Communication device, control method thereof, and program
The communication device's configuration to handle IEEE802.1X/EAP authentication failures by reconnecting after disconnection improves the convenience and reliability of wireless LAN connections.
Patent Information
- Application Number
- JP2022025604
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-02-22
- Publication Date
- 2026-03-05
- Estimated Expiration
- 2042-02-22
AI Technical Summary
There is a need to improve the convenience of communication devices that perform connection processing to wireless LANs using the IEEE802.1X/EAP authentication method, as devices that support this method become more widespread.
A communication device is configured with a receiving means to receive IEEE 802.1X authentication information, a disconnection means to disconnect the wireless connection if authentication fails, and a re-establishment means to reconnect based on authentication failure, while avoiding reconnection if the connection is not IEEE 802.1X compliant.
This configuration enhances the convenience of communication devices by improving the reliability and efficiency of wireless LAN connections using the IEEE802.1X/EAP authentication method.
Smart Images

Figure 0007824786000001 
Figure 0007824786000002 
Figure 0007824786000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a communication device having a communication interface, a control method thereof, and a program. [Background technology]
[0002] Conventionally, wireless LANs conforming to the IEEE802.11 standard use radio waves as the communication medium, making security a major issue. To address this issue, wireless communication methods using wireless LANs based on the IEEE802.11 standard have protected the network by authenticating communication devices connecting to the network. Wireless LAN authentication methods include the PSK method, which uses a pre-shared key, and the SAE (Simultaneous Authentication of Equals) method, which uses SAE. Another wireless LAN authentication method is the EAP method, which uses an IEEE802.1X / EAP-compatible authentication server to authenticate communication devices connecting to the network.
[0003] Patent Document 1 describes a method for controlling an information processing device to allow a user who cannot connect to an IEEE802.1X / EAP-compatible authentication server to connect to a network using the same access point. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-302846 Summary of the Invention [Problem to be solved by the invention]
[0005] As devices that perform connection processing to wireless LANs using the IEEE802.1X / EAP authentication method become more widespread, there is a demand for improving the convenience of communication devices that perform connection processing to wireless LANs using the IEEE802.1X / EAP authentication method.
[0006] The present invention has been made in view of the above-mentioned conventional examples, and has an object to improve the convenience of a communication device that executes a connection process to a wireless LAN using the IEEE802.1X / EAP authentication method. [Means for solving the problem]
[0007] In order to achieve the above object, the present invention has the following configuration. That is, according to one aspect, there is provided a communication device, a receiving means for receiving first information related to IEEE 802.1X authentication from an information processing device via a first wireless connection between the communication device and another device; disconnection means for disconnecting the first wireless connection; an authentication means for performing the IEEE 802.1X authentication based on the received first information in a state where the first wireless connection is not established; an execution means for executing a process for re-establishing the first wireless connection based on the failure of the IEEE 802.1X authentication; With death, the first wireless connection is a connection between an external access point and the communication device; If the first wireless connection is a connection between the external access point and the communication device that corresponds to authentication different from the IEEE 802.1X authentication, a process is executed to re-establish the first wireless connection; If the first wireless connection is a connection between the external access point that supports the IEEE 802.1X authentication and the communication device, a process for re-establishing the first wireless connection is not executed. A communication device is provided. [Effects of the Invention]
[0008] According to the present invention, it is possible to improve the convenience of a communication device that executes a connection process to a wireless LAN using the IEEE802.1X / EAP authentication method. [Brief explanation of the drawings]
[0009] [Figure 1]FIG. 1 illustrates an example of a system configuration. [Figure 2] FIG. 1 is a diagram illustrating an example of the external configuration of an MFP. [Figure 3] FIG. 1 illustrates an example of the configuration of an MFP. [Figure 4] 10A and 10B are diagrams illustrating examples of screens displayed on an operation display unit of an MFP. [Figure 5] 1 is a diagram illustrating an example of the external configuration of an information processing device. [Figure 6] FIG. 1 illustrates an example of the configuration of an information processing device. [Figure 7] FIG. 1 illustrates an example of the configuration of an access point. [Figure 8] FIG. 10 illustrates an example of the configuration of an authentication server. [Figure 9] FIG. 10 is a diagram showing an outline of a procedure to be followed when connection to a network MFP operating under an authentication method that uses an authentication server fails. [Figure 10] FIG. 1 illustrates an example of a network configuration. [Figure 11] 10A and 10B are diagrams illustrating examples of screens displayed on the operation display unit of the MFP when LAN settings are made. [Figure 12] FIG. 10 is a diagram illustrating an example of a setting screen of an MFP displayed on an information processing apparatus. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the claimed invention. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.
[0011] (System Configuration) 1 shows an example of the configuration of a communication system according to this embodiment. As an example, this system is configured so that multiple communication devices can communicate wirelessly with each other. In this embodiment, the communication devices include devices that communicate with each other, and are not limited to devices that provide a communication environment (such as access points and switches). Here, it is assumed that an information processing device 200, an MFP (multifunction printer) 300, an access point 700, and an authentication server 800 are used as the multiple communication devices.
[0012] The information processing device 200 and the MFP 300 may be simply referred to as communication devices when they are not particularly distinguished from each other. For example, the MFP 300 may be referred to as the communication device 300.
[0013] The information processing device 200 is an information processing device having a communication function via a wireless LAN, a wired LAN, or the like. A wireless LAN can be expressed as a WLAN (Wireless LAN). Examples of the information processing device 200 include a smartphone, a notebook PC (notebook-type personal computer (multifunctional peripheral device)), a tablet terminal, a PDA (Personal Digital Assistant), and the like.
[0014] The MFP 300 is a printing device having a printing function as its primary function, and may also have secondary functions such as a reading function (scanning function), a fax (facsimile) function, and a telephone function. The MFP 300 also has a communication function capable of wireless communication with the information processing device 200. While the present embodiment describes an example in which the MFP 300 is used, the present invention is not limited to this. For example, a facsimile machine, a scanner, a projector, a mobile terminal, a smartphone, a laptop PC, a tablet terminal, a PDA, or the like may be used instead of the MFP 300. Alternatively, a digital camera, a music playback device, a television, a smart speaker, or AR (Augmented Reality) glasses may be used. The MFP 300 receives print data including image data from an information processing device connected via an access point 700, and forms an image based on the data. Alternatively, the MFP 300 transmits image data scanned using a scanner function to the information processing device connected via the access point 700. Other control information may also be exchanged with the connected network via the access point 700.
[0015] The access point (AP) 700 is provided separately from (externally of) the information processing device 200 and the MFP 300 and operates as a WLAN base station device or wireless base station. A communication device equipped with a WLAN communication function can communicate in WLAN infrastructure mode (wireless infrastructure mode; hereinafter, "infrastructure" may be simply referred to as "infrastructure") via the access point 700. The access point 700 performs wireless communication with a communication device that is permitted to connect to the access point 700 (i.e., an authenticated communication device) and relays wireless communication between the communication device and other communication devices. The access point 700 can also be connected to, for example, a wired communication network and relay communication between a communication device connected to the wired communication network and another communication device wirelessly connected to the access point 700.
[0016] When the authentication method of the network established by the access point 700 is a method using the authentication server 800, the access point 700 performs access control by authenticating communication devices connecting to the network in cooperation with the authentication server 800. Communication devices connecting to the network established by the access point 700 may be restricted from communicating with devices other than the authentication server 800 until they are authenticated. Note that the access point 700 may also support an authentication method that does not use an authentication server. Details of authentication methods that use an authentication server and authentication methods that do not use an authentication server will be described later.
[0017] The authentication server (RADIUS server) 800 is provided separately from the information processing device 200, the MFP 300, and the access point 700, and collectively manages authentication information. The authentication server 800 is capable of executing authentication processing in accordance with, for example, the IEEE 802.1X standard. In this embodiment, the authentication server 800 cooperates with the access point 700 to authenticate terminals to be authenticated, and controls access to the terminals based on the authentication results.
[0018] Here, the access point 700 corresponds to an authenticator in IEEE802.1X, and the information processing device 200 and the MFP 300 correspond to a supplicant in IEEE802.1X.
[0019] The authentication server 800 performs authentication using, for example, the EAP-TLS (Transport Layer Security) method or the EAP-TTLS (Tunneled TLS) method in accordance with the IEEE 802.1X standard. The EAP-TLS method is an authentication method that uses the TLS handshake protocol, which allows authentication using a server certificate, a client certificate, etc. The EAP-TTLS method is an authentication method that uses the TLS handshake protocol, which allows authentication using a server certificate, a user name, a password, etc. As another example, the authentication server 800 can also perform authentication using the PEAP (Protected EAP) method in accordance with the IEEE 802.1X standard. The PEAP (Protected EAP) method allows authentication using a user name and a password. The information used for these IEEE 802.1X authentications can be referred to as "authentication information."
[0020] The information processing device 200 and the MFP 300 can use their respective WLAN communication functions to perform wireless communication in a wireless infrastructure mode via an external access point 700, or in a peer-to-peer (P2P) mode that does not involve the external access point 700. The P2P mode includes WFD (Wi-Fi Direct (registered trademark)) and soft AP mode. That is, the communication is realized by wireless direct that complies with the IEEE802.11 series. Note that, as will be described in detail later, the information processing device 200 and the MFP 300 can execute processes corresponding to multiple printing services using WLAN communication.
[0021] (MFP external configuration) FIG. 2 is a perspective view showing an example of the external configuration of MFP 300. MFP 300 includes an operation display unit (operation panel) 302, a print paper insertion slot 303, a print paper ejection slot 304, a document table 305, and a document cover 306. The housing of MFP 300 is provided with a power button 301, which is a hard key used to turn the power on and off. Operation display unit 302 includes a display and buttons used to operate MFP 300. For example, operation display unit 302 includes multiple keys such as character input keys, cursor keys, a confirm key, and a cancel key, and a light source such as an LED (Light Emitting Diode) or an LCD (Liquid Crystal Display). Operation display unit 302 is configured to be able to accept user operation inputs when activating individual functions of MFP 300, changing various settings, etc. Typically, a touch panel display can be used as operation display unit 302 (see FIG. 4).
[0022] Print paper insertion slot 303 is an insertion slot for setting paper of any size. Paper set in print paper insertion slot 303 is transported one sheet at a time to the printing section and printed, and the printed paper is discharged from print paper exit 304. Platen 305 is a transparent glass table that is used when placing a document on it and reading an image using the scan function. Platen pressure plate 306 is a cover that presses the document against platen 305 to prevent the document from lifting off when reading an image using the scan function, and can also block light from entering the inside of MFP300 main body from outside.
[0023] Furthermore, MFP 300 has a communication function using WLAN or wired LAN. In this embodiment, MFP 300 has a built-in antenna for realizing wireless communication, and is also provided with a communication unit 321 for wired LAN. MFP 300 also has a USB communication unit 309 that can realize communication with external information processing device 200 etc. via USB connection.
[0024] (MFP configuration) 3 is a block diagram showing an example of the configuration of MFP 300. MFP 300 includes a built-in main board 310 that controls the entire device, as well as a wireless communication unit 307 and a USB communication unit 308. Main board 310 includes a CPU (Central Processing Unit) 311, an internal bus 312, a program memory 313, a data memory 314, a print unit 316, a scan unit 317, a communication control unit 318, an operation control unit 319, and a USB communication control unit 320. Note that the processes described below as processes executed by MFP 300 are actually realized by CPU 311 executing programs stored in program memory 313, data memory 314, etc.
[0025] The CPU 311, the program memory 313, and the data memory 314 are a microprocessor, a ROM (Read Only Memory), and a RAM (Random Access Memory), respectively. In this embodiment, the CPU 311, the program memory 313, and the data memory 314 are connected to one another via a bus cable that forms an internal bus 312. The CPU 311 performs arithmetic processing to realize each function described in the embodiment, based on a control program stored in the program memory 313 and the contents of the data memory 314.
[0026] For example, CPU 311 can control scan unit 317 to read an original document and store the image (image data) in image memory 315 within data memory 314. CPU 311 can control print unit 316 to print the image stored in image memory 315 onto a recording medium. CPU 311 can control USB communication unit 308 via USB communication control unit 320 to perform USB communication with external information processing device 200 via a USB connection. CPU 311 can control operation control unit 319 to receive information indicated by operation input from power button 301 or operation display unit 302. CPU 311 can also control operation control unit 319 to display the status of MFP 300 and a function selection menu on operation display unit 302.
[0027] The wireless communication unit 307 is configured to provide WLAN communication functions, for example, functions similar to those of the WLAN unit 201 of the information processing device 200. That is, the wireless communication unit 307 transmits packets converted from data in a manner conforming to a predetermined standard to other devices, and also restores packets from other devices to the original data and outputs the data to the CPU 311. The wireless communication unit 307 is configured to perform data (packet) communication in a WLAN system conforming to the IEEE 802.11 standard series (IEEE 802.11a / b / g / n / ac / ax, etc.), but may also conform to other standards. Here, the wireless communication unit 307 is capable of communication on any channel in both the 2.4 GHz and 5 GHz frequency bands. As will be described in detail later, the wireless communication unit 307 is also capable of WFD-based communication, communication in software access point (soft AP) mode, communication in wireless infrastructure mode, etc. Furthermore, the information processing device 200 and the MFP 300 are capable of wireless direct communication based on WFD, and the wireless communication unit 307 may have a soft AP function or a group owner function. That is, the wireless communication unit 307 can build a P2P communication network and determine the channel to be used for P2P communication.
[0028] The wired LAN communication unit 321 is configured to be able to realize wired communication. For example, the wired LAN communication unit 321 can realize data (packet) communication in a wired LAN (Ethernet) system conforming to the IEEE802.3 series. Furthermore, wired communication using the wired LAN communication unit 321 is possible in wired mode. Here, the wired LAN communication unit 321 is connected to the main board 310 via a bus cable that forms the internal bus 312.
[0029] (MFP operation display section) 4(a) to 4(c) show schematic diagrams of examples of the configuration of the operation / display unit 302 of the MFP 300. FIG. 4(a) shows an example in which a touch panel display 401 is used as the operation / display unit 302.
[0030] A user can start up the MFP 300 by touching the power button 301. When the MFP 300 starts up, a home screen (typically the top level of the menu) is displayed on the touch panel display 401 as a screen on which the user can input operations.
[0031] The home screen includes a copy area 405, a scan area 406, and a print area 407. The copy area 405 accepts an instruction to execute a copy process. The scan area 406 accepts an instruction to execute a scan process. The print area 407 accepts an instruction to execute a print process.
[0032] The home screen may further include a status display area 402, a connection setting mode area 403, and a settings area 404. The status display area 402 indicates the settings and connection status of the MFP 300, such as infrastructure connection or direct connection. The connection setting mode area 403 allows the user to start operation in the connection setting mode at any time. The settings area 404 also allows the user to change various settings. Settings that can be changed include, for example, LAN settings.
[0033] FIG. 4(b) shows an example in which a relatively small LCD display 408 and various hard keys 409 to 416 are used as the operation display unit 302.
[0034] When the MFP 300 starts up, a home screen is displayed on the LCD display 408. The user can operate the cursor displayed on the LCD display 408 by pressing cursor movement buttons 411 and 412. The user can press an OK button (decision button) 414 to execute an operation, or a back button 413 to return to the previous menu screen. By selecting and deciding in this way, the user can configure the LAN settings. Pressing the QR button 409 can also display a QR code (registered trademark) containing information necessary for a direct connection with the MFP 300. Note that the code displayed here is not limited to a QR code (registered trademark) and can be any two-dimensional code. By reading this QR code (registered trademark) from the information processing device 200, the information processing device 200 and the MFP 300 are directly connected, enabling wireless communication between them. Pressing the connection setting mode button 410 can start the connection setting mode, and the MFP 300 can be connected to the access point 700 by transmitting connection information to the MFP 300 using the information processing device 200. If the stop button 415 is pressed while the MFP 300 is executing various processes, the various processes are canceled. The user can also scan an original document on the MFP 300 and execute printing by pressing the copy start button 416.
[0035] As shown in Fig. 4(c), the layout of Fig. 4(b) may be changed as appropriate; for example, cursor operation may be performed in the left-right direction. The above-mentioned elements 408 to 416 may be simply expressed as screens; for example, the LCD display 408 may also be expressed as the screen 408. The user can also perform settings related to the LAN (LAN settings), for example, from the operation display unit 302 configured as shown in Fig. 4(c).
[0036] (External configuration of information processing device) FIG. 5 shows an example of the external configuration of the information processing device 200. In this embodiment, the information processing device 200 is a smartphone, and includes a display unit 202, an operation unit 203, and a power key 204. The power key 204 is provided as a hard key for turning the power of the information processing device 200 on or off. In this embodiment, the display unit 202 is a display including an LCD-type display mechanism, but in other embodiments, information may be displayed using an LED or the like. Furthermore, the information processing device 200 may have a function to output information by voice, either in addition to or instead of the display unit 202. The operation unit 203 may include hard keys such as keys and buttons, or a touch panel, and may be configured to be able to detect user operation inputs.
[0037] In this embodiment, the functions of the display unit 202 and the operation unit 203 are realized by a touch panel display, that is, the display unit 202 and the operation unit 203 are realized by a single device. In this case, for example, button icons and a software keyboard are displayed using the function of the display unit 202, and user operation inputs thereto are detected by the function of the operation unit 203. In another embodiment, the display unit 202 and the operation unit 203 may be provided as separate hardware.
[0038] The information processing device 200 may also include a built-in WLAN unit 201 capable of providing WLAN communication functions. The WLAN unit 201 is configured to be capable of performing data (packet) communication in a WLAN system conforming to, for example, the IEEE 802.11 standard series (IEEE 802.11a / b / g / n / ac / ax, etc.). The WLAN unit 201 may also be capable of performing communication in a WLAN system conforming to other standards. Here, the WLAN unit 201 is capable of communication in both the 2.4 GHz and 5 GHz frequency bands. Furthermore, as will be described in detail later, the WLAN unit 201 is capable of performing WFD-based communication, soft AP mode communication, wireless infrastructure mode communication, etc.
[0039] (Configuration of information processing device) 6 shows an example of the configuration of the information processing device 200. The information processing device 200 includes a main board 211 that performs main control of the device itself, a WLAN unit 201 that performs WLAN communication, and a BT (Bluetooth (registered trademark)) unit 205.
[0040] In this embodiment, main board 211 includes CPU 212, ROM 213, RAM 214, image memory 215, and data conversion unit 216. Main board 211 also includes telephone unit 217, GPS (Global Positioning System) 219, camera unit 221, non-volatile memory 222, data storage unit 223, speaker unit 224, and power supply unit 225. These individual functional units within main board 211 are interconnected via system bus 228 and managed by CPU 212. Furthermore, main board 211 and WLAN unit 201, and main board 211 and BT unit 205 are connected via dedicated bus 226.
[0041] The CPU 212 functions as a system control unit that controls each element of the information processing device 200. The individual functions of the information processing device 200 illustrated here and the processes described below as processes executed by the information processing device 200 are realized by the CPU 212 expanding a program stored in the ROM 213 onto the RAM 214 and executing it.
[0042] More specifically, the ROM 213 stores control programs and embedded operating system (OS) programs executed by the CPU 212. The CPU 212 executes corresponding programs under the embedded OS to perform software control such as scheduling and task switching. The RAM 214 is configured with a static RAM (SRAM) or the like. The RAM 214 stores various data such as variables for program control, setting values registered by the user, and management data for managing the information processing device 200. The RAM 214 can be used as various work buffers. The image memory 215 is configured with a memory such as a dynamic RAM (DRAM). The image memory 215 temporarily stores image data received via the WLAN unit 201 and image data read from the data storage unit 223, enabling the image data to be processed by the CPU 212. The non-volatile memory 222 is configured with a memory such as a flash memory, and retains the stored data even when the information processing device 200 is powered off.
[0043] The memory configuration of the information processing device 200 is not limited to the above example. For example, the image memory 215 and the RAM 214 may be provided in common, or data may be backed up using the data storage unit 223. Also, although a DRAM is given here as an example of the image memory 215, other storage media such as an HDD (hard disk drive) or nonvolatile memory may also be used.
[0044] The data conversion unit 216 performs data conversion such as color conversion and image conversion, and can also analyze data in various formats. The telephone unit 217 controls telephone lines and processes audio data input and output via the speaker unit 224, enabling telephone communication. The GPS 219 receives radio waves transmitted from satellites and acquires location information such as the current latitude and longitude of the information processing device 200. The camera unit 221 has the function of electronically recording and encoding images input through a lens. Image data captured by the camera unit 221 is stored in the data storage unit 223. The speaker unit 224 controls functions such as audio input and output for telephone functions and alarm notification. The power supply unit 225 includes a battery and controls the supply of power to individual elements within the device. Power supply states include, for example, a dead battery state in which the remaining battery power is below a certain level, a power-off state in which the power key 204 is not pressed, a power-on state (startup state) in which the power key 204 is pressed, and a power-saving state in which power consumption by individual elements is suppressed.
[0045] Display unit 202 electronically controls the display content and performs control to display operation inputs by the user, the operating status of MFP 300, status status, etc. In response to receiving operation inputs from the user, operation unit 203 outputs an electrical signal corresponding to the operation input to CPU 212. As described in FIG. 5, touch panel displays can be used for display unit 202 and operation unit 203.
[0046] The information processing device 200 is capable of wireless communication using the WLAN unit 201, and performs data communication with other devices such as the MFP 300. For example, the information processing device 200 converts data into packets and transmits them to other external devices. The information processing device 200 also receives packets from other external devices via the WLAN unit 201, restores the packets to the original data, and outputs the restored data to the CPU 212.
[0047] The configuration of the main board 211 is not limited to the above example. For example, each function of the main board 211 implemented by the CPU 212 may be implemented by a processing circuit such as an ASIC (application-specific integrated circuit), that is, may be implemented by either hardware or software.
[0048] (Access point configuration) 7 shows an example of the configuration of an access point 700 equipped with wireless LAN access point functionality. The access point 700 includes a main board 710 that performs system control, a wireless LAN unit 716, a wired LAN unit 718, and operation buttons 720. The main board 710 includes a CPU 711, a program memory 713, a data memory 714, a wireless LAN communication control unit 715, a wired LAN communication control unit 717, an operation unit control circuit 719, a terminal access control unit 721, and a channel change unit 722. These are interconnected via an internal bus 712 so as to be able to communicate with each other. Note that the processes described below as processes executed by the access point 700 are actually realized by the CPU 711 executing programs stored in the program memory 713, the data memory 714, etc.
[0049] The CPU 711 performs arithmetic processing based on a control program stored in a program memory 713 and data held in a data memory 714. The CPU 711 controls a wireless LAN unit 716 via a wireless LAN communication control unit 715, thereby enabling wireless LAN communication with other communication information processing devices. The CPU 711 controls a wired LAN unit 718 via a wired LAN communication control unit 717, thereby enabling wired LAN communication with other communication information processing devices. The CPU 711 also controls an operation unit control circuit 719, thereby enabling operation input from a user via an operation button 720.
[0050] The terminal access control unit 721 protects the network by authenticating communication devices connected to the network. Examples of authentication methods include a PSK method using a Pre-Shared Key (PSK) and an SAE method using Simultaneous Authentication of Equals (SAE). The authentication method (authentication protocol) used for WPA3-Enterprise authentication is the IEEE 802.1X authentication method, which uses an authentication server operating on the Extensible Authentication Protocol (EAP). Because the IEEE 802.1X authentication method uses EAP, the IEEE 802.1X authentication method is referred to as the IEEE 802.1X / EAP authentication method. An EAP method using an IEEE 802.1X / EAP-compatible authentication server can also be used (hereinafter, IEEE 802.1X / EAP may be simply referred to as "802.1X / EAP" in the drawings). The IEEE 802.1X / EAP authentication method is also referred to as the EAP method. The communication channel authenticated in this way can be changed or switched by the channel change unit 722. In this embodiment, the authentication method that does not use an authentication server is the PSK method or the SAE method, and the authentication method that uses an authentication server is the EAP method. The authentication method that does not use an authentication server is also called the Personal method, and the authentication method that uses an authentication server is also called the Enterprise method.
[0051] (Authentication Server Configuration) 8 shows an example of the configuration of an authentication server 800. The authentication server 800 includes a main board 811 that performs system control, and a communication unit 801 that performs wired LAN communication.
[0052] The main board 811 includes a CPU 812, a ROM 813, a RAM 814, an image memory 815, a nonvolatile memory 822, a data storage unit 823, and a communication control unit 826. The main board 811 further includes a display unit 802 and an operation unit 803, which are connected to each other via a system bus (bus cable) 828. The main board 811 is also connected to the communication unit 801 by the communication control unit 826.
[0053] The CPU 812 functions as a system control unit that controls the entire authentication server 800. The processing of the authentication server 800 is realized by the CPU 812 loading a program stored in the ROM 813 into the RAM 814 and executing it.
[0054] More specifically, the ROM 813 stores control programs and embedded OS programs executed by the CPU 812. The CPU 812 executes corresponding programs under the embedded OS to perform software control such as scheduling and task switching. The RAM 814 is configured with an SRAM or the like. The RAM 814 stores various data, such as variables for program control, setting values registered by the user, and management data for managing the authentication server 800. The RAM 814 can be used as various work buffers. The image memory 815 is configured with a memory such as a DRAM. The image memory 815 temporarily stores image data received via the communication unit 801 and image data read from the data storage unit 823, enabling processing by the CPU 812. The data storage unit 812 is configured with a storage medium such as an SSD (Solid State Drive), and retains stored data even when the authentication server 800 is powered off. Other storage media, such as an HDD or nonvolatile memory, may also be used as the data storage unit 212.
[0055] Note that, like the main board 211, the individual functions of the main board 811 described here may be realized by either hardware or software.
[0056] The display unit 802 electronically controls the display content and executes control for displaying operation inputs by the user, status conditions, etc. In response to receiving operation inputs from the user, the operation unit 803 outputs an electrical signal corresponding to the operation input to the CPU 812.
[0057] The authentication server 800 can perform data communication with the access point 700 (or other devices) via the communication unit 801 using the communication control unit 826, for example, converting data into packets and transmitting them to other external devices. The communication unit 801 also receives packets from other external devices, restores the original data, and outputs it to the CPU 812. The communication unit 801 is capable of data (packet) communication in a wired LAN (Ethernet) system that complies with the IEEE 802.3 series, for example.
[0058] (P2P mode) This section describes wireless direct communication in which communication devices communicate and connect wirelessly with each other directly (directly without going through the external access point 700) in WLAN communication. For example, a communication device supports multiple modes for wireless direct communication, and can selectively use one of the multiple modes to perform P2P communication (WLAN). The P2P modes are: Mode A (Soft AP mode) Mode B (Wi-Fi Direct (WFD) mode) Two modes are assumed:
[0059] A communication device capable of P2P communication can be configured to support at least one of these modes (in this specification, Mode A and Mode B can be collectively referred to as Wireless Direct). A communication device capable of P2P communication does not need to support all of these modes and may be configured to support only some of them. Note that MFP 300 operating in P2P mode acts as a master device in connection and communication with other devices. That is, in soft AP mode, MFP 300 acts as a soft AP (access point). In WFDAP mode, MFP 300 acts as a group owner. Note that this is not limited to WFD mode; MFP 300 may act as a client device by executing group owner negotiation. Note that a communication device can also support wireless infrastructure mode (Mode C) in addition to P2P mode.
[0060] In a communication device (e.g., information processing device 200) having a WFD communication function, an application (or a dedicated application) for realizing the communication function is called by accepting a user operation via its operation unit. The communication device displays a UI (user interface) screen provided by the application to prompt the user to input an operation, and can execute WFD communication based on the input operation.
[0061] 10(c) shows a state in which the MFP 300 operates in P2P mode. In this state, communication between the MFP 300 and the information processing device 200 can be realized without going through the authentication server 800 or the access point 700.
[0062] (Wireless infrastructure mode) In the wireless infrastructure mode, communication devices (e.g., information processing device 200 and MFP 300) that communicate with each other are connected to an external access point (here, AP 700) that controls the network, and communication between the devices is performed via the AP. In other words, communication between the devices is achieved via a network established by the AP. Furthermore, MFP 300 operating in the wireless infrastructure mode operates as a slave device (station) in connection and communication with access point 700.
[0063] In the wireless infrastructure mode, each device searches for an access point by transmitting a probe request. When each device receives a probe response from the access point, it displays the SSID (Service Set Identifier) included in the probe response. When the information processing device 200 and the MFP 300 each discover the access point 700, they transmit a connection request to the access point 700, and are connected, enabling communication in the wireless infrastructure mode via the access point 700 between these communication devices.
[0064] Note that multiple communication devices may be connected to different APs. In this case, communication between the communication devices is possible by transferring data between the APs. Commands and parameters sent and received during communication between the communication devices may be compliant with the Wi-Fi standard.
[0065] The access point 700 determines the frequency band and frequency channel. For example, the access point 700 can select whether to use the 5 GHz or 2.4 GHz frequency band and which frequency channel to use within that frequency band.
[0066] When the information processing device 200 or the MFP 300 connects to the wireless LAN configured by the access point 700, authentication is performed by the access point 700. The information processing device 200 or the MFP 300 connects to the wireless LAN configured by the access point 700 using a wireless LAN authentication method such as the PSK method, the SAE method, or the EAP method in accordance with the authentication method of the wireless LAN configured by the access point 700.
[0067] 10(a) shows a state in which MFP 300 operates in wireless infrastructure mode and is connected to access point 700 that supports IEEE802.1X authentication. In this state, communication between MFP 300 and information processing device 200 can be realized based on authentication performed by authentication server 800 in cooperation with access point 700.
[0068] 10(b) shows a state in which MFP 300 operates in wireless infrastructure mode and is connected to access point 700 that does not support IEEE802.1X authentication. In this state, communication between MFP 300 and information processing device 200 can be achieved without authentication performed in cooperation with access point 700 by authentication server 800.
[0069] (wired communication mode) In wired communication mode, a communication device (e.g., MFP 300) can communicate with other communication devices via a wired interface such as a wired LAN. For example, when MFP 300 performs communication in wired communication mode, communication in wireless infrastructure mode is restricted. In wired communication mode, data (packet) communication is possible over a wired LAN (Ethernet) conforming to the IEEE 802.3 series, for example. When operating with the IEEE 802.1X / EAP setting enabled, MFP 300 performs authentication using IEEE 802.1X when connecting to the wired LAN configured by access point 700.
[0070] (Regarding simultaneous wireless operation) When two modes of communication are based on authentication methods that do not use authentication server 800, MFP 300 can simultaneously (concurrently) execute communications in each mode. That is, MFP 300 simultaneously maintains a connection for executing communications in each mode. Specifically, for example, MFP 300 can simultaneously execute communications in both wireless infrastructure mode and P2P mode. Therefore, MFP 300 simultaneously maintains a connection for communicating in wireless infrastructure mode and a connection for communicating in P2P mode. Such an operation may be referred to as "simultaneous wireless operation." Simultaneous wireless operation is, for example, an operation in which MFP 300 simultaneously operates as a client device in Wi-Fi communication in wireless infrastructure mode and as a parent device in Wi-Fi communication in P2P mode. On the other hand, when MFP 300 communicates using an authentication method that uses authentication server 800, it does not simultaneously maintain both an infrastructure connection and a P2P connection. It simultaneously maintains a Wi-Fi communication connection in one mode. When changing the communication mode, the maintained connection is released and a connection in the new communication mode is established.
[0071] (Screen flow) 11(a) to 11(j) are screen flow diagrams when LAN setting is selected from the setting menu of screen 408 in FIG. 4(b) on operation display unit 302 of MFP 300. FIG.
[0072] 11(a) is a screen that is displayed when LAN settings is selected on screen 408 in FIG. 4(b), and allows changes to the LAN settings to be made. Screen 1100 displays wireless LAN 1101, wired LAN 1102, wireless direct 1103, and common settings 1104. When connecting MFP 300 to an access point that supports the Personal method, the user selects wireless LAN 1101.
[0073] A screen 1110 shown in Fig. 11(b) is displayed when wireless LAN setting 1101 is selected on screen 1100 in Fig. 11(a), and allows changes to be made to the wireless LAN settings. Screen 1110 displays wireless LAN enable / disable 1111, wireless LAN setup 1112, wireless LAN setting display 1113, and advanced settings 1114. Wireless LAN enable / disable 1111 is an area for setting whether to enable or disable communication by MFP 300 using wireless LAN. When this area is selected, a user operation is accepted on the display screen, and the state in which communication by MFP 300 using wireless LAN is set to either disabled or enabled. When this state is set to disabled, MFP 300 does not communicate or connect using wireless LAN.
[0074] 11(c) is a screen that is displayed when advanced settings 1114 is selected on the screen 1110 of FIG. 11(b), and allows changes to be made to the LAN advanced settings. The screen 1120 displays TCP / IP settings 1121 and 802.1X / EAP settings 1122.
[0075] Screen 1130 shown in Figure 11(d) is displayed when 802.1X / EAP settings 1122 is selected on screen 1120 in Figure 11(c), and is a screen on which IEEE802.1X / EAP settings can be changed. Screen 1130 displays IEEE802.1X / EAP enable / disable 1131, EAP router search 1132, and previous authentication result confirmation 1133. Note that the EAP router to be searched here is a wireless LAN router with EAP-compatible wireless access point functionality. "EAP router" is just an example of a display, and the EAP router to be searched may be a wireless access point that functions as an IEEE802.1X authenticator.
[0076] Screen 1140 shown in Fig. 11(e) is a screen that is displayed while a wireless access point search is being performed for an authentication method that uses authentication server 800. The access point search can be performed in response to selecting "Search for EAP routers" 1132 on screen 1130 in Fig. 11(d) when IEEE802.1X / EAP settings are enabled. Screen 1140 is displayed during the search.
[0077] Note that the screen 1140 shown in FIG. 11(e) is also displayed when the wireless LAN setup 1112 is selected on the screen 1110 in FIG. 11(b) and a search for a wireless access point using an authentication method that does not use the authentication server 800 is being performed.
[0078] 11(f) is an example of a screen displaying a list of wireless access point identifiers (SSIDs) as a result of an EAP wireless LAN router search, i.e., an access point search (AP search). Screen 1150 shows an example in which a display 1151 of SSID WPA-EAP001, a display 1152 of WPA2-EAP005, and a display 1153 of WPA3-EAP003 are displayed. These correspond to the WPA-EAP, WPA2-EAP, and WPA3-EAP methods, respectively.
[0079] As another example of the display, known methods such as WPA-PSK, WPA2-PSK, and WPA3-SAE may be displayed, and the OPEN method may also be displayed.
[0080] When EAP router search 1132 is executed, only the SSIDs of access points whose authentication method is EAP are displayed on screen 1150 shown in Fig. 11(f). Also, when wireless LAN setup 1112 is executed, only the SSIDs of access points whose authentication method is not EAP are displayed.
[0081] 11(g) is a screen that is displayed while one of the SSIDs (1151 to 1153) of the access points is selected on the screen 1150 of FIG. 11(f) and the MFP 300 is executing a connection process with the selected access point. In another aspect, another display indicating that the connection process is in progress may be displayed.
[0082] Screen 1170 shown in Figure 11(h) is a screen that is displayed after screen 1160 in Figure 11(g) is displayed, when an attempt to connect to an access point is completed and the connection is successful or the connection has progressed to a predetermined stage.
[0083] 11(i) is a screen on which the IEEE802.1X / EAP setting enable / disable 1131 is selected on the screen 1130 of FIG. 11(d), allowing the IEEE802.1X / EAP setting to be changed to enable / disable. It is assumed that the screen 1180 displays enable 1151 and disable 1152. The IEEE802.1X / EAP authentication method is enabled on the MFP 300 when authentication using the IEEE802.1X / EAP authentication method and authentication using the personal method are possible. In other words, the MFP 300 is capable of connecting to an access point compatible with the IEEE802.1X / EAP authentication method and is also capable of connecting to an access point compatible with the personal method. The IEEE802.1X / EAP authentication method is disabled on the MFP 300 when authentication using the IEEE802.1X / EAP authentication method is not possible, and authentication using the personal method is possible. In other words, this is a state in which connection to an access point that supports the IEEE802.1X / EAP authentication method is not possible, but connection to an access point that supports the Personal method is possible.
[0084] A screen 1190 shown in Fig. 11(j) is displayed when EAP router search 1132 is selected on the screen 1130 in Fig. 11(d) when the IEEE802.1X / EAP setting is disabled. In other words, in this embodiment, when the IEEE802.1X / EAP setting is disabled, no router search is performed even if EAP router search 1232 is selected.
[0085] Note that the control for preventing connection to an access point using IEEE 802.1X / EAP authentication, which is executed when the IEEE 802.1X / EAP setting is disabled, is not limited to the control described above. For example, MFP 300 may execute a router search, but may not display access points for which IEEE 802.1X / EAP authentication is enabled in the list of access points discovered by the router search. Alternatively, MFP 300 may display access points for which IEEE 802.1X / EAP authentication is enabled in the list, but may not execute connection processing with such access points even if the user selects them.
[0086] FIG. 12(a) shows an example of a setting screen for MFP300 displayed on information processing device 200. This screen is displayed when a web browser or application running on information processing device 200 communicates with an HTTP server running on MFP300. Specifically, for example, the information processing device 200 accesses MFP300 by inputting the IP address of MFP300 into a web browser running on information processing device 200. In response to this access, MFP300 provides screen information for displaying the screen shown in FIG. 12 to information processing device 200. Then, information processing device 200 displays the screen shown in FIG. 12 based on the screen information provided by MFP300. That is, the screen in FIG. 12 shows an example of a remote user interface (remote UI) related to settings that is displayed on information processing device 200 based on the screen information provided by MFP300. This screen may be displayed based on a standby response to an HTTP request via USB communication using USB communication control unit 320 of MFP300. This screen displays the printer status 1201, main unit settings 1202, LAN settings 1203, and security settings 1204.
[0087] Fig. 12(b) is displayed when security settings 1204 is selected in Fig. 12(a). This screen shows SSL / TLS settings 1211 and IEEE802.1X / EAP settings 1212.
[0088] Fig. 12(c) is displayed when IEEE802.1X / EAP setting 1212 is selected in Fig. 12(b). This screen displays authentication method 1221, key and certificate setting 1222, and IEEE802.1X / EAP enable / disable 1223.
[0089] Fig. 12(d) is displayed when authentication method 1221 is selected in Fig. 12(c). This screen displays EAP-TLS 1231, EAP-TTLS 1232, and PEAP 1233 as authentication methods, as well as a user name (login name) input field 1234 and a password input field 1235. By selecting one of 1231 to 1233 here, the authentication method to be used during IEEE802.1X / EAP authentication is set in MFP 300. Furthermore, by inputting a user name and password in fields 1234 to 1235, the user name and password to be used during IEEE802.1X / EAP authentication are set in MFP 300.
[0090] When registering a certificate to be used during IEEE802.1X / EAP authentication in the MFP 300, first, select "Set Key and Certificate" 1222 on the screen of FIG. 12(c). Then, for example, in the case of EAP-TLS, select "Upload Key and Certificate" 1241 on the screen of FIG. 12(e) to display the screen of FIG. 12(f). On this screen, select a file as the certificate in field 1261, enter a password as the key in field 1262, and then select "Upload" 1263 to complete uploading (sending) the key and certificate to the MFP 300. The key and certificate specified for upload are set in the MFP 300, and the entered user name and password are also set in the MFP 300. The MFP 300 obtains the location and file name of the certificate file, key information, and user name and password from the information processing device 200, and uses the obtained information to perform settings related to IEEE802.1X / EAP authentication.
[0091] On the screen of FIG. 12(e), it is also possible to delete the certificates stored in the MFP 300 in Delete Keys and Certificates 1242, and it is also possible to display a list of the certificates stored in the MFP 300 in Confirm Keys and Certificates 1243.
[0092] Figure 12(g) is displayed by selecting IEEE802.1X / EAP enable / disable 1223 in Figure 12(c). On this screen, the IEEE802.1X / EAP settings of the MFP 300 can be enabled or disabled. Note that enabling the IEEE802.1X / EAP settings means that the MFP 300 is in a state where IEEE802.1X / EAP is enabled. Disabling the IEEE802.1X / EAP settings means that the MFP 300 is in a state where IEEE802.1X / EAP is disabled.
[0093] 12, MFP 300 receives information about authentication used in the IEEE802.1X / EAP authentication method, and based on that information, EAP-related settings are executed on MFP 300. In other words, the information about authentication includes information corresponding to each IEEE802.1X authentication method, among the authentication method used in IEEE802.1X / EAP authentication, the user name and password used in authentication, and the key and certificate used in authentication.
[0094] In this way, authentication information used in IEEE802.1X / EAP can be set in MFP 300. MFP 300 can be authenticated by authentication server 800 using this authentication information, thereby connecting to a network that uses authentication server 800 configured by access point 700. Here, if MFP 300 can simultaneously enable multiple communication modes (here, infrastructure connection and P2P connection), it can connect to the network that uses authentication server 800 via infrastructure connection and also connect to another communication device via P2P. In this case, it is possible for another communication device that has not been authenticated by authentication server 800, such as information processing device 200, to change the settings of MFP 300 or request printing.
[0095] (Processing performed by MFP300) 9 is a flowchart showing processing executed by MFP 300. Note that this flowchart is realized by CPU 311 loading a program stored in program memory 313 into data memory 314 and executing it. Also, this flowchart is assumed to start in a state where MFP 300 and information processing device 200 are connected via a network. Note that at this time, MFP 300 may be connected to information processing device 200 via an infrastructure connection, or may be connected to information processing device 200 via a direct connection. Also, at this time, MFP 300 may be in wireless infrastructure mode, P2P mode, or a simultaneous operation state.
[0096] In S901, CPU 311 receives authentication information from information processing device 200 and uses the information to perform settings related to IEEE802.1X / EAP authentication. Specifically, as described above, CPU 311 accepts access from information processing device 200 and provides information for displaying the screen shown in FIG. 12 to information processing device 200, which is connected to MFP 300. Information processing device 200 displays the screen shown in FIG. 12 based on the received information and accepts input from the user for settings related to IEEE802.1X / EAP authentication. Information processing device 200 then transmits authentication information to MFP 300 for performing settings corresponding to the accepted input on MFP 300. The authentication information transmitted in this manner is received in S901. Note that if MFP 300 is already connected to an access point that supports IEEE802.1X / EAP authentication when the authentication information is received, the previous settings are deleted by the settings based on the authentication information, and MFP 300 may disconnect from the access point.
[0097] In S902, the CPU 311 accepts a predetermined user operation on the main body of the MFP 300. The predetermined user operation is, for example, an operation for establishing a connection between the MFP 300 and an access point that supports IEEE802.1X / EAP authentication.
[0098] Upon receiving a predetermined user operation in S902, processing is executed to establish a connection between an access point that supports IEEE802.1X / EAP authentication and the MFP 300. At this time, it is assumed that the IEEE802.1X / EAP setting of the MFP 300 has been enabled by the setting in S901 or the setting executed before the start of the flowchart of Fig. 9. The processing to establish a connection between the access point that supports IEEE802.1X / EAP authentication and the MFP 300 corresponds to S903 and S904 in this embodiment.
[0099] In S903, CPU 311 disconnects the connection between MFP 300 and the network to which MFP 300 is currently connected. Specifically, for example, if MFP 300 is in wireless infrastructure mode, CPU 311 disconnects the connection between MFP 300 and the external access point. Note that if the connection between MFP 300 and the external access point has already been disconnected, this process is omitted. For example, if MFP 300 is in P2P mode, CPU 311 disconnects the connection between MFP 300 and other devices to which MFP 300 is connected via P2P. For example, if MFP 300 is in a simultaneous operation state, CPU 311 disconnects both the connection between MFP 300 and the external access point and the connection between MFP 300 and other devices to which MFP 300 is connected via P2P. Note that at this time, CPU 311 saves information for returning to the network connection state before the disconnection process.
[0100] In S904, the CPU 311 attempts to establish a connection between the MFP 300 and the network established by the access point 700 and for which IEEE802.1X / EAP authentication is enabled, based on the details of the settings performed in S901.
[0101] In S905, CPU 311 determines whether the connection establishment attempted in S904 was successful. If it is determined that the connection establishment was successful, CPU 311 displays screen 1170 shown in FIG. 11(h) and ends the processing of this flowchart. On the other hand, if it is determined that the connection establishment was unsuccessful, the processing proceeds to S906. Note that a case in which the connection establishment attempted in S904 fails would be, for example, a case in which the content of the settings executed in S901 was incorrect. In other words, a case in which the content entered by the user via the screen shown in FIG. 12 in information processing device 200 was incorrect.
[0102] In S906, CPU 311 executes processing for returning to the network connection state prior to the disconnection processing in S903, based on the information saved in S903. Specifically, for example, if MFP 300 was in wireless infrastructure mode prior to the disconnection processing, it establishes a connection between MFP 300 and an external access point. Also, for example, if MFP 300 was in P2P mode prior to the disconnection processing, it transitions to a state in which a direct connection is possible. A state in which a direct connection is possible includes, for example, a state in which MFP 300 operates as a soft AP, a state in which MFP 300 operates as a group owner, and a state in which group owner negotiation can be performed. When MFP 300 is operating in this state and a connection request is received from another device, MFP 300 establishes a direct connection with the other device. Also, for example, if MFP 300 is in a simultaneous operation state, CPU 311 executes both the establishment of a connection between MFP 300 and an external access point and the transition to a state in which a direct connection is possible.
[0103] For example, if the MFP 300 is in wireless infrastructure mode and connected to an access point that supports IEEE 802.1X / EAP authentication before the disconnection process, the settings related to IEEE 802.1X / EAP authentication have been updated. Therefore, the MFP 300 cannot return to the network connection state before the disconnection process. For example, if the access point to which the MFP 300 was connected before the disconnection process is disabled by being turned off, the MFP 300 cannot return to the network connection state before the disconnection process. If the MFP 300 cannot return to the network connection state before the disconnection process, the MFP 300 may, for example, transition to a state in which a direct connection is possible. For example, the MFP 300 may search for access points around the MFP 300 that can be connected using the Personal method, display a list of one or more found access points, and establish a connection with an access point selected from the list.
[0104] Note that the processing of S906 is not limited to the above, and it is not necessary to return to the network connection state before the disconnection processing of S903. In S906, it is sufficient that MFP300 can connect to information processing device 200 using any method. Specifically, for example, CPU 311 may search for access points around MFP300 that can be connected using the Personal method and display a list of found access points. Then, CPU 311 may execute establishment of a connection between the selected access point and MFP300. If information processing device 200 is connected to the selected access point, the above processing allows MFP300 to connect to information processing device 200.
[0105] In S907, the CPU 311 receives authentication information from the information processing device 200 and uses the information to execute settings related to IEEE802.1X / EAP authentication. This process is the same as S901.
[0106] At this time, even though a predetermined user operation was accepted in S902, the establishment of a connection between the access point supporting IEEE802.1X / EAP authentication and the MFP 300 has failed. In this embodiment, if the establishment of the connection fails, the predetermined user operation is not accepted after the IEEE802.1X / EAP authentication-related settings are executed again. In this case, the predetermined user operation is not accepted, and processing for establishing a connection between the access point supporting IEEE802.1X / EAP authentication and the MFP 300 is automatically executed. That is, based on the IEEE802.1X / EAP authentication-related settings being executed in S907, processing for establishing a connection between the access point supporting IEEE802.1X / EAP authentication and the MFP 300 is automatically executed. The automatically executed processing for establishing a connection between the access point supporting IEEE802.1X / EAP authentication and the MFP 300 corresponds to S908 and S909.
[0107] In S908, the CPU 311 disconnects the connection between the network to which the MFP 300 is currently connected and the MFP 300. This process is similar to S903.
[0108] In S909, the CPU 311 attempts to establish a connection between the MFP 300 and the network established by the access point 700 and for which IEEE802.1X / EAP authentication is enabled, based on the details of the settings performed in S907.
[0109] In S910, the CPU 311 determines whether the connection establishment attempted in S909 was successful. If it is determined that the connection establishment was successful, the CPU 311 ends the processing of this flowchart. On the other hand, if it is determined that the connection establishment was unsuccessful, the CPU 311 returns to S906.
[0110] In the above example, if authentication using IEEE802.1X / EAP fails, the user re-establishes a connection with the network or another device. After configuring the IEEE802.1X / EAP settings on the established connection, the user accesses the access point again using a communication method that requires IEEE802.1X / EAP authentication, and attempts to connect and communicate.
[0111] When the MFP 300 connects to a network that uses the authentication server 800 on the infrastructure connection side, it is desirable to prevent devices that are not authenticated by the authentication server 800 from changing the settings of the MFP 300 or executing printing, regardless of the order in which the communication modes are switched. Therefore, in this embodiment, the time required to set the communication mode can be reduced by dynamically switching the communication mode according to the IEEE802.1X / EAP settings of the MFP 300 and the authentication method of the wireless infrastructure.
[0112] In this embodiment, each communication mode is managed as an enabled (ON state) / disabled (OFF state). For example, in MFP 300, by controlling wireless communication unit 307 and wired LAN communication unit 321, it is possible to switch between enabled communication modes and control communication.
[0113] More generally, in addition to MFPs, for devices that have poor or no UI, such as various sensor devices and input / output devices, users often use a remote UI (remote user interface) to perform settings such as communication settings. The present invention can be applied to communication devices that use a remote UI for configuration. That is, if authentication is required for one of the communication methods provided by the communication function of such devices, and if the configuration is not completed or the authentication fails, the remote UI cannot be provided for that communication method. Therefore, by providing a remote UI for another communication method that does not require authentication, the user can perform configuration via the remote UI.
[0114] The names of the individual elements or functional units described in the above embodiments are expressed in this specification based on their main functions, but may also be expressed based on their sub-functions. Therefore, the present invention is not strictly limited to such expressions (the expressions may be replaced with similar expressions). In the same spirit, the expression "unit" may be replaced with "part," "member," "structure," "assembly," "circuit," etc., or may be omitted.
[0115] The present invention may be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in a computer of the system or device read and execute the program. For example, the present invention may be realized by a circuit (e.g., an ASIC) that realizes one or more functions.
[0116] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]
[0117] 300: communication device, 700: access point, 800: authentication server
Claims
1. A communication device, a receiving means for receiving first information related to IEEE 802.1X authentication from an information processing device via a first wireless connection between the communication device and another device; disconnection means for disconnecting the first wireless connection; an authentication means for performing the IEEE 802.1X authentication based on the received first information in a state where the first wireless connection is not established; an execution means for executing a process for re-establishing the first wireless connection based on the failure of the IEEE 802.1X authentication; and the first wireless connection is a connection between an external access point and the communication device; If the first wireless connection is a connection between the external access point and the communication device corresponding to authentication different from the IEEE 802.1X authentication, a process is performed to re-establish the first wireless connection; If the first wireless connection is a connection between the external access point that supports the IEEE 802.1X authentication and the communication device, a process for re-establishing the first wireless connection is not executed. A communication device comprising:
2. After the process for re-establishing the first wireless connection is executed, second information regarding the IEEE 802.1X authentication is received from the information processing device via the first wireless connection; the IEEE 802.1X authentication based on the received second information is performed in a state where the first wireless connection is not established.
2. The communication device according to claim 1.
3. the IEEE 802.1X authentication based on the received first information is performed based on a predetermined user operation being performed on the communication device after the first information is received.
3. The communication device according to claim 1 or 2.
4. the IEEE 802.1X authentication based on the received second information is automatically performed without the predetermined user operation being performed after the second information is received.
4. A communication device according to claim 3, dependent on claim 2.
5. a transmitting means for transmitting information for displaying a screen for inputting information relating to the IEEE 802.1X authentication to the information processing device via the first wireless connection; 5. The communication device according to claim 1, wherein the first information is information based on an input to the screen.
6. 6. The communication device according to claim 1, wherein the process for re-establishing the first wireless connection is a process for establishing a connection between the external access point and the communication device.
7. A communication device described in any one of claims 1 to 6, characterized in that when the first wireless connection is a connection between the external access point corresponding to the IEEE 802.1X authentication and the communication device, a process is executed to establish a direct connection between the information processing device and the communication device without going through an external access point.
8. A communication device described in any one of claims 1 to 6, characterized in that when the first wireless connection is a connection between the external access point corresponding to the IEEE 802.1X authentication and the communication device, a process is executed to establish a connection between the external access point corresponding to an authentication different from the IEEE 802.1X authentication and the communication device.
9. The communication device described in claim 8, characterized in that the process for establishing a connection between the external access point corresponding to authentication different from the IEEE 802.1X authentication and the communication device includes a process of displaying a list of one or more external access points corresponding to authentication different from the IEEE 802.1X authentication and establishing a connection between the external access point selected from the list and the communication device.
10. and establishing means for establishing a second connection between the communication device and an external access point that supports the IEEE 802.1X authentication after the first information is received; 10. The communication device according to claim 1, wherein the IEEE 802.1X authentication based on the received first information is performed in a state where the second connection is established.
11. 11. The communication device according to claim 1, wherein if the IEEE802.1X authentication is successful, processing for re-establishing the first wireless connection is not executed.
12. 12. The communication device according to claim 1, further comprising a setting unit for switching between a first state in which the IEEE802.1X authentication is valid and a second state in which the IEEE802.1X authentication is invalid.
13. 13. The communication device according to claim 1, wherein the IEEE 802.1X authentication is an authentication method that uses an authentication server that operates on EAP (Extensible Authentication Protocol).
14. 14. The communication device according to claim 13, wherein the authentication server performs authentication using an EAP-TLS (Transport Layer Security) method or an EAP-TTLS (Tunneled TLS) method.
15. It is possible to perform authentication different from the IEEE 802.1X authentication, 15. The communication device according to claim 1, wherein the authentication different from the IEEE 802.1X authentication is an authentication method that does not use an authentication server that operates in accordance with EAP (Extensible Authentication Protocol).
16. It is possible to perform authentication different from the IEEE 802.1X authentication, 16. The communication device according to claim 1, wherein the authentication different from the IEEE 802.1X authentication is a method using PSK (Pre Shared Key) or a method using SAE (Simultaneous Authentication of Equals).
17. 17. A communication device according to claim 1, wherein the first information includes at least one of an authentication method used for the IEEE802.1X authentication, a user name used for the IEEE802.1X authentication, a password used for the IEEE802.1X authentication, a key used for the IEEE802.1X authentication, and a certificate used for the IEEE802.1X authentication.
18. 18. The communication device according to claim 1, further comprising a printing unit for executing printing.
19. A method for controlling a communication device, comprising: a receiving step of receiving first information related to IEEE 802.1X authentication from an information processing device via a first wireless connection between the communication device and another device; a disconnection step of disconnecting the first wireless connection; an authentication step of performing the IEEE 802.1X authentication based on the received first information in a state where the first wireless connection is not established; an execution step of executing a process for re-establishing the first wireless connection based on the failure of the IEEE 802.1X authentication; and the first wireless connection is a connection between an external access point and the communication device; If the first wireless connection is a connection between the external access point and the communication device corresponding to authentication different from the IEEE 802.1X authentication, a process is performed to re-establish the first wireless connection; If the first wireless connection is a connection between the external access point that supports the IEEE 802.1X authentication and the communication device, a process for re-establishing the first wireless connection is not executed. A control method comprising:
20. Computer, A program causing the communication device according to any one of claims 1 to 18 to function as each of the means.
Citation Information
Patent Citations
Communication device
JP2013239906A
Information processing device, control method thereof, and program
JP2018033004A
JP302846A