirelessly connected to the access point 400. Furthermore, if the authentication method of the network formed by the access point 400 is a method that uses an authentication server (if the access point 400 is compatible with the authentication method that uses an authentication server), the access point 400 cooperates with the authentication server 500 to authenticate communication devices that connect to the network, thereby performing access control. Communication devices that connect to the network formed by the access point 400 are restricted from communicating with devices other than the authentication server 500 until they are authenticated. Note that the access point 400 may also be compatible with an authentication method that does not use an authentication server. Details of authentication methods that use an authentication server and authentication methods that do not use an authentication server will be described later.
[0017] The authentication server 500 is a communication device that is provided separately (externally) from the information processing device 200, the MFP 300, and the access point 400, and operates as an authentication server that collectively manages authentication information. The authentication server 500 authenticates the terminals that are the subject of authentication in cooperation with the access point 400, and controls access to the terminals based on the authentication results. The authentication server 500 is configured to be able to execute authentication processing that complies with, for example, the IEEE 802.1X standard.
[0018] The access point 400 corresponds to an authenticator in IEEE802.1X. The information processing device 200 and the MFP 300 correspond to a supplicant in IEEE802.1X. The authentication server may be called a "RADIUS server."
[0019] The authentication server 500 performs authentication using, for example, the EAP-TLS method, the EAP-TTLS method, and the PEAP method in accordance with the IEEE 802.1X standard. The EAP-TLS (EAP-Transport Layer Security) method is an authentication method that uses the TLS handshake protocol, and authentication is performed using a server certificate and a client certificate. The EAP-TTLS (EAP-Tunneled TLS) method is an authentication method that uses the TLS handshake protocol, and authentication is performed using a server certificate, a user name, and a password. The PEAP (Protected EAP) method is an authentication method that uses a user name and a password. Note that the information used for these IEEE 802.1X authentication methods may be collectively referred to as "authentication information."
[0020] Using their respective WLAN communication functions, the information processing device 200 and the MFP 300 can perform wireless communication in wireless infrastructure mode via an external access point 400 or in peer-to-peer mode without the external access point 400. Note that peer-to-peer mode is sometimes called "P2P mode" or "wireless direct mode" in contrast to wireless infrastructure mode. In other words, P2P mode is a mode in which a communication device communicates directly with the information processing device 200 without the access point 400. P2P mode includes Wi-Fi Direct (registered trademark) mode and software access point (soft AP) mode. Note that Wi-Fi Direct (registered trademark) is sometimes referred to as WFD. In other words, wireless direct mode can be considered a communication mode compliant with the IEEE 802.11 series.
[0021] 2 is a diagram showing an example of the external configuration of MFP 300. Power button 301 is a hardware key that allows the user to turn the power on and off. Operation display unit 302 includes a display and buttons that the user uses when operating MFP 300. Operation display unit 302 includes keys such as character input keys, cursor keys, a confirm key, and a cancel key, as well as an LED (Light Emitting Diode) and an LCD (Liquid Crystal Display). Operation display unit 302 is configured to be able to accept operation inputs from the user when starting individual functions of MFP 300, changing various settings, etc. Furthermore, operation display unit 302 may be configured to include a touch panel display.
[0022] Print paper insertion slot 303 is an insertion slot that can accommodate paper of various sizes. Paper inserted into print paper insertion slot 303 is transported one sheet at a time to the printing section, where the desired printing is performed and the paper is ejected from print paper ejection slot 304. Document table 305 is a transparent glass table that is used when the inserted document is read by the scanner. Document lid 306 is a cover that presses the document against the document table to prevent it from floating when being read by the scanner, and also prevents external light from entering the scanner unit.
[0023] The MFP 300 has a communication function using WLAN or wired LAN, and includes a wireless communication unit 307 and a wired communication unit 321, each of which includes an antenna for wireless communication. Note that the wireless communication unit 307 and the wired communication unit 321 do not necessarily have to be configured to be visible from the outside. The USB communication unit 308 includes a circuit and a USB connector that enable the MFP 300 to communicate with an external information processing device 200 or the like via a USB connection. The power supply unit 309 is connected to an external power supply and supplies power to the MFP 300.
[0024] 3 is a block diagram showing an example of the configuration of an MFP 300. The MFP 300 has a main board 310 that controls the entire device, a power button 301, an operation display unit 302, a wireless communication unit 307, a wired communication unit 320, a USB communication unit 308, and a power supply unit 309.
[0025] The main board 310 is provided with a microprocessor-type CPU 311. The CPU 311 controls the MFP 300 in accordance with a control program stored in a ROM-type program memory 313 connected via an internal bus 312 and the contents stored in a RAM-type data memory 314. The operation of the MFP 300 described in this embodiment is realized, for example, by the CPU 311 reading and executing the program stored in the program memory 313. The CPU 311 controls the scan unit 317 to scan an original and store the scanned data in an image memory 315 in the data memory 314. The CPU 311 controls the print unit 316 to print an image of the scanned data stored in the image memory 315 in the data memory 314 on a recording medium. The CPU 311 controls the USB communication unit 308 via a USB communication control unit 320 to perform USB communication with the external information processing device 200 via a USB connection. The CPU 311 controls the operation control unit 319 to receive operation information from the power button 301 and the operation display unit 302. The CPU 311 controls the operation control unit 319 to, for example, display the status of the MFP 300 and a function selection menu on the operation display unit 302. The CPU 311 controls the wireless communication unit 307 and the wired communication unit 320 via the communication control unit 318 in accordance with operation information received by the operation display unit 302. The CPU 311 changes the settings of the communication method and sets up a connection to a network in accordance with the operation information, for example.
[0026] The wireless communication unit 307 is a unit capable of providing WLAN communication functions. That is, the wireless communication unit 307 converts data into packets in accordance with the WLAN standard and transmits the packets to other communication devices. The wireless communication unit 307 also restores packets from other external communication devices to the original data and outputs the data to the CPU 311. The wireless communication unit 307 is configured to be able to perform data (packet) communication in a WLAN system conforming to, for example, the IEEE 802.11 standard series (IEEE 802.11a / b / g / n / ac / ax, etc.). However, this configuration is not limited, and the wireless communication unit 307 may be capable of performing communication in a WLAN system conforming to other standards. In this embodiment, the wireless communication unit 307 is capable of communication in both the 2.4 GHz band and the 5 GHz band. The wireless communication unit 307 is also capable of communication in WFD mode, soft AP mode, wireless infrastructure mode, etc. The information processing device 200 and the MFP 300 are capable of wireless communication based on the WFD mode, and the wireless communication unit 307 has a soft AP function or a group owner function. That is, the wireless communication unit 307 can build a communication network in the P2P mode and determine a channel to be used for communication in the P2P mode.
[0027] The wired communication unit 321 is a unit for performing wired communication. The wired communication unit 321 is capable of data (packet) communication in a wired LAN (Ethernet) system conforming to, for example, the IEEE802.3 series. Furthermore, in wired communication using the wired communication unit 321, communication in a wired communication mode is possible. The wired communication unit 321 is connected to the main board 310 via a bus cable or the like.
[0028] FIG. 4 is a diagram schematically illustrating an example of the configuration of the operation / display unit 302 of the MFP 300. FIG. 4(a) illustrates an example of the operation / display unit 302 configured with a touch panel display 331. The user presses the power button 301 to power on the MFP 300. When the MFP 300 is powered on, the touch panel display 331 displays a home screen, which is the highest level of menus that the user can operate. The home screen includes a copy area 335 for receiving an instruction to execute a copy process, a scan area 336 for receiving an instruction to execute a scan process, and a print area 337 for receiving an instruction to execute a print process. The home screen also includes a status display area 332 that displays the settings for connection in wireless infrastructure mode and wireless direct mode of the MFP 300 and the connection status of those modes. The home screen also includes a connection setting mode area 333 that allows the user to start operation in the connection setting mode at any time, and a setting area 334 that allows the user to change various settings.
[0029] FIG. 4B shows an example of an operation display unit 302 configured with a relatively small LCD display 341 and various hard keys 344 to 351. When a user presses the power button 301, the MFP 300 is powered on. When the MFP 300 is powered on, a home screen, which is the highest level of menus that the user can operate, is displayed on the LCD display 341. The user can operate a cursor displayed on the LCD display 341 by pressing cursor movement buttons 346 and 347. The user presses an OK button 349 to execute an operation, or a back button 348 to return to the previous menu screen. When a user presses the QR button 344, a QR code containing information required for a direct connection with the MFP 300 is displayed. When the displayed QR code (registered trademark) is read by the information processing device 200, a direct connection is established between the information processing device 200 and the MFP 300, enabling wireless communication between them. The code displayed here is not limited to a QR code and may be any two-dimensional code. Furthermore, when the user presses connection setting mode button 345, it becomes possible to start connection setting mode. In connection setting mode, connection information can be sent from information processing device 200 to MFP 300, thereby connecting MFP 300 to access point 400. When the user presses stop button 350 while MFP 300 is executing a process, that process is canceled. When the user presses copy start button 351, the document placed on document platen 305 is scanned and printing is executed.
[0030] FIG. 4( c) shows an example of an operation display unit 302 configured with a relatively small LCD display 361 and various hard keys 363 to 370. When a user presses the power button 301, the MFP 300 is powered on. When the MFP 300 is powered on, a home screen, which is the highest level of a menu that the user can operate, is displayed on the LCD display 361. The user can operate items displayed on the LCD display 361 by pressing the navigation buttons 364 and 365. The user presses the OK button 367 to execute an operation, or the back button 366 to return to the previous menu screen. Furthermore, when the user presses the connection setting mode button 363, the connection setting mode can be started. In the connection setting mode, the MFP 300 can be connected to the access point 400 by transmitting connection information from the information processing device 200 to the MFP 300. When the user presses the stop button 368 while the MFP 300 is executing a process, the process is canceled. When the user presses the copy start button 369, the document placed on the document table 305 is scanned and printed. When the user presses the setting button 370, the user can change various settings.
[0031] FIG. 5 is a diagram illustrating an example of the external configuration of the information processing device 200. In this embodiment, the information processing device 200 will be described as a typical smartphone (mobile terminal). The information processing device 200 includes, for example, a display unit 202, an operation unit 203, and a power key 204. The display unit 202 is, for example, a display including a liquid crystal display (LCD) type display mechanism. The display unit 202 may display information using, for example, an LED (light emitting diode). The information processing device 200 may have a speaker function that outputs information by voice in addition to or instead of the display unit 202. The operation unit 203 includes hard keys such as keys and buttons, a touch panel, and the like for detecting user operations. In this embodiment, the display of information on the display unit 202 and the reception of user operations by the operation unit 203 are performed using a common touch panel display, and therefore the display unit 202 and the operation unit 203 are implemented by a single device. In this case, for example, button icons and a software keyboard are displayed using the display function of the display unit 202, and the touch of the user on those locations is detected by the operation reception function of the operation unit 203. Note that the display unit 202 and the operation unit 203 may be separated, and hardware for display and hardware for operation reception may be configured separately. The power key 204 is a hardware key for receiving a user operation to turn on or off the power of the information processing device 200.
[0032] The information processing device 200 includes a wireless communication unit 201 that provides a WLAN communication function, as shown in FIG. 6. The wireless communication unit 201 is configured to be able to perform data (packet) communication in a WLAN system that complies with, for example, the IEEE 802.11 standard series (IEEE 802.11a / b / g / n / ac / ax, etc.). However, the present invention is not limited to this, and the wireless communication unit 201 may be able to perform communication in a WLAN system that complies with other standards. In this embodiment, the wireless communication unit 201 is capable of communication in both the 2.4 GHz and 5 GHz frequency bands. The wireless communication unit 201 is also capable of communication in WFD mode, soft AP mode, wireless infrastructure mode, etc.
[0033] FIG. 6 is a diagram illustrating an example of the configuration of an information processing device 200. The information processing device 200 includes a main board 211 that controls the entire device, a wireless communication unit 201 that performs WLAN communication, a display unit 202, an operation unit 203, and a short-range wireless communication unit 205 that performs wireless communication different from that of the wireless communication unit 201. The main board 211 includes, for example, a CPU 212, a ROM 213, a RAM 214, an image memory 215, a data conversion unit 216, a telephone unit 217, a GPS 219, a camera unit 221, a non-volatile memory 222, a data storage unit 223, a speaker unit 224, and a power supply unit 225. GPS is an abbreviation for Global Positioning System. The functional units within the main board 211 are interconnected via a system bus 228. The main board 211 and the wireless communication unit 201, and the main board 211 and the short-range wireless communication unit 205 are connected, for example, via dedicated buses. The main board 211 and the display unit 202, and the main board 211 and the operation unit 203 are connected via dedicated buses, for example.
[0034] The CPU 212 is a system control unit and controls the entire information processing device 200. The operation of the information processing device 200 described in this embodiment is realized, for example, by the CPU 212 reading and executing programs stored in the ROM 213. Dedicated hardware for each process may be provided. The ROM 213 stores control programs executed by the CPU 212, an embedded operating system (OS) program, and the like. The CPU 212 executes each control program stored in the ROM 213 under the management of the embedded OS stored in the ROM 213, thereby performing software control such as scheduling and task switching. The RAM 214 is configured with an SRAM (Static RAM) or the like. The RAM 214 stores data such as program control variables, setting values registered by the user, and management data for the information processing device 200. The RAM 214 may also be used as a buffer for various work tasks. The image memory 215 is configured with a memory such as a DRAM (Dynamic RAM). The image memory 215 temporarily stores image data received via the wireless communication unit 201 and image data read from the data storage unit 223 for processing by the CPU 212. The non-volatile memory 222 is configured by a memory such as a flash memory, and continues to store data even when the information processing device 200 is powered off. The memory configuration of the information processing device 200 is not limited to the above-mentioned configuration. For example, the image memory 215 and the RAM 214 may be shared, or data may be backed up using the data storage unit 223. In addition, although the present embodiment uses a DRAM as an example of the image memory 215, other storage media such as a hard disk or a non-volatile memory may also be used.
[0035] The data conversion unit 216 analyzes data in various formats and performs data conversion such as color conversion and image conversion. The telephone unit 217 controls telephone lines and realizes telephone communication by processing audio data input and output via a speaker unit 224 including a microphone and speaker. The GPS 219 receives radio waves transmitted from satellites and acquires location information such as the current latitude and longitude of the information processing device 200. The camera unit 221 has the function of electronically recording and encoding images input through a lens. Image data obtained by capturing images using the camera unit 221 is stored in the data storage unit 223. The speaker unit 224 controls the input and output of audio for telephone functions and other functions such as alarm notification. The power supply unit 225 is, for example, a portable battery and controls the power supply to the device. The power supply states of the information processing device 200 include, for example, a dead battery state in which the battery has no remaining power, a power-off state in which the power key 204 is not pressed, a power-on state (started state) in which the power key 204 is pressed, and a power-save state in which the device is started but is in a power-save mode in which the power consumption of each element is suppressed. The display unit 202 electronically controls the display content and executes control for displaying various input contents, the operating status and status of the MFP 300, etc. Upon receiving a user operation, the operation unit 203 executes control for generating an electrical signal corresponding to the operation and outputting it to the CPU 212, etc.
[0036] The information processing device 200 performs wireless communication using the wireless communication unit 201, and performs data communication with other communication devices such as the MFP 300. The wireless communication unit 201 converts data into packets and transmits the packets to the other communication devices. The wireless communication unit 201 also restores packets from other external communication devices to the original data and outputs the data to the CPU 212. The wireless communication unit 201 is a unit for realizing communication in accordance with standards such as WLAN. The short-range wireless communication unit 205 communicates using a communication method different from that used by the wireless communication unit 201, such as Bluetooth (registered trademark). The configuration of the main board 211 is not limited to the above. For example, each function of the main board 211 implemented by the CPU 212 may be realized by a processing circuit such as an ASIC (application-specific integrated circuit), and may be realized by either hardware or software.
[0037] 7 is a block diagram showing an example of the configuration of an access point 400 having a wireless LAN access point function. The access point 400 includes a main board 410 that controls the access point 400, a wireless communication unit 420, a wired communication unit 421, and an operation button 422. These are connected via an internal bus 419 so that they can communicate with each other.
[0038] The main board 410 is provided with a microprocessor-type CPU 411. The CPU 411 operates according to a control program stored in a ROM-type program memory 412 and contents stored in a RAM-type data memory 413, both of which are connected via an internal bus 418. The operation of the access point 400 in this embodiment is realized, for example, by the CPU 411 reading and executing the program stored in the program memory 412. The CPU 411 controls a wireless communication unit 420 via a wireless communication control unit 414 to perform wireless LAN communication with other communication devices. The CPU 411 also controls a wired communication unit 421 via a wired communication control unit 415 to perform wired LAN communication with other communication devices. The CPU 411 accepts user operations using an operation button 422 via an operation unit control circuit 416.
[0039] The access point 400 includes a terminal access control unit 417. The terminal access control unit 417 protects the network by authenticating communication devices connecting to the network. The terminal access control unit 417 authenticates communication devices connecting to the network using various methods. Examples of the various methods include the PSK method using a pre-shared key, the SAE method using SAE (Simultaneous Authentication of Equals), and the EAP method using an authentication server 500 compatible with IEEE802.1X / EAP. The channel of communication authenticated in this manner can be changed or switched by a channel change unit 418. Note that in this embodiment, the authentication method that does not use an authentication server is the PSK method or the SAE method, and the authentication method that uses an authentication server is the EAP method. The authentication method that does not use an authentication server is also called the personal method, and the authentication method that uses an authentication server is also called the enterprise method.
[0040] 8 is a diagram showing an example of the configuration of the authentication server 500. The authentication server 500 has a main board 511 that controls the authentication server 500, a communication unit 501 that performs wired LAN communication and the like, a display unit 502, and an operation unit 503. The main board 511 includes a CPU 512, a ROM 513, a RAM 514, an image memory 515, a nonvolatile memory 516, a data storage unit 518, and a communication control unit 517. The functional units within the main board 511 are connected to each other via a system bus 519. The main board 511 and the communication unit 501, the main board 511 and the display unit 502, and the main board 511 and the operation unit 503 are connected, for example, via dedicated buses.
[0041] The CPU 512 is a system control unit and controls the entire authentication server 500. The operation of the authentication server 500 in this embodiment is realized, for example, by the CPU 512 reading and executing programs stored in the ROM 513. Dedicated hardware for each process may be provided. The ROM 513 stores control programs executed by the CPU 512, an embedded operating system (OS) program, and the like. The CPU 512 executes each control program stored in the ROM 513 under the management of the embedded OS stored in the ROM 513, thereby performing software control such as scheduling and task switching. The RAM 514 is configured with a static RAM (SRAM) or the like. The RAM 514 stores data such as program control variables, setting values registered by the user, and management data for the authentication server 500. The RAM 514 may also be used as a buffer for various work tasks. The image memory 515 is configured with a memory such as a dynamic RAM (DRAM). The image memory 515 temporarily stores image data received via the communication unit 501 and image data read from the data storage unit 518 for processing by the CPU 512. The data storage unit 518 is configured with a storage medium such as an SSD (Solid State Drive), and continues to store data even when the authentication server 500 is powered off. In this embodiment, an SSD is given as an example of the data storage unit 518, but other storage media such as a hard disk or non-volatile memory may also be used. The display unit 502 electronically controls the display content and executes control for displaying various input contents and status conditions, etc. The operation unit 503 executes control for generating an electrical signal corresponding to a user operation upon receiving the operation and outputting the signal to the CPU 512, etc.
[0042] The CPU 512 controls the communication control unit 517 to perform communication using the communication unit 501, and performs data communication with other communication devices such as the access point 400. The communication unit 501 converts data into packets and transmits the packets to other communication devices. The communication unit 501 also restores packets from other external communication devices to the original data and outputs the data to the CPU 512. The communication unit 501 is capable of data (packet) communication in a wired LAN (Ethernet) system that complies with, for example, the IEEE802.3 series.
[0043] The communication modes in which the communication devices in the communication system 100 can operate will be described below.
[0044] [Wireless Direct Mode] This section describes a communication method in wireless direct mode in WLAN communication, in which devices communicate directly with each other wirelessly without going through an external access point. Communication in wireless direct mode can be realized using a number of methods, and for example, a communication device selectively uses one of the wireless direct modes described above to perform communication in wireless direct mode. Note that communication in wireless direct mode may also be called "wireless direct communication" or "P2P communication."
[0045] For example, a communication device capable of performing Wireless Direct Communication is configured to support at least one of the Soft AP mode and the Wi-Fi Direct (WFD) mode. On the other hand, even a communication device capable of performing Wireless Direct Communication does not have to support all of these modes, and may be configured to support only some of them. In this embodiment, the communication device can also support the Wireless Infrastructure mode in addition to the Wireless Direct mode.
[0046] A communication device (e.g., information processing device 200) having a communication function in WFD mode accepts user operations via its operation unit and calls an application for realizing the communication function. Then, communication in WFD mode is performed based on the user operations accepted via a user interface screen provided by the application. Note that MFP 300 operating in P2P mode acts as a master device in connection and communication with other devices. Note that this is not limited to WFD mode, and MFP 300 may also act as a slave device by executing group owner negotiation.
[0047] [Wireless Infrastructure Mode] In contrast to the wireless direct mode, in the wireless infrastructure mode, communication devices that communicate with each other are connected to an external access point that manages the network, and communication between the communication devices is performed via the external access point. Here, the communication between the communication devices refers to, for example, the information processing device 200 and the MFP 300. In other words, communication between the communication devices is performed via a network established by the external access point. Furthermore, the MFP 300 operating in the wireless infrastructure mode acts as a slave (station) in connection and communication with the access point 400. In the wireless infrastructure mode, each communication device searches for an external access point by transmitting a device discovery request (Probe Request). When each communication device receives a device discovery response (Probe Response) from the external access point, it displays the SSID included in the Probe Response. For example, the information processing device 200 and the MFP 300 each discover the access point 400 and transmit a connection request to the access point 400 to connect, thereby enabling communication between these communication devices in the wireless infrastructure mode via the access point 400. Note that multiple communication devices may be connected to different access points. In this case, data transfer between each access point enables communication between communication devices. The commands and parameters transmitted and received during communication between each communication device via the access point are those specified in the Wi-Fi standard. In the above configuration, the access point 400 determines the frequency band and frequency channel. Therefore, the access point 400 selects which frequency band to use from 5 GHz and 2.4 GHz, and which frequency channel to use within that frequency band.
[0048] When the information processing device 200 or the MFP 300 connects to a wireless LAN configured by the access point 400, authentication is performed by the access point 400. The information processing device 200 or the MFP 300 can connect to the wireless LAN by being authenticated by the authentication method of the wireless LAN configured by the access point 400. The authentication method of the wireless LAN includes a PSK method using a pre-shared key, an SAE method using SAE, an EAP method using an authentication server compatible with IEEE802.1X / EAP, and the like.
[0049] [Wired communication mode] The wired communication mode is a communication mode for communication between communication devices via a wired LAN or the like. When the MFP 300 operates in the wired communication mode, it cannot operate in the wireless infrastructure mode. In the wired communication mode, data (packet) communication is performed over a wired LAN (Ethernet) conforming to the IEEE 802.3 series, for example. When the MFP 300 operates with the IEEE 802.1X / EAP setting enabled, authentication by IEEE 802.1X is performed when connecting to the wired LAN configured by the access point 400.
[0050] [Simultaneous wireless operation] When two modes of communication, namely, communication in wireless infrastructure mode and communication in wireless direct mode, are communication using authentication methods that do not use authentication server 500, MFP 300 can simultaneously (concurrently) execute communication in each mode. That is, MFP 300 can simultaneously maintain connections for executing communication in each mode. Specifically, for example, MFP 300 can simultaneously execute communication in wireless infrastructure mode and communication in wireless direct mode. Therefore, MFP 300 simultaneously maintains a connection for communication in wireless infrastructure mode and a connection for communication in wireless direct mode. Such an operation may be expressed as a "wireless simultaneous operation." Note that wireless simultaneous operation is, for example, an operation in which MFP 300 simultaneously operates as a client device in Wi-Fi communication in wireless infrastructure mode and as a parent device in Wi-Fi communication in P2P mode. On the other hand, when MFP 300 communicates using an authentication method that uses authentication server 500, MFP 300 does not simultaneously maintain both an infrastructure connection and a P2P connection.
[0051] In the Wireless Direct Mode, connection is possible without authentication depending on the settings, so when access is managed by authentication server 500 on the connection side in the wireless infrastructure mode, a discrepancy occurs in the authentication level at which access to MFP 300 is permitted. To prevent such a discrepancy in authentication, in this embodiment, MFP 300 restricts connection in the Wireless Direct Mode when the connection side in the wireless infrastructure mode operates using an authentication method that uses authentication server 500. The connection restriction will be described later with reference to FIGS. 13 to 15.
[0052] Next, a user interface screen displayed on the operation display unit 302 of the MFP 300 and the display unit 202 of the information processing device 200 in order to connect the MFP 300 to the network of the access point 400 that uses the authentication method using the authentication server 500 will be described.
[0053] Fig. 11 is a diagram illustrating the transition of screens when LAN settings 343 is selected from the setting menu of screen 341 of Fig. 4(b) on operation display unit 302 of MFP 300. Screen 1100 shown in Fig. 11(a) is displayed when "LAN settings" 342 is selected on screen 341 of Fig. 4(b), and allows the user to change the LAN settings. Screen 1100 displays, for example, wireless LAN 1101, wired LAN 1102, wireless direct 1103, and common settings 1104.
[0054] A screen 1110 shown in FIG. 11(b) is displayed when "Wireless LAN" 1101 is selected on the screen 1100 of FIG. 11(a), and allows the user to change the wireless LAN settings. The screen 1110 displays, for example, wireless LAN enable / disable 1111, wireless LAN setup 1112, wireless LAN setting display 1113, and advanced settings 1114. The wireless LAN enable / disable 1111 is an area for setting whether to enable or disable the state in which the MFP 300 can communicate using the wireless LAN. When this area is selected, a user operation is accepted on the display screen, and the state in which the MFP 300 can communicate using the wireless LAN is set to either disabled or enabled. When this state is set to disabled, the MFP 300 does not communicate or connect using the wireless LAN.
[0055] A screen 1120 shown in Fig. 11(c) is displayed when "Advanced Settings" 1114 is selected on the screen 1110 of Fig. 11(b), and allows the user to change the LAN advanced settings. For example, TCP / IP settings 1121 and 802.1X / EAP settings 1122 are displayed on the screen 1120 of Fig. 11(c). A screen 1130 shown in Fig. 11(d) is displayed when "802.1X / EAP Settings" 1122 is selected on the screen 1120 of Fig. 11(c), and allows the user to change the IEEE802.1X / EAP settings. For example, the screen 1130 displays IEEE802.1X / EAP enable / disable 1131, EAP router search 1132, and last authentication result confirmation 1133.
[0056] Screen 1140 shown in Fig. 11(e) is displayed when IEEE802.1X / EAP settings are enabled and "Search for EAP router" 1132 is selected on screen 1130, and a wireless access point search is being performed using an authentication method that uses authentication server 500. A wireless access point search is a process of searching for access points that exist in the vicinity of MFP 300. Screen 1140 shown in Fig. 11(e) is also displayed when "Wireless LAN setup" 1112 is selected on screen 1110 in Fig. 11(b) and a wireless access point search is being performed using an authentication method that does not use authentication server 500.
[0057] Screen 1150 shown in FIG. 11(f) displays a list of wireless access point identification names (SSIDs: Service Set Identifiers) as a result of a wireless access point search. When "EAP Router Search" 1132 is selected, an EAP router search is performed on screen 1150 shown in FIG. 11(f), and only the SSIDs of wireless access points that use the IEEE802.1X / EAP authentication method are displayed. Note that in this embodiment, the access point is, for example, a router, so the router search is essentially a wireless access point search. Furthermore, when "Wireless LAN Setup" 1112 is performed, only the SSIDs of wireless access points that do not use the IEEE802.1X / EAP authentication method are displayed. Screen 1150 shown in FIG. 11(f) displays SSIDs 1151 to 1153: SSIDWPA-EAP0001, WPA2-EAP005, and WPA3-EAP003. These correspond to the WPA-EAP, WPA2-EAP, and WPA3-EAP methods, respectively. As another example of the display, known methods such as WPA-PSK, WPA-PSK, and WPA3-SAE may be displayed, and the OPEN method may also be displayed.
[0058] Screen 1160 shown in Fig. 11(g) is a screen that is displayed when one of SSIDs 1151, 1152, and 1153 of a wireless access point is selected on screen 1150 in Fig. 11(f) and connection processing with the wireless access point is being performed. Screen 1170 shown in Fig. 11(h) is a screen that is displayed after screen 1160 in Fig. 11(g) is displayed, when an attempt to connect to the access point is completed and the connection is successful or when the connection has progressed to a predetermined stage.
[0059] A screen 1180 shown in FIG. 11(i) is a screen on which the user can change the IEEE802.1X / EAP setting to enabled or disabled when "Enable / Disable IEEE802.1X / EAP" 1131 is selected on the screen 1130 of FIG. 11(d). It is assumed that "Enable" 1151 and "Disable" 1152 are displayed on the screen 1180. When the IEEE802.1X / EAP setting is set to disabled, the MFP 300 does not connect to an access point using IEEE802.1X / EAP. A screen 1190 shown in FIG. 11(j) is a screen that is displayed when "Search for EAP router" 1132 is selected on the screen 1130 of FIG. 11(d). That is, in this embodiment, when the IEEE802.1X / EAP setting is disabled, a router search is not performed even if "Search for EAP router" 1132 is selected. 11(k) is a screen that is displayed when "Wireless Direct" 1103 is selected while the IEEE802.1X / EAP setting is enabled on the screen 1100 in Fig. 11(a). In this manner, in this embodiment, when Wireless Direct 1103 is selected while the IEEE802.1X / EAP setting is enabled, a message is displayed indicating that connection in Wireless Direct mode will not be performed.
[0060] Note that the control for preventing connection to an access point using IEEE 802.1X / EAP authentication, which is executed when the IEEE 802.1X / EAP setting is disabled, is not limited to the control described above. For example, MFP 300 may execute a router search, but may not display access points for which IEEE 802.1X / EAP authentication is enabled in the list of access points discovered by the router search. Alternatively, MFP 300 may display access points for which IEEE 802.1X / EAP authentication is enabled in the list, but may not execute connection processing with such access points even if the user selects them.
[0061] When connecting the MFP 300 to a network for which IEEE802.1X / EAP authentication is enabled, authentication must be performed after setting information required for authentication in the MFP 300. An overview of the process of connecting the MFP 300 to a network for which IEEE802.1X / EAP authentication is enabled, configured by the access point 400, in this embodiment will be described with reference to FIG. 9 .
[0062] First, in S901, a connection is established between the information processing device 200 and the MFP 300 using a connection method that does not use IEEE 802.1X / EAP authentication. In S901, the information processing device 200 and the MFP 300 are connected to a network that does not use IEEE 802.1X / EAP authentication and is configured using an access point 400 as shown in FIG. 10(b), and the communication devices can communicate with each other via the access point 400. A network that does not use IEEE 802.1X / EAP authentication is, for example, a network that uses an authentication method that does not use an authentication server 500. The connection between the information processing device 200 and the MFP 300 may also be realized by connecting the information processing device 200 to a network in which the MFP 300 serves as a master station in Wireless Direct mode as shown in FIG. 10(c). That is, specifically, in S901, for example, the MFP 300 accepts a connection request from the information processing device 200 and establishes a connection between the MFP 300 and the information processing device 200 operating in P2P mode.
[0063] Next, in S902, as will be described in FIG. 12, information processing device 200 transmits IEEE 802.1X / EAP authentication information to MFP 300. Then, MFP 300 uses that information to perform settings related to IEEE 802.1X / EAP authentication. Then, in S903, as will be described in FIG. 13, MFP 300 connects to a network configured by access point 400 and for which IEEE 802.1X / EAP authentication is enabled. In other words, MFP 300 establishes a connection with an access point for which IEEE 802.1X / EAP authentication is enabled. In S903, MFP 300 is connected to a network configured by access point 400 and for which IEEE 802.1X / EAP authentication is enabled (for example, using authentication server 500) as shown in FIG. 10(a), and communication devices can communicate with each other via access point 400.
[0064] Fig. 12 is a diagram illustrating screen transitions in information processing device 200. Fig. 12(a) shows an example of a setting screen for MFP 300 displayed on information processing device 200. Screen 1200 in Fig. 12(a) is displayed when a web browser or application program (hereinafter, referred to as an application) running on information processing device 200 communicates with an HTTP server running on MFP 300. Screen 1200 displays, for example, printer status 1201, main unit settings 1202, LAN settings 1203, and security settings 1204. Note that screen 1200 shown in Fig. 12(a) may also be displayed when USB communication control unit 320 of MFP 300 waits for and responds to an HTTP request via USB communication.
[0065] When "Security Settings" 1204 is selected on screen 1200 of Fig. 12(a), screen 1210 shown in Fig. 12(b) is displayed. Screen 1210 displays, for example, SSL / TLS settings 1211 and IEEE802.1X / EAP settings 1212. When "IEEE802.1X / EAP Settings" 1212 is selected on screen 1210 of Fig. 12(b), screen 1220 shown in Fig. 12(c) is displayed.
[0066] When "Authentication method" 1221 is selected on screen 1220 of Fig. 12(c), screen 1230 shown in Fig. 12(d) is displayed. By selecting any one of "EAP-TLS" 1231, "EAP-TTLS" 1232, and "PEAP" 1233 on screen 1230 of Fig. 12(d), the authentication method to be used during IEEE802.1X / EAP authentication is set on MFP 300. Furthermore, by inputting a login name in "User name" 1234 and a password in "Password" 1235 on screen 1230 of Fig. 12(d), the login name and password to be used during IEEE802.1X / EAP authentication are set on MFP 300.
[0067] When the user selects "Set key and certificate" 1222 on screen 1220 of FIG. 12(c) and then selects "Upload key and certificate" 1241 on screen 1240 of FIG. 12(e), screen 1250 of FIG. 12(f) is displayed. On screen 1250, the user can register a certificate to be used during IEEE802.1X / EAP authentication in MFP 300. When the user selects a file in "Select file" 1251 on screen 1250 of FIG. 12(f), the certificate to be used during IEEE802.1X / EAP authentication is selected. Then, when the user inputs a password in "Password" 1252 on screen 1250 and selects "Upload" 1253, the certificate and password to be used during IEEE802.1X / EAP authentication are set in MFP 300.
[0068] When the user selects "Delete key and certificate" 1242 on screen 1240 in Fig. 12(e), it is possible to delete the certificates stored in MFP 300. Also, when the user selects "Confirm key and certificate" 1243 on screen 1240 in Fig. 12(e), it is possible to display a list of the certificates stored in MFP 300.
[0069] When the user selects "Enable / Disable IEEE802.1X / EAP" 1223 on screen 1220 in Fig. 12(c), screen 1260 shown in Fig. 12(g) is displayed. On screen 1260 in Fig. 12(g), the user can enable or disable IEEE802.1X / EAP on MFP 300 by selecting enable 1261 or disable 1262.
[0070] By performing the above user operations, the user can set authentication information to be used in IEEE802.1X / EAP authentication for the MFP 300. The MFP 300 can connect to a network that uses the authentication server 500, which is configured by the access point 400, by being authenticated by the authentication server 500 using the set authentication information. In this embodiment, the connection status in each mode is managed as valid (ON state) / invalid (OFF state). For example, the MFP 300 can switch valid connections and control communications by controlling the wireless communication unit 307 and the wired communication unit 321.
[0071] Fig. 13 is a flowchart showing the setup process for connecting MFP 300 to a network that uses authentication server 500 configured with access point 400. Before performing the setup process shown in Fig. 13, it is necessary to set authentication information used in IEEE802.1X / EAP authentication in MFP 300 in step S902 of Fig. 9. If authentication information has not been set in MFP 300, EAP authentication will fail. The process in Fig. 13 is implemented, for example, by CPU 311 reading and executing a program stored in program memory 313.
[0072] In S1301, the CPU 311 of the MFP 300 receives a search request for an access point. For example, the user selects "Search for EAP router" 1132 on the screen 1130 in FIG. 11(d), causing the CPU 311 to receive the search request for an access point.
[0073] In S1302, the CPU 311 determines whether the type of the access point search request is “EAP.” In other words, in S1302, it is determined whether the search is for an access point that uses the authentication server 500. For example, if the user selects “Search for EAP Routers” 1132 on the screen 1130 of FIG. 11(d), the CPU 311 determines that the type of the access point search request is “EAP.” Alternatively, the determination in S1302 may be made based on whether the search request received by the MFP 300 via the communication path includes an instruction to search for an access point that uses the authentication server 500. On the other hand, if the user selects “Wireless LAN Setup” 1112 on the screen 1110 of FIG. 11(b), the CPU 311 determines that the type of the access point search request is not “EAP.” If it is determined in S1302 that the type of the access point search request is “EAP,” the process proceeds to S1303. On the other hand, if it is determined that the type of the access point search request is not "EAP", the process proceeds to S1307.
[0074] In S1303, the CPU 311 determines whether the IEEE802.1X / EAP settings are valid. The determination in S1303 is made based on, for example, the setting of "IEEE802.1X / EAP enabled / disabled" 1131 on the screen 1130 in Fig. 11(d). If it is determined in S1303 that the IEEE802.1X / EAP settings are valid, the process proceeds to S1305, and if it is determined that the IEEE802.1X / EAP settings are not valid, the process proceeds to S1304.
[0075] In S1304, the CPU 311 responds that a search for an access point that uses the authentication server 500 as the authentication method cannot be executed, and then ends the processing in Fig. 13. For example, if the IEEE802.1X / EAP setting is disabled and "Search for EAP router" 1132 is selected on the screen 1130 in Fig. 11(d), a screen such as the screen 1190 in Fig. 11(j) is displayed in S1304.
[0076] In S1305, the CPU 311 searches for an access point that supports an authentication method using the authentication server 500, and in S1306, stores the fact that a search has been performed for an access point that supports an authentication method using the authentication server 500. Note that S1305 and S1306 may be performed in the reverse order.
[0077] If it is determined in S1302 that the type of the access point search request is not "EAP," then in S1307, the CPU 311 searches for access points that use an authentication method other than the authentication method using the authentication server 500. Then, in S1308, the CPU 311 stores the fact that it has searched for access points that use an authentication method other than the authentication method using the authentication server 500. Note that S1307 and S1308 may be performed in the reverse order. After S1306 and S1308, the process proceeds to S1309.
[0078] In S1309, the CPU 311 displays a list of SSIDs of wireless access points as a search result for access points, as shown in screen 1150 of Fig. 11(f). In S1310, the CPU 311 accepts a user selection of the SSID of the access point to connect to.
[0079] In S1311, CPU 311 determines whether wireless direct mode is enabled. In this embodiment, whether each communication mode is enabled (ON state) or disabled (OFF state) is stored as setting information in MFP 300, and therefore the determination in S1311 is made based on, for example, the stored information of each communication mode. If it is determined that wireless direct mode is enabled, the process proceeds to S1312, and if it is determined that wireless direct mode is not enabled, the process proceeds to S1316.
[0080] In S1312, the CPU 311 determines whether the IEEE802.1X / EAP settings are valid. The determination in S1312 is made based on, for example, the setting of "IEEE802.1X / EAP enabled / disabled" 1131 on the screen 1130 in Fig. 11(d). If it is determined that the IEEE802.1X / EAP settings are valid, the process proceeds to S1313, and if it is determined that the IEEE802.1X / EAP settings are not valid, the process proceeds to S1316.
[0081] In S1313, the CPU 311 determines whether the access point to be connected is an access point that uses an authentication method that uses the authentication server 500. If it is determined that the access point is an access point that uses an authentication method that uses the authentication server 500, the process proceeds to S1314, and if it is determined that the access point is not an access point that uses an authentication method that uses the authentication server 500, the process proceeds to S1316. The determination in S1313 is made based on the contents stored in S1306 and S1308, for example.
[0082] In S1314, CPU 311 disables Wireless Direct mode. Then, in S1315, CPU 311 enables Wireless Infrastructure mode and uses the authentication information set in S902 to connect to a network that uses an authentication method that uses authentication server 500 configured by access point 400. Note that disabling Wireless Direct mode specifically means, for example, that MFP 300 stops operating as an access point or as a Wi-Fi Direct group owner, and enters a state in which a Wi-Fi Direct connection with other devices is not established.
[0083] In S1311 and thereafter, if the wireless direct mode is enabled, the IEEE802.1 / EAP setting is enabled, and the access point to be connected uses an authentication method that uses authentication server 500, the wireless direct mode is disabled and the wireless infrastructure mode is enabled. When the wireless infrastructure mode is enabled, MFP 300 connects to access point 400 using authentication information set by information processing device 200. Note that enabling the wireless infrastructure mode means starting operation in the wireless infrastructure mode.
[0084] On the other hand, if it is determined that any one of the conditions in S1311, S1312, and S1313 is not satisfied, in S1316, CPU 311 enables wireless infrastructure mode and connects MFP 300 to access point 400. However, the connection in wireless infrastructure mode at this time is established without using the IEEE 802.1X / EAP authentication method. Also, if it is determined that the condition is not satisfied in S1312 or if it is determined that the condition is not satisfied in S1313, both wireless infrastructure mode, which does not use the IEEE 802.1X / EAP authentication method, and wireless direct mode are enabled. Note that if the SSID of the access point is selected in S1310 and the process proceeds to S1315, screen 1160 in FIG. 11(g) is displayed until an access point connection attempt is started in S1315. If the process proceeds to S1316, the screen 1160 in FIG. 11(g) is displayed until the success or failure of the connection to the access point is confirmed in S1316.
[0085] As described above, MFP 300 can be connected to a network that employs an authentication method using authentication server 500 configured by access point 400. At that time, if Wireless Direct mode is enabled, MFP 300 is connected to the network that employs an authentication method using authentication server 500 after disabling Wireless Direct mode.
[0086] In S1302, the type of search request for the access point 400 does not have to be specified. For example, a search request for an access point that uses an authentication method that uses the authentication server 500 may be given priority, or connection to an access point may be attempted regardless of type.
[0087] In FIG. 13, when a connection to an access point that uses an authentication method using authentication server 500 is requested, if Wireless Direct mode is enabled, the Wireless Direct mode is disabled and then Wireless Infrastructure mode is enabled.
[0088] An example of a case in which the wireless direct mode is enabled is when "Wireless Direct" 1103 is selected on the screen 1100 in FIG. 11(a). Another example is when an instruction to enable the wireless direct mode is received in communication with the information processing device 200 connected in wireless infrastructure mode. In this embodiment, when a request to enable the wireless direct mode is received as in the above case, if the MFP 300 is operating in wireless infrastructure mode, which is an authentication method that uses the authentication server 500, the request to enable the wireless direct mode is rejected. Such an operation will be described below with reference to FIG. 14.
[0089] 14 is a flowchart showing the operation of MFP 300 when a request to enable Wireless Direct Mode is received. The processing in FIG. 14 is realized, for example, by CPU 311 reading and executing a program stored in program memory 313.
[0090] In S1401, the CPU 311 receives a request to enable the Wireless Direct mode. The request to enable the Wireless Direct mode is an instruction to start operation in the Wireless Direct mode. The start instruction is issued, for example, by the user selecting "Wireless Direct" 1103 on the screen 1100 of FIG. 11A. The start instruction is transmitted to the MFP 300 in communication with the information processing device 200. The operation of selecting "Wireless Direct" 1103 is an operation to enable the Wireless Direct mode. The start instruction may be received from the information processing device 200 via an access point to which the MFP 300 is connected in wireless infrastructure mode. The start instruction may be received from the information processing device 200 via communication with the information processing device 200 using a communication standard other than the IEEE 802.11 standard series. Examples of communication standards other than the IEEE 802.11 standard series include Bluetooth Classic, Bluetooth Low Energy (BLE), and Near Field Communication (NFC).
[0091] In S1402, CPU 311 determines whether wireless infrastructure mode is enabled. In this embodiment, whether each communication mode is enabled (ON state) or disabled (OFF state) is stored as setting information in MFP 300, so the determination in S1402 is made based on, for example, the stored information on each communication mode. If it is determined that wireless infrastructure mode is enabled, the process proceeds to S1403, and if it is determined that wireless infrastructure mode is not enabled, the process proceeds to S1406.
[0092] In S1403, the CPU 311 determines whether the IEEE802.1X / EAP settings are valid. The determination in S1403 is made based on, for example, the setting of "IEEE802.1X / EAP enabled / disabled" 1131 on the screen 1130 in Fig. 11(d). If it is determined that the IEEE802.1X / EAP settings are valid, the process proceeds to S1404, and if it is determined that the IEEE802.1X / EAP settings are not valid, the process proceeds to S1406.
[0093] In S1404, CPU 311 determines whether the authentication method used by the access point to which MFP 300 is connected is an authentication method that uses authentication server 500. In other words, CPU 311 determines whether MFP 300 is connected to an access point that has been connected using an authentication method that uses authentication server 500. The determination in S1404 is made, for example, based on the contents stored in S1306 and S1308 of Fig. 13. If it is determined that the authentication method uses authentication server 500, the process proceeds to S1405, and if it is determined that the authentication method does not use authentication server 500, the process proceeds to S1406.
[0094] Proceeding to S1405 means that a request to enable wireless direct mode has been received while MFP 300 is operating in an authentication method using authentication server 500 on the connection side in wireless infrastructure mode. In this embodiment, CPU 311 rejects the request to enable wireless direct mode (i.e., controls so as not to operate in wireless direct mode). This controls so that a connection in wireless direct mode and a connection in wireless infrastructure mode with IEEE802.1X / EAP settings are not established simultaneously. At this time, screen 1195 in FIG. 11(k) is displayed on the operation display unit 302.
[0095] On the other hand, in S1406, the CPU 311 enables the wireless direct mode. If it is determined in S1402 that the wireless infrastructure mode is not enabled and the process proceeds to S1406, only the wireless direct mode is enabled. If the process proceeds to S1406 in either S1403 or S1404, both the wireless infrastructure mode (however, not an authentication method using authentication server 500) and the wireless direct mode are enabled. If the process proceeds to S1402, S1403, S1404, and S1405, only the wireless infrastructure mode (authentication method using authentication server 500) is enabled.
[0096] 15 is a flowchart showing the operation of MFP 300 when a request to enable wireless infrastructure mode is received. The processing in FIG. 15 is realized, for example, by CPU 311 reading and executing a program stored in program memory 313.
[0097] In S1501, CPU 311 receives a request to enable wireless infrastructure mode. For example, if "Enable / Disable IEEE802.1X / EAP" 1131 on screen 1130 in Fig. 11(d) is set to enabled, it is assumed that a request to enable wireless infrastructure mode has been received, and the process proceeds to S1502. Thereafter, in S1502 to S1507, the same processes as in S1311 to S1316 in Fig. 13 are performed. In other words, when a request to enable wireless infrastructure mode is received, if wireless direct mode is enabled, wireless direct mode is disabled and then wireless infrastructure mode is enabled.
[0098] As described above, according to this embodiment, when MFP 300 is operating in wireless infrastructure mode using an authentication method that uses authentication server 500, it is not simultaneously operated in wireless direct mode. With such a configuration, it is possible to prevent a difference in authentication level between the two modes caused by connection being made without authentication in wireless direct mode while operating in wireless infrastructure mode using an authentication method that uses authentication server 500.
[0099] In the above description, the determinations in S1403 and S1404 are performed to prevent a connection in Wireless Direct mode and a connection in Wireless Infrastructure mode using IEEE802.1X / EAP settings from being established simultaneously. However, the present invention is not limited to this, and only one of the determinations in S1403 and S1404 may be performed. Furthermore, if either determination is NO, the process may proceed to S1406, and if the determination is YES, the process may proceed to S1405.
[0100] In the above description, a process for not starting the wireless direct mode even when a start instruction is received is executed as a process for controlling so that a connection in the wireless direct mode and a connection in the wireless infrastructure mode using the IEEE802.1X / EAP setting are not simultaneously established. However, the process is not limited to this. For example, when a connection in the wireless infrastructure mode using the IEEE802.1X / EAP setting is established, a control may be executed such that a button for performing an operation to instruct the start of the wireless direct mode (specifically, for example, "Wireless Direct" 1103) is grayed out or not displayed. This makes it possible to control so that an operation to instruct the start of the wireless direct mode is not accepted and a connection in the wireless direct mode is not established.
[0101] [Second embodiment] The second embodiment will be described below focusing on the differences from the first embodiment. In the first embodiment, a configuration was described for disabling connection in Wireless Direct mode while MFP 300 is operating in wireless infrastructure mode, which is an authentication method that uses authentication server 500. In this embodiment, connection in Wireless Direct mode is executed only to communication with authenticated information processing devices 200. Hereinafter, a connection state in Wireless Direct mode that is limited to communication that executes such authentication will be referred to as an "authentication limited state," and a connection state in Wireless Direct mode that does not impose such limitations will be referred to as a "normal state."
[0102] As described in the first embodiment, the MFP 300 is capable of "wireless simultaneous operation." Connection in Wireless Direct mode can be performed without authentication depending on the authentication settings, and when access is managed by the authentication server 500 in Wireless Infrastructure mode, a discrepancy occurs in the authentication level at which access to the MFP 300 can be made. In this embodiment, when the MFP 300 is operating in Wireless Infrastructure mode, an authentication method that uses the authentication server 500, connection in Wireless Direct mode is set to an authentication-limited state, and communication is limited to only with authenticated information processing devices 200. As a result, a discrepancy in the authentication level at which access to the MFP 300 can be made can be prevented.
[0103] Fig. 16 is a flowchart showing the setup process for connecting MFP 300 to a network that uses authentication server 500 configured with access point 400. Before performing the setup process shown in Fig. 16, it is necessary to set authentication information used in IEEE802.1X / EAP authentication in MFP 300 in step S902 of Fig. 9. If authentication information has not been set in MFP 300, EAP authentication will fail. The process in Fig. 16 is implemented, for example, by CPU 311 reading and executing a program stored in program memory 313.
[0104] S1601 to S1613 in FIG. 16 are the same as S1301 to S1313 in FIG. 13, and therefore their description will be omitted.
[0105] If it is determined in S1613 that the access point to connect to is an access point that uses the authentication method of authentication server 500, the process proceeds to S1614. In S1614, CPU 311 sets the connection in Wireless Direct mode to an authentication limited state, and the process proceeds to S1615. The operation of setting the authentication limited state will be described later with reference to FIGS.
[0106] In S1615, CPU 311 enables wireless infrastructure mode, and uses the authentication information set in S902 to connect MFP 300 to a network that uses authentication server 500 configured by access point 400. As a result, when MFP 300 connects to a network in which IEEE802.1X / EAP authentication is enabled, even if MFP 300 simultaneously operates in Wireless Direct mode, the connection side in Wireless Direct mode is limited to communication with authenticated information processing device 200. After S1615, the processing in FIG. 16 ends.
[0107] On the other hand, if the process proceeds to S1616 from any of S1611, S1612, and S1613, CPU 311 sets the connection in Wireless Direct Mode to the normal state, and proceeds to S1617. In S1617, CPU 311 enables the wireless infrastructure mode and connects MFP 300 to the network configured by access point 400. Here, since the connection in Wireless Direct Mode is in the normal state, communication without authentication can also be performed.
[0108] In this way, MFP 300 can be connected to a wireless infrastructure network that employs an authentication method using authentication server 500 configured by access point 400. At that time, if Wireless Direct mode is enabled, MFP 300 is connected to the network that employs an authentication method using authentication server 500 after the Wireless Direct mode is set to an authentication limited state.
[0109] In FIG. 16, when a connection to an access point that uses an authentication method using authentication server 500 is requested and wireless direct mode is enabled, the wireless direct mode is set to an authentication limited state and wireless infrastructure mode is enabled.
[0110] An example of a case in which the wireless direct mode is enabled is when Wireless Direct 1103 is selected on screen 1100 in Fig. 11(a). Another example is when an instruction to enable the wireless direct mode is received in communication with information processing device 200 connected in wireless infrastructure mode. In this embodiment, when a request to enable the wireless direct mode is received as in the above case, if MFP 300 is operating in wireless infrastructure mode, which is an authentication method that uses authentication server 500, the wireless direct mode is enabled as an authentication limited state. Such processing will be described below with reference to Fig. 17.
[0111] 17 is a flowchart showing the operation of MFP 300 when a request to enable Wireless Direct mode is received. The processing in FIG. 17 is realized, for example, by CPU 311 reading and executing a program stored in program memory 313.
[0112] S1701 to S1704 in FIG. 17 are the same as S1401 to S1404 in FIG. 14, and therefore their description will be omitted.
[0113] If it is determined that the authentication method of the access point to be connected is an authentication method that uses authentication server 500, then in S1705 CPU 311 sets the connection in wireless direct mode to an authentication limited state. Thereafter, in S1706 CPU 311 enables wireless direct mode. On the other hand, if the determination is No in any of S1702 to S1704, then in S1707 CPU 311 sets the connection in wireless direct mode to a normal state. Thereafter, in S1706 CPU 311 enables wireless direct mode.
[0114] In this manner, in this embodiment, when a request to enable the wireless direct mode is received, if the MFP 300 is operating in the wireless infrastructure mode, which is an authentication method that uses the authentication server 500, the wireless direct mode is enabled as an authentication limited state.
[0115] 18 is a flowchart showing the operation of MFP 300 when a request to enable wireless infrastructure mode is received. The processing in FIG. 18 is realized, for example, by CPU 311 reading and executing a program stored in program memory 313.
[0116] The wireless infrastructure mode is enabled, for example, when "IEEE802.1X / EAP enabled / disabled" 1131 on the screen 1130 in FIG. 11(d) is set to enabled.
[0117] In S1801, the CPU 311 receives a request to enable the wireless infrastructure mode. For example, if "Enable / Disable IEEE802.1X / EAP" 1131 on screen 1130 in Fig. 11(d) and enable 1151 on screen 1180 are set, it is assumed that a request to enable the wireless infrastructure mode has been received, and the process proceeds to S1802. Thereafter, in S1802 to S1808, the same processes as in S1611 to S1617 in Fig. 16 are performed. In other words, when a request to enable the wireless infrastructure mode is made, if the wireless direct mode is enabled, the wireless direct mode is set to an authentication limited state and then the wireless infrastructure mode is enabled.
[0118] The operation of entering the authentication limited state will be described below. When MFP300 is connected in wireless infrastructure mode to a network for which IEEE802.1X / EAP authentication is enabled, control is performed to limit communication to that involving authentication even in a connection in wireless direct mode that operates simultaneously, in order to match the authentication level. In this embodiment, the state in which communication is limited to that involving authentication is called the authentication limited state. A method for realizing this authentication limited state will be described with reference to FIGS. 19 to 21. In this embodiment, the process for realizing the authentication limited state will be described using three flowcharts, but the flowcharts of FIGS. 19 to 21 are not limited as long as the same effects as those of each process are achieved. Note that the processes of FIGS. 19 to 21 are executed when a communication procedure is started in a connection in wireless direct mode between information processing device 200 and MFP300. The communication procedure between information processing device 200 and MFP300 includes, for example, an application-level communication procedure that uses the functions of MFP300.
[0119] Fig. 19 is a flowchart showing processing in MFP 300 performed when starting a communication procedure through a connection in Wireless Direct mode. In the processing in Fig. 19, when starting a communication procedure between MFP 300 and information processing device 200, MFP 300 executes processing to authenticate information processing device 200. The processing in Fig. 19 is realized, for example, by CPU 311 reading and executing a program stored in program memory 313.
[0120] In S1901, the CPU 311 starts a communication procedure with the information processing device 200 via a connection in Wireless Direct mode. The communication procedure here refers to the communication procedure described above. In S1902, the CPU 311 authenticates the information processing device 200 because the connection in Wireless Direct mode is in an authentication-limited state. This authentication may be performed by the information processing device 200 sending an ID and password assigned to the information processing device 200 to the MFP 300, which then confirms the ID and password. Note that authentication may also be performed using a challenge-and-response method, a client certificate, a token, or the like, instead of an ID and password. In S1903, the CPU 311 determines whether the authentication was successful. If it is determined to be successful, the process proceeds to S1904; if it is determined to be unsuccessful, the process proceeds to S1905. Note that in S1903, the authentication is determined to be successful if, for example, authentication information (such as an ID and password) of the information processing device 200 that is permitted to access the MFP 300 via IEEE 802.1X / EAP authentication can be confirmed.
[0121] If the authentication is successful, in S1904, the CPU 311 continues to execute the communication procedure with the information processing device 200. For example, the CPU 311 can execute operations such as printing image data, scanning images, and changing settings based on information received from the information processing device 200 via the communication procedure. On the other hand, if the authentication is unsuccessful, in S1905, the CPU 311 interrupts the communication procedure with the information processing device 200.
[0122] In this way, when the connection in the Wireless Direct mode is in the authentication limited state, it is determined whether to continue the communication procedure with the information processing device 200, based on the authentication information uniquely assigned to the information processing device 200. As a result, the communication procedure is executed only to the information processing device 200 that has been successfully authenticated, and communication other than that communication procedure is restricted, so that it is possible to prevent communication in the Wireless Direct mode from being continued without authentication.
[0123] Fig. 20 is a flowchart showing processing in MFP 300 performed when starting a communication procedure via connection in Wireless Direct mode. In the processing in Fig. 20, processing is executed to authenticate information processing device 200 based on whether authentication has been performed in the communication procedure and whether the connection via Wireless Direct mode is in an authentication limited state. The processing in Fig. 20 is realized, for example, by CPU 311 reading and executing a program stored in program memory 313.
[0124] In S1911, CPU 311 starts a communication procedure with information processing device 200 through a connection in Wireless Direct mode. The communication procedure here refers to the communication procedure described above. In S1912, CPU 311 determines whether the communication procedure between MFP 300 and information processing device 200 is a communication procedure in which authentication processing is executed. The determination in S1912 is made based on, for example, a setting content for whether an application in information processing device 200 that controls communication with MFP 300 executes authentication with MFP 300 or negotiation with information processing device 200. If it is determined that the communication procedure is one in which authentication processing is executed, the process proceeds to S1913. If it is determined that the communication procedure is not one in which authentication processing is executed, the process proceeds to S1916. Note that if the connection in Wireless Direct mode is in an authentication limited state, authentication of information processing device 200 in S1913 may be executed regardless of a setting content for whether the application executes authentication.
[0125] In S1913, similarly to S1902, CPU 311 authenticates information processing device 200. This authentication may be performed by information processing device 200 transmitting an ID and password assigned to information processing device 200 to MFP 300, which then confirms the ID and password. Alternatively, information processing device 200 may transmit an administrator password or administrator ID set in MFP 300 to MFP 300, which then confirms the administrator password or administrator ID. Note that authentication may be performed using a challenge-and-response method, a client certificate, a token, or the like, instead of an ID and password. In S1914, CPU 311 determines whether authentication has been successful. If it is determined that authentication has been successful, the process proceeds to S1915; if it is determined that authentication has failed, the process proceeds to S1917.
[0126] If it is determined that the authentication was successful, in S1915, CPU 311 continues to execute the communication procedure with information processing device 200. For example, CPU 311 can execute operations such as printing image data, scanning images, and changing settings based on information received from information processing device 200 via the communication procedure. CPU 311 can also execute operations such as changing the IEEE802.1X / EAP settings of MFP 300. On the other hand, if it is determined that the authentication was unsuccessful, CPU 311 interrupts the communication procedure with information processing device 200 in S1917.
[0127] If it is determined in S1912 that the communication procedure does not require authentication processing, then in S1916, CPU 311 determines whether or not the connection in Wireless Direct mode is in the authentication limited state. If it is determined that the connection is in the authentication limited state, then in S1917, CPU 311 suspends the communication procedure with information processing device 200. On the other hand, if it is determined that the connection is not in the authentication limited state, then in S1915, CPU 311 continues to execute the communication procedure with information processing device 200.
[0128] In this way, in a connection in the Wireless Direct mode between MFP 300 and information processing device 200, the communication procedure is such that authentication is executed at the application level or the like, and communication can be limited to communication with information processing device 200 having the same access level as the access level to MFP 300 by IEEE802.1X / EAP authentication. Furthermore, it is not necessary to change the setting of authentication at the application level in accordance with IEEE802.1X / EAP authentication.
[0129] Fig. 21 is a flowchart showing processing in MFP 300 performed when starting a communication procedure through a connection in Wireless Direct mode. In the processing in Fig. 21, communication from information processing device 200 to MFP 300 is limited to only communications whose destination information satisfies a condition. The processing in Fig. 21 is realized, for example, by CPU 311 reading and executing a program stored in program memory 313.
[0130] In S1921, CPU 311 starts a communication procedure with information processing device 200 through a connection in Wireless Direct Mode. The communication procedure here is the communication procedure described above. In S1922, CPU 311 acquires communication destination information from information processing device 200. Here, the destination information is information indicating a destination on the MFP 300 side, such as an IP address, port number, URL, or query.
[0131] At S1923, CPU 311 determines whether the acquired destination information satisfies a predetermined condition. At S1923, CPU 311 determines that the predetermined condition is satisfied if the communication corresponding to the destination information is communication including authentication processing. This may be determined based on whether authentication has been performed at the application level, for example. If it is determined that the predetermined condition is satisfied, the process proceeds to S1924, and if it is determined that the predetermined condition is not satisfied, the process proceeds to S1925.
[0132] If it is determined that the predetermined condition is satisfied, then in S1924, the CPU 311 continues to execute the communication procedure with the information processing device 200. In this communication procedure, authentication of the information processing device 200 is executed, as in S1902 and S1913. That is, in this authentication, authentication using an ID and password, a challenge-and-response method, a client certificate, a token, or the like may be used. Furthermore, if the authentication fails, the communication procedure with the information processing device 200 is interrupted. On the other hand, if it is determined that the predetermined condition is not satisfied in S1923, authentication processing will not be executed even if the communication procedure is continued, and therefore, in S1925, the CPU 311 interrupts the communication procedure with the information processing device 200.
[0133] In this way, in a wireless direct mode connection between the MFP 300 and the information processing device 200, the communication procedure can be limited to one in which authentication is performed at the application level, for example, and communication can be limited to communication with the information processing device 200 having the same access level as the access level to the MFP 300 using IEEE802.1X / EAP authentication.
[0134] As described above, according to each embodiment, even if MFP 300 operates in Wireless Direct Mode when connected to a network in which IEEE802.1X / EAP authentication is enabled, communication with information processing device 200 is restricted on the connection side in Wireless Direct Mode. This prevents a discrepancy in authentication level, such as when connection in Wireless Direct Mode is performed without authentication, even if MFP 300 is connected in Wireless Infrastructure Mode to a network in which IEEE802.1X / EAP authentication is enabled.
[0135] The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0136] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]
[0137] 100 communication systems: 200 information processing devices: 300 MFPs: 400 access points: 500 authentication servers
Claims
1. A communication device capable of communicating with an information processing device and an access point, establishing means for establishing a connection between the access point and the communication device; a first receiving means for receiving a predetermined request for enabling a predetermined mode in the communication device for direct communication between the communication device and the information processing device without going through the access point; a first enabling means for enabling the predetermined mode in the communication device when a connection between the communication device and the access point is established and an authentication method used for the connection between the communication device and the access point is not a predetermined authentication method, based on the predetermined request being accepted; a control means for executing predetermined control so as not to enable the predetermined mode in the communication device when a connection between the communication device and the access point is established and an authentication method used for the connection between the communication device and the access point is the predetermined authentication method; A communication device comprising:
2. A communication device as described in Claim 1, characterized in that when a connection between the communication device and the access point is not established, the specified mode is enabled in the communication device based on the specified request being accepted.
3. A communication device as described in claim 1 or 2, characterized in that the specified request is a request issued by a specified user operation on a user interface screen of the communication device.
4. The communication device described in Claim 3, characterized in that the specified control is a process of graying out a button for accepting the specified operation, or a process of not displaying a button for accepting the specified operation.
5. A communication device described in any one of claims 1 to 4, characterized in that the specified request is a request sent from the information processing device to the communication device.
6. A communication device described in any one of claims 1 to 5, characterized in that the specified control is control for preventing the specified request from being accepted.
7. A communication device described in any one of claims 1 to 5, characterized in that the specified control is control for preventing the specified mode from being enabled in the communication device even if the specified request is accepted.
8. A second receiving means for receiving a specific request to enable a specific mode in the communication device for communication between the communication device and the information processing device via the access point; a second enabling means for enabling the specific mode in the communication device based on the specific request; a disabling means for disabling the predetermined mode when an authentication method used for a connection between the communication device and the access point established based on the specific request is the predetermined authentication method and the communication device is in the predetermined mode when the specific request is accepted; 8. The communication device according to claim 1, further comprising:
9. A communication device as described in Claim 8, characterized in that if the authentication method used for the connection between the communication device and the access point established based on the specific request is the specified authentication method, and if the communication device is in the specified mode when the specific request is accepted, the specified mode is disabled and then the specific mode is enabled.
10. A communication device as described in Claim 8 or 9, characterized in that if the authentication method used for the connection between the communication device and the access point established based on the specific request is not the specified authentication method and the communication device is in the specified mode when the specific request is accepted, the specific mode is enabled while the specified mode remains enabled.
11. A communication device described in any one of claims 8 to 10, characterized in that the specific request is a request issued by a specific user operation on a user interface screen of the communication device.
12. A communication device described in any one of claims 1 to 11, characterized in that the specified authentication method is an authentication method specified in IEEE802.1X / EAP.
13. A communication device described in any one of claims 1 to 12, characterized in that the authentication method that is not the specified authentication method is a personal method.
14. A communication device described in any one of claims 1 to 13, characterized in that the authentication method that is not the specified authentication method is a PreShared Key (PSK) method or a Simultaneous Authentication of Equals (SAE) method.
15. A communication device as described in any one of claims 1 to 14, characterized in that the specified mode is a mode in which the communication device operates as an access point.
16. The communication device according to claim 1, wherein the predetermined mode is a mode for communicating via Wi-Fi Direct (registered trademark).
17. A communication device described in any one of claims 1 to 16, characterized in that the communication device is a printer.
18. A computer of a communication device capable of communicating with an information processing device and an access point, establishing means for establishing a connection between said access point and said communication device; a first receiving means for receiving a predetermined request for enabling a predetermined mode in the communication device for communicating directly between the communication device and the information processing device without going through the access point; a first enabling means for enabling the predetermined mode in the communication device based on the acceptance of the predetermined request, when a connection between the communication device and the access point has been established and an authentication method used for the connection between the communication device and the access point is not a predetermined authentication method; a control means for executing predetermined control so as not to enable the predetermined mode in the communication device when a connection between the communication device and the access point has been established and an authentication method used for the connection between the communication device and the access point is the predetermined authentication method; A program to function as a
19. A method for controlling an information processing device and a communication device capable of communicating with an access point, comprising: establishing a connection between the access point and the communication device; a first receiving step of receiving a predetermined request for enabling a predetermined mode in the communication device for direct communication between the communication device and the information processing device without going through the access point; a first enabling step of enabling the predetermined mode in the communication device based on acceptance of the predetermined request, when a connection between the communication device and the access point has been established and an authentication method used for the connection between the communication device and the access point is not a predetermined authentication method; a control step of executing predetermined control so as not to enable the predetermined mode in the communication device when a connection between the communication device and the access point is established and an authentication method used for the connection between the communication device and the access point is the predetermined authentication method; A control method comprising:
Citation Information
Patent Citations
Communication device
JP2013239906A
Communication equipment
JP2016140001A
Printer, control method and program thereof
JP2017007112A
Printer, control method and program of printer
JP2017087506A
Communication apparatus
JP2023035054A