A first communication device, a computer program for the first communication device, and an application program for the second communication device.

The communication device and mobile terminal use a method that does not include the MAC address in authentication requests to output verification images, enhancing security and user convenience in establishing Wi-Fi connections, addressing limitations in existing methods.

JP7835081B2Active Publication Date: 2026-03-25BROTHER KOGYO KK
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-29
Publication Date
2026-03-25

Smart Images

  • Figure 0007835081000001
    Figure 0007835081000001
  • Figure 0007835081000002
    Figure 0007835081000002
  • Figure 0007835081000003
    Figure 0007835081000003
Patent Text Reader

Abstract

To provide a technique for establishing a wireless connection in accordance with the Wi-Fi standard between a communication device and an external device using a method different from conventional methods.SOLUTION: A first communication device causes an output unit to output an output image obtained using a first key that is a bootstrapping key of the first communication device when receiving, from a second communication device, a first authentication request that does not include a MAC address assigned to the first communication device as a destination address. The first communication device communicates connection information with the second communication device when receiving a second authentication request using the first key from the second communication device after the output image is output. The connection information is information for establishing a wireless connection in accordance with the Wi-Fi standard between the first communication device or the second communication device and an external device.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification discloses a technique for establishing a wireless connection according to the Wi-Fi standard between a communication device and an external device.

Background Art

[0002] Patent Document 1 discloses a technique for establishing a Wi-Fi connection between a printer and an AP (Access Point) using a terminal in accordance with DPP (Device Provisioning Protocol). When the printer receives a Probe request including a predetermined SSID (Service Set Identifier) from the terminal, the printer displays a QR code (registered trademark) obtained by encoding the public key of the printer. The terminal acquires the public key by reading the QR code. Thereby, the terminal uses the public key to establish a Wi-Fi connection between the printer and the AP.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] This specification provides a technique for establishing a wireless connection according to the Wi-Fi standard between a communication device and an external device using a method different from the conventional one.

Means for Solving the Problems

[0005] The first communication device disclosed herein includes a first wireless interface for performing wireless communication in accordance with the Wi-Fi standard, an output unit, and a DPP (Device Provisioning) device that receives a second communication device via the first wireless interface. The system may include: a first authentication request receiving unit that receives a first authentication request in accordance with the DPP protocol, wherein the first authentication request does not include the MAC address assigned to the first wireless interface as the destination address; an output control unit that, when the first authentication request is received from the second communication device, causes the output unit to output an output image obtained using a first key, which is the bootstrapping key of the first communication device; a second authentication request receiving unit that, after the output image has been output, receives a second authentication request in accordance with the DPP, which uses the first key, from the second communication device via the first wireless interface; and a connection information communication unit that, when the second authentication request is received from the second communication device, communicates connection information in accordance with the DPP with the second communication device via the first wireless interface, wherein the connection information is information for establishing a wireless connection in accordance with the Wi-Fi standard between the first or second communication device and an external device.

[0006] According to the above configuration, the first communication device outputs an output image when it receives a first authentication request from the second communication device that does not include the MAC address of the first communication device as the destination address. For this reason, this technology makes it possible to establish a wireless connection in accordance with the Wi-Fi standard between the first or second communication device and an external device using a method different from conventional methods.

[0007] This specification also discloses an application program for a second communication device. The second communication device may include a second wireless interface for performing wireless communication in accordance with the Wi-Fi standard, a camera, and a computer. The application program directs the computer to the following parts: a first authentication request transmission unit that transmits a first authentication request in accordance with DPP (Device Provisioning Protocol) via the second wireless interface, wherein the first authentication request does not include as a destination address the MAC address assigned to the first wireless interface of the first communication device for performing wireless communication in accordance with the Wi-Fi standard; and when the first authentication request is transmitted to the first communication device, and an output image obtained using a first key which is the bootstrapping key of the first communication device is output by the first communication device, and the first output image is captured by the camera, the first key The system may function as follows: an acquisition unit that acquires the key; a second authentication request transmission unit that, when the first key is acquired, transmits a second authentication request in accordance with the DPP, which utilizes the first key, to the first communication device via the second wireless interface; and a connection information communication unit that, when the second authentication request is transmitted to the first communication device, communicates connection information in accordance with the DPP with the first communication device via the second wireless interface, wherein the connection information is information for establishing a wireless connection in accordance with the Wi-Fi standard between the first or second communication device and an external device.

[0008] According to the above configuration, the second communication device sends a first authentication request to the first communication device that does not include the MAC address of the first communication device as the destination address. As a result, the output image is output by the first communication device, and the second communication device can obtain the first key by capturing the first output image. Therefore, according to this technology, a wireless connection in accordance with the Wi-Fi standard can be established between the first or second communication device and an external device using a method different from conventional methods.

[0009] A computer program for realizing the first communication device, and a computer-readable storage medium for storing the computer program, are also novel and useful. A method executed by the first communication device is also novel and useful. A computer-readable storage medium for storing the above-mentioned application program, the second communication device itself realized by the application program, and a method executed by the second communication device are also novel and useful. Furthermore, a communication system comprising the first communication device and the second communication device is also novel and useful. [Brief explanation of the drawing]

[0010] [Figure 1] This shows the configuration of the communication system. [Figure 2] This shows a flowchart of the printer's QR code display process. [Figure 3] This shows a flowchart of the printer verification display process. [Figure 4] The sequence diagram for Case A of the first embodiment is shown. [Figure 5] The sequence diagram for Case B of the first embodiment is shown. [Figure 6] The sequence diagram for the second embodiment is shown. [Figure 7] A sequence diagram of the third embodiment is shown. [Figure 8] A sequence diagram of the fourth embodiment is shown. [Modes for carrying out the invention]

[0011] (First embodiment) (Configuration of communication system 2; Figure 1) As shown in Figure 1, the communication system 2 includes a printer 10 and a mobile terminal 100. In this embodiment, the mobile terminal 100 is used to establish a wireless connection (hereinafter referred to as "Wi-Fi connection") between the printer 10 and the AP (Access Point) 6 in accordance with the Wi-Fi standard. Hereafter, the mobile terminal 100 will be simply referred to as "terminal 100".

[0012] (Printer 10 configuration) The printer 10 is a peripheral device (for example, a peripheral device of terminal 100) capable of performing printing functions. In a modified example, the printer 10 may be a multi-function device capable of performing scanning functions, fax functions, etc., in addition to printing functions. The printer 10 comprises an operation unit 12, a display unit 14, a wireless LAN (abbreviation for Local Area Network) interface 16, a print execution unit 18, and a control unit 30. Each unit 12 to 30 is connected to a bus line (symbol omitted). Hereafter, the interface will be referred to as "I / F".

[0013] The control unit 12 is equipped with multiple keys. By operating the control unit 12, the user can input various instructions to the printer 10. The display unit 14 is a display that shows various information. The display unit 14 also functions as a so-called touch panel (i.e., a control unit that accepts user input). The print execution unit 18 is equipped with a printing mechanism such as an inkjet or laser printer.

[0014] Wireless LANI / F16 is a wireless interface for performing Wi-Fi communication in accordance with the Wi-Fi standard. Wireless LANI / F16 is assigned the MAC address Mp. The Wi-Fi standard is a wireless communication standard for performing wireless communication in accordance with standards such as IEEE (The Institute of Electrical and Electronics Engineers, Inc.) 802.11 and equivalent standards (e.g., 802.11a, 11b, 11g, 11n, 11ac, etc.). In particular, Wireless LANI / F16 supports DPP (Device Provisioning Protocol), which was developed by the Wi-Fi Alliance. Details of DPP are described in the "Wi-Fi Easy Connect Specification Version 2.0" standard document created by the Wi-Fi Alliance.

[0015] The control unit 30 comprises a CPU 32 and a memory 34. The CPU 32 performs various processes according to the program 36 stored in the memory 34. The memory 34 is composed of volatile memory, non-volatile memory, etc.

[0016] In addition to the program 36, the memory 34 pre-stores a secret key SKp1, a public key PKp2, a secret key SKp2 corresponding to the public key PKp2, and a QR code (registered trademark). The secret key SKp1 is a secret key corresponding to the public key PKt1 stored in the terminal 100. The secret key SKp1 is used in the first Authentication (hereinafter referred to as "Auth") executed between the printer 10 and the terminal 100. The public key PKp2 and the secret key SKp2 are used in the second Auth executed between the printer 10 and the terminal 100. The QR code is a code image obtained by encoding the public key PKp2 and the MAC address Mp of the wireless LAN I / F16. The QR code is displayed on the display unit 14 in response to the execution of the first Auth. In this embodiment, the QR code is pre-stored in the memory 34 since the shipment of the printer 10. However, in a modified example, the QR code may be generated when the QR code is displayed.

[0017] (Configuration of Terminal 100) The terminal 100 is a portable terminal device such as a mobile phone (e.g., a smartphone), a PDA, or a tablet PC. In a modified example, the terminal 100 may be a stationary PC, a notebook PC, etc. The terminal 100 includes an operation unit 112, a display unit 114, a wireless LAN I / F116, a camera 118, and a control unit 130. Each unit 112 to 130 is connected by a bus line (reference numerals omitted).

[0018] The operation unit 112 includes a plurality of keys. The user can input various instructions to the terminal 100 by operating the operation unit 112. The display unit 114 is a display for displaying various information. The display unit 114 also functions as a so-called touch panel (i.e., an operation unit that accepts user operations). The wireless LAN I / F116 is the same as the wireless LAN I / F16 of the printer 10. That is, the wireless LAN I / F116 supports the DPP method. The camera 118 is a device for photographing an object. In this embodiment, the camera 118 is used to photograph the QR code displayed on the printer 10.

[0019] The control unit 130 includes a CPU 132 and a memory 134. The CPU 132 executes various processes according to programs 136 and 138 stored in the memory 134. The memory 134 is composed of a volatile memory, a non-volatile memory, etc.

[0020] The OS (abbreviation for Operating System) program 136 is a program for realizing the basic operations of the terminal 100. The application 138 is a program for establishing a Wi-Fi connection between the terminal 100 and the AP6 or for establishing a Wi-Fi connection between the printer 10 and the AP6. Hereinafter, the OS program 136 and the application 138 will be described as "OS 136" and "app 138", respectively. The app 138 is installed on the terminal 100 from, for example, a server on the Internet (not shown) provided by the vendor of the printer 10 or a server on the Internet (not shown) provided by the vendor of the OS 136. The app 138 can cause the OS 136 to execute various processes or cause other apps to execute various processes via the OS 136 by supplying instructions to the OS 136. Therefore, it can be said that each of the following processes executed by the OS 136 or other apps in response to instructions from the app 138 is a process realized by the app 138 (that is, the app 138 functions as the execution unit that executes the process by causing the CPU 132 to function).

[0021] (QR code display process of printer 10: Figure 2) Referring to Figure 2, the QR code display process executed by the CPU 32 of the printer 10 will be described. The process of Figure 2 is executed triggered by the printer 10 being powered on.

[0022] In S10, the CPU 32 determines whether or not AP information is already stored in memory 34. AP information is information for establishing a Wi-Fi connection with AP6. For example, if the SSID (Service Set Identifier) ​​and password of AP6 are entered into the printer 10 by the user, AP information including the SSID and password is stored in memory 34. Also, if a printer Configuration Object (hereinafter referred to as "printer CO") according to the DPP described later is sent from terminal 100 to printer 10, AP information including the printer CO is stored in memory 34. If the CPU 32 determines that AP information is already stored in memory 34 (YES in S10), it proceeds to S50, and in this case, it does not execute the processes in S20 to S42 described later. In this way, when printer 10 has stored AP information, it does not execute the process for displaying the QR code (for example, monitoring and verifying the Auth Req described later). This prevents unnecessary reconfiguration of AP information from being performed on printer 10. On the other hand, if the CPU 32 determines that the AP information is not already stored in memory 34 (NO in S10), it proceeds to S12.

[0023] In S12, the CPU 32 changes the state of the printer 10 from a state in which it is unable to perform processing according to DPP (hereinafter referred to as "DPPOFF state") to a state in which it is able to perform processing according to DPP (hereinafter referred to as "DPPON state"). The DPPOFF state is a state in which it is unable to send an Auth Response in response to receiving an Auth Request from terminal 100. Hereinafter, Request and Response will be referred to as "Req" and "Res", respectively. The DPPON state is a state in which it is able to send an Auth Res in response to receiving an Auth Req from terminal 100.

[0024] In S20, the CPU 32 monitors whether a first predetermined time T1 has elapsed since the printer 10 was powered on. If T1 has elapsed (YES in S20), the CPU 32 proceeds to S62; otherwise, if T1 has not elapsed (NO in S20), the CPU 32 proceeds to S30.

[0025] In S30, CPU32 monitors for the reception of a broadcast Auth Request. In a broadcast Auth Request, the MAC address Mp of printer 10 is not specified as the destination address; instead, a predetermined address indicating a broadcast (e.g., ff:ff:ff:ff:ff:ff) is specified as the destination address. If CPU32 receives the Auth Request from terminal 100 (YES in S30), it proceeds to S40; otherwise, it returns to monitoring in S20.

[0026] In S40, CPU32 performs verification and display processing to verify the Auth Request and display the QR code.

[0027] In S42, CPU32 determines whether or not a QR code was displayed in S40. If a QR code was displayed in S40 (YES in S42), CPU32 terminates the process shown in Figure 2. If a QR code was not displayed in S40 (NO in S42), CPU32 returns to monitoring in S20.

[0028] In S50, the CPU 32 monitors whether a DPPON operation is performed on the operation unit 12 or the display unit 14. A DPPON operation is an operation to change the state of the printer 10 from the DPPOFF state to the DPPON state. If a DPPON operation is performed (YES in S50), the CPU 32 proceeds to S52; if a DPPON operation is not performed (NO in S50), it continues monitoring in S50.

[0029] S52 is the same as S12. In S60, the CPU 32 monitors whether a second predetermined time T2 has elapsed since the DPPON operation was performed in S50. If T2 has elapsed (YES in S60), the CPU 32 proceeds to S62; otherwise, it proceeds to S70.

[0030] In S62, the CPU 32 changes the state of the printer 10 from the DPPON state to the DPPOFF state. Thus, if T1 has elapsed since the power-on operation without receiving an Auth Req (YES in S20), the printer 10 changes from the DPPON state to the DPPOFF state (S62) and does not display the QR code. Also, if T2 has elapsed since the DPPON operation without receiving an Auth Req (YES in S60), the printer 10 changes from the DPPON state to the DPPOFF state (S62) and does not display the QR code. Therefore, it is possible to suppress the printer 10 from performing unnecessary AP information reconfiguration. When S62 is completed, the CPU 32 returns to monitoring in S50.

[0031] S70, S80, and S82 are the same as S30, S40, and S42, respectively. CPU32 terminates the process shown in Figure 2 if a QR code is displayed in S80 (YES in S82), and returns to monitoring S50 if a QR code is not displayed in S80 (NO in S82).

[0032] (Verification display process: Figure 3) Referring to Figure 3, the verification display process performed in S40 or S80 in Figure 2 will be explained. In S100, the CPU 32 determines whether the verification of the Auth Request received in S30 or S70 was successful. The Auth Request includes verification data, which is generated by using a public key. The public key may be stored in advance on the device that sent the Auth Request (e.g., terminal 100), or it may be generated by the device using a PKEX file as described in the DPP specification. The CPU 32 uses the private key SKp1 in memory 34 to perform verification of the verification data.

[0033] If the Auth Request received in S30 or S70 was sent from terminal 100, the verification data included in the Auth Request is generated by using the public key PKt1 stored in terminal 100, specifically the public key PKt1 corresponding to the private key SKp1. In this case, CPU 32 succeeds in verifying the verification data (YES in S100) and proceeds to S110. On the other hand, if the Auth Request received in S30 or S70 was sent from a device other than terminal 100, the verification data included in the Auth Request is generated by using a public key different from the public key PKt1. In this case, CPU 32 fails to verify the verification data (NO in S100) and terminates the process shown in Figure 3 without executing S110 (i.e., without displaying the QR code).

[0034] In S110, the CPU 32 displays a QR code pre-stored in memory 34 on the display unit 14 without sending an Auth Res to the terminal 100. When S110 is completed, the process shown in Figure 3 is finished.

[0035] (Specific cases: Figures 4 and 5) Referring to Figures 4 and 5, we will explain specific cases realized by the processes shown in Figures 2 and 3. For ease of understanding, the operations performed by the CPU of each device (e.g., CPU 32) will be described from the perspective of each device (e.g., printer 10, terminal 100) rather than the CPU. Furthermore, each of the following communications will be performed via wireless LAN I / F16 or 116. Therefore, the phrase "via wireless LAN I / F16 or 116" will be omitted when describing each of the following communications.

[0036] (Case A: Figure 4) First, let's explain Case A with reference to Figure 4. In the initial state shown in Figure 4, terminal 100 has established a Wi-Fi connection with AP6. Therefore, terminal 100 stores AP information for establishing a Wi-Fi connection with AP6. For example, if the SSID and password of AP6 have already been entered into terminal 100 by the user, AP information including the SSID and password will be stored in terminal 100. Also, if a Wi-Fi connection has been established between terminal 100 and AP6 according to DPP, AP information according to DPP (e.g., a Configuration Object for terminals) will be stored in terminal 100. Note that printer 10 does not yet store AP information, for example, when it is first powered on after being shipped.

[0037] At T10, printer 10 receives a power-on command from the user (trigger for the process in Figure 2). In this case, at T12, printer 10 transitions from the DPPOFF state to the DPPON state (YES at S10, S12).

[0038] Terminal 100 receives an operation from the user to launch application 138 at T20. In this case, terminal 100 launches application 138. As a result, all subsequent processes executed by terminal 100 are initiated by application 138. That is, all subsequent processes executed by terminal 100 are processes implemented by application 138 (i.e., application 138 causes CPU 132 to function as the execution unit that executes the said process).

[0039] Terminal 100 accepts DPP operations from the user at T22. A DPP operation is the operation of selecting the DPP button included in the home screen (not shown) displayed by application 138. As a result, terminal 100 starts the process of establishing a Wi-Fi connection between printer 10 and AP6 according to DPP.

[0040] When terminal 100 receives a DPP operation at T22, it generates an Auth Req. The Auth Req is a signal requesting verification of verification data. Specifically, application 138 already contains the public key PKt1. Terminal 100 uses the public key PKt1 to generate verification data and also generates an address indicating a broadcast. Then, terminal 100 generates an Auth Req that includes the verification data and the address as the destination address. Then, at T30, terminal 100 sends the generated broadcast Auth Req (i.e., an Auth Req that does not specify the MAC address of a particular device).

[0041] The T30 process described above is achieved when the application 138 on terminal 100 generates an Auth Request and instructs the OS 136 to send the Auth Request. As a result, the OS 136 executes processing according to DPP, including the sending of the Auth Request. Here, after a predetermined time has elapsed since the application 138 instructed the OS 136 to send the Auth Request, it instructs the OS 136 to cancel the processing according to DPP. The predetermined time is set in advance so that the processing according to DPP is canceled after the sending of the Auth Request is completed (i.e., after the printer 10 displays the QR code). As a result, the OS 136 cancels the processing according to DPP, and can properly execute the second Auth described later according to the instructions from the application 138.

[0042] At T12, printer 10 transitions to the DPPON state, and at T30, it can receive an Auth Request from terminal 100 (YES at S20). In this case, printer 10 uses the private key SKp1 to verify the verification data contained in the Auth Request (S100 in Figure 3). The private key SKp1 corresponds to the public key PKt1 used to generate the verification data. Therefore, at T32, the verification is successful (YES at S100). The processes at T30 and T32 described above correspond to DPP authentication, and in this embodiment in particular, they correspond to the first authentication. In a modified example, printer 10 may use other information instead of the private key SKp1 to perform the verification. For example, printer 10 may store the same information as terminal 100's public key PKt1 and use the public key PKt1 to perform the verification.

[0043] The printer 10 displays the QR code stored in memory 34 at T34 without sending Auth Res to terminal 100 (S110). In this way, since the printer 10 does not send Auth Res, the processing load on the printer 10 can be reduced.

[0044] Since printer 10 does not send an Auth Res, the following effects can be obtained. For example, consider a situation where multiple printers, including printer 10, exist around terminal 100. The user of terminal 100 wants to establish a Wi-Fi connection between only printer 10 and AP6. If a configuration were adopted in which each printer sends an Auth Res to terminal 100, terminal 100 may receive an Auth Res from a printer other than printer 10 in response to sending an Auth Req in T30. In this case, processing according to DPP would proceed between terminal 100 and the other printer, so for example, terminal 100 may send AP information to the other printer to establish a Wi-Fi connection with AP6. As a result, a Wi-Fi connection may be established between AP6 and a printer that the user did not intend. In contrast, in this embodiment, since a configuration is adopted in which each printer does not send an Auth Res, processing according to DPP between terminal 100 and the above-mentioned other printer can be suppressed. As a result, it is possible to suppress the establishment of a Wi-Fi connection between AP6 and a printer that the user did not intend.

[0045] In particular, terminal 100 transmits an Auth Request using one of the multiple channels (i.e., multiple frequency bands) in T30. If terminal 100 does not receive an Auth Res in response to the Auth Request, it sequentially transmits Auth Requests using the other channels among the multiple channels. Therefore, even if each of the multiple printers is waiting for an Auth Request on a different channel, the QR code can be displayed on each of the multiple printers. Consequently, the QR code can be displayed appropriately on printer 10.

[0046] Furthermore, in this embodiment, since the user has terminal 100 take a picture of the QR code displayed on the printer, even if a QR code is displayed on each of the multiple printers mentioned above, the user only needs to have terminal 100 take a picture of the QR code displayed on printer 10 among the multiple printers, and a Wi-Fi connection can be properly established between printer 10 and AP6.

[0047] Furthermore, the printer 10 receives an Auth Request using the public key PKt1 from the terminal 100 and displays a QR code only if the Auth Request is successfully verified. If the printer 10 were configured to display a QR code even if it fails to verify the Auth Request, it would display a QR code representing its public key PKp2 and MAC address Mp even if it received an Auth Request from a device that does not have the public key PKt1 (i.e., a device that does not have the application 138). This would increase the likelihood that the printer 10's public key PKp2, etc., could be obtained by a third party, creating a security problem. In contrast, this embodiment employs a configuration where the printer 10 displays a QR code only if the Auth Request is successfully verified, thus reducing the likelihood that the printer 10's public key PKp2, etc., could be obtained by a third party, resulting in high security.

[0048] Furthermore, consider an environment with multiple printers, including printer 10, where a configuration is adopted that displays a QR code even if each printer fails to verify the Auth Request. In this case, each printer will display a QR code regardless of whether the verification succeeds or fails, regardless of which terminal receives the Auth Request. Consequently, a QR code may be displayed on a printer that the user of terminal 100 did not intend to use. In this case, the user of that printer may be confused by the display of the QR code, and the user of terminal 100 may be confused about which printer to establish a Wi-Fi connection between the AP and the printer. In other words, user convenience may be impaired. In contrast, this embodiment adopts a configuration that displays a QR code only if printer 10 successfully verifies the Auth Request, so that the QR code can be displayed on the printer 10 that the user of terminal 100 intended to use (i.e., the printer 10 corresponding to application 38). Therefore, the impairment of user convenience can be suppressed.

[0049] When terminal 100 sends an Auth Request at T30, it displays a screen (not shown) prompting the user to take a picture of the QR code displayed on printer 10. Therefore, at T40, terminal 100 accepts an operation from the user to take a picture of the QR code. In this case, terminal 100 decodes the QR code and obtains the public key PKp2 and MAC address Mp. Each of the processes from T34 to T42 described above corresponds to DPP Bootstrapping.

[0050] Terminal 100 generates an Auth Request at T50. Specifically, terminal 100 generates verification data using the public key PKp2 obtained at T40. Then, terminal 100 generates an Auth Request that includes this verification data and the MAC address Mp obtained at T40 as the destination address. Next, terminal 100 sends the generated Auth Request (i.e., an Auth Request specifying the MAC address of a particular device) to printer 10. In a modified example, the Auth Request at T50 may include an address indicating a broadcast as the destination address instead of the MAC address Mp. That is, the Auth Request at T50 may be a broadcast Auth Request.

[0051] When printer 10 receives an Auth Request from terminal 100 at T50, it uses the private key SKp2 to verify the verification data contained in the Auth Request. The private key SKp2 corresponds to the public key PKp2 used to generate the verification data. Therefore, verification succeeds at T52. In this case, printer 10 sends an Auth Res indicating successful verification to terminal 100 at T54.

[0052] When terminal 100 receives an Auth Res from printer 10 at T54, it sends an Auth Confirm to printer 10 at T56 indicating that it has received the Auth Res. Each of the processes from T50 to T56 described above corresponds to DPP authentication, and in this embodiment in particular, it corresponds to the second authentication.

[0053] When printer 10 receives Auth Confirm from terminal 100 at T56, it sends a Configuration (hereinafter referred to as "Config") Req to terminal 100 at T60. The Config Req is a signal requesting terminal 100 to send a printer CO.

[0054] When terminal 100 receives a Config Request from printer 10 at T60, it generates a printer CO. Specifically, if terminal 100 has stored AP information, including the SSID and password of AP6, it generates a printer CO that includes the SSID and password. Also, if terminal 100 has stored AP information according to DPP, for example, it generates a printer CO corresponding to that AP information. Then, at T62, terminal 100 sends a Config Request containing the generated printer CO to printer 10.

[0055] When printer 10 receives Config Res from terminal 100 in T62, it stores the printer CO included in Config Res in T64. Each of the processes from T56 to T64 described above corresponds to the DPP configuration.

[0056] Next, printer 10 performs DPP Network Access with AP6 on T70. Network Access is a process that uses the information contained in the printer CO to communicate with AP6 and establish a Wi-Fi connection with AP6. As a result, a Wi-Fi connection is established between printer 10 and AP6. Consequently, both printer 10 and terminal 100 belong to the wireless network formed by AP6.

[0057] As described above, the printer 10 can establish a Wi-Fi connection with the AP6. To do this, the printer 10 can receive print data representing the image to be printed from the terminal 100 via the AP6 and execute printing of the image represented by the print data.

[0058] (Case B: Figure 5) Next, we will explain Case B with reference to Figure 5. T110 and T112 are the same as T10 and T12 in Figure 4.

[0059] If the printer 10 has not received a broadcast Auth Request since the power-on operation T110 was performed, and a first predetermined time T1 has elapsed, at T114, it will transition from the DPPON state to the DPPOFF state (YES at S20, S62).

[0060] Subsequently, when printer 10 receives a DPPON operation at T120, it transitions from the DPPOFF state to the DPPON state at T122 (YES at S50, S52). Therefore, printer 10 can once again transition to a state where it can perform processing for displaying a QR code (e.g., monitoring and verifying the Auth Request). The subsequent processing is the same as T20 to T70 in Figure 4.

[0061] (Effects of this embodiment) According to the above embodiment, when the printer 10 receives a broadcast Auth Request from the terminal 100 that does not include the printer 10's MAC address Mp as the destination address (T30 in Figure 4), it displays a QR code (T34). Therefore, the printer 10 can establish a Wi-Fi connection with AP6 using a method different from conventional methods.

[0062] Here, we consider a comparative example in which terminal 100 sends a Probe Request that includes a predetermined SSID as the destination SSID, instead of sending a broadcast Auth Request. This predetermined SSID includes a predetermined string of characters for displaying a QR code on printer 10. Therefore, when printer 10 receives a Probe Request containing the predetermined SSID from terminal 100, it displays a QR code. However, with this configuration, terminal 100's OS program 136 recognizes the predetermined SSID as the SSID of an existing AP, and may display a confirmation screen to ask the user whether it is OK to establish a Wi-Fi connection with the AP before sending the Probe Request. However, since the AP does not actually exist, this may cause confusion for the user. In contrast, according to this embodiment, terminal 100 displays a QR code on printer 10 by sending a broadcast Auth Request instead of a Probe Request containing the predetermined SSID. For this reason, OS program 136 does not display the above confirmation screen. Since a confirmation screen that may cause confusion for the user is not displayed, user convenience is improved.

[0063] (Correspondence) Printer 10, terminal 100, and AP6 are examples of the "first communication device," "second communication device," and "external device," respectively. The correspondence regarding the "first communication device" is as follows. Display unit 14 and wireless LAN I / F 16 are examples of the "output unit" and "first wireless interface," respectively. Public key PKp2 and public key PKt1 are examples of the "first key" and "second key," respectively. Processing S30 or S70 in Figure 2 is an example of processing performed by the "first authentication request receiving unit." Processing S110 or S130 is an example of processing performed by the "output control unit." Processing T50 and T62 in Figure 4 are examples of processing performed by the "second authentication request receiving unit" and "connection information communication unit," respectively.

[0064] The correspondence regarding the "second communication device" is as follows: Wireless LANI / F116 is an example of the "second wireless interface". The processes T30, T42, T50, and T62 in Figure 4 are examples of processes executed by the "first authentication request transmission unit", "acquisition unit", "second authentication request transmission unit", and "connection information communication unit", respectively.

[0065] (Second embodiment: Figure 3) Next, a second embodiment will be described. In this embodiment, the processing at S110 in Figure 3 differs from that of the first embodiment. Despite the verification being successful in S100, the CPU 32 sends an Auth Res to the terminal 100 in S110 indicating that the verification failed (i.e., an error). The CPU 32 then displays a QR code on the display unit 14.

[0066] (Specific case: Figure 6) Referring to Figure 6, a specific case realized by this embodiment will be explained. T210 to T232 are the same as T10 to T32 in Figure 4. At T233, the printer 10 sends an Auth Res indicating an error to the terminal 100 (S110 in Figure 3). Therefore, the terminal 100 can know that the verification of the Auth Req has failed. As a result, the terminal 100 terminates the processing according to DPP, and the user can immediately have the terminal 100 take a picture of the QR code. The subsequent T234 to T270 are the same as T34 to T70 in Figure 4.

[0067] (Third embodiment: Figure 3) Next, a second embodiment will be described. In this embodiment, the process in S110 in Figure 3 differs from that in the first and second embodiments. In S110, the CPU 32 sends an Auth Res to the terminal 100 indicating that the verification was successful, and receives an Auth Confirm from the terminal 100. The Auth Confirm is a confirmation signal indicating that the Auth Res has been received. The CPU 32 then displays a QR code on the display unit 14.

[0068] (Specific case: Figure 7) Referring to Figure 7, a specific case realized by this embodiment will be explained. T310 to T332 are the same as T10 to T32 in Figure 4. At T333, printer 10 sends an Auth Res indicating success to terminal 100 (S110 in Figure 3). Therefore, terminal 100 can know that the verification of the Auth Req was successful.

[0069] Subsequently, printer 10 receives Auth Confirm from terminal 100 at T334 (S110). In this case, printer 10 displays a QR code at T336 (S110). Thus, in this embodiment, the QR code is displayed on printer 10 after all Auth processing as defined in DPP is completed.

[0070] In this embodiment, since the first authentication is successful between the printer 10 and the terminal 100, the terminal 100 may continue processing according to DPP. To avoid this, the application 138 instructs the OS 136 to cancel the processing according to DPP after a predetermined time has elapsed since instructing the OS 136 to send the Auth Request. The predetermined time is set in advance so that the processing according to DPP is canceled after the transmission of the Auth Confirm is completed (i.e., after the printer 10 displays the QR code) and before the terminal 100 completes the processing according to DPP in response to the success of the first authentication. As a result, the OS 136 cancels the processing according to DPP, thus preventing the continuation of processing according to DPP in response to the success of the first authentication. As a result, the OS 136 can appropriately execute the transmission of the second Auth Request according to the instructions from the application 138.

[0071] In this embodiment, the processing of T333 and the processing of T334 are examples of processes performed by the "authentication response transmission unit" and the "authentication confirmation reception unit," respectively.

[0072] (Fourth embodiment: Figure 3) Next, a fourth embodiment will be described. In this embodiment, the memory 34 of the printer 10 does not pre-store the secret key SKp1. Then, in the verification display process shown in Figure 3, the processes S120 and S130 are executed instead of the processes S100 and S110 in Figure 3.

[0073] When CPU32 performs verification of the Auth Request received in S30 or S70 in Figure 2, it cannot use the private key SKp1. Therefore, in S120, CPU32 fails to verify the Auth Request. In this case, in S130, CPU32 displays a QR code without sending an Auth Res to terminal 100. In a modified example, CPU32 may send an Auth Res indicating that verification failed (i.e., an error) to terminal 100 in S130.

[0074] (Specific case: Figure 8) Referring to Figure 8, a specific case realized by this embodiment will be explained. T410 to T430 are the same as T10 to T30 in Figure 4. Printer 10 fails to verify the Auth Request at T432 (S120). Printer 10 displays a QR code at T436 without sending the Auth Res to terminal 100 (S130). The subsequent T440 to T470 are the same as T40 to T70 in Figure 4. According to this embodiment, since printer 10 does not need to store the secret key SKp1 in advance, the amount of information that printer 10 needs to store can be reduced.

[0075] Although specific examples of the present invention have been described in detail above, these are merely illustrative and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes to the specific examples illustrated above. Modifications of the above embodiments are listed below.

[0076] (Modification 1) In step S110 or S130 of Figure 3, instead of displaying the QR code on the display unit 14, the printer 10 may, for example, have the print execution unit 18 print the QR code. In this modification, the print execution unit 18 is an example of an "output unit".

[0077] (Modification 2) At T62 in Figure 4, the printer 10 may receive a printer CO from terminal 100 to establish a Wi-Fi connection with terminal 100. In this case, at T70, instead of establishing a Wi-Fi connection with AP6, the printer 10 uses the printer CO to establish a Wi-Fi connection with terminal 100. In this modification, the printer CO is an example of "connection information," and terminal 100 is an example of an "external device."

[0078] (Modification 3) The "first communication device" may be another device such as a terminal device, scanner, multifunction printer, or server instead of the printer 10. The "second communication device" may be another device such as a printer, scanner, multifunction printer, or server instead of the terminal 100. Here, for example, consider a modification in which the "first communication device" and the "second communication device" are the first terminal device and the second terminal device, respectively. The first terminal device has already established a Wi-Fi connection with AP6 and stores AP information. When the first terminal device receives a broadcast Auth Request from the second terminal device, it displays a QR code obtained using the public key of the first terminal device, then receives an Auth Request from the second terminal device, sends an Auth Res to the second terminal device, and receives an Auth Confirm from the second terminal device. Then, the first terminal device receives a Config Request from the second terminal device, generates a CO for the second terminal device using the AP information, and sends a Config Res including the CO to the second terminal device. In this case, the second terminal device uses the CO to establish a Wi-Fi connection with AP6. In this modified example, the first terminal device and the second terminal device are examples of the "first communication device" and the "second communication device," respectively, and the "connection information communication unit" transmits connection information to the second communication device. In this case, the "connection information" is information for establishing a wireless connection between the "second communication device" and the "external device."

[0079] (Modification 4) The printer 10 does not need to pre-store the private key SKp1, and the terminal 100 does not need to pre-store the public key PKt1. Both or one of the printer 10 and the terminal 100 may pre-store information used in PKEX as defined in DPP (e.g., a specific key, string, etc.). In this case, the printer 10 and the terminal 100 may perform communication using PKEX before performing communication of the broadcast Auth Request to generate the public key to be used in Auth. Then, the printer 10 and the terminal 100 perform communication of the broadcast Auth Request using the generated public key. Generally speaking, the "second communication device" does not need to pre-store the second key.

[0080] (Modification 5) The process in S20 in Figure 2 may be omitted, and the process may proceed to S30 after S12, and if NO is found in S30, monitoring of S30 may continue. Generally speaking, the "output control unit" does not need to change its processing depending on whether or not the "first predetermined time" has elapsed.

[0081] (Modification 6) The processes in S60 and S62 in Figure 2 may be omitted, and the process may proceed to S70 after S52, and if NO is found in S70, monitoring of S70 may continue. Generally speaking, the "output control unit" does not need to change its processing depending on whether or not the "second predetermined time" has elapsed.

[0082] (Modification 7) The process in S10 in Figure 2 may be omitted, and the process may always proceed to S12 when the printer 10 is powered on. Generally speaking, the "output control unit" does not need to change its processing depending on whether or not the "connection information" is stored in memory.

[0083] (Modification 8) In each of the above embodiments, the processes shown in Figures 2 to 8 are realized by the CPUs 32 and 132 executing programs 36 and 136. Alternatively, any of the processes shown in Figures 2 to 8 may be realized by hardware such as logic circuits.

[0084] Furthermore, the technical elements described herein or in the drawings demonstrate technical usefulness individually or in various combinations, and are not limited to the combinations described in the claims at the time of filing. In addition, the technologies illustrated herein or in the drawings achieve multiple objectives simultaneously, and achieving even one of these objectives constitutes technical usefulness in itself. [Explanation of Symbols]

[0085] 2: Communication system, 6: AP, 10: Printer, 12: Operation unit, 14: Display unit, 16: Wireless LAN interface, 18: Print execution unit, 30: Control unit, 32: CPU, 34: Memory, 36: Program, 100: Mobile terminal, 112: Operation unit, 114: Display unit, 116: Wireless LAN interface, 118: Print execution unit, 130: Control unit, 132: CPU, 134: Memory, 136: OS program, 138: Application, SKp1, SKp2: Private key, PKt1, PKp2: Public key

Claims

1. A first communication device, A first wireless interface for performing wireless communication in accordance with the Wi-Fi standard, Output section, A first authentication request receiving unit receives a first authentication request in accordance with DPP (Device Provisioning Protocol) from a second communication device via the first wireless interface, wherein the first authentication request does not include the MAC address assigned to the first wireless interface as the destination address. When the first authentication request is received from the second communication device, an output control unit causes the output unit to output an output image obtained using the first key, which is the bootstrapping key of the first communication device. After the output image is output, the second authentication request receiving unit receives a second authentication request in accordance with the DPP, which is the second authentication request using the first key, from the second communication device via the first wireless interface. When the second authentication request is received from the second communication device, a connection information communication unit communicates connection information in accordance with the DPP to the second communication device via the first wireless interface, wherein the connection information is information for establishing a wireless connection in accordance with the Wi-Fi standard between the first or second communication device and an external device, the connection information communication unit, A first communication device comprising the following:

2. The first communication device according to claim 1, wherein the first authentication request receiving unit receives the first authentication request from the second communication device using a second key which is a bootstrapping key.

3. The first communication device according to claim 1 or 2, wherein the output control unit causes the output image to be output to the output unit when the first authentication request is received from the second communication device.

4. The first communication device further includes: When the first authentication request is received from the second communication device, an authentication response transmission unit transmits an authentication response in accordance with the DPP to the second communication device via the first wireless interface, The system includes an authentication confirmation receiving unit that receives an authentication confirmation in accordance with the DPP from the second communication device via the first wireless interface when the authentication response is transmitted to the second communication device. The first communication device according to claim 1 or 2, wherein the output control unit causes the output image to be output to the output unit when the authentication confirmation is received from the second communication device.

5. The first communication device according to any one of claims 1 to 4, wherein the output control unit causes the output image to be output to the output unit when the first authentication request is received from the second communication device and the verification of the first authentication request is successful.

6. The first communication device according to claim 5, wherein if the first authentication request is received from the second communication device and the verification of the first authentication request is successful, an authentication response in accordance with the DPP is not transmitted to the second communication device.

7. The first communication device further includes: The first communication device according to claim 5, further comprising an authentication response transmission unit that, when the first authentication request is received from the second communication device and the verification of the first authentication request is successful, transmits to the second communication device via the first wireless interface an authentication response in accordance with the DPP, which indicates that the verification has failed.

8. The first communication device according to any one of claims 1 to 3, wherein the output control unit causes the output image to be output to the output unit when the first authentication request is received from the second communication device and the verification of the first authentication request fails.

9. The output control unit, If the first authentication request is received from the second communication device before a first predetermined time has elapsed since the power of the first communication device was turned ON, the output image is output to the output unit. The first communication device according to any one of claims 1 to 8, wherein the output image is not output to the output unit when a predetermined first time has elapsed since the power of the first communication device was turned ON.

10. The output control unit, When the power of the first communication device is turned ON, and before a second predetermined time has elapsed since a predetermined operation was performed on the first communication device, if the first authentication request is received from the second communication device, the output image is output to the output unit. The first communication device according to any one of claims 1 to 9, wherein, when the power of the first communication device is turned ON, the output image is not output to the output unit when a second predetermined time has elapsed since the predetermined operation has been performed on the first communication device.

11. The output control unit, When the connection information for establishing the wireless connection between the first communication device and the external device is not stored in the memory of the first communication device, and the first authentication request is received from the second communication device, the output image is output to the output unit. The first communication device according to any one of claims 1 to 10, wherein the output image is not output to the output unit when the connection information is stored in the memory.

12. A computer program for a first communication device, The first communication device is A first wireless interface for performing wireless communication in accordance with the Wi-Fi standard, Output section, Equipped with a computer, The computer program provides the following components to the computer, namely: A first authentication request receiving unit receives a first authentication request in accordance with DPP (Device Provisioning Protocol) from a second communication device via the first wireless interface, wherein the first authentication request does not include the MAC address assigned to the first wireless interface as the destination address. When the first authentication request is received from the second communication device, an output control unit causes the output unit to output an output image obtained using the first key, which is the bootstrapping key of the first communication device. After the output image is output, the second authentication request receiving unit receives a second authentication request in accordance with the DPP, which is the second authentication request using the first key, from the second communication device via the first wireless interface. When the second authentication request is received from the second communication device, a connection information communication unit communicates connection information in accordance with the DPP to the second communication device via the first wireless interface, wherein the connection information is information for establishing a wireless connection in accordance with the Wi-Fi standard between the first or second communication device and an external device, the connection information communication unit, A computer program that functions as such.

13. An application program for a second communication device, The second communication device is A second wireless interface for performing wireless communication in accordance with the Wi-Fi standard, Camera and, Equipped with a computer, The aforementioned application program controls the computer as follows: A first authentication request transmission unit that transmits a first authentication request in accordance with DPP (Device Provisioning Protocol) via the second wireless interface, wherein the first authentication request does not include as a destination address the MAC address assigned to the first wireless interface of the first communication device for performing wireless communication in accordance with the Wi-Fi standard, When the first authentication request is transmitted to the first communication device, and an output image obtained using the first key, which is the bootstrapping key of the first communication device, is output by the first communication device, and the output image is captured by the camera, an acquisition unit acquires the first key, When the first key is obtained, a second authentication request transmission unit transmits a second authentication request in accordance with the DPP, which utilizes the first key, to the first communication device via the second wireless interface. When the second authentication request is transmitted to the first communication device, a connection information communication unit communicates connection information in accordance with the DPP with the first communication device via the second wireless interface, wherein the connection information is information for establishing a wireless connection in accordance with the Wi-Fi standard between the first or second communication device and an external device, An application program that functions as such.

14. The application program according to claim 13, wherein the first authentication request transmission unit transmits a first authentication request using a second key, which is a bootstrapping key, to the first communication device.

Citation Information

Patent Citations

  • Network device search system, network device, and network search program

    JP2014010718A

  • Communication device and computer program for communication device

    JP2019180036A

  • Communication device and computer program therefor

    JP2021057760A